From 98df9e58509214c728c48c4ef40a636bbfcadbeb Mon Sep 17 00:00:00 2001 From: speakeasybot Date: Tue, 1 Sep 2026 00:59:01 +0000 Subject: [PATCH 1/2] =?UTF-8?q?##=20Go=20SDK=20Changes:=20*=20`Conductoron?= =?UTF-8?q?eApi.AccessReviewTemplate.Create()`:=20=20=20*=20=20`request.Re?= =?UTF-8?q?quest`=20**Changed**=20(Breaking=20=E2=9A=A0=EF=B8=8F)=20=20=20?= =?UTF-8?q?*=20=20`response.AccessReviewTemplate`=20**Changed**=20*=20`Con?= =?UTF-8?q?ductoroneApi.AccessReviewTemplate.Update()`:=20=20=20*=20=20`re?= =?UTF-8?q?quest.Request.AccessReviewTemplateServiceUpdateRequest.AccessRe?= =?UTF-8?q?viewTemplate`=20**Changed**=20(Breaking=20=E2=9A=A0=EF=B8=8F)?= =?UTF-8?q?=20=20=20*=20=20`response.AccessReviewTemplate`=20**Changed**?= =?UTF-8?q?=20*=20`ConductoroneApi.A2Ui.GetSurfaceProvenance()`:=20**Added?= =?UTF-8?q?**=20*=20`ConductoroneApi.AccessReviewReport.List()`:=20**Added?= =?UTF-8?q?**=20*=20`ConductoroneApi.AccessReviewActions.GenerateReport()`?= =?UTF-8?q?:=20**Added**=20*=20`ConductoroneApi.McpResource.Get()`:=20**Ad?= =?UTF-8?q?ded**=20*=20`ConductoroneApi.McpResource.List()`:=20**Added**?= =?UTF-8?q?=20*=20`ConductoroneApi.McpResource.ListHistory()`:=20**Added**?= =?UTF-8?q?=20*=20`ConductoroneApi.McpResource.Search()`:=20**Added**=20*?= =?UTF-8?q?=20`ConductoroneApi.McpResource.Update()`:=20**Added**=20*=20`C?= =?UTF-8?q?onductoroneApi.McpAccessProfile.SearchAccessProfiles()`:=20**Ad?= =?UTF-8?q?ded**=20*=20`ConductoroneApi.AppEntitlementSearch.SearchReachab?= =?UTF-8?q?leResourcesForUser()`:=20**Added**=20*=20`ConductoroneApi.AppMa?= =?UTF-8?q?nagedState.Get()`:=20**Added**=20*=20`ConductoroneApi.AppManage?= =?UTF-8?q?dState.List()`:=20**Added**=20*=20`ConductoroneApi.AppManagedSt?= =?UTF-8?q?ate.Promote()`:=20**Added**=20*=20`ConductoroneApi.SsoApplicati?= =?UTF-8?q?on.BatchDeleteSubjectCompatibility()`:=20**Added**=20*=20`Condu?= =?UTF-8?q?ctoroneApi.SsoApplication.BatchImportSubjectCompatibility()`:?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.SsoApplication.Create()`:?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.SsoApplication.CreateClient?= =?UTF-8?q?()`:=20**Added**=20*=20`ConductoroneApi.SsoApplication.Delete()?= =?UTF-8?q?`:=20**Added**=20*=20`ConductoroneApi.SsoApplication.DeleteClie?= =?UTF-8?q?nt()`:=20**Added**=20*=20`ConductoroneApi.SsoApplication.Get()`?= =?UTF-8?q?:=20**Added**=20*=20`ConductoroneApi.SsoApplication.List()`:=20?= =?UTF-8?q?**Added**=20*=20`ConductoroneApi.SsoApplication.ListClients()`:?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.SsoApplication.ListHistory(?= =?UTF-8?q?)`:=20**Added**=20*=20`ConductoroneApi.SsoApplication.ParseSaml?= =?UTF-8?q?ServiceProviderMetadata()`:=20**Added**=20*=20`ConductoroneApi.?= =?UTF-8?q?SsoApplication.RotateClientSecret()`:=20**Added**=20*=20`Conduc?= =?UTF-8?q?toroneApi.SsoApplication.Search()`:=20**Added**=20*=20`Conducto?= =?UTF-8?q?roneApi.SsoApplication.Update()`:=20**Added**=20*=20`Conductoro?= =?UTF-8?q?neApi.SsoApplication.UpdateClient()`:=20**Added**=20*=20`Conduc?= =?UTF-8?q?toroneApi.UiConversations.EnsureOnboardingSession()`:=20**Added?= =?UTF-8?q?**=20*=20`ConductoroneApi.FindingSettings.ListFindingSettings()?= =?UTF-8?q?`:=20**Added**=20*=20`ConductoroneApi.FindingSettings.UpdateFin?= =?UTF-8?q?dingSettings()`:=20**Added**=20*=20`ConductoroneApi.AppCap.Dele?= =?UTF-8?q?te()`:=20**Added**=20*=20`ConductoroneApi.AppCap.Get()`:=20**Ad?= =?UTF-8?q?ded**=20*=20`ConductoroneApi.AppCap.List()`:=20**Added**=20*=20?= =?UTF-8?q?`ConductoroneApi.AppCap.ListHistory()`:=20**Added**=20*=20`Cond?= =?UTF-8?q?uctoroneApi.AppCap.SetLimit()`:=20**Added**=20*=20`Conductorone?= =?UTF-8?q?Api.AppCap.Suspend()`:=20**Added**=20*=20`ConductoroneApi.AppCa?= =?UTF-8?q?p.Unsuspend()`:=20**Added**=20*=20`ConductoroneApi.FundAssignme?= =?UTF-8?q?nt.ClearExtension()`:=20**Added**=20*=20`ConductoroneApi.FundAs?= =?UTF-8?q?signment.Delete()`:=20**Added**=20*=20`ConductoroneApi.FundAssi?= =?UTF-8?q?gnment.Get()`:=20**Added**=20*=20`ConductoroneApi.FundAssignmen?= =?UTF-8?q?t.GrantExtension()`:=20**Added**=20*=20`ConductoroneApi.FundAss?= =?UTF-8?q?ignment.ListHistory()`:=20**Added**=20*=20`ConductoroneApi.Fund?= =?UTF-8?q?Assignment.Search()`:=20**Added**=20*=20`ConductoroneApi.FundAs?= =?UTF-8?q?signment.SetLimit()`:=20**Added**=20*=20`ConductoroneApi.FundAs?= =?UTF-8?q?signment.Suspend()`:=20**Added**=20*=20`ConductoroneApi.FundAss?= =?UTF-8?q?ignment.Unsuspend()`:=20**Added**=20*=20`ConductoroneApi.MyFund?= =?UTF-8?q?Limits.Delete()`:=20**Added**=20*=20`ConductoroneApi.MyFundLimi?= =?UTF-8?q?ts.List()`:=20**Added**=20*=20`ConductoroneApi.MyFundLimits.Lis?= =?UTF-8?q?tHistory()`:=20**Added**=20*=20`ConductoroneApi.MyFundLimits.Pa?= =?UTF-8?q?use()`:=20**Added**=20*=20`ConductoroneApi.MyFundLimits.Resume(?= =?UTF-8?q?)`:=20**Added**=20*=20`ConductoroneApi.MyFundLimits.SetLimit()`?= =?UTF-8?q?:=20**Added**=20*=20`ConductoroneApi.FundPolicy.Create()`:=20**?= =?UTF-8?q?Added**=20*=20`ConductoroneApi.FundPolicy.Delete()`:=20**Added*?= =?UTF-8?q?*=20*=20`ConductoroneApi.FundPolicy.FreezeTenant()`:=20**Added*?= =?UTF-8?q?*=20*=20`ConductoroneApi.FundPolicy.Get()`:=20**Added**=20*=20`?= =?UTF-8?q?ConductoroneApi.FundPolicy.ListHistory()`:=20**Added**=20*=20`C?= =?UTF-8?q?onductoroneApi.FundPolicy.SetOrgCeiling()`:=20**Added**=20*=20`?= =?UTF-8?q?ConductoroneApi.FundPolicy.UnfreezeTenant()`:=20**Added**=20*?= =?UTF-8?q?=20`ConductoroneApi.FundPolicy.Update()`:=20**Added**=20*=20`Co?= =?UTF-8?q?nductoroneApi.FundRule.Create()`:=20**Added**=20*=20`Conductoro?= =?UTF-8?q?neApi.FundRule.Delete()`:=20**Added**=20*=20`ConductoroneApi.Fu?= =?UTF-8?q?ndRule.Get()`:=20**Added**=20*=20`ConductoroneApi.FundRule.List?= =?UTF-8?q?()`:=20**Added**=20*=20`ConductoroneApi.FundRule.ListHistory()`?= =?UTF-8?q?:=20**Added**=20*=20`ConductoroneApi.FundRule.Search()`:=20**Ad?= =?UTF-8?q?ded**=20*=20`ConductoroneApi.FundRule.Update()`:=20**Added**=20?= =?UTF-8?q?*=20`ConductoroneApi.GatewayKey.List()`:=20**Added**=20*=20`Con?= =?UTF-8?q?ductoroneApi.GatewayKey.Mint()`:=20**Added**=20*=20`Conductoron?= =?UTF-8?q?eApi.GatewayKey.Revoke()`:=20**Added**=20*=20`ConductoroneApi.P?= =?UTF-8?q?roviderCredential.Clear()`:=20**Added**=20*=20`ConductoroneApi.?= =?UTF-8?q?ProviderCredential.Get()`:=20**Added**=20*=20`ConductoroneApi.P?= =?UTF-8?q?roviderCredential.Set()`:=20**Added**=20*=20`ConductoroneApi.Re?= =?UTF-8?q?porting.Delete()`:=20**Added**=20*=20`ConductoroneApi.Reporting?= =?UTF-8?q?.Get()`:=20**Added**=20*=20`ConductoroneApi.Reporting.GetRunPro?= =?UTF-8?q?venance()`:=20**Added**=20*=20`ConductoroneApi.Reporting.List()?= =?UTF-8?q?`:=20**Added**=20*=20`ConductoroneApi.Reporting.Run()`:=20**Add?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.Reporting.Save()`:=20**Added**=20*?= =?UTF-8?q?=20`ConductoroneApi.Reporting.Update()`:=20**Added**=20*=20`Con?= =?UTF-8?q?ductoroneApi.RoleMiningManagement.EvaluateEntitlementSelection(?= =?UTF-8?q?)`:=20**Added**=20*=20`ConductoroneApi.SsoSettings.Get()`:=20**?= =?UTF-8?q?Added**=20*=20`ConductoroneApi.SsoSettings.ListHistory()`:=20**?= =?UTF-8?q?Added**=20*=20`ConductoroneApi.SsoSettings.Update()`:=20**Added?= =?UTF-8?q?**=20*=20`ConductoroneApi.TaskActions.RetryProvisioning()`:=20*?= =?UTF-8?q?*Added**=20*=20`ConductoroneApi.A2Ui.ListSurfaces()`:=20=20`res?= =?UTF-8?q?ponse.Surfaces[].Components[]`=20**Changed**=20*=20`Conductoron?= =?UTF-8?q?eApi.AccessReview.Create()`:=20=20`response.AccessReview.Access?= =?UTF-8?q?Review.ColumnConfig.OrderedColumns`=20**Added**=20*=20`Conducto?= =?UTF-8?q?roneApi.AccessReview.Get()`:=20=20`response.AccessReview.Access?= =?UTF-8?q?Review.ColumnConfig.OrderedColumns`=20**Added**=20*=20`Conducto?= =?UTF-8?q?roneApi.AccessReview.List()`:=20=20`response.List[].AccessRevie?= =?UTF-8?q?w.ColumnConfig.OrderedColumns`=20**Added**=20*=20`ConductoroneA?= =?UTF-8?q?pi.AccessReview.Update()`:=20=20=20*=20=20`request.Request.Acce?= =?UTF-8?q?ssReviewServiceUpdateRequest.AccessReview.ColumnConfig.OrderedC?= =?UTF-8?q?olumns`=20**Added**=20=20=20*=20=20`response.AccessReview.Acces?= =?UTF-8?q?sReview.ColumnConfig.OrderedColumns`=20**Added**=20*=20`Conduct?= =?UTF-8?q?oroneApi.AccessReviewTemplate.Get()`:=20=20`response.AccessRevi?= =?UTF-8?q?ewTemplate`=20**Changed**=20*=20`ConductoroneApi.AppUser.List()?= =?UTF-8?q?`:=20=20`response.List[].AppUser`=20**Changed**=20*=20`Conducto?= =?UTF-8?q?roneApi.AppUser.ListAppUsersForUser()`:=20=20`response.List[].A?= =?UTF-8?q?ppUser`=20**Changed**=20*=20`ConductoroneApi.AppUser.ListOwnedS?= =?UTF-8?q?erviceAccounts()`:=20=20`response.List[].AppUser`=20**Changed**?= =?UTF-8?q?=20*=20`ConductoroneApi.AppUser.Search()`:=20=20=20*=20=20`requ?= =?UTF-8?q?est.Request`=20**Changed**=20=20=20*=20=20`response.List[].AppU?= =?UTF-8?q?ser`=20**Changed**=20*=20`ConductoroneApi.AppUser.Update()`:=20?= =?UTF-8?q?=20`response.AppUserView.AppUser`=20**Changed**=20*=20`Conducto?= =?UTF-8?q?roneApi.Apps.Create()`:=20=20=20*=20=20`request.Request.MatchBa?= =?UTF-8?q?tonRef`=20**Added**=20=20=20*=20=20`response.App.MatchBatonRef`?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.Apps.Get()`:=20=20`response?= =?UTF-8?q?.App.MatchBatonRef`=20**Added**=20*=20`ConductoroneApi.Apps.Lis?= =?UTF-8?q?t()`:=20=20`response.List[].MatchBatonRef`=20**Added**=20*=20`C?= =?UTF-8?q?onductoroneApi.Apps.Update()`:=20=20=20*=20=20`request.Request.?= =?UTF-8?q?UpdateAppRequest.App.MatchBatonRef`=20**Added**=20=20=20*=20=20?= =?UTF-8?q?`response.App.MatchBatonRef`=20**Added**=20*=20`ConductoroneApi?= =?UTF-8?q?.McpTool.Get()`:=20=20`response.Tool`=20**Changed**=20*=20`Cond?= =?UTF-8?q?uctoroneApi.McpTool.List()`:=20=20`response.Tools[]`=20**Change?= =?UTF-8?q?d**=20*=20`ConductoroneApi.McpTool.ListHistory()`:=20=20`respon?= =?UTF-8?q?se.List[].Snapshot`=20**Changed**=20*=20`ConductoroneApi.McpToo?= =?UTF-8?q?l.Search()`:=20=20=20*=20=20`request.Request.McpToolServiceSear?= =?UTF-8?q?chRequest.IncludeRequestable`=20**Added**=20=20=20*=20=20`respo?= =?UTF-8?q?nse.List[]`=20**Changed**=20*=20`ConductoroneApi.McpTool.Update?= =?UTF-8?q?()`:=20=20`response.Tool`=20**Changed**=20*=20`ConductoroneApi.?= =?UTF-8?q?McpAccessProfile.Create()`:=20=20`response.Profile`=20**Changed?= =?UTF-8?q?**=20*=20`ConductoroneApi.McpAccessProfile.Get()`:=20=20`respon?= =?UTF-8?q?se.Profile`=20**Changed**=20*=20`ConductoroneApi.McpAccessProfi?= =?UTF-8?q?le.GetByAppEntitlementId()`:=20=20`response.Profile`=20**Change?= =?UTF-8?q?d**=20*=20`ConductoroneApi.McpAccessProfile.List()`:=20=20`resp?= =?UTF-8?q?onse.Profiles[]`=20**Changed**=20*=20`ConductoroneApi.McpAccess?= =?UTF-8?q?Profile.Update()`:=20=20`response.Profile`=20**Changed**=20*=20?= =?UTF-8?q?`ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesF?= =?UTF-8?q?orTools()`:=20=20`response.AccessProfilesForTools[].AccessProfi?= =?UTF-8?q?les[]`=20**Changed**=20*=20`ConductoroneApi.AppEntitlements.Cre?= =?UTF-8?q?ate()`:=20=20=20*=20=20`request.Request.CreateAppEntitlementReq?= =?UTF-8?q?uest.ProvisionPolicy`=20**Changed**=20=20=20*=20=20`response.Ap?= =?UTF-8?q?pEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlace?= =?UTF-8?q?ment`=20**Added**=20*=20`ConductoroneApi.AppEntitlements.Get()`?= =?UTF-8?q?:=20=20`response.AppEntitlementView.AppEntitlement.Deprovisione?= =?UTF-8?q?rPolicy.DevicePlacement`=20**Added**=20*=20`ConductoroneApi.App?= =?UTF-8?q?Entitlements.List()`:=20=20=20*=20=20`request.Request`=20**Chan?= =?UTF-8?q?ged**=20=20=20*=20=20`response.List[].AppEntitlement.Deprovisio?= =?UTF-8?q?nerPolicy.DevicePlacement`=20**Added**=20*=20`ConductoroneApi.A?= =?UTF-8?q?ppEntitlements.ListForAppResource()`:=20=20`response.List[].App?= =?UTF-8?q?Entitlement.DeprovisionerPolicy.DevicePlacement`=20**Added**=20?= =?UTF-8?q?*=20`ConductoroneApi.AppEntitlements.ListForAppUser()`:=20=20`r?= =?UTF-8?q?esponse.List[].AppEntitlement.DeprovisionerPolicy.DevicePlaceme?= =?UTF-8?q?nt`=20**Added**=20*=20`ConductoroneApi.AppEntitlements.ListUser?= =?UTF-8?q?s()`:=20=20`response.List[].AppUser.AppUser`=20**Changed**=20*?= =?UTF-8?q?=20`ConductoroneApi.AppEntitlements.Update()`:=20=20=20*=20=20`?= =?UTF-8?q?request.Request.UpdateAppEntitlementRequest.Entitlement.Deprovi?= =?UTF-8?q?sionerPolicy`=20**Changed**=20=20=20*=20=20`response.AppEntitle?= =?UTF-8?q?mentView.AppEntitlement.DeprovisionerPolicy.DevicePlacement`=20?= =?UTF-8?q?**Added**=20*=20`ConductoroneApi.AppEntitlementSearch.Search()`?= =?UTF-8?q?:=20=20`response.List[].AppEntitlement.DeprovisionerPolicy.Devi?= =?UTF-8?q?cePlacement`=20**Added**=20*=20`ConductoroneApi.AppEntitlementS?= =?UTF-8?q?earch.SearchAppEntitlementsForAppUser()`:=20=20`response.List[]?= =?UTF-8?q?.AppEntitlement.DeprovisionerPolicy.DevicePlacement`=20**Added*?= =?UTF-8?q?*=20*=20`ConductoroneApi.AppEntitlementSearch.SearchAppEntitlem?= =?UTF-8?q?entsWithExpired()`:=20=20`response.List[].AppUser`=20**Changed*?= =?UTF-8?q?*=20*=20`ConductoroneApi.AppEntitlementSearch.SearchGrants()`:?= =?UTF-8?q?=20=20`response.List[]`=20**Changed**=20*=20`ConductoroneApi.Ap?= =?UTF-8?q?pEntitlementUserBinding.SearchPastGrants()`:=20=20`response.Lis?= =?UTF-8?q?t[].History.Id`=20**Added**=20*=20`ConductoroneApi.McpServer.Ge?= =?UTF-8?q?t()`:=20=20`response.McpServer.EndpointUrlLocked`=20**Added**?= =?UTF-8?q?=20*=20`ConductoroneApi.McpServer.GetCatalog()`:=20=20`response?= =?UTF-8?q?.CatalogEntry`=20**Changed**=20*=20`ConductoroneApi.McpServer.L?= =?UTF-8?q?ist()`:=20=20`response.List[].EndpointUrlLocked`=20**Added**=20?= =?UTF-8?q?*=20`ConductoroneApi.McpServer.ListCatalog()`:=20=20`response.L?= =?UTF-8?q?ist[]`=20**Changed**=20*=20`ConductoroneApi.McpServer.Register(?= =?UTF-8?q?)`:=20=20=20*=20=20`request.Request.McpServerServiceRegisterReq?= =?UTF-8?q?uest.AccessProfileIds`=20**Added**=20=20=20*=20=20`response`=20?= =?UTF-8?q?**Changed**=20*=20`ConductoroneApi.McpServer.SearchWithToolCoun?= =?UTF-8?q?t()`:=20=20`response.List[].McpServer.EndpointUrlLocked`=20**Ad?= =?UTF-8?q?ded**=20*=20`ConductoroneApi.McpServer.Update()`:=20=20`respons?= =?UTF-8?q?e.McpServer.EndpointUrlLocked`=20**Added**=20*=20`ConductoroneA?= =?UTF-8?q?pi.McpServer.UpdateCredentials()`:=20=20`response.McpServer.End?= =?UTF-8?q?pointUrlLocked`=20**Added**=20*=20`ConductoroneApi.AppResourceT?= =?UTF-8?q?ype.CreateManuallyManagedResourceType()`:=20=20=20*=20=20`reque?= =?UTF-8?q?st.Request.CreateManuallyManagedResourceTypeRequest.ResourceTyp?= =?UTF-8?q?e.Enum(clawAgent)`=20**Added**=20*=20`ConductoroneApi.Auth.Intr?= =?UTF-8?q?ospect()`:=20=20`response.DisabledModules`=20**Added**=20*=20`C?= =?UTF-8?q?onductoroneApi.Automation.CreateAutomation()`:=20=20=20*=20=20`?= =?UTF-8?q?request.Request.AutomationSteps[].CreateRevokeTasksV2.GrantSour?= =?UTF-8?q?ceFilter`=20**Added**=20=20=20*=20=20`response.Automation.Autom?= =?UTF-8?q?ationSteps[].CreateRevokeTasksV2.GrantSourceFilter`=20**Added**?= =?UTF-8?q?=20*=20`ConductoroneApi.Automation.GetAutomation()`:=20=20`resp?= =?UTF-8?q?onse.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSour?= =?UTF-8?q?ceFilter`=20**Added**=20*=20`ConductoroneApi.Automation.ListAut?= =?UTF-8?q?omations()`:=20=20`response.List[].AutomationSteps[].CreateRevo?= =?UTF-8?q?keTasksV2.GrantSourceFilter`=20**Added**=20*=20`ConductoroneApi?= =?UTF-8?q?.Automation.UpdateAutomation()`:=20=20=20*=20=20`request.Reques?= =?UTF-8?q?t.UpdateAutomationRequest.Automation.AutomationSteps[].CreateRe?= =?UTF-8?q?vokeTasksV2.GrantSourceFilter`=20**Added**=20=20=20*=20=20`resp?= =?UTF-8?q?onse.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSour?= =?UTF-8?q?ceFilter`=20**Added**=20*=20`ConductoroneApi.RequestCatalogMana?= =?UTF-8?q?gement.Create()`:=20=20=20*=20=20`request.Request.Type`=20**Add?= =?UTF-8?q?ed**=20=20=20*=20=20`response.RequestCatalogView.RequestCatalog?= =?UTF-8?q?`=20**Changed**=20*=20`ConductoroneApi.RequestCatalogManagement?= =?UTF-8?q?.Get()`:=20=20`response.RequestCatalogView.RequestCatalog`=20**?= =?UTF-8?q?Changed**=20*=20`ConductoroneApi.RequestCatalogManagement.List(?= =?UTF-8?q?)`:=20=20`response.List[].RequestCatalog`=20**Changed**=20*=20`?= =?UTF-8?q?ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAcc?= =?UTF-8?q?ess()`:=20=20`response.List[].AppEntitlement.DeprovisionerPolic?= =?UTF-8?q?y.DevicePlacement`=20**Added**=20*=20`ConductoroneApi.RequestCa?= =?UTF-8?q?talogManagement.ListEntitlementsPerCatalog()`:=20=20`response.L?= =?UTF-8?q?ist[].AppEntitlement.DeprovisionerPolicy.DevicePlacement`=20**A?= =?UTF-8?q?dded**=20*=20`ConductoroneApi.RequestCatalogManagement.Update()?= =?UTF-8?q?`:=20=20=20*=20=20`request.Request.RequestCatalogManagementServ?= =?UTF-8?q?iceUpdateRequest.Catalog.AccessEntitlements[].DeprovisionerPoli?= =?UTF-8?q?cy`=20**Changed**=20=20=20*=20=20`response.RequestCatalogView.R?= =?UTF-8?q?equestCatalog`=20**Changed**=20*=20`ConductoroneApi.ConnectorCa?= =?UTF-8?q?talog.ConfigurationSchema()`:=20=20`response.FormSchema.Fields[?= =?UTF-8?q?].StringField`=20**Changed**=20*=20`ConductoroneApi.Finding.Bul?= =?UTF-8?q?kCreateFindingTasks()`:=20=20=20*=20=20`request.Request.SearchR?= =?UTF-8?q?equest.FindingTypes[]`=20**Changed**=20*=20`ConductoroneApi.Fin?= =?UTF-8?q?ding.BulkUpdateFindingState()`:=20=20`request.Request`=20**Chan?= =?UTF-8?q?ged**=20*=20`ConductoroneApi.Finding.CreateFinding()`:=20=20`re?= =?UTF-8?q?sponse.Finding`=20**Changed**=20*=20`ConductoroneApi.Finding.Cr?= =?UTF-8?q?eateFindingTask()`:=20=20`response.Finding`=20**Changed**=20*?= =?UTF-8?q?=20`ConductoroneApi.Finding.GetFinding()`:=20=20`response.Findi?= =?UTF-8?q?ng`=20**Changed**=20*=20`ConductoroneApi.Finding.UpdateFindingS?= =?UTF-8?q?tate()`:=20=20`response.Finding`=20**Changed**=20*=20`Conductor?= =?UTF-8?q?oneApi.FindingRoutingRule.CreateFindingRoutingRule()`:=20=20=20?= =?UTF-8?q?*=20=20`request.Request.RoutingRule`=20**Changed**=20=20=20*=20?= =?UTF-8?q?=20`response.RoutingRule`=20**Changed**=20*=20`ConductoroneApi.?= =?UTF-8?q?FindingRoutingRule.GetFindingRoutingRule()`:=20=20`response.Rou?= =?UTF-8?q?tingRule`=20**Changed**=20*=20`ConductoroneApi.FindingRoutingRu?= =?UTF-8?q?le.ListFindingRoutingRules()`:=20=20`response.List[]`=20**Chang?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.FindingRoutingRule.UpdateFindingRou?= =?UTF-8?q?tingRule()`:=20=20=20*=20=20`request.Request.UpdateFindingRouti?= =?UTF-8?q?ngRuleRequest.RoutingRule`=20**Changed**=20=20=20*=20=20`respon?= =?UTF-8?q?se.RoutingRule`=20**Changed**=20*=20`ConductoroneApi.FindingSea?= =?UTF-8?q?rch.Search()`:=20=20=20*=20=20`request.Request.FindingTypes[]`?= =?UTF-8?q?=20**Changed**=20=20=20*=20=20`response.List[]`=20**Changed**?= =?UTF-8?q?=20*=20`ConductoroneApi.FindingTransformationRule.CreateFinding?= =?UTF-8?q?TransformationRule()`:=20=20=20*=20=20`request.Request.Transfor?= =?UTF-8?q?mationRule.FindingType`=20**Added**=20=20=20*=20=20`response.Tr?= =?UTF-8?q?ansformationRule.FindingType`=20**Added**=20*=20`ConductoroneAp?= =?UTF-8?q?i.FindingTransformationRule.GetFindingTransformationRule()`:=20?= =?UTF-8?q?=20`response.TransformationRule.FindingType`=20**Added**=20*=20?= =?UTF-8?q?`ConductoroneApi.FindingTransformationRule.ListFindingTransform?= =?UTF-8?q?ationRules()`:=20=20`response.List[].FindingType`=20**Added**?= =?UTF-8?q?=20*=20`ConductoroneApi.FindingTransformationRule.UpdateFinding?= =?UTF-8?q?TransformationRule()`:=20=20=20*=20=20`request.Request.UpdateFi?= =?UTF-8?q?ndingTransformationRuleRequest.TransformationRule.FindingType`?= =?UTF-8?q?=20**Added**=20=20=20*=20=20`response.TransformationRule.Findin?= =?UTF-8?q?gType`=20**Added**=20*=20`ConductoroneApi.Functions.CreateFunct?= =?UTF-8?q?ion()`:=20=20`response.Function`=20**Changed**=20*=20`Conductor?= =?UTF-8?q?oneApi.Functions.GetFunction()`:=20=20`response.Function`=20**C?= =?UTF-8?q?hanged**=20*=20`ConductoroneApi.Functions.ListFunctions()`:=20?= =?UTF-8?q?=20`response.List[]`=20**Changed**=20*=20`ConductoroneApi.Funct?= =?UTF-8?q?ions.UpdateFunction()`:=20=20=20*=20=20`request.Request`=20**Ch?= =?UTF-8?q?anged**=20=20=20*=20=20`response`=20**Changed**=20*=20`Conducto?= =?UTF-8?q?roneApi.Hooks.Create()`:=20=20=20*=20=20`request.Request`=20**C?= =?UTF-8?q?hanged**=20=20=20*=20=20`response.Hook`=20**Changed**=20*=20`Co?= =?UTF-8?q?nductoroneApi.Hooks.Get()`:=20=20`response.Hook`=20**Changed**?= =?UTF-8?q?=20*=20`ConductoroneApi.Hooks.List()`:=20=20`response.List[]`?= =?UTF-8?q?=20**Changed**=20*=20`ConductoroneApi.Hooks.Update()`:=20=20=20?= =?UTF-8?q?*=20=20`request.Request.HooksServiceUpdateRequest.Hook`=20**Cha?= =?UTF-8?q?nged**=20=20=20*=20=20`response.Hook`=20**Changed**=20*=20`Cond?= =?UTF-8?q?uctoroneApi.Policies.Create()`:=20=20=20*=20=20`request.Request?= =?UTF-8?q?`=20**Changed**=20=20=20*=20=20`response.Policy`=20**Changed**?= =?UTF-8?q?=20*=20`ConductoroneApi.Policies.Get()`:=20=20`response.Policy`?= =?UTF-8?q?=20**Changed**=20*=20`ConductoroneApi.Policies.List()`:=20=20`r?= =?UTF-8?q?esponse.List[]`=20**Changed**=20*=20`ConductoroneApi.Policies.U?= =?UTF-8?q?pdate()`:=20=20=20*=20=20`request.Request.UpdatePolicyRequest.P?= =?UTF-8?q?olicy`=20**Changed**=20=20=20*=20=20`response.Policy`=20**Chang?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.RequestSchema.Create()`:=20=20=20*?= =?UTF-8?q?=20=20`request.Request.Fields[].StringField`=20**Changed**=20?= =?UTF-8?q?=20=20*=20=20`response.RequestSchema.Form.Fields[].StringField`?= =?UTF-8?q?=20**Changed**=20*=20`ConductoroneApi.RequestSchema.Get()`:=20?= =?UTF-8?q?=20`response.RequestSchema.Form.Fields[].StringField`=20**Chang?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.RequestSchema.Update()`:=20=20=20*?= =?UTF-8?q?=20=20`request.Request.RequestSchemaServiceUpdateRequest.Reques?= =?UTF-8?q?tSchema.Form.Fields[].StringField`=20**Changed**=20=20=20*=20?= =?UTF-8?q?=20`response.RequestSchema.Form.Fields[].StringField`=20**Chang?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.RoleMiningManagement.GetCustomAnaly?= =?UTF-8?q?sisResult()`:=20=20`response.CutoffImpactPoints`=20**Added**=20?= =?UTF-8?q?*=20`ConductoroneApi.AppSearch.Search()`:=20=20`response.List[]?= =?UTF-8?q?.MatchBatonRef`=20**Added**=20*=20`ConductoroneApi.AutomationSe?= =?UTF-8?q?arch.SearchAutomationTemplateVersions()`:=20=20`response.List[]?= =?UTF-8?q?.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter`=20**A?= =?UTF-8?q?dded**=20*=20`ConductoroneApi.AutomationSearch.SearchAutomation?= =?UTF-8?q?s()`:=20=20`response.List[].AutomationSteps[].CreateRevokeTasks?= =?UTF-8?q?V2.GrantSourceFilter`=20**Added**=20*=20`ConductoroneApi.Findin?= =?UTF-8?q?gAudit.Search()`:=20=20=20*=20=20`request.Request.EventTypes[]`?= =?UTF-8?q?=20**Changed**=20=20=20*=20=20`response.List[].EventType`=20**C?= =?UTF-8?q?hanged**=20*=20`ConductoroneApi.FunctionsSearch.Search()`:=20?= =?UTF-8?q?=20`response.List[]`=20**Changed**=20*=20`ConductoroneApi.Hooks?= =?UTF-8?q?Search.Search()`:=20=20`response.List[]`=20**Changed**=20*=20`C?= =?UTF-8?q?onductoroneApi.ExternalClientSearch.Search()`:=20=20`response.L?= =?UTF-8?q?ist[].ClientIdType.Enum(clientIdTypeApp)`=20**Added**=20*=20`Co?= =?UTF-8?q?nductoroneApi.PolicySearch.Search()`:=20=20=20*=20=20`request.R?= =?UTF-8?q?equest`=20**Changed**=20=20=20*=20=20`response.List[]`=20**Chan?= =?UTF-8?q?ged**=20*=20`ConductoroneApi.RequestCatalogSearch.SearchEntitle?= =?UTF-8?q?ments()`:=20=20`response.List[].Entitlement.AppEntitlement.Depr?= =?UTF-8?q?ovisionerPolicy.DevicePlacement`=20**Added**=20*=20`Conductoron?= =?UTF-8?q?eApi.TaskSearch.Search()`:=20=20=20*=20=20`request.Request.Acco?= =?UTF-8?q?untStatuses`=20**Added**=20=20=20*=20=20`response.List[].Task`?= =?UTF-8?q?=20**Changed**=20*=20`ConductoroneApi.UserSearch.Search()`:=20?= =?UTF-8?q?=20=20*=20=20`request.Request.SourceAppIds`=20**Added**=20*=20`?= =?UTF-8?q?ConductoroneApi.AiGovernanceSettings.Get()`:=20=20`response.AiG?= =?UTF-8?q?overnanceSettings.UntrustedJudgeDisable`=20**Added**=20*=20`Con?= =?UTF-8?q?ductoroneApi.AiGovernanceSettings.ListHistory()`:=20=20`respons?= =?UTF-8?q?e.List[].Snapshot.UntrustedJudgeDisable`=20**Added**=20*=20`Con?= =?UTF-8?q?ductoroneApi.AiGovernanceSettings.Update()`:=20=20=20*=20=20`re?= =?UTF-8?q?quest.Request.AiGovernanceSettings.UntrustedJudgeDisable`=20**A?= =?UTF-8?q?dded**=20=20=20*=20=20`response.AiGovernanceSettings.UntrustedJ?= =?UTF-8?q?udgeDisable`=20**Added**=20*=20`ConductoroneApi.OrgNotification?= =?UTF-8?q?Settings.Get()`:=20=20`response.OrgNotificationSettings.Channel?= =?UTF-8?q?Settings`=20**Changed**=20*=20`ConductoroneApi.OrgNotificationS?= =?UTF-8?q?ettings.Update()`:=20=20=20*=20=20`request.Request.ChannelSetti?= =?UTF-8?q?ngs`=20**Changed**=20=20=20*=20=20`response.OrgNotificationSett?= =?UTF-8?q?ings.ChannelSettings`=20**Changed**=20*=20`ConductoroneApi.User?= =?UTF-8?q?NotificationSettings.Get()`:=20=20`response.UserNotificationSet?= =?UTF-8?q?tings.ChannelSettings`=20**Changed**=20*=20`ConductoroneApi.Use?= =?UTF-8?q?rNotificationSettings.Update()`:=20=20=20*=20=20`request.Reques?= =?UTF-8?q?t.ChannelSettings`=20**Changed**=20=20=20*=20=20`response.UserN?= =?UTF-8?q?otificationSettings.ChannelSettings`=20**Changed**=20*=20`Condu?= =?UTF-8?q?ctoroneApi.RequestSettings.Get()`:=20=20`response.RequestSettin?= =?UTF-8?q?gs.MaxBulkEntitlementSelection`=20**Added**=20*=20`Conductorone?= =?UTF-8?q?Api.RequestSettings.Update()`:=20=20=20*=20=20`request.Request.?= =?UTF-8?q?RequestSettings.MaxBulkEntitlementSelection`=20**Added**=20=20?= =?UTF-8?q?=20*=20=20`response.RequestSettings.MaxBulkEntitlementSelection?= =?UTF-8?q?`=20**Added**=20*=20`ConductoroneApi.Task.CreateActionTask()`:?= =?UTF-8?q?=20=20`response.TaskView.Task`=20**Changed**=20*=20`Conductoron?= =?UTF-8?q?eApi.Task.CreateGrantTask()`:=20=20`response.TaskView.Task`=20*?= =?UTF-8?q?*Changed**=20*=20`ConductoroneApi.Task.CreateOffboardingTask()`?= =?UTF-8?q?:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Conductoro?= =?UTF-8?q?neApi.Task.CreateResourceActionTask()`:=20=20`response.TaskView?= =?UTF-8?q?.Task`=20**Changed**=20*=20`ConductoroneApi.Task.CreateRevokeTa?= =?UTF-8?q?sk()`:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Condu?= =?UTF-8?q?ctoroneApi.Task.Get()`:=20=20`response.TaskView.Task`=20**Chang?= =?UTF-8?q?ed**=20*=20`ConductoroneApi.TaskAudit.List()`:=20=20=20*=20=20`?= =?UTF-8?q?request.Request.ExcludeComments`=20**Added**=20=20=20*=20=20`re?= =?UTF-8?q?sponse`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Approv?= =?UTF-8?q?e()`:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Conduc?= =?UTF-8?q?toroneApi.TaskActions.ApproveWithStepUp()`:=20=20`response.Task?= =?UTF-8?q?View.Task`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Clo?= =?UTF-8?q?se()`:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Condu?= =?UTF-8?q?ctoroneApi.TaskActions.Comment()`:=20=20`response.TaskView.Task?= =?UTF-8?q?`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Deny()`:=20?= =?UTF-8?q?=20`response.TaskView.Task`=20**Changed**=20*=20`ConductoroneAp?= =?UTF-8?q?i.TaskActions.EscalateToEmergencyAccess()`:=20=20`response.Task?= =?UTF-8?q?View.Task`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Har?= =?UTF-8?q?dReset()`:=20=20`response.TaskView.Task`=20**Changed**=20*=20`C?= =?UTF-8?q?onductoroneApi.TaskActions.ProcessNow()`:=20=20`response.TaskVi?= =?UTF-8?q?ew.Task`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Reass?= =?UTF-8?q?ign()`:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Cond?= =?UTF-8?q?uctoroneApi.TaskActions.Restart()`:=20=20`response.TaskView.Tas?= =?UTF-8?q?k`=20**Changed**=20*=20`ConductoroneApi.TaskActions.SkipStep()`?= =?UTF-8?q?:=20=20`response.TaskView.Task`=20**Changed**=20*=20`Conductoro?= =?UTF-8?q?neApi.TaskActions.UpdateGrantDuration()`:=20=20`response.TaskVi?= =?UTF-8?q?ew.Task`=20**Changed**=20*=20`ConductoroneApi.TaskActions.Updat?= =?UTF-8?q?eRequestData()`:=20=20`response.TaskView.Task`=20**Changed**=20?= =?UTF-8?q?*=20`ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner()?= =?UTF-8?q?`:=20=20`response.ConnectorOwnerEntitlement.AppEntitlement.Depr?= =?UTF-8?q?ovisionerPolicy.DevicePlacement`=20**Added**=20*=20`Conductoron?= =?UTF-8?q?eApi.ConnectorOwnersV2.GetEntitlementOwner()`:=20=20`response.C?= =?UTF-8?q?onnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.Dev?= =?UTF-8?q?icePlacement`=20**Added**=20*=20`ConductoroneApi.ConnectorOwner?= =?UTF-8?q?sV2.SearchEntitlementOwners()`:=20=20`response.List[].AppEntitl?= =?UTF-8?q?ement.DeprovisionerPolicy.DevicePlacement`=20**Added**=20*=20`C?= =?UTF-8?q?onductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner()`?= =?UTF-8?q?:=20=20`response.AppEntitlementOwnerEntitlement.AppEntitlement.?= =?UTF-8?q?DeprovisionerPolicy.DevicePlacement`=20**Added**=20*=20`Conduct?= =?UTF-8?q?oroneApi.AppEntitlementOwnersV2.GetEntitlementOwner()`:=20=20`r?= =?UTF-8?q?esponse.AppEntitlementOwnerEntitlement.AppEntitlement.Deprovisi?= =?UTF-8?q?onerPolicy.DevicePlacement`=20**Added**=20*=20`ConductoroneApi.?= =?UTF-8?q?AppEntitlementOwnersV2.SearchEntitlementOwners()`:=20=20`respon?= =?UTF-8?q?se.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement`?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.AppOwnersV2.CreateEntitleme?= =?UTF-8?q?ntOwner()`:=20=20`response.AppOwnerEntitlement.AppEntitlement.D?= =?UTF-8?q?eprovisionerPolicy.DevicePlacement`=20**Added**=20*=20`Conducto?= =?UTF-8?q?roneApi.AppOwnersV2.GetEntitlementOwner()`:=20=20`response.AppO?= =?UTF-8?q?wnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacem?= =?UTF-8?q?ent`=20**Added**=20*=20`ConductoroneApi.AppOwnersV2.SearchEntit?= =?UTF-8?q?lementOwners()`:=20=20`response.List[].AppEntitlement.Deprovisi?= =?UTF-8?q?onerPolicy.DevicePlacement`=20**Added**=20*=20`ConductoroneApi.?= =?UTF-8?q?AppResourceOwnersV2.CreateEntitlementOwner()`:=20=20`response.A?= =?UTF-8?q?ppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.D?= =?UTF-8?q?evicePlacement`=20**Added**=20*=20`ConductoroneApi.AppResourceO?= =?UTF-8?q?wnersV2.GetEntitlementOwner()`:=20=20`response.AppResourceOwner?= =?UTF-8?q?Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement`?= =?UTF-8?q?=20**Added**=20*=20`ConductoroneApi.AppResourceOwnersV2.SearchE?= =?UTF-8?q?ntitlementOwners()`:=20=20`response.List[].AppEntitlement.Depro?= =?UTF-8?q?visionerPolicy.DevicePlacement`=20**Added**=20*=20`Conductorone?= =?UTF-8?q?Api.AppUserOwnersV2.CreateEntitlementOwner()`:=20=20`response.A?= =?UTF-8?q?ppUserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.Devic?= =?UTF-8?q?ePlacement`=20**Added**=20*=20`ConductoroneApi.AppUserOwnersV2.?= =?UTF-8?q?SearchEntitlementOwners()`:=20=20`response.List[].AppEntitlemen?= =?UTF-8?q?t.DeprovisionerPolicy.DevicePlacement`=20**Added**=20*=20`Condu?= =?UTF-8?q?ctoroneApi.UserOwnersV2.CreateEntitlementOwner()`:=20=20`respon?= =?UTF-8?q?se.UserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.Devi?= =?UTF-8?q?cePlacement`=20**Added**=20*=20`ConductoroneApi.UserOwnersV2.Se?= =?UTF-8?q?archEntitlementOwners()`:=20=20`response.List[].AppEntitlement.?= =?UTF-8?q?DeprovisionerPolicy.DevicePlacement`=20**Added**?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .speakeasy/gen.lock | 4832 +- .speakeasy/logs/changes/changes.html | 4846 +- .speakeasy/logs/changes/changes.md | 3525 +- .speakeasy/logs/changes/new.openapi.yaml | 48873 ++++++---- .speakeasy/logs/changes/old.openapi.yaml | 77977 ++++++++++------ .speakeasy/logs/naming.log | 579 +- .speakeasy/workflow.lock | 10 +- README.md | 134 + RELEASES.md | 12 +- a2ui.go | 208 + accessreviewactions.go | 247 + accessreviewreport.go | 242 + aigovernancesettings.go | 6 +- appcap.go | 1515 + appentitlementroutingrule.go | 18 +- appentitlements.go | 17 +- appentitlementsearch.go | 217 + appmanagedstate.go | 660 + automation.go | 2 +- conductoroneapi.go | 36 +- connector.go | 5 +- contacts.go | 10 +- ...1a2uiservicegetsurfaceprovenancerequest.md | 9 + ...a2uiservicegetsurfaceprovenanceresponse.md | 11 + ...viewactionsservicegeneratereportrequest.md | 9 + ...iewactionsservicegeneratereportresponse.md | 11 + ...wv1accessreviewreportservicelistrequest.md | 10 + ...v1accessreviewreportservicelistresponse.md | 11 + ...ofileservicesearchaccessprofilesrequest.md | 10 + ...fileservicesearchaccessprofilesresponse.md | 11 + ...overnancev1mcpresourceservicegetrequest.md | 10 + ...vernancev1mcpresourceservicegetresponse.md | 11 + ...ev1mcpresourceservicelisthistoryrequest.md | 12 + ...v1mcpresourceservicelisthistoryresponse.md | 11 + ...vernancev1mcpresourceservicelistrequest.md | 11 + ...ernancev1mcpresourceservicelistresponse.md | 11 + ...rnancev1mcpresourceservicesearchrequest.md | 10 + ...nancev1mcpresourceservicesearchresponse.md | 11 + ...rnancev1mcpresourceserviceupdaterequest.md | 11 + ...nancev1mcpresourceserviceupdateresponse.md | 11 + ...searchreachableresourcesforuserresponse.md | 11 + .../c1apiappv1appentitlementslistrequest.md | 4 +- ...piappv1appmanagedstateservicegetrequest.md | 10 + ...iappv1appmanagedstateservicegetresponse.md | 11 + ...iappv1appmanagedstateservicelistrequest.md | 11 + ...appv1appmanagedstateservicelistresponse.md | 11 + ...pv1appmanagedstateservicepromoterequest.md | 11 + ...v1appmanagedstateservicepromoteresponse.md | 11 + .../c1apiappv1appscreateresponse.md | 2 +- ...iappv1connectorserviceforcesyncresponse.md | 12 +- ...sserviceensureonboardingsessionresponse.md | 11 + ...tingsservicelistfindingsettingsresponse.md | 11 + ...ngsserviceupdatefindingsettingsresponse.md | 11 + .../c1apifundsv1appcapservicedeleterequest.md | 9 + ...c1apifundsv1appcapservicedeleteresponse.md | 11 + .../c1apifundsv1appcapservicegetrequest.md | 8 + .../c1apifundsv1appcapservicegetresponse.md | 11 + ...ifundsv1appcapservicelisthistoryrequest.md | 10 + ...fundsv1appcapservicelisthistoryresponse.md | 11 + .../c1apifundsv1appcapservicelistrequest.md | 9 + .../c1apifundsv1appcapservicelistresponse.md | 11 + ...1apifundsv1appcapservicesetlimitrequest.md | 9 + ...apifundsv1appcapservicesetlimitresponse.md | 11 + ...c1apifundsv1appcapservicesuspendrequest.md | 9 + ...1apifundsv1appcapservicesuspendresponse.md | 11 + ...apifundsv1appcapserviceunsuspendrequest.md | 9 + ...pifundsv1appcapserviceunsuspendresponse.md | 11 + ...dassignmentserviceclearextensionrequest.md | 9 + ...assignmentserviceclearextensionresponse.md | 11 + ...ndsv1fundassignmentservicedeleterequest.md | 9 + ...dsv1fundassignmentservicedeleteresponse.md | 11 + ...ifundsv1fundassignmentservicegetrequest.md | 8 + ...fundsv1fundassignmentservicegetresponse.md | 11 + ...dassignmentservicegrantextensionrequest.md | 9 + ...assignmentservicegrantextensionresponse.md | 11 + ...fundassignmentservicelisthistoryrequest.md | 10 + ...undassignmentservicelisthistoryresponse.md | 11 + ...dsv1fundassignmentservicesearchresponse.md | 11 + ...sv1fundassignmentservicesetlimitrequest.md | 9 + ...v1fundassignmentservicesetlimitresponse.md | 11 + ...dsv1fundassignmentservicesuspendrequest.md | 9 + ...sv1fundassignmentservicesuspendresponse.md | 11 + ...v1fundassignmentserviceunsuspendrequest.md | 9 + ...1fundassignmentserviceunsuspendresponse.md | 11 + ...ifundsv1fundpolicyservicecreateresponse.md | 11 + ...ifundsv1fundpolicyservicedeleteresponse.md | 11 + ...v1fundpolicyservicefreezetenantresponse.md | 11 + ...1apifundsv1fundpolicyservicegetresponse.md | 11 + ...dsv1fundpolicyservicelisthistoryrequest.md | 9 + ...sv1fundpolicyservicelisthistoryresponse.md | 11 + ...1fundpolicyservicesetorgceilingresponse.md | 11 + ...fundpolicyserviceunfreezetenantresponse.md | 11 + ...ifundsv1fundpolicyserviceupdateresponse.md | 11 + ...apifundsv1fundruleservicecreateresponse.md | 11 + ...1apifundsv1fundruleservicedeleterequest.md | 9 + ...apifundsv1fundruleservicedeleteresponse.md | 11 + .../c1apifundsv1fundruleservicegetrequest.md | 8 + .../c1apifundsv1fundruleservicegetresponse.md | 11 + ...undsv1fundruleservicelisthistoryrequest.md | 10 + ...ndsv1fundruleservicelisthistoryresponse.md | 11 + .../c1apifundsv1fundruleservicelistrequest.md | 9 + ...c1apifundsv1fundruleservicelistresponse.md | 11 + ...apifundsv1fundruleservicesearchresponse.md | 11 + ...1apifundsv1fundruleserviceupdaterequest.md | 9 + ...apifundsv1fundruleserviceupdateresponse.md | 11 + ...fundsv1myfundlimitsservicedeleterequest.md | 9 + ...undsv1myfundlimitsservicedeleteresponse.md | 11 + ...v1myfundlimitsservicelisthistoryrequest.md | 10 + ...1myfundlimitsservicelisthistoryresponse.md | 11 + ...pifundsv1myfundlimitsservicelistrequest.md | 9 + ...ifundsv1myfundlimitsservicelistresponse.md | 11 + ...ifundsv1myfundlimitsservicepauserequest.md | 9 + ...fundsv1myfundlimitsservicepauseresponse.md | 11 + ...fundsv1myfundlimitsserviceresumerequest.md | 9 + ...undsv1myfundlimitsserviceresumeresponse.md | 11 + ...ndsv1myfundlimitsservicesetlimitrequest.md | 9 + ...dsv1myfundlimitsservicesetlimitresponse.md | 11 + ...mgatewayv1gatewaykeyservicelistresponse.md | 11 + ...mgatewayv1gatewaykeyservicemintresponse.md | 11 + ...gatewayv1gatewaykeyservicerevokerequest.md | 9 + ...atewayv1gatewaykeyservicerevokeresponse.md | 11 + ...v1providercredentialserviceclearrequest.md | 9 + ...1providercredentialserviceclearresponse.md | 11 + ...ayv1providercredentialservicegetrequest.md | 8 + ...yv1providercredentialservicegetresponse.md | 11 + ...ayv1providercredentialservicesetrequest.md | 9 + ...yv1providercredentialservicesetresponse.md | 11 + ...eportingv1reportingservicedeleterequest.md | 9 + ...portingv1reportingservicedeleteresponse.md | 11 + ...pireportingv1reportingservicegetrequest.md | 8 + ...ireportingv1reportingservicegetresponse.md | 11 + ...reportingservicegetrunprovenancerequest.md | 9 + ...eportingservicegetrunprovenanceresponse.md | 11 + ...ireportingv1reportingservicelistrequest.md | 9 + ...reportingv1reportingservicelistresponse.md | 11 + ...pireportingv1reportingservicerunrequest.md | 9 + ...ireportingv1reportingservicerunresponse.md | 11 + ...reportingv1reportingservicesaveresponse.md | 11 + ...eportingv1reportingserviceupdaterequest.md | 9 + ...portingv1reportingserviceupdateresponse.md | 11 + ...viceevaluateentitlementselectionrequest.md | 9 + ...iceevaluateentitlementselectionresponse.md | 11 + ...ebatchdeletesubjectcompatibilityrequest.md | 10 + ...batchdeletesubjectcompatibilityresponse.md | 11 + ...ebatchimportsubjectcompatibilityrequest.md | 10 + ...batchimportsubjectcompatibilityresponse.md | 11 + ...soapplicationservicecreateclientrequest.md | 10 + ...oapplicationservicecreateclientresponse.md | 11 + ...ssov1ssoapplicationservicecreaterequest.md | 9 + ...sov1ssoapplicationservicecreateresponse.md | 11 + ...soapplicationservicedeleteclientrequest.md | 10 + ...oapplicationservicedeleteclientresponse.md | 11 + ...ssov1ssoapplicationservicedeleterequest.md | 10 + ...sov1ssoapplicationservicedeleteresponse.md | 11 + ...apissov1ssoapplicationservicegetrequest.md | 9 + ...pissov1ssoapplicationservicegetresponse.md | 11 + ...ssoapplicationservicelistclientsrequest.md | 11 + ...soapplicationservicelistclientsresponse.md | 11 + ...ssoapplicationservicelisthistoryrequest.md | 11 + ...soapplicationservicelisthistoryresponse.md | 11 + ...pissov1ssoapplicationservicelistrequest.md | 10 + ...issov1ssoapplicationservicelistresponse.md | 11 + ...arsesamlserviceprovidermetadataresponse.md | 11 + ...icationservicerotateclientsecretrequest.md | 10 + ...cationservicerotateclientsecretresponse.md | 11 + ...sov1ssoapplicationservicesearchresponse.md | 11 + ...soapplicationserviceupdateclientrequest.md | 10 + ...oapplicationserviceupdateclientresponse.md | 11 + ...ssov1ssoapplicationserviceupdaterequest.md | 10 + ...sov1ssoapplicationserviceupdateresponse.md | 11 + ...c1apissov1ssosettingsservicegetresponse.md | 11 + ...ov1ssosettingsservicelisthistoryrequest.md | 9 + ...v1ssosettingsservicelisthistoryresponse.md | 11 + ...pissov1ssosettingsserviceupdateresponse.md | 11 + ...kactionsserviceretryprovisioningrequest.md | 9 + ...actionsserviceretryprovisioningresponse.md | 11 + docs/pkg/models/shared/a2uicomponent.md | 4 + .../pkg/models/shared/a2uiprovenanceobject.md | 12 + .../pkg/models/shared/a2uiprovenancesource.md | 17 + docs/pkg/models/shared/a2uiprovenancestep.md | 13 + .../shared/a2uiprovenancesteprecordtype.md | 51 + .../models/shared/a2uiprovenancetoolcall.md | 12 + ...a2uiservicegetsurfaceprovenanceresponse.md | 21 + ...viewactionsservicegeneratereportrequest.md | 11 + ...iewactionsservicegeneratereportresponse.md | 9 + .../models/shared/accessreviewcolumnconfig.md | 7 +- docs/pkg/models/shared/accessreviewreport.md | 16 + .../shared/accessreviewreportcolumnconfig.md | 10 + .../accessreviewreportcolumnconfigcolumns.md | 50 + .../models/shared/accessreviewreportformat.md | 26 + .../accessreviewreportservicelistresponse.md | 11 + .../models/shared/accessreviewreportstate.md | 26 + .../shared/accessreviewtaskcolumnref.md | 19 + .../pkg/models/shared/accessreviewtemplate.md | 2 + .../shared/accessreviewtemplateinput.md | 2 + docs/pkg/models/shared/accountstatuses.md | 24 + docs/pkg/models/shared/actions.md | 3 +- docs/pkg/models/shared/actiontype.md | 3 +- docs/pkg/models/shared/agentstatus.md | 28 + docs/pkg/models/shared/agentstatuses.md | 14 +- .../pkg/models/shared/aigovernancesettings.md | 1 + docs/pkg/models/shared/app.md | 1 + docs/pkg/models/shared/appcap.md | 14 + docs/pkg/models/shared/appcaphistoryentry.md | 11 + .../shared/appcapservicedeleterequest.md | 9 + .../shared/appcapservicedeleteresponse.md | 9 + .../models/shared/appcapservicegetresponse.md | 10 + .../appcapservicelisthistoryresponse.md | 11 + .../shared/appcapservicelistresponse.md | 11 + .../shared/appcapservicesetlimitrequest.md | 11 + .../shared/appcapservicesetlimitresponse.md | 10 + .../shared/appcapservicesuspendrequest.md | 10 + .../shared/appcapservicesuspendresponse.md | 10 + .../shared/appcapserviceunsuspendrequest.md | 9 + .../shared/appcapserviceunsuspendresponse.md | 10 + ...esearchreachableresourcesforuserrequest.md | 14 + ...searchreachableresourcesforuserresponse.md | 12 + .../appentitlementuserbindinghistory.md | 1 + docs/pkg/models/shared/appinput.md | 1 + docs/pkg/models/shared/appmanagedstate.md | 16 + .../models/shared/appmanagedstatebinding.md | 17 + .../appmanagedstatebindingexpandmask.md | 10 + .../shared/appmanagedstatebindingref.md | 12 +- .../shared/appmanagedstatebindingview.md | 12 + .../models/shared/appmanagedstatemanaged.md | 10 + .../models/shared/appmanagedstateunmanaged.md | 9 + docs/pkg/models/shared/appmatchbatonref.md | 12 + docs/pkg/models/shared/appuser.md | 39 +- docs/pkg/models/shared/appusernhitype.md | 27 + .../shared/appuserservicesearchrequest.md | 2 + docs/pkg/models/shared/blockoutputconfig.md | 12 + docs/pkg/models/shared/blocktoolcallconfig.md | 11 + docs/pkg/models/shared/builtin.md | 55 + docs/pkg/models/shared/builtinpattern.md | 14 + docs/pkg/models/shared/bulkreprocessaction.md | 30 + .../shared/bulkupdatefindingstaterequest.md | 2 + docs/pkg/models/shared/c1metriccard.md | 15 + .../models/shared/c1metriccardscomponent.md | 12 + docs/pkg/models/shared/c1tablecomponent.md | 17 + docs/pkg/models/shared/c1tablerow.md | 11 + docs/pkg/models/shared/c1userfilter.md | 7 +- .../shared/clearprovidercredentialrequest.md | 9 + .../shared/clearprovidercredentialresponse.md | 10 + docs/pkg/models/shared/clientidtype.md | 3 +- docs/pkg/models/shared/component.md | 31 + docs/pkg/models/shared/composite.md | 8 +- docs/pkg/models/shared/compositeformat.md | 26 + docs/pkg/models/shared/connectoractionref.md | 10 +- .../shared/connectoractionrefoperation.md | 24 + docs/pkg/models/shared/connectorexpandmask.md | 6 +- .../shared/connectorsyncfailingevidence.md | 14 + .../models/shared/connectorsyncfailingtype.md | 11 + docs/pkg/models/shared/createapprequest.md | 5 +- docs/pkg/models/shared/createappresponse.md | 2 +- docs/pkg/models/shared/createpolicyrequest.md | 4 +- docs/pkg/models/shared/createrevoketasksv2.md | 29 +- .../shared/credentialexpiringevidence.md | 11 + .../models/shared/credentialexpiringtype.md | 18 + .../credentialpubliclyexposedevidence.md | 17 + .../shared/credentialpubliclyexposedtype.md | 22 + docs/pkg/models/shared/datefield.md | 15 + .../models/shared/deactivatedownerdetail.md | 13 + .../models/shared/deactivatedownerevidence.md | 10 + .../pkg/models/shared/deactivatedownertype.md | 13 + .../shared/deactivatedownertypesource.md | 26 + .../shared/decoypubliclyexposedevidence.md | 17 + .../models/shared/decoypubliclyexposedtype.md | 12 + .../shared/defaultidtokensignedresponsealg.md | 27 + docs/pkg/models/shared/defaultsubjecttype.md | 28 + docs/pkg/models/shared/deltasentiment.md | 26 + docs/pkg/models/shared/destination.md | 25 + docs/pkg/models/shared/detaillevel.md | 25 + .../models/shared/deviceplacementprovision.md | 10 + docs/pkg/models/shared/disabledmodules.md | 22 + .../shared/disabledreasoncircuitbreaker.md | 12 +- .../disabledreasoncircuitbreakerperiod.md | 27 + .../pkg/models/shared/emailchannelsettings.md | 2 + .../shared/encodedcontentguardconfig.md | 13 + docs/pkg/models/shared/encryptionalgorithm.md | 26 + .../shared/ensureonboardingsessionrequest.md | 9 + .../shared/ensureonboardingsessionresponse.md | 11 + .../shared/entitlementcutoffimpactpoint.md | 13 + docs/pkg/models/shared/entitlementref.md | 10 +- .../evaluateentitlementselectionrequest.md | 14 + .../evaluateentitlementselectionresponse.md | 13 + docs/pkg/models/shared/evaluateexpressions.md | 4 +- docs/pkg/models/shared/event.md | 3 +- docs/pkg/models/shared/eventtypes.md | 4 +- docs/pkg/models/shared/expression.md | 4 +- docs/pkg/models/shared/finding.md | 117 +- docs/pkg/models/shared/findingaudience.md | 16 + .../pkg/models/shared/findingaudienceusers.md | 10 + .../shared/findingauditeventeventtype.md | 4 +- docs/pkg/models/shared/findingdispatcher.md | 27 + .../shared/findingdispatchoutcomenotify.md | 12 + docs/pkg/models/shared/findingroutingrule.md | 2 + .../pkg/models/shared/findingsearchrequest.md | 2 +- .../shared/findingsearchrequestnhitypes.md | 24 + .../pkg/models/shared/findingsettingsentry.md | 15 + .../shared/findingsettingsentryfindingtype.md | 36 + .../shared/findingtransformationrule.md | 1 + .../findingtransformationrulefindingtype.md | 36 + docs/pkg/models/shared/findingtype.md | 36 + docs/pkg/models/shared/findingtypes.md | 8 +- docs/pkg/models/shared/findingtypesetting.md | 15 + .../shared/findingtypesettingfindingtype.md | 36 + docs/pkg/models/shared/forcesyncresponse.md | 3 +- docs/pkg/models/shared/format.md | 19 +- docs/pkg/models/shared/formstringfield.md | 2 + docs/pkg/models/shared/function.md | 4 +- .../functionsserviceupdatefunctionrequest.md | 10 +- .../functionsserviceupdatefunctionresponse.md | 7 +- docs/pkg/models/shared/fundassignment.md | 14 + .../shared/fundassignmenthistoryentry.md | 11 + ...dassignmentserviceclearextensionrequest.md | 9 + ...assignmentserviceclearextensionresponse.md | 10 + .../fundassignmentservicedeleterequest.md | 9 + .../fundassignmentservicedeleteresponse.md | 9 + .../fundassignmentservicegetresponse.md | 10 + ...dassignmentservicegrantextensionrequest.md | 12 + ...assignmentservicegrantextensionresponse.md | 10 + ...undassignmentservicelisthistoryresponse.md | 11 + .../fundassignmentservicesearchrequest.md | 12 + .../fundassignmentservicesearchresponse.md | 11 + .../fundassignmentservicesetlimitrequest.md | 11 + ...dassignmentservicesetlimitrequestperiod.md | 28 + .../fundassignmentservicesetlimitresponse.md | 10 + .../fundassignmentservicesuspendrequest.md | 10 + .../fundassignmentservicesuspendresponse.md | 10 + .../fundassignmentserviceunsuspendrequest.md | 9 + .../fundassignmentserviceunsuspendresponse.md | 10 + docs/pkg/models/shared/fundpolicy.md | 18 + .../models/shared/fundpolicyhistoryentry.md | 11 + docs/pkg/models/shared/fundpolicyperiod.md | 28 + .../shared/fundpolicyservicecreaterequest.md | 12 + .../fundpolicyservicecreaterequestperiod.md | 28 + .../shared/fundpolicyservicecreateresponse.md | 10 + .../shared/fundpolicyservicedeleterequest.md | 9 + .../shared/fundpolicyservicedeleteresponse.md | 9 + .../fundpolicyservicefreezetenantrequest.md | 10 + .../fundpolicyservicefreezetenantresponse.md | 10 + .../shared/fundpolicyservicegetresponse.md | 10 + .../fundpolicyservicelisthistoryresponse.md | 11 + .../fundpolicyservicesetorgceilingrequest.md | 11 + ...policyservicesetorgceilingrequestperiod.md | 28 + .../fundpolicyservicesetorgceilingresponse.md | 10 + .../fundpolicyserviceunfreezetenantrequest.md | 9 + ...fundpolicyserviceunfreezetenantresponse.md | 10 + .../shared/fundpolicyserviceupdaterequest.md | 11 + .../shared/fundpolicyserviceupdateresponse.md | 10 + docs/pkg/models/shared/fundrule.md | 17 + .../pkg/models/shared/fundrulehistoryentry.md | 11 + .../shared/fundruleservicecreaterequest.md | 13 + .../shared/fundruleservicecreateresponse.md | 10 + .../shared/fundruleservicedeleterequest.md | 9 + .../shared/fundruleservicedeleteresponse.md | 9 + .../shared/fundruleservicegetresponse.md | 10 + .../fundruleservicelisthistoryresponse.md | 11 + .../shared/fundruleservicelistresponse.md | 11 + .../shared/fundruleservicesearchrequest.md | 12 + .../shared/fundruleservicesearchresponse.md | 11 + .../shared/fundruleserviceupdaterequest.md | 11 + .../shared/fundruleserviceupdateresponse.md | 10 + docs/pkg/models/shared/gatewaykey.md | 15 + .../getappmanagedstatebindingresponse.md | 11 + ...tappmanagedstatebindingresponseexpanded.md | 11 + .../shared/getcustomanalysisresultresponse.md | 1 + .../shared/getprovidercredentialresponse.md | 10 + docs/pkg/models/shared/grantfilter.md | 10 +- .../shared/grantfiltergrantsourcefilter.md | 25 + docs/pkg/models/shared/grantsourcefilter.md | 7 +- docs/pkg/models/shared/headerstyle.md | 25 + docs/pkg/models/shared/hook.md | 29 +- docs/pkg/models/shared/hookfilter.md | 9 +- docs/pkg/models/shared/hookinput.md | 25 +- .../shared/hooksservicecreaterequest.md | 3 + .../shared/hooksservicecreaterequestevent.md | 3 +- .../models/shared/idtokensignedresponsealg.md | 26 + docs/pkg/models/shared/introspectresponse.md | 19 +- .../models/shared/invokefunctiondispatcher.md | 12 + docs/pkg/models/shared/jsonpatchconfig.md | 22 + docs/pkg/models/shared/kindfilter.md | 23 + docs/pkg/models/shared/level.md | 17 +- docs/pkg/models/shared/linkfilterconfig.md | 13 + .../models/shared/linkfilterconfigaction.md | 25 + .../listappmanagedstatebindingsresponse.md | 12 + ...appmanagedstatebindingsresponseexpanded.md | 11 + .../shared/listfindingsettingsresponse.md | 11 + .../models/shared/listgatewaykeysresponse.md | 11 + docs/pkg/models/shared/mcpaccessprofile.md | 26 +- .../models/shared/mcpaccessprofileinput.md | 19 + ...fileservicesearchaccessprofilesresponse.md | 12 + .../mcpaccessprofileserviceupdaterequest.md | 8 +- docs/pkg/models/shared/mcpresource.md | 28 + .../models/shared/mcpresourcehistoryentry.md | 11 + docs/pkg/models/shared/mcpresourceinput.md | 26 + docs/pkg/models/shared/mcpresourcekind.md | 25 + .../shared/mcpresourceservicegetresponse.md | 10 + .../mcpresourceservicelisthistoryresponse.md | 11 + .../shared/mcpresourceservicelistresponse.md | 11 + .../shared/mcpresourceservicesearchrequest.md | 17 + .../mcpresourceservicesearchrequestsortby.md | 27 + .../mcpresourceservicesearchresponse.md | 11 + .../shared/mcpresourceserviceupdaterequest.md | 11 + .../mcpresourceserviceupdateresponse.md | 10 + docs/pkg/models/shared/mcpresourcestate.md | 27 + .../models/shared/mcpservercatalogauthmode.md | 2 + .../mcpservercatalogauthmodeclientidmode.md | 27 + .../models/shared/mcpservercatalogentry.md | 1 + .../shared/mcpserverserviceregisterrequest.md | 1 + .../mcpserverserviceregisterresponse.md | 7 +- docs/pkg/models/shared/mcpserverview.md | 1 + docs/pkg/models/shared/mcptool.md | 46 +- .../shared/mcptoolservicesearchrequest.md | 5 +- ...cptoolservicesearchrequestsortdirection.md | 25 + .../mcptoolservicesearchrequeststatefilter.md | 25 + .../models/shared/mintgatewaykeyrequest.md | 10 + .../models/shared/mintgatewaykeyresponse.md | 11 + docs/pkg/models/shared/money.md | 15 + docs/pkg/models/shared/msteamschannel.md | 11 + .../models/shared/msteamschannelsettings.md | 2 + docs/pkg/models/shared/myfundlimit.md | 14 + .../models/shared/myfundlimithistoryentry.md | 11 + .../myfundlimitsservicedeleterequest.md | 9 + .../myfundlimitsservicedeleteresponse.md | 9 + .../myfundlimitsservicelisthistoryresponse.md | 11 + .../shared/myfundlimitsservicelistresponse.md | 11 + .../shared/myfundlimitsservicepauserequest.md | 10 + .../myfundlimitsservicepauseresponse.md | 10 + .../myfundlimitsserviceresumerequest.md | 9 + .../myfundlimitsserviceresumeresponse.md | 10 + .../myfundlimitsservicesetlimitrequest.md | 11 + ...yfundlimitsservicesetlimitrequestperiod.md | 28 + .../myfundlimitsservicesetlimitresponse.md | 10 + docs/pkg/models/shared/nameformat.md | 26 + docs/pkg/models/shared/nameidformat.md | 30 + docs/pkg/models/shared/nhitypes.md | 14 +- docs/pkg/models/shared/notifydispatcher.md | 16 + docs/pkg/models/shared/oidcclaimmapping.md | 13 + docs/pkg/models/shared/operation.md | 21 +- .../models/shared/payloadfindingdispatch.md | 14 + docs/pkg/models/shared/period.md | 19 +- docs/pkg/models/shared/pkcepolicy.md | 25 + docs/pkg/models/shared/policy.md | 32 +- docs/pkg/models/shared/policyinput.md | 22 +- docs/pkg/models/shared/policyscope.md | 12 + docs/pkg/models/shared/pretoolblockconfig.md | 11 + docs/pkg/models/shared/programref.md | 12 + .../promoteappmanagedstatebindingrequest.md | 12 + .../shared/promptinjectionscanconfig.md | 12 + docs/pkg/models/shared/providercredential.md | 17 + docs/pkg/models/shared/provisioninstance.md | 1 + .../models/shared/provisioninstancestate.md | 1 + docs/pkg/models/shared/provisionpolicy.md | 22 +- .../pkg/models/shared/provisionpolicyinput.md | 22 +- docs/pkg/models/shared/provisionwaitingon.md | 18 + docs/pkg/models/shared/reason.md | 26 + docs/pkg/models/shared/recordtype.md | 52 + docs/pkg/models/shared/recurrencerule.md | 2 +- .../models/shared/recurrencerulefrequency.md | 3 +- docs/pkg/models/shared/report.md | 23 + .../shared/reportingservicedeleterequest.md | 9 + .../shared/reportingservicedeleteresponse.md | 9 + .../shared/reportingservicegetresponse.md | 13 + ...eportingservicegetrunprovenanceresponse.md | 16 + .../shared/reportingservicelistresponse.md | 11 + .../shared/reportingservicerunrequest.md | 9 + .../shared/reportingservicerunresponse.md | 10 + .../shared/reportingservicesaverequest.md | 13 + .../shared/reportingservicesaveresponse.md | 10 + .../shared/reportingserviceupdaterequest.md | 13 + .../shared/reportingserviceupdateresponse.md | 10 + docs/pkg/models/shared/reportrun.md | 29 + docs/pkg/models/shared/reportrunstatus.md | 27 + docs/pkg/models/shared/reportsource.md | 19 + docs/pkg/models/shared/requestcatalog.md | 1 + ...stcatalogmanagementservicecreaterequest.md | 1 + ...talogmanagementservicecreaterequesttype.md | 34 + docs/pkg/models/shared/requestcatalogtype.md | 29 + .../models/shared/requestcreatedpreference.md | 11 + docs/pkg/models/shared/requestsettings.md | 7 +- docs/pkg/models/shared/resourcetype.md | 3 +- .../models/shared/revokegatewaykeyrequest.md | 9 + .../models/shared/revokegatewaykeyresponse.md | 10 + docs/pkg/models/shared/rule.md | 26 +- .../pkg/models/shared/samlattributemapping.md | 14 + docs/pkg/models/shared/samlmetadatafinding.md | 13 + docs/pkg/models/shared/scopeobjecttype.md | 26 + docs/pkg/models/shared/scopeslot.md | 26 + docs/pkg/models/shared/scopeview.md | 29 + .../shared/searchappresourcesrequest.md | 2 +- .../searchappresourcesrequestagentstatuses.md | 24 + .../models/shared/searchcohortusersrequest.md | 12 +- .../shared/searchcohortusersresponse.md | 10 +- .../models/shared/searchpoliciesrequest.md | 25 +- docs/pkg/models/shared/searchusersrequest.md | 43 +- .../pkg/models/shared/secretsmaskingconfig.md | 12 + .../shared/sessionpolicystepuprequired.md | 2 +- .../sessionpolicystepuprequiredlevel.md | 28 + .../shared/setprovidercredentialrequest.md | 12 + ...setprovidercredentialrequestheaderstyle.md | 25 + .../shared/setprovidercredentialresponse.md | 10 + .../pkg/models/shared/slackchannelsettings.md | 2 + docs/pkg/models/shared/slackchanneltarget.md | 13 + docs/pkg/models/shared/slot.md | 25 + docs/pkg/models/shared/spendcontrols.md | 21 + docs/pkg/models/shared/spendcontrolsperiod.md | 30 + docs/pkg/models/shared/spendextension.md | 14 + docs/pkg/models/shared/spendlimit.md | 20 + docs/pkg/models/shared/spendlimitamount.md | 10 + docs/pkg/models/shared/spendlimitblocked.md | 11 + docs/pkg/models/shared/spendlimitunlimited.md | 11 + docs/pkg/models/shared/spendsuspension.md | 13 + docs/pkg/models/shared/ssoapplication.md | 28 + .../shared/ssoapplicationhistoryentry.md | 12 + .../models/shared/ssoapplicationoidcclient.md | 18 + ...licationoidcclientauthclientsecretbasic.md | 9 + ...plicationoidcclientauthclientsecretpost.md | 9 + .../ssoapplicationoidcclientauthentication.md | 21 + .../ssoapplicationoidcclientauthnone.md | 9 + ...oapplicationoidcclientauthprivatekeyjwt.md | 12 + .../shared/ssoapplicationoidcclientconfig.md | 14 + ...soapplicationoidcclientconfigpkcepolicy.md | 27 + .../models/shared/ssoapplicationoidcconfig.md | 11 + .../models/shared/ssoapplicationsamlconfig.md | 20 + ...ebatchdeletesubjectcompatibilityrequest.md | 11 + ...batchdeletesubjectcompatibilityresponse.md | 12 + ...ebatchimportsubjectcompatibilityrequest.md | 13 + ...batchimportsubjectcompatibilityresponse.md | 17 + ...soapplicationservicecreateclientrequest.md | 11 + ...oapplicationservicecreateclientresponse.md | 12 + .../ssoapplicationservicecreaterequest.md | 23 + ...licationservicecreaterequestsubjecttype.md | 27 + .../ssoapplicationservicecreateresponse.md | 12 + ...soapplicationservicedeleteclientrequest.md | 10 + ...oapplicationservicedeleteclientresponse.md | 9 + .../ssoapplicationservicedeleterequest.md | 9 + .../ssoapplicationservicedeleteresponse.md | 9 + .../ssoapplicationservicegetresponse.md | 10 + ...soapplicationservicelistclientsresponse.md | 12 + ...soapplicationservicelisthistoryresponse.md | 12 + .../ssoapplicationservicelistresponse.md | 11 + ...parsesamlserviceprovidermetadatarequest.md | 11 + ...arsesamlserviceprovidermetadataresponse.md | 13 + ...icationservicerotateclientsecretrequest.md | 11 + ...cationservicerotateclientsecretresponse.md | 11 + .../ssoapplicationservicesearchrequest.md | 13 + .../ssoapplicationservicesearchresponse.md | 11 + ...soapplicationserviceupdateclientrequest.md | 12 + ...oapplicationserviceupdateclientresponse.md | 10 + .../ssoapplicationserviceupdaterequest.md | 11 + .../ssoapplicationserviceupdateresponse.md | 10 + docs/pkg/models/shared/ssosettings.md | 16 + .../models/shared/ssosettingshistoryentry.md | 12 + .../shared/ssosettingsservicegetresponse.md | 10 + .../ssosettingsservicelisthistoryresponse.md | 11 + .../shared/ssosettingsserviceupdaterequest.md | 11 + .../ssosettingsserviceupdateresponse.md | 10 + .../models/shared/ssosubjectcompatibility.md | 11 + .../ssosubjectcompatibilitydeleteissue.md | 12 + .../ssosubjectcompatibilityimportentry.md | 12 + .../ssosubjectcompatibilityimportissue.md | 14 + docs/pkg/models/shared/statefilter.md | 16 +- docs/pkg/models/shared/subjecttype.md | 26 + docs/pkg/models/shared/surfaces.md | 23 + docs/pkg/models/shared/systempreference.md | 11 + ...kactionsserviceretryprovisioningrequest.md | 12 + .../models/shared/taskauditaccountdeleted.md | 16 + .../shared/taskauditautomationtriggered.md | 13 + ...skauditconditionalpolicyexecutionresult.md | 17 +- .../pkg/models/shared/taskauditlistrequest.md | 17 +- .../models/shared/taskauditlistresponse.md | 9 +- ...auditprovisionentitlementmergecompleted.md | 11 + ...kauditprovisionentitlementmergetimedout.md | 11 + ...uditprovisionwaitingforentitlementmerge.md | 12 + docs/pkg/models/shared/taskauditview.md | 10 + .../models/shared/taskauditwebhooksuccess.md | 13 +- docs/pkg/models/shared/tasksearchrequest.md | 1 + docs/pkg/models/shared/threshold.md | 27 + docs/pkg/models/shared/tieroverride.md | 25 + .../shared/triggerautomationdispatcher.md | 11 + .../pkg/models/shared/unusedsecretevidence.md | 10 + docs/pkg/models/shared/unusedsecrettype.md | 10 + .../shared/updatefindingsettingsrequest.md | 10 + .../shared/updatefindingsettingsresponse.md | 10 + .../shared/waitingfordeviceplacement.md | 11 + .../shared/waitingforentitlementmerge.md | 11 + docs/pkg/models/shared/webhookdispatcher.md | 11 + .../models/shared/xaaclientaudiencemapping.md | 18 +- docs/sdks/a2ui/README.md | 62 + docs/sdks/accessreviewactions/README.md | 68 + docs/sdks/accessreviewreport/README.md | 66 + docs/sdks/aigovernancesettings/README.md | 6 +- docs/sdks/appcap/README.md | 424 + docs/sdks/appentitlementroutingrule/README.md | 14 +- docs/sdks/appentitlements/README.md | 14 +- docs/sdks/appentitlementsearch/README.md | 60 + docs/sdks/appmanagedstate/README.md | 190 + docs/sdks/automation/README.md | 2 +- docs/sdks/connector/README.md | 4 +- docs/sdks/contacts/README.md | 8 +- docs/sdks/findingsettings/README.md | 119 + docs/sdks/functions/README.md | 12 +- docs/sdks/fundassignment/README.md | 543 + docs/sdks/fundpolicy/README.md | 466 + docs/sdks/fundrule/README.md | 423 + docs/sdks/gatewaykey/README.md | 179 + docs/sdks/hooks/README.md | 15 +- docs/sdks/hookssearch/README.md | 3 +- docs/sdks/mcpaccessprofile/README.md | 60 + docs/sdks/mcpresource/README.md | 319 + docs/sdks/myfundlimits/README.md | 369 + docs/sdks/providercredential/README.md | 188 + docs/sdks/reporting/README.md | 427 + docs/sdks/roleminingmanagement/README.md | 70 +- docs/sdks/ssoapplication/README.md | 927 + docs/sdks/ssosettings/README.md | 177 + docs/sdks/taskactions/README.md | 61 + docs/sdks/uiconversations/README.md | 63 + findingsettings.go | 452 + functions.go | 12 +- fundassignment.go | 1945 + fundpolicy.go | 1737 + fundrule.go | 1521 + gatewaykey.go | 667 + gen.yaml | 5 +- hooks.go | 18 +- hookssearch.go | 4 +- mcpaccessprofile.go | 214 + mcpresource.go | 1093 + myfundlimits.go | 1312 + ...pia2uiv1a2uiservicegetsurfaceprovenance.go | 73 + ...ccessreviewactionsservicegeneratereport.go | 72 + ...ssreviewv1accessreviewreportservicelist.go | 80 + ...ccessprofileservicesearchaccessprofiles.go | 81 + ...1apiaigovernancev1mcpresourceserviceget.go | 80 + ...apiaigovernancev1mcpresourceservicelist.go | 88 + ...vernancev1mcpresourceservicelisthistory.go | 96 + ...iaigovernancev1mcpresourceservicesearch.go | 80 + ...iaigovernancev1mcpresourceserviceupdate.go | 88 + ...hservicesearchreachableresourcesforuser.go | 51 + .../c1apiappv1appentitlementslist.go | 16 + .../c1apiappv1appmanagedstateserviceget.go | 80 + .../c1apiappv1appmanagedstateservicelist.go | 88 + ...c1apiappv1appmanagedstateservicepromote.go | 88 + pkg/models/operations/c1apiappv1appscreate.go | 2 +- .../c1apiappv1connectorserviceforcesync.go | 3 +- ...ersationsserviceensureonboardingsession.go | 50 + ...ndingsettingsservicelistfindingsettings.go | 50 + ...ingsettingsserviceupdatefindingsettings.go | 50 + .../c1apifundsv1appcapservicedelete.go | 72 + .../c1apifundsv1appcapserviceget.go | 64 + .../c1apifundsv1appcapservicelist.go | 72 + .../c1apifundsv1appcapservicelisthistory.go | 80 + .../c1apifundsv1appcapservicesetlimit.go | 72 + .../c1apifundsv1appcapservicesuspend.go | 72 + .../c1apifundsv1appcapserviceunsuspend.go | 72 + ...dsv1fundassignmentserviceclearextension.go | 72 + ...c1apifundsv1fundassignmentservicedelete.go | 72 + .../c1apifundsv1fundassignmentserviceget.go | 64 + ...dsv1fundassignmentservicegrantextension.go | 72 + ...fundsv1fundassignmentservicelisthistory.go | 80 + ...c1apifundsv1fundassignmentservicesearch.go | 50 + ...apifundsv1fundassignmentservicesetlimit.go | 72 + ...1apifundsv1fundassignmentservicesuspend.go | 72 + ...pifundsv1fundassignmentserviceunsuspend.go | 72 + .../c1apifundsv1fundpolicyservicecreate.go | 50 + .../c1apifundsv1fundpolicyservicedelete.go | 50 + ...apifundsv1fundpolicyservicefreezetenant.go | 50 + .../c1apifundsv1fundpolicyserviceget.go | 50 + ...1apifundsv1fundpolicyservicelisthistory.go | 72 + ...pifundsv1fundpolicyservicesetorgceiling.go | 50 + ...ifundsv1fundpolicyserviceunfreezetenant.go | 50 + .../c1apifundsv1fundpolicyserviceupdate.go | 50 + .../c1apifundsv1fundruleservicecreate.go | 50 + .../c1apifundsv1fundruleservicedelete.go | 72 + .../c1apifundsv1fundruleserviceget.go | 64 + .../c1apifundsv1fundruleservicelist.go | 72 + .../c1apifundsv1fundruleservicelisthistory.go | 80 + .../c1apifundsv1fundruleservicesearch.go | 50 + .../c1apifundsv1fundruleserviceupdate.go | 72 + .../c1apifundsv1myfundlimitsservicedelete.go | 72 + .../c1apifundsv1myfundlimitsservicelist.go | 72 + ...pifundsv1myfundlimitsservicelisthistory.go | 80 + .../c1apifundsv1myfundlimitsservicepause.go | 72 + .../c1apifundsv1myfundlimitsserviceresume.go | 72 + ...c1apifundsv1myfundlimitsservicesetlimit.go | 72 + .../c1apillmgatewayv1gatewaykeyservicelist.go | 50 + .../c1apillmgatewayv1gatewaykeyservicemint.go | 50 + ...1apillmgatewayv1gatewaykeyservicerevoke.go | 72 + ...gatewayv1providercredentialserviceclear.go | 72 + ...lmgatewayv1providercredentialserviceget.go | 64 + ...lmgatewayv1providercredentialserviceset.go | 72 + .../c1apireportingv1reportingservicedelete.go | 72 + .../c1apireportingv1reportingserviceget.go | 64 + ...rtingv1reportingservicegetrunprovenance.go | 72 + .../c1apireportingv1reportingservicelist.go | 72 + .../c1apireportingv1reportingservicerun.go | 72 + .../c1apireportingv1reportingservicesave.go | 50 + .../c1apireportingv1reportingserviceupdate.go | 72 + ...mentserviceevaluateentitlementselection.go | 73 + ...nservicebatchdeletesubjectcompatibility.go | 81 + ...nservicebatchimportsubjectcompatibility.go | 81 + .../c1apissov1ssoapplicationservicecreate.go | 72 + ...issov1ssoapplicationservicecreateclient.go | 81 + .../c1apissov1ssoapplicationservicedelete.go | 80 + ...issov1ssoapplicationservicedeleteclient.go | 80 + .../c1apissov1ssoapplicationserviceget.go | 72 + .../c1apissov1ssoapplicationservicelist.go | 80 + ...pissov1ssoapplicationservicelistclients.go | 89 + ...pissov1ssoapplicationservicelisthistory.go | 89 + ...serviceparsesamlserviceprovidermetadata.go | 52 + ...ssoapplicationservicerotateclientsecret.go | 81 + .../c1apissov1ssoapplicationservicesearch.go | 50 + .../c1apissov1ssoapplicationserviceupdate.go | 80 + ...issov1ssoapplicationserviceupdateclient.go | 80 + .../c1apissov1ssosettingsserviceget.go | 50 + ...c1apissov1ssosettingsservicelisthistory.go | 72 + .../c1apissov1ssosettingsserviceupdate.go | 50 + ...skv1taskactionsserviceretryprovisioning.go | 72 + pkg/models/shared/a2uicomponent.go | 18 + pkg/models/shared/a2uiprovenanceobject.go | 91 + pkg/models/shared/a2uiprovenancesource.go | 96 + pkg/models/shared/a2uiprovenancestep.go | 122 + pkg/models/shared/a2uiprovenancetoolcall.go | 52 + ...a2uiservicegetsurfaceprovenanceresponse.go | 126 + ...viewactionsservicegeneratereportrequest.go | 56 + ...iewactionsservicegeneratereportresponse.go | 7 + pkg/models/shared/accessreviewcolumnconfig.go | 17 +- pkg/models/shared/accessreviewreport.go | 135 + .../shared/accessreviewreportcolumnconfig.go | 69 + .../accessreviewreportservicelistresponse.go | 25 + .../shared/accessreviewtaskcolumnref.go | 91 + pkg/models/shared/accessreviewtemplate.go | 18 + pkg/models/shared/aigovernancesettings.go | 17 +- pkg/models/shared/app.go | 20 +- pkg/models/shared/appcap.go | 65 + pkg/models/shared/appcaphistoryentry.go | 23 + .../shared/appcapservicedeleterequest.go | 7 + .../shared/appcapservicedeleteresponse.go | 7 + pkg/models/shared/appcapservicegetresponse.go | 15 + .../appcapservicelisthistoryresponse.go | 25 + .../shared/appcapservicelistresponse.go | 25 + .../shared/appcapservicesetlimitrequest.go | 51 + .../shared/appcapservicesetlimitresponse.go | 15 + .../shared/appcapservicesuspendrequest.go | 16 + .../shared/appcapservicesuspendresponse.go | 15 + .../shared/appcapserviceunsuspendrequest.go | 7 + .../shared/appcapserviceunsuspendresponse.go | 15 + ...esearchreachableresourcesforuserrequest.go | 53 + ...searchreachableresourcesforuserresponse.go | 28 + .../appentitlementuserbindinghistory.go | 9 + pkg/models/shared/appmanagedstate.go | 27 + pkg/models/shared/appmanagedstatebinding.go | 91 + .../appmanagedstatebindingexpandmask.go | 16 + .../shared/appmanagedstatebindingref.go | 8 +- .../shared/appmanagedstatebindingview.go | 33 + pkg/models/shared/appmanagedstatemanaged.go | 16 + pkg/models/shared/appmanagedstateunmanaged.go | 7 + pkg/models/shared/appmatchbatonref.go | 35 + pkg/models/shared/appuser.go | 93 +- .../shared/appuserservicesearchrequest.go | 68 + pkg/models/shared/blockoutputconfig.go | 53 + pkg/models/shared/blocktoolcallconfig.go | 19 + pkg/models/shared/builtinpattern.go | 63 + pkg/models/shared/bulkreprocessaction.go | 48 + .../shared/bulkupdatefindingstaterequest.go | 9 + pkg/models/shared/c1metriccard.go | 82 + pkg/models/shared/c1metriccardscomponent.go | 36 + pkg/models/shared/c1tablecomponent.go | 88 + pkg/models/shared/c1tablerow.go | 21 + pkg/models/shared/c1userfilter.go | 28 + .../shared/clearprovidercredentialrequest.go | 7 + .../shared/clearprovidercredentialresponse.go | 15 + pkg/models/shared/composite.go | 18 +- pkg/models/shared/connectoractionref.go | 16 +- pkg/models/shared/connectorexpandmask.go | 3 +- .../shared/connectorsyncfailingevidence.go | 60 + pkg/models/shared/connectorsyncfailingtype.go | 10 + pkg/models/shared/createapprequest.go | 14 +- pkg/models/shared/createappresponse.go | 2 +- ...reatemanuallymanagedresourcetyperequest.go | 3 +- pkg/models/shared/createpolicyrequest.go | 23 +- pkg/models/shared/createrevoketasksv2.go | 45 +- .../shared/credentialexpiringevidence.go | 40 + pkg/models/shared/credentialexpiringtype.go | 34 + .../credentialpubliclyexposedevidence.go | 93 + .../shared/credentialpubliclyexposedtype.go | 68 + pkg/models/shared/datefield.go | 62 + pkg/models/shared/deactivatedownerdetail.go | 53 + pkg/models/shared/deactivatedownerevidence.go | 16 + pkg/models/shared/deactivatedownertype.go | 45 + .../shared/decoypubliclyexposedevidence.go | 93 + pkg/models/shared/decoypubliclyexposedtype.go | 27 + pkg/models/shared/deviceplacementprovision.go | 16 + .../shared/disabledreasoncircuitbreaker.go | 22 +- pkg/models/shared/emailchannelsettings.go | 16 + .../shared/encodedcontentguardconfig.go | 36 + .../shared/ensureonboardingsessionrequest.go | 7 + .../shared/ensureonboardingsessionresponse.go | 25 + .../shared/entitlementcutoffimpactpoint.go | 36 + pkg/models/shared/entitlementref.go | 6 +- .../evaluateentitlementselectionrequest.go | 45 + .../evaluateentitlementselectionresponse.go | 36 + pkg/models/shared/evaluateexpressions.go | 2 + pkg/models/shared/expression.go | 2 + pkg/models/shared/externalclientinfo.go | 3 +- pkg/models/shared/finding.go | 141 +- pkg/models/shared/findingaudience.go | 21 + pkg/models/shared/findingaudienceusers.go | 16 + pkg/models/shared/findingauditevent.go | 4 +- .../findingauditservicesearchrequest.go | 4 +- pkg/models/shared/findingdispatcher.go | 117 + .../shared/findingdispatchoutcomenotify.go | 34 + pkg/models/shared/findingroutingrule.go | 53 + pkg/models/shared/findingsearchrequest.go | 26 +- pkg/models/shared/findingsettingsentry.go | 66 + .../shared/findingtransformationrule.go | 44 + pkg/models/shared/findingtypesetting.go | 66 + pkg/models/shared/forcesyncresponse.go | 4 +- pkg/models/shared/formstringfield.go | 9 + pkg/models/shared/function.go | 22 + .../functionsserviceupdatefunctionrequest.go | 26 +- .../functionsserviceupdatefunctionresponse.go | 10 +- pkg/models/shared/fundassignment.go | 65 + .../shared/fundassignmenthistoryentry.go | 23 + ...dassignmentserviceclearextensionrequest.go | 7 + ...assignmentserviceclearextensionresponse.go | 15 + .../fundassignmentservicedeleterequest.go | 7 + .../fundassignmentservicedeleteresponse.go | 7 + .../fundassignmentservicegetresponse.go | 15 + ...dassignmentservicegrantextensionrequest.go | 48 + ...assignmentservicegrantextensionresponse.go | 15 + ...undassignmentservicelisthistoryresponse.go | 25 + .../fundassignmentservicesearchrequest.go | 34 + .../fundassignmentservicesearchresponse.go | 25 + .../fundassignmentservicesetlimitrequest.go | 51 + .../fundassignmentservicesetlimitresponse.go | 15 + .../fundassignmentservicesuspendrequest.go | 16 + .../fundassignmentservicesuspendresponse.go | 15 + .../fundassignmentserviceunsuspendrequest.go | 7 + .../fundassignmentserviceunsuspendresponse.go | 15 + pkg/models/shared/fundpolicy.go | 112 + pkg/models/shared/fundpolicyhistoryentry.go | 23 + .../shared/fundpolicyservicecreaterequest.go | 60 + .../shared/fundpolicyservicecreateresponse.go | 15 + .../shared/fundpolicyservicedeleterequest.go | 7 + .../shared/fundpolicyservicedeleteresponse.go | 7 + .../fundpolicyservicefreezetenantrequest.go | 16 + .../fundpolicyservicefreezetenantresponse.go | 15 + .../shared/fundpolicyservicegetresponse.go | 15 + .../fundpolicyservicelisthistoryresponse.go | 25 + .../fundpolicyservicesetorgceilingrequest.go | 51 + .../fundpolicyservicesetorgceilingresponse.go | 15 + .../fundpolicyserviceunfreezetenantrequest.go | 7 + ...fundpolicyserviceunfreezetenantresponse.go | 15 + .../shared/fundpolicyserviceupdaterequest.go | 23 + .../shared/fundpolicyserviceupdateresponse.go | 15 + pkg/models/shared/fundrule.go | 94 + pkg/models/shared/fundrulehistoryentry.go | 23 + .../shared/fundruleservicecreaterequest.go | 41 + .../shared/fundruleservicecreateresponse.go | 15 + .../shared/fundruleservicedeleterequest.go | 7 + .../shared/fundruleservicedeleteresponse.go | 7 + .../shared/fundruleservicegetresponse.go | 15 + .../fundruleservicelisthistoryresponse.go | 25 + .../shared/fundruleservicelistresponse.go | 25 + .../shared/fundruleservicesearchrequest.go | 34 + .../shared/fundruleservicesearchresponse.go | 25 + .../shared/fundruleserviceupdaterequest.go | 23 + .../shared/fundruleserviceupdateresponse.go | 15 + pkg/models/shared/gatewaykey.go | 74 + .../getappmanagedstatebindingresponse.go | 60 + .../shared/getcustomanalysisresultresponse.go | 9 + .../shared/getprovidercredentialresponse.go | 15 + pkg/models/shared/grantfilter.go | 18 +- pkg/models/shared/hook.go | 49 +- pkg/models/shared/hookfilter.go | 19 +- .../shared/hooksservicecreaterequest.go | 27 +- pkg/models/shared/introspectresponse.go | 34 + pkg/models/shared/invokefunctiondispatcher.go | 35 + pkg/models/shared/jsonpatchconfig.go | 37 + pkg/models/shared/linkfilterconfig.go | 61 + .../listappmanagedstatebindingsresponse.go | 70 + .../shared/listfindingsettingsresponse.go | 30 + pkg/models/shared/listgatewaykeysresponse.go | 25 + pkg/models/shared/mcpaccessprofile.go | 22 + pkg/models/shared/mcpaccessprofileinput.go | 110 + ...fileservicesearchaccessprofilesresponse.go | 27 + .../mcpaccessprofileserviceupdaterequest.go | 6 +- pkg/models/shared/mcpresource.go | 408 + pkg/models/shared/mcpresourcehistoryentry.go | 23 + .../shared/mcpresourceservicegetresponse.go | 15 + .../mcpresourceservicelisthistoryresponse.go | 25 + .../shared/mcpresourceservicelistresponse.go | 25 + .../shared/mcpresourceservicesearchrequest.go | 182 + .../mcpresourceservicesearchresponse.go | 25 + .../shared/mcpresourceserviceupdaterequest.go | 23 + .../mcpresourceserviceupdateresponse.go | 15 + pkg/models/shared/mcpservercatalogauthmode.go | 47 + pkg/models/shared/mcpservercatalogentry.go | 13 + .../shared/mcpserverserviceregisterrequest.go | 13 + .../mcpserverserviceregisterresponse.go | 14 +- pkg/models/shared/mcpserverview.go | 15 +- pkg/models/shared/mcptool.go | 22 + .../shared/mcptoolservicesearchrequest.go | 50 +- pkg/models/shared/mintgatewaykeyrequest.go | 16 + pkg/models/shared/mintgatewaykeyresponse.go | 24 + pkg/models/shared/money.go | 57 + pkg/models/shared/msteamschannel.go | 25 + pkg/models/shared/msteamschannelsettings.go | 16 + pkg/models/shared/myfundlimit.go | 58 + pkg/models/shared/myfundlimithistoryentry.go | 23 + .../myfundlimitsservicedeleterequest.go | 7 + .../myfundlimitsservicedeleteresponse.go | 7 + .../myfundlimitsservicelisthistoryresponse.go | 25 + .../shared/myfundlimitsservicelistresponse.go | 25 + .../shared/myfundlimitsservicepauserequest.go | 16 + .../myfundlimitsservicepauseresponse.go | 15 + .../myfundlimitsserviceresumerequest.go | 7 + .../myfundlimitsserviceresumeresponse.go | 15 + .../myfundlimitsservicesetlimitrequest.go | 51 + .../myfundlimitsservicesetlimitresponse.go | 15 + pkg/models/shared/notifydispatcher.go | 70 + pkg/models/shared/oidcclaimmapping.go | 62 + pkg/models/shared/payloadfindingdispatch.go | 52 + pkg/models/shared/policy.go | 54 +- pkg/models/shared/policyscope.go | 61 + pkg/models/shared/pretoolblockconfig.go | 19 + pkg/models/shared/programref.go | 38 + .../promoteappmanagedstatebindingrequest.go | 34 + .../shared/promptinjectionscanconfig.go | 55 + pkg/models/shared/providercredential.go | 116 + pkg/models/shared/provisioninstance.go | 13 +- pkg/models/shared/provisionpolicy.go | 25 +- pkg/models/shared/provisionpolicyinput.go | 25 +- pkg/models/shared/provisionwaitingon.go | 59 + pkg/models/shared/recurrencerule.go | 13 +- pkg/models/shared/report.go | 137 + .../shared/reportingservicedeleterequest.go | 7 + .../shared/reportingservicedeleteresponse.go | 7 + .../shared/reportingservicegetresponse.go | 42 + ...eportingservicegetrunprovenanceresponse.go | 73 + .../shared/reportingservicelistresponse.go | 25 + .../shared/reportingservicerunrequest.go | 7 + .../shared/reportingservicerunresponse.go | 15 + .../shared/reportingservicesaverequest.go | 46 + .../shared/reportingservicesaveresponse.go | 15 + .../shared/reportingserviceupdaterequest.go | 36 + .../shared/reportingserviceupdateresponse.go | 15 + pkg/models/shared/reportrun.go | 231 + pkg/models/shared/reportsource.go | 64 + pkg/models/shared/requestcatalog.go | 40 + ...stcatalogmanagementservicecreaterequest.go | 50 + pkg/models/shared/requestcreatedpreference.go | 25 + pkg/models/shared/requestsettings.go | 12 + pkg/models/shared/revokegatewaykeyrequest.go | 7 + pkg/models/shared/revokegatewaykeyresponse.go | 15 + pkg/models/shared/rule.go | 51 +- pkg/models/shared/samlattributemapping.go | 71 + pkg/models/shared/samlmetadatafinding.go | 90 + .../shared/searchappresourcesrequest.go | 18 +- pkg/models/shared/searchcohortusersrequest.go | 5 +- .../shared/searchcohortusersresponse.go | 5 +- pkg/models/shared/searchpoliciesrequest.go | 133 + pkg/models/shared/searchusersrequest.go | 11 + pkg/models/shared/secretsmaskingconfig.go | 28 + .../shared/sessionpolicystepuprequired.go | 24 +- .../shared/setprovidercredentialrequest.go | 58 + .../shared/setprovidercredentialresponse.go | 15 + pkg/models/shared/slackchannelsettings.go | 16 + pkg/models/shared/slackchanneltarget.go | 28 + pkg/models/shared/spendcontrols.go | 81 + pkg/models/shared/spendextension.go | 52 + pkg/models/shared/spendlimit.go | 39 + pkg/models/shared/spendlimitamount.go | 15 + pkg/models/shared/spendlimitblocked.go | 10 + pkg/models/shared/spendlimitunlimited.go | 10 + pkg/models/shared/spendsuspension.go | 43 + pkg/models/shared/ssoapplication.go | 179 + .../shared/ssoapplicationhistoryentry.go | 25 + pkg/models/shared/ssoapplicationoidcclient.go | 125 + ...licationoidcclientauthclientsecretbasic.go | 7 + ...plicationoidcclientauthclientsecretpost.go | 7 + .../ssoapplicationoidcclientauthentication.go | 47 + .../ssoapplicationoidcclientauthnone.go | 7 + ...oapplicationoidcclientauthprivatekeyjwt.go | 19 + .../shared/ssoapplicationoidcclientconfig.go | 75 + pkg/models/shared/ssoapplicationoidcconfig.go | 51 + pkg/models/shared/ssoapplicationsamlconfig.go | 179 + ...ebatchdeletesubjectcompatibilityrequest.go | 18 + ...batchdeletesubjectcompatibilityresponse.go | 27 + ...ebatchimportsubjectcompatibilityrequest.go | 37 + ...batchimportsubjectcompatibilityresponse.go | 77 + ...soapplicationservicecreateclientrequest.go | 17 + ...oapplicationservicecreateclientresponse.go | 27 + .../ssoapplicationservicecreaterequest.go | 116 + .../ssoapplicationservicecreateresponse.go | 33 + ...soapplicationservicedeleteclientrequest.go | 16 + ...oapplicationservicedeleteclientresponse.go | 7 + .../ssoapplicationservicedeleterequest.go | 7 + .../ssoapplicationservicedeleteresponse.go | 7 + .../ssoapplicationservicegetresponse.go | 15 + ...soapplicationservicelistclientsresponse.go | 27 + ...soapplicationservicelisthistoryresponse.go | 27 + .../ssoapplicationservicelistresponse.go | 25 + ...parsesamlserviceprovidermetadatarequest.go | 19 + ...arsesamlserviceprovidermetadataresponse.go | 28 + ...icationservicerotateclientsecretrequest.go | 18 + ...cationservicerotateclientsecretresponse.go | 18 + .../ssoapplicationservicesearchrequest.go | 44 + .../ssoapplicationservicesearchresponse.go | 25 + ...soapplicationserviceupdateclientrequest.go | 26 + ...oapplicationserviceupdateclientresponse.go | 15 + .../ssoapplicationserviceupdaterequest.go | 23 + .../ssoapplicationserviceupdateresponse.go | 15 + pkg/models/shared/ssosettings.go | 137 + pkg/models/shared/ssosettingshistoryentry.go | 25 + .../shared/ssosettingsservicegetresponse.go | 15 + .../ssosettingsservicelisthistoryresponse.go | 25 + .../shared/ssosettingsserviceupdaterequest.go | 23 + .../ssosettingsserviceupdateresponse.go | 15 + pkg/models/shared/ssosubjectcompatibility.go | 21 + .../ssosubjectcompatibilitydeleteissue.go | 27 + .../ssosubjectcompatibilityimportentry.go | 34 + .../ssosubjectcompatibilityimportissue.go | 45 + pkg/models/shared/submittedtaskaction.go | 3 +- pkg/models/shared/systempreference.go | 25 + pkg/models/shared/task.go | 3 +- ...kactionsserviceretryprovisioningrequest.go | 33 + pkg/models/shared/taskauditaccountdeleted.go | 63 + .../shared/taskauditautomationtriggered.go | 52 + ...skauditconditionalpolicyexecutionresult.go | 30 + pkg/models/shared/taskauditlistrequest.go | 11 + pkg/models/shared/taskauditlistresponse.go | 31 + ...auditprovisionentitlementmergecompleted.go | 25 + ...kauditprovisionentitlementmergetimedout.go | 25 + ...uditprovisionwaitingforentitlementmerge.go | 49 + pkg/models/shared/taskauditview.go | 71 +- pkg/models/shared/taskauditwebhooksuccess.go | 9 + pkg/models/shared/tasksearchrequest.go | 33 + .../shared/triggerautomationdispatcher.go | 26 + pkg/models/shared/unusedsecretevidence.go | 31 + pkg/models/shared/unusedsecrettype.go | 9 + .../shared/updatefindingsettingsrequest.go | 19 + .../shared/updatefindingsettingsresponse.go | 17 + .../shared/waitingfordeviceplacement.go | 25 + .../shared/waitingforentitlementmerge.go | 25 + pkg/models/shared/webhookdispatcher.go | 25 + pkg/models/shared/xaaclientaudiencemapping.go | 4 +- providercredential.go | 667 + reporting.go | 1517 + roleminingmanagement.go | 226 +- ssoapplication.go | 3240 + ssosettings.go | 662 + taskactions.go | 215 + uiconversations.go | 246 + 1057 files changed, 132497 insertions(+), 57985 deletions(-) create mode 100644 accessreviewactions.go create mode 100644 accessreviewreport.go create mode 100644 appcap.go create mode 100644 appmanagedstate.go create mode 100644 docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md create mode 100644 docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md create mode 100644 docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md create mode 100644 docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md create mode 100644 docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md create mode 100644 docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md create mode 100644 docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md create mode 100644 docs/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md create mode 100644 docs/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md create mode 100644 docs/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md create mode 100644 docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md create mode 100644 docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicerunrequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicerunresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md create mode 100644 docs/pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md create mode 100644 docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md create mode 100644 docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md create mode 100644 docs/pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md create mode 100644 docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md create mode 100644 docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md create mode 100644 docs/pkg/models/shared/a2uiprovenanceobject.md create mode 100644 docs/pkg/models/shared/a2uiprovenancesource.md create mode 100644 docs/pkg/models/shared/a2uiprovenancestep.md create mode 100644 docs/pkg/models/shared/a2uiprovenancesteprecordtype.md create mode 100644 docs/pkg/models/shared/a2uiprovenancetoolcall.md create mode 100644 docs/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md create mode 100644 docs/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md create mode 100644 docs/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md create mode 100644 docs/pkg/models/shared/accessreviewreport.md create mode 100644 docs/pkg/models/shared/accessreviewreportcolumnconfig.md create mode 100644 docs/pkg/models/shared/accessreviewreportcolumnconfigcolumns.md create mode 100644 docs/pkg/models/shared/accessreviewreportformat.md create mode 100644 docs/pkg/models/shared/accessreviewreportservicelistresponse.md create mode 100644 docs/pkg/models/shared/accessreviewreportstate.md create mode 100644 docs/pkg/models/shared/accessreviewtaskcolumnref.md create mode 100644 docs/pkg/models/shared/accountstatuses.md create mode 100644 docs/pkg/models/shared/agentstatus.md create mode 100644 docs/pkg/models/shared/appcap.md create mode 100644 docs/pkg/models/shared/appcaphistoryentry.md create mode 100644 docs/pkg/models/shared/appcapservicedeleterequest.md create mode 100644 docs/pkg/models/shared/appcapservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/appcapservicegetresponse.md create mode 100644 docs/pkg/models/shared/appcapservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/appcapservicelistresponse.md create mode 100644 docs/pkg/models/shared/appcapservicesetlimitrequest.md create mode 100644 docs/pkg/models/shared/appcapservicesetlimitresponse.md create mode 100644 docs/pkg/models/shared/appcapservicesuspendrequest.md create mode 100644 docs/pkg/models/shared/appcapservicesuspendresponse.md create mode 100644 docs/pkg/models/shared/appcapserviceunsuspendrequest.md create mode 100644 docs/pkg/models/shared/appcapserviceunsuspendresponse.md create mode 100644 docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md create mode 100644 docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md create mode 100644 docs/pkg/models/shared/appmanagedstate.md create mode 100644 docs/pkg/models/shared/appmanagedstatebinding.md create mode 100644 docs/pkg/models/shared/appmanagedstatebindingexpandmask.md create mode 100644 docs/pkg/models/shared/appmanagedstatebindingview.md create mode 100644 docs/pkg/models/shared/appmanagedstatemanaged.md create mode 100644 docs/pkg/models/shared/appmanagedstateunmanaged.md create mode 100644 docs/pkg/models/shared/appmatchbatonref.md create mode 100644 docs/pkg/models/shared/appusernhitype.md create mode 100644 docs/pkg/models/shared/blockoutputconfig.md create mode 100644 docs/pkg/models/shared/blocktoolcallconfig.md create mode 100644 docs/pkg/models/shared/builtin.md create mode 100644 docs/pkg/models/shared/bulkreprocessaction.md create mode 100644 docs/pkg/models/shared/c1metriccard.md create mode 100644 docs/pkg/models/shared/c1metriccardscomponent.md create mode 100644 docs/pkg/models/shared/c1tablecomponent.md create mode 100644 docs/pkg/models/shared/c1tablerow.md create mode 100644 docs/pkg/models/shared/clearprovidercredentialrequest.md create mode 100644 docs/pkg/models/shared/clearprovidercredentialresponse.md create mode 100644 docs/pkg/models/shared/component.md create mode 100644 docs/pkg/models/shared/compositeformat.md create mode 100644 docs/pkg/models/shared/connectoractionrefoperation.md create mode 100644 docs/pkg/models/shared/connectorsyncfailingevidence.md create mode 100644 docs/pkg/models/shared/connectorsyncfailingtype.md create mode 100644 docs/pkg/models/shared/credentialexpiringevidence.md create mode 100644 docs/pkg/models/shared/credentialexpiringtype.md create mode 100644 docs/pkg/models/shared/credentialpubliclyexposedevidence.md create mode 100644 docs/pkg/models/shared/credentialpubliclyexposedtype.md create mode 100644 docs/pkg/models/shared/datefield.md create mode 100644 docs/pkg/models/shared/deactivatedownerdetail.md create mode 100644 docs/pkg/models/shared/deactivatedownerevidence.md create mode 100644 docs/pkg/models/shared/deactivatedownertype.md create mode 100644 docs/pkg/models/shared/deactivatedownertypesource.md create mode 100644 docs/pkg/models/shared/decoypubliclyexposedevidence.md create mode 100644 docs/pkg/models/shared/decoypubliclyexposedtype.md create mode 100644 docs/pkg/models/shared/defaultidtokensignedresponsealg.md create mode 100644 docs/pkg/models/shared/defaultsubjecttype.md create mode 100644 docs/pkg/models/shared/deltasentiment.md create mode 100644 docs/pkg/models/shared/destination.md create mode 100644 docs/pkg/models/shared/detaillevel.md create mode 100644 docs/pkg/models/shared/deviceplacementprovision.md create mode 100644 docs/pkg/models/shared/disabledmodules.md create mode 100644 docs/pkg/models/shared/disabledreasoncircuitbreakerperiod.md create mode 100644 docs/pkg/models/shared/encodedcontentguardconfig.md create mode 100644 docs/pkg/models/shared/encryptionalgorithm.md create mode 100644 docs/pkg/models/shared/ensureonboardingsessionrequest.md create mode 100644 docs/pkg/models/shared/ensureonboardingsessionresponse.md create mode 100644 docs/pkg/models/shared/entitlementcutoffimpactpoint.md create mode 100644 docs/pkg/models/shared/evaluateentitlementselectionrequest.md create mode 100644 docs/pkg/models/shared/evaluateentitlementselectionresponse.md create mode 100644 docs/pkg/models/shared/findingaudience.md create mode 100644 docs/pkg/models/shared/findingaudienceusers.md create mode 100644 docs/pkg/models/shared/findingdispatcher.md create mode 100644 docs/pkg/models/shared/findingdispatchoutcomenotify.md create mode 100644 docs/pkg/models/shared/findingsearchrequestnhitypes.md create mode 100644 docs/pkg/models/shared/findingsettingsentry.md create mode 100644 docs/pkg/models/shared/findingsettingsentryfindingtype.md create mode 100644 docs/pkg/models/shared/findingtransformationrulefindingtype.md create mode 100644 docs/pkg/models/shared/findingtype.md create mode 100644 docs/pkg/models/shared/findingtypesetting.md create mode 100644 docs/pkg/models/shared/findingtypesettingfindingtype.md create mode 100644 docs/pkg/models/shared/fundassignment.md create mode 100644 docs/pkg/models/shared/fundassignmenthistoryentry.md create mode 100644 docs/pkg/models/shared/fundassignmentserviceclearextensionrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentserviceclearextensionresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicedeleterequest.md create mode 100644 docs/pkg/models/shared/fundassignmentservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicegetresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicegrantextensionrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentservicegrantextensionresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesearchrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesearchresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesetlimitrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesetlimitresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesuspendrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentservicesuspendresponse.md create mode 100644 docs/pkg/models/shared/fundassignmentserviceunsuspendrequest.md create mode 100644 docs/pkg/models/shared/fundassignmentserviceunsuspendresponse.md create mode 100644 docs/pkg/models/shared/fundpolicy.md create mode 100644 docs/pkg/models/shared/fundpolicyhistoryentry.md create mode 100644 docs/pkg/models/shared/fundpolicyperiod.md create mode 100644 docs/pkg/models/shared/fundpolicyservicecreaterequest.md create mode 100644 docs/pkg/models/shared/fundpolicyservicecreaterequestperiod.md create mode 100644 docs/pkg/models/shared/fundpolicyservicecreateresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyservicedeleterequest.md create mode 100644 docs/pkg/models/shared/fundpolicyservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyservicefreezetenantrequest.md create mode 100644 docs/pkg/models/shared/fundpolicyservicefreezetenantresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyservicegetresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyservicesetorgceilingrequest.md create mode 100644 docs/pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md create mode 100644 docs/pkg/models/shared/fundpolicyservicesetorgceilingresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md create mode 100644 docs/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md create mode 100644 docs/pkg/models/shared/fundpolicyserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/fundpolicyserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/fundrule.md create mode 100644 docs/pkg/models/shared/fundrulehistoryentry.md create mode 100644 docs/pkg/models/shared/fundruleservicecreaterequest.md create mode 100644 docs/pkg/models/shared/fundruleservicecreateresponse.md create mode 100644 docs/pkg/models/shared/fundruleservicedeleterequest.md create mode 100644 docs/pkg/models/shared/fundruleservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/fundruleservicegetresponse.md create mode 100644 docs/pkg/models/shared/fundruleservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/fundruleservicelistresponse.md create mode 100644 docs/pkg/models/shared/fundruleservicesearchrequest.md create mode 100644 docs/pkg/models/shared/fundruleservicesearchresponse.md create mode 100644 docs/pkg/models/shared/fundruleserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/fundruleserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/gatewaykey.md create mode 100644 docs/pkg/models/shared/getappmanagedstatebindingresponse.md create mode 100644 docs/pkg/models/shared/getappmanagedstatebindingresponseexpanded.md create mode 100644 docs/pkg/models/shared/getprovidercredentialresponse.md create mode 100644 docs/pkg/models/shared/grantfiltergrantsourcefilter.md create mode 100644 docs/pkg/models/shared/headerstyle.md create mode 100644 docs/pkg/models/shared/idtokensignedresponsealg.md create mode 100644 docs/pkg/models/shared/invokefunctiondispatcher.md create mode 100644 docs/pkg/models/shared/jsonpatchconfig.md create mode 100644 docs/pkg/models/shared/kindfilter.md create mode 100644 docs/pkg/models/shared/linkfilterconfig.md create mode 100644 docs/pkg/models/shared/linkfilterconfigaction.md create mode 100644 docs/pkg/models/shared/listappmanagedstatebindingsresponse.md create mode 100644 docs/pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md create mode 100644 docs/pkg/models/shared/listfindingsettingsresponse.md create mode 100644 docs/pkg/models/shared/listgatewaykeysresponse.md create mode 100644 docs/pkg/models/shared/mcpaccessprofileinput.md create mode 100644 docs/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md create mode 100644 docs/pkg/models/shared/mcpresource.md create mode 100644 docs/pkg/models/shared/mcpresourcehistoryentry.md create mode 100644 docs/pkg/models/shared/mcpresourceinput.md create mode 100644 docs/pkg/models/shared/mcpresourcekind.md create mode 100644 docs/pkg/models/shared/mcpresourceservicegetresponse.md create mode 100644 docs/pkg/models/shared/mcpresourceservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/mcpresourceservicelistresponse.md create mode 100644 docs/pkg/models/shared/mcpresourceservicesearchrequest.md create mode 100644 docs/pkg/models/shared/mcpresourceservicesearchrequestsortby.md create mode 100644 docs/pkg/models/shared/mcpresourceservicesearchresponse.md create mode 100644 docs/pkg/models/shared/mcpresourceserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/mcpresourceserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/mcpresourcestate.md create mode 100644 docs/pkg/models/shared/mcpservercatalogauthmodeclientidmode.md create mode 100644 docs/pkg/models/shared/mcptoolservicesearchrequestsortdirection.md create mode 100644 docs/pkg/models/shared/mcptoolservicesearchrequeststatefilter.md create mode 100644 docs/pkg/models/shared/mintgatewaykeyrequest.md create mode 100644 docs/pkg/models/shared/mintgatewaykeyresponse.md create mode 100644 docs/pkg/models/shared/money.md create mode 100644 docs/pkg/models/shared/msteamschannel.md create mode 100644 docs/pkg/models/shared/myfundlimit.md create mode 100644 docs/pkg/models/shared/myfundlimithistoryentry.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicedeleterequest.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicelistresponse.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicepauserequest.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicepauseresponse.md create mode 100644 docs/pkg/models/shared/myfundlimitsserviceresumerequest.md create mode 100644 docs/pkg/models/shared/myfundlimitsserviceresumeresponse.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicesetlimitrequest.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md create mode 100644 docs/pkg/models/shared/myfundlimitsservicesetlimitresponse.md create mode 100644 docs/pkg/models/shared/nameformat.md create mode 100644 docs/pkg/models/shared/nameidformat.md create mode 100644 docs/pkg/models/shared/notifydispatcher.md create mode 100644 docs/pkg/models/shared/oidcclaimmapping.md create mode 100644 docs/pkg/models/shared/payloadfindingdispatch.md create mode 100644 docs/pkg/models/shared/pkcepolicy.md create mode 100644 docs/pkg/models/shared/policyscope.md create mode 100644 docs/pkg/models/shared/pretoolblockconfig.md create mode 100644 docs/pkg/models/shared/programref.md create mode 100644 docs/pkg/models/shared/promoteappmanagedstatebindingrequest.md create mode 100644 docs/pkg/models/shared/promptinjectionscanconfig.md create mode 100644 docs/pkg/models/shared/providercredential.md create mode 100644 docs/pkg/models/shared/provisionwaitingon.md create mode 100644 docs/pkg/models/shared/reason.md create mode 100644 docs/pkg/models/shared/recordtype.md create mode 100644 docs/pkg/models/shared/report.md create mode 100644 docs/pkg/models/shared/reportingservicedeleterequest.md create mode 100644 docs/pkg/models/shared/reportingservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/reportingservicegetresponse.md create mode 100644 docs/pkg/models/shared/reportingservicegetrunprovenanceresponse.md create mode 100644 docs/pkg/models/shared/reportingservicelistresponse.md create mode 100644 docs/pkg/models/shared/reportingservicerunrequest.md create mode 100644 docs/pkg/models/shared/reportingservicerunresponse.md create mode 100644 docs/pkg/models/shared/reportingservicesaverequest.md create mode 100644 docs/pkg/models/shared/reportingservicesaveresponse.md create mode 100644 docs/pkg/models/shared/reportingserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/reportingserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/reportrun.md create mode 100644 docs/pkg/models/shared/reportrunstatus.md create mode 100644 docs/pkg/models/shared/reportsource.md create mode 100644 docs/pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md create mode 100644 docs/pkg/models/shared/requestcatalogtype.md create mode 100644 docs/pkg/models/shared/requestcreatedpreference.md create mode 100644 docs/pkg/models/shared/revokegatewaykeyrequest.md create mode 100644 docs/pkg/models/shared/revokegatewaykeyresponse.md create mode 100644 docs/pkg/models/shared/samlattributemapping.md create mode 100644 docs/pkg/models/shared/samlmetadatafinding.md create mode 100644 docs/pkg/models/shared/scopeobjecttype.md create mode 100644 docs/pkg/models/shared/scopeslot.md create mode 100644 docs/pkg/models/shared/scopeview.md create mode 100644 docs/pkg/models/shared/searchappresourcesrequestagentstatuses.md create mode 100644 docs/pkg/models/shared/secretsmaskingconfig.md create mode 100644 docs/pkg/models/shared/sessionpolicystepuprequiredlevel.md create mode 100644 docs/pkg/models/shared/setprovidercredentialrequest.md create mode 100644 docs/pkg/models/shared/setprovidercredentialrequestheaderstyle.md create mode 100644 docs/pkg/models/shared/setprovidercredentialresponse.md create mode 100644 docs/pkg/models/shared/slackchanneltarget.md create mode 100644 docs/pkg/models/shared/slot.md create mode 100644 docs/pkg/models/shared/spendcontrols.md create mode 100644 docs/pkg/models/shared/spendcontrolsperiod.md create mode 100644 docs/pkg/models/shared/spendextension.md create mode 100644 docs/pkg/models/shared/spendlimit.md create mode 100644 docs/pkg/models/shared/spendlimitamount.md create mode 100644 docs/pkg/models/shared/spendlimitblocked.md create mode 100644 docs/pkg/models/shared/spendlimitunlimited.md create mode 100644 docs/pkg/models/shared/spendsuspension.md create mode 100644 docs/pkg/models/shared/ssoapplication.md create mode 100644 docs/pkg/models/shared/ssoapplicationhistoryentry.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclient.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientauthentication.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientauthnone.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientconfig.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md create mode 100644 docs/pkg/models/shared/ssoapplicationoidcconfig.md create mode 100644 docs/pkg/models/shared/ssoapplicationsamlconfig.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicecreateclientrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicecreateclientresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicecreaterequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicecreateresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicedeleteclientrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicedeleteclientresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicedeleterequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicedeleteresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicegetresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicelistclientsresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicelistresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicesearchrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationservicesearchresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceupdateclientrequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceupdateclientresponse.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/ssoapplicationserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/ssosettings.md create mode 100644 docs/pkg/models/shared/ssosettingshistoryentry.md create mode 100644 docs/pkg/models/shared/ssosettingsservicegetresponse.md create mode 100644 docs/pkg/models/shared/ssosettingsservicelisthistoryresponse.md create mode 100644 docs/pkg/models/shared/ssosettingsserviceupdaterequest.md create mode 100644 docs/pkg/models/shared/ssosettingsserviceupdateresponse.md create mode 100644 docs/pkg/models/shared/ssosubjectcompatibility.md create mode 100644 docs/pkg/models/shared/ssosubjectcompatibilitydeleteissue.md create mode 100644 docs/pkg/models/shared/ssosubjectcompatibilityimportentry.md create mode 100644 docs/pkg/models/shared/ssosubjectcompatibilityimportissue.md create mode 100644 docs/pkg/models/shared/subjecttype.md create mode 100644 docs/pkg/models/shared/surfaces.md create mode 100644 docs/pkg/models/shared/systempreference.md create mode 100644 docs/pkg/models/shared/taskactionsserviceretryprovisioningrequest.md create mode 100644 docs/pkg/models/shared/taskauditaccountdeleted.md create mode 100644 docs/pkg/models/shared/taskauditautomationtriggered.md create mode 100644 docs/pkg/models/shared/taskauditprovisionentitlementmergecompleted.md create mode 100644 docs/pkg/models/shared/taskauditprovisionentitlementmergetimedout.md create mode 100644 docs/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md create mode 100644 docs/pkg/models/shared/threshold.md create mode 100644 docs/pkg/models/shared/tieroverride.md create mode 100644 docs/pkg/models/shared/triggerautomationdispatcher.md create mode 100644 docs/pkg/models/shared/unusedsecretevidence.md create mode 100644 docs/pkg/models/shared/unusedsecrettype.md create mode 100644 docs/pkg/models/shared/updatefindingsettingsrequest.md create mode 100644 docs/pkg/models/shared/updatefindingsettingsresponse.md create mode 100644 docs/pkg/models/shared/waitingfordeviceplacement.md create mode 100644 docs/pkg/models/shared/waitingforentitlementmerge.md create mode 100644 docs/pkg/models/shared/webhookdispatcher.md create mode 100644 docs/sdks/accessreviewactions/README.md create mode 100644 docs/sdks/accessreviewreport/README.md create mode 100644 docs/sdks/appcap/README.md create mode 100644 docs/sdks/appmanagedstate/README.md create mode 100644 docs/sdks/findingsettings/README.md create mode 100644 docs/sdks/fundassignment/README.md create mode 100644 docs/sdks/fundpolicy/README.md create mode 100644 docs/sdks/fundrule/README.md create mode 100644 docs/sdks/gatewaykey/README.md create mode 100644 docs/sdks/mcpresource/README.md create mode 100644 docs/sdks/myfundlimits/README.md create mode 100644 docs/sdks/providercredential/README.md create mode 100644 docs/sdks/reporting/README.md create mode 100644 docs/sdks/ssoapplication/README.md create mode 100644 docs/sdks/ssosettings/README.md create mode 100644 docs/sdks/uiconversations/README.md create mode 100644 findingsettings.go create mode 100644 fundassignment.go create mode 100644 fundpolicy.go create mode 100644 fundrule.go create mode 100644 gatewaykey.go create mode 100644 mcpresource.go create mode 100644 myfundlimits.go create mode 100644 pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenance.go create mode 100644 pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereport.go create mode 100644 pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelist.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofiles.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpresourceserviceget.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpresourceservicelist.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistory.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearch.go create mode 100644 pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdate.go create mode 100644 pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuser.go create mode 100644 pkg/models/operations/c1apiappv1appmanagedstateserviceget.go create mode 100644 pkg/models/operations/c1apiappv1appmanagedstateservicelist.go create mode 100644 pkg/models/operations/c1apiappv1appmanagedstateservicepromote.go create mode 100644 pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsession.go create mode 100644 pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettings.go create mode 100644 pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettings.go create mode 100644 pkg/models/operations/c1apifundsv1appcapservicedelete.go create mode 100644 pkg/models/operations/c1apifundsv1appcapserviceget.go create mode 100644 pkg/models/operations/c1apifundsv1appcapservicelist.go create mode 100644 pkg/models/operations/c1apifundsv1appcapservicelisthistory.go create mode 100644 pkg/models/operations/c1apifundsv1appcapservicesetlimit.go create mode 100644 pkg/models/operations/c1apifundsv1appcapservicesuspend.go create mode 100644 pkg/models/operations/c1apifundsv1appcapserviceunsuspend.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentserviceclearextension.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicedelete.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentserviceget.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicegrantextension.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicelisthistory.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicesearch.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicesetlimit.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentservicesuspend.go create mode 100644 pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspend.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyservicecreate.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyservicedelete.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenant.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyserviceget.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyservicelisthistory.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceiling.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenant.go create mode 100644 pkg/models/operations/c1apifundsv1fundpolicyserviceupdate.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleservicecreate.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleservicedelete.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleserviceget.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleservicelist.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleservicelisthistory.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleservicesearch.go create mode 100644 pkg/models/operations/c1apifundsv1fundruleserviceupdate.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsservicedelete.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsservicelist.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistory.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsservicepause.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsserviceresume.go create mode 100644 pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimit.go create mode 100644 pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelist.go create mode 100644 pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemint.go create mode 100644 pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevoke.go create mode 100644 pkg/models/operations/c1apillmgatewayv1providercredentialserviceclear.go create mode 100644 pkg/models/operations/c1apillmgatewayv1providercredentialserviceget.go create mode 100644 pkg/models/operations/c1apillmgatewayv1providercredentialserviceset.go create mode 100644 pkg/models/operations/c1apireportingv1reportingservicedelete.go create mode 100644 pkg/models/operations/c1apireportingv1reportingserviceget.go create mode 100644 pkg/models/operations/c1apireportingv1reportingservicegetrunprovenance.go create mode 100644 pkg/models/operations/c1apireportingv1reportingservicelist.go create mode 100644 pkg/models/operations/c1apireportingv1reportingservicerun.go create mode 100644 pkg/models/operations/c1apireportingv1reportingservicesave.go create mode 100644 pkg/models/operations/c1apireportingv1reportingserviceupdate.go create mode 100644 pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselection.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibility.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibility.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicecreate.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicecreateclient.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicedelete.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicedeleteclient.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationserviceget.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicelist.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicelistclients.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicelisthistory.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadata.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecret.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationservicesearch.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationserviceupdate.go create mode 100644 pkg/models/operations/c1apissov1ssoapplicationserviceupdateclient.go create mode 100644 pkg/models/operations/c1apissov1ssosettingsserviceget.go create mode 100644 pkg/models/operations/c1apissov1ssosettingsservicelisthistory.go create mode 100644 pkg/models/operations/c1apissov1ssosettingsserviceupdate.go create mode 100644 pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioning.go create mode 100644 pkg/models/shared/a2uiprovenanceobject.go create mode 100644 pkg/models/shared/a2uiprovenancesource.go create mode 100644 pkg/models/shared/a2uiprovenancestep.go create mode 100644 pkg/models/shared/a2uiprovenancetoolcall.go create mode 100644 pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.go create mode 100644 pkg/models/shared/accessreviewactionsservicegeneratereportrequest.go create mode 100644 pkg/models/shared/accessreviewactionsservicegeneratereportresponse.go create mode 100644 pkg/models/shared/accessreviewreport.go create mode 100644 pkg/models/shared/accessreviewreportcolumnconfig.go create mode 100644 pkg/models/shared/accessreviewreportservicelistresponse.go create mode 100644 pkg/models/shared/accessreviewtaskcolumnref.go create mode 100644 pkg/models/shared/appcap.go create mode 100644 pkg/models/shared/appcaphistoryentry.go create mode 100644 pkg/models/shared/appcapservicedeleterequest.go create mode 100644 pkg/models/shared/appcapservicedeleteresponse.go create mode 100644 pkg/models/shared/appcapservicegetresponse.go create mode 100644 pkg/models/shared/appcapservicelisthistoryresponse.go create mode 100644 pkg/models/shared/appcapservicelistresponse.go create mode 100644 pkg/models/shared/appcapservicesetlimitrequest.go create mode 100644 pkg/models/shared/appcapservicesetlimitresponse.go create mode 100644 pkg/models/shared/appcapservicesuspendrequest.go create mode 100644 pkg/models/shared/appcapservicesuspendresponse.go create mode 100644 pkg/models/shared/appcapserviceunsuspendrequest.go create mode 100644 pkg/models/shared/appcapserviceunsuspendresponse.go create mode 100644 pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.go create mode 100644 pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.go create mode 100644 pkg/models/shared/appmanagedstate.go create mode 100644 pkg/models/shared/appmanagedstatebinding.go create mode 100644 pkg/models/shared/appmanagedstatebindingexpandmask.go create mode 100644 pkg/models/shared/appmanagedstatebindingview.go create mode 100644 pkg/models/shared/appmanagedstatemanaged.go create mode 100644 pkg/models/shared/appmanagedstateunmanaged.go create mode 100644 pkg/models/shared/appmatchbatonref.go create mode 100644 pkg/models/shared/blockoutputconfig.go create mode 100644 pkg/models/shared/blocktoolcallconfig.go create mode 100644 pkg/models/shared/bulkreprocessaction.go create mode 100644 pkg/models/shared/c1metriccard.go create mode 100644 pkg/models/shared/c1metriccardscomponent.go create mode 100644 pkg/models/shared/c1tablecomponent.go create mode 100644 pkg/models/shared/c1tablerow.go create mode 100644 pkg/models/shared/clearprovidercredentialrequest.go create mode 100644 pkg/models/shared/clearprovidercredentialresponse.go create mode 100644 pkg/models/shared/connectorsyncfailingevidence.go create mode 100644 pkg/models/shared/connectorsyncfailingtype.go create mode 100644 pkg/models/shared/credentialexpiringevidence.go create mode 100644 pkg/models/shared/credentialexpiringtype.go create mode 100644 pkg/models/shared/credentialpubliclyexposedevidence.go create mode 100644 pkg/models/shared/credentialpubliclyexposedtype.go create mode 100644 pkg/models/shared/datefield.go create mode 100644 pkg/models/shared/deactivatedownerdetail.go create mode 100644 pkg/models/shared/deactivatedownerevidence.go create mode 100644 pkg/models/shared/deactivatedownertype.go create mode 100644 pkg/models/shared/decoypubliclyexposedevidence.go create mode 100644 pkg/models/shared/decoypubliclyexposedtype.go create mode 100644 pkg/models/shared/deviceplacementprovision.go create mode 100644 pkg/models/shared/encodedcontentguardconfig.go create mode 100644 pkg/models/shared/ensureonboardingsessionrequest.go create mode 100644 pkg/models/shared/ensureonboardingsessionresponse.go create mode 100644 pkg/models/shared/entitlementcutoffimpactpoint.go create mode 100644 pkg/models/shared/evaluateentitlementselectionrequest.go create mode 100644 pkg/models/shared/evaluateentitlementselectionresponse.go create mode 100644 pkg/models/shared/findingaudience.go create mode 100644 pkg/models/shared/findingaudienceusers.go create mode 100644 pkg/models/shared/findingdispatcher.go create mode 100644 pkg/models/shared/findingdispatchoutcomenotify.go create mode 100644 pkg/models/shared/findingsettingsentry.go create mode 100644 pkg/models/shared/findingtypesetting.go create mode 100644 pkg/models/shared/fundassignment.go create mode 100644 pkg/models/shared/fundassignmenthistoryentry.go create mode 100644 pkg/models/shared/fundassignmentserviceclearextensionrequest.go create mode 100644 pkg/models/shared/fundassignmentserviceclearextensionresponse.go create mode 100644 pkg/models/shared/fundassignmentservicedeleterequest.go create mode 100644 pkg/models/shared/fundassignmentservicedeleteresponse.go create mode 100644 pkg/models/shared/fundassignmentservicegetresponse.go create mode 100644 pkg/models/shared/fundassignmentservicegrantextensionrequest.go create mode 100644 pkg/models/shared/fundassignmentservicegrantextensionresponse.go create mode 100644 pkg/models/shared/fundassignmentservicelisthistoryresponse.go create mode 100644 pkg/models/shared/fundassignmentservicesearchrequest.go create mode 100644 pkg/models/shared/fundassignmentservicesearchresponse.go create mode 100644 pkg/models/shared/fundassignmentservicesetlimitrequest.go create mode 100644 pkg/models/shared/fundassignmentservicesetlimitresponse.go create mode 100644 pkg/models/shared/fundassignmentservicesuspendrequest.go create mode 100644 pkg/models/shared/fundassignmentservicesuspendresponse.go create mode 100644 pkg/models/shared/fundassignmentserviceunsuspendrequest.go create mode 100644 pkg/models/shared/fundassignmentserviceunsuspendresponse.go create mode 100644 pkg/models/shared/fundpolicy.go create mode 100644 pkg/models/shared/fundpolicyhistoryentry.go create mode 100644 pkg/models/shared/fundpolicyservicecreaterequest.go create mode 100644 pkg/models/shared/fundpolicyservicecreateresponse.go create mode 100644 pkg/models/shared/fundpolicyservicedeleterequest.go create mode 100644 pkg/models/shared/fundpolicyservicedeleteresponse.go create mode 100644 pkg/models/shared/fundpolicyservicefreezetenantrequest.go create mode 100644 pkg/models/shared/fundpolicyservicefreezetenantresponse.go create mode 100644 pkg/models/shared/fundpolicyservicegetresponse.go create mode 100644 pkg/models/shared/fundpolicyservicelisthistoryresponse.go create mode 100644 pkg/models/shared/fundpolicyservicesetorgceilingrequest.go create mode 100644 pkg/models/shared/fundpolicyservicesetorgceilingresponse.go create mode 100644 pkg/models/shared/fundpolicyserviceunfreezetenantrequest.go create mode 100644 pkg/models/shared/fundpolicyserviceunfreezetenantresponse.go create mode 100644 pkg/models/shared/fundpolicyserviceupdaterequest.go create mode 100644 pkg/models/shared/fundpolicyserviceupdateresponse.go create mode 100644 pkg/models/shared/fundrule.go create mode 100644 pkg/models/shared/fundrulehistoryentry.go create mode 100644 pkg/models/shared/fundruleservicecreaterequest.go create mode 100644 pkg/models/shared/fundruleservicecreateresponse.go create mode 100644 pkg/models/shared/fundruleservicedeleterequest.go create mode 100644 pkg/models/shared/fundruleservicedeleteresponse.go create mode 100644 pkg/models/shared/fundruleservicegetresponse.go create mode 100644 pkg/models/shared/fundruleservicelisthistoryresponse.go create mode 100644 pkg/models/shared/fundruleservicelistresponse.go create mode 100644 pkg/models/shared/fundruleservicesearchrequest.go create mode 100644 pkg/models/shared/fundruleservicesearchresponse.go create mode 100644 pkg/models/shared/fundruleserviceupdaterequest.go create mode 100644 pkg/models/shared/fundruleserviceupdateresponse.go create mode 100644 pkg/models/shared/gatewaykey.go create mode 100644 pkg/models/shared/getappmanagedstatebindingresponse.go create mode 100644 pkg/models/shared/getprovidercredentialresponse.go create mode 100644 pkg/models/shared/invokefunctiondispatcher.go create mode 100644 pkg/models/shared/jsonpatchconfig.go create mode 100644 pkg/models/shared/linkfilterconfig.go create mode 100644 pkg/models/shared/listappmanagedstatebindingsresponse.go create mode 100644 pkg/models/shared/listfindingsettingsresponse.go create mode 100644 pkg/models/shared/listgatewaykeysresponse.go create mode 100644 pkg/models/shared/mcpaccessprofileinput.go create mode 100644 pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.go create mode 100644 pkg/models/shared/mcpresource.go create mode 100644 pkg/models/shared/mcpresourcehistoryentry.go create mode 100644 pkg/models/shared/mcpresourceservicegetresponse.go create mode 100644 pkg/models/shared/mcpresourceservicelisthistoryresponse.go create mode 100644 pkg/models/shared/mcpresourceservicelistresponse.go create mode 100644 pkg/models/shared/mcpresourceservicesearchrequest.go create mode 100644 pkg/models/shared/mcpresourceservicesearchresponse.go create mode 100644 pkg/models/shared/mcpresourceserviceupdaterequest.go create mode 100644 pkg/models/shared/mcpresourceserviceupdateresponse.go create mode 100644 pkg/models/shared/mintgatewaykeyrequest.go create mode 100644 pkg/models/shared/mintgatewaykeyresponse.go create mode 100644 pkg/models/shared/money.go create mode 100644 pkg/models/shared/msteamschannel.go create mode 100644 pkg/models/shared/myfundlimit.go create mode 100644 pkg/models/shared/myfundlimithistoryentry.go create mode 100644 pkg/models/shared/myfundlimitsservicedeleterequest.go create mode 100644 pkg/models/shared/myfundlimitsservicedeleteresponse.go create mode 100644 pkg/models/shared/myfundlimitsservicelisthistoryresponse.go create mode 100644 pkg/models/shared/myfundlimitsservicelistresponse.go create mode 100644 pkg/models/shared/myfundlimitsservicepauserequest.go create mode 100644 pkg/models/shared/myfundlimitsservicepauseresponse.go create mode 100644 pkg/models/shared/myfundlimitsserviceresumerequest.go create mode 100644 pkg/models/shared/myfundlimitsserviceresumeresponse.go create mode 100644 pkg/models/shared/myfundlimitsservicesetlimitrequest.go create mode 100644 pkg/models/shared/myfundlimitsservicesetlimitresponse.go create mode 100644 pkg/models/shared/notifydispatcher.go create mode 100644 pkg/models/shared/oidcclaimmapping.go create mode 100644 pkg/models/shared/payloadfindingdispatch.go create mode 100644 pkg/models/shared/policyscope.go create mode 100644 pkg/models/shared/pretoolblockconfig.go create mode 100644 pkg/models/shared/programref.go create mode 100644 pkg/models/shared/promoteappmanagedstatebindingrequest.go create mode 100644 pkg/models/shared/promptinjectionscanconfig.go create mode 100644 pkg/models/shared/providercredential.go create mode 100644 pkg/models/shared/provisionwaitingon.go create mode 100644 pkg/models/shared/report.go create mode 100644 pkg/models/shared/reportingservicedeleterequest.go create mode 100644 pkg/models/shared/reportingservicedeleteresponse.go create mode 100644 pkg/models/shared/reportingservicegetresponse.go create mode 100644 pkg/models/shared/reportingservicegetrunprovenanceresponse.go create mode 100644 pkg/models/shared/reportingservicelistresponse.go create mode 100644 pkg/models/shared/reportingservicerunrequest.go create mode 100644 pkg/models/shared/reportingservicerunresponse.go create mode 100644 pkg/models/shared/reportingservicesaverequest.go create mode 100644 pkg/models/shared/reportingservicesaveresponse.go create mode 100644 pkg/models/shared/reportingserviceupdaterequest.go create mode 100644 pkg/models/shared/reportingserviceupdateresponse.go create mode 100644 pkg/models/shared/reportrun.go create mode 100644 pkg/models/shared/reportsource.go create mode 100644 pkg/models/shared/requestcreatedpreference.go create mode 100644 pkg/models/shared/revokegatewaykeyrequest.go create mode 100644 pkg/models/shared/revokegatewaykeyresponse.go create mode 100644 pkg/models/shared/samlattributemapping.go create mode 100644 pkg/models/shared/samlmetadatafinding.go create mode 100644 pkg/models/shared/secretsmaskingconfig.go create mode 100644 pkg/models/shared/setprovidercredentialrequest.go create mode 100644 pkg/models/shared/setprovidercredentialresponse.go create mode 100644 pkg/models/shared/slackchanneltarget.go create mode 100644 pkg/models/shared/spendcontrols.go create mode 100644 pkg/models/shared/spendextension.go create mode 100644 pkg/models/shared/spendlimit.go create mode 100644 pkg/models/shared/spendlimitamount.go create mode 100644 pkg/models/shared/spendlimitblocked.go create mode 100644 pkg/models/shared/spendlimitunlimited.go create mode 100644 pkg/models/shared/spendsuspension.go create mode 100644 pkg/models/shared/ssoapplication.go create mode 100644 pkg/models/shared/ssoapplicationhistoryentry.go create mode 100644 pkg/models/shared/ssoapplicationoidcclient.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientauthentication.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientauthnone.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.go create mode 100644 pkg/models/shared/ssoapplicationoidcclientconfig.go create mode 100644 pkg/models/shared/ssoapplicationoidcconfig.go create mode 100644 pkg/models/shared/ssoapplicationsamlconfig.go create mode 100644 pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicecreateclientrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicecreateclientresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicecreaterequest.go create mode 100644 pkg/models/shared/ssoapplicationservicecreateresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicedeleteclientrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicedeleteclientresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicedeleterequest.go create mode 100644 pkg/models/shared/ssoapplicationservicedeleteresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicegetresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicelistclientsresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicelisthistoryresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicelistresponse.go create mode 100644 pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.go create mode 100644 pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.go create mode 100644 pkg/models/shared/ssoapplicationservicesearchrequest.go create mode 100644 pkg/models/shared/ssoapplicationservicesearchresponse.go create mode 100644 pkg/models/shared/ssoapplicationserviceupdateclientrequest.go create mode 100644 pkg/models/shared/ssoapplicationserviceupdateclientresponse.go create mode 100644 pkg/models/shared/ssoapplicationserviceupdaterequest.go create mode 100644 pkg/models/shared/ssoapplicationserviceupdateresponse.go create mode 100644 pkg/models/shared/ssosettings.go create mode 100644 pkg/models/shared/ssosettingshistoryentry.go create mode 100644 pkg/models/shared/ssosettingsservicegetresponse.go create mode 100644 pkg/models/shared/ssosettingsservicelisthistoryresponse.go create mode 100644 pkg/models/shared/ssosettingsserviceupdaterequest.go create mode 100644 pkg/models/shared/ssosettingsserviceupdateresponse.go create mode 100644 pkg/models/shared/ssosubjectcompatibility.go create mode 100644 pkg/models/shared/ssosubjectcompatibilitydeleteissue.go create mode 100644 pkg/models/shared/ssosubjectcompatibilityimportentry.go create mode 100644 pkg/models/shared/ssosubjectcompatibilityimportissue.go create mode 100644 pkg/models/shared/systempreference.go create mode 100644 pkg/models/shared/taskactionsserviceretryprovisioningrequest.go create mode 100644 pkg/models/shared/taskauditaccountdeleted.go create mode 100644 pkg/models/shared/taskauditautomationtriggered.go create mode 100644 pkg/models/shared/taskauditprovisionentitlementmergecompleted.go create mode 100644 pkg/models/shared/taskauditprovisionentitlementmergetimedout.go create mode 100644 pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.go create mode 100644 pkg/models/shared/triggerautomationdispatcher.go create mode 100644 pkg/models/shared/unusedsecretevidence.go create mode 100644 pkg/models/shared/unusedsecrettype.go create mode 100644 pkg/models/shared/updatefindingsettingsrequest.go create mode 100644 pkg/models/shared/updatefindingsettingsresponse.go create mode 100644 pkg/models/shared/waitingfordeviceplacement.go create mode 100644 pkg/models/shared/waitingforentitlementmerge.go create mode 100644 pkg/models/shared/webhookdispatcher.go create mode 100644 providercredential.go create mode 100644 reporting.go create mode 100644 ssoapplication.go create mode 100644 ssosettings.go create mode 100644 uiconversations.go diff --git a/.speakeasy/gen.lock b/.speakeasy/gen.lock index 7df9b77c0..ab29596fd 100755 --- a/.speakeasy/gen.lock +++ b/.speakeasy/gen.lock @@ -1,20 +1,20 @@ lockVersion: 2.0.0 id: 92b09ddd-c177-4138-92d3-695ede152b21 management: - docChecksum: 702d88307c60efe3f5dc3fafd0f0d755 + docChecksum: c8b6990564618d81bc0ef846e57f822d docVersion: 0.1.0-alpha speakeasyVersion: 1.790.2 generationVersion: 2.918.3 - releaseVersion: 1.29.0 - configChecksum: c1faf18490fa06e2f3ec9c388677a428 + releaseVersion: 1.29.1 + configChecksum: 243572a28ac66ec3f98ed5d1ab9f643a repoURL: https://github.com/ConductorOne/conductorone-sdk-go.git repoSubDirectory: . installationURL: https://github.com/ConductorOne/conductorone-sdk-go published: true persistentEdits: - generation_id: 10704ac7-4d66-42ca-ac59-00ab6a77809a - pristine_commit_hash: 711c34cfac570d98fa39650151656c7ed0e6da45 - pristine_tree_hash: 4aaf54782ceb02f257e269246fbff6913c3d0d92 + generation_id: bda928fb-40fc-4ac0-aebf-647c7d52f176 + pristine_commit_hash: 145c48ae5f36ea1752ff69726a4a095af786b675 + pristine_tree_hash: a213e7e3cba871fac606a2c77afac91b9b9d2a31 features: go: additionalDependencies: 0.1.0 @@ -46,8 +46,8 @@ trackedFiles: pristine_git_object: e6a994416d0f527912d2d272e2583458f4fc9bcb a2ui.go: id: 9eca3c82e4c1 - last_write_checksum: sha1:eef3a1e55443d8d02eae42b0b659d6e5ec2ac0c4 - pristine_git_object: f7962a742678a169b02fd1680d382876d61b29e0 + last_write_checksum: sha1:81ef27c19aa77bd0bc39405eaed0b5322ce8b2d7 + pristine_git_object: 4a3a2c53de5acd6d4ba7c767161ca9c949befa79 accessconflict.go: id: 18e5ac559fd1 last_write_checksum: sha1:5255ff7f5bc67a6369b4942b3fab17acdf0a0d4f @@ -56,6 +56,14 @@ trackedFiles: id: 28695dfe81c4 last_write_checksum: sha1:58c16d820c1b070328f268b6aeda395f05a111b2 pristine_git_object: 1f7f65f7c95b5c0f6cb4ec737158279c3271f55d + accessreviewactions.go: + id: e7d0652ef385 + last_write_checksum: sha1:460863246e8fa2ec72772246c190d4899a890665 + pristine_git_object: c12c5db36bc0d7882e233c977bc18cc5bb31d4f0 + accessreviewreport.go: + id: 3d54cfd01c4f + last_write_checksum: sha1:b1bdd3539eba064633948489749431fa220e9eb0 + pristine_git_object: 112c0552d3ac02dd1a80f198030e2ea6b453e2f3 accessreviewsetupentitlement.go: id: 6cf5266bdc70 last_write_checksum: sha1:6c5581f0719ffbd2ce182c0975b4fb2f095380c3 @@ -74,12 +82,16 @@ trackedFiles: pristine_git_object: 7aada44b3fc20691d300a5c38cea1d437ffc8d22 aigovernancesettings.go: id: 34ba0725779f - last_write_checksum: sha1:567fce89559b8b63c76daa126dd59087304cc702 - pristine_git_object: c3c13dd5f5b0f18bbddfa81f9a1a9190c62d692b + last_write_checksum: sha1:29ecf74d98b3a6bdec541c78ad15aeeeb1fb9e6d + pristine_git_object: 09b1875a1e4f5286591042d4a8237eb07e471dd9 appaccessrequestsdefaults.go: id: 0f09db207302 last_write_checksum: sha1:64ab837505c685ef8b7161c9f673e17a145576f7 pristine_git_object: cd1df66513becdc47e8d616e64aa51a6c835cb57 + appcap.go: + id: b5d23c3fd043 + last_write_checksum: sha1:79acd07ffbeac6c198f15a6a29d205912afe9062 + pristine_git_object: ecdbff74ce155636e2049403772406c02b6b0c9b appentitlementmonitorbinding.go: id: 5f3b7ae94e0c last_write_checksum: sha1:4b9a33e976f0371820b7a9fbb298743dc34ec88f @@ -94,16 +106,16 @@ trackedFiles: pristine_git_object: 58dc73c63329d4e8bc8b4b03c3a73e14b532705d appentitlementroutingrule.go: id: 0bcd172c2743 - last_write_checksum: sha1:6c124d5d576d968a84d20bcdd62fc30e046060ee - pristine_git_object: 6c4e096482572c1f3a8779835a3de84d0a96ed69 + last_write_checksum: sha1:5a734142ad6d60645a58e8cb2aba227a3f63e04b + pristine_git_object: 05d22ad207d71ad27e20344fb9ea4b5b292025f7 appentitlements.go: id: 500f27179473 - last_write_checksum: sha1:12173caedf9bc549ea11053e951b9a223c27c57d - pristine_git_object: 8bc4cad055650a3bbe3f66aed629b0e6442ac370 + last_write_checksum: sha1:a98e84ddc3eb0323c0f8c2e8cb1cc2e249c86caa + pristine_git_object: fda526e15d25490cc39fbc38a9dde004c03ff30e appentitlementsearch.go: id: "787442035888" - last_write_checksum: sha1:5a18cfff3392c031c9b36ad461ae95f389289490 - pristine_git_object: de67e77ca153b92d8046060ac36a8d162b44b536 + last_write_checksum: sha1:534f0e17c0e759f511b807888672e315e41d8f57 + pristine_git_object: 69433c60cf634dfcb4f14c4c3a18a932e66dfe36 appentitlementsproxy.go: id: f0d2648ad8a8 last_write_checksum: sha1:41f5f8663166fd33a43fa1a01f91ffe810ebc4b5 @@ -112,6 +124,10 @@ trackedFiles: id: c1a0843f3208 last_write_checksum: sha1:0e4ba58ce0b1f674c354e2b792bc4b3e57d1ca7f pristine_git_object: 359d6a60e449b9c8a7ef50837fdea5f36e443864 + appmanagedstate.go: + id: 86d0e7951d79 + last_write_checksum: sha1:004d7b40a60373c99c3925cb49fc2b4736a9d24e + pristine_git_object: 44167ddfda39d32e208fc2013148837fdc6300e7 appowners.go: id: f912cbdf1304 last_write_checksum: sha1:f7024c33cc60826ece00bb0e34d86a3a45b9ef6d @@ -182,8 +198,8 @@ trackedFiles: pristine_git_object: 34f29532b29accc41aa4b162954eb4f8a066d170 automation.go: id: 2737c5f414c0 - last_write_checksum: sha1:8df3242e496265d23af64b1f0423f6a0b0b527d0 - pristine_git_object: 055d6b15862d3d280fca96b4a380c558ad93010a + last_write_checksum: sha1:c5dc790627249d44ee8d98676ccf5362ed73273f + pristine_git_object: b24210777b033d528a55f3bf382b2acb151cbaf8 automationexecution.go: id: ad0f2b94e15f last_write_checksum: sha1:3fef226bfe6d9be96645b7816aa84a1cba2a5a44 @@ -206,12 +222,12 @@ trackedFiles: pristine_git_object: b470b740f8261c0291138f9269fa3147fe8c17fa conductoroneapi.go: id: e5ba30c7c4ce - last_write_checksum: sha1:8a1e45164e6ca8711d74fc1acff967afb3582ab0 - pristine_git_object: 04948488aa8f56447677efc8a0b6b2679101193a + last_write_checksum: sha1:e3ae8e203a2a48f7f22907cfd766c8b1a8660c80 + pristine_git_object: 70a7b5182b18158bb6f74fa0a9bc57d9a2830ae4 connector.go: id: f7ed3a032daf - last_write_checksum: sha1:40bd5265238266202490b5eefb64d5d6b7a6fd78 - pristine_git_object: 2db198947f6681be170cd2e25962cbee0e9a7ca0 + last_write_checksum: sha1:41fdd722a5182003e275d06e49906f6dcea56954 + pristine_git_object: 1939bac5cca33b0dcc485dea3038797def03f7ad connectorauthoringactivation.go: id: f0edc39ecf3a last_write_checksum: sha1:722c7057b926a772d7c76c10473846d9adc92a49 @@ -226,8 +242,8 @@ trackedFiles: pristine_git_object: 6ec6c4588387a80b0ea919a33202f2e2933bb00a contacts.go: id: bac181c17bed - last_write_checksum: sha1:b0d7dcea9b64091479fc1d7b0171c9a241a62698 - pristine_git_object: 144e4ca220c957cd4defeae98d47e85ac5bace82 + last_write_checksum: sha1:9c0a8ba90e64f5e33de6ca801193e220663e6943 + pristine_git_object: c40962e2546e116c629a6851536ee6b42c10a1d5 credentialinventorypolicy.go: id: 22481d3ddfa8 last_write_checksum: sha1:dbd9bab29493ca7255a736b38a61336d1429b4b6 @@ -252,6 +268,14 @@ trackedFiles: id: 8a5095a5a4e0 last_write_checksum: sha1:e51db58d98fdec0295bd13197b5843c6c13cb675 pristine_git_object: 4da49595a845ebd5b869fea1d318c1eccf9021ad + docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md: + id: 530a0a7e23ea + last_write_checksum: sha1:38a02e130aab387bdc35624e2a485f77382d5b7a + pristine_git_object: 902c9433c01f2b0efb6f21ca0e93120ce01a1f9e + docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md: + id: 782d3ef143fe + last_write_checksum: sha1:3ac75796379684f2d1b64f92b39aad5cebe2f8b1 + pristine_git_object: 9732c7df1433ff2fdb1a87b1f1d2630f811a2dca docs/pkg/models/operations/c1apia2uiv1a2uiservicelistsurfacefeedbackrequest.md: id: 89e914ebc537 last_write_checksum: sha1:5d5bde851270478765cc09a2e1115fa0f8f2c1ee @@ -316,6 +340,22 @@ trackedFiles: id: 92724e8304c5 last_write_checksum: sha1:9eaf9351f6ae2715af45ff8638af974a454d8369 pristine_git_object: 893fdb21fcd9d8cb03329b8b1b275ddee9ed506e + docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md: + id: d2ab471cefa0 + last_write_checksum: sha1:54d31097984b73c308cbd8f0bafa427e8156b465 + pristine_git_object: e85a9555ea0bb49f6618b119623fd61e35d8f434 + docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md: + id: 043a109dbded + last_write_checksum: sha1:f022013be56648cb2329505aa46cff85d5041a00 + pristine_git_object: d5c8d0362ff46474d9d77153947d8b31435cf95d + docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md: + id: b71729100445 + last_write_checksum: sha1:710086dba783261ebe4defd48ccefd17371032b8 + pristine_git_object: 5c5e03b8cfe1d86feae029c0e8881d2ad658adf9 + docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md: + id: 007c7bdc01e3 + last_write_checksum: sha1:ea0e2769b9e10ea4fb5037f507fa2a09dd54f2cf + pristine_git_object: eb8bb2d41afd288b21fadf3291b8ec8a3af18cfa docs/pkg/models/operations/c1apiaccessreviewv1accessreviewservicecreateresponse.md: id: 1c231ca1bbdd last_write_checksum: sha1:96f1f49b6fa7d922eb6569de00643ffc4cbab7e4 @@ -492,6 +532,14 @@ trackedFiles: id: 83e821db1d2e last_write_checksum: sha1:4d4743827a9838e5d2455f88fe993086829571ee pristine_git_object: 15f15794d26fd39b113fa818d9fdf87d20bcc707 + docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md: + id: 389e9488d8e2 + last_write_checksum: sha1:621a14c5b5be3117ef3b4c163c35d8aefe38454c + pristine_git_object: 6a0a739a4b16808691ca19fa2a9b0dc97515a560 + docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md: + id: fff125b26338 + last_write_checksum: sha1:c135dc3b4ace2a2b51f4b255b0c59e24ef8414e9 + pristine_git_object: c7b645c495ef873c76d6188af2dde3e7df6b0000 docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchrequestableconnectorsrequest.md: id: d16eb232013d last_write_checksum: sha1:05a537ace9b02bc19894df1fff5775cb2d1021a6 @@ -556,6 +604,46 @@ trackedFiles: id: 46a16646cf96 last_write_checksum: sha1:18f1cf2a3b2fbcdacf4c7a335249aedd8b6e14a9 pristine_git_object: 55ac967ae5ddea476a3997b537dd093c51aa3b2c + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md: + id: 58750624aebb + last_write_checksum: sha1:a0d51315dd841bb2e1d230d2e22e02763ed1bcae + pristine_git_object: b04feb4f288ae4de4e31b70aba178df33f216966 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md: + id: 625f8f825f72 + last_write_checksum: sha1:b29dc66265cb6cd7d217e5529577f2f018a7b6df + pristine_git_object: e37ac81e5531a7c7bed4c09285f6840f5b8108f7 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md: + id: eab42f7d700a + last_write_checksum: sha1:c7b25bfa3ac76ec2e3b35cb240c6e527f2bf8e4e + pristine_git_object: 07b96921fb2cf55461ae1b6b985d027820db328a + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md: + id: a63680daa601 + last_write_checksum: sha1:b7210c3f7073a240d09d9859f726c8014c3be64f + pristine_git_object: 7bfba7ef1a19b4693bffd8cb59d5f670d5449a36 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md: + id: f63a2da6dc3b + last_write_checksum: sha1:0f98679e91d2353d0c9dda1564fc5ff5d2009351 + pristine_git_object: cb44710bda9ff6b44c28ae61b95be1b4176d618a + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md: + id: 31a670568f9d + last_write_checksum: sha1:67c89d85309131bd3665315a6316eca9ee1156ef + pristine_git_object: e08f7d6922f2b327a3253bf75b24ec9244fa826d + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md: + id: 2d389cf79a3c + last_write_checksum: sha1:019d0b51f0e56ca6840fd4a0d22a939b387d5e42 + pristine_git_object: 23e8b048cc3cea8e69f5e9828a662e2041b6be60 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md: + id: c034ec227a7b + last_write_checksum: sha1:e8a57d82271ab5ed1babb61ee510c7f981104d1e + pristine_git_object: 788c965be47c5ae05391f418a9f9e8677b2388c1 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md: + id: 7dd0dbce9205 + last_write_checksum: sha1:5368b6a5671873cfcdc8d13d8485885ab6da33d5 + pristine_git_object: 1dff8cd690c260c2ce0ee00f393844f12ef91935 + docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md: + id: 3e89329676ff + last_write_checksum: sha1:c003d56fecd34873ffcbaf2519b2760d33e071f8 + pristine_git_object: 22d317921342169f2ec73bdb9538810b0b623af9 docs/pkg/models/operations/c1apiaigovernancev1mcpserverservicedeleterequest.md: id: b8af4a1d9421 last_write_checksum: sha1:6320ace831f5a81ddfb0e44587225452412aadcf @@ -896,6 +984,10 @@ trackedFiles: id: 7979b8654ad0 last_write_checksum: sha1:b1c4e28db43899a85a2d98573510927048b775d8 pristine_git_object: 043efb004842f16c8f35b8ed3750b864c33a239f + docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md: + id: 2f2ce9a5da6d + last_write_checksum: sha1:6e33b2706deb8e5a565e61ab1eebfec6d046c341 + pristine_git_object: 39af5af9180bbda80a1de60416743c2a1db5281d docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchresponse.md: id: 9bb90a94ea12 last_write_checksum: sha1:64c657e6f52a7158b92b1b9235c76d6dc76386de @@ -942,8 +1034,8 @@ trackedFiles: pristine_git_object: 394c0bbddd1fe536f722418b060d37dec98d61aa docs/pkg/models/operations/c1apiappv1appentitlementslistrequest.md: id: 0a1510daa0d3 - last_write_checksum: sha1:bd3d1e028e74664afec29a7ea08fee78549c3535 - pristine_git_object: 5cee8742412c888c6037dbe78298c8b9efedfeec + last_write_checksum: sha1:f4fda7dee81eb76154629ead6226c7b3683cafe1 + pristine_git_object: b5dd401e3e320aeab9513969bdcb05df71088628 docs/pkg/models/operations/c1apiappv1appentitlementslistresponse.md: id: ab3f641fdca9 last_write_checksum: sha1:16033a4be377abd9c94ed3697842d207c01ec4e7 @@ -1044,6 +1136,30 @@ trackedFiles: id: f3270541bf0d last_write_checksum: sha1:be7a35de31849b6fcbc4cbea380aa7c05b96a7b3 pristine_git_object: d03e26dc5976c9f86df8eca0b70e672e059422d2 + docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md: + id: 6115f39f67cf + last_write_checksum: sha1:c4b2890e6cb1fb27764bf39311e17de61f2f5db0 + pristine_git_object: 1b377a29641e3b8e43b6dc57f99d8b6dff1bc9c5 + docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md: + id: 46bda072a279 + last_write_checksum: sha1:98ad0681837fcfa03435cb2d1b3e781108a091a1 + pristine_git_object: fe56adb59c26c7f4fa57282d31ddfa45b6ac5cbf + docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md: + id: 8ffe9cc365bf + last_write_checksum: sha1:28ce0efda521ab38a7ac05b9004319d3cf32616d + pristine_git_object: b30cc2b3ac6d5ec0cca7be0140119b670097874c + docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md: + id: 8b41bf0437f5 + last_write_checksum: sha1:1468600f2fed1dd461ea83f759d70c1e00545020 + pristine_git_object: 38a488f6530be7338c28ec8f7f1800b4be2bd99a + docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md: + id: 8d32796e8364 + last_write_checksum: sha1:4ba1b741d71c103179c6e48259b260de9e67e074 + pristine_git_object: 5652bcfa72dddc2414a90a7713add331ef89fd1d + docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md: + id: c2810862c244 + last_write_checksum: sha1:bf5efd79b5803d1127852c2ebb07d79b138418be + pristine_git_object: 0e72b10c8c3f0c0f2e089cc86a2cd8af7900dbf2 docs/pkg/models/operations/c1apiappv1appownersaddrequest.md: id: e57ee6722bb2 last_write_checksum: sha1:c9fb2c6b0a84d9ee94d8aaf4675a28e8154cc8c0 @@ -1246,8 +1362,8 @@ trackedFiles: pristine_git_object: d07f62dd6a01a1b4aaf13b433d61db0a2524278e docs/pkg/models/operations/c1apiappv1appscreateresponse.md: id: 32435acc54e8 - last_write_checksum: sha1:4bac2e862c8986157a79965beecac97fc92e649c - pristine_git_object: 5007a79ecb5f790b160dfcd063c782fede5d4c6b + last_write_checksum: sha1:634311240a6b80f959c80a313178506c31f0ea9c + pristine_git_object: 07467d1b115c73328823d21443268284255ed104 docs/pkg/models/operations/c1apiappv1appsdeleterequest.md: id: a2efbf435d12 last_write_checksum: sha1:7aec186255191b679c117a476a1dfdd24a37afc7 @@ -1382,8 +1498,8 @@ trackedFiles: pristine_git_object: ebca2b29af70d5e153916bd86930e7a366e88c72 docs/pkg/models/operations/c1apiappv1connectorserviceforcesyncresponse.md: id: db4792aa1fe7 - last_write_checksum: sha1:6992ac5d8a8a925c2e89116115c19fd01256e113 - pristine_git_object: 7952f8f0463a5a4bcdd8f64c64e15fcd447cb9bb + last_write_checksum: sha1:3cbeb0658ab155baa4570c5cff7b164427c60216 + pristine_git_object: a5ec7b9ad7c5e9055fccee046a59d884120a3b8f docs/pkg/models/operations/c1apiappv1connectorservicegetconnectorsyncdownloadurlrequest.md: id: da7953da51a1 last_write_checksum: sha1:f945558b8c460d612de5e52987c00d6dd200de1f @@ -2052,6 +2168,10 @@ trackedFiles: id: 67a7163b3f7c last_write_checksum: sha1:a1cac651c998321e5f83c7b522b48e219868a5c7 pristine_git_object: 96662a4d273f3c2f8ac2caa4b645013717cd3845 + docs/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md: + id: 5dc74ce8e0fb + last_write_checksum: sha1:cf3919cef8af9a41d7ad676c8ac27ac8c807a2b7 + pristine_git_object: 1ec532222c06875d90c7d6069ec87e043bba191d docs/pkg/models/operations/c1apicredentialinventoryv1credentialinventorypolicyservicecreateresponse.md: id: 104e77607f30 last_write_checksum: sha1:7cd0b27d913c16bdef4cf1ae3a88b367d9dc0ad7 @@ -2548,6 +2668,14 @@ trackedFiles: id: 23ac435e2f77 last_write_checksum: sha1:37635d3393028048d07fba2e13fa94c3eef5f541 pristine_git_object: 90e692432307b2a7bbb8c2b4a04442d0579230f9 + docs/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md: + id: cfbcdcf04da3 + last_write_checksum: sha1:617bdba8e583e3201cf4f6e9c20d431b071399a9 + pristine_git_object: e62f12ba448598e88efe3545447c045142e85698 + docs/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md: + id: 6c429542479e + last_write_checksum: sha1:8ad2b2f78c82147c1a40ba66e44e8cfaecb04ab2 + pristine_git_object: 90f08cbe7d6aec3798902b67c9a503aed7026f9b docs/pkg/models/operations/c1apifindingv1findingtransformationruleservicecreatefindingtransformationruleresponse.md: id: 656b9906828f last_write_checksum: sha1:61e10f2ba917126aa79b580947ecaa9f5f8ce1b6 @@ -2708,6 +2836,262 @@ trackedFiles: id: f083c4a206aa last_write_checksum: sha1:e37f56477250ad86bb9b5c48da5a04db9d084177 pristine_git_object: 2afeeb5964ce3f30f57069734189e67270df0429 + docs/pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md: + id: 8e06a9f051d2 + last_write_checksum: sha1:fd81e59351db12a6a2611335d612e1d4542f6c3f + pristine_git_object: 7a287adc78573f4f4f2615ca5f7be33823337abd + docs/pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md: + id: 203216dc2c3f + last_write_checksum: sha1:fa647a3d1cb7c47b06d6bc6b68e9336c414dc4bd + pristine_git_object: ffd519b06c11b249c82a63c03af285e6c870bcc9 + docs/pkg/models/operations/c1apifundsv1appcapservicegetrequest.md: + id: 9d94ec3b845d + last_write_checksum: sha1:12915203c072823fa0a26a6cf690e517665fd5c0 + pristine_git_object: 5681d300ceeb3286d3d07e1c45b1f96c8cb5559a + docs/pkg/models/operations/c1apifundsv1appcapservicegetresponse.md: + id: 302d88bc3852 + last_write_checksum: sha1:a012655776ef886f92a9dc084323e61b7e06976f + pristine_git_object: 2a7bf9121667d51fcfd54f9e40f02dcdebb8bb92 + docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md: + id: a941efd404da + last_write_checksum: sha1:5eb7bf08f2b5e3c38a6e525e403c10ebdcca59d0 + pristine_git_object: 03cd8504747ca21a0785c69594e926df02816b65 + docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md: + id: d751ca84e280 + last_write_checksum: sha1:b6b815489165e45e867abb6bca12d1cb603a2c64 + pristine_git_object: 75e1459feb55230672632479db13b0df6aacabcc + docs/pkg/models/operations/c1apifundsv1appcapservicelistrequest.md: + id: 2363dce997ec + last_write_checksum: sha1:ca4c8164aad8169137873134f87d99610d341c7f + pristine_git_object: 1a0002d1e74bfba50d1588638383020c0361d1f3 + docs/pkg/models/operations/c1apifundsv1appcapservicelistresponse.md: + id: a7c0ba12beaf + last_write_checksum: sha1:7c9c734e6cdeeb82ae521e4c4b55dfdd3ea41cc6 + pristine_git_object: 7f7eac842dcb444dce72988f8d0a9a1207eba4f9 + docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md: + id: a1cb8597f7ef + last_write_checksum: sha1:a71c3073d8d5a7e5ec60e603791d9b8d0dd83eff + pristine_git_object: bc51ac3f8b0e023e82b8e652cca81a6f85b58b5f + docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md: + id: 17c4376634b2 + last_write_checksum: sha1:f14a51cb8e650ba7d1a8fdda3016c659ff1635e7 + pristine_git_object: c60739bdb9ea88dbaa514163b06b1d78da51aecf + docs/pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md: + id: c21e849d815a + last_write_checksum: sha1:e8b41d62dc367cebec3e3a42cd41f6b20e62225c + pristine_git_object: 1992409671e227aed96fa0e310be7f81469f8d52 + docs/pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md: + id: 7b10ac643c9a + last_write_checksum: sha1:742447adef739cfc60f1a9c5b983823f46c896af + pristine_git_object: 6c1a396173efb3d3d03a5862c6281c9122863c5d + docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md: + id: 856806bf275d + last_write_checksum: sha1:42f3674831005fd75512f3907a7e035114d69ab2 + pristine_git_object: 727a1e77cb15c2bf4d54f4d42e01d7d805c6059f + docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md: + id: 4fac282e77fa + last_write_checksum: sha1:b96857a6254d95a398d7e3c64a97f12a6c714b5a + pristine_git_object: 72fcb877992faa8c018f184f1a6e99a1b7459461 + docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md: + id: e18418236f05 + last_write_checksum: sha1:6be152e3d5c887a3e9eaa621b2b079cad0a9441b + pristine_git_object: a17520c727342b24d12d076bbfbbefb49700eaa0 + docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md: + id: 922c2ecf92f2 + last_write_checksum: sha1:4df137b1a5a323b60b478d2722d64583ed37bd2f + pristine_git_object: 644b899c52bbc66cb4b5c1c77804ddd170dc047d + docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md: + id: efd203d3060b + last_write_checksum: sha1:5fb064c40bc373ec93ba3dad56179236a85ab5fb + pristine_git_object: 70eba7801baf9c9a49dfed554258f5fd0d7be5e7 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md: + id: 13f2099ac4f6 + last_write_checksum: sha1:d5f526ca64f4b38caf9f40c33bec6b9be7b2b320 + pristine_git_object: dd77ddafaabeb31c63e89d3bcd87c6090d4998dd + docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md: + id: 86bda865c683 + last_write_checksum: sha1:b8b47c148e14f5ccd062876046e8af822f4fe815 + pristine_git_object: fc04b75b7c670b0e67ce19ba4bdd45d06f378fbf + docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md: + id: a4a7dca809ae + last_write_checksum: sha1:2fb81bc1a839cf31295c8546723f631aec17e4df + pristine_git_object: 26253300b2bc41b38ce2859aa6a8d27b2c77a5ed + docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md: + id: 5d9523fde022 + last_write_checksum: sha1:5ebfa7f26bea0093669815e101d9c83e81cdf404 + pristine_git_object: 2c65418eee7e7ac8ec088cfa6571b5fb8c934000 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md: + id: 2cd0855e9ada + last_write_checksum: sha1:d8d0cc7eaa65bd23300bf4a48106d873fa693f59 + pristine_git_object: 51948906d29eafe6e961017b72f55f4ccebff701 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md: + id: d73eb6e9ab0e + last_write_checksum: sha1:dcae1fca0b7cb9912051d99541e3c4e0097e76e5 + pristine_git_object: b2830adb865f83660cf8ed0680e8841b2b608474 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md: + id: 6bcc33c7a4c6 + last_write_checksum: sha1:36d0b58709ccaf21c7a58056a959df6f46bb07a3 + pristine_git_object: 513c45aea7657af393110361ecc260fd64c6a6be + docs/pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md: + id: c95851721eaf + last_write_checksum: sha1:f509214a484ba0946edf8b8cf6067992f4cfc254 + pristine_git_object: d98d9e9d23aefedd3e7c91e5b8d4ad73cc6da652 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md: + id: a74b9e215d8c + last_write_checksum: sha1:19d600076905c97e8b5e5d620676b722ed156736 + pristine_git_object: 3efa41be33e3ba07acf0a3c045ebd1f91f838dc3 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md: + id: 6748be031f9e + last_write_checksum: sha1:5678eca4b842c15c628c5e951203194460c1d729 + pristine_git_object: 18e8d4c2a8a179f974d99604533825a65f01a114 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md: + id: 279f3cce608b + last_write_checksum: sha1:ca5dc2a2feb5c930e269e2579871b3f80948e0be + pristine_git_object: e8e3137b52535f84cc1bb16a41bfffd6f9bff260 + docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md: + id: 4ecf4f2b0985 + last_write_checksum: sha1:93cd889bb55dbf6b7c0d4bcd234ab91067fc349c + pristine_git_object: e3c9c8907c5aa7fa790d0b8977f56c779894bf0e + docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md: + id: 76dfcecfb59e + last_write_checksum: sha1:4d7614bbbc79e993fd7a63d0cecac0ac14743be2 + pristine_git_object: 5d805c8d70ca44027b563bcb69aca3431c1d090a + docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md: + id: f50ecc21d6eb + last_write_checksum: sha1:9ead7ee54215511b038e46ae4c4f9418c3242638 + pristine_git_object: e6ee913375337f8423a6ccdd0c70966dd8b67339 + docs/pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md: + id: e2d8a39cc749 + last_write_checksum: sha1:b8584d39c9a538b98ffeeb9998a0165a890316ee + pristine_git_object: 8b2997f1bdded7acf5554ec7ba6fbcb8dbe87d9b + docs/pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md: + id: 920935347be7 + last_write_checksum: sha1:42383edfb4722b29cac464a3c8425574a8b08d0e + pristine_git_object: bd0bafeee070ed497f8a238919a4eef9ba812b8e + docs/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md: + id: b69e18d518e9 + last_write_checksum: sha1:100fa1bff8050578596f51ed761ee4124470eda4 + pristine_git_object: d73cda289aeb440307fe37c15cb468fab72b4c15 + docs/pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md: + id: ee0c46a310db + last_write_checksum: sha1:4206f8c26aed2ad5a4e7cc093f1fab887b344276 + pristine_git_object: dc428ab863cab506a3a2874a3837d969ab356c2b + docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md: + id: 0cf33a9882bd + last_write_checksum: sha1:d0f1d289638bae414e6c4808a3009ae15f1c3bc6 + pristine_git_object: 0e65892bc87a443aad818af20dc9fc8d62968f7d + docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md: + id: 121cf966ac07 + last_write_checksum: sha1:cf2d864b79c1101f5023e92e7dbf2affb8092565 + pristine_git_object: 89dd38fa8f47f139153333180b2382ed927687bb + docs/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md: + id: 1e5f5c43a98c + last_write_checksum: sha1:228873eeedfe8c06604269b41f456ec4bd12c6c8 + pristine_git_object: 0b339d16426ad765202252dc8415f248fa2ec5aa + docs/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md: + id: 2a58cc5ae3d5 + last_write_checksum: sha1:7e02ef543095475c9e156be8a39ba208f33af0ab + pristine_git_object: 01425116df51c305df88d85836d6fd378a9c4359 + docs/pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md: + id: 93403a5de28b + last_write_checksum: sha1:8f04bccefed95c54c727cebb169bcfc940c1a20e + pristine_git_object: f1d78de4288d21c7fa2117eae59c4d5bebcc7528 + docs/pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md: + id: 943b7a231815 + last_write_checksum: sha1:a15f236b60dcef314d12a92ebadf7ed5873f75fe + pristine_git_object: 4e77007da8c8ad16230b71f9dd1b0a5e9c7dd435 + docs/pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md: + id: 1fd346f1379d + last_write_checksum: sha1:f495a4cf7f337a705f67aea7cf6548ab1e423560 + pristine_git_object: 068303722fdafd380ac2477cc9ae5593b98b3a61 + docs/pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md: + id: 01e813e1faa4 + last_write_checksum: sha1:7262a53f301cc702e230c14d0c3d737229ef55eb + pristine_git_object: ecc7c8f9e67267c2ede3fc9540ccb0840f94c49e + docs/pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md: + id: 9f6f4bedb880 + last_write_checksum: sha1:cf8df6d392e53d192d08f8e45edeb5e51cef4992 + pristine_git_object: 6582bb93c18fa63e251f45d46ea56ecfd104e034 + docs/pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md: + id: 0aaf4909f68c + last_write_checksum: sha1:10716c8af7849a14834ee3c16aeca444907ef15a + pristine_git_object: 1366bd5a3cb8e753bb7e56e8a890a05cab3dda9f + docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md: + id: e6e5dd998df0 + last_write_checksum: sha1:7ded9f4fd42c3425434fab840a2f8d4fd358592b + pristine_git_object: 59d053aed458da773c841489cd6827b3c65164af + docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md: + id: 572529e7c67b + last_write_checksum: sha1:828d189d8c22945a034a745db87c03befc3c401d + pristine_git_object: 4702b5322a04beb8947c2cef37d31039c88c5fbc + docs/pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md: + id: a3c0cc803fb5 + last_write_checksum: sha1:5f97a53514e5bf7047a9e60dd3af4f16fbaec371 + pristine_git_object: 3bf07586a25b269585f12d931e95d04cc6f1fbe2 + docs/pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md: + id: e7864ce85cd4 + last_write_checksum: sha1:8c3aa6a0e5eccef6230d7c5d8ddc93818f8565fc + pristine_git_object: 80957aaffee60009216ab35e7a284984da4551b6 + docs/pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md: + id: e986bcb627fc + last_write_checksum: sha1:7d46310a483a38f409eae5e895b313042abc72ef + pristine_git_object: 10de092580d5bf8185bb7119c2e0f4a6da4ac211 + docs/pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md: + id: 51b50f907543 + last_write_checksum: sha1:caf612646f9d2fdc026ea8acfea7180d01482e82 + pristine_git_object: 48bfb972c2ec6e6bb9619124967035fe8ecdde59 + docs/pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md: + id: fa5979e63a78 + last_write_checksum: sha1:e5f0bd2d1b797df5994939fa1dac8a2a2e8031c9 + pristine_git_object: 238c85063cd68ea0bcf771841f0e07ff18a2eec2 + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md: + id: f2315b02c744 + last_write_checksum: sha1:46a385c69bb188d047e939f6f567bc0e398a11d6 + pristine_git_object: 065d87c6728ed9287e315aec300b0a88fb8eccae + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md: + id: 3a7deeb90d52 + last_write_checksum: sha1:e7f0c120c807cce3f9502d36248d1ad23d036320 + pristine_git_object: 76ba529487881b66216cce560f69933aba570d9d + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md: + id: d07c37396d40 + last_write_checksum: sha1:349c1cd1f59403d17b64c470365e282b10eca230 + pristine_git_object: 56d7cd954534338b42f14ce4bcd143823a975cab + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md: + id: 742333a56e93 + last_write_checksum: sha1:8ba91a1145fba07111ebdb54405326f46df70ccb + pristine_git_object: 07c335f10318f4cf4b2249668ea71fff073f99d7 + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md: + id: a8cdf2cf2a5f + last_write_checksum: sha1:f0c0c1db9b4a39426d0316fdf98fb14a0a7cf08b + pristine_git_object: 5789ec19c406d51d6d43537db332e10835341c6d + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md: + id: 499cd3b9ba9a + last_write_checksum: sha1:79e9485142729769c38a844322af292395c09782 + pristine_git_object: 4a95a05897036ffed1a669d24bf6879723f43168 + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md: + id: 7019e3f563e9 + last_write_checksum: sha1:cd6db30a78e58e51fff23a3a71488e0d4ffb22c2 + pristine_git_object: a0d4b0b5565d6cc47248fedfa34b0b519073bcc9 + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md: + id: 178a4f9dd0a6 + last_write_checksum: sha1:2b3c1f38e625ed75c33468702e1b92bfe30a0700 + pristine_git_object: dce54c73b9b545a35290701b94d732147aaab7a3 + docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md: + id: a8cdda3d684e + last_write_checksum: sha1:6d518fa7935d5f530cacdcc8b63aa47cefb453ce + pristine_git_object: b717a01ff64dc549c21222e8cb4f6ca0f09e1ba0 + docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md: + id: f32de2c810d2 + last_write_checksum: sha1:61335f229ad0579413f14135219fbc51ab86e590 + pristine_git_object: f23b9619ab7787b75390c3e8c5402c668b13f833 + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md: + id: 34034a250139 + last_write_checksum: sha1:b0c6020d0b34287d66031af105760ac6d6b066ae + pristine_git_object: 7a2e15216f63267f5098245c5a674903980182fa + docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md: + id: 4a8debb6abd6 + last_write_checksum: sha1:b9a50decba7f3bbd4474f261e90aa7e29a1c0f37 + pristine_git_object: 8476e5ed68d6d9ebd99f7e073e86437b5f3182ee docs/pkg/models/operations/c1apihooksv1hookssearchsearchresponse.md: id: a4a655a3dda1 last_write_checksum: sha1:b2c1a788ae09db6686a6effd95ccb54e1ddc3849 @@ -2932,6 +3316,46 @@ trackedFiles: id: 42a44920bcea last_write_checksum: sha1:11b420730ca234183a7b3241478cc82328c10c44 pristine_git_object: ba3bb2d6e197923c3c1abdf4cbc9ecf38a580f40 + docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md: + id: 9df30e5a7607 + last_write_checksum: sha1:9855eb20f30c7723d0b0e2740776b6a6ba2c769e + pristine_git_object: 3397e4f331a2cf504daffe5ad6cfb394ab62e365 + docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md: + id: 26fd13a0bc93 + last_write_checksum: sha1:acd76024993adb7125af099fff36537921e07a94 + pristine_git_object: c1029073db5a9e40ffdfd3787433a082ee9c5685 + docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md: + id: 18d4c8caf887 + last_write_checksum: sha1:c93234e69f73ec7f16f762a25e0a28027c6a2bad + pristine_git_object: cfd24aad209c71314e2ae4592f3128eb622b6830 + docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md: + id: 8f6341372aa2 + last_write_checksum: sha1:db87108aa4a2bdcc91d032bf017bc41e5733165e + pristine_git_object: b2831195a3fc4e17c2e9928a1b875273127fcf35 + docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md: + id: a0ed2881063e + last_write_checksum: sha1:931b5eb04c43d418861d99a4c351e3016abf7659 + pristine_git_object: 8e69138f9585caddf7f342c3103abb387043ece5 + docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md: + id: 6a354e1c1ac6 + last_write_checksum: sha1:70e7ba54bb6c2708116494d3b3a623149af08f2c + pristine_git_object: 995e1bc54634e54f38c9d0e7dfa4cccd67d6751a + docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md: + id: e11bfdc0477a + last_write_checksum: sha1:ada9cbf3c8b04aca860609eef9f561d80b394e26 + pristine_git_object: eb826200571a7e5c953f328b4bcd6c831f8fde32 + docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md: + id: cbbc90b391bc + last_write_checksum: sha1:b4accd8e81f83ad1b1a514a4314c39c8c60a42f4 + pristine_git_object: e109b0ad1d0127db319d1fd79e1e344c001d7f8e + docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md: + id: a70e000ecce9 + last_write_checksum: sha1:82aa5a196b9dcf9edf2c3c8d5f7a131497399630 + pristine_git_object: 3b7cf87ea60d877f9f8b81906231acbd66693050 + docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md: + id: bd1f44842859 + last_write_checksum: sha1:6eca74ab180e4db7d31f4179141fda64f9023bb9 + pristine_git_object: f3c03e44b9b864567f55335f257f5cc4354397de docs/pkg/models/operations/c1apilocaldirectoryv1localdirectoryconfigservicecreateresponse.md: id: 4f4069db1881 last_write_checksum: sha1:8c4d67b6d94cceaf8d26e5aa1245ccd9f862edfe @@ -3044,6 +3468,58 @@ trackedFiles: id: 1828554750c4 last_write_checksum: sha1:025630cf05d264693f5b4d8025ac2307cb7e6d58 pristine_git_object: 11495da30b1da105386385442e563e18c0895b93 + docs/pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md: + id: c69730995394 + last_write_checksum: sha1:40c68785808ec77351703782b95261c3bdca54bf + pristine_git_object: 46db929a38a2c74ad2b78ba0c7cd7bb78a8cb878 + docs/pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md: + id: 42c4a6c592f2 + last_write_checksum: sha1:814d88290208ddeadf925424e6df4a01fe4824a3 + pristine_git_object: 263b7b89661a1f3e25c6315fc8eee9e2742eae6b + docs/pkg/models/operations/c1apireportingv1reportingservicegetrequest.md: + id: 29088dd31241 + last_write_checksum: sha1:bb5c90fdabf9e9edb6313b96e2eefd1bbad21e95 + pristine_git_object: 57ee9ff6e9146bc6e78df649c0d99e0d817507cf + docs/pkg/models/operations/c1apireportingv1reportingservicegetresponse.md: + id: e4d4157f8416 + last_write_checksum: sha1:21027beffa97dab35cb9d81333d693991d49908c + pristine_git_object: cdd7d9c349984c12085ca8ed975d7ca97c19e54c + docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md: + id: 93a54ef9661e + last_write_checksum: sha1:91ead98c533afd6f9e5bf99e092375d91563c906 + pristine_git_object: 687a104f8aa233381a5400f9fb214a72665db8d8 + docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md: + id: 03e12611319b + last_write_checksum: sha1:9d4e40b1b9971d766d7b72fdcb68b722a23e271f + pristine_git_object: 76fcbec7198ec8b5004c8f32a4a0a32674c388e9 + docs/pkg/models/operations/c1apireportingv1reportingservicelistrequest.md: + id: 90b25a75990f + last_write_checksum: sha1:6b9b6c9364874c5a0dd60ea5acc1560d4266e82b + pristine_git_object: b0ff02a2bb26158297502ba5739f25fd05dd9c8a + docs/pkg/models/operations/c1apireportingv1reportingservicelistresponse.md: + id: 680a323f149a + last_write_checksum: sha1:c32aad68c5f3f914b89eb758a9233cde18d0a71e + pristine_git_object: a05333ac7730943931ec695baa6266990187e8e5 + docs/pkg/models/operations/c1apireportingv1reportingservicerunrequest.md: + id: 31ae92a37a99 + last_write_checksum: sha1:a59067257d20d2339a88f644bb45d591e983c7ea + pristine_git_object: fd22f04bfb6114f28776201299ade18c8d008af1 + docs/pkg/models/operations/c1apireportingv1reportingservicerunresponse.md: + id: 97c751b39b1b + last_write_checksum: sha1:b790d7047a9627c075b3d5f8c031e896fd0ca0ef + pristine_git_object: a002c12fc8bc53047d06d1a1cdd7eb1102191aff + docs/pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md: + id: b96bb239470f + last_write_checksum: sha1:af583fe709fd6071d5a28c2e7dd94ff0a7f6dd26 + pristine_git_object: d38924ae4ae51c881475e6782c707c45c816b9be + docs/pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md: + id: 00786a64eb07 + last_write_checksum: sha1:28707f923216e505111af0b13deacfd2b99a2602 + pristine_git_object: f666524bb319a6337843bb7c125693b0c1b78399 + docs/pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md: + id: b96853b48ea0 + last_write_checksum: sha1:49f5a70428b03ebe1d800e6adea702a5646ffbef + pristine_git_object: f69f129cb659dd6d25178855eca6893f9dbfe943 docs/pkg/models/operations/c1apirequestcatalogv1requestcatalogmanagementserviceaddaccessentitlementsrequest.md: id: 036bb4bcefee last_write_checksum: sha1:958cd90b138665a605b660112c6f18d086f2cd0f @@ -3268,6 +3744,14 @@ trackedFiles: id: fa5aec8ed421 last_write_checksum: sha1:55aacdf1f1d8df2166559efef3f306d6c2796381 pristine_git_object: da0c4328a0db683072af77bce4bbff0d54d95a4e + docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md: + id: 0da51ab0ec8e + last_write_checksum: sha1:f7b50c84283ec2dcf92a96b485cb223020a43582 + pristine_git_object: 358bfdeb6c97ed875ef598af5bdb6d3771bc67c4 + docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md: + id: c0ab1db0aa4f + last_write_checksum: sha1:974e76c446e544a78d64ca2fc3a489957f2af67a + pristine_git_object: 4cf4117c9bc9efe1f3726058ab33a9ed0078e44e docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementservicegetcustomanalysisresultrequest.md: id: 362448b5e8a3 last_write_checksum: sha1:6ad6f96b77e5266b6a664e8416b64cde313b10f6 @@ -3776,6 +4260,134 @@ trackedFiles: id: 00a970bd3406 last_write_checksum: sha1:dbaaa6e3ad4220371e9587494e2b3679e001f6d2 pristine_git_object: 00849103f0c602b4d8d777abc2caef54f7a7f5b9 + docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md: + id: 55f0c0106544 + last_write_checksum: sha1:509f605f1de91af754de5593d354e26f616953c0 + pristine_git_object: e07f77490d8cadc12f67f2106946bd1d3a381830 + docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md: + id: 9bce91ba2a87 + last_write_checksum: sha1:54641d940b91f0ec462be5cdbe24e0c1b426287a + pristine_git_object: 4e69b7fb84dea54eaa1b18ac79da26381a729917 + docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md: + id: dc2f10e90c8a + last_write_checksum: sha1:286aff0642e15159020ce5415dda962217879d58 + pristine_git_object: aefacc1b7a322c0c88d018b1fd06be961d198c0e + docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md: + id: "416572062499" + last_write_checksum: sha1:3ff87434a08b42c2ec0b5a7e64f39ebe115d6fa1 + pristine_git_object: 4dd2235c6f0dae6fb8b0ed0270d3c883f6febd6a + docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md: + id: 589ee2d1d7ee + last_write_checksum: sha1:ad4f957b3a807b30ab07b731bc54f11c2f85ea7a + pristine_git_object: 7dc49ab7ca56c757e44ca92c4b5823ac93f06dde + docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md: + id: 5a54336b1ae3 + last_write_checksum: sha1:b9014adb15a8605145183cfafc25e722fc610294 + pristine_git_object: 27429569630232b38091198f7e206b2a87abd247 + docs/pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md: + id: 352b6b0338e9 + last_write_checksum: sha1:353a8cef634e61fdfc88547ebc63602621a43761 + pristine_git_object: f3c12edd87426363748fa976ecc09c15a7949998 + docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md: + id: 2c5b73fd4e1e + last_write_checksum: sha1:fe9ad1196b6ceb7cefc22510549af48843554868 + pristine_git_object: 4c4bd7341683d097f1308e38f004cdc279504d4d + docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md: + id: 2bf04845b030 + last_write_checksum: sha1:40e9d3764cff78b616d2ae431dfaad666c307387 + pristine_git_object: 108bb5a1cf758064775708baf4a1f90d9afecae6 + docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md: + id: 43bb40b9c289 + last_write_checksum: sha1:db31efc3fdc8ba0ca7daacf0055e7c7f5ac0833c + pristine_git_object: 1a214cd9654af211745b836a79fe5c37f3db21f4 + docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md: + id: 0bafd7f9fee0 + last_write_checksum: sha1:a7ab2eea217af43fe3165190bc8488eb0f60e427 + pristine_git_object: b1cdc8bdc3308b489bf6cfe97035e1aa0efa9a81 + docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md: + id: b63a4e7daef0 + last_write_checksum: sha1:35ee514bfb0c76253a2630132250434d686cb647 + pristine_git_object: dda289691ec9ef2ad19e10b228eeaf18f0217676 + docs/pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md: + id: f121fc6b3ca5 + last_write_checksum: sha1:ca443e83173343385abbea8ea88124d51bf16c46 + pristine_git_object: 0492f763cdb3856abe7214d98aa1eff81777a7bd + docs/pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md: + id: ef182a772e9c + last_write_checksum: sha1:fdbd45ad6dd85db7c427092e70890ff9a7bc8b69 + pristine_git_object: 1e0f700e6beb02f133f3ede2130daa151f9c58ef + docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md: + id: a3437d45971a + last_write_checksum: sha1:e0fce898fd4b1f31b1120ecd21e0f820b60ce330 + pristine_git_object: 733661a54f6a21693cae9b72db94e2fba244c4e5 + docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md: + id: 6444c28879bd + last_write_checksum: sha1:b2ed3906ad9803c9a4521156e457f6375de9bd51 + pristine_git_object: df485c06c70f196ee2a5ac6a3e3720b8f194f73b + docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md: + id: c23c548d4ce9 + last_write_checksum: sha1:212a5fbaa875c7b167156544e0447d5cd815dd48 + pristine_git_object: 42af669a9a64046c8f2380ec9c80dd26e8707c3f + docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md: + id: 8948ec80c059 + last_write_checksum: sha1:3ce468b6cea9bd57120eab928245fb8eeb4b69a6 + pristine_git_object: 01902d16243bf27784565aa34a4b978c4ba88fab + docs/pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md: + id: 068957b4bedc + last_write_checksum: sha1:df4300c8e49c3b767b83250247168ab0d2b17edf + pristine_git_object: 874d45c32bd47f7ac08e493a3001626b74cb2d14 + docs/pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md: + id: 8c6f60f588ed + last_write_checksum: sha1:f9965d3eb4244226b7d414a252303d451ac98ed1 + pristine_git_object: a3d2bbcd207ad133019abf525009d542097a6805 + docs/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md: + id: a1d9a927e861 + last_write_checksum: sha1:c112a25d34d6e8a2a9f2008f6dde62ee1079daac + pristine_git_object: b7397e9a52d4005fb60936a6b761078b59197d4f + docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md: + id: f876d68a84a4 + last_write_checksum: sha1:a52402e4ba59c4c3a1e912fbd1364a9d37b09cb1 + pristine_git_object: 454df2eb5c0dd088e913253a95e186adc164fbd5 + docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md: + id: d42a9f9885f4 + last_write_checksum: sha1:e90fcefea4633db70485c9862365fcfa95a084dd + pristine_git_object: 597699caefa9ea00da590c3900f85f6270cc3956 + docs/pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md: + id: e9d685462294 + last_write_checksum: sha1:d74bbf77b4abb5d19caa6785884ca13c14e96430 + pristine_git_object: 5b9edb578d6fa440880e495efaa8861f35807067 + docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md: + id: b0226da470a8 + last_write_checksum: sha1:7b7ea3e8dcbb47081e244364bd5fac19f016170e + pristine_git_object: eedd4c7a3f907037c792c961b158420089c60965 + docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md: + id: cf648729ba20 + last_write_checksum: sha1:c2c1773d14e19987ccbed2c7ef17dcb03a2ae970 + pristine_git_object: 7db2ce735d2e64d2aa45ced577c2ca4e748f3f80 + docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md: + id: 8eac470c888b + last_write_checksum: sha1:a38b3f19f87a8f13d3597ca5a0389d72805ae663 + pristine_git_object: c7a386fce5709bb672019bb3801362a169abc2a6 + docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md: + id: 024559a90120 + last_write_checksum: sha1:2c1ed9455a5485e530be8e45f375606dba55674e + pristine_git_object: b9342a6af9cd999d552fbd9cdd85f5c9591227f0 + docs/pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md: + id: ae05d6b4348f + last_write_checksum: sha1:04bbd8f82588bfed1f3ab4095108ca37967dc5d8 + pristine_git_object: 30ef6e0ed4cc8bb3ec8082999eff1e5da924dc42 + docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md: + id: e6c087df3274 + last_write_checksum: sha1:97c327eeb589ba9b680ea01b2f0c3d899aa4b6ec + pristine_git_object: 4ea75545d84c3d7e753b4ad96e7c5d4706cb3f1c + docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md: + id: ee91606b0bd0 + last_write_checksum: sha1:62fbadbd6aabcb7693362bf7922a78c251987623 + pristine_git_object: 754db71fc44602907487751e147974b03a5dbf9c + docs/pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md: + id: adec472e2294 + last_write_checksum: sha1:81b004f9aa35b88f60db71a79367da50112b9896 + pristine_git_object: fefc643bbf82b238cc268da6456b226165f062ff docs/pkg/models/operations/c1apistepupv1stepupproviderservicecreateresponse.md: id: 07a00b1c38b2 last_write_checksum: sha1:082f8749d6e113ccdf28ca1bb4372a5707a84453 @@ -3972,6 +4584,14 @@ trackedFiles: id: a379d6438e76 last_write_checksum: sha1:dafd54676762b9223a58ce2ccd75716249da45b7 pristine_git_object: 36311ad14089f917199d01db4fc3afacbb0d4788 + docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md: + id: 76911622bf64 + last_write_checksum: sha1:7b6339874baccc911b7e76b3d591eb4997b9c9e8 + pristine_git_object: 97ff808b583704197af68f11b115764716d761ae + docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md: + id: 05db24542058 + last_write_checksum: sha1:0cbd19b8c43a8056b9db0e7df9bc701cf616c7b8 + pristine_git_object: 08dea2fc624513795d308bf5f188b3dfea13db03 docs/pkg/models/operations/c1apitaskv1taskactionsserviceskipsteprequest.md: id: d3370fe3c5b1 last_write_checksum: sha1:3e9879a5c3d0a7095374fb6b612f9993518ca70c @@ -4310,8 +4930,28 @@ trackedFiles: pristine_git_object: 6cfc6abd949c3e95c6d263c8f979a5d4b06e25d6 docs/pkg/models/shared/a2uicomponent.md: id: a57ab3175799 - last_write_checksum: sha1:660b1c3af7b641f8b73fcd70260cdffa881bb863 - pristine_git_object: 31aa2eed2c8f60295f81d6d0712aef1398b6881c + last_write_checksum: sha1:266a773d3e6c6340ee306b8abccbdd655c5647e2 + pristine_git_object: 06c885e43e39e7be9c237f503e6ae4d97445ca2a + docs/pkg/models/shared/a2uiprovenanceobject.md: + id: 6a0ee9baef15 + last_write_checksum: sha1:38fbd9e1e5ace689db13d83158456a666bb5ef82 + pristine_git_object: 6b28257cd9f3edb5d8527190411422e0d6347fb3 + docs/pkg/models/shared/a2uiprovenancesource.md: + id: a859c78a49bb + last_write_checksum: sha1:bfcc3261a2dccc2aac3934bd8a47e8bac081530b + pristine_git_object: 37ca45bdd085878846a74317f366a5d635086c19 + docs/pkg/models/shared/a2uiprovenancestep.md: + id: ecb34fb44be9 + last_write_checksum: sha1:bf73f0041abc4e03dcdd4ee222120271bd4061ff + pristine_git_object: 534c53b0c6933fc7951f637666cd445fb9659de0 + docs/pkg/models/shared/a2uiprovenancesteprecordtype.md: + id: 09671d2cd383 + last_write_checksum: sha1:aa7b3d4068fb0aaaf6d6a42d01466c7b55161ccf + pristine_git_object: 322c2112f43d08e8352369e1a37c59207d076806 + docs/pkg/models/shared/a2uiprovenancetoolcall.md: + id: 3d19208cc206 + last_write_checksum: sha1:39801df526938693e8da9236f9820361f4ecb998 + pristine_git_object: 3c18e5762494543efae07783d6bf822e1c7e5467 docs/pkg/models/shared/a2uiservicecreatesurfacefeedbackrequest.md: id: 672e004e13bb last_write_checksum: sha1:6acd6566b878828bee424598883a6bf8c38addd3 @@ -4320,6 +4960,10 @@ trackedFiles: id: 0c81bf2b5778 last_write_checksum: sha1:f400b0500d577c9e1a29bcc414774eeff69c07ae pristine_git_object: acc6e978be3cd416ad86228746bfc013c9b84dab + docs/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md: + id: a4716b26fb94 + last_write_checksum: sha1:57ca90d3f524de89f9e4087e61782138ebe6f6f0 + pristine_git_object: 6ef3fe5b2abe27cd631dd7274300b6215e514672 docs/pkg/models/shared/a2uiservicelistsurfacefeedbackresponse.md: id: 3aa34eea8d1e last_write_checksum: sha1:7effa7ed20353344a37fb95cc71ea716fe312a19 @@ -4396,10 +5040,18 @@ trackedFiles: id: bda0e23bdc0f last_write_checksum: sha1:2e45fb5e7831e1df8b09fd7aeafc92cb1b68bd0e pristine_git_object: 3c46ebab78f40bbb87bd01c44522d7fbc5680606 + docs/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md: + id: 13f69542554e + last_write_checksum: sha1:8c762b7e91e76d334f90fca1b62bf1d1f04e26a8 + pristine_git_object: 7cc0b5de5179ce0a6e5dc6dfda9a31302cbeee7a + docs/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md: + id: 97b36481f347 + last_write_checksum: sha1:8508f0f1f1e0ebb6d01fac1469dbdc5cd2e524ec + pristine_git_object: 5bfd3978f02621ae6bf83db9db6b815e60e68143 docs/pkg/models/shared/accessreviewcolumnconfig.md: id: 1d01e64359dc - last_write_checksum: sha1:0b4f92a093849628e338e142b643c28f88d3befe - pristine_git_object: 94b0aab5a1f7bbbbb4f8e50e30a9173c4a6d1e64 + last_write_checksum: sha1:68cf0acd66fdd09a0a3b5371347a1616455c1f1d + pristine_git_object: fef93cd980bd9899be61724e3502e9a8ac1ef2eb docs/pkg/models/shared/accessreviewexclusionscope.md: id: 0b363daac4fa last_write_checksum: sha1:a59239b3f7319a3877697fdef782a9bfa3742e90 @@ -4424,6 +5076,30 @@ trackedFiles: id: 17b20b669e32 last_write_checksum: sha1:20314f5fde4bbb791cd12d5ff348fbfae01b3ae2 pristine_git_object: 2f99664336297ba4faf23dd57fdf437d7517b00d + docs/pkg/models/shared/accessreviewreport.md: + id: 65d5a9cb7574 + last_write_checksum: sha1:c7099debb0f4b29645672ce1378803d89ad85f20 + pristine_git_object: 7d793b103bd3739a2586f659e3454267757c30fa + docs/pkg/models/shared/accessreviewreportcolumnconfig.md: + id: afc660fccb5d + last_write_checksum: sha1:60ad91d297886731add1ec5fbf965e4eaf8a4a9a + pristine_git_object: 47bda06b46e20c5134d19a948d01b9ab10620b0d + docs/pkg/models/shared/accessreviewreportcolumnconfigcolumns.md: + id: 170bad77fdee + last_write_checksum: sha1:1e45d6aa216b173d3367e2052a23630a09da5c90 + pristine_git_object: 99b7089036496631e573d8721001319b1b07f2c2 + docs/pkg/models/shared/accessreviewreportformat.md: + id: 81cb54339f21 + last_write_checksum: sha1:b846b17cfb8eb01bb124b411b39c85d6e58f560e + pristine_git_object: 9fc6a61ce75ec991ce02c760d8d6623e2680f7e4 + docs/pkg/models/shared/accessreviewreportservicelistresponse.md: + id: 038c397ed7b5 + last_write_checksum: sha1:6a751c2fc70f11851b259748a33cb9890d048c9c + pristine_git_object: bd2a60af288b5bbbd7d05c66f6dcf218ed3527b7 + docs/pkg/models/shared/accessreviewreportstate.md: + id: 98e220a59c10 + last_write_checksum: sha1:215f790a2c51a56da8bcc12ed22933d358961a96 + pristine_git_object: 562230f8d735fed66c49e860bb5fc2302ed3fa36 docs/pkg/models/shared/accessreviewscope.md: id: f48dcddedde5 last_write_checksum: sha1:6793ccb3fad8a0fa088301e9a9605c15b9870343 @@ -4528,10 +5204,14 @@ trackedFiles: id: 3d35858cd7a3 last_write_checksum: sha1:728a2be1f8b935860a58f8ed9ebe803c24dc867d pristine_git_object: 61cf7ee56c6703748559e29d5e68353b146404dc + docs/pkg/models/shared/accessreviewtaskcolumnref.md: + id: 09d138405d72 + last_write_checksum: sha1:99237c6e74c5e563d559b303c7686da8afe4fe0b + pristine_git_object: f81a006b1e6fd415c9c5fbcc9f9a7619a9021233 docs/pkg/models/shared/accessreviewtemplate.md: id: f15e6ff936c7 - last_write_checksum: sha1:e8e9079768689e79711f73c5cfeefad87b520ffe - pristine_git_object: 0f5bd5fe82a5e717720dd743fa00163d4cf8f61e + last_write_checksum: sha1:1e8c8b0c2e0710a8f0fba9cef29cb066110084f5 + pristine_git_object: 611f745eaa7d7cdca1b619e70fbaeb906406f821 docs/pkg/models/shared/accessreviewtemplateaccuracyissueaction.md: id: fc055448c440 last_write_checksum: sha1:fd3ec8ee357fcfb3a7b54b2c3d6b4cfc41333ec4 @@ -4546,8 +5226,8 @@ trackedFiles: pristine_git_object: c54d81d6e7d7a6206b89983c06d199cb5eb2679e docs/pkg/models/shared/accessreviewtemplateinput.md: id: 89a8e908dd89 - last_write_checksum: sha1:8ab7bef7357bc3fb2f00b12ef2d0daf42f5521cc - pristine_git_object: f31d24055f8e3c7b93fe2aab1d33f2cfd58a2e6c + last_write_checksum: sha1:a224736c5273bb54a0ae2d325b05201cf09169f5 + pristine_git_object: 0781fd9d774e5e579c626b8592b059562c08d3a9 docs/pkg/models/shared/accessreviewtemplatescopetype.md: id: 1b2056c07cdb last_write_checksum: sha1:dc4ea9519f3d23d7f0e6c8cb2f84a6fc7175b1a7 @@ -4672,6 +5352,10 @@ trackedFiles: id: 34efad019663 last_write_checksum: sha1:2469dec334cdb887b57fab1328aeb8a1d2bc19e7 pristine_git_object: ab5f50e3424f5fd9738369349e990d113b073cbe + docs/pkg/models/shared/accountstatuses.md: + id: 3e81b73c7986 + last_write_checksum: sha1:252c34a93ed2ed841bca949636581c9153f75028 + pristine_git_object: 2b8d48bc63b3a6442ebaafeab579a33996dc464f docs/pkg/models/shared/accounttype.md: id: 47eb42379953 last_write_checksum: sha1:c34717b7918e8d7708d4a981735264b17b75da48 @@ -4718,8 +5402,8 @@ trackedFiles: pristine_git_object: 010f10b6733798c8d183eafa659078bfde78798c docs/pkg/models/shared/actions.md: id: 737b762446f8 - last_write_checksum: sha1:16c4495b32162c5fc5e2191cde20e0b103a3a2fc - pristine_git_object: 9e0ab49e3ebb0704311f042747f28c62ae4b9883 + last_write_checksum: sha1:3f6a4cfd77a90b47a1dd39f6a738893ea5e7f2ea + pristine_git_object: e0146b4e433cf3852656e75362001921ed37a5ff docs/pkg/models/shared/actiontargetautomation.md: id: 69ceca4f4a40 last_write_checksum: sha1:4f767fe4919933596728d589351a769a570367f2 @@ -4746,8 +5430,8 @@ trackedFiles: pristine_git_object: e9482c6ea36d25974c714fb943d09dfd39c12766 docs/pkg/models/shared/actiontype.md: id: 6f8f64911c8c - last_write_checksum: sha1:a09ed3aaeb533c57c6468760b162ee36b3627ef3 - pristine_git_object: 17e7a5834d872c672f74c7e01575ccfff3bd3d0b + last_write_checksum: sha1:130b68d059e87303946c394624e0b580f8f11daa + pristine_git_object: 866a5724ccab325abe60fd23a258712c7f24eeca docs/pkg/models/shared/actorobjectpermissions.md: id: b4e90d951c16 last_write_checksum: sha1:8b6a5bcfbf59b322672ff2b7165343e2ec7a6176 @@ -4804,10 +5488,14 @@ trackedFiles: id: 72fee0e2c5e9 last_write_checksum: sha1:49c6ebf2476de2e00d193e7599628426882eef30 pristine_git_object: 8db49ecc8c345029aa35e69fa839e9011c582bb3 + docs/pkg/models/shared/agentstatus.md: + id: 043cdd451cdb + last_write_checksum: sha1:4a4e13bd2ae6a809c8115c912f1d20d24e915054 + pristine_git_object: cc7d2f28c86e20e0bb11371cfff56fb67a4e0328 docs/pkg/models/shared/agentstatuses.md: id: 24a274c5a74f - last_write_checksum: sha1:6b661b0632a00b5ba7e420301eef9e18953e875b - pristine_git_object: 6b8b7395e4fa59550860f9073f80989df94c781f + last_write_checksum: sha1:bdabd97823119c71f5d6be263d7cd684691da2d0 + pristine_git_object: 1d3231a2819296c1601f8f32983681300b491d81 docs/pkg/models/shared/agenttrait.md: id: 402653cc928b last_write_checksum: sha1:c4a61475404b1fad2f332b92244ceaeb9bc837e8 @@ -4822,8 +5510,8 @@ trackedFiles: pristine_git_object: 784705220ddb67369c2c595be4cf67c9b0fe09a5 docs/pkg/models/shared/aigovernancesettings.md: id: 583c4bc74802 - last_write_checksum: sha1:c914d8c5472c0f6500dcc7296db21ba57df5bf3b - pristine_git_object: 9000130526226b0d269fa436d1eb14f6e7a95499 + last_write_checksum: sha1:ba7ce4d19209aa5c2018bf4d61ce2be0dee01332 + pristine_git_object: 78157687f3acecce4f5d646095bff12480118a3c docs/pkg/models/shared/aigovernancesettingshistoryentry.md: id: dd5f9587a538 last_write_checksum: sha1:b353c5d3908b44aec4d0a7772413795845c1113d @@ -4882,8 +5570,8 @@ trackedFiles: pristine_git_object: be5b526cd51abd08de630c497fe7ab4c687e06a6 docs/pkg/models/shared/app.md: id: 626ffb401888 - last_write_checksum: sha1:5125607a894abee568bf4ad7bc78b882ffe51edb - pristine_git_object: 4d2b3ce80a2e17ab0be105495d5090f38597aa8f + last_write_checksum: sha1:b392c8a8ae612e40276d7d23fd4ce1d47ac9b24a + pristine_git_object: 2f4abd70facfbb5a6b03186cd6df3dd66b2d7b94 docs/pkg/models/shared/appaccessrequestdefaults.md: id: da37c620d123 last_write_checksum: sha1:adeaf0740fba073adf61d1de10fd2ff05fb76fa6 @@ -4904,6 +5592,58 @@ trackedFiles: id: 2e558bac33c4 last_write_checksum: sha1:5497180c0031c18bb8b4f793f32a479c2e55e7e8 pristine_git_object: 0cd03fba26474bc7a03597dcfe6c04a3c781821b + docs/pkg/models/shared/appcap.md: + id: 41ad2e5bccf0 + last_write_checksum: sha1:38a58d49801bf0eb91f837fdc966edd1ba7d8721 + pristine_git_object: 9a9b3eb352ba7a4b8605d005d0161e9f4c8b7daa + docs/pkg/models/shared/appcaphistoryentry.md: + id: e63227225785 + last_write_checksum: sha1:bde3a856e90f8be31d809172197960207dfd12e9 + pristine_git_object: 38ddaf03b832114f231199012cb2a125fc28d632 + docs/pkg/models/shared/appcapservicedeleterequest.md: + id: 1102ad606667 + last_write_checksum: sha1:61f8d1b1455d419f1637b1acd6e59c50d0467a77 + pristine_git_object: 02dbf0546aec8cd66953ebd31ab19d0ca747d04c + docs/pkg/models/shared/appcapservicedeleteresponse.md: + id: 9dea93a63847 + last_write_checksum: sha1:747704bfc1baae0ea5f5f3ee08d34a3a3f4ef991 + pristine_git_object: 2302784740940f34f4213887094c364c02736ff7 + docs/pkg/models/shared/appcapservicegetresponse.md: + id: ccf1ce8fa73f + last_write_checksum: sha1:98c1c59f2152ebbde453e10bd0c6bc5122c40206 + pristine_git_object: a4572ca92a8a64a20e358b4b36ef5fb7a1ed53b3 + docs/pkg/models/shared/appcapservicelisthistoryresponse.md: + id: 2fec6224976e + last_write_checksum: sha1:c1e8b1e10d936acc1170912a800221f924fcadfd + pristine_git_object: ae2a7ac14c2353680b8e5e389b6bbe951fa314a7 + docs/pkg/models/shared/appcapservicelistresponse.md: + id: e3326d85c349 + last_write_checksum: sha1:8588dd9e4ec1d58edc078f8a3554bac37fb4ac2b + pristine_git_object: 6cb758789bbab026944dfda12e9b6d3e788591ba + docs/pkg/models/shared/appcapservicesetlimitrequest.md: + id: 4c07ad0f9996 + last_write_checksum: sha1:792f11ec347223109b745931d060cbd0e0439116 + pristine_git_object: 2cefeffc84b35ecd263586543dbb07d814391893 + docs/pkg/models/shared/appcapservicesetlimitresponse.md: + id: a829889372f4 + last_write_checksum: sha1:23bf98112f648027350758a8aa0897648791d318 + pristine_git_object: 9803e7d83a11386800b289d9f1ed67a8eed68571 + docs/pkg/models/shared/appcapservicesuspendrequest.md: + id: 3efe2317398b + last_write_checksum: sha1:63873987207fa4948b9b5a43c5fd8ddf8a9f9017 + pristine_git_object: 21bc2284827d9ee9c48008fe6a1eecfd6f1d41ed + docs/pkg/models/shared/appcapservicesuspendresponse.md: + id: d8134b55814b + last_write_checksum: sha1:ad3f2dfdb956fb9373c35614a6f2b0daae171433 + pristine_git_object: b8234f329d87b875e44cc144eedb358d05cb184c + docs/pkg/models/shared/appcapserviceunsuspendrequest.md: + id: 6aa7f3432bc7 + last_write_checksum: sha1:c48bcc3870e894550a66d1fa041b70c80245da37 + pristine_git_object: 4ceaf22c1963571950bb6311507568d6d834bedc + docs/pkg/models/shared/appcapserviceunsuspendresponse.md: + id: d441bf3a5d36 + last_write_checksum: sha1:7c2cc4e61438bf2157d13157d74cdd55597e4d3c + pristine_git_object: 57fec8facd43c40a1046de799eaa9fe9726f5f0c docs/pkg/models/shared/appentitlement.md: id: de7b1cd8581b last_write_checksum: sha1:f7e8b0788a3a70e0043b6efb11f1bcaa19d3e65f @@ -5028,6 +5768,14 @@ trackedFiles: id: c6d24f23ff5d last_write_checksum: sha1:cbc5c06141b6070c00417d5c9e3eb58339f971fe pristine_git_object: e9c5b0ff3e939ad785cc71b5437e6e0ed076728c + docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md: + id: 9721b5ee8a87 + last_write_checksum: sha1:a0e87a6d3065cae64d01c54c03ef1fdfbaa2075d + pristine_git_object: 1c590323ab6f7f1b22b17cbcaebf10d094f86080 + docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md: + id: 5a82ffb06a19 + last_write_checksum: sha1:80b6706e2dca68d5b327cc61fd213a479b755511 + pristine_git_object: 724c8183a58fb18219aef5e35c818637c6dfc9a3 docs/pkg/models/shared/appentitlementsearchservicesearchrequest.md: id: f57324ab1365 last_write_checksum: sha1:b3a1a33f31781e87b788f4ada931832b2db4c092 @@ -5070,8 +5818,8 @@ trackedFiles: pristine_git_object: 5f01d3bedc487cc8e226849db969a162eb2916cb docs/pkg/models/shared/appentitlementuserbindinghistory.md: id: 7d5fd9b958d5 - last_write_checksum: sha1:41891a5ae98e9bf60f335673d58c8aa80b5215d5 - pristine_git_object: 01456325f5f7b0910a562fc0a7408bb830c481ec + last_write_checksum: sha1:404769712d3daa4e8d6f0cff70453665d17cea61 + pristine_git_object: 0817597b59b21321f0b620d1928b84c89c20c397 docs/pkg/models/shared/appentitlementuserbindinghistoryview.md: id: 17e98dd3baf5 last_write_checksum: sha1:87c315eeb09bf7dd8e1067ec470397933648d0e5 @@ -5102,16 +5850,44 @@ trackedFiles: pristine_git_object: 7b8fb2ee3d9072cd46cd6c431f07abdba217deb4 docs/pkg/models/shared/appinput.md: id: 98fb63d4c3c3 - last_write_checksum: sha1:5372f390573bb0cd0dce6e68c7774444182962d6 - pristine_git_object: 7225d9aa5b5b62c0eb2aff9e7f6e583832025a24 + last_write_checksum: sha1:43f9ace29942b52af0bf15a7cceed266112282c7 + pristine_git_object: d882a2b022fb015e9fa5f39c931fb1207655949b docs/pkg/models/shared/applicationaccessscope.md: id: 3890299275ea last_write_checksum: sha1:471f39bcd77dd769830ef423382335830c433f5a pristine_git_object: d70eae1afeb86d7e98579b493fc6ddda88164e9c + docs/pkg/models/shared/appmanagedstate.md: + id: d6899b6b93c3 + last_write_checksum: sha1:57efa0d4d702c57cf3fdd3acf5075fe2599e9fda + pristine_git_object: 8f024057d14c246a327fa1968f400dea65282c3d + docs/pkg/models/shared/appmanagedstatebinding.md: + id: 95b91a62684c + last_write_checksum: sha1:8a0527f5adfd90b0b257716d740c6fd3941578ce + pristine_git_object: 7c300096d0250388c98c27091b04836a721822b4 + docs/pkg/models/shared/appmanagedstatebindingexpandmask.md: + id: acd6666ba542 + last_write_checksum: sha1:da61e376d59a0ec07d3058d4bc12e10b654dbd22 + pristine_git_object: ffc2b71f8cf6d3d32d1e9e42c553e6fa3fe2007c docs/pkg/models/shared/appmanagedstatebindingref.md: id: 013ba1556394 - last_write_checksum: sha1:8e3474ba48d65ff8bdf3fc1fe5640473e68e56d9 - pristine_git_object: 8f78f8f62255fcf292bd976950cf865aed2a6482 + last_write_checksum: sha1:42dbb1e874062c5ce3fe44c3fab96db7b61793e1 + pristine_git_object: 72ee1cbd035bf12de64295c473b9417623dfe539 + docs/pkg/models/shared/appmanagedstatebindingview.md: + id: 790272b643e4 + last_write_checksum: sha1:f903943f4843cc7157401eb0852a372292ded639 + pristine_git_object: 3162a26d3f9fb1f4d8d2a694490d488f736e42a6 + docs/pkg/models/shared/appmanagedstatemanaged.md: + id: 4482262e34db + last_write_checksum: sha1:c90d2490968dcb3c94062d827c09eb6ce3d93e32 + pristine_git_object: ed13525315b71ef0e1f7f0a0c071394a60d4f31e + docs/pkg/models/shared/appmanagedstateunmanaged.md: + id: e801261b6efa + last_write_checksum: sha1:6f2ac961ecfafd9cbd3cc2e654406b37a040ef34 + pristine_git_object: b040f9eccf80b002b9cb26de4e884ab024b531cb + docs/pkg/models/shared/appmatchbatonref.md: + id: 7c18a6988e33 + last_write_checksum: sha1:286721d1594231f94bf8ee131c3d5b2229918a6b + pristine_git_object: b4ae3f24517a201663974bae6a8e17eba0b11e76 docs/pkg/models/shared/appownerapproval.md: id: 88623041e417 last_write_checksum: sha1:a53aacc512fa3cfb89bcf582271d643675c9c197 @@ -5270,8 +6046,8 @@ trackedFiles: pristine_git_object: 98de96b6ee388bbc2529c9e478cb3e44eb0d3a8e docs/pkg/models/shared/appuser.md: id: d2ca6de2dfe9 - last_write_checksum: sha1:a2a778989ea4449ff4e6dd0c71a881b69c7dd818 - pristine_git_object: 6adf001e56842b3b6401ffefd0e1e120b71d1202 + last_write_checksum: sha1:a80fda0abe91cca9017bc9445b494c76bfc6d773 + pristine_git_object: b6e17e3726803414d2fc569a1bfd0fb062f5c5cf docs/pkg/models/shared/appusercreatedtrigger.md: id: fa83289244f5 last_write_checksum: sha1:68f6e4be66c65bb81380af8f1816b0c300664801 @@ -5312,6 +6088,10 @@ trackedFiles: id: 16c7d5e36822 last_write_checksum: sha1:151e18b0d153b27c346e23be523210005f9f4dd5 pristine_git_object: 48adf75932dc5fb4014f821c989d6626eefa20bb + docs/pkg/models/shared/appusernhitype.md: + id: fffaac552e17 + last_write_checksum: sha1:9de84c2ee912ea448f33ab968a1117cd634cac1f + pristine_git_object: 0d86a7b17bc535b89523afebf51bc570ac77947d docs/pkg/models/shared/appuserownerentitlement.md: id: 322362d3ef49 last_write_checksum: sha1:d2740f5afc4b7546a1609625405d2bc9a7a27f0c @@ -5338,8 +6118,8 @@ trackedFiles: pristine_git_object: 709b1ee04f3f366017af943f4b4bf47ec18498e2 docs/pkg/models/shared/appuserservicesearchrequest.md: id: ff2652f510ab - last_write_checksum: sha1:e51e61ab310f4b22495d76df7d83474ac97d9d96 - pristine_git_object: 489c560638e8d19257d82743ad4263c1f8815de1 + last_write_checksum: sha1:b998ba9070e1de3a4ca6cde4ec83721f0dbedb6a + pristine_git_object: ddbc232dcc4e9796a53b0d729a21dcba0086524d docs/pkg/models/shared/appuserservicesearchrequestappuserstatuses.md: id: 66652d6e5503 last_write_checksum: sha1:8366435784371cbadc23ade80a44747c7e9d1afa @@ -5584,6 +6364,14 @@ trackedFiles: id: 59df1ae37f0e last_write_checksum: sha1:6444e2c058af184bde4d88854996037503ca480e pristine_git_object: 7e2785678f3d04857e414a61a7ea8eebb6b4a0ec + docs/pkg/models/shared/blockoutputconfig.md: + id: bbb5ce10de0d + last_write_checksum: sha1:7a90791edd605969c2ad91e154e04d0350e31600 + pristine_git_object: d246c4c471767ebfafad9167b8cc4518ccf703bc + docs/pkg/models/shared/blocktoolcallconfig.md: + id: 143f37bd6486 + last_write_checksum: sha1:7795423b9dc2308fdcbfa517438408419f37756f + pristine_git_object: 7a30a88d961901af8cf624058314a0ef9f804751 docs/pkg/models/shared/body.md: id: c06bca44ea4b last_write_checksum: sha1:9485dfa010b4cd4062a4c83715c0d46e1592fbf5 @@ -5596,10 +6384,14 @@ trackedFiles: id: 50b21ad8e843 last_write_checksum: sha1:be98deeece207ac07735f6551e3f615073252b74 pristine_git_object: c213e5bd5dbd089c4c3f5ac69fd3aebfd09ee6c6 + docs/pkg/models/shared/builtin.md: + id: 4132ba3a7a9b + last_write_checksum: sha1:ad0ad44099cedc0bfebbae16da730909bc3290ef + pristine_git_object: 74d38bc0f8c41398cd6dbf962ba89935070985fd docs/pkg/models/shared/builtinpattern.md: id: f829667efa85 - last_write_checksum: sha1:786cee7c55a0d8fcca7d98f3aa707cee3aad0a99 - pristine_git_object: dd4ac39ec19f0af72c3a35b174f9b967b435722d + last_write_checksum: sha1:3f26144678a3ff058c6967f0234d8b5eb34a1035 + pristine_git_object: 0d3ad50c90b921a3f5a52bf388cb207ba87fb87c docs/pkg/models/shared/bulkacceptriskaction.md: id: b09169afda68 last_write_checksum: sha1:16c97200db4e8deb4f4e3a637d72f0717250077f @@ -5620,6 +6412,10 @@ trackedFiles: id: 3649202b7444 last_write_checksum: sha1:577ef2ac1b8265d2c68d25394c07afbd904c1a38 pristine_git_object: 75c752d1469cf891cde4fd2b8aab37995b9bc2f1 + docs/pkg/models/shared/bulkreprocessaction.md: + id: 36ef8ffa7e4d + last_write_checksum: sha1:58a336b0e30c6179c82135d9d0802cac40f369e4 + pristine_git_object: d75a25076a9d3c15f2f1e5e3a7846643609e7112 docs/pkg/models/shared/bulksnoozeaction.md: id: f958bdca6fdd last_write_checksum: sha1:76b05fbd1258e2f6fd9c4b50026ecc4b0f973569 @@ -5634,8 +6430,8 @@ trackedFiles: pristine_git_object: 29d141e44d8ef2b22f912401a5bdbdd99d796788 docs/pkg/models/shared/bulkupdatefindingstaterequest.md: id: 58a26f24a0a8 - last_write_checksum: sha1:fb0e8dcca4c95841c26aff025a607bf4873d40b7 - pristine_git_object: 05509246530aefbc7e8e01b919d7c227af860c41 + last_write_checksum: sha1:06c6ea7c1fc2c7d4fcf9f71de5e8243bc8c346df + pristine_git_object: d6c4e5c72ef0166a8341cad8c60f39a30a82edbc docs/pkg/models/shared/bulkupdatefindingstateresponse.md: id: 528b4dfea854 last_write_checksum: sha1:4618a3e882024155d471ed75f645577ae825d4e5 @@ -5748,6 +6544,14 @@ trackedFiles: id: 1d338fbd82f7 last_write_checksum: sha1:5f22229c45b8da9c84102def323498451be27f8f pristine_git_object: ea912a0890d93660f6b822ca2571852d8de3d7b8 + docs/pkg/models/shared/c1metriccard.md: + id: 5c3f01df42ce + last_write_checksum: sha1:3ba7f21d1e465353037005f34cf7f11c8f2e294d + pristine_git_object: 773b1e6161459e3bc9387be3162f9e8eb0ed8392 + docs/pkg/models/shared/c1metriccardscomponent.md: + id: 2e23b2dde95c + last_write_checksum: sha1:d4c75159063a196cdefd37be714ff99737ab8e2c + pristine_git_object: b4679281f628805ae5e62b207d69f1805a471738 docs/pkg/models/shared/c1msteamsnotificationscomponent.md: id: dae7ae437f1a last_write_checksum: sha1:111fbef40c8c083df85708f3d80f486538a3371d @@ -5780,6 +6584,14 @@ trackedFiles: id: a94667a209fa last_write_checksum: sha1:82ea7310615f59fa77b84ee43454048b4be72af4 pristine_git_object: 3ad468516ded2567fb7982ffb0333f22d65d6076 + docs/pkg/models/shared/c1tablecomponent.md: + id: f64c38f88499 + last_write_checksum: sha1:49c13511e949db34d0cd5db010f06f5c4a68e386 + pristine_git_object: 3f1281a6af8e815837daadcf32feea1dfd3282cc + docs/pkg/models/shared/c1tablerow.md: + id: b68dbc92392b + last_write_checksum: sha1:a28421ade913f81a89b136565036134b89be63e2 + pristine_git_object: dbb8301c64575b17e6ba584262d4d361d0511437 docs/pkg/models/shared/c1todoitem.md: id: 2aa03a5e4096 last_write_checksum: sha1:b1ea5a8abc9a8cca51a3a452ce19fb19c81d2b21 @@ -5790,8 +6602,8 @@ trackedFiles: pristine_git_object: 25c1d7c36b494017874ef94c999b20d799eda549 docs/pkg/models/shared/c1userfilter.md: id: e33d57bd5298 - last_write_checksum: sha1:f88dbb3c2f79ddf1c22b7ef3b9ac3fec65d4e542 - pristine_git_object: f483b3ddb21b702d9e1d7f00ff3be5963ae55510 + last_write_checksum: sha1:2b8f35c842438007b0b90a384d58b48a18b752e8 + pristine_git_object: 842d6f44b14f8bfa6595c4e1b8176520c5687d4c docs/pkg/models/shared/callfunction.md: id: 8209c148f54f last_write_checksum: sha1:e8e0497658d80d9951521a9f4b08d726784a6c68 @@ -5900,6 +6712,14 @@ trackedFiles: id: 6be1d09ae686 last_write_checksum: sha1:eb949ce5a5aeea2ba8047d3351b1380a722ee3cc pristine_git_object: 092f01d5231cfa994405bda3e599b57ea3abee7f + docs/pkg/models/shared/clearprovidercredentialrequest.md: + id: 03d82c7c9cbf + last_write_checksum: sha1:02e2f8dca0f71c372717b339818f5807a4157a62 + pristine_git_object: 6161278695d2a055abc707374b939456ec4c9e95 + docs/pkg/models/shared/clearprovidercredentialresponse.md: + id: 89821014ad00 + last_write_checksum: sha1:0d30b859a47a12e9a8c999c47bbf89f65330fdef + pristine_git_object: aa5534e82e0ece99deefdacbac2e2b6eaab47f06 docs/pkg/models/shared/clientidmetadatadocumentpolicy.md: id: 70b38c34e459 last_write_checksum: sha1:5e1a3f0d08ba2225237d1e564abf6909fc448957 @@ -5910,8 +6730,8 @@ trackedFiles: pristine_git_object: 28f62b331f81fd68fb37b552f39ba3108e1d14d5 docs/pkg/models/shared/clientidtype.md: id: 75bc56f448e5 - last_write_checksum: sha1:0d04965df5c85fb5dcea7c4a4490482d8ff8c64c - pristine_git_object: 42d9277b1e8d1e3f101ac6455d11db8beb639400 + last_write_checksum: sha1:f912fe6a6675a6b81e42bad5f02e87097c11d8ab + pristine_git_object: b51a2188234e7b4de1ab79f55185da4c71c84ee4 docs/pkg/models/shared/closeaction.md: id: 2cfb203bbcaa last_write_checksum: sha1:ce2e179fd9017a4ded605c500f10517583788112 @@ -5952,14 +6772,22 @@ trackedFiles: id: 259e49fc2e1d last_write_checksum: sha1:19a6778d944aeeac340a2a76cf97f60d81e2d23e pristine_git_object: a94f58b1b7215f8f87657efa90540594d68d9758 + docs/pkg/models/shared/component.md: + id: f1d3e7c22d5a + last_write_checksum: sha1:61bd21447fb009b2bce970a7591a24c4280d7599 + pristine_git_object: d93738511e767c78f9fb69b0be3905a94d79efe2 docs/pkg/models/shared/composite.md: id: 42c8839c7990 - last_write_checksum: sha1:758ec56adf999b737c5d2912856ee3eac0f494dd - pristine_git_object: 7a2a1fe3d5e2c9f9da5824100663a690ee3888db + last_write_checksum: sha1:0062de469cb1bba02cbc3f0d5646a28eb9bdb7f4 + pristine_git_object: 60ea550dda8956dd1224bdb2f501166c83d931c1 docs/pkg/models/shared/compositefield.md: id: 0ce40385a765 last_write_checksum: sha1:323af316b54a1d4d0442d6045a644fe454ba95f0 pristine_git_object: 311fb7902e7075e42fd3b92e4fa0bb74266d31bc + docs/pkg/models/shared/compositeformat.md: + id: 714090c16314 + last_write_checksum: sha1:ea7585739382fb6d65f63b14aae5f24288cb4009 + pristine_git_object: 39908bd400a72f1ccd71aea4b8abdbddc463940f docs/pkg/models/shared/compositekeyfield.md: id: a2cea7d889aa last_write_checksum: sha1:7c1bafded2d8b63ba5237157216b50c40cb63543 @@ -6038,12 +6866,16 @@ trackedFiles: pristine_git_object: 3531efb12a69f8a0915c28bee2e1ac6db5948274 docs/pkg/models/shared/connectoractionref.md: id: ea0213bc32c5 - last_write_checksum: sha1:9459e811b29ca0ca05a058f63987cc918484885a - pristine_git_object: 5b9448ce922d9b6c262c4ea35d0470e64e83c98b + last_write_checksum: sha1:02f9a01dc03ed2ed1e05b20543da81db60fde445 + pristine_git_object: 9467af608844e23eeb6684e39c1b6d4d18b16d82 docs/pkg/models/shared/connectoractionrefinput.md: id: 985f031ef99b last_write_checksum: sha1:b069c50b79a42bcc8ff14bf48cca39677323c024 pristine_git_object: fa0ca4584877307ff776af9eb806e9558deadd45 + docs/pkg/models/shared/connectoractionrefoperation.md: + id: 086c084c5112 + last_write_checksum: sha1:7ecc9c5cabe3aac9604d852ea243e8cd7e7cb0dc + pristine_git_object: 1346b7b5a893a370247ec092031c43e325caae8e docs/pkg/models/shared/connectoranomalydetectiondisabledtype.md: id: 2c9b214e4323 last_write_checksum: sha1:fd328c9b2175f31f35b33976f551ee9b5a2cc1d7 @@ -6086,8 +6918,8 @@ trackedFiles: pristine_git_object: d3345fa84ba6c3c89d80b2052ed93b5e17590cf9 docs/pkg/models/shared/connectorexpandmask.md: id: f42bf66d90de - last_write_checksum: sha1:b15dff9749ac412f6bd97298f619c09bb159d676 - pristine_git_object: 07850c22cdda89b3b6a87bb42fc612958d67944a + last_write_checksum: sha1:09db1a2b28b6a7becff1a8653ee76bf3e3078f0e + pristine_git_object: e48fdaedf2b04ef48422ac9f6b5a6a0cfcbd19da docs/pkg/models/shared/connectorinput.md: id: b4259a478c30 last_write_checksum: sha1:db8c5915b670021c608c39d323a2cda6fa79da9c @@ -6212,6 +7044,14 @@ trackedFiles: id: b599b7a8d164 last_write_checksum: sha1:d46f5c09746568b53bbf9a705eb98d9b8c0f7bb7 pristine_git_object: 9c04e31b8dd968707b03d7c1f08d65da1036cd2b + docs/pkg/models/shared/connectorsyncfailingevidence.md: + id: 64d08f235861 + last_write_checksum: sha1:0bdbc636d418d3223f8b61842db097882fea8d01 + pristine_git_object: 93cf4cc2e68a17af5a2ba0c84b6822edba38f532 + docs/pkg/models/shared/connectorsyncfailingtype.md: + id: 65f1bb1c18f3 + last_write_checksum: sha1:8810032432c2db0d84924621b72a6de943d2c922 + pristine_git_object: 12861ec9c5dd38a3f7cf1adfb484f1378e92c557 docs/pkg/models/shared/connectortarget.md: id: d33a08b9b559 last_write_checksum: sha1:d59664ab57cfe78a69b9cec161eab99cc2103628 @@ -6318,8 +7158,8 @@ trackedFiles: pristine_git_object: 29da4d04c75d3d70232b0f51d3e59dcc8112d46f docs/pkg/models/shared/createapprequest.md: id: a88194e0de39 - last_write_checksum: sha1:1e41bf2a91f49421d8d9750656464f07dcb0fdaa - pristine_git_object: 3ff2d326d4174b70aebb45ef55b11dfec7e70df1 + last_write_checksum: sha1:e463b7ed8a265cffed5678c484e8f7e7800fbd1e + pristine_git_object: 3f716180a7d04649a9d569755728b4baa9d8addd docs/pkg/models/shared/createapprequestidentitymatching.md: id: 65186792fa64 last_write_checksum: sha1:dfcafaf9cfd5cfeb5bc8806ba68b55a7d4da0a24 @@ -6342,8 +7182,8 @@ trackedFiles: pristine_git_object: 42c5410aa911819dfa207bbf0b08ab8f9c5dbd91 docs/pkg/models/shared/createappresponse.md: id: b316f8903364 - last_write_checksum: sha1:0239d308fecfb3a8b813b81411317927d5e8e23a - pristine_git_object: f455ab92a9d682565d8b04ea6e9cf200af201a0b + last_write_checksum: sha1:a93898a5197c01747f89a111ee7125da7eb2fa76 + pristine_git_object: b6ff921ecd0a5cab46614a10904ac0b90f491cea docs/pkg/models/shared/createappuserentitlementownerrequest.md: id: dafeb7bd605a last_write_checksum: sha1:b9768feb2d88f462915dfe554923e94c9a5bcdaa @@ -6466,8 +7306,8 @@ trackedFiles: pristine_git_object: 75bb671fcc9cbb0e55b6d558a1f4538821002d98 docs/pkg/models/shared/createpolicyrequest.md: id: 7668641e86e4 - last_write_checksum: sha1:b959943078124b3f11a609a63e9b2bb5d6c5d97a - pristine_git_object: 2c5df3e24d6ffd626a841c9ecdc509d25f8b42cf + last_write_checksum: sha1:9e93212d7891dbda87228dd2abf0b70c85bbae58 + pristine_git_object: e73796101ba123fb9f8fb211ea8d2ac6b240a359 docs/pkg/models/shared/createpolicyresponse.md: id: d5ed65d7b1b6 last_write_checksum: sha1:5dbefcfb76cfb14d2b58c55770c5136b597cbd6f @@ -6478,8 +7318,8 @@ trackedFiles: pristine_git_object: e31a4fd8b800154ddfd2dd185bb7ae3e0577dd26 docs/pkg/models/shared/createrevoketasksv2.md: id: 252c37430190 - last_write_checksum: sha1:c5a93c0611fcbed46404b670a68ab15b1c444f12 - pristine_git_object: fdebef7b4ec109c8a9781532ecd7d08c6329a7c0 + last_write_checksum: sha1:ec5e9826138dd589647b7051c6967e69809ad08a + pristine_git_object: b2d29bc2e3741e61de1781e31881ee06ff01fddd docs/pkg/models/shared/createrisklevelattributevaluerequest.md: id: ed0430ceef92 last_write_checksum: sha1:576091df1677dd044eb9c4dc74fd336ea0ddc8bd @@ -6524,6 +7364,14 @@ trackedFiles: id: 01d10ba558fb last_write_checksum: sha1:875019603fb875929dabcbd440a0a93097cdb21c pristine_git_object: 628b93b35f2e6bf01860e4595fdc7efc745e412c + docs/pkg/models/shared/credentialexpiringevidence.md: + id: da8b2994a297 + last_write_checksum: sha1:5be4ab2cbf821d13ae86455b254239b8b6334de3 + pristine_git_object: ae3affc91a59a3754c9a932621aef00fe2310f2c + docs/pkg/models/shared/credentialexpiringtype.md: + id: 3976e14c2163 + last_write_checksum: sha1:79f5e18c99b8dd3f07b6a9ad4ea8590f08fdf43f + pristine_git_object: 287c95fb23c705904192ddd31adf6dae69f7458d docs/pkg/models/shared/credentialinventorypolicy.md: id: e7ba1a4a65fb last_write_checksum: sha1:ff5b6b12542725aa8f72df0dfb3bdba81860d3c8 @@ -6580,6 +7428,14 @@ trackedFiles: id: 0f9e7d1d798f last_write_checksum: sha1:eb9e007afb74f494820a4e4f564cd74aa16c732b pristine_git_object: 1c230c0dc0ee1f5fb4d83d495774804afceda3fe + docs/pkg/models/shared/credentialpubliclyexposedevidence.md: + id: d419a32c9609 + last_write_checksum: sha1:90433963895f88e4177751885a46f82a56a0a16b + pristine_git_object: bb2d3da8948bcd9ef4a88e9a2c7577bfe8614bcc + docs/pkg/models/shared/credentialpubliclyexposedtype.md: + id: efe33063599d + last_write_checksum: sha1:be0a94d9663829d40cf97eada5d0a966fd5bcf1e + pristine_git_object: 444af7ea265679cd39699c408c66ce733b3fb64d docs/pkg/models/shared/credentialstatus.md: id: 3f72d8bdbd0e last_write_checksum: sha1:355b64ef7da9b424db52c73bed163391a2b794bb @@ -6628,6 +7484,10 @@ trackedFiles: id: 1165068156c3 last_write_checksum: sha1:dd60da98d29889be29457875643629f4f52b10a3 pristine_git_object: 9c76ad52b68c17b465328d4dfc6c23c96305a8e0 + docs/pkg/models/shared/datefield.md: + id: 65ee38937751 + last_write_checksum: sha1:eb95f5973fc0b300d72fc81e2feecd1f7859b63b + pristine_git_object: fc642787afb1fdde248cf6e7bb4f54e8a5ca2351 docs/pkg/models/shared/datetimeinputcomponent.md: id: b936d4490393 last_write_checksum: sha1:c00e85f0d4eac66e6064f017a7167b77cbf138ce @@ -6636,6 +7496,22 @@ trackedFiles: id: 1455b6eb3ca3 last_write_checksum: sha1:87362a58a2d94a36a67ee2ba8521fbe3bbbb5cf8 pristine_git_object: 0ad0f62a4d7bb51422c4aacdc384c8afe999277b + docs/pkg/models/shared/deactivatedownerdetail.md: + id: b4f4562c10d2 + last_write_checksum: sha1:8188159f113729157ef09050b26d122f68cc0e2e + pristine_git_object: ee28be3736ef56eb7b7fdcced76b2e14c52717a1 + docs/pkg/models/shared/deactivatedownerevidence.md: + id: dd9914a5b073 + last_write_checksum: sha1:0cfef3a7c6a34b8710500e4cb73edf35a194c2a7 + pristine_git_object: e0373a9e71e8dc812b3d05556c24c05aed966b92 + docs/pkg/models/shared/deactivatedownertype.md: + id: f4c05f83edb7 + last_write_checksum: sha1:dfd20a799e6cd70f7ba8022434dca27b432d6c41 + pristine_git_object: 8461af06b0041f35284c39fef79e8ff7eb96f0be + docs/pkg/models/shared/deactivatedownertypesource.md: + id: b54bbf064393 + last_write_checksum: sha1:b5c2a4ce865d25b866f9cb6c6cbbadb4ff0c77ec + pristine_git_object: 99424f98620033d88d8590d949071842b715eaac docs/pkg/models/shared/decision.md: id: bc2ee45b2475 last_write_checksum: sha1:c26b4033e8fbbea71d6813dbedff297a4f8dbd81 @@ -6672,6 +7548,14 @@ trackedFiles: id: ffc23d5b3cb0 last_write_checksum: sha1:4a870d57efef0c300a3ad521e81113e83693d870 pristine_git_object: 91bdd396b752212d75a74a1947df4ab2a7174573 + docs/pkg/models/shared/decoypubliclyexposedevidence.md: + id: 3cede8f06c84 + last_write_checksum: sha1:89c1626ffaa7ef7744956c20ea700c5794be38f1 + pristine_git_object: 878a8ea7529009bd18a4d22442ebb6d4dec92cc7 + docs/pkg/models/shared/decoypubliclyexposedtype.md: + id: 8aeb6852efdd + last_write_checksum: sha1:7b4e6b023584dd63efee14154693388feb8a6628 + pristine_git_object: b6d723898ec921f788628a2a40e6977f036bb3c0 docs/pkg/models/shared/decoysearchrequest.md: id: 51ba449e90b9 last_write_checksum: sha1:f1b255c200cb012ef442b1a32ac3764087d9a79b @@ -6752,10 +7636,18 @@ trackedFiles: id: 83e40a20b5fb last_write_checksum: sha1:0fa987272c57ca189f03b83d49136dac4f902c72 pristine_git_object: 6596edb6a92adfb8b47e91e05ac3816c0beba16a + docs/pkg/models/shared/defaultidtokensignedresponsealg.md: + id: d8c735fc364c + last_write_checksum: sha1:a9d82149cab7ea9991bfd799c42988f1e3f97cf7 + pristine_git_object: 127580e9abccdbede84a7ff4f6ce2fa8e27424fc docs/pkg/models/shared/defaultsigningalgorithm.md: id: 12c3b9c65fc7 last_write_checksum: sha1:d4026ca7ee38e8d61edb0a554a3de05f191f1883 pristine_git_object: a77220dd169f56d99905a5a0ae46d49a14906cbc + docs/pkg/models/shared/defaultsubjecttype.md: + id: a519352ede74 + last_write_checksum: sha1:dac68dc6cc25fc18676beec2968b998f2c714644 + pristine_git_object: 3ff2241caf3aafc5073b54e177b301b3d57f6872 docs/pkg/models/shared/defaulttoolclassification.md: id: b762a5714f2f last_write_checksum: sha1:7efcba9863ed5208f88b2dc398f244d05ad61b82 @@ -7044,6 +7936,10 @@ trackedFiles: id: 5d92e3769309 last_write_checksum: sha1:a421e7c52d17bf7b64e68baf7efdeebb0380b608 pristine_git_object: 0f7eae0e4493145a4b6120759cf34a46844a6835 + docs/pkg/models/shared/deltasentiment.md: + id: 282170cd740c + last_write_checksum: sha1:944e1a1d467325e8987bd490b62146940433e64c + pristine_git_object: 65d878fb115b176d7656312a370acb7f3b0c37b6 docs/pkg/models/shared/deniedaction.md: id: fb3d2fce23af last_write_checksum: sha1:8dc3dc23513675e076f3f12162e6a8959f982274 @@ -7056,6 +7952,14 @@ trackedFiles: id: 4f8ec6062e4b last_write_checksum: sha1:830b80af88ab88c7d942e5fba8e4417635c4178d pristine_git_object: d590e1470944387236138f3b82e6a084ad262642 + docs/pkg/models/shared/destination.md: + id: 8f2b3610a75f + last_write_checksum: sha1:ff96871247d2ebeaf965265f415d73f6cde30dea + pristine_git_object: ad4127acf4cf74e1a5c128650a86000cb3bdab39 + docs/pkg/models/shared/detaillevel.md: + id: de9416ab1b3a + last_write_checksum: sha1:ca2472517d898318b3e6fe401ddead3d136cb6c9 + pristine_git_object: 6edc8fe8ae12c31ea55504f11eada6276c191fdc docs/pkg/models/shared/details.md: id: 7d79e3e8bd28 last_write_checksum: sha1:69fc077f8c7798c774e1e7fff2099c7a0eff0fe9 @@ -7064,6 +7968,10 @@ trackedFiles: id: b2c79caa7b42 last_write_checksum: sha1:080b5288297e0e3874151c0ca454a3ad5b90e9f3 pristine_git_object: 7241686c87ce148ceec3973f6cc846fc65db727c + docs/pkg/models/shared/deviceplacementprovision.md: + id: 746a285efd4c + last_write_checksum: sha1:27572867646f5a462a5fa48d71b537428c2a903d + pristine_git_object: 2c4508157c53e78c62be348e1af458ccb677d086 docs/pkg/models/shared/digestpreference.md: id: 99e59621782b last_write_checksum: sha1:5dfdcaaa25fdf792a7cab1f4c8dae6d2e95e5fcb @@ -7152,10 +8060,18 @@ trackedFiles: id: eab0e26d3769 last_write_checksum: sha1:9c52556121a00129d2b4c5dd50af023f1392b91c pristine_git_object: a4eeaf72fa627c53467dd2dc788d2ca330b84424 + docs/pkg/models/shared/disabledmodules.md: + id: a7909229b1db + last_write_checksum: sha1:c58c11f2bc571cb0949143efe25a6e49ea2fdd22 + pristine_git_object: 931c59331c0dcff6c76f4907368b4d9e5a6bc5f3 docs/pkg/models/shared/disabledreasoncircuitbreaker.md: id: 57f91343460b - last_write_checksum: sha1:783a30e6579f39db287d73f2d45238587c56ef48 - pristine_git_object: 28912b43b4e505d85cfa573b1e09f8506bae41b0 + last_write_checksum: sha1:3e05c5d5ca4f2580bfbc59bc8b4acffce1717b6a + pristine_git_object: 858a35d2b5ee32bd7dff0d7cab7b497f0721a5b3 + docs/pkg/models/shared/disabledreasoncircuitbreakerperiod.md: + id: ef10c0e771e0 + last_write_checksum: sha1:6c516d81e1bf81258e78f498aa41f8ae18902e89 + pristine_git_object: c69198b12e46351977526ee91be2f56bfb5b9ca3 docs/pkg/models/shared/dividercomponent.md: id: c7c57e1af434 last_write_checksum: sha1:2e07ad2ac3a23d3fecdb8887a6f15a9196c50eb6 @@ -7218,8 +8134,8 @@ trackedFiles: pristine_git_object: f7ce5769c604183ec1f863088fdc37270c3b235c docs/pkg/models/shared/emailchannelsettings.md: id: 98c3bde6f4b9 - last_write_checksum: sha1:c1f1e53d6f7873427c5dc4ce154502519d6042dd - pristine_git_object: 03f1ff57315984de2dea23024f6bde77995338e4 + last_write_checksum: sha1:881435e1fe69a59878e84aa322b5a99f52ced27f + pristine_git_object: 6f52972d5dd5912bdcad45926cc86986d43458c2 docs/pkg/models/shared/emailnotifications.md: id: 868fe0111111 last_write_checksum: sha1:f54fff54a209425fe3621b9ec28e6785586752e5 @@ -7240,10 +8156,18 @@ trackedFiles: id: e59042ddbe38 last_write_checksum: sha1:5be49821c265997eac1e9d099320c60d41a501ff pristine_git_object: a9b773d48c90486b90c23bae2f232bd096204146 + docs/pkg/models/shared/encodedcontentguardconfig.md: + id: 9e6cf4ad60e1 + last_write_checksum: sha1:61ba1499ae57d9a75924389414afc3eaeee35c1a + pristine_git_object: 57dcea0d8540e546312270d5dece8d90d6be89fb docs/pkg/models/shared/encrypteddata.md: id: fe4948753c28 last_write_checksum: sha1:af0d30c789fbb74a0c16c79920a232524c2df693 pristine_git_object: e9e95560662d5938e57b39d24f954dae8f214308 + docs/pkg/models/shared/encryptionalgorithm.md: + id: 954a561ad49c + last_write_checksum: sha1:93534de9a937b94ce289a17f56d21a27725ceeaa + pristine_git_object: 829931771d7d060b2bfc4f246b508cf7be037f51 docs/pkg/models/shared/enrollmentbehavior.md: id: 15fd9090cba1 last_write_checksum: sha1:ce2f6013d40a8023086e1d444a58f4fedc9fa858 @@ -7252,10 +8176,22 @@ trackedFiles: id: 9d9fc2796769 last_write_checksum: sha1:de0f69a0909528aab317dd8e2f09232767b777b4 pristine_git_object: 481d1e6f30935c404cbf12b5cfeb8ae94ae90c8a + docs/pkg/models/shared/ensureonboardingsessionrequest.md: + id: 78b9ec3e48aa + last_write_checksum: sha1:a226f4a4c11a9d473fbc163dfed4473f109cb9c1 + pristine_git_object: 657993a07c16b66b80d84c47a74bbe6634c8196e + docs/pkg/models/shared/ensureonboardingsessionresponse.md: + id: 232ae5e5c1ea + last_write_checksum: sha1:f4863832338812f85e925a0c085869b5e33c0773 + pristine_git_object: 16aad91ae3d898e2e9df6484400c1f4f29bd5036 docs/pkg/models/shared/entitlementcluster.md: id: 39c42fe99a67 last_write_checksum: sha1:96d22121de29867c79fd925999ac9cd1e788fe43 pristine_git_object: 65e52dcd53aa96c1bbc2a1a1d31dfee0891e94ad + docs/pkg/models/shared/entitlementcutoffimpactpoint.md: + id: ce871c7d2e89 + last_write_checksum: sha1:7a62b77be0109cde4b1ffad85d2f299380bac312 + pristine_git_object: c48acb13427c64e8b94b0069a3446c979c37f4c6 docs/pkg/models/shared/entitlementexclusioncriteria.md: id: d16b2115590d last_write_checksum: sha1:32281c513a53cdabed621801f93784601cc201a3 @@ -7306,8 +8242,8 @@ trackedFiles: pristine_git_object: 3456dd0d74dbbb0469235d2de548a6d782d814ac docs/pkg/models/shared/entitlementref.md: id: 48fdea425a3f - last_write_checksum: sha1:b1a3f925f7cf7ca2d5065fef7f09126dbcd37303 - pristine_git_object: f13f8ce0c702c260a71cff5d0e42d524719150e0 + last_write_checksum: sha1:288658aeeb350d8c16c8509fd0ee7b8f8739ec64 + pristine_git_object: 13df5a15774e3ffce90e6d868887144c3531756c docs/pkg/models/shared/entitlementtodetails.md: id: 7c33d558a635 last_write_checksum: sha1:e8a50f631203c425540ecb09a18526eb492f9b27 @@ -7352,22 +8288,30 @@ trackedFiles: id: 0b7492051180 last_write_checksum: sha1:33d8010350e93af704c8ab2fad52070804032ffb pristine_git_object: ebcf24826b3544264805af7598fdfc91725fd0e3 + docs/pkg/models/shared/evaluateentitlementselectionrequest.md: + id: 81958dd8b9bf + last_write_checksum: sha1:2b6d06e3f1b8ed8d507f0c42d23cf089d9ffdbcc + pristine_git_object: f9226eefca421e68f2ea3c6d91103e21729ffc30 + docs/pkg/models/shared/evaluateentitlementselectionresponse.md: + id: 5a507726c3e6 + last_write_checksum: sha1:5e14f1789d590cbc0c7e8a2b3b164447d44a7938 + pristine_git_object: 512dddea4449e78df67b7548e3c57302577d0749 docs/pkg/models/shared/evaluateexpressions.md: id: fd3294a2736c - last_write_checksum: sha1:3f722249ae442e736baf361d8f041db46c811979 - pristine_git_object: fcf7d241f2ae5732c9c895ade21380211628de1a + last_write_checksum: sha1:71902d68b8ad44ceea0828e2892e9dd1ab64a75d + pristine_git_object: 552098d4d736f26c0cb3ec29644dc8fa3e19bffa docs/pkg/models/shared/event.md: id: f214e020cf1e - last_write_checksum: sha1:646425e9c2b0cfdd5cf37f4567c3d5796d051b7b - pristine_git_object: a797558c22c8cb8dafe0e5970a1a3080240defbd + last_write_checksum: sha1:c7e5ab4067c12d710f34b3bed76e45a4a037fbeb + pristine_git_object: 5eb13c6b3d8822f9773649d7c1899e0bbf73241c docs/pkg/models/shared/eventtype.md: id: f9700266a1a8 last_write_checksum: sha1:9c6cb9b3fc8d7b0d716a6f76d06f211343a20cd1 pristine_git_object: 470e4acd16d4a0feed243ca5b4b32e6f3ca0965e docs/pkg/models/shared/eventtypes.md: id: f3045f42f136 - last_write_checksum: sha1:09576fb9df237d860edf33bb5685db68553d9ffd - pristine_git_object: b0057303ee29508726040aae40a1ffe1bbadd708 + last_write_checksum: sha1:2cbc04db1407dbceb23ad4adffa16e8512009d3c + pristine_git_object: 4d772d2a1cef1ac0e6d0c389a86e50fff41c5253 docs/pkg/models/shared/excludeorigins.md: id: 07007281289c last_write_checksum: sha1:7f5a4984e515c301607c5d844cc485e673b6bfbd @@ -7478,8 +8422,8 @@ trackedFiles: pristine_git_object: 9fa30f25f5dbf437b51ee3bc8ae27c1f7ef0bcea docs/pkg/models/shared/expression.md: id: 4b45b4902e4d - last_write_checksum: sha1:5cc376620780c61f9cf85aa23a41c3f89d112c8f - pristine_git_object: cad5f8e010a5bfa972e0312d982713f8a5530803 + last_write_checksum: sha1:f0faa52c60bd101f066c6cc2c9121e898669e40d + pristine_git_object: 3ef384019d230483b10bf3d67cb6d1fc43b591ff docs/pkg/models/shared/expressionapproval.md: id: 716a6272c3aa last_write_checksum: sha1:89f355806279d7fbba19d7358545185d2ad1e71a @@ -7570,16 +8514,24 @@ trackedFiles: pristine_git_object: 247656f45a131994d4f5e77ca024b820261068cd docs/pkg/models/shared/finding.md: id: 0c2036e3db92 - last_write_checksum: sha1:491af47033ecf87911b83977346255110bcad57a - pristine_git_object: 0cf40132ea276393be4423b566e4bacb95d057ec + last_write_checksum: sha1:271782b08630b6740e791ec1605f1324b2503622 + pristine_git_object: 5645063619f7de1290015f3cdc61f3f99798301e + docs/pkg/models/shared/findingaudience.md: + id: 18ac232e1e23 + last_write_checksum: sha1:eb58b72fe1aaed8e3ac73bd2f1dc1be620d18d30 + pristine_git_object: 4e87f378685056ab77451d493ebc95eacd181362 + docs/pkg/models/shared/findingaudienceusers.md: + id: 4369b60ba152 + last_write_checksum: sha1:b42e0884760ca36553cf7baab04dfbf06f88d0ba + pristine_git_object: 019373f070df34e9abea759b063f88ae23d4b1c0 docs/pkg/models/shared/findingauditevent.md: id: b166df28c83b last_write_checksum: sha1:fe810a51989f4a969434336696f58bdb25e47097 pristine_git_object: 76bd02ebe75b340b1ff904b14450559143d2c262 docs/pkg/models/shared/findingauditeventeventtype.md: id: e0c1cccdbf7a - last_write_checksum: sha1:51cf87edee62da27af50b26d591391d2eb44e414 - pristine_git_object: 2f2b70a670032b635de20f37afde9da963b53751 + last_write_checksum: sha1:ac7acad7bf6d13792b15cf2538e7f01980200a71 + pristine_git_object: ab0650fa7dcac18e324ad257bd57b8b123077493 docs/pkg/models/shared/findingauditservicesearchrequest.md: id: 9d7b1212e8d1 last_write_checksum: sha1:514f4499897aadf64a5c49dd250476ea5bc32c40 @@ -7588,6 +8540,14 @@ trackedFiles: id: 6118af8cee66 last_write_checksum: sha1:f7ee040b1f9051088e43e5cf08cb9d74d07cf13b pristine_git_object: aef20ed6c95bdec3d809fd94d1751ec3fcf98081 + docs/pkg/models/shared/findingdispatcher.md: + id: ce5a242ba4a4 + last_write_checksum: sha1:322c4d6fdfdc9374415ac9efe35f8404f4618072 + pristine_git_object: 9592e9bac156edb9468b9eba035bbd040a436439 + docs/pkg/models/shared/findingdispatchoutcomenotify.md: + id: b4d79c8bf2ca + last_write_checksum: sha1:55bb9d4338cacd20802ee7312346bf089b3a18ed + pristine_git_object: b6dafe5270ab3d313ba787c93bfc33ed848be08b docs/pkg/models/shared/findingownerref.md: id: 6dc4b7d78b77 last_write_checksum: sha1:1e2fb111e2441060b855fa829120ccb3dabebf38 @@ -7610,24 +8570,36 @@ trackedFiles: pristine_git_object: 1cfa3f5c70d874427c8a5db0ddbf9a4db06a8944 docs/pkg/models/shared/findingroutingrule.md: id: fb8f991a7a9e - last_write_checksum: sha1:8b78c5e2618ab7216fb22ba85840c48a08e24a30 - pristine_git_object: 1928d51092803088153305ded3c6a236a530f0af + last_write_checksum: sha1:44bea02665700983f5399683817ba0fc84a01a74 + pristine_git_object: 3879fc91f50f1e53c28aef1b467702c1e5953ab5 docs/pkg/models/shared/findingroutingruleaction.md: id: 580d551694d7 last_write_checksum: sha1:12e7fed9580ea9b32e2b4e4f2eade3581e148499 pristine_git_object: 6521d9fe9805c19a44423ee192fe1bdba4f772c4 docs/pkg/models/shared/findingsearchrequest.md: id: 13203a3e9418 - last_write_checksum: sha1:c5d762825da7d045b805a7aeaacf1c5bf4296359 - pristine_git_object: dd920031220ad9966b3b09a4eda0246081c36ebb + last_write_checksum: sha1:f2c1c0bb231b129298514a81d4bd15d5fbe2f5aa + pristine_git_object: d92a4200b0e0342d71d008b8182ef907fd3ffac1 docs/pkg/models/shared/findingsearchrequestappusertypes.md: id: ede9e5b914c9 last_write_checksum: sha1:a14dcb0f326de5b8486646ca96d9965f79feeb69 pristine_git_object: a8215c7ab3eb759ecfa60081fade79ba6ac0a370 + docs/pkg/models/shared/findingsearchrequestnhitypes.md: + id: e4df518aa712 + last_write_checksum: sha1:ef19912f7d498c8eeb07ecfcf5e36ca2fcee666a + pristine_git_object: 8863d72ee10d0979ec3a6bad3527baa28aaa69f7 docs/pkg/models/shared/findingsearchresponse.md: id: 633d3df4c6fb last_write_checksum: sha1:544a419322db2fd64445508b404a887f375e8691 pristine_git_object: 35edeb3be234d27b203e82d45decef12f07d9882 + docs/pkg/models/shared/findingsettingsentry.md: + id: 502c1de4ebae + last_write_checksum: sha1:69768379c38f7311e8d08958094b91cb586fd8cf + pristine_git_object: f3100e4b6566553ff12d7767adb23ee124fc8d7c + docs/pkg/models/shared/findingsettingsentryfindingtype.md: + id: 367cb47fa6c2 + last_write_checksum: sha1:e6b6863110ac93b93f83ae530653b97bd1409b06 + pristine_git_object: d4fc97f485b61a461a09921e9c68e866792fef09 docs/pkg/models/shared/findingseverity.md: id: c18741613cc3 last_write_checksum: sha1:0a3660b986f84430fe65dd6fab98e461d9098019 @@ -7650,12 +8622,28 @@ trackedFiles: pristine_git_object: 6785ab2e6be0021864b1527c6a9fb3824ae53f3b docs/pkg/models/shared/findingtransformationrule.md: id: e583b3facf06 - last_write_checksum: sha1:bfad534a107b5959b8d4463ce815e57c3ff83397 - pristine_git_object: db74f4ff80e07ec9cb37f2ece2e9845f55161f3c + last_write_checksum: sha1:7053639f0fd165558face9ae794b7a8823ddce6d + pristine_git_object: 7e6d42dc3592647f41d8b0f203b0b8dd7e9d619d + docs/pkg/models/shared/findingtransformationrulefindingtype.md: + id: 2253f08b133d + last_write_checksum: sha1:b53ea0c3facd63740c3fbb60b675bf62c875377c + pristine_git_object: 4d78998f59a60f91edd5dacb4a1cf3dde4a491ab + docs/pkg/models/shared/findingtype.md: + id: 4897d4bf96f0 + last_write_checksum: sha1:ab035684fa6d96dc65c9f0cc662b4d4542890919 + pristine_git_object: 709e92437d1278a3ac8127f0a717e05ac30abbe0 docs/pkg/models/shared/findingtypes.md: id: 64ead4bf7d0a - last_write_checksum: sha1:32afc269bc1098aeb62940db1a1fde88d4a94095 - pristine_git_object: 9f777030cccd25b81823a42b55040959861c9c8b + last_write_checksum: sha1:f7eb91341fab780bdf62cde4440ae903d34ea8fe + pristine_git_object: 67d2e8ebce9d3bb4278fc94cf7f78e424b56b5bc + docs/pkg/models/shared/findingtypesetting.md: + id: 7d0d6a6fd3e5 + last_write_checksum: sha1:a6f2116d7674e386422f8da2f47a76828493de06 + pristine_git_object: 2a4766cdc341284816ba324762fb270213b4f4d1 + docs/pkg/models/shared/findingtypesettingfindingtype.md: + id: a70128161ae7 + last_write_checksum: sha1:e20cb0a8b7d12b1fccf2c5689697bbf817d7bd67 + pristine_git_object: 2cd5167df3b8f8b6634d3a306c1bd7fa8b8c8b8b docs/pkg/models/shared/fixed32rules.md: id: 694e88206798 last_write_checksum: sha1:fa2cc73e22bf73858015704c917c2e67d019f7ae @@ -7686,16 +8674,16 @@ trackedFiles: pristine_git_object: d65d3ab411ee784997552bbc52e79a594d81c4f5 docs/pkg/models/shared/forcesyncresponse.md: id: 950b7d7810cd - last_write_checksum: sha1:7b581eaa7dcf378c897f73ff4dfc38187a4a3532 - pristine_git_object: 56a9957162e01c359ba542771e9d3be52056ca1e + last_write_checksum: sha1:1234b3536f6d99e0d18a6d28288a2e60a3949224 + pristine_git_object: f4573b3e5dfd9fdf3a154322bb2664ff135c9343 docs/pkg/models/shared/form.md: id: 6667541f8d79 last_write_checksum: sha1:7d775f06651079b44af1625f93b13d54c54765e0 pristine_git_object: d74c7039ab0eaa64157d4f431f4c101455ad779f docs/pkg/models/shared/format.md: id: b6f2073b4091 - last_write_checksum: sha1:e949adbd29e170bc5395ed1bbd2ffdcda514f550 - pristine_git_object: 2813deae12170afca988e01a33566a5223d7834e + last_write_checksum: sha1:c6f0e00441ad01345f51a6b27ff9b71f5a6291b6 + pristine_git_object: e691399731871f3c5e8ffe3d4be3925e5c3d3e7b docs/pkg/models/shared/formcompletedaction.md: id: 7cb8ac01f1cd last_write_checksum: sha1:6966a97db1cd9e780cdced7c593d9b894a12090d @@ -7722,8 +8710,8 @@ trackedFiles: pristine_git_object: e73b564796fda2d3396a46639760cc3dbd5a8a98 docs/pkg/models/shared/formstringfield.md: id: 158a50f6af1d - last_write_checksum: sha1:9ec59098cd552ab0fb44b67f4d88a1e2dac9f5ed - pristine_git_object: c8248da8c2481f3e17008b726820c04eef96c513 + last_write_checksum: sha1:46a6d8477d6770b51562605bbf6634cd1bbe58f9 + pristine_git_object: 09a80517d9668605a69c9c599e12c07087e3b88f docs/pkg/models/shared/formstringmapfield.md: id: 2be62391f0d7 last_write_checksum: sha1:dbaa53d501268ff37096d7a5feda4bfce0091890 @@ -7734,8 +8722,8 @@ trackedFiles: pristine_git_object: 355ffed2dd0f1d961e28eca2afdf19e6e18e3268 docs/pkg/models/shared/function.md: id: afc8230554e2 - last_write_checksum: sha1:113ae69cc869529454a56ae82e735e57c4e4ead7 - pristine_git_object: 10b6b3dfc79c014b6ef69eb79a63c3db2a244eb6 + last_write_checksum: sha1:e6c2c8afc358eb913f992aeadd962149909567e5 + pristine_git_object: 9aa3d3f75d2c4a0c358f60b6f7d9978e0d7c769c docs/pkg/models/shared/functioncall.md: id: 9942350291ec last_write_checksum: sha1:8a4b638ace492feb142ac5ae0b6e01ca6cdeab2b @@ -7866,12 +8854,12 @@ trackedFiles: pristine_git_object: 3c22ca27e3202bccda7acebbf053215c56b7078e docs/pkg/models/shared/functionsserviceupdatefunctionrequest.md: id: 3ccfe9e3e684 - last_write_checksum: sha1:d6adc7e941609dcbcd1ed640818496bd12c7cb70 - pristine_git_object: ce2fcdea78ccd5b3eccb9011fac0765085f94770 + last_write_checksum: sha1:c967c9985b400d8e3470c4610c7a966f1e388548 + pristine_git_object: 583a8ff5fcae1d8c3f2bf5a1235286dd0d7dd34d docs/pkg/models/shared/functionsserviceupdatefunctionresponse.md: id: 369febe61215 - last_write_checksum: sha1:78be65c1eb0a5dd4757031400a175bd45ac11ef1 - pristine_git_object: c7c25598745b282b144bcea50023f119993a3d9d + last_write_checksum: sha1:b78a91e6e1f58103853fb05ca3bfafae299d3dd2 + pristine_git_object: 22440339a332b06383000062f935ed939c396ad1 docs/pkg/models/shared/functiontestresult.md: id: bf0f05b0ac49 last_write_checksum: sha1:c44be2b2439469a56df50795d37f27b5d30c89e1 @@ -7896,6 +8884,210 @@ trackedFiles: id: efebc4c1962d last_write_checksum: sha1:0e140c873b691b2fb220ef9a2d7cf2513d53c938 pristine_git_object: f2ade4428599b12f861c40fca5bca88d6377d4fd + docs/pkg/models/shared/fundassignment.md: + id: ed77e6fcaf1f + last_write_checksum: sha1:9067ca32c3b2c37f5d63f35d7356d3891b862978 + pristine_git_object: 9ef7fd4528625805f8183bc14045c8bdd7050ee1 + docs/pkg/models/shared/fundassignmenthistoryentry.md: + id: c22441aa5b7d + last_write_checksum: sha1:60362b99d3cc0d17c0aed25c3f36c0adbbc04432 + pristine_git_object: 638dbbfc20cc1095ca30e3da6d327b004f95fa1e + docs/pkg/models/shared/fundassignmentserviceclearextensionrequest.md: + id: f73ba01877f8 + last_write_checksum: sha1:28fa747775728688fa6e0f698ac9c68e8ee88ed1 + pristine_git_object: d5d573123693ff93086eb84c8246d8feebcdca25 + docs/pkg/models/shared/fundassignmentserviceclearextensionresponse.md: + id: 393e2ac5f509 + last_write_checksum: sha1:0c33c89840adad2e5040da2945ddaf241b7f7d49 + pristine_git_object: ce558d306a9ae4183ab68868cd8b6a26c8024012 + docs/pkg/models/shared/fundassignmentservicedeleterequest.md: + id: 6a3aa61139da + last_write_checksum: sha1:e07aa4cf06cec2a90f19d97753687f8513a8f1d3 + pristine_git_object: a780af739d4d2c6b5094ec041728335138e9dd74 + docs/pkg/models/shared/fundassignmentservicedeleteresponse.md: + id: fa715bf44a3a + last_write_checksum: sha1:f31adc78206a8fbc010081fc6a68aa2c9dbb4882 + pristine_git_object: 7145c8af7cd6ca1e3d91857e41b6acd8eedb4f8c + docs/pkg/models/shared/fundassignmentservicegetresponse.md: + id: d66c32084b56 + last_write_checksum: sha1:b87fa1b51e2b8251b9f613743934adb89aae5ddd + pristine_git_object: 78ab2c978c8fd178ee8f2adb4e90101e41cd0d83 + docs/pkg/models/shared/fundassignmentservicegrantextensionrequest.md: + id: 73c866260f66 + last_write_checksum: sha1:d713a769c56f167c22baa4ec16257fce7e64a3bf + pristine_git_object: ab2d050bfe566f2eff2de90c514dbf6939132eed + docs/pkg/models/shared/fundassignmentservicegrantextensionresponse.md: + id: 0003a777626c + last_write_checksum: sha1:77c38f858bb5bdadfe59b9173711f7ed1c0d240d + pristine_git_object: 7c4f84471ddbb20f53052141d8fd08ae0fb0c065 + docs/pkg/models/shared/fundassignmentservicelisthistoryresponse.md: + id: 4402771ec9a1 + last_write_checksum: sha1:de592e4d212d653204c69c2bd4c7c280bb615d2d + pristine_git_object: 430c6853d4c9e6bf990e4ba52aab66994acbc2d1 + docs/pkg/models/shared/fundassignmentservicesearchrequest.md: + id: dac3f5e8a091 + last_write_checksum: sha1:c1e552adbf74674cb4e79995025f3dd28a6ddde8 + pristine_git_object: dab4ed1c29b2a795f9bce3b6d3f837032edf245a + docs/pkg/models/shared/fundassignmentservicesearchresponse.md: + id: 8bd940109792 + last_write_checksum: sha1:100d83d3724e6bd95c160f1a28529a648beef7a7 + pristine_git_object: 2cade0554fbb2c2aa98f1a7880a8f4c2a5a4ca98 + docs/pkg/models/shared/fundassignmentservicesetlimitrequest.md: + id: 92a89aec9737 + last_write_checksum: sha1:2c7e6c0db10692f8fa5f2cb6ba4f2f59e19a2548 + pristine_git_object: 709d0c6aa83422f14856e6d9f62e1cf513d7af31 + docs/pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md: + id: 8c6d83dbae11 + last_write_checksum: sha1:b3ee6191a3993b4e79889aa443a9170e4820ad4f + pristine_git_object: f1e5f7fac17981cf1109a69f478045a62842a6be + docs/pkg/models/shared/fundassignmentservicesetlimitresponse.md: + id: 276dc5398da4 + last_write_checksum: sha1:cdca8a11076d5d722e7871d9eb849a33393bd47b + pristine_git_object: ed36dfe538c9c945df56091d454520ab639b7ae7 + docs/pkg/models/shared/fundassignmentservicesuspendrequest.md: + id: ab0324199e5f + last_write_checksum: sha1:525f3667e9ca6513afc970b8ea29748eeddcbfaa + pristine_git_object: 2433961ca317be4c7461ee0f27a7bad3f52d3f66 + docs/pkg/models/shared/fundassignmentservicesuspendresponse.md: + id: 3f1603515515 + last_write_checksum: sha1:89e991a8d8e6653d28588c012e3e9f5b0e3c5e43 + pristine_git_object: 6ec18861f300394ff842065c22424a32ba4dc01d + docs/pkg/models/shared/fundassignmentserviceunsuspendrequest.md: + id: 65a623565390 + last_write_checksum: sha1:17b241e337bc9f51e0055230386b4bf56a222522 + pristine_git_object: 9ca1ca7f3dbbb1c2e01de10b5218a717a8935555 + docs/pkg/models/shared/fundassignmentserviceunsuspendresponse.md: + id: 7d0708d93a21 + last_write_checksum: sha1:2b2f7fbc3a731b16fecf09ed4f15b2519605060e + pristine_git_object: bf73c8d0fb8b8ace1b4d7e6462b14c502579ae01 + docs/pkg/models/shared/fundpolicy.md: + id: e87e7cd53236 + last_write_checksum: sha1:9f943e7e204b7fe3e36a3c030de94d5872627ed6 + pristine_git_object: 775392ffe2a2acc55970c98ac1a4d1ec45a0a43e + docs/pkg/models/shared/fundpolicyhistoryentry.md: + id: 68bc7ba5a49b + last_write_checksum: sha1:c5dd824297afe82652fb4f6a693eecfaf6ab68da + pristine_git_object: 2d4360c6b3fba9e44718480c28e240b1967e5f6b + docs/pkg/models/shared/fundpolicyperiod.md: + id: bf0dfe420b09 + last_write_checksum: sha1:95e38f72afd3ad2999b45835310d1cdd340de8f0 + pristine_git_object: 40e63966f94742bc9db3c768a696943ffcb74188 + docs/pkg/models/shared/fundpolicyservicecreaterequest.md: + id: 0a07d83c47d1 + last_write_checksum: sha1:fb10f9ccead1ae350ccd143f8af25d47f1ad380c + pristine_git_object: f3cb1deb04067a6d1db07a94ec011585830a088d + docs/pkg/models/shared/fundpolicyservicecreaterequestperiod.md: + id: 2eab8f0cab4b + last_write_checksum: sha1:634cf02687caa0ea521d28ecf4339c3ca6b72d03 + pristine_git_object: 9c03c837b7dec503d4f65accd2d6064ba89f49ef + docs/pkg/models/shared/fundpolicyservicecreateresponse.md: + id: 426c02dd8b12 + last_write_checksum: sha1:82a3d7a119acb8bfcfd893544cf0c520b19b5cbd + pristine_git_object: 7da0b61078cb40dabf95badc2cb5428e81d96d21 + docs/pkg/models/shared/fundpolicyservicedeleterequest.md: + id: 4707cc8368c6 + last_write_checksum: sha1:9f987442f5f3bf0fdfddb76b87e0f2ad0c56f232 + pristine_git_object: 5f3c7cb0a6cfa3efeb9c07869b9c9bc444383b03 + docs/pkg/models/shared/fundpolicyservicedeleteresponse.md: + id: 4ca40f164624 + last_write_checksum: sha1:bcf08a5b0c7c22200cb1d646e5f101f41bf5acd4 + pristine_git_object: 78df7b10599ca8a62be2f831b88a8da57f3dd5a8 + docs/pkg/models/shared/fundpolicyservicefreezetenantrequest.md: + id: 6159cbacd1bb + last_write_checksum: sha1:36f13970c9433601c85d14006136e698506158b8 + pristine_git_object: 1d729bb6602fe5c831e0fe4ea0f1227f3db75c72 + docs/pkg/models/shared/fundpolicyservicefreezetenantresponse.md: + id: ca9d8588a22a + last_write_checksum: sha1:f1e210dea7b1e39b66311d4957ccb8a9cc8ee1dd + pristine_git_object: 917ffb4b7e24a00dec69b08ab3f57a8f275338a9 + docs/pkg/models/shared/fundpolicyservicegetresponse.md: + id: bdaeec8f55a4 + last_write_checksum: sha1:e018aeb25c9e3fa77bd13aaaf9c2a6683a1b8665 + pristine_git_object: 050f444016e33ad9f10a23c515576bd774391425 + docs/pkg/models/shared/fundpolicyservicelisthistoryresponse.md: + id: eb691ae408f8 + last_write_checksum: sha1:7df8621ad52ddb810c4c7fd6a1c9ddb8c1181aac + pristine_git_object: 559deee36e602d3f457e83b8ea6cd04cd38b936c + docs/pkg/models/shared/fundpolicyservicesetorgceilingrequest.md: + id: 32097cb02dcd + last_write_checksum: sha1:2ed995d042d15c5a8442b886b247d6f5705632b1 + pristine_git_object: a0b23faa61c2d069f7c21846c1b5b430ff49c1cf + docs/pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md: + id: f0d0f6f86f72 + last_write_checksum: sha1:80b5ea8ba1486fb14efb7a48c1be95fb40c67266 + pristine_git_object: b4c7f2e8900289f3cdac7426776c7a3ef9271f5f + docs/pkg/models/shared/fundpolicyservicesetorgceilingresponse.md: + id: 3840057a2f72 + last_write_checksum: sha1:5c4ed81feeae7f4779c9a1637f6af4c31018afb9 + pristine_git_object: 0e1faecb0b756c11dc783cd5ce439b599c67cc0f + docs/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md: + id: 1ab5ee46fd88 + last_write_checksum: sha1:5cd0b1292b0c907df856affb1a57d0862dce679f + pristine_git_object: 98195e8d6b4ff76e6d3fb13761c4f80d3969a106 + docs/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md: + id: 0eefae23b222 + last_write_checksum: sha1:f241fe69426c7f22870ff2498ddef001c129c995 + pristine_git_object: 31c399778ef1e85450d85529278b0c9cb59658b5 + docs/pkg/models/shared/fundpolicyserviceupdaterequest.md: + id: 1694e9e29810 + last_write_checksum: sha1:2090830de108e7bc2d421831e965cac5d3bd085f + pristine_git_object: c2605ea90695c7ed2f155c2d1d8146f8e881b871 + docs/pkg/models/shared/fundpolicyserviceupdateresponse.md: + id: c76db348b4f8 + last_write_checksum: sha1:5aa3533e1f4e2c2f29fd3ad16180a63bc12b8ca0 + pristine_git_object: 7b882bf430079e5682b70fa9f0d4cb3d4b8f72ce + docs/pkg/models/shared/fundrule.md: + id: 00ec83ffbe21 + last_write_checksum: sha1:1d8306f1590c34532685c31dfac16df8e1dc5d55 + pristine_git_object: 53532b49bbe4a613bda065dbded4c0ee282e2f3f + docs/pkg/models/shared/fundrulehistoryentry.md: + id: c2b48d53828e + last_write_checksum: sha1:c5bf40e16abf9eae7909f55ec94e7839730be4a0 + pristine_git_object: 9d662d08c0ab944b7443326243ac0b7b84c63615 + docs/pkg/models/shared/fundruleservicecreaterequest.md: + id: 9f0543daed80 + last_write_checksum: sha1:0039ec293a45bc8ec051b21255de8519d48d7817 + pristine_git_object: 19c426705555975187015af2fd84502947582b0b + docs/pkg/models/shared/fundruleservicecreateresponse.md: + id: fb4325d1297f + last_write_checksum: sha1:9677dfb0f8896e372bd9a88d1db62d0805afe898 + pristine_git_object: a73699fb3c1df0759b0f365518212aa15905f4a5 + docs/pkg/models/shared/fundruleservicedeleterequest.md: + id: 47d1e48f2d5b + last_write_checksum: sha1:c3370ba8f59b7e4cfacd11227340e3dd3d248232 + pristine_git_object: ca533a509ad10ca44b5821c1e2bb94246cb533ca + docs/pkg/models/shared/fundruleservicedeleteresponse.md: + id: 6b311f8db54a + last_write_checksum: sha1:f712d85589cfa4c2caa230b85fd81780523b0d8c + pristine_git_object: 221bd7d29482fef86d22f581b35ebe10b3ffbe47 + docs/pkg/models/shared/fundruleservicegetresponse.md: + id: 97d096c9886d + last_write_checksum: sha1:4248f127297b39746822c79b9b8623e20967ec74 + pristine_git_object: aa3b883812c56c7ce8f22c66613b002ee2ba5676 + docs/pkg/models/shared/fundruleservicelisthistoryresponse.md: + id: c5c1c52e744c + last_write_checksum: sha1:e9eacbd9fae639f4890327f24e3acf0953c0ff7d + pristine_git_object: b6631838fd4df8c5b569a6a087e2de7e21e12dee + docs/pkg/models/shared/fundruleservicelistresponse.md: + id: 959656d9c85e + last_write_checksum: sha1:a11fbe1e6a6ee15a3c9837e5c5f5a7e2c234e3ef + pristine_git_object: 8fe0b565c09904bb2abfbd0e95f567dbbae3bd79 + docs/pkg/models/shared/fundruleservicesearchrequest.md: + id: 5b895a34429f + last_write_checksum: sha1:290b73c6f217895ff522db3afb772ac8ce24de3d + pristine_git_object: 83e92040bf1c45c71f1fc696cc1eee39b7f11180 + docs/pkg/models/shared/fundruleservicesearchresponse.md: + id: 4efa5f38efc6 + last_write_checksum: sha1:cdfdefa321500dd3301efe9c7f1e50f6f0cb0182 + pristine_git_object: 2d5d0c81adbe2af9ddd228e1e5363ab3f59d8193 + docs/pkg/models/shared/fundruleserviceupdaterequest.md: + id: 4f3641ecba6d + last_write_checksum: sha1:39cceaaec59e61b55439b44de9fe6498805de5ef + pristine_git_object: 18ff2ce446e76cdec3bd4efb0dc4ab6d71ba145e + docs/pkg/models/shared/fundruleserviceupdateresponse.md: + id: bf008cca1131 + last_write_checksum: sha1:b8edeebec743eb1b19fac9bd51588000fa24dfa9 + pristine_git_object: 54c70b0a1695d6911d368685d15c7d8cd2c7b163 docs/pkg/models/shared/gatedtoolcalltarget.md: id: edc1e377672a last_write_checksum: sha1:a39114e2c005d3716753afdd21307ac7ff4cfabf @@ -7904,6 +9096,10 @@ trackedFiles: id: 7c1d510b6363 last_write_checksum: sha1:859c128a5dced3cac680bc4cd27b8fceb0b31c2b pristine_git_object: 6b30c6b966d42806018fb88340535fd3b1253940 + docs/pkg/models/shared/gatewaykey.md: + id: de1c63815332 + last_write_checksum: sha1:8736b97622ef86ab67f43aca9dbcca3534ef2087 + pristine_git_object: fb1870fa25d580e24128231262d9cb38d728a1a2 docs/pkg/models/shared/generatepassword.md: id: fe148d7958a8 last_write_checksum: sha1:485eda0db4c383da38e1991f52b0cd20c3b19751 @@ -7956,6 +9152,14 @@ trackedFiles: id: 81cf8f0b5c80 last_write_checksum: sha1:d2766a86c4dd4bde17eb920a8ea444f45c8daf9c pristine_git_object: 86daf68fb2fbc0274591b20c56647b23e17688bd + docs/pkg/models/shared/getappmanagedstatebindingresponse.md: + id: fd12b3726f31 + last_write_checksum: sha1:6c0c57900efbb2ef02977b31afd8a9980fdcccab + pristine_git_object: b4f3461bace8ce2cba25bda70b9c7cdaa723e97e + docs/pkg/models/shared/getappmanagedstatebindingresponseexpanded.md: + id: bd9db1966b04 + last_write_checksum: sha1:0d69d1d1d73b474b41c5bac65327346c1868af9f + pristine_git_object: b7bfd1768c13b6c8d3fa01d984ea42c9ec4b6572 docs/pkg/models/shared/getappresourceentitlementownerresponse.md: id: eb1da335ac92 last_write_checksum: sha1:45380862e798c154d84a160d81659e75d3f2d3e8 @@ -8018,8 +9222,8 @@ trackedFiles: pristine_git_object: 7396ebeb77ab7b55c329e1792c191ec799d8823f docs/pkg/models/shared/getcustomanalysisresultresponse.md: id: 95c1b9f1d016 - last_write_checksum: sha1:a85e8257f076df88df8cde5a58373cd3fde79915 - pristine_git_object: 8eee8613237b78b6c7e50dce3f880929547eb79f + last_write_checksum: sha1:3db7deb82fa25357f9ca9c3f9d7d430d4e538a59 + pristine_git_object: fe877188fbd086e846e3ce8734dfa8146e446a65 docs/pkg/models/shared/getcustomanalysisresultresponsestatus.md: id: 3d22663baba0 last_write_checksum: sha1:fa2774efff492ded4bb27c3acabbe496b51cd502 @@ -8064,6 +9268,10 @@ trackedFiles: id: a14c7e0eda18 last_write_checksum: sha1:016240c45c7453f20b3a46baccb60c0f77f17081 pristine_git_object: 26ec682d9eb8386662a05554ea14ab65ed75c940 + docs/pkg/models/shared/getprovidercredentialresponse.md: + id: 975258afe828 + last_write_checksum: sha1:5e8803e467fc67d1b93182770292b913559b1700 + pristine_git_object: 59a4dbb9619ba995fd6bd7a263c01053f7f7260c docs/pkg/models/shared/getrequestsettingsresponse.md: id: 3ed68ab9cd14 last_write_checksum: sha1:f2b8737e5a49e7ec0c95787c8648a57688f088d2 @@ -8170,8 +9378,12 @@ trackedFiles: pristine_git_object: 16a2a39baa8d01a3b4bf32c859cc2644e3a6a220 docs/pkg/models/shared/grantfilter.md: id: ef4494f31708 - last_write_checksum: sha1:dbfe64e5db2227caae5911d9da223ff1c44f3dbc - pristine_git_object: e6f9b1165178e584d017eafdfbda11489d1f972e + last_write_checksum: sha1:c4405a50fe7235ac2d499e3766905463a045eeda + pristine_git_object: f2c7b60788bf643c28e874db678b0b67ffdd3877 + docs/pkg/models/shared/grantfiltergrantsourcefilter.md: + id: 16b39209e6bd + last_write_checksum: sha1:698f79b69ab55673b91e8e5eaed2c64259a73351 + pristine_git_object: c65d6edc5dedfa6484538bf5bb17c6fa52be1bab docs/pkg/models/shared/grantfiltertype.md: id: c5281ed8bcc0 last_write_checksum: sha1:340fa69a7300c0530621c3e46ffcc79e24d95bd8 @@ -8202,8 +9414,8 @@ trackedFiles: pristine_git_object: 42ec5622b9009bea30437158adb5df5002739d90 docs/pkg/models/shared/grantsourcefilter.md: id: 9b1bcaa63c18 - last_write_checksum: sha1:c241a9978b81ed5d93da682484c1c7144eb14068 - pristine_git_object: e646b393c3c2a0be99a21a7796687554c4bc073e + last_write_checksum: sha1:13c77feaa16b4f6885d696b5a534d82e5845a063 + pristine_git_object: 2c4fd85a177403fd1a272131e91ea34347a5c06a docs/pkg/models/shared/granttriggerfilter.md: id: 790e3ecc84cd last_write_checksum: sha1:327ab6a420ed0de9defaac78f3e7105ec636e02b @@ -8232,6 +9444,10 @@ trackedFiles: id: 65417577f3f7 last_write_checksum: sha1:b9dc1162cebcb225aed63a24b6d6392a81425fbf pristine_git_object: e8bf91e3f6a9556e4a1526b9cc0bf06a2a1af604 + docs/pkg/models/shared/headerstyle.md: + id: 5f3900d2fa5b + last_write_checksum: sha1:b9f63d7605b594f379abd15072c0c56b9f193adc + pristine_git_object: aa462a8e5d9743a57f1f79242adc8f2e0a4cfa2e docs/pkg/models/shared/historyactor.md: id: 8609097b129b last_write_checksum: sha1:c8ff37d63863495a31784213a6073cba9140054b @@ -8254,20 +9470,20 @@ trackedFiles: pristine_git_object: b6e2ecc84d854736b2252b61e3e4013d81c3e9cc docs/pkg/models/shared/hook.md: id: f77efe9bcd1f - last_write_checksum: sha1:fb9750297a36bac89fb2a3a66e5b7c5c34d52351 - pristine_git_object: 8121d275f6972c2aa4ce09dd3c5bf8e02ce9ceb3 + last_write_checksum: sha1:4e69119f4b378a08d29ad24077e154182402801e + pristine_git_object: ee8fe56a63503068a0911743ad6d58bf34406fe2 docs/pkg/models/shared/hookfilter.md: id: 96d092d3cb42 - last_write_checksum: sha1:e4da4bec8ab975844615f8dd5bc7dad021776667 - pristine_git_object: b00088a180aaac6dad36dd586974c96e26548a35 + last_write_checksum: sha1:1cbb474355d60469aa414529853800bc67400d6b + pristine_git_object: 705e8c92dbc738b27fe66e962fe23fcb6f1ab6ee docs/pkg/models/shared/hookfunctionref.md: id: 3f1799d346eb last_write_checksum: sha1:2cc59e688f7b718366e9916ebee6aa3cb2d4e654 pristine_git_object: c8a5c159cb07cfdc7c8103c6b15acb0865b9055d docs/pkg/models/shared/hookinput.md: id: 119e45225528 - last_write_checksum: sha1:ee231579ae67977bbac464e127f7dcaefa206ca2 - pristine_git_object: 3ba45c1b10b7bf990b3154f805ed3276073cf68c + last_write_checksum: sha1:974f23dc1a26a941536da544c3a036bb4f6f9da4 + pristine_git_object: d2001bb959c772c6d6eeb5a5f8c107f8ca2652bc docs/pkg/models/shared/hookref.md: id: a3150dac84d4 last_write_checksum: sha1:8f171e99f6b072f4718290526e2ed59cab6c32bb @@ -8282,12 +9498,12 @@ trackedFiles: pristine_git_object: b961c8d7f810563f00c7cddc02d93c81ec5987d5 docs/pkg/models/shared/hooksservicecreaterequest.md: id: f0662859a622 - last_write_checksum: sha1:b08e2542d6264618239d06110f1595e377161b7d - pristine_git_object: 3cb42d5f837458e49b109d8945696abdefb67640 + last_write_checksum: sha1:ab3f0642a6015d9f8d87ddbd1030726b0e0ad60c + pristine_git_object: 24c9a3d63efac0f3ea9aa3671f2bae08a90e226b docs/pkg/models/shared/hooksservicecreaterequestevent.md: id: 8f41601a2a45 - last_write_checksum: sha1:2d42f2227e97cf53601d634e7a26402364908d12 - pristine_git_object: 3701983b14385abf07f03cddac56e9b6ce9ed902 + last_write_checksum: sha1:8a87bede0398c29620fa3634f77871725f7aec86 + pristine_git_object: 58114ae6273cadb53ddc2f0378cada53ad89ef70 docs/pkg/models/shared/hooksservicecreateresponse.md: id: 2d654ad71989 last_write_checksum: sha1:7f0e966f92a7efc675cb8750ba3ad986d490e36b @@ -8344,6 +9560,10 @@ trackedFiles: id: cb9a3cae565f last_write_checksum: sha1:99a0c016416b445b17c42dcdb731d2eb4bdd05bf pristine_git_object: 19feaad41e157aef2972dc985db776ce762a263d + docs/pkg/models/shared/idtokensignedresponsealg.md: + id: 692e2ca72f97 + last_write_checksum: sha1:a01fbccb06671594018345d2b585e6c527743e3c + pristine_git_object: 24c482e0280972a6686819308b1de6aee2c39606 docs/pkg/models/shared/importfield.md: id: 8c10fe0ba002 last_write_checksum: sha1:8ad8de44c659cc5485f75ede9dba0e74469bf049 @@ -8382,12 +9602,20 @@ trackedFiles: pristine_git_object: ba540037f1cf5331f413a4c1384c2f8e033d4e49 docs/pkg/models/shared/introspectresponse.md: id: fd01cb10344e - last_write_checksum: sha1:145fc48273d15825338f18b06c2965c635911654 - pristine_git_object: a84554d1c5b8026ffc14940c24575470a3b00556 + last_write_checksum: sha1:e35b154caee1a56374926b397bb8c0c8c2b53b21 + pristine_git_object: f4ccc80bff2472d5edabe0fac2b1e92d06c524ea + docs/pkg/models/shared/invokefunctiondispatcher.md: + id: fc6032b5802e + last_write_checksum: sha1:dfd26ef5d26435ae2747ba45b254c33762fdb264 + pristine_git_object: 22caf3a5f47f7e2af830d0c02baf9c31710a5579 docs/pkg/models/shared/item.md: id: e588231b86a5 last_write_checksum: sha1:7b59d2935ba944be61a387f47ecadf544ff3ad5f pristine_git_object: 0c21d4ae2ed55fe097f39da48bc6eb74c2520836 + docs/pkg/models/shared/jsonpatchconfig.md: + id: 21353f226dd6 + last_write_checksum: sha1:4e3c761a6e1bca868756d60222d54db34eee777c + pristine_git_object: 9055bf629ea8f14396b4df69b204bee3bb36266d docs/pkg/models/shared/justificationvisibility.md: id: c68fdde195b3 last_write_checksum: sha1:db0a09cb142d311627a2f02eb069ac71d785cde8 @@ -8400,14 +9628,26 @@ trackedFiles: id: 7efe08ae5871 last_write_checksum: sha1:bc5234696c101985650c559abd71349cd681cc27 pristine_git_object: 1dd79a90e146f13689c49fb6dcf764408abb0396 + docs/pkg/models/shared/kindfilter.md: + id: 04e861442fe1 + last_write_checksum: sha1:daa3abee862c41b5769f75f5a1bde559f5118f8d + pristine_git_object: 7c71a3ce862cb39cdcc3029dadda67733e22498d docs/pkg/models/shared/kinds.md: id: d549eb76dc67 last_write_checksum: sha1:0834a0a77552e2f1af21aafe0ad5e84489739677 pristine_git_object: aa227974d22ef232a96ad3b10114b4192d48b92b docs/pkg/models/shared/level.md: id: c4068224e290 - last_write_checksum: sha1:b252fda9b347a3dff61220064579c88ed0f57e64 - pristine_git_object: 1f051a6f65d261e4db6e525562db19bd648d19bb + last_write_checksum: sha1:6f88be7f7aa925a40a174a5397b04dad99edc442 + pristine_git_object: 3eca9142d5c5a269058f3181206d1d5fb0f24f9f + docs/pkg/models/shared/linkfilterconfig.md: + id: a779ba07d569 + last_write_checksum: sha1:83f148ae916c9a60a28bdacf9132482d6e9e8433 + pristine_git_object: f0a231d78424b82d66636a6987946380fe21ab74 + docs/pkg/models/shared/linkfilterconfigaction.md: + id: 8d3dc7e8aca3 + last_write_checksum: sha1:fdac691f5cdfb1b12efbeb6df6bba097492bf331 + pristine_git_object: 4c897e330e65d2516ecf5535da8cbfa294266e3d docs/pkg/models/shared/listaigovernancesettingshistoryresponse.md: id: b98a5bda4ada last_write_checksum: sha1:240f82cbed205b4c240c1e3888e23b24dc0b3702 @@ -8440,6 +9680,14 @@ trackedFiles: id: cdeacce41df5 last_write_checksum: sha1:fad758d33944d6b5bae8938f427a511eaa50d547 pristine_git_object: 502996094aedfe52c7a42b1bc521fb17ff80ca1c + docs/pkg/models/shared/listappmanagedstatebindingsresponse.md: + id: 26d908cb7818 + last_write_checksum: sha1:db585ac3731d799bd5445bccf5fb9707d4abb38f + pristine_git_object: ced27667fa6e60e496eeb55317dde14fa0fabfb4 + docs/pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md: + id: df2a3588da05 + last_write_checksum: sha1:624047bf4cf189fc293b93b3e72990eb07551173 + pristine_git_object: 1eff66e5706b0545a8c825d0b11e2fdd094dc877 docs/pkg/models/shared/listappowneridsresponse.md: id: a230f006652a last_write_checksum: sha1:407d3a30bdc30871760326c824d1ed2e49b29e28 @@ -8496,10 +9744,18 @@ trackedFiles: id: 7de2c42fb27c last_write_checksum: sha1:f839925f61b6c05aab97bf6736d109051b3f8740 pristine_git_object: ca64df1ac7f5c2627ab698e97be9d49d868e7094 + docs/pkg/models/shared/listfindingsettingsresponse.md: + id: ac0a3caacb7d + last_write_checksum: sha1:10252e3fb34d7527cf1418736f374014d30db505 + pristine_git_object: 996460d6017232db33aa03f3534a9dd62fd7e034 docs/pkg/models/shared/listfindingtransformationrulesresponse.md: id: e84bc94cda6c last_write_checksum: sha1:895cca42695e96adb787595edda20f88636c746a pristine_git_object: f057c381a3936dca285c5d500945b257be697a53 + docs/pkg/models/shared/listgatewaykeysresponse.md: + id: ee2a01cc115f + last_write_checksum: sha1:e0bccb0487cd298ec1e94f97ae9ff622d6343ed6 + pristine_git_object: d6f04c2f0c9a0f804033370a2f16ca03668cbed8 docs/pkg/models/shared/listhistoryentrymetadata.md: id: 46b416e874b1 last_write_checksum: sha1:12296d4b8b865207f2bbffc8360505ebd44884a3 @@ -8666,8 +9922,12 @@ trackedFiles: pristine_git_object: 11e81f0979b5bf36cd79a74e73d24b27c585ec8c docs/pkg/models/shared/mcpaccessprofile.md: id: cd7c5c5a7d0c - last_write_checksum: sha1:9c0128fcfc309e44c2c783c675106de2da5cd6ab - pristine_git_object: e183cce8950acd5e591a4f025c8a849ba4176764 + last_write_checksum: sha1:692eafd68825a0310add1213e9536174bc931654 + pristine_git_object: b46b6ff3755b169b0232dff0abe689555d3586f9 + docs/pkg/models/shared/mcpaccessprofileinput.md: + id: 24108b682b7e + last_write_checksum: sha1:cf4a9148ba394decf64728b9ea3fd6f49bdbe453 + pristine_git_object: 554c9bd9196cc8b33cec23874f24b5624870be06 docs/pkg/models/shared/mcpaccessprofileservicecreaterequest.md: id: 8f87b7828c1f last_write_checksum: sha1:a90f830f4b01c5e288da885b730a2f3eadb03952 @@ -8700,14 +9960,18 @@ trackedFiles: id: 9f01c17ebb12 last_write_checksum: sha1:aebce0573e5f0e40919b484869800adb088e7f52 pristine_git_object: c088ba1365e2245ccffed8d5afd5f2379ac5e87f + docs/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md: + id: b8071195a4a4 + last_write_checksum: sha1:c76e384a09f9f21569891ed791553f6c47466f1c + pristine_git_object: 320b6b0633ad5276d01a76a89bf825c041a93e7b docs/pkg/models/shared/mcpaccessprofileservicesearchrequestableconnectorsresponse.md: id: 2bee73b16c7e last_write_checksum: sha1:151475aef627c399474516912699bc99177b6520 pristine_git_object: d43de6a5af7d216e9e2d20716e0e2548f2f00070 docs/pkg/models/shared/mcpaccessprofileserviceupdaterequest.md: id: 0eebdbbe42ec - last_write_checksum: sha1:7f23b8172989ef9774314b212069abe7847eaa4c - pristine_git_object: cd53cd3e64deaedcf4ccaf6eb7e69cad5499ccfb + last_write_checksum: sha1:49cd587d9412786f17072557ee8b514a96a31d7b + pristine_git_object: 1d5e4e7a8f3aeafc8f6cef5404dbf007173ba263 docs/pkg/models/shared/mcpaccessprofileserviceupdateresponse.md: id: 5cbe3f450969 last_write_checksum: sha1:12a6202cdd7412a2932085c5a2dd9f6fa2287791 @@ -8792,6 +10056,58 @@ trackedFiles: id: 3a92e48d717b last_write_checksum: sha1:c98700d746f79f3232c4712471c3ca996fab931b pristine_git_object: 7888f784724920caf65177755b603cace34db910 + docs/pkg/models/shared/mcpresource.md: + id: fe2322c82644 + last_write_checksum: sha1:60e95ba144cafbab5c8230c09b00811d514f1844 + pristine_git_object: 24bdb5adc504402064788c2578630ce2f809defa + docs/pkg/models/shared/mcpresourcehistoryentry.md: + id: 8b047bd62486 + last_write_checksum: sha1:6a9a3620a640f1de291690adc96176419974ebf4 + pristine_git_object: 448999e7bc284b98da2e291b08b0c2b559e64fc8 + docs/pkg/models/shared/mcpresourceinput.md: + id: 826ef3fb35bd + last_write_checksum: sha1:82282f284418c12a5ec867ec7aecba77ee329ac7 + pristine_git_object: 6926e53a45d1cdebb423b751eed2afd03b5b57c9 + docs/pkg/models/shared/mcpresourcekind.md: + id: 2ab2e12ec7c5 + last_write_checksum: sha1:1f6f3b01e57c54d5341458c7fcfab2c2e0b894d1 + pristine_git_object: 8e73494f176884b763761f7b8d4cfc3b07ec43f4 + docs/pkg/models/shared/mcpresourceservicegetresponse.md: + id: 9ab36fab229e + last_write_checksum: sha1:3246a3d3ed305b6e57384454d028fb3387ab5187 + pristine_git_object: 89d2a15b069e0bb6b3d1b80f293bbe8677e7d928 + docs/pkg/models/shared/mcpresourceservicelisthistoryresponse.md: + id: e74dd5ee0894 + last_write_checksum: sha1:2b05d58bfbd7d75934666db206be5c17b51e1b99 + pristine_git_object: 5ea6bfa1a20e76c82343169d320ed9b75c1d2805 + docs/pkg/models/shared/mcpresourceservicelistresponse.md: + id: 6ef53e62247e + last_write_checksum: sha1:8ac3edf7f4cce108986f3b26ef1a2bc172cc6d6d + pristine_git_object: 593ee9dca553a5eb4fe2aec7c20daaaee237041a + docs/pkg/models/shared/mcpresourceservicesearchrequest.md: + id: f557ab0e0c29 + last_write_checksum: sha1:2eb8fb5f0e70c80a158be23f52b55467858b84a6 + pristine_git_object: 3897aa23b7f0aebb53c800c379ed8a44625086f7 + docs/pkg/models/shared/mcpresourceservicesearchrequestsortby.md: + id: 52137b928287 + last_write_checksum: sha1:a9a7e37b422ad7c74b12854945bc81fad34d0082 + pristine_git_object: f0333359c7f89213b4242173cb16630c01f89d7b + docs/pkg/models/shared/mcpresourceservicesearchresponse.md: + id: fe13e4867f4a + last_write_checksum: sha1:a65b8b2bd6c25feb88d2fc6428bf78ac985020ff + pristine_git_object: 022db41b43ee793d540c34ecccad1f12e399b0cc + docs/pkg/models/shared/mcpresourceserviceupdaterequest.md: + id: ac7691228e7b + last_write_checksum: sha1:0e2e2fb31929b13790bfaeaed631cfdd76ad3e11 + pristine_git_object: 91964c2877c041ecb566c308f2d71bb69656deb2 + docs/pkg/models/shared/mcpresourceserviceupdateresponse.md: + id: 33c8d5a6384d + last_write_checksum: sha1:8cbb2d17e831009f8130ca43ee3dd91dfe4e00cf + pristine_git_object: e8afd774145dd30c321e79eef047a28610a1b973 + docs/pkg/models/shared/mcpresourcestate.md: + id: 6baef88da008 + last_write_checksum: sha1:e1797487914525de30c1ae91cf4c59936ca13a67 + pristine_git_object: 6e87e700962be74dc89de2612fb2d070b3ebff18 docs/pkg/models/shared/mcpserverauthawssigv4.md: id: 2d0e7cc7f1c7 last_write_checksum: sha1:57f643bbe173dea8bef682b7797da6e56e699a1a @@ -8822,12 +10138,16 @@ trackedFiles: pristine_git_object: 0d7911b700f853db934dbc699afad100a72649d8 docs/pkg/models/shared/mcpservercatalogauthmode.md: id: 5b40a7223193 - last_write_checksum: sha1:54d697d5e0bcfacc598039de9d13822bf8dcf45d - pristine_git_object: e2bb208662a775f09ea9a694bdf0d7d378a5b3b7 + last_write_checksum: sha1:efd29c4e1b5a14b167b8f7d0f8d7b8bf10790e7e + pristine_git_object: 2d9898aa21e993cf987b06e6f86167a0eb9e01d5 docs/pkg/models/shared/mcpservercatalogauthmodeauthmethod.md: id: c6e3f96a19c3 last_write_checksum: sha1:9bc7acbfd6c43389bc4628e12bed319d0e5cbdd9 pristine_git_object: c66e6f0cd16987b2f21605ca697f1fbd58ade15a + docs/pkg/models/shared/mcpservercatalogauthmodeclientidmode.md: + id: b1e6d02c5ace + last_write_checksum: sha1:d70a591f79a13eab09e4bfb65d20b7ac49bb8353 + pristine_git_object: e73782c9c372ce8af6f5f785d323b1c5d0b6c741 docs/pkg/models/shared/mcpservercatalogconfigfield.md: id: 8cbe124c25ca last_write_checksum: sha1:68f5cd28076565ffeb2fe4cea33722e87ec6ba21 @@ -8838,8 +10158,8 @@ trackedFiles: pristine_git_object: e70e8e6272f80f9842acbf84ec9f66978cabfa6b docs/pkg/models/shared/mcpservercatalogentry.md: id: e328e8e3daaf - last_write_checksum: sha1:2809f658ccd0fd08fbbb935e9a362648d5e42620 - pristine_git_object: fce6086fc65acbe8fadd2ca6babac04623f2b884 + last_write_checksum: sha1:b6a6c051ac47341db486a67eb97b303bceef8fef + pristine_git_object: 0524224702b79d093095c6f602f7873a43942d85 docs/pkg/models/shared/mcpserverexternalconfig.md: id: bbe0a9c84581 last_write_checksum: sha1:91b81d22f6d3ad751fcc1efe58a2e7569423f9f5 @@ -8898,16 +10218,16 @@ trackedFiles: pristine_git_object: b52909b2d7c65a25ab62d0a2c737281e8bd50e3c docs/pkg/models/shared/mcpserverserviceregisterrequest.md: id: acf9b789ed1c - last_write_checksum: sha1:222856aa110e1b327d59bb3cae30ddc96df5cf7f - pristine_git_object: c9825d98d043a448365b9deedf4c2bfe1827b462 + last_write_checksum: sha1:654a49cce77cd99104a4ea93a6eaaa54f31733f6 + pristine_git_object: 47b50e3a7f2e06477e24c4214e5eac2feb601256 docs/pkg/models/shared/mcpserverserviceregisterrequestservertype.md: id: 91c6a33cd615 last_write_checksum: sha1:bdd9ec6010fcb7eb3bc179dcd024eb4d31d6286d pristine_git_object: 1c40d8944e95c5193b49242ca71fe87353d860d7 docs/pkg/models/shared/mcpserverserviceregisterresponse.md: id: a30dc7fc3278 - last_write_checksum: sha1:2542bbb07f889611cbe51150898777178fbb2a30 - pristine_git_object: a9981993cc2d3351aaafc53e890546100e0291da + last_write_checksum: sha1:9d8785e33867c37ab8c6206cb539b14829b045dd + pristine_git_object: 686818413cf51d62db952bc016f65f37797abb18 docs/pkg/models/shared/mcpserverserviceresynctoolsrequest.md: id: 91faa52befcc last_write_checksum: sha1:2cdb4d893f5ff34d5bbf515cb5dc85fdd7dbd89e @@ -8950,8 +10270,8 @@ trackedFiles: pristine_git_object: 45266dbb63d30c8fc571faffd5230223a9b93770 docs/pkg/models/shared/mcpserverview.md: id: 35d17f099d06 - last_write_checksum: sha1:d2193697ba9caf76a9f21d6ed2872c58223c3bc4 - pristine_git_object: 91c12fec349284875a193cfed3c3a7a00312f737 + last_write_checksum: sha1:60599000f71ddd85a206c3ced66e532b878343b0 + pristine_git_object: f97e20c605e00fad4802213d394a1d08b3a9cf2a docs/pkg/models/shared/mcpserverviewauthmethod.md: id: b05b1363647e last_write_checksum: sha1:706dc1f46ab53e49838b80ed582b43e7173c7765 @@ -8982,8 +10302,8 @@ trackedFiles: pristine_git_object: b4979632240df10e51b7139c82984ed7618fd756 docs/pkg/models/shared/mcptool.md: id: "349668106124" - last_write_checksum: sha1:0dbfe9f919d65aea376b8133bfb73e17ffe15fea - pristine_git_object: 8d4b219ea142c4fbbb05fee3979280fcba9152ab + last_write_checksum: sha1:7e1b3f5a4aed9df81391210e6277842f8d02a7f3 + pristine_git_object: 767f32e26c2907e0778821ea9a2860811116a5fe docs/pkg/models/shared/mcptoolallowedclienttypes.md: id: 72291c9d1799 last_write_checksum: sha1:09b8f1930f9b14ac4a08dcd06cbcba6ddc932161 @@ -9022,12 +10342,20 @@ trackedFiles: pristine_git_object: 8ada1dda5843844ae028a926c9b1652cb81dc4aa docs/pkg/models/shared/mcptoolservicesearchrequest.md: id: dcfc24ef678f - last_write_checksum: sha1:801b346b5208d3500b759d1b514d55446231c9c3 - pristine_git_object: b79114c6ea9f4087fc9acbeac7946d6facbd9408 + last_write_checksum: sha1:5674ad9b2c087e18e926f3c12a59efad67f063c8 + pristine_git_object: 059c7b8d2bac8a48d8db10efe7944ede33ce760b docs/pkg/models/shared/mcptoolservicesearchrequestsortby.md: id: 348282ab72ed last_write_checksum: sha1:fba7cbecf562af47d0487bcfff51d2fad3eb025d pristine_git_object: 25101d2bde66beafa875e65250dedb516b0f36ac + docs/pkg/models/shared/mcptoolservicesearchrequestsortdirection.md: + id: 47d40397446f + last_write_checksum: sha1:98316442c95664bae573bad01ebca5862ca398fb + pristine_git_object: e32d56d558ed459ec5d90819098add6d893e0056 + docs/pkg/models/shared/mcptoolservicesearchrequeststatefilter.md: + id: 3c7c21d14423 + last_write_checksum: sha1:b170defb69ea252f2f5728c183ff1a5bddf579b1 + pristine_git_object: 90b739cdc6942fb6f05468b20a989793c4fb83e0 docs/pkg/models/shared/mcptoolservicesearchresponse.md: id: 39567056a46e last_write_checksum: sha1:043572c755ab4486954731774ba4d72f573e644a @@ -9060,14 +10388,30 @@ trackedFiles: id: ea93b1c7d5ef last_write_checksum: sha1:98e95af4834a64df81265a13c93f3b9e89031f78 pristine_git_object: 28b603e6c460037967f770d0fbfb610b943193cb + docs/pkg/models/shared/mintgatewaykeyrequest.md: + id: d3080be9b3c4 + last_write_checksum: sha1:3106b46cfb1f780d394cb1c0617cb1ba257d25b0 + pristine_git_object: c5a1e1060e7fe72ccc4bdce93729717af3e79f47 + docs/pkg/models/shared/mintgatewaykeyresponse.md: + id: 1a6155f388fb + last_write_checksum: sha1:ff29a2e3ef3e304f1ff24352db25ad1b3b056b9d + pristine_git_object: f7cb9755e44f9ce5b5cf083c3ac54a1781b2d43a docs/pkg/models/shared/mode.md: id: ffe89372b8d1 last_write_checksum: sha1:5de7ede0ed775ba8c73e1e08f71675ac9f5a43ea pristine_git_object: aa7cf76968ec5a8def5e2274d57e9dc1fe20d2ca + docs/pkg/models/shared/money.md: + id: ede7d10da34e + last_write_checksum: sha1:119aec08e43b0d215421642a9b41e7f4c79a9b14 + pristine_git_object: 408f62adf33315a474447dabbd60e8ef1b40e0cc + docs/pkg/models/shared/msteamschannel.md: + id: 6c6de57e45db + last_write_checksum: sha1:184663bb1e6236facb88b47eaa57adecae1b04ea + pristine_git_object: df01ea7ab8636d2b5d1c5ac135211f169b7eea27 docs/pkg/models/shared/msteamschannelsettings.md: id: 0b1d57fa997b - last_write_checksum: sha1:1bedfe912867820b85f1e1e98c5298d9e1d2ae6a - pristine_git_object: 181f6349a7d082131cf88832703bc1c6559bd2ee + last_write_checksum: sha1:65acf263672c60f65de048abe3bdc8bfdf20f80f + pristine_git_object: 9aa6775e655fde8961f95657c412f430c04d166a docs/pkg/models/shared/multiappentitlement.md: id: cf5ad380b434 last_write_checksum: sha1:4fee2abe5aea31bae88f91cd3a1dc8ca52abbc20 @@ -9084,14 +10428,74 @@ trackedFiles: id: 83fb8e05ad37 last_write_checksum: sha1:3949273ca73fd09963e147e8b19b9fddee787efd pristine_git_object: f11bb41e11f5cca03fde63c6d52731c4ff8e344a + docs/pkg/models/shared/myfundlimit.md: + id: 123b731a0364 + last_write_checksum: sha1:2a3129469b1a034fc45c642e40342be5c162fcad + pristine_git_object: c31744682ae3262d81e3f77a5229e926f422f5dd + docs/pkg/models/shared/myfundlimithistoryentry.md: + id: a5a6d6e171ed + last_write_checksum: sha1:82d812e5af8aece46ba41dcf23c5101822191291 + pristine_git_object: 11ac388093fc5dd9839b414d027f7e453a817c29 + docs/pkg/models/shared/myfundlimitsservicedeleterequest.md: + id: 894b74d17a66 + last_write_checksum: sha1:41032813e526662af1ebf490b6057c3686bea687 + pristine_git_object: f045235551ed96685bb7a3520ca0f0bbc9b4b7b5 + docs/pkg/models/shared/myfundlimitsservicedeleteresponse.md: + id: 0e95ae590bef + last_write_checksum: sha1:a301a69751511d22e81658b24489b2096383c7ea + pristine_git_object: 53f9fc3bdbf32e21d094edda238b87dcda6fb8ba + docs/pkg/models/shared/myfundlimitsservicelisthistoryresponse.md: + id: 82e1466ba018 + last_write_checksum: sha1:f55b3ec55ddd1f603ce9d4c55c5b2f5332d9d2ba + pristine_git_object: 702eed0ecff9bc42dde8bcec0e6d02f3881b0dd8 + docs/pkg/models/shared/myfundlimitsservicelistresponse.md: + id: 45feaef82537 + last_write_checksum: sha1:fee661aa67482c48ff87acfd75c4c334e89b63f1 + pristine_git_object: 48dbf6698c71dde69fc76b1e2ebca927945aa254 + docs/pkg/models/shared/myfundlimitsservicepauserequest.md: + id: 05f5109eb5e0 + last_write_checksum: sha1:24e73781ee12412c9ce4d79ea1ecd100dc235016 + pristine_git_object: 594ff59ebab1e7329e240fa316abfdce220591dd + docs/pkg/models/shared/myfundlimitsservicepauseresponse.md: + id: 0ceec7822d99 + last_write_checksum: sha1:9629a1bb884d6617e7e027f4527a83f8aee45e2e + pristine_git_object: 52b5f5754a974a5fd2cea60263eadf643be87125 + docs/pkg/models/shared/myfundlimitsserviceresumerequest.md: + id: 9a28a40e0b68 + last_write_checksum: sha1:5a3d248f50505d8cb7326da703e41cc9e80cd537 + pristine_git_object: 5b7618476a6c606caa9f56aea1b543e9a532ac94 + docs/pkg/models/shared/myfundlimitsserviceresumeresponse.md: + id: ffcccfdd35d3 + last_write_checksum: sha1:3b1dc8acb66f97d4e03978d01945910ceb3ce3c4 + pristine_git_object: 424fd890180791fd54d915ebbc01d33f68cb6a68 + docs/pkg/models/shared/myfundlimitsservicesetlimitrequest.md: + id: 543d393d4e18 + last_write_checksum: sha1:f4e0f708a4ec43b55e29034ed052a728a79fb8dd + pristine_git_object: d8ccd4b2f4c2fcea31c2e355c6e63c57cd9b6cc2 + docs/pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md: + id: d1f4f843cde7 + last_write_checksum: sha1:9e3d9707f9532ef34ae348ed264a208ce1c37e29 + pristine_git_object: 0ab70b123d931354cdab7a8a95605debd7138bad + docs/pkg/models/shared/myfundlimitsservicesetlimitresponse.md: + id: ef28c4523aa0 + last_write_checksum: sha1:187271219c504e428e2b6cc1442d8f8806331558 + pristine_git_object: 03705b141da7d9a11246859f396d3d27b6308119 + docs/pkg/models/shared/nameformat.md: + id: f72a8104c448 + last_write_checksum: sha1:62c4bf5833da5b5c18235ddf33c54ab22179d792 + pristine_git_object: db60314e10c98dad65475775c2f0d82b918468a0 + docs/pkg/models/shared/nameidformat.md: + id: 1b81f0ba664b + last_write_checksum: sha1:ba1a78b4a233fd95d00bc6a24812846e34191f1e + pristine_git_object: 011befbc65fc879e4bb5ccbf4f83f245655732d7 docs/pkg/models/shared/nhitype.md: id: 3221c0e5be4c last_write_checksum: sha1:ec778dee8a08a82c8dcd9ed27417cdfe61fc6ce5 pristine_git_object: fa9d5d76b2380a1847f6fdc76e98ef069e63b0a9 docs/pkg/models/shared/nhitypes.md: id: 5d870f989d64 - last_write_checksum: sha1:65c904d7571606b42c7cf42a25130adadcd6b6e4 - pristine_git_object: 906c73ad3bf7fbe46c57128562cebb56c88eb12f + last_write_checksum: sha1:4bab4fdac25f4360546db9476e6a7cda53296219 + pristine_git_object: f7fda336029ffc120eb1209d0f4f3dc9cbbe2b3a docs/pkg/models/shared/nhiunownedtype.md: id: ce5a1deda5de last_write_checksum: sha1:c1ecf68c064b0020e7ace50fcc364d62c659a77e @@ -9100,6 +10504,10 @@ trackedFiles: id: 9c0f452c8293 last_write_checksum: sha1:8f44e45ef6b6fc90059c22003c793c79a2cb6783 pristine_git_object: 65722f262dc970864cd921d70ef9411d9d5d037d + docs/pkg/models/shared/notifydispatcher.md: + id: 1ec3e14add60 + last_write_checksum: sha1:e665eb974d88559e3d061036d30d99854d5463b8 + pristine_git_object: e2b1860fac91530687752470c2e55acbe80d9e53 docs/pkg/models/shared/numberfield.md: id: 9ee6060989bf last_write_checksum: sha1:590af8132628a383ab9fc22059df728c77171e9a @@ -9132,6 +10540,10 @@ trackedFiles: id: 28e111322add last_write_checksum: sha1:59d3175b3364729202f5a039519611a893beb4f1 pristine_git_object: de34619736791f984c33beab7673b9e444f9f9c2 + docs/pkg/models/shared/oidcclaimmapping.md: + id: 026d088ce024 + last_write_checksum: sha1:172f5cd99d1bcb3f9aae03dddac020493435043d + pristine_git_object: dedbd325ace8a6b521fe300bf32f709674e25cab docs/pkg/models/shared/oidcsettings.md: id: 9435196b39b3 last_write_checksum: sha1:f38b6cb4c2e30f021079d279d92b8983713fc08c @@ -9142,8 +10554,8 @@ trackedFiles: pristine_git_object: 3804df482b866707da579f9c60a33a374c910d12 docs/pkg/models/shared/operation.md: id: 2205287a7679 - last_write_checksum: sha1:df6975efeb6c73e2148fc2794c7592f9577580a9 - pristine_git_object: b6b3b08a54e0769b8dde780a414de4dbe882a67c + last_write_checksum: sha1:8fa99c6f592691b333a5b9190fed607c476cd2e9 + pristine_git_object: e122466ed55a5d0c8fff0aefe5064259c0dd4700 docs/pkg/models/shared/optionsfield.md: id: 6df07750d11b last_write_checksum: sha1:2180b9c1b9baeed612bc416f4b1f2a47fc57cb55 @@ -9364,6 +10776,10 @@ trackedFiles: id: 46d27495e183 last_write_checksum: sha1:a8fb9d970a8985c261ec3ce7702b6c55703b70d1 pristine_git_object: 16437604b4642d625eed4e5d14cf1e11f1fdd22c + docs/pkg/models/shared/payloadfindingdispatch.md: + id: 54e208d47172 + last_write_checksum: sha1:4bcde449c09dd41606481429aeba9ec70d1a1759 + pristine_git_object: ad89b16537642f1b379f215e6a2bdfa44be4484b docs/pkg/models/shared/payloadpolicyapprovalstep.md: id: 432ca4fb23a2 last_write_checksum: sha1:8935714da96d73a4768111c607cadb5d4dc04b92 @@ -9406,8 +10822,8 @@ trackedFiles: pristine_git_object: 1f36d98dd9ace9561c492af915aa802ceaf18d32 docs/pkg/models/shared/period.md: id: baa81aa7b768 - last_write_checksum: sha1:83d59b2999ce4543c01f7cbd73555ccb3045bfc1 - pristine_git_object: 69ce46fae778070f5806066901e30838d930ba5d + last_write_checksum: sha1:da525365ad5410318e68b2e64c2d9b2dccfc1e5c + pristine_git_object: 778745e83e2743543de16250ff8c381edb965cd0 docs/pkg/models/shared/persistence.md: id: e973e821ced3 last_write_checksum: sha1:177ab52b2d2b0bd0c64a00cbbbf2db1be3538437 @@ -9528,10 +10944,14 @@ trackedFiles: id: ba9d6df0ea4c last_write_checksum: sha1:e3d96ef3c4f880eda9931849074d117d4d2c946f pristine_git_object: fbae3d473b65bbdf42feb4ee18b145424922f511 + docs/pkg/models/shared/pkcepolicy.md: + id: b1f999cf9c9e + last_write_checksum: sha1:3520b1d50ed9327a55159d250f0f6ed20ccecb3b + pristine_git_object: d72fbc6ab0027a0ea1a83fbf66653337ec0b0ba1 docs/pkg/models/shared/policy.md: id: 27ad2a0cdf89 - last_write_checksum: sha1:c5439963666d12d1ca83dbc7f5fbb39e311876da - pristine_git_object: 2d519a6cdcaea243a73730402fbf855288ecab32 + last_write_checksum: sha1:87da4f44e35b94190a8caff66433fd1a84a86404 + pristine_git_object: 45f63bcc2546545065aaa014fd95e1a2bda42990 docs/pkg/models/shared/policyeditorvalidaterequest.md: id: abbb95bf6edb last_write_checksum: sha1:70467885881c697d29314123c59494986d7b26a9 @@ -9542,8 +10962,8 @@ trackedFiles: pristine_git_object: 1de5c19b77008afea6ef487c4b783dc515332650 docs/pkg/models/shared/policyinput.md: id: adf018b98fc0 - last_write_checksum: sha1:12b35ba1b4e954c7b4bfa6540681d0855b672535 - pristine_git_object: 6032e2f8043e11058986bc82fa18753b1fa804ad + last_write_checksum: sha1:8f03728c897dcf4d8f9596a29f8c859caf4e9c89 + pristine_git_object: 3cc43524249b4edc064d43e9935636f930279a16 docs/pkg/models/shared/policyinstance.md: id: 385d419d445d last_write_checksum: sha1:b483c9eb1805da6c0dac5482d2eeac7e13adea15 @@ -9572,6 +10992,10 @@ trackedFiles: id: 45daa85a06d9 last_write_checksum: sha1:565b90ee0825deaa8c62323dddb91de19eb24fe1 pristine_git_object: 2f4a1dfa9d2901a2c429601e096b5eb4c7b1519c + docs/pkg/models/shared/policyscope.md: + id: e4db3c0e3027 + last_write_checksum: sha1:58a58f712a55d077fc47d1273dac62293071548b + pristine_git_object: f14c51f76f27c7d8f272f4c8b9216ea2a28e347f docs/pkg/models/shared/policystep.md: id: dd673c20e370 last_write_checksum: sha1:b64dd210e80043b82d04017eabcc3067530602b2 @@ -9604,6 +11028,10 @@ trackedFiles: id: 12982c1760a3 last_write_checksum: sha1:d3afff8bfc0cbe96f03593387e7c7b1f64526807 pristine_git_object: 1ddce7203fe1475779c9b59c565a17568c229e72 + docs/pkg/models/shared/pretoolblockconfig.md: + id: 563cdf1963ad + last_write_checksum: sha1:37a25cb5a0f1803290f2caf5df52a674472d8693 + pristine_git_object: d732ce47b535feebfeda5eaaba454e5de4f97872 docs/pkg/models/shared/previousstate.md: id: e8f4cdd059da last_write_checksum: sha1:617a4620768020355e53d5bbe21d1f52a2e2c551 @@ -9628,10 +11056,26 @@ trackedFiles: id: 5cc1e5088191 last_write_checksum: sha1:4eb0d04dd854a09b2f7bb414915ff952fcaecf3c pristine_git_object: 1db71be09231dcb6d7948e4d7f6aff918187697b + docs/pkg/models/shared/programref.md: + id: 7319087bb121 + last_write_checksum: sha1:2d5b5d3b26e30fe23c5cdc14aec02a6171ee4623 + pristine_git_object: d706747e27261d05c422654e436f208056487773 docs/pkg/models/shared/progressbarcomponent.md: id: d52fe3ffe48d last_write_checksum: sha1:cba2c67eaf5a8bfbb68a3e3610755681f13a7fe1 pristine_git_object: 5bdf4a5d1cae454c5b546362f4e5d570fbdd39a2 + docs/pkg/models/shared/promoteappmanagedstatebindingrequest.md: + id: 6ce849572414 + last_write_checksum: sha1:347a4e00d0be8db45250bfba64034878bd238848 + pristine_git_object: 6f98dbc0f1a80357fb44e4ac251ffe5877fc54f4 + docs/pkg/models/shared/promptinjectionscanconfig.md: + id: ce5bdf6290b7 + last_write_checksum: sha1:234ae80336b7344739e07762d5255e3b2ba70c0b + pristine_git_object: 42eacc53e4b85abf4cf76a70f6768dd7ec3f0367 + docs/pkg/models/shared/providercredential.md: + id: 89f4e630c6b0 + last_write_checksum: sha1:ba33c45251964132fa11a89b4de2f8de186fc99e + pristine_git_object: 5831971116a7bc7a453d56291d5d602825cab917 docs/pkg/models/shared/providertype.md: id: a785ccbfa37e last_write_checksum: sha1:29976f46b695614c28ecf80d4f5a53f4f3bd6f56 @@ -9650,24 +11094,28 @@ trackedFiles: pristine_git_object: 62b8dc86524cd2db476b36f3030b0cf805cc339f docs/pkg/models/shared/provisioninstance.md: id: 831222eb0550 - last_write_checksum: sha1:9ee2aba710f5e8d0078fb69955c8a44e7e5421d5 - pristine_git_object: bdeb7b29f7d9abd09bf12cb6710efdf42ced2dc3 + last_write_checksum: sha1:e195061053c8e921c55dd20aed5c7747c01bd5a5 + pristine_git_object: 3ee1532ce107b523d1f982f7e2645fbfd4c5b160 docs/pkg/models/shared/provisioninstancestate.md: id: 99dd8de67279 - last_write_checksum: sha1:4668cbddd6b79055ffeb9c73580571bf15601fc4 - pristine_git_object: 604b4ef6dc8be3ab5c106857d796ee78b0a5f2aa + last_write_checksum: sha1:316faf433d5b3a806d365afb5d81058c18cc529a + pristine_git_object: 26ea1eff700e080856bf069e47fdec034a280869 docs/pkg/models/shared/provisionpolicy.md: id: e455892cf48e - last_write_checksum: sha1:f9afc5362a5614752eec5f715a4b2ec5eadf38d0 - pristine_git_object: cff4aad12ae22ef075c2af695292f919369d846e + last_write_checksum: sha1:8322d35f05f5585ce207d5308b2968c024e09094 + pristine_git_object: 46f829b69d1f7ac048eaf169cc9a3af8d747fac2 docs/pkg/models/shared/provisionpolicyinput.md: id: 9c985e0b33c0 - last_write_checksum: sha1:f4ceaa8c5f083e71090f9c79657f0c7ade79e8b7 - pristine_git_object: 9fd9c6ca44cda7cfddc7faa48c0c27a2120d2d00 + last_write_checksum: sha1:c23f29c6ff704d8cce67b8c7d8fc0cd55d1e5fa5 + pristine_git_object: 5bbdcf435306af3c480cc1baa22a3e3798160507 docs/pkg/models/shared/provisiontarget.md: id: 514747660c6f last_write_checksum: sha1:e5c3653523ba83e59c9399773b7f93c00fdc6ce4 pristine_git_object: 7e3bafbf1ef96fba071caf7917d8280e603e2542 + docs/pkg/models/shared/provisionwaitingon.md: + id: 9c56c14ce457 + last_write_checksum: sha1:14e0336f159a164ecc5b9e96e64b5e3e0b65902f + pristine_git_object: b28152b2d350dfd74c1db829376c65c2ea0161fd docs/pkg/models/shared/purpose.md: id: a09b30336b28 last_write_checksum: sha1:933ecf75151223c0338efd8f90f3f3ab83bdeba9 @@ -9684,6 +11132,10 @@ trackedFiles: id: 232eb3f3f3f3 last_write_checksum: sha1:5ee891ae971c52d89b4faee7b70e344c9bf99313 pristine_git_object: 350ddcdd8e3f6da484921bf4bfb860db26779695 + docs/pkg/models/shared/reason.md: + id: 612aa74d21b5 + last_write_checksum: sha1:0287f13f730cd939d6dbf67eeb99bde8568cd882 + pristine_git_object: 8e491734a22f6a47a0cd2050fa23294034411d9e docs/pkg/models/shared/reassignaction.md: id: 7378a3cb7a2b last_write_checksum: sha1:e1662695636f4677d2aabc222d5af5442d5cb61b @@ -9704,6 +11156,10 @@ trackedFiles: id: 32d7afd92cb1 last_write_checksum: sha1:1125621f53094bef62a6bda50d8493a4ccd8615f pristine_git_object: dce90537e1f1f6ca5465389327a31f367e26503e + docs/pkg/models/shared/recordtype.md: + id: f65d7efbbc03 + last_write_checksum: sha1:587cddac6e790a41690ca0b978f44617feb7b91b + pristine_git_object: 16401d5e7155ef2512265fe13c1f9fd6c5a3c66a docs/pkg/models/shared/recoverypolicy.md: id: 81b92e3297ca last_write_checksum: sha1:14c99795b622ee41f161a95d98803958155952df @@ -9766,12 +11222,12 @@ trackedFiles: pristine_git_object: d7ce58165ae31302966529a3d1783e1b5800a700 docs/pkg/models/shared/recurrencerule.md: id: ec460cfe8f8e - last_write_checksum: sha1:f49eec44950f59c012332a3d8d031fe6896ffd32 - pristine_git_object: 6e179b4e84cce4ff32f57566b3f5645ed5ef7e87 + last_write_checksum: sha1:14236e2a7983ab71fa2631d3a5286c3e2a7e8ad7 + pristine_git_object: 266b4da58b22be20f5e937277965be02e8a30628 docs/pkg/models/shared/recurrencerulefrequency.md: id: 7034daba3187 - last_write_checksum: sha1:0aca20df4ddeba84dc2ea92b08a3d98a1f985f7b - pristine_git_object: 5362138af6ebca3d6170d272fb2fdc48eec9db74 + last_write_checksum: sha1:3ed4e5c13252cd6ce10666a4dbb2ad118fd79486 + pristine_git_object: 35a26697da740db27240fddcf852e9661813fb8a docs/pkg/models/shared/referencestrength.md: id: f997d22e1b6d last_write_checksum: sha1:5318d57f64bfa687c47c0dd93162d668fa18e7b9 @@ -9860,6 +11316,66 @@ trackedFiles: id: def7db68332b last_write_checksum: sha1:2605831aa04682ecf39de05afb98757959cf1237 pristine_git_object: 4cb295cd824bbaa609466ef5a72ddce556ab74c7 + docs/pkg/models/shared/report.md: + id: c246b1ed5e6a + last_write_checksum: sha1:5304716ce39e3c7d4ff598283813fbb93dacf9a7 + pristine_git_object: 2a7cd23ef4faea6a3ebce6cfd29cc094a5dbc10e + docs/pkg/models/shared/reportingservicedeleterequest.md: + id: 37b4f86f1169 + last_write_checksum: sha1:367cae513e5443accb0f3d5865aee2693f4d898f + pristine_git_object: ae2f6b8de8b2c318104a5fc6241dfac661e7b3db + docs/pkg/models/shared/reportingservicedeleteresponse.md: + id: 8d45aa6259f6 + last_write_checksum: sha1:0ea78f4fb205976a356cad6770192b88ac720ae9 + pristine_git_object: 798ade82813ba01f4d528db54e72d4d2a45af209 + docs/pkg/models/shared/reportingservicegetresponse.md: + id: 255454ce221d + last_write_checksum: sha1:63bbe46bfe992240fb96bf2183f586fd27f98bda + pristine_git_object: b6a48db85da4948e4430236a63913870b32da0aa + docs/pkg/models/shared/reportingservicegetrunprovenanceresponse.md: + id: a9497f50d1ab + last_write_checksum: sha1:a33bb1801824ee261662cebe962060805abf8ae7 + pristine_git_object: 4e890055e45f290c110b29f11c694d10fd12c748 + docs/pkg/models/shared/reportingservicelistresponse.md: + id: 64d83d48d966 + last_write_checksum: sha1:83419e5c5e0a04f14a5af938af0ec4267250b8f5 + pristine_git_object: 967bc1b81d8f91ac222b4d728275bd64d4908610 + docs/pkg/models/shared/reportingservicerunrequest.md: + id: cee256c43fde + last_write_checksum: sha1:0f3847f68ef4836bfadadee6f1efc6d8e0bdfc5b + pristine_git_object: 77caa5a0f63b633b6cf8d8f796690d8d0816b98b + docs/pkg/models/shared/reportingservicerunresponse.md: + id: 2b58ecb68357 + last_write_checksum: sha1:bafa11e8f0ed1c2aec6f120ff47873148690fca2 + pristine_git_object: 1f484e3d76adc9a0c7fbccc46339d6256fb5dbb8 + docs/pkg/models/shared/reportingservicesaverequest.md: + id: b954dd479c6a + last_write_checksum: sha1:1d8ace4f5dc1ddeeafaa63c7b21dec63e7d97044 + pristine_git_object: 6db664d76b8a79ada7478815806e3d161a002dc4 + docs/pkg/models/shared/reportingservicesaveresponse.md: + id: 18cdd5be0362 + last_write_checksum: sha1:110fa82f74b7fc15b7f292c7c641248ba19e8f52 + pristine_git_object: 65a2436fae71e8e537f853c9240bb410e99f6151 + docs/pkg/models/shared/reportingserviceupdaterequest.md: + id: 1e2b7cbfb7ff + last_write_checksum: sha1:99ca03abf04b75e1d8e1a256930bea0945065ef5 + pristine_git_object: cd27ec780a38e26fde08e1b2852f5cf24ecec82b + docs/pkg/models/shared/reportingserviceupdateresponse.md: + id: cc300bdde485 + last_write_checksum: sha1:01ac66e149e3a95da96fde77aa3e790f58a3b5ec + pristine_git_object: 17c8ce94c7a0273d76a77cbe0825fc9b0c320bfb + docs/pkg/models/shared/reportrun.md: + id: 80a4b2eb1d8f + last_write_checksum: sha1:85795e23ea2c32864120a1b3a1949403d79b21bf + pristine_git_object: a5c2dfd12142480edc0d69e16394e52fbad9e3d6 + docs/pkg/models/shared/reportrunstatus.md: + id: 95f5c60a0baa + last_write_checksum: sha1:7ae8027e8d41a443fa0594afc0e1eace52684622 + pristine_git_object: 0b28a4638f5905fa38d192400855f147a62a9b03 + docs/pkg/models/shared/reportsource.md: + id: 0035b5b2c751 + last_write_checksum: sha1:43c12303c7df1ceb8d2cc8bbfe230a91bc4fecb3 + pristine_git_object: 2fadf63278ffddb79f95861b781fd3aea569267f docs/pkg/models/shared/requestableconnector.md: id: 1061c31df80d last_write_checksum: sha1:06da2baa1616f8d290ff97349693d5ddddb43995 @@ -9874,8 +11390,8 @@ trackedFiles: pristine_git_object: 0751e0e95b160b841b27bff8dcd92bb1b5673bc3 docs/pkg/models/shared/requestcatalog.md: id: 3ef7d7d0daef - last_write_checksum: sha1:5d45c49f23442adbb11d11c53ac5d2542acaf499 - pristine_git_object: 550f3ffc419686ae8c2af7787500b7399e6aec6a + last_write_checksum: sha1:d91fd822ead0e9763360d80970ee676bacc01691 + pristine_git_object: 548c9f6d593ca3b1c6042842337671be56927737 docs/pkg/models/shared/requestcatalogexpandmask.md: id: e2803c0b5a5e last_write_checksum: sha1:f2886b12fa32287f1bedfcbb023c03e51159393d @@ -9902,8 +11418,8 @@ trackedFiles: pristine_git_object: 68d669c8c028264a150d8e2a50b7c2f2f7cef400 docs/pkg/models/shared/requestcatalogmanagementservicecreaterequest.md: id: 6200b1a292c4 - last_write_checksum: sha1:f6e6c87b4a14933d2ec8ee0de06266ef82660319 - pristine_git_object: 4ee1abdd96e00330eaad3888ca5675d1df3c615c + last_write_checksum: sha1:173906d886947d7c31f6439d468cc2529c0aa809 + pristine_git_object: 90c2bc3ba7cdc216b01153eb789c05ca2803da87 docs/pkg/models/shared/requestcatalogmanagementservicecreaterequestableentryrequest.md: id: 18a9d285b120 last_write_checksum: sha1:16b8246b666627f0abc77c919c39565587db5a9e @@ -9916,6 +11432,10 @@ trackedFiles: id: 0ff22853d8fb last_write_checksum: sha1:8a7a3db444e6cc073abea1c77a0062797e42c612 pristine_git_object: 62cbdf192d96b0b4a2560174cb64405a8dcc54ef + docs/pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md: + id: 25cac22fd1d2 + last_write_checksum: sha1:2f88d0f651f95496cf407651eb1d425a88ffd584 + pristine_git_object: a7c33ab8c011a5c9ad2e6fca2c8fc7f766c143be docs/pkg/models/shared/requestcatalogmanagementservicecreaterequestunenrollmentbehavior.md: id: 0bcadebac538 last_write_checksum: sha1:6e5d6cff7c11de54cbbd3f4ad50c612e28d72013 @@ -10020,10 +11540,18 @@ trackedFiles: id: 65f57211aac8 last_write_checksum: sha1:401c1d85db23b1f2a4a5dee4f4026d1ea4004867 pristine_git_object: c569adbcf912d0868a92d052619ab6f841001b09 + docs/pkg/models/shared/requestcatalogtype.md: + id: fc88c180b3f2 + last_write_checksum: sha1:5e06fd37481824b1f3b4c4edc7883df345a4de3d + pristine_git_object: d76027d5790610cd57af723e4b529535d3accff5 docs/pkg/models/shared/requestcatalogview.md: id: 3938f974384a last_write_checksum: sha1:9e7aca8bee1ef3cb5099bc0b11bf3d88bcd8a618 pristine_git_object: 48eef5a4bf3f14c5bbcead206da10eed8e66c0bf + docs/pkg/models/shared/requestcreatedpreference.md: + id: 456499ee1620 + last_write_checksum: sha1:c2b23af9179f8a7a44c3df4d95130bdc86ff72a3 + pristine_git_object: 041dbd811be223e8d01b1ed42e2120a0bd1022a5 docs/pkg/models/shared/requestschema.md: id: 372a97809ff9 last_write_checksum: sha1:edca6c1293e39f5ac9c3b56b23eb138b42a0dae3 @@ -10090,8 +11618,8 @@ trackedFiles: pristine_git_object: fed762baab2a036a86d16f10f2b24e39ddcf109e docs/pkg/models/shared/requestsettings.md: id: 1bbb9cc4c2b8 - last_write_checksum: sha1:47ebce08b0a8ed755cbea81ff71508a3078aaa18 - pristine_git_object: cf3a95cf6a5ac085e84a61cc75065f634b7bd1ed + last_write_checksum: sha1:7fa793718775a355d8870de9b4738c651cca66fb + pristine_git_object: 3154d53e72fa136b3e415483ee6956ee99176082 docs/pkg/models/shared/requiredagesuite.md: id: c19d698918ce last_write_checksum: sha1:37d43f908b0e4d6adc8bcd34a3e72f2d79537009 @@ -10134,8 +11662,8 @@ trackedFiles: pristine_git_object: 013183d09ebe3c255cae0c3982ebc13a20d78deb docs/pkg/models/shared/resourcetype.md: id: c3ca0f88f959 - last_write_checksum: sha1:907dd7af18599b5fa4acf23b34766fe586fa5f16 - pristine_git_object: a86fe4125a41be43910eef7a198aaa268b63bab5 + last_write_checksum: sha1:a299e6b379de4f077b28794b62543109db56c6c7 + pristine_git_object: 9cb191e107b2a92741d6289fedbe3438b66c51f0 docs/pkg/models/shared/resourcetypeidref.md: id: 439452ba68de last_write_checksum: sha1:1f69edddf46c7398e58bfb6fa230bd3e40295e71 @@ -10224,6 +11752,14 @@ trackedFiles: id: c9bd96a9c81a last_write_checksum: sha1:03bd37b03f3c4110a9c41ffd2826cf89e97813b5 pristine_git_object: 1132f1689a50b392170216476f0974fdffb1137e + docs/pkg/models/shared/revokegatewaykeyrequest.md: + id: a223c46bdb58 + last_write_checksum: sha1:ab13f885ed82de8d5bbd694c316255188e001d9e + pristine_git_object: 9f41a7e123bbcab84c9a20fd44458767c0ab5b94 + docs/pkg/models/shared/revokegatewaykeyresponse.md: + id: 0d651143a4e9 + last_write_checksum: sha1:5ee997c3ff6b55fc5cf160c81db6abf162efe9e7 + pristine_git_object: 74aa3f91f0b916e16a9bec894879c1a34afdd336 docs/pkg/models/shared/revokeoutcomes.md: id: 3d812ab92f79 last_write_checksum: sha1:d0b913b4b9073e0f06adda3dc9620225e09925af @@ -10278,8 +11814,8 @@ trackedFiles: pristine_git_object: 5a6c508c88a150b0ac104cd6a811443ca34c404d docs/pkg/models/shared/rule.md: id: 48bb05087053 - last_write_checksum: sha1:14da440a5f9f805a95e3d27aa24330c90a62e398 - pristine_git_object: 41589625f208de3f207d952509ea74a628a2996f + last_write_checksum: sha1:d8178f50d040abe396e404f80e5a7f379ff3e32a + pristine_git_object: ed774fbb51f48275c674c1b5c7e9d3144ae960ec docs/pkg/models/shared/runautomation.md: id: 866cca347022 last_write_checksum: sha1:68158bc1c4697e9d6ffc9f9e0e84eb4b8dd324e3 @@ -10292,6 +11828,14 @@ trackedFiles: id: 9ebbeb56524b last_write_checksum: sha1:5255bb8740b819e7e1ede9b01885148956934947 pristine_git_object: cd86fa705bc76fac0f4e56658890a8a2ba005be2 + docs/pkg/models/shared/samlattributemapping.md: + id: 146ab6f97e5b + last_write_checksum: sha1:c96e4c275854a112638f3de3ef47a7e418b9f2d6 + pristine_git_object: cc873abe2721b50c18f4aabdde97bfaaad3e6d4e + docs/pkg/models/shared/samlmetadatafinding.md: + id: bc79ea21a4e4 + last_write_checksum: sha1:07b7d5d1941881a3fb631ff6c98d90e6b1d80639 + pristine_git_object: 3580ae5a95a332ded014e7e31aec52ac3c52a2f2 docs/pkg/models/shared/savetovault.md: id: 50db49044c34 last_write_checksum: sha1:62125fcfca673cf044a00d80a7cf811954996ff6 @@ -10312,6 +11856,10 @@ trackedFiles: id: 711129f855f5 last_write_checksum: sha1:3cd29341113fbf96da66fe3da6f4206ffafefc67 pristine_git_object: 24f296d7cc355919346e7ca245f84be923a0a9f8 + docs/pkg/models/shared/scopeobjecttype.md: + id: 4bc505af04e5 + last_write_checksum: sha1:fee1f6b706eebd2d920c24748e4350374da2c6c6 + pristine_git_object: 409311a6639343c5040818e113819c90ff68372e docs/pkg/models/shared/scoperole.md: id: 19e6192b226f last_write_checksum: sha1:44cc9b44226639f863810b919e3d373e7704e6e1 @@ -10324,10 +11872,18 @@ trackedFiles: id: 070cec06b816 last_write_checksum: sha1:bf461494ebe2357c83a372b7109f4ad82274961e pristine_git_object: b9c821ab72dc835744ac3e2b394a5da5f669e900 + docs/pkg/models/shared/scopeslot.md: + id: 07efdf185cc7 + last_write_checksum: sha1:bc49f50a65d3338d0f96fbf2546a642768a12799 + pristine_git_object: b70a4a93419dddbed04e908852843556b2b8759e docs/pkg/models/shared/scopetype.md: id: 6b4d47e57d81 last_write_checksum: sha1:92b3d8c72feed75ef5ea2b2dd022834358a5adcd pristine_git_object: 9e9b0bffe7883bca1cff82a499cbe109f4451288 + docs/pkg/models/shared/scopeview.md: + id: 25a985c37632 + last_write_checksum: sha1:49e0eeca09c683d6c71a5344e1eee081f3282b89 + pristine_git_object: f09167fe678378f00b06fde25fe8b1e4f9e3cdbd docs/pkg/models/shared/searchallautomationexecutionsrequest.md: id: 9e9831800741 last_write_checksum: sha1:c896f150abd00a0c3a5996f130887f7448ef6226 @@ -10362,8 +11918,12 @@ trackedFiles: pristine_git_object: cedc56c057e2ebd307f5d15608e1f6ec09be6e44 docs/pkg/models/shared/searchappresourcesrequest.md: id: c86ec47301b6 - last_write_checksum: sha1:1b97556573d36a1182613397066e30c9c11f19c9 - pristine_git_object: 96f170129e5143b4785e4395dddc21607a77ebf2 + last_write_checksum: sha1:e421f0300b2fe3bb68ada33198506c6241e7215e + pristine_git_object: eea682954567e99cb6e96a6b82f391e36a048418 + docs/pkg/models/shared/searchappresourcesrequestagentstatuses.md: + id: 5f5a84d107af + last_write_checksum: sha1:de46f1986b4fa2dbe167453dd2403ceca914f351 + pristine_git_object: 243e015808c345f09d7a920b962d3353ba62e880 docs/pkg/models/shared/searchappresourcesrequestcredentialtypes.md: id: 39dcc8534b15 last_write_checksum: sha1:93e52d9c6a41251bb1fe95add87b3e011a29480e @@ -10462,12 +12022,12 @@ trackedFiles: pristine_git_object: 995ea8dd08636b96513974e00c85cb9887026978 docs/pkg/models/shared/searchcohortusersrequest.md: id: 6a19429b97a4 - last_write_checksum: sha1:102303a439e28ca89784f035538dacf614aae418 - pristine_git_object: 2ba1f0686d8b8d6af7eef05dfd30a68d63b770fd + last_write_checksum: sha1:1874988a882dc27ee1504115509f974feccd4e88 + pristine_git_object: 165556728267d7d2c5d510ff4b7c42f6db4feaf8 docs/pkg/models/shared/searchcohortusersresponse.md: id: 38726be51dc0 - last_write_checksum: sha1:a75a0db05020df228f171d88f8dff749290a56a1 - pristine_git_object: c90042a57ac2081c238cdb372ef06bcf007d7cb6 + last_write_checksum: sha1:2a5be04fbccf85968351cc277b4bba800d6db820 + pristine_git_object: e4a320dbe7748bd64671d98f90fd23a7ca59fe17 docs/pkg/models/shared/searchconnectorentitlementownersresponse.md: id: dcdea15e42f3 last_write_checksum: sha1:2565784180ffc96f83cd4e0b0f26d811d7b760d7 @@ -10510,8 +12070,8 @@ trackedFiles: pristine_git_object: 0da0e4931948f80cf6e8032358c36cf9bc8273a3 docs/pkg/models/shared/searchpoliciesrequest.md: id: 8528474d3153 - last_write_checksum: sha1:3396e1592834c155436a71f1abb6726ea94d065d - pristine_git_object: 56d4f6ff509ff599276fd8069a48087e453f15e7 + last_write_checksum: sha1:634edfeb9c39481d1642135153889c0056dc387e + pristine_git_object: 3140dec49667364ed3f74e0e6400a66405082f86 docs/pkg/models/shared/searchpoliciesresponse.md: id: 845b427cc319 last_write_checksum: sha1:fecd1c04eb6888026c60feb856b4a10e6a65c9b7 @@ -10554,8 +12114,8 @@ trackedFiles: pristine_git_object: 1064277bf087d8ea6eb0d88a0539ab5fb99b25f3 docs/pkg/models/shared/searchusersrequest.md: id: d9994f3097dc - last_write_checksum: sha1:a2ddcdd8349f4e6a87318d61f8d5788bcc5c333f - pristine_git_object: c0eecbfa6530eca2229ff68b74fab4b362d08149 + last_write_checksum: sha1:ded24001bcf405cc3b0669c07c92e7302b5adbea + pristine_git_object: 270701f31be4e342cd115a89f88fa7790770a818 docs/pkg/models/shared/searchusersrequestuserstatuses.md: id: c46f5ba9d052 last_write_checksum: sha1:86267447dc3ffd1da41acc0ddb51f1aaf5109cc0 @@ -10572,6 +12132,10 @@ trackedFiles: id: e0509fd6a77e last_write_checksum: sha1:482210fcfb925aa8861f4c35f8da8ef4aad3b607 pristine_git_object: 546f6596561215cff8cb6cb0f61baae030374bbc + docs/pkg/models/shared/secretsmaskingconfig.md: + id: 4dbc572d95ea + last_write_checksum: sha1:4d5f34abc798bb61a75a3e575a44195da60bcd70 + pristine_git_object: f3b5dee5cc3bb0b66c663e442e9680c5ada4b525 docs/pkg/models/shared/secrettrait.md: id: d605720617b0 last_write_checksum: sha1:f21498244104ea598f4ad9509bee3801f38e150e @@ -10894,8 +12458,12 @@ trackedFiles: pristine_git_object: bbb6c7f00f89d34f7ab0e9955f2cdc95441f0007 docs/pkg/models/shared/sessionpolicystepuprequired.md: id: d60e855e4c61 - last_write_checksum: sha1:b099f31bc8c56571f5ff810854af673c1a80a3aa - pristine_git_object: 15816b6adbb7073a3cd38acb7e4cd6fe500109a2 + last_write_checksum: sha1:175da4787d81a49ddd33a7c20950e194155efc49 + pristine_git_object: c35f912964df498b1579628a3067b797f14b7bcd + docs/pkg/models/shared/sessionpolicystepuprequiredlevel.md: + id: eb4bdaa986d8 + last_write_checksum: sha1:a8d7172b98e6065346fbe34157b0b7dd6f8e0477 + pristine_git_object: 75a24bb2a4b4f6cdf9d07ad73b431865097fd3f9 docs/pkg/models/shared/sessionpolicystepuprequiredtypes.md: id: 199f8f9ba749 last_write_checksum: sha1:270e7ede5a8a601a4be76dc9ebe7426d025ddf69 @@ -10988,6 +12556,18 @@ trackedFiles: id: d2da187456c9 last_write_checksum: sha1:2fe42f13fb3583cab9cc7232ed4b55c0bdf274f7 pristine_git_object: 14b5c08781aa00e552d4e1d6582cd1dbe30dfeeb + docs/pkg/models/shared/setprovidercredentialrequest.md: + id: 7355a5d16b80 + last_write_checksum: sha1:6b853d100639a8cf0137a0d6f81ae3c826463d2f + pristine_git_object: 64631dc01a1be8d61ac568f325620e98432dbb85 + docs/pkg/models/shared/setprovidercredentialrequestheaderstyle.md: + id: 23f8a0906c3e + last_write_checksum: sha1:59ce98ccfa697520cf833672dda96a203c03d6f0 + pristine_git_object: 9b7e1d47e185f5c4ec5f8b4afcf243244c081686 + docs/pkg/models/shared/setprovidercredentialresponse.md: + id: fb0039dd4f94 + last_write_checksum: sha1:d1848d8a028164e5b9d04c4779283575ffdc1fd6 + pristine_git_object: 3213b3e80ee7280136e48acc46d436db85276a3b docs/pkg/models/shared/setseverity.md: id: d37eb20cfdbb last_write_checksum: sha1:c93b122f77272098ee540a4be9e562dff58aac00 @@ -11142,8 +12722,12 @@ trackedFiles: pristine_git_object: 8b522324e8d2402cb3d86b0b09d6c240d07e6e2f docs/pkg/models/shared/slackchannelsettings.md: id: 0739ea7deaee - last_write_checksum: sha1:6029ef2e1951d6ea45d69b9d68e8d83d24634071 - pristine_git_object: 423c92567fc53d0617e6499a92cd930f08242dfc + last_write_checksum: sha1:da5ae8ff4b48d7c18b33c9cb9fbfff8ac5012e5a + pristine_git_object: 97269d12fd4bb0601ce0d0fd281ba4d4f0281666 + docs/pkg/models/shared/slackchanneltarget.md: + id: df171f07656a + last_write_checksum: sha1:8a980732c15eba26aedb8101de27138b971e5a2a + pristine_git_object: 4fd55f14830f7336c1288939030b9531376d530f docs/pkg/models/shared/slacknotifications.md: id: 16204da759e2 last_write_checksum: sha1:865f9c8bc5e5372f509be8038e4e5b4a9457c3dc @@ -11152,6 +12736,10 @@ trackedFiles: id: 7b24430173e4 last_write_checksum: sha1:97f3e7a5ff2f507f75daca9bd4f573d5a9c9c58f pristine_git_object: e8e5c31acc18d12021f458a363b8ba61e3100789 + docs/pkg/models/shared/slot.md: + id: d1506369062b + last_write_checksum: sha1:725a8dd110a2d4e1e0653874e79eaf44eca7536c + pristine_git_object: 9b4ce5bc6ad7959dcc291ae44e6dc9b6335afa53 docs/pkg/models/shared/snoozeaction.md: id: b95e243ad977 last_write_checksum: sha1:6fdd4654595bc8f566fbc48316c0c6e5225e23a9 @@ -11196,6 +12784,38 @@ trackedFiles: id: cdc8894eaa85 last_write_checksum: sha1:232e05388fd4e9ff69bf23c9019530196802e688 pristine_git_object: 41412b0acb2f9303a0bd1bf10d095f889141b708 + docs/pkg/models/shared/spendcontrols.md: + id: 4ccdb2baa571 + last_write_checksum: sha1:1f4c32465c50616f6bb74cadde97038ac28f5a94 + pristine_git_object: 0cc56a06f3bbf3246c7e919c15f90443437fe8a0 + docs/pkg/models/shared/spendcontrolsperiod.md: + id: "667854740724" + last_write_checksum: sha1:22975918e6a8e379dc27b4bc1d98c10d8713697a + pristine_git_object: ff9ddf9367949b01ebbf6f473d1fc7c88fd4506c + docs/pkg/models/shared/spendextension.md: + id: 360b31c84ab0 + last_write_checksum: sha1:6d454b7fecc52b130bfcdf979ee31fce16f64933 + pristine_git_object: 22f1b3db23ac60a7ef2503e640927809f5d11cc9 + docs/pkg/models/shared/spendlimit.md: + id: ebb6415292b2 + last_write_checksum: sha1:d77f208c6d093cf460647da7a39ec6a9375fc1e1 + pristine_git_object: d0ea4b3c2ddf21593338a315b297cc0f62750a98 + docs/pkg/models/shared/spendlimitamount.md: + id: 861d60b47901 + last_write_checksum: sha1:e50d43402185bc8595a78ca91e0c21979eb9ecf4 + pristine_git_object: 89ff8f0785404ceb4d792201e268814fd290ef41 + docs/pkg/models/shared/spendlimitblocked.md: + id: 36bacae38939 + last_write_checksum: sha1:23584b440ec93514c0e8f77f57f59ad7cf15cf63 + pristine_git_object: f8da576048f533b36278dd4c0bac98a757646cef + docs/pkg/models/shared/spendlimitunlimited.md: + id: 48793d0db94b + last_write_checksum: sha1:1c6a22e2f252ec093dd0c8306ee0b948f7c028e9 + pristine_git_object: ea285e3b67c71ab1d8f2791e70d9b374f8bac3da + docs/pkg/models/shared/spendsuspension.md: + id: b48a12ffbecf + last_write_checksum: sha1:3f62c82eae1b7247ea12e57103d0d2449a3d7e57 + pristine_git_object: 63e4ad5b133e84f97fc7c097ffae9847a165d1d9 docs/pkg/models/shared/spiffesettings.md: id: 79c8ae784b21 last_write_checksum: sha1:44525152f49294cfdded7bfe6174b62f6f585ee2 @@ -11312,6 +12932,202 @@ trackedFiles: id: d3289b2893f2 last_write_checksum: sha1:4e376d55dd27bb28d59d78f47106f76d9a941776 pristine_git_object: 32abe1cc747bec3cdbe8caac9f247ab7b5a625c7 + docs/pkg/models/shared/ssoapplication.md: + id: e514f33f9158 + last_write_checksum: sha1:74e61b52eba81eeb5828f0b9dcb4f7d753dbaf0f + pristine_git_object: 16dbe691d1a2b760c07bfb8a10b89a06bd47cd87 + docs/pkg/models/shared/ssoapplicationhistoryentry.md: + id: 25bf13494035 + last_write_checksum: sha1:4cd4d127007ea5695716dd79f34ce6e739ed972c + pristine_git_object: faa66d2bbb9d33b6b0496ba0c05a4f79867bcf9b + docs/pkg/models/shared/ssoapplicationoidcclient.md: + id: "1719754564e8" + last_write_checksum: sha1:02651077ba97856dff1b0b62cc294ae1a3c69450 + pristine_git_object: ce15c90ec8480fc3264e5c988498979b75b3e8d5 + docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md: + id: b2dc59e9fed0 + last_write_checksum: sha1:a10a23dc7d24ed93b9572e8910c4600fac675ccd + pristine_git_object: b49839f5ecea33165445ec97bf99e65147ef8194 + docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md: + id: 0afef85c73ef + last_write_checksum: sha1:ff84c98ab8ded7b7b882ac93af3de71b970049d0 + pristine_git_object: d61dea7233cf38e69f3eb7ee68708baf50e00dc2 + docs/pkg/models/shared/ssoapplicationoidcclientauthentication.md: + id: 0918b1a1e567 + last_write_checksum: sha1:7e45ce01288952e2fb8fb4a5bae0b6849031adc9 + pristine_git_object: aeff6e23ed14292f8acb8cc0ee7d9dabeec16efe + docs/pkg/models/shared/ssoapplicationoidcclientauthnone.md: + id: 8f4722ea9c68 + last_write_checksum: sha1:a2606de7dc7afa3108831cd0527c6bf924ac2ca2 + pristine_git_object: 562fced96004ff1eabd84a5cbcd77e191f7d219a + docs/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md: + id: 5b135d5a2ea8 + last_write_checksum: sha1:77ed33446e6609542adb02eddd16c9b0019548b2 + pristine_git_object: 3dc426c35999f93fbf3a9f77c33f66635839c4b5 + docs/pkg/models/shared/ssoapplicationoidcclientconfig.md: + id: 8fb3b7302d06 + last_write_checksum: sha1:0756694ab8304b2a69204ca0773ea4fcbf9941c2 + pristine_git_object: ccabfdc127b6133dfe3a363e1279074d8b754739 + docs/pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md: + id: ac5ca48dce5c + last_write_checksum: sha1:58916e2e36f0e19b42421a8b42bddbb153910b37 + pristine_git_object: 52fd0e4519153b0d2616ea3bd60007b7fbb85ef2 + docs/pkg/models/shared/ssoapplicationoidcconfig.md: + id: 57b8691e7502 + last_write_checksum: sha1:e3946337470715cea207066feb6af36a836f076d + pristine_git_object: 1368c70e98031be6353897dfd58fe42e3943d98e + docs/pkg/models/shared/ssoapplicationsamlconfig.md: + id: 98088f73cdfb + last_write_checksum: sha1:99d9b60c5eb609d3dc59775374911e87f4ba054e + pristine_git_object: 15355be5978964eeb530f038b418d03d70592cd3 + docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md: + id: fdea25c200bc + last_write_checksum: sha1:cf77d4287f4920945734526e4fc91d9894aa1a18 + pristine_git_object: abf7f7332c820310a8cdb4046e2867553683fedd + docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md: + id: f96efdc7ab81 + last_write_checksum: sha1:5d463eb24a6ce4c2377d93240cdc81506865a297 + pristine_git_object: ec90a702a49874309dad42f93574ff9c6f2269dc + docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md: + id: 3d0566c0d65c + last_write_checksum: sha1:fe5828ab7dd7397fadfa2a4e7648d1ffeb19cab1 + pristine_git_object: 5c0ddf819c8df6df3850686aa9659f10be91f1da + docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md: + id: 94700ec6f873 + last_write_checksum: sha1:2138c23b0ff3c20d1a967bdd5b6bfe699924acfe + pristine_git_object: 15a6cbbf58141070dce7c91a492ef9aec7bb9ca6 + docs/pkg/models/shared/ssoapplicationservicecreateclientrequest.md: + id: 4ef816951796 + last_write_checksum: sha1:d7e8e959576a2e566d259ccf5a80e8aee1d99ab8 + pristine_git_object: 071f84a2ec105639453dbb12729381a2758ea79c + docs/pkg/models/shared/ssoapplicationservicecreateclientresponse.md: + id: eea5ea2d9076 + last_write_checksum: sha1:803611affb48de0ea3cadfaa071fa1495b4b1494 + pristine_git_object: 40bcea0ae832adbfc7c8a0385a470710fdfe67e9 + docs/pkg/models/shared/ssoapplicationservicecreaterequest.md: + id: beb952fca532 + last_write_checksum: sha1:3aef485afb56c3bbd39a9ac1fbe39eb0b402659a + pristine_git_object: 030250237db65567208706a68f39e97652cfee65 + docs/pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md: + id: 5752c4a5f5fb + last_write_checksum: sha1:96faf0c1e45b69dec25e21843c735c289002aab0 + pristine_git_object: f6f51c4bba9ac8f7ef5f0fd814f48dae335bebc7 + docs/pkg/models/shared/ssoapplicationservicecreateresponse.md: + id: c4d09ad3844a + last_write_checksum: sha1:c2b59cef2327dabe651c6b5c5153e158765b56df + pristine_git_object: 8cfaada0ccb52eb5a357b4805a4131ba53530700 + docs/pkg/models/shared/ssoapplicationservicedeleteclientrequest.md: + id: d4dade95922c + last_write_checksum: sha1:b15dc95476f4ce33e3aaecb6bbc58efc03d0810f + pristine_git_object: 50cfe24d9920d3938d9b79ce8f729937ff5f64fa + docs/pkg/models/shared/ssoapplicationservicedeleteclientresponse.md: + id: b9a85f7dfda0 + last_write_checksum: sha1:fdfc9d253bec17dc6cd0cedc117c1348cc3e35db + pristine_git_object: 4c77f1bdbe2ccf027f8a140ad8140f431727ebeb + docs/pkg/models/shared/ssoapplicationservicedeleterequest.md: + id: 3f4a37587d6a + last_write_checksum: sha1:52ca9cf0b1c3322b2be30393128b74777f4e3ab7 + pristine_git_object: daebc0984c1aca6aec1efecc5a93837dd2dba4db + docs/pkg/models/shared/ssoapplicationservicedeleteresponse.md: + id: ee191e1727d5 + last_write_checksum: sha1:9c911f7c3eb0c3b2c6ca754ae3be8bfdbb01545d + pristine_git_object: 17c499d7a5995632f55c4e9025d28f0bf81d573c + docs/pkg/models/shared/ssoapplicationservicegetresponse.md: + id: 0252c6aeacd7 + last_write_checksum: sha1:c90ace03e8fd635dfc54354f7da03d8f634b8d84 + pristine_git_object: 421b6cd8601eecddd58d0b7b6755e9169a05a61d + docs/pkg/models/shared/ssoapplicationservicelistclientsresponse.md: + id: d350f8add526 + last_write_checksum: sha1:be884a7d447e63813ed1a865f3c189bec5401813 + pristine_git_object: f05a2229f3a1ca807120f4044f74c35c65bd804a + docs/pkg/models/shared/ssoapplicationservicelisthistoryresponse.md: + id: 547db320beae + last_write_checksum: sha1:4e9347ccb266e4b83e2df023a153aceee0ee3a22 + pristine_git_object: cf9d3d411e5aa4fe3d3a9593150ef5376b95a662 + docs/pkg/models/shared/ssoapplicationservicelistresponse.md: + id: 93c8096f3295 + last_write_checksum: sha1:e128b0fd0bb24555a92dec0783024d71e520584a + pristine_git_object: 9bb9330ccf4bf609e9fec25ff6b566dc42512dc2 + docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md: + id: 1b333d9b0be9 + last_write_checksum: sha1:03a0d15161ac1b97e60c063a6692280a3fffc2a9 + pristine_git_object: 99524b01f6ca267009a461bda52456f289852ccd + docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md: + id: 3b8e2d4223a8 + last_write_checksum: sha1:8cb10779edd33e0372ae7fbcf44d29a915d11043 + pristine_git_object: 79a7bd44877426820b703622f4058afa6c5e70a3 + docs/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md: + id: 5683db40b664 + last_write_checksum: sha1:b303b19f34f72bcc3adea8583a948e19aa398fdf + pristine_git_object: 80319473dafaac8937a50d5b7365134bd89915ea + docs/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md: + id: 43c92d8a4564 + last_write_checksum: sha1:968ee540e32c206c5820b7581a9980e5e6c8f42e + pristine_git_object: a076e35a7829d9cf8a155a1a004a0f466786dc17 + docs/pkg/models/shared/ssoapplicationservicesearchrequest.md: + id: 59f31c3611aa + last_write_checksum: sha1:15785d7ad57570f91019ac93d16822281d77e2dc + pristine_git_object: bd13d394fb049c90c6747d1e9223a67c902dfa30 + docs/pkg/models/shared/ssoapplicationservicesearchresponse.md: + id: 39595906e349 + last_write_checksum: sha1:ee627b6f944f2c1b20bceff35364251e2c2a3478 + pristine_git_object: b4bfce35095ca44822d30ecd92571d46b6d3dda6 + docs/pkg/models/shared/ssoapplicationserviceupdateclientrequest.md: + id: 12542ffce3aa + last_write_checksum: sha1:9c4ccee566f91bb2778f38703c0f45a274614cd4 + pristine_git_object: 579f9e6d602145eaa9543b661c084c2e9fd89923 + docs/pkg/models/shared/ssoapplicationserviceupdateclientresponse.md: + id: aec6d1bfd624 + last_write_checksum: sha1:88217b48fdd87c1b304431b6b16245c203571b75 + pristine_git_object: 61d7850f103775975a79f9413e2de079bd10bf36 + docs/pkg/models/shared/ssoapplicationserviceupdaterequest.md: + id: e4f1f93666a2 + last_write_checksum: sha1:d4de5580860797e9bcba6749f9f5353ae19ae3f9 + pristine_git_object: e5a65fe565dfd61d5c1dd899d4dfddfebade3303 + docs/pkg/models/shared/ssoapplicationserviceupdateresponse.md: + id: bb9543bd38bf + last_write_checksum: sha1:f2505a69a04cac15bb9f2a29cf55d988afa5b35c + pristine_git_object: fcd1671ae389290c94da6492b5f0c3ddf70ac4ee + docs/pkg/models/shared/ssosettings.md: + id: 0c3428a1a5f6 + last_write_checksum: sha1:d39948954fb1993de09cc974254eb566ba937312 + pristine_git_object: 1b10bb9e75a62649a885d9d9a3cb6a6075aa0a3e + docs/pkg/models/shared/ssosettingshistoryentry.md: + id: 15d72b20ead1 + last_write_checksum: sha1:a1bd806e9c9a166fcc10f9ba471bf2a6fade72ad + pristine_git_object: 8c8b6fa75d1cd97150418a05ac3904e2f562f195 + docs/pkg/models/shared/ssosettingsservicegetresponse.md: + id: 64c24eb50a4f + last_write_checksum: sha1:e990603c7b61366772ab6e101d305a4c6eda2fff + pristine_git_object: ad5b82947d726073b4e47f41bb4ff7b4182cc522 + docs/pkg/models/shared/ssosettingsservicelisthistoryresponse.md: + id: 9dc16e353b17 + last_write_checksum: sha1:bec71bd3c18fe96e858b77e418164777eb2cf87c + pristine_git_object: 45d2635b8a3a1d3e42fda802f15900cf580d3592 + docs/pkg/models/shared/ssosettingsserviceupdaterequest.md: + id: 41306f0c8db4 + last_write_checksum: sha1:f8cc441de538330f58f8b3408522cf07a8401693 + pristine_git_object: a3e67d67e7c534dee7a9a73e6262d0cfa0422cf1 + docs/pkg/models/shared/ssosettingsserviceupdateresponse.md: + id: 2136b065ed6f + last_write_checksum: sha1:9ae32f9b7ae5cd03047416d36717e5b4cb8da28b + pristine_git_object: 3077388a2c75e415afc5780fdaf8c4044a6dfa2a + docs/pkg/models/shared/ssosubjectcompatibility.md: + id: 25af0a45aae2 + last_write_checksum: sha1:31a9dbead0b3ab442308410058293d8a6ad860ad + pristine_git_object: fe4020196c3022ed1a0d688a5dae76f6e711c965 + docs/pkg/models/shared/ssosubjectcompatibilitydeleteissue.md: + id: 556994c28d74 + last_write_checksum: sha1:c5b42586d069759c49b069417bb58f3a28068f61 + pristine_git_object: ec3b4c027bdaef2de7f627463715f8179d19ec99 + docs/pkg/models/shared/ssosubjectcompatibilityimportentry.md: + id: fbbac9cc681b + last_write_checksum: sha1:ce088a7278f390c99506c949c739c21b89392ce2 + pristine_git_object: 76dbd31855281a0aab02a369b2a7c7d81d5f529d + docs/pkg/models/shared/ssosubjectcompatibilityimportissue.md: + id: 8bd30c8d8da3 + last_write_checksum: sha1:91bf78c3897030874da0efb9265e25e4e6656979 + pristine_git_object: 309e9054764466d2457722755165605ec67439a7 docs/pkg/models/shared/state.md: id: e51cbc5a21af last_write_checksum: sha1:b4e3f281906cf551f6d2a3bd6ab8c3395b8b6ea1 @@ -11322,8 +13138,8 @@ trackedFiles: pristine_git_object: 92187613c5258d5a0338baa550fb4a8e5da8ced4 docs/pkg/models/shared/statefilter.md: id: 9ab3989c6dce - last_write_checksum: sha1:eabca0030efc86abfd89c1f89957f172e53e4484 - pristine_git_object: 6d9404d48f9e8a29d24988b7b0e94aa1d93333e4 + last_write_checksum: sha1:402e7bcad2da694fec9a6a560b69d1118b3d4e18 + pristine_git_object: 88d611bc5bee3ae518af9aae1a4a3b9bc5c147ec docs/pkg/models/shared/states.md: id: c41aeee54503 last_write_checksum: sha1:fe7c3515fcf1db0200e3ba88f9a02a2f51af080c @@ -11416,6 +13232,10 @@ trackedFiles: id: 5ba182a670aa last_write_checksum: sha1:5395167a1c7669e064ae9c46ce4b84bf71f8e485 pristine_git_object: 8fa13c1b2e538c676d4b9ea6515f0e19d11b0578 + docs/pkg/models/shared/subjecttype.md: + id: 83ea479cd10c + last_write_checksum: sha1:680ee7389708d167aa473733da4232473a52d5b6 + pristine_git_object: 55c8a281c1355e1e07d0a0260e93bb88b58cda59 docs/pkg/models/shared/submittedtaskaction.md: id: c46fdafcfddc last_write_checksum: sha1:d0c056c2e1df1570056d7b4c31c89c30bdcade38 @@ -11436,6 +13256,10 @@ trackedFiles: id: 243196c064c4 last_write_checksum: sha1:8746d9f70f8701467aa6dcca185a42d1e78b87fe pristine_git_object: 3054e30940f2a0cd4b3c74a4daf240c7d07dfb6e + docs/pkg/models/shared/surfaces.md: + id: c1b26d340077 + last_write_checksum: sha1:56d591f763feb873c59f5700db2ce3086e5ae617 + pristine_git_object: c226b13f3a84c741810b7fcf785cd8db18a11e6f docs/pkg/models/shared/syncconfig.md: id: 5f2a41bdfa3d last_write_checksum: sha1:a09b4f6e26742abded26273835c58899457abe10 @@ -11452,6 +13276,10 @@ trackedFiles: id: 1cf0ea918e02 last_write_checksum: sha1:9cb5312b0af0a2f89f4b8a5d93375b729c3721e0 pristine_git_object: 080f8c0e43b06ab0ff3307cf765f8bbb159f59df + docs/pkg/models/shared/systempreference.md: + id: c5124ddf9bcb + last_write_checksum: sha1:9407e51cdea9a07fb54142f19df7604e26d4d070 + pristine_git_object: e8c910c19aa95d9df4badaf6ec7aa022dd0a9734 docs/pkg/models/shared/targetedappusertypes.md: id: 86597a580e34 last_write_checksum: sha1:3ce95ccb762da2b10d306ffdad2557086629027a @@ -11596,6 +13424,10 @@ trackedFiles: id: 0e943dd1d25a last_write_checksum: sha1:217a39b1a94a58522f67f9e8bcacf86c24e3717f pristine_git_object: fb915b295556cd1933db44eaac47d94096615406 + docs/pkg/models/shared/taskactionsserviceretryprovisioningrequest.md: + id: 63f565ae21fe + last_write_checksum: sha1:07ee693cf4ebc55143deac40e6045d3a97b9f595 + pristine_git_object: f4f29c0f6065a867434bcfad86181a545e4d552d docs/pkg/models/shared/taskactionsserviceskipsteprequest.md: id: 5332bba5afa0 last_write_checksum: sha1:9857f41355f34313c364f9886e8b9a7abc5f19ea @@ -11616,6 +13448,10 @@ trackedFiles: id: fe19c9c559fd last_write_checksum: sha1:2a3ccb392693bbfbb9df5ab6a182e29c27883852 pristine_git_object: ab0e45a5fefaf147482c525340f07809c3fd9d4b + docs/pkg/models/shared/taskauditaccountdeleted.md: + id: 2d2e927243d1 + last_write_checksum: sha1:a6c2ee58f36b761862bd139b27ca9201a398b14f + pristine_git_object: 47b14b5ff19c7437331fafdd8c4e08847543d53b docs/pkg/models/shared/taskauditaccountlifecycleactioncreated.md: id: 2ed0905fbc24 last_write_checksum: sha1:4ff5ac5e84c57b0bd6b0c2a639cbb01c0d5cdf6d @@ -11656,6 +13492,10 @@ trackedFiles: id: 105fd09ae562 last_write_checksum: sha1:a6ba3bf1a334447b46e99e25ebdfe4f1a6e97b94 pristine_git_object: a1fd5ba7330e13c9733c02e2d9bafea97bc3818e + docs/pkg/models/shared/taskauditautomationtriggered.md: + id: 851ac8f0ee2a + last_write_checksum: sha1:24ec7f1e7d9c0177e8325d5b5dee7cc81541c11f + pristine_git_object: 46b20f4abf0ee973cbd7388ee2974ec2f0bc408e docs/pkg/models/shared/taskauditbulkactionerror.md: id: b76b155715fe last_write_checksum: sha1:524f47b256f0b6df5defceeaaab60f683f903bf6 @@ -11678,8 +13518,8 @@ trackedFiles: pristine_git_object: 5576ece0dae7059debcd6f53d6d7d35ff9dbb141 docs/pkg/models/shared/taskauditconditionalpolicyexecutionresult.md: id: b81d1c0141c5 - last_write_checksum: sha1:c27758ce2abf126c5158ddfeb7bf3485d43a351f - pristine_git_object: 8db6f82ea2450a61463da76a6c9958807d8a252a + last_write_checksum: sha1:8541e8a7a15cb67335cf0255bdde5dbe4efd5b8d + pristine_git_object: 7150a43bd826e3e6f062db5c626c41f6567ad3e3 docs/pkg/models/shared/taskauditconnectoractionresult.md: id: 99895cc2877d last_write_checksum: sha1:a55b6d330c26420b85261a122ddd794ee5f6f463 @@ -11742,12 +13582,12 @@ trackedFiles: pristine_git_object: e4b8a53a0e2a9b1da0e7e1c88587b30afe2120e2 docs/pkg/models/shared/taskauditlistrequest.md: id: c8d0bdabad0f - last_write_checksum: sha1:f27fd42c3da0ed669a75ba7da8ce2763680c389f - pristine_git_object: 11380c753b0235c75dfe1281a263508dedb9c3aa + last_write_checksum: sha1:b2b0ed557871413fe70ae8164c60ad3c22557e5f + pristine_git_object: 9d5a2eae312c8c722a52d59a45a9ecccf4dedb00 docs/pkg/models/shared/taskauditlistresponse.md: id: 10d9f2d2340e - last_write_checksum: sha1:7dc2d9cb36a65ca8952a26ff5c117ac69a5df50e - pristine_git_object: e8bcb8fd13346d325cf7026baafde87c865d3d9e + last_write_checksum: sha1:25394d543e4f038e5cdf6262282a7bef9e250fcb + pristine_git_object: 5cf2523d103600517e5f53c043b26c29a08b40a0 docs/pkg/models/shared/taskauditmetadata.md: id: 5d653a233c3b last_write_checksum: sha1:4effc075c2ab5ec112af0cada44209dab25d31ae @@ -11788,6 +13628,18 @@ trackedFiles: id: 9ed241ed55b4 last_write_checksum: sha1:9c5f995b18bfa320cbf4aa272fb7ceef089ab147 pristine_git_object: 5a3f6a5c1cb303593e535895ebb4a96532aef538 + docs/pkg/models/shared/taskauditprovisionentitlementmergecompleted.md: + id: b8fc25bb6f6e + last_write_checksum: sha1:30329b210f5ff286752178bce545ae127463dd79 + pristine_git_object: 3aaf0f195fe6268e1058c3ba7ae09f361f896b5e + docs/pkg/models/shared/taskauditprovisionentitlementmergetimedout.md: + id: 91225931349f + last_write_checksum: sha1:fbe337d9e6c9cbe57b9cea3bca1bd9aeae343b42 + pristine_git_object: 19aa0c00760551aa998b0fe566948702a05ee342 + docs/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md: + id: 6fd73b5753d7 + last_write_checksum: sha1:7b894a9c3f67299985dd573075cabe771641c224 + pristine_git_object: 78bdcf8804207fda219c3253b81643ce8ac811c0 docs/pkg/models/shared/taskauditreassignedtodelegate.md: id: 70c65a55b805 last_write_checksum: sha1:df6a317a39c8d08d6edb49728045eb559dae384f @@ -11850,8 +13702,8 @@ trackedFiles: pristine_git_object: 0d9af6a92642e7a2952a19d6d37d4661ece94d95 docs/pkg/models/shared/taskauditview.md: id: 7f865d91dd04 - last_write_checksum: sha1:fdaed9f8ef804a86baef9a8266b026e2283030ef - pristine_git_object: 8a1ea7870638c402ac1dc6fa786d924b6fe7d283 + last_write_checksum: sha1:4748d7102a64ea7ed68be97e4d7cbd8746f1c587 + pristine_git_object: 26f3afb2abfd96a5104ab30b2697d4df6f515841 docs/pkg/models/shared/taskauditvieweventtype.md: id: 6d236549c176 last_write_checksum: sha1:877e99fb66f21850717f018393158ed5b9e30d6d @@ -11918,8 +13770,8 @@ trackedFiles: pristine_git_object: 7ab4faa4a2893b57d6b19ee666e868e59f950cb0 docs/pkg/models/shared/taskauditwebhooksuccess.md: id: 6df7a1c94bcc - last_write_checksum: sha1:4095163b4adaa3a956cd1b2dc1b86c909f25f960 - pristine_git_object: 9a6d1da0e1f3f3b72542829f0605466312ac625c + last_write_checksum: sha1:df4457962dfcafa3fb1cfa101d4537ec76f58bb0 + pristine_git_object: fc5611deff0b4ed33ceb69f162b422a0fc473f43 docs/pkg/models/shared/taskauditwebhooktriggered.md: id: 7f9ca8684114 last_write_checksum: sha1:60e12464b920bea4151add1fd00c7ab8152c29f9 @@ -11966,8 +13818,8 @@ trackedFiles: pristine_git_object: 43be3232eba097d69972bc0fd549d3cb4f46fbde docs/pkg/models/shared/tasksearchrequest.md: id: 1a918e7c116f - last_write_checksum: sha1:92b06794bf5b3b37c9144fa25b6e73d5c9ca7d6f - pristine_git_object: 1f19e9d91a39554574772c4da44367d1c609330c + last_write_checksum: sha1:99522eb54fcd87383910dc8fed9f177478254fc8 + pristine_git_object: 0b232262ed40f8e2c52645a901b73b942e6b1684 docs/pkg/models/shared/tasksearchrequestaccounttypes.md: id: 87557033c7a1 last_write_checksum: sha1:024a08cc123bb999fd75662911caf0ea91715f62 @@ -12316,6 +14168,14 @@ trackedFiles: id: 7f15453d39af last_write_checksum: sha1:f15dc190582bb158dcd24ecb878a9cfcfa02eaca pristine_git_object: d3f553eef0b2987840fccae64e2212fd6d3aba84 + docs/pkg/models/shared/threshold.md: + id: d35fc7abd4de + last_write_checksum: sha1:8421ef96fed6ef46f3f6e05feb85053588832dea + pristine_git_object: df7c79e4d77808e6771c3e9f2efc429f53f1e537 + docs/pkg/models/shared/tieroverride.md: + id: a5e494076c93 + last_write_checksum: sha1:d1cc8d941eeab6708f715ffea8592458ad799b11 + pristine_git_object: 9c9755def1b1bdbf9130136530fbcaa83d7b788b docs/pkg/models/shared/timestamprules.md: id: d25d1d8b32aa last_write_checksum: sha1:f99c84c401311870cd46b863e19a945d531266ac @@ -12356,6 +14216,10 @@ trackedFiles: id: 062c92e9c317 last_write_checksum: sha1:19cc16845654821e06fc6ab089c1179fc2d75987 pristine_git_object: 6e45975a13bcbf29dcc6dde0b7d043a61b96380c + docs/pkg/models/shared/triggerautomationdispatcher.md: + id: 792dba0876de + last_write_checksum: sha1:29a4c7f01221e65de93c70d94d648e487f83da7c + pristine_git_object: c7f794c3fc11babebaa3444ad574727408795d2f docs/pkg/models/shared/triggercustomanalysisrequest.md: id: 4a6a4a76e201 last_write_checksum: sha1:cb6eee2e72605e635374dd57170d379bef82049c @@ -12488,6 +14352,14 @@ trackedFiles: id: d5e7be86f63e last_write_checksum: sha1:a0692f796747556528f5d6429d7183ae8bbeb0ce pristine_git_object: 01d548a52b8807281b30306662381224a64a8218 + docs/pkg/models/shared/unusedsecretevidence.md: + id: c91d19bdb927 + last_write_checksum: sha1:6558442095686cedfce54508baa3c56c802b7eb2 + pristine_git_object: 8e9594552f18a3847263e8b3724933c056c00e90 + docs/pkg/models/shared/unusedsecrettype.md: + id: 4fd0a5102da5 + last_write_checksum: sha1:e0059705a5c0ed2f10b01cf910f7af6f148ef225 + pristine_git_object: 61416d94f1f7d09c621a5c76171fa52280a0ccf5 docs/pkg/models/shared/updateaigovernancesettingsrequest.md: id: 8625dc40b497 last_write_checksum: sha1:27774d796a40327d89fcbae0e49df595eff4f15a @@ -12564,6 +14436,14 @@ trackedFiles: id: 193cfcf8c48c last_write_checksum: sha1:f792c95bea777f9071247c352db441ef2175de02 pristine_git_object: 34e798b5847c8ae60e35da4e0a06a8046c99c1b5 + docs/pkg/models/shared/updatefindingsettingsrequest.md: + id: b679cabff091 + last_write_checksum: sha1:f7bba7a9c0bc5cdd9c65fe24212cf50ce801e215 + pristine_git_object: fb75e2529599265e397d07c292133e8229548e02 + docs/pkg/models/shared/updatefindingsettingsresponse.md: + id: 61275fe20220 + last_write_checksum: sha1:e8c70e664c1a46c1e171f2cc25f0d00f90050017 + pristine_git_object: c62317e48e58c56739cdf95cd7e0f056546467d5 docs/pkg/models/shared/updatefindingstaterequest.md: id: e3e58d447f30 last_write_checksum: sha1:c15f193b327c59d5590a985297c405fde3fba35b @@ -12952,6 +14832,14 @@ trackedFiles: id: 9c17bf198c7d last_write_checksum: sha1:4eddef88876f288d1fe6b445c8d59c68085d1972 pristine_git_object: 3edea50f2304944c7b13244d28f9ab4cabfec485 + docs/pkg/models/shared/waitingfordeviceplacement.md: + id: 38604363c230 + last_write_checksum: sha1:ba7f12775e1bc891de2b463da9ba5cc059f4bcc6 + pristine_git_object: bcf2cbad65be25cb03295ccddddbbbebcd160130 + docs/pkg/models/shared/waitingforentitlementmerge.md: + id: fd9f2c553914 + last_write_checksum: sha1:c19a5e0538db9b5e0d66f0dcef3486d81ba28d2b + pristine_git_object: 7a5e2aaf5dae3cbd0e53dfe61ae420e95d1fb54b docs/pkg/models/shared/waitinstance.md: id: 89072d6af1a0 last_write_checksum: sha1:ac970988db421f97be7ee2c7ad1b79bf87573734 @@ -12980,6 +14868,10 @@ trackedFiles: id: 9bd2c19532e2 last_write_checksum: sha1:6422ec74157dbf535074196b63420e67a854e978 pristine_git_object: 0fe8f8d7908bf76cadedac838a1e6052dc17ef64 + docs/pkg/models/shared/webhookdispatcher.md: + id: 53386cafdc98 + last_write_checksum: sha1:da3e59ddf62affd7cc1e4c8fb08dbb4d85bcea01 + pristine_git_object: 896f31a856bd80ddf59247dfa245d0bfcec804df docs/pkg/models/shared/webhookendpoint.md: id: a58310256f59 last_write_checksum: sha1:8325859df5ac0705f72270453a4ec1f9246b9fe1 @@ -13318,8 +15210,8 @@ trackedFiles: pristine_git_object: b2ee1d116010f57ff75542c0ff89c69a0100b910 docs/pkg/models/shared/xaaclientaudiencemapping.md: id: a9332a57a3b6 - last_write_checksum: sha1:fa69b300021869ab80b1ce339bc741fc93c9827d - pristine_git_object: c1ab336249c4b8d8ae054fcc6a5dcba4e20712e4 + last_write_checksum: sha1:54753b9c579e22bf5344ee7d5f6e732944f5da71 + pristine_git_object: e4c6d2db6ce8ba0ce2ad40fcaf3539358feaf44e docs/pkg/models/shared/xaaclientaudiencemappinghistoryentry.md: id: 34b663ae1584 last_write_checksum: sha1:e7c661e52018417a1c8b58d2a18b62b6b153d773 @@ -13550,8 +15442,8 @@ trackedFiles: pristine_git_object: 15930d85d19e0587c6d518257d47a53bcf80bd99 docs/sdks/a2ui/README.md: id: 815223fd2123 - last_write_checksum: sha1:fa3bbf4853d8f128d40ca380a09c0c149f0199bf - pristine_git_object: 9b683f6ab843e3d119a664aa070627d538d8e86e + last_write_checksum: sha1:efb673907373ee0937b70fe82e9b5fbbee8d1153 + pristine_git_object: 4b0ce221885cf3e40a1443d6045f19977e2ea62b docs/sdks/accessconflict/README.md: id: b446dbae84ce last_write_checksum: sha1:67689200b542e15725795553fb1c235e6b873863 @@ -13560,6 +15452,14 @@ trackedFiles: id: bded304980b7 last_write_checksum: sha1:aae2fdd8acbc673520dc5ddd508bf1fdd4b80177 pristine_git_object: 9a03df5bb1fddca876d80ae8f9285c4f416951da + docs/sdks/accessreviewactions/README.md: + id: 17c9832373dd + last_write_checksum: sha1:ad5f9bf17daba73da04507302ffbffd7ce09d923 + pristine_git_object: 44e29a6138314a2e7f0023b7e619c31e088cdd2d + docs/sdks/accessreviewreport/README.md: + id: 63ca323bc2dc + last_write_checksum: sha1:34544b2bc46c6137dc2882b6e187837b83d18752 + pristine_git_object: f83162ec4331cd61b5ecec12f099aaf4a455d0c4 docs/sdks/accessreviewsetupentitlement/README.md: id: f00dade44c87 last_write_checksum: sha1:4010104a89ed06b12d35a3c1417862ee24196367 @@ -13578,12 +15478,16 @@ trackedFiles: pristine_git_object: 56c5c2504c3e603a7608f78fe4c35bc52f3ebcff docs/sdks/aigovernancesettings/README.md: id: df731144ce97 - last_write_checksum: sha1:52cd74b5cca8ac5c2c10fa9cf9fa874846995e54 - pristine_git_object: 1bc3a7c381d8269217bfff06bc41e079f174c713 + last_write_checksum: sha1:c1d2de546010109521d8c8c11bdacecf7219fac9 + pristine_git_object: dea8c8c67dfc470c7d3ea4e276375d40f9e552eb docs/sdks/appaccessrequestsdefaults/README.md: id: 3837dee15210 last_write_checksum: sha1:20b2b92e1378b0550e9a65f2a8874278b3e9e92f pristine_git_object: bf18e3b1b36dab4c1c70172dfcff4e04d603563f + docs/sdks/appcap/README.md: + id: c463580f3595 + last_write_checksum: sha1:06c87a14aa2eeafe9b7a4a01812ff1b18ecc568c + pristine_git_object: 398e2874ea119bc0140a7d26577f3e948826e093 docs/sdks/appentitlementmonitorbinding/README.md: id: 2e4fc0e89fb8 last_write_checksum: sha1:b532e5a1845f0970df458eb0937085f21ad5a792 @@ -13598,16 +15502,16 @@ trackedFiles: pristine_git_object: e1d459ebda8fa04afb509fb83f8bbaf1dc60c498 docs/sdks/appentitlementroutingrule/README.md: id: a370b3d79ec3 - last_write_checksum: sha1:fd77234a7a72bed5bd99524dbec80518a2641669 - pristine_git_object: 72557cc6ec729ac7e115b372b022af20e209ffa4 + last_write_checksum: sha1:613ecf2084edbdcbe1c85515fb2f1ecf27ce586d + pristine_git_object: d422468cc68c625c85f0a75c7fcba717d94e4b18 docs/sdks/appentitlements/README.md: id: 5182d279c9e8 - last_write_checksum: sha1:515caee3136b10619a157c834097c5133715f13e - pristine_git_object: 1258e44b503bec1a7f284c2e22a6ae15003bf8bd + last_write_checksum: sha1:c96b2e52e69e1794d00f189675ee8442dc9387b6 + pristine_git_object: ac1ea04b77176ccd671f4aa05e5db42322a7d48a docs/sdks/appentitlementsearch/README.md: id: ac9e4e5e8d3d - last_write_checksum: sha1:e668efbea61c27e0696f4bd464557bc59f06efb5 - pristine_git_object: 0c18105a803dd80a391af32d21c61828cefb05eb + last_write_checksum: sha1:3439726aeb62bf10f52c28602548fec6c97e1e0a + pristine_git_object: 7b376fb17978b5551978325ac5ec5d6957493ca4 docs/sdks/appentitlementsproxy/README.md: id: 912c87f783b6 last_write_checksum: sha1:fc275fbaf2982289605a4ca8bf8662809bae54ed @@ -13616,6 +15520,10 @@ trackedFiles: id: 60a964a7cd7e last_write_checksum: sha1:555bf0e6b6a582ad78f9414c800ee23e3405c01d pristine_git_object: e6685535904d19cdaca27135d9d6146d76afc570 + docs/sdks/appmanagedstate/README.md: + id: 168ddd222eeb + last_write_checksum: sha1:67ad6683d6c5cf5ab00bf338871c69fe668e19bf + pristine_git_object: 38de6023fd75051613ae3968f14dbb581d66127b docs/sdks/appowners/README.md: id: 85e753fe9bf3 last_write_checksum: sha1:7ff182f4f9a3f96c1e283893cbc35a3a236d9f39 @@ -13686,8 +15594,8 @@ trackedFiles: pristine_git_object: 5edfe4199d61edd299529aca36e52c74f8ed40ba docs/sdks/automation/README.md: id: 7fce70e3c51c - last_write_checksum: sha1:bc801c77858359d0fd035b26de2d24908112f3ad - pristine_git_object: e05482b968dc0dc347c786002bee59338bd97b86 + last_write_checksum: sha1:7396aa465848e0c039c0ffda2db92add734ff375 + pristine_git_object: 84ac3b6ebced7de4e8bc8e0227c91e7a3cd64877 docs/sdks/automationexecution/README.md: id: 69a3ce8a2b19 last_write_checksum: sha1:02466e179ce202db785e1607ebd46c327de9c77d @@ -13710,8 +15618,8 @@ trackedFiles: pristine_git_object: 28ebf85b5e3c8389695f9e223d98fc178286e839 docs/sdks/connector/README.md: id: a727a19d7993 - last_write_checksum: sha1:c38b22ee1452826c323fe0efc55c9528d0808270 - pristine_git_object: 9a14e52b816c9ed6cdfcf8aff370fe2b46a34cf3 + last_write_checksum: sha1:fdf684cd12782498fc226497c14748d9ba55c36e + pristine_git_object: 91c5d37adc6815f7c4814d7f5a572ef5e66439f8 docs/sdks/connectorauthoringactivation/README.md: id: 1b1a3663c1fc last_write_checksum: sha1:6c1e04c2e8b53b7ea9c5300ba169db4e47acfdea @@ -13726,8 +15634,8 @@ trackedFiles: pristine_git_object: c88502a9389e5b58279c12d2cd9dace707f8983c docs/sdks/contacts/README.md: id: 4174fb287a81 - last_write_checksum: sha1:c161ce970b7111a9fcd714a79af6f78e952af9b0 - pristine_git_object: a24c4ee749c40e1396024333ac0b069f10b63006 + last_write_checksum: sha1:69186381526a910d7fe32c8739e0f5123dc13fab + pristine_git_object: cdcf39e4de7de419a5f0b46652714c4b9831de8c docs/sdks/credentialinventorypolicy/README.md: id: feb1fac661b0 last_write_checksum: sha1:062ae4dbba948936cbd49e54faa1a2ff959ac878 @@ -13772,14 +15680,18 @@ trackedFiles: id: 7937bd1beb41 last_write_checksum: sha1:f18db2aa4000e6704d4961d8a5c74ec1681692a2 pristine_git_object: 26d142895e2ca7b04b8607b8f6ad60bdde630cb8 + docs/sdks/findingsettings/README.md: + id: f6bddaafd969 + last_write_checksum: sha1:42e441bc7d0259cef50dbbe1e67ce0a88cbead1e + pristine_git_object: e5733063a3b82a43f626052255ac038448cb21a4 docs/sdks/findingtransformationrule/README.md: id: cc61a47e2650 last_write_checksum: sha1:c8a00879be9a50617a190137db63497981602815 pristine_git_object: d82dcd6dae87889a67e6ec30400cef1b10f64488 docs/sdks/functions/README.md: id: 5c831af22db5 - last_write_checksum: sha1:2298d92c186290caca93774a59136aa1b9e0f1ae - pristine_git_object: 2c08037b383cfc8692f309e60c3326fdadfd20ae + last_write_checksum: sha1:939c1832529695be821fc082790ac086a76c5f12 + pristine_git_object: 53fefe04e6edf3da5a9317774c34774c8e8c5222 docs/sdks/functionsinvocation/README.md: id: cd7c4250e689 last_write_checksum: sha1:6bc1c6e93f9253bc11b6dd238532284abde276e9 @@ -13792,14 +15704,30 @@ trackedFiles: id: f50e89a1c1ef last_write_checksum: sha1:6b4d10650359db3454cf3d05bb86039c45af74eb pristine_git_object: a7d722479e21305daa1218c56407f51144d88fb3 + docs/sdks/fundassignment/README.md: + id: 1632a8428c82 + last_write_checksum: sha1:49bf7aef0186b2344644cb89ef87293d967a53cf + pristine_git_object: 5af07b55dccbd7cd5874acd8c4977f0a09c80a07 + docs/sdks/fundpolicy/README.md: + id: 7fa767abf010 + last_write_checksum: sha1:dac6093988e96d5ec1805fdc8ff244895dfc946d + pristine_git_object: f57c9b6537b38977825e0369f22c08900ccadcb7 + docs/sdks/fundrule/README.md: + id: 3acd3ad583f8 + last_write_checksum: sha1:1b179346454b2a98c765d0f51d941e947dcc11b0 + pristine_git_object: c7861ab3d90b2153837510f3a561b10bda1addea + docs/sdks/gatewaykey/README.md: + id: 15ec5066ec5d + last_write_checksum: sha1:77d58bd2aa562e26e9130bc393ab406f7103c6a5 + pristine_git_object: 9d4030c013e64c3de86818f83eea8c03feb5b19c docs/sdks/hooks/README.md: id: 5ea596d7a5b4 - last_write_checksum: sha1:bdc630c84a753b32b6dd46b1cdfdb0dddcbeeb26 - pristine_git_object: 4aaca2d6b9b2a914fd07978d12d420b204bd35fd + last_write_checksum: sha1:10f676dd1b1089f966f847e34c9dd64fce0c714e + pristine_git_object: ebe19250be18ee3b53c5afa3c9d86af3f6a0bb7a docs/sdks/hookssearch/README.md: id: 265f74f526ee - last_write_checksum: sha1:38da1bc344c47bbd86bb3af27fb72903de981530 - pristine_git_object: 040e2fc780f34a7dbd68767f980bb9860fda3f4b + last_write_checksum: sha1:bdb8c3796d26e4144132f9b44c779f115fe48600 + pristine_git_object: cdee7254afe624d73c6f9a9411607de8af68ff35 docs/sdks/identitypolicytenantdefaults/README.md: id: 90ba96c0bd62 last_write_checksum: sha1:e1e7fe2099ef23a091958d637dc1d48b8241ea39 @@ -13814,12 +15742,16 @@ trackedFiles: pristine_git_object: 026a755bedd727ff1778c5424c7cec5394c94861 docs/sdks/mcpaccessprofile/README.md: id: 8840532e6614 - last_write_checksum: sha1:73414215fda6307daad8900f7401609fe805593e - pristine_git_object: fdeefa9f43fe05f9ebbb21c7bf72c2af422ba353 + last_write_checksum: sha1:2810d2e8a4bc9ca66654279dcb67fef671a47509 + pristine_git_object: f7411aef6dee9b00a40b14dcf58899975cc2d794 docs/sdks/mcpaccessprofiletoolbinding/README.md: id: 057c7462035a last_write_checksum: sha1:dc1f09bbe30de34e5d550286ce1d9e2b2cae6c68 pristine_git_object: c06a2f9ccc96a3841d2d97b5d6c00329ff5a7d49 + docs/sdks/mcpresource/README.md: + id: 61a195eb1854 + last_write_checksum: sha1:518304689d6f9c630cbb74f46bdd8b7e9b0dd81d + pristine_git_object: c9094385658f97cd90b07bd19d8086e5606d99d7 docs/sdks/mcpserver/README.md: id: 85c743c46217 last_write_checksum: sha1:9582bad44db6b6121e7641e54e26085f6b857caf @@ -13828,6 +15760,10 @@ trackedFiles: id: 3230c1d8d380 last_write_checksum: sha1:641bb61859d448806010e2849ae81e1349df95ff pristine_git_object: de633488d662b44c167abc48cd22945477b0857a + docs/sdks/myfundlimits/README.md: + id: a20b5446464b + last_write_checksum: sha1:536691bcaa4997afaea283a039ebba3ce03d5140 + pristine_git_object: de0890941fbfd5ea77835ec198a7e516b4cbafcd docs/sdks/onboardingsettings/README.md: id: 2feae180827a last_write_checksum: sha1:d42afd03313ccf585d67b5c331c7860b4eb53ad7 @@ -13876,10 +15812,18 @@ trackedFiles: id: a4aee609100a last_write_checksum: sha1:ba2a417d4cd54c9cff8869c5666f53818a8bef16 pristine_git_object: 673af8c91653abe496ec242eac31ee467f14def3 + docs/sdks/providercredential/README.md: + id: 2b8cb250aed6 + last_write_checksum: sha1:bb5eff15e01523fe3735042e912e479b0631388c + pristine_git_object: 7d8106b7770428f50cc8431c006aef09270d4a5d docs/sdks/recoverypolicy/README.md: id: ba0ed578bd09 last_write_checksum: sha1:39c8fc9d0b3dddaa76507317cd8cfff47f23a867 pristine_git_object: f6f2809c56ed9a9011fb16c8614792e851a6cd84 + docs/sdks/reporting/README.md: + id: bcf996960be3 + last_write_checksum: sha1:b8bec19dbfc17a9c1e2e061f119f1cfd08e02ba6 + pristine_git_object: ebd251170caddfeb9361a424e1f44cdd0cfaac9b docs/sdks/requestcatalogmanagement/README.md: id: 45e144fe5ace last_write_checksum: sha1:4d22cda68550e883fc5e33c87cbe4c3e4cb8e35b @@ -13898,8 +15842,8 @@ trackedFiles: pristine_git_object: 0ffdbc07c7d56364de0deffe1154cf6234f0256a docs/sdks/roleminingmanagement/README.md: id: 8e3834e84039 - last_write_checksum: sha1:0f2aed6e1aa7c59302d6f93927b9e9f7734b795f - pristine_git_object: 53c30501aee4e320fc4f012b47cd69b49081561f + last_write_checksum: sha1:33f0d5bc15b7b82850860bf8bfe9fbec0c863575 + pristine_git_object: 6dd1e3e821b3c7eac7333d43b718c32e55f71944 docs/sdks/roleminingmanagementsearch/README.md: id: 1d3422c1fd5d last_write_checksum: sha1:25d6ca213a77f377b24dbfb66244f1baaa53328f @@ -13932,6 +15876,14 @@ trackedFiles: id: c8230ebe9d1c last_write_checksum: sha1:438b11785da197fe9bda4774bb5ae8e3889bc212 pristine_git_object: e3f8344204b6c1829715df490ec302cdcaa47ca8 + docs/sdks/ssoapplication/README.md: + id: bc7bb036f213 + last_write_checksum: sha1:8034b1d1a92e0db9e4b203f42865e2f746c2b5e2 + pristine_git_object: 106e538d24fdf33e9c5cf3da45a9b9cfbdad201a + docs/sdks/ssosettings/README.md: + id: 4fb850d4d594 + last_write_checksum: sha1:7052303645863a9267f9458c324d6132695fc7d6 + pristine_git_object: e464b198239a988aaa6f5b6c7055218842208bde docs/sdks/stepupprovider/README.md: id: 4ff90df68528 last_write_checksum: sha1:0300fa76549b75df0e897626f56e327f2ec37d75 @@ -13950,8 +15902,8 @@ trackedFiles: pristine_git_object: bfd3861ed95f5e7d150226783e6ecc2a04b98c3f docs/sdks/taskactions/README.md: id: 4c85dba073b6 - last_write_checksum: sha1:d3d7454fc733fcdb4c828dc8569bb24cdbfa9ff5 - pristine_git_object: bfa2caee2ef017dd3b27c4159986244a4478f306 + last_write_checksum: sha1:5803a24d2bd5201935c603843e653533ca132371 + pristine_git_object: 395e67b9c486094ec444260a46f32d61773b36e9 docs/sdks/taskaudit/README.md: id: d9923068f548 last_write_checksum: sha1:38d0473a12fdecb624cd9b8a8ba2f50336845b6d @@ -13976,6 +15928,10 @@ trackedFiles: id: ed14f76b22ee last_write_checksum: sha1:76c4531e55045a55225ffcdc884d9e973a7dd723 pristine_git_object: 698d388518f28c0e87f5604e1058b013ed42ca38 + docs/sdks/uiconversations/README.md: + id: a2509715f271 + last_write_checksum: sha1:e60454fdb25c3f25487f7ade2a28a042a9b3aa41 + pristine_git_object: 183615937f749ae0f6b8c2c796461248882c278e docs/sdks/user/README.md: id: 437dd7dc6e30 last_write_checksum: sha1:35a43ac92337a24cb20f7e4394597ff29b5a1fd5 @@ -14064,14 +16020,18 @@ trackedFiles: id: 73cafbf74608 last_write_checksum: sha1:b968ba2505eb999f2f4abadc0fbe3b2bbb1b2aab pristine_git_object: 950d5482483a5e5df9109618977d26cecc73a2bb + findingsettings.go: + id: 1a2fda4dcb7d + last_write_checksum: sha1:67cb4e26c8f86fda351111f8514a42353e82c525 + pristine_git_object: ad6e36ddd1426f0130c80ba5b5cf5e8078c09c36 findingtransformationrule.go: id: 47c0a69043a2 last_write_checksum: sha1:488febf367593bef99fe8e4921cd7dbbfff762d0 pristine_git_object: adad9a4652b56f4d1036755d7ade504f31c37504 functions.go: id: 0f7b27d65923 - last_write_checksum: sha1:024f4786dcda9a277181d65600fb709b6f7a5a09 - pristine_git_object: 6a7690d7a737e76cb5d96941224d94f213f1d7bd + last_write_checksum: sha1:1164dac92d89f65cdb8f8db77f8b4a02751a51de + pristine_git_object: 2aabc81c6fce56f1c7e27a33cfaadc6d7bb5b414 functionsinvocation.go: id: c07d17ceb20e last_write_checksum: sha1:d0c640fd17b5583aad1386058f4548e24cbba4d8 @@ -14084,14 +16044,30 @@ trackedFiles: id: c7b2771eb48c last_write_checksum: sha1:14d66c11a68a1f1ee2827bc7455dfe54f71760b8 pristine_git_object: f208345f64584fbe7ae33beccf3e0c56b9763fcb + fundassignment.go: + id: d385063cc43a + last_write_checksum: sha1:c12e1ad294855cc267686f2a4f5862ecf31b82f5 + pristine_git_object: b0dcf5030003f7796c340757526873564a4c27cc + fundpolicy.go: + id: d24f5b508c66 + last_write_checksum: sha1:804b45a39b1e5ef01690df9046d5188974952076 + pristine_git_object: 855761157e1c8879b5b462eeda69e8eb230a7686 + fundrule.go: + id: 75f7f98f9e59 + last_write_checksum: sha1:6882682cad19a603afdd98b16ce9f3404406c565 + pristine_git_object: 0d3e0a14254f48fa333c6db8d0061770d9c100b7 + gatewaykey.go: + id: 8747e5eb3eb6 + last_write_checksum: sha1:ab221520806e673fff417af3c08f07b1cf271596 + pristine_git_object: 5298b003ac08a13d5410b4549b3b7d47b0dd5924 hooks.go: id: 8068b0f7c9d7 - last_write_checksum: sha1:8359945e0832994e9f9132a271cd052c5e6c431e - pristine_git_object: 42ac61ca48db921780a38404b4db52b7a682c659 + last_write_checksum: sha1:4599ec71e591ca0e9c3d54871805a8cae4daabd4 + pristine_git_object: b2fedf77a525f84261ce86c9dcab434e9be53304 hookssearch.go: id: 548cd63f5eef - last_write_checksum: sha1:02a3d07803cc2d6d2f29323c8e15cadc8246b6e6 - pristine_git_object: b9b97ffd78de1257555a5caa5d68086e660a225c + last_write_checksum: sha1:55442cd992fdce779e4795ad0bc5bc90f499a1aa + pristine_git_object: 8312eb39eb1f14d38095f3a45017266ad2efec29 identitypolicytenantdefaults.go: id: 4ab4cf7a4cf4 last_write_checksum: sha1:04f42db37f8f17c2809185257e3bd15f9957afa2 @@ -14114,12 +16090,16 @@ trackedFiles: pristine_git_object: 202752d16f02226b58cbcbc74a94905c227ed9cb mcpaccessprofile.go: id: 24d663e03158 - last_write_checksum: sha1:a2dde69dd503adfd2311744e720a359b343a76a5 - pristine_git_object: c0218b94c093aa8fc8f8ca3bb00059fdfff61745 + last_write_checksum: sha1:126e33e7374a53eb9b1b2651da551a7d790c8f6f + pristine_git_object: 4440652424206abe55b841fd0f658a27985d71cc mcpaccessprofiletoolbinding.go: id: 48a91b46f2af last_write_checksum: sha1:a2b87d907f4cd67890718362e881db112ce89514 pristine_git_object: ad78c9e1d33d1716ad9962adf4a6167450beaa02 + mcpresource.go: + id: 9cd523a7a1be + last_write_checksum: sha1:922f26467f8f153ca936621e3bafcd18acde7903 + pristine_git_object: e0132ca5313f9e763d5fae11c4416d51154441d8 mcpserver.go: id: 2b54bb3d6ee3 last_write_checksum: sha1:daca285143073750c58b64d3e8bfedd0504d07a0 @@ -14128,6 +16108,10 @@ trackedFiles: id: 8e67d7cedffc last_write_checksum: sha1:6c15def5b070c237d9e67976cbd4d4065c2ad7b8 pristine_git_object: 312fd981c7011a7887734f971243c4d4b04cc31c + myfundlimits.go: + id: 225a73e7aca5 + last_write_checksum: sha1:d3644c4d85ad48f64f58e574666855e237db581a + pristine_git_object: ba73259707f5ea25e6a8514438a661c591813895 onboardingsettings.go: id: cca5eff66df1 last_write_checksum: sha1:f3fad69d1becce61809e174c02f1cea66ebcca21 @@ -14164,6 +16148,10 @@ trackedFiles: id: 560b2e1de406 last_write_checksum: sha1:a1cbc421015eeb9cc95ccc8c9a77cab3054bcdd6 pristine_git_object: fbed18a54db228e303fa56d7a4b446db33026bdb + pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenance.go: + id: fe5880a8a5f7 + last_write_checksum: sha1:2a93bdcc20ce96ba111cdf3144882341afba76e1 + pristine_git_object: d258b3be44035117986d8168e01c08f96455ac3f pkg/models/operations/c1apia2uiv1a2uiservicelistsurfacefeedback.go: id: f21cbccae58e last_write_checksum: sha1:88fefeb819481961d784b243de128dff353ab678 @@ -14204,6 +16192,14 @@ trackedFiles: id: 7b074ceb96eb last_write_checksum: sha1:31caa078611186d431a58b127b34ab0c0f6e8367 pristine_git_object: b3b4275a62a06560f30b2a3c2ecd36bc754e7bf4 + pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereport.go: + id: 264debf2ce49 + last_write_checksum: sha1:742cb4f894fdc21ad20fa89b2ec61899baa9c87d + pristine_git_object: ab755c41672517f7a62dfead1660b19375401b33 + pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelist.go: + id: 4dd3869f5088 + last_write_checksum: sha1:69e6880838035868a11d07c039255d04e71337a2 + pristine_git_object: e7eef6992571587e7f518552b2dc3d1c407aba13 pkg/models/operations/c1apiaccessreviewv1accessreviewservicecreate.go: id: 2b8cea87265c last_write_checksum: sha1:6343f6c156938e25ee6d9ea31e00633665f44966 @@ -14304,6 +16300,10 @@ trackedFiles: id: ed7a46796c0b last_write_checksum: sha1:d9e90a03b89845cc1ab8f3fb3b3f1dd4b2f39065 pristine_git_object: b951bfcefb4cc666360539ee539cd69e262e89f9 + pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofiles.go: + id: 12f357954d80 + last_write_checksum: sha1:c33e733433b333b6d3ab2013fd83b9d216db6a6c + pristine_git_object: dc9a83cf5d17996e10ead2c84ca5e4d0a932a58c pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchrequestableconnectors.go: id: 4c90e09cc394 last_write_checksum: sha1:5c1e50d19b10d90bcfc6301b6976d1a3124709f8 @@ -14336,6 +16336,26 @@ trackedFiles: id: aab85df86b1a last_write_checksum: sha1:f04fcce9ee6f4862692266b22bc395b50c274f7f pristine_git_object: 9cbc6277f53f72d2232dee659ea265b98bd72cf8 + pkg/models/operations/c1apiaigovernancev1mcpresourceserviceget.go: + id: 28cffbf07032 + last_write_checksum: sha1:98539016983326e760a4ceec3a2a505dd2326fbf + pristine_git_object: 74f69e4144dc3789048f18795deac640704505e6 + pkg/models/operations/c1apiaigovernancev1mcpresourceservicelist.go: + id: bb74121dd7ed + last_write_checksum: sha1:5cd091a938e2387db06bdc32bfe7686c6e4692c7 + pristine_git_object: 81d98c242f42fbe307cc2e42ecff12f2a01f92b6 + pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistory.go: + id: a3b02340aab1 + last_write_checksum: sha1:4f780a3101ee6cb07b293949a6081e3383b60488 + pristine_git_object: 61fc99458486ff0152ecf19bde69be5c587c8f98 + pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearch.go: + id: 9477181f9595 + last_write_checksum: sha1:80bf1d1ef3924d9480db1daab7c6ae993d4fb75b + pristine_git_object: 18bfde079fa5861c68804fdfe2a998c36bd322d4 + pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdate.go: + id: 47f8a5cfceac + last_write_checksum: sha1:ec75032d26f971963e67d91dd334c5f47decf237 + pristine_git_object: b7fea1d1de81cb3f4c1d39e2c7251e0cfc6a5d83 pkg/models/operations/c1apiaigovernancev1mcpserverservicedelete.go: id: 3daa6966e5e8 last_write_checksum: sha1:774bfc65e07bda9e961d76ece1a92efffaa281d1 @@ -14520,6 +16540,10 @@ trackedFiles: id: 74492c09f7b0 last_write_checksum: sha1:3dfbe18811ca99353e77ef3d1f3017f5f406f20a pristine_git_object: 0db21d15292372dd1dc956278fd8b9a37dcbe978 + pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuser.go: + id: 3aada7734bb0 + last_write_checksum: sha1:f70e1af3f8d5523e46aa3581b82887846e07d016 + pristine_git_object: 8e166ef784219afaf58919ec6001eb3e407202a4 pkg/models/operations/c1apiappv1appentitlementsget.go: id: 2f2ec14841b4 last_write_checksum: sha1:f498b38ed4f8ff2a88eea32b252c367989f16fcd @@ -14530,8 +16554,8 @@ trackedFiles: pristine_git_object: c7b94858b174eb759ecfa0b1753ecd226b82fae8 pkg/models/operations/c1apiappv1appentitlementslist.go: id: 4cfdc67c59ea - last_write_checksum: sha1:a2545ded729cbdea072e284bd1104c902d0e2b82 - pristine_git_object: e7242ef4fbb59e282016c42998b2d2cb9537910f + last_write_checksum: sha1:1f543ba4f8fde9a70e48bdad97acab405c481911 + pristine_git_object: 32333740e25b0eab8929596ec9dc9210ab0f3b75 pkg/models/operations/c1apiappv1appentitlementslistautomationexclusions.go: id: 8bdd5a3f17dd last_write_checksum: sha1:401ac1c24350284a796ed4ae017106995021dbfc @@ -14596,6 +16620,18 @@ trackedFiles: id: 1dfdab568fb9 last_write_checksum: sha1:6d9a4bad5ba354d1c23bfd016a12670208901964 pristine_git_object: a11f767bdb6c36e7c6cead34e16f14a2777e5e3c + pkg/models/operations/c1apiappv1appmanagedstateserviceget.go: + id: ba8281f02dbb + last_write_checksum: sha1:3037e60265ff58895edbaa3054c748023ff74c25 + pristine_git_object: 5ac20779821122e1c8ce43dbd71f9ff28ba85a21 + pkg/models/operations/c1apiappv1appmanagedstateservicelist.go: + id: cb9ab67e4df1 + last_write_checksum: sha1:fa9fd0d932357b9030c2947b9e86b6a5639bd590 + pristine_git_object: a7a5ef79ad262c7c0e0eb03fe18a51f18803835a + pkg/models/operations/c1apiappv1appmanagedstateservicepromote.go: + id: aa15632912d2 + last_write_checksum: sha1:2c681313ca8153d5bd55b9536b34dd6d83ef9434 + pristine_git_object: 2f08a265a192439661adae07efe366e27e92dca9 pkg/models/operations/c1apiappv1appownersadd.go: id: 4386774a2058 last_write_checksum: sha1:429755518d41aab1695e092a1eff7140b16411a0 @@ -14702,8 +16738,8 @@ trackedFiles: pristine_git_object: 213d29769a470ae83eeb3c4f596e3727965cf6ab pkg/models/operations/c1apiappv1appscreate.go: id: 0fb2ce8011a4 - last_write_checksum: sha1:d1af8755e258ec0c670f1e6274f2d214900c2b13 - pristine_git_object: 7938303e3996e4923f8589bd2464faa9a14c4af1 + last_write_checksum: sha1:c33962443f9f0d2f1d2e28bd40d691d5e17dd7d4 + pristine_git_object: f79d8654082350670e9e43e6601c80f68a99c2a8 pkg/models/operations/c1apiappv1appsdelete.go: id: 4c4584d60738 last_write_checksum: sha1:b2c70382c879ca267e2a2b09feccc6d69fa91eeb @@ -14778,8 +16814,8 @@ trackedFiles: pristine_git_object: 6729a04f6512a7d7150906755546c538d6105556 pkg/models/operations/c1apiappv1connectorserviceforcesync.go: id: a1680b2a00cc - last_write_checksum: sha1:087cdc086b897532900b4e8745e77d26c024feb5 - pristine_git_object: a1e60cc2fb48e2702c3946a6d557afac2b1ee5c0 + last_write_checksum: sha1:081a8254a704fa2f6653dbd405a351b77aa84bde + pristine_git_object: 0e56975499f68fc4c82a7fdfe69a8f4943c2027d pkg/models/operations/c1apiappv1connectorserviceget.go: id: 16c0d72c2aa8 last_write_checksum: sha1:c8a6ec0f78e04de746604a4d906790640b3a80c7 @@ -15148,6 +17184,10 @@ trackedFiles: id: 71bc67a5f3e7 last_write_checksum: sha1:c9a4aa180f1faaa804260b538c57ea82db6d3dee pristine_git_object: e577eb0cb022f55b0dd8edcc338b019c201a92d2 + pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsession.go: + id: 8c9d72c8ecb3 + last_write_checksum: sha1:7cf8965df72ff247635b73a5a979f14f21a7210a + pristine_git_object: 49e1ec059d7272fd51348ce583c5e570dd135457 pkg/models/operations/c1apicredentialinventoryv1credentialinventorypolicyservicecreate.go: id: 585ba485712d last_write_checksum: sha1:5b4f52f11669734bb53c25986e58c79f0c6ae8e7 @@ -15440,6 +17480,14 @@ trackedFiles: id: 964500b2de15 last_write_checksum: sha1:d3b635fe97c20692a205a7cdaff92b812cd13bc3 pristine_git_object: ccb862adf4d24218350c08c992a1e9a43df652d4 + pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettings.go: + id: d0ea5309379b + last_write_checksum: sha1:27591733d0b3d6cf9ca1d22d823dc1d950ab9320 + pristine_git_object: fb574cf727bf50f31e101ecd819f9cc78e778d2f + pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettings.go: + id: a87b575ecaae + last_write_checksum: sha1:e8f86f3d2d1deb3d3ddd0104e729f3336b377ce9 + pristine_git_object: 9775aa4986743e52fcd01a100d1c404d55f0dd4e pkg/models/operations/c1apifindingv1findingtransformationruleservicecreatefindingtransformationrule.go: id: e3830e84de43 last_write_checksum: sha1:21f7d927bb06cc7fe732ec5f0a87ba98030e6702 @@ -15532,6 +17580,154 @@ trackedFiles: id: d61608ffeb2d last_write_checksum: sha1:eeea0a95c97534bc167f24903a8bfc3104099892 pristine_git_object: c74d0daee48211c7327f432fe1d480b29d3b6e74 + pkg/models/operations/c1apifundsv1appcapservicedelete.go: + id: 527eac9fbc08 + last_write_checksum: sha1:a5867e17de56954a51a9134ddad2c7b25139ca9a + pristine_git_object: 2fde51ca49c492176f0977431a853ed025d6041d + pkg/models/operations/c1apifundsv1appcapserviceget.go: + id: ff84b881b63d + last_write_checksum: sha1:6499ee2d964c5be57ba7f795b58da8fc056cd375 + pristine_git_object: 1e0b0e2435d20a12e6bfdbf4fa7de0c6ce0ddd70 + pkg/models/operations/c1apifundsv1appcapservicelist.go: + id: 8dd622b7c20d + last_write_checksum: sha1:b2b45595831af587e3bea9b8ddc9aa54638e4036 + pristine_git_object: 61eb15a81d057cf714ae81ba7b6039db100faf1e + pkg/models/operations/c1apifundsv1appcapservicelisthistory.go: + id: 762e4212d623 + last_write_checksum: sha1:c22a3799b6ba5a168bc5be6163868f07a245ad04 + pristine_git_object: 7aa4064a893161be83f8f711472305aebbf36766 + pkg/models/operations/c1apifundsv1appcapservicesetlimit.go: + id: e957212dea62 + last_write_checksum: sha1:c6e039d183cca2b29372c52d3b57462df789ebd7 + pristine_git_object: 4e5f46307af9787a02b1b5248d246259e3d46496 + pkg/models/operations/c1apifundsv1appcapservicesuspend.go: + id: 15c0fdbefc4d + last_write_checksum: sha1:7f08822b8f5d95f86dc8e5849dd35447079f8b7d + pristine_git_object: 46a04a4e7424d655c7794f2b9965ea0da6dce924 + pkg/models/operations/c1apifundsv1appcapserviceunsuspend.go: + id: 90e129e3684f + last_write_checksum: sha1:3e420b58839f19d00594d8ea36a20e6f742ecc64 + pristine_git_object: a56c83d06af5c65a7c0d74295af7a33a002d1df4 + pkg/models/operations/c1apifundsv1fundassignmentserviceclearextension.go: + id: b0d39953b6fd + last_write_checksum: sha1:dd696c16fcbdc9f69bbb978c48f35a11411474db + pristine_git_object: d84ed8f711d5783870645969a55019827b297997 + pkg/models/operations/c1apifundsv1fundassignmentservicedelete.go: + id: 56dcfb0a74f9 + last_write_checksum: sha1:b13530f0da39d090999bf2845c70b56b577dbf35 + pristine_git_object: 9cfca0980cdc4ae2615c5d95aec9ab9e9362e611 + pkg/models/operations/c1apifundsv1fundassignmentserviceget.go: + id: 10c755c79bb8 + last_write_checksum: sha1:71ec2577c8dc703e904c2221b5fa33d4205855a6 + pristine_git_object: c4ae3a833aca9ab7dc40eafd1573f3a3c2768c7f + pkg/models/operations/c1apifundsv1fundassignmentservicegrantextension.go: + id: 4f1ebc5eb3d1 + last_write_checksum: sha1:c9b0e30550b74c0a67ec6e9bfb1f1259b9eaf7c4 + pristine_git_object: 14b1419bdb97671aeb35dde8182c122fd3e6ddaa + pkg/models/operations/c1apifundsv1fundassignmentservicelisthistory.go: + id: dcbe8a70d200 + last_write_checksum: sha1:54b4760075c3cb485462181dd160b03d99fc76ae + pristine_git_object: 806b0ca9aee37baf9df7f65b9e50ad2e775b8c44 + pkg/models/operations/c1apifundsv1fundassignmentservicesearch.go: + id: c638047431aa + last_write_checksum: sha1:49b8c8c2509aecc926b46e6580088fcd089dcf39 + pristine_git_object: fdf8def861e291ae9cb97d621b94189c25b4b0d7 + pkg/models/operations/c1apifundsv1fundassignmentservicesetlimit.go: + id: a5b6c45551ff + last_write_checksum: sha1:1c247715abb13b09f45f1f4a3ff7b08519cc7e47 + pristine_git_object: 8182b9f830e8cb97d6dfdaf359b8657e8cee2e66 + pkg/models/operations/c1apifundsv1fundassignmentservicesuspend.go: + id: 2b4b1d33759c + last_write_checksum: sha1:5572969aa9f15e729ea5d838e8d8d1715d9c926f + pristine_git_object: 9ca3c1f6cc59a62be488d014d8ec3fba0389c465 + pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspend.go: + id: 9fd46baf6218 + last_write_checksum: sha1:f29a19148573bfd1668f0934660a3d2fc5147311 + pristine_git_object: 5d617a71fcd0f2aa026f41628cb6a34b82cfd846 + pkg/models/operations/c1apifundsv1fundpolicyservicecreate.go: + id: 5d75bab0a09d + last_write_checksum: sha1:6739c7cbb1128ec2dfa4cb32b473e5e1b07b9b14 + pristine_git_object: f74b9118daf524357b392e4122c9160d1d0b0439 + pkg/models/operations/c1apifundsv1fundpolicyservicedelete.go: + id: a0f685ba764a + last_write_checksum: sha1:794a6479457c1cc1160a36ed05abbd603c92f1b6 + pristine_git_object: 1bf5397d1388de2880d9192a1fa48c85098405f8 + pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenant.go: + id: d1664f6d7519 + last_write_checksum: sha1:b8bf40a626c068db9c69900db91d5a86c36a8edd + pristine_git_object: e8c43050b45585998294f2398cb99da1d6afbb98 + pkg/models/operations/c1apifundsv1fundpolicyserviceget.go: + id: d36454eab573 + last_write_checksum: sha1:8d8e509f0a355cc9dbfbba84504c53fbc34c8e31 + pristine_git_object: 80332cb0ef4e055f16676c038afc4d624a71de2c + pkg/models/operations/c1apifundsv1fundpolicyservicelisthistory.go: + id: e9f4d91bcf38 + last_write_checksum: sha1:5be440b760c8dca5b78774ee0566c88690996356 + pristine_git_object: e30e7afe299c37c69e546e33277f0dc4b6028276 + pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceiling.go: + id: abb28783ae82 + last_write_checksum: sha1:5b34578157fc8f4cb93dad277093abadf4136d1c + pristine_git_object: 825c524a0875a4eba50faa5279c8c20d8d7dc5b3 + pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenant.go: + id: 7fbd087e00d4 + last_write_checksum: sha1:f4650af3cbb8a81b350dd0a4c54690de43e9f8d9 + pristine_git_object: 43faf6f77d05195035e45d87fae891c9f98d8c74 + pkg/models/operations/c1apifundsv1fundpolicyserviceupdate.go: + id: c7bf8a4444e1 + last_write_checksum: sha1:f74ff43eb64643e0f988443f4f952307b4f453ae + pristine_git_object: 4373ab15c7690ee39adb77f8c5b746347de47125 + pkg/models/operations/c1apifundsv1fundruleservicecreate.go: + id: d3927bc66f1f + last_write_checksum: sha1:80fce72edc0b0f2c80bb04b59f7830defeae3af2 + pristine_git_object: 4d6429c071b150b6e8b4189593c230a1e070b02e + pkg/models/operations/c1apifundsv1fundruleservicedelete.go: + id: 694060df3a23 + last_write_checksum: sha1:9588aa4d3f58bcda743c9a67b68c93c2f3cc3e0b + pristine_git_object: 407f1bd8ad92254524376a06103f666ebd777707 + pkg/models/operations/c1apifundsv1fundruleserviceget.go: + id: 000c3ef1edf9 + last_write_checksum: sha1:f7bd7959e2662be550bd73a27dc533fb7d0b7a61 + pristine_git_object: aa461677cb6b1f07174184364688f1469e65dd14 + pkg/models/operations/c1apifundsv1fundruleservicelist.go: + id: d66d45e70257 + last_write_checksum: sha1:6590c2f9f4fe7d386f5f41b5ece1d5bf5bd5bac7 + pristine_git_object: cd5b0bcd4dd435f47966da92aa30d8742f0d9253 + pkg/models/operations/c1apifundsv1fundruleservicelisthistory.go: + id: 9cb223711546 + last_write_checksum: sha1:e9fc7b3f225da9591c225b6f87213efdd108c7a3 + pristine_git_object: 85d3d06bcaddb8c23ecf1758db5b8b9ab1c4b345 + pkg/models/operations/c1apifundsv1fundruleservicesearch.go: + id: 0669edd6989e + last_write_checksum: sha1:1fc4f23ad26b9b50fb53c67dd1aed94439e1a3dd + pristine_git_object: e06c7e331de55ba10ad7bb4e10b4deef624b8452 + pkg/models/operations/c1apifundsv1fundruleserviceupdate.go: + id: 3087fa49cb7c + last_write_checksum: sha1:0a4cf8c6b0a5f5188ab710fef1c416ef2c409376 + pristine_git_object: 6c6215527fdc73bbd7f574f713b9271751ccec89 + pkg/models/operations/c1apifundsv1myfundlimitsservicedelete.go: + id: c7f67cdf7103 + last_write_checksum: sha1:24d0b15d230ff7381b911c913182f522db3bc10a + pristine_git_object: 0c414db4c1a825080ec5a5b54c98a9339c15af0d + pkg/models/operations/c1apifundsv1myfundlimitsservicelist.go: + id: 05a51b54dbae + last_write_checksum: sha1:1e3c8f06f8f786b3f49956aab62905227075664b + pristine_git_object: c60fc9785377314337c4cdf939916246fbb6bdfa + pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistory.go: + id: 60b65ee406e3 + last_write_checksum: sha1:97af554de5dbfe19b7544faafa1d84fd4fd8fe88 + pristine_git_object: a27c380d5b735fb313c10bb61f27a38c42759a6a + pkg/models/operations/c1apifundsv1myfundlimitsservicepause.go: + id: 4f3c9f0552ff + last_write_checksum: sha1:97b9278953b90c097b92bb71952a533703be06d1 + pristine_git_object: 87f79d729ac8c45779cfc9ff9c02774548db19ec + pkg/models/operations/c1apifundsv1myfundlimitsserviceresume.go: + id: b7c358d8daf8 + last_write_checksum: sha1:c2e2333b56f071fed063b8dc00004d8f60c2612a + pristine_git_object: 980d507cba6603feeffd110f24605088bf8bd6cc + pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimit.go: + id: 9fa27e05b3ed + last_write_checksum: sha1:dc7655a4f5a9b47d295b16accd161343adfd89d0 + pristine_git_object: fecfe6f7c2eff7693132b5ab2315012969147051 pkg/models/operations/c1apihooksv1hookssearchsearch.go: id: 7785f6e8e55c last_write_checksum: sha1:37addbf759761c05503ecabef0dd8d8ff34d142a @@ -15668,6 +17864,30 @@ trackedFiles: id: 1d7af8951a05 last_write_checksum: sha1:dd25a69e33eba06210d867ad033dfdb9a578a171 pristine_git_object: 0c17d450ce0b2c8c39daa1096ee58c1e01949b4a + pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelist.go: + id: 7752ffd8e8cd + last_write_checksum: sha1:fa935c455b44965ce57503da1eb13c4f8a16a985 + pristine_git_object: 47edd258473ff8dfe8b183bc72544c6bc0f79f74 + pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemint.go: + id: 9119b64d82f1 + last_write_checksum: sha1:7b1bf13722fca1ae85f47fdff2931a0ea20f8572 + pristine_git_object: 285e151b2c0bfccf533b7178043c2ad631f1ce44 + pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevoke.go: + id: d81345fc8808 + last_write_checksum: sha1:31cc2b4a8156ccdcd717f516c3c39baa4e151daf + pristine_git_object: fa2e5076a024e0f328cb31d87baa13eba1ba660f + pkg/models/operations/c1apillmgatewayv1providercredentialserviceclear.go: + id: 74f6435d9929 + last_write_checksum: sha1:9903393960f60c5e118cf1f332c306bd6ce6b24f + pristine_git_object: 1db108f8d1f03a294612abdbc8c5bdea897a06fe + pkg/models/operations/c1apillmgatewayv1providercredentialserviceget.go: + id: cd41bf7156f5 + last_write_checksum: sha1:de157e72456b2f145467be322ab3f3385fec5dea + pristine_git_object: 33d1e86cba7196f3cfea2c8cee95ee490995ce06 + pkg/models/operations/c1apillmgatewayv1providercredentialserviceset.go: + id: c6db24b66d72 + last_write_checksum: sha1:91b193a456c67fa4e4a8d9908ad17c932901a42b + pristine_git_object: 940bb453be115cfb77d67b67ce398a37ab97b7a9 pkg/models/operations/c1apilocaldirectoryv1localdirectoryconfigservicecreate.go: id: 455f22c68ed0 last_write_checksum: sha1:782c79c8ab6130ac7aa458f2dbebe6012ce5f622 @@ -15736,6 +17956,34 @@ trackedFiles: id: 35f410b0ac02 last_write_checksum: sha1:9b4c95ba0f649fddd9c9916adef27ff11b75537f pristine_git_object: b90e845ba0d701da74b6e462ad0b8dbadca4195a + pkg/models/operations/c1apireportingv1reportingservicedelete.go: + id: 21e4f7168dfd + last_write_checksum: sha1:57b0f642310e3e5c532aca09b9bd6093e91a0cc2 + pristine_git_object: da447e15f6d60bfb8e644ccb0e557d805586634d + pkg/models/operations/c1apireportingv1reportingserviceget.go: + id: 08cb7ad48738 + last_write_checksum: sha1:de35202dd8df1583c0fa2b887d88692d4c00e286 + pristine_git_object: 665cbb2ed435592f860b91cee23e7177934331f2 + pkg/models/operations/c1apireportingv1reportingservicegetrunprovenance.go: + id: 5ca20884156e + last_write_checksum: sha1:22c59180a78b6e5328ed046e8df15594c5c0cd8d + pristine_git_object: b662ee015d49e8a732f9da676231767b39481a68 + pkg/models/operations/c1apireportingv1reportingservicelist.go: + id: 17e29b0d811c + last_write_checksum: sha1:1e66868e8c1568ccaa6320d8e8b77dc6f0daf186 + pristine_git_object: 659c4ff05caf273a80c09bc2a611593c4a7a18ff + pkg/models/operations/c1apireportingv1reportingservicerun.go: + id: f45aa19a8467 + last_write_checksum: sha1:daf130449c9e992b66c660a63972376f781c4c62 + pristine_git_object: f36dff36ab7600af994b7a747f12019671cf0f59 + pkg/models/operations/c1apireportingv1reportingservicesave.go: + id: 4fd9a9f7f456 + last_write_checksum: sha1:64d24c08dad1d84155106fa68e85c59b098ce75e + pristine_git_object: a87ddd14f4fb672582d63de73586c4c4ef8e7ee8 + pkg/models/operations/c1apireportingv1reportingserviceupdate.go: + id: 757a5c139bce + last_write_checksum: sha1:106d3b50bef32ab51ffabf6a44bb42f48fd674f5 + pristine_git_object: b6a1b3fd3aebbf8b9faa5f18775d1999203cd1a7 pkg/models/operations/c1apirequestcatalogv1requestcatalogmanagementserviceaddaccessentitlements.go: id: 54b240052254 last_write_checksum: sha1:d07d12229d980bbbbcf92489eb2939d3e7af04e8 @@ -15864,6 +18112,10 @@ trackedFiles: id: 0bcebcbb075b last_write_checksum: sha1:4ba3f2e26eb94774709bb6047f13290d187976f5 pristine_git_object: a9dbb7c0893591ae4733f6e5f18ef5c9f0471680 + pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselection.go: + id: 3aa359344851 + last_write_checksum: sha1:6638f53737824d5de262a5434304f7cc83e36a87 + pristine_git_object: d75fa11f830e37c55f306ad12dee333a1aa8e77f pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementservicegetcustomanalysisresult.go: id: 2a315b899d33 last_write_checksum: sha1:fa43d8c6bf898223cde059b7325ef5624b5f6958 @@ -16212,6 +18464,78 @@ trackedFiles: id: 55463d0e3f69 last_write_checksum: sha1:8dd1f2399b915ffdfafabf80b0cae47d03b8c3e2 pristine_git_object: b9820bf73a9c3b6cc16905a6680641a469f52ee0 + pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibility.go: + id: 06ad9624e5d0 + last_write_checksum: sha1:544e1cf17cad547bb7c341f291c15bcdd38cabfc + pristine_git_object: a581f1b7d21f7413813a56c4c806e5c28f4b06b2 + pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibility.go: + id: 7d46093342b1 + last_write_checksum: sha1:d7160f52078597a450bb112a99bedccbe03304d8 + pristine_git_object: 96c94e8a5892829e6aba6f2a66a0f67a7da89ac8 + pkg/models/operations/c1apissov1ssoapplicationservicecreate.go: + id: 95c1a9ca9034 + last_write_checksum: sha1:81bf6807c0336b86c048d6d1d0b7e9c3f8cf38c2 + pristine_git_object: df461212d8411456e4f2a548a556a48040a3475d + pkg/models/operations/c1apissov1ssoapplicationservicecreateclient.go: + id: 9108ad293b1f + last_write_checksum: sha1:8073885f2d7c3b77b25b2f025c67a47d43bea73a + pristine_git_object: 7b0e713e5503220076951add4d5d37269a718127 + pkg/models/operations/c1apissov1ssoapplicationservicedelete.go: + id: 8c76adf7ccfc + last_write_checksum: sha1:4e7ade226e0b40d88ad125aebdc080cb046db925 + pristine_git_object: 997fc45ae7d7486dfe499e410e75b7f8d4f60a02 + pkg/models/operations/c1apissov1ssoapplicationservicedeleteclient.go: + id: 7f0385f3c59a + last_write_checksum: sha1:5685712943d9bc57ac119cce5cac70acf72fa3e5 + pristine_git_object: 776753fd00803a0abf453b9dd01a6d5f911fd8c3 + pkg/models/operations/c1apissov1ssoapplicationserviceget.go: + id: b3709387ba52 + last_write_checksum: sha1:66e223f544df4b0e401dfe400ddfef6f783b005b + pristine_git_object: e77d8a75b0fc93660aa04bb7ded49e674da4c826 + pkg/models/operations/c1apissov1ssoapplicationservicelist.go: + id: 78ccfc3032e2 + last_write_checksum: sha1:ed726c9f25b8666f81ebfdfdf3d9c762ba53dd05 + pristine_git_object: 12b9ce15c9e339aac505d6a8aa3be06ad355fbe9 + pkg/models/operations/c1apissov1ssoapplicationservicelistclients.go: + id: 2b26daf44b39 + last_write_checksum: sha1:a5d8ba0eecb7db47bfadb0707154b473c49e3063 + pristine_git_object: 7a90b859be9fee57458e663ea7a8b297674a595e + pkg/models/operations/c1apissov1ssoapplicationservicelisthistory.go: + id: 0ecdca2a947f + last_write_checksum: sha1:a749b3c2a41ac8f3de21403d7af76ab32dac4bd1 + pristine_git_object: b761a8c2eba6de4c3608a915da46d54c8b1fb1d1 + pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadata.go: + id: 7bf691f1be05 + last_write_checksum: sha1:d78f8fb6665c6403b5bc18b7dcffbb6ac7149cb5 + pristine_git_object: 5db0b5b6a3e2b227f5ad5c62bc99f9118fc46785 + pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecret.go: + id: 455f969d81b1 + last_write_checksum: sha1:91a8487a77ad7faca6bcdc93f27f3e0ed9bb08b2 + pristine_git_object: d65f8d61a4081b692b2ecc138b54e692a9bbc9e1 + pkg/models/operations/c1apissov1ssoapplicationservicesearch.go: + id: eb2b10cf1914 + last_write_checksum: sha1:c839018128e27d4267e8c97b4067819865a7f947 + pristine_git_object: 977ba4efd6d8b00221483ce448dacf77bb9c7e59 + pkg/models/operations/c1apissov1ssoapplicationserviceupdate.go: + id: c5cf7b2ccb5d + last_write_checksum: sha1:c2bc7bfefa9d002d5cba3d23ba426d880cb9f01e + pristine_git_object: 254e56ff0abeeebd144187c031cced080336b8af + pkg/models/operations/c1apissov1ssoapplicationserviceupdateclient.go: + id: 890dc7605eb5 + last_write_checksum: sha1:f3b95dd89d44218edf9224987eaec0336bb26886 + pristine_git_object: 10aef18d072eff1e993e642b97eb086880b2381a + pkg/models/operations/c1apissov1ssosettingsserviceget.go: + id: 2c0730ec1768 + last_write_checksum: sha1:32fced9a49b46997dc78befa4f6ec1cd160d6b2d + pristine_git_object: 5fbcb1cad39bc1aeae0b9632694177e10d20576c + pkg/models/operations/c1apissov1ssosettingsservicelisthistory.go: + id: ccabc1d227f3 + last_write_checksum: sha1:0c3bb5a74b2f0c5b81cfb9731f0efd6dea7e17ae + pristine_git_object: 7af9c075025b60ba956e04fdc284e8699a3b61cf + pkg/models/operations/c1apissov1ssosettingsserviceupdate.go: + id: 23a2b3f7ea18 + last_write_checksum: sha1:6b704900c01801a9b15c6e7e5faf234a7b3d326e + pristine_git_object: 88d792f8b61385de963dfa5280c66e5e5be99594 pkg/models/operations/c1apistepupv1stepupproviderservicecreate.go: id: 451a5d24fce9 last_write_checksum: sha1:39383d999955f086bac5ddcfeac46e4aa556e65b @@ -16324,6 +18648,10 @@ trackedFiles: id: 66b8fd3abc54 last_write_checksum: sha1:d48c30e14bcdc4394838baa393ac55f7a88f763d pristine_git_object: fce669a13a6a06eb231bd0062a1e5e96e3c1b441 + pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioning.go: + id: 8f090921f225 + last_write_checksum: sha1:8917e1f57e9720c239979c632e6455159e165a95 + pristine_git_object: 70abf11dc68531c0f803142d41fb585ba832e86d pkg/models/operations/c1apitaskv1taskactionsserviceskipstep.go: id: 82cbf75417c4 last_write_checksum: sha1:23c28513d7df3df0c4bd3f6635ac36af7a803508 @@ -16534,8 +18862,24 @@ trackedFiles: pristine_git_object: 0be01673a693466b74b26b60b11def624bb4ef12 pkg/models/shared/a2uicomponent.go: id: bb9dc0bbe63e - last_write_checksum: sha1:388409875e99a0a52e166b7bb1c858517021135b - pristine_git_object: ad15aad64e3d8b057d1b9cc2c2bff7c01c50d6cf + last_write_checksum: sha1:264819083d7904044bf2c50b90799618d3b17b6b + pristine_git_object: 1a4c40d082073540c7beb4f790d02666677120aa + pkg/models/shared/a2uiprovenanceobject.go: + id: 8611b38ead78 + last_write_checksum: sha1:4479f9363966856436bd7ac62feab26d7b2907dc + pristine_git_object: 2db0736934fda261974b09fdd37e8b0bafefe8c3 + pkg/models/shared/a2uiprovenancesource.go: + id: e6a12942f70b + last_write_checksum: sha1:9afc04eb613971dbf69b429b9070a2a4c54770b6 + pristine_git_object: c29efa530786a0c226e5b4b54145903697c4d6ce + pkg/models/shared/a2uiprovenancestep.go: + id: fb7a0bafaa8d + last_write_checksum: sha1:cfaac7b88a1d897bf4d974226a54c4f9961ee6aa + pristine_git_object: d31b55434fd6dc1b8f83959d3617014967c03706 + pkg/models/shared/a2uiprovenancetoolcall.go: + id: bfbc01053fec + last_write_checksum: sha1:e1561d8198b6feec7309bbffc8063ca499688e2f + pristine_git_object: 104567effc971d474aff2c5dc6c1431b95f1f14f pkg/models/shared/a2uiservicecreatesurfacefeedbackrequest.go: id: f6fd1bf14f3d last_write_checksum: sha1:615e2b3ccc0b767a143c3fbdc36e69dc7aeddf4d @@ -16544,6 +18888,10 @@ trackedFiles: id: 77fda63851b5 last_write_checksum: sha1:5940c921e291ad50796bbeabad5f57246ec5520c pristine_git_object: 5b9244bca7dbbae916421a97947d623616649570 + pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.go: + id: 41f72e3843a6 + last_write_checksum: sha1:b2a1a00e71cd1e160deed775ac0af75c2d32ea03 + pristine_git_object: 0278e407e240a2952b62940e486cf174825453a7 pkg/models/shared/a2uiservicelistsurfacefeedbackresponse.go: id: 288b6675183f last_write_checksum: sha1:03e988a60cc55886beccacc61d80fb81041d33b2 @@ -16608,10 +18956,18 @@ trackedFiles: id: b71b5a1e03ea last_write_checksum: sha1:02edec5ebf42348c9568876a9b278403919c973d pristine_git_object: 161e14211abf5420c91d9d53aac15c7163799699 + pkg/models/shared/accessreviewactionsservicegeneratereportrequest.go: + id: 082c570f3047 + last_write_checksum: sha1:025b086b9ec53bd4db59c0b694a05afdb67860d6 + pristine_git_object: f9a121bd422e0ee09b7faefc75198678fd2ddf3f + pkg/models/shared/accessreviewactionsservicegeneratereportresponse.go: + id: 967e490cf394 + last_write_checksum: sha1:65e550b8dd1d78dc13782c09f447e6bb863ece54 + pristine_git_object: fbfeb4d358c3aa5e5ed773397a7dfe5e3fff07b5 pkg/models/shared/accessreviewcolumnconfig.go: id: 25f598ca870a - last_write_checksum: sha1:09e9f0c454fbf0ed065cf7ef602802c580eaeb14 - pristine_git_object: 2cd33210b58487238544e0e95a5e64fcf605c445 + last_write_checksum: sha1:d69f3bdd06af3256dba54e4afb90e104a7425284 + pristine_git_object: 7fb8ad59bd86619ec380c1168d1cb3b7bf701df8 pkg/models/shared/accessreviewexclusionscope.go: id: 82deb182a744 last_write_checksum: sha1:4a6e659d76df110318711596dd3e461f6b844275 @@ -16624,6 +18980,18 @@ trackedFiles: id: a8b9aa3ebb47 last_write_checksum: sha1:d6ad255675cb5bde26f3a001e2ad8fb5c7bc8d4d pristine_git_object: f18056a65e7f750881e41f7f6f6406c949ae37ce + pkg/models/shared/accessreviewreport.go: + id: a261fc3bc408 + last_write_checksum: sha1:30b71bf2475781b454e3bd9ccf8f7805b9e5e5c2 + pristine_git_object: 0352c3e039eebb371edf7c70faf58b618bc08371 + pkg/models/shared/accessreviewreportcolumnconfig.go: + id: 5802e95493ad + last_write_checksum: sha1:cfcb8ebdbcebb6f818771e87d04a18832434b870 + pristine_git_object: 6071ee0b69ff1546bc5eebfc166eebe7841de2fb + pkg/models/shared/accessreviewreportservicelistresponse.go: + id: bac60819d886 + last_write_checksum: sha1:5c3223324ca96f025905d505d80131880a415276 + pristine_git_object: 5ae0c699bc229eb20081de53795ae874992bb7ed pkg/models/shared/accessreviewscope.go: id: 68909cdf34ef last_write_checksum: sha1:5d49185095b14b629fd20a79366e9c29d1402012 @@ -16696,10 +19064,14 @@ trackedFiles: id: 36aee2681fb4 last_write_checksum: sha1:387448b67d71be9f3c21ca488d9433984880dc8e pristine_git_object: c7a612baf5c42c6923b180f05754e328381b96cb + pkg/models/shared/accessreviewtaskcolumnref.go: + id: 2a1662624d86 + last_write_checksum: sha1:10b7611b8193f44dc7a6c7c60e4eb477a45ed67d + pristine_git_object: 974ccca092518c484c712cef6e09fef0a040b2c4 pkg/models/shared/accessreviewtemplate.go: id: 9bd797f06090 - last_write_checksum: sha1:cecee9ee66383c180da0ebf02101176fc3f4cc86 - pristine_git_object: b852121d5130041a61f692fbb9361b06f8615082 + last_write_checksum: sha1:86d3854f3d2c4b101d49e40547828ddc7010f907 + pristine_git_object: e76a9eaa7672f4004ed3414c77c038e61af59130 pkg/models/shared/accessreviewtemplateservicecreaterequest.go: id: 1c83d120e854 last_write_checksum: sha1:4715342ae28cae2804e198eb63e0a35f2f5ec8fa @@ -16894,8 +19266,8 @@ trackedFiles: pristine_git_object: ac42864cdc0793a9235ac5be704514789ccd5cca pkg/models/shared/aigovernancesettings.go: id: 547415ed9e38 - last_write_checksum: sha1:99d2664392fbe68d42883985672ba206e5619d17 - pristine_git_object: e4b83848b997fab42ec3ea49c0e5942d0d4498a3 + last_write_checksum: sha1:dd8b384bddd5a7da99a97fb3d0e9e5c0092a4c5a + pristine_git_object: a60dc93e5cb1a480af2826aca42ff74fc2feb04c pkg/models/shared/aigovernancesettingshistoryentry.go: id: ab2e46bd3edd last_write_checksum: sha1:09a80d0af3d656fa48b397b1a20d1df21148f523 @@ -16934,8 +19306,8 @@ trackedFiles: pristine_git_object: b25fc3d6f1daae954d735c4a1937609c51d9a545 pkg/models/shared/app.go: id: ba1be54230b7 - last_write_checksum: sha1:d2493823887118bf1fa0088019acdadbed4789c8 - pristine_git_object: ebd33735dda6e59b4a7fa093580f4d04d6cea784 + last_write_checksum: sha1:b1fab0269edd26fda7a75a6a8304e1055dbee18f + pristine_git_object: 7dabae0cb95368cab3af4f5a50908a5ea04e5ff3 pkg/models/shared/appaccessrequestdefaults.go: id: ce8923ee69a5 last_write_checksum: sha1:b1a11dbda0a7a1679118812086881bd0b7b7f8ec @@ -16948,6 +19320,58 @@ trackedFiles: id: b3fef3383e9c last_write_checksum: sha1:5f6d6d4ecc8360f534613fafd57ef3991f97841e pristine_git_object: 168230e87813d0231f97e600bf6899190375561a + pkg/models/shared/appcap.go: + id: c0d889dc12e2 + last_write_checksum: sha1:c1468e855793114230d2320ab94b28658c4ffaa1 + pristine_git_object: df87805f2c4407ebb38c1ba2ff1bc6d2fdf6cfa6 + pkg/models/shared/appcaphistoryentry.go: + id: d1342bb2194f + last_write_checksum: sha1:5bc4d48510d6abe119c87d9b1efb42724a924fdd + pristine_git_object: 87b5152d1d18e1cc50b942977026c3e99dbc6a79 + pkg/models/shared/appcapservicedeleterequest.go: + id: f41a47e8a8ff + last_write_checksum: sha1:3c36cb140af16f19071e825365526040c2a9f1d3 + pristine_git_object: ffeb5c36a3c4caad3ac4e1f6cd73ef72a76f7fcb + pkg/models/shared/appcapservicedeleteresponse.go: + id: 5faac34a5deb + last_write_checksum: sha1:d2f751cc479b2a1e23d5b368030e1b8a07de7afb + pristine_git_object: 7e90f05894169d2556f8d93141e16a842b616c78 + pkg/models/shared/appcapservicegetresponse.go: + id: 9a62fd94a97a + last_write_checksum: sha1:119520ab1a519ffe371fdcf5d1864924c5b6b3b5 + pristine_git_object: f65ea1d5818470dd4951656891dcacda445a3845 + pkg/models/shared/appcapservicelisthistoryresponse.go: + id: b7ae9d11ee8a + last_write_checksum: sha1:43f11ba5379a7d043803a8b141a6ed0676b310be + pristine_git_object: 318f22278da194ead941ffe610b1a1fb86c61c21 + pkg/models/shared/appcapservicelistresponse.go: + id: 39d5824f1f3c + last_write_checksum: sha1:1e4805d72e4bb8f6aa9b81120f1a0dee04e8797f + pristine_git_object: 99c96504461ac59017013a27d6cbd0f12bb078cb + pkg/models/shared/appcapservicesetlimitrequest.go: + id: a00721eb2bc4 + last_write_checksum: sha1:0c0dbb2d8dbcf67685b7ff68a5512c0742a7412c + pristine_git_object: 156f111bcad15c68ff42cbb04b9ba70daa4b2a97 + pkg/models/shared/appcapservicesetlimitresponse.go: + id: 9b348636ec25 + last_write_checksum: sha1:addbbda83ac2a4a4c4fbf05b00b4e4e7f39bcd15 + pristine_git_object: 170017c9bf71981676d3497b259515343c24a175 + pkg/models/shared/appcapservicesuspendrequest.go: + id: a57568949788 + last_write_checksum: sha1:7da555a181d9efc6f3ce33382d173b71ef19bed6 + pristine_git_object: a94659752bd2e7d68d2a5493e91a9fe328fb4c54 + pkg/models/shared/appcapservicesuspendresponse.go: + id: 1dce41fc744f + last_write_checksum: sha1:e6828cede64e969884ba6bcf87261bfa22f4379e + pristine_git_object: 05e54a68ad5a5e25b48b01d74f4e15504e9ad7ae + pkg/models/shared/appcapserviceunsuspendrequest.go: + id: 70ad9969a28d + last_write_checksum: sha1:a74497015d0826d34af358f14a82cd5946c72678 + pristine_git_object: b1d220b0beb4b88c021cca0793746013feb30a56 + pkg/models/shared/appcapserviceunsuspendresponse.go: + id: d9e9539d0661 + last_write_checksum: sha1:156f2e408d56bc7eb657c741cbc5b9054620d2d4 + pristine_git_object: 3a93f86c7e429df078b927911238f139357ae3a7 pkg/models/shared/appentitlement.go: id: 04f39ddee822 last_write_checksum: sha1:fde2ff80e518b9825eed7c607f0fe2c2ed5df283 @@ -17052,6 +19476,14 @@ trackedFiles: id: 21b8eef69830 last_write_checksum: sha1:555948d3a81ca0b3eee480f2f5b41f5dc6887ff4 pristine_git_object: 8b38e23a9f7587a88768c2c86e26a51d02f57db8 + pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.go: + id: aa7211b98b61 + last_write_checksum: sha1:fe1dd4b621e3ef193f13f875360a54397ec3dd66 + pristine_git_object: 224a36bee6071571b21c3af89497d7cde96ce30e + pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.go: + id: 32e5c28c4203 + last_write_checksum: sha1:40e2221c0b57ee88bce3f73d4bba1510f2743424 + pristine_git_object: 2bc7b5e84f9b2195f98003c65559109d73633c0d pkg/models/shared/appentitlementsearchservicesearchrequest.go: id: 0668c3512fe1 last_write_checksum: sha1:0a0a20049a7b0c554e2c0ed110cfd7c57b1955c1 @@ -17090,8 +19522,8 @@ trackedFiles: pristine_git_object: d4812d32ce06228204fdfe28a1b734e484c5e59d pkg/models/shared/appentitlementuserbindinghistory.go: id: edb9a80c8112 - last_write_checksum: sha1:de2fe8ab489e167c2e33289db01a0a7feae02718 - pristine_git_object: 535c58f13cf963c3d7c94e19873280485753e9f9 + last_write_checksum: sha1:b924182c708fd7bf662b27aba025eb3d67b83af0 + pristine_git_object: f7cdc5901f4021d085398ad4e68aed3be2f03303 pkg/models/shared/appentitlementuserbindinghistoryview.go: id: 15191edd5341 last_write_checksum: sha1:8d2b9516d34e6f16a37083fdad76237489101d2e @@ -17124,10 +19556,38 @@ trackedFiles: id: 2ac6c31f0262 last_write_checksum: sha1:0a74e9256f0a835396677646a32f1d3a1db33dad pristine_git_object: d615f9687686002d255a784ead4539352caacf94 + pkg/models/shared/appmanagedstate.go: + id: b30f7892d3f4 + last_write_checksum: sha1:cb95238f4520605651b9078caa2dc9e9f4ad5e6a + pristine_git_object: 98fece5a27e274aa67baf6a08478364d3dfbe9be + pkg/models/shared/appmanagedstatebinding.go: + id: 9220d7f555a7 + last_write_checksum: sha1:bf2dac6ed4eb590b0eda743d7714cd6f1a769409 + pristine_git_object: d0422a7e9b5216b95722c7c88c94213a5b7f59bb + pkg/models/shared/appmanagedstatebindingexpandmask.go: + id: ba2629607a61 + last_write_checksum: sha1:2f718792fd006de8ee14de10afcbf61109df2e43 + pristine_git_object: 3d29b09eaff06c3600af1cd3c348059272d7dfaf pkg/models/shared/appmanagedstatebindingref.go: id: 31530f3279ba - last_write_checksum: sha1:8692fddff997bf9e3c99ab2c44f29e0ef5307e33 - pristine_git_object: d76e28b12e35cf4d431201d45d37bbb124f25b1b + last_write_checksum: sha1:3caacd11fca4ef9a31915c3001ebfeba8519d4c1 + pristine_git_object: 52cecac94788e47365ef9a935abc7f6602c4afbc + pkg/models/shared/appmanagedstatebindingview.go: + id: 266a71811994 + last_write_checksum: sha1:2f722086e3380dd93456e5c1d0fe37c6c815bb0e + pristine_git_object: c696be273ee7b0378fc36c4045f985cadb2f1add + pkg/models/shared/appmanagedstatemanaged.go: + id: 40f39e7009c1 + last_write_checksum: sha1:0989eab903e4f4718c85b5469f47e331a99f9a87 + pristine_git_object: 9c176709a524a6d9895857fa949e72db0111cf9c + pkg/models/shared/appmanagedstateunmanaged.go: + id: 29e3f5131fac + last_write_checksum: sha1:92dc488cdf088264e7edef728b0c5ced4f3a925a + pristine_git_object: 1cb6eb00027b53d4d2bcf9edb13e856d53f2a377 + pkg/models/shared/appmatchbatonref.go: + id: edad54255035 + last_write_checksum: sha1:59caedc15be896eb79d76703138cf05cfb476c68 + pristine_git_object: d4c6a85cf4380fd206f256c1930ed1e6ddc2488b pkg/models/shared/appownerapproval.go: id: b6ce405f158d last_write_checksum: sha1:35005fb62de847606e07babffbb80fd8d1fa02c4 @@ -17258,8 +19718,8 @@ trackedFiles: pristine_git_object: 92d63d66af503493ece05f47b1d00f26e94e4641 pkg/models/shared/appuser.go: id: 7ea0457ec75a - last_write_checksum: sha1:bcdfcf88e07751660234c9cb147dfdeeb660ea89 - pristine_git_object: 14969b719dd13223f9a927e71774e9f3a2c40e65 + last_write_checksum: sha1:e3e23ecd36ec4de81dd31c22d6b40e469251aab8 + pristine_git_object: d45c6ed13640ba67749aa1d95548701f729466e1 pkg/models/shared/appusercreatedtrigger.go: id: 0d8329018024 last_write_checksum: sha1:c9b4949550af0630ab9063b8c2cf64a9e1c4ab72 @@ -17314,8 +19774,8 @@ trackedFiles: pristine_git_object: a92bce066a9ece4eb8a7d5271ef7092f13c96668 pkg/models/shared/appuserservicesearchrequest.go: id: dde7c4140a5d - last_write_checksum: sha1:a13864ee9065a67ed5a376e9af617a84e34ef35b - pristine_git_object: 7ed678e5abebc0dfbd5317f96d19d23fa0bffee4 + last_write_checksum: sha1:6e1f2b1e83ff0fafa1c73958338a45f5916a62ae + pristine_git_object: 038d15e117fbf5204032334b6928da3ca1f006b5 pkg/models/shared/appuserservicesearchresponse.go: id: 2a46bfda6e32 last_write_checksum: sha1:d9a520e73d4ad91fc4ba07369fe20f4308ef79f8 @@ -17484,6 +19944,14 @@ trackedFiles: id: c2c5b0b4a9aa last_write_checksum: sha1:e17acaa73b2a12e4250c1ebd44cfab67f9d6c12b pristine_git_object: 67585249969381e1f084f4101985ceaab1845684 + pkg/models/shared/blockoutputconfig.go: + id: 88f3b103b31d + last_write_checksum: sha1:7b7dd617a62b7d1ec87595f8cc395fa88f5dd2fb + pristine_git_object: d3295a507902ef0c32fc4b45d68a591118d04865 + pkg/models/shared/blocktoolcallconfig.go: + id: 3ed23d62b44d + last_write_checksum: sha1:b80efa1e8d766fdf2ee2b19068eb694556152825 + pristine_git_object: 8cae484a3796105acafd201f7d2abc8bd72f0ae3 pkg/models/shared/body.go: id: 29743b4e1af4 last_write_checksum: sha1:19f132ea4ec7180768c39d42cf19f2a8e6c92046 @@ -17498,8 +19966,8 @@ trackedFiles: pristine_git_object: 6b64cf1fe8d0f1b302fe62252f382fddc342b337 pkg/models/shared/builtinpattern.go: id: af6f3ca00359 - last_write_checksum: sha1:329088b0334c0d52876dc2bcf27c8baa19d9db1b - pristine_git_object: 697af2135aac9780471d4a30de3a325e9f71101c + last_write_checksum: sha1:45abe77fc21b7cc7a880c879e22b9c3a087578b8 + pristine_git_object: 7c4bcd3715ff48d3ff7547fea5fcd0a604f66890 pkg/models/shared/bulkacceptriskaction.go: id: f334e163876d last_write_checksum: sha1:41459aecc38c7166733f1e9c7a5c2532dce04693 @@ -17520,6 +19988,10 @@ trackedFiles: id: 092b68861fc5 last_write_checksum: sha1:e83b1e1686696b398f9223a9c359af0a7424c424 pristine_git_object: 74e726ff86f0c753eb7f846f6cb30f012db13f0f + pkg/models/shared/bulkreprocessaction.go: + id: 956c0a96b6b7 + last_write_checksum: sha1:e8d6a221509f54e57d5977d18ac2d10943a4f70c + pristine_git_object: c16370a3fc84d800d80c77aca399b1f9b9704422 pkg/models/shared/bulksnoozeaction.go: id: 78b7031ba982 last_write_checksum: sha1:d442e57d4baa7d6a8a37847b6197c0daff0aef93 @@ -17534,8 +20006,8 @@ trackedFiles: pristine_git_object: bb74577d91835d879bf904a0224b9a821093ab84 pkg/models/shared/bulkupdatefindingstaterequest.go: id: fdc08ea99a9c - last_write_checksum: sha1:781f16ca7242d145e68cd849cc5f2502954d3f28 - pristine_git_object: 87f97b6259b253f6d92a71fafe81f84ad8c9426e + last_write_checksum: sha1:25b82a2da2dbbd6fc642053c4aa823875ff5b083 + pristine_git_object: e11d0ea719a03bafef536becdb9e7addc0e05159 pkg/models/shared/bulkupdatefindingstateresponse.go: id: d1e4a56a6efb last_write_checksum: sha1:35b79c692efb939d82ada971277ccad00812a6d9 @@ -17632,6 +20104,14 @@ trackedFiles: id: 041c9c5b7d62 last_write_checksum: sha1:3438396c0e483553bf31e40b5e4b0c6c25dff9de pristine_git_object: 78b8a0c5794d47e4cac91444653695e16ba908fd + pkg/models/shared/c1metriccard.go: + id: 523a7c345d51 + last_write_checksum: sha1:cd44a02a1d05758ad114ddfbe145b2d37bc5a017 + pristine_git_object: c044277cd9b0b14177f91cfd5d1d29649eb61e8a + pkg/models/shared/c1metriccardscomponent.go: + id: 655e1f0957aa + last_write_checksum: sha1:c206db4224184a66e21abe73bf9d9a45de1b23ac + pristine_git_object: a1eb224d38a2b96fb8abd3fb7df32516b61bd191 pkg/models/shared/c1msteamsnotificationscomponent.go: id: 9e10ad83dc62 last_write_checksum: sha1:0baf07ba881bff39f4b8480bfc9ee5df2e25799e @@ -17664,6 +20144,14 @@ trackedFiles: id: 3388d4d6b666 last_write_checksum: sha1:228a5420222802cb0368447b9686e53b860e597c pristine_git_object: 21ae83cb7803e0d02325e7ce9bdd673a122981bb + pkg/models/shared/c1tablecomponent.go: + id: fa6a5ef54d9f + last_write_checksum: sha1:8a592a6b5c61b9f4148436f862ade2a8240d081d + pristine_git_object: 0fcd7dfbe19654384abecdb488fece29120bd51f + pkg/models/shared/c1tablerow.go: + id: eea8902faf56 + last_write_checksum: sha1:e404181de455ebe9f93b28fdf19263fc3f30e169 + pristine_git_object: dc216026c4b7c5438837475123ca35f60f7898da pkg/models/shared/c1todoitem.go: id: b616a3c01098 last_write_checksum: sha1:736f4f207953332ed0aac37999457dc0504be3e9 @@ -17674,8 +20162,8 @@ trackedFiles: pristine_git_object: 5f707666fc14e02f168f2afcbf2dc3d25ed57810 pkg/models/shared/c1userfilter.go: id: 94a76810d90d - last_write_checksum: sha1:7ff9a2676467b91a42ea8f6e09b9036b97232445 - pristine_git_object: d3868856fd2d5861c0f5b1d5300331c6a970cec0 + last_write_checksum: sha1:f12dcc6b10bb04d6d14e4ab7b97c42a578c7216b + pristine_git_object: 5965a178c836fc03db86982a249b529f5bf31190 pkg/models/shared/callfunction.go: id: ea47e22a4a23 last_write_checksum: sha1:5c7438a985ecd349dc32116366b013e3cc95b95c @@ -17756,6 +20244,14 @@ trackedFiles: id: d60812e7a16d last_write_checksum: sha1:653a6a15165466dbdaa20d32a936d9b54b033c26 pristine_git_object: 9ea97e0fb32550f5b3f2770b1ae7ac85758af117 + pkg/models/shared/clearprovidercredentialrequest.go: + id: ec7e85a2ce80 + last_write_checksum: sha1:88c69c7e4cfa2037f2842790309fa3073c5fa089 + pristine_git_object: 2b727b615674822b3b567d9f5c13f4cb8bd40f48 + pkg/models/shared/clearprovidercredentialresponse.go: + id: 927fe031ce13 + last_write_checksum: sha1:e27786540096156b917773a1da2f4570878587a6 + pristine_git_object: e9dd869eb56a7c5e4bfa824803005982b58366a2 pkg/models/shared/closeaction.go: id: 20d2d74700f8 last_write_checksum: sha1:5d1ef73a01af706dee4342543ef4bd6e97c659d9 @@ -17794,8 +20290,8 @@ trackedFiles: pristine_git_object: 2c50154f9cde07ac28415867b6b8dbc9b217e05f pkg/models/shared/composite.go: id: 1caee26a1c56 - last_write_checksum: sha1:b211af89e603c2bf78dd88b248bc502f62f93461 - pristine_git_object: 6142f46e8830fe499ef8f195a347f832bbce79b9 + last_write_checksum: sha1:06a3964e245b345d85c5fce7df5cb19dee88c58e + pristine_git_object: b45f5530ac1121e702ecb3c380d2237ed5678a22 pkg/models/shared/compositefield.go: id: 0b7b1794f05b last_write_checksum: sha1:553b3650c986ea706818db52332f93bdd5976f68 @@ -17870,8 +20366,8 @@ trackedFiles: pristine_git_object: 0fdc14233bd54eb555a51793c141effcb0ccf523 pkg/models/shared/connectoractionref.go: id: 9733fdf1bbfe - last_write_checksum: sha1:ef069b3f54f1f02efab1b3972c0f57c808edcb63 - pristine_git_object: a514e301a04d130ec3a9496380fb71fa38a888da + last_write_checksum: sha1:de2432a41adeb84facec69bdd95846ce6671142e + pristine_git_object: 077262d552a26b93bdf9e946a6ac5aa1fc47e71d pkg/models/shared/connectoractionrefinput.go: id: 7a8aa374bc69 last_write_checksum: sha1:aec3e0a51c562a16468fe04507a684282dc87ab9 @@ -17918,8 +20414,8 @@ trackedFiles: pristine_git_object: e771c9386c22957caea7942f2319efcb102c4a9c pkg/models/shared/connectorexpandmask.go: id: 8c6eebbeb1c9 - last_write_checksum: sha1:51e1ffd309194938f11b99d0dd31c73a9993be1f - pristine_git_object: 9de9e38e7c3363c2d9b4301b3b64e2757a66c29f + last_write_checksum: sha1:cde408b4b56c8966b7b86e6283ff86532d672539 + pristine_git_object: 45be187a0fb2d6b8690e0f170a6410b866eadc14 pkg/models/shared/connectorissuespreference.go: id: 73832c39c226 last_write_checksum: sha1:100065e277bedeabe39770b0b957e3d6e378a1b2 @@ -18016,6 +20512,14 @@ trackedFiles: id: c7a321242501 last_write_checksum: sha1:9494cc6ba04e174542fe444aa929048882c5cb09 pristine_git_object: 051e340449ca9a44dfa0f2b8b77544b1082fcac0 + pkg/models/shared/connectorsyncfailingevidence.go: + id: 54db81268d53 + last_write_checksum: sha1:7f39c40d450bbb6499fb4fcde57782187f917bad + pristine_git_object: 70be14f4df7eb7499e3d216cccea19f4044e0287 + pkg/models/shared/connectorsyncfailingtype.go: + id: 7ba4d2a232e6 + last_write_checksum: sha1:dad5ebf62175f1cd11aa3bd2f967caaccecc73c7 + pristine_git_object: 2ff2e3e86a38bc6a3d8a6414ac4fd1dbdd7e58a6 pkg/models/shared/connectortarget.go: id: eceba8f712ea last_write_checksum: sha1:ee20c3b9bd5c72ba5387809b8ac7c6465596a220 @@ -18102,8 +20606,8 @@ trackedFiles: pristine_git_object: 5b6d2870d68bdadf98204869ffe76bafd64fd897 pkg/models/shared/createapprequest.go: id: 5418ea908564 - last_write_checksum: sha1:74ade8db3dcb6b3c7614c2df08c53cfa571dac51 - pristine_git_object: 313bda08615d78a17d57d758e709fbb2d156ea5c + last_write_checksum: sha1:7bea64369e202ea4a8c85dc75854ccb53aa1acc0 + pristine_git_object: f7fc797215544107ce87825ac2bb26221113d016 pkg/models/shared/createappresourceentitlementownerrequest.go: id: 9d464843ab84 last_write_checksum: sha1:942cc9cea982a96632ca3d00ef3c2df49cb44979 @@ -18122,8 +20626,8 @@ trackedFiles: pristine_git_object: 1e7766de2fcbebe25cfd9bcfe3a23ff79043fb9e pkg/models/shared/createappresponse.go: id: 1ec3efba0f0c - last_write_checksum: sha1:ca6f018f40be64124f209b350fdbc71f8c3c1d17 - pristine_git_object: 04b9807d53e1091feb473b78e8076d3229dc33c7 + last_write_checksum: sha1:459f072545aeb3d6c2c6d58fad528321a69087a7 + pristine_git_object: 8c1a718e70d38f18caae25fc7c134bd622563184 pkg/models/shared/createappuserentitlementownerrequest.go: id: 95bc68530e07 last_write_checksum: sha1:ba82683e92460ddd84338b4047675b03da7743c1 @@ -18234,16 +20738,16 @@ trackedFiles: pristine_git_object: 098dc1e13cc54a5f63ac48ba501333a227c3e81a pkg/models/shared/createmanuallymanagedresourcetyperequest.go: id: cc4c9371878c - last_write_checksum: sha1:4c2d5ff6ce3d3f3748dfa2eef600782a63573e77 - pristine_git_object: acd8948d21baae7bb8a33b218dd39b991fdd26fb + last_write_checksum: sha1:cf4dd0d5b561ec3b1e623297c3b8ae19573bda29 + pristine_git_object: d23d9f5c6059785f5b2f81e866fc53e1cd2f50f1 pkg/models/shared/createmanuallymanagedresourcetyperesponse.go: id: 6cde1c277093 last_write_checksum: sha1:b26bd224f9f1f32ecc508718e09c36eeb8cac522 pristine_git_object: 3b5a8530364924c1825413791c0226684e73370b pkg/models/shared/createpolicyrequest.go: id: 9ae3cbb3bf7c - last_write_checksum: sha1:2710e6d0c229484163840dc373c137ada8de0501 - pristine_git_object: 41f2131f7a8991deebced5d9cd17346f5acde8e0 + last_write_checksum: sha1:54e3ca8c1abd9326f9169b00e8f9fe0935ca5891 + pristine_git_object: 155a2ec4210ef0618a459acedbcdf758a55f8cae pkg/models/shared/createpolicyresponse.go: id: 7451800e15ae last_write_checksum: sha1:fed6e2510d6009500c07c5a028ba25fac6732c9c @@ -18254,8 +20758,8 @@ trackedFiles: pristine_git_object: 922524e94da9ebfaf3a35327b4c07d15772e83c5 pkg/models/shared/createrevoketasksv2.go: id: c6dd9a9f572d - last_write_checksum: sha1:f013fd281c73ea39c24700b8fa2d614f4c71ac09 - pristine_git_object: f833a7c47ff7cc174b01f54920912a3fda90a9df + last_write_checksum: sha1:ffe219579a0781b4cf71d670a5d4f3846dd08b8c + pristine_git_object: 3c766e4bb0e020632d7737ce525192fb05bd5230 pkg/models/shared/createrisklevelattributevaluerequest.go: id: 6d4828cf8428 last_write_checksum: sha1:44c5266aee6d58e3034f8f7be5514ea3fbb81f9a @@ -18292,6 +20796,14 @@ trackedFiles: id: 502e428f92db last_write_checksum: sha1:c0c7bdba2dc10fa5afa73760863e9f4851e3b17c pristine_git_object: 4fb02d6304846f6301fc6414612a7ab384d02b6f + pkg/models/shared/credentialexpiringevidence.go: + id: 6198663a3f14 + last_write_checksum: sha1:ce8e5a4c93308a2941515bb23df67cdf9bc1c262 + pristine_git_object: 28918461841bbac520cc717773d27d1c0f7bb6c0 + pkg/models/shared/credentialexpiringtype.go: + id: 5579382b698c + last_write_checksum: sha1:a1e53e4e372479574a5d0be4f4e27cff60a4289d + pristine_git_object: ce13bfc7d0068d6b119b340fac0a1c6836bf0129 pkg/models/shared/credentialinventorypolicy.go: id: 466436017ed1 last_write_checksum: sha1:3a7c8c3782a548912f99e1693f3400b57ee10b80 @@ -18340,6 +20852,14 @@ trackedFiles: id: 508b26681553 last_write_checksum: sha1:92497c1abb5264f38fa3d0c7d1fbf1a3dbd5b2e8 pristine_git_object: 72c6e8a5baf19583cc350711073303c7292b94f6 + pkg/models/shared/credentialpubliclyexposedevidence.go: + id: c249b40d9d21 + last_write_checksum: sha1:69b56c02985f5f18169b283351ac7ba39b655fa2 + pristine_git_object: 2c8c22e06bfbf30b9ba0ee80c7361b6a83c462db + pkg/models/shared/credentialpubliclyexposedtype.go: + id: 55be4b50f773 + last_write_checksum: sha1:dc7406148ca9bb7971d5e94662f5ac82ba01b309 + pristine_git_object: 7bc8bb2ec93942a5fe22c3e8af39efe58436ffff pkg/models/shared/creditcardblockingconfig.go: id: 2918caeb60b5 last_write_checksum: sha1:bacf29c74719b8066ba0d846b3bdbc4289a5fe94 @@ -18356,10 +20876,26 @@ trackedFiles: id: 32f12282d9d1 last_write_checksum: sha1:fcb82284bb1f8066d32ba7ebb2773147f2e4ee04 pristine_git_object: 00b0e0f06be20a29732fbdd29ae434b7f9b73d51 + pkg/models/shared/datefield.go: + id: 56e861c59620 + last_write_checksum: sha1:241d2cdb29437d18a3a28799f0268a4a983a3f45 + pristine_git_object: 8e37c75ca0030962f6ceda54e7eabf10ab27f27d pkg/models/shared/datetimeinputcomponent.go: id: ab66d4a12375 last_write_checksum: sha1:9fcb3ea2a404ad923ffc65c170a5ef2df6ca7585 pristine_git_object: c1b6629a8b718164837dec78319c7870edf3606e + pkg/models/shared/deactivatedownerdetail.go: + id: 3ed96b53a9e0 + last_write_checksum: sha1:09bb82e122eb55148480ba8025bcabd351019bc2 + pristine_git_object: 7b3b435b0e4cdf2c1259beba81362af2cc194d80 + pkg/models/shared/deactivatedownerevidence.go: + id: 1b7931fb5c12 + last_write_checksum: sha1:97d3544a978e69bfb50bd22bcdd3301b92af1dc0 + pristine_git_object: 0b8077c2299b8bde815b3996a6ae1583ac68bee3 + pkg/models/shared/deactivatedownertype.go: + id: e3b4e911671d + last_write_checksum: sha1:672745caf2d72c5af10888994c3d26e537e8dc40 + pristine_git_object: 315a5503b98519cefab4350addcf43fe9046d5ad pkg/models/shared/decoy.go: id: 67b634b01cc4 last_write_checksum: sha1:7086046f282cb4c10126520022edfebedff4b4b3 @@ -18388,6 +20924,14 @@ trackedFiles: id: 68e25a08c87f last_write_checksum: sha1:f35390eb93544dff10608f17b0e5df1024caced0 pristine_git_object: 777c2db3cbc066262247feff33fa01ad3fb7d070 + pkg/models/shared/decoypubliclyexposedevidence.go: + id: 094755a792f5 + last_write_checksum: sha1:e4813195747928496bd2752379dae1f59bb4fe45 + pristine_git_object: 9d24e76e75caa6b9d52dedc03e20c242c0d4ba8b + pkg/models/shared/decoypubliclyexposedtype.go: + id: 9bff32d28436 + last_write_checksum: sha1:cd9ce8e30bbb62dd6ca34bb70d86182748344468 + pristine_git_object: fc61e8ddfc57dfd2e704f369d62fd495b2a35436 pkg/models/shared/decoysearchrequest.go: id: 06a9915eaf23 last_write_checksum: sha1:61706219d7713668a23e3cdd83688d08983d15ab @@ -18732,6 +21276,10 @@ trackedFiles: id: d853cda555b0 last_write_checksum: sha1:106466511bda20ba93cd83e5b068cb718dac0614 pristine_git_object: 3c2bf17ee197c0eeb3ef7a38ae5e439149b181d9 + pkg/models/shared/deviceplacementprovision.go: + id: 5b0b8984b93c + last_write_checksum: sha1:248059c5b3f33c2d6cee721682a0db95c6043595 + pristine_git_object: 33571d0b7fb81794acfa918606af8d064b70d180 pkg/models/shared/digestpreference.go: id: ba4130237329 last_write_checksum: sha1:996d359b263c03b1f2577b5eaf5ed475bdd52d43 @@ -18798,8 +21346,8 @@ trackedFiles: pristine_git_object: 5a4dff0f3015c0d79aad9499e88b55a94a42b833 pkg/models/shared/disabledreasoncircuitbreaker.go: id: bd6b78b193cf - last_write_checksum: sha1:2919eb4524c8bb6ea041817f09cf74928d63eed1 - pristine_git_object: f115282a7f2c5f17a2249f06fe43aba76eba9ba2 + last_write_checksum: sha1:69973eb1264f8a787272a932fb31faa430851bea + pristine_git_object: aac4246316839b9c5b140971439e95528dba714a pkg/models/shared/dividercomponent.go: id: 855c5f504583 last_write_checksum: sha1:c9b89b019cc4a96d16c2c7bc60b845dc0cfb61ae @@ -18842,8 +21390,8 @@ trackedFiles: pristine_git_object: 5e98cdaa9f42028ac9f6e76466117defcb088712 pkg/models/shared/emailchannelsettings.go: id: d482f68d0076 - last_write_checksum: sha1:cf283ae3bb9ad4422ab6b20766a8afc8861aa14f - pristine_git_object: ecba1648cdb863c806401df2ab6fcf70f4c647ba + last_write_checksum: sha1:277d088933f8df058b0095ce55deb41f6bbeae95 + pristine_git_object: 8a5219906bfab900980b19cf29bd14bfd10201cc pkg/models/shared/emailnotifications.go: id: ce426dc1dbfe last_write_checksum: sha1:077cd39826ce31335239947e5bc44f9b3b636f73 @@ -18852,6 +21400,10 @@ trackedFiles: id: 25d482245618 last_write_checksum: sha1:681e0af6392e417efa4d7c936c0434a92adf3f3c pristine_git_object: 53cc057f5f086f3a11815f132a04fcb78a886e6d + pkg/models/shared/encodedcontentguardconfig.go: + id: 6502c09cafc0 + last_write_checksum: sha1:40b151ac85f9326689ebce138bdd0f8c8a4098fb + pristine_git_object: c441eb168fdf3aa33e4b85717107fe129f1eebf4 pkg/models/shared/encrypteddata.go: id: 02b3cd2ce16f last_write_checksum: sha1:bafff3e59ad441bbf4a240a71f52b36b51c019e6 @@ -18860,10 +21412,22 @@ trackedFiles: id: bfc1d020e669 last_write_checksum: sha1:37cc6563ef797510794394d9c8bc3230c9dbba94 pristine_git_object: ce9e347b815ab9c436fb941ff488f154c56e2bd8 + pkg/models/shared/ensureonboardingsessionrequest.go: + id: 2204ef6bbcc1 + last_write_checksum: sha1:19c567adcfc85637b0d790219c7853273938e7a0 + pristine_git_object: c2c8afefc6c5e8c04d7490bc729e2a8741a3edb0 + pkg/models/shared/ensureonboardingsessionresponse.go: + id: c72989037590 + last_write_checksum: sha1:15203deed06d454ad768b2a76a61b510af7cf162 + pristine_git_object: 6c87507dcfb5d9fade15fc244ace78850c6681ab pkg/models/shared/entitlementcluster.go: id: 9e36665fe550 last_write_checksum: sha1:909071974fe9770f3c63a73ed90b92ff7f83b926 pristine_git_object: afcf797b4377332dbd9c2c6d4de83038ae00020d + pkg/models/shared/entitlementcutoffimpactpoint.go: + id: b2a5b4ee32a4 + last_write_checksum: sha1:b578df4e731dea4c10d8bdccb03a08c6ad660edb + pristine_git_object: 65eb1ee389e84e16c7eb9d72c653e928514a5a4c pkg/models/shared/entitlementexclusioncriteria.go: id: 010a63c06870 last_write_checksum: sha1:cd96f99304e6011cf57c1402ccb7074413477437 @@ -18910,8 +21474,8 @@ trackedFiles: pristine_git_object: 1424eb6075b51cbdb7ba329bf3b8e7542f850d21 pkg/models/shared/entitlementref.go: id: 855941f924f6 - last_write_checksum: sha1:0824d38542b5d506e2dfcaf6f1b3eb3a813cef90 - pristine_git_object: ce2b5b69a9f20a5cde4b67b4588d4c622d37c3d8 + last_write_checksum: sha1:c1222b36a8722a7b64edaab4c708c0aeba166d3b + pristine_git_object: a63ce1ceca1c1043e01734c0c4d3bea4fe9f0a4a pkg/models/shared/entitlementtodetails.go: id: 1058ef509145 last_write_checksum: sha1:15d5277b5ddf16c14f017e7a60ee8c52ce7e78e4 @@ -18952,10 +21516,18 @@ trackedFiles: id: 2e25e3c134d3 last_write_checksum: sha1:729696effa382c118983cda70cdc574877b213a9 pristine_git_object: a52561ef44a3d08c22f9479a884478f41307488d + pkg/models/shared/evaluateentitlementselectionrequest.go: + id: 80acb81c7563 + last_write_checksum: sha1:523b906dc28fe40164dc61a76a00c3a5851f3a64 + pristine_git_object: 4fd6ec1a26d5b5cd1c7ea729ee3802be35eff812 + pkg/models/shared/evaluateentitlementselectionresponse.go: + id: 0ed2985ea727 + last_write_checksum: sha1:90d32a5daf052e6403b454b83c8b722f142a48f9 + pristine_git_object: 9b7c564f378e394ab0d67fd6d562529fc5bbef9e pkg/models/shared/evaluateexpressions.go: id: fbc69a0525b1 - last_write_checksum: sha1:d53c6a322c8850db5a6c5cd93e73238483c51faa - pristine_git_object: 30667dfbec809133b49d31de9c1a8b31c60b86e1 + last_write_checksum: sha1:cad40676be215baac95515d82c61ddc65a6301f9 + pristine_git_object: 66a4116a3fdc871bb189117139ed300e896efc05 pkg/models/shared/executeautomationrequest.go: id: 16853fc90857 last_write_checksum: sha1:7d5d554b6a6229dbcb297c551ba0f0d90585cc62 @@ -19038,8 +21610,8 @@ trackedFiles: pristine_git_object: 6eb45767c3640da31e0d81b3a571653c2df8c034 pkg/models/shared/expression.go: id: 633f99cf8cde - last_write_checksum: sha1:563c174fe9dfaf764ab633ff8b1cad4ba2eb5716 - pristine_git_object: 49621fb7d6f36e827aa1d5ce460bb02f11968b98 + last_write_checksum: sha1:2879f02ab8f318c386c7212ce45f9470e318a673 + pristine_git_object: b7962894a02dbf5351857b5b1823c9a0f369bdd7 pkg/models/shared/expressionapproval.go: id: 976a1b5b60c5 last_write_checksum: sha1:4ce1695491c85aa96d1ec39b4e22c0e77f1d7d44 @@ -19054,8 +21626,8 @@ trackedFiles: pristine_git_object: ba8bfb552a3f12a10554a5b3988f2ec89d7443bf pkg/models/shared/externalclientinfo.go: id: d6e09a54f31b - last_write_checksum: sha1:4485c7f0f45151992e854491c6d459876d091324 - pristine_git_object: 5ae47d64a08d5861733f0d51c506621b5ddb375b + last_write_checksum: sha1:e330ff47a1ac13bbfdd872e48bb30a29affff113 + pristine_git_object: 53590fe613066fa32eda841883cd235244d1e24c pkg/models/shared/externalclientsearchservicesearchrequest.go: id: beb4ac087b17 last_write_checksum: sha1:c63e89ed84385d67e24ca41f1c60c3d0719d1cd6 @@ -19122,20 +21694,36 @@ trackedFiles: pristine_git_object: 2ba0fe8f62df36b2bb7a36023f739a033bb37e86 pkg/models/shared/finding.go: id: bc6dac4e45f0 - last_write_checksum: sha1:82665796813f7fab3550b70e5e87658f89dec84d - pristine_git_object: 2584b1e318d2249a1aae8840caacfe4d996e6d67 + last_write_checksum: sha1:3109a32c7f86e73cd5b99e02ef86b625cf55ea4c + pristine_git_object: d5e62639290fa9f577284c7c511874439f624e07 + pkg/models/shared/findingaudience.go: + id: 3b89afce8ba3 + last_write_checksum: sha1:f65cc60066dbbd302ec518caf9f1be9569ec13f8 + pristine_git_object: 83cbc4fb53347257b6acb318d297ba50573e2c6e + pkg/models/shared/findingaudienceusers.go: + id: 217d71632e56 + last_write_checksum: sha1:24a2cf7da3a6cb15af144c5a2ed07a57177018b4 + pristine_git_object: 4263ab5b90608974a116bbcac5a7b5eedcf03b3d pkg/models/shared/findingauditevent.go: id: 3769505c6ca1 - last_write_checksum: sha1:4c1ef911c234485a2c3d54a1417f554388eb52a0 - pristine_git_object: d21f08f979bbf4925c3c1f665c3dee1cd9334c4e + last_write_checksum: sha1:f7e9a184c0dc6ebb5a030459079da3437589c418 + pristine_git_object: 8bc69e61a8869f09f141e3509d90f1ec049655c8 pkg/models/shared/findingauditservicesearchrequest.go: id: 0d8288249156 - last_write_checksum: sha1:603529e7973edea0a141ce5f6a8f35dfde1510c0 - pristine_git_object: 9708b1ca473d5350e97451594a70e1b145aadaef + last_write_checksum: sha1:effd9f604b52beecea7b59c56e074139e02ec07a + pristine_git_object: aa6ef55f3c5d250398b310892fd4149bfd97c173 pkg/models/shared/findingauditservicesearchresponse.go: id: 0a7f4da3abd4 last_write_checksum: sha1:a6e3464921ba87117acc59aeb8c6c73f8b6749eb pristine_git_object: 41a5bddd2dd6be478ded38f42ec7dbef03e41066 + pkg/models/shared/findingdispatcher.go: + id: 5b01d7444317 + last_write_checksum: sha1:1870280c0ab9e4d2913e6624ed17531e7de55592 + pristine_git_object: 93095ce2cd25d21346263b5fc1e97003291a8cf8 + pkg/models/shared/findingdispatchoutcomenotify.go: + id: 8ff16d59ff36 + last_write_checksum: sha1:850e7356a053c2352229cd7d6bee3ef5eb9585f4 + pristine_git_object: f7cf98ca1ecaca96cedbff8be771567b5534ca1b pkg/models/shared/findingownerref.go: id: bbc594973cba last_write_checksum: sha1:1a4ab78f84adcad637dc4f578b5e295ba65cdd68 @@ -19154,20 +21742,24 @@ trackedFiles: pristine_git_object: a71acd24f096ac53ae39641c3295bad0c174401f pkg/models/shared/findingroutingrule.go: id: a28d165e9c67 - last_write_checksum: sha1:e56bd756f9c2b64a6aa4bce5c252e6075bc03fdc - pristine_git_object: 528116708a2657863b68faf82be5dcd37736cc3f + last_write_checksum: sha1:314919257209858a0c7d8f65ac07ddc76746052b + pristine_git_object: 07d2829ad23ec56f36958eac4bc134922fc2f31f pkg/models/shared/findingroutingruleaction.go: id: 39a861c6e319 last_write_checksum: sha1:c1c418b7df65f7f7db68e918cda6f6346e2b2dfa pristine_git_object: e24e6683bbc181f7276b2bf06490bfb3ead32db7 pkg/models/shared/findingsearchrequest.go: id: 2865f3058153 - last_write_checksum: sha1:d905dc26a17f1c70687b5008c8d0fc8e169012be - pristine_git_object: 3641805d7c6f16a7ecb63a54ceccc34c975d7379 + last_write_checksum: sha1:77e63b10971c0edec0707bbf875acef13a063dee + pristine_git_object: b32b28ce1067c69b525b2fb87a3c7b5c88f7eb61 pkg/models/shared/findingsearchresponse.go: id: 9334a1343441 last_write_checksum: sha1:0361df643c39a6b616679209aa30e7bbc1624e12 pristine_git_object: ad4017f00d5a067728a9e84a46ba304e61e10c63 + pkg/models/shared/findingsettingsentry.go: + id: 5eba988cf088 + last_write_checksum: sha1:77db9fdb47fb6b02a91239056f0969293c37b99c + pristine_git_object: 3461b7908fca4d8c9e5353cad639fe6598c5a5de pkg/models/shared/findingtarget.go: id: 86f92a48e925 last_write_checksum: sha1:da29078aafd1c0c16dfde64601e96e693e6e43fb @@ -19182,8 +21774,12 @@ trackedFiles: pristine_git_object: fecabc9d9896f32c68aef5b5e2ffe221a27e8b70 pkg/models/shared/findingtransformationrule.go: id: 5c3838a820e4 - last_write_checksum: sha1:fef4894c119c3e9e3bba9cc7838314031a741590 - pristine_git_object: e5f6cb9e4879dc75009d2da0544902de2d59f55a + last_write_checksum: sha1:ba4d394f1d6d1a3713e18a5a365c5d5663ae9204 + pristine_git_object: 64f35e3ccc768a5c015af5caf694c224f2c615de + pkg/models/shared/findingtypesetting.go: + id: 49ade2823330 + last_write_checksum: sha1:d626ff487f8a07cf95bd3e329f77c9449b6550ba + pristine_git_object: 88406a13cdb892db90abc5fbc5cc2aeead70a8a9 pkg/models/shared/fixed32rules.go: id: 2cbd92b3a4d3 last_write_checksum: sha1:4a9cef895696fb608d36cc43e31a25672ec4decc @@ -19210,8 +21806,8 @@ trackedFiles: pristine_git_object: af4e4c6d0689b0c670067445aef305587eb5b49f pkg/models/shared/forcesyncresponse.go: id: 18829de65e1a - last_write_checksum: sha1:49a9b8833b1c52f25eaa250e28ae0c0cc05b9309 - pristine_git_object: 9af1cc2c38140fba6f0af571b6765de28f0874be + last_write_checksum: sha1:4f23c92fd166bc813e69ea0b0a3d427943472ac4 + pristine_git_object: 0b89e750087c2a8ccb05352e3b6d8ec535f25ff3 pkg/models/shared/form.go: id: 437e129c6f9a last_write_checksum: sha1:93d91c558cf3217d0f9cf2ddd7975951a78575d7 @@ -19238,16 +21834,16 @@ trackedFiles: pristine_git_object: 46d868eb19e64be77588ef2ce085fdd6390acf64 pkg/models/shared/formstringfield.go: id: 7b2964b193f2 - last_write_checksum: sha1:4d191774490bdad14c205b67676cc1ccc1f4c95e - pristine_git_object: 2bbd79c03467d4f124c828dd2db5b582609258d1 + last_write_checksum: sha1:07c597064783123d2680c14353477bb849b2ff2c + pristine_git_object: 3f9cc872f9acc3014e7f2636ef73eed32306b384 pkg/models/shared/formstringmapfield.go: id: a993d089741e last_write_checksum: sha1:35f4378b6dcff947a22601da0b14f92718121f38 pristine_git_object: 9393a47a0625558eabc8efeca88e2574880fcb44 pkg/models/shared/function.go: id: 39fbe9b9888f - last_write_checksum: sha1:479f5a82ad1b18df85b01c153b0bc9dcc2381f00 - pristine_git_object: f50a268b9f174a19cb6fbdca2d44a617488b97a9 + last_write_checksum: sha1:4626d5322b10e19515f66641381c0c509e44cf64 + pristine_git_object: b4f723c1e2cbde5faeca475ffaf708d822c9cb94 pkg/models/shared/functioncall.go: id: 882fd37c7498 last_write_checksum: sha1:4e37b1a66fe3145bb950d4e58da08419c796f916 @@ -19366,12 +21962,12 @@ trackedFiles: pristine_git_object: 1c0ebb2587356018623ff6e7d096ff0a8c239b8b pkg/models/shared/functionsserviceupdatefunctionrequest.go: id: 162b9c8678c7 - last_write_checksum: sha1:fe58ca649b1cc658be8b6e1aec1ac1bb94d49784 - pristine_git_object: 777e9794dbe3fc14957295728d2b39be81ed55fe + last_write_checksum: sha1:d99fe4107ff20b332499fba1975c2dd349993d87 + pristine_git_object: 886ed4d5ec1d17abfe7afafe844562ba5a1c63af pkg/models/shared/functionsserviceupdatefunctionresponse.go: id: 765bee95a1c2 - last_write_checksum: sha1:f7423165e1dc34e8657b1d6e8afe3a343016a27d - pristine_git_object: bdd26ea68ee00afa3cdb68740611692d3f3f47b7 + last_write_checksum: sha1:606cf4d071f4b644204f0f7454829ef256ecd7bf + pristine_git_object: c25a1fa1923804bb6c9d46d1d52eb2f646077d8a pkg/models/shared/functiontestresult.go: id: 23c9a0cc8c9d last_write_checksum: sha1:0b6c174c9207504d9b37477bc92cac570fcdb45d @@ -19384,6 +21980,194 @@ trackedFiles: id: 9f059b2300fd last_write_checksum: sha1:4bcbe98972ac3ccb6ef455ca741209747cd23cad pristine_git_object: 44201f9cd327bc62a4c701a79747573aae31b486 + pkg/models/shared/fundassignment.go: + id: 0c842fb44d9e + last_write_checksum: sha1:0dd5332f16d8a88eb55e914f4ab93974d4afd71f + pristine_git_object: cdc2c506ce9c601969821ee4cc8d01b2f5ccbf76 + pkg/models/shared/fundassignmenthistoryentry.go: + id: 316b8c537466 + last_write_checksum: sha1:653011cea61ebbc0c71c92b45d81337a1b15d2ac + pristine_git_object: edf65370564bdb622b51609058ea49d2cfc00fb3 + pkg/models/shared/fundassignmentserviceclearextensionrequest.go: + id: f22fa39dd9fd + last_write_checksum: sha1:6db75d314781cb1ac2744225e70819dc29e7bb76 + pristine_git_object: b4deec027a439103e10aafddde05a0686cfe9e43 + pkg/models/shared/fundassignmentserviceclearextensionresponse.go: + id: 830e84fad5ed + last_write_checksum: sha1:c318057f4bd172014ec2cc09d085a3ab90547b65 + pristine_git_object: 3ea77fbbf1be54feca061a4e768b970faffdfc66 + pkg/models/shared/fundassignmentservicedeleterequest.go: + id: 60deea01f23e + last_write_checksum: sha1:044dabf299ce0d27f561f5e168a5fd8c98c5d030 + pristine_git_object: 5bb97aa69f42c56c6b5b3e42449173511b74bc37 + pkg/models/shared/fundassignmentservicedeleteresponse.go: + id: 009ae9c8944d + last_write_checksum: sha1:900a9c1610a5c63ce14019d6df083ccdc9072882 + pristine_git_object: 682e7b155f57ca978853aed7e8d88ebc09e28fec + pkg/models/shared/fundassignmentservicegetresponse.go: + id: 145586acff73 + last_write_checksum: sha1:e034d381ff3e5c85180c44dc03922ad193c761d1 + pristine_git_object: 2ed1d671e607d98fd714b3a521967ddc05a9dd87 + pkg/models/shared/fundassignmentservicegrantextensionrequest.go: + id: 1e79c83a8fdc + last_write_checksum: sha1:72c58908008a8ac42f0681f8046a3cb3bfaf7cac + pristine_git_object: 8f98c597fdcf747eadb28f36853a63f42b4ebeaf + pkg/models/shared/fundassignmentservicegrantextensionresponse.go: + id: 8b1c3cf26cc2 + last_write_checksum: sha1:976c7eb35ff6158950cdb8b2791ab16d48cc2816 + pristine_git_object: 05cf771d765cbd479256fcaf58eefcea8e514aee + pkg/models/shared/fundassignmentservicelisthistoryresponse.go: + id: f3357eb993c9 + last_write_checksum: sha1:a523ad8e18600e5f60b562b981c5052dd2162a07 + pristine_git_object: f07f55d64e81298d5915e38668a5f5f9d376aa57 + pkg/models/shared/fundassignmentservicesearchrequest.go: + id: 9190e4fb3520 + last_write_checksum: sha1:deaf7f00677fcdac0783c2e41627a0a91fc6da25 + pristine_git_object: a8101bdd7f539b5565d22dbc6f7f76996bab9046 + pkg/models/shared/fundassignmentservicesearchresponse.go: + id: 9589ffa7f7fd + last_write_checksum: sha1:ed636924050aa0b95f9285471ef5f36360dc6c37 + pristine_git_object: d1c4a04b7aeccc8318b4915b2fb6478bc3736bfd + pkg/models/shared/fundassignmentservicesetlimitrequest.go: + id: 46183754e9a0 + last_write_checksum: sha1:4e5ac3dfb177b5460afe6c4494bd15a2b7d9a9f9 + pristine_git_object: 8d543c662a6f5467bcd01c0840e81876d081fdfb + pkg/models/shared/fundassignmentservicesetlimitresponse.go: + id: efe692ea5144 + last_write_checksum: sha1:7dc5c09cc8d2294b89a383509f2f06b2586e78a9 + pristine_git_object: 6180704f1c55abb377653800fef237b4715c1c99 + pkg/models/shared/fundassignmentservicesuspendrequest.go: + id: c07541ed11f9 + last_write_checksum: sha1:69da03b56138b326808960a0e0791ac24ab32e21 + pristine_git_object: 0df0a88a09f426b5130b9b6931c74d1881b323da + pkg/models/shared/fundassignmentservicesuspendresponse.go: + id: 862b656cc5f8 + last_write_checksum: sha1:983d1b41eb3aadaafe8cbe088f251ab321317983 + pristine_git_object: 107abc561bba24db1e5622c2c0147b7c164b444c + pkg/models/shared/fundassignmentserviceunsuspendrequest.go: + id: e9593f7908f7 + last_write_checksum: sha1:15c3bde22ed0ccc5f82f7ab9a9fcc6ffe4c36ce8 + pristine_git_object: 4c33792f30232772b0cc3866340a3bbdcd756dfd + pkg/models/shared/fundassignmentserviceunsuspendresponse.go: + id: 8c4b3efac5f5 + last_write_checksum: sha1:afc1531e37444c80aa979b3457bd1de10bd08549 + pristine_git_object: 527fc0acf4c762257a57b35089b5a3781e6d0947 + pkg/models/shared/fundpolicy.go: + id: a0d387cbcc69 + last_write_checksum: sha1:4824e3b85d4ca5fe9856aa94074c0d6b632dcb9e + pristine_git_object: 2d4b25256b68bd947129d1f0d498cf91b8d463ad + pkg/models/shared/fundpolicyhistoryentry.go: + id: c12b109ddc82 + last_write_checksum: sha1:9fc17491b42b860c4f01398d2e7ba77f68725634 + pristine_git_object: 95bcfb830354d2ac6b044405697748808011b2d4 + pkg/models/shared/fundpolicyservicecreaterequest.go: + id: 1de952eafe1e + last_write_checksum: sha1:ab7ff4f5ce43e9129a9dbe7ac9e7cff33c3ca23c + pristine_git_object: fc4951513418eb7cad6a888b4adc81c4df1a683e + pkg/models/shared/fundpolicyservicecreateresponse.go: + id: 3837ed453f50 + last_write_checksum: sha1:46a4668ececcb15f514adb23597381659aa478d8 + pristine_git_object: f0e9d539c8242f07edb0a6f7e648c15c498211d4 + pkg/models/shared/fundpolicyservicedeleterequest.go: + id: eeb9a9ccb717 + last_write_checksum: sha1:9422b955291b933ba05ad10d7ebbb7f7f130dfc2 + pristine_git_object: 0293da665a129320feabf99789f0a6051b745b7b + pkg/models/shared/fundpolicyservicedeleteresponse.go: + id: 989f01ee3b0d + last_write_checksum: sha1:6f5f792d3dc7e9887c0bad1b718f0179c6c9d836 + pristine_git_object: 1a2bce75311adfc64a8a802b24a6b32fcb6ad851 + pkg/models/shared/fundpolicyservicefreezetenantrequest.go: + id: cc313c79482b + last_write_checksum: sha1:8bef3dd4479801ffd00d1b480c30631b3dd9b187 + pristine_git_object: 4f826b96cdbccd3e7d0e26e9136df4192d61e8bc + pkg/models/shared/fundpolicyservicefreezetenantresponse.go: + id: 4de7c6ed35ec + last_write_checksum: sha1:ae3bd56c47eb9cae1c10d513bb308f4f6110963c + pristine_git_object: 869cc75a9a0adef8db485c6061b6ddc6d4f0adc6 + pkg/models/shared/fundpolicyservicegetresponse.go: + id: 06c5ab5fc8b6 + last_write_checksum: sha1:8072a49b8869df29c79f03c720f819f8bbbe3dbf + pristine_git_object: 2b6d9b6630d213ca54e71a7039de43ea935b9e8a + pkg/models/shared/fundpolicyservicelisthistoryresponse.go: + id: 4802a59fb986 + last_write_checksum: sha1:e1970a09fe545c5d6b8471ce9644128401626ef7 + pristine_git_object: 016bb5abf4b5f94c9b041423b0304c5c30e2cfd2 + pkg/models/shared/fundpolicyservicesetorgceilingrequest.go: + id: 25028e2a01e5 + last_write_checksum: sha1:2c107bc69a80d832eb2f1d072d621093cb1802e6 + pristine_git_object: 5e1f01e203e91b9b53e825e4bd17d70c796067e9 + pkg/models/shared/fundpolicyservicesetorgceilingresponse.go: + id: 9f83aefb3cd3 + last_write_checksum: sha1:02118a5d247db087fe517f4887225e4417d7bce9 + pristine_git_object: d8a709677cbcbd93759cba7cc50dcaee005792b7 + pkg/models/shared/fundpolicyserviceunfreezetenantrequest.go: + id: 673760593a7d + last_write_checksum: sha1:8445ec6654de84a4e817eba3fc89015e17626f21 + pristine_git_object: caaabd42336e4cd12184209a967610ff3182edcc + pkg/models/shared/fundpolicyserviceunfreezetenantresponse.go: + id: 37a8c0ad1eff + last_write_checksum: sha1:6ec4beb9ca5dacf1f85f7c8700e272187678e97e + pristine_git_object: 1b4b2af641f8669ee52c625926f9ed301874ea80 + pkg/models/shared/fundpolicyserviceupdaterequest.go: + id: 936ee0c2524b + last_write_checksum: sha1:848aa81c6e3ad82a395fd7145e074000a8713eaf + pristine_git_object: 45648b7686415cac7ab25ba8478592c982617af0 + pkg/models/shared/fundpolicyserviceupdateresponse.go: + id: bb8940ae48c0 + last_write_checksum: sha1:b560ca8d4fa1b3bd3f5a69d4c72ce2228ebfcb2c + pristine_git_object: b90067ecd31ba3b04afc029f50a41688ee488aea + pkg/models/shared/fundrule.go: + id: 6b555b6306bf + last_write_checksum: sha1:1c3784bd7f2d6ce13a0889edff7fac682cd947fb + pristine_git_object: 18939784d54d0b4964ea87e882febc2752198a0c + pkg/models/shared/fundrulehistoryentry.go: + id: 40d12ee36610 + last_write_checksum: sha1:a2df13be3dd35375fe8238baeb2784594087164e + pristine_git_object: 69a23febc0690cf3fad4aa24255c5c30760f4282 + pkg/models/shared/fundruleservicecreaterequest.go: + id: c497cbe0b71f + last_write_checksum: sha1:de40ab83e38ee22bda1ccf901ded66f376c8a1e4 + pristine_git_object: b66c3a8d653d8ff0035e54083059b010451aa51b + pkg/models/shared/fundruleservicecreateresponse.go: + id: 9aa7f608fbdb + last_write_checksum: sha1:d67b2ccfa244043ccd6140c8f4cdb042de0798b7 + pristine_git_object: 7554d703760b636d11e9508e4aeff1ce4807063a + pkg/models/shared/fundruleservicedeleterequest.go: + id: 2ffb98b90c08 + last_write_checksum: sha1:4c92ab780c74de4ed32ab769a5c5a6763d431ff0 + pristine_git_object: 1d8bd65c3bd255c0277f9b4d587352e3475b18b9 + pkg/models/shared/fundruleservicedeleteresponse.go: + id: c3dd9fd3b80c + last_write_checksum: sha1:b0c22b6ea64700a4c89d3c31bed3ef37f6540c93 + pristine_git_object: a1a6bc182040ca7d318d9f6e3d084800f4c6287e + pkg/models/shared/fundruleservicegetresponse.go: + id: e2dd9bbe7d50 + last_write_checksum: sha1:c4d80b48eb88acd9ca64d87fdc689b4ccf7caa58 + pristine_git_object: 79160720985d6b1b8bdf8b556ec932716094a226 + pkg/models/shared/fundruleservicelisthistoryresponse.go: + id: ea78218751e2 + last_write_checksum: sha1:44e7f5b7233e695ea7a9767b30d4b5082e0539e0 + pristine_git_object: e7f8f3b06fcd3b742c74d141ccd2785e0431d276 + pkg/models/shared/fundruleservicelistresponse.go: + id: 2ce392630e90 + last_write_checksum: sha1:6d14bb42a00731ce76565c170aaceb93edcae257 + pristine_git_object: a3454249d3995c4c934520a00cd6ff355ce8476d + pkg/models/shared/fundruleservicesearchrequest.go: + id: c039fb8a2f23 + last_write_checksum: sha1:ce705b54c5f4685e02f67ab32cddfa4f47790b49 + pristine_git_object: 5d3b68068ea50fae5ecc360c157573b834e65692 + pkg/models/shared/fundruleservicesearchresponse.go: + id: 4e140a2e5090 + last_write_checksum: sha1:965e064099f3503536b4844b7dbd38eebf9d9356 + pristine_git_object: cfb0c0052ccfe4de7fc0530fcc0e99d43a84b3bb + pkg/models/shared/fundruleserviceupdaterequest.go: + id: 4cb042d9effe + last_write_checksum: sha1:d18c0ac233d7a32307d044bf6663ee959de41001 + pristine_git_object: 8b4956caabbedc630d2fa139985707fc62a973ac + pkg/models/shared/fundruleserviceupdateresponse.go: + id: 4ffee3074ebc + last_write_checksum: sha1:30dff05dbfd247fe155931786534b8051a5be48d + pristine_git_object: b0a658ea0c4af8ecc31ba4451ef97bba1cd1b0a6 pkg/models/shared/gatedtoolcalltarget.go: id: 4dfd8479743c last_write_checksum: sha1:60d2c30dbad781c611bc46182d7d191d9ec107e5 @@ -19392,6 +22176,10 @@ trackedFiles: id: 40b35b6a8a18 last_write_checksum: sha1:4fc268c2517396d4f205cc54c27e728a5bb9ffd9 pristine_git_object: 29c12e3f6247cf1ac5f2992db48fcf6ab39bc726 + pkg/models/shared/gatewaykey.go: + id: 42e324ee120f + last_write_checksum: sha1:dec4fc20d3ec971728709c7218ec1778aec014d6 + pristine_git_object: 78e82194e370e262df7663c0ea681a9cd82ac3a6 pkg/models/shared/generatepassword.go: id: 3e0472597c85 last_write_checksum: sha1:dd469d462e42c9ff6d2f186e22b38775c1538d44 @@ -19432,6 +22220,10 @@ trackedFiles: id: 9b2f7cc94c7b last_write_checksum: sha1:c567e36533f9a3181b1976e511101bee2e995e17 pristine_git_object: 7cf328e67d87b8df2440cc1d186d09462ee68aff + pkg/models/shared/getappmanagedstatebindingresponse.go: + id: 6978160570f4 + last_write_checksum: sha1:adb25f16fd7d2169bd239a9a6f8447fe6c22f045 + pristine_git_object: 2c44aca425a3e955ad03794ea021802229817644 pkg/models/shared/getappresourceentitlementownerresponse.go: id: 0951def1a86b last_write_checksum: sha1:a96b81abf1f943c93518d09b5c6f30a2e3b72a32 @@ -19490,8 +22282,8 @@ trackedFiles: pristine_git_object: d057ad4bc10b216af34cd7d3efa9d9e2cfaf07c1 pkg/models/shared/getcustomanalysisresultresponse.go: id: 65844cbd0947 - last_write_checksum: sha1:e31789d58bbc4c63ced30744b5750c023a742b32 - pristine_git_object: 716bf3095a2d60016229e5e18292b8f54d978bc6 + last_write_checksum: sha1:5d6211affefce9f076a6438ad25af124e9960b52 + pristine_git_object: ff9e2daa9d6cc2cc9904b209a59ef4689f98a0be pkg/models/shared/getemailcapabilitiesresponse.go: id: 3cdd64b5564d last_write_checksum: sha1:435f03c3d59f69753e895dda2e1f97ffab06c2b6 @@ -19524,6 +22316,10 @@ trackedFiles: id: 7e4a001f7501 last_write_checksum: sha1:39648447ff367fa3d8b7ac883b53395a6b9fd959 pristine_git_object: bc435cadd54df6ffbf5e5da59a9709bdfe1b31ca + pkg/models/shared/getprovidercredentialresponse.go: + id: 1175ec3dbcc2 + last_write_checksum: sha1:839c1350977d10391c312c006c5547f284d0f9a3 + pristine_git_object: aba3f11db6e5b5e9dca69e2c157a5e1facf9a156 pkg/models/shared/getrequestsettingsresponse.go: id: 5c54fa9395cc last_write_checksum: sha1:f5bb49d5dc9abb4a5e12ea03218ec59ece9406c0 @@ -19626,8 +22422,8 @@ trackedFiles: pristine_git_object: 3daad185d960e613a8947c127fcfc2b1b4a5df54 pkg/models/shared/grantfilter.go: id: fa2093b1affa - last_write_checksum: sha1:294d7d652a40000a25f215816b950829a6476baf - pristine_git_object: e58edef3ac71b9ab043ebc9a69a24a2e8603efc6 + last_write_checksum: sha1:754166095d88b4d5c65522caf25d9a096963020f + pristine_git_object: d9c19107c0db701007a794f528e6e3d5a1a6e7ea pkg/models/shared/grantfoundtrigger.go: id: 2f9f933af4e7 last_write_checksum: sha1:dc4044aa5c484ccce9d24ce3487b6f5bd7b77784 @@ -19682,12 +22478,12 @@ trackedFiles: pristine_git_object: 2cf251eec7eefd8ffc7c50dd610ee43002c7d664 pkg/models/shared/hook.go: id: 6ebc8c8569b1 - last_write_checksum: sha1:642489174e46ed2d317a9f35c127bbddb35ee6c6 - pristine_git_object: bbd14cde3773bff097129ea04ad11c56901cf493 + last_write_checksum: sha1:c874049f64c0deaf21026473250ab43608b59f7f + pristine_git_object: 300ab716bb20a6e2c63274444d11ab7a24b26511 pkg/models/shared/hookfilter.go: id: 4f0e0f64f53e - last_write_checksum: sha1:e1833e4b73e7653275fb009e84d4f930da666cbb - pristine_git_object: 73440df39125fc6f64e4841e262205606e2f7948 + last_write_checksum: sha1:cb998691824f0ba11e7e803a0f886b5ab895ef83 + pristine_git_object: 802edd64f260a280e83831fd0f4dd091a9ddcc9d pkg/models/shared/hookfunctionref.go: id: 85e3b2df0451 last_write_checksum: sha1:28b97263474e4d2cf1d94df8d0a9dc437b0fda26 @@ -19706,8 +22502,8 @@ trackedFiles: pristine_git_object: 14ec96f41b2d9bb89d2479f2406c97041d372ceb pkg/models/shared/hooksservicecreaterequest.go: id: 8514386030cb - last_write_checksum: sha1:2d8baf4fdcbde46f05d32b6e8dbc7816c695c14f - pristine_git_object: 4b1fe2f4517febd929c5a0334ff58fd87bef0390 + last_write_checksum: sha1:f11ba230237b8172df4f51eb94f8e295b9346d6b + pristine_git_object: 10bc658a85590393ac95f5dd743e8f818b9b3086 pkg/models/shared/hooksservicecreateresponse.go: id: 476a93ba1589 last_write_checksum: sha1:384855a2114bcd48674ec366c3e99234c692cb5d @@ -19790,16 +22586,28 @@ trackedFiles: pristine_git_object: ed46e22e288f855a6d92fc594b365cfed7092a29 pkg/models/shared/introspectresponse.go: id: b90bb738bd44 - last_write_checksum: sha1:27fc92e1f5c3924d44ede086e890baef054a93b1 - pristine_git_object: a12d54205633db275649290f9915f27fc0e908a2 + last_write_checksum: sha1:85ee5c04cb400dfa362041f76b706a7f508be7ab + pristine_git_object: 00e7051949d57cd5b5e5fe3d48da3660a025d778 + pkg/models/shared/invokefunctiondispatcher.go: + id: 3ce69d302b7b + last_write_checksum: sha1:bb810c0a8afd1402d2d5035631df4a0fb6787619 + pristine_git_object: 1c1e5e283e1ed68e10631120aa59438710ddd9e3 pkg/models/shared/item.go: id: bb5c666cb8b8 last_write_checksum: sha1:3fc217b838cff5730d573d83899b3123acdade78 pristine_git_object: 9216e369c4ff9fcdbd45a6032ccbc506695d2b54 + pkg/models/shared/jsonpatchconfig.go: + id: 6698a3fc3b50 + last_write_checksum: sha1:750fc9bd13cb489b4e1c8de0caef614afc068e5d + pristine_git_object: 2ec776102976b1e566d13e2e331399a7470b520c pkg/models/shared/keyvaluefield.go: id: c330c4d0b3c6 last_write_checksum: sha1:70bc58e9a1832b0850575c5cfc2a9e050ca2d0d4 pristine_git_object: cd1e815538deb2ac8a59c6be49459da1c0824647 + pkg/models/shared/linkfilterconfig.go: + id: d1ebc6964713 + last_write_checksum: sha1:c091a2ba1f6f1c044de5832039a4182c73698d89 + pristine_git_object: 65073ae3422ed2ae6f66cbfc95b234741f0f700e pkg/models/shared/listaigovernancesettingshistoryresponse.go: id: 052181595f0b last_write_checksum: sha1:049bb6084113873b2f896ff24b6dc4f5e688c661 @@ -19824,6 +22632,10 @@ trackedFiles: id: 936b1bb2dd57 last_write_checksum: sha1:13c084e0abb76f88eaeab1ae8e2ae1ab414b4ab4 pristine_git_object: d857f4eb2b54dba61f3f6471f62a49b00a9f9b4e + pkg/models/shared/listappmanagedstatebindingsresponse.go: + id: 7bdab60928f7 + last_write_checksum: sha1:997627dd7fdc60557e51ecca25e563076d6c50cb + pristine_git_object: 3b31199017df8aec0c2b9df9b7f0e08ce7d6e7b2 pkg/models/shared/listappowneridsresponse.go: id: 0b8b61d91eaf last_write_checksum: sha1:fe71988e6d36d98c4a211a992d6fde1c8c567f89 @@ -19880,10 +22692,18 @@ trackedFiles: id: f4e5af959911 last_write_checksum: sha1:8942f9d6fa0b5379325f701dbd1271f05cafa640 pristine_git_object: 6e5e2071aea04f7d3b74d2dd48ad633825ea27ef + pkg/models/shared/listfindingsettingsresponse.go: + id: 5a9c0a73dcb2 + last_write_checksum: sha1:3d4f5b3bcdbb231164fa25ff61b1b95380f9ae17 + pristine_git_object: f379d0c5a68d23e27e3c588eb9eb629790f95ad0 pkg/models/shared/listfindingtransformationrulesresponse.go: id: 40874fad449c last_write_checksum: sha1:d07ec1fc385333cc75b17bce46eda9f20542f6e2 pristine_git_object: 5da07bda4e72b3cb8454f460b26eae26819b7ad8 + pkg/models/shared/listgatewaykeysresponse.go: + id: 23219329d2a2 + last_write_checksum: sha1:d9b51783a53b0531062c8effd5338f0cf5bb0aac + pristine_git_object: 3e3e430a8b9453b5cc7f978ae126812fcb1e2aa2 pkg/models/shared/listhistoryentrymetadata.go: id: 859647acce86 last_write_checksum: sha1:22c011256092ee34ef390b647bc98228d8aea9bd @@ -20026,8 +22846,12 @@ trackedFiles: pristine_git_object: d03aef4ccfe7b93c63cc431092a48a314343951a pkg/models/shared/mcpaccessprofile.go: id: 09082db326c1 - last_write_checksum: sha1:2833aedcd283b0a4d51ebf02d5027cc3ed2c9c36 - pristine_git_object: a33923e075e7ba5221cf476b421111e710a67a50 + last_write_checksum: sha1:721f85d44ef04ae09eef654238196f8ba381df4b + pristine_git_object: f2c57612463620147364ea51045985c185a0d682 + pkg/models/shared/mcpaccessprofileinput.go: + id: 7d4bbe199318 + last_write_checksum: sha1:b00c1e5f8bb79040c8e067698b690c3803d9420f + pristine_git_object: 7bb0770c23f636ea5aff164d130137e056cab90c pkg/models/shared/mcpaccessprofileservicecreaterequest.go: id: c85872a18579 last_write_checksum: sha1:4ae3232f26a2043b282246320fadf03842e9ee3a @@ -20060,14 +22884,18 @@ trackedFiles: id: 47afcd3ac17c last_write_checksum: sha1:de37399de801804c32730f486f0c5a0d325a8e43 pristine_git_object: c454f279047f9ccf3e55fd75378964985137fda6 + pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.go: + id: a910cde04a41 + last_write_checksum: sha1:4023b06b645ec8beb9e4f0f6c6afaf73385f0eee + pristine_git_object: 8bbf52ff7843fee7f338dfc5c88d46a003db0aca pkg/models/shared/mcpaccessprofileservicesearchrequestableconnectorsresponse.go: id: 648aed3e3743 last_write_checksum: sha1:83e8cfb81b1f5ab71a76fb816fb7d376005275b4 pristine_git_object: 72de8e702b50fb3a2083f8a3d55f1edd8820d832 pkg/models/shared/mcpaccessprofileserviceupdaterequest.go: id: f5af1352b011 - last_write_checksum: sha1:d7452d6a24a2b05796e567bb21296dfc56a140a4 - pristine_git_object: 33c55fe3abe388ac1cd0fb3f313ee346eeda6494 + last_write_checksum: sha1:d9bc3a2a8efb267bd491d4bf48c9da0e04ea7991 + pristine_git_object: 2a81b3240da1c8e691ac102b2c8532933ba52ce4 pkg/models/shared/mcpaccessprofileserviceupdateresponse.go: id: 77e8a8b65581 last_write_checksum: sha1:c7b8fdac55c734c77706bdba3c442fb9b97817db @@ -20136,6 +22964,42 @@ trackedFiles: id: bae1932c961b last_write_checksum: sha1:f99a34c443fafa6ed98970ff863cf0b4c1e32b50 pristine_git_object: 752f467cbdedd5aa0d9b6947853315563a77eabc + pkg/models/shared/mcpresource.go: + id: c357cf61673e + last_write_checksum: sha1:ee8a06b49fe326485c255915e57aad7250023492 + pristine_git_object: 63b3df532915eb774c9462752be4a7db013b8df0 + pkg/models/shared/mcpresourcehistoryentry.go: + id: 00d00c03be37 + last_write_checksum: sha1:15179e1b0af2f4423c1d34a59013296d22281420 + pristine_git_object: 3ba1fbf7859ba037f8ab132ebbb61d509dedac6c + pkg/models/shared/mcpresourceservicegetresponse.go: + id: e287cf94ed3b + last_write_checksum: sha1:b2e56472fccce9b5c3f81fbdddeb1830cbaa89bb + pristine_git_object: 030d1c09a2cf3d47c75c5298c0480ec15799eb11 + pkg/models/shared/mcpresourceservicelisthistoryresponse.go: + id: c958e3cfd6fc + last_write_checksum: sha1:42fbbcc5323f28f6bfad4d899dccb7269cd3b812 + pristine_git_object: 5cb83fdc8501cb95160a6837515975f6919cb5eb + pkg/models/shared/mcpresourceservicelistresponse.go: + id: 753423edd430 + last_write_checksum: sha1:a0bb4db20f2f5f9165d8187a29b458537a970d1e + pristine_git_object: 13828b32c5fe3fcdde03f94dc1ff3051622d1f7d + pkg/models/shared/mcpresourceservicesearchrequest.go: + id: 9e13dc16e291 + last_write_checksum: sha1:0ed2a6142fb0c3676b33e84b6d83be3ff12b0a15 + pristine_git_object: dea97780a41d5bbf66d48dc7b7f785e87e3283da + pkg/models/shared/mcpresourceservicesearchresponse.go: + id: ec46f59d9089 + last_write_checksum: sha1:4184fa842b08b04fdf4baef8a4c1abd5b9616987 + pristine_git_object: 51efde32f845270a0314964c221a39c0d14ccf83 + pkg/models/shared/mcpresourceserviceupdaterequest.go: + id: 3f131fa9268a + last_write_checksum: sha1:c4d8d8ddb89c7b6228e56e9a18006499d5523109 + pristine_git_object: 030a76564cc3abfaedf624a8910e2f3b409ce519 + pkg/models/shared/mcpresourceserviceupdateresponse.go: + id: 9a2f7e633896 + last_write_checksum: sha1:8966ee9b2bc5dcec08d5732a9957f35ec414f682 + pristine_git_object: 508a8f5b0ac9181ac757db77ffc32288a2a11676 pkg/models/shared/mcpserverauthawssigv4.go: id: 4e2d09c3105b last_write_checksum: sha1:b0da7e7ebc2f708f254f871ccd38a3cc1669d52f @@ -20166,8 +23030,8 @@ trackedFiles: pristine_git_object: c053ec9ec0d2050af5b08072484b38eff95ed4bb pkg/models/shared/mcpservercatalogauthmode.go: id: 56e98c37a6bb - last_write_checksum: sha1:5337a08803e3472311cb90096f67d5576f0aa9ab - pristine_git_object: d2cc810174fd2c84bb838fb3ed2c06af2a276174 + last_write_checksum: sha1:88b0a1d8b6fc4eb935dcbbecd64c67596168aca7 + pristine_git_object: c69afc6ffe001e30c92780a87d10dd51751c74ed pkg/models/shared/mcpservercatalogconfigfield.go: id: bac4f5a21516 last_write_checksum: sha1:0898c0e3c375e1d2b9edcb047e79b9c5e05696db @@ -20178,8 +23042,8 @@ trackedFiles: pristine_git_object: 9e93043ec5985e5d1aa55fa6b63a406b31cd81f4 pkg/models/shared/mcpservercatalogentry.go: id: 6677ab8e26b3 - last_write_checksum: sha1:7350805a32cb11b7930dbe14da07c0944a208fca - pristine_git_object: ebe370b3f2e6b60a2a4aeaab5877e0b679774623 + last_write_checksum: sha1:2186bcfa80cab5e192a1670fd7ec21805cdcf9ff + pristine_git_object: c3740031232957ba62783c4458b0872712d79b78 pkg/models/shared/mcpserverexternalconfig.go: id: 31bed9076eaf last_write_checksum: sha1:3b5511b0c3eae9dce5f4f18dc85d6d9ebceb1b8e @@ -20230,12 +23094,12 @@ trackedFiles: pristine_git_object: 59f812af48a4fdcd4366032fac5ccc2699a58820 pkg/models/shared/mcpserverserviceregisterrequest.go: id: 922b82ceefc6 - last_write_checksum: sha1:969ca23e440ceec625ce02d77fe46d63beb64139 - pristine_git_object: 36499022b43ee79a3b00d29eca0acea5a14184ef + last_write_checksum: sha1:669d60a568d1010b5c611cc23aae95cf596b7433 + pristine_git_object: e9638606d9c61896483fbe78097b3de63537c856 pkg/models/shared/mcpserverserviceregisterresponse.go: id: 4d1888727000 - last_write_checksum: sha1:aa2414ebe7bef61c5c7b1044657b0bec23e52a83 - pristine_git_object: 2489324a3f762e1bd396984efdbe6fd98d94f637 + last_write_checksum: sha1:5d3eefe20620d05ce563d7346a5e08d3a2af8e9b + pristine_git_object: 78a70a1785e34a513929a54a66af5f606448c889 pkg/models/shared/mcpserverserviceresynctoolsrequest.go: id: 189c49f841ff last_write_checksum: sha1:b2063ad52533c88178583b1c345b00e2cfa5c3b2 @@ -20278,12 +23142,12 @@ trackedFiles: pristine_git_object: 21cdafabab1c252d102ca19f6e8b4773bc25496b pkg/models/shared/mcpserverview.go: id: 07adc5aab827 - last_write_checksum: sha1:76ebba665ac799cca97c63b565acf332b3e792f3 - pristine_git_object: 929bbb82925e758d6b907969926b81b0ba05c32f + last_write_checksum: sha1:017ba9575609529885f3b8411be5eac2863265ea + pristine_git_object: 671ebc8f161465b73d46eadcf2019559150bd60b pkg/models/shared/mcptool.go: id: 971e39e08bb2 - last_write_checksum: sha1:1b38e8037956e2c7635b7c7e0f5f5437ee832bd5 - pristine_git_object: a71f9c7c93910a6b57ce19e4d59c908e38d959fa + last_write_checksum: sha1:57bf0de117612e7ce4f4c90961db96caeaf0eae6 + pristine_git_object: 0edb3323c20b5da2a296dc337ae166e4fab66c2b pkg/models/shared/mcptoolhistoryentry.go: id: e90557c9243c last_write_checksum: sha1:5fb009f917ffc32e919e37b189a23bb87e1aefcd @@ -20314,8 +23178,8 @@ trackedFiles: pristine_git_object: db1a7797388bb0b17aaecc9c364d85531d64317e pkg/models/shared/mcptoolservicesearchrequest.go: id: 2e877dbecea1 - last_write_checksum: sha1:5cbfbad9adc4d708b3673248a3ba9ce1d3ac8d83 - pristine_git_object: b7ab83954050e76d35bf539be5641935d37d7cd0 + last_write_checksum: sha1:3e202ec7bfc06decc7a5f5a60b98bef205abf4a2 + pristine_git_object: 42c4409b42659b34139272cf6faaca042903520a pkg/models/shared/mcptoolservicesearchresponse.go: id: 77a8c72ac030 last_write_checksum: sha1:8e53a5cd333b26361dc30cf32c54003e05d542a0 @@ -20336,10 +23200,26 @@ trackedFiles: id: 61405096203b last_write_checksum: sha1:70311181042868c0e276809c671a67f3e21fce79 pristine_git_object: 50f9a69fbe4420e7bc166a27d82f8b2d98f8a152 + pkg/models/shared/mintgatewaykeyrequest.go: + id: c24981ff2bcd + last_write_checksum: sha1:cb4876c43a778c69795d5c38452dc942047376b0 + pristine_git_object: 5edc509c45bc84469e0ba3da5c061834dbee51f4 + pkg/models/shared/mintgatewaykeyresponse.go: + id: f945f0888f6d + last_write_checksum: sha1:2923f7a8c554277684fb29f0d4f3a4d868b83c0f + pristine_git_object: 514af8dcb69c6f637413ec9b834726c0d0c20b9e + pkg/models/shared/money.go: + id: 519c8f29542e + last_write_checksum: sha1:bddca0c174c62ba76c4b304b36626064b393ef34 + pristine_git_object: abc322b4f621726140747430149d2e3116cbb69d + pkg/models/shared/msteamschannel.go: + id: 2c16837698de + last_write_checksum: sha1:f12cfe55e891b9cd9654909a47f1caebd7cf8f50 + pristine_git_object: 721b10259e1596373d93b0f17fbe4dece7e27fc5 pkg/models/shared/msteamschannelsettings.go: id: 1405afe46288 - last_write_checksum: sha1:32c89a26d629117d3cbe229f4459793364548e2c - pristine_git_object: 24697a5b57874472f9b468d450e2fff2f76cc21a + last_write_checksum: sha1:afdf6dac0f8343d4a6cc951eb37c9606b1a70ef3 + pristine_git_object: 640f874b21eeb6e10d180a175fd56915d33e950d pkg/models/shared/multiappentitlement.go: id: 5e45f4d01484 last_write_checksum: sha1:67a57872911fe0d81acd3b35df570349472c9473 @@ -20356,6 +23236,54 @@ trackedFiles: id: 8fd1d8d74948 last_write_checksum: sha1:e4c894a8583aac0c3b33c46c3cc7ed1ec214e321 pristine_git_object: 7f015f384515b2f387010699cebe422ced16cdc1 + pkg/models/shared/myfundlimit.go: + id: 2a76f4c9b1af + last_write_checksum: sha1:9ce45ebf0725b37c2a3969a9689ee9b95e413528 + pristine_git_object: 9772558c4330f736d1e3c723a9ebf1cfc5243033 + pkg/models/shared/myfundlimithistoryentry.go: + id: 844b3c6914b9 + last_write_checksum: sha1:d7f9e59c48a43a364f68d217a1c72083a249e668 + pristine_git_object: 8e29b763630c54685a8afba4962e92825e837a74 + pkg/models/shared/myfundlimitsservicedeleterequest.go: + id: 4e83f3e3d023 + last_write_checksum: sha1:765d63cefe118eaa4de149cea5616db6481850b4 + pristine_git_object: 2028c489e94afd91874b2973a203d5ce5331fa1f + pkg/models/shared/myfundlimitsservicedeleteresponse.go: + id: 8a19e7539ef2 + last_write_checksum: sha1:89c5db29a68478e200f52dfa77d6fdba7c92bd70 + pristine_git_object: 33cc810a4cf1bed8b36868c66dc98a49a01ef19c + pkg/models/shared/myfundlimitsservicelisthistoryresponse.go: + id: 3742fcb8289b + last_write_checksum: sha1:be97ecc89940407c83f8ff4077a7e38001b07480 + pristine_git_object: aa157831aec1dc2eae4d9887450b3a7555370cf9 + pkg/models/shared/myfundlimitsservicelistresponse.go: + id: 3995481ba181 + last_write_checksum: sha1:3776fca13255c7e76c410cdf360955a3c4ad93d9 + pristine_git_object: 1516a0a51551d75b7bfaec5815b0c617556f6163 + pkg/models/shared/myfundlimitsservicepauserequest.go: + id: af8c9fb5daa1 + last_write_checksum: sha1:29f04afcfeb3020abd4b70450d4250a544277809 + pristine_git_object: 27d7555ef39abba76a731938140938b2f2357c4a + pkg/models/shared/myfundlimitsservicepauseresponse.go: + id: 559cfce26951 + last_write_checksum: sha1:b816fbada16e6ac7bdb35f85677138145b370de3 + pristine_git_object: 1c768782ce8442969793f4e27851b101b830192a + pkg/models/shared/myfundlimitsserviceresumerequest.go: + id: ae02d5e328b7 + last_write_checksum: sha1:d708a79ab87737b9ca48bc5450e1d530342e486e + pristine_git_object: 45cd187044e1804d0167f0581ddaa8be762e1913 + pkg/models/shared/myfundlimitsserviceresumeresponse.go: + id: 943fb090d5d6 + last_write_checksum: sha1:ab0d579721f2427dfb5cd1bc7828873bb5b8b61f + pristine_git_object: 2578998a8ff360b39c0d25c56555177d92e1b9a7 + pkg/models/shared/myfundlimitsservicesetlimitrequest.go: + id: 02694225d791 + last_write_checksum: sha1:c66146e87f02b19edb22250dde3411b1536ee2e3 + pristine_git_object: 9b05001a369ad02b095bf0966f984375228fb4ec + pkg/models/shared/myfundlimitsservicesetlimitresponse.go: + id: 5e3140fe44a4 + last_write_checksum: sha1:26bf486dabb3a9f43a67c83ec744ead33018dcea + pristine_git_object: 5e6e0a3036a31f6e17a06c4467184edc50c7dcbe pkg/models/shared/nhiunownedtype.go: id: bff5ca4c3618 last_write_checksum: sha1:597d322ec5ccb962365405777ca03e795356145b @@ -20364,6 +23292,10 @@ trackedFiles: id: d22d9d8425fe last_write_checksum: sha1:98f52d058ad29953dd80538ff9255cd87119dbd1 pristine_git_object: 4b5d71240d70df9d76b2d48b8b1d5c7d06881151 + pkg/models/shared/notifydispatcher.go: + id: 0b7bde9d422f + last_write_checksum: sha1:85434273bcd271950e13d3516f10b35fcce49854 + pristine_git_object: bb7e9cd2962158f8fe871ab72a080a3973143579 pkg/models/shared/numberfield.go: id: 845a030b147c last_write_checksum: sha1:0e8723baee2befaaedd2f85b02620588b911d821 @@ -20388,6 +23320,10 @@ trackedFiles: id: 240f68e7c499 last_write_checksum: sha1:7aa58c720a5fdb1e85317c409ba44dce928a2c0a pristine_git_object: 7bc70e293576717a17363076ed55e22aee919fac + pkg/models/shared/oidcclaimmapping.go: + id: 9d98e6427bf2 + last_write_checksum: sha1:dc26d5529d5c93ed9f2e22b7fe747d3ff002de30 + pristine_git_object: 0f00c95bea11890f385143320f482d65fcb56bbe pkg/models/shared/oidcsettings.go: id: 617d72516d85 last_write_checksum: sha1:fc6beb3d88627be69001b9ba6fca7c6ea40afbc7 @@ -20520,6 +23456,10 @@ trackedFiles: id: 46cb5f71c750 last_write_checksum: sha1:9485ef0711f0515b072855cd3cbbd48caa2d4c83 pristine_git_object: c9b520869d2e45cbb2b203a9eb197099e0f5f40e + pkg/models/shared/payloadfindingdispatch.go: + id: 3ef05adb4345 + last_write_checksum: sha1:7b274744483ba5db8abc2e4b5566bea16ab50c9f + pristine_git_object: 81fef839054f0a6cf5b0e6ebbb6655d151766b89 pkg/models/shared/payloadpolicyapprovalstep.go: id: 3365b9306ece last_write_checksum: sha1:b29aaa39f6b434312907df190c343687958a7129 @@ -20654,8 +23594,8 @@ trackedFiles: pristine_git_object: 7bc117dabad7f96b163e5a1309d545b2b9f90382 pkg/models/shared/policy.go: id: 3f2f70674c76 - last_write_checksum: sha1:3cea89b96256e92af9f612fc205632ceac4ebb58 - pristine_git_object: 7a65fa4a9c75ae76f4bab4cbe2804bfe72ed6916 + last_write_checksum: sha1:bd04d3e0882f22133004be657204cfa2b30fddaf + pristine_git_object: 3a233f17aff1fddc2a182cc838dd0f3b7af301d1 pkg/models/shared/policyeditorvalidaterequest.go: id: 1fe19bdcbd97 last_write_checksum: sha1:3a162eaeaabcd4edf934857b71d209d6573fd6b7 @@ -20684,6 +23624,10 @@ trackedFiles: id: 5998112e9164 last_write_checksum: sha1:b59e6748bc03551f5a07eede660efac1e672f7e8 pristine_git_object: 3a161e3290e0b5c65c52029e438f39d434ce9761 + pkg/models/shared/policyscope.go: + id: 496426474d62 + last_write_checksum: sha1:283aff87d4933e30c067f3b547339f0b0d62f181 + pristine_git_object: 629f2fef51db20ae7418dba2420c3894d680d3c7 pkg/models/shared/policystep.go: id: 00531339834a last_write_checksum: sha1:b1d6d8672da6a9b950d156276ec8e37b9a6ece72 @@ -20704,6 +23648,10 @@ trackedFiles: id: 7735b2ef303e last_write_checksum: sha1:b931b751221c4d6cc2b863b2ac916917aa0b65ea pristine_git_object: 8c889bce017012f27ce8dedd963a8be0a721ea2c + pkg/models/shared/pretoolblockconfig.go: + id: 5e78e0dd13f3 + last_write_checksum: sha1:c821d3b04222e34adccb9b57ea2eb774a71ee3c4 + pristine_git_object: cf874cf3ae75d39791685bc3b1970fba83171c5e pkg/models/shared/profilefilter.go: id: 6b65b2727a5b last_write_checksum: sha1:53390cf5a46f529d94499d7f09f9094eba1ef38f @@ -20712,10 +23660,26 @@ trackedFiles: id: 17d61e61117a last_write_checksum: sha1:ba47d1589112bf13b79f92976f3130986255b436 pristine_git_object: 79efc4819c6de8b881ceda9f77ba189a53ec7f83 + pkg/models/shared/programref.go: + id: 60e8faf11ce9 + last_write_checksum: sha1:cd3d3847e05ec60c49e34da9d0f337374f6712ad + pristine_git_object: a2f5d98b3a0297413198a7e4e2c79e371c72ed2b pkg/models/shared/progressbarcomponent.go: id: 5d670a188bab last_write_checksum: sha1:aee62bc7287f66352cf92e83af0305e52b66d206 pristine_git_object: 1a2756eef31fa2d743cd90b1dff8024d0357932d + pkg/models/shared/promoteappmanagedstatebindingrequest.go: + id: 8a34826033ad + last_write_checksum: sha1:84422983a459880946f20c7f2d20ca9798f3ca35 + pristine_git_object: 811229501f60c4edc9435b801d83cb805243d7d4 + pkg/models/shared/promptinjectionscanconfig.go: + id: 28247d859998 + last_write_checksum: sha1:e5b819c13a8b97dbf17a55577f8176eb926f682f + pristine_git_object: eb61e89b31cd589da882727960f556e152bbc0a0 + pkg/models/shared/providercredential.go: + id: 26d165b53c08 + last_write_checksum: sha1:a8bda43ad37d3cca420186ae555ea1b30f84f572 + pristine_git_object: 0941f4379269627a22bc6f5415e250772a29dcb2 pkg/models/shared/provision.go: id: e8e888e22268 last_write_checksum: sha1:0377abd685114045a4e55c316e314a57edc4f45f @@ -20730,20 +23694,24 @@ trackedFiles: pristine_git_object: cbd97bca32417fed9e6e29a0cebef1d4447d3ed8 pkg/models/shared/provisioninstance.go: id: 453b35cedad4 - last_write_checksum: sha1:4d788a6f9e46a7fc2b45e38b167b99721804de44 - pristine_git_object: 7698220e10bfbd3132a3f9a0886adbed5f6c1d30 + last_write_checksum: sha1:c06cfa8a45bba6293ea697d3531fbf29a60263a9 + pristine_git_object: c346789f597181f6b42db0d9fa7222b4adb70e30 pkg/models/shared/provisionpolicy.go: id: 7f7303aea9a2 - last_write_checksum: sha1:a9e25ac0f4a4418b6138069d9d6c7395e0a054c0 - pristine_git_object: 7d2d1e5f7311ecaf165af8a6e719414087bd718b + last_write_checksum: sha1:b4cb9f1da69e1cb42939cb38badc42aa90eb44cc + pristine_git_object: 1b1024feecd9c43a1e9184bbd0ee74b1d7b84de4 pkg/models/shared/provisionpolicyinput.go: id: 4c3c80e73103 - last_write_checksum: sha1:c667e0063788c732ea5b4dfed1b79de63e3f03bc - pristine_git_object: 51f0bb755076be586472e51f9ba0e6683157fc94 + last_write_checksum: sha1:ce834a3ca011b4eba7789d05498f4592211b9a81 + pristine_git_object: e358223460b257d2a016f6f8a25ba67ba3c0c915 pkg/models/shared/provisiontarget.go: id: 1e6d17534980 last_write_checksum: sha1:dee7013069d7e961b3a8149953c871efd3df5409 pristine_git_object: 97c7f23de5b61dead91c8d9b8371f1dc6671ccc3 + pkg/models/shared/provisionwaitingon.go: + id: 0d88aa17ced7 + last_write_checksum: sha1:8ce9307272277abdebd1036cee275c20bae24dda + pristine_git_object: 5b1c79ac7b4905a9f1d05712c18eb075e6342b93 pkg/models/shared/queryscopelimitconfig.go: id: 9e221e6f2161 last_write_checksum: sha1:2cea793e9f0ac2636abaaaeff1a1caf7a0a6482c @@ -20822,8 +23790,8 @@ trackedFiles: pristine_git_object: 98190e6f5607c6202eb3b0d47f82c613476e8227 pkg/models/shared/recurrencerule.go: id: 86bd6b9c4951 - last_write_checksum: sha1:88bd0dc36285d844c8d923415abbf421974bec55 - pristine_git_object: 46a116ae16c06a6b405ab7c02b77c0d901991390 + last_write_checksum: sha1:e4ddae6000cd35241a702577bdc08fba8a8aaad0 + pristine_git_object: df7339a2f563efeef99935d42afb6bb113eb6242 pkg/models/shared/reject.go: id: 885bb0262ec8 last_write_checksum: sha1:496a6b947feb9d0eaac240e1299208d22560c69d @@ -20908,6 +23876,62 @@ trackedFiles: id: 0a7df61e89e6 last_write_checksum: sha1:7c06b9b7dd77e794add221a369fae52789c7a69d pristine_git_object: 37911c01d65068c9caffe9e6460b56211e50f8ca + pkg/models/shared/report.go: + id: a43851862e2d + last_write_checksum: sha1:35c7ada376e76b379686734b29d21e5c4d35ee11 + pristine_git_object: 90a3e93336175891e0364c41ec4e45b563753b22 + pkg/models/shared/reportingservicedeleterequest.go: + id: 550d87873206 + last_write_checksum: sha1:34e1b7a351787590ef33a0035bc97e5b329ea16f + pristine_git_object: 1575efbc812cb36f43e375bd2b0a1467fdc1e74c + pkg/models/shared/reportingservicedeleteresponse.go: + id: 582a73161c7f + last_write_checksum: sha1:e19331d3eae7327478246b3ebb1d6733dafe57f8 + pristine_git_object: d1ab6d56986378209f10a1666547541c1466534e + pkg/models/shared/reportingservicegetresponse.go: + id: 40fc22a75baf + last_write_checksum: sha1:108adc3b8a1429bf0b33b5dbb1f0620bc193aba3 + pristine_git_object: fc0babbb7dedca20ec32ee60f913f3bcf4dfab3e + pkg/models/shared/reportingservicegetrunprovenanceresponse.go: + id: fa3307622306 + last_write_checksum: sha1:6ea31c13f3989713653c1d5688302f9e5548bf1d + pristine_git_object: c396fe0d4e1cc2957510198e377435c9311aad74 + pkg/models/shared/reportingservicelistresponse.go: + id: b9c9f11308d9 + last_write_checksum: sha1:6591ea6f6810e8aeecb561624047c43487b5e448 + pristine_git_object: dfbf3b1b563a070d76cdf3c7c983f45154e9a1a3 + pkg/models/shared/reportingservicerunrequest.go: + id: 08f06e63e3ff + last_write_checksum: sha1:2f18562c4ba957bd89836a33e5e26b1941113773 + pristine_git_object: 3920e7bd7879d17269bc127ec635b09869212dd6 + pkg/models/shared/reportingservicerunresponse.go: + id: 2ff81feef575 + last_write_checksum: sha1:63f91a62a2085b1c7fd67a47a7517090a778bb4a + pristine_git_object: b9f0f980e9a4c696f8d89fab699443f51bd6e08f + pkg/models/shared/reportingservicesaverequest.go: + id: c6a06d771b97 + last_write_checksum: sha1:8c8b30e3dd3d7227accfc03b464d508c12b815f1 + pristine_git_object: e80fe9632abd794b6314ffa70dc9ba4ad7a3ccda + pkg/models/shared/reportingservicesaveresponse.go: + id: df476f14c343 + last_write_checksum: sha1:f865f87185d499cd9826eec3b965e8f8b109006f + pristine_git_object: e3e38ba3622a1c887c29e407da510623f374094e + pkg/models/shared/reportingserviceupdaterequest.go: + id: 8ec97c2e6bd3 + last_write_checksum: sha1:9e2cbd0b222d3b85c6338f65469deecb484c59eb + pristine_git_object: 23444611e42d1ec523c9b002ae824c7cae91df88 + pkg/models/shared/reportingserviceupdateresponse.go: + id: c6a9771d950b + last_write_checksum: sha1:b7b28c771a02b96b0c857b6fabf207b816109f67 + pristine_git_object: 8cd4eee7039d40c4e9249f5914efb1875bc4135a + pkg/models/shared/reportrun.go: + id: e9333a6612e9 + last_write_checksum: sha1:0465a4d2e01f393cb51d1e4a27dc0da4ac921190 + pristine_git_object: 70a12a831b385f7f2ec2b7dbab45860877876566 + pkg/models/shared/reportsource.go: + id: 180fc89b283f + last_write_checksum: sha1:d5cad9c3555c6b73d107820147103c50cd42a1c0 + pristine_git_object: b57580a7b84ba97c9e3abb3fdde08a5f482610fb pkg/models/shared/requestableconnector.go: id: e1952812584b last_write_checksum: sha1:4334e7c398fc8972fdc6205eb64dd010c6c7dd47 @@ -20922,8 +23946,8 @@ trackedFiles: pristine_git_object: 1477f2791f11c2f9fd996bf4a8140d8e32f35549 pkg/models/shared/requestcatalog.go: id: e32a58e9679c - last_write_checksum: sha1:3265d739df70047470b62dbdf1099a5c9f7843f6 - pristine_git_object: 8cfc6129e7e5bdd3783cebc20593a94e5723d568 + last_write_checksum: sha1:f41482da32c8f6b1dfca17707ed1afd31cf3f869 + pristine_git_object: 24468f910e3c373c64e48326472908f15e08015f pkg/models/shared/requestcatalogexpandmask.go: id: 64b2d4bcae06 last_write_checksum: sha1:07704e4530e3a126cf74ee517e43267596f391d3 @@ -20946,8 +23970,8 @@ trackedFiles: pristine_git_object: f865baf0444874d24cbf59b5e0dba949492b6515 pkg/models/shared/requestcatalogmanagementservicecreaterequest.go: id: 4123560f8a75 - last_write_checksum: sha1:d1d12141159910288d622a6285f5f8394604e24c - pristine_git_object: e08abf692c880e7d1960aec1affcedb2d0bb1f87 + last_write_checksum: sha1:6e63131f2b776fd6519599c445466f65421b712e + pristine_git_object: 2a31e4c78b2c153fa94047743157d3300fc4450e pkg/models/shared/requestcatalogmanagementservicecreaterequestableentryrequest.go: id: 785fd4d06afd last_write_checksum: sha1:46e1c3e51e73105a6c19c4f44059aa094386c45c @@ -21036,6 +24060,10 @@ trackedFiles: id: e265861e72c8 last_write_checksum: sha1:403b6f098e2aad266d5f31a78b3339f58712c1c0 pristine_git_object: 98f6f4220fc846e25438d4ef8aa993790f7213db + pkg/models/shared/requestcreatedpreference.go: + id: 7c3b21c75da8 + last_write_checksum: sha1:406748597e0b67ac12550920c93f3f171db31a1b + pristine_git_object: 991310e78a797c3ff95ef745c2e138f2e3b1a16a pkg/models/shared/requestschema.go: id: 5125a14c3ffc last_write_checksum: sha1:48cb1983c1f5a01c4ae94992c7b01478aff63fcb @@ -21098,8 +24126,8 @@ trackedFiles: pristine_git_object: b27995698d775de9b3601dac77a5c72222268c2c pkg/models/shared/requestsettings.go: id: 3e54b1edf109 - last_write_checksum: sha1:3ad3b90fb799c05e65ffa0f45da847e88d4dc554 - pristine_git_object: a5b9ac617a9180d94a836abee85b76dec1c639d0 + last_write_checksum: sha1:d56d6992309acb1e93e19eeb8e92403a9ec62a4f + pristine_git_object: 809c7b7bdee5bf5b8ff90234294fe7e529c484aa pkg/models/shared/requiredtogether.go: id: 356d15c32771 last_write_checksum: sha1:0bca845eeaa1ab659a256d547c65f59d3b0c61e7 @@ -21216,6 +24244,14 @@ trackedFiles: id: 1717e51d18d4 last_write_checksum: sha1:378eff1a42a52f39598378e50295e65dd039aa36 pristine_git_object: 849391b6f3b610d95b593e2f8d3bc97a0ebb62ce + pkg/models/shared/revokegatewaykeyrequest.go: + id: 64cd7a8bbc65 + last_write_checksum: sha1:3c3b3069135107b095b45c816d2fcf312c07c59a + pristine_git_object: c6546c46e0bf2d3dc34b4d805d3d31d7353ac768 + pkg/models/shared/revokegatewaykeyresponse.go: + id: 19a359c11526 + last_write_checksum: sha1:7990a9f1bbe934e9093caaac71a04d5bb6f3427f + pristine_git_object: 641d402755f2d18766f7341145219614f243ec30 pkg/models/shared/role.go: id: 61e750e62f57 last_write_checksum: sha1:6598752c86480385d63ac52d1acefcdad0d71637 @@ -21258,8 +24294,8 @@ trackedFiles: pristine_git_object: b0ce655039a7007fe8288b7fc0af9bcfad6984a0 pkg/models/shared/rule.go: id: 20f6ad5db1d2 - last_write_checksum: sha1:393b9018d2c80e318513657bf65ecf88863ece85 - pristine_git_object: 89efdd5171e15dd23820f9ea8682b88617200c57 + last_write_checksum: sha1:8653becb2f5261e8190dc4634b5ce27e6784bcf1 + pristine_git_object: e82cdd6752e72fd54af88769aff938779d381b07 pkg/models/shared/runautomation.go: id: d7adb08ffbbb last_write_checksum: sha1:9b82e4ba530245fb9f8b84b0d46044f7b76aa6a2 @@ -21272,6 +24308,14 @@ trackedFiles: id: c1f575435c93 last_write_checksum: sha1:e911342bccb3111d0531a7498ac97fdeafa76ed3 pristine_git_object: 8d7e4f1f662b76cb30317ee124a2f1b4870b9512 + pkg/models/shared/samlattributemapping.go: + id: ec33f5142bcf + last_write_checksum: sha1:d83d86249ca378ae774207ed59c61da407d95159 + pristine_git_object: ad4674188e4f5ae25a9ec15d75376a5de8aa17a3 + pkg/models/shared/samlmetadatafinding.go: + id: 3a8e25e6ab97 + last_write_checksum: sha1:48ab111ba02b1056784b3f245536fa5c93e28626 + pristine_git_object: f4658ea72c5cd2b3d4408157fc6a230a7989b997 pkg/models/shared/savetovault.go: id: 1a20b0efad26 last_write_checksum: sha1:a9b92f06ee4d63ad86d199a765f1693255d9d4a5 @@ -21330,8 +24374,8 @@ trackedFiles: pristine_git_object: d8aca6d347750c2d21b4d23ce552efbc7e34c7b0 pkg/models/shared/searchappresourcesrequest.go: id: 59a58ef98b93 - last_write_checksum: sha1:ea09bc9563bb3272509af62c87f0afed9bd989eb - pristine_git_object: 6fb0136d1f6afcdaedf8090dbf7e408906d6965c + last_write_checksum: sha1:9e1fc70bc793491598d345f4a7272bdb64d7adf8 + pristine_git_object: 7dc0e9f7f7112f298b3ba29fa2a571e2e12d3fa6 pkg/models/shared/searchappresourcesresponse.go: id: 6ec3898da18f last_write_checksum: sha1:7de304c270f36a7c4785a168314d20b323987a0d @@ -21402,12 +24446,12 @@ trackedFiles: pristine_git_object: 0346b8a6712cd4e2ebe74f90990dea1be3e3a8b6 pkg/models/shared/searchcohortusersrequest.go: id: 1d4c4f9534d8 - last_write_checksum: sha1:2c120f4a26b36f4df8929856dd4e04b8f62d9f1d - pristine_git_object: 5f5c55ca029c114b0806461c948b6ac18632e6e7 + last_write_checksum: sha1:27a274f3e26bb3c191cbead3cf98dfc04e38ad1d + pristine_git_object: e9412087b277ccbbe4e7b31ef0c4003739a3bcba pkg/models/shared/searchcohortusersresponse.go: id: 6fb48cf844ee - last_write_checksum: sha1:8c32a16a4e9736aa5d8219a4484e5807e0f601a2 - pristine_git_object: a489307cae006c08592be801a2516030a66184ae + last_write_checksum: sha1:3b92c1ee1138c0244561c0dd5fcbb04b604817d9 + pristine_git_object: 0717b99aa8484a866a6905c4745b8eb56ea316c2 pkg/models/shared/searchconnectorentitlementownersresponse.go: id: c2bcfc1ad7c7 last_write_checksum: sha1:d946c3642bb56fc635a9209b3de84b7256bb0f1c @@ -21442,8 +24486,8 @@ trackedFiles: pristine_git_object: 243f1f14c1e910ea088bf0fa78f8459d43996b34 pkg/models/shared/searchpoliciesrequest.go: id: 96d8bb2d65ef - last_write_checksum: sha1:e272afef025103d1124c1c52fbb3823e8bbed4fc - pristine_git_object: beed0626b5874c23ae736d827ebd80d0a713b75f + last_write_checksum: sha1:856f2f8e6999694798c8866702cc05e352ea398a + pristine_git_object: 1d8f3823cb9c056f03c8a93fdbd94794aa4e8dd4 pkg/models/shared/searchpoliciesresponse.go: id: 577c0fc30a38 last_write_checksum: sha1:bcb831d8c8428d5ce43d04f800902cb174d3d196 @@ -21482,8 +24526,8 @@ trackedFiles: pristine_git_object: 7053a730376c0d00d49022e47425b14e755da493 pkg/models/shared/searchusersrequest.go: id: 5c75da006db1 - last_write_checksum: sha1:8544a9cc0d1036c8aa94ae747bad865bbabd0b28 - pristine_git_object: cdbfc9d0f1d3068480757d88eadaeda380a08cf2 + last_write_checksum: sha1:1fd68fcff9d346ad75c906edfb6d62fb30dfe8ab + pristine_git_object: 0d8baf1ced535d94d222b2df8dbe3b816893b5cb pkg/models/shared/searchusersresponse.go: id: bf705bc306e7 last_write_checksum: sha1:a4da554c75ee61d644351edc61f7ee530e55fc03 @@ -21492,6 +24536,10 @@ trackedFiles: id: 4bdfb11b03df last_write_checksum: sha1:8d1df5b98c526dcb299c51b340dd8a4cefdf600d pristine_git_object: d68aaf9bdf433904a6edec33cb377ab55f96e8b4 + pkg/models/shared/secretsmaskingconfig.go: + id: 6b8476dd40be + last_write_checksum: sha1:dc0a40dc45baf4451d47a9162e7415cf8bbd6f5f + pristine_git_object: 42c00d85df315fc335b9eb8e8d7564dea5c1922b pkg/models/shared/secrettrait.go: id: 9675f3364554 last_write_checksum: sha1:8a88ce2c2a5e514c9efc297df3c5bc438977b05c @@ -21774,8 +24822,8 @@ trackedFiles: pristine_git_object: 8d37c4e124ad7e50319d154d62b62294c308244f pkg/models/shared/sessionpolicystepuprequired.go: id: e97b1a4a4aa3 - last_write_checksum: sha1:32482c82f835ad090ec98b7879f2e3c99b46fcce - pristine_git_object: c14f88c3aab86b34cd6e955185b5930dec7bc97f + last_write_checksum: sha1:6ac9abaa7612115ae6349f91a29700ba984bbf52 + pristine_git_object: 90941adf032adc93dea855f9a73012872f7c21b7 pkg/models/shared/sessionsettings.go: id: cf946171dec0 last_write_checksum: sha1:a56373de5415ff5b2e9d6c6c4c5018a37b5b51e6 @@ -21860,6 +24908,14 @@ trackedFiles: id: 8fbe6dc63e7c last_write_checksum: sha1:bcfbdd2201b299b96c14be0ed360f810875bf90a pristine_git_object: b610c8bf9eabee9f8c4d216a53c791a104b1bfaa + pkg/models/shared/setprovidercredentialrequest.go: + id: 1bb8ab228ac3 + last_write_checksum: sha1:ad67f53ea00d26fe05db58b83c9b2c2fead7bd7d + pristine_git_object: 1901932daef933eadbcbe4d2710818dc154cc556 + pkg/models/shared/setprovidercredentialresponse.go: + id: f35420cfcd6f + last_write_checksum: sha1:f2218a8a1f3fcd604b432d89a6568048c6892644 + pristine_git_object: 3ea5b5186109119948a73f01a2019d7a20d59ac3 pkg/models/shared/setseverity.go: id: 17deca23a44e last_write_checksum: sha1:7c652e6198e3ff7fd78c138e873f32327cc64254 @@ -21974,8 +25030,12 @@ trackedFiles: pristine_git_object: bbca6b2933e91da87fc12b1f79c70c65267ec83c pkg/models/shared/slackchannelsettings.go: id: 8729e4eb8d09 - last_write_checksum: sha1:1bdda794af3002e79664c5e423ed8c09e97cf10d - pristine_git_object: c4040e725bacddf5720b4d515b6add95db00a19c + last_write_checksum: sha1:038e1a8231c8e007afb38024d85d69f3d45d86b4 + pristine_git_object: aeb7081559aa949858ecdb4011a3a4d8182fa940 + pkg/models/shared/slackchanneltarget.go: + id: aa6765ab45e5 + last_write_checksum: sha1:b0a4fb26ac95bf461efe6913af736ea84f320e97 + pristine_git_object: 9bcc85b018c6f1043a49989e2b946aab64dec336 pkg/models/shared/slacknotifications.go: id: 41159f9f2297 last_write_checksum: sha1:0268ad2af4cafa437001ae3d64a0eda284c025ef @@ -22000,6 +25060,34 @@ trackedFiles: id: 5e6b8d969fab last_write_checksum: sha1:54be71b2333d198125430b3e11ba51a062e611a9 pristine_git_object: 588cd11aac4999d75245e8f2dfa459b81c41acf6 + pkg/models/shared/spendcontrols.go: + id: f4c5f4ade2f1 + last_write_checksum: sha1:f55d2582df5047ffd41a1434370977c20251ca6f + pristine_git_object: e1310549d159bd25c5624d1eedad1447e670ce67 + pkg/models/shared/spendextension.go: + id: 2765bfae7586 + last_write_checksum: sha1:cd7611ead622c929e1b6069ad91bef1f777eef56 + pristine_git_object: 7c660235b64ab43336a601d114b828e34b35d48a + pkg/models/shared/spendlimit.go: + id: d7758b06fe77 + last_write_checksum: sha1:89c5453af6a2715d583c1a01e361a6642e947d24 + pristine_git_object: aa27da6946ff66dfe8c81f1f60874bf51af2fcd2 + pkg/models/shared/spendlimitamount.go: + id: 92ada8e088dc + last_write_checksum: sha1:9f7a33e744920d6b93dbcf2e328314428af500cc + pristine_git_object: 9ba59c05889ccdeac0b67b5d87aecdc5e718b280 + pkg/models/shared/spendlimitblocked.go: + id: 678edcdfb667 + last_write_checksum: sha1:632e545c7623e498e388e9c1ea7d8d67f47f5381 + pristine_git_object: 4b504e15ee38f8ed141788f69e2c99bd1d9c8951 + pkg/models/shared/spendlimitunlimited.go: + id: edf22a322c10 + last_write_checksum: sha1:11b5515983b76ad797d558d64503b60d42defc7f + pristine_git_object: 21051476b554e5bf9d90ce13d14bb77be473c3d5 + pkg/models/shared/spendsuspension.go: + id: 8c4ffbd69ba8 + last_write_checksum: sha1:55b2c40b2c1b38a988f2fe74ce810dc67a924f25 + pristine_git_object: 597ff8710f6b16a94b592e5a51ce6249c5d7ad48 pkg/models/shared/spiffesettings.go: id: 2704cc843e14 last_write_checksum: sha1:d996dbd567931a674cb99dda1e370fb6e7de1208 @@ -22088,6 +25176,194 @@ trackedFiles: id: 3471f9f7091e last_write_checksum: sha1:8335cf82d4aaf96d431d6ac968134eda933c342f pristine_git_object: 77aa7380b9fc6bc1d253408d8ad2d5b766528ec7 + pkg/models/shared/ssoapplication.go: + id: 51089cd20938 + last_write_checksum: sha1:5a288069ab4b32220b2c59125040ca47996964a9 + pristine_git_object: 337de4aa579d6c58c4b31bd96a4417b71f3ac2d8 + pkg/models/shared/ssoapplicationhistoryentry.go: + id: d0c0d51b3049 + last_write_checksum: sha1:ccc76d540949e5ea977d87629856f0f1ea36b94b + pristine_git_object: 3cb0d52de5fb3bf653a642064daf3d4517874d85 + pkg/models/shared/ssoapplicationoidcclient.go: + id: a57db9a0da94 + last_write_checksum: sha1:9c3a3c7be82185f3d4526ddc745eb4356a1ff610 + pristine_git_object: 62e4ef9a36b010adf7123d922270459a812b54d4 + pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.go: + id: c70af730ea83 + last_write_checksum: sha1:975c55fd861075045f91147a74060469daf3a071 + pristine_git_object: 8fb6be6d6433c8602ba0f1dd88f007ebd60be2e0 + pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.go: + id: 37ab44602582 + last_write_checksum: sha1:2755e8c3ff114bfe0ae2beddd2fc402121ba0b5d + pristine_git_object: 49eaa00a562895c836fc3bd12dcd642c3f7c9cd3 + pkg/models/shared/ssoapplicationoidcclientauthentication.go: + id: 91e51b2fd00d + last_write_checksum: sha1:d5b187d2096cad49dbe03de75dd11ef90d8328a9 + pristine_git_object: fa0994662f4851db0362511146bc4a10c6f558a7 + pkg/models/shared/ssoapplicationoidcclientauthnone.go: + id: 0debead180b2 + last_write_checksum: sha1:2ce07abee0a1076ea058484243f024876834c2d7 + pristine_git_object: 0fba744d20e79b1382c3f166e4f261dcaa09c602 + pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.go: + id: 84f9f439d933 + last_write_checksum: sha1:d5b41dbb0db34a57a397a3fba449c16839036503 + pristine_git_object: 9f25b9137160411fe756bd7d125782b2ec8361b3 + pkg/models/shared/ssoapplicationoidcclientconfig.go: + id: d48ed93c32be + last_write_checksum: sha1:364b17c16a4ac4cae58c96ba1cda8ea0a01b431b + pristine_git_object: 4d41b48b8377b3f1cd3d73fe9da25e0edc6e7d32 + pkg/models/shared/ssoapplicationoidcconfig.go: + id: 6644ac03e1b9 + last_write_checksum: sha1:cbe76fa16f01ed5df41f8057681a0d7109726b64 + pristine_git_object: 1808ac215f1ace4390924bc0fa7763eb13bc1ac3 + pkg/models/shared/ssoapplicationsamlconfig.go: + id: 0d92248f5843 + last_write_checksum: sha1:1b52187137a211c90ca948829f684ce033f72793 + pristine_git_object: e9325db31f3d1a8eac0518226c2e27560116d755 + pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.go: + id: cab0e263d7a7 + last_write_checksum: sha1:cd4b4813d9e98b33ffc1708628ce0f45ef5a7e8b + pristine_git_object: da0978ece66ea6a81415f71c72d8f8b77371e137 + pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.go: + id: fb38493c39dc + last_write_checksum: sha1:16f154c8dd87a0b815886f108730712e0864d8f9 + pristine_git_object: 62298454a920b6afce0af66d8ad987008b17468d + pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.go: + id: 7bd5df18aefa + last_write_checksum: sha1:637357a0b0a3dd5dbeafbc8b4fec676c641a6efa + pristine_git_object: 820e19e937d97387c8037b22f519398fc70a5332 + pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.go: + id: c3cb9d20ba1f + last_write_checksum: sha1:b1a6e1d414e39eefc28f0cf19d6efcbf8056fef9 + pristine_git_object: 1ff2c8f63e61f2f921820b8bca6caf87faa45467 + pkg/models/shared/ssoapplicationservicecreateclientrequest.go: + id: 80ce7e777a10 + last_write_checksum: sha1:dd2d7194a4d92982fb3c860b4b96b7f3a677ab6a + pristine_git_object: 7cdb446bef617e92f319f136f343edcbf0efe82d + pkg/models/shared/ssoapplicationservicecreateclientresponse.go: + id: 5f983918ecd6 + last_write_checksum: sha1:3fd54df716db03acb3f2cfb52ddd8bd69d4c1619 + pristine_git_object: 5ee4e6181b1414b8820d24bce1ed39992cddc5d8 + pkg/models/shared/ssoapplicationservicecreaterequest.go: + id: 50914193064f + last_write_checksum: sha1:a4c565b7957e5cea423e6960a6d770bfde4edf8b + pristine_git_object: 72668f79f1929819e4de961b3baf3c997d54e4e2 + pkg/models/shared/ssoapplicationservicecreateresponse.go: + id: 32247c289c05 + last_write_checksum: sha1:b69122d722f9a8a5f91cb63b73ec39a3fa40fbf3 + pristine_git_object: b97bee66743ca673ccc467e88c82641e47bbbc7a + pkg/models/shared/ssoapplicationservicedeleteclientrequest.go: + id: e3519eee1808 + last_write_checksum: sha1:b7e705dbecf4b759e9b3c2d11f9c406410fc09f7 + pristine_git_object: e2097f70bc47ec9c4546132b1f2408d68df0114a + pkg/models/shared/ssoapplicationservicedeleteclientresponse.go: + id: 4544658e41b2 + last_write_checksum: sha1:793b9ffcdc716c914f03069db7975883711498e3 + pristine_git_object: bca373b69606380a65f5755c1e146880299f6be7 + pkg/models/shared/ssoapplicationservicedeleterequest.go: + id: 9098f64ad647 + last_write_checksum: sha1:a083f3d7c61925aaef94fbd6996e09bf559178ed + pristine_git_object: 06477bff5ae4a5cead2c5179fe86eb7735fd2fb3 + pkg/models/shared/ssoapplicationservicedeleteresponse.go: + id: ff929cbdb080 + last_write_checksum: sha1:f3111489c6715e2572b18692ea230a5633a4410b + pristine_git_object: ba66bb55c9ef3bb72f8fcadbbfa2cad099cd0b9e + pkg/models/shared/ssoapplicationservicegetresponse.go: + id: fc8a1de5b8cc + last_write_checksum: sha1:7393437d5d1d83c758ed05b21f2bb8d401abe423 + pristine_git_object: d3a0da5a5e067000107dfc8bc3c0f8acf4c8decb + pkg/models/shared/ssoapplicationservicelistclientsresponse.go: + id: ed71123ea422 + last_write_checksum: sha1:84ba389bbc7dd2685fd53d86373bc44efe3e2842 + pristine_git_object: db61a7834091311db701e4931f3ede3a610bf1a5 + pkg/models/shared/ssoapplicationservicelisthistoryresponse.go: + id: 7af78a2ca803 + last_write_checksum: sha1:5061f8649e4b3d2b3b0a3a306032fef98b0abe24 + pristine_git_object: 0cd2f21c2b6f546974a09e935a4463573de3cbd7 + pkg/models/shared/ssoapplicationservicelistresponse.go: + id: ba1079772a56 + last_write_checksum: sha1:a148e4f9236950c54375710ac566ba65d6959ac2 + pristine_git_object: 1d98bb8ffd2bc01a51aee47ad41f2a638164f833 + pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.go: + id: 18bca8ae5a19 + last_write_checksum: sha1:6542237070cf0c6b01d4c882d98174400fefd776 + pristine_git_object: 3ba93ce0f0f32864fe0f40607134fd5b81185e32 + pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.go: + id: bf06d8a83b8e + last_write_checksum: sha1:8f5b15697679a94d71635ff4e20bb965eccadb64 + pristine_git_object: 4adea223767b034d184818585e4faab7721210cd + pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.go: + id: 99211e532006 + last_write_checksum: sha1:5a1cb9e8ba7d6b5ea3d5dc8020ac1f460d6a37d9 + pristine_git_object: 7ca0fd13f08f5342c030fc42a4a3a59d86c9a93f + pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.go: + id: 354e8e27c8e4 + last_write_checksum: sha1:eb27347d352d928665f6d3cbb5ffb7836edb89a7 + pristine_git_object: ddbbec9d3bc9f1f94df3ec1e0c8d14fddd6aa1d9 + pkg/models/shared/ssoapplicationservicesearchrequest.go: + id: 78bb399f77fd + last_write_checksum: sha1:2dc35f409554cac113f56ee7e78ee956161503b8 + pristine_git_object: 40dbc31a67d234acc976fdc44c39b3d2002e4b30 + pkg/models/shared/ssoapplicationservicesearchresponse.go: + id: 56ed52384ac3 + last_write_checksum: sha1:c1466de36c682515582a06e22d15f259dc5726ee + pristine_git_object: 7c2ac2d1f7254554ab5fd0c563dd6bed0f44ffe8 + pkg/models/shared/ssoapplicationserviceupdateclientrequest.go: + id: f03847f386c9 + last_write_checksum: sha1:631fb459ffc42e66f3d2626b316f00167771baa9 + pristine_git_object: 695fe912bd2ec34f22ffe5c7380be68bb582d8c4 + pkg/models/shared/ssoapplicationserviceupdateclientresponse.go: + id: 4477bbc38325 + last_write_checksum: sha1:79fb8e71177f08695ed255f71084f65e525202c8 + pristine_git_object: d07ab615a42e8e875bc8a38453f529dc1ab21400 + pkg/models/shared/ssoapplicationserviceupdaterequest.go: + id: ab4855804179 + last_write_checksum: sha1:6b7dabc9c48ecdd1d1c845bf1adacc1e5d0fd0c1 + pristine_git_object: 650b409c82bc16d5e2d6575195d938ec995a1833 + pkg/models/shared/ssoapplicationserviceupdateresponse.go: + id: d5361e9b865e + last_write_checksum: sha1:d98e92d123d86dc1f3e30095aa02f029e2cf8da7 + pristine_git_object: 03f3d2d9ab2f5ab27e88f03e4029aafc3dd192b6 + pkg/models/shared/ssosettings.go: + id: 6839cceac898 + last_write_checksum: sha1:ac9862a2919e5e7122b0cf771f1cd75ce8d2412d + pristine_git_object: 80f9f62933be28eca2b060fd92516fb5c4da1283 + pkg/models/shared/ssosettingshistoryentry.go: + id: 2ae6eed8d7c2 + last_write_checksum: sha1:74ac2e9cc8ce7458709e6295a12766e72367b407 + pristine_git_object: d4ca5e2233e44e83421f76e634513cfca7cb03f5 + pkg/models/shared/ssosettingsservicegetresponse.go: + id: 67f59b5e2753 + last_write_checksum: sha1:70ccf3d45b6f4bd315d02ff540eab5d7714b64ae + pristine_git_object: 7b2f8583332b0266a6bdda4f627549a0fd161260 + pkg/models/shared/ssosettingsservicelisthistoryresponse.go: + id: 0ae09201741b + last_write_checksum: sha1:7bc8c332069daea3f59fba125d49cb32b4d808b5 + pristine_git_object: 052f6cdc498fee0008e6d6768dd9a6253703e2f1 + pkg/models/shared/ssosettingsserviceupdaterequest.go: + id: 4d470a01ecfb + last_write_checksum: sha1:818b8c148e167395e23a7c9fb19ac37710d4c4ea + pristine_git_object: 25dbb80b2bd7e3b3919c22586198cb2a948a4acc + pkg/models/shared/ssosettingsserviceupdateresponse.go: + id: d3cf534d8051 + last_write_checksum: sha1:e8f6f2cc5e369fb3053f61d12ee5f1d6aa2b0553 + pristine_git_object: 4027a7ffd4dc4a9a494c19fd74029f86b74d46af + pkg/models/shared/ssosubjectcompatibility.go: + id: 63024e6a1c87 + last_write_checksum: sha1:0422e87aa5d31aa7baaa562a21d2408769a4cb41 + pristine_git_object: f0f40442f5c7a943f051051ab0c29e3f76ee2ea5 + pkg/models/shared/ssosubjectcompatibilitydeleteissue.go: + id: 69fca1c106b3 + last_write_checksum: sha1:d915c7bc256e912e1964df4531a73059181901a2 + pristine_git_object: 55b6dddac73af5fbaa9fe7c0a9c4f0eb37045828 + pkg/models/shared/ssosubjectcompatibilityimportentry.go: + id: bc3330703521 + last_write_checksum: sha1:2245b6650a95e091ba39f36f9c88fc743f9458d0 + pristine_git_object: 8dace5ed31a86e1571cb950d121d64e9f5d299c6 + pkg/models/shared/ssosubjectcompatibilityimportissue.go: + id: 320c3c634df1 + last_write_checksum: sha1:a54c81c001ea015d407cfbe6689c8b655175de59 + pristine_git_object: 69d35bfe0835508a412fe371d2570fc1f854258f pkg/models/shared/status.go: id: 7195de447bfb last_write_checksum: sha1:81721422194c787c893860bce2d096a6edf8496d @@ -22150,8 +25426,8 @@ trackedFiles: pristine_git_object: a861ffe2d0892c8fea51608a84ff40b48f97bba0 pkg/models/shared/submittedtaskaction.go: id: 32e70c4caac3 - last_write_checksum: sha1:3fb7d84255e0d53681420c0a1f41c766aca0892d - pristine_git_object: d00f9ae80460b9b419e1b1680ac32c33e0e1f018 + last_write_checksum: sha1:af11c59c4a305791fac1e000803a9a696b8a39bc + pristine_git_object: b2511b622e062d9bdbcd107470eac87c032e22ea pkg/models/shared/suppressroutingaction.go: id: 23cc9694fa59 last_write_checksum: sha1:dc4145d877b31785761eac32b98dbeee59263f2e @@ -22172,6 +25448,10 @@ trackedFiles: id: 1c0941aac4a4 last_write_checksum: sha1:a8e6984b00ee33e94e1509f0f432f66ab27d549b pristine_git_object: d8f4578408028da60289c984299014337eb0a557 + pkg/models/shared/systempreference.go: + id: 1e5e2194371c + last_write_checksum: sha1:090f4a71506051d01c99a76211067b8b9cb27a93 + pristine_git_object: cac10433f4264500de1c4b188731cc6ce2e9492d pkg/models/shared/targettask.go: id: a35716b2bd5b last_write_checksum: sha1:9ba96aa48f4cd70c9cc8942e6e3e9ba65430257d @@ -22182,8 +25462,8 @@ trackedFiles: pristine_git_object: 8f1a0687f783fc8fa3fc33c72cae1fa8edc9edec pkg/models/shared/task.go: id: bc5e5c6845c6 - last_write_checksum: sha1:b5d5181de012f1f848958ab616e41d39459fe79c - pristine_git_object: e4318092e63e584c61ba28912149bd3c1e7e0168 + last_write_checksum: sha1:1a19df1fbe132b25e1f439d3ea43be7439d1c145 + pristine_git_object: 2ed14bc082f8abb657703adeaf7e0a41a23b4c72 pkg/models/shared/taskaction.go: id: be0448def898 last_write_checksum: sha1:8c3542e677c3a0cf0d6e05445c25c1642b1e826f @@ -22272,6 +25552,10 @@ trackedFiles: id: 4e7390cb502a last_write_checksum: sha1:73a9b1470bf3002f8f5e0e3b2bbf74d3ab00ddbc pristine_git_object: 0811a2bdab31565432639bdb63159b02e1736792 + pkg/models/shared/taskactionsserviceretryprovisioningrequest.go: + id: ccdf406ce4b7 + last_write_checksum: sha1:27876cb5fc3351f30c795656e4ae5be581cc544c + pristine_git_object: 31ecddc67598fa93262114fc6c2e4483a0ee3a8b pkg/models/shared/taskactionsserviceskipsteprequest.go: id: 45928b7feb22 last_write_checksum: sha1:0eaf26c9ae948da6f353819d6993a43f8352c1de @@ -22288,6 +25572,10 @@ trackedFiles: id: 28245108f4c6 last_write_checksum: sha1:d9e19c6c0d29926454e9b3d43f31b658b79ea6ab pristine_git_object: 877e83f104f83dbd72f040a460b77a74f30db63b + pkg/models/shared/taskauditaccountdeleted.go: + id: ed27b78266e9 + last_write_checksum: sha1:f86b3235d26af3faadf8d15bb947a95031fa533a + pristine_git_object: c5c69ef344fb6cc11d3b7888aaf205524f4c881a pkg/models/shared/taskauditaccountlifecycleactioncreated.go: id: 60859aaf8330 last_write_checksum: sha1:49e611d469560e78269aec38ff0c4ccf6ba60cdf @@ -22328,6 +25616,10 @@ trackedFiles: id: 1c86ef13539e last_write_checksum: sha1:454d493c463310ac5e25bc4c5fc87e9e555355b2 pristine_git_object: 4e780bb02a96ebab2b81f855190d984949f9d636 + pkg/models/shared/taskauditautomationtriggered.go: + id: e1539ae1f8d8 + last_write_checksum: sha1:d0d82f9c2c9e8af66a6305f8207cc4399282684f + pristine_git_object: a356df92411ebd6d0ac85409a50056331ab5f612 pkg/models/shared/taskauditbulkactionerror.go: id: ddf5631614e2 last_write_checksum: sha1:ced8f3d867e085af8f1b93279e868659f90220b6 @@ -22346,8 +25638,8 @@ trackedFiles: pristine_git_object: f252511ff6b3da5450c04507484b2b5e4d3683c4 pkg/models/shared/taskauditconditionalpolicyexecutionresult.go: id: 6b2a0d252730 - last_write_checksum: sha1:47309d0390c80d626e88c7a1da220983537fbf08 - pristine_git_object: 72ee081fb16c2b72791950c4a82d4c3a8d9db003 + last_write_checksum: sha1:7db3dbfef0f808fce7772dd86a28f4c83eb28dde + pristine_git_object: 8e8037784ad7df61f1910300173e7974903a25a9 pkg/models/shared/taskauditconnectoractionresult.go: id: b6eb464d2a83 last_write_checksum: sha1:442209833cb4b6954dc183afc343d7057f2e98c2 @@ -22406,12 +25698,12 @@ trackedFiles: pristine_git_object: 413989b8b3df5277a09b4cbafd3661a50f5bee20 pkg/models/shared/taskauditlistrequest.go: id: 8d1640c63ad5 - last_write_checksum: sha1:3150b91594c98dc191ece2dca579392377245a1f - pristine_git_object: 8a41fb94c1df47776d1fd9dbd22450477fb64a39 + last_write_checksum: sha1:9c6630137a153de2a1083b0a204d2553c10c5d0e + pristine_git_object: 7bcab676fe863a409a376e58eb15a14bb29fc00b pkg/models/shared/taskauditlistresponse.go: id: e2d3ab9f4e64 - last_write_checksum: sha1:4817fa4c1b65948160a69f632dd5b6e0bdaa0b7b - pristine_git_object: eef512130123ecec02d61d5aeb7d5e0ae619b005 + last_write_checksum: sha1:2ffb2f9c3593d3cd6cd2d6a6e4b1fd1eba9c2581 + pristine_git_object: 5575c074aec1b3ceeb7cb0b5bb9b2bb3e05259aa pkg/models/shared/taskauditmetadata.go: id: 6814aa771150 last_write_checksum: sha1:df26e72ac89af9f875496b4baeae520de31d196a @@ -22452,6 +25744,18 @@ trackedFiles: id: a0f2214dbe75 last_write_checksum: sha1:83495928b733b9480fbf436078e40a4bd9bd45d2 pristine_git_object: bce8712ad627f72caf6606d7a8c56131d8f4fd89 + pkg/models/shared/taskauditprovisionentitlementmergecompleted.go: + id: 62a07ad62f4a + last_write_checksum: sha1:15a85d4443e32686f53024d660a79a92e02e9650 + pristine_git_object: 7e287a1b9637041b9ad4e4f8e38b7af729f327bf + pkg/models/shared/taskauditprovisionentitlementmergetimedout.go: + id: 10aeb76232c3 + last_write_checksum: sha1:eb3ad1eb6c2d1eb513b962233f7592c1782fb6c2 + pristine_git_object: f9434817854ca797a64a678063bca59c7122e48c + pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.go: + id: 77884f221d2d + last_write_checksum: sha1:a59701908adc4789f82e441cf7ef4e7bb9e22bd3 + pristine_git_object: 3ed9702b9c6f0d0e50794293554157ae77cddfba pkg/models/shared/taskauditreassignedtodelegate.go: id: a955188db6d0 last_write_checksum: sha1:f9388a1c1bf3464e02fb23960fd8c99857a55ba0 @@ -22502,8 +25806,8 @@ trackedFiles: pristine_git_object: f94adda28d1a3ca1e45cbdada3ea302b1925a835 pkg/models/shared/taskauditview.go: id: 23f0115e6955 - last_write_checksum: sha1:cd73b4ae177488ab65c95d401bcac21f22b4645e - pristine_git_object: ab4a700a8b12c7f4ec3730e34ef8cc70e55726a5 + last_write_checksum: sha1:f4aa378aec65adbafdfef0ebf7e2f188285448a6 + pristine_git_object: ea6360ae644268547822c5a4bb83b5576d50788c pkg/models/shared/taskauditviewref.go: id: 92db59e1aa1d last_write_checksum: sha1:8b8305fd10b94a64e95e6f42930cbfd4effff5e3 @@ -22562,8 +25866,8 @@ trackedFiles: pristine_git_object: 758ffc83ec8d2e54286c1bf04de360819d6d9bbd pkg/models/shared/taskauditwebhooksuccess.go: id: 638fe37dbc16 - last_write_checksum: sha1:63f33976cc4e3ff508a8e676f9aa1ed395d28f6e - pristine_git_object: eedc29b8db2e1a805c9ac0affd307a0124f73f02 + last_write_checksum: sha1:666a49ccb3cf637f082d3f806e75795af9a2ac18 + pristine_git_object: 6bd213d7af82e166d21d27ed81fdc0725eb35fb6 pkg/models/shared/taskauditwebhooktriggered.go: id: 7f4012835cf0 last_write_checksum: sha1:28d3c541d49d0eb8e8860c49eaf9f2d31d615257 @@ -22610,8 +25914,8 @@ trackedFiles: pristine_git_object: 06b6102e6263e7baf1421405ee9a98cee221aa40 pkg/models/shared/tasksearchrequest.go: id: e79016fbdadb - last_write_checksum: sha1:a0da7b29477b25f758d75280b915c3a88c0bd216 - pristine_git_object: e7a0c6c2f0d5de8ca0be0aa515e808cf0ab0c0cf + last_write_checksum: sha1:77692c2b4cabf96fd372149b5f6fb7cc5d94898f + pristine_git_object: 2759ed71f4c1e8d7b42310e484065cb9f681b2d9 pkg/models/shared/tasksearchresponse.go: id: ca544efe5038 last_write_checksum: sha1:516deab56917de7613998eac51e567291fc302e6 @@ -22868,6 +26172,10 @@ trackedFiles: id: 6d6647bbf083 last_write_checksum: sha1:f3c882046cb4fa9f5a3393f88881b5cd1569f433 pristine_git_object: 859caa9ca031264e4c2777eab95436dc1438183d + pkg/models/shared/triggerautomationdispatcher.go: + id: bf5e203c7f8f + last_write_checksum: sha1:546a172b6729c4de8cec805bfa2c1e829d2ec878 + pristine_git_object: c677ef077cbe428a9869e270721199c2a3100572 pkg/models/shared/triggercustomanalysisrequest.go: id: 98f5a690d420 last_write_checksum: sha1:c37914c422995183bc67da300c75c47858bb0455 @@ -22968,6 +26276,14 @@ trackedFiles: id: ba657ccb9dc9 last_write_checksum: sha1:5b44beabdb69c4a78426b7814aaa7073d614c731 pristine_git_object: 30f681938542a469b5d6e4148c932b800d682b99 + pkg/models/shared/unusedsecretevidence.go: + id: dc4ea015191e + last_write_checksum: sha1:4ce1218b72418a2a094e1ccd3bbfd719296a790e + pristine_git_object: 7b766b4bc52fbe7258b2de4ec1eba71350b19d99 + pkg/models/shared/unusedsecrettype.go: + id: 1e4290567a26 + last_write_checksum: sha1:0cafe8341d0f962f1a37901d35ff6d3cd759ec95 + pristine_git_object: 7bdef948ea0ccb82d8c98bb680ca407ecf5f2b58 pkg/models/shared/updateaigovernancesettingsrequest.go: id: 78594634b088 last_write_checksum: sha1:418a6cce8f2f53cd3f17780054191518bf41a06c @@ -23040,6 +26356,14 @@ trackedFiles: id: 9648b9435216 last_write_checksum: sha1:12c15b948d492e7e4d8930bf525c94585910ea03 pristine_git_object: 36dad859be1d33e2db60719e2ef850c2f048c5a2 + pkg/models/shared/updatefindingsettingsrequest.go: + id: 383a7eb1bf58 + last_write_checksum: sha1:5d93de0d064d77c57ae500819d14c10bbb9eafc6 + pristine_git_object: f70801e78dae1b2dee55233bfe5ff9d7f75fcf9d + pkg/models/shared/updatefindingsettingsresponse.go: + id: 27c22b3c73e8 + last_write_checksum: sha1:08fce6a0f31a8107ad379d445048c94865f73812 + pristine_git_object: 3af3e5d9c9b20654a7c810f4067b1de3d0eb790b pkg/models/shared/updatefindingstaterequest.go: id: 4ad75a4c6b0a last_write_checksum: sha1:d1af90557d74970b9fd297b98101e73920911bf0 @@ -23344,6 +26668,14 @@ trackedFiles: id: c1778ca518c9 last_write_checksum: sha1:8d11a251f39c5dbd8f06d17bd15a41a7898a9d4a pristine_git_object: ecdb83a86ac979847e9417637cd6c01b3134948a + pkg/models/shared/waitingfordeviceplacement.go: + id: 789bfd9d1661 + last_write_checksum: sha1:180292732e58b4acbab5953988155aabe340c937 + pristine_git_object: 03fc51054ec52a24c6ecc5707a28a386f6a0568f + pkg/models/shared/waitingforentitlementmerge.go: + id: f063bc3a1dea + last_write_checksum: sha1:fa1d0e7693acdb376b391f538a7bf9900ad12fa4 + pristine_git_object: 5edc966330635a62878341b3b8c9543dccc7dadf pkg/models/shared/waitinstance.go: id: ca0c05919470 last_write_checksum: sha1:70bf9297df1dd8551b2a39b48c621df369706d15 @@ -23368,6 +26700,10 @@ trackedFiles: id: ce783f56e8fd last_write_checksum: sha1:9abe739b21e6be4cd267c6e83dae7c83b4a227df pristine_git_object: 43342900afdabcf5812f25d379c455f15dcce2b4 + pkg/models/shared/webhookdispatcher.go: + id: 2072a2af972d + last_write_checksum: sha1:0e208b4bae06e4062616fccb0d9199163cee7182 + pristine_git_object: 3b4ad047549e7bf498147ee23805b049bd06d93a pkg/models/shared/webhookendpoint.go: id: 603fdc27bc8c last_write_checksum: sha1:c36c237cffb76f988abf5c41a12fa23d20fbd7e7 @@ -23682,8 +27018,8 @@ trackedFiles: pristine_git_object: 01d68ad89e6cc59337db657ecacb5c1fa873b4c9 pkg/models/shared/xaaclientaudiencemapping.go: id: e663a0188e31 - last_write_checksum: sha1:d954df07f18f89e2af0d0e0f4c6721edd2674627 - pristine_git_object: 553f3463f98194b1fd791f8654093bc61f59e869 + last_write_checksum: sha1:199015f6c5ef82b303d728cb804f09a7c69b4d6f + pristine_git_object: ea81143dc00ee93885bee62018837ce042683f9a pkg/models/shared/xaaclientaudiencemappinghistoryentry.go: id: 9e15ca18c779 last_write_checksum: sha1:dc9a50fdcb3f01f52c251d3997f7219913704747 @@ -23972,10 +27308,18 @@ trackedFiles: id: 8ea6e4b1d0f0 last_write_checksum: sha1:5c790231558a38d4a55a4b591295bd1daac51d23 pristine_git_object: 28a0d3ea9ff485f63a4eed1a1110bdae1ce5bf0c + providercredential.go: + id: 607580b0371d + last_write_checksum: sha1:9dff76008a43b055ac56c04fc78ad7d0b7f4ff59 + pristine_git_object: ce20f362f2f8a4af6a3ce6ec5f05e33057b381f3 recoverypolicy.go: id: 677d05164b99 last_write_checksum: sha1:3940a5d2aa51b1e468894bd4b9ef69e18f023488 pristine_git_object: add4ca3e6b9d55af1cb5d92cc3c5a3164e60bf1c + reporting.go: + id: ec3302363294 + last_write_checksum: sha1:a50d082cddb04c419e2ed6df1ae7203df73533d4 + pristine_git_object: d6af605da15af01f9ee6cc393a51ca0bc51c6c15 requestcatalogmanagement.go: id: f5c4f657838e last_write_checksum: sha1:b4a93992c9339f3d4e22b5648329fc24ed047a96 @@ -23994,8 +27338,8 @@ trackedFiles: pristine_git_object: b90bcfd397e604dce5d37692dcdf35dd5e78a48c roleminingmanagement.go: id: 48dfdbb5dcea - last_write_checksum: sha1:cb9af0fd8bb3ceadf646a82943972017c8a73b50 - pristine_git_object: 64612f840ab133cfbbe6c376df8b27837a950bce + last_write_checksum: sha1:1328005826ae1667107c6edef61a0cb23e590abd + pristine_git_object: d8a71b9b6d726721b271dc23b7d7f1e46e920b25 roleminingmanagementsearch.go: id: 9eb1629cc9ed last_write_checksum: sha1:1863d6be74baa7c65058915c7987f04f6be3a7c6 @@ -24028,6 +27372,14 @@ trackedFiles: id: 185be1aba97d last_write_checksum: sha1:beeb04907ee10c376d46028241711a4451459397 pristine_git_object: 2cdd460c33ed2af67f4293b075c693f8618c18ca + ssoapplication.go: + id: 7d0f0a6a7975 + last_write_checksum: sha1:5ccb5d2c149c852568d01b0acae18bb9c81d4b6e + pristine_git_object: 7e3f50277a585a0d74b10757426188de81fe097b + ssosettings.go: + id: 7d6da6021f11 + last_write_checksum: sha1:1fcb74027a03038bd481c079ac9a8913907e365c + pristine_git_object: fe40f3c376ca496f7053432b294ad45e603e5ff0 stepupprovider.go: id: 354f9bfd25fb last_write_checksum: sha1:f905878d86bb861eab9539e2c9cdc03e63c782d2 @@ -24046,8 +27398,8 @@ trackedFiles: pristine_git_object: 43f750eba4de638c2fa8b187bba0d2bcdeb6e829 taskactions.go: id: acbb37f84ff8 - last_write_checksum: sha1:8bbcd7250e3c952e13ab2af61ac19e45151bbcc3 - pristine_git_object: d7678b1027ff9e397fc3f2c44368cfec5489b48a + last_write_checksum: sha1:14a3aa2658736f6b13cafc99943fc82453fd7f59 + pristine_git_object: dd1870e69fcebb6cacc93a7b5eaf19421a7ce93b taskaudit.go: id: b7e3c6922a60 last_write_checksum: sha1:c33bc734bc37f50d86307180f4d8e9029cf04c41 @@ -24072,6 +27424,10 @@ trackedFiles: id: bc309e2d7938 last_write_checksum: sha1:a75203f168e49caab3c20dc5af3b97f2dc0e99ae pristine_git_object: 32304a334487da426de0f575c12e87b81ed6769c + uiconversations.go: + id: a36206d3cdbc + last_write_checksum: sha1:d414f507fcbf8d54b7f56033d55139759640c24b + pristine_git_object: f5b77e58cef42c01574ee1c9088c52a0210b7580 user.go: id: 5aa421f647ef last_write_checksum: sha1:61309000befc30ebc36334834f82580ef148bbb7 @@ -28592,9 +31948,639 @@ examples: responses: "200": application/json: {} + c1.api.a2ui.v1.A2UIService.GetSurfaceProvenance: + speakeasy-default-c1-api-a2ui-v1-a2-UI-service-get-surface-provenance: + parameters: + path: + conversation_id: "" + surface_id: "" + responses: + "200": + application/json: {} + c1.api.accessreview.v1.AccessReviewReportService.List: + speakeasy-default-c1-api-accessreview-v1-access-review-report-service-list: + parameters: + path: + access_review_id: "" + responses: + "200": + application/json: {} + c1.api.accessreview.v1.AccessReviewActionsService.GenerateReport: + speakeasy-default-c1-api-accessreview-v1-access-review-actions-service-generate-report: + parameters: + path: + access_review_id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPResourceService.Get: + speakeasy-default-c1-api-ai-governance-v1-MCP-resource-service-get: + parameters: + path: + app_id: "" + connector_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPResourceService.List: + speakeasy-default-c1-api-ai-governance-v1-MCP-resource-service-list: + parameters: + path: + app_id: "" + connector_id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPResourceService.ListHistory: + speakeasy-default-c1-api-ai-governance-v1-MCP-resource-service-list-history: + parameters: + path: + app_id: "" + connector_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPResourceService.Search: + speakeasy-default-c1-api-ai-governance-v1-MCP-resource-service-search: + parameters: + path: + app_id: "" + connector_id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPResourceService.Update: + speakeasy-default-c1-api-ai-governance-v1-MCP-resource-service-update: + parameters: + path: + app_id: "" + connector_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.ai_governance.v1.MCPAccessProfileService.SearchAccessProfiles: + speakeasy-default-c1-api-ai-governance-v1-MCP-access-profile-service-search-access-profiles: + responses: + "200": + application/json: {} + c1.api.app.v1.AppEntitlementSearchService.SearchReachableResourcesForUser: + speakeasy-default-c1-api-app-v1-app-entitlement-search-service-search-reachable-resources-for-user: + responses: + "200": + application/json: {} + c1.api.app.v1.AppManagedStateService.Get: + speakeasy-default-c1-api-app-v1-app-managed-state-service-get: + parameters: + path: + app_id: "" + resource_type_id: "" + resource_id: "" + responses: + "200": + application/json: {} + c1.api.app.v1.AppManagedStateService.List: + speakeasy-default-c1-api-app-v1-app-managed-state-service-list: + parameters: + path: + app_id: "" + resource_type_id: "" + responses: + "200": + application/json: {} + c1.api.app.v1.AppManagedStateService.Promote: + speakeasy-default-c1-api-app-v1-app-managed-state-service-promote: + parameters: + path: + app_id: "" + resource_type_id: "" + resource_id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.BatchDeleteSubjectCompatibility: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-batch-delete-subject-compatibility: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.BatchImportSubjectCompatibility: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-batch-import-subject-compatibility: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.Create: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-create: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.CreateClient: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-create-client: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.Delete: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-delete: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.DeleteClient: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-delete-client: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.Get: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-get: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.List: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-list: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.ListClients: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-list-clients: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.ListHistory: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-list-history: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.ParseSAMLServiceProviderMetadata: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-parse-SAML-service-provider-metadata: + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.RotateClientSecret: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-rotate-client-secret: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.Search: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-search: + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.Update: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-update: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOApplicationService.UpdateClient: + speakeasy-default-c1-api-SSO-v1-SSO-application-service-update-client: + parameters: + path: + app_id: "" + id: "" + responses: + "200": + application/json: {} + c1.api.conversations.v1.UIConversationsService.EnsureOnboardingSession: + speakeasy-default-c1-api-conversations-v1-UI-conversations-service-ensure-onboarding-session: + responses: + "200": + application/json: {} + c1.api.finding.v1.FindingSettingsService.ListFindingSettings: + speakeasy-default-c1-api-finding-v1-finding-settings-service-list-finding-settings: + responses: + "200": + application/json: {} + c1.api.finding.v1.FindingSettingsService.UpdateFindingSettings: + speakeasy-default-c1-api-finding-v1-finding-settings-service-update-finding-settings: + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.Delete: + speakeasy-default-c1-api-funds-v1-app-cap-service-delete: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.Get: + speakeasy-default-c1-api-funds-v1-app-cap-service-get: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.List: + speakeasy-default-c1-api-funds-v1-app-cap-service-list: + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.ListHistory: + speakeasy-default-c1-api-funds-v1-app-cap-service-list-history: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.SetLimit: + speakeasy-default-c1-api-funds-v1-app-cap-service-set-limit: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.Suspend: + speakeasy-default-c1-api-funds-v1-app-cap-service-suspend: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.AppCapService.Unsuspend: + speakeasy-default-c1-api-funds-v1-app-cap-service-unsuspend: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.ClearExtension: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-clear-extension: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.Delete: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-delete: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.Get: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-get: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.GrantExtension: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-grant-extension: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.ListHistory: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-list-history: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.Search: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-search: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.SetLimit: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-set-limit: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.Suspend: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-suspend: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundAssignmentService.Unsuspend: + speakeasy-default-c1-api-funds-v1-fund-assignment-service-unsuspend: + parameters: + path: + user_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.Delete: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-delete: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.List: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-list: + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.ListHistory: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-list-history: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.Pause: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-pause: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.Resume: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-resume: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.MyFundLimitsService.SetLimit: + speakeasy-default-c1-api-funds-v1-my-fund-limits-service-set-limit: + parameters: + path: + app_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.Create: + speakeasy-default-c1-api-funds-v1-fund-policy-service-create: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.Delete: + speakeasy-default-c1-api-funds-v1-fund-policy-service-delete: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.FreezeTenant: + speakeasy-default-c1-api-funds-v1-fund-policy-service-freeze-tenant: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.Get: + speakeasy-default-c1-api-funds-v1-fund-policy-service-get: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.ListHistory: + speakeasy-default-c1-api-funds-v1-fund-policy-service-list-history: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.SetOrgCeiling: + speakeasy-default-c1-api-funds-v1-fund-policy-service-set-org-ceiling: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.UnfreezeTenant: + speakeasy-default-c1-api-funds-v1-fund-policy-service-unfreeze-tenant: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundPolicyService.Update: + speakeasy-default-c1-api-funds-v1-fund-policy-service-update: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.Create: + speakeasy-default-c1-api-funds-v1-fund-rule-service-create: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.Delete: + speakeasy-default-c1-api-funds-v1-fund-rule-service-delete: + parameters: + path: + rule_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.Get: + speakeasy-default-c1-api-funds-v1-fund-rule-service-get: + parameters: + path: + rule_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.List: + speakeasy-default-c1-api-funds-v1-fund-rule-service-list: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.ListHistory: + speakeasy-default-c1-api-funds-v1-fund-rule-service-list-history: + parameters: + path: + rule_id: "" + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.Search: + speakeasy-default-c1-api-funds-v1-fund-rule-service-search: + responses: + "200": + application/json: {} + c1.api.funds.v1.FundRuleService.Update: + speakeasy-default-c1-api-funds-v1-fund-rule-service-update: + parameters: + path: + rule_id: "" + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.GatewayKeyService.List: + speakeasy-default-c1-api-llm-gateway-v1-gateway-key-service-list: + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.GatewayKeyService.Mint: + speakeasy-default-c1-api-llm-gateway-v1-gateway-key-service-mint: + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.GatewayKeyService.Revoke: + speakeasy-default-c1-api-llm-gateway-v1-gateway-key-service-revoke: + parameters: + path: + id: "" + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.ProviderCredentialService.Clear: + speakeasy-default-c1-api-llm-gateway-v1-provider-credential-service-clear: + parameters: + path: + slot_id: "" + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.ProviderCredentialService.Get: + speakeasy-default-c1-api-llm-gateway-v1-provider-credential-service-get: + parameters: + path: + slot_id: "" + responses: + "200": + application/json: {} + c1.api.llm_gateway.v1.ProviderCredentialService.Set: + speakeasy-default-c1-api-llm-gateway-v1-provider-credential-service-set: + parameters: + path: + slot_id: "" + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.Delete: + speakeasy-default-c1-api-reporting-v1-reporting-service-delete: + parameters: + path: + id: "" + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.Get: + speakeasy-default-c1-api-reporting-v1-reporting-service-get: + parameters: + path: + id: "" + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.GetRunProvenance: + speakeasy-default-c1-api-reporting-v1-reporting-service-get-run-provenance: + parameters: + path: + id: "" + run_id: "" + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.List: + speakeasy-default-c1-api-reporting-v1-reporting-service-list: + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.Run: + speakeasy-default-c1-api-reporting-v1-reporting-service-run: + parameters: + path: + id: "" + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.Save: + speakeasy-default-c1-api-reporting-v1-reporting-service-save: + responses: + "200": + application/json: {} + c1.api.reporting.v1.ReportingService.Update: + speakeasy-default-c1-api-reporting-v1-reporting-service-update: + parameters: + path: + id: "" + responses: + "200": + application/json: {} + c1.api.role_mining_management.v1.RoleMiningManagementService.EvaluateEntitlementSelection: + speakeasy-default-c1-api-role-mining-management-v1-role-mining-management-service-evaluate-entitlement-selection: + parameters: + path: + analysis_id: "" + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOSettingsService.Get: + speakeasy-default-c1-api-SSO-v1-SSO-settings-service-get: + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOSettingsService.ListHistory: + speakeasy-default-c1-api-SSO-v1-SSO-settings-service-list-history: + responses: + "200": + application/json: {} + c1.api.sso.v1.SSOSettingsService.Update: + speakeasy-default-c1-api-SSO-v1-SSO-settings-service-update: + responses: + "200": + application/json: {} + c1.api.task.v1.TaskActionsService.RetryProvisioning: + speakeasy-default-c1-api-task-v1-task-actions-service-retry-provisioning: + parameters: + path: + task_id: "" + responses: + "200": + application/json: {} examplesVersion: 1.0.2 generatedTests: {} -releaseNotes: "## Go SDK Changes:\n* `ConductoroneApi.AttributeSearch.SearchAttributeValues()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalUserInvitation.Revoke()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.GetUserOwner()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.GetEntitlementOwner()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.DeleteUserOwner()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.DeleteEntitlementOwner()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.CreateUserOwner()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwnersV2.CreateEntitlementOwner()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementOwnersV2.Set()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.ConnectorOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Webhooks.Update()`: \n * `request.Request.WebhooksServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Webhooks.Test()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Webhooks.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Webhooks.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Webhooks.Create()`: \n * `request.Request.CallbackTimeout` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Vault.Update()`: \n * `request.Request.VaultServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Vault.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Vault.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.User.SetExpiringUserDelegationBindingByAdmin()`: \n * `request.Request.SetExpiringUserDelegationBindingByAdminRequest` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.User.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementUserBinding.RemoveGrantDuration()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.User.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.UpdateRequestData()`: \n * `request.Request.TaskActionsServiceUpdateRequestDataRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.UpdateGrantDuration()`: \n * `request.Request.TaskActionsServiceUpdateGrantDurationRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.SkipStep()`: \n * `request.Request.TaskActionsServiceSkipStepRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Restart()`: \n * `request.Request.TaskActionsServiceRestartRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Reassign()`: \n * `request.Request.TaskActionsServiceReassignRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.ProcessNow()`: \n * `request.Request.TaskActionsServiceProcessNowRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.HardReset()`: \n * `request.Request.TaskActionsServiceHardResetRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.EscalateToEmergencyAccess()`: \n * `request.Request.TaskActionsServiceEscalateToEmergencyAccessRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Deny()`: \n * `request.Request.TaskActionsServiceDenyRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Comment()`: \n * `request.Request.TaskActionsServiceCommentRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Close()`: \n * `request.Request.TaskActionsServiceCloseRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.ApproveWithStepUp()`: \n * `request.Request.TaskActionsServiceApproveWithStepUpRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskActions.Approve()`: \n * `request.Request.TaskActionsServiceApproveRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Task.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Task.CreateRevokeTask()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Task.CreateOffboardingTask()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Task.CreateGrantTask()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskAudit.List()`: \n * `request.Request` **Changed**\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementUserBinding.ListAppUsersForIdentityWithGrant()`: `response.Bindings[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Export.Update()`: \n * `request.Request.ExportServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Export.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Export.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Export.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverEvent.List()`: `response.List[].ReceivedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverStream.Update()`: \n * `request.Request.SsfReceiverStreamServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverStream.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverStream.GetStats()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverStream.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverStream.Create()`: \n * `request.Request.PollInterval` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SessionSettings.Update()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SessionSettings.TestSourceIp()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SessionSettings.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.OnboardingSettings.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.UserNotificationSettings.Update()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.UserNotificationSettings.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.OrgNotificationSettings.Update()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.OrgNotificationSettings.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantEmailProvider.Update()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantEmailProvider.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.OrgDomain.Update()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.OrgDomain.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Contacts.UpdateContacts()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Contacts.GetContacts()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AwsExternalIdSettings.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.UpdateCredential()`: \n * `request.Request.ServicePrincipalServiceUpdateCredentialRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.Update()`: \n * `request.Request.ServicePrincipalServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.ListCredentials()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.ListBindings()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.Bindings[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.GetCredential()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.DeleteBinding()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.CreateCredential()`: \n * `request.Request.ServicePrincipalServiceCreateCredentialRequest.Expires` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.Create()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Principal.AddBinding()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.UpdateTrust()`: \n * `request.Request.WorkloadFederationServiceUpdateTrustRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.UpdateProvider()`: \n * `request.Request.WorkloadFederationServiceUpdateProviderRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.TestToken()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.SearchTrusts()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.ListTrusts()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.ListProviders()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.GetTrust()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.GetProvider()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.CreateTrust()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WorkloadFederation.CreateProvider()`: \n * `request.Request` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.WebhooksSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.UserSearch.Search()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TaskSearch.Search()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.ExportsSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpTransaction.Search()`: \n * `request.Request` **Changed**\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpTransaction.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.UpdateSecret()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.Update()`: \n * `request.Request.UpdateStepUpProviderRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.StepUpProvider.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SsfReceiverEventSearch.Search()`: `response.List[].ReceivedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.SetTextContent()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.SearchMySecrets()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.Revoke()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.GetContent()`: `response.CreatedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.GetByShareCode()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.CreateInternal()`: \n * `request.Request` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecret.CreateExternal()`: \n * `request.Request` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecretAdmin.Search()`: \n * `request.Request` **Changed**\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecretAdmin.Revoke()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PaperSecretAdmin.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagementSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogSearch.SearchEntitlements()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PolicySearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PersonalClientSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.ExternalClientSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.HooksSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FunctionsSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationSearch.SearchAutomations()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceSearch.SearchAppResources()`: \n * `request.Request` **Changed**\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceSearch.SearchAppResourceTypes()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationExecutionSearch.SearchAutomationExecutions()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationExecutionSearch.SearchAllAutomationExecutions()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.UpdateSuggestionState()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.UpdateRoleMiningConfig()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.SearchCohortUsers()`: \n * `request.Request.SearchCohortUsersRequest.SelectedEntitlements` **Added**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.ListSuggestions()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.ListRuns()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.GetSuggestion()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.GetRoleMiningConfig()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RoleMiningManagement.GetLatestRun()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.Update()`: \n * `request.Request.RequestSchemaServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.RemoveEntitlementBinding()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.FindBindingForAppEntitlement()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.CreateEntitlementBinding()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestSchema.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Policies.Update()`: \n * `request.Request.UpdatePolicyRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Policies.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Policies.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Policies.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalUserInvitation.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.Update()`: \n * `request.Request.RequestCatalogManagementServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalUserInvitation.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalUserInvitation.Create()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalDirectoryConfig.Update()`: \n * `request.Request.LocalDirectoryConfigServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalDirectoryConfig.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalDirectoryConfig.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.LocalDirectoryConfig.Create()`: \n * `request.Request.InvitationTtl` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Roles.Update()`: \n * `request.Request.UpdateRoleRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Roles.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Roles.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PersonalClient.Update()`: \n * `request.Request.PersonalClientServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PersonalClient.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PersonalClient.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.PersonalClient.Create()`: \n * `request.Request.Expires` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Hooks.Update()`: \n * `request.Request.HooksServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Hooks.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Hooks.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Hooks.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FunctionsInvocationSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FunctionsInvocation.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FunctionsInvocation.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.UpdateFunction()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.Test()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.ListTags()`: `response.Tags.Map.CreatedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementUserBinding.SearchGrantFeed()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.ListFunctions()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.ListCommits()`: `response.List[].CreatedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.GetFunction()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.GetCommitContent()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.CreateFunction()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Functions.CreateFinalCommit()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FindingSearch.Search()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule()`: \n * `request.Request.UpdateFindingRoutingRuleRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Finding.UpdateFindingState()`: \n * `request.Request.UpdateFindingStateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Finding.GetFinding()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Finding.CreateFindingTask()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.A2Ui.CreateSurfaceFeedback()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.A2Ui.ListSurfaceFeedback()`: `response.Feedback[].CreatedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.A2Ui.ListSurfaces()`: `response.Surfaces[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Finding.BulkUpdateFindingState()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReview.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReview.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReview.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReview.Update()`: \n * `request.Request.AccessReviewServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewSetupEntitlement.GetCampaignScopeAndEntitlements()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeAndEntitlements()`: \n * `request.Request.AccessReviewSetupEntitlementAndScopeServiceSetRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeByResourceType()`: \n * `request.Request.AccessReviewSetScopeByResourceTypeRequest` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplate.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplate.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplate.Update()`: \n * `request.Request.AccessReviewTemplateServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.GetScopeAndEntitlements()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeAndEntitlements()`: \n * `request.Request.AccessReviewTemplateSetupEntitlementServiceSetRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeByResourceType()`: \n * `request.Request.AccessReviewTemplateSetScopeByResourceTypeRequest` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessConflict.CreateMonitor()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessConflict.GetMonitor()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AccessConflict.UpdateMonitor()`: \n * `request.Request.ConflictMonitorUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementMonitorBinding.CreateAppEntitlementMonitorBinding()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementMonitorBinding.GetAppEntitlementMonitorBinding()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Apps.Create()`: \n * `request.Request.Annotations` **Added**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Apps.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Apps.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Apps.Update()`: \n * `request.Request.UpdateAppRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.Create()`: \n * `request.Request.ConnectorServiceCreateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.CreateDelegated()`: \n * `request.Request.ConnectorServiceCreateDelegatedRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.GetCredentials()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.RotateCredential()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.Update()`: \n * `request.Request.ConnectorServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.UpdateConnectorSchedule()`: \n * `request.Request.UpdateConnectorScheduleRequest` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Connector.UpdateDelegated()`: \n * `request.Request.ConnectorServiceUpdateDelegatedRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppAccessRequestsDefaults.CancelAppAccessRequestsDefaults()`: `response.DurationGrant` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppAccessRequestsDefaults.CreateAppAccessRequestsDefaults()`: \n * `request.Request.AppAccessRequestDefaults.DurationGrant` **Changed**\n * `response.DurationGrant` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppAccessRequestsDefaults.GetAppAccessRequestsDefaults()`: `response.DurationGrant` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUser.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUser.ListAppUserCredentials()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUser.ListAppUsersForUser()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUser.Search()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUser.Update()`: \n * `request.Request.AppUserServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.Create()`: \n * `request.Request.CreateAppEntitlementRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.CreateAutomation()`: \n * `request.Request.CreateAutomationRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.GetAutomation()`: `response.AppEntitlementAutomation` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.ListAutomationExclusions()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.ListForAppResource()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.ListForAppUser()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.ListUsers()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.Update()`: \n * `request.Request.UpdateAppEntitlementRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlements.UpdateAutomation()`: \n * `request.Request.AppEntitlementServiceUpdateAutomationRequest` **Changed** (Breaking ⚠️)\n * `response.AppEntitlementAutomation` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementSearch.Search()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementSearch.SearchGrants()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Finding.BulkCreateFindingTasks()`: `request.Request` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Directory.Update()`: \n * `request.Request.DirectoryServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Directory.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementUserBinding.UpdateGrantDuration()`: \n * `request.Request.UpdateGrantDurationRequest.NewDeprovisionAt` **Changed**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppReport.List()`: `response.List[].CreatedAt` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType()`: \n * `request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(sessionPolicy)` **Added**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceType.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceType.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceType.UpdateManuallyManagedResourceType()`: \n * `request.Request.UpdateManuallyManagedResourceTypeRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResource.CreateManuallyManagedAppResource()`: \n * `request.Request.CreateManuallyManagedAppResourceRequest.Annotations` **Added**\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResource.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResource.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResource.Update()`: \n * `request.Request.AppResourceServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppResourceOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUsageControls.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppUsageControls.Update()`: \n * `request.Request.UpdateAppUsageControlsRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementsProxy.Create()`: \n * `request.Request.CreateAppEntitlementProxyRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AppEntitlementsProxy.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.CreateAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.CreateComplianceFrameworkAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.CreateRiskLevelAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.GetAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.GetComplianceFrameworkAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.GetRiskLevelAttributeValue()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.ListAttributeValues()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.ListComplianceFrameworks()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Attributes.ListRiskLevels()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantAuthConfig.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantAuthConfig.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantAuthConfig.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.TenantAuthConfig.Update()`: \n * `request.Request.TenantAuthConfigServiceUpdateRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Directory.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationExecution.GetAutomationExecution()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.AutomationExecution.ListAutomationExecutions()`: `response.AutomationExecutions[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Directory.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Automation.CreateAutomation()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Automation.ExecuteAutomation()`: \n * `request.Request.ExecuteAutomationRequest` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Automation.GetAutomation()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Automation.ListAutomations()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.ConnectorCatalog.ConfigurationSchema()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.Automation.UpdateAutomation()`: \n * `request.Request.UpdateAutomationRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.CreateBundleAutomation()`: \n * `request.Request.CreateBundleAutomationRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.CreateRequestableEntry()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.Get()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.GetBundleAutomation()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.GetRequestableEntry()`: `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.List()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog()`: `response.List[]` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.RequestCatalogManagement.SetBundleAutomation()`: \n * `request.Request.SetBundleAutomationRequest` **Changed** (Breaking ⚠️)\n * `response` **Changed** (Breaking ⚠️)\n* `ConductoroneApi.SignInPolicy.Delete()`: **Added**\n* `ConductoroneApi.Automation.ResolvePausedAutomationExecutions()`: `response.BulkActionId` **Added**\n* `ConductoroneApi.Automation.ClearAutomationCircuitBreaker()`: \n * `request.Request.ClearAutomationCircuitBreakerRequest` **Changed**\n * `response.BulkActionId` **Added**\n* `ConductoroneApi.Auth.Introspect()`: `response` **Changed**\n* `ConductoroneApi.AppResourceOwnersV2.Set()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.ReorderAppEntitlementRoutingRules()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.GetByAppEntitlementId()`: **Added**\n* `ConductoroneApi.A2Ui.SubmitAction()`: \n * `request.Request.A2UiServiceSubmitActionRequest.ClientTimestamp` **Changed**\n* `ConductoroneApi.UserOwnersV2.Set()`: **Added**\n* `ConductoroneApi.UserOwnersV2.SearchUserOwners()`: **Added**\n* `ConductoroneApi.UserOwnersV2.SearchEntitlementOwners()`: **Added**\n* `ConductoroneApi.UserOwnersV2.DeleteUserOwner()`: **Added**\n* `ConductoroneApi.UserOwnersV2.DeleteEntitlementOwner()`: **Added**\n* `ConductoroneApi.UserOwnersV2.CreateUserOwner()`: **Added**\n* `ConductoroneApi.UserOwnersV2.CreateEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.Set()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.SearchUserOwners()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.DeleteUserOwner()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.DeleteEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.CreateUserOwner()`: **Added**\n* `ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.SearchUserOwners()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.GetUserOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.DeleteUserOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.DeleteEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.CreateUserOwner()`: **Added**\n* `ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.GetUserOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.DeleteUserOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.DeleteEntitlementOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.CreateUserOwner()`: **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.GetUserOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.DeleteUserOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.DeleteEntitlementOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.CreateUserOwner()`: **Added**\n* `ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner()`: **Added**\n* `ConductoroneApi.User.Introspect()`: **Added**\n* `ConductoroneApi.TerraformExport.GetSchema()`: **Added**\n* `ConductoroneApi.Task.CreateResourceActionTask()`: **Added**\n* `ConductoroneApi.Task.CreateActionTask()`: **Added**\n* `ConductoroneApi.RequestSettings.Update()`: **Added**\n* `ConductoroneApi.RequestSettings.Get()`: **Added**\n* `ConductoroneApi.IdentityPolicyTenantDefaults.Update()`: **Added**\n* `ConductoroneApi.IdentityPolicyTenantDefaults.Get()`: **Added**\n* `ConductoroneApi.UserDeveloperPreferences.Update()`: **Added**\n* `ConductoroneApi.UserDeveloperPreferences.Get()`: **Added**\n* `ConductoroneApi.XaaSettings.Update()`: **Added**\n* `ConductoroneApi.XaaSettings.ListHistory()`: **Added**\n* `ConductoroneApi.XaaSettings.Get()`: **Added**\n* `ConductoroneApi.AiGovernanceSettings.Update()`: **Added**\n* `ConductoroneApi.AiGovernanceSettings.ListHistory()`: **Added**\n* `ConductoroneApi.RoleMiningManagement.CreateAccessProfileFromCohort()`: `request.Request` **Changed**\n* `ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult()`: `response.Clusters[].Entitlements[].RiskLevelValueId` **Added**\n* `ConductoroneApi.AiGovernanceSettings.GetTenantDefaults()`: **Added**\n* `ConductoroneApi.AiGovernanceSettings.Get()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.Update()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.Search()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.ListHistory()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.List()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.Get()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.Delete()`: **Added**\n* `ConductoroneApi.XaaClientAudienceMapping.Create()`: **Added**\n* `ConductoroneApi.SignInPolicy.Update()`: **Added**\n* `ConductoroneApi.SignInPolicy.Search()`: **Added**\n* `ConductoroneApi.SignInPolicy.List()`: **Added**\n* `ConductoroneApi.SignInPolicy.Get()`: **Added**\n* `ConductoroneApi.AppUser.ListOwnedServiceAccounts()`: **Added**\n* `ConductoroneApi.McpTool.Delete()`: **Added**\n* `ConductoroneApi.SignInPolicy.Create()`: **Added**\n* `ConductoroneApi.SessionPolicy.Update()`: **Added**\n* `ConductoroneApi.SessionPolicy.UnassignUser()`: **Added**\n* `ConductoroneApi.SessionPolicy.UnassignGroup()`: **Added**\n* `ConductoroneApi.SessionPolicy.Search()`: **Added**\n* `ConductoroneApi.SessionPolicy.ListAssignments()`: **Added**\n* `ConductoroneApi.SessionPolicy.List()`: **Added**\n* `ConductoroneApi.SessionPolicy.Get()`: **Added**\n* `ConductoroneApi.SessionPolicy.Delete()`: **Added**\n* `ConductoroneApi.SessionPolicy.Create()`: **Added**\n* `ConductoroneApi.SessionPolicy.AssignUser()`: **Added**\n* `ConductoroneApi.SessionPolicy.AssignGroup()`: **Added**\n* `ConductoroneApi.FindingAudit.Search()`: **Added**\n* `ConductoroneApi.RoleMiningManagement.ListCustomAnalysisResults()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.Update()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.Search()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.List()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.Get()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.Delete()`: **Added**\n* `ConductoroneApi.RecoveryPolicy.Create()`: **Added**\n* `ConductoroneApi.TunnelCredentials.UpdateBridge()`: **Added**\n* `ConductoroneApi.TunnelCredentials.RevokeBridgeCredential()`: **Added**\n* `ConductoroneApi.TunnelCredentials.ListBridges()`: **Added**\n* `ConductoroneApi.TunnelCredentials.ListBridgeCredentials()`: **Added**\n* `ConductoroneApi.TunnelCredentials.ListBridgeAnnouncedServices()`: **Added**\n* `ConductoroneApi.TunnelCredentials.GetBridge()`: **Added**\n* `ConductoroneApi.TunnelCredentials.DeleteBridge()`: **Added**\n* `ConductoroneApi.TunnelCredentials.CreateBridgeCredential()`: **Added**\n* `ConductoroneApi.TunnelCredentials.CreateBridge()`: **Added**\n* `ConductoroneApi.PersonalDevice.UpdateDevice()`: **Added**\n* `ConductoroneApi.PersonalDevice.Search()`: **Added**\n* `ConductoroneApi.PersonalDevice.RevokeDeviceClient()`: **Added**\n* `ConductoroneApi.PersonalDevice.RevokeDevice()`: **Added**\n* `ConductoroneApi.PersonalDevice.ListDeviceClients()`: **Added**\n* `ConductoroneApi.PersonalDevice.GetDevice()`: **Added**\n* `ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule()`: **Added**\n* `ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules()`: **Added**\n* `ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule()`: **Added**\n* `ConductoroneApi.FindingTransformationRule.DeleteFindingTransformationRule()`: **Added**\n* `ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule()`: **Added**\n* `ConductoroneApi.Finding.CreateFinding()`: **Added**\n* `ConductoroneApi.DecoySearch.Search()`: **Added**\n* `ConductoroneApi.Decoy.Update()`: **Added**\n* `ConductoroneApi.Decoy.Rotate()`: **Added**\n* `ConductoroneApi.Decoy.List()`: **Added**\n* `ConductoroneApi.Decoy.Get()`: **Added**\n* `ConductoroneApi.Decoy.Delete()`: **Added**\n* `ConductoroneApi.Decoy.Create()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.Update()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.Search()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.List()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.Get()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.Delete()`: **Added**\n* `ConductoroneApi.CredentialInventoryPolicy.Create()`: **Added**\n* `ConductoroneApi.ConnectorAuthoringActivation.RollbackRevision()`: **Added**\n* `ConductoroneApi.ConnectorAuthoringActivation.ActivateRevision()`: **Added**\n* `ConductoroneApi.XaaScope.Update()`: **Added**\n* `ConductoroneApi.XaaScope.Search()`: **Added**\n* `ConductoroneApi.XaaScope.ListHistory()`: **Added**\n* `ConductoroneApi.XaaScope.List()`: **Added**\n* `ConductoroneApi.XaaScope.Get()`: **Added**\n* `ConductoroneApi.XaaScope.Delete()`: **Added**\n* `ConductoroneApi.XaaScope.Create()`: **Added**\n* `ConductoroneApi.XaaResourceServer.Update()`: **Added**\n* `ConductoroneApi.XaaResourceServer.Search()`: **Added**\n* `ConductoroneApi.OnboardingSettings.Update()`: \n * `request.Request` **Changed**\n * `response` **Changed**\n* `ConductoroneApi.XaaResourceServer.ListHistory()`: **Added**\n* `ConductoroneApi.XaaResourceServer.List()`: **Added**\n* `ConductoroneApi.XaaResourceServer.Get()`: **Added**\n* `ConductoroneApi.XaaResourceServer.Delete()`: **Added**\n* `ConductoroneApi.XaaResourceServer.Create()`: **Added**\n* `ConductoroneApi.XaaAccessProfileScopeBinding.Search()`: **Added**\n* `ConductoroneApi.XaaAccessProfileScopeBinding.List()`: **Added**\n* `ConductoroneApi.XaaAccessProfileScopeBinding.DeleteBindings()`: **Added**\n* `ConductoroneApi.XaaAccessProfileScopeBinding.CreateBindings()`: **Added**\n* `ConductoroneApi.SystemLog.ListEvents()`: `request.Request` **Changed**\n* `ConductoroneApi.XaaAccessProfile.Update()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.Search()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.ListHistory()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.List()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.Get()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.Delete()`: **Added**\n* `ConductoroneApi.XaaAccessProfile.Create()`: **Added**\n* `ConductoroneApi.McpServer.UpdateCredentials()`: **Added**\n* `ConductoroneApi.McpServer.Update()`: **Added**\n* `ConductoroneApi.McpServer.TestConnection()`: **Added**\n* `ConductoroneApi.McpServer.SearchWithToolCount()`: **Added**\n* `ConductoroneApi.McpServer.ResyncTools()`: **Added**\n* `ConductoroneApi.McpServer.Register()`: **Added**\n* `ConductoroneApi.McpServer.ListConnections()`: **Added**\n* `ConductoroneApi.McpServer.ListCatalog()`: **Added**\n* `ConductoroneApi.McpServer.List()`: **Added**\n* `ConductoroneApi.McpServer.GetCatalog()`: **Added**\n* `ConductoroneApi.McpServer.Get()`: **Added**\n* `ConductoroneApi.McpServer.DiscoverOidcEndpoints()`: **Added**\n* `ConductoroneApi.McpServer.Delete()`: **Added**\n* `ConductoroneApi.AppEntitlementSearch.SearchGraph()`: **Added**\n* `ConductoroneApi.AppEntitlementSearch.CountGrantsForUserByApp()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.UpdateAppEntitlementRoutingRule()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.ListAppEntitlementRoutingRules()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.GetAppEntitlementRoutingRule()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.DeleteAppEntitlementRoutingRule()`: **Added**\n* `ConductoroneApi.AppEntitlementRoutingRule.CreateAppEntitlementRoutingRule()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.ListToolsByProfileHistory()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.ListProfilesByToolHistory()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.List()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.DeleteBindings()`: **Added**\n* `ConductoroneApi.McpAccessProfileToolBinding.CreateBindings()`: **Added**\n* `ConductoroneApi.McpAccessProfile.Update()`: **Added**\n* `ConductoroneApi.McpAccessProfile.SearchRequestableConnectors()`: **Added**\n* `ConductoroneApi.McpAccessProfile.ListRequestableConnectors()`: **Added**\n* `ConductoroneApi.McpAccessProfile.List()`: **Added**\n* `ConductoroneApi.McpAccessProfile.GetByAppEntitlementId()`: **Added**\n* `ConductoroneApi.McpAccessProfile.Get()`: **Added**\n* `ConductoroneApi.McpAccessProfile.Delete()`: **Added**\n* `ConductoroneApi.McpAccessProfile.Create()`: **Added**\n* `ConductoroneApi.McpTool.Update()`: **Added**\n* `ConductoroneApi.McpTool.Search()`: **Added**\n* `ConductoroneApi.McpTool.ListHistory()`: **Added**\n* `ConductoroneApi.McpTool.List()`: **Added**\n* `ConductoroneApi.McpTool.Get()`: **Added**\n" +releaseNotes: "## Go SDK Changes:\n* `ConductoroneApi.AccessReviewTemplate.Create()`: \n * `request.Request` **Changed** (Breaking ⚠️)\n * `response.AccessReviewTemplate` **Changed**\n* `ConductoroneApi.AccessReviewTemplate.Update()`: \n * `request.Request.AccessReviewTemplateServiceUpdateRequest.AccessReviewTemplate` **Changed** (Breaking ⚠️)\n * `response.AccessReviewTemplate` **Changed**\n* `ConductoroneApi.A2Ui.GetSurfaceProvenance()`: **Added**\n* `ConductoroneApi.AccessReviewReport.List()`: **Added**\n* `ConductoroneApi.AccessReviewActions.GenerateReport()`: **Added**\n* `ConductoroneApi.McpResource.Get()`: **Added**\n* `ConductoroneApi.McpResource.List()`: **Added**\n* `ConductoroneApi.McpResource.ListHistory()`: **Added**\n* `ConductoroneApi.McpResource.Search()`: **Added**\n* `ConductoroneApi.McpResource.Update()`: **Added**\n* `ConductoroneApi.McpAccessProfile.SearchAccessProfiles()`: **Added**\n* `ConductoroneApi.AppEntitlementSearch.SearchReachableResourcesForUser()`: **Added**\n* `ConductoroneApi.AppManagedState.Get()`: **Added**\n* `ConductoroneApi.AppManagedState.List()`: **Added**\n* `ConductoroneApi.AppManagedState.Promote()`: **Added**\n* `ConductoroneApi.SsoApplication.BatchDeleteSubjectCompatibility()`: **Added**\n* `ConductoroneApi.SsoApplication.BatchImportSubjectCompatibility()`: **Added**\n* `ConductoroneApi.SsoApplication.Create()`: **Added**\n* `ConductoroneApi.SsoApplication.CreateClient()`: **Added**\n* `ConductoroneApi.SsoApplication.Delete()`: **Added**\n* `ConductoroneApi.SsoApplication.DeleteClient()`: **Added**\n* `ConductoroneApi.SsoApplication.Get()`: **Added**\n* `ConductoroneApi.SsoApplication.List()`: **Added**\n* `ConductoroneApi.SsoApplication.ListClients()`: **Added**\n* `ConductoroneApi.SsoApplication.ListHistory()`: **Added**\n* `ConductoroneApi.SsoApplication.ParseSamlServiceProviderMetadata()`: **Added**\n* `ConductoroneApi.SsoApplication.RotateClientSecret()`: **Added**\n* `ConductoroneApi.SsoApplication.Search()`: **Added**\n* `ConductoroneApi.SsoApplication.Update()`: **Added**\n* `ConductoroneApi.SsoApplication.UpdateClient()`: **Added**\n* `ConductoroneApi.UiConversations.EnsureOnboardingSession()`: **Added**\n* `ConductoroneApi.FindingSettings.ListFindingSettings()`: **Added**\n* `ConductoroneApi.FindingSettings.UpdateFindingSettings()`: **Added**\n* `ConductoroneApi.AppCap.Delete()`: **Added**\n* `ConductoroneApi.AppCap.Get()`: **Added**\n* `ConductoroneApi.AppCap.List()`: **Added**\n* `ConductoroneApi.AppCap.ListHistory()`: **Added**\n* `ConductoroneApi.AppCap.SetLimit()`: **Added**\n* `ConductoroneApi.AppCap.Suspend()`: **Added**\n* `ConductoroneApi.AppCap.Unsuspend()`: **Added**\n* `ConductoroneApi.FundAssignment.ClearExtension()`: **Added**\n* `ConductoroneApi.FundAssignment.Delete()`: **Added**\n* `ConductoroneApi.FundAssignment.Get()`: **Added**\n* `ConductoroneApi.FundAssignment.GrantExtension()`: **Added**\n* `ConductoroneApi.FundAssignment.ListHistory()`: **Added**\n* `ConductoroneApi.FundAssignment.Search()`: **Added**\n* `ConductoroneApi.FundAssignment.SetLimit()`: **Added**\n* `ConductoroneApi.FundAssignment.Suspend()`: **Added**\n* `ConductoroneApi.FundAssignment.Unsuspend()`: **Added**\n* `ConductoroneApi.MyFundLimits.Delete()`: **Added**\n* `ConductoroneApi.MyFundLimits.List()`: **Added**\n* `ConductoroneApi.MyFundLimits.ListHistory()`: **Added**\n* `ConductoroneApi.MyFundLimits.Pause()`: **Added**\n* `ConductoroneApi.MyFundLimits.Resume()`: **Added**\n* `ConductoroneApi.MyFundLimits.SetLimit()`: **Added**\n* `ConductoroneApi.FundPolicy.Create()`: **Added**\n* `ConductoroneApi.FundPolicy.Delete()`: **Added**\n* `ConductoroneApi.FundPolicy.FreezeTenant()`: **Added**\n* `ConductoroneApi.FundPolicy.Get()`: **Added**\n* `ConductoroneApi.FundPolicy.ListHistory()`: **Added**\n* `ConductoroneApi.FundPolicy.SetOrgCeiling()`: **Added**\n* `ConductoroneApi.FundPolicy.UnfreezeTenant()`: **Added**\n* `ConductoroneApi.FundPolicy.Update()`: **Added**\n* `ConductoroneApi.FundRule.Create()`: **Added**\n* `ConductoroneApi.FundRule.Delete()`: **Added**\n* `ConductoroneApi.FundRule.Get()`: **Added**\n* `ConductoroneApi.FundRule.List()`: **Added**\n* `ConductoroneApi.FundRule.ListHistory()`: **Added**\n* `ConductoroneApi.FundRule.Search()`: **Added**\n* `ConductoroneApi.FundRule.Update()`: **Added**\n* `ConductoroneApi.GatewayKey.List()`: **Added**\n* `ConductoroneApi.GatewayKey.Mint()`: **Added**\n* `ConductoroneApi.GatewayKey.Revoke()`: **Added**\n* `ConductoroneApi.ProviderCredential.Clear()`: **Added**\n* `ConductoroneApi.ProviderCredential.Get()`: **Added**\n* `ConductoroneApi.ProviderCredential.Set()`: **Added**\n* `ConductoroneApi.Reporting.Delete()`: **Added**\n* `ConductoroneApi.Reporting.Get()`: **Added**\n* `ConductoroneApi.Reporting.GetRunProvenance()`: **Added**\n* `ConductoroneApi.Reporting.List()`: **Added**\n* `ConductoroneApi.Reporting.Run()`: **Added**\n* `ConductoroneApi.Reporting.Save()`: **Added**\n* `ConductoroneApi.Reporting.Update()`: **Added**\n* `ConductoroneApi.RoleMiningManagement.EvaluateEntitlementSelection()`: **Added**\n* `ConductoroneApi.SsoSettings.Get()`: **Added**\n* `ConductoroneApi.SsoSettings.ListHistory()`: **Added**\n* `ConductoroneApi.SsoSettings.Update()`: **Added**\n* `ConductoroneApi.TaskActions.RetryProvisioning()`: **Added**\n* `ConductoroneApi.A2Ui.ListSurfaces()`: `response.Surfaces[].Components[]` **Changed**\n* `ConductoroneApi.AccessReview.Create()`: `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added**\n* `ConductoroneApi.AccessReview.Get()`: `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added**\n* `ConductoroneApi.AccessReview.List()`: `response.List[].AccessReview.ColumnConfig.OrderedColumns` **Added**\n* `ConductoroneApi.AccessReview.Update()`: \n * `request.Request.AccessReviewServiceUpdateRequest.AccessReview.ColumnConfig.OrderedColumns` **Added**\n * `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added**\n* `ConductoroneApi.AccessReviewTemplate.Get()`: `response.AccessReviewTemplate` **Changed**\n* `ConductoroneApi.AppUser.List()`: `response.List[].AppUser` **Changed**\n* `ConductoroneApi.AppUser.ListAppUsersForUser()`: `response.List[].AppUser` **Changed**\n* `ConductoroneApi.AppUser.ListOwnedServiceAccounts()`: `response.List[].AppUser` **Changed**\n* `ConductoroneApi.AppUser.Search()`: \n * `request.Request` **Changed**\n * `response.List[].AppUser` **Changed**\n* `ConductoroneApi.AppUser.Update()`: `response.AppUserView.AppUser` **Changed**\n* `ConductoroneApi.Apps.Create()`: \n * `request.Request.MatchBatonRef` **Added**\n * `response.App.MatchBatonRef` **Added**\n* `ConductoroneApi.Apps.Get()`: `response.App.MatchBatonRef` **Added**\n* `ConductoroneApi.Apps.List()`: `response.List[].MatchBatonRef` **Added**\n* `ConductoroneApi.Apps.Update()`: \n * `request.Request.UpdateAppRequest.App.MatchBatonRef` **Added**\n * `response.App.MatchBatonRef` **Added**\n* `ConductoroneApi.McpTool.Get()`: `response.Tool` **Changed**\n* `ConductoroneApi.McpTool.List()`: `response.Tools[]` **Changed**\n* `ConductoroneApi.McpTool.ListHistory()`: `response.List[].Snapshot` **Changed**\n* `ConductoroneApi.McpTool.Search()`: \n * `request.Request.McpToolServiceSearchRequest.IncludeRequestable` **Added**\n * `response.List[]` **Changed**\n* `ConductoroneApi.McpTool.Update()`: `response.Tool` **Changed**\n* `ConductoroneApi.McpAccessProfile.Create()`: `response.Profile` **Changed**\n* `ConductoroneApi.McpAccessProfile.Get()`: `response.Profile` **Changed**\n* `ConductoroneApi.McpAccessProfile.GetByAppEntitlementId()`: `response.Profile` **Changed**\n* `ConductoroneApi.McpAccessProfile.List()`: `response.Profiles[]` **Changed**\n* `ConductoroneApi.McpAccessProfile.Update()`: `response.Profile` **Changed**\n* `ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools()`: `response.AccessProfilesForTools[].AccessProfiles[]` **Changed**\n* `ConductoroneApi.AppEntitlements.Create()`: \n * `request.Request.CreateAppEntitlementRequest.ProvisionPolicy` **Changed**\n * `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlements.Get()`: `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlements.List()`: \n * `request.Request` **Changed**\n * `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlements.ListForAppResource()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlements.ListForAppUser()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlements.ListUsers()`: `response.List[].AppUser.AppUser` **Changed**\n* `ConductoroneApi.AppEntitlements.Update()`: \n * `request.Request.UpdateAppEntitlementRequest.Entitlement.DeprovisionerPolicy` **Changed**\n * `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementSearch.Search()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired()`: `response.List[].AppUser` **Changed**\n* `ConductoroneApi.AppEntitlementSearch.SearchGrants()`: `response.List[]` **Changed**\n* `ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants()`: `response.List[].History.Id` **Added**\n* `ConductoroneApi.McpServer.Get()`: `response.McpServer.EndpointUrlLocked` **Added**\n* `ConductoroneApi.McpServer.GetCatalog()`: `response.CatalogEntry` **Changed**\n* `ConductoroneApi.McpServer.List()`: `response.List[].EndpointUrlLocked` **Added**\n* `ConductoroneApi.McpServer.ListCatalog()`: `response.List[]` **Changed**\n* `ConductoroneApi.McpServer.Register()`: \n * `request.Request.McpServerServiceRegisterRequest.AccessProfileIds` **Added**\n * `response` **Changed**\n* `ConductoroneApi.McpServer.SearchWithToolCount()`: `response.List[].McpServer.EndpointUrlLocked` **Added**\n* `ConductoroneApi.McpServer.Update()`: `response.McpServer.EndpointUrlLocked` **Added**\n* `ConductoroneApi.McpServer.UpdateCredentials()`: `response.McpServer.EndpointUrlLocked` **Added**\n* `ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType()`: \n * `request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(clawAgent)` **Added**\n* `ConductoroneApi.Auth.Introspect()`: `response.DisabledModules` **Added**\n* `ConductoroneApi.Automation.CreateAutomation()`: \n * `request.Request.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n * `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.Automation.GetAutomation()`: `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.Automation.ListAutomations()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.Automation.UpdateAutomation()`: \n * `request.Request.UpdateAutomationRequest.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n * `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.RequestCatalogManagement.Create()`: \n * `request.Request.Type` **Added**\n * `response.RequestCatalogView.RequestCatalog` **Changed**\n* `ConductoroneApi.RequestCatalogManagement.Get()`: `response.RequestCatalogView.RequestCatalog` **Changed**\n* `ConductoroneApi.RequestCatalogManagement.List()`: `response.List[].RequestCatalog` **Changed**\n* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.RequestCatalogManagement.Update()`: \n * `request.Request.RequestCatalogManagementServiceUpdateRequest.Catalog.AccessEntitlements[].DeprovisionerPolicy` **Changed**\n * `response.RequestCatalogView.RequestCatalog` **Changed**\n* `ConductoroneApi.ConnectorCatalog.ConfigurationSchema()`: `response.FormSchema.Fields[].StringField` **Changed**\n* `ConductoroneApi.Finding.BulkCreateFindingTasks()`: \n * `request.Request.SearchRequest.FindingTypes[]` **Changed**\n* `ConductoroneApi.Finding.BulkUpdateFindingState()`: `request.Request` **Changed**\n* `ConductoroneApi.Finding.CreateFinding()`: `response.Finding` **Changed**\n* `ConductoroneApi.Finding.CreateFindingTask()`: `response.Finding` **Changed**\n* `ConductoroneApi.Finding.GetFinding()`: `response.Finding` **Changed**\n* `ConductoroneApi.Finding.UpdateFindingState()`: `response.Finding` **Changed**\n* `ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule()`: \n * `request.Request.RoutingRule` **Changed**\n * `response.RoutingRule` **Changed**\n* `ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule()`: `response.RoutingRule` **Changed**\n* `ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules()`: `response.List[]` **Changed**\n* `ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule()`: \n * `request.Request.UpdateFindingRoutingRuleRequest.RoutingRule` **Changed**\n * `response.RoutingRule` **Changed**\n* `ConductoroneApi.FindingSearch.Search()`: \n * `request.Request.FindingTypes[]` **Changed**\n * `response.List[]` **Changed**\n* `ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule()`: \n * `request.Request.TransformationRule.FindingType` **Added**\n * `response.TransformationRule.FindingType` **Added**\n* `ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule()`: `response.TransformationRule.FindingType` **Added**\n* `ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules()`: `response.List[].FindingType` **Added**\n* `ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule()`: \n * `request.Request.UpdateFindingTransformationRuleRequest.TransformationRule.FindingType` **Added**\n * `response.TransformationRule.FindingType` **Added**\n* `ConductoroneApi.Functions.CreateFunction()`: `response.Function` **Changed**\n* `ConductoroneApi.Functions.GetFunction()`: `response.Function` **Changed**\n* `ConductoroneApi.Functions.ListFunctions()`: `response.List[]` **Changed**\n* `ConductoroneApi.Functions.UpdateFunction()`: \n * `request.Request` **Changed**\n * `response` **Changed**\n* `ConductoroneApi.Hooks.Create()`: \n * `request.Request` **Changed**\n * `response.Hook` **Changed**\n* `ConductoroneApi.Hooks.Get()`: `response.Hook` **Changed**\n* `ConductoroneApi.Hooks.List()`: `response.List[]` **Changed**\n* `ConductoroneApi.Hooks.Update()`: \n * `request.Request.HooksServiceUpdateRequest.Hook` **Changed**\n * `response.Hook` **Changed**\n* `ConductoroneApi.Policies.Create()`: \n * `request.Request` **Changed**\n * `response.Policy` **Changed**\n* `ConductoroneApi.Policies.Get()`: `response.Policy` **Changed**\n* `ConductoroneApi.Policies.List()`: `response.List[]` **Changed**\n* `ConductoroneApi.Policies.Update()`: \n * `request.Request.UpdatePolicyRequest.Policy` **Changed**\n * `response.Policy` **Changed**\n* `ConductoroneApi.RequestSchema.Create()`: \n * `request.Request.Fields[].StringField` **Changed**\n * `response.RequestSchema.Form.Fields[].StringField` **Changed**\n* `ConductoroneApi.RequestSchema.Get()`: `response.RequestSchema.Form.Fields[].StringField` **Changed**\n* `ConductoroneApi.RequestSchema.Update()`: \n * `request.Request.RequestSchemaServiceUpdateRequest.RequestSchema.Form.Fields[].StringField` **Changed**\n * `response.RequestSchema.Form.Fields[].StringField` **Changed**\n* `ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult()`: `response.CutoffImpactPoints` **Added**\n* `ConductoroneApi.AppSearch.Search()`: `response.List[].MatchBatonRef` **Added**\n* `ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.AutomationSearch.SearchAutomations()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added**\n* `ConductoroneApi.FindingAudit.Search()`: \n * `request.Request.EventTypes[]` **Changed**\n * `response.List[].EventType` **Changed**\n* `ConductoroneApi.FunctionsSearch.Search()`: `response.List[]` **Changed**\n* `ConductoroneApi.HooksSearch.Search()`: `response.List[]` **Changed**\n* `ConductoroneApi.ExternalClientSearch.Search()`: `response.List[].ClientIdType.Enum(clientIdTypeApp)` **Added**\n* `ConductoroneApi.PolicySearch.Search()`: \n * `request.Request` **Changed**\n * `response.List[]` **Changed**\n* `ConductoroneApi.RequestCatalogSearch.SearchEntitlements()`: `response.List[].Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.TaskSearch.Search()`: \n * `request.Request.AccountStatuses` **Added**\n * `response.List[].Task` **Changed**\n* `ConductoroneApi.UserSearch.Search()`: \n * `request.Request.SourceAppIds` **Added**\n* `ConductoroneApi.AiGovernanceSettings.Get()`: `response.AiGovernanceSettings.UntrustedJudgeDisable` **Added**\n* `ConductoroneApi.AiGovernanceSettings.ListHistory()`: `response.List[].Snapshot.UntrustedJudgeDisable` **Added**\n* `ConductoroneApi.AiGovernanceSettings.Update()`: \n * `request.Request.AiGovernanceSettings.UntrustedJudgeDisable` **Added**\n * `response.AiGovernanceSettings.UntrustedJudgeDisable` **Added**\n* `ConductoroneApi.OrgNotificationSettings.Get()`: `response.OrgNotificationSettings.ChannelSettings` **Changed**\n* `ConductoroneApi.OrgNotificationSettings.Update()`: \n * `request.Request.ChannelSettings` **Changed**\n * `response.OrgNotificationSettings.ChannelSettings` **Changed**\n* `ConductoroneApi.UserNotificationSettings.Get()`: `response.UserNotificationSettings.ChannelSettings` **Changed**\n* `ConductoroneApi.UserNotificationSettings.Update()`: \n * `request.Request.ChannelSettings` **Changed**\n * `response.UserNotificationSettings.ChannelSettings` **Changed**\n* `ConductoroneApi.RequestSettings.Get()`: `response.RequestSettings.MaxBulkEntitlementSelection` **Added**\n* `ConductoroneApi.RequestSettings.Update()`: \n * `request.Request.RequestSettings.MaxBulkEntitlementSelection` **Added**\n * `response.RequestSettings.MaxBulkEntitlementSelection` **Added**\n* `ConductoroneApi.Task.CreateActionTask()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.Task.CreateGrantTask()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.Task.CreateOffboardingTask()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.Task.CreateResourceActionTask()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.Task.CreateRevokeTask()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.Task.Get()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskAudit.List()`: \n * `request.Request.ExcludeComments` **Added**\n * `response` **Changed**\n* `ConductoroneApi.TaskActions.Approve()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.ApproveWithStepUp()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.Close()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.Comment()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.Deny()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.EscalateToEmergencyAccess()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.HardReset()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.ProcessNow()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.Reassign()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.Restart()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.SkipStep()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.UpdateGrantDuration()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.TaskActions.UpdateRequestData()`: `response.TaskView.Task` **Changed**\n* `ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner()`: `response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner()`: `response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner()`: `response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner()`: `response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppOwnersV2.CreateEntitlementOwner()`: `response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppOwnersV2.GetEntitlementOwner()`: `response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner()`: `response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner()`: `response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner()`: `response.AppUserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.UserOwnersV2.CreateEntitlementOwner()`: `response.UserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n* `ConductoroneApi.UserOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added**\n" generatedFiles: - .gitattributes - /pkg/models/operations/c1apiaccessconflictv1accessconflictservicecreatemonitor.go diff --git a/.speakeasy/logs/changes/changes.html b/.speakeasy/logs/changes/changes.html index 04e0fd690..5d6cd11d4 100644 --- a/.speakeasy/logs/changes/changes.html +++ b/.speakeasy/logs/changes/changes.html @@ -98,4134 +98,1426 @@

Go SDK Changes:

    -
  • ConductoroneApi.AttributeSearch.SearchAttributeValues(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.LocalUserInvitation.Revoke(): response Changed (Breaking ⚠️) - -
      -
    • Invitation Added
    • -
    • LocalUserInvitation Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.SearchUserOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.SearchEntitlementOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.GetUserOwner(): response Changed (Breaking ⚠️) - -
      -
    • AppOwnerUser Added
    • -
    • AppOwnerUser Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.GetEntitlementOwner(): response Changed (Breaking ⚠️) - -
      -
    • AppOwnerEntitlement Added
    • -
    • AppOwnerEntitlement Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.DeleteUserOwner(): request.Request Changed (Breaking ⚠️) - -
      -
    • DeleteAppUserOwnerRequest Added
    • -
    • DeleteUserOwnerRequest Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.DeleteEntitlementOwner(): request.Request Changed (Breaking ⚠️) - -
      -
    • DeleteAppEntitlementOwnerRequest Added
    • -
    • DeleteEntitlementOwnerRequest Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppOwnersV2.CreateUserOwner(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • CreateAppUserOwnerRequest Added
      • -
      • CreateUserOwnerRequest Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AppOwnerUser Added
      • -
      • AppOwnerUser Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.AppOwnersV2.CreateEntitlementOwner(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • CreateAppEntitlementOwnerRequest Added
      • -
      • CreateEntitlementOwnerRequest Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AppOwnerEntitlement Added
      • -
      • AppOwnerEntitlement Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.Set(): request.Request Changed (Breaking ⚠️) - -
      -
    • SetAppEntitlementOwnersRequestV2 Added
    • -
    • SetAppEntitlementOwnersV2Request Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.SearchUserOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppId Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • EntitlementId Added
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • AppId Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • EntitlementId Added
    • -
  • -
  • ConductoroneApi.ConnectorOwnersV2.SearchUserOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppId Added
    • -
    • ConnectorId Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • AppId Added
    • -
    • ConnectorId Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Webhooks.Update(): - -
      -
    • request.Request.WebhooksServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • WebhookEndpoint Removed (Breaking ⚠️)
      • -
      • Webhook Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • WebhookEndpoint Removed (Breaking ⚠️)
      • -
      • Webhook Added
      • -
    • -
  • -
  • ConductoroneApi.Webhooks.Test(): response Changed (Breaking ⚠️) - -
      -
    • WebhookInstance Removed (Breaking ⚠️)
    • -
    • Webhook Added
    • -
  • -
  • ConductoroneApi.Webhooks.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CallbackTimeout Changed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Webhooks.Get(): response Changed (Breaking ⚠️) - -
      -
    • WebhookEndpoint Removed (Breaking ⚠️)
    • -
    • Webhook Added
    • -
  • -
  • ConductoroneApi.Webhooks.Create(): - -
      -
    • request.Request.CallbackTimeout Changed
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • WebhookEndpoint Removed (Breaking ⚠️)
      • -
      • Webhook Added
      • -
    • -
  • -
  • ConductoroneApi.Vault.Update(): - -
      -
    • request.Request.VaultServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • Vault Added
      • -
      • Vault Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Vault Added
      • -
      • Vault Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Vault.Get(): response Changed (Breaking ⚠️) - -
      -
    • Vault Added
    • -
    • Vault Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Vault.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • GroupAuthzVault Added
      • -
      • GroupAuthzVault Removed (Breaking ⚠️)
      • -
      • MagicVault Added
      • -
      • MagicVault Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Vault Added
      • -
      • Vault Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.User.SetExpiringUserDelegationBindingByAdmin(): - -
      -
    • request.Request.SetExpiringUserDelegationBindingByAdminRequest Changed - -
        -
      • DelegationExpireAt Changed
      • -
      • DelegationStartAt Changed
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • ExpiringUserDelegationBinding Removed (Breaking ⚠️)
      • -
      • Item Added
      • -
    • -
  • -
  • ConductoroneApi.User.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • ObjectPermissions Added
    • -
    • UserId Added
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppEntitlementUserBinding.RemoveGrantDuration(): response Changed (Breaking ⚠️) - -
      -
    • AppEntitlementUserBinding Removed (Breaking ⚠️)
    • -
    • Binding Added
    • -
  • -
  • ConductoroneApi.User.Get(): response Changed (Breaking ⚠️) - -
      -
    • UserView Added
    • -
    • UserView Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.TaskActions.UpdateRequestData(): - -
      -
    • request.Request.TaskActionsServiceUpdateRequestDataRequest Changed (Breaking ⚠️) - -
        -
      • Data Changed
      • -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.UpdateGrantDuration(): - -
      -
    • request.Request.TaskActionsServiceUpdateGrantDurationRequest Changed (Breaking ⚠️) - -
        -
      • Duration Changed
      • -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.SkipStep(): - -
      -
    • request.Request.TaskActionsServiceSkipStepRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Restart(): - -
      -
    • request.Request.TaskActionsServiceRestartRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Reassign(): - -
      -
    • request.Request.TaskActionsServiceReassignRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.ProcessNow(): - -
      -
    • request.Request.TaskActionsServiceProcessNowRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.HardReset(): - -
      -
    • request.Request.TaskActionsServiceHardResetRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.EscalateToEmergencyAccess(): - -
      -
    • request.Request.TaskActionsServiceEscalateToEmergencyAccessRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Deny(): - -
      -
    • request.Request.TaskActionsServiceDenyRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Comment(): - -
      -
    • request.Request.TaskActionsServiceCommentRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Close(): - -
      -
    • request.Request.TaskActionsServiceCloseRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.ApproveWithStepUp(): - -
      -
    • request.Request.TaskActionsServiceApproveWithStepUpRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskActions.Approve(): - -
      -
    • request.Request.TaskActionsServiceApproveRequest Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Task.Get(): response Changed (Breaking ⚠️) - -
      -
    • TaskView Added
    • -
    • TaskView Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Task.CreateRevokeTask(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Task.CreateOffboardingTask(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Task.CreateGrantTask(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • GrantDuration Changed
      • -
      • RequestData Changed
      • -
      • Source Added
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
      • TaskGrantSource Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • TaskView Added
      • -
      • TaskView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskAudit.List(): - -
      -
    • request.Request Changed - -
        -
      • CommentsOnly Added
      • -
      • NewestFirst Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AccessRequestOutcome Added
      • -
      • AccountLifecycleActionCreated Added
      • -
      • AccountLifecycleActionFailed Added
      • -
      • ActionInstanceCreated Added
      • -
      • ActionInstanceFailed Added
      • -
      • ActionInstanceSucceeded Added
      • -
      • ActionResult Added
      • -
      • ActionSubmitted Added
      • -
      • ApprovalAutoAcceptedByPolicy Added
      • -
      • ApprovalAutoRejectedByPolicy Added
      • -
      • ApprovalInstanceChange Added
      • -
      • ApprovalReassigned Added
      • -
      • ApprovedAutomatically Added
      • -
      • BulkActionError Added
      • -
      • CertifyOutcome Added
      • -
      • Comment Added
      • -
      • ConditionalPolicyExecutionResult Added
      • -
      • ConnectorActionsEnd Added
      • -
      • ConnectorActionsStart Added
      • -
      • CreatedReplacementExtensionGrantTask Added
      • -
      • Created Changed (Breaking ⚠️)
      • -
      • ExpressionPolicyStepError Added
      • -
      • ExternalTicketCreated Added
      • -
      • ExternalTicketError Added
      • -
      • ExternalTicketProvisionStepResolved Added
      • -
      • ExternalTicketTriggered Added
      • -
      • FormInstanceChange Added
      • -
      • GrantDurationUpdated Added
      • -
      • GrantOutcome Added
      • -
      • HardReset Added
      • -
      • Metadata Added
      • -
      • PolicyChanged Added
      • -
      • PolicyEvaluationStep Added
      • -
      • ProvisionCancelled Added
      • -
      • ProvisionError Added
      • -
      • ProvisionReassigned Added
      • -
      • ReassignedToDelegate Added
      • -
      • ReassignmentFallbackToAdmin Added
      • -
      • ReassignmentListError Added
      • -
      • RequestDefaultsApplied Added
      • -
      • RevokeOutcome Added
      • -
      • SlaEscalation Added
      • -
      • StateChange Added
      • -
      • StepSkipped Added
      • -
      • StepUpApproval Added
      • -
      • TaskAuditAccessRequestOutcome Removed (Breaking ⚠️)
      • -
      • TaskAuditAccountLifecycleActionCreated Removed (Breaking ⚠️)
      • -
      • TaskAuditAccountLifecycleActionFailed Removed (Breaking ⚠️)
      • -
      • TaskAuditActionInstanceCreated Removed (Breaking ⚠️)
      • -
      • TaskAuditActionInstanceFailed Removed (Breaking ⚠️)
      • -
      • TaskAuditActionInstanceSucceeded Removed (Breaking ⚠️)
      • -
      • TaskAuditActionSubmitted Removed (Breaking ⚠️)
      • -
      • TaskAuditApprovalAutoAcceptedByPolicy Removed (Breaking ⚠️)
      • -
      • TaskAuditApprovalAutoRejectedByPolicy Removed (Breaking ⚠️)
      • -
      • TaskAuditApprovalHappenedAutomatically Removed (Breaking ⚠️)
      • -
      • TaskAuditApprovalInstanceChange Removed (Breaking ⚠️)
      • -
      • TaskAuditBulkActionError Removed (Breaking ⚠️)
      • -
      • TaskAuditCertifyOutcome Removed (Breaking ⚠️)
      • -
      • TaskAuditComment Removed (Breaking ⚠️)
      • -
      • TaskAuditConditionalPolicyExecutionResult Removed (Breaking ⚠️)
      • -
      • TaskAuditConnectorActionResult Removed (Breaking ⚠️)
      • -
      • TaskAuditCreatedReplacementExtensionGrantTask Removed (Breaking ⚠️)
      • -
      • TaskAuditEscalateToEmergencyAccess Removed (Breaking ⚠️)
      • -
      • TaskAuditExpressionPolicyStepError Removed (Breaking ⚠️)
      • -
      • TaskAuditExternalTicketCreated Removed (Breaking ⚠️)
      • -
      • TaskAuditExternalTicketError Removed (Breaking ⚠️)
      • -
      • TaskAuditExternalTicketProvisionStepResolved Removed (Breaking ⚠️)
      • -
      • TaskAuditExternalTicketTriggered Removed (Breaking ⚠️)
      • -
      • TaskAuditFinishedConnectorActions Removed (Breaking ⚠️)
      • -
      • TaskAuditFormInstanceChange Removed (Breaking ⚠️)
      • -
      • TaskAuditGrantDurationUpdated Removed (Breaking ⚠️)
      • -
      • TaskAuditGrantOutcome Removed (Breaking ⚠️)
      • -
      • TaskAuditHardReset Removed (Breaking ⚠️)
      • -
      • TaskAuditMetaData Removed (Breaking ⚠️)
      • -
      • TaskAuditNewTaskCreatedFrom Removed (Breaking ⚠️)
      • -
      • TaskAuditNewTask Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyApprovalReassigned Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyChanged Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyEvaluationStep Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyProvisionCancelled Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyProvisionError Removed (Breaking ⚠️)
      • -
      • TaskAuditPolicyProvisionReassigned Removed (Breaking ⚠️)
      • -
      • TaskAuditReassignedToDelegate Removed (Breaking ⚠️)
      • -
      • TaskAuditReassignmentFallbackToAdmin Removed (Breaking ⚠️)
      • -
      • TaskAuditReassignmentListError Removed (Breaking ⚠️)
      • -
      • TaskAuditRestart Removed (Breaking ⚠️)
      • -
      • TaskAuditRevokeOutcome Removed (Breaking ⚠️)
      • -
      • TaskAuditSlaEscalation Removed (Breaking ⚠️)
      • -
      • TaskAuditStartedConnectorActions Removed (Breaking ⚠️)
      • -
      • TaskAuditStateChange Removed (Breaking ⚠️)
      • -
      • TaskAuditStepSkipped Removed (Breaking ⚠️)
      • -
      • TaskAuditStepUpApproval Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitForAnalysisStepSuccess Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitForAnalysisStepTimedOut Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitForAnalysisStepWaiting Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitStepSuccess Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitStepTimedOut Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitStepUntilTime Removed (Breaking ⚠️)
      • -
      • TaskAuditWaitStepWaiting Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookApprovalAttempt Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookApprovalBadResponse Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookApprovalFatalError Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookApprovalSuccess Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookApprovalTriggered Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookAttempt Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookSuccess Removed (Breaking ⚠️)
      • -
      • TaskAuditWebhookTriggered Removed (Breaking ⚠️)
      • -
      • TaskCreatedFrom Added
      • -
      • TaskCreated Added
      • -
      • TaskEscalated Added
      • -
      • TaskRestarted Added
      • -
      • WaitStepAnalysisSuccess Added
      • -
      • WaitStepAnalysisTimedOut Added
      • -
      • WaitStepAnalysisWaiting Added
      • -
      • WaitStepSuccess Added
      • -
      • WaitStepTimedOut Added
      • -
      • WaitStepUntilTime Added
      • -
      • WaitStepWaiting Added
      • -
      • WebhookApprovalAttempt Added
      • -
      • WebhookApprovalBadResponse Added
      • -
      • WebhookApprovalFatalError Added
      • -
      • WebhookApprovalSuccess Added
      • -
      • WebhookApprovalTriggered Added
      • -
      • WebhookAttempt Added
      • -
      • WebhookSuccess Added
      • -
      • WebhookTriggered Added
      • -
    • -
  • -
  • ConductoroneApi.AppEntitlementUserBinding.ListAppUsersForIdentityWithGrant(): response.Bindings[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • DeprovisionAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Export.Update(): - -
      -
    • request.Request.ExportServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • Exporter Added
      • -
      • Exporter Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Exporter Added
      • -
      • Exporter Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Export.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Datasource Added
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ExportToDatasource Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Export.Get(): response Changed (Breaking ⚠️) - -
      -
    • Exporter Added
    • -
    • Exporter Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Export.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Datasource Added
      • -
      • ExportToDatasource Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Exporter Added
      • -
      • Exporter Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.SsfReceiverEvent.List(): response.List[].ReceivedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.SsfReceiverStream.Update(): - -
      -
    • request.Request.SsfReceiverStreamServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • SsfReceiverStream Added
      • -
      • SsfReceiverStream Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • SsfReceiverStream Added
      • -
      • SsfReceiverStream Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.SsfReceiverStream.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • LastErrorAt Changed (Breaking ⚠️)
    • -
    • LastVerifiedAt Changed (Breaking ⚠️)
    • -
    • OutboundAuthBearer Added
    • -
    • OutboundAuthOauth2 Added
    • -
    • PollInterval Changed (Breaking ⚠️)
    • -
    • SsfOutboundAuthBearer Removed (Breaking ⚠️)
    • -
    • SsfOutboundAuthOAuth2 Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.SsfReceiverStream.GetStats(): response Changed (Breaking ⚠️) - -
      -
    • SsfReceiverStreamStats Removed (Breaking ⚠️)
    • -
    • Stats Added
    • -
  • -
  • ConductoroneApi.SsfReceiverStream.Get(): response Changed (Breaking ⚠️) - -
      -
    • SsfReceiverStream Added
    • -
    • SsfReceiverStream Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.SsfReceiverStream.Create(): - -
      -
    • request.Request.PollInterval Changed
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • SsfReceiverStream Added
      • -
      • SsfReceiverStream Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.SessionSettings.Update(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • SessionSettings Added
      • -
      • SessionSettings Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • SessionSettings Added
      • -
      • SessionSettings Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.SessionSettings.TestSourceIp(): response Changed (Breaking ⚠️) - -
      -
    • Details Added
    • -
    • Status Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.SessionSettings.Get(): response Changed (Breaking ⚠️) - -
      -
    • SessionSettings Added
    • -
    • SessionSettings Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.OnboardingSettings.Get(): response Changed (Breaking ⚠️) - -
      -
    • McpOnboardingGoal Added
    • -
    • McpOnboardingStatus Added
    • -
    • McpOnboardingTargets Added
    • -
    • OnboardingOrgContext Removed (Breaking ⚠️)
    • -
    • OrgContext Added
    • -
  • -
  • ConductoroneApi.UserNotificationSettings.Update(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ChannelSettings Added
      • -
      • ChannelSettings Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • UserNotificationSettings Added
      • -
      • UserNotificationSettings Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.UserNotificationSettings.Get(): response Changed (Breaking ⚠️) - -
      -
    • UserNotificationSettings Added
    • -
    • UserNotificationSettings Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.OrgNotificationSettings.Update(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ChannelSettings Added
      • -
      • ChannelSettings Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • OrgNotificationSettings Added
      • -
      • OrgNotificationSettings Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.OrgNotificationSettings.Get(): response Changed (Breaking ⚠️) - -
      -
    • OrgNotificationSettings Added
    • -
    • OrgNotificationSettings Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.TenantEmailProvider.Update(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • EmailProvider Added
      • -
      • TenantEmailProvider Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • EmailProvider Added
      • -
      • TenantEmailProvider Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TenantEmailProvider.Get(): response Changed (Breaking ⚠️) - -
      -
    • EmailProvider Added
    • -
    • TenantEmailProvider Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.OrgDomain.Update(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.OrgDomain.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Contacts.UpdateContacts(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Contacts Added
      • -
      • Contacts Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Contacts Added
      • -
      • Contacts Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Contacts.GetContacts(): response Changed (Breaking ⚠️) - -
      -
    • Contacts Added
    • -
    • Contacts Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AwsExternalIdSettings.Get(): response Changed (Breaking ⚠️) - -
      -
    • AwsExternalId Added
    • -
    • AwsExternalId Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.UpdateCredential(): - -
      -
    • request.Request.ServicePrincipalServiceUpdateCredentialRequest Changed (Breaking ⚠️) - -
        -
      • Credential Added
      • -
      • ServicePrincipalCredential Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Credential Added
      • -
      • ServicePrincipalCredential Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Principal.Update(): - -
      -
    • request.Request.ServicePrincipalServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • ServicePrincipal Added
      • -
      • ServicePrincipal Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • ServicePrincipal Added
      • -
      • ServicePrincipal Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Principal.ListCredentials(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • ExpiresAt Changed (Breaking ⚠️)
    • -
    • LastUsedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.ListBindings(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ServicePrincipalBindingSubject Removed (Breaking ⚠️)
      • -
      • Subject Added
      • -
    • -
    • response.Bindings[] Changed (Breaking ⚠️) - -
        -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Principal.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.GetCredential(): response Changed (Breaking ⚠️) - -
      -
    • Credential Added
    • -
    • ServicePrincipalCredential Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.Get(): response Changed (Breaking ⚠️) - -
      -
    • ServicePrincipal Added
    • -
    • ServicePrincipal Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.DeleteBinding(): request.Request Changed (Breaking ⚠️) - -
      -
    • ServicePrincipalBindingSubject Removed (Breaking ⚠️)
    • -
    • Subject Added
    • -
  • -
  • ConductoroneApi.Principal.CreateCredential(): - -
      -
    • request.Request.ServicePrincipalServiceCreateCredentialRequest.Expires Changed
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Credential Added
      • -
      • ServicePrincipalCredential Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Principal.Create(): response Changed (Breaking ⚠️) - -
      -
    • ServicePrincipal Added
    • -
    • ServicePrincipal Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Principal.AddBinding(): request.Request Changed (Breaking ⚠️) - -
      -
    • ServicePrincipalBindingSubject Removed (Breaking ⚠️)
    • -
    • Subject Added
    • -
  • -
  • ConductoroneApi.WorkloadFederation.UpdateTrust(): - -
      -
    • request.Request.WorkloadFederationServiceUpdateTrustRequest Changed (Breaking ⚠️) - -
        -
      • Trust Added
      • -
      • WorkloadFederationTrust Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Trust Added
      • -
      • WorkloadFederationTrust Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.WorkloadFederation.UpdateProvider(): - -
      -
    • request.Request.WorkloadFederationServiceUpdateProviderRequest Changed (Breaking ⚠️) - -
        -
      • Provider Added
      • -
      • WorkloadFederationProvider Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Provider Added
      • -
      • WorkloadFederationProvider Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.WorkloadFederation.TestToken(): response Changed (Breaking ⚠️) - -
      -
    • AudienceValidation Added
    • -
    • CelEvaluation Added
    • -
    • CidrCheck Added
    • -
    • IssuerMatch Added
    • -
    • JwtDecode Added
    • -
    • SignatureValidation Added
    • -
    • SubjectValidation Added
    • -
    • TestTokenStepResult1 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult2 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult3 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult4 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult5 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult6 Removed (Breaking ⚠️)
    • -
    • TestTokenStepResult Removed (Breaking ⚠️)
    • -
    • TokenFreshness Added
    • -
  • -
  • ConductoroneApi.WorkloadFederation.SearchTrusts(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.WorkloadFederation.ListTrusts(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.WorkloadFederation.ListProviders(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Oidc Added
    • -
    • Spiffe Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
    • WellKnownProvider.Enum(wellKnownWorkloadProviderSpiffe) Added
    • -
  • -
  • ConductoroneApi.WorkloadFederation.GetTrust(): response Changed (Breaking ⚠️) - -
      -
    • Trust Added
    • -
    • WorkloadFederationTrust Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.WorkloadFederation.GetProvider(): response Changed (Breaking ⚠️) - -
      -
    • Provider Added
    • -
    • WorkloadFederationProvider Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.WorkloadFederation.CreateTrust(): response Changed (Breaking ⚠️) - -
      -
    • Trust Added
    • -
    • WorkloadFederationTrust Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.WorkloadFederation.CreateProvider(): - -
      -
    • request.Request Changed - -
        -
      • Oidc Added
      • -
      • Spiffe Added
      • -
      • WellKnownProvider.Enum(wellKnownWorkloadProviderSpiffe) Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Provider Added
      • -
      • WorkloadFederationProvider Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.WebhooksSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CallbackTimeout Changed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.UserSearch.Search(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • ExpandMask Added
      • -
      • UserExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • ObjectPermissions Added
      • -
      • UserId Added
      • -
      • User Added
      • -
      • User Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.TaskSearch.Search(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • CreatedAfter Changed
      • -
      • CreatedBefore Changed
      • -
      • ExpandMask Added
      • -
      • IncludeActedAfter Changed
      • -
      • OlderThanDuration Changed
      • -
      • OutcomeAfter Changed
      • -
      • OutcomeBefore Changed
      • -
      • TaskExpandMask Removed (Breaking ⚠️)
      • -
      • TaskTypes[].Action Added
      • -
      • TaskTypes[].Certify Added
      • -
      • TaskTypes[].Finding Added
      • -
      • TaskTypes[].Grant Added
      • -
      • TaskTypes[].Offboarding Added
      • -
      • TaskTypes[].Revoke Added
      • -
      • TaskTypes[].TaskTypeAction Removed (Breaking ⚠️)
      • -
      • TaskTypes[].TaskTypeCertify Removed (Breaking ⚠️)
      • -
      • TaskTypes[].TaskTypeFinding Removed (Breaking ⚠️)
      • -
      • TaskTypes[].TaskTypeGrant Removed (Breaking ⚠️)
      • -
      • TaskTypes[].TaskTypeOffboarding Removed (Breaking ⚠️)
      • -
      • TaskTypes[].TaskTypeRevoke Removed (Breaking ⚠️)
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • ObjectPermissions Added
      • -
      • PrincipalResourcePath Added
      • -
      • Task Added
      • -
      • Task Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.ExportsSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Datasource Added
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ExportToDatasource Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.StepUpTransaction.Search(): - -
      -
    • request.Request Changed - -
        -
      • CreatedAfter Changed
      • -
      • CreatedBefore Changed
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • ApproveTask Added
      • -
      • Claims Changed (Breaking ⚠️)
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • ExpiresAt Changed (Breaking ⚠️)
      • -
      • TargetTask Removed (Breaking ⚠️)
      • -
      • TargetTest Removed (Breaking ⚠️)
      • -
      • Test Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.StepUpTransaction.Get(): response Changed (Breaking ⚠️) - -
      -
    • StepUpTransaction Removed (Breaking ⚠️)
    • -
    • Transaction Added
    • -
  • -
  • ConductoroneApi.StepUpProvider.UpdateSecret(): response Changed (Breaking ⚠️) - -
      -
    • StepUpProvider Added
    • -
    • StepUpProvider Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.StepUpProvider.Update(): - -
      -
    • request.Request.UpdateStepUpProviderRequest Changed (Breaking ⚠️) - -
        -
      • StepUpProvider Added
      • -
      • StepUpProvider Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • StepUpProvider Added
      • -
      • StepUpProvider Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.StepUpProvider.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • LastTestedAt Changed (Breaking ⚠️)
    • -
    • Microsoft Added
    • -
    • Oauth2 Added
    • -
    • StepUpMicrosoftSettings Removed (Breaking ⚠️)
    • -
    • StepUpOAuth2Settings Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.StepUpProvider.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • LastTestedAt Changed (Breaking ⚠️)
    • -
    • Microsoft Added
    • -
    • Oauth2 Added
    • -
    • StepUpMicrosoftSettings Removed (Breaking ⚠️)
    • -
    • StepUpOAuth2Settings Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.StepUpProvider.Get(): response Changed (Breaking ⚠️) - -
      -
    • StepUpProvider Added
    • -
    • StepUpProvider Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.StepUpProvider.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Microsoft Added
      • -
      • Oauth2 Added
      • -
      • StepUpMicrosoftSettings Removed (Breaking ⚠️)
      • -
      • StepUpOAuth2Settings Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • StepUpProvider Added
      • -
      • StepUpProvider Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.SsfReceiverEventSearch.Search(): response.List[].ReceivedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.PaperSecret.SetTextContent(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.PaperSecret.SearchMySecrets(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AgeSuite Added
    • -
    • ContentExpiresAt Changed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.PaperSecret.Revoke(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.PaperSecret.GetContent(): response.CreatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.PaperSecret.GetByShareCode(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.PaperSecret.Get(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.PaperSecret.CreateInternal(): - -
      -
    • request.Request Changed - -
        -
      • ExpiresIn Changed
      • -
      • RequiredAgeSuite Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AgeSuite Added
      • -
      • PaperSecret Removed (Breaking ⚠️)
      • -
      • Secret Added
      • -
    • -
  • -
  • ConductoroneApi.PaperSecret.CreateExternal(): - -
      -
    • request.Request Changed - -
        -
      • ExpiresIn Changed
      • -
      • RequiredAgeSuite Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AgeSuite Added
      • -
      • PaperSecret Removed (Breaking ⚠️)
      • -
      • Secret Added
      • -
    • -
  • -
  • ConductoroneApi.PaperSecretAdmin.Search(): - -
      -
    • request.Request Changed - -
        -
      • CreatedAfter Changed
      • -
      • CreatedBefore Changed
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AgeSuite Added
      • -
      • ContentExpiresAt Changed (Breaking ⚠️)
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • DeletedAt Changed (Breaking ⚠️)
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.PaperSecretAdmin.Revoke(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.PaperSecretAdmin.Get(): response Changed (Breaking ⚠️) - -
      -
    • PaperSecret Removed (Breaking ⚠️)
    • -
    • Secret Added
    • -
  • -
  • ConductoroneApi.RoleMiningManagementSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Entitlements[].RiskLevelValueId Added
    • -
    • LastGeneratedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RequestCatalogSearch.SearchEntitlements(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AppEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AppEntitlementUserBindings[].CreatedAt Changed (Breaking ⚠️)
      • -
      • AppEntitlementUserBindings[].DeletedAt Changed (Breaking ⚠️)
      • -
      • AppEntitlementUserBindings[].DeprovisionAt Changed (Breaking ⚠️)
      • -
      • AppEntitlementView Removed (Breaking ⚠️)
      • -
      • Entitlement Added
      • -
    • -
  • -
  • ConductoroneApi.PolicySearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Annotations Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Accept Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Accept Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Action Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Action Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Approval Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Approval Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Form Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Form Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Provision Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Provision Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Reject Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Reject Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Wait Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Wait Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.PersonalClientSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ExpiresTime Changed (Breaking ⚠️)
    • -
    • LastUsedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.ExternalClientSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • LastUsedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.HooksSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • BuiltInPattern Removed (Breaking ⚠️)
    • -
    • BuiltinPattern Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Filter Added
    • -
    • Function Added
    • -
    • HookFilter Removed (Breaking ⚠️)
    • -
    • HookFunctionRef Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.FunctionsSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ProvisionedConcurrency Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AutomationSearch.SearchAutomations(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Annotations Added
    • -
    • AutomationContext Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].AccountLifecycleAction Added
    • -
    • AutomationSteps[].AccountLifecycleAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CallFunction Added
    • -
    • AutomationSteps[].CallFunction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorAction Added
    • -
    • AutomationSteps[].ConnectorAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorCreateAccount Added
    • -
    • AutomationSteps[].ConnectorCreateAccount Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateAccessReview Added
    • -
    • AutomationSteps[].CreateAccessReview Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Added
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasks Added
    • -
    • AutomationSteps[].CreateRevokeTasks Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].EvaluateExpressions Added
    • -
    • AutomationSteps[].EvaluateExpressions Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GeneratePassword Added
    • -
    • AutomationSteps[].GeneratePassword Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GrantEntitlements Added
    • -
    • AutomationSteps[].GrantEntitlements Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RemoveFromDelegation Added
    • -
    • AutomationSteps[].RemoveFromDelegation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RunAutomation Added
    • -
    • AutomationSteps[].RunAutomation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendEmail Added
    • -
    • AutomationSteps[].SendEmail Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendSlackMessage Added
    • -
    • AutomationSteps[].SendSlackMessage Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SetCredential Added
    • -
    • AutomationSteps[].SetCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].StoreCredential Added
    • -
    • AutomationSteps[].StoreCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].TaskAction Added
    • -
    • AutomationSteps[].TaskAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Added
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UpdateUser Added
    • -
    • AutomationSteps[].UpdateUser Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].WaitForDuration Added
    • -
    • AutomationSteps[].WaitForDuration Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].Webhook Added
    • -
    • AutomationSteps[].Webhook Removed (Breaking ⚠️)
    • -
    • CircuitBreaker Added
    • -
    • Context Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DisabledReasonCircuitBreaker Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AccessConflictTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AccessConflict Added
    • -
    • DraftTriggers[].AppUserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AppUserCreated Added
    • -
    • DraftTriggers[].AppUserUpdatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AppUserUpdated Added
    • -
    • DraftTriggers[].GrantDeletedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].GrantDeleted Added
    • -
    • DraftTriggers[].GrantFoundTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].GrantFound Added
    • -
    • DraftTriggers[].ScheduleAppUser Added
    • -
    • DraftTriggers[].ScheduleNoUser Added
    • -
    • DraftTriggers[].ScheduleTriggerAppUser Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].ScheduleTriggerNoUser Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].ScheduleTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].Schedule Added
    • -
    • DraftTriggers[].UsageBasedRevocationTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UsageBasedRevocation Added
    • -
    • DraftTriggers[].UserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UserCreated Added
    • -
    • DraftTriggers[].UserProfileChangeTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UserProfileChange Added
    • -
    • DraftTriggers[].WebhookAutomationTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].Webhook Added
    • -
    • LastExecutedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AutomationSteps[].AccountLifecycleAction Added
    • -
    • AutomationSteps[].AccountLifecycleAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CallFunction Added
    • -
    • AutomationSteps[].CallFunction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorAction Added
    • -
    • AutomationSteps[].ConnectorAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorCreateAccount Added
    • -
    • AutomationSteps[].ConnectorCreateAccount Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateAccessReview Added
    • -
    • AutomationSteps[].CreateAccessReview Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Added
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasks Added
    • -
    • AutomationSteps[].CreateRevokeTasks Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].EvaluateExpressions Added
    • -
    • AutomationSteps[].EvaluateExpressions Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GeneratePassword Added
    • -
    • AutomationSteps[].GeneratePassword Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GrantEntitlements Added
    • -
    • AutomationSteps[].GrantEntitlements Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RemoveFromDelegation Added
    • -
    • AutomationSteps[].RemoveFromDelegation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RunAutomation Added
    • -
    • AutomationSteps[].RunAutomation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendEmail Added
    • -
    • AutomationSteps[].SendEmail Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendSlackMessage Added
    • -
    • AutomationSteps[].SendSlackMessage Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SetCredential Added
    • -
    • AutomationSteps[].SetCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].StoreCredential Added
    • -
    • AutomationSteps[].StoreCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].TaskAction Added
    • -
    • AutomationSteps[].TaskAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Added
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UpdateUser Added
    • -
    • AutomationSteps[].UpdateUser Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].WaitForDuration Added
    • -
    • AutomationSteps[].WaitForDuration Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].Webhook Added
    • -
    • AutomationSteps[].Webhook Removed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • Triggers[].AccessConflictTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].AccessConflict Added
    • -
    • Triggers[].AppUserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].AppUserCreated Added
    • -
    • Triggers[].AppUserUpdatedTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].AppUserUpdated Added
    • -
    • Triggers[].GrantDeletedTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].GrantDeleted Added
    • -
    • Triggers[].GrantFoundTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].GrantFound Added
    • -
    • Triggers[].ScheduleAppUser Added
    • -
    • Triggers[].ScheduleNoUser Added
    • -
    • Triggers[].ScheduleTriggerAppUser Removed (Breaking ⚠️)
    • -
    • Triggers[].ScheduleTriggerNoUser Removed (Breaking ⚠️)
    • -
    • Triggers[].ScheduleTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].Schedule Added
    • -
    • Triggers[].UsageBasedRevocationTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].UsageBasedRevocation Added
    • -
    • Triggers[].UserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].UserCreated Added
    • -
    • Triggers[].UserProfileChangeTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].UserProfileChange Added
    • -
    • Triggers[].WebhookAutomationTrigger Removed (Breaking ⚠️)
    • -
    • Triggers[].Webhook Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Annotations Added
    • -
    • AppOwners[].CreatedAt Changed (Breaking ⚠️)
    • -
    • AppOwners[].DeletedAt Changed (Breaking ⚠️)
    • -
    • AppOwners[].DepartmentSources[].Priority Added
    • -
    • AppOwners[].Profile Changed (Breaking ⚠️)
    • -
    • AppOwners[].UpdatedAt Changed (Breaking ⚠️)
    • -
    • AppUserMapper Added
    • -
    • AppUserMapper Removed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • RevokeGrantSources Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppResourceSearch.SearchAppResources(): - -
      -
    • request.Request Changed - -
        -
      • AgentStatuses Added
      • -
      • AppIds Added
      • -
      • CredentialTypes Added
      • -
      • Direction Added
      • -
      • ExcludeDeletedApps Added
      • -
      • NhiTypes Added
      • -
      • SecretAging Added
      • -
      • SortField Added
      • -
      • UnownedOnly Added
      • -
      • WithOpenFindings Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • ActorObjectPermissions Removed (Breaking ⚠️)
      • -
      • AppResource Added
      • -
      • AppResource Removed (Breaking ⚠️)
      • -
      • ObjectPermissions Added
      • -
    • -
  • -
  • ConductoroneApi.AppResourceSearch.SearchAppResourceTypes(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AutomationExecutionSearch.SearchAutomationExecutions(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AutomationExecutionExpandMask Removed (Breaking ⚠️)
      • -
      • ExecutionStepStates[].Enum(automationExecutionStatePausedByCircuitBreaker) Added
      • -
      • ExpandMask Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AutomationExecution Added
      • -
      • AutomationExecution Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.AutomationExecutionSearch.SearchAllAutomationExecutions(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AutomationExecutionExpandMask Removed (Breaking ⚠️)
      • -
      • ExecutionStates[].Enum(automationExecutionStatePausedByCircuitBreaker) Added
      • -
      • ExpandMask Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AutomationExecution Added
      • -
      • AutomationExecution Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.UpdateSuggestionState(): response Changed (Breaking ⚠️) - -
      -
    • RoleMiningManagementSuggestion Removed (Breaking ⚠️)
    • -
    • Suggestion Added
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.UpdateRoleMiningConfig(): response Changed (Breaking ⚠️) - -
      -
    • Config Added
    • -
    • RoleMiningManagementConfig Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.SearchCohortUsers(): - -
      -
    • request.Request.SearchCohortUsersRequest.SelectedEntitlements Added
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • List[].CreatedAt Changed (Breaking ⚠️)
      • -
      • List[].DeletedAt Changed (Breaking ⚠️)
      • -
      • List[].DepartmentSources[].Priority Added
      • -
      • List[].Profile Changed (Breaking ⚠️)
      • -
      • List[].UpdatedAt Changed (Breaking ⚠️)
      • -
      • UsersWithCoverage Added
      • -
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.ListSuggestions(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Entitlements[].RiskLevelValueId Added
    • -
    • LastGeneratedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.ListRuns(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CompletedAt Changed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.GetSuggestion(): response Changed (Breaking ⚠️) - -
      -
    • RoleMiningManagementSuggestion Removed (Breaking ⚠️)
    • -
    • Suggestion Added
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.GetRoleMiningConfig(): response Changed (Breaking ⚠️) - -
      -
    • Config Added
    • -
    • RoleMiningManagementConfig Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.GetLatestRun(): response Changed (Breaking ⚠️) - -
      -
    • RoleMiningManagementRun Removed (Breaking ⚠️)
    • -
    • Run Added
    • -
  • -
  • ConductoroneApi.RequestSchema.Update(): - -
      -
    • request.Request.RequestSchemaServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • RequestSchema Added
      • -
      • RequestSchema Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • RequestSchema Added
      • -
      • RequestSchema Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.RequestSchema.RemoveEntitlementBinding(): request.Request Changed (Breaking ⚠️) - -
      -
    • AppEntitlementRef Removed (Breaking ⚠️)
    • -
    • EntitlementRef Added
    • -
  • -
  • ConductoroneApi.RequestSchema.Get(): response Changed (Breaking ⚠️) - -
      -
    • RequestSchema Added
    • -
    • RequestSchema Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RequestSchema.FindBindingForAppEntitlement(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AppEntitlementRef Removed (Breaking ⚠️)
      • -
      • EntitlementRef Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AppEntitlementRef Removed (Breaking ⚠️)
      • -
      • EntitlementRef Added
      • -
    • -
  • -
  • ConductoroneApi.RequestSchema.CreateEntitlementBinding(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AppEntitlementRef Removed (Breaking ⚠️)
      • -
      • EntitlementRef Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AppEntitlementRef Removed (Breaking ⚠️)
      • -
      • EntitlementRef Added
      • -
    • -
  • -
  • ConductoroneApi.RequestSchema.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • FieldRelationships[].AtLeastOne Added
      • -
      • FieldRelationships[].AtLeastOne Removed (Breaking ⚠️)
      • -
      • FieldRelationships[].DependentOn Added
      • -
      • FieldRelationships[].DependentOn Removed (Breaking ⚠️)
      • -
      • FieldRelationships[].MutuallyExclusive Added
      • -
      • FieldRelationships[].MutuallyExclusive Removed (Breaking ⚠️)
      • -
      • FieldRelationships[].RequiredTogether Added
      • -
      • FieldRelationships[].RequiredTogether Removed (Breaking ⚠️)
      • -
      • Fields[].AdminConfig Added
      • -
      • Fields[].AdminProviderConfig Removed (Breaking ⚠️)
      • -
      • Fields[].BoolField Added
      • -
      • Fields[].BoolField Removed (Breaking ⚠️)
      • -
      • Fields[].FileField Added
      • -
      • Fields[].FileField Removed (Breaking ⚠️)
      • -
      • Fields[].FormStringField Removed (Breaking ⚠️)
      • -
      • Fields[].FormStringMapField Removed (Breaking ⚠️)
      • -
      • Fields[].Int64Field Added
      • -
      • Fields[].Int64Field Removed (Breaking ⚠️)
      • -
      • Fields[].Oauth2Field Added
      • -
      • Fields[].Oauth2Field Removed (Breaking ⚠️)
      • -
      • Fields[].ReadOnly Added
      • -
      • Fields[].SharedConfig Added
      • -
      • Fields[].SharedProviderConfig Removed (Breaking ⚠️)
      • -
      • Fields[].StringField Added
      • -
      • Fields[].StringMapField Added
      • -
      • Fields[].StringSliceField Added
      • -
      • Fields[].StringSliceField Removed (Breaking ⚠️)
      • -
      • Fields[].UserConfig Added
      • -
      • Fields[].UserProviderConfig Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • RequestSchema Added
      • -
      • RequestSchema Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Policies.Update(): - -
      -
    • request.Request.UpdatePolicyRequest Changed (Breaking ⚠️) - -
        -
      • Policy Added
      • -
      • Policy Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Policy Added
      • -
      • Policy Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Policies.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Annotations Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Accept Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Accept Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Action Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Action Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Approval Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Approval Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Form Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Form Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Provision Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Provision Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Reject Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Reject Removed (Breaking ⚠️)
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Wait Added
    • -
    • PolicySteps.Map<PolicySteps>.Steps[].Wait Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Policies.Get(): response Changed (Breaking ⚠️) - -
      -
    • Policy Added
    • -
    • Policy Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Policies.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Annotations Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Accept Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Accept Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Action Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Action Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Approval Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Approval Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Form Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Form Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Provision Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Provision Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Reject Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Reject Removed (Breaking ⚠️)
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Wait Added
      • -
      • PolicySteps.Map<PolicySteps>.Steps[].Wait Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Policy Added
      • -
      • Policy Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.LocalUserInvitation.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AcceptedAt Changed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • ExpiresAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RequestCatalogManagement.Update(): - -
      -
    • request.Request.RequestCatalogManagementServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • Catalog Added
      • -
      • ExpandMask Added
      • -
      • RequestCatalogExpandMask Removed (Breaking ⚠️)
      • -
      • RequestCatalog Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • RequestCatalogView Added
      • -
      • RequestCatalogView Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.LocalUserInvitation.Get(): response Changed (Breaking ⚠️) - -
      -
    • Invitation Added
    • -
    • LocalUserInvitation Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.LocalUserInvitation.Create(): response Changed (Breaking ⚠️) - -
      -
    • Invitation Added
    • -
    • LocalUserInvitation Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.LocalDirectoryConfig.Update(): - -
      -
    • request.Request.LocalDirectoryConfigServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • LocalDirectoryConfig Added
      • -
      • LocalDirectoryConfig Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • LocalDirectoryConfig Added
      • -
      • LocalDirectoryConfig Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.LocalDirectoryConfig.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • InvitationTtl Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.LocalDirectoryConfig.Get(): response Changed (Breaking ⚠️) - -
      -
    • LocalDirectoryConfig Added
    • -
    • LocalDirectoryConfig Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.LocalDirectoryConfig.Create(): - -
      -
    • request.Request.InvitationTtl Changed
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • LocalDirectoryConfig Added
      • -
      • LocalDirectoryConfig Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Roles.Update(): - -
      -
    • request.Request.UpdateRoleRequest Changed (Breaking ⚠️) - -
        -
      • Role Added
      • -
      • Role Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Role Added
      • -
      • Role Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Roles.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Roles.Get(): response Changed (Breaking ⚠️) - -
      -
    • Role Added
    • -
    • Role Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.PersonalClient.Update(): - -
      -
    • request.Request.PersonalClientServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • Client Added
      • -
      • PersonalClient Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Client Added
      • -
      • PersonalClient Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.PersonalClient.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ExpiresTime Changed (Breaking ⚠️)
    • -
    • LastUsedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.PersonalClient.Get(): response Changed (Breaking ⚠️) - -
      -
    • Client Added
    • -
    • PersonalClient Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.PersonalClient.Create(): - -
      -
    • request.Request.Expires Changed
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Client Added
      • -
      • PersonalClient Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Hooks.Update(): - -
      -
    • request.Request.HooksServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • Hook Added
      • -
      • Hook Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Hook Added
      • -
      • Hook Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Hooks.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • BuiltInPattern Removed (Breaking ⚠️)
    • -
    • BuiltinPattern Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Filter Added
    • -
    • Function Added
    • -
    • HookFilter Removed (Breaking ⚠️)
    • -
    • HookFunctionRef Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Hooks.Get(): response Changed (Breaking ⚠️) - -
      -
    • Hook Added
    • -
    • Hook Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Hooks.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • BuiltInPattern Removed (Breaking ⚠️)
      • -
      • BuiltinPattern Added
      • -
      • Filter Added
      • -
      • Function Added
      • -
      • HookFilter Removed (Breaking ⚠️)
      • -
      • HookFunctionRef Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Hook Added
      • -
      • Hook Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.FunctionsInvocationSearch.Search(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Input Changed (Breaking ⚠️)
    • -
    • Output Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.FunctionsInvocation.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • Input Changed (Breaking ⚠️)
    • -
    • Output Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.FunctionsInvocation.Get(): response Changed (Breaking ⚠️) - -
      -
    • FunctionInvocation Removed (Breaking ⚠️)
    • -
    • Invocation Added
    • -
  • -
  • ConductoroneApi.Functions.UpdateFunction(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Function Added
      • -
      • Function Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Function Added
      • -
      • Function Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Functions.Test(): response Changed (Breaking ⚠️) - -
      -
    • FunctionTestResult Removed (Breaking ⚠️)
    • -
    • Result Added
    • -
  • -
  • ConductoroneApi.Functions.ListTags(): response.Tags.Map<FunctionCommit>.CreatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppEntitlementUserBinding.SearchGrantFeed(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • After Changed
      • -
      • AppEntitlementUserBindingExpandHistoryMask Removed (Breaking ⚠️)
      • -
      • Before Changed
      • -
      • ExpandMask Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AppEntitlementUserBindingFeed Removed (Breaking ⚠️)
      • -
      • Feed Added
      • -
    • -
  • -
  • ConductoroneApi.Functions.ListFunctions(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • ProvisionedConcurrency Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Functions.ListCommits(): response.List[].CreatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.Functions.GetFunction(): response Changed (Breaking ⚠️) - -
      -
    • Function Added
    • -
    • Function Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Functions.GetCommitContent(): response Changed (Breaking ⚠️) - -
      -
    • Commit Added
    • -
    • FunctionCommit Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Functions.CreateFunction(): response Changed (Breaking ⚠️) - -
      -
    • Commit Added
    • -
    • FunctionCommit Removed (Breaking ⚠️)
    • -
    • Function Added
    • -
    • Function Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Functions.CreateFinalCommit(): response Changed (Breaking ⚠️) - -
      -
    • Commit Added
    • -
    • FunctionCommit Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.FindingSearch.Search(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AppResourceIds Added
      • -
      • AppResourceTraitIds Added
      • -
      • AppResourceTypeIds Added
      • -
      • AppUserTypes Added
      • -
      • ConnectorIds Added
      • -
      • CustomSubTypes Added
      • -
      • DecoyIds Added
      • -
      • FindingTypes[] Changed (Breaking ⚠️)
      • -
      • IncludeUnassigned Added
      • -
      • NhiTypes Added
      • -
      • OwnerIdentityUserIds Added
      • -
      • Refs Added
      • -
      • ScopeToAppOwner Added
      • -
      • SourceKinds Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) - -
        -
      • AppResourceTarget Added
      • -
      • AppUserTarget Added
      • -
      • AppUserTarget Removed (Breaking ⚠️)
      • -
      • AssignedOwner Added
      • -
      • ComputedOwner Added
      • -
      • ConnectorAnomalyDetectionDisabled Added
      • -
      • ConnectorTarget Added
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • CustomSubType Added
      • -
      • Custom Added
      • -
      • DecoyCredentialUsed Added
      • -
      • DecoyTarget Added
      • -
      • DedupKeyParts Added
      • -
      • Description Added
      • -
      • FindingOwnerRef1 Removed (Breaking ⚠️)
      • -
      • FindingOwnerRef Removed (Breaking ⚠️)
      • -
      • FindingRiskScore Removed (Breaking ⚠️)
      • -
      • FirstObservedAt Changed (Breaking ⚠️)
      • -
      • IdentityUserTarget Added
      • -
      • IdentityUserTarget Removed (Breaking ⚠️)
      • -
      • LastAppearedAt Added
      • -
      • LastObservedAt Changed (Breaking ⚠️)
      • -
      • NhiUnowned Added
      • -
      • ResolvedAt Changed (Breaking ⚠️)
      • -
      • RiskAcceptanceExpiresAt Changed (Breaking ⚠️)
      • -
      • RiskScore Added
      • -
      • ServiceAccountMisclassificationEvidence Added
      • -
      • ServiceAccountMisclassificationEvidence Removed (Breaking ⚠️)
      • -
      • ServiceAccountMisclassificationType Removed (Breaking ⚠️)
      • -
      • ServiceAccountMisclassification Added
      • -
      • ServiceAccountUnowned Added
      • -
      • SimilarUsernameMatchEvidence Added
      • -
      • SimilarUsernameMatchEvidence Removed (Breaking ⚠️)
      • -
      • SimilarUsernameMatchType Removed (Breaking ⚠️)
      • -
      • SimilarUsernameMatch Added
      • -
      • SnoozeUntil Changed (Breaking ⚠️)
      • -
      • SourceKind Added
      • -
      • TenantTarget Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule(): - -
      -
    • request.Request.UpdateFindingRoutingRuleRequest Changed (Breaking ⚠️) - -
        -
      • FindingRoutingRule Removed (Breaking ⚠️)
      • -
      • RoutingRule Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • FindingRoutingRule Removed (Breaking ⚠️)
      • -
      • RoutingRule Added
      • -
    • -
  • -
  • ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Action Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • FindingRoutingRuleAction Removed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule(): response Changed (Breaking ⚠️) - -
      -
    • FindingRoutingRule Removed (Breaking ⚠️)
    • -
    • RoutingRule Added
    • -
  • -
  • ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • FindingRoutingRule Removed (Breaking ⚠️)
      • -
      • RoutingRule Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • FindingRoutingRule Removed (Breaking ⚠️)
      • -
      • RoutingRule Added
      • -
    • -
  • -
  • ConductoroneApi.Finding.UpdateFindingState(): - -
      -
    • request.Request.UpdateFindingStateRequest Changed (Breaking ⚠️) - -
        -
      • AcceptRiskAction Removed (Breaking ⚠️)
      • -
      • AcceptRisk Added
      • -
      • ReopenAction Removed (Breaking ⚠️)
      • -
      • Reopen Added
      • -
      • ResolveAction Removed (Breaking ⚠️)
      • -
      • Resolve Added
      • -
      • SnoozeAction Removed (Breaking ⚠️)
      • -
      • Snooze Added
      • -
      • SuppressStateAction Removed (Breaking ⚠️)
      • -
      • Suppress Added
      • -
      • UnsuppressAction Removed (Breaking ⚠️)
      • -
      • Unsuppress Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Finding Added
      • -
      • Finding Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Finding.GetFinding(): response Changed (Breaking ⚠️) - -
      -
    • Finding Added
    • -
    • Finding Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Finding.CreateFindingTask(): response Changed (Breaking ⚠️) - -
      -
    • Finding Added
    • -
    • Finding Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.A2Ui.CreateSurfaceFeedback(): response Changed (Breaking ⚠️) - -
      -
    • A2UiSurfaceFeedback Removed (Breaking ⚠️)
    • -
    • Feedback Added
    • -
  • -
  • ConductoroneApi.A2Ui.ListSurfaceFeedback(): response.Feedback[].CreatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.A2Ui.ListSurfaces(): response.Surfaces[] Changed (Breaking ⚠️) - -
      -
    • Components[].ButtonComponent Removed (Breaking ⚠️)
    • -
    • Components[].Button Added
    • -
    • Components[].C1Chart Added
    • -
    • Components[].C1CodeBlockComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1CodeBlock Added
    • -
    • Components[].C1ConnectorConfigFormComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1ConnectorConfigForm Added
    • -
    • Components[].C1ConnectorSyncDetailComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1ConnectorSyncDetail Added
    • -
    • Components[].C1ConnectorSyncProgressComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1ConnectorSyncProgress Added
    • -
    • Components[].C1DurationPickerComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1DurationPicker Added
    • -
    • Components[].C1MsTeamsNotificationsComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1MsTeamsNotifications Added
    • -
    • Components[].C1OnboardingPlanComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1OnboardingPlan Added
    • -
    • Components[].C1OnboardingWelcomeComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1OnboardingWelcome Added
    • -
    • Components[].C1ResourcePickerComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1ResourcePicker Added
    • -
    • Components[].C1SlackNotificationsComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1SlackNotifications Added
    • -
    • Components[].C1StatusIndicatorComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1StatusIndicator Added
    • -
    • Components[].C1TodoListComponent Removed (Breaking ⚠️)
    • -
    • Components[].C1TodoList Added
    • -
    • Components[].CardComponent Removed (Breaking ⚠️)
    • -
    • Components[].Card Added
    • -
    • Components[].CheckBoxComponent Removed (Breaking ⚠️)
    • -
    • Components[].CheckBox Added
    • -
    • Components[].ChoicePickerComponent Removed (Breaking ⚠️)
    • -
    • Components[].ChoicePicker Added
    • -
    • Components[].ColumnComponent Removed (Breaking ⚠️)
    • -
    • Components[].Column Added
    • -
    • Components[].DateTimeInputComponent Removed (Breaking ⚠️)
    • -
    • Components[].DateTimeInput Added
    • -
    • Components[].DividerComponent Removed (Breaking ⚠️)
    • -
    • Components[].Divider Added
    • -
    • Components[].ProgressBarComponent Removed (Breaking ⚠️)
    • -
    • Components[].ProgressBar Added
    • -
    • Components[].RowComponent Removed (Breaking ⚠️)
    • -
    • Components[].Row Added
    • -
    • Components[].SliderComponent Removed (Breaking ⚠️)
    • -
    • Components[].Slider Added
    • -
    • Components[].TextComponent Removed (Breaking ⚠️)
    • -
    • Components[].TextFieldComponent Removed (Breaking ⚠️)
    • -
    • Components[].TextField Added
    • -
    • Components[].Text Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • Role Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Finding.BulkUpdateFindingState(): request.Request Changed (Breaking ⚠️) - -
      -
    • AcceptRisk Added
    • -
    • AssignOwner Added
    • -
    • BulkAcceptRiskAction Removed (Breaking ⚠️)
    • -
    • BulkAssignOwnerAction Removed (Breaking ⚠️)
    • -
    • BulkReopenAction Removed (Breaking ⚠️)
    • -
    • BulkSnoozeAction Removed (Breaking ⚠️)
    • -
    • BulkSuppressAction Removed (Breaking ⚠️)
    • -
    • BulkUnsuppressAction Removed (Breaking ⚠️)
    • -
    • FindingSearchRequest Removed (Breaking ⚠️)
    • -
    • Reopen Added
    • -
    • SearchRequest Added
    • -
    • Snooze Added
    • -
    • Suppress Added
    • -
    • Unsuppress Added
    • -
  • -
  • ConductoroneApi.AccessReview.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AccessReviewExpandMask Removed (Breaking ⚠️)
      • -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • CompletionDate Changed
      • -
      • ExpandMask Added
      • -
      • NotificationConfig Added
      • -
      • NotificationConfig Removed (Breaking ⚠️)
      • -
      • ScopeType.Enum(accessReviewScopeTypeByUsers) Added
      • -
      • ScopeV2 Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AccessReviewView Removed (Breaking ⚠️)
      • -
      • AccessReview Added
      • -
    • -
  • -
  • ConductoroneApi.AccessReview.Get(): response Changed (Breaking ⚠️) - -
      -
    • AccessReviewView Removed (Breaking ⚠️)
    • -
    • AccessReview Added
    • -
  • -
  • ConductoroneApi.AccessReview.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AccessReview Added
    • -
    • AccessReview Removed (Breaking ⚠️)
    • -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • -
  • -
  • ConductoroneApi.AccessReview.Update(): - -
      -
    • request.Request.AccessReviewServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • AccessReviewExpandMask Removed (Breaking ⚠️)
      • -
      • AccessReview Added
      • -
      • AccessReview Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AccessReviewView Removed (Breaking ⚠️)
      • -
      • AccessReview Added
      • -
    • -
  • -
  • ConductoroneApi.AccessReviewSetupEntitlement.GetCampaignScopeAndEntitlements(): response Changed (Breaking ⚠️) - -
      -
    • AccessReviewScopeV2 Removed (Breaking ⚠️)
    • -
    • List[].AccessReviewEntitlement Added
    • -
    • List[].AccessReviewSetupEntitlement Removed (Breaking ⚠️)
    • -
    • ScopeV2 Added
    • -
  • -
  • ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeAndEntitlements(): - -
      -
    • request.Request.AccessReviewSetupEntitlementAndScopeServiceSetRequest Changed (Breaking ⚠️) - -
        -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • AccessReviewSetupEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
      • ScopeV2 Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • List[].AccessReviewEntitlement Added
      • -
      • List[].AccessReviewSetupEntitlement Removed (Breaking ⚠️)
      • -
      • ScopeV2 Added
      • -
    • -
  • -
  • ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeByResourceType(): - -
      -
    • request.Request.AccessReviewSetScopeByResourceTypeRequest Changed (Breaking ⚠️) - -
        -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • ScopeV2 Added
      • -
    • -
  • ConductoroneApi.AccessReviewTemplate.Create():
    • request.Request Changed (Breaking ⚠️)
        -
      • AccessReviewColumnConfig Removed (Breaking ⚠️)
      • -
      • AccessReviewDuration Changed
      • -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • Annotations Added
      • -
      • ColumnConfig Added
      • -
      • NotificationConfig Added
      • -
      • NotificationConfig Removed (Breaking ⚠️)
      • -
      • RecurrenceRule Added
      • -
      • RecurrenceRule Removed (Breaking ⚠️)
      • -
      • ReviewSignatureConfig Removed (Breaking ⚠️)
      • -
      • ReviewerAttributeConfig Added
      • -
      • ScopeType.Enum(accessReviewScopeTypeByUsers) Added
      • -
      • Scope Added
      • -
      • SignatureConfig Added
      • +
      • ColumnConfig.OrderedColumns Added
      • +
      • RecurrenceRule.Frequency Changed (Breaking ⚠️)
    • -
    • response Changed (Breaking ⚠️) +
    • response.AccessReviewTemplate Changed
        -
      • AccessReviewTemplate Added
      • -
      • AccessReviewTemplate Removed (Breaking ⚠️)
      • +
      • ColumnConfig.OrderedColumns Added
      • +
      • MsTeamsChannel Added
      • +
      • RecurrenceRule.Frequency Changed
  • -
  • ConductoroneApi.AccessReviewTemplate.Get(): response Changed (Breaking ⚠️) - -
      -
    • AccessReviewTemplate Added
    • -
    • AccessReviewTemplate Removed (Breaking ⚠️)
    • -
  • ConductoroneApi.AccessReviewTemplate.Update():
      -
    • request.Request.AccessReviewTemplateServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • AccessReviewTemplate Added
      • -
      • AccessReviewTemplate Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • AccessReviewTemplate Added
      • -
      • AccessReviewTemplate Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.AccessReviewTemplateSetupEntitlement.GetScopeAndEntitlements(): response Changed (Breaking ⚠️) - -
      -
    • AccessReviewScopeV2 Removed (Breaking ⚠️)
    • -
    • List[].AccessReviewTemplateEntitlement Added
    • -
    • List[].AccessReviewTemplateSetupEntitlement Removed (Breaking ⚠️)
    • -
    • Scope Added
    • -
  • -
  • ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeAndEntitlements(): - -
      -
    • request.Request.AccessReviewTemplateSetupEntitlementServiceSetRequest Changed (Breaking ⚠️) - -
        -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • AccessReviewTemplateSetupEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
      • Scope Added
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.AccessReviewTemplateServiceUpdateRequest.AccessReviewTemplate Changed (Breaking ⚠️) + +
        +
      • ColumnConfig.OrderedColumns Added
      • +
      • MsTeamsChannel Added
      • +
      • RecurrenceRule.Frequency Changed (Breaking ⚠️)
      • +
    • +
    • response.AccessReviewTemplate Changed + +
        +
      • ColumnConfig.OrderedColumns Added
      • +
      • MsTeamsChannel Added
      • +
      • RecurrenceRule.Frequency Changed
      • +
    • +
  • +
  • ConductoroneApi.A2Ui.GetSurfaceProvenance(): Added
  • +
  • ConductoroneApi.AccessReviewReport.List(): Added
  • +
  • ConductoroneApi.AccessReviewActions.GenerateReport(): Added
  • +
  • ConductoroneApi.McpResource.Get(): Added
  • +
  • ConductoroneApi.McpResource.List(): Added
  • +
  • ConductoroneApi.McpResource.ListHistory(): Added
  • +
  • ConductoroneApi.McpResource.Search(): Added
  • +
  • ConductoroneApi.McpResource.Update(): Added
  • +
  • ConductoroneApi.McpAccessProfile.SearchAccessProfiles(): Added
  • +
  • ConductoroneApi.AppEntitlementSearch.SearchReachableResourcesForUser(): Added
  • +
  • ConductoroneApi.AppManagedState.Get(): Added
  • +
  • ConductoroneApi.AppManagedState.List(): Added
  • +
  • ConductoroneApi.AppManagedState.Promote(): Added
  • +
  • ConductoroneApi.SsoApplication.BatchDeleteSubjectCompatibility(): Added
  • +
  • ConductoroneApi.SsoApplication.BatchImportSubjectCompatibility(): Added
  • +
  • ConductoroneApi.SsoApplication.Create(): Added
  • +
  • ConductoroneApi.SsoApplication.CreateClient(): Added
  • +
  • ConductoroneApi.SsoApplication.Delete(): Added
  • +
  • ConductoroneApi.SsoApplication.DeleteClient(): Added
  • +
  • ConductoroneApi.SsoApplication.Get(): Added
  • +
  • ConductoroneApi.SsoApplication.List(): Added
  • +
  • ConductoroneApi.SsoApplication.ListClients(): Added
  • +
  • ConductoroneApi.SsoApplication.ListHistory(): Added
  • +
  • ConductoroneApi.SsoApplication.ParseSamlServiceProviderMetadata(): Added
  • +
  • ConductoroneApi.SsoApplication.RotateClientSecret(): Added
  • +
  • ConductoroneApi.SsoApplication.Search(): Added
  • +
  • ConductoroneApi.SsoApplication.Update(): Added
  • +
  • ConductoroneApi.SsoApplication.UpdateClient(): Added
  • +
  • ConductoroneApi.UiConversations.EnsureOnboardingSession(): Added
  • +
  • ConductoroneApi.FindingSettings.ListFindingSettings(): Added
  • +
  • ConductoroneApi.FindingSettings.UpdateFindingSettings(): Added
  • +
  • ConductoroneApi.AppCap.Delete(): Added
  • +
  • ConductoroneApi.AppCap.Get(): Added
  • +
  • ConductoroneApi.AppCap.List(): Added
  • +
  • ConductoroneApi.AppCap.ListHistory(): Added
  • +
  • ConductoroneApi.AppCap.SetLimit(): Added
  • +
  • ConductoroneApi.AppCap.Suspend(): Added
  • +
  • ConductoroneApi.AppCap.Unsuspend(): Added
  • +
  • ConductoroneApi.FundAssignment.ClearExtension(): Added
  • +
  • ConductoroneApi.FundAssignment.Delete(): Added
  • +
  • ConductoroneApi.FundAssignment.Get(): Added
  • +
  • ConductoroneApi.FundAssignment.GrantExtension(): Added
  • +
  • ConductoroneApi.FundAssignment.ListHistory(): Added
  • +
  • ConductoroneApi.FundAssignment.Search(): Added
  • +
  • ConductoroneApi.FundAssignment.SetLimit(): Added
  • +
  • ConductoroneApi.FundAssignment.Suspend(): Added
  • +
  • ConductoroneApi.FundAssignment.Unsuspend(): Added
  • +
  • ConductoroneApi.MyFundLimits.Delete(): Added
  • +
  • ConductoroneApi.MyFundLimits.List(): Added
  • +
  • ConductoroneApi.MyFundLimits.ListHistory(): Added
  • +
  • ConductoroneApi.MyFundLimits.Pause(): Added
  • +
  • ConductoroneApi.MyFundLimits.Resume(): Added
  • +
  • ConductoroneApi.MyFundLimits.SetLimit(): Added
  • +
  • ConductoroneApi.FundPolicy.Create(): Added
  • +
  • ConductoroneApi.FundPolicy.Delete(): Added
  • +
  • ConductoroneApi.FundPolicy.FreezeTenant(): Added
  • +
  • ConductoroneApi.FundPolicy.Get(): Added
  • +
  • ConductoroneApi.FundPolicy.ListHistory(): Added
  • +
  • ConductoroneApi.FundPolicy.SetOrgCeiling(): Added
  • +
  • ConductoroneApi.FundPolicy.UnfreezeTenant(): Added
  • +
  • ConductoroneApi.FundPolicy.Update(): Added
  • +
  • ConductoroneApi.FundRule.Create(): Added
  • +
  • ConductoroneApi.FundRule.Delete(): Added
  • +
  • ConductoroneApi.FundRule.Get(): Added
  • +
  • ConductoroneApi.FundRule.List(): Added
  • +
  • ConductoroneApi.FundRule.ListHistory(): Added
  • +
  • ConductoroneApi.FundRule.Search(): Added
  • +
  • ConductoroneApi.FundRule.Update(): Added
  • +
  • ConductoroneApi.GatewayKey.List(): Added
  • +
  • ConductoroneApi.GatewayKey.Mint(): Added
  • +
  • ConductoroneApi.GatewayKey.Revoke(): Added
  • +
  • ConductoroneApi.ProviderCredential.Clear(): Added
  • +
  • ConductoroneApi.ProviderCredential.Get(): Added
  • +
  • ConductoroneApi.ProviderCredential.Set(): Added
  • +
  • ConductoroneApi.Reporting.Delete(): Added
  • +
  • ConductoroneApi.Reporting.Get(): Added
  • +
  • ConductoroneApi.Reporting.GetRunProvenance(): Added
  • +
  • ConductoroneApi.Reporting.List(): Added
  • +
  • ConductoroneApi.Reporting.Run(): Added
  • +
  • ConductoroneApi.Reporting.Save(): Added
  • +
  • ConductoroneApi.Reporting.Update(): Added
  • +
  • ConductoroneApi.RoleMiningManagement.EvaluateEntitlementSelection(): Added
  • +
  • ConductoroneApi.SsoSettings.Get(): Added
  • +
  • ConductoroneApi.SsoSettings.ListHistory(): Added
  • +
  • ConductoroneApi.SsoSettings.Update(): Added
  • +
  • ConductoroneApi.TaskActions.RetryProvisioning(): Added
  • +
  • ConductoroneApi.A2Ui.ListSurfaces(): response.Surfaces[].Components[] Changed + +
      +
    • C1MetricCards Added
    • +
    • C1Table Added
    • +
  • +
  • ConductoroneApi.AccessReview.Create(): response.AccessReview.AccessReview.ColumnConfig.OrderedColumns Added
  • +
  • ConductoroneApi.AccessReview.Get(): response.AccessReview.AccessReview.ColumnConfig.OrderedColumns Added
  • +
  • ConductoroneApi.AccessReview.List(): response.List[].AccessReview.ColumnConfig.OrderedColumns Added
  • +
  • ConductoroneApi.AccessReview.Update():
      -
    • AccessReviewScopeV2 Removed (Breaking ⚠️)
    • -
    • List[].AccessReviewTemplateEntitlement Added
    • -
    • List[].AccessReviewTemplateSetupEntitlement Removed (Breaking ⚠️)
    • -
    • Scope Added
    • +
    • request.Request.AccessReviewServiceUpdateRequest.AccessReview.ColumnConfig.OrderedColumns Added
    • +
    • response.AccessReview.AccessReview.ColumnConfig.OrderedColumns Added
  • -
-
  • ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeByResourceType(): - -
      -
    • request.Request.AccessReviewTemplateSetScopeByResourceTypeRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.AccessReviewTemplate.Get(): response.AccessReviewTemplate Changed
        -
      • AccessReviewScopeV2 Removed (Breaking ⚠️)
      • -
      • Scope Added
      • +
      • ColumnConfig.OrderedColumns Added
      • +
      • MsTeamsChannel Added
      • +
      • RecurrenceRule.Frequency Changed
    • -
  • -
  • ConductoroneApi.AccessConflict.CreateMonitor(): - -
      -
    • request.Request Changed (Breaking ⚠️) +
    • ConductoroneApi.AppUser.List(): response.List[].AppUser Changed
        -
      • AccessConflictNotificationConfig Removed (Breaking ⚠️)
      • -
      • NotificationConfig Added
      • +
      • AgentStatus Added
      • +
      • NhiDetail Added
      • +
      • NhiType Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.AppUser.ListAppUsersForUser(): response.List[].AppUser Changed
        -
      • AccessConflictNotificationConfig Removed (Breaking ⚠️)
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • DeletedAt Changed (Breaking ⚠️)
      • -
      • NegateGroupB Added
      • -
      • NotificationConfig Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • +
      • AgentStatus Added
      • +
      • NhiDetail Added
      • +
      • NhiType Added
    • -
  • -
  • ConductoroneApi.AccessConflict.GetMonitor(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.AppUser.ListOwnedServiceAccounts(): response.List[].AppUser Changed
      -
    • AccessConflictNotificationConfig Removed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • NegateGroupB Added
    • -
    • NotificationConfig Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • AgentStatus Added
    • +
    • NhiDetail Added
    • +
    • NhiType Added
  • -
  • ConductoroneApi.AccessConflict.UpdateMonitor(): +
  • ConductoroneApi.AppUser.Search():
      -
    • request.Request.ConflictMonitorUpdateRequest Changed (Breaking ⚠️) +
    • request.Request Changed
        -
      • AccessConflictNotificationConfig Removed (Breaking ⚠️)
      • -
      • NegateGroupB Added
      • -
      • NotificationConfig Added
      • +
      • AgentStatuses Added
      • +
      • NhiTypes Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.List[].AppUser Changed
        -
      • AccessConflictNotificationConfig Removed (Breaking ⚠️)
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • DeletedAt Changed (Breaking ⚠️)
      • -
      • NegateGroupB Added
      • -
      • NotificationConfig Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • +
    • AgentStatus Added
    • +
    • NhiDetail Added
    • +
    • NhiType Added
  • -
  • ConductoroneApi.AppEntitlementMonitorBinding.CreateAppEntitlementMonitorBinding(): response Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppEntitlementMonitorBinding.GetAppEntitlementMonitorBinding(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.AppUser.Update(): response.AppUserView.AppUser Changed
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • AgentStatus Added
    • +
    • NhiDetail Added
    • +
    • NhiType Added
  • ConductoroneApi.Apps.Create():
      -
    • request.Request.Annotations Added
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • App Added
      • -
      • App Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Apps.Get(): response Changed (Breaking ⚠️) - -
      -
    • App Added
    • -
    • App Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Apps.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Annotations Added
    • -
    • AppOwners[].CreatedAt Changed (Breaking ⚠️)
    • -
    • AppOwners[].DeletedAt Changed (Breaking ⚠️)
    • -
    • AppOwners[].DepartmentSources[].Priority Added
    • -
    • AppOwners[].Profile Changed (Breaking ⚠️)
    • -
    • AppOwners[].UpdatedAt Changed (Breaking ⚠️)
    • -
    • AppUserMapper Added
    • -
    • AppUserMapper Removed (Breaking ⚠️)
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • RevokeGrantSources Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • request.Request.MatchBatonRef Added
    • +
    • response.App.MatchBatonRef Added
  • +
  • ConductoroneApi.Apps.Get(): response.App.MatchBatonRef Added
  • +
  • ConductoroneApi.Apps.List(): response.List[].MatchBatonRef Added
  • ConductoroneApi.Apps.Update():
      -
    • request.Request.UpdateAppRequest Changed (Breaking ⚠️) - -
        -
      • App Added
      • -
      • App Removed (Breaking ⚠️)
      • +
      • request.Request.UpdateAppRequest.App.MatchBatonRef Added
      • +
      • response.App.MatchBatonRef Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.McpTool.Get(): response.Tool Changed
        -
      • App Added
      • -
      • App Removed (Breaking ⚠️)
      • +
      • RequestableViaToolset Added
      • +
      • Requestable Added
    • -
  • -
  • ConductoroneApi.Connector.Create(): - -
      -
    • request.Request.ConnectorServiceCreateRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.McpTool.List(): response.Tools[] Changed
        -
      • Config Changed
      • -
      • ConnectorExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • RequestableViaToolset Added
      • +
      • Requestable Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.McpTool.ListHistory(): response.List[].Snapshot Changed
        -
      • ConnectorView Added
      • -
      • ConnectorView Removed (Breaking ⚠️)
      • -
    • +
    • RequestableViaToolset Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.CreateDelegated(): +
  • ConductoroneApi.McpTool.Search():
      -
    • request.Request.ConnectorServiceCreateDelegatedRequest Changed (Breaking ⚠️) +
    • request.Request.McpToolServiceSearchRequest.IncludeRequestable Added
    • +
    • response.List[] Changed
        -
      • AppManagedStateBindingRef Added
      • -
      • AppManagedStateBindingRef Removed (Breaking ⚠️)
      • -
      • ConnectorExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • RequestableViaToolset Added
      • +
      • Requestable Added
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • ConnectorView Added
      • -
      • ConnectorView Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Connector.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.McpTool.Update(): response.Tool Changed
      -
    • ConnectorView Added
    • -
    • ConnectorView Removed (Breaking ⚠️)
    • +
    • RequestableViaToolset Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.GetCredentials(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.McpAccessProfile.Create(): response.Profile Changed
      -
    • ConnectorCredential Removed (Breaking ⚠️)
    • -
    • Credential Added
    • +
    • ConnectorDisplayName Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.List(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.McpAccessProfile.Get(): response.Profile Changed
      -
    • Connector Added
    • -
    • Connector Removed (Breaking ⚠️)
    • +
    • ConnectorDisplayName Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.RotateCredential(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.McpAccessProfile.GetByAppEntitlementId(): response.Profile Changed
      -
    • ConnectorCredential Removed (Breaking ⚠️)
    • -
    • Credential Added
    • +
    • ConnectorDisplayName Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.Update(): - -
      -
    • request.Request.ConnectorServiceUpdateRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.McpAccessProfile.List(): response.Profiles[] Changed
        -
      • ConnectorExpandMask Removed (Breaking ⚠️)
      • -
      • Connector Added
      • -
      • Connector Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • ConnectorDisplayName Added
      • +
      • Requestable Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.McpAccessProfile.Update(): response.Profile Changed
        -
      • ConnectorView Added
      • -
      • ConnectorView Removed (Breaking ⚠️)
      • -
    • +
    • ConnectorDisplayName Added
    • +
    • Requestable Added
  • -
  • ConductoroneApi.Connector.UpdateConnectorSchedule(): - -
      -
    • request.Request.UpdateConnectorScheduleRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools(): response.AccessProfilesForTools[].AccessProfiles[] Changed
        -
      • ConnectorScheduleCron Removed (Breaking ⚠️)
      • -
      • Cron Added
      • +
      • ConnectorDisplayName Added
      • +
      • Requestable Added
    • -
  • -
  • ConductoroneApi.Connector.UpdateDelegated(): - -
      -
    • request.Request.ConnectorServiceUpdateDelegatedRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.AppEntitlements.Create():
        -
      • ConnectorExpandMask Removed (Breaking ⚠️)
      • -
      • Connector Added
      • -
      • Connector Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.CreateAppEntitlementRequest.ProvisionPolicy Changed
        -
      • ConnectorView Added
      • -
      • ConnectorView Removed (Breaking ⚠️)
      • +
      • DevicePlacement Added
      • +
      • MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • -
  • ConductoroneApi.AppAccessRequestsDefaults.CancelAppAccessRequestsDefaults(): response.DurationGrant Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppAccessRequestsDefaults.CreateAppAccessRequestsDefaults(): +
  • ConductoroneApi.AppEntitlements.Get(): response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlements.List():
      -
    • request.Request.AppAccessRequestDefaults.DurationGrant Changed
    • -
    • response.DurationGrant Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppAccessRequestsDefaults.GetAppAccessRequestsDefaults(): response.DurationGrant Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppUser.List(): response.List[] Changed (Breaking ⚠️) +
  • request.Request Changed
      -
    • AppUser Added
    • -
    • AppUser Removed (Breaking ⚠️)
    • +
    • AppUserId Added
    • +
    • Q Added
  • -
  • ConductoroneApi.AppUser.ListAppUserCredentials(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • EncryptedData Added
    • -
    • EncryptedData Removed (Breaking ⚠️)
    • -
    • ExpiresAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • -
  • ConductoroneApi.AppUser.ListAppUsersForUser(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.AppEntitlements.ListForAppResource(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlements.ListForAppUser(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlements.ListUsers(): response.List[].AppUser.AppUser Changed
      -
    • AppUser Added
    • -
    • AppUser Removed (Breaking ⚠️)
    • +
    • AgentStatus Added
    • +
    • NhiDetail Added
    • +
    • NhiType Added
  • -
  • ConductoroneApi.AppUser.Search(): - -
      -
    • request.Request Changed (Breaking ⚠️) +
    • ConductoroneApi.AppEntitlements.Update():
        -
      • AppIds Added
      • -
      • AppUserExpandMask Removed (Breaking ⚠️)
      • -
      • ExcludeDeletedApps Added
      • -
      • ExpandMask Added
      • -
      • SortBy Added
      • -
      • WithOpenFindings Added
      • -
      • WithoutResponsibleParty Added
      • -
    • -
    • response.List[] Changed (Breaking ⚠️) +
    • request.Request.UpdateAppEntitlementRequest.Entitlement.DeprovisionerPolicy Changed
        -
      • AppUser Added
      • -
      • AppUser Removed (Breaking ⚠️)
      • +
      • DevicePlacement Added
      • +
      • MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • -
  • ConductoroneApi.AppUser.Update(): +
  • ConductoroneApi.AppEntitlementSearch.Search(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired(): response.List[].AppUser Changed
      -
    • request.Request.AppUserServiceUpdateRequest Changed (Breaking ⚠️) - -
        -
      • AppUserExpandMask Removed (Breaking ⚠️)
      • -
      • AppUser Added
      • -
      • AppUser Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • AgentStatus Added
      • +
      • NhiDetail Added
      • +
      • NhiType Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.AppEntitlementSearch.SearchGrants(): response.List[] Changed
        -
      • AppUserView Added
      • -
      • AppUserView Removed (Breaking ⚠️)
      • +
      • AppEntitlementUserBinding.AppUser.AppUser.AgentStatus Added
      • +
      • AppEntitlementUserBinding.AppUser.AppUser.NhiDetail Added
      • +
      • AppEntitlementUserBinding.AppUser.AppUser.NhiType Added
      • +
      • Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
    • -
  • -
  • ConductoroneApi.AppEntitlements.Create(): +
  • ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants(): response.List[].History.Id Added
  • +
  • ConductoroneApi.McpServer.Get(): response.McpServer.EndpointUrlLocked Added
  • +
  • ConductoroneApi.McpServer.GetCatalog(): response.CatalogEntry Changed
      -
    • request.Request.CreateAppEntitlementRequest Changed (Breaking ⚠️) - -
        -
      • Annotations Added
      • -
      • AppEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • DurationGrant Changed
      • -
      • ExpandMask Added
      • -
      • ProvisionPolicy Added
      • -
      • ProvisionPolicy Removed (Breaking ⚠️)
      • +
      • AuthModes[].ClientIdMode Added
      • +
      • AuthModes[].OptionalScopes Added
      • +
      • DefaultToolPrefix Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.McpServer.List(): response.List[].EndpointUrlLocked Added
    • +
    • ConductoroneApi.McpServer.ListCatalog(): response.List[] Changed
        -
      • AppEntitlementView Added
      • -
      • AppEntitlementView Removed (Breaking ⚠️)
      • -
    • +
    • AuthModes[].ClientIdMode Added
    • +
    • AuthModes[].OptionalScopes Added
    • +
    • DefaultToolPrefix Added
  • -
  • ConductoroneApi.AppEntitlements.CreateAutomation(): +
  • ConductoroneApi.McpServer.Register():
      -
    • request.Request.CreateAutomationRequest Changed (Breaking ⚠️) - -
        -
      • AppEntitlementAutomation Removed (Breaking ⚠️)
      • -
      • Automation Added
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.McpServerServiceRegisterRequest.AccessProfileIds Added
    • +
    • response Changed
        -
      • AppEntitlementAutomation Removed (Breaking ⚠️)
      • -
      • Automation Added
      • +
      • AccessProfilesAttached Added
      • +
      • McpServer.EndpointUrlLocked Added
  • -
  • ConductoroneApi.AppEntitlements.Get(): response Changed (Breaking ⚠️) - -
      -
    • AppEntitlementView Added
    • -
    • AppEntitlementView Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AppEntitlements.GetAutomation(): response.AppEntitlementAutomation Changed (Breaking ⚠️) +
  • ConductoroneApi.McpServer.SearchWithToolCount(): response.List[].McpServer.EndpointUrlLocked Added
  • +
  • ConductoroneApi.McpServer.Update(): response.McpServer.EndpointUrlLocked Added
  • +
  • ConductoroneApi.McpServer.UpdateCredentials(): response.McpServer.EndpointUrlLocked Added
  • +
  • ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType():
      -
    • AppEntitlementAutomationLastRunStatus Removed (Breaking ⚠️)
    • -
    • AppEntitlementAutomationRuleBasic Removed (Breaking ⚠️)
    • -
    • AppEntitlementAutomationRuleCel Removed (Breaking ⚠️)
    • -
    • AppEntitlementAutomationRuleEntitlement Removed (Breaking ⚠️)
    • -
    • AppEntitlementAutomationRuleNone Removed (Breaking ⚠️)
    • -
    • Basic Added
    • -
    • Cel Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • Entitlements Added
    • -
    • LastRunStatus Added
    • -
    • None Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(clawAgent) Added
  • -
  • ConductoroneApi.AppEntitlements.List(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.Auth.Introspect(): response.DisabledModules Added
  • +
  • ConductoroneApi.Automation.CreateAutomation():
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • +
    • request.Request.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
    • +
    • response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • -
  • ConductoroneApi.AppEntitlements.ListAutomationExclusions(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.Automation.GetAutomation(): response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • +
  • ConductoroneApi.Automation.ListAutomations(): response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • +
  • ConductoroneApi.Automation.UpdateAutomation():
      -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • +
    • request.Request.UpdateAutomationRequest.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
    • +
    • response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • -
  • ConductoroneApi.AppEntitlements.ListForAppResource(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.RequestCatalogManagement.Create():
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • -
  • -
  • ConductoroneApi.AppEntitlements.ListForAppUser(): response.List[] Changed (Breaking ⚠️) +
  • request.Request.Type Added
  • +
  • response.RequestCatalogView.RequestCatalog Changed
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • +
    • AccessEntitlements[].DeprovisionerPolicy.DevicePlacement Added
    • +
    • Type Added
  • -
  • ConductoroneApi.AppEntitlements.ListUsers(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppEntitlementId Added
    • -
    • AppEntitlementUserBindingCreatedAt Changed (Breaking ⚠️)
    • -
    • AppEntitlementUserBindingDeprovisionAt Changed (Breaking ⚠️)
    • -
    • AppId Added
    • -
    • AppUserId Added
    • -
    • AppUserView Removed (Breaking ⚠️)
    • -
    • AppUser Added
  • -
  • ConductoroneApi.AppEntitlements.Update(): +
  • ConductoroneApi.RequestCatalogManagement.Get(): response.RequestCatalogView.RequestCatalog Changed
      -
    • request.Request.UpdateAppEntitlementRequest Changed (Breaking ⚠️) - -
        -
      • AppEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • AppEntitlement Removed (Breaking ⚠️)
      • -
      • Entitlement Added
      • -
      • ExpandMask Added
      • +
      • AccessEntitlements[].DeprovisionerPolicy.DevicePlacement Added
      • +
      • Type Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.RequestCatalogManagement.List(): response.List[].RequestCatalog Changed
        -
      • AppEntitlementView Added
      • -
      • AppEntitlementView Removed (Breaking ⚠️)
      • +
      • AccessEntitlements[].DeprovisionerPolicy.DevicePlacement Added
      • +
      • Type Added
    • -
  • -
  • ConductoroneApi.AppEntitlements.UpdateAutomation(): +
  • ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.RequestCatalogManagement.Update():
      -
    • request.Request.AppEntitlementServiceUpdateAutomationRequest Changed (Breaking ⚠️) +
    • request.Request.RequestCatalogManagementServiceUpdateRequest.Catalog.AccessEntitlements[].DeprovisionerPolicy Changed
        -
      • AppEntitlementAutomationRuleBasic Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleCel Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleEntitlement Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleNone Removed (Breaking ⚠️)
      • -
      • Basic Added
      • -
      • Cel Added
      • -
      • Entitlements Added
      • -
      • None Added
      • +
      • DevicePlacement Added
      • +
      • MultiStep.ProvisionSteps[].DevicePlacement Added
    • -
    • response.AppEntitlementAutomation Changed (Breaking ⚠️) +
    • response.RequestCatalogView.RequestCatalog Changed
        -
      • AppEntitlementAutomationLastRunStatus Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleBasic Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleCel Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleEntitlement Removed (Breaking ⚠️)
      • -
      • AppEntitlementAutomationRuleNone Removed (Breaking ⚠️)
      • -
      • Basic Added
      • -
      • Cel Added
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • DeletedAt Changed (Breaking ⚠️)
      • -
      • Entitlements Added
      • -
      • LastRunStatus Added
      • -
      • None Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • +
      • AccessEntitlements[].DeprovisionerPolicy.DevicePlacement Added
      • +
      • Type Added
  • -
  • ConductoroneApi.AppEntitlementSearch.Search(): +
  • ConductoroneApi.ConnectorCatalog.ConfigurationSchema(): response.FormSchema.Fields[].StringField Changed
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • AppEntitlementExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
      • RequestSchemaIds Added
      • +
      • DateField Added
      • +
      • PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PickerField.C1UserPicker.UserIds Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.Finding.BulkCreateFindingTasks():
        -
      • Facets Added
      • -
      • Facets Removed (Breaking ⚠️)
      • -
      • List[].ActorObjectPermissions Removed (Breaking ⚠️)
      • -
      • List[].AppEntitlement Added
      • -
      • List[].AppEntitlement Removed (Breaking ⚠️)
      • -
      • List[].ObjectPermissions Added
      • -
    • -
  • -
  • ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser(): response.List[] Changed (Breaking ⚠️) +
  • request.Request.SearchRequest.FindingTypes[] Changed
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • +
    • Enum(findingTypeConnectorSyncFailing) Added
    • +
    • Enum(findingTypeCredentialExpiring) Added
    • +
    • Enum(findingTypeCredentialPubliclyExposed) Added
    • +
    • Enum(findingTypeDeactivatedOwner) Added
    • +
    • Enum(findingTypeDecoyPubliclyExposed) Added
    • +
    • Enum(findingTypeUnusedSecret) Added
    • +
  • -
  • ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.Finding.BulkUpdateFindingState(): request.Request Changed
      -
    • AppUser Added
    • -
    • AppUser Removed (Breaking ⚠️)
    • -
    • Discovered Changed (Breaking ⚠️)
    • -
    • Expired Changed (Breaking ⚠️)
    • -
    • GrantReasons[].CreatedAt Changed (Breaking ⚠️)
    • -
    • GrantReasons[].DeletedAt Changed (Breaking ⚠️)
    • -
    • GrantReasons[].ReasonExpiresAt Changed (Breaking ⚠️)
    • -
    • GrantReasons[].UpdatedAt Changed (Breaking ⚠️)
    • -
    • User Added
    • -
    • User Removed (Breaking ⚠️)
    • +
    • Reprocess Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeConnectorSyncFailing) Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeCredentialExpiring) Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeCredentialPubliclyExposed) Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeDeactivatedOwner) Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeDecoyPubliclyExposed) Added
    • +
    • SearchRequest.FindingTypes[].Enum(findingTypeUnusedSecret) Added
  • -
  • ConductoroneApi.AppEntitlementSearch.SearchGrants(): +
  • ConductoroneApi.Finding.CreateFinding(): response.Finding Changed
      -
    • request.Request Changed (Breaking ⚠️) +
    • Annotations Added
    • +
    • ConnectorSyncFailingEvidence Added
    • +
    • ConnectorSyncFailing Added
    • +
    • CredentialExpiringEvidence Added
    • +
    • CredentialExpiring Added
    • +
    • CredentialPubliclyExposedEvidence Added
    • +
    • CredentialPubliclyExposed Added
    • +
    • DeactivatedOwnerEvidence Added
    • +
    • DeactivatedOwner Added
    • +
    • DecoyPubliclyExposedEvidence Added
    • +
    • DecoyPubliclyExposed Added
    • +
    • UnusedSecretEvidence Added
    • +
    • UnusedSecret Added
    • +
  • +
  • ConductoroneApi.Finding.CreateFindingTask(): response.Finding Changed
      -
    • AppEntitlementExpandMask Removed (Breaking ⚠️)
    • -
    • ExpandMask Added
    • -
  • -
  • response.List[] Changed (Breaking ⚠️) +
  • Annotations Added
  • +
  • ConnectorSyncFailingEvidence Added
  • +
  • ConnectorSyncFailing Added
  • +
  • CredentialExpiringEvidence Added
  • +
  • CredentialExpiring Added
  • +
  • CredentialPubliclyExposedEvidence Added
  • +
  • CredentialPubliclyExposed Added
  • +
  • DeactivatedOwnerEvidence Added
  • +
  • DeactivatedOwner Added
  • +
  • DecoyPubliclyExposedEvidence Added
  • +
  • DecoyPubliclyExposed Added
  • +
  • UnusedSecretEvidence Added
  • +
  • UnusedSecret Added
  • + +
  • ConductoroneApi.Finding.GetFinding(): response.Finding Changed
      -
    • AppEntitlementUserBinding Added
    • -
    • AppEntitlementUserView Removed (Breaking ⚠️)
    • -
    • AppEntitlementView Removed (Breaking ⚠️)
    • -
    • Entitlement Added
    • -
  • - -
  • ConductoroneApi.Finding.BulkCreateFindingTasks(): request.Request Changed (Breaking ⚠️) +
  • Annotations Added
  • +
  • ConnectorSyncFailingEvidence Added
  • +
  • ConnectorSyncFailing Added
  • +
  • CredentialExpiringEvidence Added
  • +
  • CredentialExpiring Added
  • +
  • CredentialPubliclyExposedEvidence Added
  • +
  • CredentialPubliclyExposed Added
  • +
  • DeactivatedOwnerEvidence Added
  • +
  • DeactivatedOwner Added
  • +
  • DecoyPubliclyExposedEvidence Added
  • +
  • DecoyPubliclyExposed Added
  • +
  • UnusedSecretEvidence Added
  • +
  • UnusedSecret Added
  • + +
  • ConductoroneApi.Finding.UpdateFindingState(): response.Finding Changed
      -
    • FindingSearchRequest Removed (Breaking ⚠️)
    • -
    • SearchRequest Added
    • +
    • Annotations Added
    • +
    • ConnectorSyncFailingEvidence Added
    • +
    • ConnectorSyncFailing Added
    • +
    • CredentialExpiringEvidence Added
    • +
    • CredentialExpiring Added
    • +
    • CredentialPubliclyExposedEvidence Added
    • +
    • CredentialPubliclyExposed Added
    • +
    • DeactivatedOwnerEvidence Added
    • +
    • DeactivatedOwner Added
    • +
    • DecoyPubliclyExposedEvidence Added
    • +
    • DecoyPubliclyExposed Added
    • +
    • UnusedSecretEvidence Added
    • +
    • UnusedSecret Added
  • -
  • ConductoroneApi.Directory.Update(): +
  • ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule():
      -
    • request.Request.DirectoryServiceUpdateRequest Changed (Breaking ⚠️) +
    • request.Request.RoutingRule Changed
        -
      • All Added
      • -
      • CelExpression Added
      • -
      • DirectoryAccountFilterAll Removed (Breaking ⚠️)
      • -
      • DirectoryAccountFilterCel Removed (Breaking ⚠️)
      • -
      • DirectoryExpandMask Removed (Breaking ⚠️)
      • -
      • DirectoryMergeConfig Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
      • MergeConfig Added
      • +
      • Dispatchers Added
      • +
      • FindingType Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.RoutingRule Changed
        -
      • DirectoryView Added
      • -
      • DirectoryView Removed (Breaking ⚠️)
      • -
    • +
    • Dispatchers Added
    • +
    • FindingType Added
  • -
  • ConductoroneApi.Directory.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • Directory Added
    • -
    • Directory Removed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants(): - -
      -
    • request.Request Changed (Breaking ⚠️) +
    • ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule(): response.RoutingRule Changed
        -
      • AppEntitlementUserBindingExpandHistoryMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • Dispatchers Added
      • +
      • FindingType Added
    • -
    • response.List[] Changed (Breaking ⚠️) +
    • ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules(): response.List[] Changed
        -
      • AppEntitlementUserBindingHistory Removed (Breaking ⚠️)
      • -
      • History Added
      • -
    • +
    • Dispatchers Added
    • +
    • FindingType Added
  • -
  • ConductoroneApi.AppEntitlementUserBinding.UpdateGrantDuration(): +
  • ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule():
      -
    • request.Request.UpdateGrantDurationRequest.NewDeprovisionAt Changed
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.UpdateFindingRoutingRuleRequest.RoutingRule Changed
        -
      • AppEntitlementUserBinding Removed (Breaking ⚠️)
      • -
      • Binding Added
      • -
    • +
    • Dispatchers Added
    • +
    • FindingType Added
  • -
  • ConductoroneApi.AppEntitlementOwners.List(): response.List[] Changed (Breaking ⚠️) +
  • response.RoutingRule Changed
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • DepartmentSources[].Priority Added
    • -
    • Profile Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • Dispatchers Added
    • +
    • FindingType Added
  • -
  • ConductoroneApi.AppOwners.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • DepartmentSources[].Priority Added
    • -
    • Profile Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppReport.List(): response.List[].CreatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType(): +
  • ConductoroneApi.FindingSearch.Search():
      -
    • request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(sessionPolicy) Added
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.FindingTypes[] Changed
        -
      • AppResourceType Added
      • -
      • AppResourceType Removed (Breaking ⚠️)
      • +
      • Enum(findingTypeConnectorSyncFailing) Added
      • +
      • Enum(findingTypeCredentialExpiring) Added
      • +
      • Enum(findingTypeCredentialPubliclyExposed) Added
      • +
      • Enum(findingTypeDeactivatedOwner) Added
      • +
      • Enum(findingTypeDecoyPubliclyExposed) Added
      • +
      • Enum(findingTypeUnusedSecret) Added
    • -
  • -
  • ConductoroneApi.AppResourceType.Get(): response Changed (Breaking ⚠️) +
  • response.List[] Changed
      -
    • AppResourceTypeView Added
    • -
    • AppResourceTypeView Removed (Breaking ⚠️)
    • +
    • Annotations Added
    • +
    • ConnectorSyncFailingEvidence Added
    • +
    • ConnectorSyncFailing Added
    • +
    • CredentialExpiringEvidence Added
    • +
    • CredentialExpiring Added
    • +
    • CredentialPubliclyExposedEvidence Added
    • +
    • CredentialPubliclyExposed Added
    • +
    • DeactivatedOwnerEvidence Added
    • +
    • DeactivatedOwner Added
    • +
    • DecoyPubliclyExposedEvidence Added
    • +
    • DecoyPubliclyExposed Added
    • +
    • UnusedSecretEvidence Added
    • +
    • UnusedSecret Added
  • -
  • ConductoroneApi.AppResourceType.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AppResourceType Added
    • -
    • AppResourceType Removed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppResourceType.UpdateManuallyManagedResourceType(): +
  • ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule():
      -
    • request.Request.UpdateManuallyManagedResourceTypeRequest Changed (Breaking ⚠️) - -
        -
      • AppResourceType Added
      • -
      • AppResourceType Removed (Breaking ⚠️)
      • +
      • request.Request.TransformationRule.FindingType Added
      • +
      • response.TransformationRule.FindingType Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule(): response.TransformationRule.FindingType Added
    • +
    • ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules(): response.List[].FindingType Added
    • +
    • ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule():
        -
      • AppResourceType Added
      • -
      • AppResourceType Removed (Breaking ⚠️)
      • +
      • request.Request.UpdateFindingTransformationRuleRequest.TransformationRule.FindingType Added
      • +
      • response.TransformationRule.FindingType Added
    • -
  • -
  • ConductoroneApi.AppResource.CreateManuallyManagedAppResource(): - -
      -
    • request.Request.CreateManuallyManagedAppResourceRequest.Annotations Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.Functions.CreateFunction(): response.Function Changed
        -
      • AppResource Added
      • -
      • AppResource Removed (Breaking ⚠️)
      • -
    • +
    • HookRefs Added
    • +
    • WorkflowTemplateRefs Added
  • -
  • ConductoroneApi.AppResource.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.Functions.GetFunction(): response.Function Changed
      -
    • AppResourceView Added
    • -
    • AppResourceView Removed (Breaking ⚠️)
    • +
    • HookRefs Added
    • +
    • WorkflowTemplateRefs Added
  • -
  • ConductoroneApi.AppResource.List(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.Functions.ListFunctions(): response.List[] Changed
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppResource Added
    • -
    • AppResource Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • +
    • HookRefs Added
    • +
    • WorkflowTemplateRefs Added
  • -
  • ConductoroneApi.AppResource.Update(): - -
      -
    • request.Request.AppResourceServiceUpdateRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.Functions.UpdateFunction():
        -
      • AppResourceExpandMask Removed (Breaking ⚠️)
      • -
      • AppResource Added
      • -
      • AppResource Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request Changed
        -
      • AppResourceView Added
      • -
      • AppResourceView Removed (Breaking ⚠️)
      • -
    • +
    • CommitMessage Added
    • +
    • Content Added
  • -
  • ConductoroneApi.AppResourceOwners.List(): response.List[] Changed (Breaking ⚠️) +
  • response Changed
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • DepartmentSources[].Priority Added
    • -
    • Profile Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • Commit Added
    • +
    • Function.HookRefs Added
    • +
    • Function.WorkflowTemplateRefs Added
  • -
  • ConductoroneApi.AppUsageControls.Get(): response Changed (Breaking ⚠️) - -
      -
    • AppUsageControls Added
    • -
    • AppUsageControls Removed (Breaking ⚠️)
  • -
  • ConductoroneApi.AppUsageControls.Update(): - -
      -
    • request.Request.UpdateAppUsageControlsRequest Changed (Breaking ⚠️) +
    • ConductoroneApi.Hooks.Create():
        -
      • AppUsageControls Added
      • -
      • AppUsageControls Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request Changed
        -
      • AppUsageControls Added
      • -
      • AppUsageControls Removed (Breaking ⚠️)
      • -
    • +
    • BuiltinPattern.BlockOutput Added
    • +
    • BuiltinPattern.BlockToolCall Added
    • +
    • BuiltinPattern.EncodedContentGuard Added
    • +
    • BuiltinPattern.LinkFilter Added
    • +
    • BuiltinPattern.PreToolBlock Added
    • +
    • BuiltinPattern.PromptInjectionScan Added
    • +
    • BuiltinPattern.SecretsMasking Added
    • +
    • Event.Enum(hookEventTypePreOutput) Added
    • +
    • JsonPatch Added
    • +
    • ManagedByGuardrails Added
    • +
  • +
  • response.Hook Changed + +
      +
    • BuiltinPattern.BlockOutput Added
    • +
    • BuiltinPattern.BlockToolCall Added
    • +
    • BuiltinPattern.EncodedContentGuard Added
    • +
    • BuiltinPattern.LinkFilter Added
    • +
    • BuiltinPattern.PreToolBlock Added
    • +
    • BuiltinPattern.PromptInjectionScan Added
    • +
    • BuiltinPattern.SecretsMasking Added
    • +
    • Event.Enum(hookEventTypePreOutput) Added
    • +
    • JsonPatch Added
    • +
    • ManagedByGuardrails Added
    • +
  • + +
  • ConductoroneApi.Hooks.Get(): response.Hook Changed + +
      +
    • BuiltinPattern.BlockOutput Added
    • +
    • BuiltinPattern.BlockToolCall Added
    • +
    • BuiltinPattern.EncodedContentGuard Added
    • +
    • BuiltinPattern.LinkFilter Added
    • +
    • BuiltinPattern.PreToolBlock Added
    • +
    • BuiltinPattern.PromptInjectionScan Added
    • +
    • BuiltinPattern.SecretsMasking Added
    • +
    • Event.Enum(hookEventTypePreOutput) Added
    • +
    • JsonPatch Added
    • +
    • ManagedByGuardrails Added
    • +
  • +
  • ConductoroneApi.Hooks.List(): response.List[] Changed + +
      +
    • BuiltinPattern.BlockOutput Added
    • +
    • BuiltinPattern.BlockToolCall Added
    • +
    • BuiltinPattern.EncodedContentGuard Added
    • +
    • BuiltinPattern.LinkFilter Added
    • +
    • BuiltinPattern.PreToolBlock Added
    • +
    • BuiltinPattern.PromptInjectionScan Added
    • +
    • BuiltinPattern.SecretsMasking Added
    • +
    • Event.Enum(hookEventTypePreOutput) Added
    • +
    • JsonPatch Added
    • +
    • ManagedByGuardrails Added
  • -
  • ConductoroneApi.AppEntitlementsProxy.Create(): +
  • ConductoroneApi.Hooks.Update():
      -
    • request.Request.CreateAppEntitlementProxyRequest Changed (Breaking ⚠️) +
    • request.Request.HooksServiceUpdateRequest.Hook Changed
        -
      • AppEntitlementProxyExpandMask Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • +
      • BuiltinPattern.BlockOutput Added
      • +
      • BuiltinPattern.BlockToolCall Added
      • +
      • BuiltinPattern.EncodedContentGuard Added
      • +
      • BuiltinPattern.LinkFilter Added
      • +
      • BuiltinPattern.PreToolBlock Added
      • +
      • BuiltinPattern.PromptInjectionScan Added
      • +
      • BuiltinPattern.SecretsMasking Added
      • +
      • Event.Enum(hookEventTypePreOutput) Added
      • +
      • JsonPatch Added
      • +
      • ManagedByGuardrails Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.Hook Changed
        -
      • AppEntitlementProxyView Removed (Breaking ⚠️)
      • -
      • AppProxyEntitlementView Added
      • +
      • BuiltinPattern.BlockOutput Added
      • +
      • BuiltinPattern.BlockToolCall Added
      • +
      • BuiltinPattern.EncodedContentGuard Added
      • +
      • BuiltinPattern.LinkFilter Added
      • +
      • BuiltinPattern.PreToolBlock Added
      • +
      • BuiltinPattern.PromptInjectionScan Added
      • +
      • BuiltinPattern.SecretsMasking Added
      • +
      • Event.Enum(hookEventTypePreOutput) Added
      • +
      • JsonPatch Added
      • +
      • ManagedByGuardrails Added
  • -
  • ConductoroneApi.AppEntitlementsProxy.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.Policies.Create():
      -
    • AppEntitlementProxyView Removed (Breaking ⚠️)
    • -
    • AppProxyEntitlementView Added
    • -
  • -
  • ConductoroneApi.Attributes.CreateAttributeValue(): response Changed (Breaking ⚠️) +
  • request.Request Changed
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.CreateComplianceFrameworkAttributeValue(): response Changed (Breaking ⚠️) +
  • response.Policy Changed
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.CreateRiskLevelAttributeValue(): response Changed (Breaking ⚠️) - -
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
  • -
  • ConductoroneApi.Attributes.GetAttributeValue(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.Policies.Get(): response.Policy Changed
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.GetComplianceFrameworkAttributeValue(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.Policies.List(): response.List[] Changed
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.GetRiskLevelAttributeValue(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.Policies.Update():
      -
    • AttributeValue Removed (Breaking ⚠️)
    • -
    • Value Added
    • -
  • -
  • ConductoroneApi.Attributes.ListAttributeValues(): response.List[] Changed (Breaking ⚠️) +
  • request.Request.UpdatePolicyRequest.Policy Changed
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.ListComplianceFrameworks(): response.List[] Changed (Breaking ⚠️) +
  • response.Policy Changed
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • BaselinePolicyId Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Rules[].PolicyId Added
    • +
    • Rules[].StepKey Added
    • +
    • Scope Added
  • -
  • ConductoroneApi.Attributes.ListRiskLevels(): response.List[] Changed (Breaking ⚠️) - -
      -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • UpdatedAt Changed (Breaking ⚠️)
  • -
  • ConductoroneApi.TenantAuthConfig.Create(): +
  • ConductoroneApi.RequestSchema.Create():
      -
    • request.Request Changed (Breaking ⚠️) +
    • request.Request.Fields[].StringField Changed
        -
      • AuthConfigC1Local Removed (Breaking ⚠️)
      • -
      • AuthConfigGoogle Removed (Breaking ⚠️)
      • -
      • AuthConfigJumpCloud Removed (Breaking ⚠️)
      • -
      • AuthConfigMicrosoft Removed (Breaking ⚠️)
      • -
      • AuthConfigOidc Removed (Breaking ⚠️)
      • -
      • AuthConfigOkta Removed (Breaking ⚠️)
      • -
      • AuthConfigOneLogin Removed (Breaking ⚠️)
      • -
      • AuthConfigPingOne Removed (Breaking ⚠️)
      • -
      • C1Local Added
      • -
      • DeprecationDeadline Changed
      • -
      • Google Added
      • -
      • Jumpcloud Added
      • -
      • Microsoft Added
      • -
      • Oidc Added
      • -
      • Okta Added
      • -
      • Onelogin Added
      • -
      • Pingone Added
      • +
      • DateField Added
      • +
      • PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PickerField.C1UserPicker.UserIds Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.RequestSchema.Form.Fields[].StringField Changed
        -
      • AuthConfig Added
      • -
      • TenantAuthConfig Removed (Breaking ⚠️)
      • +
      • DateField Added
      • +
      • PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PickerField.C1UserPicker.UserIds Added
  • -
  • ConductoroneApi.TenantAuthConfig.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.RequestSchema.Get(): response.RequestSchema.Form.Fields[].StringField Changed
      -
    • AuthConfig Added
    • -
    • TenantAuthConfig Removed (Breaking ⚠️)
    • +
    • DateField Added
    • +
    • PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • PickerField.C1UserPicker.UserIds Added
  • -
  • ConductoroneApi.TenantAuthConfig.List(): response.List[] Changed (Breaking ⚠️) - -
      -
    • AuthConfigC1Local Removed (Breaking ⚠️)
    • -
    • AuthConfigGoogle Removed (Breaking ⚠️)
    • -
    • AuthConfigJumpCloud Removed (Breaking ⚠️)
    • -
    • AuthConfigMicrosoft Removed (Breaking ⚠️)
    • -
    • AuthConfigOidc Removed (Breaking ⚠️)
    • -
    • AuthConfigOkta Removed (Breaking ⚠️)
    • -
    • AuthConfigOneLogin Removed (Breaking ⚠️)
    • -
    • AuthConfigPingOne Removed (Breaking ⚠️)
    • -
    • C1Local Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeprecationDeadline Changed (Breaking ⚠️)
    • -
    • Google Added
    • -
    • Jumpcloud Added
    • -
    • Microsoft Added
    • -
    • Oidc Added
    • -
    • Okta Added
    • -
    • Onelogin Added
    • -
    • Pingone Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.TenantAuthConfig.Update(): +
  • ConductoroneApi.RequestSchema.Update():
      -
    • request.Request.TenantAuthConfigServiceUpdateRequest Changed (Breaking ⚠️) +
    • request.Request.RequestSchemaServiceUpdateRequest.RequestSchema.Form.Fields[].StringField Changed
        -
      • AuthConfig Added
      • -
      • TenantAuthConfig Removed (Breaking ⚠️)
      • +
      • DateField Added
      • +
      • PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PickerField.C1UserPicker.UserIds Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.RequestSchema.Form.Fields[].StringField Changed
        -
      • AuthConfig Added
      • -
      • TenantAuthConfig Removed (Breaking ⚠️)
      • +
      • DateField Added
      • +
      • PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PickerField.C1UserPicker.UserIds Added
  • -
  • ConductoroneApi.Directory.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult(): response.CutoffImpactPoints Added
  • +
  • ConductoroneApi.AppSearch.Search(): response.List[].MatchBatonRef Added
  • +
  • ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions(): response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • +
  • ConductoroneApi.AutomationSearch.SearchAutomations(): response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter Added
  • +
  • ConductoroneApi.FindingAudit.Search():
      -
    • DirectoryView Added
    • -
    • DirectoryView Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.AutomationExecution.GetAutomationExecution(): response Changed (Breaking ⚠️) +
  • request.Request.EventTypes[] Changed
      -
    • AutomationExecutionView Removed (Breaking ⚠️)
    • -
    • AutomationExecution Added
    • -
    • AutomationExecution Removed (Breaking ⚠️)
    • -
    • View Added
    • +
    • Enum(findingAuditEventTypeReprocessCompleted) Added
    • +
    • Enum(findingAuditEventTypeReprocessRequested) Added
  • -
  • ConductoroneApi.AutomationExecution.ListAutomationExecutions(): response.AutomationExecutions[] Changed (Breaking ⚠️) +
  • response.List[].EventType Changed
      -
    • AutomationContext Removed (Breaking ⚠️)
    • -
    • CompletedAt Changed (Breaking ⚠️)
    • -
    • Context Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • Duration Changed (Breaking ⚠️)
    • -
    • State.Enum(automationExecutionStatePausedByCircuitBreaker) Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • +
    • Enum(findingAuditEventTypeReprocessCompleted) Added
    • +
    • Enum(findingAuditEventTypeReprocessRequested) Added
  • -
  • ConductoroneApi.Directory.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • All Added
      • -
      • CelExpression Added
      • -
      • DirectoryAccountFilterAll Removed (Breaking ⚠️)
      • -
      • DirectoryAccountFilterCel Removed (Breaking ⚠️)
      • -
      • DirectoryExpandMask Removed (Breaking ⚠️)
      • -
      • DirectoryMergeConfig Removed (Breaking ⚠️)
      • -
      • ExpandMask Added
      • -
      • MergeConfig Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.FunctionsSearch.Search(): response.List[] Changed
        -
      • DirectoryView Added
      • -
      • DirectoryView Removed (Breaking ⚠️)
      • +
      • HookRefs Added
      • +
      • WorkflowTemplateRefs Added
    • -
  • -
  • ConductoroneApi.Automation.CreateAutomation(): - -
      -
    • request.Request Changed (Breaking ⚠️) - -
        -
      • Annotations Added
      • -
      • AutomationContext Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].AccountLifecycleAction Added
      • -
      • AutomationSteps[].AccountLifecycleAction Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].CallFunction Added
      • -
      • AutomationSteps[].CallFunction Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].ConnectorAction Added
      • -
      • AutomationSteps[].ConnectorAction Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].ConnectorCreateAccount Added
      • -
      • AutomationSteps[].ConnectorCreateAccount Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].CreateAccessReview Added
      • -
      • AutomationSteps[].CreateAccessReview Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].CreateRevokeTasksV2 Added
      • -
      • AutomationSteps[].CreateRevokeTasksV2 Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].CreateRevokeTasks Added
      • -
      • AutomationSteps[].CreateRevokeTasks Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].EvaluateExpressions Added
      • -
      • AutomationSteps[].EvaluateExpressions Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].GeneratePassword Added
      • -
      • AutomationSteps[].GeneratePassword Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].GrantEntitlements Added
      • -
      • AutomationSteps[].GrantEntitlements Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].RemoveFromDelegation Added
      • -
      • AutomationSteps[].RemoveFromDelegation Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].RunAutomation Added
      • -
      • AutomationSteps[].RunAutomation Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].SendEmail Added
      • -
      • AutomationSteps[].SendEmail Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].SendSlackMessage Added
      • -
      • AutomationSteps[].SendSlackMessage Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].SetCredential Added
      • -
      • AutomationSteps[].SetCredential Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].StoreCredential Added
      • -
      • AutomationSteps[].StoreCredential Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].TaskAction Added
      • -
      • AutomationSteps[].TaskAction Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].UnenrollFromAllAccessProfiles Added
      • -
      • AutomationSteps[].UnenrollFromAllAccessProfiles Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].UpdateUser Added
      • -
      • AutomationSteps[].UpdateUser Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].WaitForDuration Added
      • -
      • AutomationSteps[].WaitForDuration Removed (Breaking ⚠️)
      • -
      • AutomationSteps[].Webhook Added
      • -
      • AutomationSteps[].Webhook Removed (Breaking ⚠️)
      • -
      • Context Added
      • -
      • DraftTriggers[].AccessConflictTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].AccessConflict Added
      • -
      • DraftTriggers[].AppUserCreatedTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].AppUserCreated Added
      • -
      • DraftTriggers[].AppUserUpdatedTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].AppUserUpdated Added
      • -
      • DraftTriggers[].GrantDeletedTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].GrantDeleted Added
      • -
      • DraftTriggers[].GrantFoundTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].GrantFound Added
      • -
      • DraftTriggers[].ScheduleAppUser Added
      • -
      • DraftTriggers[].ScheduleNoUser Added
      • -
      • DraftTriggers[].ScheduleTriggerAppUser Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].ScheduleTriggerNoUser Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].ScheduleTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].Schedule Added
      • -
      • DraftTriggers[].UsageBasedRevocationTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].UsageBasedRevocation Added
      • -
      • DraftTriggers[].UserCreatedTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].UserCreated Added
      • -
      • DraftTriggers[].UserProfileChangeTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].UserProfileChange Added
      • -
      • DraftTriggers[].WebhookAutomationTrigger Removed (Breaking ⚠️)
      • -
      • DraftTriggers[].Webhook Added
      • -
    • -
    • response Changed (Breaking ⚠️) - -
        -
      • Automation Added
      • -
      • Automation Removed (Breaking ⚠️)
      • -
    • -
  • -
  • ConductoroneApi.Automation.ExecuteAutomation(): - -
      -
    • request.Request.ExecuteAutomationRequest Changed (Breaking ⚠️) - -
        -
      • AutomationContext Removed (Breaking ⚠️)
      • -
      • Context Added
      • -
    • -
  • -
  • ConductoroneApi.Automation.GetAutomation(): response Changed (Breaking ⚠️) - -
      -
    • Automation Added
    • -
    • Automation Removed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.Automation.ListAutomations(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.HooksSearch.Search(): response.List[] Changed
      -
    • Annotations Added
    • -
    • AutomationContext Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].AccountLifecycleAction Added
    • -
    • AutomationSteps[].AccountLifecycleAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CallFunction Added
    • -
    • AutomationSteps[].CallFunction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorAction Added
    • -
    • AutomationSteps[].ConnectorAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].ConnectorCreateAccount Added
    • -
    • AutomationSteps[].ConnectorCreateAccount Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateAccessReview Added
    • -
    • AutomationSteps[].CreateAccessReview Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Added
    • -
    • AutomationSteps[].CreateRevokeTasksV2 Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].CreateRevokeTasks Added
    • -
    • AutomationSteps[].CreateRevokeTasks Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].EvaluateExpressions Added
    • -
    • AutomationSteps[].EvaluateExpressions Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GeneratePassword Added
    • -
    • AutomationSteps[].GeneratePassword Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].GrantEntitlements Added
    • -
    • AutomationSteps[].GrantEntitlements Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RemoveFromDelegation Added
    • -
    • AutomationSteps[].RemoveFromDelegation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].RunAutomation Added
    • -
    • AutomationSteps[].RunAutomation Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendEmail Added
    • -
    • AutomationSteps[].SendEmail Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SendSlackMessage Added
    • -
    • AutomationSteps[].SendSlackMessage Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].SetCredential Added
    • -
    • AutomationSteps[].SetCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].StoreCredential Added
    • -
    • AutomationSteps[].StoreCredential Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].TaskAction Added
    • -
    • AutomationSteps[].TaskAction Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Added
    • -
    • AutomationSteps[].UnenrollFromAllAccessProfiles Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].UpdateUser Added
    • -
    • AutomationSteps[].UpdateUser Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].WaitForDuration Added
    • -
    • AutomationSteps[].WaitForDuration Removed (Breaking ⚠️)
    • -
    • AutomationSteps[].Webhook Added
    • -
    • AutomationSteps[].Webhook Removed (Breaking ⚠️)
    • -
    • CircuitBreaker Added
    • -
    • Context Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DisabledReasonCircuitBreaker Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AccessConflictTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AccessConflict Added
    • -
    • DraftTriggers[].AppUserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AppUserCreated Added
    • -
    • DraftTriggers[].AppUserUpdatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].AppUserUpdated Added
    • -
    • DraftTriggers[].GrantDeletedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].GrantDeleted Added
    • -
    • DraftTriggers[].GrantFoundTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].GrantFound Added
    • -
    • DraftTriggers[].ScheduleAppUser Added
    • -
    • DraftTriggers[].ScheduleNoUser Added
    • -
    • DraftTriggers[].ScheduleTriggerAppUser Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].ScheduleTriggerNoUser Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].ScheduleTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].Schedule Added
    • -
    • DraftTriggers[].UsageBasedRevocationTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UsageBasedRevocation Added
    • -
    • DraftTriggers[].UserCreatedTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UserCreated Added
    • -
    • DraftTriggers[].UserProfileChangeTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].UserProfileChange Added
    • -
    • DraftTriggers[].WebhookAutomationTrigger Removed (Breaking ⚠️)
    • -
    • DraftTriggers[].Webhook Added
    • -
    • LastExecutedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.ConnectorCatalog.ConfigurationSchema(): response Changed (Breaking ⚠️) - -
      -
    • ConfigSchema Removed (Breaking ⚠️)
    • -
    • FormSchema Added
    • -
    • RequestSchemaForm Removed (Breaking ⚠️)
    • -
    • Schema Added
    • +
    • BuiltinPattern.BlockOutput Added
    • +
    • BuiltinPattern.BlockToolCall Added
    • +
    • BuiltinPattern.EncodedContentGuard Added
    • +
    • BuiltinPattern.LinkFilter Added
    • +
    • BuiltinPattern.PreToolBlock Added
    • +
    • BuiltinPattern.PromptInjectionScan Added
    • +
    • BuiltinPattern.SecretsMasking Added
    • +
    • Event.Enum(hookEventTypePreOutput) Added
    • +
    • JsonPatch Added
    • +
    • ManagedByGuardrails Added
  • -
  • ConductoroneApi.Automation.UpdateAutomation(): +
  • ConductoroneApi.ExternalClientSearch.Search(): response.List[].ClientIdType.Enum(clientIdTypeApp) Added
  • +
  • ConductoroneApi.PolicySearch.Search():
      -
    • request.Request.UpdateAutomationRequest Changed (Breaking ⚠️) +
    • request.Request Changed
        -
      • Automation Added
      • -
      • Automation Removed (Breaking ⚠️)
      • +
      • ScopeAppEntitlementId Added
      • +
      • ScopeAppId Added
      • +
      • ScopeObjectType Added
      • +
      • ScopeSlot Added
      • +
      • ScopeView Added
    • -
    • response Changed (Breaking ⚠️) +
    • response.List[] Changed
        -
      • Automation Added
      • -
      • Automation Removed (Breaking ⚠️)
      • +
      • BaselinePolicyId Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.DateField Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.DevicePlacement Added
      • +
      • PolicySteps.Map<PolicySteps>.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
      • +
      • Rules[].PolicyId Added
      • +
      • Rules[].StepKey Added
      • +
      • Scope Added
  • -
  • ConductoroneApi.RequestCatalogManagement.Create(): - -
      -
    • request.Request Changed (Breaking ⚠️) +
    • ConductoroneApi.RequestCatalogSearch.SearchEntitlements(): response.List[].Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
    • +
    • ConductoroneApi.TaskSearch.Search():
        -
      • Annotations Added
      • -
      • ExpandMask Added
      • -
      • GrantPolicyId Removed (Breaking ⚠️)
      • -
      • RequestCatalogExpandMask Removed (Breaking ⚠️)
      • -
    • -
    • response Changed (Breaking ⚠️) +
    • request.Request.AccountStatuses Added
    • +
    • response.List[].Task Changed
        -
      • RequestCatalogView Added
      • -
      • RequestCatalogView Removed (Breaking ⚠️)
      • -
    • +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
  • -
  • ConductoroneApi.RequestCatalogManagement.CreateBundleAutomation(): - -
      -
    • request.Request.CreateBundleAutomationRequest Changed (Breaking ⚠️) - -
        -
      • BundleAutomationRuleCel Removed (Breaking ⚠️)
      • -
      • BundleAutomationRuleEntitlement Removed (Breaking ⚠️)
      • -
      • Cel Added
      • -
      • EnforceOnSmallProfiles Added
      • -
      • Entitlements Added
      • -
      • RemovedMembersThresholdPercent Added
    • -
    • response Changed (Breaking ⚠️) +
    • ConductoroneApi.UserSearch.Search():
        -
      • BundleAutomationCircuitBreaker Removed (Breaking ⚠️)
      • -
      • BundleAutomationLastRunState Removed (Breaking ⚠️)
      • -
      • BundleAutomationRuleCel Removed (Breaking ⚠️)
      • -
      • BundleAutomationRuleEntitlement Removed (Breaking ⚠️)
      • -
      • Cel Added
      • -
      • CircuitBreaker Added
      • -
      • CreatedAt Changed (Breaking ⚠️)
      • -
      • DeletedAt Changed (Breaking ⚠️)
      • -
      • EnforceOnSmallProfiles Added
      • -
      • Entitlements Added
      • -
      • RemovedMembersThresholdPercent Added
      • -
      • State Added
      • -
      • UpdatedAt Changed (Breaking ⚠️)
      • -
    • +
    • request.Request.SourceAppIds Added
  • -
  • ConductoroneApi.RequestCatalogManagement.CreateRequestableEntry(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.AiGovernanceSettings.Get(): response.AiGovernanceSettings.UntrustedJudgeDisable Added
  • +
  • ConductoroneApi.AiGovernanceSettings.ListHistory(): response.List[].Snapshot.UntrustedJudgeDisable Added
  • +
  • ConductoroneApi.AiGovernanceSettings.Update():
      -
    • RequestableEntry Added
    • -
    • RequestableEntry Removed (Breaking ⚠️)
    • +
    • request.Request.AiGovernanceSettings.UntrustedJudgeDisable Added
    • +
    • response.AiGovernanceSettings.UntrustedJudgeDisable Added
  • -
  • ConductoroneApi.RequestCatalogManagement.Get(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.OrgNotificationSettings.Get(): response.OrgNotificationSettings.ChannelSettings Changed
      -
    • RequestCatalogView Added
    • -
    • RequestCatalogView Removed (Breaking ⚠️)
    • +
    • Email.RequestCreated Added
    • +
    • Email.System Added
    • +
    • Slack.RequestCreated Added
    • +
    • Slack.System Added
    • +
    • Teams.RequestCreated Added
    • +
    • Teams.System Added
  • -
  • ConductoroneApi.RequestCatalogManagement.GetBundleAutomation(): response Changed (Breaking ⚠️) +
  • ConductoroneApi.OrgNotificationSettings.Update():
      -
    • BundleAutomationCircuitBreaker Removed (Breaking ⚠️)
    • -
    • BundleAutomationLastRunState Removed (Breaking ⚠️)
    • -
    • BundleAutomationRuleCel Removed (Breaking ⚠️)
    • -
    • BundleAutomationRuleEntitlement Removed (Breaking ⚠️)
    • -
    • Cel Added
    • -
    • CircuitBreaker Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • EnforceOnSmallProfiles Added
    • -
    • Entitlements Added
    • -
    • RemovedMembersThresholdPercent Added
    • -
    • State Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • -
  • ConductoroneApi.RequestCatalogManagement.GetRequestableEntry(): response Changed (Breaking ⚠️) +
  • request.Request.ChannelSettings Changed
      -
    • RequestableEntry Added
    • -
    • RequestableEntry Removed (Breaking ⚠️)
    • +
    • Email.RequestCreated Added
    • +
    • Email.System Added
    • +
    • Slack.RequestCreated Added
    • +
    • Slack.System Added
    • +
    • Teams.RequestCreated Added
    • +
    • Teams.System Added
  • -
  • ConductoroneApi.RequestCatalogManagement.List(): response.List[] Changed (Breaking ⚠️) +
  • response.OrgNotificationSettings.ChannelSettings Changed
      -
    • RequestCatalog Added
    • -
    • RequestCatalog Removed (Breaking ⚠️)
    • +
    • Email.RequestCreated Added
    • +
    • Email.System Added
    • +
    • Slack.RequestCreated Added
    • +
    • Slack.System Added
    • +
    • Teams.RequestCreated Added
    • +
    • Teams.System Added
  • -
  • ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess(): response.List[] Changed (Breaking ⚠️) - -
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
  • -
  • ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog(): response.List[] Changed (Breaking ⚠️) +
  • ConductoroneApi.UserNotificationSettings.Get(): response.UserNotificationSettings.ChannelSettings Changed
      -
    • ActorObjectPermissions Removed (Breaking ⚠️)
    • -
    • AppEntitlement Added
    • -
    • AppEntitlement Removed (Breaking ⚠️)
    • -
    • ObjectPermissions Added
    • +
    • Email.RequestCreated Added
    • +
    • Email.System Added
    • +
    • Slack.RequestCreated Added
    • +
    • Slack.System Added
    • +
    • Teams.RequestCreated Added
    • +
    • Teams.System Added
  • -
  • ConductoroneApi.RequestCatalogManagement.SetBundleAutomation(): +
  • ConductoroneApi.UserNotificationSettings.Update():
      -
    • request.Request.SetBundleAutomationRequest Changed (Breaking ⚠️) +
    • request.Request.ChannelSettings Changed
        -
      • BundleAutomationRuleCel Removed (Breaking ⚠️)
      • -
      • BundleAutomationRuleEntitlement Removed (Breaking ⚠️)
      • -
      • Cel Added
      • -
      • EnforceOnSmallProfiles Added
      • -
      • Entitlements Added
      • -
      • RemovedMembersThresholdPercent Added
      • +
      • Email.RequestCreated Added
      • +
      • Email.System Added
      • +
      • Slack.RequestCreated Added
      • +
      • Slack.System Added
      • +
      • Teams.RequestCreated Added
      • +
      • Teams.System Added
      • +
    • +
    • response.UserNotificationSettings.ChannelSettings Changed + +
        +
      • Email.RequestCreated Added
      • +
      • Email.System Added
      • +
      • Slack.RequestCreated Added
      • +
      • Slack.System Added
      • +
      • Teams.RequestCreated Added
      • +
      • Teams.System Added
      • +
    • +
  • +
  • ConductoroneApi.RequestSettings.Get(): response.RequestSettings.MaxBulkEntitlementSelection Added
  • +
  • ConductoroneApi.RequestSettings.Update(): + +
      +
    • request.Request.RequestSettings.MaxBulkEntitlementSelection Added
    • +
    • response.RequestSettings.MaxBulkEntitlementSelection Added
    • +
  • +
  • ConductoroneApi.Task.CreateActionTask(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.Task.CreateGrantTask(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.Task.CreateOffboardingTask(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.Task.CreateResourceActionTask(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.Task.CreateRevokeTask(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.Task.Get(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
  • -
  • response Changed (Breaking ⚠️) - -
      -
    • BundleAutomationCircuitBreaker Removed (Breaking ⚠️)
    • -
    • BundleAutomationLastRunState Removed (Breaking ⚠️)
    • -
    • BundleAutomationRuleCel Removed (Breaking ⚠️)
    • -
    • BundleAutomationRuleEntitlement Removed (Breaking ⚠️)
    • -
    • Cel Added
    • -
    • CircuitBreaker Added
    • -
    • CreatedAt Changed (Breaking ⚠️)
    • -
    • DeletedAt Changed (Breaking ⚠️)
    • -
    • EnforceOnSmallProfiles Added
    • -
    • Entitlements Added
    • -
    • RemovedMembersThresholdPercent Added
    • -
    • State Added
    • -
    • UpdatedAt Changed (Breaking ⚠️)
    • -
  • - -
  • ConductoroneApi.SignInPolicy.Delete(): Added
  • -
  • ConductoroneApi.Automation.ResolvePausedAutomationExecutions(): response.BulkActionId Added
  • -
  • ConductoroneApi.Automation.ClearAutomationCircuitBreaker(): - -
      -
    • request.Request.ClearAutomationCircuitBreakerRequest Changed - -
        -
      • Decision Added
      • -
      • Reason Added
      • -
    • -
    • response.BulkActionId Added
    • -
  • -
  • ConductoroneApi.Auth.Introspect(): response Changed - -
      -
    • DeviceClientId Added
    • -
    • TenantId Added
    • -
  • -
  • ConductoroneApi.AppResourceOwnersV2.Set(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.ReorderAppEntitlementRoutingRules(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.GetByAppEntitlementId(): Added
  • -
  • ConductoroneApi.A2Ui.SubmitAction(): - -
      -
    • request.Request.A2UiServiceSubmitActionRequest.ClientTimestamp Changed
    • -
  • -
  • ConductoroneApi.UserOwnersV2.Set(): Added
  • -
  • ConductoroneApi.UserOwnersV2.SearchUserOwners(): Added
  • -
  • ConductoroneApi.UserOwnersV2.SearchEntitlementOwners(): Added
  • -
  • ConductoroneApi.UserOwnersV2.DeleteUserOwner(): Added
  • -
  • ConductoroneApi.UserOwnersV2.DeleteEntitlementOwner(): Added
  • -
  • ConductoroneApi.UserOwnersV2.CreateUserOwner(): Added
  • -
  • ConductoroneApi.UserOwnersV2.CreateEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.Set(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.SearchUserOwners(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.DeleteUserOwner(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.DeleteEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.CreateUserOwner(): Added
  • -
  • ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.SearchUserOwners(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.GetUserOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.DeleteUserOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.DeleteEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.CreateUserOwner(): Added
  • -
  • ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.GetUserOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.DeleteUserOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.DeleteEntitlementOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.CreateUserOwner(): Added
  • -
  • ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.GetUserOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.DeleteUserOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.DeleteEntitlementOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.CreateUserOwner(): Added
  • -
  • ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner(): Added
  • -
  • ConductoroneApi.User.Introspect(): Added
  • -
  • ConductoroneApi.TerraformExport.GetSchema(): Added
  • -
  • ConductoroneApi.Task.CreateResourceActionTask(): Added
  • -
  • ConductoroneApi.Task.CreateActionTask(): Added
  • -
  • ConductoroneApi.RequestSettings.Update(): Added
  • -
  • ConductoroneApi.RequestSettings.Get(): Added
  • -
  • ConductoroneApi.IdentityPolicyTenantDefaults.Update(): Added
  • -
  • ConductoroneApi.IdentityPolicyTenantDefaults.Get(): Added
  • -
  • ConductoroneApi.UserDeveloperPreferences.Update(): Added
  • -
  • ConductoroneApi.UserDeveloperPreferences.Get(): Added
  • -
  • ConductoroneApi.XaaSettings.Update(): Added
  • -
  • ConductoroneApi.XaaSettings.ListHistory(): Added
  • -
  • ConductoroneApi.XaaSettings.Get(): Added
  • -
  • ConductoroneApi.AiGovernanceSettings.Update(): Added
  • -
  • ConductoroneApi.AiGovernanceSettings.ListHistory(): Added
  • -
  • ConductoroneApi.RoleMiningManagement.CreateAccessProfileFromCohort(): request.Request Changed - -
      -
    • CelExpression Added
    • -
    • Entitlements[].RiskLevelValueId Added
    • -
  • -
  • ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult(): response.Clusters[].Entitlements[].RiskLevelValueId Added
  • -
  • ConductoroneApi.AiGovernanceSettings.GetTenantDefaults(): Added
  • -
  • ConductoroneApi.AiGovernanceSettings.Get(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.Update(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.Search(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.ListHistory(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.List(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.Get(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.Delete(): Added
  • -
  • ConductoroneApi.XaaClientAudienceMapping.Create(): Added
  • -
  • ConductoroneApi.SignInPolicy.Update(): Added
  • -
  • ConductoroneApi.SignInPolicy.Search(): Added
  • -
  • ConductoroneApi.SignInPolicy.List(): Added
  • -
  • ConductoroneApi.SignInPolicy.Get(): Added
  • -
  • ConductoroneApi.AppUser.ListOwnedServiceAccounts(): Added
  • -
  • ConductoroneApi.McpTool.Delete(): Added
  • -
  • ConductoroneApi.SignInPolicy.Create(): Added
  • -
  • ConductoroneApi.SessionPolicy.Update(): Added
  • -
  • ConductoroneApi.SessionPolicy.UnassignUser(): Added
  • -
  • ConductoroneApi.SessionPolicy.UnassignGroup(): Added
  • -
  • ConductoroneApi.SessionPolicy.Search(): Added
  • -
  • ConductoroneApi.SessionPolicy.ListAssignments(): Added
  • -
  • ConductoroneApi.SessionPolicy.List(): Added
  • -
  • ConductoroneApi.SessionPolicy.Get(): Added
  • -
  • ConductoroneApi.SessionPolicy.Delete(): Added
  • -
  • ConductoroneApi.SessionPolicy.Create(): Added
  • -
  • ConductoroneApi.SessionPolicy.AssignUser(): Added
  • -
  • ConductoroneApi.SessionPolicy.AssignGroup(): Added
  • -
  • ConductoroneApi.FindingAudit.Search(): Added
  • -
  • ConductoroneApi.RoleMiningManagement.ListCustomAnalysisResults(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.Update(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.Search(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.List(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.Get(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.Delete(): Added
  • -
  • ConductoroneApi.RecoveryPolicy.Create(): Added
  • -
  • ConductoroneApi.TunnelCredentials.UpdateBridge(): Added
  • -
  • ConductoroneApi.TunnelCredentials.RevokeBridgeCredential(): Added
  • -
  • ConductoroneApi.TunnelCredentials.ListBridges(): Added
  • -
  • ConductoroneApi.TunnelCredentials.ListBridgeCredentials(): Added
  • -
  • ConductoroneApi.TunnelCredentials.ListBridgeAnnouncedServices(): Added
  • -
  • ConductoroneApi.TunnelCredentials.GetBridge(): Added
  • -
  • ConductoroneApi.TunnelCredentials.DeleteBridge(): Added
  • -
  • ConductoroneApi.TunnelCredentials.CreateBridgeCredential(): Added
  • -
  • ConductoroneApi.TunnelCredentials.CreateBridge(): Added
  • -
  • ConductoroneApi.PersonalDevice.UpdateDevice(): Added
  • -
  • ConductoroneApi.PersonalDevice.Search(): Added
  • -
  • ConductoroneApi.PersonalDevice.RevokeDeviceClient(): Added
  • -
  • ConductoroneApi.PersonalDevice.RevokeDevice(): Added
  • -
  • ConductoroneApi.PersonalDevice.ListDeviceClients(): Added
  • -
  • ConductoroneApi.PersonalDevice.GetDevice(): Added
  • -
  • ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule(): Added
  • -
  • ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules(): Added
  • -
  • ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule(): Added
  • -
  • ConductoroneApi.FindingTransformationRule.DeleteFindingTransformationRule(): Added
  • -
  • ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule(): Added
  • -
  • ConductoroneApi.Finding.CreateFinding(): Added
  • -
  • ConductoroneApi.DecoySearch.Search(): Added
  • -
  • ConductoroneApi.Decoy.Update(): Added
  • -
  • ConductoroneApi.Decoy.Rotate(): Added
  • -
  • ConductoroneApi.Decoy.List(): Added
  • -
  • ConductoroneApi.Decoy.Get(): Added
  • -
  • ConductoroneApi.Decoy.Delete(): Added
  • -
  • ConductoroneApi.Decoy.Create(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.Update(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.Search(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.List(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.Get(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.Delete(): Added
  • -
  • ConductoroneApi.CredentialInventoryPolicy.Create(): Added
  • -
  • ConductoroneApi.ConnectorAuthoringActivation.RollbackRevision(): Added
  • -
  • ConductoroneApi.ConnectorAuthoringActivation.ActivateRevision(): Added
  • -
  • ConductoroneApi.XaaScope.Update(): Added
  • -
  • ConductoroneApi.XaaScope.Search(): Added
  • -
  • ConductoroneApi.XaaScope.ListHistory(): Added
  • -
  • ConductoroneApi.XaaScope.List(): Added
  • -
  • ConductoroneApi.XaaScope.Get(): Added
  • -
  • ConductoroneApi.XaaScope.Delete(): Added
  • -
  • ConductoroneApi.XaaScope.Create(): Added
  • -
  • ConductoroneApi.XaaResourceServer.Update(): Added
  • -
  • ConductoroneApi.XaaResourceServer.Search(): Added
  • -
  • ConductoroneApi.OnboardingSettings.Update(): - -
      -
    • request.Request Changed +
    • ConductoroneApi.TaskAudit.List():
        -
      • McpOnboardingGoal Added
      • -
      • McpOnboardingStatus Added
      • -
      • McpOnboardingTargets Added
      • -
    • +
    • request.Request.ExcludeComments Added
    • response Changed
        -
      • McpOnboardingGoal Added
      • -
      • McpOnboardingStatus Added
      • -
      • McpOnboardingTargets Added
      • -
    • -
  • -
  • ConductoroneApi.XaaResourceServer.ListHistory(): Added
  • -
  • ConductoroneApi.XaaResourceServer.List(): Added
  • -
  • ConductoroneApi.XaaResourceServer.Get(): Added
  • -
  • ConductoroneApi.XaaResourceServer.Delete(): Added
  • -
  • ConductoroneApi.XaaResourceServer.Create(): Added
  • -
  • ConductoroneApi.XaaAccessProfileScopeBinding.Search(): Added
  • -
  • ConductoroneApi.XaaAccessProfileScopeBinding.List(): Added
  • -
  • ConductoroneApi.XaaAccessProfileScopeBinding.DeleteBindings(): Added
  • -
  • ConductoroneApi.XaaAccessProfileScopeBinding.CreateBindings(): Added
  • -
  • ConductoroneApi.SystemLog.ListEvents(): request.Request Changed - -
      -
    • Since Changed
    • -
    • Until Changed
    • -
  • -
  • ConductoroneApi.XaaAccessProfile.Update(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.Search(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.ListHistory(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.List(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.Get(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.Delete(): Added
  • -
  • ConductoroneApi.XaaAccessProfile.Create(): Added
  • -
  • ConductoroneApi.McpServer.UpdateCredentials(): Added
  • -
  • ConductoroneApi.McpServer.Update(): Added
  • -
  • ConductoroneApi.McpServer.TestConnection(): Added
  • -
  • ConductoroneApi.McpServer.SearchWithToolCount(): Added
  • -
  • ConductoroneApi.McpServer.ResyncTools(): Added
  • -
  • ConductoroneApi.McpServer.Register(): Added
  • -
  • ConductoroneApi.McpServer.ListConnections(): Added
  • -
  • ConductoroneApi.McpServer.ListCatalog(): Added
  • -
  • ConductoroneApi.McpServer.List(): Added
  • -
  • ConductoroneApi.McpServer.GetCatalog(): Added
  • -
  • ConductoroneApi.McpServer.Get(): Added
  • -
  • ConductoroneApi.McpServer.DiscoverOidcEndpoints(): Added
  • -
  • ConductoroneApi.McpServer.Delete(): Added
  • -
  • ConductoroneApi.AppEntitlementSearch.SearchGraph(): Added
  • -
  • ConductoroneApi.AppEntitlementSearch.CountGrantsForUserByApp(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.UpdateAppEntitlementRoutingRule(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.ListAppEntitlementRoutingRules(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.GetAppEntitlementRoutingRule(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.DeleteAppEntitlementRoutingRule(): Added
  • -
  • ConductoroneApi.AppEntitlementRoutingRule.CreateAppEntitlementRoutingRule(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.ListToolsByProfileHistory(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.ListProfilesByToolHistory(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.List(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.DeleteBindings(): Added
  • -
  • ConductoroneApi.McpAccessProfileToolBinding.CreateBindings(): Added
  • -
  • ConductoroneApi.McpAccessProfile.Update(): Added
  • -
  • ConductoroneApi.McpAccessProfile.SearchRequestableConnectors(): Added
  • -
  • ConductoroneApi.McpAccessProfile.ListRequestableConnectors(): Added
  • -
  • ConductoroneApi.McpAccessProfile.List(): Added
  • -
  • ConductoroneApi.McpAccessProfile.GetByAppEntitlementId(): Added
  • -
  • ConductoroneApi.McpAccessProfile.Get(): Added
  • -
  • ConductoroneApi.McpAccessProfile.Delete(): Added
  • -
  • ConductoroneApi.McpAccessProfile.Create(): Added
  • -
  • ConductoroneApi.McpTool.Update(): Added
  • -
  • ConductoroneApi.McpTool.Search(): Added
  • -
  • ConductoroneApi.McpTool.ListHistory(): Added
  • -
  • ConductoroneApi.McpTool.List(): Added
  • -
  • ConductoroneApi.McpTool.Get(): Added
  • +
  • List[].AccountDeleted Added
  • +
  • List[].ActionSubmitted.Action.ActionType.Enum(taskActionTypeRetryProvisioning) Added
  • +
  • List[].AutomationTriggered Added
  • +
  • List[].ConditionalPolicyExecutionResult.ChainDepth Added
  • +
  • List[].ConditionalPolicyExecutionResult.OutcomePolicyId Added
  • +
  • List[].ConditionalPolicyExecutionResult.PolicyId Added
  • +
  • List[].ProvisionEntitlementMergeCompleted Added
  • +
  • List[].ProvisionEntitlementMergeTimedOut Added
  • +
  • List[].ProvisionWaitingForEntitlementMerge Added
  • +
  • List[].WebhookSuccess.Comment Added
  • +
  • TotalCount Added
  • + + +
  • ConductoroneApi.TaskActions.Approve(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.ApproveWithStepUp(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.Close(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.Comment(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.Deny(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.EscalateToEmergencyAccess(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.HardReset(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.ProcessNow(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.Reassign(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.Restart(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.SkipStep(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.UpdateGrantDuration(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.TaskActions.UpdateRequestData(): response.TaskView.Task Changed + +
      +
    • Actions[].Enum(taskActionTypeRetryProvisioning) Added
    • +
    • Form.Fields[].StringField.DateField Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated Added
    • +
    • Form.Fields[].StringField.PickerField.C1UserPicker.UserIds Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement Added
    • +
    • Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement Added
    • +
    • Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement) Added
    • +
    • Policy.Current.Provision.WaitingOn Added
    • +
    • Policy.Policy.BaselinePolicyId Added
    • +
    • Policy.Policy.Rules[].PolicyId Added
    • +
    • Policy.Policy.Rules[].StepKey Added
    • +
    • Policy.Policy.Scope Added
    • +
  • +
  • ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner(): response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner(): response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner(): response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner(): response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppOwnersV2.CreateEntitlementOwner(): response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppOwnersV2.GetEntitlementOwner(): response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner(): response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner(): response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner(): response.AppUserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.UserOwnersV2.CreateEntitlementOwner(): response.UserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • +
  • ConductoroneApi.UserOwnersV2.SearchEntitlementOwners(): response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement Added
  • \ No newline at end of file diff --git a/.speakeasy/logs/changes/changes.md b/.speakeasy/logs/changes/changes.md index ceebd1b95..fb633c853 100644 --- a/.speakeasy/logs/changes/changes.md +++ b/.speakeasy/logs/changes/changes.md @@ -1,2575 +1,986 @@ ## Go SDK Changes: -* `ConductoroneApi.AttributeSearch.SearchAttributeValues()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.LocalUserInvitation.Revoke()`: `response` **Changed** (Breaking ⚠️) - - `Invitation` **Added** - - `LocalUserInvitation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.GetUserOwner()`: `response` **Changed** (Breaking ⚠️) - - `AppOwnerUser` **Added** - - `AppOwnerUser` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.GetEntitlementOwner()`: `response` **Changed** (Breaking ⚠️) - - `AppOwnerEntitlement` **Added** - - `AppOwnerEntitlement` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.DeleteUserOwner()`: `request.Request` **Changed** (Breaking ⚠️) - - `DeleteAppUserOwnerRequest` **Added** - - `DeleteUserOwnerRequest` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.DeleteEntitlementOwner()`: `request.Request` **Changed** (Breaking ⚠️) - - `DeleteAppEntitlementOwnerRequest` **Added** - - `DeleteEntitlementOwnerRequest` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.CreateUserOwner()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `CreateAppUserOwnerRequest` **Added** - - `CreateUserOwnerRequest` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AppOwnerUser` **Added** - - `AppOwnerUser` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppOwnersV2.CreateEntitlementOwner()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `CreateAppEntitlementOwnerRequest` **Added** - - `CreateEntitlementOwnerRequest` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AppOwnerEntitlement` **Added** - - `AppOwnerEntitlement` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementOwnersV2.Set()`: `request.Request` **Changed** (Breaking ⚠️) - - `SetAppEntitlementOwnersRequestV2` **Added** - - `SetAppEntitlementOwnersV2Request` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppId` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `EntitlementId` **Added** - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `AppId` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `EntitlementId` **Added** -* `ConductoroneApi.ConnectorOwnersV2.SearchUserOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppId` **Added** - - `ConnectorId` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `AppId` **Added** - - `ConnectorId` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Webhooks.Update()`: - * `request.Request.WebhooksServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `WebhookEndpoint` **Removed** (Breaking ⚠️) - - `Webhook` **Added** - * `response` **Changed** (Breaking ⚠️) - - `WebhookEndpoint` **Removed** (Breaking ⚠️) - - `Webhook` **Added** -* `ConductoroneApi.Webhooks.Test()`: `response` **Changed** (Breaking ⚠️) - - `WebhookInstance` **Removed** (Breaking ⚠️) - - `Webhook` **Added** -* `ConductoroneApi.Webhooks.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CallbackTimeout` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Webhooks.Get()`: `response` **Changed** (Breaking ⚠️) - - `WebhookEndpoint` **Removed** (Breaking ⚠️) - - `Webhook` **Added** -* `ConductoroneApi.Webhooks.Create()`: - * `request.Request.CallbackTimeout` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `WebhookEndpoint` **Removed** (Breaking ⚠️) - - `Webhook` **Added** -* `ConductoroneApi.Vault.Update()`: - * `request.Request.VaultServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `Vault` **Added** - - `Vault` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Vault` **Added** - - `Vault` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Vault.Get()`: `response` **Changed** (Breaking ⚠️) - - `Vault` **Added** - - `Vault` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Vault.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `GroupAuthzVault` **Added** - - `GroupAuthzVault` **Removed** (Breaking ⚠️) - - `MagicVault` **Added** - - `MagicVault` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Vault` **Added** - - `Vault` **Removed** (Breaking ⚠️) -* `ConductoroneApi.User.SetExpiringUserDelegationBindingByAdmin()`: - * `request.Request.SetExpiringUserDelegationBindingByAdminRequest` **Changed** - - `DelegationExpireAt` **Changed** - - `DelegationStartAt` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `ExpiringUserDelegationBinding` **Removed** (Breaking ⚠️) - - `Item` **Added** -* `ConductoroneApi.User.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ObjectPermissions` **Added** - - `UserId` **Added** - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementUserBinding.RemoveGrantDuration()`: `response` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBinding` **Removed** (Breaking ⚠️) - - `Binding` **Added** -* `ConductoroneApi.User.Get()`: `response` **Changed** (Breaking ⚠️) - - `UserView` **Added** - - `UserView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.UpdateRequestData()`: - * `request.Request.TaskActionsServiceUpdateRequestDataRequest` **Changed** (Breaking ⚠️) - - `Data` **Changed** - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.UpdateGrantDuration()`: - * `request.Request.TaskActionsServiceUpdateGrantDurationRequest` **Changed** (Breaking ⚠️) - - `Duration` **Changed** - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.SkipStep()`: - * `request.Request.TaskActionsServiceSkipStepRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Restart()`: - * `request.Request.TaskActionsServiceRestartRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Reassign()`: - * `request.Request.TaskActionsServiceReassignRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.ProcessNow()`: - * `request.Request.TaskActionsServiceProcessNowRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.HardReset()`: - * `request.Request.TaskActionsServiceHardResetRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.EscalateToEmergencyAccess()`: - * `request.Request.TaskActionsServiceEscalateToEmergencyAccessRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Deny()`: - * `request.Request.TaskActionsServiceDenyRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Comment()`: - * `request.Request.TaskActionsServiceCommentRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Close()`: - * `request.Request.TaskActionsServiceCloseRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.ApproveWithStepUp()`: - * `request.Request.TaskActionsServiceApproveWithStepUpRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskActions.Approve()`: - * `request.Request.TaskActionsServiceApproveRequest` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Task.Get()`: `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Task.CreateRevokeTask()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Task.CreateOffboardingTask()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Task.CreateGrantTask()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `GrantDuration` **Changed** - - `RequestData` **Changed** - - `Source` **Added** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - - `TaskGrantSource` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `TaskView` **Added** - - `TaskView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskAudit.List()`: - * `request.Request` **Changed** - - `CommentsOnly` **Added** - - `NewestFirst` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AccessRequestOutcome` **Added** - - `AccountLifecycleActionCreated` **Added** - - `AccountLifecycleActionFailed` **Added** - - `ActionInstanceCreated` **Added** - - `ActionInstanceFailed` **Added** - - `ActionInstanceSucceeded` **Added** - - `ActionResult` **Added** - - `ActionSubmitted` **Added** - - `ApprovalAutoAcceptedByPolicy` **Added** - - `ApprovalAutoRejectedByPolicy` **Added** - - `ApprovalInstanceChange` **Added** - - `ApprovalReassigned` **Added** - - `ApprovedAutomatically` **Added** - - `BulkActionError` **Added** - - `CertifyOutcome` **Added** - - `Comment` **Added** - - `ConditionalPolicyExecutionResult` **Added** - - `ConnectorActionsEnd` **Added** - - `ConnectorActionsStart` **Added** - - `CreatedReplacementExtensionGrantTask` **Added** - - `Created` **Changed** (Breaking ⚠️) - - `ExpressionPolicyStepError` **Added** - - `ExternalTicketCreated` **Added** - - `ExternalTicketError` **Added** - - `ExternalTicketProvisionStepResolved` **Added** - - `ExternalTicketTriggered` **Added** - - `FormInstanceChange` **Added** - - `GrantDurationUpdated` **Added** - - `GrantOutcome` **Added** - - `HardReset` **Added** - - `Metadata` **Added** - - `PolicyChanged` **Added** - - `PolicyEvaluationStep` **Added** - - `ProvisionCancelled` **Added** - - `ProvisionError` **Added** - - `ProvisionReassigned` **Added** - - `ReassignedToDelegate` **Added** - - `ReassignmentFallbackToAdmin` **Added** - - `ReassignmentListError` **Added** - - `RequestDefaultsApplied` **Added** - - `RevokeOutcome` **Added** - - `SlaEscalation` **Added** - - `StateChange` **Added** - - `StepSkipped` **Added** - - `StepUpApproval` **Added** - - `TaskAuditAccessRequestOutcome` **Removed** (Breaking ⚠️) - - `TaskAuditAccountLifecycleActionCreated` **Removed** (Breaking ⚠️) - - `TaskAuditAccountLifecycleActionFailed` **Removed** (Breaking ⚠️) - - `TaskAuditActionInstanceCreated` **Removed** (Breaking ⚠️) - - `TaskAuditActionInstanceFailed` **Removed** (Breaking ⚠️) - - `TaskAuditActionInstanceSucceeded` **Removed** (Breaking ⚠️) - - `TaskAuditActionSubmitted` **Removed** (Breaking ⚠️) - - `TaskAuditApprovalAutoAcceptedByPolicy` **Removed** (Breaking ⚠️) - - `TaskAuditApprovalAutoRejectedByPolicy` **Removed** (Breaking ⚠️) - - `TaskAuditApprovalHappenedAutomatically` **Removed** (Breaking ⚠️) - - `TaskAuditApprovalInstanceChange` **Removed** (Breaking ⚠️) - - `TaskAuditBulkActionError` **Removed** (Breaking ⚠️) - - `TaskAuditCertifyOutcome` **Removed** (Breaking ⚠️) - - `TaskAuditComment` **Removed** (Breaking ⚠️) - - `TaskAuditConditionalPolicyExecutionResult` **Removed** (Breaking ⚠️) - - `TaskAuditConnectorActionResult` **Removed** (Breaking ⚠️) - - `TaskAuditCreatedReplacementExtensionGrantTask` **Removed** (Breaking ⚠️) - - `TaskAuditEscalateToEmergencyAccess` **Removed** (Breaking ⚠️) - - `TaskAuditExpressionPolicyStepError` **Removed** (Breaking ⚠️) - - `TaskAuditExternalTicketCreated` **Removed** (Breaking ⚠️) - - `TaskAuditExternalTicketError` **Removed** (Breaking ⚠️) - - `TaskAuditExternalTicketProvisionStepResolved` **Removed** (Breaking ⚠️) - - `TaskAuditExternalTicketTriggered` **Removed** (Breaking ⚠️) - - `TaskAuditFinishedConnectorActions` **Removed** (Breaking ⚠️) - - `TaskAuditFormInstanceChange` **Removed** (Breaking ⚠️) - - `TaskAuditGrantDurationUpdated` **Removed** (Breaking ⚠️) - - `TaskAuditGrantOutcome` **Removed** (Breaking ⚠️) - - `TaskAuditHardReset` **Removed** (Breaking ⚠️) - - `TaskAuditMetaData` **Removed** (Breaking ⚠️) - - `TaskAuditNewTaskCreatedFrom` **Removed** (Breaking ⚠️) - - `TaskAuditNewTask` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyApprovalReassigned` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyChanged` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyEvaluationStep` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyProvisionCancelled` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyProvisionError` **Removed** (Breaking ⚠️) - - `TaskAuditPolicyProvisionReassigned` **Removed** (Breaking ⚠️) - - `TaskAuditReassignedToDelegate` **Removed** (Breaking ⚠️) - - `TaskAuditReassignmentFallbackToAdmin` **Removed** (Breaking ⚠️) - - `TaskAuditReassignmentListError` **Removed** (Breaking ⚠️) - - `TaskAuditRestart` **Removed** (Breaking ⚠️) - - `TaskAuditRevokeOutcome` **Removed** (Breaking ⚠️) - - `TaskAuditSlaEscalation` **Removed** (Breaking ⚠️) - - `TaskAuditStartedConnectorActions` **Removed** (Breaking ⚠️) - - `TaskAuditStateChange` **Removed** (Breaking ⚠️) - - `TaskAuditStepSkipped` **Removed** (Breaking ⚠️) - - `TaskAuditStepUpApproval` **Removed** (Breaking ⚠️) - - `TaskAuditWaitForAnalysisStepSuccess` **Removed** (Breaking ⚠️) - - `TaskAuditWaitForAnalysisStepTimedOut` **Removed** (Breaking ⚠️) - - `TaskAuditWaitForAnalysisStepWaiting` **Removed** (Breaking ⚠️) - - `TaskAuditWaitStepSuccess` **Removed** (Breaking ⚠️) - - `TaskAuditWaitStepTimedOut` **Removed** (Breaking ⚠️) - - `TaskAuditWaitStepUntilTime` **Removed** (Breaking ⚠️) - - `TaskAuditWaitStepWaiting` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookApprovalAttempt` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookApprovalBadResponse` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookApprovalFatalError` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookApprovalSuccess` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookApprovalTriggered` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookAttempt` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookSuccess` **Removed** (Breaking ⚠️) - - `TaskAuditWebhookTriggered` **Removed** (Breaking ⚠️) - - `TaskCreatedFrom` **Added** - - `TaskCreated` **Added** - - `TaskEscalated` **Added** - - `TaskRestarted` **Added** - - `WaitStepAnalysisSuccess` **Added** - - `WaitStepAnalysisTimedOut` **Added** - - `WaitStepAnalysisWaiting` **Added** - - `WaitStepSuccess` **Added** - - `WaitStepTimedOut` **Added** - - `WaitStepUntilTime` **Added** - - `WaitStepWaiting` **Added** - - `WebhookApprovalAttempt` **Added** - - `WebhookApprovalBadResponse` **Added** - - `WebhookApprovalFatalError` **Added** - - `WebhookApprovalSuccess` **Added** - - `WebhookApprovalTriggered` **Added** - - `WebhookAttempt` **Added** - - `WebhookSuccess` **Added** - - `WebhookTriggered` **Added** -* `ConductoroneApi.AppEntitlementUserBinding.ListAppUsersForIdentityWithGrant()`: `response.Bindings[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `DeprovisionAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Export.Update()`: - * `request.Request.ExportServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `Exporter` **Added** - - `Exporter` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Exporter` **Added** - - `Exporter` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Export.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Datasource` **Added** - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ExportToDatasource` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Export.Get()`: `response` **Changed** (Breaking ⚠️) - - `Exporter` **Added** - - `Exporter` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Export.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `Datasource` **Added** - - `ExportToDatasource` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Exporter` **Added** - - `Exporter` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverEvent.List()`: `response.List[].ReceivedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverStream.Update()`: - * `request.Request.SsfReceiverStreamServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `SsfReceiverStream` **Added** - - `SsfReceiverStream` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `SsfReceiverStream` **Added** - - `SsfReceiverStream` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverStream.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `LastErrorAt` **Changed** (Breaking ⚠️) - - `LastVerifiedAt` **Changed** (Breaking ⚠️) - - `OutboundAuthBearer` **Added** - - `OutboundAuthOauth2` **Added** - - `PollInterval` **Changed** (Breaking ⚠️) - - `SsfOutboundAuthBearer` **Removed** (Breaking ⚠️) - - `SsfOutboundAuthOAuth2` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverStream.GetStats()`: `response` **Changed** (Breaking ⚠️) - - `SsfReceiverStreamStats` **Removed** (Breaking ⚠️) - - `Stats` **Added** -* `ConductoroneApi.SsfReceiverStream.Get()`: `response` **Changed** (Breaking ⚠️) - - `SsfReceiverStream` **Added** - - `SsfReceiverStream` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverStream.Create()`: - * `request.Request.PollInterval` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `SsfReceiverStream` **Added** - - `SsfReceiverStream` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SessionSettings.Update()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `SessionSettings` **Added** - - `SessionSettings` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `SessionSettings` **Added** - - `SessionSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SessionSettings.TestSourceIp()`: `response` **Changed** (Breaking ⚠️) - - `Details` **Added** - - `Status` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SessionSettings.Get()`: `response` **Changed** (Breaking ⚠️) - - `SessionSettings` **Added** - - `SessionSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.OnboardingSettings.Get()`: `response` **Changed** (Breaking ⚠️) - - `McpOnboardingGoal` **Added** - - `McpOnboardingStatus` **Added** - - `McpOnboardingTargets` **Added** - - `OnboardingOrgContext` **Removed** (Breaking ⚠️) - - `OrgContext` **Added** -* `ConductoroneApi.UserNotificationSettings.Update()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ChannelSettings` **Added** - - `ChannelSettings` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `UserNotificationSettings` **Added** - - `UserNotificationSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.UserNotificationSettings.Get()`: `response` **Changed** (Breaking ⚠️) - - `UserNotificationSettings` **Added** - - `UserNotificationSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.OrgNotificationSettings.Update()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ChannelSettings` **Added** - - `ChannelSettings` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `OrgNotificationSettings` **Added** - - `OrgNotificationSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.OrgNotificationSettings.Get()`: `response` **Changed** (Breaking ⚠️) - - `OrgNotificationSettings` **Added** - - `OrgNotificationSettings` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TenantEmailProvider.Update()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `EmailProvider` **Added** - - `TenantEmailProvider` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `EmailProvider` **Added** - - `TenantEmailProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TenantEmailProvider.Get()`: `response` **Changed** (Breaking ⚠️) - - `EmailProvider` **Added** - - `TenantEmailProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.OrgDomain.Update()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.OrgDomain.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Contacts.UpdateContacts()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `Contacts` **Added** - - `Contacts` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Contacts` **Added** - - `Contacts` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Contacts.GetContacts()`: `response` **Changed** (Breaking ⚠️) - - `Contacts` **Added** - - `Contacts` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AwsExternalIdSettings.Get()`: `response` **Changed** (Breaking ⚠️) - - `AwsExternalId` **Added** - - `AwsExternalId` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.UpdateCredential()`: - * `request.Request.ServicePrincipalServiceUpdateCredentialRequest` **Changed** (Breaking ⚠️) - - `Credential` **Added** - - `ServicePrincipalCredential` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Credential` **Added** - - `ServicePrincipalCredential` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.Update()`: - * `request.Request.ServicePrincipalServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `ServicePrincipal` **Added** - - `ServicePrincipal` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `ServicePrincipal` **Added** - - `ServicePrincipal` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.ListCredentials()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `ExpiresAt` **Changed** (Breaking ⚠️) - - `LastUsedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Principal.ListBindings()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ServicePrincipalBindingSubject` **Removed** (Breaking ⚠️) - - `Subject` **Added** - * `response.Bindings[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Principal.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `ObjectPermissions` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.GetCredential()`: `response` **Changed** (Breaking ⚠️) - - `Credential` **Added** - - `ServicePrincipalCredential` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.Get()`: `response` **Changed** (Breaking ⚠️) - - `ServicePrincipal` **Added** - - `ServicePrincipal` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.DeleteBinding()`: `request.Request` **Changed** (Breaking ⚠️) - - `ServicePrincipalBindingSubject` **Removed** (Breaking ⚠️) - - `Subject` **Added** -* `ConductoroneApi.Principal.CreateCredential()`: - * `request.Request.ServicePrincipalServiceCreateCredentialRequest.Expires` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `Credential` **Added** - - `ServicePrincipalCredential` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.Create()`: `response` **Changed** (Breaking ⚠️) - - `ServicePrincipal` **Added** - - `ServicePrincipal` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Principal.AddBinding()`: `request.Request` **Changed** (Breaking ⚠️) - - `ServicePrincipalBindingSubject` **Removed** (Breaking ⚠️) - - `Subject` **Added** -* `ConductoroneApi.WorkloadFederation.UpdateTrust()`: - * `request.Request.WorkloadFederationServiceUpdateTrustRequest` **Changed** (Breaking ⚠️) - - `Trust` **Added** - - `WorkloadFederationTrust` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Trust` **Added** - - `WorkloadFederationTrust` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.UpdateProvider()`: - * `request.Request.WorkloadFederationServiceUpdateProviderRequest` **Changed** (Breaking ⚠️) - - `Provider` **Added** - - `WorkloadFederationProvider` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Provider` **Added** - - `WorkloadFederationProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.TestToken()`: `response` **Changed** (Breaking ⚠️) - - `AudienceValidation` **Added** - - `CelEvaluation` **Added** - - `CidrCheck` **Added** - - `IssuerMatch` **Added** - - `JwtDecode` **Added** - - `SignatureValidation` **Added** - - `SubjectValidation` **Added** - - `TestTokenStepResult1` **Removed** (Breaking ⚠️) - - `TestTokenStepResult2` **Removed** (Breaking ⚠️) - - `TestTokenStepResult3` **Removed** (Breaking ⚠️) - - `TestTokenStepResult4` **Removed** (Breaking ⚠️) - - `TestTokenStepResult5` **Removed** (Breaking ⚠️) - - `TestTokenStepResult6` **Removed** (Breaking ⚠️) - - `TestTokenStepResult` **Removed** (Breaking ⚠️) - - `TokenFreshness` **Added** -* `ConductoroneApi.WorkloadFederation.SearchTrusts()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.ListTrusts()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.ListProviders()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Oidc` **Added** - - `Spiffe` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) - - `WellKnownProvider.Enum(wellKnownWorkloadProviderSpiffe)` **Added** -* `ConductoroneApi.WorkloadFederation.GetTrust()`: `response` **Changed** (Breaking ⚠️) - - `Trust` **Added** - - `WorkloadFederationTrust` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.GetProvider()`: `response` **Changed** (Breaking ⚠️) - - `Provider` **Added** - - `WorkloadFederationProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.CreateTrust()`: `response` **Changed** (Breaking ⚠️) - - `Trust` **Added** - - `WorkloadFederationTrust` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WorkloadFederation.CreateProvider()`: - * `request.Request` **Changed** - - `Oidc` **Added** - - `Spiffe` **Added** - - `WellKnownProvider.Enum(wellKnownWorkloadProviderSpiffe)` **Added** - * `response` **Changed** (Breaking ⚠️) - - `Provider` **Added** - - `WorkloadFederationProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.WebhooksSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CallbackTimeout` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.UserSearch.Search()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `UserExpandMask` **Removed** (Breaking ⚠️) - * `response.List[]` **Changed** (Breaking ⚠️) - - `ObjectPermissions` **Added** - - `UserId` **Added** - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TaskSearch.Search()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `CreatedAfter` **Changed** - - `CreatedBefore` **Changed** - - `ExpandMask` **Added** - - `IncludeActedAfter` **Changed** - - `OlderThanDuration` **Changed** - - `OutcomeAfter` **Changed** - - `OutcomeBefore` **Changed** - - `TaskExpandMask` **Removed** (Breaking ⚠️) - - `TaskTypes[].Action` **Added** - - `TaskTypes[].Certify` **Added** - - `TaskTypes[].Finding` **Added** - - `TaskTypes[].Grant` **Added** - - `TaskTypes[].Offboarding` **Added** - - `TaskTypes[].Revoke` **Added** - - `TaskTypes[].TaskTypeAction` **Removed** (Breaking ⚠️) - - `TaskTypes[].TaskTypeCertify` **Removed** (Breaking ⚠️) - - `TaskTypes[].TaskTypeFinding` **Removed** (Breaking ⚠️) - - `TaskTypes[].TaskTypeGrant` **Removed** (Breaking ⚠️) - - `TaskTypes[].TaskTypeOffboarding` **Removed** (Breaking ⚠️) - - `TaskTypes[].TaskTypeRevoke` **Removed** (Breaking ⚠️) - * `response.List[]` **Changed** (Breaking ⚠️) - - `ObjectPermissions` **Added** - - `PrincipalResourcePath` **Added** - - `Task` **Added** - - `Task` **Removed** (Breaking ⚠️) -* `ConductoroneApi.ExportsSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Datasource` **Added** - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ExportToDatasource` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.StepUpTransaction.Search()`: - * `request.Request` **Changed** - - `CreatedAfter` **Changed** - - `CreatedBefore` **Changed** - * `response.List[]` **Changed** (Breaking ⚠️) - - `ApproveTask` **Added** - - `Claims` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `ExpiresAt` **Changed** (Breaking ⚠️) - - `TargetTask` **Removed** (Breaking ⚠️) - - `TargetTest` **Removed** (Breaking ⚠️) - - `Test` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.StepUpTransaction.Get()`: `response` **Changed** (Breaking ⚠️) - - `StepUpTransaction` **Removed** (Breaking ⚠️) - - `Transaction` **Added** -* `ConductoroneApi.StepUpProvider.UpdateSecret()`: `response` **Changed** (Breaking ⚠️) - - `StepUpProvider` **Added** - - `StepUpProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.StepUpProvider.Update()`: - * `request.Request.UpdateStepUpProviderRequest` **Changed** (Breaking ⚠️) - - `StepUpProvider` **Added** - - `StepUpProvider` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `StepUpProvider` **Added** - - `StepUpProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.StepUpProvider.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `LastTestedAt` **Changed** (Breaking ⚠️) - - `Microsoft` **Added** - - `Oauth2` **Added** - - `StepUpMicrosoftSettings` **Removed** (Breaking ⚠️) - - `StepUpOAuth2Settings` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.StepUpProvider.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `LastTestedAt` **Changed** (Breaking ⚠️) - - `Microsoft` **Added** - - `Oauth2` **Added** - - `StepUpMicrosoftSettings` **Removed** (Breaking ⚠️) - - `StepUpOAuth2Settings` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.StepUpProvider.Get()`: `response` **Changed** (Breaking ⚠️) - - `StepUpProvider` **Added** - - `StepUpProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.StepUpProvider.Create()`: +* `ConductoroneApi.AccessReviewTemplate.Create()`: * `request.Request` **Changed** (Breaking ⚠️) - - `Microsoft` **Added** - - `Oauth2` **Added** - - `StepUpMicrosoftSettings` **Removed** (Breaking ⚠️) - - `StepUpOAuth2Settings` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `StepUpProvider` **Added** - - `StepUpProvider` **Removed** (Breaking ⚠️) -* `ConductoroneApi.SsfReceiverEventSearch.Search()`: `response.List[].ReceivedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PaperSecret.SetTextContent()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecret.SearchMySecrets()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AgeSuite` **Added** - - `ContentExpiresAt` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PaperSecret.Revoke()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecret.GetContent()`: `response.CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PaperSecret.GetByShareCode()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecret.Get()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecret.CreateInternal()`: - * `request.Request` **Changed** - - `ExpiresIn` **Changed** - - `RequiredAgeSuite` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AgeSuite` **Added** - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecret.CreateExternal()`: + - `ColumnConfig.OrderedColumns` **Added** + - `RecurrenceRule.Frequency` **Changed** (Breaking ⚠️) + * `response.AccessReviewTemplate` **Changed** + - `ColumnConfig.OrderedColumns` **Added** + - `MsTeamsChannel` **Added** + - `RecurrenceRule.Frequency` **Changed** +* `ConductoroneApi.AccessReviewTemplate.Update()`: + * `request.Request.AccessReviewTemplateServiceUpdateRequest.AccessReviewTemplate` **Changed** (Breaking ⚠️) + - `ColumnConfig.OrderedColumns` **Added** + - `MsTeamsChannel` **Added** + - `RecurrenceRule.Frequency` **Changed** (Breaking ⚠️) + * `response.AccessReviewTemplate` **Changed** + - `ColumnConfig.OrderedColumns` **Added** + - `MsTeamsChannel` **Added** + - `RecurrenceRule.Frequency` **Changed** +* `ConductoroneApi.A2Ui.GetSurfaceProvenance()`: **Added** +* `ConductoroneApi.AccessReviewReport.List()`: **Added** +* `ConductoroneApi.AccessReviewActions.GenerateReport()`: **Added** +* `ConductoroneApi.McpResource.Get()`: **Added** +* `ConductoroneApi.McpResource.List()`: **Added** +* `ConductoroneApi.McpResource.ListHistory()`: **Added** +* `ConductoroneApi.McpResource.Search()`: **Added** +* `ConductoroneApi.McpResource.Update()`: **Added** +* `ConductoroneApi.McpAccessProfile.SearchAccessProfiles()`: **Added** +* `ConductoroneApi.AppEntitlementSearch.SearchReachableResourcesForUser()`: **Added** +* `ConductoroneApi.AppManagedState.Get()`: **Added** +* `ConductoroneApi.AppManagedState.List()`: **Added** +* `ConductoroneApi.AppManagedState.Promote()`: **Added** +* `ConductoroneApi.SsoApplication.BatchDeleteSubjectCompatibility()`: **Added** +* `ConductoroneApi.SsoApplication.BatchImportSubjectCompatibility()`: **Added** +* `ConductoroneApi.SsoApplication.Create()`: **Added** +* `ConductoroneApi.SsoApplication.CreateClient()`: **Added** +* `ConductoroneApi.SsoApplication.Delete()`: **Added** +* `ConductoroneApi.SsoApplication.DeleteClient()`: **Added** +* `ConductoroneApi.SsoApplication.Get()`: **Added** +* `ConductoroneApi.SsoApplication.List()`: **Added** +* `ConductoroneApi.SsoApplication.ListClients()`: **Added** +* `ConductoroneApi.SsoApplication.ListHistory()`: **Added** +* `ConductoroneApi.SsoApplication.ParseSamlServiceProviderMetadata()`: **Added** +* `ConductoroneApi.SsoApplication.RotateClientSecret()`: **Added** +* `ConductoroneApi.SsoApplication.Search()`: **Added** +* `ConductoroneApi.SsoApplication.Update()`: **Added** +* `ConductoroneApi.SsoApplication.UpdateClient()`: **Added** +* `ConductoroneApi.UiConversations.EnsureOnboardingSession()`: **Added** +* `ConductoroneApi.FindingSettings.ListFindingSettings()`: **Added** +* `ConductoroneApi.FindingSettings.UpdateFindingSettings()`: **Added** +* `ConductoroneApi.AppCap.Delete()`: **Added** +* `ConductoroneApi.AppCap.Get()`: **Added** +* `ConductoroneApi.AppCap.List()`: **Added** +* `ConductoroneApi.AppCap.ListHistory()`: **Added** +* `ConductoroneApi.AppCap.SetLimit()`: **Added** +* `ConductoroneApi.AppCap.Suspend()`: **Added** +* `ConductoroneApi.AppCap.Unsuspend()`: **Added** +* `ConductoroneApi.FundAssignment.ClearExtension()`: **Added** +* `ConductoroneApi.FundAssignment.Delete()`: **Added** +* `ConductoroneApi.FundAssignment.Get()`: **Added** +* `ConductoroneApi.FundAssignment.GrantExtension()`: **Added** +* `ConductoroneApi.FundAssignment.ListHistory()`: **Added** +* `ConductoroneApi.FundAssignment.Search()`: **Added** +* `ConductoroneApi.FundAssignment.SetLimit()`: **Added** +* `ConductoroneApi.FundAssignment.Suspend()`: **Added** +* `ConductoroneApi.FundAssignment.Unsuspend()`: **Added** +* `ConductoroneApi.MyFundLimits.Delete()`: **Added** +* `ConductoroneApi.MyFundLimits.List()`: **Added** +* `ConductoroneApi.MyFundLimits.ListHistory()`: **Added** +* `ConductoroneApi.MyFundLimits.Pause()`: **Added** +* `ConductoroneApi.MyFundLimits.Resume()`: **Added** +* `ConductoroneApi.MyFundLimits.SetLimit()`: **Added** +* `ConductoroneApi.FundPolicy.Create()`: **Added** +* `ConductoroneApi.FundPolicy.Delete()`: **Added** +* `ConductoroneApi.FundPolicy.FreezeTenant()`: **Added** +* `ConductoroneApi.FundPolicy.Get()`: **Added** +* `ConductoroneApi.FundPolicy.ListHistory()`: **Added** +* `ConductoroneApi.FundPolicy.SetOrgCeiling()`: **Added** +* `ConductoroneApi.FundPolicy.UnfreezeTenant()`: **Added** +* `ConductoroneApi.FundPolicy.Update()`: **Added** +* `ConductoroneApi.FundRule.Create()`: **Added** +* `ConductoroneApi.FundRule.Delete()`: **Added** +* `ConductoroneApi.FundRule.Get()`: **Added** +* `ConductoroneApi.FundRule.List()`: **Added** +* `ConductoroneApi.FundRule.ListHistory()`: **Added** +* `ConductoroneApi.FundRule.Search()`: **Added** +* `ConductoroneApi.FundRule.Update()`: **Added** +* `ConductoroneApi.GatewayKey.List()`: **Added** +* `ConductoroneApi.GatewayKey.Mint()`: **Added** +* `ConductoroneApi.GatewayKey.Revoke()`: **Added** +* `ConductoroneApi.ProviderCredential.Clear()`: **Added** +* `ConductoroneApi.ProviderCredential.Get()`: **Added** +* `ConductoroneApi.ProviderCredential.Set()`: **Added** +* `ConductoroneApi.Reporting.Delete()`: **Added** +* `ConductoroneApi.Reporting.Get()`: **Added** +* `ConductoroneApi.Reporting.GetRunProvenance()`: **Added** +* `ConductoroneApi.Reporting.List()`: **Added** +* `ConductoroneApi.Reporting.Run()`: **Added** +* `ConductoroneApi.Reporting.Save()`: **Added** +* `ConductoroneApi.Reporting.Update()`: **Added** +* `ConductoroneApi.RoleMiningManagement.EvaluateEntitlementSelection()`: **Added** +* `ConductoroneApi.SsoSettings.Get()`: **Added** +* `ConductoroneApi.SsoSettings.ListHistory()`: **Added** +* `ConductoroneApi.SsoSettings.Update()`: **Added** +* `ConductoroneApi.TaskActions.RetryProvisioning()`: **Added** +* `ConductoroneApi.A2Ui.ListSurfaces()`: `response.Surfaces[].Components[]` **Changed** + - `C1MetricCards` **Added** + - `C1Table` **Added** +* `ConductoroneApi.AccessReview.Create()`: `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added** +* `ConductoroneApi.AccessReview.Get()`: `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added** +* `ConductoroneApi.AccessReview.List()`: `response.List[].AccessReview.ColumnConfig.OrderedColumns` **Added** +* `ConductoroneApi.AccessReview.Update()`: + * `request.Request.AccessReviewServiceUpdateRequest.AccessReview.ColumnConfig.OrderedColumns` **Added** + * `response.AccessReview.AccessReview.ColumnConfig.OrderedColumns` **Added** +* `ConductoroneApi.AccessReviewTemplate.Get()`: `response.AccessReviewTemplate` **Changed** + - `ColumnConfig.OrderedColumns` **Added** + - `MsTeamsChannel` **Added** + - `RecurrenceRule.Frequency` **Changed** +* `ConductoroneApi.AppUser.List()`: `response.List[].AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppUser.ListAppUsersForUser()`: `response.List[].AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppUser.ListOwnedServiceAccounts()`: `response.List[].AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppUser.Search()`: * `request.Request` **Changed** - - `ExpiresIn` **Changed** - - `RequiredAgeSuite` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AgeSuite` **Added** - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecretAdmin.Search()`: + - `AgentStatuses` **Added** + - `NhiTypes` **Added** + * `response.List[].AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppUser.Update()`: `response.AppUserView.AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.Apps.Create()`: + * `request.Request.MatchBatonRef` **Added** + * `response.App.MatchBatonRef` **Added** +* `ConductoroneApi.Apps.Get()`: `response.App.MatchBatonRef` **Added** +* `ConductoroneApi.Apps.List()`: `response.List[].MatchBatonRef` **Added** +* `ConductoroneApi.Apps.Update()`: + * `request.Request.UpdateAppRequest.App.MatchBatonRef` **Added** + * `response.App.MatchBatonRef` **Added** +* `ConductoroneApi.McpTool.Get()`: `response.Tool` **Changed** + - `RequestableViaToolset` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpTool.List()`: `response.Tools[]` **Changed** + - `RequestableViaToolset` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpTool.ListHistory()`: `response.List[].Snapshot` **Changed** + - `RequestableViaToolset` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpTool.Search()`: + * `request.Request.McpToolServiceSearchRequest.IncludeRequestable` **Added** + * `response.List[]` **Changed** + - `RequestableViaToolset` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpTool.Update()`: `response.Tool` **Changed** + - `RequestableViaToolset` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfile.Create()`: `response.Profile` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfile.Get()`: `response.Profile` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfile.GetByAppEntitlementId()`: `response.Profile` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfile.List()`: `response.Profiles[]` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfile.Update()`: `response.Profile` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools()`: `response.AccessProfilesForTools[].AccessProfiles[]` **Changed** + - `ConnectorDisplayName` **Added** + - `Requestable` **Added** +* `ConductoroneApi.AppEntitlements.Create()`: + * `request.Request.CreateAppEntitlementRequest.ProvisionPolicy` **Changed** + - `DevicePlacement` **Added** + - `MultiStep.ProvisionSteps[].DevicePlacement` **Added** + * `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlements.Get()`: `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlements.List()`: * `request.Request` **Changed** - - `CreatedAfter` **Changed** - - `CreatedBefore` **Changed** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AgeSuite` **Added** - - `ContentExpiresAt` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PaperSecretAdmin.Revoke()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.PaperSecretAdmin.Get()`: `response` **Changed** (Breaking ⚠️) - - `PaperSecret` **Removed** (Breaking ⚠️) - - `Secret` **Added** -* `ConductoroneApi.RoleMiningManagementSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Entitlements[].RiskLevelValueId` **Added** - - `LastGeneratedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogSearch.SearchEntitlements()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindings[].CreatedAt` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindings[].DeletedAt` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindings[].DeprovisionAt` **Changed** (Breaking ⚠️) - - `AppEntitlementView` **Removed** (Breaking ⚠️) - - `Entitlement` **Added** -* `ConductoroneApi.PolicySearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) + - `AppUserId` **Added** + - `Q` **Added** + * `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlements.ListForAppResource()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlements.ListForAppUser()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlements.ListUsers()`: `response.List[].AppUser.AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppEntitlements.Update()`: + * `request.Request.UpdateAppEntitlementRequest.Entitlement.DeprovisionerPolicy` **Changed** + - `DevicePlacement` **Added** + - `MultiStep.ProvisionSteps[].DevicePlacement` **Added** + * `response.AppEntitlementView.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementSearch.Search()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired()`: `response.List[].AppUser` **Changed** + - `AgentStatus` **Added** + - `NhiDetail` **Added** + - `NhiType` **Added** +* `ConductoroneApi.AppEntitlementSearch.SearchGrants()`: `response.List[]` **Changed** + - `AppEntitlementUserBinding.AppUser.AppUser.AgentStatus` **Added** + - `AppEntitlementUserBinding.AppUser.AppUser.NhiDetail` **Added** + - `AppEntitlementUserBinding.AppUser.AppUser.NhiType` **Added** + - `Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants()`: `response.List[].History.Id` **Added** +* `ConductoroneApi.McpServer.Get()`: `response.McpServer.EndpointUrlLocked` **Added** +* `ConductoroneApi.McpServer.GetCatalog()`: `response.CatalogEntry` **Changed** + - `AuthModes[].ClientIdMode` **Added** + - `AuthModes[].OptionalScopes` **Added** + - `DefaultToolPrefix` **Added** +* `ConductoroneApi.McpServer.List()`: `response.List[].EndpointUrlLocked` **Added** +* `ConductoroneApi.McpServer.ListCatalog()`: `response.List[]` **Changed** + - `AuthModes[].ClientIdMode` **Added** + - `AuthModes[].OptionalScopes` **Added** + - `DefaultToolPrefix` **Added** +* `ConductoroneApi.McpServer.Register()`: + * `request.Request.McpServerServiceRegisterRequest.AccessProfileIds` **Added** + * `response` **Changed** + - `AccessProfilesAttached` **Added** + - `McpServer.EndpointUrlLocked` **Added** +* `ConductoroneApi.McpServer.SearchWithToolCount()`: `response.List[].McpServer.EndpointUrlLocked` **Added** +* `ConductoroneApi.McpServer.Update()`: `response.McpServer.EndpointUrlLocked` **Added** +* `ConductoroneApi.McpServer.UpdateCredentials()`: `response.McpServer.EndpointUrlLocked` **Added** +* `ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType()`: + * `request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(clawAgent)` **Added** +* `ConductoroneApi.Auth.Introspect()`: `response.DisabledModules` **Added** +* `ConductoroneApi.Automation.CreateAutomation()`: + * `request.Request.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** + * `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.Automation.GetAutomation()`: `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.Automation.ListAutomations()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.Automation.UpdateAutomation()`: + * `request.Request.UpdateAutomationRequest.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** + * `response.Automation.AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.RequestCatalogManagement.Create()`: + * `request.Request.Type` **Added** + * `response.RequestCatalogView.RequestCatalog` **Changed** + - `AccessEntitlements[].DeprovisionerPolicy.DevicePlacement` **Added** + - `Type` **Added** +* `ConductoroneApi.RequestCatalogManagement.Get()`: `response.RequestCatalogView.RequestCatalog` **Changed** + - `AccessEntitlements[].DeprovisionerPolicy.DevicePlacement` **Added** + - `Type` **Added** +* `ConductoroneApi.RequestCatalogManagement.List()`: `response.List[].RequestCatalog` **Changed** + - `AccessEntitlements[].DeprovisionerPolicy.DevicePlacement` **Added** + - `Type` **Added** +* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.RequestCatalogManagement.Update()`: + * `request.Request.RequestCatalogManagementServiceUpdateRequest.Catalog.AccessEntitlements[].DeprovisionerPolicy` **Changed** + - `DevicePlacement` **Added** + - `MultiStep.ProvisionSteps[].DevicePlacement` **Added** + * `response.RequestCatalogView.RequestCatalog` **Changed** + - `AccessEntitlements[].DeprovisionerPolicy.DevicePlacement` **Added** + - `Type` **Added** +* `ConductoroneApi.ConnectorCatalog.ConfigurationSchema()`: `response.FormSchema.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** +* `ConductoroneApi.Finding.BulkCreateFindingTasks()`: + * `request.Request.SearchRequest.FindingTypes[]` **Changed** + - `Enum(findingTypeConnectorSyncFailing)` **Added** + - `Enum(findingTypeCredentialExpiring)` **Added** + - `Enum(findingTypeCredentialPubliclyExposed)` **Added** + - `Enum(findingTypeDeactivatedOwner)` **Added** + - `Enum(findingTypeDecoyPubliclyExposed)` **Added** + - `Enum(findingTypeUnusedSecret)` **Added** +* `ConductoroneApi.Finding.BulkUpdateFindingState()`: `request.Request` **Changed** + - `Reprocess` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeConnectorSyncFailing)` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeCredentialExpiring)` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeCredentialPubliclyExposed)` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeDeactivatedOwner)` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeDecoyPubliclyExposed)` **Added** + - `SearchRequest.FindingTypes[].Enum(findingTypeUnusedSecret)` **Added** +* `ConductoroneApi.Finding.CreateFinding()`: `response.Finding` **Changed** - `Annotations` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Accept` **Added** - - `PolicySteps.Map.Steps[].Accept` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Action` **Added** - - `PolicySteps.Map.Steps[].Action` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Approval` **Added** - - `PolicySteps.Map.Steps[].Approval` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Form` **Added** - - `PolicySteps.Map.Steps[].Form` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Provision` **Added** - - `PolicySteps.Map.Steps[].Provision` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Reject` **Added** - - `PolicySteps.Map.Steps[].Reject` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Wait` **Added** - - `PolicySteps.Map.Steps[].Wait` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PersonalClientSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ExpiresTime` **Changed** (Breaking ⚠️) - - `LastUsedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.ExternalClientSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `LastUsedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.HooksSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `BuiltInPattern` **Removed** (Breaking ⚠️) - - `BuiltinPattern` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Filter` **Added** - - `Function` **Added** - - `HookFilter` **Removed** (Breaking ⚠️) - - `HookFunctionRef` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.FunctionsSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ProvisionedConcurrency` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AutomationSearch.SearchAutomations()`: `response.List[]` **Changed** (Breaking ⚠️) + - `ConnectorSyncFailingEvidence` **Added** + - `ConnectorSyncFailing` **Added** + - `CredentialExpiringEvidence` **Added** + - `CredentialExpiring` **Added** + - `CredentialPubliclyExposedEvidence` **Added** + - `CredentialPubliclyExposed` **Added** + - `DeactivatedOwnerEvidence` **Added** + - `DeactivatedOwner` **Added** + - `DecoyPubliclyExposedEvidence` **Added** + - `DecoyPubliclyExposed` **Added** + - `UnusedSecretEvidence` **Added** + - `UnusedSecret` **Added** +* `ConductoroneApi.Finding.CreateFindingTask()`: `response.Finding` **Changed** - `Annotations` **Added** - - `AutomationContext` **Removed** (Breaking ⚠️) - - `AutomationSteps[].AccountLifecycleAction` **Added** - - `AutomationSteps[].AccountLifecycleAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CallFunction` **Added** - - `AutomationSteps[].CallFunction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorAction` **Added** - - `AutomationSteps[].ConnectorAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorCreateAccount` **Added** - - `AutomationSteps[].ConnectorCreateAccount` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateAccessReview` **Added** - - `AutomationSteps[].CreateAccessReview` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasksV2` **Added** - - `AutomationSteps[].CreateRevokeTasksV2` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasks` **Added** - - `AutomationSteps[].CreateRevokeTasks` **Removed** (Breaking ⚠️) - - `AutomationSteps[].EvaluateExpressions` **Added** - - `AutomationSteps[].EvaluateExpressions` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GeneratePassword` **Added** - - `AutomationSteps[].GeneratePassword` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GrantEntitlements` **Added** - - `AutomationSteps[].GrantEntitlements` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RemoveFromDelegation` **Added** - - `AutomationSteps[].RemoveFromDelegation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RunAutomation` **Added** - - `AutomationSteps[].RunAutomation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendEmail` **Added** - - `AutomationSteps[].SendEmail` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendSlackMessage` **Added** - - `AutomationSteps[].SendSlackMessage` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SetCredential` **Added** - - `AutomationSteps[].SetCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].StoreCredential` **Added** - - `AutomationSteps[].StoreCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].TaskAction` **Added** - - `AutomationSteps[].TaskAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Added** - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UpdateUser` **Added** - - `AutomationSteps[].UpdateUser` **Removed** (Breaking ⚠️) - - `AutomationSteps[].WaitForDuration` **Added** - - `AutomationSteps[].WaitForDuration` **Removed** (Breaking ⚠️) - - `AutomationSteps[].Webhook` **Added** - - `AutomationSteps[].Webhook` **Removed** (Breaking ⚠️) - - `CircuitBreaker` **Added** - - `Context` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DisabledReasonCircuitBreaker` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AccessConflictTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AccessConflict` **Added** - - `DraftTriggers[].AppUserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserCreated` **Added** - - `DraftTriggers[].AppUserUpdatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserUpdated` **Added** - - `DraftTriggers[].GrantDeletedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantDeleted` **Added** - - `DraftTriggers[].GrantFoundTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantFound` **Added** - - `DraftTriggers[].ScheduleAppUser` **Added** - - `DraftTriggers[].ScheduleNoUser` **Added** - - `DraftTriggers[].ScheduleTriggerAppUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTriggerNoUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Schedule` **Added** - - `DraftTriggers[].UsageBasedRevocationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UsageBasedRevocation` **Added** - - `DraftTriggers[].UserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserCreated` **Added** - - `DraftTriggers[].UserProfileChangeTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserProfileChange` **Added** - - `DraftTriggers[].WebhookAutomationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Webhook` **Added** - - `LastExecutedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AutomationSteps[].AccountLifecycleAction` **Added** - - `AutomationSteps[].AccountLifecycleAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CallFunction` **Added** - - `AutomationSteps[].CallFunction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorAction` **Added** - - `AutomationSteps[].ConnectorAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorCreateAccount` **Added** - - `AutomationSteps[].ConnectorCreateAccount` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateAccessReview` **Added** - - `AutomationSteps[].CreateAccessReview` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasksV2` **Added** - - `AutomationSteps[].CreateRevokeTasksV2` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasks` **Added** - - `AutomationSteps[].CreateRevokeTasks` **Removed** (Breaking ⚠️) - - `AutomationSteps[].EvaluateExpressions` **Added** - - `AutomationSteps[].EvaluateExpressions` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GeneratePassword` **Added** - - `AutomationSteps[].GeneratePassword` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GrantEntitlements` **Added** - - `AutomationSteps[].GrantEntitlements` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RemoveFromDelegation` **Added** - - `AutomationSteps[].RemoveFromDelegation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RunAutomation` **Added** - - `AutomationSteps[].RunAutomation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendEmail` **Added** - - `AutomationSteps[].SendEmail` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendSlackMessage` **Added** - - `AutomationSteps[].SendSlackMessage` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SetCredential` **Added** - - `AutomationSteps[].SetCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].StoreCredential` **Added** - - `AutomationSteps[].StoreCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].TaskAction` **Added** - - `AutomationSteps[].TaskAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Added** - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UpdateUser` **Added** - - `AutomationSteps[].UpdateUser` **Removed** (Breaking ⚠️) - - `AutomationSteps[].WaitForDuration` **Added** - - `AutomationSteps[].WaitForDuration` **Removed** (Breaking ⚠️) - - `AutomationSteps[].Webhook` **Added** - - `AutomationSteps[].Webhook` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `Triggers[].AccessConflictTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].AccessConflict` **Added** - - `Triggers[].AppUserCreatedTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].AppUserCreated` **Added** - - `Triggers[].AppUserUpdatedTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].AppUserUpdated` **Added** - - `Triggers[].GrantDeletedTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].GrantDeleted` **Added** - - `Triggers[].GrantFoundTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].GrantFound` **Added** - - `Triggers[].ScheduleAppUser` **Added** - - `Triggers[].ScheduleNoUser` **Added** - - `Triggers[].ScheduleTriggerAppUser` **Removed** (Breaking ⚠️) - - `Triggers[].ScheduleTriggerNoUser` **Removed** (Breaking ⚠️) - - `Triggers[].ScheduleTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].Schedule` **Added** - - `Triggers[].UsageBasedRevocationTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].UsageBasedRevocation` **Added** - - `Triggers[].UserCreatedTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].UserCreated` **Added** - - `Triggers[].UserProfileChangeTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].UserProfileChange` **Added** - - `Triggers[].WebhookAutomationTrigger` **Removed** (Breaking ⚠️) - - `Triggers[].Webhook` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) + - `ConnectorSyncFailingEvidence` **Added** + - `ConnectorSyncFailing` **Added** + - `CredentialExpiringEvidence` **Added** + - `CredentialExpiring` **Added** + - `CredentialPubliclyExposedEvidence` **Added** + - `CredentialPubliclyExposed` **Added** + - `DeactivatedOwnerEvidence` **Added** + - `DeactivatedOwner` **Added** + - `DecoyPubliclyExposedEvidence` **Added** + - `DecoyPubliclyExposed` **Added** + - `UnusedSecretEvidence` **Added** + - `UnusedSecret` **Added** +* `ConductoroneApi.Finding.GetFinding()`: `response.Finding` **Changed** - `Annotations` **Added** - - `AppOwners[].CreatedAt` **Changed** (Breaking ⚠️) - - `AppOwners[].DeletedAt` **Changed** (Breaking ⚠️) - - `AppOwners[].DepartmentSources[].Priority` **Added** - - `AppOwners[].Profile` **Changed** (Breaking ⚠️) - - `AppOwners[].UpdatedAt` **Changed** (Breaking ⚠️) - - `AppUserMapper` **Added** - - `AppUserMapper` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `RevokeGrantSources` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceSearch.SearchAppResources()`: - * `request.Request` **Changed** - - `AgentStatuses` **Added** - - `AppIds` **Added** - - `CredentialTypes` **Added** - - `Direction` **Added** - - `ExcludeDeletedApps` **Added** - - `NhiTypes` **Added** - - `SecretAging` **Added** - - `SortField` **Added** - - `UnownedOnly` **Added** - - `WithOpenFindings` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppResource` **Added** - - `AppResource` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppResourceSearch.SearchAppResourceTypes()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AutomationExecutionSearch.SearchAutomationExecutions()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AutomationExecutionExpandMask` **Removed** (Breaking ⚠️) - - `ExecutionStepStates[].Enum(automationExecutionStatePausedByCircuitBreaker)` **Added** - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AutomationExecution` **Added** - - `AutomationExecution` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AutomationExecutionSearch.SearchAllAutomationExecutions()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AutomationExecutionExpandMask` **Removed** (Breaking ⚠️) - - `ExecutionStates[].Enum(automationExecutionStatePausedByCircuitBreaker)` **Added** - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AutomationExecution` **Added** - - `AutomationExecution` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RoleMiningManagement.UpdateSuggestionState()`: `response` **Changed** (Breaking ⚠️) - - `RoleMiningManagementSuggestion` **Removed** (Breaking ⚠️) - - `Suggestion` **Added** -* `ConductoroneApi.RoleMiningManagement.UpdateRoleMiningConfig()`: `response` **Changed** (Breaking ⚠️) - - `Config` **Added** - - `RoleMiningManagementConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RoleMiningManagement.SearchCohortUsers()`: - * `request.Request.SearchCohortUsersRequest.SelectedEntitlements` **Added** - * `response` **Changed** (Breaking ⚠️) - - `List[].CreatedAt` **Changed** (Breaking ⚠️) - - `List[].DeletedAt` **Changed** (Breaking ⚠️) - - `List[].DepartmentSources[].Priority` **Added** - - `List[].Profile` **Changed** (Breaking ⚠️) - - `List[].UpdatedAt` **Changed** (Breaking ⚠️) - - `UsersWithCoverage` **Added** -* `ConductoroneApi.RoleMiningManagement.ListSuggestions()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Entitlements[].RiskLevelValueId` **Added** - - `LastGeneratedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RoleMiningManagement.ListRuns()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CompletedAt` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RoleMiningManagement.GetSuggestion()`: `response` **Changed** (Breaking ⚠️) - - `RoleMiningManagementSuggestion` **Removed** (Breaking ⚠️) - - `Suggestion` **Added** -* `ConductoroneApi.RoleMiningManagement.GetRoleMiningConfig()`: `response` **Changed** (Breaking ⚠️) - - `Config` **Added** - - `RoleMiningManagementConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RoleMiningManagement.GetLatestRun()`: `response` **Changed** (Breaking ⚠️) - - `RoleMiningManagementRun` **Removed** (Breaking ⚠️) - - `Run` **Added** -* `ConductoroneApi.RequestSchema.Update()`: - * `request.Request.RequestSchemaServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `RequestSchema` **Added** - - `RequestSchema` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `RequestSchema` **Added** - - `RequestSchema` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestSchema.RemoveEntitlementBinding()`: `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementRef` **Removed** (Breaking ⚠️) - - `EntitlementRef` **Added** -* `ConductoroneApi.RequestSchema.Get()`: `response` **Changed** (Breaking ⚠️) - - `RequestSchema` **Added** - - `RequestSchema` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestSchema.FindBindingForAppEntitlement()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementRef` **Removed** (Breaking ⚠️) - - `EntitlementRef` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementRef` **Removed** (Breaking ⚠️) - - `EntitlementRef` **Added** -* `ConductoroneApi.RequestSchema.CreateEntitlementBinding()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementRef` **Removed** (Breaking ⚠️) - - `EntitlementRef` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementRef` **Removed** (Breaking ⚠️) - - `EntitlementRef` **Added** -* `ConductoroneApi.RequestSchema.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `FieldRelationships[].AtLeastOne` **Added** - - `FieldRelationships[].AtLeastOne` **Removed** (Breaking ⚠️) - - `FieldRelationships[].DependentOn` **Added** - - `FieldRelationships[].DependentOn` **Removed** (Breaking ⚠️) - - `FieldRelationships[].MutuallyExclusive` **Added** - - `FieldRelationships[].MutuallyExclusive` **Removed** (Breaking ⚠️) - - `FieldRelationships[].RequiredTogether` **Added** - - `FieldRelationships[].RequiredTogether` **Removed** (Breaking ⚠️) - - `Fields[].AdminConfig` **Added** - - `Fields[].AdminProviderConfig` **Removed** (Breaking ⚠️) - - `Fields[].BoolField` **Added** - - `Fields[].BoolField` **Removed** (Breaking ⚠️) - - `Fields[].FileField` **Added** - - `Fields[].FileField` **Removed** (Breaking ⚠️) - - `Fields[].FormStringField` **Removed** (Breaking ⚠️) - - `Fields[].FormStringMapField` **Removed** (Breaking ⚠️) - - `Fields[].Int64Field` **Added** - - `Fields[].Int64Field` **Removed** (Breaking ⚠️) - - `Fields[].Oauth2Field` **Added** - - `Fields[].Oauth2Field` **Removed** (Breaking ⚠️) - - `Fields[].ReadOnly` **Added** - - `Fields[].SharedConfig` **Added** - - `Fields[].SharedProviderConfig` **Removed** (Breaking ⚠️) - - `Fields[].StringField` **Added** - - `Fields[].StringMapField` **Added** - - `Fields[].StringSliceField` **Added** - - `Fields[].StringSliceField` **Removed** (Breaking ⚠️) - - `Fields[].UserConfig` **Added** - - `Fields[].UserProviderConfig` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `RequestSchema` **Added** - - `RequestSchema` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Policies.Update()`: - * `request.Request.UpdatePolicyRequest` **Changed** (Breaking ⚠️) - - `Policy` **Added** - - `Policy` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Policy` **Added** - - `Policy` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Policies.List()`: `response.List[]` **Changed** (Breaking ⚠️) + - `ConnectorSyncFailingEvidence` **Added** + - `ConnectorSyncFailing` **Added** + - `CredentialExpiringEvidence` **Added** + - `CredentialExpiring` **Added** + - `CredentialPubliclyExposedEvidence` **Added** + - `CredentialPubliclyExposed` **Added** + - `DeactivatedOwnerEvidence` **Added** + - `DeactivatedOwner` **Added** + - `DecoyPubliclyExposedEvidence` **Added** + - `DecoyPubliclyExposed` **Added** + - `UnusedSecretEvidence` **Added** + - `UnusedSecret` **Added** +* `ConductoroneApi.Finding.UpdateFindingState()`: `response.Finding` **Changed** - `Annotations` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Accept` **Added** - - `PolicySteps.Map.Steps[].Accept` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Action` **Added** - - `PolicySteps.Map.Steps[].Action` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Approval` **Added** - - `PolicySteps.Map.Steps[].Approval` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Form` **Added** - - `PolicySteps.Map.Steps[].Form` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Provision` **Added** - - `PolicySteps.Map.Steps[].Provision` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Reject` **Added** - - `PolicySteps.Map.Steps[].Reject` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Wait` **Added** - - `PolicySteps.Map.Steps[].Wait` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Policies.Get()`: `response` **Changed** (Breaking ⚠️) - - `Policy` **Added** - - `Policy` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Policies.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) + - `ConnectorSyncFailingEvidence` **Added** + - `ConnectorSyncFailing` **Added** + - `CredentialExpiringEvidence` **Added** + - `CredentialExpiring` **Added** + - `CredentialPubliclyExposedEvidence` **Added** + - `CredentialPubliclyExposed` **Added** + - `DeactivatedOwnerEvidence` **Added** + - `DeactivatedOwner` **Added** + - `DecoyPubliclyExposedEvidence` **Added** + - `DecoyPubliclyExposed` **Added** + - `UnusedSecretEvidence` **Added** + - `UnusedSecret` **Added** +* `ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule()`: + * `request.Request.RoutingRule` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** + * `response.RoutingRule` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** +* `ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule()`: `response.RoutingRule` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** +* `ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules()`: `response.List[]` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** +* `ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule()`: + * `request.Request.UpdateFindingRoutingRuleRequest.RoutingRule` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** + * `response.RoutingRule` **Changed** + - `Dispatchers` **Added** + - `FindingType` **Added** +* `ConductoroneApi.FindingSearch.Search()`: + * `request.Request.FindingTypes[]` **Changed** + - `Enum(findingTypeConnectorSyncFailing)` **Added** + - `Enum(findingTypeCredentialExpiring)` **Added** + - `Enum(findingTypeCredentialPubliclyExposed)` **Added** + - `Enum(findingTypeDeactivatedOwner)` **Added** + - `Enum(findingTypeDecoyPubliclyExposed)` **Added** + - `Enum(findingTypeUnusedSecret)` **Added** + * `response.List[]` **Changed** - `Annotations` **Added** - - `PolicySteps.Map.Steps[].Accept` **Added** - - `PolicySteps.Map.Steps[].Accept` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Action` **Added** - - `PolicySteps.Map.Steps[].Action` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Approval` **Added** - - `PolicySteps.Map.Steps[].Approval` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Form` **Added** - - `PolicySteps.Map.Steps[].Form` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Provision` **Added** - - `PolicySteps.Map.Steps[].Provision` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Reject` **Added** - - `PolicySteps.Map.Steps[].Reject` **Removed** (Breaking ⚠️) - - `PolicySteps.Map.Steps[].Wait` **Added** - - `PolicySteps.Map.Steps[].Wait` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Policy` **Added** - - `Policy` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalUserInvitation.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AcceptedAt` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `ExpiresAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.Update()`: - * `request.Request.RequestCatalogManagementServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `Catalog` **Added** - - `ExpandMask` **Added** - - `RequestCatalogExpandMask` **Removed** (Breaking ⚠️) - - `RequestCatalog` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `RequestCatalogView` **Added** - - `RequestCatalogView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalUserInvitation.Get()`: `response` **Changed** (Breaking ⚠️) - - `Invitation` **Added** - - `LocalUserInvitation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalUserInvitation.Create()`: `response` **Changed** (Breaking ⚠️) - - `Invitation` **Added** - - `LocalUserInvitation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalDirectoryConfig.Update()`: - * `request.Request.LocalDirectoryConfigServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `LocalDirectoryConfig` **Added** - - `LocalDirectoryConfig` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `LocalDirectoryConfig` **Added** - - `LocalDirectoryConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalDirectoryConfig.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `InvitationTtl` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.LocalDirectoryConfig.Get()`: `response` **Changed** (Breaking ⚠️) - - `LocalDirectoryConfig` **Added** - - `LocalDirectoryConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.LocalDirectoryConfig.Create()`: - * `request.Request.InvitationTtl` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `LocalDirectoryConfig` **Added** - - `LocalDirectoryConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Roles.Update()`: - * `request.Request.UpdateRoleRequest` **Changed** (Breaking ⚠️) - - `Role` **Added** - - `Role` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Role` **Added** - - `Role` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Roles.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Roles.Get()`: `response` **Changed** (Breaking ⚠️) - - `Role` **Added** - - `Role` **Removed** (Breaking ⚠️) -* `ConductoroneApi.PersonalClient.Update()`: - * `request.Request.PersonalClientServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `Client` **Added** - - `PersonalClient` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Client` **Added** - - `PersonalClient` **Removed** (Breaking ⚠️) -* `ConductoroneApi.PersonalClient.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ExpiresTime` **Changed** (Breaking ⚠️) - - `LastUsedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.PersonalClient.Get()`: `response` **Changed** (Breaking ⚠️) - - `Client` **Added** - - `PersonalClient` **Removed** (Breaking ⚠️) -* `ConductoroneApi.PersonalClient.Create()`: - * `request.Request.Expires` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `Client` **Added** - - `PersonalClient` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Hooks.Update()`: - * `request.Request.HooksServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `Hook` **Added** - - `Hook` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Hook` **Added** - - `Hook` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Hooks.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `BuiltInPattern` **Removed** (Breaking ⚠️) - - `BuiltinPattern` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Filter` **Added** - - `Function` **Added** - - `HookFilter` **Removed** (Breaking ⚠️) - - `HookFunctionRef` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Hooks.Get()`: `response` **Changed** (Breaking ⚠️) - - `Hook` **Added** - - `Hook` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Hooks.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `BuiltInPattern` **Removed** (Breaking ⚠️) - - `BuiltinPattern` **Added** - - `Filter` **Added** - - `Function` **Added** - - `HookFilter` **Removed** (Breaking ⚠️) - - `HookFunctionRef` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Hook` **Added** - - `Hook` **Removed** (Breaking ⚠️) -* `ConductoroneApi.FunctionsInvocationSearch.Search()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Input` **Changed** (Breaking ⚠️) - - `Output` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.FunctionsInvocation.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `Input` **Changed** (Breaking ⚠️) - - `Output` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.FunctionsInvocation.Get()`: `response` **Changed** (Breaking ⚠️) - - `FunctionInvocation` **Removed** (Breaking ⚠️) - - `Invocation` **Added** + - `ConnectorSyncFailingEvidence` **Added** + - `ConnectorSyncFailing` **Added** + - `CredentialExpiringEvidence` **Added** + - `CredentialExpiring` **Added** + - `CredentialPubliclyExposedEvidence` **Added** + - `CredentialPubliclyExposed` **Added** + - `DeactivatedOwnerEvidence` **Added** + - `DeactivatedOwner` **Added** + - `DecoyPubliclyExposedEvidence` **Added** + - `DecoyPubliclyExposed` **Added** + - `UnusedSecretEvidence` **Added** + - `UnusedSecret` **Added** +* `ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule()`: + * `request.Request.TransformationRule.FindingType` **Added** + * `response.TransformationRule.FindingType` **Added** +* `ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule()`: `response.TransformationRule.FindingType` **Added** +* `ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules()`: `response.List[].FindingType` **Added** +* `ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule()`: + * `request.Request.UpdateFindingTransformationRuleRequest.TransformationRule.FindingType` **Added** + * `response.TransformationRule.FindingType` **Added** +* `ConductoroneApi.Functions.CreateFunction()`: `response.Function` **Changed** + - `HookRefs` **Added** + - `WorkflowTemplateRefs` **Added** +* `ConductoroneApi.Functions.GetFunction()`: `response.Function` **Changed** + - `HookRefs` **Added** + - `WorkflowTemplateRefs` **Added** +* `ConductoroneApi.Functions.ListFunctions()`: `response.List[]` **Changed** + - `HookRefs` **Added** + - `WorkflowTemplateRefs` **Added** * `ConductoroneApi.Functions.UpdateFunction()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `Function` **Added** - - `Function` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Function` **Added** - - `Function` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Functions.Test()`: `response` **Changed** (Breaking ⚠️) - - `FunctionTestResult` **Removed** (Breaking ⚠️) - - `Result` **Added** -* `ConductoroneApi.Functions.ListTags()`: `response.Tags.Map.CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementUserBinding.SearchGrantFeed()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `After` **Changed** - - `AppEntitlementUserBindingExpandHistoryMask` **Removed** (Breaking ⚠️) - - `Before` **Changed** - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindingFeed` **Removed** (Breaking ⚠️) - - `Feed` **Added** -* `ConductoroneApi.Functions.ListFunctions()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `ProvisionedConcurrency` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Functions.ListCommits()`: `response.List[].CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Functions.GetFunction()`: `response` **Changed** (Breaking ⚠️) - - `Function` **Added** - - `Function` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Functions.GetCommitContent()`: `response` **Changed** (Breaking ⚠️) - - `Commit` **Added** - - `FunctionCommit` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Functions.CreateFunction()`: `response` **Changed** (Breaking ⚠️) - - `Commit` **Added** - - `FunctionCommit` **Removed** (Breaking ⚠️) - - `Function` **Added** - - `Function` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Functions.CreateFinalCommit()`: `response` **Changed** (Breaking ⚠️) + * `request.Request` **Changed** + - `CommitMessage` **Added** + - `Content` **Added** + * `response` **Changed** - `Commit` **Added** - - `FunctionCommit` **Removed** (Breaking ⚠️) -* `ConductoroneApi.FindingSearch.Search()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppResourceIds` **Added** - - `AppResourceTraitIds` **Added** - - `AppResourceTypeIds` **Added** - - `AppUserTypes` **Added** - - `ConnectorIds` **Added** - - `CustomSubTypes` **Added** - - `DecoyIds` **Added** - - `FindingTypes[]` **Changed** (Breaking ⚠️) - - `IncludeUnassigned` **Added** - - `NhiTypes` **Added** - - `OwnerIdentityUserIds` **Added** - - `Refs` **Added** - - `ScopeToAppOwner` **Added** - - `SourceKinds` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppResourceTarget` **Added** - - `AppUserTarget` **Added** - - `AppUserTarget` **Removed** (Breaking ⚠️) - - `AssignedOwner` **Added** - - `ComputedOwner` **Added** - - `ConnectorAnomalyDetectionDisabled` **Added** - - `ConnectorTarget` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `CustomSubType` **Added** - - `Custom` **Added** - - `DecoyCredentialUsed` **Added** - - `DecoyTarget` **Added** - - `DedupKeyParts` **Added** - - `Description` **Added** - - `FindingOwnerRef1` **Removed** (Breaking ⚠️) - - `FindingOwnerRef` **Removed** (Breaking ⚠️) - - `FindingRiskScore` **Removed** (Breaking ⚠️) - - `FirstObservedAt` **Changed** (Breaking ⚠️) - - `IdentityUserTarget` **Added** - - `IdentityUserTarget` **Removed** (Breaking ⚠️) - - `LastAppearedAt` **Added** - - `LastObservedAt` **Changed** (Breaking ⚠️) - - `NhiUnowned` **Added** - - `ResolvedAt` **Changed** (Breaking ⚠️) - - `RiskAcceptanceExpiresAt` **Changed** (Breaking ⚠️) - - `RiskScore` **Added** - - `ServiceAccountMisclassificationEvidence` **Added** - - `ServiceAccountMisclassificationEvidence` **Removed** (Breaking ⚠️) - - `ServiceAccountMisclassificationType` **Removed** (Breaking ⚠️) - - `ServiceAccountMisclassification` **Added** - - `ServiceAccountUnowned` **Added** - - `SimilarUsernameMatchEvidence` **Added** - - `SimilarUsernameMatchEvidence` **Removed** (Breaking ⚠️) - - `SimilarUsernameMatchType` **Removed** (Breaking ⚠️) - - `SimilarUsernameMatch` **Added** - - `SnoozeUntil` **Changed** (Breaking ⚠️) - - `SourceKind` **Added** - - `TenantTarget` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.FindingRoutingRule.UpdateFindingRoutingRule()`: - * `request.Request.UpdateFindingRoutingRuleRequest` **Changed** (Breaking ⚠️) - - `FindingRoutingRule` **Removed** (Breaking ⚠️) - - `RoutingRule` **Added** - * `response` **Changed** (Breaking ⚠️) - - `FindingRoutingRule` **Removed** (Breaking ⚠️) - - `RoutingRule` **Added** -* `ConductoroneApi.FindingRoutingRule.ListFindingRoutingRules()`: `response.List[]` **Changed** (Breaking ⚠️) - - `Action` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `FindingRoutingRuleAction` **Removed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.FindingRoutingRule.GetFindingRoutingRule()`: `response` **Changed** (Breaking ⚠️) - - `FindingRoutingRule` **Removed** (Breaking ⚠️) - - `RoutingRule` **Added** -* `ConductoroneApi.FindingRoutingRule.CreateFindingRoutingRule()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `FindingRoutingRule` **Removed** (Breaking ⚠️) - - `RoutingRule` **Added** - * `response` **Changed** (Breaking ⚠️) - - `FindingRoutingRule` **Removed** (Breaking ⚠️) - - `RoutingRule` **Added** -* `ConductoroneApi.Finding.UpdateFindingState()`: - * `request.Request.UpdateFindingStateRequest` **Changed** (Breaking ⚠️) - - `AcceptRiskAction` **Removed** (Breaking ⚠️) - - `AcceptRisk` **Added** - - `ReopenAction` **Removed** (Breaking ⚠️) - - `Reopen` **Added** - - `ResolveAction` **Removed** (Breaking ⚠️) - - `Resolve` **Added** - - `SnoozeAction` **Removed** (Breaking ⚠️) - - `Snooze` **Added** - - `SuppressStateAction` **Removed** (Breaking ⚠️) - - `Suppress` **Added** - - `UnsuppressAction` **Removed** (Breaking ⚠️) - - `Unsuppress` **Added** - * `response` **Changed** (Breaking ⚠️) - - `Finding` **Added** - - `Finding` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Finding.GetFinding()`: `response` **Changed** (Breaking ⚠️) - - `Finding` **Added** - - `Finding` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Finding.CreateFindingTask()`: `response` **Changed** (Breaking ⚠️) - - `Finding` **Added** - - `Finding` **Removed** (Breaking ⚠️) -* `ConductoroneApi.A2Ui.CreateSurfaceFeedback()`: `response` **Changed** (Breaking ⚠️) - - `A2UiSurfaceFeedback` **Removed** (Breaking ⚠️) - - `Feedback` **Added** -* `ConductoroneApi.A2Ui.ListSurfaceFeedback()`: `response.Feedback[].CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.A2Ui.ListSurfaces()`: `response.Surfaces[]` **Changed** (Breaking ⚠️) - - `Components[].ButtonComponent` **Removed** (Breaking ⚠️) - - `Components[].Button` **Added** - - `Components[].C1Chart` **Added** - - `Components[].C1CodeBlockComponent` **Removed** (Breaking ⚠️) - - `Components[].C1CodeBlock` **Added** - - `Components[].C1ConnectorConfigFormComponent` **Removed** (Breaking ⚠️) - - `Components[].C1ConnectorConfigForm` **Added** - - `Components[].C1ConnectorSyncDetailComponent` **Removed** (Breaking ⚠️) - - `Components[].C1ConnectorSyncDetail` **Added** - - `Components[].C1ConnectorSyncProgressComponent` **Removed** (Breaking ⚠️) - - `Components[].C1ConnectorSyncProgress` **Added** - - `Components[].C1DurationPickerComponent` **Removed** (Breaking ⚠️) - - `Components[].C1DurationPicker` **Added** - - `Components[].C1MsTeamsNotificationsComponent` **Removed** (Breaking ⚠️) - - `Components[].C1MsTeamsNotifications` **Added** - - `Components[].C1OnboardingPlanComponent` **Removed** (Breaking ⚠️) - - `Components[].C1OnboardingPlan` **Added** - - `Components[].C1OnboardingWelcomeComponent` **Removed** (Breaking ⚠️) - - `Components[].C1OnboardingWelcome` **Added** - - `Components[].C1ResourcePickerComponent` **Removed** (Breaking ⚠️) - - `Components[].C1ResourcePicker` **Added** - - `Components[].C1SlackNotificationsComponent` **Removed** (Breaking ⚠️) - - `Components[].C1SlackNotifications` **Added** - - `Components[].C1StatusIndicatorComponent` **Removed** (Breaking ⚠️) - - `Components[].C1StatusIndicator` **Added** - - `Components[].C1TodoListComponent` **Removed** (Breaking ⚠️) - - `Components[].C1TodoList` **Added** - - `Components[].CardComponent` **Removed** (Breaking ⚠️) - - `Components[].Card` **Added** - - `Components[].CheckBoxComponent` **Removed** (Breaking ⚠️) - - `Components[].CheckBox` **Added** - - `Components[].ChoicePickerComponent` **Removed** (Breaking ⚠️) - - `Components[].ChoicePicker` **Added** - - `Components[].ColumnComponent` **Removed** (Breaking ⚠️) - - `Components[].Column` **Added** - - `Components[].DateTimeInputComponent` **Removed** (Breaking ⚠️) - - `Components[].DateTimeInput` **Added** - - `Components[].DividerComponent` **Removed** (Breaking ⚠️) - - `Components[].Divider` **Added** - - `Components[].ProgressBarComponent` **Removed** (Breaking ⚠️) - - `Components[].ProgressBar` **Added** - - `Components[].RowComponent` **Removed** (Breaking ⚠️) - - `Components[].Row` **Added** - - `Components[].SliderComponent` **Removed** (Breaking ⚠️) - - `Components[].Slider` **Added** - - `Components[].TextComponent` **Removed** (Breaking ⚠️) - - `Components[].TextFieldComponent` **Removed** (Breaking ⚠️) - - `Components[].TextField` **Added** - - `Components[].Text` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `Role` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Finding.BulkUpdateFindingState()`: `request.Request` **Changed** (Breaking ⚠️) - - `AcceptRisk` **Added** - - `AssignOwner` **Added** - - `BulkAcceptRiskAction` **Removed** (Breaking ⚠️) - - `BulkAssignOwnerAction` **Removed** (Breaking ⚠️) - - `BulkReopenAction` **Removed** (Breaking ⚠️) - - `BulkSnoozeAction` **Removed** (Breaking ⚠️) - - `BulkSuppressAction` **Removed** (Breaking ⚠️) - - `BulkUnsuppressAction` **Removed** (Breaking ⚠️) - - `FindingSearchRequest` **Removed** (Breaking ⚠️) - - `Reopen` **Added** - - `SearchRequest` **Added** - - `Snooze` **Added** - - `Suppress` **Added** - - `Unsuppress` **Added** -* `ConductoroneApi.AccessReview.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AccessReviewExpandMask` **Removed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `CompletionDate` **Changed** - - `ExpandMask` **Added** - - `NotificationConfig` **Added** - - `NotificationConfig` **Removed** (Breaking ⚠️) - - `ScopeType.Enum(accessReviewScopeTypeByUsers)` **Added** - - `ScopeV2` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewView` **Removed** (Breaking ⚠️) - - `AccessReview` **Added** -* `ConductoroneApi.AccessReview.Get()`: `response` **Changed** (Breaking ⚠️) - - `AccessReviewView` **Removed** (Breaking ⚠️) - - `AccessReview` **Added** -* `ConductoroneApi.AccessReview.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AccessReview` **Added** - - `AccessReview` **Removed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AccessReview.Update()`: - * `request.Request.AccessReviewServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `AccessReviewExpandMask` **Removed** (Breaking ⚠️) - - `AccessReview` **Added** - - `AccessReview` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewView` **Removed** (Breaking ⚠️) - - `AccessReview` **Added** -* `ConductoroneApi.AccessReviewSetupEntitlement.GetCampaignScopeAndEntitlements()`: `response` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `List[].AccessReviewEntitlement` **Added** - - `List[].AccessReviewSetupEntitlement` **Removed** (Breaking ⚠️) - - `ScopeV2` **Added** -* `ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeAndEntitlements()`: - * `request.Request.AccessReviewSetupEntitlementAndScopeServiceSetRequest` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `AccessReviewSetupEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `ScopeV2` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `List[].AccessReviewEntitlement` **Added** - - `List[].AccessReviewSetupEntitlement` **Removed** (Breaking ⚠️) - - `ScopeV2` **Added** -* `ConductoroneApi.AccessReviewSetupEntitlement.SetCampaignScopeByResourceType()`: - * `request.Request.AccessReviewSetScopeByResourceTypeRequest` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `ScopeV2` **Added** -* `ConductoroneApi.AccessReviewTemplate.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AccessReviewColumnConfig` **Removed** (Breaking ⚠️) - - `AccessReviewDuration` **Changed** - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `Annotations` **Added** - - `ColumnConfig` **Added** - - `NotificationConfig` **Added** - - `NotificationConfig` **Removed** (Breaking ⚠️) - - `RecurrenceRule` **Added** - - `RecurrenceRule` **Removed** (Breaking ⚠️) - - `ReviewSignatureConfig` **Removed** (Breaking ⚠️) - - `ReviewerAttributeConfig` **Added** - - `ScopeType.Enum(accessReviewScopeTypeByUsers)` **Added** + - `Function.HookRefs` **Added** + - `Function.WorkflowTemplateRefs` **Added** +* `ConductoroneApi.Hooks.Create()`: + * `request.Request` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** + * `response.Hook` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** +* `ConductoroneApi.Hooks.Get()`: `response.Hook` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** +* `ConductoroneApi.Hooks.List()`: `response.List[]` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** +* `ConductoroneApi.Hooks.Update()`: + * `request.Request.HooksServiceUpdateRequest.Hook` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** + * `response.Hook` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** +* `ConductoroneApi.Policies.Create()`: + * `request.Request` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** - `Scope` **Added** - - `SignatureConfig` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewTemplate` **Added** - - `AccessReviewTemplate` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AccessReviewTemplate.Get()`: `response` **Changed** (Breaking ⚠️) - - `AccessReviewTemplate` **Added** - - `AccessReviewTemplate` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AccessReviewTemplate.Update()`: - * `request.Request.AccessReviewTemplateServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `AccessReviewTemplate` **Added** - - `AccessReviewTemplate` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewTemplate` **Added** - - `AccessReviewTemplate` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.GetScopeAndEntitlements()`: `response` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `List[].AccessReviewTemplateEntitlement` **Added** - - `List[].AccessReviewTemplateSetupEntitlement` **Removed** (Breaking ⚠️) + * `response.Policy` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** - `Scope` **Added** -* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeAndEntitlements()`: - * `request.Request.AccessReviewTemplateSetupEntitlementServiceSetRequest` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `AccessReviewTemplateSetupEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** +* `ConductoroneApi.Policies.Get()`: `response.Policy` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** - `Scope` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) - - `List[].AccessReviewTemplateEntitlement` **Added** - - `List[].AccessReviewTemplateSetupEntitlement` **Removed** (Breaking ⚠️) +* `ConductoroneApi.Policies.List()`: `response.List[]` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** - `Scope` **Added** -* `ConductoroneApi.AccessReviewTemplateSetupEntitlement.SetScopeByResourceType()`: - * `request.Request.AccessReviewTemplateSetScopeByResourceTypeRequest` **Changed** (Breaking ⚠️) - - `AccessReviewScopeV2` **Removed** (Breaking ⚠️) +* `ConductoroneApi.Policies.Update()`: + * `request.Request.UpdatePolicyRequest.Policy` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** - `Scope` **Added** -* `ConductoroneApi.AccessConflict.CreateMonitor()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AccessConflictNotificationConfig` **Removed** (Breaking ⚠️) - - `NotificationConfig` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessConflictNotificationConfig` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `NegateGroupB` **Added** - - `NotificationConfig` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AccessConflict.GetMonitor()`: `response` **Changed** (Breaking ⚠️) - - `AccessConflictNotificationConfig` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `NegateGroupB` **Added** - - `NotificationConfig` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AccessConflict.UpdateMonitor()`: - * `request.Request.ConflictMonitorUpdateRequest` **Changed** (Breaking ⚠️) - - `AccessConflictNotificationConfig` **Removed** (Breaking ⚠️) - - `NegateGroupB` **Added** - - `NotificationConfig` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AccessConflictNotificationConfig` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `NegateGroupB` **Added** - - `NotificationConfig` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementMonitorBinding.CreateAppEntitlementMonitorBinding()`: `response` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementMonitorBinding.GetAppEntitlementMonitorBinding()`: `response` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Apps.Create()`: - * `request.Request.Annotations` **Added** - * `response` **Changed** (Breaking ⚠️) - - `App` **Added** - - `App` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Apps.Get()`: `response` **Changed** (Breaking ⚠️) - - `App` **Added** - - `App` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Apps.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `Annotations` **Added** - - `AppOwners[].CreatedAt` **Changed** (Breaking ⚠️) - - `AppOwners[].DeletedAt` **Changed** (Breaking ⚠️) - - `AppOwners[].DepartmentSources[].Priority` **Added** - - `AppOwners[].Profile` **Changed** (Breaking ⚠️) - - `AppOwners[].UpdatedAt` **Changed** (Breaking ⚠️) - - `AppUserMapper` **Added** - - `AppUserMapper` **Removed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `RevokeGrantSources` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Apps.Update()`: - * `request.Request.UpdateAppRequest` **Changed** (Breaking ⚠️) - - `App` **Added** - - `App` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `App` **Added** - - `App` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.Create()`: - * `request.Request.ConnectorServiceCreateRequest` **Changed** (Breaking ⚠️) - - `Config` **Changed** - - `ConnectorExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `ConnectorView` **Added** - - `ConnectorView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.CreateDelegated()`: - * `request.Request.ConnectorServiceCreateDelegatedRequest` **Changed** (Breaking ⚠️) - - `AppManagedStateBindingRef` **Added** - - `AppManagedStateBindingRef` **Removed** (Breaking ⚠️) - - `ConnectorExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `ConnectorView` **Added** - - `ConnectorView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.Get()`: `response` **Changed** (Breaking ⚠️) - - `ConnectorView` **Added** - - `ConnectorView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.GetCredentials()`: `response` **Changed** (Breaking ⚠️) - - `ConnectorCredential` **Removed** (Breaking ⚠️) - - `Credential` **Added** -* `ConductoroneApi.Connector.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `Connector` **Added** - - `Connector` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.RotateCredential()`: `response` **Changed** (Breaking ⚠️) - - `ConnectorCredential` **Removed** (Breaking ⚠️) - - `Credential` **Added** -* `ConductoroneApi.Connector.Update()`: - * `request.Request.ConnectorServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `ConnectorExpandMask` **Removed** (Breaking ⚠️) - - `Connector` **Added** - - `Connector` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `ConnectorView` **Added** - - `ConnectorView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Connector.UpdateConnectorSchedule()`: - * `request.Request.UpdateConnectorScheduleRequest` **Changed** (Breaking ⚠️) - - `ConnectorScheduleCron` **Removed** (Breaking ⚠️) - - `Cron` **Added** -* `ConductoroneApi.Connector.UpdateDelegated()`: - * `request.Request.ConnectorServiceUpdateDelegatedRequest` **Changed** (Breaking ⚠️) - - `ConnectorExpandMask` **Removed** (Breaking ⚠️) - - `Connector` **Added** - - `Connector` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `ConnectorView` **Added** - - `ConnectorView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppAccessRequestsDefaults.CancelAppAccessRequestsDefaults()`: `response.DurationGrant` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppAccessRequestsDefaults.CreateAppAccessRequestsDefaults()`: - * `request.Request.AppAccessRequestDefaults.DurationGrant` **Changed** - * `response.DurationGrant` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppAccessRequestsDefaults.GetAppAccessRequestsDefaults()`: `response.DurationGrant` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppUser.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppUser` **Added** - - `AppUser` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppUser.ListAppUserCredentials()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `EncryptedData` **Added** - - `EncryptedData` **Removed** (Breaking ⚠️) - - `ExpiresAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppUser.ListAppUsersForUser()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppUser` **Added** - - `AppUser` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppUser.Search()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppIds` **Added** - - `AppUserExpandMask` **Removed** (Breaking ⚠️) - - `ExcludeDeletedApps` **Added** - - `ExpandMask` **Added** - - `SortBy` **Added** - - `WithOpenFindings` **Added** - - `WithoutResponsibleParty` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppUser` **Added** - - `AppUser` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppUser.Update()`: - * `request.Request.AppUserServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `AppUserExpandMask` **Removed** (Breaking ⚠️) - - `AppUser` **Added** - - `AppUser` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppUserView` **Added** - - `AppUserView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.Create()`: - * `request.Request.CreateAppEntitlementRequest` **Changed** (Breaking ⚠️) - - `Annotations` **Added** - - `AppEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `DurationGrant` **Changed** - - `ExpandMask` **Added** - - `ProvisionPolicy` **Added** - - `ProvisionPolicy` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementView` **Added** - - `AppEntitlementView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.CreateAutomation()`: - * `request.Request.CreateAutomationRequest` **Changed** (Breaking ⚠️) - - `AppEntitlementAutomation` **Removed** (Breaking ⚠️) - - `Automation` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementAutomation` **Removed** (Breaking ⚠️) - - `Automation` **Added** -* `ConductoroneApi.AppEntitlements.Get()`: `response` **Changed** (Breaking ⚠️) - - `AppEntitlementView` **Added** - - `AppEntitlementView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.GetAutomation()`: `response.AppEntitlementAutomation` **Changed** (Breaking ⚠️) - - `AppEntitlementAutomationLastRunStatus` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleBasic` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleCel` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleNone` **Removed** (Breaking ⚠️) - - `Basic` **Added** - - `Cel` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `Entitlements` **Added** - - `LastRunStatus` **Added** - - `None` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppEntitlements.ListAutomationExclusions()`: `response.List[]` **Changed** (Breaking ⚠️) - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.ListForAppResource()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppEntitlements.ListForAppUser()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppEntitlements.ListUsers()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlementId` **Added** - - `AppEntitlementUserBindingCreatedAt` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindingDeprovisionAt` **Changed** (Breaking ⚠️) - - `AppId` **Added** - - `AppUserId` **Added** - - `AppUserView` **Removed** (Breaking ⚠️) - - `AppUser` **Added** -* `ConductoroneApi.AppEntitlements.Update()`: - * `request.Request.UpdateAppEntitlementRequest` **Changed** (Breaking ⚠️) - - `AppEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `Entitlement` **Added** - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementView` **Added** - - `AppEntitlementView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlements.UpdateAutomation()`: - * `request.Request.AppEntitlementServiceUpdateAutomationRequest` **Changed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleBasic` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleCel` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleNone` **Removed** (Breaking ⚠️) - - `Basic` **Added** - - `Cel` **Added** - - `Entitlements` **Added** - - `None` **Added** - * `response.AppEntitlementAutomation` **Changed** (Breaking ⚠️) - - `AppEntitlementAutomationLastRunStatus` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleBasic` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleCel` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `AppEntitlementAutomationRuleNone` **Removed** (Breaking ⚠️) - - `Basic` **Added** - - `Cel` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `Entitlements` **Added** - - `LastRunStatus` **Added** - - `None` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementSearch.Search()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `RequestSchemaIds` **Added** - * `response` **Changed** (Breaking ⚠️) - - `Facets` **Added** - - `Facets` **Removed** (Breaking ⚠️) - - `List[].ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `List[].AppEntitlement` **Added** - - `List[].AppEntitlement` **Removed** (Breaking ⚠️) - - `List[].ObjectPermissions` **Added** -* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsForAppUser()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppEntitlementSearch.SearchAppEntitlementsWithExpired()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppUser` **Added** - - `AppUser` **Removed** (Breaking ⚠️) - - `Discovered` **Changed** (Breaking ⚠️) - - `Expired` **Changed** (Breaking ⚠️) - - `GrantReasons[].CreatedAt` **Changed** (Breaking ⚠️) - - `GrantReasons[].DeletedAt` **Changed** (Breaking ⚠️) - - `GrantReasons[].ReasonExpiresAt` **Changed** (Breaking ⚠️) - - `GrantReasons[].UpdatedAt` **Changed** (Breaking ⚠️) - - `User` **Added** - - `User` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementSearch.SearchGrants()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBinding` **Added** - - `AppEntitlementUserView` **Removed** (Breaking ⚠️) - - `AppEntitlementView` **Removed** (Breaking ⚠️) - - `Entitlement` **Added** -* `ConductoroneApi.Finding.BulkCreateFindingTasks()`: `request.Request` **Changed** (Breaking ⚠️) - - `FindingSearchRequest` **Removed** (Breaking ⚠️) - - `SearchRequest` **Added** -* `ConductoroneApi.Directory.Update()`: - * `request.Request.DirectoryServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `All` **Added** - - `CelExpression` **Added** - - `DirectoryAccountFilterAll` **Removed** (Breaking ⚠️) - - `DirectoryAccountFilterCel` **Removed** (Breaking ⚠️) - - `DirectoryExpandMask` **Removed** (Breaking ⚠️) - - `DirectoryMergeConfig` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `MergeConfig` **Added** - * `response` **Changed** (Breaking ⚠️) - - `DirectoryView` **Added** - - `DirectoryView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Directory.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `Directory` **Added** - - `Directory` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementUserBinding.SearchPastGrants()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindingExpandHistoryMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response.List[]` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBindingHistory` **Removed** (Breaking ⚠️) - - `History` **Added** -* `ConductoroneApi.AppEntitlementUserBinding.UpdateGrantDuration()`: - * `request.Request.UpdateGrantDurationRequest.NewDeprovisionAt` **Changed** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementUserBinding` **Removed** (Breaking ⚠️) - - `Binding` **Added** -* `ConductoroneApi.AppEntitlementOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `DepartmentSources[].Priority` **Added** - - `Profile` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `DepartmentSources[].Priority` **Added** - - `Profile` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppReport.List()`: `response.List[].CreatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceType.CreateManuallyManagedResourceType()`: - * `request.Request.CreateManuallyManagedResourceTypeRequest.ResourceType.Enum(sessionPolicy)` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppResourceType` **Added** - - `AppResourceType` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceType.Get()`: `response` **Changed** (Breaking ⚠️) - - `AppResourceTypeView` **Added** - - `AppResourceTypeView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceType.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AppResourceType` **Added** - - `AppResourceType` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceType.UpdateManuallyManagedResourceType()`: - * `request.Request.UpdateManuallyManagedResourceTypeRequest` **Changed** (Breaking ⚠️) - - `AppResourceType` **Added** - - `AppResourceType` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AppResourceType` **Added** - - `AppResourceType` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResource.CreateManuallyManagedAppResource()`: - * `request.Request.CreateManuallyManagedAppResourceRequest.Annotations` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppResource` **Added** - - `AppResource` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResource.Get()`: `response` **Changed** (Breaking ⚠️) - - `AppResourceView` **Added** - - `AppResourceView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResource.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppResource` **Added** - - `AppResource` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.AppResource.Update()`: - * `request.Request.AppResourceServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `AppResourceExpandMask` **Removed** (Breaking ⚠️) - - `AppResource` **Added** - - `AppResource` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppResourceView` **Added** - - `AppResourceView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppResourceOwners.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `DepartmentSources[].Priority` **Added** - - `Profile` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.AppUsageControls.Get()`: `response` **Changed** (Breaking ⚠️) - - `AppUsageControls` **Added** - - `AppUsageControls` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppUsageControls.Update()`: - * `request.Request.UpdateAppUsageControlsRequest` **Changed** (Breaking ⚠️) - - `AppUsageControls` **Added** - - `AppUsageControls` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AppUsageControls` **Added** - - `AppUsageControls` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AppEntitlementsProxy.Create()`: - * `request.Request.CreateAppEntitlementProxyRequest` **Changed** (Breaking ⚠️) - - `AppEntitlementProxyExpandMask` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AppEntitlementProxyView` **Removed** (Breaking ⚠️) - - `AppProxyEntitlementView` **Added** -* `ConductoroneApi.AppEntitlementsProxy.Get()`: `response` **Changed** (Breaking ⚠️) - - `AppEntitlementProxyView` **Removed** (Breaking ⚠️) - - `AppProxyEntitlementView` **Added** -* `ConductoroneApi.Attributes.CreateAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.CreateComplianceFrameworkAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.CreateRiskLevelAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.GetAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.GetComplianceFrameworkAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.GetRiskLevelAttributeValue()`: `response` **Changed** (Breaking ⚠️) - - `AttributeValue` **Removed** (Breaking ⚠️) - - `Value` **Added** -* `ConductoroneApi.Attributes.ListAttributeValues()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Attributes.ListComplianceFrameworks()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Attributes.ListRiskLevels()`: `response.List[]` **Changed** (Breaking ⚠️) - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.TenantAuthConfig.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `AuthConfigC1Local` **Removed** (Breaking ⚠️) - - `AuthConfigGoogle` **Removed** (Breaking ⚠️) - - `AuthConfigJumpCloud` **Removed** (Breaking ⚠️) - - `AuthConfigMicrosoft` **Removed** (Breaking ⚠️) - - `AuthConfigOidc` **Removed** (Breaking ⚠️) - - `AuthConfigOkta` **Removed** (Breaking ⚠️) - - `AuthConfigOneLogin` **Removed** (Breaking ⚠️) - - `AuthConfigPingOne` **Removed** (Breaking ⚠️) - - `C1Local` **Added** - - `DeprecationDeadline` **Changed** - - `Google` **Added** - - `Jumpcloud` **Added** - - `Microsoft` **Added** - - `Oidc` **Added** - - `Okta` **Added** - - `Onelogin` **Added** - - `Pingone` **Added** - * `response` **Changed** (Breaking ⚠️) - - `AuthConfig` **Added** - - `TenantAuthConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TenantAuthConfig.Get()`: `response` **Changed** (Breaking ⚠️) - - `AuthConfig` **Added** - - `TenantAuthConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.TenantAuthConfig.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `AuthConfigC1Local` **Removed** (Breaking ⚠️) - - `AuthConfigGoogle` **Removed** (Breaking ⚠️) - - `AuthConfigJumpCloud` **Removed** (Breaking ⚠️) - - `AuthConfigMicrosoft` **Removed** (Breaking ⚠️) - - `AuthConfigOidc` **Removed** (Breaking ⚠️) - - `AuthConfigOkta` **Removed** (Breaking ⚠️) - - `AuthConfigOneLogin` **Removed** (Breaking ⚠️) - - `AuthConfigPingOne` **Removed** (Breaking ⚠️) - - `C1Local` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeprecationDeadline` **Changed** (Breaking ⚠️) - - `Google` **Added** - - `Jumpcloud` **Added** - - `Microsoft` **Added** - - `Oidc` **Added** - - `Okta` **Added** - - `Onelogin` **Added** - - `Pingone` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.TenantAuthConfig.Update()`: - * `request.Request.TenantAuthConfigServiceUpdateRequest` **Changed** (Breaking ⚠️) - - `AuthConfig` **Added** - - `TenantAuthConfig` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `AuthConfig` **Added** - - `TenantAuthConfig` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Directory.Get()`: `response` **Changed** (Breaking ⚠️) - - `DirectoryView` **Added** - - `DirectoryView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.AutomationExecution.GetAutomationExecution()`: `response` **Changed** (Breaking ⚠️) - - `AutomationExecutionView` **Removed** (Breaking ⚠️) - - `AutomationExecution` **Added** - - `AutomationExecution` **Removed** (Breaking ⚠️) - - `View` **Added** -* `ConductoroneApi.AutomationExecution.ListAutomationExecutions()`: `response.AutomationExecutions[]` **Changed** (Breaking ⚠️) - - `AutomationContext` **Removed** (Breaking ⚠️) - - `CompletedAt` **Changed** (Breaking ⚠️) - - `Context` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `Duration` **Changed** (Breaking ⚠️) - - `State.Enum(automationExecutionStatePausedByCircuitBreaker)` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.Directory.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `All` **Added** - - `CelExpression` **Added** - - `DirectoryAccountFilterAll` **Removed** (Breaking ⚠️) - - `DirectoryAccountFilterCel` **Removed** (Breaking ⚠️) - - `DirectoryExpandMask` **Removed** (Breaking ⚠️) - - `DirectoryMergeConfig` **Removed** (Breaking ⚠️) - - `ExpandMask` **Added** - - `MergeConfig` **Added** - * `response` **Changed** (Breaking ⚠️) - - `DirectoryView` **Added** - - `DirectoryView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Automation.CreateAutomation()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `Annotations` **Added** - - `AutomationContext` **Removed** (Breaking ⚠️) - - `AutomationSteps[].AccountLifecycleAction` **Added** - - `AutomationSteps[].AccountLifecycleAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CallFunction` **Added** - - `AutomationSteps[].CallFunction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorAction` **Added** - - `AutomationSteps[].ConnectorAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorCreateAccount` **Added** - - `AutomationSteps[].ConnectorCreateAccount` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateAccessReview` **Added** - - `AutomationSteps[].CreateAccessReview` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasksV2` **Added** - - `AutomationSteps[].CreateRevokeTasksV2` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasks` **Added** - - `AutomationSteps[].CreateRevokeTasks` **Removed** (Breaking ⚠️) - - `AutomationSteps[].EvaluateExpressions` **Added** - - `AutomationSteps[].EvaluateExpressions` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GeneratePassword` **Added** - - `AutomationSteps[].GeneratePassword` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GrantEntitlements` **Added** - - `AutomationSteps[].GrantEntitlements` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RemoveFromDelegation` **Added** - - `AutomationSteps[].RemoveFromDelegation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RunAutomation` **Added** - - `AutomationSteps[].RunAutomation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendEmail` **Added** - - `AutomationSteps[].SendEmail` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendSlackMessage` **Added** - - `AutomationSteps[].SendSlackMessage` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SetCredential` **Added** - - `AutomationSteps[].SetCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].StoreCredential` **Added** - - `AutomationSteps[].StoreCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].TaskAction` **Added** - - `AutomationSteps[].TaskAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Added** - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UpdateUser` **Added** - - `AutomationSteps[].UpdateUser` **Removed** (Breaking ⚠️) - - `AutomationSteps[].WaitForDuration` **Added** - - `AutomationSteps[].WaitForDuration` **Removed** (Breaking ⚠️) - - `AutomationSteps[].Webhook` **Added** - - `AutomationSteps[].Webhook` **Removed** (Breaking ⚠️) - - `Context` **Added** - - `DraftTriggers[].AccessConflictTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AccessConflict` **Added** - - `DraftTriggers[].AppUserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserCreated` **Added** - - `DraftTriggers[].AppUserUpdatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserUpdated` **Added** - - `DraftTriggers[].GrantDeletedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantDeleted` **Added** - - `DraftTriggers[].GrantFoundTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantFound` **Added** - - `DraftTriggers[].ScheduleAppUser` **Added** - - `DraftTriggers[].ScheduleNoUser` **Added** - - `DraftTriggers[].ScheduleTriggerAppUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTriggerNoUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Schedule` **Added** - - `DraftTriggers[].UsageBasedRevocationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UsageBasedRevocation` **Added** - - `DraftTriggers[].UserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserCreated` **Added** - - `DraftTriggers[].UserProfileChangeTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserProfileChange` **Added** - - `DraftTriggers[].WebhookAutomationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Webhook` **Added** - * `response` **Changed** (Breaking ⚠️) - - `Automation` **Added** - - `Automation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Automation.ExecuteAutomation()`: - * `request.Request.ExecuteAutomationRequest` **Changed** (Breaking ⚠️) - - `AutomationContext` **Removed** (Breaking ⚠️) - - `Context` **Added** -* `ConductoroneApi.Automation.GetAutomation()`: `response` **Changed** (Breaking ⚠️) - - `Automation` **Added** - - `Automation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.Automation.ListAutomations()`: `response.List[]` **Changed** (Breaking ⚠️) - - `Annotations` **Added** - - `AutomationContext` **Removed** (Breaking ⚠️) - - `AutomationSteps[].AccountLifecycleAction` **Added** - - `AutomationSteps[].AccountLifecycleAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CallFunction` **Added** - - `AutomationSteps[].CallFunction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorAction` **Added** - - `AutomationSteps[].ConnectorAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].ConnectorCreateAccount` **Added** - - `AutomationSteps[].ConnectorCreateAccount` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateAccessReview` **Added** - - `AutomationSteps[].CreateAccessReview` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasksV2` **Added** - - `AutomationSteps[].CreateRevokeTasksV2` **Removed** (Breaking ⚠️) - - `AutomationSteps[].CreateRevokeTasks` **Added** - - `AutomationSteps[].CreateRevokeTasks` **Removed** (Breaking ⚠️) - - `AutomationSteps[].EvaluateExpressions` **Added** - - `AutomationSteps[].EvaluateExpressions` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GeneratePassword` **Added** - - `AutomationSteps[].GeneratePassword` **Removed** (Breaking ⚠️) - - `AutomationSteps[].GrantEntitlements` **Added** - - `AutomationSteps[].GrantEntitlements` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RemoveFromDelegation` **Added** - - `AutomationSteps[].RemoveFromDelegation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].RunAutomation` **Added** - - `AutomationSteps[].RunAutomation` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendEmail` **Added** - - `AutomationSteps[].SendEmail` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SendSlackMessage` **Added** - - `AutomationSteps[].SendSlackMessage` **Removed** (Breaking ⚠️) - - `AutomationSteps[].SetCredential` **Added** - - `AutomationSteps[].SetCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].StoreCredential` **Added** - - `AutomationSteps[].StoreCredential` **Removed** (Breaking ⚠️) - - `AutomationSteps[].TaskAction` **Added** - - `AutomationSteps[].TaskAction` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Added** - - `AutomationSteps[].UnenrollFromAllAccessProfiles` **Removed** (Breaking ⚠️) - - `AutomationSteps[].UpdateUser` **Added** - - `AutomationSteps[].UpdateUser` **Removed** (Breaking ⚠️) - - `AutomationSteps[].WaitForDuration` **Added** - - `AutomationSteps[].WaitForDuration` **Removed** (Breaking ⚠️) - - `AutomationSteps[].Webhook` **Added** - - `AutomationSteps[].Webhook` **Removed** (Breaking ⚠️) - - `CircuitBreaker` **Added** - - `Context` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DisabledReasonCircuitBreaker` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AccessConflictTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AccessConflict` **Added** - - `DraftTriggers[].AppUserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserCreated` **Added** - - `DraftTriggers[].AppUserUpdatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].AppUserUpdated` **Added** - - `DraftTriggers[].GrantDeletedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantDeleted` **Added** - - `DraftTriggers[].GrantFoundTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].GrantFound` **Added** - - `DraftTriggers[].ScheduleAppUser` **Added** - - `DraftTriggers[].ScheduleNoUser` **Added** - - `DraftTriggers[].ScheduleTriggerAppUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTriggerNoUser` **Removed** (Breaking ⚠️) - - `DraftTriggers[].ScheduleTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Schedule` **Added** - - `DraftTriggers[].UsageBasedRevocationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UsageBasedRevocation` **Added** - - `DraftTriggers[].UserCreatedTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserCreated` **Added** - - `DraftTriggers[].UserProfileChangeTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].UserProfileChange` **Added** - - `DraftTriggers[].WebhookAutomationTrigger` **Removed** (Breaking ⚠️) - - `DraftTriggers[].Webhook` **Added** - - `LastExecutedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.ConnectorCatalog.ConfigurationSchema()`: `response` **Changed** (Breaking ⚠️) - - `ConfigSchema` **Removed** (Breaking ⚠️) - - `FormSchema` **Added** - - `RequestSchemaForm` **Removed** (Breaking ⚠️) - - `Schema` **Added** -* `ConductoroneApi.Automation.UpdateAutomation()`: - * `request.Request.UpdateAutomationRequest` **Changed** (Breaking ⚠️) - - `Automation` **Added** - - `Automation` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `Automation` **Added** - - `Automation` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.Create()`: - * `request.Request` **Changed** (Breaking ⚠️) - - `Annotations` **Added** - - `ExpandMask` **Added** - - `GrantPolicyId` **Removed** (Breaking ⚠️) - - `RequestCatalogExpandMask` **Removed** (Breaking ⚠️) - * `response` **Changed** (Breaking ⚠️) - - `RequestCatalogView` **Added** - - `RequestCatalogView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.CreateBundleAutomation()`: - * `request.Request.CreateBundleAutomationRequest` **Changed** (Breaking ⚠️) - - `BundleAutomationRuleCel` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `Cel` **Added** - - `EnforceOnSmallProfiles` **Added** - - `Entitlements` **Added** - - `RemovedMembersThresholdPercent` **Added** - * `response` **Changed** (Breaking ⚠️) - - `BundleAutomationCircuitBreaker` **Removed** (Breaking ⚠️) - - `BundleAutomationLastRunState` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleCel` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `Cel` **Added** - - `CircuitBreaker` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `EnforceOnSmallProfiles` **Added** - - `Entitlements` **Added** - - `RemovedMembersThresholdPercent` **Added** - - `State` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.CreateRequestableEntry()`: `response` **Changed** (Breaking ⚠️) - - `RequestableEntry` **Added** - - `RequestableEntry` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.Get()`: `response` **Changed** (Breaking ⚠️) - - `RequestCatalogView` **Added** - - `RequestCatalogView` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.GetBundleAutomation()`: `response` **Changed** (Breaking ⚠️) - - `BundleAutomationCircuitBreaker` **Removed** (Breaking ⚠️) - - `BundleAutomationLastRunState` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleCel` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `Cel` **Added** - - `CircuitBreaker` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `EnforceOnSmallProfiles` **Added** - - `Entitlements` **Added** - - `RemovedMembersThresholdPercent` **Added** - - `State` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.GetRequestableEntry()`: `response` **Changed** (Breaking ⚠️) - - `RequestableEntry` **Added** - - `RequestableEntry` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.List()`: `response.List[]` **Changed** (Breaking ⚠️) - - `RequestCatalog` **Added** - - `RequestCatalog` **Removed** (Breaking ⚠️) -* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsForAccess()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.RequestCatalogManagement.ListEntitlementsPerCatalog()`: `response.List[]` **Changed** (Breaking ⚠️) - - `ActorObjectPermissions` **Removed** (Breaking ⚠️) - - `AppEntitlement` **Added** - - `AppEntitlement` **Removed** (Breaking ⚠️) - - `ObjectPermissions` **Added** -* `ConductoroneApi.RequestCatalogManagement.SetBundleAutomation()`: - * `request.Request.SetBundleAutomationRequest` **Changed** (Breaking ⚠️) - - `BundleAutomationRuleCel` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `Cel` **Added** - - `EnforceOnSmallProfiles` **Added** - - `Entitlements` **Added** - - `RemovedMembersThresholdPercent` **Added** - * `response` **Changed** (Breaking ⚠️) - - `BundleAutomationCircuitBreaker` **Removed** (Breaking ⚠️) - - `BundleAutomationLastRunState` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleCel` **Removed** (Breaking ⚠️) - - `BundleAutomationRuleEntitlement` **Removed** (Breaking ⚠️) - - `Cel` **Added** - - `CircuitBreaker` **Added** - - `CreatedAt` **Changed** (Breaking ⚠️) - - `DeletedAt` **Changed** (Breaking ⚠️) - - `EnforceOnSmallProfiles` **Added** - - `Entitlements` **Added** - - `RemovedMembersThresholdPercent` **Added** - - `State` **Added** - - `UpdatedAt` **Changed** (Breaking ⚠️) -* `ConductoroneApi.SignInPolicy.Delete()`: **Added** -* `ConductoroneApi.Automation.ResolvePausedAutomationExecutions()`: `response.BulkActionId` **Added** -* `ConductoroneApi.Automation.ClearAutomationCircuitBreaker()`: - * `request.Request.ClearAutomationCircuitBreakerRequest` **Changed** - - `Decision` **Added** - - `Reason` **Added** - * `response.BulkActionId` **Added** -* `ConductoroneApi.Auth.Introspect()`: `response` **Changed** - - `DeviceClientId` **Added** - - `TenantId` **Added** -* `ConductoroneApi.AppResourceOwnersV2.Set()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.ReorderAppEntitlementRoutingRules()`: **Added** -* `ConductoroneApi.XaaAccessProfile.GetByAppEntitlementId()`: **Added** -* `ConductoroneApi.A2Ui.SubmitAction()`: - * `request.Request.A2UiServiceSubmitActionRequest.ClientTimestamp` **Changed** -* `ConductoroneApi.UserOwnersV2.Set()`: **Added** -* `ConductoroneApi.UserOwnersV2.SearchUserOwners()`: **Added** -* `ConductoroneApi.UserOwnersV2.SearchEntitlementOwners()`: **Added** -* `ConductoroneApi.UserOwnersV2.DeleteUserOwner()`: **Added** -* `ConductoroneApi.UserOwnersV2.DeleteEntitlementOwner()`: **Added** -* `ConductoroneApi.UserOwnersV2.CreateUserOwner()`: **Added** -* `ConductoroneApi.UserOwnersV2.CreateEntitlementOwner()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.Set()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.SearchUserOwners()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.DeleteUserOwner()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.DeleteEntitlementOwner()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.CreateUserOwner()`: **Added** -* `ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.SearchUserOwners()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.GetUserOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.DeleteUserOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.DeleteEntitlementOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.CreateUserOwner()`: **Added** -* `ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.GetUserOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.DeleteUserOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.DeleteEntitlementOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.CreateUserOwner()`: **Added** -* `ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.GetUserOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.DeleteUserOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.DeleteEntitlementOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.CreateUserOwner()`: **Added** -* `ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner()`: **Added** -* `ConductoroneApi.User.Introspect()`: **Added** -* `ConductoroneApi.TerraformExport.GetSchema()`: **Added** -* `ConductoroneApi.Task.CreateResourceActionTask()`: **Added** -* `ConductoroneApi.Task.CreateActionTask()`: **Added** -* `ConductoroneApi.RequestSettings.Update()`: **Added** -* `ConductoroneApi.RequestSettings.Get()`: **Added** -* `ConductoroneApi.IdentityPolicyTenantDefaults.Update()`: **Added** -* `ConductoroneApi.IdentityPolicyTenantDefaults.Get()`: **Added** -* `ConductoroneApi.UserDeveloperPreferences.Update()`: **Added** -* `ConductoroneApi.UserDeveloperPreferences.Get()`: **Added** -* `ConductoroneApi.XaaSettings.Update()`: **Added** -* `ConductoroneApi.XaaSettings.ListHistory()`: **Added** -* `ConductoroneApi.XaaSettings.Get()`: **Added** -* `ConductoroneApi.AiGovernanceSettings.Update()`: **Added** -* `ConductoroneApi.AiGovernanceSettings.ListHistory()`: **Added** -* `ConductoroneApi.RoleMiningManagement.CreateAccessProfileFromCohort()`: `request.Request` **Changed** - - `CelExpression` **Added** - - `Entitlements[].RiskLevelValueId` **Added** -* `ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult()`: `response.Clusters[].Entitlements[].RiskLevelValueId` **Added** -* `ConductoroneApi.AiGovernanceSettings.GetTenantDefaults()`: **Added** -* `ConductoroneApi.AiGovernanceSettings.Get()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.Update()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.Search()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.ListHistory()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.List()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.Get()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.Delete()`: **Added** -* `ConductoroneApi.XaaClientAudienceMapping.Create()`: **Added** -* `ConductoroneApi.SignInPolicy.Update()`: **Added** -* `ConductoroneApi.SignInPolicy.Search()`: **Added** -* `ConductoroneApi.SignInPolicy.List()`: **Added** -* `ConductoroneApi.SignInPolicy.Get()`: **Added** -* `ConductoroneApi.AppUser.ListOwnedServiceAccounts()`: **Added** -* `ConductoroneApi.McpTool.Delete()`: **Added** -* `ConductoroneApi.SignInPolicy.Create()`: **Added** -* `ConductoroneApi.SessionPolicy.Update()`: **Added** -* `ConductoroneApi.SessionPolicy.UnassignUser()`: **Added** -* `ConductoroneApi.SessionPolicy.UnassignGroup()`: **Added** -* `ConductoroneApi.SessionPolicy.Search()`: **Added** -* `ConductoroneApi.SessionPolicy.ListAssignments()`: **Added** -* `ConductoroneApi.SessionPolicy.List()`: **Added** -* `ConductoroneApi.SessionPolicy.Get()`: **Added** -* `ConductoroneApi.SessionPolicy.Delete()`: **Added** -* `ConductoroneApi.SessionPolicy.Create()`: **Added** -* `ConductoroneApi.SessionPolicy.AssignUser()`: **Added** -* `ConductoroneApi.SessionPolicy.AssignGroup()`: **Added** -* `ConductoroneApi.FindingAudit.Search()`: **Added** -* `ConductoroneApi.RoleMiningManagement.ListCustomAnalysisResults()`: **Added** -* `ConductoroneApi.RecoveryPolicy.Update()`: **Added** -* `ConductoroneApi.RecoveryPolicy.Search()`: **Added** -* `ConductoroneApi.RecoveryPolicy.List()`: **Added** -* `ConductoroneApi.RecoveryPolicy.Get()`: **Added** -* `ConductoroneApi.RecoveryPolicy.Delete()`: **Added** -* `ConductoroneApi.RecoveryPolicy.Create()`: **Added** -* `ConductoroneApi.TunnelCredentials.UpdateBridge()`: **Added** -* `ConductoroneApi.TunnelCredentials.RevokeBridgeCredential()`: **Added** -* `ConductoroneApi.TunnelCredentials.ListBridges()`: **Added** -* `ConductoroneApi.TunnelCredentials.ListBridgeCredentials()`: **Added** -* `ConductoroneApi.TunnelCredentials.ListBridgeAnnouncedServices()`: **Added** -* `ConductoroneApi.TunnelCredentials.GetBridge()`: **Added** -* `ConductoroneApi.TunnelCredentials.DeleteBridge()`: **Added** -* `ConductoroneApi.TunnelCredentials.CreateBridgeCredential()`: **Added** -* `ConductoroneApi.TunnelCredentials.CreateBridge()`: **Added** -* `ConductoroneApi.PersonalDevice.UpdateDevice()`: **Added** -* `ConductoroneApi.PersonalDevice.Search()`: **Added** -* `ConductoroneApi.PersonalDevice.RevokeDeviceClient()`: **Added** -* `ConductoroneApi.PersonalDevice.RevokeDevice()`: **Added** -* `ConductoroneApi.PersonalDevice.ListDeviceClients()`: **Added** -* `ConductoroneApi.PersonalDevice.GetDevice()`: **Added** -* `ConductoroneApi.FindingTransformationRule.UpdateFindingTransformationRule()`: **Added** -* `ConductoroneApi.FindingTransformationRule.ListFindingTransformationRules()`: **Added** -* `ConductoroneApi.FindingTransformationRule.GetFindingTransformationRule()`: **Added** -* `ConductoroneApi.FindingTransformationRule.DeleteFindingTransformationRule()`: **Added** -* `ConductoroneApi.FindingTransformationRule.CreateFindingTransformationRule()`: **Added** -* `ConductoroneApi.Finding.CreateFinding()`: **Added** -* `ConductoroneApi.DecoySearch.Search()`: **Added** -* `ConductoroneApi.Decoy.Update()`: **Added** -* `ConductoroneApi.Decoy.Rotate()`: **Added** -* `ConductoroneApi.Decoy.List()`: **Added** -* `ConductoroneApi.Decoy.Get()`: **Added** -* `ConductoroneApi.Decoy.Delete()`: **Added** -* `ConductoroneApi.Decoy.Create()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.Update()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.Search()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.List()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.Get()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.Delete()`: **Added** -* `ConductoroneApi.CredentialInventoryPolicy.Create()`: **Added** -* `ConductoroneApi.ConnectorAuthoringActivation.RollbackRevision()`: **Added** -* `ConductoroneApi.ConnectorAuthoringActivation.ActivateRevision()`: **Added** -* `ConductoroneApi.XaaScope.Update()`: **Added** -* `ConductoroneApi.XaaScope.Search()`: **Added** -* `ConductoroneApi.XaaScope.ListHistory()`: **Added** -* `ConductoroneApi.XaaScope.List()`: **Added** -* `ConductoroneApi.XaaScope.Get()`: **Added** -* `ConductoroneApi.XaaScope.Delete()`: **Added** -* `ConductoroneApi.XaaScope.Create()`: **Added** -* `ConductoroneApi.XaaResourceServer.Update()`: **Added** -* `ConductoroneApi.XaaResourceServer.Search()`: **Added** -* `ConductoroneApi.OnboardingSettings.Update()`: + * `response.Policy` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** + - `Scope` **Added** +* `ConductoroneApi.RequestSchema.Create()`: + * `request.Request.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** + * `response.RequestSchema.Form.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** +* `ConductoroneApi.RequestSchema.Get()`: `response.RequestSchema.Form.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** +* `ConductoroneApi.RequestSchema.Update()`: + * `request.Request.RequestSchemaServiceUpdateRequest.RequestSchema.Form.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** + * `response.RequestSchema.Form.Fields[].StringField` **Changed** + - `DateField` **Added** + - `PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PickerField.C1UserPicker.UserIds` **Added** +* `ConductoroneApi.RoleMiningManagement.GetCustomAnalysisResult()`: `response.CutoffImpactPoints` **Added** +* `ConductoroneApi.AppSearch.Search()`: `response.List[].MatchBatonRef` **Added** +* `ConductoroneApi.AutomationSearch.SearchAutomationTemplateVersions()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.AutomationSearch.SearchAutomations()`: `response.List[].AutomationSteps[].CreateRevokeTasksV2.GrantSourceFilter` **Added** +* `ConductoroneApi.FindingAudit.Search()`: + * `request.Request.EventTypes[]` **Changed** + - `Enum(findingAuditEventTypeReprocessCompleted)` **Added** + - `Enum(findingAuditEventTypeReprocessRequested)` **Added** + * `response.List[].EventType` **Changed** + - `Enum(findingAuditEventTypeReprocessCompleted)` **Added** + - `Enum(findingAuditEventTypeReprocessRequested)` **Added** +* `ConductoroneApi.FunctionsSearch.Search()`: `response.List[]` **Changed** + - `HookRefs` **Added** + - `WorkflowTemplateRefs` **Added** +* `ConductoroneApi.HooksSearch.Search()`: `response.List[]` **Changed** + - `BuiltinPattern.BlockOutput` **Added** + - `BuiltinPattern.BlockToolCall` **Added** + - `BuiltinPattern.EncodedContentGuard` **Added** + - `BuiltinPattern.LinkFilter` **Added** + - `BuiltinPattern.PreToolBlock` **Added** + - `BuiltinPattern.PromptInjectionScan` **Added** + - `BuiltinPattern.SecretsMasking` **Added** + - `Event.Enum(hookEventTypePreOutput)` **Added** + - `JsonPatch` **Added** + - `ManagedByGuardrails` **Added** +* `ConductoroneApi.ExternalClientSearch.Search()`: `response.List[].ClientIdType.Enum(clientIdTypeApp)` **Added** +* `ConductoroneApi.PolicySearch.Search()`: * `request.Request` **Changed** - - `McpOnboardingGoal` **Added** - - `McpOnboardingStatus` **Added** - - `McpOnboardingTargets` **Added** + - `ScopeAppEntitlementId` **Added** + - `ScopeAppId` **Added** + - `ScopeObjectType` **Added** + - `ScopeSlot` **Added** + - `ScopeView` **Added** + * `response.List[]` **Changed** + - `BaselinePolicyId` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.DateField` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `PolicySteps.Map.Steps[].Form.Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.DevicePlacement` **Added** + - `PolicySteps.Map.Steps[].Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Rules[].PolicyId` **Added** + - `Rules[].StepKey` **Added** + - `Scope` **Added** +* `ConductoroneApi.RequestCatalogSearch.SearchEntitlements()`: `response.List[].Entitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.TaskSearch.Search()`: + * `request.Request.AccountStatuses` **Added** + * `response.List[].Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.UserSearch.Search()`: + * `request.Request.SourceAppIds` **Added** +* `ConductoroneApi.AiGovernanceSettings.Get()`: `response.AiGovernanceSettings.UntrustedJudgeDisable` **Added** +* `ConductoroneApi.AiGovernanceSettings.ListHistory()`: `response.List[].Snapshot.UntrustedJudgeDisable` **Added** +* `ConductoroneApi.AiGovernanceSettings.Update()`: + * `request.Request.AiGovernanceSettings.UntrustedJudgeDisable` **Added** + * `response.AiGovernanceSettings.UntrustedJudgeDisable` **Added** +* `ConductoroneApi.OrgNotificationSettings.Get()`: `response.OrgNotificationSettings.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** +* `ConductoroneApi.OrgNotificationSettings.Update()`: + * `request.Request.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** + * `response.OrgNotificationSettings.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** +* `ConductoroneApi.UserNotificationSettings.Get()`: `response.UserNotificationSettings.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** +* `ConductoroneApi.UserNotificationSettings.Update()`: + * `request.Request.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** + * `response.UserNotificationSettings.ChannelSettings` **Changed** + - `Email.RequestCreated` **Added** + - `Email.System` **Added** + - `Slack.RequestCreated` **Added** + - `Slack.System` **Added** + - `Teams.RequestCreated` **Added** + - `Teams.System` **Added** +* `ConductoroneApi.RequestSettings.Get()`: `response.RequestSettings.MaxBulkEntitlementSelection` **Added** +* `ConductoroneApi.RequestSettings.Update()`: + * `request.Request.RequestSettings.MaxBulkEntitlementSelection` **Added** + * `response.RequestSettings.MaxBulkEntitlementSelection` **Added** +* `ConductoroneApi.Task.CreateActionTask()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.Task.CreateGrantTask()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.Task.CreateOffboardingTask()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.Task.CreateResourceActionTask()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.Task.CreateRevokeTask()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.Task.Get()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskAudit.List()`: + * `request.Request.ExcludeComments` **Added** * `response` **Changed** - - `McpOnboardingGoal` **Added** - - `McpOnboardingStatus` **Added** - - `McpOnboardingTargets` **Added** -* `ConductoroneApi.XaaResourceServer.ListHistory()`: **Added** -* `ConductoroneApi.XaaResourceServer.List()`: **Added** -* `ConductoroneApi.XaaResourceServer.Get()`: **Added** -* `ConductoroneApi.XaaResourceServer.Delete()`: **Added** -* `ConductoroneApi.XaaResourceServer.Create()`: **Added** -* `ConductoroneApi.XaaAccessProfileScopeBinding.Search()`: **Added** -* `ConductoroneApi.XaaAccessProfileScopeBinding.List()`: **Added** -* `ConductoroneApi.XaaAccessProfileScopeBinding.DeleteBindings()`: **Added** -* `ConductoroneApi.XaaAccessProfileScopeBinding.CreateBindings()`: **Added** -* `ConductoroneApi.SystemLog.ListEvents()`: `request.Request` **Changed** - - `Since` **Changed** - - `Until` **Changed** -* `ConductoroneApi.XaaAccessProfile.Update()`: **Added** -* `ConductoroneApi.XaaAccessProfile.Search()`: **Added** -* `ConductoroneApi.XaaAccessProfile.ListHistory()`: **Added** -* `ConductoroneApi.XaaAccessProfile.List()`: **Added** -* `ConductoroneApi.XaaAccessProfile.Get()`: **Added** -* `ConductoroneApi.XaaAccessProfile.Delete()`: **Added** -* `ConductoroneApi.XaaAccessProfile.Create()`: **Added** -* `ConductoroneApi.McpServer.UpdateCredentials()`: **Added** -* `ConductoroneApi.McpServer.Update()`: **Added** -* `ConductoroneApi.McpServer.TestConnection()`: **Added** -* `ConductoroneApi.McpServer.SearchWithToolCount()`: **Added** -* `ConductoroneApi.McpServer.ResyncTools()`: **Added** -* `ConductoroneApi.McpServer.Register()`: **Added** -* `ConductoroneApi.McpServer.ListConnections()`: **Added** -* `ConductoroneApi.McpServer.ListCatalog()`: **Added** -* `ConductoroneApi.McpServer.List()`: **Added** -* `ConductoroneApi.McpServer.GetCatalog()`: **Added** -* `ConductoroneApi.McpServer.Get()`: **Added** -* `ConductoroneApi.McpServer.DiscoverOidcEndpoints()`: **Added** -* `ConductoroneApi.McpServer.Delete()`: **Added** -* `ConductoroneApi.AppEntitlementSearch.SearchGraph()`: **Added** -* `ConductoroneApi.AppEntitlementSearch.CountGrantsForUserByApp()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.UpdateAppEntitlementRoutingRule()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.ListAppEntitlementRoutingRules()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.GetAppEntitlementRoutingRule()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.DeleteAppEntitlementRoutingRule()`: **Added** -* `ConductoroneApi.AppEntitlementRoutingRule.CreateAppEntitlementRoutingRule()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.ListToolsByProfileHistory()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.ListProfilesByToolHistory()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.List()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.GetAccessProfilesForTools()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.DeleteBindings()`: **Added** -* `ConductoroneApi.McpAccessProfileToolBinding.CreateBindings()`: **Added** -* `ConductoroneApi.McpAccessProfile.Update()`: **Added** -* `ConductoroneApi.McpAccessProfile.SearchRequestableConnectors()`: **Added** -* `ConductoroneApi.McpAccessProfile.ListRequestableConnectors()`: **Added** -* `ConductoroneApi.McpAccessProfile.List()`: **Added** -* `ConductoroneApi.McpAccessProfile.GetByAppEntitlementId()`: **Added** -* `ConductoroneApi.McpAccessProfile.Get()`: **Added** -* `ConductoroneApi.McpAccessProfile.Delete()`: **Added** -* `ConductoroneApi.McpAccessProfile.Create()`: **Added** -* `ConductoroneApi.McpTool.Update()`: **Added** -* `ConductoroneApi.McpTool.Search()`: **Added** -* `ConductoroneApi.McpTool.ListHistory()`: **Added** -* `ConductoroneApi.McpTool.List()`: **Added** -* `ConductoroneApi.McpTool.Get()`: **Added** + - `List[].AccountDeleted` **Added** + - `List[].ActionSubmitted.Action.ActionType.Enum(taskActionTypeRetryProvisioning)` **Added** + - `List[].AutomationTriggered` **Added** + - `List[].ConditionalPolicyExecutionResult.ChainDepth` **Added** + - `List[].ConditionalPolicyExecutionResult.OutcomePolicyId` **Added** + - `List[].ConditionalPolicyExecutionResult.PolicyId` **Added** + - `List[].ProvisionEntitlementMergeCompleted` **Added** + - `List[].ProvisionEntitlementMergeTimedOut` **Added** + - `List[].ProvisionWaitingForEntitlementMerge` **Added** + - `List[].WebhookSuccess.Comment` **Added** + - `TotalCount` **Added** +* `ConductoroneApi.TaskActions.Approve()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.ApproveWithStepUp()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.Close()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.Comment()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.Deny()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.EscalateToEmergencyAccess()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.HardReset()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.ProcessNow()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.Reassign()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.Restart()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.SkipStep()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.UpdateGrantDuration()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.TaskActions.UpdateRequestData()`: `response.TaskView.Task` **Changed** + - `Actions[].Enum(taskActionTypeRetryProvisioning)` **Added** + - `Form.Fields[].StringField.DateField` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.ExcludeUserIds` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.IncludeDeactivated` **Added** + - `Form.Fields[].StringField.PickerField.C1UserPicker.UserIds` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.DevicePlacement` **Added** + - `Policy.Current.Provision.Provision.ProvisionPolicy.MultiStep.ProvisionSteps[].DevicePlacement` **Added** + - `Policy.Current.Provision.State.Enum(provisionInstanceStateDevicePlacement)` **Added** + - `Policy.Current.Provision.WaitingOn` **Added** + - `Policy.Policy.BaselinePolicyId` **Added** + - `Policy.Policy.Rules[].PolicyId` **Added** + - `Policy.Policy.Rules[].StepKey` **Added** + - `Policy.Policy.Scope` **Added** +* `ConductoroneApi.ConnectorOwnersV2.CreateEntitlementOwner()`: `response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.ConnectorOwnersV2.GetEntitlementOwner()`: `response.ConnectorOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.ConnectorOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementOwnersV2.CreateEntitlementOwner()`: `response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementOwnersV2.GetEntitlementOwner()`: `response.AppEntitlementOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppEntitlementOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppOwnersV2.CreateEntitlementOwner()`: `response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppOwnersV2.GetEntitlementOwner()`: `response.AppOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppResourceOwnersV2.CreateEntitlementOwner()`: `response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppResourceOwnersV2.GetEntitlementOwner()`: `response.AppResourceOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppResourceOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppUserOwnersV2.CreateEntitlementOwner()`: `response.AppUserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.AppUserOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.UserOwnersV2.CreateEntitlementOwner()`: `response.UserOwnerEntitlement.AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** +* `ConductoroneApi.UserOwnersV2.SearchEntitlementOwners()`: `response.List[].AppEntitlement.DeprovisionerPolicy.DevicePlacement` **Added** diff --git a/.speakeasy/logs/changes/new.openapi.yaml b/.speakeasy/logs/changes/new.openapi.yaml index cdbbfc6b9..1de602309 100644 --- a/.speakeasy/logs/changes/new.openapi.yaml +++ b/.speakeasy/logs/changes/new.openapi.yaml @@ -31,6 +31,8 @@ components: - c1OnboardingPlan - c1ConnectorSyncDetail - c1Chart + - c1MetricCards + - c1Table properties: button: oneOf: @@ -60,6 +62,10 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1DurationPickerComponent' - type: "null" + c1MetricCards: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1MetricCardsComponent' + - type: "null" c1MsTeamsNotifications: oneOf: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1MSTeamsNotificationsComponent' @@ -84,6 +90,10 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1StatusIndicatorComponent' - type: "null" + c1Table: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1TableComponent' + - type: "null" c1TodoList: oneOf: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1TodoListComponent' @@ -142,6 +152,175 @@ components: title: A 2 Ui Component type: object x-speakeasy-name-override: A2UIComponent + c1.api.a2ui.v1.A2UIProvenanceObject: + description: A2UIProvenanceObject names one record a step referred to by id. + properties: + displayName: + description: |- + Empty when the record's type has no name to resolve, or the record is + gone. The id then stands alone rather than the whole row being dropped. + type: string + id: + description: The id field. + type: string + recordType: + description: |- + Not always the step's own type: a step over grants can be narrowed to one + app, and the app is the record worth naming. + enum: + - A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED + - A2UI_PROVENANCE_RECORD_TYPE_APP + - A2UI_PROVENANCE_RECORD_TYPE_USER + - A2UI_PROVENANCE_RECORD_TYPE_GRANT + - A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT + - A2UI_PROVENANCE_RECORD_TYPE_APP_USER + - A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE + - A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE + - A2UI_PROVENANCE_RECORD_TYPE_TASK + - A2UI_PROVENANCE_RECORD_TYPE_POLICY + - A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION + - A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION + - A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG + - A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK + - A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY + - A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE + - A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP + - A2UI_PROVENANCE_RECORD_TYPE_FINDING + - A2UI_PROVENANCE_RECORD_TYPE_METRIC + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION + - A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY + - A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON + - A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER + type: string + x-speakeasy-unknown-values: allow + title: A 2 Ui Provenance Object + type: object + x-speakeasy-name-override: A2UIProvenanceObject + c1.api.a2ui.v1.A2UIProvenanceSource: + description: |- + A2UIProvenanceSource is one self-reported source from a reporting component: + what a chart or table says it was drawn from, and how many rows fed it. + properties: + componentId: + description: The componentId field. + type: string + count: + description: The count field. + format: int64 + type: string + kind: + description: The kind field. + type: string + label: + description: The label field. + type: string + matchedToolCall: + deprecated: true + description: 'Deprecated: always empty. See verified.' + type: string + ref: + description: The ref field. + type: string + verified: + deprecated: true + description: |- + Deprecated: always false. Superseded by + A2UIServiceGetSurfaceProvenanceResponse.steps, which reports what the + program did rather than judging it. + type: boolean + title: A 2 Ui Provenance Source + type: object + x-speakeasy-name-override: A2UIProvenanceSource + c1.api.a2ui.v1.A2UIProvenanceStep: + description: |- + A2UIProvenanceStep is one thing the report's program did. Steps are returned + in the order the program performs them. + properties: + objects: + description: |- + The specific records this step named. Empty when the step names none, and + withheld wholesale when step_objects_visible is false. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceObject' + type: + - array + - "null" + operation: + description: The operation field. + enum: + - A2UI_PROVENANCE_OPERATION_UNSPECIFIED + - A2UI_PROVENANCE_OPERATION_LOOKED_UP + - A2UI_PROVENANCE_OPERATION_COUNTED + - A2UI_PROVENANCE_OPERATION_FETCHED_RECORD + - A2UI_PROVENANCE_OPERATION_SEARCHED + - A2UI_PROVENANCE_OPERATION_READ_TREND + - A2UI_PROVENANCE_OPERATION_CREATED + - A2UI_PROVENANCE_OPERATION_UPDATED + - A2UI_PROVENANCE_OPERATION_DELETED + - A2UI_PROVENANCE_OPERATION_RAN_PROGRAM + - A2UI_PROVENANCE_OPERATION_BUILT_REPORT + type: string + x-speakeasy-unknown-values: allow + recordType: + description: The recordType field. + enum: + - A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED + - A2UI_PROVENANCE_RECORD_TYPE_APP + - A2UI_PROVENANCE_RECORD_TYPE_USER + - A2UI_PROVENANCE_RECORD_TYPE_GRANT + - A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT + - A2UI_PROVENANCE_RECORD_TYPE_APP_USER + - A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE + - A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE + - A2UI_PROVENANCE_RECORD_TYPE_TASK + - A2UI_PROVENANCE_RECORD_TYPE_POLICY + - A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION + - A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR + - A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION + - A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG + - A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK + - A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY + - A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE + - A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP + - A2UI_PROVENANCE_RECORD_TYPE_FINDING + - A2UI_PROVENANCE_RECORD_TYPE_METRIC + - A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION + - A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY + - A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON + - A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER + type: string + x-speakeasy-unknown-values: allow + title: A 2 Ui Provenance Step + type: object + x-speakeasy-name-override: A2UIProvenanceStep + c1.api.a2ui.v1.A2UIProvenanceToolCall: + description: A2UIProvenanceToolCall is one tool call extracted from the transcript. + properties: + calledAt: + format: date-time + type: + - string + - "null" + inputDigest: + description: Leading characters of the tool input, whitespace-collapsed. + type: string + toolName: + description: The toolName field. + type: string + title: A 2 Ui Provenance Tool Call + type: object + x-speakeasy-name-override: A2UIProvenanceToolCall c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackRequestInput: description: A2UIServiceCreateSurfaceFeedbackRequest creates feedback for a surface. properties: @@ -172,6 +351,80 @@ components: title: A 2 Ui Service Create Surface Feedback Response type: object x-speakeasy-name-override: A2UIServiceCreateSurfaceFeedbackResponse + c1.api.a2ui.v1.A2UIServiceGetSurfaceProvenanceResponse: + description: |- + A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built + from: the steps its program ran, and the sources its components report. + properties: + programCommitId: + description: |- + The program's identity: code mode invokes by explicit commit, so the commit + — not the function — is what a refresh re-executes. + type: string + programFunctionId: + description: |- + The program that produced a reporting surface. Flat rather than a nested + ref: these five fields are read together by one drawer and nothing else, + and a saved report's ProgramRef is the type worth converging on later. + All empty for a surface carrying no report components, and for reports + emitted before the report-program requirement was enabled for the tenant. + type: string + programInput: + description: |- + The JSON parameters the program ran with. Empty when the invocation has aged + out of retention. + type: string + programInvocationId: + description: The run that produced this surface. + type: string + programSource: + description: |- + The program's source, read from the pinned commit. Empty when the commit has + aged out of code-mode retention — the report still renders, but what + produced it is no longer recoverable. + type: string + sources: + description: The sources field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceSource' + type: + - array + - "null" + stepObjectsVisible: + description: |- + Whether the caller may see the ids each step named. False withholds every + A2UIProvenanceStep.objects on the same boundary that withholds + program_source: those ids are the program's parameters by another name. + type: boolean + steps: + description: Everything the surface's program did, in the order it does it. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceStep' + type: + - array + - "null" + stepsAvailable: + description: |- + False when neither the pinned program nor the conversation transcript could + be read, so no record of what was looked at survives. Distinguishes that + from a record that was read and genuinely contains no steps. + type: boolean + toolCalls: + deprecated: true + description: |- + Deprecated: raw tool names, superseded by steps. Still populated for + clients on the previous shape. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceToolCall' + type: + - array + - "null" + transcriptAvailable: + description: False when the backing session or its transcript steps are gone. + type: boolean + title: A 2 Ui Service Get Surface Provenance Response + type: object + x-speakeasy-name-override: A2UIServiceGetSurfaceProvenanceResponse c1.api.a2ui.v1.A2UIServiceListSurfaceFeedbackResponse: description: A2UIServiceListSurfaceFeedbackResponse returns feedback for a surface. properties: @@ -692,6 +945,63 @@ components: title: C 1 Ms Teams Notifications Component type: object x-speakeasy-name-override: C1MSTeamsNotificationsComponent + c1.api.a2ui.v1.C1MetricCard: + description: |- + C1MetricCard is one aggregate stat: label, formatted value, optional delta + and sparkline trend. + properties: + delta: + description: The delta field. + type: string + deltaSentiment: + description: The deltaSentiment field. + enum: + - C1_METRIC_DELTA_SENTIMENT_UNSPECIFIED + - C1_METRIC_DELTA_SENTIMENT_POSITIVE + - C1_METRIC_DELTA_SENTIMENT_NEGATIVE + - C1_METRIC_DELTA_SENTIMENT_NEUTRAL + type: string + x-speakeasy-unknown-values: allow + label: + description: The label field. + type: string + sparkline: + description: Optional trend values, oldest first. Bounds double as NaN/Inf rejection. + items: + type: number + type: + - array + - "null" + value: + description: The value field. + type: string + title: C 1 Metric Card + type: object + x-speakeasy-name-override: C1MetricCard + c1.api.a2ui.v1.C1MetricCardsComponent: + description: C1MetricCardsComponent renders a row of aggregate stat cards. + properties: + cards: + description: The cards field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1MetricCard' + type: + - array + - "null" + sources: + description: 'Provenance: the queries the producing function ran.' + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartSource' + type: + - array + - "null" + title: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + title: C 1 Metric Cards Component + type: object + x-speakeasy-name-override: C1MetricCardsComponent c1.api.a2ui.v1.C1OnboardingPlanCategory: description: C1OnboardingPlanCategory groups related plan steps under a section heading. properties: @@ -821,6 +1131,66 @@ components: title: C 1 Status Indicator Component type: object x-speakeasy-name-override: C1StatusIndicatorComponent + c1.api.a2ui.v1.C1TableComponent: + description: |- + C1TableComponent renders a tabular view: typed columns + rows, capped and + paginated client-side; the full data set lives behind the artifact link. + properties: + artifactUrl: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + columns: + description: The columns field. + items: + type: string + type: + - array + - "null" + pageSize: + description: Rows per page for client-side pagination; 0 shows all rows on one page. + format: int32 + type: integer + rows: + description: The rows field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1TableRow' + type: + - array + - "null" + sources: + description: 'Provenance: the queries the producing function ran.' + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartSource' + type: + - array + - "null" + title: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + totalRows: + description: Full count when rows are truncated. + format: int64 + type: string + title: C 1 Table Component + type: object + x-speakeasy-name-override: C1TableComponent + c1.api.a2ui.v1.C1TableRow: + description: |- + C1TableRow is one row; cells align 1:1 with columns (enforced at the + parse boundary). + properties: + cells: + description: The cells field. + items: + type: string + type: + - array + - "null" + title: C 1 Table Row + type: object + x-speakeasy-name-override: C1TableRow c1.api.a2ui.v1.C1TodoItem: description: The C1TodoItem message. properties: @@ -1788,13 +2158,42 @@ components: type: object x-speakeasy-entity: Access Review x-speakeasy-name-override: AccessReview + c1.api.accessreview.v1.AccessReviewActionsServiceGenerateReportRequestInput: + description: The AccessReviewActionsServiceGenerateReportRequest message. + properties: + format: + description: |- + Output format for the report. When unspecified, programmatic public-API + callers (REST gateway and MCP) get JSON and the in-app UI gets XLSX. JSON + and CSV return the per-decision certification rows; XLSX returns the full + multi-sheet Excel workbook. + enum: + - ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED + - ACCESS_REVIEW_REPORT_FORMAT_XLSX + - ACCESS_REVIEW_REPORT_FORMAT_JSON + - ACCESS_REVIEW_REPORT_FORMAT_CSV + type: string + x-speakeasy-unknown-values: allow + reportColumnConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewReportColumnConfig' + - type: "null" + title: Access Review Actions Service Generate Report Request + type: object + x-speakeasy-name-override: AccessReviewActionsServiceGenerateReportRequest + c1.api.accessreview.v1.AccessReviewActionsServiceGenerateReportResponse: + description: The AccessReviewActionsServiceGenerateReportResponse message. + title: Access Review Actions Service Generate Report Response + type: object + x-speakeasy-name-override: AccessReviewActionsServiceGenerateReportResponse c1.api.accessreview.v1.AccessReviewColumnConfig: description: Configuration for which columns are visible in the reviewer task list. properties: columns: + deprecated: true description: |- - Ordered list of columns visible to reviewers. - If empty, the default column set for the campaign's default_view is used. + Deprecated: use `ordered_columns`, which can also include app user + attribute columns. items: enum: - ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED @@ -1833,6 +2232,16 @@ components: type: - array - "null" + orderedColumns: + description: |- + Ordered columns visible to reviewers, built-ins and attributes + interleaved. Falls back to `columns`, then to the default set for the + campaign's default_view. + items: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTaskColumnRef' + type: + - array + - "null" title: Access Review Column Config type: object x-speakeasy-name-override: AccessReviewColumnConfig @@ -1948,6 +2357,115 @@ components: title: Access Review Inclusion Scope type: object x-speakeasy-name-override: AccessReviewInclusionScope + c1.api.accessreview.v1.AccessReviewReport: + description: The AccessReviewReport message. + properties: + accessReviewId: + description: The accessReviewId field. + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + downloadUrl: + description: The downloadUrl field. + type: string + format: + description: Output format of the generated file (XLSX / JSON / CSV). + enum: + - ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED + - ACCESS_REVIEW_REPORT_FORMAT_XLSX + - ACCESS_REVIEW_REPORT_FORMAT_JSON + - ACCESS_REVIEW_REPORT_FORMAT_CSV + type: string + x-speakeasy-unknown-values: allow + hashes: + additionalProperties: + type: string + description: The hashes field. + type: object + id: + description: The id field. + type: string + state: + description: The state field. + enum: + - REPORT_STATE_UNSPECIFIED + - REPORT_STATE_PENDING + - REPORT_STATE_OK + - REPORT_STATE_ERROR + type: string + x-speakeasy-unknown-values: allow + title: Access Review Report + type: object + x-speakeasy-name-override: AccessReviewReport + c1.api.accessreview.v1.AccessReviewReportColumnConfig: + description: Configuration for columns in the generated access review Excel report. + properties: + columns: + description: |- + Ordered list of columns to include in the report's "Access Reviews" sheet. + When non-empty, the report renders exactly these columns in the order given. + When empty, the default column set is used (the original 19 columns without + Employee ID or other user-attribute extras). + items: + enum: + - ACCESS_REVIEW_REPORT_COLUMN_UNSPECIFIED + - ACCESS_REVIEW_REPORT_COLUMN_EMPLOYEE_ID + - ACCESS_REVIEW_REPORT_COLUMN_JOB_TITLE + - ACCESS_REVIEW_REPORT_COLUMN_DEPARTMENT + - ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_STATUS + - ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_TYPE + - ACCESS_REVIEW_REPORT_COLUMN_MANAGER + - ACCESS_REVIEW_REPORT_COLUMN_TASK + - ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT + - ACCESS_REVIEW_REPORT_COLUMN_USER_NAME + - ACCESS_REVIEW_REPORT_COLUMN_IDENTITY_TYPE + - ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER + - ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER_EMAIL + - ACCESS_REVIEW_REPORT_COLUMN_APPLICATION + - ACCESS_REVIEW_REPORT_COLUMN_RESOURCE + - ACCESS_REVIEW_REPORT_COLUMN_RESOURCE_TYPE + - ACCESS_REVIEW_REPORT_COLUMN_ENTITLEMENT + - ACCESS_REVIEW_REPORT_COLUMN_DESCRIPTION + - ACCESS_REVIEW_REPORT_COLUMN_CERTIFICATION_POLICY + - ACCESS_REVIEW_REPORT_COLUMN_ASSIGNED_TO + - ACCESS_REVIEW_REPORT_COLUMN_REASSIGNMENTS + - ACCESS_REVIEW_REPORT_COLUMN_CERTIFIERS + - ACCESS_REVIEW_REPORT_COLUMN_DECISIONS + - ACCESS_REVIEW_REPORT_COLUMN_RESOLVED_ON + - ACCESS_REVIEW_REPORT_COLUMN_COMMENTS + - ACCESS_REVIEW_REPORT_COLUMN_LAST_LOGIN + - ACCESS_REVIEW_REPORT_COLUMN_SUBMISSIONS + - ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET + - ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET_STATUS + - ACCESS_REVIEW_REPORT_COLUMN_SUBJECT_USERNAME + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Access Review Report Column Config + type: object + x-speakeasy-name-override: AccessReviewReportColumnConfig + c1.api.accessreview.v1.AccessReviewReportServiceListResponse: + description: The AccessReviewReportServiceListResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewReport' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Access Review Report Service List Response + type: object + x-speakeasy-name-override: AccessReviewReportServiceListResponse c1.api.accessreview.v1.AccessReviewScope: description: The AccessReviewScope message. properties: @@ -2454,6 +2972,69 @@ components: title: Access Review Setup Entitlement View type: object x-speakeasy-name-override: AccessReviewSetupEntitlementView + c1.api.accessreview.v1.AccessReviewTaskColumnRef: + description: | + One column in the reviewer task list: a built-in column, or an app user + profile attribute. An attribute only renders for apps whose + reviewer_attribute_config permits it — that config is the authorization, + this is the view preference. + + This message contains a oneof named column. Only a single field of the following list may be set at a time: + - builtin + - appUserAttributeKey + properties: + appUserAttributeKey: + description: |- + The appUserAttributeKey field. + This field is part of the `column` oneof. + See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. + type: + - string + - "null" + builtin: + description: |- + The builtin field. + This field is part of the `column` oneof. + See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. + enum: + - ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED + - ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK + - ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE + - ACCESS_REVIEW_TASK_COLUMN_ACCOUNT + - ACCESS_REVIEW_TASK_COLUMN_ACCOUNT_OWNER + - ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT + - ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT_DESCRIPTION + - ACCESS_REVIEW_TASK_COLUMN_RESOURCE + - ACCESS_REVIEW_TASK_COLUMN_RESOURCE_TYPE + - ACCESS_REVIEW_TASK_COLUMN_INSIGHTS + - ACCESS_REVIEW_TASK_COLUMN_RECOMMENDATION + - ACCESS_REVIEW_TASK_COLUMN_ASSIGNED_TO + - ACCESS_REVIEW_TASK_COLUMN_STATUS + - ACCESS_REVIEW_TASK_COLUMN_APP + - ACCESS_REVIEW_TASK_COLUMN_DUE + - ACCESS_REVIEW_TASK_COLUMN_PROJECT + - ACCESS_REVIEW_TASK_COLUMN_CREATED_ON + - ACCESS_REVIEW_TASK_COLUMN_TASK_AGE + - ACCESS_REVIEW_TASK_COLUMN_RESOLVED_ON + - ACCESS_REVIEW_TASK_COLUMN_ENROLLMENT_STATUS + - ACCESS_REVIEW_TASK_COLUMN_INHERITED_FROM + - ACCESS_REVIEW_TASK_COLUMN_DEPARTMENT + - ACCESS_REVIEW_TASK_COLUMN_JOB_TITLE + - ACCESS_REVIEW_TASK_COLUMN_CREATED_BY + - ACCESS_REVIEW_TASK_COLUMN_LAST_LOGIN + - ACCESS_REVIEW_TASK_COLUMN_RESOURCE_PARENT + - ACCESS_REVIEW_TASK_COLUMN_RESOURCE_CHILDREN + - ACCESS_REVIEW_TASK_COLUMN_APP_USER_USERNAME + - ACCESS_REVIEW_TASK_COLUMN_ACCESS_HOLDER_TYPE + - ACCESS_REVIEW_TASK_COLUMN_RISK_LEVEL + - ACCESS_REVIEW_TASK_COLUMN_COMPLIANCE_FRAMEWORK + type: + - string + - "null" + x-speakeasy-unknown-values: allow + title: Access Review Task Column Ref + type: object + x-speakeasy-name-override: AccessReviewTaskColumnRef c1.api.accessreview.v1.AccessReviewTemplate: description: | A reusable template that defines the configuration for creating access review campaigns. @@ -2461,6 +3042,7 @@ components: This message contains a oneof named slack_channel_details. Only a single field of the following list may be set at a time: - slackChannel + - msTeamsChannel properties: accessReviewDuration: format: duration @@ -2559,6 +3141,10 @@ components: isCampaignScheduleEnabled: description: Whether automatic campaign creation on the recurrence schedule is enabled. type: boolean + msTeamsChannel: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.MSTeamsChannel' + - type: "null" nextScheduledCampaignAt: format: date-time type: @@ -3265,6 +3851,18 @@ components: title: Included User Attribute Values type: object x-speakeasy-name-override: IncludedUserAttributeValues + c1.api.accessreview.v1.MSTeamsChannel: + description: The MSTeamsChannel message. + properties: + channelName: + description: The channelName field. + type: string + externalDirectoryId: + description: The externalDirectoryId field. + type: string + title: Ms Teams Channel + type: object + x-speakeasy-name-override: MSTeamsChannel c1.api.accessreview.v1.MultiAppEntitlement: description: The MultiAppEntitlement message. properties: @@ -3326,7 +3924,9 @@ components: - string - "null" frequency: - description: The frequency field. + description: |- + Frequency of the recurrence: FREQUENCY_DAILY, FREQUENCY_WEEKLY, FREQUENCY_MONTHLY, or FREQUENCY_YEARLY. + Use FREQUENCY_NONE for a non-recurring schedule. enum: - FREQUENCY_UNSPECIFIED - FREQUENCY_NONE @@ -3354,6 +3954,8 @@ components: type: - string - "null" + required: + - frequency title: Recurrence Rule type: object x-speakeasy-name-override: RecurrenceRule @@ -3634,6 +4236,14 @@ components: access-request ticket and returns a request_created envelope instead of executing. Defaults to true. type: boolean + untrustedJudgeDisable: + description: |- + When true, the A2 (untrusted-content) judge is skipped and the untrusted + dimension always scores LOW. When false (the default), the judge scores + agent turn input and tool output for prompt-injection risk on every turn. + + Defaults to false, so the judge runs by default. + type: boolean updatedAt: format: date-time type: @@ -3724,6 +4334,14 @@ components: appId: description: App identifier (app that owns the connector). type: string + connectorDisplayName: + description: |- + Display name of the connector this toolset belongs to. Computed read-only; + populated on every read. The + auto-maintained default toolsets share a display name across connectors, so + this is what tells two of them apart. + readOnly: true + type: string connectorId: description: Connector identifier. type: string @@ -3746,6 +4364,12 @@ components: id: description: Unique identifier for this access profile. type: string + requestable: + description: |- + Whether this toolset's backing entitlement is exposed in at least one + request catalog (i.e. can be requested). Computed read-only; populated on List. + readOnly: true + type: boolean toolCount: description: The number of tools currently bound to this profile. format: int32 @@ -3841,6 +4465,24 @@ components: title: Mcp Access Profile Service List Response type: object x-speakeasy-name-override: MCPAccessProfileServiceListResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceSearchAccessProfilesResponse: + description: |- + MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of + tenant-wide MCP access profiles. + properties: + nextPageToken: + description: Token for next page. + type: string + profiles: + description: The page of matching MCP access profiles. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + type: + - array + - "null" + title: Mcp Access Profile Service Search Access Profiles Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceSearchAccessProfilesResponse c1.api.ai_governance.v1.MCPAccessProfileServiceSearchRequestableConnectorsResponse: description: |- MCPAccessProfileServiceSearchRequestableConnectorsResponse returns one page @@ -4175,6 +4817,264 @@ components: title: Mcp Connection View type: object x-speakeasy-name-override: MCPConnectionView + c1.api.ai_governance.v1.MCPResource: + description: MCPResource represents metadata about an individual resource discovered from an MCP server. + properties: + appEntitlementId: + description: Bound AppEntitlement created during sync. + type: string + appId: + description: App identifier (app that owns the connector). + type: string + connectorId: + description: Connector identifier. + type: string + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + description: + description: Description from the MCP resource spec. + type: string + discoveryHash: + description: Hash of resource definition for change detection. + type: string + entitlementActive: + description: |- + Whether the bound app entitlement exists and is not deleted. Computed + read-only; populated on Search only when the request had + include_grant_status = true; ignored on write. + readOnly: true + type: boolean + grantCount: + description: |- + Number of active grants on the bound app entitlement. Computed read-only; + populated on Search only when the request had include_grant_status = true; + ignored on write. + format: int64 + readOnly: true + type: string + id: + description: Unique identifier for this MCP resource record. + type: string + kind: + description: Whether this is a static resource or a URI template. + enum: + - MCP_RESOURCE_KIND_UNSPECIFIED + - MCP_RESOURCE_KIND_STATIC + - MCP_RESOURCE_KIND_TEMPLATE + type: string + x-speakeasy-unknown-values: allow + lastDiscoveredAt: + format: date-time + type: + - string + - "null" + mimeType: + description: MIME type of the resource content, when known. + type: string + name: + description: Native MCP resource name (unique within an MCP server). + type: string + state: + description: Resource approval/lifecycle state. + enum: + - MCP_RESOURCE_STATE_UNSPECIFIED + - MCP_RESOURCE_STATE_PENDING_REVIEW + - MCP_RESOURCE_STATE_APPROVED + - MCP_RESOURCE_STATE_DISABLED + - MCP_RESOURCE_STATE_REMOVED + type: string + x-speakeasy-unknown-values: allow + title: + description: Human-readable title from the MCP resource spec. + type: string + updatedAt: + format: date-time + type: + - string + - "null" + uri: + description: Raw resource URI from MCP discovery (set for STATIC resources). + type: string + uriTemplate: + description: Raw RFC 6570 URI template from MCP discovery (set for TEMPLATE resources). + type: string + title: Mcp Resource + type: object + x-speakeasy-name-override: MCPResource + c1.api.ai_governance.v1.MCPResourceHistoryEntry: + description: MCPResourceHistoryEntry is one version of an MCP resource and its history metadata. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + - type: "null" + title: Mcp Resource History Entry + type: object + x-speakeasy-name-override: MCPResourceHistoryEntry + c1.api.ai_governance.v1.MCPResourceServiceGetResponse: + description: MCPResourceServiceGetResponse returns a single MCP resource. + properties: + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + - type: "null" + title: Mcp Resource Service Get Response + type: object + x-speakeasy-name-override: MCPResourceServiceGetResponse + c1.api.ai_governance.v1.MCPResourceServiceListHistoryResponse: + description: MCPResourceServiceListHistoryResponse returns MCP resource history entries. + properties: + list: + description: The page of history entries, newest first. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: Mcp Resource Service List History Response + type: object + x-speakeasy-name-override: MCPResourceServiceListHistoryResponse + c1.api.ai_governance.v1.MCPResourceServiceListResponse: + description: MCPResourceServiceListResponse returns a list of MCP resources. + properties: + nextPageToken: + description: Token for next page. + type: string + resources: + description: List of MCP resources. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + type: + - array + - "null" + title: Mcp Resource Service List Response + type: object + x-speakeasy-name-override: MCPResourceServiceListResponse + c1.api.ai_governance.v1.MCPResourceServiceSearchRequestInput: + description: MCPResourceServiceSearchRequest searches MCP resources with filters. + properties: + includeGrantStatus: + description: |- + When true, the server populates the computed entitlement_active and + grant_count fields on each returned row (an extra batched entitlement + lookup per page). Off by default so callers that don't render grant + status don't pay for it. + type: boolean + kindFilter: + description: Optional filter by resource kind. An empty list means no filter. + items: + enum: + - MCP_RESOURCE_KIND_UNSPECIFIED + - MCP_RESOURCE_KIND_STATIC + - MCP_RESOURCE_KIND_TEMPLATE + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: Page size (max 100). + format: int32 + type: integer + pageToken: + description: Page token for pagination. + type: string + query: + description: Optional text query matched against name, title, description, and uri. + type: string + sortBy: + description: Sort order for results. UNSPECIFIED sorts by resource name ascending. + enum: + - MCP_RESOURCE_SORT_BY_UNSPECIFIED + - MCP_RESOURCE_SORT_BY_NAME + - MCP_RESOURCE_SORT_BY_URI + - MCP_RESOURCE_SORT_BY_STATE + - MCP_RESOURCE_SORT_BY_UPDATED_AT + type: string + x-speakeasy-unknown-values: allow + sortDirection: + description: Direction for sort_by. UNSPECIFIED means ascending. + enum: + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC + type: string + x-speakeasy-unknown-values: allow + stateFilter: + description: |- + Optional filter by resource state. An empty list defaults to + PENDING_REVIEW, APPROVED, and DISABLED (REMOVED is hidden unless + explicitly requested). + items: + enum: + - MCP_RESOURCE_STATE_UNSPECIFIED + - MCP_RESOURCE_STATE_PENDING_REVIEW + - MCP_RESOURCE_STATE_APPROVED + - MCP_RESOURCE_STATE_DISABLED + - MCP_RESOURCE_STATE_REMOVED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Mcp Resource Service Search Request + type: object + x-speakeasy-name-override: MCPResourceServiceSearchRequest + c1.api.ai_governance.v1.MCPResourceServiceSearchResponse: + description: MCPResourceServiceSearchResponse returns matching MCP resources. + properties: + list: + description: Matching MCP resources. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + type: + - array + - "null" + nextPageToken: + description: Token for next page. + type: string + title: Mcp Resource Service Search Response + type: object + x-speakeasy-name-override: MCPResourceServiceSearchResponse + c1.api.ai_governance.v1.MCPResourceServiceUpdateRequestInput: + description: MCPResourceServiceUpdateRequest updates an existing MCP resource. + properties: + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + - type: "null" + updateMask: + type: + - string + - "null" + title: Mcp Resource Service Update Request + type: object + x-speakeasy-name-override: MCPResourceServiceUpdateRequest + c1.api.ai_governance.v1.MCPResourceServiceUpdateResponse: + description: MCPResourceServiceUpdateResponse returns the updated MCP resource. + properties: + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResource' + - type: "null" + title: Mcp Resource Service Update Response + type: object + x-speakeasy-name-override: MCPResourceServiceUpdateResponse c1.api.ai_governance.v1.MCPServerAuthAWSSigV4: description: |- MCPServerAuthAWSSigV4 provides AWS Signature Version 4 authentication. @@ -4430,6 +5330,17 @@ components: authorizeUrl: description: OAuth2 authorization endpoint URL. Empty for non-OAuth2 methods. type: string + clientIdMode: + description: |- + How the OAuth2 client_id is acquired for this mode. Set by the impl bundle + and shown read-only on the form. authorization_code grant only. + enum: + - MCP_SERVER_CATALOG_CLIENT_ID_MODE_UNSPECIFIED + - MCP_SERVER_CATALOG_CLIENT_ID_MODE_MANUAL + - MCP_SERVER_CATALOG_CLIENT_ID_MODE_DCR + - MCP_SERVER_CATALOG_CLIENT_ID_MODE_CIMD + type: string + x-speakeasy-unknown-values: allow credentialUrl: description: |- Documentation URL where the user can obtain a credential for this method @@ -4473,6 +5384,15 @@ components: Raw bundle string: "client_credentials", "authorization_code", "jwt_bearer", "google_service_account", or empty (infer from authorize_url). type: string + optionalScopes: + description: |- + Optional (opt-in) OAuth2 scopes from the config's optional_scopes. + Disjoint from `scopes` and not pre-selected. Empty for non-OAuth2 methods. + items: + type: string + type: + - array + - "null" passthrough: description: |- Per-user OAuth: each user authorizes individually instead of sharing a @@ -4597,6 +5517,14 @@ components: deprecated: true description: 'Deprecated: read the OAUTH2 entry''s token_url from auth_modes instead.' type: string + defaultToolPrefix: + description: |- + Curated default tool-name prefix an admin gets when they register this + catalog entry and set no custom prefix: the impl's declared server_prefix, + else its service_name. Shown as a placeholder in the create wizard's tool + prefix field. Empty when the impl declares no curated default. Mirrors the + read-only default_tool_prefix on MCPServerView surfaced in the edit flow. + type: string description: description: Short description of what the MCP server does. type: string @@ -4955,6 +5883,18 @@ components: c1.api.ai_governance.v1.MCPServerServiceRegisterRequestInput: description: MCPServerServiceRegisterRequest creates a new MCP server (Connector + config). properties: + accessProfileIds: + description: |- + Optional access profiles (request catalogs) the server should be requestable + through. Register creates the server's "All approved tools" toolset empty and adds + its entitlement to each profile, so members can request the server before discovery + has found a single tool; the sync later adopts the same toolset and fills it. Empty + skips both steps. + items: + type: string + type: + - array + - "null" acknowledgedFindingIds: description: |- finding_ids from the diagnostic the admin acknowledged. Each must cover a @@ -5059,6 +5999,13 @@ components: c1.api.ai_governance.v1.MCPServerServiceRegisterResponse: description: MCPServerServiceRegisterResponse returns the newly created MCP server. properties: + accessProfilesAttached: + description: |- + Whether the "All approved tools" toolset reached every profile in + access_profile_ids. False means the server registered but the attach failed + afterwards, and the profiles have to be wired from the server page. Always true + when access_profile_ids was empty, since there was nothing to attach. + type: boolean mcpServer: oneOf: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' @@ -5363,6 +6310,13 @@ components: description: Endpoint URL for external MCP servers. Read-only. readOnly: true type: string + endpointUrlLocked: + description: |- + Whether the endpoint URL is immutable. True once the connector has + completed its first successful sync; the URL cannot be changed after + that point. Read-only. + readOnly: true + type: boolean lastCalledAt: format: date-time readOnly: true @@ -5703,6 +6657,20 @@ components: type: - string - "null" + requestable: + description: |- + Whether this tool's backing entitlement is exposed in at least one request + catalog directly (i.e. can be requested on its own). Computed read-only; + populated on Search. + readOnly: true + type: boolean + requestableViaToolset: + description: |- + Whether this tool is requestable indirectly — it belongs to at least one + toolset (access profile) whose backing entitlement is exposed in a request + catalog. Independent of `requestable`. Computed read-only; populated on Search. + readOnly: true + type: boolean state: description: Tool approval/lifecycle state. enum: @@ -5863,6 +6831,13 @@ components: raw emit time per tool. Costs one Dynamo Limit(1) read per row; callers that don't render the "Last used" column should leave false. type: boolean + includeRequestable: + description: |- + When true, populate the computed `requestable` / `requestable_via_toolset` + fields on each tool (an extra catalog-membership lookup). Off by default so + callers that don't render requestability — e.g. tool-picker and + tools-by-toolset views — don't pay for it. + type: boolean pageSize: description: Page size (max 100). format: int32 @@ -6245,6 +7220,10 @@ components: description: The URL of a logo to display for the app. readOnly: true type: string + matchBatonRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppMatchBatonRef' + - type: "null" monthlyCostUsd: description: The cost of an app per-seat, so that total cost can be calculated by the grant count. format: int32 @@ -7194,6 +8173,54 @@ components: title: App Entitlement Search Service Search Graph Response type: object x-speakeasy-name-override: AppEntitlementSearchServiceSearchGraphResponse + c1.api.app.v1.AppEntitlementSearchServiceSearchReachableResourcesForUserRequest: + description: SearchReachableResourcesForUser request. + properties: + appIds: + description: |- + Restrict results to resources belonging to these applications. Empty + searches across every application the user can reach. + items: + type: string + type: + - array + - "null" + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Token for fetching the next page of results. + type: string + query: + description: Fuzzy search over the resource display name. + type: string + userId: + description: The user whose reachable resources to search. + type: string + title: App Entitlement Search Service Search Reachable Resources For User Request + type: object + x-speakeasy-name-override: AppEntitlementSearchServiceSearchReachableResourcesForUserRequest + c1.api.app.v1.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse: + description: |- + SearchReachableResourcesForUser response. Resources are deduplicated: a + resource reachable through more than one grant or entitlement appears once. + properties: + list: + description: |- + The reachable resources, one GraphNode (type = GRAPH_NODE_TYPE_RESOURCE) + per distinct resource. Uses the same node representation as SearchGraph. + items: + $ref: '#/components/schemas/c1.api.app.v1.GraphNode' + type: + - array + - "null" + nextPageToken: + description: Token for fetching the next page of results. + type: string + title: App Entitlement Search Service Search Reachable Resources For User Response + type: object + x-speakeasy-name-override: AppEntitlementSearchServiceSearchReachableResourcesForUserResponse c1.api.app.v1.AppEntitlementSearchServiceSearchRequest: description: Search app entitlements by a variety of filters. properties: @@ -7566,6 +8593,10 @@ components: type: - string - "null" + id: + description: The unique ID of this grant history record + readOnly: true + type: string revokedAt: format: date-time readOnly: true @@ -7719,21 +8750,147 @@ components: title: App Entitlement With User Binding type: object x-speakeasy-name-override: AppEntitlementWithUserBinding + c1.api.app.v1.AppManagedState: + description: | + AppManagedState identifies whether a discovered application is managed. + + This message contains a oneof named state. Only a single field of the following list may be set at a time: + - unmanaged + - managed + properties: + managed: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedState.AppManagedStateManaged' + - type: "null" + unmanaged: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedState.AppManagedStateUnmanaged' + - type: "null" + title: App Managed State + type: object + x-speakeasy-name-override: AppManagedState + c1.api.app.v1.AppManagedState.AppManagedStateManaged: + description: AppManagedStateManaged identifies the application created by promotion. + properties: + appId: + description: ID of the managed application. + type: string + title: App Managed State Managed + type: object + x-speakeasy-name-override: AppManagedStateManaged + c1.api.app.v1.AppManagedState.AppManagedStateUnmanaged: + description: AppManagedStateUnmanaged indicates that the discovered application has not been promoted. + title: App Managed State Unmanaged + type: object + x-speakeasy-name-override: AppManagedStateUnmanaged + c1.api.app.v1.AppManagedStateBinding: + description: AppManagedStateBinding records whether a connector-discovered application is managed in ConductorOne. + properties: + appId: + description: Application that owns the connector which discovered this application. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: Display name of the discovered application. + type: string + resourceId: + description: Resource ID of the discovered application. + readOnly: true + type: string + resourceTypeId: + description: Resource type used by the connector to represent discovered applications. + readOnly: true + type: string + state: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedState' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App Managed State Binding + type: object + x-speakeasy-name-override: AppManagedStateBinding + c1.api.app.v1.AppManagedStateBindingExpandMask: + description: AppManagedStateBindingExpandMask controls which related objects are included in a response. + properties: + paths: + description: Related objects to include. Supported values are `app_id`, `resource_id`, and `*`. + items: + type: string + type: + - array + - "null" + title: App Managed State Binding Expand Mask + type: object + x-speakeasy-name-override: AppManagedStateBindingExpandMask c1.api.app.v1.AppManagedStateBindingRef: - description: The AppManagedStateBindingRef message. + description: AppManagedStateBindingRef identifies an application discovered by a connector. properties: appId: - description: The appId field. + description: ID of the application that owns the connector. type: string resourceId: - description: The resourceId field. + description: Resource ID of the discovered application. type: string resourceTypeId: - description: The resourceTypeId field. + description: ID of the resource type used for discovered applications. type: string title: App Managed State Binding Ref type: object x-speakeasy-name-override: AppManagedStateBindingRef + c1.api.app.v1.AppManagedStateBindingView: + description: AppManagedStateBindingView contains a managed-state binding and paths to its related objects. + properties: + appManagementStateBinding: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBinding' + - type: "null" + appPath: + description: Path of the application that owns the connector. + type: string + resourcePath: + description: Path of the connector resource representing the discovered application. + type: string + title: App Managed State Binding View + type: object + x-speakeasy-name-override: AppManagedStateBindingView + c1.api.app.v1.AppMatchBatonRef: + description: AppMatchBatonRef identifies the connector application that should adopt a manually-created application during uplift. + properties: + appId: + description: Application that owns the connector. + type: string + connectorId: + description: Connector that discovers the application. + type: string + externalId: + description: |- + Canonical connector-v2 application resource ID in + `::` form (for example, `app::0oa123`). + type: string + required: + - appId + - connectorId + - externalId + title: App Match Baton Ref + type: object + x-speakeasy-name-override: AppMatchBatonRef c1.api.app.v1.AppPopulationReport: description: The AppPopulationReport is a generated report for a specific app that gives details about the app's users. These details include what groups, roles, and other entitlements the users have access to. properties: @@ -8212,6 +9369,19 @@ components: c1.api.app.v1.AppUser: description: Application User that represents an account in the application. properties: + agentStatus: + description: |- + AI-agent lifecycle status when this app user carries the agent trait. + UNSPECIFIED marks a non-agent account. Read-only; translated from the + model's agent_trait at the API boundary. + enum: + - APP_USER_AGENT_STATUS_UNSPECIFIED + - APP_USER_AGENT_STATUS_READY + - APP_USER_AGENT_STATUS_DISABLED + - APP_USER_AGENT_STATUS_DELETED + readOnly: true + type: string + x-speakeasy-unknown-values: allow appId: description: The ID of the application. readOnly: true @@ -8273,6 +9443,22 @@ components: description: The isExternal field. readOnly: true type: boolean + nhiDetail: + description: Axis-2 detail refining nhi_type (e.g. "aws.role.lambda"). Read-only. + readOnly: true + type: string + nhiType: + description: |- + NHI classification when this app user carries the non-human-identity trait. + Read-only; translated from the model's nhi_trait at the API boundary. + enum: + - APP_USER_NHI_TYPE_UNSPECIFIED + - APP_USER_NHI_TYPE_APP_REGISTRATION + - APP_USER_NHI_TYPE_ASSUMABLE_ROLE + - APP_USER_NHI_TYPE_MANAGED_IDENTITY + readOnly: true + type: string + x-speakeasy-unknown-values: allow profile: additionalProperties: true readOnly: true @@ -8464,6 +9650,21 @@ components: c1.api.app.v1.AppUserServiceSearchRequest: description: Search App users based on filters specified in the request body properties: + agentStatuses: + description: |- + Restrict to app users whose agent trait lifecycle status (agent_status) + matches one of these values. When empty, agent_status is not used as a filter. + items: + enum: + - APP_USER_AGENT_STATUS_UNSPECIFIED + - APP_USER_AGENT_STATUS_READY + - APP_USER_AGENT_STATUS_DISABLED + - APP_USER_AGENT_STATUS_DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" appId: description: The app ID to restrict the search to. type: string @@ -8540,6 +9741,21 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' - type: "null" + nhiTypes: + description: |- + Restrict to app users whose NHI trait classification (nhi_type) matches one of + these values. When empty, nhi_type is not used as a filter. + items: + enum: + - APP_USER_NHI_TYPE_UNSPECIFIED + - APP_USER_NHI_TYPE_APP_REGISTRATION + - APP_USER_NHI_TYPE_ASSUMABLE_ROLE + - APP_USER_NHI_TYPE_MANAGED_IDENTITY + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" pageSize: description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 @@ -8978,7 +10194,9 @@ components: description: The ConnectorExpandMask is used to expand related objects on a connector. properties: paths: - description: Paths that you want expanded in the response. Possible values are "app_id" and "*". + description: |- + Paths that you want expanded in the response. Possible values are "app_id", + "user_ids", "capabilities" and "*". items: type: string type: @@ -9569,7 +10787,7 @@ components: - github.com/conductorone/terraform-provider-conductorone/internal/annotations schemaDefinition: annotations.PlanModifier() appEntitlementOwnerRefs: - description: Sets entitlement owners on the app. + description: Initial entitlement owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_entitlement`. items: $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: @@ -9599,12 +10817,16 @@ components: instructions: description: Instructions shown to users in the access request form when requesting access for this app. type: string + matchBatonRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppMatchBatonRef' + - type: "null" monthlyCostUsd: description: Creates the app with this monthly cost per seat. format: int32 type: integer owners: - description: Creates the app with this array of user owners. + description: Initial user owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_user`. items: type: string type: @@ -9623,7 +10845,7 @@ components: x-speakeasy-entity: App x-speakeasy-name-override: CreateAppRequest c1.api.app.v1.CreateAppResponse: - description: Returns the new app's values. + description: CreateAppResponse contains the newly created application. properties: app: oneOf: @@ -9721,6 +10943,7 @@ components: - VAULT - PROFILE_TYPE - SESSION_POLICY + - CLAW_AGENT type: string x-speakeasy-unknown-values: allow required: @@ -9921,7 +11144,9 @@ components: type: object x-speakeasy-name-override: ForceSyncRequest c1.api.app.v1.ForceSyncResponse: - description: Empty response body. Status code indicates success. + description: |- + Empty response body. Status code indicates success. Poll the connector sync status + for progress after ForceSync accepts the request. title: Force Sync Response type: object x-speakeasy-name-override: ForceSyncResponse @@ -9981,6 +11206,29 @@ components: title: Get App Entitlement Routing Rule Response type: object x-speakeasy-name-override: GetAppEntitlementRoutingRuleResponse + c1.api.app.v1.GetAppManagedStateBindingResponse: + description: GetAppManagedStateBindingResponse contains the managed state of a discovered application. + properties: + appManagementState: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingView' + - type: "null" + expanded: + description: Related objects requested through expand_mask. REST Get requests do not support expansions; REST Promote requests do. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Get App Managed State Binding Response + type: object + x-speakeasy-name-override: GetAppManagedStateBindingResponse c1.api.app.v1.GetAppResponse: description: The GetAppResponse message contains the details of the requested app in the app field. properties: @@ -10249,6 +11497,35 @@ components: title: List App Entitlements Response type: object x-speakeasy-name-override: ListAppEntitlementsResponse + c1.api.app.v1.ListAppManagedStateBindingsResponse: + description: ListAppManagedStateBindingsResponse contains one page of discovered application managed states. + properties: + expanded: + description: Related objects included for gRPC requests that set expand_mask. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: Managed states of the discovered applications. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingView' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page. Empty when there are no more results. + type: string + title: List App Managed State Bindings Response + type: object + x-speakeasy-name-override: ListAppManagedStateBindingsResponse c1.api.app.v1.ListAppOwnerIDsResponse: description: The response message for listing app owners IDs. properties: @@ -10455,6 +11732,32 @@ components: title: Pause Sync Response type: object x-speakeasy-name-override: PauseSyncResponse + c1.api.app.v1.PromoteAppManagedStateBindingRequestInput: + description: PromoteAppManagedStateBindingRequest identifies an unmanaged application and configures its owners. + properties: + appEntitlementOwnerRefs: + description: Entitlements to assign as owners of the new application. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingExpandMask' + - type: "null" + userIds: + description: |- + User IDs to assign as owners of the new application. + If omitted, the application inherits the owners of the source connector application. + items: + type: string + type: + - array + - "null" + title: Promote App Managed State Binding Request + type: object + x-speakeasy-name-override: PromoteAppManagedStateBindingRequest c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput: description: The request message for removing an app entitlement owner. title: Remove App Entitlement Owner Request @@ -12914,6 +14217,21 @@ components: once and presents it on the subsequent token exchange. Empty for all other tokens. type: string + disabledModules: + description: |- + The modules turned off for the tenant the logged in user belongs to. Absent + from this list means enabled: every module is on by default. Clients MUST + treat an unrecognized value as "a module this client does not know about is + disabled". + items: + enum: + - MODULE_ID_UNSPECIFIED + - MODULE_ID_SECRET_SHARING + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" features: description: The list of feature flags enabled for the tenant the logged in user belongs to. items: @@ -14336,6 +15654,16 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionNone' - type: "null" + grantSourceFilter: + description: |- + Restricts the step to grants of either DIRECT (grants the user holds directly, + including grants that are also inherited) or UNSPECIFIED (all grants). + Composes with every inclusion mode, including inclusion_list_cel. + enum: + - GRANT_SOURCE_FILTER_UNSPECIFIED + - GRANT_SOURCE_FILTER_DIRECT + type: string + x-speakeasy-unknown-values: allow inclusionAccessOnly: oneOf: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAccessOnly' @@ -14553,6 +15881,7 @@ components: type: object x-speakeasy-name-override: EntitlementInclusionListCel c1.api.automations.v1.EvaluateExpressions: + deprecated: true description: The EvaluateExpressions message. properties: expressions: @@ -14586,6 +15915,7 @@ components: type: object x-speakeasy-name-override: ExecuteAutomationResponse c1.api.automations.v1.Expression: + deprecated: true description: The Expression message. properties: expressionCel: @@ -16175,6 +17505,23 @@ components: title: Connector Authoring Service Rollback Revision Response type: object x-speakeasy-name-override: ConnectorAuthoringServiceRollbackRevisionResponse + c1.api.conversations.v1.EnsureOnboardingSessionRequest: + description: Requests the active onboarding conversation for the caller's tenant. + title: Ensure Onboarding Session Request + type: object + x-speakeasy-name-override: EnsureOnboardingSessionRequest + c1.api.conversations.v1.EnsureOnboardingSessionResponse: + description: Returns the active onboarding conversation and whether this call created it. + properties: + conversationId: + description: The active onboarding conversation ID. + type: string + created: + description: True only when this call created and started the conversation. + type: boolean + title: Ensure Onboarding Session Response + type: object + x-speakeasy-name-override: EnsureOnboardingSessionResponse c1.api.credential_inventory.v1.CredentialInventoryPolicy: description: |- CredentialInventoryPolicy defines which credential types your users may @@ -17230,8 +18577,8 @@ components: type: string clientKey: description: |- - Stable client registration key. One of: a DCR software_id form - (dcr://), a CIMD client_id URL, a native C1 form + Stable client registration key. One of: a DCR client_id form + (dcr://), a CIMD client_id URL, a native C1 form (c1://), or a raw client_id. type: string createdAt: @@ -19083,6 +20430,43 @@ components: title: Bulk Reopen Action type: object x-speakeasy-name-override: BulkReopenAction + c1.api.finding.v1.BulkReprocessAction: + description: |- + BulkReprocessAction re-evaluates eligible findings against transformation + and routing rules using each finding's original detector-created state + (original severity, original annotations) rather than any rule-mutated + current state. + + `override_human_edits` chooses how far re-derivation goes for + human-attributed edits: + + - Open findings are re-derived and re-routed in both modes. + - Findings parked by a rule (snoozed, suppressed, or risk-accepted by a + routing rule with no subsequent human action) are released to open, + re-derived, and re-routed in both modes. + - Findings parked by a person re-derive their content in both modes, but + the state is only released, and a human severity override only cleared, + when `override_human_edits` is true. + - Findings in progress re-derive their content and keep both their state + and any linked ticket in both modes. + - Resolved, archived, and deleted findings are skipped in both modes. + + Assigned owners and ticket links are never touched; rules do not derive them. + properties: + overrideHumanEdits: + description: |- + When false (the default), a person's parked state and severity override + survive the re-derivation. When true, reprocessing additionally releases + findings a person parked and clears human severity overrides. + type: boolean + runDispatchers: + description: |- + When true, matched rules may re-send notification dispatches for + findings your team may have already seen. Off by default. + type: boolean + title: Bulk Reprocess Action + type: object + x-speakeasy-name-override: BulkReprocessAction c1.api.finding.v1.BulkSnoozeAction: description: The BulkSnoozeAction message. properties: @@ -19123,6 +20507,7 @@ components: - unsuppress - assignOwner - reopen + - reprocess properties: acceptRisk: oneOf: @@ -19143,6 +20528,10 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.BulkReopenAction' - type: "null" + reprocess: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkReprocessAction' + - type: "null" searchRequest: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' @@ -19179,6 +20568,41 @@ components: title: Connector Anomaly Detection Disabled Type type: object x-speakeasy-name-override: ConnectorAnomalyDetectionDisabledType + c1.api.finding.v1.ConnectorSyncFailingEvidence: + description: |- + ConnectorSyncFailingEvidence describes the failure streak behind a + CONNECTOR_SYNC_FAILING finding, refreshed on every re-observation. + properties: + consecutiveFailureCount: + description: The consecutiveFailureCount field. + format: uint32 + type: integer + lastFailedAt: + format: date-time + type: + - string + - "null" + lastSyncLifecycleId: + description: |- + Id of the newest failing sync run, not a copy of its error text -- see the + c1models message for why the error itself is deliberately not carried here. + type: string + streakStartedAt: + format: date-time + type: + - string + - "null" + title: Connector Sync Failing Evidence + type: object + x-speakeasy-name-override: ConnectorSyncFailingEvidence + c1.api.finding.v1.ConnectorSyncFailingType: + description: |- + ConnectorSyncFailingType: a connector's completed sync runs have ended in + error for at least two consecutive runs, with no intervening success. + Target: ConnectorTarget. + title: Connector Sync Failing Type + type: object + x-speakeasy-name-override: ConnectorSyncFailingType c1.api.finding.v1.ConnectorTarget: description: ConnectorTarget points at the connector that produced this finding. properties: @@ -19354,6 +20778,131 @@ components: title: Create Task Action type: object x-speakeasy-name-override: CreateTaskAction + c1.api.finding.v1.CredentialExpiringEvidence: + description: The CredentialExpiringEvidence message. + properties: + expired: + description: Whether the expiry was already past when last observed. + type: boolean + expiresAt: + format: date-time + type: + - string + - "null" + title: Credential Expiring Evidence + type: object + x-speakeasy-name-override: CredentialExpiringEvidence + c1.api.finding.v1.CredentialExpiringType: + description: | + CredentialExpiringType: a ConductorOne-managed credential is inside the + detector's expiry warning window, or already past it. Dedup is + (credential arm, credential_id). Target: IdentityUserTarget -- the identity + holding the credential. + + This message contains a oneof named credential. Only a single field of the following list may be set at a time: + - userClientId + properties: + credentialDisplayName: + description: The credentialDisplayName field. + type: string + userClientId: + description: |- + Service-principal credential. + This field is part of the `credential` oneof. + See the documentation for `c1.api.finding.v1.CredentialExpiringType` for more details. + type: + - string + - "null" + title: Credential Expiring Type + type: object + x-speakeasy-name-override: CredentialExpiringType + c1.api.finding.v1.CredentialPubliclyExposedEvidence: + description: CredentialPubliclyExposedEvidence carries scanner attribution for a public exposure. + properties: + credentialRevoked: + description: The credentialRevoked field. + type: boolean + fingerprintPrefix: + description: The fingerprintPrefix field. + type: string + firstObservedAt: + format: date-time + type: + - string + - "null" + firstScannerId: + description: The firstScannerId field. + type: string + reportingScanners: + description: The reportingScanners field. + items: + type: string + type: + - array + - "null" + revokedAt: + format: date-time + type: + - string + - "null" + sourceKind: + description: The sourceKind field. + type: string + sourceUrl: + description: The sourceUrl field. + type: string + title: Credential Publicly Exposed Evidence + type: object + x-speakeasy-name-override: CredentialPubliclyExposedEvidence + c1.api.finding.v1.CredentialPubliclyExposedType: + description: | + CredentialPubliclyExposedType: a live credential was reported as publicly exposed. + Dedup is (credential arm, credential_id). + + This message contains a oneof named credential. Only a single field of the following list may be set at a time: + - userClientId + - connectorClientId + - connectorManagedCredentialId + - functionClientId + properties: + connectorClientId: + description: |- + The connectorClientId field. + This field is part of the `credential` oneof. + See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + type: + - string + - "null" + connectorManagedCredentialId: + description: |- + The connectorManagedCredentialId field. + This field is part of the `credential` oneof. + See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + type: + - string + - "null" + credentialDisplayName: + description: The credentialDisplayName field. + type: string + functionClientId: + description: |- + The functionClientId field. + This field is part of the `credential` oneof. + See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + type: + - string + - "null" + userClientId: + description: |- + The userClientId field. + This field is part of the `credential` oneof. + See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + type: + - string + - "null" + title: Credential Publicly Exposed Type + type: object + x-speakeasy-name-override: CredentialPubliclyExposedType c1.api.finding.v1.CustomFindingType: description: |- CustomFindingType: a user- or integration-authored finding. The discriminator @@ -19362,6 +20911,59 @@ components: title: Custom Finding Type type: object x-speakeasy-name-override: CustomFindingType + c1.api.finding.v1.DeactivatedOwnerDetail: + description: |- + DeactivatedOwnerDetail is one deactivated owner found for the target at + detection time. A target can have more than one owner, and more than one + can read as deactivated. + properties: + reason: + description: The reason field. + enum: + - DEACTIVATED_OWNER_REASON_UNSPECIFIED + - DEACTIVATED_OWNER_REASON_USER_DELETED + - DEACTIVATED_OWNER_REASON_USER_DISABLED + - DEACTIVATED_OWNER_REASON_EMPLOYMENT_INACTIVE + type: string + x-speakeasy-unknown-values: allow + userId: + description: The userId field. + type: string + title: Deactivated Owner Detail + type: object + x-speakeasy-name-override: DeactivatedOwnerDetail + c1.api.finding.v1.DeactivatedOwnerEvidence: + description: The DeactivatedOwnerEvidence message. + properties: + deactivatedOwners: + description: The deactivatedOwners field. + items: + $ref: '#/components/schemas/c1.api.finding.v1.DeactivatedOwnerDetail' + type: + - array + - "null" + title: Deactivated Owner Evidence + type: object + x-speakeasy-name-override: DeactivatedOwnerEvidence + c1.api.finding.v1.DeactivatedOwnerType: + description: |- + DeactivatedOwnerType: the human responsible for a target -- either the + AppUser's own correlated identity, an ownership_v2-assigned owner, or a + secret's run-as identity is deactivated. Target: AppUserTarget or + AppResourceTarget. + properties: + source: + description: The source field. + enum: + - DEACTIVATED_OWNER_SOURCE_UNSPECIFIED + - DEACTIVATED_OWNER_SOURCE_IDENTITY_CORRELATION + - DEACTIVATED_OWNER_SOURCE_OWNERSHIP_ASSIGNED + - DEACTIVATED_OWNER_SOURCE_SECRET_RUN_AS_IDENTITY + type: string + x-speakeasy-unknown-values: allow + title: Deactivated Owner Type + type: object + x-speakeasy-name-override: DeactivatedOwnerType c1.api.finding.v1.DecoyCredentialUsedType: description: |- DecoyCredentialUsedType: a planted decoy credential authenticated @@ -19383,6 +20985,58 @@ components: title: Decoy Credential Used Type type: object x-speakeasy-name-override: DecoyCredentialUsedType + c1.api.finding.v1.DecoyPubliclyExposedEvidence: + description: DecoyPubliclyExposedEvidence mirrors CredentialPubliclyExposedEvidence for decoys. + properties: + credentialRevoked: + description: The credentialRevoked field. + type: boolean + fingerprintPrefix: + description: The fingerprintPrefix field. + type: string + firstObservedAt: + format: date-time + type: + - string + - "null" + firstScannerId: + description: The firstScannerId field. + type: string + reportingScanners: + description: The reportingScanners field. + items: + type: string + type: + - array + - "null" + revokedAt: + format: date-time + type: + - string + - "null" + sourceKind: + description: The sourceKind field. + type: string + sourceUrl: + description: The sourceUrl field. + type: string + title: Decoy Publicly Exposed Evidence + type: object + x-speakeasy-name-override: DecoyPubliclyExposedEvidence + c1.api.finding.v1.DecoyPubliclyExposedType: + description: |- + DecoyPubliclyExposedType: a planted decoy was reported as publicly exposed. + Dedup is decoy_id. + properties: + decoyDisplayName: + description: The decoyDisplayName field. + type: string + decoyId: + description: The decoyId field. + type: string + title: Decoy Publicly Exposed Type + type: object + x-speakeasy-name-override: DecoyPubliclyExposedType c1.api.finding.v1.DecoyTarget: description: |- DecoyTarget points at the planted decoy that produced this finding. @@ -19428,6 +21082,12 @@ components: - decoyCredentialUsed - custom - connectorAnomalyDetectionDisabled + - deactivatedOwner + - unusedSecret + - credentialPubliclyExposed + - decoyPubliclyExposed + - credentialExpiring + - connectorSyncFailing This message contains a oneof named target. Only a single field of the following list may be set at a time: @@ -19442,7 +21102,26 @@ components: This message contains a oneof named evidence. Only a single field of the following list may be set at a time: - similarUsernameMatchEvidence - serviceAccountMisclassificationEvidence + - deactivatedOwnerEvidence + - unusedSecretEvidence + - credentialPubliclyExposedEvidence + - decoyPubliclyExposedEvidence + - credentialExpiringEvidence + - connectorSyncFailingEvidence properties: + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag. Limits: ≤16 entries; keys 1-128 chars + matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0-256 chars; total + serialized ≤4096 bytes. Keys matching ^c1/ are reserved. Also readable + (and settable) via CEL as both finding.annotations and finding.custom_tags. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() appId: description: The appId field. type: string @@ -19466,6 +21145,14 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorAnomalyDetectionDisabledType' - type: "null" + connectorSyncFailing: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorSyncFailingType' + - type: "null" + connectorSyncFailingEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorSyncFailingEvidence' + - type: "null" connectorTarget: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorTarget' @@ -19475,6 +21162,22 @@ components: type: - string - "null" + credentialExpiring: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CredentialExpiringType' + - type: "null" + credentialExpiringEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CredentialExpiringEvidence' + - type: "null" + credentialPubliclyExposed: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CredentialPubliclyExposedType' + - type: "null" + credentialPubliclyExposedEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CredentialPubliclyExposedEvidence' + - type: "null" custom: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.CustomFindingType' @@ -19485,12 +21188,31 @@ components: customTags: additionalProperties: type: string - description: The customTags field. + deprecated: true + description: |- + Deprecated: use annotations instead. Read-only mirror of annotations; + writes to this field are ignored. type: object + deactivatedOwner: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DeactivatedOwnerType' + - type: "null" + deactivatedOwnerEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DeactivatedOwnerEvidence' + - type: "null" decoyCredentialUsed: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.DecoyCredentialUsedType' - type: "null" + decoyPubliclyExposed: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DecoyPubliclyExposedType' + - type: "null" + decoyPubliclyExposedEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DecoyPubliclyExposedEvidence' + - type: "null" decoyTarget: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.DecoyTarget' @@ -19623,7 +21345,10 @@ components: type: string x-speakeasy-unknown-values: allow stateUpdatedById: - description: The stateUpdatedById field. + description: |- + The human who authored the CURRENT state. Empty when a routing rule or the + system authored it, so do not read a populated value as "this finding has a + human owner" -- read it as "a human set the state it is in right now". type: string suppressReason: description: The suppressReason field. @@ -19635,6 +21360,14 @@ components: oneOf: - $ref: '#/components/schemas/c1.api.finding.v1.TenantTarget' - type: "null" + unusedSecret: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.UnusedSecretType' + - type: "null" + unusedSecretEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.UnusedSecretEvidence' + - type: "null" updatedAt: format: date-time type: @@ -19643,6 +21376,35 @@ components: title: Finding type: object x-speakeasy-name-override: Finding + c1.api.finding.v1.FindingAudience: + description: | + FindingAudience resolves to a set of identity user IDs to notify. Step-less: + notifications have no escalation ladder. An empty resolution falls back to + enabled system owners rather than notifying nobody. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + properties: + users: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingAudienceUsers' + - type: "null" + title: Finding Audience + type: object + x-speakeasy-name-override: FindingAudience + c1.api.finding.v1.FindingAudienceUsers: + description: The FindingAudienceUsers message. + properties: + userIds: + description: The userIds field. + items: + type: string + type: + - array + - "null" + title: Finding Audience Users + type: object + x-speakeasy-name-override: FindingAudienceUsers c1.api.finding.v1.FindingAuditEvent: description: |- FindingAuditEvent is one row in a finding's audit stream. The metadata @@ -19696,6 +21458,8 @@ components: - FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED - FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED - FINDING_AUDIT_EVENT_TYPE_TRANSFORMED + - FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED + - FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED type: string x-speakeasy-unknown-values: allow findingId: @@ -19772,6 +21536,8 @@ components: - FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED - FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED - FINDING_AUDIT_EVENT_TYPE_TRANSFORMED + - FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED + - FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED type: string x-speakeasy-unknown-values: allow type: @@ -19818,6 +21584,79 @@ components: title: Finding Audit Service Search Response type: object x-speakeasy-name-override: FindingAuditServiceSearchResponse + c1.api.finding.v1.FindingDispatchOutcomeNotify: + description: FindingDispatchOutcomeNotify notifies recipients once a dispatch settles. + properties: + onDone: + description: The onDone field. + type: boolean + onError: + description: The onError field. + type: boolean + recipients: + description: The recipients field. + items: + type: string + type: + - array + - "null" + title: Finding Dispatch Outcome Notify + type: object + x-speakeasy-name-override: FindingDispatchOutcomeNotify + c1.api.finding.v1.FindingDispatcher: + description: | + FindingDispatcher is one dispatch that fires when a routing rule matches (the + "Then dispatch" authoring step). A rule carries zero-to-many; every enabled + dispatcher fires, order-independent. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - triggerAutomation + - invokeFunction + - webhook + - notify + properties: + displayName: + description: Human-facing label. Optional. + type: string + enabled: + description: Per-dispatcher kill switch. + type: boolean + invokeFunction: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.InvokeFunctionDispatcher' + - type: "null" + key: + description: |- + Stable id within the rule; survives edits, part of the dispatch idempotency + key. Minted server-side when empty. + type: string + notify: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.NotifyDispatcher' + - type: "null" + notifyOnOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingDispatchOutcomeNotify' + - type: "null" + tierOverride: + description: Author tier override; may only tighten the derived tier. + enum: + - FINDING_DISPATCH_TIER_UNSPECIFIED + - FINDING_DISPATCH_TIER_AUTO + - FINDING_DISPATCH_TIER_REQUIRES_APPROVAL + type: string + x-speakeasy-unknown-values: allow + triggerAutomation: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.TriggerAutomationDispatcher' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.WebhookDispatcher' + - type: "null" + title: Finding Dispatcher + type: object + x-speakeasy-name-override: FindingDispatcher c1.api.finding.v1.FindingOwnerRef: description: | The FindingOwnerRef message. @@ -19952,12 +21791,38 @@ components: description: description: The description field. type: string + dispatchers: + description: Dispatchers that fire when the rule matches ("Then dispatch"). Max 10. + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingDispatcher' + type: + - array + - "null" displayName: description: The displayName field. type: string enabled: description: The enabled field. type: boolean + findingType: + description: The findingType field. + enum: + - FINDING_TYPE_UNSPECIFIED + - FINDING_TYPE_SIMILAR_USERNAME_MATCH + - FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION + - FINDING_TYPE_NHI_UNOWNED + - FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED + - FINDING_TYPE_DECOY_CREDENTIAL_USED + - FINDING_TYPE_CUSTOM + - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + - FINDING_TYPE_DEACTIVATED_OWNER + - FINDING_TYPE_UNUSED_SECRET + - FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED + - FINDING_TYPE_DECOY_PUBLICLY_EXPOSED + - FINDING_TYPE_CREDENTIAL_EXPIRING + - FINDING_TYPE_CONNECTOR_SYNC_FAILING + type: string + x-speakeasy-unknown-values: allow id: description: The id field. type: string @@ -20108,6 +21973,12 @@ components: - FINDING_TYPE_DECOY_CREDENTIAL_USED - FINDING_TYPE_CUSTOM - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + - FINDING_TYPE_DEACTIVATED_OWNER + - FINDING_TYPE_UNUSED_SECRET + - FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED + - FINDING_TYPE_DECOY_PUBLICLY_EXPOSED + - FINDING_TYPE_CREDENTIAL_EXPIRING + - FINDING_TYPE_CONNECTOR_SYNC_FAILING type: string x-speakeasy-unknown-values: allow type: @@ -20236,6 +22107,43 @@ components: title: Finding Search Response type: object x-speakeasy-name-override: FindingSearchResponse + c1.api.finding.v1.FindingSettingsEntry: + description: |- + FindingSettingsEntry is a requested change to one type, which is why it is a + separate message from FindingTypeSetting rather than the same one reused: an + update needs enum validation and presence on `enabled` so an omitted field is + an error, while a response always carries a value and must not make callers + handle an absent one. + properties: + enabled: + description: |- + Target state. Required: explicit presence keeps an omitted field from + reading as false and silently switching a detector off. + type: + - boolean + - "null" + findingType: + description: The finding type to configure. Must be a detector-backed type. + enum: + - FINDING_TYPE_UNSPECIFIED + - FINDING_TYPE_SIMILAR_USERNAME_MATCH + - FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION + - FINDING_TYPE_NHI_UNOWNED + - FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED + - FINDING_TYPE_DECOY_CREDENTIAL_USED + - FINDING_TYPE_CUSTOM + - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + - FINDING_TYPE_DEACTIVATED_OWNER + - FINDING_TYPE_UNUSED_SECRET + - FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED + - FINDING_TYPE_DECOY_PUBLICLY_EXPOSED + - FINDING_TYPE_CREDENTIAL_EXPIRING + - FINDING_TYPE_CONNECTOR_SYNC_FAILING + type: string + x-speakeasy-unknown-values: allow + title: Finding Settings Entry + type: object + x-speakeasy-name-override: FindingSettingsEntry c1.api.finding.v1.FindingTransform: description: | FindingTransform is a single mutation applied to a finding by a matched @@ -20296,6 +22204,25 @@ components: not a precedence rank. format: int32 type: integer + findingType: + description: The findingType field. + enum: + - FINDING_TYPE_UNSPECIFIED + - FINDING_TYPE_SIMILAR_USERNAME_MATCH + - FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION + - FINDING_TYPE_NHI_UNOWNED + - FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED + - FINDING_TYPE_DECOY_CREDENTIAL_USED + - FINDING_TYPE_CUSTOM + - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + - FINDING_TYPE_DEACTIVATED_OWNER + - FINDING_TYPE_UNUSED_SECRET + - FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED + - FINDING_TYPE_DECOY_PUBLICLY_EXPOSED + - FINDING_TYPE_CREDENTIAL_EXPIRING + - FINDING_TYPE_CONNECTOR_SYNC_FAILING + type: string + x-speakeasy-unknown-values: allow id: description: The id field. type: string @@ -20317,6 +22244,41 @@ components: title: Finding Transformation Rule type: object x-speakeasy-name-override: FindingTransformationRule + c1.api.finding.v1.FindingTypeSetting: + description: |- + FindingTypeSetting is one finding type's detection switch as it currently + stands. Named for a single type on purpose: the stored model + c1.models.finding.v1.FindingSettings is the tenant-wide object holding every + type, and one name for both granularities reads as the same thing twice. + Display copy for the type is client-owned; this carries state only. + properties: + enabled: + description: |- + Whether the system detects this finding type. Types never configured read + back their shipped default, which is per type rather than uniformly on. + type: boolean + findingType: + description: The findingType field. + enum: + - FINDING_TYPE_UNSPECIFIED + - FINDING_TYPE_SIMILAR_USERNAME_MATCH + - FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION + - FINDING_TYPE_NHI_UNOWNED + - FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED + - FINDING_TYPE_DECOY_CREDENTIAL_USED + - FINDING_TYPE_CUSTOM + - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + - FINDING_TYPE_DEACTIVATED_OWNER + - FINDING_TYPE_UNUSED_SECRET + - FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED + - FINDING_TYPE_DECOY_PUBLICLY_EXPOSED + - FINDING_TYPE_CREDENTIAL_EXPIRING + - FINDING_TYPE_CONNECTOR_SYNC_FAILING + type: string + x-speakeasy-unknown-values: allow + title: Finding Type Setting + type: object + x-speakeasy-name-override: FindingTypeSetting c1.api.finding.v1.GetFindingResponse: description: The GetFindingResponse message. properties: @@ -20369,6 +22331,25 @@ components: title: Identity User Target type: object x-speakeasy-name-override: IdentityUserTarget + c1.api.finding.v1.InvokeFunctionDispatcher: + description: InvokeFunctionDispatcher runs a published C1 function by id. + properties: + args: + additionalProperties: + type: string + description: |- + Arguments passed to the function, keyed by arg name (v0: verbatim values; + CEL evaluation is a later phase). + type: object + functionCommitId: + description: Optional pinned function commit; empty floats to the published commit. + type: string + functionId: + description: ID of the published function to invoke. + type: string + title: Invoke Function Dispatcher + type: object + x-speakeasy-name-override: InvokeFunctionDispatcher c1.api.finding.v1.ListFindingRoutingRulesResponse: description: The ListFindingRoutingRulesResponse message. properties: @@ -20385,6 +22366,29 @@ components: title: List Finding Routing Rules Response type: object x-speakeasy-name-override: ListFindingRoutingRulesResponse + c1.api.finding.v1.ListFindingSettingsResponse: + description: The ListFindingSettingsResponse message. + properties: + configured: + description: |- + True once the tenant has explicitly saved their finding-type settings at + least once, regardless of whether any value differs from default. False + means the tenant has never saved, so every entry in `list` is the + shipped default, unconfirmed by the tenant. + type: boolean + list: + description: |- + One entry per configurable finding type, in FindingType declaration order. + Custom findings are excluded: they arrive over CreateFinding rather than + from a detector, so there is nothing to switch off. + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingTypeSetting' + type: + - array + - "null" + title: List Finding Settings Response + type: object + x-speakeasy-name-override: ListFindingSettingsResponse c1.api.finding.v1.ListFindingTransformationRulesResponse: description: The ListFindingTransformationRulesResponse message. properties: @@ -20408,6 +22412,38 @@ components: title: Nhi Unowned Type type: object x-speakeasy-name-override: NhiUnownedType + c1.api.finding.v1.NotifyDispatcher: + description: |- + NotifyDispatcher emits a notifications_v2 notification about the matched + finding. Exactly one of audience / slack_channel is set: audience notifies + people (each on whichever channels they enabled in their own notification + settings), slack_channel posts to one channel. + properties: + audience: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingAudience' + - type: "null" + batchWindowSeconds: + description: |- + Wait-group window in seconds; 0 sends immediately. A quiet-period length, + not a fixed delay — the batcher slides it forward on each arrival. + format: uint32 + type: integer + detailLevel: + description: How much the notification reveals. Defaults to SUMMARY. + enum: + - FINDING_NOTIFY_DETAIL_LEVEL_UNSPECIFIED + - FINDING_NOTIFY_DETAIL_LEVEL_SUMMARY + - FINDING_NOTIFY_DETAIL_LEVEL_FULL_DETAIL + type: string + x-speakeasy-unknown-values: allow + slackChannel: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SlackChannelTarget' + - type: "null" + title: Notify Dispatcher + type: object + x-speakeasy-name-override: NotifyDispatcher c1.api.finding.v1.RemoveTags: description: The RemoveTags message. properties: @@ -20527,6 +22563,21 @@ components: title: Similar Username Match Type type: object x-speakeasy-name-override: SimilarUsernameMatchType + c1.api.finding.v1.SlackChannelTarget: + description: |- + SlackChannelTarget names one Slack channel. Exactly one of channel_name / + channel_id is set; a name is resolved at send time, so an unresolvable name + fails the dispatch rather than the rule edit. + properties: + channelId: + description: The channelId field. + type: string + channelName: + description: The channelName field. + type: string + title: Slack Channel Target + type: object + x-speakeasy-name-override: SlackChannelTarget c1.api.finding.v1.SnoozeAction: description: SnoozeAction parameters for UpdateFindingState. properties: @@ -20582,12 +22633,46 @@ components: title: Tenant Target type: object x-speakeasy-name-override: TenantTarget + c1.api.finding.v1.TriggerAutomationDispatcher: + description: TriggerAutomationDispatcher runs a C1 automation by id (the "Run now" path). + properties: + automationId: + description: ID of the C1 automation/workflow to run. + type: string + inputMapping: + additionalProperties: + type: string + description: |- + Inputs passed to the automation, keyed by input name (v0: verbatim values; + CEL evaluation is a later phase). + type: object + title: Trigger Automation Dispatcher + type: object + x-speakeasy-name-override: TriggerAutomationDispatcher c1.api.finding.v1.UnsuppressAction: deprecated: true description: UnsuppressAction parameters for UpdateFindingState. title: Unsuppress Action type: object x-speakeasy-name-override: UnsuppressAction + c1.api.finding.v1.UnusedSecretEvidence: + description: The UnusedSecretEvidence message. + properties: + lastUsedAt: + format: date-time + type: + - string + - "null" + title: Unused Secret Evidence + type: object + x-speakeasy-name-override: UnusedSecretEvidence + c1.api.finding.v1.UnusedSecretType: + description: |- + UnusedSecretType: a secret-trait AppResource has not been used in over the + detector's staleness threshold. Target: AppResourceTarget. + title: Unused Secret Type + type: object + x-speakeasy-name-override: UnusedSecretType c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput: description: The UpdateFindingRoutingRuleRequest message. properties: @@ -20608,6 +22693,38 @@ components: title: Update Finding Routing Rule Response type: object x-speakeasy-name-override: UpdateFindingRoutingRuleResponse + c1.api.finding.v1.UpdateFindingSettingsRequest: + description: The UpdateFindingSettingsRequest message. + properties: + settings: + description: |- + Applied as one atomic write, so an admin changing several types either + lands all of them or none. Empty is valid: a never-configured tenant's + "accept the defaults" save has nothing to diff, and the empty write still + creates the settings row. + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingSettingsEntry' + type: + - array + - "null" + title: Update Finding Settings Request + type: object + x-speakeasy-name-override: UpdateFindingSettingsRequest + c1.api.finding.v1.UpdateFindingSettingsResponse: + description: The UpdateFindingSettingsResponse message. + properties: + list: + description: |- + The full catalog after the write, in the same shape ListFindingSettings + returns. + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingTypeSetting' + type: + - array + - "null" + title: Update Finding Settings Response + type: object + x-speakeasy-name-override: UpdateFindingSettingsResponse c1.api.finding.v1.UpdateFindingStateRequestInput: description: | The UpdateFindingStateRequest message. @@ -20677,6 +22794,18 @@ components: title: Update Finding Transformation Rule Response type: object x-speakeasy-name-override: UpdateFindingTransformationRuleResponse + c1.api.finding.v1.WebhookDispatcher: + description: WebhookDispatcher POSTs to a registered webhook (webhooks v3). + properties: + payloadTemplate: + description: Optional payload template; empty uses the default finding payload. + type: string + webhookId: + description: ID of a registered webhook to POST to. + type: string + title: Webhook Dispatcher + type: object + x-speakeasy-name-override: WebhookDispatcher c1.api.form.v1.AdminProviderConfig: description: The AdminProviderConfig message. properties: @@ -20745,6 +22874,26 @@ components: description: |- C1UserFilter is used to configure a picker for selecting ConductorOne users. This is distinct from AppUserFilter which selects accounts within a connected app. + properties: + excludeUserIds: + description: Remove these users from the selectable set, after user_ids is applied. + items: + type: string + type: + - array + - "null" + includeDeactivated: + description: Make deactivated and deleted users selectable. Defaults to enabled-only. + type: boolean + userIds: + description: |- + Restrict the selectable set to these users. Empty means every user is selectable. + Capped at the number of refs SearchUsers accepts in one request. + items: + type: string + type: + - array + - "null" title: C 1 User Filter type: object x-speakeasy-name-override: C1UserFilter @@ -20758,6 +22907,45 @@ components: title: Chips Field type: object x-speakeasy-name-override: ChipsField + c1.api.form.v1.DateField: + description: |- + DateField renders a date picker. The value is an ISO-8601 calendar date + ("YYYY-MM-DD") stored in the enclosing StringField's string value. + properties: + defaultToToday: + description: Default the field to the render date when the StringField has no default_value. + type: boolean + maxDate: + description: Latest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. + type: string + maxDaysFromToday: + description: |- + Latest selectable date expressed as an offset in days from the date the + form is rendered; negative is in the past. Set this to 365 to cap a date at + one year out. When both are set, the earlier of this and max_date applies. + Enforcement is one day slack in each direction: the picker anchors today at + the submitter's local midnight and the server anchors in UTC, so 365 admits + 366 days rather than reject a date the picker itself offered. + format: int32 + type: + - integer + - "null" + minDate: + description: Earliest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. + type: string + minDaysFromToday: + description: |- + Earliest selectable date expressed as an offset in days from the date the + form is rendered; negative is in the past. Prefer this over min_date for a + rolling window, which would otherwise go stale. When both are set, the + later of the two applies. + format: int32 + type: + - integer + - "null" + title: Date Field + type: object + x-speakeasy-name-override: DateField c1.api.form.v1.DependentOn: description: |- DependentOn means the fields in field_names are only valid if all fields @@ -21145,7 +23333,12 @@ components: - passwordField - selectField - pickerField + - dateField properties: + dateField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.DateField' + - type: "null" defaultValue: description: The defaultValue field. type: string @@ -21295,6 +23488,18 @@ components: head: description: The head field. type: string + hookRefs: + description: |- + IDs of every non-deleted hook that still references this function. + Read-only: maintained by the Hook API, not by CreateFunction/UpdateFunction. + Non-empty means DeleteFunction will refuse to delete until these are + removed or retargeted. + items: + type: string + readOnly: true + type: + - array + - "null" id: description: The id field. type: string @@ -21354,6 +23559,16 @@ components: itself, never by UpdateFunction. Retired once all functions are on SPN. readOnly: true type: boolean + workflowTemplateRefs: + description: |- + IDs of every non-deleted workflow template whose CallFunction step still + references this function. Read-only, same semantics as hook_refs. + items: + type: string + readOnly: true + type: + - array + - "null" title: Function type: object x-speakeasy-entity: Function @@ -21893,6 +24108,21 @@ components: c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest: description: The FunctionsServiceUpdateFunctionRequest message. properties: + commitMessage: + description: |- + The commit message describing this code update. Defaults to a generic + message if content is set and this is empty. Ignored if content is empty. + type: string + content: + additionalProperties: + format: base64 + type: string + description: |- + File map for a new code commit, applied as the function's new head + commit. Keys are file paths in the function root; values are file + contents as bytes. See CreateFunctionRequest.initial_content for the + required entry-file signature. Independent of update_mask. + type: object function: oneOf: - $ref: '#/components/schemas/c1.api.functions.v1.Function' @@ -21907,6 +24137,10 @@ components: c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse: description: The FunctionsServiceUpdateFunctionResponse message. properties: + commit: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + - type: "null" function: oneOf: - $ref: '#/components/schemas/c1.api.functions.v1.Function' @@ -21914,334 +24148,284 @@ components: title: Functions Service Update Function Response type: object x-speakeasy-name-override: FunctionsServiceUpdateFunctionResponse - c1.api.history.v1.HistoryActor: - description: |- - HistoryActor is a typed reference to whoever performed the change. - kind mirrors the storage-model ActorKind enum; user_id is set when - kind corresponds to a user principal (API / SUPPORT) so the frontend - can resolve the user via its own avatar / lookup hooks. Protos - reference objects by id; the frontend renders / caches itself. - - The raw passport fields (token_id / principal_id) intentionally do not - leave the server. Non-user actors (workflow, connector, internal) are - identified by `kind` alone; correlating IDs (workflow_run_id, etc.) - flow through `HistoryAnnotation` instead of being plucked into the - actor message. - properties: - kind: - description: The kind field. - enum: - - ACTOR_KIND_UNSPECIFIED - - ACTOR_KIND_API - - ACTOR_KIND_SLACK - - ACTOR_KIND_MSTEAMS - - ACTOR_KIND_JIRA_CLOUD - - ACTOR_KIND_INTERNAL - - ACTOR_KIND_SUPPORT - - ACTOR_KIND_WORKFLOW - type: string - x-speakeasy-unknown-values: allow - userId: - description: |- - Bare KSUID. Set when kind = ACTOR_KIND_API or ACTOR_KIND_SUPPORT. - Empty otherwise. The frontend resolves user_id → display name via - the same lookup paths it uses elsewhere (avatars, mentions, ...). - type: string - title: History Actor - type: object - x-speakeasy-name-override: HistoryActor - c1.api.history.v1.HistoryAnnotation: - description: |- - HistoryAnnotation is a single operator-provided key/value rendered with - per-key display metadata. Annotations are minted from the - Tx.*WithHistoryAnnotations / db.WithHistoryAnnotations call options. + c1.api.funds.v1.AppCap: + description: AppCap is one app's tenant-wide ceiling as the API renders it. properties: - displayLabel: - description: Server-rendered label, e.g. "Ticket". - type: string - displayUrl: - description: |- - Resolved from tenant config; "" if none. Frontend applies its own - scheme allowlist. - type: string - displayValue: - description: UI-friendly rendering (truncated / reshaped from raw_value). - type: string - key: - description: 'Storage-side key. Bounds: ^[a-z][a-z0-9_.-]{0,63}$.' - type: string - kind: - description: The kind field. - enum: - - ANNOTATION_KIND_UNSPECIFIED - - ANNOTATION_KIND_GENERIC - - ANNOTATION_KIND_TICKET - - ANNOTATION_KIND_REASON - - ANNOTATION_KIND_WORKFLOW - - ANNOTATION_KIND_BATCH - - ANNOTATION_KIND_CORRELATION - - ANNOTATION_KIND_AUTOMATION - type: string - x-speakeasy-unknown-values: allow - rawValue: - description: |- - Raw value as stored in ObjectHistory.annotations; storage-side values - are capped at 512 bytes. + appId: + description: The C1 App the spend is attributed to. type: string - title: History Annotation - type: object - x-speakeasy-name-override: HistoryAnnotation - c1.api.history.v1.HistoryEntryMetadata: - description: |- - HistoryEntryMetadata is the shared metadata envelope embedded on every - per-service HistoryEntry. The strongly-typed snapshot lives on the - per-service entry message alongside this envelope. - properties: - actor: + controls: oneOf: - - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' + - $ref: '#/components/schemas/c1.models.funds.v1.SpendControls' - type: "null" - annotations: - description: |- - Server-rendered annotations: known keys carry display_label and - (for ticket_id, etc.) display_url resolved from tenant config. - Cap mirrors the per-object annotation ceiling (16). - items: - $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' - type: - - array - - "null" - changeKind: - description: |- - Storage-model enum re-exported here for wire compatibility with the - storage row. UNSPECIFIED should never appear on the wire. - enum: - - CHANGE_KIND_UNSPECIFIED - - CHANGE_KIND_CREATE - - CHANGE_KIND_PUT - - CHANGE_KIND_HARD_DELETE - type: string - x-speakeasy-unknown-values: allow createdAt: format: date-time type: - string - "null" - id: - description: KSUID. Same value as c1.models.history.v1.ObjectHistory.id. - type: string - syslogEventId: - description: |- - System Log event id — KSUID of the OCSF event recorded for this - write. Empty for non-RPC writes (workflows, cron). Customer-facing - copy says "System Log event"; the underlying format is OCSF. - type: string - traceId: - description: |- - OTel trace correlation. Empty when no valid span at write time. - 32-hex-char otel trace id or empty. + tenantId: + description: The tenantId field. type: string - title: History Entry Metadata - type: object - x-speakeasy-name-override: HistoryEntryMetadata - c1.api.history.v1.ListHistoryEntryMetadata: - description: ListHistoryEntryMetadata is the per-transaction metadata envelope. - properties: - actor: - oneOf: - - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' - - type: "null" - annotations: - description: Server-rendered annotations (mirrors object_history). - items: - $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' - type: - - array - - "null" - createdAt: + updatedAt: format: date-time type: - string - "null" - id: - description: KSUID. Same value as c1.models.history.v1.ListHistory.id. - type: string - syslogEventId: - description: |- - System Log event id — KSUID of the OCSF event recorded for this - transaction. Empty for non-RPC writes (workflows, cron). - type: string - traceId: - description: 32-hex-char otel trace id or empty. - type: string - title: List History Entry Metadata + title: App Cap type: object - x-speakeasy-name-override: ListHistoryEntryMetadata - c1.api.hooks.v1.BuiltInPattern: - description: | - BuiltInPattern references a ConductorOne-maintained DLP pattern. - The specific pattern and its configuration are encoded as a oneof. - - This message contains a oneof named config. Only a single field of the following list may be set at a time: - - piiRedaction - - creditCardBlocking - - queryScopeLimit - - writeAuthorization - - sensitiveFileGuard - - toolOutputSizeGuard + x-speakeasy-name-override: AppCap + c1.api.funds.v1.AppCapHistoryEntry: + description: The AppCapHistoryEntry message. properties: - creditCardBlocking: - oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.CreditCardBlockingConfig' - - type: "null" - piiRedaction: - oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.PIIRedactionConfig' - - type: "null" - queryScopeLimit: - oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.QueryScopeLimitConfig' - - type: "null" - sensitiveFileGuard: + metadata: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.SensitiveFileGuardConfig' + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' - type: "null" - toolOutputSizeGuard: + snapshot: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.ToolOutputSizeGuardConfig' + - $ref: '#/components/schemas/c1.api.funds.v1.AppCap' - type: "null" - writeAuthorization: + title: App Cap History Entry + type: object + x-speakeasy-name-override: AppCapHistoryEntry + c1.api.funds.v1.AppCapServiceDeleteRequestInput: + description: The AppCapServiceDeleteRequest message. + title: App Cap Service Delete Request + type: object + x-speakeasy-name-override: AppCapServiceDeleteRequest + c1.api.funds.v1.AppCapServiceDeleteResponse: + description: The AppCapServiceDeleteResponse message. + title: App Cap Service Delete Response + type: object + x-speakeasy-name-override: AppCapServiceDeleteResponse + c1.api.funds.v1.AppCapServiceGetResponse: + description: The AppCapServiceGetResponse message. + properties: + cap: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.WriteAuthorizationConfig' + - $ref: '#/components/schemas/c1.api.funds.v1.AppCap' - type: "null" - title: Built In Pattern + title: App Cap Service Get Response type: object - x-speakeasy-name-override: BuiltInPattern - c1.api.hooks.v1.BusinessHours: - description: BusinessHours defines a weekly time window in a specific timezone. + x-speakeasy-name-override: AppCapServiceGetResponse + c1.api.funds.v1.AppCapServiceListHistoryResponse: + description: The AppCapServiceListHistoryResponse message. properties: - days: - description: 0=Sun, 1=Mon, ..., 6=Sat. + list: + description: The list field. items: - format: int32 - type: integer + $ref: '#/components/schemas/c1.api.funds.v1.AppCapHistoryEntry' type: - array - "null" - end: - description: '"HH:MM" in 24-hour format.' + nextPageToken: + description: The nextPageToken field. type: string - start: - description: '"HH:MM" in 24-hour format.' + title: App Cap Service List History Response + type: object + x-speakeasy-name-override: AppCapServiceListHistoryResponse + c1.api.funds.v1.AppCapServiceListResponse: + description: The AppCapServiceListResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.funds.v1.AppCap' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - timezone: - description: The timezone field. + title: App Cap Service List Response + type: object + x-speakeasy-name-override: AppCapServiceListResponse + c1.api.funds.v1.AppCapServiceSetLimitRequestInput: + description: The AppCapServiceSetLimitRequest message. + properties: + limit: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + period: + description: Optional period override. Only valid together with the limit it denominates. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY type: string - title: Business Hours + x-speakeasy-unknown-values: allow + title: App Cap Service Set Limit Request type: object - x-speakeasy-name-override: BusinessHours - c1.api.hooks.v1.CreditCardBlockingConfig: - description: |- - CreditCardBlockingConfig denies any tool call whose output contains a - Luhn-valid credit card number. No configuration fields today; the - presence of the oneof arm is the whole configuration. - title: Credit Card Blocking Config + x-speakeasy-name-override: AppCapServiceSetLimitRequest + c1.api.funds.v1.AppCapServiceSetLimitResponse: + description: The AppCapServiceSetLimitResponse message. + properties: + cap: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.AppCap' + - type: "null" + title: App Cap Service Set Limit Response type: object - x-speakeasy-name-override: CreditCardBlockingConfig - c1.api.hooks.v1.Hook: - description: | - Hook represents a customer-configured interception point for tool calls. - - This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - - function - - builtinPattern + x-speakeasy-name-override: AppCapServiceSetLimitResponse + c1.api.funds.v1.AppCapServiceSuspendRequestInput: + description: The AppCapServiceSuspendRequest message. properties: - builtinPattern: + reason: + description: The reason field. + type: string + title: App Cap Service Suspend Request + type: object + x-speakeasy-name-override: AppCapServiceSuspendRequest + c1.api.funds.v1.AppCapServiceSuspendResponse: + description: The AppCapServiceSuspendResponse message. + properties: + cap: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' + - $ref: '#/components/schemas/c1.api.funds.v1.AppCap' + - type: "null" + title: App Cap Service Suspend Response + type: object + x-speakeasy-name-override: AppCapServiceSuspendResponse + c1.api.funds.v1.AppCapServiceUnsuspendRequestInput: + description: The AppCapServiceUnsuspendRequest message. + title: App Cap Service Unsuspend Request + type: object + x-speakeasy-name-override: AppCapServiceUnsuspendRequest + c1.api.funds.v1.AppCapServiceUnsuspendResponse: + description: The AppCapServiceUnsuspendResponse message. + properties: + cap: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.AppCap' + - type: "null" + title: App Cap Service Unsuspend Response + type: object + x-speakeasy-name-override: AppCapServiceUnsuspendResponse + c1.api.funds.v1.FundAssignment: + description: FundAssignment is one principal's fund exception as the API renders it. + properties: + controls: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendControls' - type: "null" createdAt: format: date-time - readOnly: true type: - string - "null" - description: - description: The description field. - type: string - displayName: - description: The displayName field. + tenantId: + description: The tenantId field. type: string - enabled: - description: The enabled field. - type: boolean - event: - description: The event field. - enum: - - HOOK_EVENT_TYPE_UNSPECIFIED - - HOOK_EVENT_TYPE_PRE_TOOL_USE - - HOOK_EVENT_TYPE_POST_TOOL_USE + updatedAt: + format: date-time + type: + - string + - "null" + userId: + description: Canonical c1.models.user.v2.User id, every UserType. type: string - x-speakeasy-unknown-values: allow - filter: + title: Fund Assignment + type: object + x-speakeasy-name-override: FundAssignment + c1.api.funds.v1.FundAssignmentHistoryEntry: + description: The FundAssignmentHistoryEntry message. + properties: + metadata: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' - type: "null" - function: + snapshot: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' - type: "null" - id: - description: The id field. - type: string - priority: - description: The priority field. - format: int32 - type: integer - updatedAt: + title: Fund Assignment History Entry + type: object + x-speakeasy-name-override: FundAssignmentHistoryEntry + c1.api.funds.v1.FundAssignmentServiceClearExtensionRequestInput: + description: The FundAssignmentServiceClearExtensionRequest message. + title: Fund Assignment Service Clear Extension Request + type: object + x-speakeasy-name-override: FundAssignmentServiceClearExtensionRequest + c1.api.funds.v1.FundAssignmentServiceClearExtensionResponse: + description: The FundAssignmentServiceClearExtensionResponse message. + properties: + assignment: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' + - type: "null" + title: Fund Assignment Service Clear Extension Response + type: object + x-speakeasy-name-override: FundAssignmentServiceClearExtensionResponse + c1.api.funds.v1.FundAssignmentServiceDeleteRequestInput: + description: The FundAssignmentServiceDeleteRequest message. + title: Fund Assignment Service Delete Request + type: object + x-speakeasy-name-override: FundAssignmentServiceDeleteRequest + c1.api.funds.v1.FundAssignmentServiceDeleteResponse: + description: The FundAssignmentServiceDeleteResponse message. + title: Fund Assignment Service Delete Response + type: object + x-speakeasy-name-override: FundAssignmentServiceDeleteResponse + c1.api.funds.v1.FundAssignmentServiceGetResponse: + description: The FundAssignmentServiceGetResponse message. + properties: + assignment: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' + - type: "null" + title: Fund Assignment Service Get Response + type: object + x-speakeasy-name-override: FundAssignmentServiceGetResponse + c1.api.funds.v1.FundAssignmentServiceGrantExtensionRequestInput: + description: The FundAssignmentServiceGrantExtensionRequest message. + properties: + expiresAt: format: date-time - readOnly: true type: - string - "null" - title: Hook - type: object - x-speakeasy-name-override: Hook - c1.api.hooks.v1.HookFilter: - description: HookFilter determines which tool calls a hook applies to. - properties: - celExpression: - description: |- - CEL expression evaluated against tool call context. - Available variable: ctx.tool_name (string). - Must evaluate to bool. Empty matches all tools. + limit: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + reason: + description: 'Subject-visible: "why do I have this bump".' type: string - title: Hook Filter + title: Fund Assignment Service Grant Extension Request type: object - x-speakeasy-name-override: HookFilter - c1.api.hooks.v1.HookFunctionRef: - description: HookFunctionRef identifies a customer-authored function to invoke. + x-speakeasy-name-override: FundAssignmentServiceGrantExtensionRequest + c1.api.funds.v1.FundAssignmentServiceGrantExtensionResponse: + description: The FundAssignmentServiceGrantExtensionResponse message. properties: - commitId: - description: If empty, the function's published commit is used at invocation time. - type: string - functionId: - description: The functionId field. - type: string - title: Hook Function Ref + assignment: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' + - type: "null" + title: Fund Assignment Service Grant Extension Response type: object - x-speakeasy-name-override: HookFunctionRef - c1.api.hooks.v1.HookRef: - description: The HookRef message. + x-speakeasy-name-override: FundAssignmentServiceGrantExtensionResponse + c1.api.funds.v1.FundAssignmentServiceListHistoryResponse: + description: The FundAssignmentServiceListHistoryResponse message. properties: - id: - description: The id field. + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Hook Ref + title: Fund Assignment Service List History Response type: object - x-speakeasy-name-override: HookRef - c1.api.hooks.v1.HooksSearchRequest: - description: The HooksSearchRequest message. + x-speakeasy-name-override: FundAssignmentServiceListHistoryResponse + c1.api.funds.v1.FundAssignmentServiceSearchRequest: + description: The FundAssignmentServiceSearchRequest message. properties: pageSize: description: The pageSize field. @@ -22250,383 +24434,453 @@ components: pageToken: description: The pageToken field. type: string - query: - description: The query field. - type: string - refs: - description: The refs field. + userIds: + description: Restrict to these subjects; empty returns every assignment in the tenant. items: - $ref: '#/components/schemas/c1.api.hooks.v1.HookRef' + type: string type: - array - "null" - title: Hooks Search Request + title: Fund Assignment Service Search Request type: object - x-speakeasy-name-override: HooksSearchRequest - c1.api.hooks.v1.HooksSearchResponse: - description: The HooksSearchResponse message. + x-speakeasy-name-override: FundAssignmentServiceSearchRequest + c1.api.funds.v1.FundAssignmentServiceSearchResponse: + description: The FundAssignmentServiceSearchResponse message. properties: list: description: The list field. items: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' type: - array - "null" nextPageToken: description: The nextPageToken field. type: string - title: Hooks Search Response + title: Fund Assignment Service Search Response type: object - x-speakeasy-name-override: HooksSearchResponse - c1.api.hooks.v1.HooksServiceCreateRequest: - description: | - The HooksServiceCreateRequest message. - - This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - - function - - builtinPattern + x-speakeasy-name-override: FundAssignmentServiceSearchResponse + c1.api.funds.v1.FundAssignmentServiceSetLimitRequestInput: + description: The FundAssignmentServiceSetLimitRequest message. properties: - builtinPattern: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' - type: "null" - description: - description: The description field. - type: string - displayName: - description: The displayName field. - type: string - enabled: - description: The enabled field. - type: boolean - event: - description: The event field. + period: + description: Optional period override. Only valid together with the limit it denominates. enum: - - HOOK_EVENT_TYPE_UNSPECIFIED - - HOOK_EVENT_TYPE_PRE_TOOL_USE - - HOOK_EVENT_TYPE_POST_TOOL_USE + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY type: string x-speakeasy-unknown-values: allow - filter: - oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' - - type: "null" - function: + title: Fund Assignment Service Set Limit Request + type: object + x-speakeasy-name-override: FundAssignmentServiceSetLimitRequest + c1.api.funds.v1.FundAssignmentServiceSetLimitResponse: + description: The FundAssignmentServiceSetLimitResponse message. + properties: + assignment: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' - type: "null" - priority: - description: The priority field. - format: int32 - type: integer - required: - - displayName - title: Hooks Service Create Request + title: Fund Assignment Service Set Limit Response type: object - x-speakeasy-name-override: HooksServiceCreateRequest - c1.api.hooks.v1.HooksServiceCreateResponse: - description: The HooksServiceCreateResponse message. + x-speakeasy-name-override: FundAssignmentServiceSetLimitResponse + c1.api.funds.v1.FundAssignmentServiceSuspendRequestInput: + description: The FundAssignmentServiceSuspendRequest message. properties: - hook: + reason: + description: The reason field. + type: string + title: Fund Assignment Service Suspend Request + type: object + x-speakeasy-name-override: FundAssignmentServiceSuspendRequest + c1.api.funds.v1.FundAssignmentServiceSuspendResponse: + description: The FundAssignmentServiceSuspendResponse message. + properties: + assignment: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' - type: "null" - title: Hooks Service Create Response - type: object - x-speakeasy-name-override: HooksServiceCreateResponse - c1.api.hooks.v1.HooksServiceDeleteRequestInput: - description: The HooksServiceDeleteRequest message. - title: Hooks Service Delete Request + title: Fund Assignment Service Suspend Response type: object - x-speakeasy-name-override: HooksServiceDeleteRequest - c1.api.hooks.v1.HooksServiceDeleteResponse: - description: The HooksServiceDeleteResponse message. - title: Hooks Service Delete Response + x-speakeasy-name-override: FundAssignmentServiceSuspendResponse + c1.api.funds.v1.FundAssignmentServiceUnsuspendRequestInput: + description: The FundAssignmentServiceUnsuspendRequest message. + title: Fund Assignment Service Unsuspend Request type: object - x-speakeasy-name-override: HooksServiceDeleteResponse - c1.api.hooks.v1.HooksServiceGetResponse: - description: The HooksServiceGetResponse message. + x-speakeasy-name-override: FundAssignmentServiceUnsuspendRequest + c1.api.funds.v1.FundAssignmentServiceUnsuspendResponse: + description: The FundAssignmentServiceUnsuspendResponse message. properties: - hook: + assignment: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - $ref: '#/components/schemas/c1.api.funds.v1.FundAssignment' - type: "null" - title: Hooks Service Get Response + title: Fund Assignment Service Unsuspend Response type: object - x-speakeasy-name-override: HooksServiceGetResponse - c1.api.hooks.v1.HooksServiceListResponse: - description: The HooksServiceListResponse message. + x-speakeasy-name-override: FundAssignmentServiceUnsuspendResponse + c1.api.funds.v1.FundPolicy: + description: |- + FundPolicy is the tenant's fund policy as the API renders it. Every field is + server-owned on the way out; requests name the fields they change rather than + sending this message back. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + createdAt: + format: date-time type: - - array + - string - "null" - nextPageToken: - description: The nextPageToken field. + currencyCode: + description: ISO 4217. Set at Create and immutable thereafter. type: string - title: Hooks Service List Response - type: object - x-speakeasy-name-override: HooksServiceListResponse - c1.api.hooks.v1.HooksServiceUpdateRequestInput: - description: The HooksServiceUpdateRequest message. - properties: - hook: + defaultLimit: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' - type: "null" - updateMask: + orgCeiling: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendControls' + - type: "null" + period: + description: The root period every amount in the tenant is denominated in. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY + type: string + x-speakeasy-unknown-values: allow + tenantId: + description: The tenantId field. + type: string + updatedAt: + format: date-time type: - string - "null" - title: Hooks Service Update Request + title: Fund Policy type: object - x-speakeasy-name-override: HooksServiceUpdateRequest - c1.api.hooks.v1.HooksServiceUpdateResponse: - description: The HooksServiceUpdateResponse message. + x-speakeasy-name-override: FundPolicy + c1.api.funds.v1.FundPolicyHistoryEntry: + description: The FundPolicyHistoryEntry message. properties: - hook: + metadata: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' - type: "null" - title: Hooks Service Update Response + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy History Entry type: object - x-speakeasy-name-override: HooksServiceUpdateResponse - c1.api.hooks.v1.PIIRedactionConfig: - description: PIIRedactionConfig configures post-tool-use redaction of sensitive fields. + x-speakeasy-name-override: FundPolicyHistoryEntry + c1.api.funds.v1.FundPolicyServiceCreateRequest: + description: The FundPolicyServiceCreateRequest message. properties: - redactFields: - description: The redactFields field. - items: - type: string - type: - - array - - "null" - replacement: - description: The replacement field. + currencyCode: + description: ISO 4217. Immutable once set. type: string - title: Pii Redaction Config + defaultLimit: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + period: + description: The period field. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY + type: string + x-speakeasy-unknown-values: allow + title: Fund Policy Service Create Request type: object - x-speakeasy-name-override: PIIRedactionConfig - c1.api.hooks.v1.QueryScopeLimitConfig: - description: |- - QueryScopeLimitConfig caps numeric fields (e.g. limit, page_size) in tool - input so callers cannot request unbounded data. + x-speakeasy-name-override: FundPolicyServiceCreateRequest + c1.api.funds.v1.FundPolicyServiceCreateResponse: + description: The FundPolicyServiceCreateResponse message. properties: - fields: - description: The fields field. - items: - type: string - type: - - array - - "null" - maxLimit: - description: The maxLimit field. - format: int32 - type: integer - title: Query Scope Limit Config + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Create Response type: object - x-speakeasy-name-override: QueryScopeLimitConfig - c1.api.hooks.v1.SensitiveFileGuardConfig: - description: |- - SensitiveFileGuardConfig blocks tool calls that reference sensitive file - paths or directories. + x-speakeasy-name-override: FundPolicyServiceCreateResponse + c1.api.funds.v1.FundPolicyServiceDeleteRequest: + description: The FundPolicyServiceDeleteRequest message. + title: Fund Policy Service Delete Request + type: object + x-speakeasy-name-override: FundPolicyServiceDeleteRequest + c1.api.funds.v1.FundPolicyServiceDeleteResponse: + description: The FundPolicyServiceDeleteResponse message. + title: Fund Policy Service Delete Response + type: object + x-speakeasy-name-override: FundPolicyServiceDeleteResponse + c1.api.funds.v1.FundPolicyServiceFreezeTenantRequest: + description: The FundPolicyServiceFreezeTenantRequest message. properties: - blockedDirectories: - description: The blockedDirectories field. - items: - type: string - type: - - array - - "null" - blockedPatterns: - description: The blockedPatterns field. - items: - type: string - type: - - array - - "null" - title: Sensitive File Guard Config + reason: + description: The reason field. + type: string + title: Fund Policy Service Freeze Tenant Request type: object - x-speakeasy-name-override: SensitiveFileGuardConfig - c1.api.hooks.v1.ToolOutputSizeGuardConfig: - description: ToolOutputSizeGuardConfig caps post-tool-use output size in bytes. + x-speakeasy-name-override: FundPolicyServiceFreezeTenantRequest + c1.api.funds.v1.FundPolicyServiceFreezeTenantResponse: + description: The FundPolicyServiceFreezeTenantResponse message. properties: - maxBytes: - description: Maximum tool output size in bytes. Outputs exceeding this are denied. - format: int32 - type: integer - title: Tool Output Size Guard Config + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Freeze Tenant Response type: object - x-speakeasy-name-override: ToolOutputSizeGuardConfig - c1.api.hooks.v1.WriteAuthorizationConfig: - description: |- - WriteAuthorizationConfig blocks tool calls whose ToolClassification is in - blocked_classifications, optionally permitting them within business hours. + x-speakeasy-name-override: FundPolicyServiceFreezeTenantResponse + c1.api.funds.v1.FundPolicyServiceGetResponse: + description: The FundPolicyServiceGetResponse message. properties: - blockedClassifications: - description: |- - Tool classifications to block. Must have at least one entry; a hook - with no blocked classifications would be a silent misconfiguration. + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Get Response + type: object + x-speakeasy-name-override: FundPolicyServiceGetResponse + c1.api.funds.v1.FundPolicyServiceListHistoryResponse: + description: The FundPolicyServiceListHistoryResponse message. + properties: + list: + description: The list field. items: - enum: - - TOOL_CLASSIFICATION_UNSPECIFIED - - TOOL_CLASSIFICATION_READ - - TOOL_CLASSIFICATION_WRITE - - TOOL_CLASSIFICATION_DESTRUCTIVE - - TOOL_CLASSIFICATION_SENSITIVE - - TOOL_CLASSIFICATION_DANGEROUS - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyHistoryEntry' type: - array - "null" - businessHours: + nextPageToken: + description: The nextPageToken field. + type: string + title: Fund Policy Service List History Response + type: object + x-speakeasy-name-override: FundPolicyServiceListHistoryResponse + c1.api.funds.v1.FundPolicyServiceSetOrgCeilingRequest: + description: The FundPolicyServiceSetOrgCeilingRequest message. + properties: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.hooks.v1.BusinessHours' + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' - type: "null" - title: Write Authorization Config + period: + description: Optional period override for the ceiling. Only valid together with limit. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY + type: string + x-speakeasy-unknown-values: allow + title: Fund Policy Service Set Org Ceiling Request type: object - x-speakeasy-name-override: WriteAuthorizationConfig - c1.api.iam.v1.ActorObjectPermissions: - description: |- - Legacy: do not use for new objects. Retained only for the existing - AppResource / AppEntitlement / access-review consumers, which will migrate to - c1.api.authorization.v1.ActorObjectPermissions in IGA-2331. New object views - should reference c1.api.authorization.v1.ActorObjectPermissions instead. + x-speakeasy-name-override: FundPolicyServiceSetOrgCeilingRequest + c1.api.funds.v1.FundPolicyServiceSetOrgCeilingResponse: + description: The FundPolicyServiceSetOrgCeilingResponse message. properties: - delete: - description: The delete field. - type: boolean - edit: - description: The edit field. - type: boolean - extra: - additionalProperties: - type: boolean - description: The extra field. - type: object - read: - description: The read field. - type: boolean - title: Actor Object Permissions + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Set Org Ceiling Response type: object - x-speakeasy-name-override: ActorObjectPermissions - c1.api.iam.v1.AnnouncedTunnelService: - description: |- - AnnouncedTunnelService is one service entry the appliance declared in its - wormhole HELLO frame. Read live from the discovery store; not persisted. + x-speakeasy-name-override: FundPolicyServiceSetOrgCeilingResponse + c1.api.funds.v1.FundPolicyServiceUnfreezeTenantRequest: + description: The FundPolicyServiceUnfreezeTenantRequest message. + title: Fund Policy Service Unfreeze Tenant Request + type: object + x-speakeasy-name-override: FundPolicyServiceUnfreezeTenantRequest + c1.api.funds.v1.FundPolicyServiceUnfreezeTenantResponse: + description: The FundPolicyServiceUnfreezeTenantResponse message. properties: - name: - description: Logical name of the service as declared by the appliance. - type: string - port: - description: TCP port the service listens on inside the appliance network. - format: uint32 - type: integer - servicePath: - description: Optional URL path prefix for the service. - type: string - serviceType: - description: Application-level protocol type (e.g. "http", "grpc"). - type: string - transportType: - description: Transport protocol used by the wormhole tunnel (e.g. "tcp"). - type: string - title: Announced Tunnel Service + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Unfreeze Tenant Response type: object - x-speakeasy-name-override: AnnouncedTunnelService - c1.api.iam.v1.ExternalClientInfo: - description: |- - ExternalClientInfo provides information about an approved external client. - Used by both List (user's own grants) and Search (admin view of all grants). + x-speakeasy-name-override: FundPolicyServiceUnfreezeTenantResponse + c1.api.funds.v1.FundPolicyServiceUpdateRequest: + description: The FundPolicyServiceUpdateRequest message. + properties: + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Fund Policy Service Update Request + type: object + x-speakeasy-name-override: FundPolicyServiceUpdateRequest + c1.api.funds.v1.FundPolicyServiceUpdateResponse: + description: The FundPolicyServiceUpdateResponse message. + properties: + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundPolicy' + - type: "null" + title: Fund Policy Service Update Response + type: object + x-speakeasy-name-override: FundPolicyServiceUpdateResponse + c1.api.funds.v1.FundRule: + description: FundRule is one group grant as the API renders it. properties: - clientId: - description: OAuth2 client ID - canonical identifier for this connection (globally unique per DCR) - type: string - clientIdType: - description: How the client_id was established. - enum: - - CLIENT_ID_TYPE_UNSPECIFIED - - CLIENT_ID_TYPE_DCR - - CLIENT_ID_TYPE_METADATA_URL - type: string - x-speakeasy-unknown-values: allow - clientIdUrl: - description: |- - Original CIMD metadata URL (e.g., "https://cursor.com/.well-known/oauth-client"). - Empty for DCR clients. - type: string - clientName: - description: Original client name from DCR registration - type: string createdAt: format: date-time type: - string - "null" displayName: - description: User-provided custom name (defaults to client_name if not set) + description: |- + Admin-facing label, so a rule list reads as policy rather than as ids. + Bounded on the message rather than only on Create: Update carries a whole + FundRule, and this is the column the mirror's full-text and btree indexes + are built on. type: string - lastUsedAt: + grant: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + groupRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + reason: + description: Why this cohort is funded. Subject-visible where a grant is explained. + type: string + ruleId: + description: The ruleId field. + type: string + tenantId: + description: The tenantId field. + type: string + updatedAt: format: date-time type: - string - "null" - mcpClientId: - description: MCP client record ID for AI governance tracking. May be empty for legacy grants. + title: Fund Rule + type: object + x-speakeasy-name-override: FundRule + c1.api.funds.v1.FundRuleHistoryEntry: + description: The FundRuleHistoryEntry message. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundRule' + - type: "null" + title: Fund Rule History Entry + type: object + x-speakeasy-name-override: FundRuleHistoryEntry + c1.api.funds.v1.FundRuleServiceCreateRequest: + description: The FundRuleServiceCreateRequest message. + properties: + displayName: + description: The displayName field. type: string - roleIds: - description: Role IDs granted to this client - frontend can fetch display names via SearchRoles + grant: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + groupRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + reason: + description: The reason field. + type: string + title: Fund Rule Service Create Request + type: object + x-speakeasy-name-override: FundRuleServiceCreateRequest + c1.api.funds.v1.FundRuleServiceCreateResponse: + description: The FundRuleServiceCreateResponse message. + properties: + rule: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundRule' + - type: "null" + title: Fund Rule Service Create Response + type: object + x-speakeasy-name-override: FundRuleServiceCreateResponse + c1.api.funds.v1.FundRuleServiceDeleteRequestInput: + description: The FundRuleServiceDeleteRequest message. + title: Fund Rule Service Delete Request + type: object + x-speakeasy-name-override: FundRuleServiceDeleteRequest + c1.api.funds.v1.FundRuleServiceDeleteResponse: + description: The FundRuleServiceDeleteResponse message. + title: Fund Rule Service Delete Response + type: object + x-speakeasy-name-override: FundRuleServiceDeleteResponse + c1.api.funds.v1.FundRuleServiceGetResponse: + description: The FundRuleServiceGetResponse message. + properties: + rule: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundRule' + - type: "null" + title: Fund Rule Service Get Response + type: object + x-speakeasy-name-override: FundRuleServiceGetResponse + c1.api.funds.v1.FundRuleServiceListHistoryResponse: + description: The FundRuleServiceListHistoryResponse message. + properties: + list: + description: The list field. items: - type: string + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleHistoryEntry' type: - array - "null" - userId: - description: The user who approved this external client (always populated) - type: string - verifiedDomain: - description: |- - Verified domain from the client_id URL (e.g., "cursor.com"). - Empty for DCR clients. - type: string - wellKnownClient: - description: The wellKnownClient field. - enum: - - WELL_KNOWN_CLIENT_UNSPECIFIED - - WELL_KNOWN_CLIENT_UNKNOWN - - WELL_KNOWN_CLIENT_CLAUDE_AI - - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP - - WELL_KNOWN_CLIENT_CLAUDE_CODE - - WELL_KNOWN_CLIENT_MCP_INSPECTOR - - WELL_KNOWN_CLIENT_CHATGPT - - WELL_KNOWN_CLIENT_VSCODE - - WELL_KNOWN_CLIENT_CURSOR - - WELL_KNOWN_CLIENT_WINDSURF - - WELL_KNOWN_CLIENT_ZED - - WELL_KNOWN_CLIENT_JETBRAINS - - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT + nextPageToken: + description: The nextPageToken field. type: string - x-speakeasy-unknown-values: allow - title: External Client Info + title: Fund Rule Service List History Response type: object - x-speakeasy-name-override: ExternalClientInfo - c1.api.iam.v1.ExternalClientSearchServiceSearchRequest: - description: The ExternalClientSearchServiceSearchRequest message. + x-speakeasy-name-override: FundRuleServiceListHistoryResponse + c1.api.funds.v1.FundRuleServiceListResponse: + description: The FundRuleServiceListResponse message. properties: - clientIdUrls: - description: |- - Exact-match filter on client_id values (e.g., CIMD URLs). - Returns only grants whose client_id matches one of these values. + list: + description: The list field. items: - type: string + $ref: '#/components/schemas/c1.api.funds.v1.FundRule' type: - array - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Fund Rule Service List Response + type: object + x-speakeasy-name-override: FundRuleServiceListResponse + c1.api.funds.v1.FundRuleServiceSearchRequest: + description: The FundRuleServiceSearchRequest message. + properties: pageSize: description: The pageSize field. format: int32 @@ -22635,3724 +24889,3339 @@ components: description: The pageToken field. type: string query: - description: Free-text search on client_name and user display name + description: Case-insensitive search over the rule display name; empty returns all. type: string - users: - description: Filter by specific user IDs - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - type: - - array - - "null" - wellKnownClients: - description: Filter by well-known client type (e.g., CLAUDE_CODE, CURSOR, etc.) - items: - enum: - - WELL_KNOWN_CLIENT_UNSPECIFIED - - WELL_KNOWN_CLIENT_UNKNOWN - - WELL_KNOWN_CLIENT_CLAUDE_AI - - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP - - WELL_KNOWN_CLIENT_CLAUDE_CODE - - WELL_KNOWN_CLIENT_MCP_INSPECTOR - - WELL_KNOWN_CLIENT_CHATGPT - - WELL_KNOWN_CLIENT_VSCODE - - WELL_KNOWN_CLIENT_CURSOR - - WELL_KNOWN_CLIENT_WINDSURF - - WELL_KNOWN_CLIENT_ZED - - WELL_KNOWN_CLIENT_JETBRAINS - - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" - title: External Client Search Service Search Request + title: Fund Rule Service Search Request type: object - x-speakeasy-name-override: ExternalClientSearchServiceSearchRequest - c1.api.iam.v1.ExternalClientSearchServiceSearchResponse: - description: The ExternalClientSearchServiceSearchResponse message. + x-speakeasy-name-override: FundRuleServiceSearchRequest + c1.api.funds.v1.FundRuleServiceSearchResponse: + description: The FundRuleServiceSearchResponse message. properties: list: - description: Uses ExternalClientInfo with user_id populated for admin views + description: The list field. items: - $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientInfo' + $ref: '#/components/schemas/c1.api.funds.v1.FundRule' type: - array - "null" nextPageToken: description: The nextPageToken field. type: string - title: External Client Search Service Search Response + title: Fund Rule Service Search Response type: object - x-speakeasy-name-override: ExternalClientSearchServiceSearchResponse - c1.api.iam.v1.GetRolesResponse: - description: The GetRolesResponse message contains the retrieved role. + x-speakeasy-name-override: FundRuleServiceSearchResponse + c1.api.funds.v1.FundRuleServiceUpdateRequestInput: + description: The FundRuleServiceUpdateRequest message. properties: - role: + rule: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - $ref: '#/components/schemas/c1.api.funds.v1.FundRule' - type: "null" - title: Get Roles Response - type: object - x-speakeasy-name-override: GetRolesResponse - c1.api.iam.v1.ListRolesResponse: - description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. - properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.iam.v1.Role' + updateMask: type: - - array + - string - "null" - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: List Roles Response + title: Fund Rule Service Update Request type: object - x-speakeasy-name-override: ListRolesResponse - c1.api.iam.v1.PersonalClient: - description: The PersonalClient message contains information about a presonal client credential. + x-speakeasy-name-override: FundRuleServiceUpdateRequest + c1.api.funds.v1.FundRuleServiceUpdateResponse: + description: The FundRuleServiceUpdateResponse message. properties: - allowSourceCidr: - description: |- - If set, only allows the CIDRs in the array to use the credential. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. - items: - type: string - type: - - array - - "null" - clientId: - description: The clientID of the credential. - readOnly: true + rule: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.FundRule' + - type: "null" + title: Fund Rule Service Update Response + type: object + x-speakeasy-name-override: FundRuleServiceUpdateResponse + c1.api.funds.v1.MyFundLimit: + description: |- + MyFundLimit is one of the caller's own per-app limits. It carries no user id: + it is always the caller's. + properties: + appId: + description: The C1 App this limit applies to. type: string + controls: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendControls' + - type: "null" createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - displayName: - description: The display name of the personal client credential. - type: string - expiresTime: format: date-time type: - string - "null" - id: - description: The unique ID of the personal client credential. - readOnly: true - type: string - lastUsedAt: - format: date-time - readOnly: true - type: - - string - - "null" - scopedRoles: - description: |- - scoped_roles provides a list of IAM Roles - that this OAuth2 Client's API permissions - are reduced to. The permissions granted to OAuth2 Client - are AND'ed against the owning User's own permissions. - items: - type: string - type: - - array - - "null" updatedAt: format: date-time - readOnly: true type: - string - "null" - userId: - description: The ID of the user that this credential is created for. - readOnly: true - type: string - title: Personal Client + title: My Fund Limit type: object - x-speakeasy-name-override: PersonalClient - c1.api.iam.v1.PersonalClientSearchServiceSearchRequest: - description: The PersonalClientSearchServiceSearchRequest message. + x-speakeasy-name-override: MyFundLimit + c1.api.funds.v1.MyFundLimitHistoryEntry: + description: The MyFundLimitHistoryEntry message. properties: - pageSize: - description: The maximum number of results to return per page. - format: int32 - type: integer - pageToken: - description: A pagination token returned from a previous Search call. - type: string - query: - description: A text query to filter personal clients by display name. - type: string - users: - description: Filter results to personal clients owned by the specified users. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - type: - - array - - "null" - title: Personal Client Search Service Search Request + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimit' + - type: "null" + title: My Fund Limit History Entry type: object - x-speakeasy-name-override: PersonalClientSearchServiceSearchRequest - c1.api.iam.v1.PersonalClientSearchServiceSearchResponse: - description: The PersonalClientSearchServiceSearchResponse message. + x-speakeasy-name-override: MyFundLimitHistoryEntry + c1.api.funds.v1.MyFundLimitsServiceDeleteRequestInput: + description: The MyFundLimitsServiceDeleteRequest message. + title: My Fund Limits Service Delete Request + type: object + x-speakeasy-name-override: MyFundLimitsServiceDeleteRequest + c1.api.funds.v1.MyFundLimitsServiceDeleteResponse: + description: The MyFundLimitsServiceDeleteResponse message. + title: My Fund Limits Service Delete Response + type: object + x-speakeasy-name-override: MyFundLimitsServiceDeleteResponse + c1.api.funds.v1.MyFundLimitsServiceListHistoryResponse: + description: The MyFundLimitsServiceListHistoryResponse message. properties: list: - description: The list of personal client credentials matching the search criteria. + description: The list field. items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitHistoryEntry' type: - array - "null" nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. + description: The nextPageToken field. type: string - title: Personal Client Search Service Search Response + title: My Fund Limits Service List History Response type: object - x-speakeasy-name-override: PersonalClientSearchServiceSearchResponse - c1.api.iam.v1.PersonalClientServiceCreateRequest: - description: The PersonalClientServiceCreateRequest message contains the fields for creating a new personal client. + x-speakeasy-name-override: MyFundLimitsServiceListHistoryResponse + c1.api.funds.v1.MyFundLimitsServiceListResponse: + description: The MyFundLimitsServiceListResponse message. properties: - allowSourceCidr: - description: |- - A list of CIDRs to restrict this credential to. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + list: + description: The list field. items: - type: string + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimit' type: - array - "null" - displayName: - description: The display name for the new personal client. + nextPageToken: + description: The nextPageToken field. type: string - expires: - format: duration - type: - - string - - "null" - scopedRoles: - description: The list of roles to restrict the credential to. - items: - type: string - type: - - array - - "null" - title: Personal Client Service Create Request + title: My Fund Limits Service List Response type: object - x-speakeasy-name-override: PersonalClientServiceCreateRequest - c1.api.iam.v1.PersonalClientServiceCreateResponse: - description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. + x-speakeasy-name-override: MyFundLimitsServiceListResponse + c1.api.funds.v1.MyFundLimitsServicePauseRequestInput: + description: The MyFundLimitsServicePauseRequest message. properties: - client: + reason: + description: The reason field. + type: string + title: My Fund Limits Service Pause Request + type: object + x-speakeasy-name-override: MyFundLimitsServicePauseRequest + c1.api.funds.v1.MyFundLimitsServicePauseResponse: + description: The MyFundLimitsServicePauseResponse message. + properties: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimit' - type: "null" - clientSecret: - description: The client secret that corresponds to the personal client. Make sure to save this, because it cannot be returned or queried again. - type: string - title: Personal Client Service Create Response + title: My Fund Limits Service Pause Response type: object - x-speakeasy-name-override: PersonalClientServiceCreateResponse - c1.api.iam.v1.PersonalClientServiceDeleteRequestInput: - description: The PersonalClientServiceDeleteRequest message. - title: Personal Client Service Delete Request + x-speakeasy-name-override: MyFundLimitsServicePauseResponse + c1.api.funds.v1.MyFundLimitsServiceResumeRequestInput: + description: The MyFundLimitsServiceResumeRequest message. + title: My Fund Limits Service Resume Request type: object - x-speakeasy-name-override: PersonalClientServiceDeleteRequest - c1.api.iam.v1.PersonalClientServiceDeleteResponse: - description: The PersonalClientServiceDeleteResponse message. - title: Personal Client Service Delete Response - type: object - x-speakeasy-name-override: PersonalClientServiceDeleteResponse - c1.api.iam.v1.PersonalClientServiceGetResponse: - description: The PersonalClientServiceGetResponse message. + x-speakeasy-name-override: MyFundLimitsServiceResumeRequest + c1.api.funds.v1.MyFundLimitsServiceResumeResponse: + description: The MyFundLimitsServiceResumeResponse message. properties: - client: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimit' - type: "null" - title: Personal Client Service Get Response - type: object - x-speakeasy-name-override: PersonalClientServiceGetResponse - c1.api.iam.v1.PersonalClientServiceListResponse: - description: The PersonalClientServiceListResponse message. - properties: - list: - description: The list of personal client credentials owned by the calling user. - items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - type: - - array - - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - type: string - title: Personal Client Service List Response + title: My Fund Limits Service Resume Response type: object - x-speakeasy-name-override: PersonalClientServiceListResponse - c1.api.iam.v1.PersonalClientServiceUpdateRequestInput: - description: The PersonalClientServiceUpdateRequest message. + x-speakeasy-name-override: MyFundLimitsServiceResumeResponse + c1.api.funds.v1.MyFundLimitsServiceSetLimitRequestInput: + description: The MyFundLimitsServiceSetLimitRequest message. properties: - client: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' - type: "null" - updateMask: - type: - - string - - "null" - title: Personal Client Service Update Request + period: + description: Optional period override. Only valid together with the limit it denominates. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY + type: string + x-speakeasy-unknown-values: allow + title: My Fund Limits Service Set Limit Request type: object - x-speakeasy-name-override: PersonalClientServiceUpdateRequest - c1.api.iam.v1.PersonalClientServiceUpdateResponse: - description: The PersonalClientServiceUpdateResponse message. + x-speakeasy-name-override: MyFundLimitsServiceSetLimitRequest + c1.api.funds.v1.MyFundLimitsServiceSetLimitResponse: + description: The MyFundLimitsServiceSetLimitResponse message. properties: - client: + limit: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimit' - type: "null" - title: Personal Client Service Update Response + title: My Fund Limits Service Set Limit Response type: object - x-speakeasy-name-override: PersonalClientServiceUpdateResponse - c1.api.iam.v1.PersonalDevice: + x-speakeasy-name-override: MyFundLimitsServiceSetLimitResponse + c1.api.history.v1.HistoryActor: description: |- - PersonalDevice is one physical device with its app clients. The device - identity is a stable thumbprint of the device's root signing key; the root key - never authenticates an app — each client uses its own key. + HistoryActor is a typed reference to whoever performed the change. + kind mirrors the storage-model ActorKind enum; user_id is set when + kind corresponds to a user principal (API / SUPPORT) so the frontend + can resolve the user via its own avatar / lookup hooks. Protos + reference objects by id; the frontend renders / caches itself. + + The raw passport fields (token_id / principal_id) intentionally do not + leave the server. Non-user actors (workflow, connector, internal) are + identified by `kind` alone; correlating IDs (workflow_run_id, etc.) + flow through `HistoryAnnotation` instead of being plucked into the + actor message. properties: - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - deviceId: - description: |- - The stable device identity: a base64url-encoded SHA-256 thumbprint of the - device's root public signing key. - readOnly: true + kind: + description: The kind field. + enum: + - ACTOR_KIND_UNSPECIFIED + - ACTOR_KIND_API + - ACTOR_KIND_SLACK + - ACTOR_KIND_MSTEAMS + - ACTOR_KIND_JIRA_CLOUD + - ACTOR_KIND_INTERNAL + - ACTOR_KIND_SUPPORT + - ACTOR_KIND_WORKFLOW type: string - deviceOs: - description: The device operating system, e.g. "macos-14.5". - readOnly: true + x-speakeasy-unknown-values: allow + userId: + description: |- + Bare KSUID. Set when kind = ACTOR_KIND_API or ACTOR_KIND_SUPPORT. + Empty otherwise. The frontend resolves user_id → display name via + the same lookup paths it uses elsewhere (avatars, mentions, ...). type: string - deviceSurface: - description: The device surface, e.g. "macos-desktop". - readOnly: true + title: History Actor + type: object + x-speakeasy-name-override: HistoryActor + c1.api.history.v1.HistoryAnnotation: + description: |- + HistoryAnnotation is a single operator-provided key/value rendered with + per-key display metadata. Annotations are minted from the + Tx.*WithHistoryAnnotations / db.WithHistoryAnnotations call options. + properties: + displayLabel: + description: Server-rendered label, e.g. "Ticket". type: string - displayName: + displayUrl: description: |- - The human-friendly device label, defaulted from the first app's name at - registration. Devices are listed sorted by this name. Mutable via - UpdateDevice. + Resolved from tenant config; "" if none. Frontend applies its own + scheme allowlist. type: string - status: - description: |- - The device's lifecycle status. Revoked devices are retained for audit and are - returned by Search only when the status filter requests them. + displayValue: + description: UI-friendly rendering (truncated / reshaped from raw_value). + type: string + key: + description: 'Storage-side key. Bounds: ^[a-z][a-z0-9_.-]{0,63}$.' + type: string + kind: + description: The kind field. enum: - - PERSONAL_DEVICE_STATUS_UNSPECIFIED - - PERSONAL_DEVICE_STATUS_ACTIVE - - PERSONAL_DEVICE_STATUS_REVOKED - readOnly: true + - ANNOTATION_KIND_UNSPECIFIED + - ANNOTATION_KIND_GENERIC + - ANNOTATION_KIND_TICKET + - ANNOTATION_KIND_REASON + - ANNOTATION_KIND_WORKFLOW + - ANNOTATION_KIND_BATCH + - ANNOTATION_KIND_CORRELATION + - ANNOTATION_KIND_AUTOMATION type: string x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - userId: - description: The ID of the user this device is bound to (the approving user). - readOnly: true + rawValue: + description: |- + Raw value as stored in ObjectHistory.annotations; storage-side values + are capped at 512 bytes. type: string - title: Personal Device + title: History Annotation type: object - x-speakeasy-name-override: PersonalDevice - c1.api.iam.v1.PersonalDeviceClient: + x-speakeasy-name-override: HistoryAnnotation + c1.api.history.v1.HistoryEntryMetadata: description: |- - PersonalDeviceClient is a single app client on a device. The client - authenticates with its own asymmetric key; there is no client secret. + HistoryEntryMetadata is the shared metadata envelope embedded on every + per-service HistoryEntry. The strongly-typed snapshot lives on the + per-service entry message alongside this envelope. properties: - clientId: - description: The full client_id of the device credential. - readOnly: true - type: string - clientName: - description: The human-friendly client name from its registration metadata. - readOnly: true - type: string - consumerKeyId: - description: The stable identity of this client's per-app key. - readOnly: true + actor: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' + - type: "null" + annotations: + description: |- + Server-rendered annotations: known keys carry display_label and + (for ticket_id, etc.) display_url resolved from tenant config. + Cap mirrors the per-object annotation ceiling (16). + items: + $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' + type: + - array + - "null" + changeKind: + description: |- + Storage-model enum re-exported here for wire compatibility with the + storage row. UNSPECIFIED should never appear on the wire. + enum: + - CHANGE_KIND_UNSPECIFIED + - CHANGE_KIND_CREATE + - CHANGE_KIND_PUT + - CHANGE_KIND_HARD_DELETE type: string + x-speakeasy-unknown-values: allow createdAt: format: date-time - readOnly: true type: - string - "null" - deviceOs: - description: The device operating system captured for this client, e.g. "macos-14.5". - readOnly: true - type: string - deviceSurface: - description: The device surface captured for this client, e.g. "macos-desktop". - readOnly: true - type: string - displayName: - description: The display name of the device credential. - readOnly: true - type: string id: - description: The unique ID of the device client (the local part of client_id). - readOnly: true + description: KSUID. Same value as c1.models.history.v1.ObjectHistory.id. type: string - lastUsedAt: - format: date-time - readOnly: true - type: - - string - - "null" - softwareId: - description: An identifier for the client software, from its registration metadata. - readOnly: true + syslogEventId: + description: |- + System Log event id — KSUID of the OCSF event recorded for this + write. Empty for non-RPC writes (workflows, cron). Customer-facing + copy says "System Log event"; the underlying format is OCSF. type: string - softwareVersion: - description: The version of the client software, from its registration metadata. - readOnly: true + traceId: + description: |- + OTel trace correlation. Empty when no valid span at write time. + 32-hex-char otel trace id or empty. type: string - title: Personal Device Client + title: History Entry Metadata type: object - x-speakeasy-name-override: PersonalDeviceClient - c1.api.iam.v1.PersonalDeviceServiceGetDeviceResponse: - description: The PersonalDeviceServiceGetDeviceResponse message. + x-speakeasy-name-override: HistoryEntryMetadata + c1.api.history.v1.ListHistoryEntryMetadata: + description: ListHistoryEntryMetadata is the per-transaction metadata envelope. properties: - device: + actor: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' - type: "null" - title: Personal Device Service Get Device Response - type: object - x-speakeasy-name-override: PersonalDeviceServiceGetDeviceResponse - c1.api.iam.v1.PersonalDeviceServiceListDeviceClientsResponse: - description: The PersonalDeviceServiceListDeviceClientsResponse message. - properties: - clients: - description: The app clients registered on the device. + annotations: + description: Server-rendered annotations (mirrors object_history). items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceClient' + $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more. - type: string - title: Personal Device Service List Device Clients Response - type: object - x-speakeasy-name-override: PersonalDeviceServiceListDeviceClientsResponse - c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientRequestInput: - description: The PersonalDeviceServiceRevokeDeviceClientRequest message. - title: Personal Device Service Revoke Device Client Request - type: object - x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientRequest - c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientResponse: - description: The PersonalDeviceServiceRevokeDeviceClientResponse message. - title: Personal Device Service Revoke Device Client Response - type: object - x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientResponse - c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceRequestInput: - description: The PersonalDeviceServiceRevokeDeviceRequest message. - title: Personal Device Service Revoke Device Request - type: object - x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceRequest - c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceResponse: - description: The PersonalDeviceServiceRevokeDeviceResponse message. - title: Personal Device Service Revoke Device Response - type: object - x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceResponse - c1.api.iam.v1.PersonalDeviceServiceSearchRequest: - description: The PersonalDeviceServiceSearchRequest message. - properties: - pageSize: - description: The maximum number of results to return per page. - format: int32 - type: integer - pageToken: - description: A pagination token returned from a previous Search call. + createdAt: + format: date-time + type: + - string + - "null" + id: + description: KSUID. Same value as c1.models.history.v1.ListHistory.id. type: string - query: - description: An optional case-insensitive filter on the device display name. + syslogEventId: + description: |- + System Log event id — KSUID of the OCSF event recorded for this + transaction. Empty for non-RPC writes (workflows, cron). type: string - statusFilter: - description: Which device statuses to return. Defaults to active devices only. - enum: - - PERSONAL_DEVICE_STATUS_FILTER_UNSPECIFIED - - PERSONAL_DEVICE_STATUS_FILTER_ACTIVE - - PERSONAL_DEVICE_STATUS_FILTER_REVOKED - - PERSONAL_DEVICE_STATUS_FILTER_ALL + traceId: + description: 32-hex-char otel trace id or empty. type: string - x-speakeasy-unknown-values: allow - title: Personal Device Service Search Request + title: List History Entry Metadata type: object - x-speakeasy-name-override: PersonalDeviceServiceSearchRequest - c1.api.iam.v1.PersonalDeviceServiceSearchResponse: - description: The PersonalDeviceServiceSearchResponse message. + x-speakeasy-name-override: ListHistoryEntryMetadata + c1.api.hooks.v1.BlockOutputConfig: + description: |- + BlockOutputConfig denies the in-flight response chunk when its hook's + filter matches. Only valid for HOOK_EVENT_TYPE_PRE_OUTPUT. properties: - list: - description: The devices the calling user has registered, matching the search criteria. + message: + description: |- + Message shown to the user when this hook blocks the response. Empty + falls back to the curating AgentGuardrailRule's deny_reason, then to a + generic default. + type: string + surfaces: + description: |- + Output surfaces this hook applies to. Empty means none — the hook is + inert until at least one surface is explicitly selected. items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + enum: + - HOOK_OUTPUT_SURFACE_UNSPECIFIED + - HOOK_OUTPUT_SURFACE_SLACK + - HOOK_OUTPUT_SURFACE_WEB + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more. + title: Block Output Config + type: object + x-speakeasy-name-override: BlockOutputConfig + c1.api.hooks.v1.BlockToolCallConfig: + description: |- + BlockToolCallConfig unconditionally denies the tool call when its hook's + filter matches. Only valid for HOOK_EVENT_TYPE_POST_TOOL_USE. + properties: + message: + description: |- + Message shown when the tool call is denied. Empty falls back to a + generic default. type: string - title: Personal Device Service Search Response + title: Block Tool Call Config type: object - x-speakeasy-name-override: PersonalDeviceServiceSearchResponse - c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceRequestInput: - description: The PersonalDeviceServiceUpdateDeviceRequest message. + x-speakeasy-name-override: BlockToolCallConfig + c1.api.hooks.v1.BuiltInPattern: + description: | + BuiltInPattern references a ConductorOne-maintained DLP pattern. + The specific pattern and its configuration are encoded as a oneof. + + This message contains a oneof named config. Only a single field of the following list may be set at a time: + - piiRedaction + - creditCardBlocking + - queryScopeLimit + - writeAuthorization + - sensitiveFileGuard + - toolOutputSizeGuard + - secretsMasking + - linkFilter + - encodedContentGuard + - promptInjectionScan + - blockOutput + - blockToolCall + - preToolBlock properties: - device: + blockOutput: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - $ref: '#/components/schemas/c1.api.hooks.v1.BlockOutputConfig' - type: "null" - updateMask: + blockToolCall: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.BlockToolCallConfig' + - type: "null" + creditCardBlocking: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.CreditCardBlockingConfig' + - type: "null" + encodedContentGuard: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.EncodedContentGuardConfig' + - type: "null" + linkFilter: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.LinkFilterConfig' + - type: "null" + piiRedaction: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.PIIRedactionConfig' + - type: "null" + preToolBlock: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.PreToolBlockConfig' + - type: "null" + promptInjectionScan: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.PromptInjectionScanConfig' + - type: "null" + queryScopeLimit: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.QueryScopeLimitConfig' + - type: "null" + secretsMasking: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.SecretsMaskingConfig' + - type: "null" + sensitiveFileGuard: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.SensitiveFileGuardConfig' + - type: "null" + toolOutputSizeGuard: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.ToolOutputSizeGuardConfig' + - type: "null" + writeAuthorization: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.WriteAuthorizationConfig' + - type: "null" + title: Built In Pattern + type: object + x-speakeasy-name-override: BuiltInPattern + c1.api.hooks.v1.BusinessHours: + description: BusinessHours defines a weekly time window in a specific timezone. + properties: + days: + description: 0=Sun, 1=Mon, ..., 6=Sat. + items: + format: int32 + type: integer type: - - string + - array - "null" - title: Personal Device Service Update Device Request + end: + description: '"HH:MM" in 24-hour format.' + type: string + start: + description: '"HH:MM" in 24-hour format.' + type: string + timezone: + description: The timezone field. + type: string + title: Business Hours type: object - x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceRequest - c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceResponse: - description: The PersonalDeviceServiceUpdateDeviceResponse message. + x-speakeasy-name-override: BusinessHours + c1.api.hooks.v1.CreditCardBlockingConfig: + description: |- + CreditCardBlockingConfig denies any tool call whose output contains a + Luhn-valid credit card number. No configuration fields today; the + presence of the oneof arm is the whole configuration. + title: Credit Card Blocking Config + type: object + x-speakeasy-name-override: CreditCardBlockingConfig + c1.api.hooks.v1.EncodedContentGuardConfig: + description: |- + EncodedContentGuardConfig detects encoded/obfuscated smuggling in tool input: + long base64 blobs, long hex runs, and invisible/zero-width unicode. properties: - device: - oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' - - type: "null" - title: Personal Device Service Update Device Response + flagOnly: + description: When true, detection records the finding but does not deny (observe-only). + type: boolean + minBase64Run: + description: Minimum contiguous base64 run length to flag. <= 0 = default (256). + format: int32 + type: integer + minHexRun: + description: Minimum contiguous hex run length to flag. <= 0 = default (128). + format: int32 + type: integer + title: Encoded Content Guard Config type: object - x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceResponse - c1.api.iam.v1.Role: - description: Role is a role that can be assigned to a user in ConductorOne. + x-speakeasy-name-override: EncodedContentGuardConfig + c1.api.hooks.v1.Hook: + description: | + Hook represents a customer-configured interception point for tool calls. + + This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: + - function + - builtinPattern + - jsonPatch properties: + builtinPattern: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' + - type: "null" createdAt: format: date-time readOnly: true type: - string - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" + description: + description: The description field. + type: string displayName: - description: The display name of the role. + description: The displayName field. + type: string + enabled: + description: The enabled field. + type: boolean + event: + description: The event field. + enum: + - HOOK_EVENT_TYPE_UNSPECIFIED + - HOOK_EVENT_TYPE_PRE_TOOL_USE + - HOOK_EVENT_TYPE_POST_TOOL_USE + - HOOK_EVENT_TYPE_PRE_OUTPUT type: string + x-speakeasy-unknown-values: allow + filter: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' + - type: "null" + function: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - type: "null" id: - description: The id of the role. - readOnly: true + description: The id field. type: string - name: - description: The internal name of the role. + jsonPatch: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.JSONPatchConfig' + - type: "null" + managedByGuardrails: + description: |- + managed_by_guardrails marks a hook as selectable in a guardrail rule's + curated pre_hook_ids/post_hook_ids. A hook left false (the default, + including every pre-existing hook) always runs regardless of guardrail + state; a hook set true only runs when a matched rule selects it. + type: boolean + priority: + description: The priority field. + format: int32 + type: integer + updatedAt: + format: date-time readOnly: true - type: string - permissions: - description: The list of permissions this role has. - items: - type: string type: - - array + - string - "null" - serviceRoles: - description: The list of serviceRoles that this role has. - items: - type: string - type: - - array - - "null" - systemApiOnly: - description: This Role is intended for API keys usage only, and the user interface may not function as expected. - readOnly: true - type: boolean - systemBuiltin: - description: The system builtin field. If this field is set, the role is not editable. - readOnly: true - type: boolean - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Role + title: Hook type: object - x-speakeasy-name-override: Role - c1.api.iam.v1.TunnelAppliance: + x-speakeasy-name-override: Hook + c1.api.hooks.v1.HookFilter: description: |- - TunnelAppliance is the live state of the customer-side appliance for one - bridge. + HookFilter determines which calls (or, for HOOK_EVENT_TYPE_PRE_OUTPUT, + which outgoing response chunks) a hook applies to. properties: - announcedServiceCount: - description: Number of services the appliance is currently announcing. - format: uint32 - type: integer - lastSeenAt: - format: date-time - type: - - string - - "null" - links: + celExpression: description: |- - Wormhole relays currently holding a Link for this bridge. Typically of - length 1. - items: - $ref: '#/components/schemas/c1.api.iam.v1.TunnelApplianceLink' - type: - - array - - "null" - status: - description: The status field. - enum: - - TUNNEL_APPLIANCE_STATUS_UNSPECIFIED - - TUNNEL_APPLIANCE_STATUS_CONNECTED - - TUNNEL_APPLIANCE_STATUS_DISCONNECTED - - TUNNEL_APPLIANCE_STATUS_NEVER_CONNECTED + CEL expression evaluated against event context. Must evaluate to bool, + empty = matches everything for the event type. + HOOK_EVENT_TYPE_PRE_TOOL_USE / POST_TOOL_USE: ctx.tool_name (string), + and for a call originating from a chat channel ctx.surface (string, + "slack", "web", or "teams"), ctx.channel_id (string, the channel the + message arrived on — only set for "slack"/"teams"; "web" channel refs are + per-conversation and not admin-predictable), and ctx.workspace_id + (string, the Slack/Teams workspace, when known). All three are absent + otherwise, so guard them with has(ctx.surface) / has(ctx.channel_id) / + has(ctx.workspace_id). + HOOK_EVENT_TYPE_PRE_OUTPUT: ctx.untrusted_class (string), ctx.surface + (string, "slack" or "web"). type: string - x-speakeasy-unknown-values: allow - title: Tunnel Appliance + title: Hook Filter type: object - x-speakeasy-name-override: TunnelAppliance - c1.api.iam.v1.TunnelApplianceLink: - description: The TunnelApplianceLink message. + x-speakeasy-name-override: HookFilter + c1.api.hooks.v1.HookFunctionRef: + description: HookFunctionRef identifies a customer-authored function to invoke. properties: - avgRtt: - format: duration - type: - - string - - "null" - leaseExpiresAt: - format: date-time - type: - - string - - "null" - relayAddress: - description: |- - Public address (host:port) of the relay server, suitable for use in - client-side connection strings. + commitId: + description: If empty, the function's published commit is used at invocation time. type: string - relayId: - description: Identifier of the wormhole relay server holding this Link. + functionId: + description: The functionId field. type: string - title: Tunnel Appliance Link + title: Hook Function Ref type: object - x-speakeasy-name-override: TunnelApplianceLink - c1.api.iam.v1.TunnelBridge: - description: |- - TunnelBridge is the API view of a bridge — the customer-facing entity - for managing a wormhole tunnel appliance. + x-speakeasy-name-override: HookFunctionRef + c1.api.hooks.v1.HookRef: + description: The HookRef message. properties: - appliance: - oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.TunnelAppliance' - - type: "null" - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - description: - description: The description field. - type: string - displayName: - description: The displayName field. - type: string id: description: The id field. - readOnly: true type: string - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Tunnel Bridge + title: Hook Ref type: object - x-speakeasy-name-override: TunnelBridge - c1.api.iam.v1.TunnelCredential: - description: |- - TunnelCredential is the API view of one OAuth credential within a bridge. - The plaintext client_secret is only populated on the CreateBridgeCredential - response. + x-speakeasy-name-override: HookRef + c1.api.hooks.v1.HooksSearchRequest: + description: The HooksSearchRequest message. properties: - bridgeId: - description: The bridge this credential belongs to. - readOnly: true - type: string - clientId: - description: The client_id (full ${id}@${tenant_domain}/tcc form). - readOnly: true - type: string - clientSecret: - description: |- - The plaintext client_secret. ONLY populated on the - CreateBridgeCredential response; empty on Get / List. - readOnly: true + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - credentialStatus: - description: Lifecycle status of this credential record. - enum: - - TUNNEL_CREDENTIAL_STATUS_UNSPECIFIED - - TUNNEL_CREDENTIAL_STATUS_ACTIVE - - TUNNEL_CREDENTIAL_STATUS_REVOKED - - TUNNEL_CREDENTIAL_STATUS_EXPIRED - readOnly: true + query: + description: The query field. type: string - x-speakeasy-unknown-values: allow - deletedAt: - format: date-time - readOnly: true + refs: + description: The refs field. + items: + $ref: '#/components/schemas/c1.api.hooks.v1.HookRef' type: - - string + - array - "null" - expiresTime: - format: date-time - readOnly: true + title: Hooks Search Request + type: object + x-speakeasy-name-override: HooksSearchRequest + c1.api.hooks.v1.HooksSearchResponse: + description: The HooksSearchResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.hooks.v1.Hook' type: - - string + - array - "null" - id: - description: The id field. - readOnly: true + nextPageToken: + description: The nextPageToken field. type: string - lastUsedAt: - format: date-time - readOnly: true - type: - - string - - "null" - revokedAt: - format: date-time - readOnly: true - type: - - string - - "null" - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Tunnel Credential - type: object - x-speakeasy-name-override: TunnelCredential - c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialRequestInput: - description: The TunnelCredentialsServiceCreateBridgeCredentialRequest message. - title: Tunnel Credentials Service Create Bridge Credential Request + title: Hooks Search Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialRequest - c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialResponse: - description: The TunnelCredentialsServiceCreateBridgeCredentialResponse message. + x-speakeasy-name-override: HooksSearchResponse + c1.api.hooks.v1.HooksServiceCreateRequest: + description: | + The HooksServiceCreateRequest message. + + This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: + - function + - builtinPattern + - jsonPatch properties: - credential: + builtinPattern: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' + - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' - type: "null" - title: Tunnel Credentials Service Create Bridge Credential Response - type: object - x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialResponse - c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeRequest: - description: The TunnelCredentialsServiceCreateBridgeRequest message. - properties: description: description: The description field. type: string displayName: description: The displayName field. type: string - title: Tunnel Credentials Service Create Bridge Request + enabled: + description: The enabled field. + type: boolean + event: + description: The event field. + enum: + - HOOK_EVENT_TYPE_UNSPECIFIED + - HOOK_EVENT_TYPE_PRE_TOOL_USE + - HOOK_EVENT_TYPE_POST_TOOL_USE + - HOOK_EVENT_TYPE_PRE_OUTPUT + type: string + x-speakeasy-unknown-values: allow + filter: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' + - type: "null" + function: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - type: "null" + jsonPatch: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.JSONPatchConfig' + - type: "null" + managedByGuardrails: + description: The managedByGuardrails field. + type: boolean + priority: + description: The priority field. + format: int32 + type: integer + required: + - displayName + title: Hooks Service Create Request type: object - x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeRequest - c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeResponse: - description: The TunnelCredentialsServiceCreateBridgeResponse message. + x-speakeasy-name-override: HooksServiceCreateRequest + c1.api.hooks.v1.HooksServiceCreateResponse: + description: The HooksServiceCreateResponse message. properties: - bridge: + hook: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - type: "null" - title: Tunnel Credentials Service Create Bridge Response + title: Hooks Service Create Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeResponse - c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeRequestInput: - description: The TunnelCredentialsServiceDeleteBridgeRequest message. - title: Tunnel Credentials Service Delete Bridge Request + x-speakeasy-name-override: HooksServiceCreateResponse + c1.api.hooks.v1.HooksServiceDeleteRequestInput: + description: The HooksServiceDeleteRequest message. + title: Hooks Service Delete Request type: object - x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeRequest - c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeResponse: - description: Empty response body. Status code indicates success. - title: Tunnel Credentials Service Delete Bridge Response + x-speakeasy-name-override: HooksServiceDeleteRequest + c1.api.hooks.v1.HooksServiceDeleteResponse: + description: The HooksServiceDeleteResponse message. + title: Hooks Service Delete Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeResponse - c1.api.iam.v1.TunnelCredentialsServiceGetBridgeResponse: - description: The TunnelCredentialsServiceGetBridgeResponse message. + x-speakeasy-name-override: HooksServiceDeleteResponse + c1.api.hooks.v1.HooksServiceGetResponse: + description: The HooksServiceGetResponse message. properties: - bridge: + hook: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - type: "null" - title: Tunnel Credentials Service Get Bridge Response - type: object - x-speakeasy-name-override: TunnelCredentialsServiceGetBridgeResponse - c1.api.iam.v1.TunnelCredentialsServiceListBridgeAnnouncedServicesResponse: - description: The TunnelCredentialsServiceListBridgeAnnouncedServicesResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.iam.v1.AnnouncedTunnelService' - type: - - array - - "null" - title: Tunnel Credentials Service List Bridge Announced Services Response - type: object - x-speakeasy-name-override: TunnelCredentialsServiceListBridgeAnnouncedServicesResponse - c1.api.iam.v1.TunnelCredentialsServiceListBridgeCredentialsResponse: - description: The TunnelCredentialsServiceListBridgeCredentialsResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' - type: - - array - - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Tunnel Credentials Service List Bridge Credentials Response + title: Hooks Service Get Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceListBridgeCredentialsResponse - c1.api.iam.v1.TunnelCredentialsServiceListBridgesResponse: - description: The TunnelCredentialsServiceListBridgesResponse message. + x-speakeasy-name-override: HooksServiceGetResponse + c1.api.hooks.v1.HooksServiceListResponse: + description: The HooksServiceListResponse message. properties: list: description: The list field. items: - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + $ref: '#/components/schemas/c1.api.hooks.v1.Hook' type: - array - "null" nextPageToken: description: The nextPageToken field. type: string - title: Tunnel Credentials Service List Bridges Response - type: object - x-speakeasy-name-override: TunnelCredentialsServiceListBridgesResponse - c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialRequestInput: - description: The TunnelCredentialsServiceRevokeBridgeCredentialRequest message. - title: Tunnel Credentials Service Revoke Bridge Credential Request - type: object - x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialRequest - c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialResponse: - description: Empty response body. Status code indicates success. - title: Tunnel Credentials Service Revoke Bridge Credential Response + title: Hooks Service List Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialResponse - c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeRequestInput: - description: The TunnelCredentialsServiceUpdateBridgeRequest message. + x-speakeasy-name-override: HooksServiceListResponse + c1.api.hooks.v1.HooksServiceUpdateRequestInput: + description: The HooksServiceUpdateRequest message. properties: - description: - description: |- - New description. Applied only when "description" is in update_mask. - Empty clears the description. - type: string - displayName: - description: |- - New display name. Applied only when "display_name" is in update_mask. - Must be non-empty when applied. - type: string + hook: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - type: "null" updateMask: type: - string - "null" - title: Tunnel Credentials Service Update Bridge Request + title: Hooks Service Update Request type: object - x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeRequest - c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeResponse: - description: The TunnelCredentialsServiceUpdateBridgeResponse message. + x-speakeasy-name-override: HooksServiceUpdateRequest + c1.api.hooks.v1.HooksServiceUpdateResponse: + description: The HooksServiceUpdateResponse message. properties: - bridge: + hook: oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - type: "null" - title: Tunnel Credentials Service Update Bridge Response + title: Hooks Service Update Response type: object - x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeResponse - c1.api.iam.v1.UpdateRoleRequestInput: - description: The UpdateRoleRequest message contains the role to update and the update mask. + x-speakeasy-name-override: HooksServiceUpdateResponse + c1.api.hooks.v1.JSONPatchConfig: + description: | + JSONPatchConfig adds, overwrites, or removes fields on a tool call's JSON + input, with no function invocation. Only valid on + HOOK_EVENT_TYPE_PRE_TOOL_USE. cel_expression is evaluated against + ctx/input/caller and must produce a map; static_overlay is a fixed map. + Either result is shallow-merged onto the input under RFC 7396 merge patch + semantics: a key overwrites or adds that key, a null value removes it, and a + nested object replaces rather than merging into the existing one. + + This message contains a oneof named source. Only a single field of the following list may be set at a time: + - celExpression + - staticOverlay properties: - role: - oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.Role' - - type: "null" - updateMask: + celExpression: + description: |- + The celExpression field. + This field is part of the `source` oneof. + See the documentation for `c1.api.hooks.v1.JSONPatchConfig` for more details. type: - string - "null" - title: Update Role Request - type: object - x-speakeasy-name-override: UpdateRoleRequest - c1.api.iam.v1.UpdateRolesResponse: - description: UpdateRolesResponse is the response message containing the updated role. - properties: - role: - oneOf: - - $ref: '#/components/schemas/c1.api.iam.v1.Role' - - type: "null" - title: Update Roles Response + staticOverlay: + additionalProperties: true + type: + - object + - "null" + title: Json Patch Config type: object - x-speakeasy-name-override: UpdateRolesResponse - c1.api.identity_platform.v1.IdentityPolicyTenantDefaults: + x-speakeasy-name-override: JSONPatchConfig + c1.api.hooks.v1.LinkFilterConfig: description: |- - IdentityPolicyTenantDefaults is the tenant-wide set of default identity - policies applied when no more specific policy matches a user. + LinkFilterConfig strips or annotates URLs and markdown images in tool output + whose host is not in allowed_hosts. properties: - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - credentialInventoryPolicyId: - description: The default credential inventory policy (which credential types users may enroll). - type: string - enrollmentRequirementId: - description: The default enrollment requirement. - type: string - recoveryPolicyId: - description: The default recovery policy. - type: string - resourcePolicyId: - description: The default resource policy. - type: string - sessionPolicyId: - description: The default session policy. - type: string - signInPolicyId: - description: The default sign-in policy. + action: + description: Action taken on a disallowed link. Unspecified = REDACT. + enum: + - LINK_FILTER_ACTION_UNSPECIFIED + - LINK_FILTER_ACTION_REDACT + - LINK_FILTER_ACTION_ANNOTATE type: string - universalPromiseIds: + x-speakeasy-unknown-values: allow + allowedHosts: description: |- - Tenant-wide promises every user must satisfy (e.g. terms-of-service - acceptance). + Hosts that are permitted. Empty = every host is disallowed. Matched + case-insensitively; a leading "." allows subdomains. items: type: string type: - array - "null" - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Identity Policy Tenant Defaults - type: object - x-speakeasy-entity: IdentityPolicyTenantDefaults - x-speakeasy-name-override: IdentityPolicyTenantDefaults - c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceGetResponse: - description: The IdentityPolicyTenantDefaultsServiceGetResponse message. - properties: - defaults: - oneOf: - - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - - type: "null" - title: Identity Policy Tenant Defaults Service Get Response + blockImages: + description: When true, markdown image links to disallowed hosts are also acted on. + type: boolean + title: Link Filter Config type: object - x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceGetResponse - c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateRequest: - description: The IdentityPolicyTenantDefaultsServiceUpdateRequest message. + x-speakeasy-name-override: LinkFilterConfig + c1.api.hooks.v1.PIIRedactionConfig: + description: PIIRedactionConfig configures post-tool-use redaction of sensitive fields. properties: - defaults: - oneOf: - - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - - type: "null" - updateMask: + redactFields: + description: The redactFields field. + items: + type: string type: - - string + - array - "null" - title: Identity Policy Tenant Defaults Service Update Request + replacement: + description: The replacement field. + type: string + title: Pii Redaction Config type: object - x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateRequest - c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateResponse: - description: The IdentityPolicyTenantDefaultsServiceUpdateResponse message. + x-speakeasy-name-override: PIIRedactionConfig + c1.api.hooks.v1.PreToolBlockConfig: + description: |- + PreToolBlockConfig unconditionally denies the tool call before it executes + when its hook's filter matches. Only valid for HOOK_EVENT_TYPE_PRE_TOOL_USE. properties: - defaults: - oneOf: - - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - - type: "null" - title: Identity Policy Tenant Defaults Service Update Response + message: + description: |- + Message shown when the tool call is denied. Empty falls back to a + generic default. + type: string + title: Pre Tool Block Config type: object - x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateResponse - c1.api.integration.connector.v1.CheckboxField: - description: The CheckboxField message. + x-speakeasy-name-override: PreToolBlockConfig + c1.api.hooks.v1.PromptInjectionScanConfig: + description: |- + PromptInjectionScanConfig scans tool output for prompt-injection using the + aigov A2 judge and acts when the verdict is at or above threshold. properties: - checked: - description: The checked field. + flagOnly: + description: When true, a detection records the finding but does not deny (observe-only). type: boolean - title: Checkbox Field + threshold: + description: |- + Deny (or flag) when the judge scores at or above this level. Unspecified = + HIGH. + enum: + - PROMPT_INJECTION_THRESHOLD_UNSPECIFIED + - PROMPT_INJECTION_THRESHOLD_LOW + - PROMPT_INJECTION_THRESHOLD_MEDIUM + - PROMPT_INJECTION_THRESHOLD_HIGH + type: string + x-speakeasy-unknown-values: allow + title: Prompt Injection Scan Config type: object - x-speakeasy-name-override: ConnectorCheckboxField - c1.api.integration.connector.v1.ConfigSchema: - description: The ConfigSchema message. + x-speakeasy-name-override: PromptInjectionScanConfig + c1.api.hooks.v1.QueryScopeLimitConfig: + description: |- + QueryScopeLimitConfig caps numeric fields (e.g. limit, page_size) in tool + input so callers cannot request unbounded data. properties: - displayName: - description: The displayName field. - type: string - fieldGroups: - description: Optional. Metadata for displaying fields in the UI. - items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.FieldGroup' - type: - - array - - "null" fields: description: The fields field. items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.Field' + type: string type: - array - "null" - helpUrl: - description: The helpUrl field. - type: string - iconUrl: - deprecated: true - description: The iconUrl field. - type: string - isOauth2: - description: The isOauth2 field. - type: boolean - requiresExternalConnector: - description: The requiresExternalConnector field. - type: boolean - supportsExternalResources: - description: The supportsExternalResources field. - type: boolean - title: Config Schema - type: object - x-speakeasy-name-override: ConfigSchema - c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest: - description: ConnectorCatalogServiceConfigurationSchemaRequest is the request for retrieving a connector's configuration schema. - properties: - appId: - description: The ID of the app associated with the connector. Optional. - type: string - catalogId: - description: The catalog entry ID identifying the connector type. - type: string - connectorId: - description: The ID of an existing connector to retrieve its current configuration schema. Optional. - type: string - title: Connector Catalog Service Configuration Schema Request - type: object - x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaRequest - c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse: - description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. - properties: - formSchema: - oneOf: - - $ref: '#/components/schemas/c1.api.form.v1.Form' - - type: "null" - schema: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConfigSchema' - - type: "null" - title: Connector Catalog Service Configuration Schema Response + maxLimit: + description: The maxLimit field. + format: int32 + type: integer + title: Query Scope Limit Config type: object - x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaResponse - c1.api.integration.connector.v1.Field: - description: | - The Field message. - - This message contains a oneof named field. Only a single field of the following list may be set at a time: - - str - - select - - random - - import - - oauth2 - - readOnly - - options - - checkbox - - secret - - strList - - text - - keyValue - - stringMap + x-speakeasy-name-override: QueryScopeLimitConfig + c1.api.hooks.v1.SecretsMaskingConfig: + description: |- + SecretsMaskingConfig configures post-tool-use redaction of secret-shaped + substrings (API keys, tokens, private keys) in tool output. properties: - additionalPlaceholder: + additionalPatterns: description: |- - Optional. Additional placeholder text for the field - In cases where a single placeholder is not enough to describe the field - type: string - checkbox: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.CheckboxField' - - type: "null" - dependsOnFields: - description: The dependsOnFields field. + Extra RE2 regexes whose matches are redacted in addition to the built-in + secret patterns. items: type: string type: - array - "null" - displayName: - description: Human-readable label for this Field - type: string - helpUrl: - description: empty or https URL - type: string - import: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.ImportField' - - type: "null" - keyValue: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.KeyValueField' - - type: "null" - name: - description: Must not start with `C1_` and match [a-zA-Z0-9_]{2,64}. Must be unique within a connector. - type: string - oauth2: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.OAuth2Field' - - type: "null" - options: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.OptionsField' - - type: "null" placeholder: - description: The placeholder field. + description: Replacement string for a matched secret. Empty = "***REDACTED-SECRET***". type: string - postCreate: - description: The postCreate field. - type: boolean - random: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.RandomStringField' - - type: "null" - readOnly: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.ReadOnlyField' - - type: "null" - secret: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.RotatableSecretField' - - type: "null" - select: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField' - - type: "null" - str: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringField' - - type: "null" - strList: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringListField' - - type: "null" - stringMap: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringMapField' - - type: "null" - text: - oneOf: - - $ref: '#/components/schemas/c1.api.integration.connector.v1.TextField' - - type: "null" - title: Field + title: Secrets Masking Config type: object - x-speakeasy-name-override: Field - c1.api.integration.connector.v1.FieldGroup: - description: The FieldGroup message. + x-speakeasy-name-override: SecretsMaskingConfig + c1.api.hooks.v1.SensitiveFileGuardConfig: + description: |- + SensitiveFileGuardConfig blocks tool calls that reference sensitive file + paths or directories. properties: - default: - description: The default field. - type: boolean - displayName: - description: Nice name this group (e.g. renders as a Tab label) - type: string - fieldNames: - description: Field names are "guaranteed" to be unique, but can be repeated in and between lists. + blockedDirectories: + description: The blockedDirectories field. items: type: string type: - array - "null" - helpText: - description: Optional. User-facing help text. - type: string - name: - description: Unique ID. - type: string - title: Field Group - type: object - x-speakeasy-name-override: FieldGroup - c1.api.integration.connector.v1.ImportField: - description: The ImportField message. - properties: - allowedExtensions: - description: The allowedExtensions field. + blockedPatterns: + description: The blockedPatterns field. items: type: string type: - array - "null" - secret: - description: The secret field. - type: boolean - valueValidator: - oneOf: - - $ref: '#/components/schemas/validate.StringRules' - - type: "null" - title: Import Field - type: object - x-speakeasy-name-override: ImportField - c1.api.integration.connector.v1.KeyValueField: - description: The KeyValueField message. - properties: - secret: - description: The secret field. - type: boolean - supportsFileUpload: - description: When true, UI allows file uploads per key-value entry. - type: boolean - title: Key Value Field - type: object - x-speakeasy-name-override: KeyValueField - c1.api.integration.connector.v1.OAuth2Field: - description: The OAuth2Field message. - title: O Auth 2 Field - type: object - x-speakeasy-name-override: OAuth2Field - c1.api.integration.connector.v1.OptionsField: - description: The OptionsField message. - title: Options Field + title: Sensitive File Guard Config type: object - x-speakeasy-name-override: OptionsField - c1.api.integration.connector.v1.RandomStringField: - description: The RandomStringField message. + x-speakeasy-name-override: SensitiveFileGuardConfig + c1.api.hooks.v1.ToolOutputSizeGuardConfig: + description: ToolOutputSizeGuardConfig caps post-tool-use output size in bytes. properties: - length: - description: The length field. + maxBytes: + description: Maximum tool output size in bytes. Outputs exceeding this are denied. format: int32 type: integer - title: Random String Field - type: object - x-speakeasy-name-override: RandomStringField - c1.api.integration.connector.v1.ReadOnlyField: - description: The ReadOnlyField message. - title: Read Only Field - type: object - x-speakeasy-name-override: ReadOnlyField - c1.api.integration.connector.v1.RotatableSecretField: - description: The RotatableSecretField message. - title: Rotatable Secret Field + title: Tool Output Size Guard Config type: object - x-speakeasy-name-override: RotatableSecretField - c1.api.integration.connector.v1.SelectField: - description: The SelectField message. + x-speakeasy-name-override: ToolOutputSizeGuardConfig + c1.api.hooks.v1.WriteAuthorizationConfig: + description: |- + WriteAuthorizationConfig blocks tool calls whose ToolClassification is in + blocked_classifications, optionally permitting them within business hours. properties: - items: - description: list of items that are selected from + blockedClassifications: + description: |- + Tool classifications to block. Must have at least one entry; a hook + with no blocked classifications would be a silent misconfiguration. items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField.Item' + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - title: Select Field - type: object - x-speakeasy-name-override: ConnectorSelectField - c1.api.integration.connector.v1.SelectField.Item: - description: The Item message. - properties: - displayName: - description: The displayName field. - type: string - value: - description: The value field. - type: string - title: Item - type: object - x-speakeasy-name-override: Item - c1.api.integration.connector.v1.StringField: - description: The StringField message. - properties: - secret: - description: If secret, value is write-only in UI and a password-type form is used. - type: boolean - valueValidator: - oneOf: - - $ref: '#/components/schemas/validate.StringRules' - - type: "null" - title: String Field - type: object - x-speakeasy-name-override: StringField - c1.api.integration.connector.v1.StringListField: - description: The StringListField message. - properties: - valueValidator: + businessHours: oneOf: - - $ref: '#/components/schemas/validate.StringRules' + - $ref: '#/components/schemas/c1.api.hooks.v1.BusinessHours' - type: "null" - title: String List Field + title: Write Authorization Config type: object - x-speakeasy-name-override: StringListField - c1.api.integration.connector.v1.StringMapField: - description: The StringMapField message. + x-speakeasy-name-override: WriteAuthorizationConfig + c1.api.iam.v1.ActorObjectPermissions: + description: |- + Legacy: do not use for new objects. Retained only for the existing + AppResource / AppEntitlement / access-review consumers, which will migrate to + c1.api.authorization.v1.ActorObjectPermissions in IGA-2331. New object views + should reference c1.api.authorization.v1.ActorObjectPermissions instead. properties: - optional: - description: The optional field. + delete: + description: The delete field. type: boolean - title: String Map Field + edit: + description: The edit field. + type: boolean + extra: + additionalProperties: + type: boolean + description: The extra field. + type: object + read: + description: The read field. + type: boolean + title: Actor Object Permissions type: object - x-speakeasy-name-override: StringMapField - c1.api.integration.connector.v1.TextField: - description: The TextField message. + x-speakeasy-name-override: ActorObjectPermissions + c1.api.iam.v1.AnnouncedTunnelService: + description: |- + AnnouncedTunnelService is one service entry the appliance declared in its + wormhole HELLO frame. Read live from the discovery store; not persisted. properties: - secret: - description: The secret field. - type: boolean - valueValidator: - oneOf: - - $ref: '#/components/schemas/validate.StringRules' - - type: "null" - title: Text Field + name: + description: Logical name of the service as declared by the appliance. + type: string + port: + description: TCP port the service listens on inside the appliance network. + format: uint32 + type: integer + servicePath: + description: Optional URL path prefix for the service. + type: string + serviceType: + description: Application-level protocol type (e.g. "http", "grpc"). + type: string + transportType: + description: Transport protocol used by the wormhole tunnel (e.g. "tcp"). + type: string + title: Announced Tunnel Service type: object - x-speakeasy-name-override: ConnectorTextField - c1.api.local_directory.v1.LocalDirectoryConfig: + x-speakeasy-name-override: AnnouncedTunnelService + c1.api.iam.v1.ExternalClientInfo: description: |- - LocalDirectoryConfig is the public representation of a C1-managed local - directory configuration. The underlying directory infrastructure is provided - by the linked App (identified by app_id). + ExternalClientInfo provides information about an approved external client. + Used by both List (user's own grants) and Search (admin view of all grants). properties: - allowSelfRegistration: - description: Whether unauthenticated users may self-register in this directory. - type: boolean - appId: - description: app_id is the identifier for this config and its linked App. Read-only after creation. - readOnly: true + clientId: + description: OAuth2 client ID - canonical identifier for this connection (globally unique per DCR) + type: string + clientIdType: + description: How the client_id was established. + enum: + - CLIENT_ID_TYPE_UNSPECIFIED + - CLIENT_ID_TYPE_DCR + - CLIENT_ID_TYPE_METADATA_URL + - CLIENT_ID_TYPE_APP + type: string + x-speakeasy-unknown-values: allow + clientIdUrl: + description: |- + Original CIMD metadata URL (e.g., "https://cursor.com/.well-known/oauth-client"). + Empty for DCR clients. + type: string + clientName: + description: Original client name from DCR registration type: string createdAt: format: date-time - readOnly: true type: - string - "null" - defaultProfileTypeId: - description: Optional FK to a ProfileType applied to new users created via this directory. - type: string displayName: - description: The displayName field. + description: User-provided custom name (defaults to client_name if not set) type: string - invitationTtl: - format: duration + lastUsedAt: + format: date-time type: - string - "null" - isDefault: - description: |- - Whether this is the default local directory for the tenant. - At most one config per tenant may be the default. - type: boolean - onboardingFlowId: - description: Optional FK to an onboarding flow applied by default when inviting users. - type: string - organizationId: - description: Optional FK to a ThirdPartyOrganization. Empty means standalone (no vendor linkage). + mcpClientId: + description: MCP client record ID for AI governance tracking. May be empty for legacy grants. type: string - selfRegistrationDomains: - description: |- - Email domain allowlist for self-registration. Empty allows any domain when - allow_self_registration is true. + roleIds: + description: Role IDs granted to this client - frontend can fetch display names via SearchRoles items: type: string type: - array - "null" - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Local Directory Config - type: object - x-speakeasy-name-override: LocalDirectoryConfig - c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest: - description: The LocalDirectoryConfigServiceCreateRequest message. - properties: - allowSelfRegistration: - description: The allowSelfRegistration field. - type: boolean - appId: - description: FK to the existing App that will back this local directory. - type: string - defaultProfileTypeId: - description: The defaultProfileTypeId field. - type: string - displayName: - description: The displayName field. + userId: + description: The user who approved this external client (always populated) type: string - invitationTtl: - format: duration - type: - - string - - "null" - isDefault: - description: Whether this should be the default local directory for the tenant. - type: boolean - onboardingFlowId: - description: The onboardingFlowId field. + verifiedDomain: + description: |- + Verified domain from the client_id URL (e.g., "cursor.com"). + Empty for DCR clients. type: string - organizationId: - description: Optional FK to a ThirdPartyOrganization. + wellKnownClient: + description: The wellKnownClient field. + enum: + - WELL_KNOWN_CLIENT_UNSPECIFIED + - WELL_KNOWN_CLIENT_UNKNOWN + - WELL_KNOWN_CLIENT_CLAUDE_AI + - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP + - WELL_KNOWN_CLIENT_CLAUDE_CODE + - WELL_KNOWN_CLIENT_MCP_INSPECTOR + - WELL_KNOWN_CLIENT_CHATGPT + - WELL_KNOWN_CLIENT_VSCODE + - WELL_KNOWN_CLIENT_CURSOR + - WELL_KNOWN_CLIENT_WINDSURF + - WELL_KNOWN_CLIENT_ZED + - WELL_KNOWN_CLIENT_JETBRAINS + - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT type: string - selfRegistrationDomains: - description: The selfRegistrationDomains field. + x-speakeasy-unknown-values: allow + title: External Client Info + type: object + x-speakeasy-name-override: ExternalClientInfo + c1.api.iam.v1.ExternalClientSearchServiceSearchRequest: + description: The ExternalClientSearchServiceSearchRequest message. + properties: + clientIdUrls: + description: |- + Exact-match filter on client_id values (e.g., CIMD URLs). + Returns only grants whose client_id matches one of these values. items: type: string type: - array - "null" - required: - - appId - - displayName - title: Local Directory Config Service Create Request + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + query: + description: Free-text search on client_name and user display name + type: string + users: + description: Filter by specific user IDs + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + wellKnownClients: + description: Filter by well-known client type (e.g., CLAUDE_CODE, CURSOR, etc.) + items: + enum: + - WELL_KNOWN_CLIENT_UNSPECIFIED + - WELL_KNOWN_CLIENT_UNKNOWN + - WELL_KNOWN_CLIENT_CLAUDE_AI + - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP + - WELL_KNOWN_CLIENT_CLAUDE_CODE + - WELL_KNOWN_CLIENT_MCP_INSPECTOR + - WELL_KNOWN_CLIENT_CHATGPT + - WELL_KNOWN_CLIENT_VSCODE + - WELL_KNOWN_CLIENT_CURSOR + - WELL_KNOWN_CLIENT_WINDSURF + - WELL_KNOWN_CLIENT_ZED + - WELL_KNOWN_CLIENT_JETBRAINS + - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: External Client Search Service Search Request type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceCreateRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse: - description: The LocalDirectoryConfigServiceCreateResponse message. + x-speakeasy-name-override: ExternalClientSearchServiceSearchRequest + c1.api.iam.v1.ExternalClientSearchServiceSearchResponse: + description: The ExternalClientSearchServiceSearchResponse message. properties: - localDirectoryConfig: - oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - - type: "null" - title: Local Directory Config Service Create Response - type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceCreateResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput: - description: The LocalDirectoryConfigServiceDeleteRequest message. - title: Local Directory Config Service Delete Request - type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse: - description: The LocalDirectoryConfigServiceDeleteResponse message. - title: Local Directory Config Service Delete Response + list: + description: Uses ExternalClientInfo with user_id populated for admin views + items: + $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientInfo' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: External Client Search Service Search Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse: - description: The LocalDirectoryConfigServiceGetResponse message. + x-speakeasy-name-override: ExternalClientSearchServiceSearchResponse + c1.api.iam.v1.GetRolesResponse: + description: The GetRolesResponse message contains the retrieved role. properties: - localDirectoryConfig: + role: oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - $ref: '#/components/schemas/c1.api.iam.v1.Role' - type: "null" - title: Local Directory Config Service Get Response + title: Get Roles Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceGetResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse: - description: The LocalDirectoryConfigServiceListResponse message. + x-speakeasy-name-override: GetRolesResponse + c1.api.iam.v1.ListRolesResponse: + description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. properties: list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + $ref: '#/components/schemas/c1.api.iam.v1.Role' type: - array - "null" nextPageToken: - description: The nextPageToken field. + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Local Directory Config Service List Response + title: List Roles Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceListResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput: - description: The LocalDirectoryConfigServiceUpdateRequest message. + x-speakeasy-name-override: ListRolesResponse + c1.api.iam.v1.PersonalClient: + description: The PersonalClient message contains information about a presonal client credential. properties: - localDirectoryConfig: - oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - - type: "null" - updateMask: + allowSourceCidr: + description: |- + If set, only allows the CIDRs in the array to use the credential. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string type: - - string + - array - "null" - title: Local Directory Config Service Update Request - type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse: - description: The LocalDirectoryConfigServiceUpdateResponse message. - properties: - localDirectoryConfig: - oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - - type: "null" - title: Local Directory Config Service Update Response - type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateResponse - c1.api.local_directory.v1.LocalUserInvitation: - description: LocalUserInvitation is the public representation of a per-directory user invitation. - properties: - acceptedAt: + clientId: + description: The clientID of the credential. + readOnly: true + type: string + createdAt: format: date-time readOnly: true type: - string - "null" - createdAt: + deletedAt: format: date-time readOnly: true type: - string - "null" - createdUserId: - description: Set when status = ACCEPTED. FK to the created User. Read-only. - readOnly: true - type: string - directoryAppId: - description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. Read-only after creation. - readOnly: true - type: string displayName: - description: Display name to pre-populate on the new user account. - type: string - email: - description: Email address the invitation was sent to. + description: The display name of the personal client credential. type: string - expiresAt: + expiresTime: format: date-time - readOnly: true type: - string - "null" id: - description: Unique KSUID identifier. Read-only. + description: The unique ID of the personal client credential. readOnly: true type: string - initialRoleIds: - description: Optional initial role IDs to assign to the user upon acceptance. + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + scopedRoles: + description: |- + scoped_roles provides a list of IAM Roles + that this OAuth2 Client's API permissions + are reduced to. The permissions granted to OAuth2 Client + are AND'ed against the owning User's own permissions. items: type: string type: - array - "null" - invitedByUserId: - description: FK to the User who created the invitation. Read-only. - readOnly: true - type: string - jobId: - description: Optional FK to a ThirdPartyJob. - type: string - onboardingFlowId: - description: Optional onboarding flow override for this invitation. - type: string - purpose: - description: Human-readable reason this user was invited. - type: string - sponsorUserId: - description: Optional sponsor User override for this invitation. - type: string - status: - description: Current lifecycle status. Read-only. - enum: - - LOCAL_INVITATION_STATUS_UNSPECIFIED - - LOCAL_INVITATION_STATUS_PENDING - - LOCAL_INVITATION_STATUS_ACCEPTED - - LOCAL_INVITATION_STATUS_REVOKED - - LOCAL_INVITATION_STATUS_EXPIRED - readOnly: true - type: string - x-speakeasy-unknown-values: allow updatedAt: format: date-time readOnly: true type: - string - "null" - title: Local User Invitation + userId: + description: The ID of the user that this credential is created for. + readOnly: true + type: string + title: Personal Client type: object - x-speakeasy-name-override: LocalUserInvitation - c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput: - description: The LocalUserInvitationServiceCreateRequest message. + x-speakeasy-name-override: PersonalClient + c1.api.iam.v1.PersonalClientSearchServiceSearchRequest: + description: The PersonalClientSearchServiceSearchRequest message. properties: - displayName: - description: The displayName field. + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token returned from a previous Search call. type: string - email: - description: The email field. + query: + description: A text query to filter personal clients by display name. type: string - initialRoleIds: - description: Optional initial role IDs to assign upon acceptance. + users: + description: Filter results to personal clients owned by the specified users. items: - type: string + $ref: '#/components/schemas/c1.api.user.v1.UserRef' type: - array - "null" - jobId: - description: Optional FK to a ThirdPartyJob. - type: string - onboardingFlowId: - description: Optional onboarding flow override. - type: string - purpose: - description: Human-readable reason for the invitation. - type: string - sponsorUserId: - description: Optional sponsor User override. + title: Personal Client Search Service Search Request + type: object + x-speakeasy-name-override: PersonalClientSearchServiceSearchRequest + c1.api.iam.v1.PersonalClientSearchServiceSearchResponse: + description: The PersonalClientSearchServiceSearchResponse message. + properties: + list: + description: The list of personal client credentials matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - required: - - email - - displayName - title: Local User Invitation Service Create Request + title: Personal Client Search Service Search Response type: object - x-speakeasy-name-override: LocalUserInvitationServiceCreateRequest - c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse: - description: The LocalUserInvitationServiceCreateResponse message. + x-speakeasy-name-override: PersonalClientSearchServiceSearchResponse + c1.api.iam.v1.PersonalClientServiceCreateRequest: + description: The PersonalClientServiceCreateRequest message contains the fields for creating a new personal client. properties: - invitation: - oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - - type: "null" - title: Local User Invitation Service Create Response + allowSourceCidr: + description: |- + A list of CIDRs to restrict this credential to. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + displayName: + description: The display name for the new personal client. + type: string + expires: + format: duration + type: + - string + - "null" + scopedRoles: + description: The list of roles to restrict the credential to. + items: + type: string + type: + - array + - "null" + title: Personal Client Service Create Request type: object - x-speakeasy-name-override: LocalUserInvitationServiceCreateResponse - c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse: - description: The LocalUserInvitationServiceGetResponse message. + x-speakeasy-name-override: PersonalClientServiceCreateRequest + c1.api.iam.v1.PersonalClientServiceCreateResponse: + description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. properties: - invitation: + client: oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - type: "null" - title: Local User Invitation Service Get Response + clientSecret: + description: The client secret that corresponds to the personal client. Make sure to save this, because it cannot be returned or queried again. + type: string + title: Personal Client Service Create Response type: object - x-speakeasy-name-override: LocalUserInvitationServiceGetResponse - c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput: - description: The LocalUserInvitationServiceRevokeRequest message. - title: Local User Invitation Service Revoke Request + x-speakeasy-name-override: PersonalClientServiceCreateResponse + c1.api.iam.v1.PersonalClientServiceDeleteRequestInput: + description: The PersonalClientServiceDeleteRequest message. + title: Personal Client Service Delete Request type: object - x-speakeasy-name-override: LocalUserInvitationServiceRevokeRequest - c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse: - description: The LocalUserInvitationServiceRevokeResponse message. + x-speakeasy-name-override: PersonalClientServiceDeleteRequest + c1.api.iam.v1.PersonalClientServiceDeleteResponse: + description: The PersonalClientServiceDeleteResponse message. + title: Personal Client Service Delete Response + type: object + x-speakeasy-name-override: PersonalClientServiceDeleteResponse + c1.api.iam.v1.PersonalClientServiceGetResponse: + description: The PersonalClientServiceGetResponse message. properties: - invitation: + client: oneOf: - - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - type: "null" - title: Local User Invitation Service Revoke Response - type: object - x-speakeasy-name-override: LocalUserInvitationServiceRevokeResponse - c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest: - description: The LocalUserInvitationServiceSearchRequest message. - properties: - directoryAppId: - description: The directoryAppId field. - type: string - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - statusFilter: - description: Optional filter by invitation status. - enum: - - LOCAL_INVITATION_STATUS_UNSPECIFIED - - LOCAL_INVITATION_STATUS_PENDING - - LOCAL_INVITATION_STATUS_ACCEPTED - - LOCAL_INVITATION_STATUS_REVOKED - - LOCAL_INVITATION_STATUS_EXPIRED - type: string - x-speakeasy-unknown-values: allow - title: Local User Invitation Service Search Request + title: Personal Client Service Get Response type: object - x-speakeasy-name-override: LocalUserInvitationServiceSearchRequest - c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse: - description: The LocalUserInvitationServiceSearchResponse message. + x-speakeasy-name-override: PersonalClientServiceGetResponse + c1.api.iam.v1.PersonalClientServiceListResponse: + description: The PersonalClientServiceListResponse message. properties: list: - description: The list field. + description: The list of personal client credentials owned by the calling user. items: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' type: - array - "null" nextPageToken: - description: The nextPageToken field. - type: string - title: Local User Invitation Service Search Response - type: object - x-speakeasy-name-override: LocalUserInvitationServiceSearchResponse - c1.api.policy.v1.Accept: - description: This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - properties: - acceptMessage: - description: An optional message to include in the comments when a task is automatically accepted. - type: string - title: Accept - type: object - x-speakeasy-name-override: Accept - c1.api.policy.v1.AcceptInstance: - description: |- - This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - The instance is just a marker for it being copied into an active policy. - properties: - acceptMessage: - description: An optional message to include in the comments when a task is automatically accepted. + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - title: Accept Instance + title: Personal Client Service List Response type: object - x-speakeasy-name-override: AcceptInstance - c1.api.policy.v1.Action: - description: | - The Action message. - - This message contains a oneof named target. Only a single field of the following list may be set at a time: - - automation - - batonResourceAction - - clientIdApproval + x-speakeasy-name-override: PersonalClientServiceListResponse + c1.api.iam.v1.PersonalClientServiceUpdateRequestInput: + description: The PersonalClientServiceUpdateRequest message. properties: - automation: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomation' - - type: "null" - batonResourceAction: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceAction' - - type: "null" - clientIdApproval: + client: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApproval' + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - type: "null" - title: Action + updateMask: + type: + - string + - "null" + title: Personal Client Service Update Request type: object - x-speakeasy-name-override: Action - c1.api.policy.v1.ActionInstance: - description: | - The ActionInstance message. - - This message contains a oneof named target_instance. Only a single field of the following list may be set at a time: - - automation - - batonResourceActionInstance - - clientIdApprovalInstance - - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - success - - denied - - error - - cancelled + x-speakeasy-name-override: PersonalClientServiceUpdateRequest + c1.api.iam.v1.PersonalClientServiceUpdateResponse: + description: The PersonalClientServiceUpdateResponse message. properties: - action: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Action' - - type: "null" - automation: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomationInstance' - - type: "null" - batonResourceActionInstance: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceActionInstance' - - type: "null" - cancelled: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeCancelled' - - type: "null" - clientIdApprovalInstance: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApprovalInstance' - - type: "null" - denied: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeDenied' - - type: "null" - error: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeError' - - type: "null" - state: - description: The current state of the action execution. - enum: - - ACTION_INSTANCE_STATE_UNSPECIFIED - - ACTION_INSTANCE_STATE_INIT - - ACTION_INSTANCE_STATE_RUNNING - - ACTION_INSTANCE_STATE_DONE - - ACTION_INSTANCE_STATE_ERROR - type: string - x-speakeasy-unknown-values: allow - success: + client: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeSuccess' + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - type: "null" - title: Action Instance + title: Personal Client Service Update Response type: object - x-speakeasy-name-override: ActionInstance - c1.api.policy.v1.ActionOutcomeCancelled: - description: The ActionOutcomeCancelled message. + x-speakeasy-name-override: PersonalClientServiceUpdateResponse + c1.api.iam.v1.PersonalDevice: + description: |- + PersonalDevice is one physical device with its app clients. The device + identity is a stable thumbprint of the device's root signing key; the root key + never authenticates an app — each client uses its own key. properties: - outcomeTime: + createdAt: format: date-time + readOnly: true type: - string - "null" - title: Action Outcome Cancelled - type: object - x-speakeasy-name-override: ActionOutcomeCancelled - c1.api.policy.v1.ActionOutcomeDenied: - description: The ActionOutcomeDenied message. - properties: - outcomeTime: + deviceId: + description: |- + The stable device identity: a base64url-encoded SHA-256 thumbprint of the + device's root public signing key. + readOnly: true + type: string + deviceOs: + description: The device operating system, e.g. "macos-14.5". + readOnly: true + type: string + deviceSurface: + description: The device surface, e.g. "macos-desktop". + readOnly: true + type: string + displayName: + description: |- + The human-friendly device label, defaulted from the first app's name at + registration. Devices are listed sorted by this name. Mutable via + UpdateDevice. + type: string + status: + description: |- + The device's lifecycle status. Revoked devices are retained for audit and are + returned by Search only when the status filter requests them. + enum: + - PERSONAL_DEVICE_STATUS_UNSPECIFIED + - PERSONAL_DEVICE_STATUS_ACTIVE + - PERSONAL_DEVICE_STATUS_REVOKED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + updatedAt: format: date-time + readOnly: true type: - string - "null" - title: Action Outcome Denied + userId: + description: The ID of the user this device is bound to (the approving user). + readOnly: true + type: string + title: Personal Device type: object - x-speakeasy-name-override: ActionOutcomeDenied - c1.api.policy.v1.ActionOutcomeError: - description: The ActionOutcomeError message. + x-speakeasy-name-override: PersonalDevice + c1.api.iam.v1.PersonalDeviceClient: + description: |- + PersonalDeviceClient is a single app client on a device. The client + authenticates with its own asymmetric key; there is no client secret. properties: - errorCode: - description: The errorCode field. + clientId: + description: The full client_id of the device credential. + readOnly: true type: string - errorMessage: - description: The errorMessage field. + clientName: + description: The human-friendly client name from its registration metadata. + readOnly: true type: string - outcomeTime: + consumerKeyId: + description: The stable identity of this client's per-app key. + readOnly: true + type: string + createdAt: format: date-time + readOnly: true type: - string - "null" - title: Action Outcome Error - type: object - x-speakeasy-name-override: ActionOutcomeError - c1.api.policy.v1.ActionOutcomeSuccess: - description: The ActionOutcomeSuccess message. - properties: - outcomeTime: + deviceOs: + description: The device operating system captured for this client, e.g. "macos-14.5". + readOnly: true + type: string + deviceSurface: + description: The device surface captured for this client, e.g. "macos-desktop". + readOnly: true + type: string + displayName: + description: The display name of the device credential. + readOnly: true + type: string + id: + description: The unique ID of the device client (the local part of client_id). + readOnly: true + type: string + lastUsedAt: format: date-time + readOnly: true type: - string - "null" - title: Action Outcome Success - type: object - x-speakeasy-name-override: ActionOutcomeSuccess - c1.api.policy.v1.ActionProvision: - description: This provision step indicates that account lifecycle action should be called to provision this entitlement. - properties: - actionName: - description: The actionName field. - type: string - appId: - description: The appId field. - type: string - connectorId: - description: The connectorId field. + softwareId: + description: An identifier for the client software, from its registration metadata. + readOnly: true type: string - displayName: - description: The displayName field. + softwareVersion: + description: The version of the client software, from its registration metadata. + readOnly: true type: string - title: Action Provision + title: Personal Device Client type: object - x-speakeasy-name-override: ActionProvision - c1.api.policy.v1.ActionTargetAutomation: - description: ActionTargetAutomation targets automation templates for policy actions. + x-speakeasy-name-override: PersonalDeviceClient + c1.api.iam.v1.PersonalDeviceServiceGetDeviceResponse: + description: The PersonalDeviceServiceGetDeviceResponse message. properties: - automationTemplateId: - description: The automationTemplateId field. - type: string - title: Action Target Automation + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + title: Personal Device Service Get Device Response type: object - x-speakeasy-name-override: ActionTargetAutomation - c1.api.policy.v1.ActionTargetAutomationInstance: - description: The ActionTargetAutomationInstance message. + x-speakeasy-name-override: PersonalDeviceServiceGetDeviceResponse + c1.api.iam.v1.PersonalDeviceServiceListDeviceClientsResponse: + description: The PersonalDeviceServiceListDeviceClientsResponse message. properties: - automationExecutionId: - description: The automationExecutionId field. + clients: + description: The app clients registered on the device. + items: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceClient' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more. type: string - title: Action Target Automation Instance + title: Personal Device Service List Device Clients Response type: object - x-speakeasy-name-override: ActionTargetAutomationInstance - c1.api.policy.v1.ActionTargetBatonResourceAction: - description: ActionTargetResource targets resource actions for policy actions. - properties: - batonResourceActionId: - description: The batonResourceActionId field. - type: string - title: Action Target Baton Resource Action + x-speakeasy-name-override: PersonalDeviceServiceListDeviceClientsResponse + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientRequestInput: + description: The PersonalDeviceServiceRevokeDeviceClientRequest message. + title: Personal Device Service Revoke Device Client Request type: object - x-speakeasy-name-override: ActionTargetBatonResourceAction - c1.api.policy.v1.ActionTargetBatonResourceActionInstance: - description: The ActionTargetBatonResourceActionInstance message. - properties: - batonActionInvocationId: - description: The batonActionInvocationId field. - type: string - title: Action Target Baton Resource Action Instance + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientRequest + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientResponse: + description: The PersonalDeviceServiceRevokeDeviceClientResponse message. + title: Personal Device Service Revoke Device Client Response type: object - x-speakeasy-name-override: ActionTargetBatonResourceActionInstance - c1.api.policy.v1.ActionTargetClientIdApproval: - description: |- - ActionTargetClientIdApproval targets administrator review of an external - OAuth client registration (CIMD or DCR) for policy actions. - title: Action Target Client Id Approval + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientResponse + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceRequestInput: + description: The PersonalDeviceServiceRevokeDeviceRequest message. + title: Personal Device Service Revoke Device Request type: object - x-speakeasy-name-override: ActionTargetClientIdApproval - c1.api.policy.v1.ActionTargetClientIdApprovalInstance: - description: |- - ActionTargetClientIdApprovalInstance carries the registration key of the - external OAuth client that is being reviewed. - properties: - clientIdUrl: - description: The clientIdUrl field. - type: string - title: Action Target Client Id Approval Instance + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceRequest + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceResponse: + description: The PersonalDeviceServiceRevokeDeviceResponse message. + title: Personal Device Service Revoke Device Response type: object - x-speakeasy-name-override: ActionTargetClientIdApprovalInstance - c1.api.policy.v1.AgentApproval: - description: The agent to assign the task to. + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceResponse + c1.api.iam.v1.PersonalDeviceServiceSearchRequest: + description: The PersonalDeviceServiceSearchRequest message. properties: - agentFailureAction: - description: The action to take if the agent fails to approve, deny, or reassign the task. - enum: - - APPROVAL_AGENT_FAILURE_ACTION_UNSPECIFIED - - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_USERS - - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_SUPER_ADMINS - - APPROVAL_AGENT_FAILURE_ACTION_SKIP_POLICY_STEP + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token returned from a previous Search call. type: string - x-speakeasy-unknown-values: allow - agentMode: - description: The mode of the agent, full control, change policy only, or comment only. + query: + description: An optional case-insensitive filter on the device display name. + type: string + statusFilter: + description: Which device statuses to return. Defaults to active devices only. enum: - - APPROVAL_AGENT_MODE_UNSPECIFIED - - APPROVAL_AGENT_MODE_FULL_CONTROL - - APPROVAL_AGENT_MODE_CHANGE_POLICY_ONLY - - APPROVAL_AGENT_MODE_COMMENT_ONLY + - PERSONAL_DEVICE_STATUS_FILTER_UNSPECIFIED + - PERSONAL_DEVICE_STATUS_FILTER_ACTIVE + - PERSONAL_DEVICE_STATUS_FILTER_REVOKED + - PERSONAL_DEVICE_STATUS_FILTER_ALL type: string x-speakeasy-unknown-values: allow - agentUserId: - deprecated: true - description: |- - Deprecated: agent steps are evaluated by the system; no agent user is - selected. Retained so pre-migration policies still validate. - type: string - instructions: - description: Instructions for the agent. - type: string - policyIds: - description: The allow list of policy IDs to re-route the task to. + title: Personal Device Service Search Request + type: object + x-speakeasy-name-override: PersonalDeviceServiceSearchRequest + c1.api.iam.v1.PersonalDeviceServiceSearchResponse: + description: The PersonalDeviceServiceSearchResponse message. + properties: + list: + description: The devices the calling user has registered, matching the search criteria. items: - type: string + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' type: - array - "null" - reassignToUserIds: - description: The users to reassign the task to if the agent failure action is reassign to users. - items: - type: string + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more. + type: string + title: Personal Device Service Search Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceSearchResponse + c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceRequestInput: + description: The PersonalDeviceServiceUpdateDeviceRequest message. + properties: + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + updateMask: type: - - array + - string - "null" - title: Agent Approval + title: Personal Device Service Update Device Request type: object - x-speakeasy-name-override: AgentApproval - c1.api.policy.v1.AppEntitlementReference: - description: This object references an app entitlement's ID and AppID. + x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceRequest + c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceResponse: + description: The PersonalDeviceServiceUpdateDeviceResponse message. properties: - appEntitlementId: - description: The ID of the Entitlement. - type: string - appId: - description: The ID of the App this entitlement belongs to. - type: string - title: App Entitlement Reference + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + title: Personal Device Service Update Device Response type: object - x-speakeasy-name-override: AppEntitlementReference - c1.api.policy.v1.AppGroupApproval: - description: The AppGroupApproval object provides the configuration for setting a group as the approvers of an approval policy step. + x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceResponse + c1.api.iam.v1.Role: + description: Role is a role that can be assigned to a user in ConductorOne. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is a member of the group during this step. - type: boolean - appGroupId: - description: The ID of the group specified for approval. + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the role. type: string - appId: - description: The ID of the app that contains the group specified for approval. + id: + description: The id of the role. + readOnly: true type: string - fallback: - description: Configuration to allow a fallback if the group is empty. - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the group is empty. + name: + description: The internal name of the role. + readOnly: true + type: string + permissions: + description: The list of permissions this role has. items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: string type: - array - "null" - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the group is empty. + serviceRoles: + description: The list of serviceRoles that this role has. items: type: string type: - array - "null" - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - type: boolean - title: App Group Approval - type: object - x-speakeasy-name-override: AppGroupApproval - c1.api.policy.v1.AppOwnerApproval: - description: App owner approval provides the configuration for an approval step when the app owner is the target. - properties: - allowSelfApproval: - description: Configuration that allows a user to self approve if they are an app owner during this approval step. + systemApiOnly: + description: This Role is intended for API keys usage only, and the user interface may not function as expected. + readOnly: true type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. + systemBuiltin: + description: The system builtin field. If this field is set, the role is not editable. + readOnly: true type: boolean - title: App Owner Approval + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Role type: object - x-speakeasy-name-override: AppOwnerApproval - c1.api.policy.v1.AppOwnerProvisioner: - description: AppOwnerProvisioner resolves to app owners. + x-speakeasy-name-override: Role + c1.api.iam.v1.TunnelAppliance: + description: |- + TunnelAppliance is the live state of the customer-side appliance for one + bridge. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - type: boolean - fallbackUserIds: - description: Fallback user IDs if no app owners are found. + announcedServiceCount: + description: Number of services the appliance is currently announcing. + format: uint32 + type: integer + lastSeenAt: + format: date-time + type: + - string + - "null" + links: + description: |- + Wormhole relays currently holding a Link for this bridge. Typically of + length 1. items: - type: string + $ref: '#/components/schemas/c1.api.iam.v1.TunnelApplianceLink' type: - array - "null" - title: App Owner Provisioner + status: + description: The status field. + enum: + - TUNNEL_APPLIANCE_STATUS_UNSPECIFIED + - TUNNEL_APPLIANCE_STATUS_CONNECTED + - TUNNEL_APPLIANCE_STATUS_DISCONNECTED + - TUNNEL_APPLIANCE_STATUS_NEVER_CONNECTED + type: string + x-speakeasy-unknown-values: allow + title: Tunnel Appliance type: object - x-speakeasy-name-override: AppOwnerProvisioner - c1.api.policy.v1.Approval: - description: | - The Approval message. - - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - users - - manager - - appOwners - - group - - self - - entitlementOwners - - expression - - webhook - - resourceOwners - - agent + x-speakeasy-name-override: TunnelAppliance + c1.api.iam.v1.TunnelApplianceLink: + description: The TunnelApplianceLink message. properties: - agent: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.AgentApproval' - - type: "null" - allowDelegation: - description: Whether ticket delegation is allowed for this step. - type: boolean - allowReassignment: - description: Configuration to allow reassignment by reviewers during this step. - type: boolean - allowedReassignees: - description: List of users for whom this step can be reassigned. - items: - type: string + avgRtt: + format: duration type: - - array + - string - "null" - appOwners: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerApproval' - - type: "null" - assigned: - description: A field indicating whether this step is assigned. - readOnly: true - type: boolean - entitlementOwners: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerApproval' - - type: "null" - escalation: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Escalation' - - type: "null" - escalationEnabled: - description: Whether escalation is enabled for this step. - type: boolean - expression: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionApproval' - - type: "null" - group: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.AppGroupApproval' - - type: "null" - manager: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ManagerApproval' - - type: "null" - requireApprovalReason: - description: Configuration to require a reason when approving this step. - type: boolean - requireDenialReason: - description: Configuration to require a reason when denying this step. - type: boolean - requireReassignmentReason: - description: Configuration to require a reason when reassigning this step. - type: boolean - requiresStepUpProviderId: + leaseExpiresAt: + format: date-time + type: + - string + - "null" + relayAddress: description: |- - The ID of a step-up authentication provider that will be required for approvals on this step. - If set, approvers must complete the step-up authentication flow before they can approve. + Public address (host:port) of the relay server, suitable for use in + client-side connection strings. type: string - resourceOwners: + relayId: + description: Identifier of the wormhole relay server holding this Link. + type: string + title: Tunnel Appliance Link + type: object + x-speakeasy-name-override: TunnelApplianceLink + c1.api.iam.v1.TunnelBridge: + description: |- + TunnelBridge is the API view of a bridge — the customer-facing entity + for managing a wormhole tunnel appliance. + properties: + appliance: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ResourceOwnerApproval' - - type: "null" - self: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.SelfApproval' - - type: "null" - users: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.UserApproval' - - type: "null" - webhook: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WebhookApproval' + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelAppliance' - type: "null" - title: Approval + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: The description field. + type: string + displayName: + description: The displayName field. + type: string + id: + description: The id field. + readOnly: true + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Tunnel Bridge type: object - x-speakeasy-name-override: Approval - c1.api.policy.v1.ApprovalInstance: - description: | - The approval instance object describes the way a policy step should be approved as well as its outcomes and state. - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - approved - - denied - - reassigned - - restarted - - reassignedByError - - skipped + x-speakeasy-name-override: TunnelBridge + c1.api.iam.v1.TunnelCredential: + description: |- + TunnelCredential is the API view of one OAuth credential within a bridge. + The plaintext client_secret is only populated on the CreateBridgeCredential + response. properties: - approval: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Approval' - - type: "null" - approved: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ApprovedAction' - - type: "null" - assignedAt: + bridgeId: + description: The bridge this credential belongs to. + readOnly: true + type: string + clientId: + description: The client_id (full ${id}@${tenant_domain}/tcc form). + readOnly: true + type: string + clientSecret: + description: |- + The plaintext client_secret. ONLY populated on the + CreateBridgeCredential response; empty on Get / List. + readOnly: true + type: string + createdAt: format: date-time readOnly: true type: - string - "null" - denied: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.DeniedAction' - - type: "null" - escalationInstance: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance' - - type: "null" - reassigned: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' - - type: "null" - reassignedByError: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' - - type: "null" - restarted: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' - - type: "null" - skipped: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' - - type: "null" - state: - description: The state of the approval instance + credentialStatus: + description: Lifecycle status of this credential record. enum: - - APPROVAL_INSTANCE_STATE_UNSPECIFIED - - APPROVAL_INSTANCE_STATE_INIT - - APPROVAL_INSTANCE_STATE_SENDING_NOTIFICATIONS - - APPROVAL_INSTANCE_STATE_WAITING - - APPROVAL_INSTANCE_STATE_DONE + - TUNNEL_CREDENTIAL_STATUS_UNSPECIFIED + - TUNNEL_CREDENTIAL_STATUS_ACTIVE + - TUNNEL_CREDENTIAL_STATUS_REVOKED + - TUNNEL_CREDENTIAL_STATUS_EXPIRED readOnly: true type: string x-speakeasy-unknown-values: allow - title: Approval Instance - type: object - x-speakeasy-name-override: ApprovalInstance - c1.api.policy.v1.ApprovedAction: - description: The approved action indicates that the approvalinstance had an outcome of approved. - properties: - approvedAt: + deletedAt: format: date-time readOnly: true type: - string - "null" - entitlements: - description: The entitlements that were approved. This will only ever be a list of one entitlement. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + expiresTime: + format: date-time readOnly: true type: - - array + - string - "null" - stepUpTransactionId: - description: The ID of the step-up transaction that was used for this approval, if step-up was required. - readOnly: true - type: string - userId: - description: The UserID that approved this step. + id: + description: The id field. readOnly: true type: string - title: Approved Action - type: object - x-speakeasy-name-override: ApprovedAction - c1.api.policy.v1.CancelledAction: - description: The outcome of a provision instance that is cancelled. - properties: - cancelledAt: + lastUsedAt: format: date-time + readOnly: true type: - string - "null" - cancelledByUserId: - description: The userID, usually the system, that cancells a provision instance. - type: string - title: Cancelled Action - type: object - x-speakeasy-name-override: CancelledAction - c1.api.policy.v1.CompletedAction: - description: The outcome of a provision instance that has been completed succesfully. - properties: - completedAt: + revokedAt: format: date-time + readOnly: true type: - string - "null" - entitlements: - description: The list of entitlements that were provisioned. This is leftover from an older design, and is only ever going to be a single entitlement. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + updatedAt: + format: date-time + readOnly: true type: - - array + - string - "null" - userId: - description: The UserID of who completed provisioning. For connector provisioning this is the system user id, for manual provisioning this is who clicked "provision complete" - type: string - title: Completed Action + title: Tunnel Credential type: object - x-speakeasy-name-override: CompletedAction - c1.api.policy.v1.ConnectorProvision: - description: | - Indicates that a connector should perform the provisioning. This object has no fields. - - This message contains a oneof named provision_type. Only a single field of the following list may be set at a time: - - defaultBehavior - - account - - deleteAccount + x-speakeasy-name-override: TunnelCredential + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialRequestInput: + description: The TunnelCredentialsServiceCreateBridgeCredentialRequest message. + title: Tunnel Credentials Service Create Bridge Credential Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialRequest + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialResponse: + description: The TunnelCredentialsServiceCreateBridgeCredentialResponse message. properties: - account: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.AccountProvision' - - type: "null" - defaultBehavior: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DefaultBehavior' - - type: "null" - deleteAccount: + credential: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DeleteAccount' + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' - type: "null" - title: Connector Provision + title: Tunnel Credentials Service Create Bridge Credential Response type: object - x-speakeasy-name-override: ConnectorProvision - c1.api.policy.v1.ConnectorProvision.AccountProvision: - description: | - The AccountProvision message. - - This message contains a oneof named storage_type. Only a single field of the following list may be set at a time: - - saveToVault - - doNotSave + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialResponse + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeRequest: + description: The TunnelCredentialsServiceCreateBridgeRequest message. properties: - config: - additionalProperties: true - type: - - object - - "null" - connectorId: - description: The connectorId field. + description: + description: The description field. type: string - doNotSave: + displayName: + description: The displayName field. + type: string + title: Tunnel Credentials Service Create Bridge Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeResponse: + description: The TunnelCredentialsServiceCreateBridgeResponse message. + properties: + bridge: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DoNotSave' + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' - type: "null" - saveToVault: + title: Tunnel Credentials Service Create Bridge Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeRequestInput: + description: The TunnelCredentialsServiceDeleteBridgeRequest message. + title: Tunnel Credentials Service Delete Bridge Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeResponse: + description: Empty response body. Status code indicates success. + title: Tunnel Credentials Service Delete Bridge Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceGetBridgeResponse: + description: The TunnelCredentialsServiceGetBridgeResponse message. + properties: + bridge: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.SaveToVault' + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' - type: "null" - schemaId: - description: The schemaId field. - type: string - title: Account Provision + title: Tunnel Credentials Service Get Bridge Response type: object - x-speakeasy-name-override: AccountProvision - c1.api.policy.v1.ConnectorProvision.DefaultBehavior: - description: The DefaultBehavior message. + x-speakeasy-name-override: TunnelCredentialsServiceGetBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgeAnnouncedServicesResponse: + description: The TunnelCredentialsServiceListBridgeAnnouncedServicesResponse message. properties: - connectorId: - description: |- - this checks if the entitlement is enabled by provisioning in a specific connector - this can happen automatically and doesn't need any extra info - type: string - title: Default Behavior + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.iam.v1.AnnouncedTunnelService' + type: + - array + - "null" + title: Tunnel Credentials Service List Bridge Announced Services Response type: object - x-speakeasy-name-override: DefaultBehavior - c1.api.policy.v1.ConnectorProvision.DeleteAccount: - description: The DeleteAccount message. + x-speakeasy-name-override: TunnelCredentialsServiceListBridgeAnnouncedServicesResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgeCredentialsResponse: + description: The TunnelCredentialsServiceListBridgeCredentialsResponse message. properties: - connectorId: - description: The connectorId field. + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Delete Account - type: object - x-speakeasy-name-override: DeleteAccount - c1.api.policy.v1.ConnectorProvision.DoNotSave: - description: The DoNotSave message. - title: Do Not Save + title: Tunnel Credentials Service List Bridge Credentials Response type: object - x-speakeasy-name-override: DoNotSave - c1.api.policy.v1.ConnectorProvision.SaveToVault: - description: The SaveToVault message. + x-speakeasy-name-override: TunnelCredentialsServiceListBridgeCredentialsResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgesResponse: + description: The TunnelCredentialsServiceListBridgesResponse message. properties: - vaultIds: - description: The vaultIds field. + list: + description: The list field. items: - type: string + $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' type: - array - "null" - title: Save To Vault + nextPageToken: + description: The nextPageToken field. + type: string + title: Tunnel Credentials Service List Bridges Response type: object - x-speakeasy-name-override: SaveToVault - c1.api.policy.v1.CreatePolicyRequest: - description: The CreatePolicyRequest message is used to create a new policy. + x-speakeasy-name-override: TunnelCredentialsServiceListBridgesResponse + c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialRequestInput: + description: The TunnelCredentialsServiceRevokeBridgeCredentialRequest message. + title: Tunnel Credentials Service Revoke Bridge Credential Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialRequest + c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialResponse: + description: Empty response body. Status code indicates success. + title: Tunnel Credentials Service Revoke Bridge Credential Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialResponse + c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeRequestInput: + description: The TunnelCredentialsServiceUpdateBridgeRequest message. properties: - annotations: - additionalProperties: - type: string - description: |- - Bounded key/value metadata bag for IaC marking and customer tags. - See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 - chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars - matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting - with `c1/` are reserved for server-managed use and rejected on write. - - Well-known keys: `managed_by`, `iac_workspace`, - `iac_resource_address`, `iac_tool_version`. - type: object - x-speakeasy-terraform-plan-modifier: - imports: - - github.com/conductorone/terraform-provider-conductorone/internal/annotations - schemaDefinition: annotations.PlanModifier() description: - description: The description of the new policy. + description: |- + New description. Applied only when "description" is in update_mask. + Empty clears the description. type: string displayName: - description: The display name of the new policy. - type: string - policySteps: - additionalProperties: - $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' description: |- - Step sequences for this policy. The map must include a baseline entry keyed - by the lowercased policy type (e.g., "grant"). Additional entries with - opaque keys can be added for conditional routing via the rules array. - type: object - policyType: - description: The type of policy to create (grant, revoke, or certify). - enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION + New display name. Applied only when "display_name" is in update_mask. + Must be non-empty when applied. type: string - x-speakeasy-unknown-values: allow - postActions: - description: Ordered actions to execute after the policy completes processing. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' - type: - - array - - "null" - reassignTasksToDelegates: - deprecated: true - description: This field is no longer used. Configure delegate reassignment in the policy step instead. - type: boolean - rules: - description: Conditional routing rules. See the Policy message for details on evaluation order. - items: - $ref: '#/components/schemas/c1.api.policy.v1.Rule' + updateMask: type: - - array + - string - "null" - required: - - displayName - title: Create Policy Request + title: Tunnel Credentials Service Update Bridge Request type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: CreatePolicyRequest - c1.api.policy.v1.CreatePolicyResponse: - description: The CreatePolicyResponse message contains the created policy object. + x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeResponse: + description: The TunnelCredentialsServiceUpdateBridgeResponse message. properties: - policy: + bridge: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' - type: "null" - title: Create Policy Response + title: Tunnel Credentials Service Update Bridge Response type: object - x-speakeasy-name-override: CreatePolicyResponse - c1.api.policy.v1.DelegatedProvision: - description: This provision step indicates that we should delegate provisioning to the configuration of another app entitlement. This app entitlement does not have to be one from the same app, but MUST be configured as a proxy binding leading into this entitlement. + x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeResponse + c1.api.iam.v1.UpdateRoleRequestInput: + description: The UpdateRoleRequest message contains the role to update and the update mask. properties: - appId: - description: The AppID of the entitlement to delegate provisioning to. - type: string - entitlementId: - description: The ID of the entitlement we are delegating provisioning to. - type: string - implicit: - description: If true, a binding will be automatically created from the entitlement of the parent app. - type: boolean - title: Delegated Provision - type: object - x-speakeasy-name-override: DelegatedProvision - c1.api.policy.v1.DeletePolicyRequestInput: - description: The DeletePolicyRequest message contains the ID of the policy to delete. It uses URL value for input. - title: Delete Policy Request + role: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Role Request type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: DeletePolicyRequest - c1.api.policy.v1.DeletePolicyResponse: - description: Empty response with a status code indicating success. - title: Delete Policy Response + x-speakeasy-name-override: UpdateRoleRequest + c1.api.iam.v1.UpdateRolesResponse: + description: UpdateRolesResponse is the response message containing the updated role. + properties: + role: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - type: "null" + title: Update Roles Response type: object - x-speakeasy-name-override: DeletePolicyResponse - c1.api.policy.v1.DeniedAction: - description: The denied action indicates that the c1.api.policy.v1.ApprovalInstance had an outcome of denied. + x-speakeasy-name-override: UpdateRolesResponse + c1.api.identity_platform.v1.IdentityPolicyTenantDefaults: + description: |- + IdentityPolicyTenantDefaults is the tenant-wide set of default identity + policies applied when no more specific policy matches a user. properties: - deniedAt: + createdAt: format: date-time readOnly: true type: - string - "null" - userId: - description: The UserID that denied this step. - readOnly: true + credentialInventoryPolicyId: + description: The default credential inventory policy (which credential types users may enroll). type: string - title: Denied Action - type: object - x-speakeasy-name-override: DeniedAction - c1.api.policy.v1.EditorValidateRequest: - description: The EditorValidateRequest message. - properties: - text: - description: The text field. + enrollmentRequirementId: + description: The default enrollment requirement. type: string - title: Editor Validate Request - type: object - x-speakeasy-name-override: PolicyEditorValidateRequest - c1.api.policy.v1.EditorValidateResponse: - description: The EditorValidateResponse message. - properties: - markers: - description: The markers field. - items: - $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' - type: - - array - - "null" - title: Editor Validate Response - type: object - x-speakeasy-name-override: PolicyEditorValidateResponse - c1.api.policy.v1.EntitlementOwnerApproval: - description: The entitlement owner approval allows configuration of the approval step when the target approvers are the entitlement owners. - properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is an entitlement owner during this step. - type: boolean - fallback: - description: Configuration to allow a fallback if the entitlement owner cannot be identified. - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the entitlement owner cannot be identified. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - type: - - array - - "null" - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the entitlement owner cannot be identified. - items: - type: string - type: - - array - - "null" - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - type: boolean - title: Entitlement Owner Approval - type: object - x-speakeasy-name-override: EntitlementOwnerApproval - c1.api.policy.v1.EntitlementOwnerProvisioner: - description: EntitlementOwnerProvisioner resolves to entitlement owners. - properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - type: boolean - fallbackUserIds: - description: Fallback user IDs if no entitlement owners are found. + recoveryPolicyId: + description: The default recovery policy. + type: string + resourcePolicyId: + description: The default resource policy. + type: string + sessionPolicyId: + description: The default session policy. + type: string + signInPolicyId: + description: The default sign-in policy. + type: string + universalPromiseIds: + description: |- + Tenant-wide promises every user must satisfy (e.g. terms-of-service + acceptance). items: type: string type: - array - "null" - title: Entitlement Owner Provisioner - type: object - x-speakeasy-name-override: EntitlementOwnerProvisioner - c1.api.policy.v1.ErroredAction: - description: The outcome of a provision instance that has errored. - properties: - description: - description: The description of a provision instance that has errored. - type: string - errorCode: - description: The error code of a provision instance that has errored. This is only PEC-1 for now, but more will be added in the future. - type: string - erroredAt: + updatedAt: format: date-time + readOnly: true type: - string - "null" - title: Errored Action + title: Identity Policy Tenant Defaults type: object - x-speakeasy-name-override: ErroredAction - c1.api.policy.v1.Escalation: - description: | - The Escalation message. - - This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: - - replacePolicy - - reassignToApprovers - - cancelTicket - - skipStep + x-speakeasy-entity: IdentityPolicyTenantDefaults + x-speakeasy-name-override: IdentityPolicyTenantDefaults + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceGetResponse: + description: The IdentityPolicyTenantDefaultsServiceGetResponse message. properties: - cancelTicket: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.CancelTicket' - - type: "null" - escalationComment: - description: The escalationComment field. - type: string - expiration: - description: The expiration field. - format: int64 - type: string - reassignToApprovers: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReassignToApprovers' - - type: "null" - replacePolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReplacePolicy' - - type: "null" - skipStep: + defaults: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.SkipStep' + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - type: "null" - title: Escalation - type: object - x-speakeasy-name-override: Escalation - c1.api.policy.v1.Escalation.CancelTicket: - description: The CancelTicket message. - title: Cancel Ticket - type: object - x-speakeasy-name-override: CancelTicket - c1.api.policy.v1.Escalation.ReassignToApprovers: - description: The ReassignToApprovers message. - properties: - approverIds: - description: The approverIds field. - items: - type: string - type: - - array - - "null" - title: Reassign To Approvers - type: object - x-speakeasy-name-override: ReassignToApprovers - c1.api.policy.v1.Escalation.ReplacePolicy: - description: The ReplacePolicy message. - properties: - policyId: - description: The policyId field. - type: string - title: Replace Policy - type: object - x-speakeasy-name-override: ReplacePolicy - c1.api.policy.v1.Escalation.SkipStep: - description: The SkipStep message. - title: Skip Step + title: Identity Policy Tenant Defaults Service Get Response type: object - x-speakeasy-name-override: SkipStep - c1.api.policy.v1.EscalationInstance: - description: | - The EscalationInstance message. - - This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: - - replacePolicy - - reassignToApprovers - - cancelTicket - - skipStep + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceGetResponse + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateRequest: + description: The IdentityPolicyTenantDefaultsServiceUpdateRequest message. properties: - alreadyEscalated: - description: The alreadyEscalated field. - type: boolean - cancelTicket: + defaults: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.CancelTicket' + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - type: "null" - escalationComment: - description: The escalationComment field. - type: string - expiresAt: - format: date-time + updateMask: type: - string - "null" - reassignToApprovers: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReassignToApprovers' - - type: "null" - replacePolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReplacePolicy' - - type: "null" - skipStep: + title: Identity Policy Tenant Defaults Service Update Request + type: object + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateRequest + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateResponse: + description: The IdentityPolicyTenantDefaultsServiceUpdateResponse message. + properties: + defaults: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.SkipStep' + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' - type: "null" - title: Escalation Instance - type: object - x-speakeasy-name-override: EscalationInstance - c1.api.policy.v1.EscalationInstance.CancelTicket: - description: The CancelTicket message. - title: Cancel Ticket + title: Identity Policy Tenant Defaults Service Update Response type: object - x-speakeasy-name-override: EscalationInstanceCancelTicket - c1.api.policy.v1.EscalationInstance.ReassignToApprovers: - description: The ReassignToApprovers message. + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateResponse + c1.api.integration.connector.v1.CheckboxField: + description: The CheckboxField message. properties: - approverIds: - description: The approverIds field. - items: - type: string - type: - - array - - "null" - title: Reassign To Approvers + checked: + description: The checked field. + type: boolean + title: Checkbox Field type: object - x-speakeasy-name-override: EscalationInstanceReassignToApprovers - c1.api.policy.v1.EscalationInstance.ReplacePolicy: - description: The ReplacePolicy message. + x-speakeasy-name-override: ConnectorCheckboxField + c1.api.integration.connector.v1.ConfigSchema: + description: The ConfigSchema message. properties: - policyId: - description: The policyId field. + displayName: + description: The displayName field. type: string - title: Replace Policy - type: object - x-speakeasy-name-override: EscalationInstanceReplacePolicy - c1.api.policy.v1.EscalationInstance.SkipStep: - description: The SkipStep message. - title: Skip Step - type: object - x-speakeasy-name-override: EscalationInstanceSkipStep - c1.api.policy.v1.ExpressionApproval: - description: The ExpressionApproval message. - properties: - allowSelfApproval: - description: Configuration to allow self approval of if the user is specified and also the target of the ticket. - type: boolean - assignedUserIds: - description: The assignedUserIds field. - items: - type: string - readOnly: true - type: - - array - - "null" - expressions: - description: Array of dynamic expressions to determine the approvers. The first expression to return a non-empty list of users will be used. - items: - type: string - type: - - array - - "null" - fallback: - description: Configuration to allow a fallback if the expression does not return a valid list of users. - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the expression does not return a valid list of users. + fieldGroups: + description: Optional. Metadata for displaying fields in the UI. items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + $ref: '#/components/schemas/c1.api.integration.connector.v1.FieldGroup' type: - array - "null" - fallbackUserIds: - description: Configuration to specific which users to fallback to if and the expression does not return a valid list of users. + fields: + description: The fields field. items: - type: string + $ref: '#/components/schemas/c1.api.integration.connector.v1.Field' type: - array - "null" - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. + helpUrl: + description: The helpUrl field. + type: string + iconUrl: + deprecated: true + description: The iconUrl field. + type: string + isOauth2: + description: The isOauth2 field. type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. + requiresExternalConnector: + description: The requiresExternalConnector field. type: boolean - title: Expression Approval - type: object - x-speakeasy-name-override: ExpressionApproval - c1.api.policy.v1.ExpressionProvisioner: - description: ExpressionProvisioner evaluates CEL expressions to determine provisioners. - properties: - allowReassignment: - description: Whether the provisioner can reassign the task. + supportsExternalResources: + description: The supportsExternalResources field. type: boolean - expressions: - description: The CEL expressions to evaluate. - items: - type: string - type: - - array - - "null" - fallbackUserIds: - description: Fallback user IDs if expression evaluation yields no users. - items: - type: string - type: - - array - - "null" - title: Expression Provisioner + title: Config Schema type: object - x-speakeasy-name-override: ExpressionProvisioner - c1.api.policy.v1.ExternalTicketProvision: - description: This provision step indicates that we should check an external ticket to provision this entitlement + x-speakeasy-name-override: ConfigSchema + c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest: + description: ConnectorCatalogServiceConfigurationSchemaRequest is the request for retrieving a connector's configuration schema. properties: appId: - description: The appId field. - type: string - connectorId: - description: The connectorId field. + description: The ID of the app associated with the connector. Optional. type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. + catalogId: + description: The catalog entry ID identifying the connector type. type: string - instructions: - description: This field indicates a text body of instructions for the provisioner to indicate. + connectorId: + description: The ID of an existing connector to retrieve its current configuration schema. Optional. type: string - title: External Ticket Provision + title: Connector Catalog Service Configuration Schema Request type: object - x-speakeasy-name-override: ExternalTicketProvision - c1.api.policy.v1.Form: - description: The Form message. + x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaRequest + c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse: + description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. properties: - form: + formSchema: oneOf: - $ref: '#/components/schemas/c1.api.form.v1.Form' - type: "null" - title: Form - type: object - x-speakeasy-name-override: Form - c1.api.policy.v1.FormCompletedAction: - description: The FormCompletedAction message. - properties: - completedAt: - format: date-time - type: - - string - - "null" - userId: - description: The userId field. - type: string - title: Form Completed Action + schema: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConfigSchema' + - type: "null" + title: Connector Catalog Service Configuration Schema Response type: object - x-speakeasy-name-override: FormCompletedAction - c1.api.policy.v1.FormInstance: + x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaResponse + c1.api.integration.connector.v1.Field: description: | - The FormInstance message. + The Field message. - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - completed - - restarted - - reassigned - - skipped + This message contains a oneof named field. Only a single field of the following list may be set at a time: + - str + - select + - random + - import + - oauth2 + - readOnly + - options + - checkbox + - secret + - strList + - text + - keyValue + - stringMap properties: - completed: + additionalPlaceholder: + description: |- + Optional. Additional placeholder text for the field + In cases where a single placeholder is not enough to describe the field + type: string + checkbox: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.FormCompletedAction' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.CheckboxField' - type: "null" - data: - additionalProperties: true + dependsOnFields: + description: The dependsOnFields field. + items: + type: string type: - - object + - array - "null" - form: + displayName: + description: Human-readable label for this Field + type: string + helpUrl: + description: empty or https URL + type: string + import: oneOf: - - $ref: '#/components/schemas/c1.api.form.v1.Form' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ImportField' - type: "null" - reassigned: + keyValue: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.KeyValueField' - type: "null" - restarted: + name: + description: Must not start with `C1_` and match [a-zA-Z0-9_]{2,64}. Must be unique within a connector. + type: string + oauth2: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.OAuth2Field' - type: "null" - skipped: + options: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.OptionsField' - type: "null" - state: - description: The state field. - enum: - - FORM_INSTANCE_STATE_UNSPECIFIED - - FORM_INSTANCE_STATE_WAITING - - FORM_INSTANCE_STATE_DONE + placeholder: + description: The placeholder field. type: string - x-speakeasy-unknown-values: allow - title: Form Instance - type: object - x-speakeasy-name-override: FormInstance - c1.api.policy.v1.GetPolicyResponse: - description: The GetPolicyResponse message contains the policy object. - properties: - policy: + postCreate: + description: The postCreate field. + type: boolean + random: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - $ref: '#/components/schemas/c1.api.integration.connector.v1.RandomStringField' - type: "null" - title: Get Policy Response + readOnly: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ReadOnlyField' + - type: "null" + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.RotatableSecretField' + - type: "null" + select: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField' + - type: "null" + str: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringField' + - type: "null" + strList: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringListField' + - type: "null" + stringMap: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringMapField' + - type: "null" + text: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.TextField' + - type: "null" + title: Field type: object - x-speakeasy-name-override: GetPolicyResponse - c1.api.policy.v1.GroupProvisioner: - description: GroupProvisioner resolves to members of a specific group. + x-speakeasy-name-override: Field + c1.api.integration.connector.v1.FieldGroup: + description: The FieldGroup message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. + default: + description: The default field. type: boolean - appGroupId: - description: The app group ID (entitlement ID). - type: string - appId: - description: The app ID containing the group. + displayName: + description: Nice name this group (e.g. renders as a Tab label) type: string - fallbackUserIds: - description: Fallback user IDs if no group members are found. + fieldNames: + description: Field names are "guaranteed" to be unique, but can be repeated in and between lists. items: type: string type: - array - "null" - title: Group Provisioner + helpText: + description: Optional. User-facing help text. + type: string + name: + description: Unique ID. + type: string + title: Field Group type: object - x-speakeasy-name-override: GroupProvisioner - c1.api.policy.v1.ListPolicyResponse: - description: The ListPolicyResponse message. + x-speakeasy-name-override: FieldGroup + c1.api.integration.connector.v1.ImportField: + description: The ImportField message. properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request - items: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + allowedExtensions: + description: The allowedExtensions field. + items: + type: string type: - array - "null" - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: List Policy Response + secret: + description: The secret field. + type: boolean + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: Import Field type: object - x-speakeasy-name-override: ListPolicyResponse - c1.api.policy.v1.ManagerApproval: - description: The manager approval object provides configuration options for approval when the target of the approval is the manager of the user in the task. + x-speakeasy-name-override: ImportField + c1.api.integration.connector.v1.KeyValueField: + description: The KeyValueField message. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is their own manager. This may occur if a service account has an identity user and manager specified as the same person. + secret: + description: The secret field. type: boolean - assignedUserIds: - description: The array of users determined to be the manager during processing time. - items: - type: string - readOnly: true - type: - - array - - "null" - fallback: - description: Configuration to allow a fallback if no manager is found. + supportsFileUpload: + description: When true, UI allows file uploads per key-value entry. type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and no manager is found. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - type: - - array - - "null" - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and no manager is found. + title: Key Value Field + type: object + x-speakeasy-name-override: KeyValueField + c1.api.integration.connector.v1.OAuth2Field: + description: The OAuth2Field message. + title: O Auth 2 Field + type: object + x-speakeasy-name-override: OAuth2Field + c1.api.integration.connector.v1.OptionsField: + description: The OptionsField message. + title: Options Field + type: object + x-speakeasy-name-override: OptionsField + c1.api.integration.connector.v1.RandomStringField: + description: The RandomStringField message. + properties: + length: + description: The length field. + format: int32 + type: integer + title: Random String Field + type: object + x-speakeasy-name-override: RandomStringField + c1.api.integration.connector.v1.ReadOnlyField: + description: The ReadOnlyField message. + title: Read Only Field + type: object + x-speakeasy-name-override: ReadOnlyField + c1.api.integration.connector.v1.RotatableSecretField: + description: The RotatableSecretField message. + title: Rotatable Secret Field + type: object + x-speakeasy-name-override: RotatableSecretField + c1.api.integration.connector.v1.SelectField: + description: The SelectField message. + properties: + items: + description: list of items that are selected from items: - type: string + $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField.Item' type: - array - "null" - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. + title: Select Field + type: object + x-speakeasy-name-override: ConnectorSelectField + c1.api.integration.connector.v1.SelectField.Item: + description: The Item message. + properties: + displayName: + description: The displayName field. + type: string + value: + description: The value field. + type: string + title: Item + type: object + x-speakeasy-name-override: Item + c1.api.integration.connector.v1.StringField: + description: The StringField message. + properties: + secret: + description: If secret, value is write-only in UI and a password-type form is used. type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: String Field + type: object + x-speakeasy-name-override: StringField + c1.api.integration.connector.v1.StringListField: + description: The StringListField message. + properties: + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: String List Field + type: object + x-speakeasy-name-override: StringListField + c1.api.integration.connector.v1.StringMapField: + description: The StringMapField message. + properties: + optional: + description: The optional field. type: boolean - title: Manager Approval + title: String Map Field type: object - x-speakeasy-name-override: ManagerApproval - c1.api.policy.v1.ManagerProvisioner: - description: ManagerProvisioner resolves to the user's manager. + x-speakeasy-name-override: StringMapField + c1.api.integration.connector.v1.TextField: + description: The TextField message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. + secret: + description: The secret field. type: boolean - fallbackUserIds: - description: Fallback user IDs if no manager is found. - items: - type: string - type: - - array - - "null" - title: Manager Provisioner + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: Text Field type: object - x-speakeasy-name-override: ManagerProvisioner - c1.api.policy.v1.ManualProvision: - description: Manual provisioning indicates that a human must intervene for the provisioning of this step. + x-speakeasy-name-override: ConnectorTextField + c1.api.llm_gateway.v1.ClearProviderCredentialRequestInput: + description: The ClearProviderCredentialRequest message. + title: Clear Provider Credential Request + type: object + x-speakeasy-name-override: ClearProviderCredentialRequest + c1.api.llm_gateway.v1.ClearProviderCredentialResponse: + description: The ClearProviderCredentialResponse message. properties: - assignee: + credential: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionerAssignment' + - $ref: '#/components/schemas/c1.api.llm_gateway.v1.ProviderCredential' - type: "null" - instructions: - description: This field indicates a text body of instructions for the provisioner to indicate. + title: Clear Provider Credential Response + type: object + x-speakeasy-name-override: ClearProviderCredentialResponse + c1.api.llm_gateway.v1.GatewayKey: + description: The GatewayKey message. + properties: + createdAt: + format: date-time + type: + - string + - "null" + displayName: + description: The displayName field. type: string - userIds: - description: |- - An array of users that are required to provision during this step. - Deprecated: Use assignee field instead for dynamic provisioner assignment. - items: - type: string + id: + description: The id field. + type: string + keyPrefix: + description: The keyPrefix field. + type: string + revokedAt: + format: date-time type: - - array + - string - "null" - title: Manual Provision + updatedAt: + format: date-time + type: + - string + - "null" + title: Gateway Key type: object - x-speakeasy-name-override: ManualProvision - c1.api.policy.v1.MultiStep: - description: MultiStep indicates that this provision step has multiple steps to process. + x-speakeasy-name-override: GatewayKey + c1.api.llm_gateway.v1.GetProviderCredentialResponse: + description: The GetProviderCredentialResponse message. properties: - provisionSteps: - description: The array of provision steps to process. + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.llm_gateway.v1.ProviderCredential' + - type: "null" + title: Get Provider Credential Response + type: object + x-speakeasy-name-override: GetProviderCredentialResponse + c1.api.llm_gateway.v1.ListGatewayKeysResponse: + description: The ListGatewayKeysResponse message. + properties: + list: + description: The list field. items: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + $ref: '#/components/schemas/c1.api.llm_gateway.v1.GatewayKey' type: - array - "null" - title: Multi Step + nextPageToken: + description: The nextPageToken field. + type: string + title: List Gateway Keys Response type: object - x-speakeasy-name-override: MultiStep - c1.api.policy.v1.Policy: - description: |- - A policy defines a workflow (sequence of steps) that runs when processing - access requests, reviews, or revocations. Policies support conditional - routing: different conditions can trigger different step sequences, with a - baseline fallback. + x-speakeasy-name-override: ListGatewayKeysResponse + c1.api.llm_gateway.v1.MintGatewayKeyRequest: + description: The MintGatewayKeyRequest message. + properties: + displayName: + description: The displayName field. + type: string + title: Mint Gateway Key Request + type: object + x-speakeasy-name-override: MintGatewayKeyRequest + c1.api.llm_gateway.v1.MintGatewayKeyResponse: + description: The MintGatewayKeyResponse message. + properties: + gatewayKey: + oneOf: + - $ref: '#/components/schemas/c1.api.llm_gateway.v1.GatewayKey' + - type: "null" + plaintextKey: + description: The plaintextKey field. + type: string + title: Mint Gateway Key Response + type: object + x-speakeasy-name-override: MintGatewayKeyResponse + c1.api.llm_gateway.v1.ProviderCredential: + description: The ProviderCredential message. properties: - annotations: - additionalProperties: - type: string - description: |- - Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256 - chars; URL-safe ASCII. Keys starting with `c1/` are reserved. - - Updates have PATCH semantics: keys absent from the request are - preserved; an empty value deletes the key. - - Well-known keys: `managed_by`, `iac_workspace`, - `iac_resource_address`, `iac_tool_version`. - type: object - x-speakeasy-terraform-plan-modifier: - imports: - - github.com/conductorone/terraform-provider-conductorone/internal/annotations - schemaDefinition: annotations.PlanModifier() createdAt: format: date-time - readOnly: true type: - string - "null" - deletedAt: + displayName: + description: The displayName field. + type: string + headerStyle: + description: The headerStyle field. + enum: + - PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED + - PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY + - PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER + type: string + x-speakeasy-unknown-values: allow + keyPrefix: + description: The keyPrefix field. + type: string + revokedAt: format: date-time - readOnly: true type: - string - "null" - description: - description: The description of the Policy. + slotId: + description: The slotId field. type: string - displayName: - description: The display name of the Policy. + updatedAt: + format: date-time + type: + - string + - "null" + userId: + description: The userId field. type: string - id: - description: The ID of the Policy. - readOnly: true + title: Provider Credential + type: object + x-speakeasy-name-override: ProviderCredential + c1.api.llm_gateway.v1.RevokeGatewayKeyRequestInput: + description: The RevokeGatewayKeyRequest message. + title: Revoke Gateway Key Request + type: object + x-speakeasy-name-override: RevokeGatewayKeyRequest + c1.api.llm_gateway.v1.RevokeGatewayKeyResponse: + description: The RevokeGatewayKeyResponse message. + properties: + gatewayKey: + oneOf: + - $ref: '#/components/schemas/c1.api.llm_gateway.v1.GatewayKey' + - type: "null" + title: Revoke Gateway Key Response + type: object + x-speakeasy-name-override: RevokeGatewayKeyResponse + c1.api.llm_gateway.v1.SetProviderCredentialRequestInput: + description: The SetProviderCredentialRequest message. + properties: + apiKey: + description: The apiKey field. type: string - policySteps: - additionalProperties: - $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' - description: |- - A map from string keys to step sequences. One entry is always the baseline, - keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify"). - Additional entries have opaque keys (UUIDs) and are referenced by the rules - array for conditional routing. If no conditional rules are configured, only - the baseline entry exists. - type: object - policyType: - description: |- - The type of this policy (grant, revoke, or certify). The lowercased type - name (e.g., "grant") is also the key for the baseline entry in policy_steps. + displayName: + description: The displayName field. + type: string + headerStyle: + description: The headerStyle field. enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION + - PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED + - PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY + - PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER type: string x-speakeasy-unknown-values: allow - postActions: - description: Ordered actions to execute after the policy completes processing. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' + title: Set Provider Credential Request + type: object + x-speakeasy-name-override: SetProviderCredentialRequest + c1.api.llm_gateway.v1.SetProviderCredentialResponse: + description: The SetProviderCredentialResponse message. + properties: + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.llm_gateway.v1.ProviderCredential' + - type: "null" + title: Set Provider Credential Response + type: object + x-speakeasy-name-override: SetProviderCredentialResponse + c1.api.local_directory.v1.LocalDirectoryConfig: + description: |- + LocalDirectoryConfig is the public representation of a C1-managed local + directory configuration. The underlying directory infrastructure is provided + by the linked App (identified by app_id). + properties: + allowSelfRegistration: + description: Whether unauthenticated users may self-register in this directory. + type: boolean + appId: + description: app_id is the identifier for this config and its linked App. Read-only after creation. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true type: - - array + - string - "null" - reassignTasksToDelegates: - deprecated: true - description: This field is no longer used. Configure delegate reassignment in the policy step instead. + defaultProfileTypeId: + description: Optional FK to a ProfileType applied to new users created via this directory. + type: string + displayName: + description: The displayName field. + type: string + invitationTtl: + format: duration + type: + - string + - "null" + isDefault: + description: |- + Whether this is the default local directory for the tenant. + At most one config per tenant may be the default. type: boolean - rules: + onboardingFlowId: + description: Optional FK to an onboarding flow applied by default when inviting users. + type: string + organizationId: + description: Optional FK to a ThirdPartyOrganization. Empty means standalone (no vendor linkage). + type: string + selfRegistrationDomains: description: |- - Ordered conditional routing rules. Evaluated top-to-bottom; the first - matching rule selects a step sequence from policy_steps. If no rule matches - (or if this array is empty), the baseline entry in policy_steps is used. + Email domain allowlist for self-registration. Empty allows any domain when + allow_self_registration is true. items: - $ref: '#/components/schemas/c1.api.policy.v1.Rule' + type: string type: - array - "null" - systemBuiltin: - description: Whether this policy is a builtin system policy. Builtin system policies cannot be edited. - readOnly: true - type: boolean updatedAt: format: date-time readOnly: true type: - string - "null" - title: Policy + title: Local Directory Config type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: Policy - c1.api.policy.v1.PolicyInstance: - description: A policy instance is an object that contains a reference to the policy it was created from, the currently executing step, the next steps, and the history of previously completed steps. + x-speakeasy-name-override: LocalDirectoryConfig + c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest: + description: The LocalDirectoryConfigServiceCreateRequest message. properties: - current: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' - - type: "null" - history: - description: An array of steps that were previously processed by the ticket with their outcomes set, in order. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' - readOnly: true + allowSelfRegistration: + description: The allowSelfRegistration field. + type: boolean + appId: + description: FK to the existing App that will back this local directory. + type: string + defaultProfileTypeId: + description: The defaultProfileTypeId field. + type: string + displayName: + description: The displayName field. + type: string + invitationTtl: + format: duration type: - - array + - string - "null" - next: - description: An array of steps that will be processed by the ticket, in order. + isDefault: + description: Whether this should be the default local directory for the tenant. + type: boolean + onboardingFlowId: + description: The onboardingFlowId field. + type: string + organizationId: + description: Optional FK to a ThirdPartyOrganization. + type: string + selfRegistrationDomains: + description: The selfRegistrationDomains field. items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' - readOnly: true + type: string type: - array - "null" - policy: + required: + - appId + - displayName + title: Local Directory Config Service Create Request + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceCreateRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse: + description: The LocalDirectoryConfigServiceCreateResponse message. + properties: + localDirectoryConfig: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - type: "null" - title: Policy Instance + title: Local Directory Config Service Create Response type: object - x-speakeasy-name-override: PolicyInstance - c1.api.policy.v1.PolicyPostActions: - description: | - Actions to execute after a policy finishes processing. - - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - certifyRemediateImmediately + x-speakeasy-name-override: LocalDirectoryConfigServiceCreateResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput: + description: The LocalDirectoryConfigServiceDeleteRequest message. + title: Local Directory Config Service Delete Request + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse: + description: The LocalDirectoryConfigServiceDeleteResponse message. + title: Local Directory Config Service Delete Response + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse: + description: The LocalDirectoryConfigServiceGetResponse message. properties: - certifyRemediateImmediately: - description: |- - Only valid on certify policies. When true, any revocations resulting from - the certification are applied immediately when the campaign task closes. - This field is part of the `action` oneof. - See the documentation for `c1.api.policy.v1.PolicyPostActions` for more details. - type: - - boolean - - "null" - title: Policy Post Actions + localDirectoryConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - type: "null" + title: Local Directory Config Service Get Response type: object - x-speakeasy-name-override: PolicyPostActions - c1.api.policy.v1.PolicyRef: - description: The PolicyRef message. + x-speakeasy-name-override: LocalDirectoryConfigServiceGetResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse: + description: The LocalDirectoryConfigServiceListResponse message. properties: - id: - description: The id field. + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Policy Ref + title: Local Directory Config Service List Response type: object - x-speakeasy-name-override: PolicyRef - c1.api.policy.v1.PolicyStep: - description: | - A single step in a policy workflow. Exactly one step type is set. - - This message contains a oneof named step. Only a single field of the following list may be set at a time: - - approval - - provision - - accept - - reject - - wait - - form - - action + x-speakeasy-name-override: LocalDirectoryConfigServiceListResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput: + description: The LocalDirectoryConfigServiceUpdateRequest message. properties: - accept: + localDirectoryConfig: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Accept' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - type: "null" - action: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Action' - - type: "null" - approval: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Approval' - - type: "null" - form: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Form' - - type: "null" - provision: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Provision' - - type: "null" - reject: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Reject' - - type: "null" - wait: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Wait' - - type: "null" - title: Policy Step + updateMask: + type: + - string + - "null" + title: Local Directory Config Service Update Request type: object - x-speakeasy-name-override: PolicyStep - c1.api.policy.v1.PolicyStepInstance: - description: | - The policy step instance includes a reference to an instance of a policy step that tracks state and has a unique ID. - - This message contains a oneof named instance. Only a single field of the following list may be set at a time: - - approval - - provision - - accept - - reject - - wait - - form - - action + x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse: + description: The LocalDirectoryConfigServiceUpdateResponse message. properties: - accept: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.AcceptInstance' - - type: "null" - action: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - - type: "null" - approval: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' - - type: "null" - form: + localDirectoryConfig: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.FormInstance' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - type: "null" + title: Local Directory Config Service Update Response + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateResponse + c1.api.local_directory.v1.LocalUserInvitation: + description: LocalUserInvitation is the public representation of a per-directory user invitation. + properties: + acceptedAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdUserId: + description: Set when status = ACCEPTED. FK to the created User. Read-only. + readOnly: true + type: string + directoryAppId: + description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. Read-only after creation. + readOnly: true + type: string + displayName: + description: Display name to pre-populate on the new user account. + type: string + email: + description: Email address the invitation was sent to. + type: string + expiresAt: + format: date-time + readOnly: true + type: + - string + - "null" id: - description: The ID of the PolicyStepInstance. This is required by many action submission endpoints to indicate what step you're approving. + description: Unique KSUID identifier. Read-only. readOnly: true type: string - policyGenerationId: - description: The policy generation id refers to the version of the policy that this step was created from. + initialRoleIds: + description: Optional initial role IDs to assign to the user upon acceptance. + items: + type: string + type: + - array + - "null" + invitedByUserId: + description: FK to the User who created the invitation. Read-only. + readOnly: true type: string - provision: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionInstance' - - type: "null" - reject: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.RejectInstance' - - type: "null" - state: - description: The state of the step, which is either active or done. + jobId: + description: Optional FK to a ThirdPartyJob. + type: string + onboardingFlowId: + description: Optional onboarding flow override for this invitation. + type: string + purpose: + description: Human-readable reason this user was invited. + type: string + sponsorUserId: + description: Optional sponsor User override for this invitation. + type: string + status: + description: Current lifecycle status. Read-only. enum: - - POLICY_STEP_STATE_UNSPECIFIED - - POLICY_STEP_STATE_ACTIVE - - POLICY_STEP_STATE_DONE + - LOCAL_INVITATION_STATUS_UNSPECIFIED + - LOCAL_INVITATION_STATUS_PENDING + - LOCAL_INVITATION_STATUS_ACCEPTED + - LOCAL_INVITATION_STATUS_REVOKED + - LOCAL_INVITATION_STATUS_EXPIRED readOnly: true type: string x-speakeasy-unknown-values: allow - wait: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance' - - type: "null" - title: Policy Step Instance + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Local User Invitation type: object - x-speakeasy-name-override: PolicyStepInstance - c1.api.policy.v1.PolicySteps: - description: A named sequence of steps that execute in order within a policy. + x-speakeasy-name-override: LocalUserInvitation + c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput: + description: The LocalUserInvitationServiceCreateRequest message. properties: - steps: - description: |- - Ordered array of steps. Each step is a oneof -- exactly one step type is - set per entry. Steps execute sequentially. + displayName: + description: The displayName field. + type: string + email: + description: The email field. + type: string + initialRoleIds: + description: Optional initial role IDs to assign upon acceptance. items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + type: string type: - array - "null" - title: Policy Steps + jobId: + description: Optional FK to a ThirdPartyJob. + type: string + onboardingFlowId: + description: Optional onboarding flow override. + type: string + purpose: + description: Human-readable reason for the invitation. + type: string + sponsorUserId: + description: Optional sponsor User override. + type: string + required: + - email + - displayName + title: Local User Invitation Service Create Request type: object - x-speakeasy-name-override: PolicySteps - c1.api.policy.v1.Provision: - description: The provision step references a provision policy for this step. + x-speakeasy-name-override: LocalUserInvitationServiceCreateRequest + c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse: + description: The LocalUserInvitationServiceCreateResponse message. properties: - assigned: - description: A field indicating whether this step is assigned. - type: boolean - provisionPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - - type: "null" - provisionTarget: + invitation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionTarget' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - type: "null" - title: Provision + title: Local User Invitation Service Create Response type: object - x-speakeasy-name-override: Provision - c1.api.policy.v1.ProvisionInstance: - description: | - A provision instance describes the specific configuration of an executing provision policy step including actions taken and notification id. - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - completed - - cancelled - - errored - - reassignedByError - - skipped + x-speakeasy-name-override: LocalUserInvitationServiceCreateResponse + c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse: + description: The LocalUserInvitationServiceGetResponse message. properties: - batonActionInvocationId: - description: This indicates the account lifecycle action id for this step. - type: string - cancelled: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.CancelledAction' - - type: "null" - completed: + invitation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.CompletedAction' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - type: "null" - errored: + title: Local User Invitation Service Get Response + type: object + x-speakeasy-name-override: LocalUserInvitationServiceGetResponse + c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput: + description: The LocalUserInvitationServiceRevokeRequest message. + title: Local User Invitation Service Revoke Request + type: object + x-speakeasy-name-override: LocalUserInvitationServiceRevokeRequest + c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse: + description: The LocalUserInvitationServiceRevokeResponse message. + properties: + invitation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ErroredAction' + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - type: "null" - externalTicketId: - description: This indicates the external ticket id for this step. + title: Local User Invitation Service Revoke Response + type: object + x-speakeasy-name-override: LocalUserInvitationServiceRevokeResponse + c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest: + description: The LocalUserInvitationServiceSearchRequest message. + properties: + directoryAppId: + description: The directoryAppId field. type: string - externalTicketProvisionerConfigId: - description: This indicates the external ticket provisioner config id for this step. + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - notificationId: - description: This indicates the notification id for this step. + statusFilter: + description: Optional filter by invitation status. + enum: + - LOCAL_INVITATION_STATUS_UNSPECIFIED + - LOCAL_INVITATION_STATUS_PENDING + - LOCAL_INVITATION_STATUS_ACCEPTED + - LOCAL_INVITATION_STATUS_REVOKED + - LOCAL_INVITATION_STATUS_EXPIRED type: string - provision: + x-speakeasy-unknown-values: allow + title: Local User Invitation Service Search Request + type: object + x-speakeasy-name-override: LocalUserInvitationServiceSearchRequest + c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse: + description: The LocalUserInvitationServiceSearchResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Local User Invitation Service Search Response + type: object + x-speakeasy-name-override: LocalUserInvitationServiceSearchResponse + c1.api.policy.v1.Accept: + description: This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + properties: + acceptMessage: + description: An optional message to include in the comments when a task is automatically accepted. + type: string + title: Accept + type: object + x-speakeasy-name-override: Accept + c1.api.policy.v1.AcceptInstance: + description: |- + This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + The instance is just a marker for it being copied into an active policy. + properties: + acceptMessage: + description: An optional message to include in the comments when a task is automatically accepted. + type: string + title: Accept Instance + type: object + x-speakeasy-name-override: AcceptInstance + c1.api.policy.v1.Action: + description: | + The Action message. + + This message contains a oneof named target. Only a single field of the following list may be set at a time: + - automation + - batonResourceAction + - clientIdApproval + properties: + automation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Provision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomation' - type: "null" - reassignedByError: + batonResourceAction: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceAction' - type: "null" - skipped: + clientIdApproval: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApproval' - type: "null" - state: - description: This property indicates the current state of this step. - enum: - - PROVISION_INSTANCE_STATE_UNSPECIFIED - - PROVISION_INSTANCE_STATE_INIT - - PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET - - PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS - - PROVISION_INSTANCE_STATE_WAITING - - PROVISION_INSTANCE_STATE_WEBHOOK - - PROVISION_INSTANCE_STATE_WEBHOOK_WAITING - - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET - - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING - - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS - - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING - - PROVISION_INSTANCE_STATE_DONE - type: string - x-speakeasy-unknown-values: allow - webhookId: - description: This indicates the webhook id for this step. - type: string - webhookInstanceId: - description: This indicates the webhook instance id for this step. - type: string - title: Provision Instance + title: Action type: object - x-speakeasy-name-override: ProvisionInstance - c1.api.policy.v1.ProvisionPolicy: + x-speakeasy-name-override: Action + c1.api.policy.v1.ActionInstance: description: | - ProvisionPolicy is a oneOf that indicates how a provision step should be processed. + The ActionInstance message. - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - connector - - manual - - delegated - - webhook - - multiStep - - externalTicket - - unconfigured - - action + This message contains a oneof named target_instance. Only a single field of the following list may be set at a time: + - automation + - batonResourceActionInstance + - clientIdApprovalInstance + + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - success + - denied + - error + - cancelled properties: action: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.Action' - type: "null" - connector: + automation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomationInstance' - type: "null" - delegated: + batonResourceActionInstance: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.DelegatedProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceActionInstance' - type: "null" - externalTicket: + cancelled: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ExternalTicketProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeCancelled' - type: "null" - manual: + clientIdApprovalInstance: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ManualProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApprovalInstance' - type: "null" - multiStep: + denied: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.MultiStep' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeDenied' - type: "null" - unconfigured: + error: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.UnconfiguredProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeError' - type: "null" - webhook: + state: + description: The current state of the action execution. + enum: + - ACTION_INSTANCE_STATE_UNSPECIFIED + - ACTION_INSTANCE_STATE_INIT + - ACTION_INSTANCE_STATE_RUNNING + - ACTION_INSTANCE_STATE_DONE + - ACTION_INSTANCE_STATE_ERROR + type: string + x-speakeasy-unknown-values: allow + success: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WebhookProvision' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeSuccess' - type: "null" - title: Provision Policy + title: Action Instance type: object - x-speakeasy-name-override: ProvisionPolicy - c1.api.policy.v1.ProvisionTarget: - description: ProvisionTarget indicates the specific app, app entitlement, and if known, the app user and grant duration of this provision step + x-speakeasy-name-override: ActionInstance + c1.api.policy.v1.ActionOutcomeCancelled: + description: The ActionOutcomeCancelled message. properties: - appEntitlementId: - description: The app entitlement that should be provisioned. - type: string - appId: - description: The app in which the entitlement should be provisioned - type: string - appUserId: - description: The app user that should be provisioned. May be unset if the app user is unknown - type: string - grantDuration: - format: duration + outcomeTime: + format: date-time type: - string - "null" - title: Provision Target - type: object - x-speakeasy-name-override: ProvisionTarget - c1.api.policy.v1.ProvisionerAssignment: - description: | - ProvisionerAssignment defines how a provisioner is dynamically assigned. - - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - users - - appOwners - - group - - manager - - expression - - entitlementOwners - properties: - appOwners: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerProvisioner' - - type: "null" - entitlementOwners: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerProvisioner' - - type: "null" - expression: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionProvisioner' - - type: "null" - group: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.GroupProvisioner' - - type: "null" - manager: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ManagerProvisioner' - - type: "null" - users: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.UserProvisioner' - - type: "null" - title: Provisioner Assignment + title: Action Outcome Cancelled type: object - x-speakeasy-name-override: ProvisionerAssignment - c1.api.policy.v1.ReassignedAction: - description: The ReassignedAction object describes the outcome of a policy step that has been reassigned. + x-speakeasy-name-override: ActionOutcomeCancelled + c1.api.policy.v1.ActionOutcomeDenied: + description: The ActionOutcomeDenied message. properties: - newPolicyStepId: - description: The ID of the policy step that was created as a result of this reassignment. - readOnly: true - type: string - reassignedAt: + outcomeTime: format: date-time - readOnly: true type: - string - "null" - userId: - description: The UserID of the person who reassigned this step. - readOnly: true - type: string - title: Reassigned Action + title: Action Outcome Denied type: object - x-speakeasy-name-override: ReassignedAction - c1.api.policy.v1.ReassignedByErrorAction: - description: The ReassignedByErrorAction object describes the outcome of a policy step that has been reassigned because it had an error provisioning. + x-speakeasy-name-override: ActionOutcomeDenied + c1.api.policy.v1.ActionOutcomeError: + description: The ActionOutcomeError message. properties: - description: - description: The description of the error with more details on why this was reassigned. - readOnly: true - type: string errorCode: - description: Additional information about the error, like http status codes or error messages from SDKs. - readOnly: true + description: The errorCode field. type: string - errorUserId: - description: The UserID of the user who reassigned this due to an error. This will exclusively be the System's UserID. - readOnly: true + errorMessage: + description: The errorMessage field. type: string - erroredAt: + outcomeTime: format: date-time - readOnly: true type: - string - "null" - newPolicyStepId: - description: The ID of the policy step that was created by this reassignment. - readOnly: true - type: string - reassignedAt: + title: Action Outcome Error + type: object + x-speakeasy-name-override: ActionOutcomeError + c1.api.policy.v1.ActionOutcomeSuccess: + description: The ActionOutcomeSuccess message. + properties: + outcomeTime: format: date-time - readOnly: true type: - string - "null" - title: Reassigned By Error Action + title: Action Outcome Success type: object - x-speakeasy-name-override: ReassignedByErrorAction - c1.api.policy.v1.Reject: - description: This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + x-speakeasy-name-override: ActionOutcomeSuccess + c1.api.policy.v1.ActionProvision: + description: This provision step indicates that account lifecycle action should be called to provision this entitlement. properties: - rejectMessage: - description: An optional message to include in the comments when a task is automatically rejected. + actionName: + description: The actionName field. type: string - title: Reject + appId: + description: The appId field. + type: string + connectorId: + description: The connectorId field. + type: string + displayName: + description: The displayName field. + type: string + title: Action Provision type: object - x-speakeasy-name-override: Reject - c1.api.policy.v1.RejectInstance: - description: |- - This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - The instance is just a marker for it being copied into an active policy. + x-speakeasy-name-override: ActionProvision + c1.api.policy.v1.ActionTargetAutomation: + description: ActionTargetAutomation targets automation templates for policy actions. properties: - rejectMessage: - description: An optional message to include in the comments when a task is automatically rejected. + automationTemplateId: + description: The automationTemplateId field. type: string - title: Reject Instance + title: Action Target Automation type: object - x-speakeasy-name-override: RejectInstance - c1.api.policy.v1.ResourceOwnerApproval: - description: The resource owner approval allows configuration of the approval step when the target approvers are the resource owners. + x-speakeasy-name-override: ActionTargetAutomation + c1.api.policy.v1.ActionTargetAutomationInstance: + description: The ActionTargetAutomationInstance message. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is an resource owner during this step. - type: boolean - fallback: - description: Configuration to allow a fallback if the resource owner cannot be identified. - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the resource owner cannot be identified. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - type: - - array - - "null" - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the resource owner cannot be identified. - items: - type: string - type: - - array - - "null" - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - type: boolean - title: Resource Owner Approval + automationExecutionId: + description: The automationExecutionId field. + type: string + title: Action Target Automation Instance type: object - x-speakeasy-name-override: ResourceOwnerApproval - c1.api.policy.v1.RestartAction: - description: The restart action describes the outcome of policy steps for when the task was restarted. This can be applied to multiple steps since restart skips all pending next steps. + x-speakeasy-name-override: ActionTargetAutomationInstance + c1.api.policy.v1.ActionTargetBatonResourceAction: + description: ActionTargetResource targets resource actions for policy actions. properties: - oldPolicyStepId: - description: The step ID that was restarted. Potentially multiple "history" steps will reference this ID to indicate by what step they were restarted. - readOnly: true + batonResourceActionId: + description: The batonResourceActionId field. type: string - restartedAt: - format: date-time - readOnly: true - type: - - string - - "null" - userId: - description: The user that submitted the restart action. - readOnly: true + title: Action Target Baton Resource Action + type: object + x-speakeasy-name-override: ActionTargetBatonResourceAction + c1.api.policy.v1.ActionTargetBatonResourceActionInstance: + description: The ActionTargetBatonResourceActionInstance message. + properties: + batonActionInvocationId: + description: The batonActionInvocationId field. type: string - title: Restart Action + title: Action Target Baton Resource Action Instance type: object - x-speakeasy-name-override: RestartAction - c1.api.policy.v1.Rule: + x-speakeasy-name-override: ActionTargetBatonResourceActionInstance + c1.api.policy.v1.ActionTargetClientIdApproval: + description: |- + ActionTargetClientIdApproval targets administrator review of an external + OAuth client registration (CIMD or DCR) for policy actions. + title: Action Target Client Id Approval + type: object + x-speakeasy-name-override: ActionTargetClientIdApproval + c1.api.policy.v1.ActionTargetClientIdApprovalInstance: description: |- - A conditional routing rule that maps a CEL expression to a step sequence. - Rules are evaluated top-to-bottom; the first matching rule's policy_key - selects the step sequence from the policy's policy_steps map. If no rule - matches, the baseline entry is used. + ActionTargetClientIdApprovalInstance carries the registration key of the + external OAuth client that is being reviewed. properties: - condition: - description: |- - A CEL expression that is evaluated against the request context. If it - returns true, the step sequence identified by policy_key is used. - type: string - policyKey: - description: |- - A key into the policy's policy_steps map identifying which step sequence - to execute when this rule's condition matches. + clientIdUrl: + description: The clientIdUrl field. type: string - title: Rule + title: Action Target Client Id Approval Instance type: object - x-speakeasy-name-override: Rule - c1.api.policy.v1.SearchPoliciesRequest: - description: Search Policies by a few properties. + x-speakeasy-name-override: ActionTargetClientIdApprovalInstance + c1.api.policy.v1.AgentApproval: + description: The agent to assign the task to. properties: - displayName: - description: Search for policies with a case insensitive match on the display name. + agentFailureAction: + description: The action to take if the agent fails to approve, deny, or reassign the task. + enum: + - APPROVAL_AGENT_FAILURE_ACTION_UNSPECIFIED + - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_USERS + - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_SUPER_ADMINS + - APPROVAL_AGENT_FAILURE_ACTION_SKIP_POLICY_STEP type: string - excludePolicyIds: - description: The policy IDs to exclude from the search. - items: - type: string - type: - - array - - "null" - includeDeleted: - description: The includeDeleted field. - type: boolean - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - type: integer - pageToken: - description: The pageToken field. + x-speakeasy-unknown-values: allow + agentMode: + description: The mode of the agent, full control, change policy only, or comment only. + enum: + - APPROVAL_AGENT_MODE_UNSPECIFIED + - APPROVAL_AGENT_MODE_FULL_CONTROL + - APPROVAL_AGENT_MODE_CHANGE_POLICY_ONLY + - APPROVAL_AGENT_MODE_COMMENT_ONLY type: string - policyTypes: - description: The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. + x-speakeasy-unknown-values: allow + agentUserId: + deprecated: true + description: |- + Deprecated: agent steps are evaluated by the system; no agent user is + selected. Retained so pre-migration policies still validate. + type: string + instructions: + description: Instructions for the agent. + type: string + policyIds: + description: The allow list of policy IDs to re-route the task to. items: - enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION type: string - x-speakeasy-unknown-values: allow type: - array - "null" - query: - description: Query the policies with a fuzzy search on display name and description. - type: string - refs: - description: The refs field. + reassignToUserIds: + description: The users to reassign the task to if the agent failure action is reassign to users. items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' + type: string type: - array - "null" - title: Search Policies Request + title: Agent Approval type: object - x-speakeasy-name-override: SearchPoliciesRequest - c1.api.policy.v1.SearchPoliciesResponse: - description: The SearchPoliciesResponse message. + x-speakeasy-name-override: AgentApproval + c1.api.policy.v1.AppEntitlementReference: + description: This object references an app entitlement's ID and AppID. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - type: - - array - - "null" - nextPageToken: - description: The nextPageToken field. + appEntitlementId: + description: The ID of the Entitlement. type: string - title: Search Policies Response + appId: + description: The ID of the App this entitlement belongs to. + type: string + title: App Entitlement Reference type: object - x-speakeasy-name-override: SearchPoliciesResponse - c1.api.policy.v1.SelfApproval: - description: The self approval object describes the configuration of a policy step that needs to be approved by the target of the request. + x-speakeasy-name-override: AppEntitlementReference + c1.api.policy.v1.AppGroupApproval: + description: The AppGroupApproval object provides the configuration for setting a group as the approvers of an approval policy step. properties: - assignedUserIds: - description: The array of users determined to be themselves during approval. This should only ever be one person, but is saved because it may change if the owner of an app user changes while the ticket is open. - items: - type: string - readOnly: true - type: - - array - - "null" + allowSelfApproval: + description: Configuration to allow self approval if the target user is a member of the group during this step. + type: boolean + appGroupId: + description: The ID of the group specified for approval. + type: string + appId: + description: The ID of the app that contains the group specified for approval. + type: string fallback: - description: Configuration to allow a fallback if the identity user of the target app user cannot be determined. + description: Configuration to allow a fallback if the group is empty. type: boolean fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. + description: Configuration to specify which groups to fallback to if fallback is enabled and the group is empty. items: $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - array - "null" fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. + description: Configuration to specific which users to fallback to if fallback is enabled and the group is empty. items: type: string type: @@ -26361,6641 +28230,6010 @@ components: isGroupFallbackEnabled: description: Configuration to enable fallback for group fallback. type: boolean - title: Self Approval - type: object - x-speakeasy-name-override: SelfApproval - c1.api.policy.v1.SkippedAction: - description: The SkippedAction object describes the outcome of a policy step that has been skipped. - properties: - newPolicyStepId: - description: The ID of the policy step that was created as a result of this skipping. - readOnly: true - type: string - skippedAt: - format: date-time - readOnly: true - type: - - string - - "null" - userId: - description: The UserID of the user who skipped this step. - readOnly: true - type: string - title: Skipped Action - type: object - x-speakeasy-name-override: SkippedAction - c1.api.policy.v1.TestAccountProvisionPolicyRequest: - description: TestAccountProvisionPolicyRequest is the request for testing an account provision policy. - properties: - cel: - description: The CEL expression to evaluate for the account provision policy. - type: string - title: Test Account Provision Policy Request - type: object - x-speakeasy-name-override: TestAccountProvisionPolicyRequest - c1.api.policy.v1.TestAccountProvisionPolicyResponse: - description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. - properties: - type: - description: The data type of the computed result value. - type: string - value: - description: The computed result value of the CEL expression evaluation. - type: string - title: Test Account Provision Policy Response - type: object - x-speakeasy-name-override: TestAccountProvisionPolicyResponse - c1.api.policy.v1.UnconfiguredProvision: - description: The UnconfiguredProvision message. - title: Unconfigured Provision - type: object - x-speakeasy-name-override: UnconfiguredProvision - c1.api.policy.v1.UpdatePolicyRequestInput: - description: The UpdatePolicyRequest message contains the policy object to update and a field mask to indicate which fields to update. It uses URL value for input. - properties: - policy: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - - type: "null" - updateMask: - type: - - string - - "null" - title: Update Policy Request - type: object - x-speakeasy-name-override: UpdatePolicyRequest - c1.api.policy.v1.UpdatePolicyResponse: - description: The UpdatePolicyResponse message contains the updated policy object. - properties: - policy: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - - type: "null" - title: Update Policy Response + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: App Group Approval type: object - x-speakeasy-name-override: UpdatePolicyResponse - c1.api.policy.v1.UserApproval: - description: The user approval object describes the approval configuration of a policy step that needs to be approved by a specific list of users. + x-speakeasy-name-override: AppGroupApproval + c1.api.policy.v1.AppOwnerApproval: + description: App owner approval provides the configuration for an approval step when the app owner is the target. properties: allowSelfApproval: - description: Configuration to allow self approval of if the user is specified and also the target of the ticket. + description: Configuration that allows a user to self approve if they are an app owner during this approval step. type: boolean requireDistinctApprovers: description: Configuration to require distinct approvers across approval steps of a rule. type: boolean - userIds: - description: Array of users configured for approval. - items: - type: string - type: - - array - - "null" - title: User Approval + title: App Owner Approval type: object - x-speakeasy-name-override: UserApproval - c1.api.policy.v1.UserProvisioner: - description: UserProvisioner assigns specific users as provisioners. + x-speakeasy-name-override: AppOwnerApproval + c1.api.policy.v1.AppOwnerProvisioner: + description: AppOwnerProvisioner resolves to app owners. properties: allowReassignment: description: Whether the provisioner can reassign the task. type: boolean - userIds: - description: The user IDs to assign as provisioners. + fallbackUserIds: + description: Fallback user IDs if no app owners are found. items: type: string type: - array - "null" - title: User Provisioner + title: App Owner Provisioner type: object - x-speakeasy-name-override: UserProvisioner - c1.api.policy.v1.Wait: + x-speakeasy-name-override: AppOwnerProvisioner + c1.api.policy.v1.Approval: description: | - Define a Wait step for a policy to wait on a condition to be met. + The Approval message. - This message contains a oneof named until. Only a single field of the following list may be set at a time: - - condition - - duration - - untilTime + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + - manager + - appOwners + - group + - self + - entitlementOwners + - expression + - webhook + - resourceOwners + - agent properties: - commentOnFirstWait: - description: The comment to post on first failed check. - type: string - commentOnTimeout: - description: The comment to post if we timeout. - type: string - condition: - oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitCondition' - - type: "null" - duration: + agent: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitDuration' + - $ref: '#/components/schemas/c1.api.policy.v1.AgentApproval' - type: "null" - name: - description: The name of our condition to show on the task details page - type: string - timeoutDuration: - format: duration + allowDelegation: + description: Whether ticket delegation is allowed for this step. + type: boolean + allowReassignment: + description: Configuration to allow reassignment by reviewers during this step. + type: boolean + allowedReassignees: + description: List of users for whom this step can be reassigned. + items: + type: string type: - - string + - array - "null" - untilTime: + appOwners: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTime' + - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerApproval' - type: "null" - title: Wait - type: object - x-speakeasy-name-override: Wait - c1.api.policy.v1.WaitCondition: - description: The WaitCondition message. - properties: - condition: - description: The condition that has to be true for this wait condition to continue. - type: string - title: Wait Condition - type: object - x-speakeasy-name-override: WaitCondition - c1.api.policy.v1.WaitConditionInstance: - description: Used by the policy engine to describe an instantiated condition to wait on. - properties: - condition: - description: The condition that has to be true for this wait condition instance to continue. - type: string - title: Wait Condition Instance - type: object - x-speakeasy-name-override: WaitConditionInstance - c1.api.policy.v1.WaitDuration: - description: The WaitDuration message. - properties: - duration: - format: duration - type: - - string - - "null" - title: Wait Duration - type: object - x-speakeasy-name-override: WaitDuration - c1.api.policy.v1.WaitInstance: - description: | - Used by the policy engine to describe an instantiated wait step. - - This message contains a oneof named until. Only a single field of the following list may be set at a time: - - condition - - untilTime - - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - succeeded - - timedOut - - skipped - properties: - commentOnFirstWait: - description: The comment to post on first failed check. - type: string - commentOnTimeout: - description: The comment to post if we timeout. - type: string - condition: + assigned: + description: A field indicating whether this step is assigned. + readOnly: true + type: boolean + entitlementOwners: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitConditionInstance' + - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerApproval' - type: "null" - name: - description: The name field. - type: string - skipped: + escalation: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation' - type: "null" - startedWaitingAt: - format: date-time - type: - - string - - "null" - state: - description: The state field. - enum: - - WAIT_INSTANCE_STATE_UNSPECIFIED - - WAIT_INSTANCE_STATE_WAITING - - WAIT_INSTANCE_STATE_COMPLETED - - WAIT_INSTANCE_STATE_TIMED_OUT + escalationEnabled: + description: Whether escalation is enabled for this step. + type: boolean + expression: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionApproval' + - type: "null" + group: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AppGroupApproval' + - type: "null" + manager: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManagerApproval' + - type: "null" + requireApprovalReason: + description: Configuration to require a reason when approving this step. + type: boolean + requireDenialReason: + description: Configuration to require a reason when denying this step. + type: boolean + requireReassignmentReason: + description: Configuration to require a reason when reassigning this step. + type: boolean + requiresStepUpProviderId: + description: |- + The ID of a step-up authentication provider that will be required for approvals on this step. + If set, approvers must complete the step-up authentication flow before they can approve. type: string - x-speakeasy-unknown-values: allow - succeeded: + resourceOwners: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionSucceeded' + - $ref: '#/components/schemas/c1.api.policy.v1.ResourceOwnerApproval' - type: "null" - timedOut: + self: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionTimedOut' + - $ref: '#/components/schemas/c1.api.policy.v1.SelfApproval' - type: "null" - timeout: + users: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UserApproval' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WebhookApproval' + - type: "null" + title: Approval + type: object + x-speakeasy-name-override: Approval + c1.api.policy.v1.ApprovalInstance: + description: | + The approval instance object describes the way a policy step should be approved as well as its outcomes and state. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - approved + - denied + - reassigned + - restarted + - reassignedByError + - skipped + properties: + approval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Approval' + - type: "null" + approved: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovedAction' + - type: "null" + assignedAt: format: date-time + readOnly: true type: - string - "null" - timeoutDuration: - format: duration - type: - - string - - "null" - untilTime: + denied: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTimeInstance' + - $ref: '#/components/schemas/c1.api.policy.v1.DeniedAction' - type: "null" - title: Wait Instance + escalationInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance' + - type: "null" + reassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' + - type: "null" + reassignedByError: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' + - type: "null" + restarted: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: The state of the approval instance + enum: + - APPROVAL_INSTANCE_STATE_UNSPECIFIED + - APPROVAL_INSTANCE_STATE_INIT + - APPROVAL_INSTANCE_STATE_SENDING_NOTIFICATIONS + - APPROVAL_INSTANCE_STATE_WAITING + - APPROVAL_INSTANCE_STATE_DONE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + title: Approval Instance type: object - x-speakeasy-name-override: WaitInstance - c1.api.policy.v1.WaitInstance.ConditionSucceeded: - description: The ConditionSucceeded message. + x-speakeasy-name-override: ApprovalInstance + c1.api.policy.v1.ApprovedAction: + description: The approved action indicates that the approvalinstance had an outcome of approved. properties: - succeededAt: + approvedAt: format: date-time + readOnly: true type: - string - "null" - title: Condition Succeeded + entitlements: + description: The entitlements that were approved. This will only ever be a list of one entitlement. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + readOnly: true + type: + - array + - "null" + stepUpTransactionId: + description: The ID of the step-up transaction that was used for this approval, if step-up was required. + readOnly: true + type: string + userId: + description: The UserID that approved this step. + readOnly: true + type: string + title: Approved Action type: object - x-speakeasy-name-override: ConditionSucceeded - c1.api.policy.v1.WaitInstance.ConditionTimedOut: - description: The ConditionTimedOut message. + x-speakeasy-name-override: ApprovedAction + c1.api.policy.v1.CancelledAction: + description: The outcome of a provision instance that is cancelled. properties: - timedOutAt: + cancelledAt: format: date-time type: - string - "null" - title: Condition Timed Out - type: object - x-speakeasy-name-override: ConditionTimedOut - c1.api.policy.v1.WaitUntilTime: - description: Waits until a specific time of the day (UTC) - properties: - hours: - description: The hours field. - format: uint32 - type: integer - minutes: - description: The minutes field. - format: uint32 - type: integer - timezone: - description: The timezone field. + cancelledByUserId: + description: The userID, usually the system, that cancells a provision instance. type: string - title: Wait Until Time + title: Cancelled Action type: object - x-speakeasy-name-override: WaitUntilTime - c1.api.policy.v1.WaitUntilTimeInstance: - description: The WaitUntilTimeInstance message. + x-speakeasy-name-override: CancelledAction + c1.api.policy.v1.CompletedAction: + description: The outcome of a provision instance that has been completed succesfully. properties: - durationIfExists: - format: duration - type: - - string - - "null" - untilTime: + completedAt: format: date-time type: - string - "null" - title: Wait Until Time Instance - type: object - x-speakeasy-name-override: WaitUntilTimeInstance - c1.api.policy.v1.WebhookApproval: - description: The WebhookApproval message. - properties: - webhookId: - description: The ID of the webhook to call for approval. - type: string - title: Webhook Approval - type: object - x-speakeasy-name-override: WebhookApproval - c1.api.policy.v1.WebhookProvision: - description: This provision step indicates that a webhook should be called to provision this entitlement. - properties: - webhookId: - description: The ID of the webhook to call for provisioning. - type: string - title: Webhook Provision - type: object - x-speakeasy-name-override: WebhookProvision - c1.api.profiletype.v1.ProfileType: - description: ProfileType represents a type of profile in the system - properties: - description: - description: The description field. - type: string - displayToUser: - description: Whether to display this profile type to users in profile page. Defaults to false if not set - type: boolean - iconUrl: - description: The iconUrl field. - type: string - id: - description: The id field. - type: string - name: - description: The name field. - type: string - priority: - description: The priority field. - format: uint32 - type: integer - sizes: - description: icon sizes + entitlements: + description: The list of entitlements that were provisioned. This is leftover from an older design, and is only ever going to be a single entitlement. items: - format: int32 - type: integer + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - array - "null" - slug: - description: Add this field to allow users to reference profile type in cel expressions + userId: + description: The UserID of who completed provisioning. For connector provisioning this is the system user id, for manual provisioning this is who clicked "provision complete" type: string - title: Profile Type + title: Completed Action type: object - x-speakeasy-name-override: ProfileType - c1.api.request_schema.v1.RequestSchema: - description: A request schema defines a form template that users fill out when requesting access. + x-speakeasy-name-override: CompletedAction + c1.api.policy.v1.ConnectorProvision: + description: | + Indicates that a connector should perform the provisioning. This object has no fields. + + This message contains a oneof named provision_type. Only a single field of the following list may be set at a time: + - defaultBehavior + - account + - deleteAccount properties: - createdAt: - format: date-time - type: - - string - - "null" - deletedAt: - format: date-time - type: - - string - - "null" - form: + account: oneOf: - - $ref: '#/components/schemas/c1.api.form.v1.Form' + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.AccountProvision' - type: "null" - id: - description: The unique identifier of this request schema. - type: string - justificationVisibility: - description: Controls whether the justification field is shown or hidden on the request form. - enum: - - JUSTIFICATION_VISIBILITY_UNSPECIFIED - - JUSTIFICATION_VISIBILITY_SHOW - - JUSTIFICATION_VISIBILITY_HIDE - type: string - x-speakeasy-unknown-values: allow - modifiedAt: - format: date-time - type: - - string - - "null" - title: Request Schema + defaultBehavior: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DefaultBehavior' + - type: "null" + deleteAccount: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DeleteAccount' + - type: "null" + title: Connector Provision type: object - x-speakeasy-name-override: RequestSchema - c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest: - description: The request message for creating a single entitlement binding on a request schema. + x-speakeasy-name-override: ConnectorProvision + c1.api.policy.v1.ConnectorProvision.AccountProvision: + description: | + The AccountProvision message. + + This message contains a oneof named storage_type. Only a single field of the following list may be set at a time: + - saveToVault + - doNotSave properties: - entitlementRef: + config: + additionalProperties: true + type: + - object + - "null" + connectorId: + description: The connectorId field. + type: string + doNotSave: oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DoNotSave' - type: "null" - requestSchemaId: - description: The unique identifier of the request schema to bind the entitlement to. + saveToVault: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.SaveToVault' + - type: "null" + schemaId: + description: The schemaId field. type: string - title: Request Schema Service Create Entitlement Binding Request + title: Account Provision type: object - x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingRequest - c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse: - description: The response message for creating a single entitlement binding. + x-speakeasy-name-override: AccountProvision + c1.api.policy.v1.ConnectorProvision.DefaultBehavior: + description: The DefaultBehavior message. properties: - entitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - requestSchemaId: - description: The unique identifier of the request schema the entitlement was bound to. + connectorId: + description: |- + this checks if the entitlement is enabled by provisioning in a specific connector + this can happen automatically and doesn't need any extra info type: string - title: Request Schema Service Create Entitlement Binding Response + title: Default Behavior type: object - x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingResponse - c1.api.request_schema.v1.RequestSchemaServiceCreateRequest: - description: The request message for creating a new request schema. + x-speakeasy-name-override: DefaultBehavior + c1.api.policy.v1.ConnectorProvision.DeleteAccount: + description: The DeleteAccount message. properties: - description: - description: An optional description of the request schema's purpose. + connectorId: + description: The connectorId field. type: string - fieldGroups: - description: Logical groupings of fields for display purposes. + title: Delete Account + type: object + x-speakeasy-name-override: DeleteAccount + c1.api.policy.v1.ConnectorProvision.DoNotSave: + description: The DoNotSave message. + title: Do Not Save + type: object + x-speakeasy-name-override: DoNotSave + c1.api.policy.v1.ConnectorProvision.SaveToVault: + description: The SaveToVault message. + properties: + vaultIds: + description: The vaultIds field. items: - $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' + type: string type: - array - "null" - fieldRelationships: - description: Dependencies between fields that control conditional visibility or validation. + title: Save To Vault + type: object + x-speakeasy-name-override: SaveToVault + c1.api.policy.v1.CreatePolicyRequest: + description: The CreatePolicyRequest message is used to create a new policy. + properties: + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + baselinePolicyId: + description: |- + When set, the new policy's baseline defers to another policy of the same + type when no rule matches, instead of an inline baseline step list. + Mutually exclusive with the baseline entry in policy_steps. Requires the + POLICY_REFERENCES_POLICY feature; obeys the same depth/cycle/self rules as + Rule.policy_id. + type: string + description: + description: The description of the new policy. + type: string + displayName: + description: The display name of the new policy. + type: string + policySteps: + additionalProperties: + $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' + description: |- + Step sequences for this policy. The map must include a baseline entry keyed + by the lowercased policy type (e.g., "grant"). Additional entries with + opaque keys can be added for conditional routing via the rules array. + type: object + policyType: + description: The type of policy to create (grant, revoke, or certify). + enum: + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION + type: string + x-speakeasy-unknown-values: allow + postActions: + description: Ordered actions to execute after the policy completes processing. items: - $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' + $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' type: - array - "null" - fields: - description: The form fields that users must fill out when requesting access. + reassignTasksToDelegates: + deprecated: true + description: This field is no longer used. Configure delegate reassignment in the policy step instead. + type: boolean + rules: + description: Conditional routing rules. See the Policy message for details on evaluation order. items: - $ref: '#/components/schemas/c1.api.form.v1.Field' + $ref: '#/components/schemas/c1.api.policy.v1.Rule' type: - array - "null" - justificationVisibility: - description: Controls whether the justification field is shown or hidden on the request form. - enum: - - JUSTIFICATION_VISIBILITY_UNSPECIFIED - - JUSTIFICATION_VISIBILITY_SHOW - - JUSTIFICATION_VISIBILITY_HIDE - type: string - x-speakeasy-unknown-values: allow - name: - description: The human-readable name for the request schema. - type: string - title: Request Schema Service Create Request - type: object - x-speakeasy-name-override: RequestSchemaServiceCreateRequest - c1.api.request_schema.v1.RequestSchemaServiceCreateResponse: - description: The response message for creating a request schema. - properties: - requestSchema: + scope: oneOf: - - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyScope' - type: "null" - title: Request Schema Service Create Response - type: object - x-speakeasy-name-override: RequestSchemaServiceCreateResponse - c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput: - description: The request message for deleting a request schema. - title: Request Schema Service Delete Request - type: object - x-speakeasy-name-override: RequestSchemaServiceDeleteRequest - c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse: - description: The response message for deleting a request schema. - title: Request Schema Service Delete Response + required: + - displayName + title: Create Policy Request type: object - x-speakeasy-name-override: RequestSchemaServiceDeleteResponse - c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest: - description: The request message for finding which request schema is bound to a given app entitlement. + x-speakeasy-entity: Policy + x-speakeasy-name-override: CreatePolicyRequest + c1.api.policy.v1.CreatePolicyResponse: + description: The CreatePolicyResponse message contains the created policy object. properties: - entitlementRef: + policy: oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - type: "null" - title: Request Schema Service Find Binding For App Entitlement Request + title: Create Policy Response type: object - x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementRequest - c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse: - description: The response message containing the binding for the specified app entitlement. + x-speakeasy-name-override: CreatePolicyResponse + c1.api.policy.v1.DelegatedProvision: + description: This provision step indicates that we should delegate provisioning to the configuration of another app entitlement. This app entitlement does not have to be one from the same app, but MUST be configured as a proxy binding leading into this entitlement. properties: - entitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - requestSchemaId: - description: The unique identifier of the request schema bound to this entitlement, if any. + appId: + description: The AppID of the entitlement to delegate provisioning to. type: string - title: Request Schema Service Find Binding For App Entitlement Response - type: object - x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementResponse - c1.api.request_schema.v1.RequestSchemaServiceGetResponse: - description: The response message for retrieving a request schema. - properties: - requestSchema: - oneOf: - - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - - type: "null" - title: Request Schema Service Get Response - type: object - x-speakeasy-name-override: RequestSchemaServiceGetResponse - c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest: - description: The request message for removing a single entitlement binding from a request schema. - properties: - entitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - requestSchemaId: - description: The unique identifier of the request schema to remove the binding from. + entitlementId: + description: The ID of the entitlement we are delegating provisioning to. type: string - title: Request Schema Service Remove Entitlement Binding Request + implicit: + description: If true, a binding will be automatically created from the entitlement of the parent app. + type: boolean + title: Delegated Provision type: object - x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingRequest - c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse: - description: The response message for removing a single entitlement binding. - title: Request Schema Service Remove Entitlement Binding Response + x-speakeasy-name-override: DelegatedProvision + c1.api.policy.v1.DeletePolicyRequestInput: + description: The DeletePolicyRequest message contains the ID of the policy to delete. It uses URL value for input. + title: Delete Policy Request type: object - x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingResponse - c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput: - description: The request message for updating an existing request schema. + x-speakeasy-entity: Policy + x-speakeasy-name-override: DeletePolicyRequest + c1.api.policy.v1.DeletePolicyResponse: + description: Empty response with a status code indicating success. + title: Delete Policy Response + type: object + x-speakeasy-name-override: DeletePolicyResponse + c1.api.policy.v1.DeniedAction: + description: The denied action indicates that the c1.api.policy.v1.ApprovalInstance had an outcome of denied. properties: - requestSchema: - oneOf: - - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - - type: "null" - updateMask: + deniedAt: + format: date-time + readOnly: true type: - string - "null" - title: Request Schema Service Update Request + userId: + description: The UserID that denied this step. + readOnly: true + type: string + title: Denied Action type: object - x-speakeasy-name-override: RequestSchemaServiceUpdateRequest - c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse: - description: The response message for updating a request schema. + x-speakeasy-name-override: DeniedAction + c1.api.policy.v1.DevicePlacementProvision: + description: This provision step is fulfilled by a Latchkey member device producing an MLS Welcome for the recipient. It has no assignee and no instructions because the step is not human-actionable. properties: - requestSchema: - oneOf: - - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - - type: "null" - title: Request Schema Service Update Response + vaultBoundaryId: + description: The vaultBoundaryId field. + type: string + title: Device Placement Provision type: object - x-speakeasy-name-override: RequestSchemaServiceUpdateResponse - c1.api.requestcatalog.v1.AppEntitlementWithUserBindings: - description: The AppEntitlementWithUserBindings message represents an app entitlement and its associated user bindings. + x-speakeasy-name-override: DevicePlacementProvision + c1.api.policy.v1.EditorValidateRequest: + description: The EditorValidateRequest message. properties: - appEntitlementUserBindings: - description: An array of AppEntitlementUserBinding objects which represent the relationships that give app users access to the specific app entitlement. + text: + description: The text field. + type: string + title: Editor Validate Request + type: object + x-speakeasy-name-override: PolicyEditorValidateRequest + c1.api.policy.v1.EditorValidateResponse: + description: The EditorValidateResponse message. + properties: + markers: + description: The markers field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' + $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' type: - array - "null" - entitlement: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - - type: "null" - title: App Entitlement With User Bindings + title: Editor Validate Response type: object - x-speakeasy-name-override: AppEntitlementWithUserBindings - c1.api.requestcatalog.v1.BundleAutomation: - description: | - The BundleAutomation message. - - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel + x-speakeasy-name-override: PolicyEditorValidateResponse + c1.api.policy.v1.EntitlementOwnerApproval: + description: The entitlement owner approval allows configuration of the approval step when the target approvers are the entitlement owners. properties: - cel: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - - type: "null" - circuitBreaker: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker' - - type: "null" - createTasks: - description: The createTasks field. + allowSelfApproval: + description: Configuration to allow self approval if the target user is an entitlement owner during this step. type: boolean - createdAt: - format: date-time + fallback: + description: Configuration to allow a fallback if the entitlement owner cannot be identified. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the entitlement owner cannot be identified. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - - string + - array - "null" - deletedAt: - format: date-time + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the entitlement owner cannot be identified. + items: + type: string type: - - string + - array - "null" - disableCircuitBreaker: - description: The disableCircuitBreaker field. - type: boolean - enabled: - description: The enabled field. + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. type: boolean - enforceOnSmallProfiles: - description: |- - When true, the circuit breaker is evaluated even on profiles below the - tenant min-members floor. + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. type: boolean - entitlements: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - - type: "null" - removedMembersThresholdPercent: - description: |- - Per-automation override for the removed-members percent that trips the - circuit breaker (1-100). 0 / unset means the tenant default applies. - format: int64 - type: string - requestCatalogId: - description: The requestCatalogId field. - type: string - state: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationLastRunState' - - type: "null" - tenantId: - description: The tenantId field. - type: string - updatedAt: - format: date-time - type: - - string - - "null" - title: Bundle Automation + title: Entitlement Owner Approval type: object - x-speakeasy-name-override: BundleAutomation - c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState: - description: The BundleAutomationCelEvaluationState message. + x-speakeasy-name-override: EntitlementOwnerApproval + c1.api.policy.v1.EntitlementOwnerProvisioner: + description: EntitlementOwnerProvisioner resolves to entitlement owners. properties: - errorMessage: - description: The errorMessage field. - type: string - lastEvaluatedAt: - format: date-time + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + fallbackUserIds: + description: Fallback user IDs if no entitlement owners are found. + items: + type: string type: - - string + - array - "null" - matchedUsers: - description: The matchedUsers field. - format: int64 - type: string - status: - description: The status field. - enum: - - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED - - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS - - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE - - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS - - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL - type: string - x-speakeasy-unknown-values: allow - title: Bundle Automation Cel Evaluation State + title: Entitlement Owner Provisioner type: object - x-speakeasy-name-override: BundleAutomationCelEvaluationState - c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker: - description: The BundleAutomationCircuitBreaker message. + x-speakeasy-name-override: EntitlementOwnerProvisioner + c1.api.policy.v1.ErroredAction: + description: The outcome of a provision instance that has errored. properties: - removedMembersThresholdPercentage: - description: The removedMembersThresholdPercentage field. - format: int64 + description: + description: The description of a provision instance that has errored. type: string - state: - description: The state field. - enum: - - CIRCUIT_BREAKER_STATE_UNSPECIFIED - - CIRCUIT_BREAKER_STATE_TRIGGERED - - CIRCUIT_BREAKER_STATE_BYPASS - - CIRCUIT_BREAKER_STATE_SUPPORT_DISABLED + errorCode: + description: The error code of a provision instance that has errored. This is only PEC-1 for now, but more will be added in the future. type: string - x-speakeasy-unknown-values: allow - updatedAt: + erroredAt: format: date-time type: - string - "null" - userRef: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - - type: "null" - title: Bundle Automation Circuit Breaker + title: Errored Action type: object - x-speakeasy-name-override: BundleAutomationCircuitBreaker - c1.api.requestcatalog.v1.BundleAutomationLastRunState: - description: The BundleAutomationLastRunState message. + x-speakeasy-name-override: ErroredAction + c1.api.policy.v1.Escalation: + description: | + The Escalation message. + + This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: + - replacePolicy + - reassignToApprovers + - cancelTicket + - skipStep properties: - celEvaluation: + cancelTicket: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState' + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.CancelTicket' - type: "null" - errorMessage: - description: The errorMessage field. + escalationComment: + description: The escalationComment field. type: string - lastRunAt: - format: date-time - type: - - string - - "null" - status: - description: The status field. - enum: - - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED - - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS - - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE - - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS - - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL + expiration: + description: The expiration field. + format: int64 type: string - x-speakeasy-unknown-values: allow - title: Bundle Automation Last Run State + reassignToApprovers: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReassignToApprovers' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReplacePolicy' + - type: "null" + skipStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.SkipStep' + - type: "null" + title: Escalation type: object - x-speakeasy-name-override: BundleAutomationLastRunState - c1.api.requestcatalog.v1.BundleAutomationRuleCEL: - description: The BundleAutomationRuleCEL message. - properties: - expression: - description: The expression field. - type: string - title: Bundle Automation Rule Cel + x-speakeasy-name-override: Escalation + c1.api.policy.v1.Escalation.CancelTicket: + description: The CancelTicket message. + title: Cancel Ticket type: object - x-speakeasy-name-override: BundleAutomationRuleCEL - c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement: - description: The BundleAutomationRuleEntitlement message. + x-speakeasy-name-override: CancelTicket + c1.api.policy.v1.Escalation.ReassignToApprovers: + description: The ReassignToApprovers message. properties: - entitlementRefs: - description: The entitlementRefs field. + approverIds: + description: The approverIds field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - title: Bundle Automation Rule Entitlement + title: Reassign To Approvers type: object - x-speakeasy-name-override: BundleAutomationRuleEntitlement - c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput: + x-speakeasy-name-override: ReassignToApprovers + c1.api.policy.v1.Escalation.ReplacePolicy: + description: The ReplacePolicy message. + properties: + policyId: + description: The policyId field. + type: string + title: Replace Policy + type: object + x-speakeasy-name-override: ReplacePolicy + c1.api.policy.v1.Escalation.SkipStep: + description: The SkipStep message. + title: Skip Step + type: object + x-speakeasy-name-override: SkipStep + c1.api.policy.v1.EscalationInstance: description: | - The request message for creating a new bundle automation rule on a catalog. + The EscalationInstance message. - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel + This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: + - replacePolicy + - reassignToApprovers + - cancelTicket + - skipStep properties: - cel: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - - type: "null" - createTasks: - description: Whether to create access request tasks for matched users instead of granting directly. - type: boolean - disableCircuitBreaker: - description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. - type: boolean - enabled: - description: Whether the automation should actively run on its schedule. - type: boolean - enforceOnSmallProfiles: - description: |- - When true, the circuit breaker is evaluated even on profiles below the - tenant min-members floor. Defaults to false. + alreadyEscalated: + description: The alreadyEscalated field. type: boolean - entitlements: + cancelTicket: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.CancelTicket' - type: "null" - removedMembersThresholdPercent: - description: |- - Per-automation override for the removed-members percent that trips the - circuit breaker (1-100). 0 / unset means inherit the tenant default. - format: int64 + escalationComment: + description: The escalationComment field. type: string - title: Create Bundle Automation Request - type: object - x-speakeasy-name-override: CreateBundleAutomationRequest - c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput: - description: The request message for deleting a bundle automation from a catalog. - title: Delete Bundle Automation Request + expiresAt: + format: date-time + type: + - string + - "null" + reassignToApprovers: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReassignToApprovers' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReplacePolicy' + - type: "null" + skipStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.SkipStep' + - type: "null" + title: Escalation Instance type: object - x-speakeasy-name-override: DeleteBundleAutomationRequest - c1.api.requestcatalog.v1.DeleteBundleAutomationResponse: - description: The response message for deleting a bundle automation. - title: Delete Bundle Automation Response + x-speakeasy-name-override: EscalationInstance + c1.api.policy.v1.EscalationInstance.CancelTicket: + description: The CancelTicket message. + title: Cancel Ticket type: object - x-speakeasy-name-override: DeleteBundleAutomationResponse - c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput: - description: The request message for triggering an immediate bundle automation run. + x-speakeasy-name-override: EscalationInstanceCancelTicket + c1.api.policy.v1.EscalationInstance.ReassignToApprovers: + description: The ReassignToApprovers message. properties: - refs: - description: Optional entitlement references to scope the run to specific entitlements. + approverIds: + description: The approverIds field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - title: Force Run Bundle Automation Request + title: Reassign To Approvers type: object - x-speakeasy-name-override: ForceRunBundleAutomationRequest - c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse: - description: The response message for triggering a bundle automation run. - title: Force Run Bundle Automation Response + x-speakeasy-name-override: EscalationInstanceReassignToApprovers + c1.api.policy.v1.EscalationInstance.ReplacePolicy: + description: The ReplacePolicy message. + properties: + policyId: + description: The policyId field. + type: string + title: Replace Policy type: object - x-speakeasy-name-override: ForceRunBundleAutomationResponse - c1.api.requestcatalog.v1.RequestCatalog: - description: The RequestCatalog is used for managing which entitlements are requestable, and who can request them. + x-speakeasy-name-override: EscalationInstanceReplacePolicy + c1.api.policy.v1.EscalationInstance.SkipStep: + description: The SkipStep message. + title: Skip Step + type: object + x-speakeasy-name-override: EscalationInstanceSkipStep + c1.api.policy.v1.ExpressionApproval: + description: The ExpressionApproval message. properties: - accessEntitlements: - description: An array of app entitlements that, if the user has, can view the contents of this catalog. + allowSelfApproval: + description: Configuration to allow self approval of if the user is specified and also the target of the ticket. + type: boolean + assignedUserIds: + description: The assignedUserIds field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + type: string + readOnly: true type: - array - "null" - annotations: - additionalProperties: + expressions: + description: Array of dynamic expressions to determine the approvers. The first expression to return a non-empty list of users will be used. + items: type: string - description: |- - Bounded key/value metadata bag for IaC marking and customer tags. - See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 - chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars - URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ - are reserved. - - Well-known keys: `managed_by`, `iac_workspace`, - `iac_resource_address`, `iac_tool_version`. - type: object - x-speakeasy-terraform-plan-modifier: - imports: - - github.com/conductorone/terraform-provider-conductorone/internal/annotations - schemaDefinition: annotations.PlanModifier() - createdAt: - format: date-time - readOnly: true type: - - string + - array - "null" - createdByUserId: - description: The id of the user this request catalog was created by. - type: string - deletedAt: - format: date-time - readOnly: true + fallback: + description: Configuration to allow a fallback if the expression does not return a valid list of users. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the expression does not return a valid list of users. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - - string + - array - "null" - description: - description: The description of the request catalog. - type: string - displayName: - description: The display name of the request catalog. - type: string - enrollmentBehavior: - description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. - enum: - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY - type: string - x-speakeasy-unknown-values: allow - id: - description: The id of the request catalog. - type: string - published: - description: Whether or not this catalog is published. - type: boolean - requestBundle: - description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. - type: boolean - unenrollmentBehavior: - description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED - type: string - x-speakeasy-unknown-values: allow - unenrollmentEntitlementBehavior: - description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE - type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - visibleToEveryone: - description: If this is true, the access entitlement requirement is ignored. - type: boolean - title: Request Catalog - type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalog - c1.api.requestcatalog.v1.RequestCatalogExpandMask: - description: The RequestCatalogExpandMask includes the paths in the catalog view to expand in the return value of this call. - properties: - paths: - description: An array of paths to be expanded in the response. May be any combination of "*", "created_by_user_id", "app_ids", and "access_entitlements". + fallbackUserIds: + description: Configuration to specific which users to fallback to if and the expression does not return a valid list of users. items: type: string type: - array - "null" - title: Request Catalog Expand Mask + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: Expression Approval type: object - x-speakeasy-name-override: RequestCatalogExpandMask - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput: - description: |- - The RequestCatalogManagementServiceAddAccessEntitlementsRequest message is used to add access entitlements to a request - catalog to determine which users can view the request catalog. + x-speakeasy-name-override: ExpressionApproval + c1.api.policy.v1.ExpressionProvisioner: + description: ExpressionProvisioner evaluates CEL expressions to determine provisioners. properties: - accessEntitlements: - description: List of entitlements to add to the request catalog as access entitlements. + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + expressions: + description: The CEL expressions to evaluate. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - required: - - accessEntitlements - title: Request Catalog Management Service Add Access Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Visibility_Bindings - x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Add Access Entitlements Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceAddAppEntitlementsRequest object is used to add app requestable app entitlements to a request catalog. - properties: - appEntitlements: - description: List of entitlements to add to the request catalog. + fallbackUserIds: + description: Fallback user IDs if expression evaluation yields no users. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - createRequests: - description: |- - Whether or not to create requests for newly added entitlements for users in the catalog. - By default, this is false and no requests are created. - type: boolean - required: - - appEntitlements - title: Request Catalog Management Service Add App Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Add App Entitlements Response + title: Expression Provisioner type: object - x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest: - description: Create a request catalog. + x-speakeasy-name-override: ExpressionProvisioner + c1.api.policy.v1.ExternalTicketProvision: + description: This provision step indicates that we should check an external ticket to provision this entitlement properties: - annotations: - additionalProperties: - type: string - description: |- - Bounded key/value metadata bag for IaC marking and customer tags. - See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 - chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars - matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting - with `c1/` are reserved for server-managed use and rejected on write. - - Well-known keys: `managed_by`, `iac_workspace`, - `iac_resource_address`, `iac_tool_version`. - type: object - x-speakeasy-terraform-plan-modifier: - imports: - - github.com/conductorone/terraform-provider-conductorone/internal/annotations - schemaDefinition: annotations.PlanModifier() - description: - description: The description of the new request catalog. - type: string - displayName: - description: The display name of the new request catalog. + appId: + description: The appId field. type: string - enrollmentBehavior: - description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. - enum: - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY + connectorId: + description: The connectorId field. type: string - x-speakeasy-unknown-values: allow - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' - - type: "null" - published: - description: Whether or not the new catalog should be created as published. - type: boolean - requestBundle: - description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. - type: boolean - unenrollmentBehavior: - description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. type: string - x-speakeasy-unknown-values: allow - unenrollmentEntitlementBehavior: - description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE + instructions: + description: This field indicates a text body of instructions for the provisioner to indicate. type: string - x-speakeasy-unknown-values: allow - visibleToEveryone: - description: Whether or not the new catalog is visible to everyone by default. - type: boolean - required: - - displayName - title: Request Catalog Management Service Create Request - type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput: - description: Create a single requestable entry - properties: - createRequests: - description: |- - Whether or not to create requests for newly added entitlement for users in the catalog. - By default, this is false and no requests are created. - type: boolean - title: Request Catalog Management Service Create Requestable Entry Request + title: External Ticket Provision type: object - x-speakeasy-entity: Access_Profile_Requestable_Entry - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse: - description: Response containing the created requestable entry + x-speakeasy-name-override: ExternalTicketProvision + c1.api.policy.v1.Form: + description: The Form message. properties: - requestableEntry: + form: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' + - $ref: '#/components/schemas/c1.api.form.v1.Form' - type: "null" - title: Request Catalog Management Service Create Requestable Entry Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput: - description: Delete a request catalog by Id. It uses URL value for input. - title: Request Catalog Management Service Delete Request - type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput: - description: Delete a single requestable entry - title: Request Catalog Management Service Delete Requestable Entry Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entry - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse: - description: Empty response for delete operation - title: Request Catalog Management Service Delete Requestable Entry Response + title: Form type: object - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Delete Response + x-speakeasy-name-override: Form + c1.api.policy.v1.FormCompletedAction: + description: The FormCompletedAction message. + properties: + completedAt: + format: date-time + type: + - string + - "null" + userId: + description: The userId field. + type: string + title: Form Completed Action type: object - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse: - description: Response containing the requested entry + x-speakeasy-name-override: FormCompletedAction + c1.api.policy.v1.FormInstance: + description: | + The FormInstance message. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - completed + - restarted + - reassigned + - skipped properties: - requestableEntry: + completed: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' + - $ref: '#/components/schemas/c1.api.policy.v1.FormCompletedAction' - type: "null" - title: Request Catalog Management Service Get Requestable Entry Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceGetRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse: - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + data: + additionalProperties: true type: - - array + - object - "null" - requestCatalogView: + form: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' + - $ref: '#/components/schemas/c1.api.form.v1.Form' - type: "null" - title: Request Catalog Management Service Get Response + reassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' + - type: "null" + restarted: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: The state field. + enum: + - FORM_INSTANCE_STATE_UNSPECIFIED + - FORM_INSTANCE_STATE_WAITING + - FORM_INSTANCE_STATE_DONE + type: string + x-speakeasy-unknown-values: allow + title: Form Instance type: object - x-speakeasy-name-override: RequestCatalogManagementServiceGetResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse: - description: The response message containing all requestable entitlement references in the catalog. + x-speakeasy-name-override: FormInstance + c1.api.policy.v1.GetPolicyResponse: + description: The GetPolicyResponse message contains the policy object. properties: - refs: - description: The complete list of app entitlement references in this catalog. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - type: - - array - - "null" - title: Request Catalog Management Service List All Entitlement Ids Per Catalog Response + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + title: Get Policy Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse: - description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: GetPolicyResponse + c1.api.policy.v1.GroupProvisioner: + description: GroupProvisioner resolves to members of a specific group. properties: - expanded: - description: List of serialized related objects. + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + appGroupId: + description: The app group ID (entitlement ID). + type: string + appId: + description: The app ID containing the group. + type: string + fallbackUserIds: + description: Fallback user IDs if no group members are found. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + type: string type: - array - "null" + title: Group Provisioner + type: object + x-speakeasy-name-override: GroupProvisioner + c1.api.policy.v1.ListPolicyResponse: + description: The ListPolicyResponse message. + properties: list: - description: The list of results containing up to X results, where X is the page size defined in the request. + description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + $ref: '#/components/schemas/c1.api.policy.v1.Policy' type: - array - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Request Catalog Management Service List Entitlements For Access Response + title: List Policy Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsForAccessResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse: - description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ListPolicyResponse + c1.api.policy.v1.ManagerApproval: + description: The manager approval object provides configuration options for approval when the target of the approval is the manager of the user in the task. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - list: - description: The list of results containing up to X results, where X is the page size defined in the request. + allowSelfApproval: + description: Configuration to allow self approval if the target user is their own manager. This may occur if a service account has an identity user and manager specified as the same person. + type: boolean + assignedUserIds: + description: The array of users determined to be the manager during processing time. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + type: string + readOnly: true type: - array - "null" - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: Request Catalog Management Service List Entitlements Per Catalog Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsPerCatalogResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse: - description: The RequestCatalogManagementServiceListResponse message. - properties: - expanded: - description: List of serialized related objects. + fallback: + description: Configuration to allow a fallback if no manager is found. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and no manager is found. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - array - "null" - list: - description: The list of request catalogs. + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and no manager is found. items: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' + type: string type: - array - "null" - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: Request Catalog Management Service List Response + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: Manager Approval type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput: - description: |- - The RequestCatalogManagementServiceRemoveAccessEntitlementsRequest message is used to remove access entitlements from a request catalog. - The access entitlements are used to determine which users can view the request catalog. + x-speakeasy-name-override: ManagerApproval + c1.api.policy.v1.ManagerProvisioner: + description: ManagerProvisioner resolves to the user's manager. properties: - accessEntitlements: - description: The list of access entitlements to remove from the catalog. + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + fallbackUserIds: + description: Fallback user IDs if no manager is found. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - title: Request Catalog Management Service Remove Access Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Visibility_Bindings - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Remove Access Entitlements Response + title: Manager Provisioner type: object - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceRemoveAppEntitlementsRequest message is used to remove app entitlements from a request catalog. + x-speakeasy-name-override: ManagerProvisioner + c1.api.policy.v1.ManualProvision: + description: Manual provisioning indicates that a human must intervene for the provisioning of this step. properties: - appEntitlements: - description: The list of app entitlements to remove from the catalog. + assignee: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionerAssignment' + - type: "null" + instructions: + description: This field indicates a text body of instructions for the provisioner to indicate. + type: string + userIds: + description: |- + An array of users that are required to provision during this step. + Deprecated: Use assignee field instead for dynamic provisioner assignment. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: string type: - array - "null" - title: Request Catalog Management Service Remove App Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse: - description: Empty response with a status code indicating success - title: Request Catalog Management Service Remove App Entitlements Response + title: Manual Provision type: object - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceUpdateAppEntitlementsRequest object is used to update app entitlements to a request catalog id. + x-speakeasy-name-override: ManualProvision + c1.api.policy.v1.MultiStep: + description: MultiStep indicates that this provision step has multiple steps to process. properties: - appEntitlements: - description: The entitlement to get from the request catalog. + provisionSteps: + description: The array of provision steps to process. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' type: - array - "null" - required: - - appEntitlements - title: Request Catalog Management Service Update App Entitlements Request + title: Multi Step type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse: - description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. - title: Request Catalog Management Service Update App Entitlements Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput: - description: Update a request catalog object by ID. + x-speakeasy-name-override: MultiStep + c1.api.policy.v1.Policy: + description: |- + A policy defines a workflow (sequence of steps) that runs when processing + access requests, reviews, or revocations. Policies support conditional + routing: different conditions can trigger different step sequences, with a + baseline fallback. properties: - catalog: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' - - type: "null" - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' - - type: "null" - updateMask: + annotations: + additionalProperties: + type: string + description: |- + Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256 + chars; URL-safe ASCII. Keys starting with `c1/` are reserved. + + Updates have PATCH semantics: keys absent from the request are + preserved; an empty value deletes the key. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + baselinePolicyId: + description: |- + When set, the baseline defers to another policy of the same type when no + rule matches, instead of the baseline entry in policy_steps (keyed by the + lowercased policy_type). Mutually exclusive with that baseline entry: set + one or the other, not both. The referenced policy must share this + policy's policy_type, must not introduce a cycle or self-reference, and + must not push any reachable chain over depth 5. Gated by the + POLICY_REFERENCES_POLICY feature flag. + type: string + createdAt: + format: date-time + readOnly: true type: - string - "null" - title: Request Catalog Management Service Update Request - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateRequest - c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest: - description: The RequestCatalogSearchServiceSearchEntitlementsRequest searches entitlements, but only ones that are available to you through the open catalogs. - properties: - appDisplayName: - description: Search entitlements that belong to this app name (exact match). + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: The description of the Policy. type: string - entitlementAlias: - description: Search for entitlements with this alias (exact match). + displayName: + description: The display name of the Policy. type: string - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - - type: "null" - grantedStatus: - description: Search entitlements with this granted status for your signed in user. + id: + description: The ID of the Policy. + readOnly: true + type: string + policySteps: + additionalProperties: + $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' + description: |- + A map from string keys to step sequences. One entry is always the baseline, + keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify"). + Additional entries have opaque keys (UUIDs) and are referenced by the rules + array for conditional routing. If no conditional rules are configured, only + the baseline entry exists. + type: object + policyType: + description: |- + The type of this policy (grant, revoke, or certify). The lowercased type + name (e.g., "grant") is also the key for the baseline entry in policy_steps. enum: - - UNSPECIFIED - - ALL - - GRANTED - - NOT_GRANTED + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION type: string x-speakeasy-unknown-values: allow - includeDeleted: - description: Include deleted entitlements - type: boolean - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - query: - description: Fuzzy search the display name of resource types. - type: string - title: Request Catalog Search Service Search Entitlements Request - type: object - x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse: - description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - properties: - expanded: - description: List of serialized related objects. + postActions: + description: Ordered actions to execute after the policy completes processing. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' type: - array - "null" - list: - description: The list of results containing up to X results, where X is the page size defined in the request. + reassignTasksToDelegates: + deprecated: true + description: This field is no longer used. Configure delegate reassignment in the policy step instead. + type: boolean + rules: + description: |- + Ordered conditional routing rules. Evaluated top-to-bottom; the first + matching rule selects a step sequence from policy_steps. If no rule matches + (or if this array is empty), the baseline entry in policy_steps is used. items: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.AppEntitlementWithUserBindings' + $ref: '#/components/schemas/c1.api.policy.v1.Rule' type: - array - "null" - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: Request Catalog Search Service Search Entitlements Response - type: object - x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogView: - description: The request catalog view contains the serialized request catalog and paths to objects referenced by the request catalog. - properties: - accessEntitlementsPath: - description: JSONPATH expression indicating the location of the access entitlement objects, that the request catalog allows users to request, in the array. - type: string - createdByUserPath: - description: JSONPATH expression indicating the location of the User object, that created the request catalog, in the array. - type: string - memberCount: - description: Total number of the members of the catalog - format: int64 - type: string - requestCatalog: + scope: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyScope' - type: "null" - title: Request Catalog View - type: object - x-speakeasy-name-override: RequestCatalogView - c1.api.requestcatalog.v1.RequestableEntry: - description: A requestable entry in a catalog - properties: - appId: - description: The ID of the app that contains the entitlement - type: string - catalogId: - description: The ID of the access profile (catalog) - type: string - entitlementId: - description: The ID of the entitlement - type: string - title: Requestable Entry - type: object - x-speakeasy-name-override: RequestableEntry - c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput: - description: The request message for resuming a paused bundle automation. - title: Resume Paused Bundle Automation Request - type: object - x-speakeasy-name-override: ResumePausedBundleAutomationRequest - c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse: - description: The response message for resuming a paused bundle automation. - title: Resume Paused Bundle Automation Response + systemBuiltin: + description: Whether this policy is a builtin system policy. Builtin system policies cannot be edited. + readOnly: true + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Policy type: object - x-speakeasy-name-override: ResumePausedBundleAutomationResponse - c1.api.requestcatalog.v1.SetBundleAutomationRequestInput: - description: | - The request message for creating or updating a bundle automation rule on a catalog. - - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel + x-speakeasy-entity: Policy + x-speakeasy-name-override: Policy + c1.api.policy.v1.PolicyInstance: + description: A policy instance is an object that contains a reference to the policy it was created from, the currently executing step, the next steps, and the history of previously completed steps. properties: - cel: - oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - - type: "null" - createTasks: - description: Whether to create access request tasks for matched users instead of granting directly. - type: boolean - disableCircuitBreaker: - description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. - type: boolean - enabled: - description: Whether the automation should actively run on its schedule. - type: boolean - enforceOnSmallProfiles: - description: |- - When true, the circuit breaker is evaluated even on profiles below the - tenant min-members floor. Defaults to false. - type: boolean - entitlements: + current: oneOf: - - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' - type: "null" - removedMembersThresholdPercent: - description: |- - Per-automation override for the removed-members percent that trips the - circuit breaker (1-100). 0 / unset means inherit the tenant default. - format: int64 - type: string - title: Set Bundle Automation Request - type: object - x-speakeasy-name-override: SetBundleAutomationRequest - c1.api.role_mining_management.v1.CohortHintInput: - description: The CohortHintInput message. - properties: - attribute: - description: The user attribute name to use for cohort grouping (e.g., "department", "job_title"). - type: string - priority: - description: Relative priority of this hint. Higher values cause the analysis to weight this attribute more heavily. - format: int32 - type: integer - values: - description: Specific attribute values to focus on. If empty, all values for the attribute are considered. + history: + description: An array of steps that were previously processed by the ticket with their outcomes set, in order. items: - type: string + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' + readOnly: true type: - array - "null" - title: Cohort Hint Input - type: object - x-speakeasy-name-override: CohortHintInput - c1.api.role_mining_management.v1.CohortHintView: - description: The CohortHintView message. - properties: - attribute: - description: The user attribute name used for cohort grouping. - type: string - priority: - description: Relative priority of this hint. - format: int32 - type: integer - values: - description: The specific attribute values targeted by this hint. + next: + description: An array of steps that will be processed by the ticket, in order. items: - type: string + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + readOnly: true type: - array - "null" - title: Cohort Hint View - type: object - x-speakeasy-name-override: CohortHintView - c1.api.role_mining_management.v1.CohortUserWithCoverage: - description: CohortUserWithCoverage pairs a user with the count of selected entitlements they hold. - properties: - coveredCount: - description: Number of selected_entitlements that this user currently holds. - format: int32 - type: integer - user: + policy: oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - type: "null" - title: Cohort User With Coverage + title: Policy Instance type: object - x-speakeasy-name-override: CohortUserWithCoverage - c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest: - description: The CreateAccessProfileFromCohortRequest message. + x-speakeasy-name-override: PolicyInstance + c1.api.policy.v1.PolicyPostActions: + description: | + Actions to execute after a policy finishes processing. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - certifyRemediateImmediately properties: - celExpression: - description: |- - Optional CEL expression for dynamic membership. When non-empty, used - instead of auto-generating from profile_filters. - type: string - createTasks: + certifyRemediateImmediately: description: |- - If true, the automation will create JIT tasks for access changes. - If false, users are synced to membership without creating tasks. - type: boolean - description: - description: Description for the access profile. - type: string - displayName: - description: Display name for the access profile. - type: string - enableAutomation: - description: If true, enable the dynamic membership automation immediately. - type: boolean - entitlements: - description: Entitlements to add to the access profile. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - type: - - array - - "null" - profileFilters: - description: Profile filters defining the cohort for dynamic membership. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + Only valid on certify policies. When true, any revocations resulting from + the certification are applied immediately when the campaign task closes. + This field is part of the `action` oneof. + See the documentation for `c1.api.policy.v1.PolicyPostActions` for more details. type: - - array + - boolean - "null" - suggestionId: - description: Optional suggestion ID to mark as accepted after creating the profile. - type: string - title: Create Access Profile From Cohort Request - type: object - x-speakeasy-name-override: CreateAccessProfileFromCohortRequest - c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse: - description: The CreateAccessProfileFromCohortResponse message. - properties: - accessProfileId: - description: The ID of the created access profile. - type: string - celExpression: - description: The CEL expression generated for dynamic membership. - type: string - title: Create Access Profile From Cohort Response + title: Policy Post Actions type: object - x-speakeasy-name-override: CreateAccessProfileFromCohortResponse - c1.api.role_mining_management.v1.CustomAnalysisResultView: - description: CustomAnalysisResultView is a lightweight summary of a past custom analysis run. + x-speakeasy-name-override: PolicyPostActions + c1.api.policy.v1.PolicyRef: + description: The PolicyRef message. properties: - cohortSize: - description: Number of users in the cohort. - format: int32 - type: integer - completedAt: - format: date-time - type: - - string - - "null" - createdAt: - format: date-time - type: - - string - - "null" - errorMessage: - description: Error message if the analysis failed, empty on success. - type: string id: - description: Unique identifier for this custom analysis result. - type: string - profileFilters: - description: Profile filters that defined the cohort for this analysis. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - type: - - array - - "null" - status: - description: Execution status of this analysis (e.g., running, completed, failed). - enum: - - RUN_STATUS_UNSPECIFIED - - RUN_STATUS_RUNNING - - RUN_STATUS_COMPLETED - - RUN_STATUS_FAILED - type: string - x-speakeasy-unknown-values: allow - suggestionsGenerated: - description: Number of role suggestions generated. - format: int32 - type: integer - title: Custom Analysis Result View - type: object - x-speakeasy-name-override: CustomAnalysisResultView - c1.api.role_mining_management.v1.EntitlementRef: - description: EntitlementRef identifies an entitlement by app and entitlement ID. - properties: - appId: - description: The appId field. - type: string - entitlementId: - description: The entitlementId field. + description: The id field. type: string - title: Entitlement Ref + title: Policy Ref type: object - x-speakeasy-name-override: EntitlementRef - c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse: - description: The GetCustomAnalysisResultResponse message. + x-speakeasy-name-override: PolicyRef + c1.api.policy.v1.PolicyScope: + description: Scopes a policy to an app or to a single entitlement within an app. properties: - appsAnalyzed: - description: The appsAnalyzed field. - format: int32 - type: integer - clusters: - description: Cluster results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.EntitlementCluster' - type: - - array - - "null" - cohortSize: - description: The cohortSize field. - format: int32 - type: integer - entitlements: - description: Entitlement coverage results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - type: - - array - - "null" - errorMessage: - description: The errorMessage field. + appEntitlementId: + description: |- + Optional. When set, the policy is scoped to this entitlement of app_id + rather than to the whole app. type: string - facetUserCount: - description: The facetUserCount field. - format: int32 - type: integer - facets: - description: Facet results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeFacet' - type: - - array - - "null" - id: - description: The id field. + appId: + description: The ID of the app this policy is scoped to. type: string - status: - description: The status field. + slot: + description: |- + Which of the object's local-policy slots this policy occupies. Part of the + scope, and immutable with it. enum: - - RUN_STATUS_UNSPECIFIED - - RUN_STATUS_RUNNING - - RUN_STATUS_COMPLETED - - RUN_STATUS_FAILED + - POLICY_SCOPE_SLOT_UNSPECIFIED + - POLICY_SCOPE_SLOT_EMERGENCY type: string x-speakeasy-unknown-values: allow - title: Get Custom Analysis Result Response + title: Policy Scope type: object - x-speakeasy-name-override: GetCustomAnalysisResultResponse - c1.api.role_mining_management.v1.GetLatestRunResponse: - description: The GetLatestRunResponse message. + x-speakeasy-name-override: PolicyScope + c1.api.policy.v1.PolicyStep: + description: | + A single step in a policy workflow. Exactly one step type is set. + + This message contains a oneof named step. Only a single field of the following list may be set at a time: + - approval + - provision + - accept + - reject + - wait + - form + - action properties: - run: + accept: oneOf: - - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' + - $ref: '#/components/schemas/c1.api.policy.v1.Accept' - type: "null" - title: Get Latest Run Response - type: object - x-speakeasy-name-override: GetLatestRunResponse - c1.api.role_mining_management.v1.GetRoleMiningConfigResponse: - description: The GetRoleMiningConfigResponse message. - properties: - config: + action: oneOf: - - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' + - $ref: '#/components/schemas/c1.api.policy.v1.Action' - type: "null" - title: Get Role Mining Config Response - type: object - x-speakeasy-name-override: GetRoleMiningConfigResponse - c1.api.role_mining_management.v1.GetSuggestionResponse: - description: The GetSuggestionResponse message. - properties: - suggestion: + approval: oneOf: - - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + - $ref: '#/components/schemas/c1.api.policy.v1.Approval' - type: "null" - title: Get Suggestion Response - type: object - x-speakeasy-name-override: GetSuggestionResponse - c1.api.role_mining_management.v1.ListCustomAnalysisResultsResponse: - description: The ListCustomAnalysisResultsResponse message. + form: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Form' + - type: "null" + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Provision' + - type: "null" + reject: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Reject' + - type: "null" + wait: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Wait' + - type: "null" + title: Policy Step + type: object + x-speakeasy-name-override: PolicyStep + c1.api.policy.v1.PolicyStepInstance: + description: | + The policy step instance includes a reference to an instance of a policy step that tracks state and has a unique ID. + + This message contains a oneof named instance. Only a single field of the following list may be set at a time: + - approval + - provision + - accept + - reject + - wait + - form + - action properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CustomAnalysisResultView' - type: - - array - - "null" - nextPageToken: - description: The nextPageToken field. + accept: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AcceptInstance' + - type: "null" + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + approval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' + - type: "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.FormInstance' + - type: "null" + id: + description: The ID of the PolicyStepInstance. This is required by many action submission endpoints to indicate what step you're approving. + readOnly: true type: string - title: List Custom Analysis Results Response + policyGenerationId: + description: The policy generation id refers to the version of the policy that this step was created from. + type: string + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionInstance' + - type: "null" + reject: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RejectInstance' + - type: "null" + state: + description: The state of the step, which is either active or done. + enum: + - POLICY_STEP_STATE_UNSPECIFIED + - POLICY_STEP_STATE_ACTIVE + - POLICY_STEP_STATE_DONE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + wait: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance' + - type: "null" + title: Policy Step Instance type: object - x-speakeasy-name-override: ListCustomAnalysisResultsResponse - c1.api.role_mining_management.v1.ListRunsResponse: - description: The ListRunsResponse message. + x-speakeasy-name-override: PolicyStepInstance + c1.api.policy.v1.PolicySteps: + description: A named sequence of steps that execute in order within a policy. properties: - list: - description: The list of role mining analysis runs. + steps: + description: |- + Ordered array of steps. Each step is a oneof -- exactly one step type is + set per entry. Steps execute sequentially. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' type: - array - "null" - nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. - type: string - title: List Runs Response + title: Policy Steps type: object - x-speakeasy-name-override: ListRunsResponse - c1.api.role_mining_management.v1.ListSuggestionsResponse: - description: The ListSuggestionsResponse message. + x-speakeasy-name-override: PolicySteps + c1.api.policy.v1.Provision: + description: The provision step references a provision policy for this step. properties: - list: - description: The list of role mining suggestions. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - type: - - array - - "null" - nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. + assigned: + description: A field indicating whether this step is assigned. + type: boolean + provisionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + - type: "null" + provisionTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionTarget' + - type: "null" + title: Provision + type: object + x-speakeasy-name-override: Provision + c1.api.policy.v1.ProvisionInstance: + description: | + A provision instance describes the specific configuration of an executing provision policy step including actions taken and notification id. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - completed + - cancelled + - errored + - reassignedByError + - skipped + properties: + batonActionInvocationId: + description: This indicates the account lifecycle action id for this step. type: string - title: List Suggestions Response + cancelled: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.CancelledAction' + - type: "null" + completed: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.CompletedAction' + - type: "null" + errored: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ErroredAction' + - type: "null" + externalTicketId: + description: This indicates the external ticket id for this step. + type: string + externalTicketProvisionerConfigId: + description: This indicates the external ticket provisioner config id for this step. + type: string + notificationId: + description: This indicates the notification id for this step. + type: string + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Provision' + - type: "null" + reassignedByError: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: This property indicates the current state of this step. + enum: + - PROVISION_INSTANCE_STATE_UNSPECIFIED + - PROVISION_INSTANCE_STATE_INIT + - PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET + - PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS + - PROVISION_INSTANCE_STATE_WAITING + - PROVISION_INSTANCE_STATE_WEBHOOK + - PROVISION_INSTANCE_STATE_WEBHOOK_WAITING + - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET + - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING + - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS + - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING + - PROVISION_INSTANCE_STATE_DEVICE_PLACEMENT + - PROVISION_INSTANCE_STATE_DONE + type: string + x-speakeasy-unknown-values: allow + waitingOn: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionWaitingOn' + - type: "null" + webhookId: + description: This indicates the webhook id for this step. + type: string + webhookInstanceId: + description: This indicates the webhook instance id for this step. + type: string + title: Provision Instance type: object - x-speakeasy-name-override: ListSuggestionsResponse - c1.api.role_mining_management.v1.RoleMiningManagementConfig: - description: The RoleMiningManagementConfig message. + x-speakeasy-name-override: ProvisionInstance + c1.api.policy.v1.ProvisionPolicy: + description: | + ProvisionPolicy is a oneOf that indicates how a provision step should be processed. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - connector + - manual + - delegated + - webhook + - multiStep + - externalTicket + - unconfigured + - action + - devicePlacement properties: - cohortHints: - description: Configured cohort hints that guide which user attributes the analysis prioritizes. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintView' + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionProvision' + - type: "null" + connector: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision' + - type: "null" + delegated: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.DelegatedProvision' + - type: "null" + devicePlacement: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.DevicePlacementProvision' + - type: "null" + externalTicket: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExternalTicketProvision' + - type: "null" + manual: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManualProvision' + - type: "null" + multiStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.MultiStep' + - type: "null" + unconfigured: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UnconfiguredProvision' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WebhookProvision' + - type: "null" + title: Provision Policy + type: object + x-speakeasy-name-override: ProvisionPolicy + c1.api.policy.v1.ProvisionTarget: + description: ProvisionTarget indicates the specific app, app entitlement, and if known, the app user and grant duration of this provision step + properties: + appEntitlementId: + description: The app entitlement that should be provisioned. + type: string + appId: + description: The app in which the entitlement should be provisioned + type: string + appUserId: + description: The app user that should be provisioned. May be unset if the app user is unknown + type: string + grantDuration: + format: duration type: - - array + - string - "null" - maxSuggestions: - description: Maximum number of suggestions the analysis will produce per run. - format: int32 - type: integer - minCohortSize: - description: Minimum number of users a cohort must contain to generate a suggestion. - format: int32 - type: integer - title: Role Mining Management Config + title: Provision Target type: object - x-speakeasy-name-override: RoleMiningManagementConfig - c1.api.role_mining_management.v1.RoleMiningManagementRun: - description: The RoleMiningManagementRun message. + x-speakeasy-name-override: ProvisionTarget + c1.api.policy.v1.ProvisionWaitingOn: + description: | + Describes why a provision step is paused in the WAITING state. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - entitlementMerge + - devicePlacement properties: - cohortsAnalyzed: - description: Number of user cohorts evaluated during the analysis. - format: int32 - type: integer - completedAt: + devicePlacement: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitingForDevicePlacement' + - type: "null" + entitlementMerge: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitingForEntitlementMerge' + - type: "null" + fallbackAt: format: date-time type: - string - "null" - createdAt: + startedWaitingAt: format: date-time type: - string - "null" - errorMessage: - description: Error message if the run failed, empty on success. - type: string - id: - description: Unique identifier for this analysis run. - type: string - status: - description: Current execution status of this run (e.g., running, completed, failed). - enum: - - RUN_STATUS_UNSPECIFIED - - RUN_STATUS_RUNNING - - RUN_STATUS_COMPLETED - - RUN_STATUS_FAILED - type: string - x-speakeasy-unknown-values: allow - suggestionsGenerated: - description: Number of role suggestions produced by this run. - format: int32 - type: integer - totalUsers: - description: Total number of users evaluated during the analysis. - format: int32 - type: integer - triggerDetail: - description: Additional detail about the trigger, such as the user or schedule that initiated the run. - type: string - triggerType: - description: How this run was initiated (e.g., manual, scheduled). - enum: - - TRIGGER_TYPE_UNSPECIFIED - - TRIGGER_TYPE_MANUAL - - TRIGGER_TYPE_UPLIFT_COMPLETION - - TRIGGER_TYPE_SCHEDULED - - TRIGGER_TYPE_DIRECTORY_MERGE + title: Provision Waiting On + type: object + x-speakeasy-name-override: ProvisionWaitingOn + c1.api.policy.v1.ProvisionerAssignment: + description: | + ProvisionerAssignment defines how a provisioner is dynamically assigned. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + - appOwners + - group + - manager + - expression + - entitlementOwners + properties: + appOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerProvisioner' + - type: "null" + entitlementOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerProvisioner' + - type: "null" + expression: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionProvisioner' + - type: "null" + group: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.GroupProvisioner' + - type: "null" + manager: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManagerProvisioner' + - type: "null" + users: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UserProvisioner' + - type: "null" + title: Provisioner Assignment + type: object + x-speakeasy-name-override: ProvisionerAssignment + c1.api.policy.v1.ReassignedAction: + description: The ReassignedAction object describes the outcome of a policy step that has been reassigned. + properties: + newPolicyStepId: + description: The ID of the policy step that was created as a result of this reassignment. + readOnly: true type: string - x-speakeasy-unknown-values: allow - updatedAt: + reassignedAt: format: date-time + readOnly: true type: - string - "null" - title: Role Mining Management Run + userId: + description: The UserID of the person who reassigned this step. + readOnly: true + type: string + title: Reassigned Action type: object - x-speakeasy-name-override: RoleMiningManagementRun - c1.api.role_mining_management.v1.RoleMiningManagementSuggestion: - description: The RoleMiningManagementSuggestion message. + x-speakeasy-name-override: ReassignedAction + c1.api.policy.v1.ReassignedByErrorAction: + description: The ReassignedByErrorAction object describes the outcome of a policy step that has been reassigned because it had an error provisioning. properties: - avgCoverage: - description: Average fraction of suggested entitlements held by each user in the cohort. - type: number - cohortFilters: - description: The profile filters that define which users belong to this cohort. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + description: + description: The description of the error with more details on why this was reassigned. + readOnly: true + type: string + errorCode: + description: Additional information about the error, like http status codes or error messages from SDKs. + readOnly: true + type: string + errorUserId: + description: The UserID of the user who reassigned this due to an error. This will exclusively be the System's UserID. + readOnly: true + type: string + erroredAt: + format: date-time + readOnly: true type: - - array + - string - "null" - cohortSize: - description: Total number of users in the cohort matching the profile filters. - format: int32 - type: integer - confidence: - description: Overall confidence score for this suggestion, from 0.0 to 1.0. - type: number - createdAt: + newPolicyStepId: + description: The ID of the policy step that was created by this reassignment. + readOnly: true + type: string + reassignedAt: format: date-time + readOnly: true type: - string - "null" - createdCatalogId: - description: The ID of the access profile created when this suggestion was accepted, empty if not yet accepted. + title: Reassigned By Error Action + type: object + x-speakeasy-name-override: ReassignedByErrorAction + c1.api.policy.v1.Reject: + description: This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + properties: + rejectMessage: + description: An optional message to include in the comments when a task is automatically rejected. type: string - description: - description: A human-readable description of the proposed role and the cohort it serves. + title: Reject + type: object + x-speakeasy-name-override: Reject + c1.api.policy.v1.RejectInstance: + description: |- + This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + The instance is just a marker for it being copied into an active policy. + properties: + rejectMessage: + description: An optional message to include in the comments when a task is automatically rejected. type: string - dimensionCount: - description: Number of distinct attribute dimensions used to define the cohort. - format: int32 - type: integer - entitlements: - description: The entitlements that are commonly held by users in this cohort. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - type: - - array - - "null" - existingProfileMatches: - description: Existing access profiles that overlap with this suggestion. + title: Reject Instance + type: object + x-speakeasy-name-override: RejectInstance + c1.api.policy.v1.ResourceOwnerApproval: + description: The resource owner approval allows configuration of the approval step when the target approvers are the resource owners. + properties: + allowSelfApproval: + description: Configuration to allow self approval if the target user is an resource owner during this step. + type: boolean + fallback: + description: Configuration to allow a fallback if the resource owner cannot be identified. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the resource owner cannot be identified. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AccessProfileMatch' + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - array - "null" - id: - description: Unique identifier for this suggestion. - type: string - insights: - description: Human-readable insights explaining why this role was suggested. + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the resource owner cannot be identified. items: type: string type: - array - "null" - lastGeneratedAt: - format: date-time - type: - - string - - "null" - runId: - description: The ID of the analysis run that produced this suggestion. - type: string - suggestedName: - description: The suggested display name for the proposed role. - type: string - suggestionState: - description: Current workflow state of this suggestion (e.g., pending, accepted, dismissed). - enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: Resource Owner Approval + type: object + x-speakeasy-name-override: ResourceOwnerApproval + c1.api.policy.v1.RestartAction: + description: The restart action describes the outcome of policy steps for when the task was restarted. This can be applied to multiple steps since restart skips all pending next steps. + properties: + oldPolicyStepId: + description: The step ID that was restarted. Potentially multiple "history" steps will reference this ID to indicate by what step they were restarted. + readOnly: true type: string - x-speakeasy-unknown-values: allow - updatedAt: + restartedAt: format: date-time + readOnly: true type: - string - "null" - usersWithAll: - description: Number of users in the cohort that hold all of the suggested entitlements. - format: int32 - type: integer - title: Role Mining Management Suggestion + userId: + description: The user that submitted the restart action. + readOnly: true + type: string + title: Restart Action type: object - x-speakeasy-name-override: RoleMiningManagementSuggestion - c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest: - description: The RoleMiningSearchSuggestionsRequest message. + x-speakeasy-name-override: RestartAction + c1.api.policy.v1.Rule: + description: | + A conditional routing rule that maps a CEL expression to an outcome. + Rules are evaluated top-to-bottom; the first matching rule's outcome + determines which steps run. If the outcome is policy_key, the step sequence + of that key in this policy's policy_steps map is used. If the outcome is + policy_id, the referenced policy is evaluated recursively (depth-bounded, + cycle-free, same policy_type). If no rule matches, the baseline entry of + policy_steps is used. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - stepKey + - policyId properties: - cohortTypes: - description: Filter by cohort type (e.g. "department", "job_title", "manager"). - items: - type: string + condition: + description: |- + A CEL expression that is evaluated against the request context. If it + returns true, the step sequence identified by the outcome is used. + type: string + policyId: + description: |- + The ID of another Policy that is evaluated recursively when this + rule matches. The referenced policy must share this policy's + policy_type, must not introduce a cycle, and must not push any + reachable chain over depth 5. Gated by the + POLICY_REFERENCES_POLICY feature flag. + This field is part of the `outcome` oneof. + See the documentation for `c1.api.policy.v1.Rule` for more details. type: - - array + - string - "null" - matchTypes: - description: Filter by match type against existing access profiles. + policyKey: + deprecated: true + description: |- + Deprecated: prefer outcome.step_key. Still read by the request path + for backward compatibility with rules persisted before the outcome + oneof existed. + type: string + x-sunset: "2027-05-30" + stepKey: + description: |- + A key into the policy's policy_steps map identifying which step + sequence to execute when this rule's condition matches. + This field is part of the `outcome` oneof. + See the documentation for `c1.api.policy.v1.Rule` for more details. + type: + - string + - "null" + title: Rule + type: object + x-speakeasy-name-override: Rule + c1.api.policy.v1.SearchPoliciesRequest: + description: Search Policies by a few properties. + properties: + displayName: + description: Search for policies with a case insensitive match on the display name. + type: string + excludePolicyIds: + description: The policy IDs to exclude from the search. items: - enum: - - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED - - ACCESS_PROFILE_MATCH_TYPE_EXACT - - ACCESS_PROFILE_MATCH_TYPE_SUPERSET - - ACCESS_PROFILE_MATCH_TYPE_PARTIAL type: string - x-speakeasy-unknown-values: allow type: - array - "null" + includeDeleted: + description: The includeDeleted field. + type: boolean pageSize: - description: Maximum number of suggestions to return per page. + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 type: integer pageToken: - description: Pagination token from a previous response. - type: string - query: - description: Text search — matches against suggested_name, description, and cohort filter values. + description: The pageToken field. type: string - states: - description: Filter by suggestion state. + policyTypes: + description: The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. items: enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION type: string x-speakeasy-unknown-values: allow type: - array - "null" - title: Role Mining Search Suggestions Request + query: + description: Query the policies with a fuzzy search on display name and description. + type: string + refs: + description: The refs field. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' + type: + - array + - "null" + scopeAppEntitlementId: + description: |- + When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped + to this entitlement. + type: string + scopeAppId: + description: |- + When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped + to this app. + type: string + scopeObjectType: + description: |- + When scope_view is POLICY_SCOPE_VIEW_SCOPED, narrow local policies to a + coarse object type (app-local vs entitlement-local). + enum: + - POLICY_SCOPE_OBJECT_TYPE_UNSPECIFIED + - POLICY_SCOPE_OBJECT_TYPE_APP + - POLICY_SCOPE_OBJECT_TYPE_ENTITLEMENT + type: string + x-speakeasy-unknown-values: allow + scopeSlot: + description: |- + When scope_view narrows to one object, only return that object's local + policies in this slot. Ignored when no object is identified by + scope_app_id, which lists every local policy regardless of slot. + enum: + - POLICY_SCOPE_SLOT_UNSPECIFIED + - POLICY_SCOPE_SLOT_EMERGENCY + type: string + x-speakeasy-unknown-values: allow + scopeView: + description: |- + Which policies to return based on scope. Defaults to global-only, so + app/entitlement-scoped policies never appear unless explicitly requested. + Ignored when refs are provided (explicit ID lookups always resolve). + enum: + - POLICY_SCOPE_VIEW_UNSPECIFIED + - POLICY_SCOPE_VIEW_GLOBAL + - POLICY_SCOPE_VIEW_SCOPED + - POLICY_SCOPE_VIEW_ALL + - POLICY_SCOPE_VIEW_GLOBAL_AND_OBJECT + type: string + x-speakeasy-unknown-values: allow + title: Search Policies Request type: object - x-speakeasy-name-override: RoleMiningSearchSuggestionsRequest - c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse: - description: The RoleMiningSearchSuggestionsResponse message. + x-speakeasy-name-override: SearchPoliciesRequest + c1.api.policy.v1.SearchPoliciesResponse: + description: The SearchPoliciesResponse message. properties: list: - description: The list of matching role mining suggestions. + description: The list field. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + $ref: '#/components/schemas/c1.api.policy.v1.Policy' type: - array - "null" nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. + description: The nextPageToken field. type: string - title: Role Mining Search Suggestions Response + title: Search Policies Response type: object - x-speakeasy-name-override: RoleMiningSearchSuggestionsResponse - c1.api.role_mining_management.v1.SearchCohortUsersRequestInput: - description: The SearchCohortUsersRequest message. + x-speakeasy-name-override: SearchPoliciesResponse + c1.api.policy.v1.SelfApproval: + description: The self approval object describes the configuration of a policy step that needs to be approved by the target of the request. properties: - pageSize: - description: Maximum number of users to return per page. - format: int32 - type: integer - pageToken: - description: Pagination token from a previous response. - type: string - profileFilters: - description: Additional profile filters to narrow the cohort user search. + assignedUserIds: + description: The array of users determined to be themselves during approval. This should only ever be one person, but is saved because it may change if the owner of an app user changes while the ticket is open. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: string + readOnly: true type: - array - "null" - selectedEntitlements: - description: Optional list of entitlements to compute per-user coverage for. + fallback: + description: Configuration to allow a fallback if the identity user of the target app user cannot be determined. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.EntitlementRef' + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' type: - array - "null" - title: Search Cohort Users Request - type: object - x-speakeasy-name-override: SearchCohortUsersRequest - c1.api.role_mining_management.v1.SearchCohortUsersResponse: - description: The SearchCohortUsersResponse message. - properties: - list: - description: The list of users matching the cohort and optional filters. + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. items: - $ref: '#/components/schemas/c1.api.user.v1.User' + type: string type: - array - "null" - nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + title: Self Approval + type: object + x-speakeasy-name-override: SelfApproval + c1.api.policy.v1.SkippedAction: + description: The SkippedAction object describes the outcome of a policy step that has been skipped. + properties: + newPolicyStepId: + description: The ID of the policy step that was created as a result of this skipping. + readOnly: true type: string - usersWithCoverage: - description: Per-user coverage counts, populated when selected_entitlements is non-empty. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortUserWithCoverage' + skippedAt: + format: date-time + readOnly: true type: - - array + - string - "null" - title: Search Cohort Users Response - type: object - x-speakeasy-name-override: SearchCohortUsersResponse - c1.api.role_mining_management.v1.TriggerAnalysisRequest: - description: The TriggerAnalysisRequest message. - title: Trigger Analysis Request - type: object - x-speakeasy-name-override: TriggerAnalysisRequest - c1.api.role_mining_management.v1.TriggerAnalysisResponse: - description: The TriggerAnalysisResponse message. - properties: - runId: - description: The ID of the newly created analysis run. + userId: + description: The UserID of the user who skipped this step. + readOnly: true type: string - title: Trigger Analysis Response + title: Skipped Action type: object - x-speakeasy-name-override: TriggerAnalysisResponse - c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest: - description: The TriggerCustomAnalysisRequest message. + x-speakeasy-name-override: SkippedAction + c1.api.policy.v1.TestAccountProvisionPolicyRequest: + description: TestAccountProvisionPolicyRequest is the request for testing an account provision policy. properties: - profileFilters: - description: The profileFilters field. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - type: - - array - - "null" - title: Trigger Custom Analysis Request + cel: + description: The CEL expression to evaluate for the account provision policy. + type: string + title: Test Account Provision Policy Request type: object - x-speakeasy-name-override: TriggerCustomAnalysisRequest - c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse: - description: The TriggerCustomAnalysisResponse message. + x-speakeasy-name-override: TestAccountProvisionPolicyRequest + c1.api.policy.v1.TestAccountProvisionPolicyResponse: + description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. properties: - id: - description: The id field. + type: + description: The data type of the computed result value. type: string - title: Trigger Custom Analysis Response + value: + description: The computed result value of the CEL expression evaluation. + type: string + title: Test Account Provision Policy Response type: object - x-speakeasy-name-override: TriggerCustomAnalysisResponse - c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest: - description: The UpdateRoleMiningConfigRequest message. + x-speakeasy-name-override: TestAccountProvisionPolicyResponse + c1.api.policy.v1.UnconfiguredProvision: + description: The UnconfiguredProvision message. + title: Unconfigured Provision + type: object + x-speakeasy-name-override: UnconfiguredProvision + c1.api.policy.v1.UpdatePolicyRequestInput: + description: The UpdatePolicyRequest message contains the policy object to update and a field mask to indicate which fields to update. It uses URL value for input. properties: - cohortHints: - description: Hints that guide the analysis to prioritize specific user attributes and values when forming cohorts. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintInput' + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + updateMask: type: - - array + - string - "null" - maxSuggestions: - description: Maximum number of suggestions the analysis should produce per run. - format: int32 - type: integer - minCohortSize: - description: Minimum number of users a cohort must contain to generate a suggestion. - format: int32 - type: integer - title: Update Role Mining Config Request + title: Update Policy Request type: object - x-speakeasy-name-override: UpdateRoleMiningConfigRequest - c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse: - description: The UpdateRoleMiningConfigResponse message. + x-speakeasy-name-override: UpdatePolicyRequest + c1.api.policy.v1.UpdatePolicyResponse: + description: The UpdatePolicyResponse message contains the updated policy object. properties: - config: + policy: oneOf: - - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - type: "null" - title: Update Role Mining Config Response + title: Update Policy Response type: object - x-speakeasy-name-override: UpdateRoleMiningConfigResponse - c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput: - description: The UpdateSuggestionStateRequest message. + x-speakeasy-name-override: UpdatePolicyResponse + c1.api.policy.v1.UserApproval: + description: The user approval object describes the approval configuration of a policy step that needs to be approved by a specific list of users. properties: - createdCatalogId: - description: The ID of the access profile created from this suggestion, set when accepting. - type: string - state: - description: The new state to transition the suggestion to. - enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED - type: string - x-speakeasy-unknown-values: allow - title: Update Suggestion State Request + allowSelfApproval: + description: Configuration to allow self approval of if the user is specified and also the target of the ticket. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + userIds: + description: Array of users configured for approval. + items: + type: string + type: + - array + - "null" + title: User Approval type: object - x-speakeasy-name-override: UpdateSuggestionStateRequest - c1.api.role_mining_management.v1.UpdateSuggestionStateResponse: - description: The UpdateSuggestionStateResponse message. + x-speakeasy-name-override: UserApproval + c1.api.policy.v1.UserProvisioner: + description: UserProvisioner assigns specific users as provisioners. properties: - suggestion: - oneOf: - - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - - type: "null" - title: Update Suggestion State Response + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + userIds: + description: The user IDs to assign as provisioners. + items: + type: string + type: + - array + - "null" + title: User Provisioner type: object - x-speakeasy-name-override: UpdateSuggestionStateResponse - c1.api.search.v1.FacetCategory: + x-speakeasy-name-override: UserProvisioner + c1.api.policy.v1.Wait: description: | - The FacetCategory indicates a grouping of facets by type. For example, facets "OnePassword" and "Okta" would group under an "Apps" category. + Define a Wait step for a policy to wait on a condition to be met. - This message contains a oneof named item. Only a single field of the following list may be set at a time: - - value - - range + This message contains a oneof named until. Only a single field of the following list may be set at a time: + - condition + - duration + - untilTime properties: - displayName: - description: The display name of the category. - type: string - iconUrl: - description: An icon for the category. + commentOnFirstWait: + description: The comment to post on first failed check. type: string - param: - description: The param that is being set when checking a facet in this category. + commentOnTimeout: + description: The comment to post if we timeout. type: string - range: + condition: oneOf: - - $ref: '#/components/schemas/c1.api.search.v1.FacetRangeItem' + - $ref: '#/components/schemas/c1.api.policy.v1.WaitCondition' - type: "null" - value: + duration: oneOf: - - $ref: '#/components/schemas/c1.api.search.v1.FacetValueItem' + - $ref: '#/components/schemas/c1.api.policy.v1.WaitDuration' - type: "null" - title: Facet Category - type: object - x-speakeasy-name-override: FacetCategory - c1.api.search.v1.FacetRange: - description: The FacetRange message. - properties: - count: - description: The count of items in the range. - format: int64 - type: string - displayName: - description: The display name of the range. - type: string - from: - description: The starting value of the range. - format: int64 - type: string - iconUrl: - description: The icon of the range. - type: string - to: - description: The ending value of the range. - format: int64 + name: + description: The name of our condition to show on the task details page type: string - title: Facet Range - type: object - x-speakeasy-name-override: FacetRange - c1.api.search.v1.FacetRangeItem: - description: The FacetRangeItem message. - properties: - ranges: - description: An array of facet ranges. - items: - $ref: '#/components/schemas/c1.api.search.v1.FacetRange' + timeoutDuration: + format: duration type: - - array + - string - "null" - title: Facet Range Item + untilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTime' + - type: "null" + title: Wait type: object - x-speakeasy-name-override: FacetRangeItem - c1.api.search.v1.FacetValue: - description: A FacetValue message contains count and value of the facet entry. + x-speakeasy-name-override: Wait + c1.api.policy.v1.WaitCondition: + description: The WaitCondition message. properties: - count: - description: The count of the values in this facet. - format: int64 - type: string - displayName: - description: The name of this facet. - type: string - iconUrl: - description: The icon for this facet. + condition: + description: The condition that has to be true for this wait condition to continue. type: string - value: - description: The value of this facet. + title: Wait Condition + type: object + x-speakeasy-name-override: WaitCondition + c1.api.policy.v1.WaitConditionInstance: + description: Used by the policy engine to describe an instantiated condition to wait on. + properties: + condition: + description: The condition that has to be true for this wait condition instance to continue. type: string - title: Facet Value + title: Wait Condition Instance type: object - x-speakeasy-name-override: FacetValue - c1.api.search.v1.FacetValueItem: - description: The FacetValueItem message. + x-speakeasy-name-override: WaitConditionInstance + c1.api.policy.v1.WaitDuration: + description: The WaitDuration message. properties: - values: - description: An array of facet values. - items: - $ref: '#/components/schemas/c1.api.search.v1.FacetValue' + duration: + format: duration type: - - array + - string - "null" - title: Facet Value Item + title: Wait Duration type: object - x-speakeasy-name-override: FacetValueItem - c1.api.search.v1.Facets: - description: Indicates one value of a facet. + x-speakeasy-name-override: WaitDuration + c1.api.policy.v1.WaitInstance: + description: | + Used by the policy engine to describe an instantiated wait step. + + This message contains a oneof named until. Only a single field of the following list may be set at a time: + - condition + - untilTime + + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - succeeded + - timedOut + - skipped properties: - count: - description: The count of items in this facet. - format: int64 + commentOnFirstWait: + description: The comment to post on first failed check. type: string - facets: - description: The facet being referenced. - items: - $ref: '#/components/schemas/c1.api.search.v1.FacetCategory' - type: - - array + commentOnTimeout: + description: The comment to post if we timeout. + type: string + condition: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitConditionInstance' + - type: "null" + name: + description: The name field. + type: string + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + startedWaitingAt: + format: date-time + type: + - string - "null" - title: Facets - type: object - x-speakeasy-name-override: Facets - c1.api.secrets.v1.PaperSecret: - description: |- - PaperSecret is the API view of a secret (combines Vault + PaperVault fields). - The vault_id is the primary identifier (Vault.id). - properties: - ageSuite: - description: Exact Age suite used by the stored ciphertext. + state: + description: The state field. enum: - - AGE_SUITE_UNSPECIFIED - - AGE_SUITE_X25519 - - AGE_SUITE_MLKEM768X25519 + - WAIT_INSTANCE_STATE_UNSPECIFIED + - WAIT_INSTANCE_STATE_WAITING + - WAIT_INSTANCE_STATE_COMPLETED + - WAIT_INSTANCE_STATE_TIMED_OUT type: string x-speakeasy-unknown-values: allow - allowedEmails: - description: The allowedEmails field. - items: - type: string + succeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionSucceeded' + - type: "null" + timedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionTimedOut' + - type: "null" + timeout: + format: date-time type: - - array + - string - "null" - allowedUserIds: - description: Access control - items: - type: string + timeoutDuration: + format: duration type: - - array + - string - "null" - contentDeleted: - description: The contentDeleted field. - type: boolean - contentExpiresAt: + untilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTimeInstance' + - type: "null" + title: Wait Instance + type: object + x-speakeasy-name-override: WaitInstance + c1.api.policy.v1.WaitInstance.ConditionSucceeded: + description: The ConditionSucceeded message. + properties: + succeededAt: format: date-time type: - string - "null" - contentReady: - description: Whether content has been set (text uploaded or file uploaded) - type: boolean - contentType: - description: The contentType field. - type: string - createdAt: + title: Condition Succeeded + type: object + x-speakeasy-name-override: ConditionSucceeded + c1.api.policy.v1.WaitInstance.ConditionTimedOut: + description: The ConditionTimedOut message. + properties: + timedOutAt: format: date-time - readOnly: true type: - string - "null" - creatorUserId: - description: Creator - type: string - currentViews: - description: The currentViews field. + title: Condition Timed Out + type: object + x-speakeasy-name-override: ConditionTimedOut + c1.api.policy.v1.WaitUntilTime: + description: Waits until a specific time of the day (UTC) + properties: + hours: + description: The hours field. format: uint32 type: integer - deletedAt: + minutes: + description: The minutes field. + format: uint32 + type: integer + timezone: + description: The timezone field. + type: string + title: Wait Until Time + type: object + x-speakeasy-name-override: WaitUntilTime + c1.api.policy.v1.WaitUntilTimeInstance: + description: The WaitUntilTimeInstance message. + properties: + durationIfExists: + format: duration + type: + - string + - "null" + untilTime: format: date-time - readOnly: true type: - string - "null" - displayName: - description: From Vault + title: Wait Until Time Instance + type: object + x-speakeasy-name-override: WaitUntilTimeInstance + c1.api.policy.v1.WaitingForDevicePlacement: + description: Describes a provision step that is paused until the recipient joins the vault's MLS group. + properties: + recipientUserId: + description: The ID of the user being placed. type: string - fileSize: - description: File metadata - format: int64 + vaultBoundaryId: + description: The ID of the vault boundary the recipient is being placed in. type: string - filename: - description: 'For FILE secrets: original filename (sanitized)' + title: Waiting For Device Placement + type: object + x-speakeasy-name-override: WaitingForDevicePlacement + c1.api.policy.v1.WaitingForEntitlementMerge: + description: Describes a provision step that is paused until the target entitlement, created ahead of connector sync with a Baton match ID, is merged with its connector-synced counterpart. + properties: + appEntitlementId: + description: The ID of the entitlement being waited on. type: string - inputFormat: - description: The inputFormat field. - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE + appId: + description: The ID of the app the awaited entitlement belongs to. type: string - x-speakeasy-unknown-values: allow - maxViews: - description: View tracking - format: uint32 - type: integer - secretType: - description: The secretType field. - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE + title: Waiting For Entitlement Merge + type: object + x-speakeasy-name-override: WaitingForEntitlementMerge + c1.api.policy.v1.WebhookApproval: + description: The WebhookApproval message. + properties: + webhookId: + description: The ID of the webhook to call for approval. type: string - x-speakeasy-unknown-values: allow - shareCode: - description: Human-friendly share code (XXXX-XXXX-XXXX) for shareable URLs + title: Webhook Approval + type: object + x-speakeasy-name-override: WebhookApproval + c1.api.policy.v1.WebhookProvision: + description: This provision step indicates that a webhook should be called to provision this entitlement. + properties: + webhookId: + description: The ID of the webhook to call for provisioning. type: string - shareUrl: - description: URL to share with recipients (populated when content_ready is true) + title: Webhook Provision + type: object + x-speakeasy-name-override: WebhookProvision + c1.api.profiletype.v1.ProfileType: + description: ProfileType represents a type of profile in the system + properties: + description: + description: The description field. type: string - sharingMode: - description: From PaperVault - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL + displayToUser: + description: Whether to display this profile type to users in profile page. Defaults to false if not set + type: boolean + iconUrl: + description: The iconUrl field. type: string - x-speakeasy-unknown-values: allow - status: - description: Computed status - enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED + id: + description: The id field. type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true + name: + description: The name field. + type: string + priority: + description: The priority field. + format: uint32 + type: integer + sizes: + description: icon sizes + items: + format: int32 + type: integer type: - - string + - array - "null" - vaultId: - description: Vault.id - primary identifier for the secret + slug: + description: Add this field to allow users to reference profile type in cel expressions type: string - title: Paper Secret - type: object - x-speakeasy-name-override: PaperSecret - c1.api.secrets.v1.PaperSecretAdminServiceGetResponse: - description: The PaperSecretAdminServiceGetResponse message. - properties: - secret: - oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - - type: "null" - title: Paper Secret Admin Service Get Response - type: object - x-speakeasy-name-override: PaperSecretAdminServiceGetResponse - c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput: - description: The PaperSecretAdminServiceRevokeRequest message. - title: Paper Secret Admin Service Revoke Request + title: Profile Type type: object - x-speakeasy-name-override: PaperSecretAdminServiceRevokeRequest - c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse: - description: The PaperSecretAdminServiceRevokeResponse message. + x-speakeasy-name-override: ProfileType + c1.api.reporting.v1.ProgramRef: + description: ProgramRef points at a pinned, executable program. properties: - secret: - oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - - type: "null" - title: Paper Secret Admin Service Revoke Response + commitId: + description: |- + Code mode invokes by explicit commit, so the commit — not the function — is + what a refresh re-executes. + type: string + functionId: + description: |- + A saved report owns its Function, so this is per-report rather than the + shared code-mode scratch function the program first ran on. + type: string + plannedFromPrompt: + description: |- + The prompt this program was planned from. Report.prompt is editable and a + refresh never re-plans, so this is the only way to detect that a report's + question has drifted from the program answering it. + type: string + title: Program Ref type: object - x-speakeasy-name-override: PaperSecretAdminServiceRevokeResponse - c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest: - description: The PaperSecretAdminServiceSearchAuditEventsRequest message. + x-speakeasy-name-override: ProgramRef + c1.api.reporting.v1.Report: + description: |- + Report is a saved report: the question, the program that answers it, and the + parameters a re-run may vary. properties: - actorEmail: - description: Filter by external email (partial match via full-text search) + createdAt: + format: date-time + type: + - string + - "null" + createdByUserId: + description: The createdByUserId field. type: string - actorUserId: - description: Filter by C1 user ID (internal users) + deletedAt: + format: date-time + type: + - string + - "null" + displayName: + description: The displayName field. type: string - clientIp: - description: Filter by client IP (exact match) + id: + description: The id field. type: string - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. + latestRunId: + description: |- + Separate pointers: the last attempt may have failed while callers still need + the last renderable result. type: string - vaultId: - description: Filter by specific vault + latestSuccessfulRunId: + description: The latestSuccessfulRunId field. type: string - title: Paper Secret Admin Service Search Audit Events Request - type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsRequest - c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse: - description: The PaperSecretAdminServiceSearchAuditEventsResponse message. - properties: - list: - description: |- - List contains OCSF events directly as JSON structs. - Follows the same pattern as SystemLogServiceListEventsResponse. - items: - additionalProperties: true - type: object + parameterSchema: + additionalProperties: true type: - - array + - object - "null" - nextPageToken: - description: The nextPageToken field. + parameterValues: + additionalProperties: true + type: + - object + - "null" + program: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.ProgramRef' + - type: "null" + prompt: + description: The editable natural-language question. Only a re-plan reads this. type: string - title: Paper Secret Admin Service Search Audit Events Response + tenantId: + description: The tenantId field. + type: string + updatedAt: + format: date-time + type: + - string + - "null" + title: Report type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsResponse - c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest: - description: Admin search request - can filter by any user's secrets. + x-speakeasy-name-override: Report + c1.api.reporting.v1.ReportRun: + description: ReportRun is one execution of a Report's program. Write-once. properties: - createdAfter: + artifactUrl: + description: The artifactUrl field. + type: string + conversationId: + description: |- + Where the output came from, kept for provenance rather than to read it back: + the surface itself is in surface_snapshot. Both are required to address a + surface, and a headless refresh has neither. + type: string + createdAt: format: date-time type: - string - "null" - createdBefore: + deletedAt: format: date-time type: - string - "null" - creatorUserIds: - description: Filter by creator user ID (admin can see all users' secrets) - items: - type: string + error: + description: The error field. + type: string + expiresAt: + format: date-time type: - - array + - string - "null" - includeDeleted: - description: Include deleted secrets - type: boolean - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. + id: + description: KSUID, so runs sort by time. type: string - query: - description: Fuzzy search by display name + invocationId: + description: |- + Not a live join: the originating code-mode invocation is archived at the + code-mode retention cutoff. type: string - secretType: - description: Filter by secret type (optional) - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE + lineage: + additionalProperties: true + type: + - object + - "null" + parameterValues: + additionalProperties: true + type: + - object + - "null" + program: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.ProgramRef' + - type: "null" + reportId: + description: The reportId field. type: string - x-speakeasy-unknown-values: allow - sharingMode: - description: Filter by sharing mode (optional) - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL + runByUserId: + description: |- + Copied from the invocation's user_id, which is archived at the code-mode + retention cutoff. Not Report.created_by_user_id — a refresh may execute as a + different principal than the report's owner. type: string - x-speakeasy-unknown-values: allow - sortBy: - description: Sort order + sources: + deprecated: true + description: |- + Never written: for a run saved out of a conversation, provenance is read back + through A2UIService.GetSurfaceProvenance, which reads the surface's own + components. A headless refresh has no conversation or surface to ask about, + and how such a run reports what it read is still open. + items: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportSource' + type: + - array + - "null" + status: + description: The status field. enum: - - SEARCH_SORT_BY_UNSPECIFIED - - SEARCH_SORT_BY_CREATED_DESC - - SEARCH_SORT_BY_CREATED_ASC - - SEARCH_SORT_BY_EXPIRES_ASC - - SEARCH_SORT_BY_NAME_ASC + - REPORT_RUN_STATUS_UNSPECIFIED + - REPORT_RUN_STATUS_PENDING + - REPORT_RUN_STATUS_SUCCEEDED + - REPORT_RUN_STATUS_FAILED + - REPORT_RUN_STATUS_STALE_PROGRAM type: string x-speakeasy-unknown-values: allow - statuses: - description: Filter by status (optional) + surfaceId: + description: The surfaceId field. + type: string + surfaceSnapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UISurface' + - type: "null" + tenantId: + description: The tenantId field. + type: string + updatedAt: + format: date-time + type: + - string + - "null" + vfsId: + description: The vfsId field. + type: string + title: Report Run + type: object + x-speakeasy-name-override: ReportRun + c1.api.reporting.v1.ReportSource: + deprecated: true + description: |- + ReportSource is one provenance entry: what a run read to produce its numbers. + + Retired: a run saved out of a conversation records the surface it came from, + and provenance is read back through A2UIService.GetSurfaceProvenance rather + than copied here. Kept because a published message may not be deleted. + properties: + count: + description: Rows contributing. + format: int64 + type: string + kind: + description: The kind field. + type: string + label: + description: The label field. + type: string + ref: + description: Tool + query fingerprint, or object type/id. + type: string + title: Report Source + type: object + x-speakeasy-name-override: ReportSource + c1.api.reporting.v1.ReportingServiceDeleteRequestInput: + description: The ReportingServiceDeleteRequest message. + title: Reporting Service Delete Request + type: object + x-speakeasy-name-override: ReportingServiceDeleteRequest + c1.api.reporting.v1.ReportingServiceDeleteResponse: + description: The ReportingServiceDeleteResponse message. + title: Reporting Service Delete Response + type: object + x-speakeasy-name-override: ReportingServiceDeleteResponse + c1.api.reporting.v1.ReportingServiceGetResponse: + description: The ReportingServiceGetResponse message. + properties: + latestRun: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.ReportRun' + - type: "null" + latestSuccessfulRun: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.ReportRun' + - type: "null" + promptDrifted: + description: |- + True when prompt no longer matches program.planned_from_prompt. A rerun + re-executes and never re-plans, so an edited question leaves the program + answering the old one. + type: boolean + report: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.Report' + - type: "null" + title: Reporting Service Get Response + type: object + x-speakeasy-name-override: ReportingServiceGetResponse + c1.api.reporting.v1.ReportingServiceGetRunProvenanceResponse: + description: The ReportingServiceGetRunProvenanceResponse message. + properties: + programCommitId: + description: The programCommitId field. + type: string + programFunctionId: + description: The programFunctionId field. + type: string + programInput: + description: |- + The parameters this run was bound to, as JSON. "{}" for a program that + takes none — a real answer, distinct from absent. + type: string + programSource: + description: The programSource field. + type: string + sources: + description: |- + What each part of the report shows, read off the run's own copy of the + surface rather than a live one. items: - enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceSource' type: - array - "null" - title: Paper Secret Admin Service Search Request + steps: + description: What the program looked at, derived from its source. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIProvenanceStep' + type: + - array + - "null" + stepsAvailable: + description: |- + False when the program's source could not be read, which is what makes an + empty steps list mean "unknown" rather than "it read nothing". + type: boolean + title: Reporting Service Get Run Provenance Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchRequest - c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse: - description: The PaperSecretAdminServiceSearchResponse message. + x-speakeasy-name-override: ReportingServiceGetRunProvenanceResponse + c1.api.reporting.v1.ReportingServiceListResponse: + description: The ReportingServiceListResponse message. properties: list: description: The list field. items: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + $ref: '#/components/schemas/c1.api.reporting.v1.Report' type: - array - "null" nextPageToken: description: The nextPageToken field. type: string - title: Paper Secret Admin Service Search Response + title: Reporting Service List Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchResponse - c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest: - description: The PaperSecretServiceCreateExternalRequest message. + x-speakeasy-name-override: ReportingServiceListResponse + c1.api.reporting.v1.ReportingServiceRunRequestInput: + description: The ReportingServiceRunRequest message. + title: Reporting Service Run Request + type: object + x-speakeasy-name-override: ReportingServiceRunRequest + c1.api.reporting.v1.ReportingServiceRunResponse: + description: The ReportingServiceRunResponse message. properties: - allowedEmails: + run: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.ReportRun' + - type: "null" + title: Reporting Service Run Response + type: object + x-speakeasy-name-override: ReportingServiceRunResponse + c1.api.reporting.v1.ReportingServiceSaveRequest: + description: The ReportingServiceSaveRequest message. + properties: + conversationId: description: |- - External email addresses allowed to view this secret (1 to 64). - Recipients authenticate via email magic link or Google OAuth. - items: - type: string - type: - - array - - "null" - contentType: - description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' + The conversation and surface are both required to address a rendered + surface; neither identifies one alone. type: string displayName: + description: The displayName field. + type: string + prompt: description: |- - Optional cleartext label visible to the creator in "My Secrets" view. - Not encrypted — do not put sensitive data here. + The question this surface answered. The surface records its program but not + the words behind it, so the caller supplies them; without it the report has + nothing to compare against when deciding its program has gone stale. type: string - expiresIn: - format: duration - type: - - string - - "null" - fileSize: - description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' - format: int64 - type: string - filename: - description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' - type: string - inputFormat: - description: |- - For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). - Used by the viewer UI for syntax highlighting. Does not affect encryption. - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - type: string - x-speakeasy-unknown-values: allow - maxViews: - description: Maximum number of views before the secret is burned (0 = unlimited). - format: uint32 - type: integer - requiredAgeSuite: - description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. - enum: - - AGE_SUITE_UNSPECIFIED - - AGE_SUITE_X25519 - - AGE_SUITE_MLKEM768X25519 - type: string - x-speakeasy-unknown-values: allow - secretType: - description: |- - Secret type: TEXT or FILE. - TEXT secrets use SetTextContent to upload encrypted content (max 64KB). - FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE + surfaceId: + description: The surfaceId field. type: string - x-speakeasy-unknown-values: allow - title: Paper Secret Service Create External Request + title: Reporting Service Save Request type: object - x-speakeasy-name-override: PaperSecretServiceCreateExternalRequest - c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest: - description: The PaperSecretServiceCreateInternalRequest message. + x-speakeasy-name-override: ReportingServiceSaveRequest + c1.api.reporting.v1.ReportingServiceSaveResponse: + description: The ReportingServiceSaveResponse message. + properties: + report: + oneOf: + - $ref: '#/components/schemas/c1.api.reporting.v1.Report' + - type: "null" + title: Reporting Service Save Response + type: object + x-speakeasy-name-override: ReportingServiceSaveResponse + c1.api.reporting.v1.ReportingServiceUpdateRequestInput: + description: |- + Both editable fields are optional; an empty one leaves the stored value alone. + At least one must be set. properties: - allowedUserIds: - description: C1 User IDs allowed to view this secret (1 to 128). - items: - type: string - type: - - array - - "null" - contentType: - description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' - type: string displayName: - description: |- - Optional cleartext label visible to the creator in "My Secrets" view. - Not encrypted — do not put sensitive data here. + description: The displayName field. type: string - expiresIn: - format: duration + parameterValues: + additionalProperties: true type: - - string + - object - "null" - fileSize: - description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' - format: int64 - type: string - filename: - description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' - type: string - inputFormat: - description: |- - For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). - Used by the viewer UI for syntax highlighting. Does not affect encryption. - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - type: string - x-speakeasy-unknown-values: allow - maxViews: - description: Maximum number of views before the secret is burned (0 = unlimited). - format: uint32 - type: integer - requiredAgeSuite: - description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. - enum: - - AGE_SUITE_UNSPECIFIED - - AGE_SUITE_X25519 - - AGE_SUITE_MLKEM768X25519 - type: string - x-speakeasy-unknown-values: allow - secretType: + prompt: description: |- - Secret type: TEXT or FILE. - TEXT secrets use SetTextContent to upload encrypted content (max 64KB). - FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE + Editing this does not re-plan, so it may drift from + program.planned_from_prompt — that drift is how a stale report is detected. type: string - x-speakeasy-unknown-values: allow - title: Paper Secret Service Create Internal Request + title: Reporting Service Update Request type: object - x-speakeasy-name-override: PaperSecretServiceCreateInternalRequest - c1.api.secrets.v1.PaperSecretServiceCreateResponse: - description: The PaperSecretServiceCreateResponse message. + x-speakeasy-name-override: ReportingServiceUpdateRequest + c1.api.reporting.v1.ReportingServiceUpdateResponse: + description: The ReportingServiceUpdateResponse message. properties: - ageRecipient: - description: |- - Canonical recipient public key for the exact age_suite returned below. - All content MUST be encrypted to this recipient using the Age encryption format - before calling SetTextContent or uploading to upload_url. - See: https://age-encryption.org - type: string - ageSuite: - description: Exact Age suite required for this submission. - enum: - - AGE_SUITE_UNSPECIFIED - - AGE_SUITE_X25519 - - AGE_SUITE_MLKEM768X25519 - type: string - x-speakeasy-unknown-values: allow - secret: + report: oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - $ref: '#/components/schemas/c1.api.reporting.v1.Report' - type: "null" - uploadUrl: - description: |- - For FILE secrets: capability URL for uploading the Age-encrypted file. - Send an HTTP PUT request with the Age-encrypted file bytes as the body - and Content-Type: application/octet-stream. The payload MUST begin with - the Age header "age-encryption.org/v1\n". Maximum file size: 1GB. - Empty for TEXT secrets. - type: string - vaultId: - description: Vault ID - primary identifier for this secret. - type: string - title: Paper Secret Service Create Response - type: object - x-speakeasy-name-override: PaperSecretServiceCreateResponse - c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput: - description: The PaperSecretServiceGetContentRequest message. - properties: - readerRecipient: - description: |- - Client's ephemeral Age recipient (age1...) for re-encryption - Server re-encrypts the content to this recipient - type: string - title: Paper Secret Service Get Content Request + title: Reporting Service Update Response type: object - x-speakeasy-name-override: PaperSecretServiceGetContentRequest - c1.api.secrets.v1.PaperSecretServiceGetContentResponse: - description: | - The PaperSecretServiceGetContentResponse message. - - This message contains a oneof named content. Only a single field of the following list may be set at a time: - - encryptedContent - - downloadUrl + x-speakeasy-name-override: ReportingServiceUpdateResponse + c1.api.request_schema.v1.RequestSchema: + description: A request schema defines a form template that users fill out when requesting access. properties: createdAt: format: date-time type: - string - "null" - creatorUserId: - description: The creatorUserId field. - type: string - downloadUrl: - description: |- - For file secrets: presigned S3 download URL (5 minute expiry) - File is still E2E encrypted - client must decrypt after download - This field is part of the `content` oneof. - See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. - type: - - string - - "null" - encryptedContent: - description: |- - For text secrets: Age-encrypted content (encrypted to reader's recipient) - This field is part of the `content` oneof. - See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. - format: base64 + deletedAt: + format: date-time type: - string - "null" - filename: - description: Original filename (file secrets only) - type: string - inputFormat: - description: Input format hint for rendering (text secrets only) - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + id: + description: The unique identifier of this request schema. type: string - x-speakeasy-unknown-values: allow - secretType: - description: Secret metadata + justificationVisibility: + description: Controls whether the justification field is shown or hidden on the request form. enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE + - JUSTIFICATION_VISIBILITY_UNSPECIFIED + - JUSTIFICATION_VISIBILITY_SHOW + - JUSTIFICATION_VISIBILITY_HIDE type: string x-speakeasy-unknown-values: allow - viewsRemaining: - description: Views remaining after this view (-1 = unlimited) - format: int32 - type: integer - title: Paper Secret Service Get Content Response + modifiedAt: + format: date-time + type: + - string + - "null" + title: Request Schema type: object - x-speakeasy-name-override: PaperSecretServiceGetContentResponse - c1.api.secrets.v1.PaperSecretServiceGetResponse: - description: The PaperSecretServiceGetResponse message. + x-speakeasy-name-override: RequestSchema + c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest: + description: The request message for creating a single entitlement binding on a request schema. properties: - secret: + entitlementRef: oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - type: "null" - title: Paper Secret Service Get Response - type: object - x-speakeasy-name-override: PaperSecretServiceGetResponse - c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput: - description: The PaperSecretServiceRevokeRequest message. - title: Paper Secret Service Revoke Request + requestSchemaId: + description: The unique identifier of the request schema to bind the entitlement to. + type: string + title: Request Schema Service Create Entitlement Binding Request type: object - x-speakeasy-name-override: PaperSecretServiceRevokeRequest - c1.api.secrets.v1.PaperSecretServiceRevokeResponse: - description: The PaperSecretServiceRevokeResponse message. + x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingRequest + c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse: + description: The response message for creating a single entitlement binding. properties: - secret: + entitlementRef: oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - type: "null" - title: Paper Secret Service Revoke Response - type: object - x-speakeasy-name-override: PaperSecretServiceRevokeResponse - c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest: - description: |- - PaperSecretServiceSearchAuditEventsRequest searches audit events for a secret - owned by the calling user. Only the secret creator may query events. Results - are sanitized to include only time, event type, and actor information. - properties: - pageSize: - description: Maximum number of results per page (0 uses server default, max 100). - format: int32 - type: integer - pageToken: - description: Pagination token from a previous response's next_page_token. - type: string - vaultId: - description: Required. The vault ID of the secret whose audit events to retrieve. + requestSchemaId: + description: The unique identifier of the request schema the entitlement was bound to. type: string - title: Paper Secret Service Search Audit Events Request + title: Request Schema Service Create Entitlement Binding Response type: object - x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsRequest - c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse: - description: |- - PaperSecretServiceSearchAuditEventsResponse contains a page of audit events - for the requested secret. + x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingResponse + c1.api.request_schema.v1.RequestSchemaServiceCreateRequest: + description: The request message for creating a new request schema. properties: - list: - description: |- - Sanitized OCSF events containing only time, event type, and actor fields. - Sensitive fields such as IP addresses, messages, and raw payloads are removed. + description: + description: An optional description of the request schema's purpose. + type: string + fieldGroups: + description: Logical groupings of fields for display purposes. items: - additionalProperties: true - type: object + $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' type: - array - "null" - nextPageToken: - description: Token to retrieve the next page of results. Empty when no more pages exist. - type: string - title: Paper Secret Service Search Audit Events Response - type: object - x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsResponse - c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest: - description: |- - SearchMySecrets request - for end users viewing their own secrets. - Automatically scoped to current user. - properties: - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - query: - description: Fuzzy search by display name - type: string - secretType: - description: Filter by secret type (optional) - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - type: string - x-speakeasy-unknown-values: allow - sharingMode: - description: Filter by sharing mode (optional) - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL - type: string - x-speakeasy-unknown-values: allow - sortBy: - description: Sort order - enum: - - SEARCH_SORT_BY_UNSPECIFIED - - SEARCH_SORT_BY_CREATED_DESC - - SEARCH_SORT_BY_CREATED_ASC - - SEARCH_SORT_BY_EXPIRES_ASC - - SEARCH_SORT_BY_NAME_ASC - type: string - x-speakeasy-unknown-values: allow - statuses: - description: Filter by status (optional) + fieldRelationships: + description: Dependencies between fields that control conditional visibility or validation. items: - enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' type: - array - "null" - title: Paper Secret Service Search My Secrets Request - type: object - x-speakeasy-name-override: PaperSecretServiceSearchMySecretsRequest - c1.api.secrets.v1.PaperSecretServiceSearchResponse: - description: Search response for user's own secrets - properties: - list: - description: The list field. + fields: + description: The form fields that users must fill out when requesting access. items: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + $ref: '#/components/schemas/c1.api.form.v1.Field' type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Paper Secret Service Search Response - type: object - x-speakeasy-name-override: PaperSecretServiceSearchResponse - c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput: - description: The PaperSecretServiceSetTextContentRequest message. - properties: - encryptedContent: - description: |- - Age-encrypted content bytes. The plaintext MUST be encrypted using the Age - encryption format to the age_recipient returned by CreateInternal/CreateExternal. - The resulting bytes begin with "age-encryption.org/v1\n" followed by the - encrypted payload. Maximum 64KB after encryption — for larger content, create - a FILE secret and use the upload_url instead. - format: base64 - type: string - inputFormat: - description: |- - Input format hint for the viewer UI when the secret is decrypted. - Does not affect encryption — this is metadata only. + justificationVisibility: + description: Controls whether the justification field is shown or hidden on the request form. enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE + - JUSTIFICATION_VISIBILITY_UNSPECIFIED + - JUSTIFICATION_VISIBILITY_SHOW + - JUSTIFICATION_VISIBILITY_HIDE type: string x-speakeasy-unknown-values: allow - title: Paper Secret Service Set Text Content Request + name: + description: The human-readable name for the request schema. + type: string + title: Request Schema Service Create Request type: object - x-speakeasy-name-override: PaperSecretServiceSetTextContentRequest - c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse: - description: The PaperSecretServiceSetTextContentResponse message. + x-speakeasy-name-override: RequestSchemaServiceCreateRequest + c1.api.request_schema.v1.RequestSchemaServiceCreateResponse: + description: The response message for creating a request schema. properties: - secret: + requestSchema: oneOf: - - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - type: "null" - title: Paper Secret Service Set Text Content Response + title: Request Schema Service Create Response type: object - x-speakeasy-name-override: PaperSecretServiceSetTextContentResponse - c1.api.service_principal.v1.ServicePrincipal: - description: ServicePrincipal represents a tenant-managed non-human identity. + x-speakeasy-name-override: RequestSchemaServiceCreateResponse + c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput: + description: The request message for deleting a request schema. + title: Request Schema Service Delete Request + type: object + x-speakeasy-name-override: RequestSchemaServiceDeleteRequest + c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse: + description: The response message for deleting a request schema. + title: Request Schema Service Delete Response + type: object + x-speakeasy-name-override: RequestSchemaServiceDeleteResponse + c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest: + description: The request message for finding which request schema is bound to a given app entitlement. properties: - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - displayName: - description: The display name of the service principal. + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Request Schema Service Find Binding For App Entitlement Request + type: object + x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementRequest + c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse: + description: The response message containing the binding for the specified app entitlement. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema bound to this entitlement, if any. type: string - id: - description: The unique user ID of the service principal. - readOnly: true + title: Request Schema Service Find Binding For App Entitlement Response + type: object + x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementResponse + c1.api.request_schema.v1.RequestSchemaServiceGetResponse: + description: The response message for retrieving a request schema. + properties: + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + title: Request Schema Service Get Response + type: object + x-speakeasy-name-override: RequestSchemaServiceGetResponse + c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest: + description: The request message for removing a single entitlement binding from a request schema. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema to remove the binding from. type: string - objectPermissions: + title: Request Schema Service Remove Entitlement Binding Request + type: object + x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingRequest + c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse: + description: The response message for removing a single entitlement binding. + title: Request Schema Service Remove Entitlement Binding Response + type: object + x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingResponse + c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput: + description: The request message for updating an existing request schema. + properties: + requestSchema: oneOf: - - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - type: "null" - updatedAt: - format: date-time - readOnly: true + updateMask: type: - string - "null" - user: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' - - type: "null" - title: Service Principal + title: Request Schema Service Update Request type: object - x-speakeasy-name-override: ServicePrincipal - c1.api.service_principal.v1.ServicePrincipalBinding: - description: |- - ServicePrincipalBinding is one row in the binding store, naming a - subject's link to a single service principal. + x-speakeasy-name-override: RequestSchemaServiceUpdateRequest + c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse: + description: The response message for updating a request schema. properties: - createdAt: - format: date-time - type: - - string - - "null" - servicePrincipalId: - description: The servicePrincipalId field. - type: string - updatedAt: - format: date-time + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + title: Request Schema Service Update Response + type: object + x-speakeasy-name-override: RequestSchemaServiceUpdateResponse + c1.api.requestcatalog.v1.AppEntitlementWithUserBindings: + description: The AppEntitlementWithUserBindings message represents an app entitlement and its associated user bindings. + properties: + appEntitlementUserBindings: + description: An array of AppEntitlementUserBinding objects which represent the relationships that give app users access to the specific app entitlement. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' type: - - string + - array - "null" - title: Service Principal Binding + entitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" + title: App Entitlement With User Bindings type: object - x-speakeasy-name-override: ServicePrincipalBinding - c1.api.service_principal.v1.ServicePrincipalBindingSubject: + x-speakeasy-name-override: AppEntitlementWithUserBindings + c1.api.requestcatalog.v1.BundleAutomation: description: | - ServicePrincipalBindingSubject identifies the entity that is bound to a - service principal. Open-ended oneof so future subject kinds (workflows, - connectors, etc.) can be added without changing the RPC shape. + The BundleAutomation message. - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - functionId + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - functionId: - description: |- - Function ID. The function authenticates outbound c1-api calls as - user: instead of function:. - This field is part of the `kind` oneof. - See the documentation for `c1.api.service_principal.v1.ServicePrincipalBindingSubject` for more details. + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' + - type: "null" + circuitBreaker: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker' + - type: "null" + createTasks: + description: The createTasks field. + type: boolean + createdAt: + format: date-time type: - string - "null" - title: Service Principal Binding Subject - type: object - x-speakeasy-name-override: ServicePrincipalBindingSubject - c1.api.service_principal.v1.ServicePrincipalCredential: - description: ServicePrincipalCredential represents a client credential for a service principal. - properties: - allowSourceCidrs: - description: CIDR restrictions for this credential. - items: - type: string - readOnly: true - type: - - array - - "null" - clientId: - description: 'The full client ID in format: ${cutename}@${tenant}.${installation}/spc' - readOnly: true - type: string - createdAt: + deletedAt: format: date-time - readOnly: true type: - string - "null" - displayName: - description: The display name of the credential. + disableCircuitBreaker: + description: The disableCircuitBreaker field. + type: boolean + enabled: + description: The enabled field. + type: boolean + enforceOnSmallProfiles: + description: |- + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. + type: boolean + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - type: "null" + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means the tenant default applies. + format: int64 type: string - expiresAt: + requestCatalogId: + description: The requestCatalogId field. + type: string + state: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationLastRunState' + - type: "null" + tenantId: + description: The tenantId field. + type: string + updatedAt: format: date-time - readOnly: true type: - string - "null" - id: - description: The unique ID of the credential (cutename format). - readOnly: true + title: Bundle Automation + type: object + x-speakeasy-name-override: BundleAutomation + c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState: + description: The BundleAutomationCelEvaluationState message. + properties: + errorMessage: + description: The errorMessage field. type: string - lastUsedAt: + lastEvaluatedAt: format: date-time - readOnly: true type: - string - "null" - requireDpop: - description: Whether DPoP proof-of-possession is required for this credential. - readOnly: true - type: boolean - scopedRoleIds: - description: Scoped role IDs for this credential (intersection with SP roles at token issuance). - items: - type: string - readOnly: true - type: - - array - - "null" - servicePrincipalId: - description: The service principal user ID this credential belongs to. - readOnly: true + matchedUsers: + description: The matchedUsers field. + format: int64 type: string - title: Service Principal Credential + status: + description: The status field. + enum: + - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED + - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS + - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE + - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS + - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL + type: string + x-speakeasy-unknown-values: allow + title: Bundle Automation Cel Evaluation State type: object - x-speakeasy-name-override: ServicePrincipalCredential - c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest: - description: The ServicePrincipalServiceAddBindingRequest message. + x-speakeasy-name-override: BundleAutomationCelEvaluationState + c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker: + description: The BundleAutomationCircuitBreaker message. properties: - servicePrincipalId: - description: The servicePrincipalId field. + removedMembersThresholdPercentage: + description: The removedMembersThresholdPercentage field. + format: int64 type: string - subject: + state: + description: The state field. + enum: + - CIRCUIT_BREAKER_STATE_UNSPECIFIED + - CIRCUIT_BREAKER_STATE_TRIGGERED + - CIRCUIT_BREAKER_STATE_BYPASS + - CIRCUIT_BREAKER_STATE_SUPPORT_DISABLED + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + userRef: oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - type: "null" - title: Service Principal Service Add Binding Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceAddBindingRequest - c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse: - description: The ServicePrincipalServiceAddBindingResponse message. - title: Service Principal Service Add Binding Response + title: Bundle Automation Circuit Breaker type: object - x-speakeasy-name-override: ServicePrincipalServiceAddBindingResponse - c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput: - description: The ServicePrincipalServiceCreateCredentialRequest message. + x-speakeasy-name-override: BundleAutomationCircuitBreaker + c1.api.requestcatalog.v1.BundleAutomationLastRunState: + description: The BundleAutomationLastRunState message. properties: - allowSourceCidrs: - description: |- - A list of CIDRs to restrict this credential to. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. - items: - type: string - type: - - array - - "null" - displayName: - description: The display name for the new credential. + celEvaluation: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState' + - type: "null" + errorMessage: + description: The errorMessage field. type: string - expires: - format: duration + lastRunAt: + format: date-time type: - string - "null" - requireDpop: - description: If true, requires DPoP proof-of-possession for token exchange using this credential. - type: boolean - scopedRoles: - description: The list of roles to restrict the credential to. - items: - type: string - type: - - array - - "null" - title: Service Principal Service Create Credential Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse: - description: The ServicePrincipalServiceCreateCredentialResponse message. - properties: - clientSecret: - description: The client secret. Shown exactly once at creation -- cannot be retrieved again. + status: + description: The status field. + enum: + - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED + - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS + - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE + - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS + - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL type: string - credential: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - - type: "null" - title: Service Principal Service Create Credential Response + x-speakeasy-unknown-values: allow + title: Bundle Automation Last Run State type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest: - description: The ServicePrincipalServiceCreateRequest message. + x-speakeasy-name-override: BundleAutomationLastRunState + c1.api.requestcatalog.v1.BundleAutomationRuleCEL: + description: The BundleAutomationRuleCEL message. properties: - displayName: - description: The display name for the new service principal. + expression: + description: The expression field. type: string - title: Service Principal Service Create Request + title: Bundle Automation Rule Cel type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateRequest - c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse: - description: The ServicePrincipalServiceCreateResponse message. + x-speakeasy-name-override: BundleAutomationRuleCEL + c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement: + description: The BundleAutomationRuleEntitlement message. properties: - servicePrincipal: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - - type: "null" - title: Service Principal Service Create Response + entitlementRefs: + description: The entitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Bundle Automation Rule Entitlement type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateResponse - c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest: - description: The ServicePrincipalServiceDeleteBindingRequest message. + x-speakeasy-name-override: BundleAutomationRuleEntitlement + c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput: + description: | + The request message for creating a new bundle automation rule on a catalog. + + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - servicePrincipalId: - description: The servicePrincipalId field. - type: string - subject: + cel: oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - type: "null" - title: Service Principal Service Delete Binding Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingRequest - c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse: - description: The ServicePrincipalServiceDeleteBindingResponse message. - title: Service Principal Service Delete Binding Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingResponse - c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput: - description: The ServicePrincipalServiceDeleteRequest message. - title: Service Principal Service Delete Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteRequest - c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse: - description: The ServicePrincipalServiceDeleteResponse message. - title: Service Principal Service Delete Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteResponse - c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse: - description: The ServicePrincipalServiceGetCredentialResponse message. - properties: - credential: + createTasks: + description: Whether to create access request tasks for matched users instead of granting directly. + type: boolean + disableCircuitBreaker: + description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. + type: boolean + enabled: + description: Whether the automation should actively run on its schedule. + type: boolean + enforceOnSmallProfiles: + description: |- + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. Defaults to false. + type: boolean + entitlements: oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - type: "null" - title: Service Principal Service Get Credential Response + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means inherit the tenant default. + format: int64 + type: string + title: Create Bundle Automation Request type: object - x-speakeasy-name-override: ServicePrincipalServiceGetCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceGetResponse: - description: The ServicePrincipalServiceGetResponse message. - properties: - servicePrincipal: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - - type: "null" - title: Service Principal Service Get Response + x-speakeasy-name-override: CreateBundleAutomationRequest + c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput: + description: The request message for deleting a bundle automation from a catalog. + title: Delete Bundle Automation Request type: object - x-speakeasy-name-override: ServicePrincipalServiceGetResponse - c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest: - description: The ServicePrincipalServiceListBindingsRequest message. - properties: - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - subject: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - - type: "null" - title: Service Principal Service List Bindings Request + x-speakeasy-name-override: DeleteBundleAutomationRequest + c1.api.requestcatalog.v1.DeleteBundleAutomationResponse: + description: The response message for deleting a bundle automation. + title: Delete Bundle Automation Response type: object - x-speakeasy-name-override: ServicePrincipalServiceListBindingsRequest - c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse: - description: The ServicePrincipalServiceListBindingsResponse message. + x-speakeasy-name-override: DeleteBundleAutomationResponse + c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput: + description: The request message for triggering an immediate bundle automation run. properties: - bindings: - description: |- - Active bindings held by the subject in this page. Empty when the - subject is unbound. Order is unspecified. + refs: + description: Optional entitlement references to scope the run to specific entitlements. items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBinding' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Service Principal Service List Bindings Response + title: Force Run Bundle Automation Request type: object - x-speakeasy-name-override: ServicePrincipalServiceListBindingsResponse - c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse: - description: The ServicePrincipalServiceListCredentialsResponse message. + x-speakeasy-name-override: ForceRunBundleAutomationRequest + c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse: + description: The response message for triggering a bundle automation run. + title: Force Run Bundle Automation Response + type: object + x-speakeasy-name-override: ForceRunBundleAutomationResponse + c1.api.requestcatalog.v1.RequestCatalog: + description: The RequestCatalog is used for managing which entitlements are requestable, and who can request them. properties: - list: - description: The list field. + accessEntitlements: + description: An array of app entitlements that, if the user has, can view the contents of this catalog. items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Service Principal Service List Credentials Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceListCredentialsResponse - c1.api.service_principal.v1.ServicePrincipalServiceListResponse: - description: The ServicePrincipalServiceListResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ + are reserved. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + createdAt: + format: date-time + readOnly: true type: - - array + - string - "null" - nextPageToken: - description: The nextPageToken field. + createdByUserId: + description: The id of the user this request catalog was created by. type: string - title: Service Principal Service List Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceListResponse - c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput: - description: The ServicePrincipalServiceRevokeCredentialRequest message. - title: Service Principal Service Revoke Credential Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse: - description: The ServicePrincipalServiceRevokeCredentialResponse message. - title: Service Principal Service Revoke Credential Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput: - description: The ServicePrincipalServiceUpdateCredentialRequest message. - properties: - credential: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - - type: "null" - updateMask: + deletedAt: + format: date-time + readOnly: true type: - string - "null" - title: Service Principal Service Update Credential Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse: - description: The ServicePrincipalServiceUpdateCredentialResponse message. - properties: - credential: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - - type: "null" - title: Service Principal Service Update Credential Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput: - description: The ServicePrincipalServiceUpdateRequest message. - properties: - servicePrincipal: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - - type: "null" - updateMask: - type: - - string - - "null" - title: Service Principal Service Update Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateRequest - c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse: - description: The ServicePrincipalServiceUpdateResponse message. - properties: - servicePrincipal: - oneOf: - - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - - type: "null" - title: Service Principal Service Update Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateResponse - c1.api.session_policy.v1.Allow: - description: Allow continues the session. - properties: - floorLevel: - description: The minimum assurance level that satisfies this rule. + description: + description: The description of the request catalog. + type: string + displayName: + description: The display name of the request catalog. + type: string + enrollmentBehavior: + description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. enum: - - AUTH_LEVEL_UNSPECIFIED - - AUTH_LEVEL_NONE - - AUTH_LEVEL_SINGLE_FACTOR - - AUTH_LEVEL_MULTI_FACTOR - - AUTH_LEVEL_PHR - - AUTH_LEVEL_PHRH + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY type: string x-speakeasy-unknown-values: allow - title: Allow - type: object - x-speakeasy-name-override: SessionPolicyAllow - c1.api.session_policy.v1.Assignment: - description: Assignment is one principal (user) assigned to a session policy. - properties: - source: - description: Whether the assignment is direct or conferred through a group. + id: + description: The id of the request catalog. + type: string + published: + description: Whether or not this catalog is published. + type: boolean + requestBundle: + description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. + type: boolean + type: + description: |- + The type of this access profile. Reports CATALOG_AND_BUNDLE for a profile + created before the type was recorded; UNSPECIFIED only for a tenant whose + backfill has not been run. enum: - - ASSIGNMENT_SOURCE_UNSPECIFIED - - ASSIGNMENT_SOURCE_DIRECT - - ASSIGNMENT_SOURCE_GROUP + - REQUEST_CATALOG_TYPE_UNSPECIFIED + - REQUEST_CATALOG_TYPE_CATALOG + - REQUEST_CATALOG_TYPE_PROFILE + - REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE + - REQUEST_CATALOG_TYPE_BUNDLE + readOnly: true type: string x-speakeasy-unknown-values: allow - userId: - description: The assigned user's ID. + unenrollmentBehavior: + description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED type: string - title: Assignment + x-speakeasy-unknown-values: allow + unenrollmentEntitlementBehavior: + description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + visibleToEveryone: + description: If this is true, the access entitlement requirement is ignored. + type: boolean + title: Request Catalog type: object - x-speakeasy-name-override: Assignment - c1.api.session_policy.v1.ChallengeRequired: - description: ChallengeRequired asks for an additional factor. + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalog + c1.api.requestcatalog.v1.RequestCatalogExpandMask: + description: The RequestCatalogExpandMask includes the paths in the catalog view to expand in the return value of this call. properties: - types: - description: The types field. + paths: + description: An array of paths to be expanded in the response. May be any combination of "*", "created_by_user_id", "app_ids", and "access_entitlements". items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - x-speakeasy-unknown-values: allow type: - array - "null" - title: Challenge Required + title: Request Catalog Expand Mask type: object - x-speakeasy-name-override: SessionPolicyChallengeRequired - c1.api.session_policy.v1.Deny: - description: Deny terminates the session. + x-speakeasy-name-override: RequestCatalogExpandMask + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput: + description: |- + The RequestCatalogManagementServiceAddAccessEntitlementsRequest message is used to add access entitlements to a request + catalog to determine which users can view the request catalog. properties: - reasonAdmin: - description: Reason shown in admin-only audit. - type: string - reasonUser: - description: Reason safe to show the end user. - type: string - title: Deny + accessEntitlements: + description: List of entitlements to add to the request catalog as access entitlements. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + required: + - accessEntitlements + title: Request Catalog Management Service Add Access Entitlements Request type: object - x-speakeasy-name-override: SessionPolicyDeny - c1.api.session_policy.v1.EnrollmentRequired: - description: EnrollmentRequired tells the user to enroll a credential before continuing. + x-speakeasy-entity: Access_Profile_Visibility_Bindings + x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Add Access Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceAddAppEntitlementsRequest object is used to add app requestable app entitlements to a request catalog. properties: - credentialTypes: - description: The credentialTypes field. + appEntitlements: + description: List of entitlements to add to the request catalog. items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: - array - "null" - title: Enrollment Required + createRequests: + description: |- + Whether or not to create requests for newly added entitlements for users in the catalog. + By default, this is false and no requests are created. + type: boolean + required: + - appEntitlements + title: Request Catalog Management Service Add App Entitlements Request type: object - x-speakeasy-name-override: SessionPolicyEnrollmentRequired - c1.api.session_policy.v1.PerCredentialDuration: - description: |- - PerCredentialDuration overrides session lifetimes for sessions established - with a particular credential type — stronger credentials can earn longer - sessions. + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Add App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest: + description: Create a request catalog. properties: - accessTokenTtlSeconds: - description: Access-token lifetime for this credential type, in seconds. - format: int32 - type: integer - credentialType: - description: The credentialType field. + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + description: + description: The description of the new request catalog. + type: string + displayName: + description: The display name of the new request catalog. + type: string + enrollmentBehavior: + description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY type: string x-speakeasy-unknown-values: allow - maxSessionDurationSeconds: - description: Maximum total session duration for this credential type, in seconds. - format: int32 - type: integer - title: Per Credential Duration - type: object - x-speakeasy-name-override: PerCredentialDuration - c1.api.session_policy.v1.PolicyOutcome: - description: | - PolicyOutcome is the effect of a matched rule. Exactly one kind is set. For - session continuous-evaluation, the meaningful kinds are Allow (continue), - Deny (terminate), and StepUpRequired. - - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - allow - - deny - - stepUpRequired - - challengeRequired - - enrollmentRequired - properties: - allow: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.Allow' - - type: "null" - challengeRequired: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.ChallengeRequired' - - type: "null" - deny: + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.Deny' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' - type: "null" - enrollmentRequired: + published: + description: Whether or not the new catalog should be created as published. + type: boolean + requestBundle: + description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. + type: boolean + type: + description: |- + The type of access profile to create. Leave unset for + REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE, which is what every profile + created before this field existed is. Setting it requires the + ACCESS_PROFILE_TYPES feature. + + PROFILE is rejected rather than resolved: it is deprecated, has no stored + counterpart, and shares wire number 2 with the stored BUNDLE, so honoring + it would silently persist a type the caller did not ask for. + enum: + - REQUEST_CATALOG_TYPE_UNSPECIFIED + - REQUEST_CATALOG_TYPE_CATALOG + - REQUEST_CATALOG_TYPE_PROFILE + - REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE + - REQUEST_CATALOG_TYPE_BUNDLE + type: string + x-speakeasy-unknown-values: allow + unenrollmentBehavior: + description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED + type: string + x-speakeasy-unknown-values: allow + unenrollmentEntitlementBehavior: + description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE + type: string + x-speakeasy-unknown-values: allow + visibleToEveryone: + description: Whether or not the new catalog is visible to everyone by default. + type: boolean + required: + - displayName + title: Request Catalog Management Service Create Request + type: object + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput: + description: Create a single requestable entry + properties: + createRequests: + description: |- + Whether or not to create requests for newly added entitlement for users in the catalog. + By default, this is false and no requests are created. + type: boolean + title: Request Catalog Management Service Create Requestable Entry Request + type: object + x-speakeasy-entity: Access_Profile_Requestable_Entry + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse: + description: Response containing the created requestable entry + properties: + requestableEntry: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.EnrollmentRequired' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' - type: "null" - stepUpRequired: + title: Request Catalog Management Service Create Requestable Entry Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput: + description: Delete a request catalog by Id. It uses URL value for input. + title: Request Catalog Management Service Delete Request + type: object + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput: + description: Delete a single requestable entry + title: Request Catalog Management Service Delete Requestable Entry Request + type: object + x-speakeasy-entity: Access_Profile_Requestable_Entry + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse: + description: Empty response for delete operation + title: Request Catalog Management Service Delete Requestable Entry Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Delete Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse: + description: Response containing the requested entry + properties: + requestableEntry: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.StepUpRequired' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' - type: "null" - title: Policy Outcome + title: Request Catalog Management Service Get Requestable Entry Response type: object - x-speakeasy-name-override: SessionPolicyPolicyOutcome - c1.api.session_policy.v1.PolicyRule: - description: |- - PolicyRule is one rung of the ordered continuous-evaluation cascade. Rules - are evaluated top to bottom on every request; the first enforced rule whose - condition matches supplies the outcome. + x-speakeasy-name-override: RequestCatalogManagementServiceGetRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse: + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. properties: - description: - description: The description field. - type: string - id: - description: The id field. - type: string - matchCel: - description: The matchCel field. - type: string - mode: - description: The mode field. - enum: - - POLICY_RULE_MODE_UNSPECIFIED - - POLICY_RULE_MODE_ENFORCE - - POLICY_RULE_MODE_OBSERVE - - POLICY_RULE_MODE_DISABLED - type: string - x-speakeasy-unknown-values: allow - outcome: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + requestCatalogView: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' - type: "null" - title: Policy Rule + title: Request Catalog Management Service Get Response type: object - x-speakeasy-name-override: SessionPolicyPolicyRule - c1.api.session_policy.v1.SSFReceiverConfig: - description: |- - SSFReceiverConfig selects which inbound shared-signals streams this session - trusts. Each stream's issuer, keys, expected audience, and per-event actions - are configured on the stream itself; this policy just lists the stream IDs. + x-speakeasy-name-override: RequestCatalogManagementServiceGetResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse: + description: The response message containing all requestable entitlement references in the catalog. properties: - enabled: - description: Whether inbound shared-signals consumption is enabled for this policy. - type: boolean - ssfReceiverStreamIds: - description: The inbound stream IDs this policy trusts. + refs: + description: The complete list of app entitlement references in this catalog. items: - type: string + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: - array - "null" - title: Ssf Receiver Config + title: Request Catalog Management Service List All Entitlement Ids Per Catalog Response type: object - x-speakeasy-name-override: SSFReceiverConfig - c1.api.session_policy.v1.SSFTransmitterConfig: - description: |- - SSFTransmitterConfig selects which outbound shared-signals streams this - session emits security events to. Each stream's delivery endpoint, - authentication, and per-event allowlist are configured on the stream itself; - this policy just lists the stream IDs and the event types to emit. + x-speakeasy-name-override: RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse: + description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. properties: - enabled: - description: Whether outbound shared-signals emission is enabled for this policy. - type: boolean - eventTypes: - description: The shared-signals event types to emit at the policy level. + expanded: + description: List of serialized related objects. items: - type: string + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - ssfTransmitterStreamIds: - description: The outbound stream IDs this policy emits to. + list: + description: The list of results containing up to X results, where X is the page size defined in the request. items: - type: string + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' type: - array - "null" - title: Ssf Transmitter Config + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: Request Catalog Management Service List Entitlements For Access Response type: object - x-speakeasy-name-override: SSFTransmitterConfig - c1.api.session_policy.v1.SessionPolicy: - description: SessionPolicy defines session lifetime and continuous-evaluation behavior. + x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsForAccessResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse: + description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. properties: - accessTokenTtlSeconds: - description: How long an access token is valid, in seconds. - format: int32 - type: integer - continuousDefaultOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' - - type: "null" - continuousRules: - description: |- - The continuous-evaluation rule cascade, re-checked on every request and on - inbound shared-signals events. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - credentialDurations: - description: Per-credential-type lifetime overrides. + list: + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' type: - array - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - displayName: - description: A human-readable name for the policy. - type: string - id: - description: Unique identifier for the policy. - readOnly: true - type: string - idleTimeoutSeconds: - description: How long a session may be idle before it ends, in seconds. - format: int32 - type: integer - isBuiltin: - description: |- - True for built-in policies provided by ConductorOne. Built-in policies - cannot be edited or deleted. - readOnly: true - type: boolean - maxSessionDurationSeconds: - description: The maximum total lifetime of a session, in seconds. - format: int32 - type: integer - persistence: - description: Whether sessions may persist across browser restarts. - enum: - - PERSISTENCE_MODE_UNSPECIFIED - - PERSISTENCE_MODE_ALLOW_USER_CHOICE - - PERSISTENCE_MODE_ALWAYS_PERSIST - - PERSISTENCE_MODE_SESSION_ONLY - type: string - x-speakeasy-unknown-values: allow - priority: - description: |- - When a user matches more than one policy, the policy with the highest - priority applies. - format: int32 - type: integer - refreshRotationWindowSeconds: + nextPageToken: description: |- - Grace window after rotation during which the previous refresh token is - still accepted, in seconds (covers in-flight client retries). - format: int32 - type: integer - refreshTokenTtlSeconds: - description: How long a refresh token is valid, in seconds. - format: int32 - type: integer - rotateRefreshOnUse: - description: Whether to issue a new refresh token each time one is used. - type: boolean - ssfReceive: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' - - type: "null" - ssfTransmit: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' - - type: "null" - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - title: Session Policy - type: object - x-speakeasy-entity: SessionPolicy - x-speakeasy-name-override: SessionPolicy - c1.api.session_policy.v1.SessionPolicyRef: - description: SessionPolicyRef is a lightweight reference to a session policy by ID. - properties: - id: - description: The id field. - type: string - title: Session Policy Ref - type: object - x-speakeasy-name-override: SessionPolicyRef - c1.api.session_policy.v1.SessionPolicyServiceAssignGroupRequestInput: - description: The SessionPolicyServiceAssignGroupRequest message. - properties: - groupAppEntitlementId: - description: The group's app-entitlement ID. Every member of the group becomes assigned. - type: string - required: - - groupAppEntitlementId - title: Session Policy Service Assign Group Request - type: object - x-speakeasy-name-override: SessionPolicyServiceAssignGroupRequest - c1.api.session_policy.v1.SessionPolicyServiceAssignGroupResponse: - description: The SessionPolicyServiceAssignGroupResponse message. - title: Session Policy Service Assign Group Response - type: object - x-speakeasy-name-override: SessionPolicyServiceAssignGroupResponse - c1.api.session_policy.v1.SessionPolicyServiceAssignUserRequestInput: - description: The SessionPolicyServiceAssignUserRequest message. - properties: - userId: - description: The user to assign. + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - required: - - userId - title: Session Policy Service Assign User Request - type: object - x-speakeasy-name-override: SessionPolicyServiceAssignUserRequest - c1.api.session_policy.v1.SessionPolicyServiceAssignUserResponse: - description: The SessionPolicyServiceAssignUserResponse message. - title: Session Policy Service Assign User Response + title: Request Catalog Management Service List Entitlements Per Catalog Response type: object - x-speakeasy-name-override: SessionPolicyServiceAssignUserResponse - c1.api.session_policy.v1.SessionPolicyServiceCreateRequest: - description: The SessionPolicyServiceCreateRequest message. + x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsPerCatalogResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse: + description: The RequestCatalogManagementServiceListResponse message. properties: - accessTokenTtlSeconds: - description: The accessTokenTtlSeconds field. - format: int32 - type: integer - continuousDefaultOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' - - type: "null" - continuousRules: - description: The continuousRules field. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - credentialDurations: - description: The credentialDurations field. + list: + description: The list of request catalogs. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' type: - array - "null" - displayName: - description: The displayName field. - type: string - idleTimeoutSeconds: - description: The idleTimeoutSeconds field. - format: int32 - type: integer - maxSessionDurationSeconds: - description: The maxSessionDurationSeconds field. - format: int32 - type: integer - persistence: - description: The persistence field. - enum: - - PERSISTENCE_MODE_UNSPECIFIED - - PERSISTENCE_MODE_ALLOW_USER_CHOICE - - PERSISTENCE_MODE_ALWAYS_PERSIST - - PERSISTENCE_MODE_SESSION_ONLY + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - x-speakeasy-unknown-values: allow - priority: - description: The priority field. - format: int32 - type: integer - refreshRotationWindowSeconds: - description: The refreshRotationWindowSeconds field. - format: int32 - type: integer - refreshTokenTtlSeconds: - description: The refreshTokenTtlSeconds field. - format: int32 - type: integer - rotateRefreshOnUse: - description: The rotateRefreshOnUse field. - type: boolean - ssfReceive: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' - - type: "null" - ssfTransmit: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' - - type: "null" - required: - - displayName - title: Session Policy Service Create Request + title: Request Catalog Management Service List Response type: object - x-speakeasy-entity: SessionPolicy - x-speakeasy-name-override: SessionPolicyServiceCreateRequest - c1.api.session_policy.v1.SessionPolicyServiceCreateResponse: - description: The SessionPolicyServiceCreateResponse message. + x-speakeasy-name-override: RequestCatalogManagementServiceListResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput: + description: |- + The RequestCatalogManagementServiceRemoveAccessEntitlementsRequest message is used to remove access entitlements from a request catalog. + The access entitlements are used to determine which users can view the request catalog. properties: - sessionPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - - type: "null" - title: Session Policy Service Create Response - type: object - x-speakeasy-name-override: SessionPolicyServiceCreateResponse - c1.api.session_policy.v1.SessionPolicyServiceDeleteRequestInput: - description: The SessionPolicyServiceDeleteRequest message. - title: Session Policy Service Delete Request - type: object - x-speakeasy-entity: SessionPolicy - x-speakeasy-name-override: SessionPolicyServiceDeleteRequest - c1.api.session_policy.v1.SessionPolicyServiceDeleteResponse: - description: The SessionPolicyServiceDeleteResponse message. - title: Session Policy Service Delete Response + accessEntitlements: + description: The list of access entitlements to remove from the catalog. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Request Catalog Management Service Remove Access Entitlements Request type: object - x-speakeasy-name-override: SessionPolicyServiceDeleteResponse - c1.api.session_policy.v1.SessionPolicyServiceGetResponse: - description: The SessionPolicyServiceGetResponse message. - properties: - sessionPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - - type: "null" - title: Session Policy Service Get Response + x-speakeasy-entity: Access_Profile_Visibility_Bindings + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Remove Access Entitlements Response type: object - x-speakeasy-name-override: SessionPolicyServiceGetResponse - c1.api.session_policy.v1.SessionPolicyServiceListAssignmentsResponse: - description: The SessionPolicyServiceListAssignmentsResponse message. + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceRemoveAppEntitlementsRequest message is used to remove app entitlements from a request catalog. properties: - assignments: - description: The assignments field. + appEntitlements: + description: The list of app entitlements to remove from the catalog. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.Assignment' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Session Policy Service List Assignments Response + title: Request Catalog Management Service Remove App Entitlements Request type: object - x-speakeasy-name-override: SessionPolicyServiceListAssignmentsResponse - c1.api.session_policy.v1.SessionPolicyServiceListResponse: - description: The SessionPolicyServiceListResponse message. + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse: + description: Empty response with a status code indicating success + title: Request Catalog Management Service Remove App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceUpdateAppEntitlementsRequest object is used to update app entitlements to a request catalog id. properties: - list: - description: The list field. + appEntitlements: + description: The entitlement to get from the request catalog. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: Session Policy Service List Response + required: + - appEntitlements + title: Request Catalog Management Service Update App Entitlements Request type: object - x-speakeasy-name-override: SessionPolicyServiceListResponse - c1.api.session_policy.v1.SessionPolicyServiceSearchRequest: - description: The SessionPolicyServiceSearchRequest message. + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse: + description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. + title: Request Catalog Management Service Update App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput: + description: Update a request catalog object by ID. + properties: + catalog: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: Request Catalog Management Service Update Request + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateRequest + c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest: + description: The RequestCatalogSearchServiceSearchEntitlementsRequest searches entitlements, but only ones that are available to you through the open catalogs. properties: + appDisplayName: + description: Search entitlements that belong to this app name (exact match). + type: string + entitlementAlias: + description: Search for entitlements with this alias (exact match). + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" + grantedStatus: + description: Search entitlements with this granted status for your signed in user. + enum: + - UNSPECIFIED + - ALL + - GRANTED + - NOT_GRANTED + type: string + x-speakeasy-unknown-values: allow + includeDeleted: + description: Include deleted entitlements + type: boolean pageSize: - description: The pageSize field. + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 type: integer pageToken: description: The pageToken field. type: string query: - description: Free-text search over the policy name. Empty matches all policies. + description: Fuzzy search the display name of resource types. type: string - refs: - description: Restrict results to these specific policies. Empty matches all policies. + title: Request Catalog Search Service Search Entitlements Request + type: object + x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse: + description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + properties: + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyRef' + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - title: Session Policy Service Search Request - type: object - x-speakeasy-name-override: SessionPolicyServiceSearchRequest - c1.api.session_policy.v1.SessionPolicyServiceSearchResponse: - description: The SessionPolicyServiceSearchResponse message. - properties: list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.AppEntitlementWithUserBindings' type: - array - "null" nextPageToken: - description: The nextPageToken field. + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Session Policy Service Search Response + title: Request Catalog Search Service Search Entitlements Response type: object - x-speakeasy-name-override: SessionPolicyServiceSearchResponse - c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupRequestInput: - description: The SessionPolicyServiceUnassignGroupRequest message. - title: Session Policy Service Unassign Group Request + x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogView: + description: The request catalog view contains the serialized request catalog and paths to objects referenced by the request catalog. + properties: + accessEntitlementsPath: + description: JSONPATH expression indicating the location of the access entitlement objects, that the request catalog allows users to request, in the array. + type: string + createdByUserPath: + description: JSONPATH expression indicating the location of the User object, that created the request catalog, in the array. + type: string + memberCount: + description: Total number of the members of the catalog + format: int64 + type: string + requestCatalog: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' + - type: "null" + title: Request Catalog View type: object - x-speakeasy-name-override: SessionPolicyServiceUnassignGroupRequest - c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupResponse: - description: The SessionPolicyServiceUnassignGroupResponse message. - title: Session Policy Service Unassign Group Response + x-speakeasy-name-override: RequestCatalogView + c1.api.requestcatalog.v1.RequestableEntry: + description: A requestable entry in a catalog + properties: + appId: + description: The ID of the app that contains the entitlement + type: string + catalogId: + description: The ID of the access profile (catalog) + type: string + entitlementId: + description: The ID of the entitlement + type: string + title: Requestable Entry type: object - x-speakeasy-name-override: SessionPolicyServiceUnassignGroupResponse - c1.api.session_policy.v1.SessionPolicyServiceUnassignUserRequestInput: - description: The SessionPolicyServiceUnassignUserRequest message. - title: Session Policy Service Unassign User Request + x-speakeasy-name-override: RequestableEntry + c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput: + description: The request message for resuming a paused bundle automation. + title: Resume Paused Bundle Automation Request type: object - x-speakeasy-name-override: SessionPolicyServiceUnassignUserRequest - c1.api.session_policy.v1.SessionPolicyServiceUnassignUserResponse: - description: The SessionPolicyServiceUnassignUserResponse message. - title: Session Policy Service Unassign User Response + x-speakeasy-name-override: ResumePausedBundleAutomationRequest + c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse: + description: The response message for resuming a paused bundle automation. + title: Resume Paused Bundle Automation Response type: object - x-speakeasy-name-override: SessionPolicyServiceUnassignUserResponse - c1.api.session_policy.v1.SessionPolicyServiceUpdateRequestInput: - description: The SessionPolicyServiceUpdateRequest message. + x-speakeasy-name-override: ResumePausedBundleAutomationResponse + c1.api.requestcatalog.v1.SetBundleAutomationRequestInput: + description: | + The request message for creating or updating a bundle automation rule on a catalog. + + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - sessionPolicy: + cel: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - type: "null" - updateMask: - type: - - string - - "null" - title: Session Policy Service Update Request - type: object - x-speakeasy-name-override: SessionPolicyServiceUpdateRequest - c1.api.session_policy.v1.SessionPolicyServiceUpdateResponse: - description: The SessionPolicyServiceUpdateResponse message. - properties: - sessionPolicy: + createTasks: + description: Whether to create access request tasks for matched users instead of granting directly. + type: boolean + disableCircuitBreaker: + description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. + type: boolean + enabled: + description: Whether the automation should actively run on its schedule. + type: boolean + enforceOnSmallProfiles: + description: |- + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. Defaults to false. + type: boolean + entitlements: oneOf: - - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - type: "null" - title: Session Policy Service Update Response + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means inherit the tenant default. + format: int64 + type: string + title: Set Bundle Automation Request type: object - x-speakeasy-name-override: SessionPolicyServiceUpdateResponse - c1.api.session_policy.v1.StepUpRequired: - description: |- - StepUpRequired demands a stronger re-authentication before the session may - continue. + x-speakeasy-name-override: SetBundleAutomationRequest + c1.api.role_mining_management.v1.CohortHintInput: + description: The CohortHintInput message. properties: - level: - description: The level field. - enum: - - AUTH_LEVEL_UNSPECIFIED - - AUTH_LEVEL_NONE - - AUTH_LEVEL_SINGLE_FACTOR - - AUTH_LEVEL_MULTI_FACTOR - - AUTH_LEVEL_PHR - - AUTH_LEVEL_PHRH + attribute: + description: The user attribute name to use for cohort grouping (e.g., "department", "job_title"). type: string - x-speakeasy-unknown-values: allow - maxAgeSeconds: - description: How fresh the step-up must be, in seconds. + priority: + description: Relative priority of this hint. Higher values cause the analysis to weight this attribute more heavily. format: int32 type: integer - types: - description: The types field. + values: + description: Specific attribute values to focus on. If empty, all values for the attribute are considered. items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - x-speakeasy-unknown-values: allow type: - array - "null" - title: Step Up Required - type: object - x-speakeasy-name-override: SessionPolicyStepUpRequired - c1.api.settings.v1.AWSExternalID: - description: AWSExternalID contains the tenant's external ID for AWS IAM role trust policies. - properties: - externalId: - description: The external ID value to include in the AWS IAM role trust policy condition. - type: string - title: Aws External Id + title: Cohort Hint Input type: object - x-speakeasy-entity: AWS_EXTERNAL_ID - x-speakeasy-name-override: AWSExternalID - c1.api.settings.v1.AWSSESProviderConfig: - description: AWSSESProviderConfig configures sending via a customer's AWS SES account. + x-speakeasy-name-override: CohortHintInput + c1.api.role_mining_management.v1.CohortHintView: + description: The CohortHintView message. properties: - configurationSetName: - description: Optional SES configuration set name for tracking/metrics. - type: string - region: - description: AWS region where SES identities are verified (e.g., "us-east-1"). - type: string - roleArn: - description: |- - IAM role ARN for sts:AssumeRole. The trust policy should require the - tenant's AWS External ID (GET /api/v1/settings/aws-external-id). + attribute: + description: The user attribute name used for cohort grouping. type: string - title: Awsses Provider Config + priority: + description: Relative priority of this hint. + format: int32 + type: integer + values: + description: The specific attribute values targeted by this hint. + items: + type: string + type: + - array + - "null" + title: Cohort Hint View type: object - x-speakeasy-name-override: AWSSESProviderConfig - c1.api.settings.v1.AccessProvisionedPreference: - description: The AccessProvisionedPreference message. + x-speakeasy-name-override: CohortHintView + c1.api.role_mining_management.v1.CohortUserWithCoverage: + description: CohortUserWithCoverage pairs a user with the count of selected entitlements they hold. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Access Provisioned Preference + coveredCount: + description: Number of selected_entitlements that this user currently holds. + format: int32 + type: integer + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Cohort User With Coverage type: object - x-speakeasy-name-override: AccessProvisionedPreference - c1.api.settings.v1.ApprovalNeededPreference: - description: The ApprovalNeededPreference message. + x-speakeasy-name-override: CohortUserWithCoverage + c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest: + description: The CreateAccessProfileFromCohortRequest message. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. + celExpression: + description: |- + Optional CEL expression for dynamic membership. When non-empty, used + instead of auto-generating from profile_filters. + type: string + createTasks: + description: |- + If true, the automation will create JIT tasks for access changes. + If false, users are synced to membership without creating tasks. type: boolean - title: Approval Needed Preference - type: object - x-speakeasy-name-override: ApprovalNeededPreference - c1.api.settings.v1.C1BuiltInProviderConfig: - description: |- - C1BuiltInProviderConfig selects the ConductorOne built-in email provider. - Emails are sent from no-reply@conductorone.com via the platform SendGrid account. - Only supports sending to C1 users — external email addresses are not supported. - No configuration fields required. - title: C 1 Built In Provider Config - type: object - x-speakeasy-name-override: C1BuiltInProviderConfig - c1.api.settings.v1.CIDRRestriction: - description: CIDRRestriction defines an IP-based access restriction with an enable toggle and a list of allowed CIDRs. - properties: - enabled: - description: Whether this CIDR restriction is enforced. + description: + description: Description for the access profile. + type: string + displayName: + description: Display name for the access profile. + type: string + enableAutomation: + description: If true, enable the dynamic membership automation immediately. type: boolean - sourceCidr: - description: |- - The list of CIDR ranges that are allowed when the restriction is enabled. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + entitlements: + description: Entitlements to add to the access profile. items: - type: string + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' type: - array - "null" - title: Cidr Restriction + profileFilters: + description: Profile filters defining the cohort for dynamic membership. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + suggestionId: + description: Optional suggestion ID to mark as accepted after creating the profile. + type: string + title: Create Access Profile From Cohort Request type: object - x-speakeasy-name-override: CIDRRestriction - c1.api.settings.v1.ChannelSettings: - description: ChannelSettings groups notification preferences for all supported channels. + x-speakeasy-name-override: CreateAccessProfileFromCohortRequest + c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse: + description: The CreateAccessProfileFromCohortResponse message. properties: - email: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.EmailChannelSettings' - - type: "null" - slack: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.SlackChannelSettings' - - type: "null" - teams: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.MSTeamsChannelSettings' - - type: "null" - title: Channel Settings + accessProfileId: + description: The ID of the created access profile. + type: string + celExpression: + description: The CEL expression generated for dynamic membership. + type: string + title: Create Access Profile From Cohort Response type: object - x-speakeasy-name-override: ChannelSettings - c1.api.settings.v1.CommentOnRequestPreference: - description: The CommentOnRequestPreference message. + x-speakeasy-name-override: CreateAccessProfileFromCohortResponse + c1.api.role_mining_management.v1.CustomAnalysisResultView: + description: CustomAnalysisResultView is a lightweight summary of a past custom analysis run. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Comment On Request Preference + cohortSize: + description: Number of users in the cohort. + format: int32 + type: integer + completedAt: + format: date-time + type: + - string + - "null" + createdAt: + format: date-time + type: + - string + - "null" + errorMessage: + description: Error message if the analysis failed, empty on success. + type: string + id: + description: Unique identifier for this custom analysis result. + type: string + profileFilters: + description: Profile filters that defined the cohort for this analysis. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + status: + description: Execution status of this analysis (e.g., running, completed, failed). + enum: + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED + type: string + x-speakeasy-unknown-values: allow + suggestionsGenerated: + description: Number of role suggestions generated. + format: int32 + type: integer + title: Custom Analysis Result View type: object - x-speakeasy-name-override: CommentOnRequestPreference - c1.api.settings.v1.CompletionPreference: - description: The CompletionPreference message. + x-speakeasy-name-override: CustomAnalysisResultView + c1.api.role_mining_management.v1.EntitlementRef: + description: EntitlementRef identifies an entitlement by application and entitlement ID. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Completion Preference + appId: + description: Application that owns the entitlement. + type: string + entitlementId: + description: Entitlement within the application. + type: string + title: Entitlement Ref type: object - x-speakeasy-name-override: CompletionPreference - c1.api.settings.v1.ConnectorIssuesPreference: - description: The ConnectorIssuesPreference message. + x-speakeasy-name-override: EntitlementRef + c1.api.role_mining_management.v1.EvaluateEntitlementSelectionRequestInput: + description: |- + EvaluateEntitlementSelectionRequest selects analyzed entitlements using an + inclusive coverage cutoff plus optional manual overrides. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. + explicitlyExcluded: + description: Analyzed entitlements to exclude when they meet the cutoff. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EntitlementRef' + type: + - array + - "null" + explicitlyIncluded: + description: Analyzed entitlements to include even when they fall below the cutoff. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EntitlementRef' + type: + - array + - "null" + includeFacets: + description: Whether to return profile attribute facets for exact holders. type: boolean - title: Connector Issues Preference + minimumCoverageBasisPoints: + description: Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. + format: int32 + type: integer + title: Evaluate Entitlement Selection Request type: object - x-speakeasy-name-override: ConnectorIssuesPreference - c1.api.settings.v1.Contacts: - description: Contacts represents the contact configuration for an organization. + x-speakeasy-name-override: EvaluateEntitlementSelectionRequest + c1.api.role_mining_management.v1.EvaluateEntitlementSelectionResponse: + description: |- + EvaluateEntitlementSelectionResponse contains the exact impact of the + resolved entitlement selection. properties: - billingEmails: - description: Email addresses of billing contacts for this organization. + coreHolderFacets: + description: Profile attribute facets narrowed to users who hold every selected entitlement. items: - type: string + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeFacet' type: - array - "null" - createdAt: - format: date-time - readOnly: true + selectedEntitlementCount: + description: Number of entitlements in the resolved selection. + format: int32 + type: integer + usersWithAllEntitlements: + description: Exact number of cohort users who hold every selected entitlement. + format: int32 + type: integer + title: Evaluate Entitlement Selection Response + type: object + x-speakeasy-name-override: EvaluateEntitlementSelectionResponse + c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse: + description: The GetCustomAnalysisResultResponse message. + properties: + appsAnalyzed: + description: The appsAnalyzed field. + format: int32 + type: integer + clusters: + description: Cluster results. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.EntitlementCluster' type: - - string + - array - "null" - operationsEmails: - description: Email addresses of operations contacts for this organization. + cohortSize: + description: The cohortSize field. + format: int32 + type: integer + cutoffImpactPoints: + description: Exact holder counts at each distinct inclusive entitlement coverage cutoff. items: - type: string + $ref: '#/components/schemas/c1.mcp.role_mining.v1.EntitlementCutoffImpactPoint' type: - array - "null" - securityEmails: - description: Email addresses of security contacts for this organization. + entitlements: + description: Entitlement coverage results. items: - type: string + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' type: - array - "null" - updatedAt: - format: date-time - readOnly: true + errorMessage: + description: The errorMessage field. + type: string + facetUserCount: + description: The facetUserCount field. + format: int32 + type: integer + facets: + description: Facet results. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeFacet' type: - - string + - array - "null" - title: Contacts - type: object - x-speakeasy-name-override: Contacts - c1.api.settings.v1.DigestPreference: - description: DigestPreference controls whether summary digest notifications are sent and how often. - properties: - dayOfWeek: - description: The day of the week to send weekly digests. - enum: - - WEEKDAY_UNSPECIFIED - - WEEKDAY_MONDAY - - WEEKDAY_TUESDAY - - WEEKDAY_WEDNESDAY - - WEEKDAY_THURSDAY - - WEEKDAY_FRIDAY - - WEEKDAY_SATURDAY - - WEEKDAY_SUNDAY + id: + description: The id field. type: string - x-speakeasy-unknown-values: allow - enabled: - description: Whether digest notifications are enabled. - type: boolean - frequency: - description: How often digest notifications are sent. + status: + description: The status field. enum: - - DIGEST_FREQUENCY_UNSPECIFIED - - DIGEST_FREQUENCY_DAILY - - DIGEST_FREQUENCY_WEEKLY + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED type: string x-speakeasy-unknown-values: allow - locked: - description: Whether this preference is locked by org-level settings, preventing users from overriding it. - type: boolean - title: Digest Preference + title: Get Custom Analysis Result Response type: object - x-speakeasy-name-override: DigestPreference - c1.api.settings.v1.EmailChannelSettings: - description: The EmailChannelSettings message. + x-speakeasy-name-override: GetCustomAnalysisResultResponse + c1.api.role_mining_management.v1.GetLatestRunResponse: + description: The GetLatestRunResponse message. properties: - accessProvisioned: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - - type: "null" - approvalNeeded: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - - type: "null" - commentOnRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - - type: "null" - completion: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - - type: "null" - connectorIssues: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - - type: "null" - digest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - - type: "null" - enabled: - description: The enabled field. - type: boolean - expiringAccess: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - - type: "null" - provisioningRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - - type: "null" - reviews: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - - type: "null" - taskReminders: + run: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' - type: "null" - title: Email Channel Settings - type: object - x-speakeasy-name-override: EmailChannelSettings - c1.api.settings.v1.ExpiringAccessPreference: - description: The ExpiringAccessPreference message. - properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Expiring Access Preference + title: Get Latest Run Response type: object - x-speakeasy-name-override: ExpiringAccessPreference - c1.api.settings.v1.GetAWSExternalIDResponse: - description: The GetAWSExternalIDResponse message. + x-speakeasy-name-override: GetLatestRunResponse + c1.api.role_mining_management.v1.GetRoleMiningConfigResponse: + description: The GetRoleMiningConfigResponse message. properties: - awsExternalId: + config: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.AWSExternalID' + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' - type: "null" - title: Get Aws External Id Response + title: Get Role Mining Config Response type: object - x-speakeasy-name-override: GetAWSExternalIDResponse - c1.api.settings.v1.GetContactsResponse: - description: The GetContactsResponse message. + x-speakeasy-name-override: GetRoleMiningConfigResponse + c1.api.role_mining_management.v1.GetSuggestionResponse: + description: The GetSuggestionResponse message. properties: - contacts: + suggestion: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - type: "null" - title: Get Contacts Response + title: Get Suggestion Response type: object - x-speakeasy-name-override: GetContactsResponse - c1.api.settings.v1.GetEmailCapabilitiesResponse: - description: The GetEmailCapabilitiesResponse message. + x-speakeasy-name-override: GetSuggestionResponse + c1.api.role_mining_management.v1.ListCustomAnalysisResultsResponse: + description: The ListCustomAnalysisResultsResponse message. properties: - externalEmailSupported: - description: |- - True when external email addresses (outside C1 users) can be used as - recipients in automation email steps. False when only the C1 built-in - provider is configured (C1 users only). - type: boolean - title: Get Email Capabilities Response + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CustomAnalysisResultView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: List Custom Analysis Results Response type: object - x-speakeasy-name-override: GetEmailCapabilitiesResponse - c1.api.settings.v1.GetOnboardingSettingsResponse: - description: The GetOnboardingSettingsResponse message. + x-speakeasy-name-override: ListCustomAnalysisResultsResponse + c1.api.role_mining_management.v1.ListRunsResponse: + description: The ListRunsResponse message. properties: - conversationId: - description: The identifier of the onboarding conversation thread, if one is in progress. - type: string - intents: - description: The intents field. + list: + description: The list of role mining analysis runs. items: - type: string + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' type: - array - "null" - mcpOnboardingGoal: - description: The admin's free-form AIAM onboarding goal, captured at the Goals step. - type: string - mcpOnboardingStatus: - description: |- - The current status of the AIAM MCP onboarding briefing, tracked - independently of `status`. - enum: - - MCP_ONBOARDING_STATUS_UNSPECIFIED - - MCP_ONBOARDING_STATUS_NOT_STARTED - - MCP_ONBOARDING_STATUS_IN_PROGRESS - - MCP_ONBOARDING_STATUS_COMPLETE - - MCP_ONBOARDING_STATUS_DISMISSED + nextPageToken: + description: Token to retrieve the next page of results, empty if no more results. type: string - x-speakeasy-unknown-values: allow - mcpOnboardingTargets: - description: |- - Per-target progress of the AIAM briefing: the servers/apps the admin chose - to govern and how far each got. + title: List Runs Response + type: object + x-speakeasy-name-override: ListRunsResponse + c1.api.role_mining_management.v1.ListSuggestionsResponse: + description: The ListSuggestionsResponse message. + properties: + list: + description: The list of role mining suggestions. items: - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' type: - array - "null" - orgContext: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.OnboardingOrgContext' - - type: "null" - status: - description: The current status of the tenant onboarding process. - enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED - type: string - x-speakeasy-unknown-values: allow - title: Get Onboarding Settings Response - type: object - x-speakeasy-name-override: GetOnboardingSettingsResponse - c1.api.settings.v1.GetOrgNotificationSettingsResponse: - description: The GetOrgNotificationSettingsResponse message. - properties: - orgNotificationSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' - - type: "null" - title: Get Org Notification Settings Response - type: object - x-speakeasy-name-override: GetOrgNotificationSettingsResponse - c1.api.settings.v1.GetRequestSettingsResponse: - description: The GetRequestSettingsResponse message. - properties: - requestSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' - - type: "null" - title: Get Request Settings Response - type: object - x-speakeasy-name-override: GetRequestSettingsResponse - c1.api.settings.v1.GetSessionSettingsResponse: - description: The GetSessionSettingsResponse message. - properties: - sessionSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - - type: "null" - title: Get Session Settings Response - type: object - x-speakeasy-name-override: GetSessionSettingsResponse - c1.api.settings.v1.GetTenantEmailProviderResponse: - description: The GetTenantEmailProviderResponse message. - properties: - emailProvider: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - - type: "null" - title: Get Tenant Email Provider Response - type: object - x-speakeasy-name-override: GetTenantEmailProviderResponse - c1.api.settings.v1.GetUserDeveloperPreferencesResponse: - description: The GetUserDeveloperPreferencesResponse message. - properties: - userDeveloperPreferences: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' - - type: "null" - title: Get User Developer Preferences Response - type: object - x-speakeasy-name-override: GetUserDeveloperPreferencesResponse - c1.api.settings.v1.GetUserNotificationSettingsResponse: - description: The GetUserNotificationSettingsResponse message. - properties: - userNotificationSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' - - type: "null" - title: Get User Notification Settings Response - type: object - x-speakeasy-name-override: GetUserNotificationSettingsResponse - c1.api.settings.v1.GoogleWorkspaceProviderConfig: - description: |- - GoogleWorkspaceProviderConfig configures sending via Google Workspace Gmail API - using domain-wide delegation with a service account. - Requires: customer Workspace super admin grants DWD to the service account's - OAuth client ID for the gmail.send scope. - properties: - delegatedUser: - description: |- - The Workspace user email to impersonate via domain-wide delegation. - Typically a dedicated sender like noreply@customer.com. - type: string - serviceAccountJson: - description: |- - Service account JSON credentials. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing credentials". + nextPageToken: + description: Token to retrieve the next page of results, empty if no more results. type: string - title: Google Workspace Provider Config + title: List Suggestions Response type: object - x-speakeasy-name-override: GoogleWorkspaceProviderConfig - c1.api.settings.v1.ListOrgDomainsResponse: - description: The ListOrgDomainsResponse message. + x-speakeasy-name-override: ListSuggestionsResponse + c1.api.role_mining_management.v1.RoleMiningManagementConfig: + description: The RoleMiningManagementConfig message. properties: - list: - description: The list of verified domains. + cohortHints: + description: Configured cohort hints that guide which user attributes the analysis prioritizes. items: - $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintView' type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - type: string - title: List Org Domains Response - type: object - x-speakeasy-name-override: ListOrgDomainsResponse - c1.api.settings.v1.MSTeamsChannelSettings: - description: The MSTeamsChannelSettings message. - properties: - accessProvisioned: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - - type: "null" - approvalNeeded: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - - type: "null" - commentOnRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - - type: "null" - completion: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - - type: "null" - connectorIssues: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - - type: "null" - digest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - - type: "null" - enabled: - description: The enabled field. - type: boolean - expiringAccess: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - - type: "null" - isConfigured: - description: The isConfigured field. - type: boolean - provisioningRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - - type: "null" - reviews: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - - type: "null" - taskReminders: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' - - type: "null" - title: Ms Teams Channel Settings + maxSuggestions: + description: Maximum number of suggestions the analysis will produce per run. + format: int32 + type: integer + minCohortSize: + description: Minimum number of users a cohort must contain to generate a suggestion. + format: int32 + type: integer + title: Role Mining Management Config type: object - x-speakeasy-name-override: MSTeamsChannelSettings - c1.api.settings.v1.McpOnboardingTarget: - description: |- - McpOnboardingTarget is one server/app the admin chose to govern during the - AIAM briefing, plus its progress. + x-speakeasy-name-override: RoleMiningManagementConfig + c1.api.role_mining_management.v1.RoleMiningManagementRun: + description: The RoleMiningManagementRun message. properties: - displayName: - description: Snapshot of the human label at selection time. + cohortsAnalyzed: + description: Number of user cohorts evaluated during the analysis. + format: int32 + type: integer + completedAt: + format: date-time + type: + - string + - "null" + createdAt: + format: date-time + type: + - string + - "null" + errorMessage: + description: Error message if the run failed, empty on success. type: string id: - description: Identifies the target within the id space named by kind. + description: Unique identifier for this analysis run. type: string - kind: - description: The kind field. + status: + description: Current execution status of this run (e.g., running, completed, failed). enum: - - MCP_ONBOARDING_TARGET_KIND_UNSPECIFIED - - MCP_ONBOARDING_TARGET_KIND_APP - - MCP_ONBOARDING_TARGET_KIND_CATALOG_ENTRY - - MCP_ONBOARDING_TARGET_KIND_MCP_SERVER + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED type: string x-speakeasy-unknown-values: allow - mcpServerId: - description: The registered MCP server a CATALOG_ENTRY target became, once registered. + suggestionsGenerated: + description: Number of role suggestions produced by this run. + format: int32 + type: integer + totalUsers: + description: Total number of users evaluated during the analysis. + format: int32 + type: integer + triggerDetail: + description: Additional detail about the trigger, such as the user or schedule that initiated the run. type: string - status: - description: The status field. + triggerType: + description: How this run was initiated (e.g., manual, scheduled). enum: - - MCP_ONBOARDING_TARGET_STATUS_UNSPECIFIED - - MCP_ONBOARDING_TARGET_STATUS_PENDING - - MCP_ONBOARDING_TARGET_STATUS_DONE - - MCP_ONBOARDING_TARGET_STATUS_SKIPPED + - TRIGGER_TYPE_UNSPECIFIED + - TRIGGER_TYPE_MANUAL + - TRIGGER_TYPE_UPLIFT_COMPLETION + - TRIGGER_TYPE_SCHEDULED + - TRIGGER_TYPE_DIRECTORY_MERGE type: string x-speakeasy-unknown-values: allow - title: Mcp Onboarding Target + updatedAt: + format: date-time + type: + - string + - "null" + title: Role Mining Management Run type: object - x-speakeasy-name-override: McpOnboardingTarget - c1.api.settings.v1.McpOnboardingTargetList: - description: |- - McpOnboardingTargetList wraps the target list so an update can distinguish - replace (present, even if empty) from leave-unchanged (omitted). + x-speakeasy-name-override: RoleMiningManagementRun + c1.api.role_mining_management.v1.RoleMiningManagementSuggestion: + description: The RoleMiningManagementSuggestion message. properties: - targets: - description: The targets field. + avgCoverage: + description: Average fraction of suggested entitlements held by each user in the cohort. + type: number + cohortFilters: + description: The profile filters that define which users belong to this cohort. items: - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' type: - array - "null" - title: Mcp Onboarding Target List - type: object - x-speakeasy-name-override: McpOnboardingTargetList - c1.api.settings.v1.MicrosoftGraphProviderConfig: - description: |- - MicrosoftGraphProviderConfig configures sending via Microsoft Graph sendMail API. - Requires an Azure AD app registration with Mail.Send application permission (admin-consented). - properties: - azureTenantId: - description: Customer's Azure AD tenant ID (directory ID). - type: string - clientId: - description: App registration client ID with Mail.Send application permission. - type: string - clientSecret: - description: |- - Client secret. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing secret". - type: string - title: Microsoft Graph Provider Config - type: object - x-speakeasy-name-override: MicrosoftGraphProviderConfig - c1.api.settings.v1.OnboardingOrgContext: - description: The OnboardingOrgContext message. - properties: - industry: - description: The industry field. - type: string - organizationSize: - description: The organizationSize field. - type: string - title: Onboarding Org Context - type: object - x-speakeasy-name-override: OnboardingOrgContext - c1.api.settings.v1.OrgDomain: - description: OrgDomain represents a verified email domain associated with the tenant. - properties: + cohortSize: + description: Total number of users in the cohort matching the profile filters. + format: int32 + type: integer + confidence: + description: Overall confidence score for this suggestion, from 0.0 to 1.0. + type: number createdAt: format: date-time - readOnly: true type: - string - "null" - deletedAt: + createdCatalogId: + description: The ID of the access profile created when this suggestion was accepted, empty if not yet accepted. + type: string + description: + description: A human-readable description of the proposed role and the cohort it serves. + type: string + dimensionCount: + description: Number of distinct attribute dimensions used to define the cohort. + format: int32 + type: integer + entitlements: + description: The entitlements that are commonly held by users in this cohort. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + existingProfileMatches: + description: Existing access profiles that overlap with this suggestion. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AccessProfileMatch' + type: + - array + - "null" + id: + description: Unique identifier for this suggestion. + type: string + insights: + description: Human-readable insights explaining why this role was suggested. + items: + type: string + type: + - array + - "null" + lastGeneratedAt: format: date-time - readOnly: true type: - string - "null" - domain: - description: The verified domain name (e.g., "example.com"). + runId: + description: The ID of the analysis run that produced this suggestion. type: string - id: - description: The unique identifier of the domain record. + suggestedName: + description: The suggested display name for the proposed role. + type: string + suggestionState: + description: Current workflow state of this suggestion (e.g., pending, accepted, dismissed). + enum: + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED type: string + x-speakeasy-unknown-values: allow updatedAt: format: date-time - readOnly: true type: - string - "null" - title: Org Domain - type: object - x-speakeasy-name-override: OrgDomain - c1.api.settings.v1.OrgNotificationSettings: - description: OrgNotificationSettings contains organization-wide notification channel configurations and default preferences. - properties: - channelSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - - type: "null" - title: Org Notification Settings - type: object - x-speakeasy-name-override: OrgNotificationSettings - c1.api.settings.v1.ProvisioningRequestPreference: - description: The ProvisioningRequestPreference message. - properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Provisioning Request Preference - type: object - x-speakeasy-name-override: ProvisioningRequestPreference - c1.api.settings.v1.RequestSettings: - description: RequestSettings holds tenant-wide configuration for the access-request flow. - properties: - skipJustification: - description: |- - When true, request surfaces (webapp, Slack, MS Teams) skip prompting the - requester for a justification. - type: boolean - title: Request Settings - type: object - x-speakeasy-name-override: RequestSettings - c1.api.settings.v1.ReviewsPreference: - description: The ReviewsPreference message. - properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Reviews Preference + usersWithAll: + description: Number of users in the cohort that hold all of the suggested entitlements. + format: int32 + type: integer + title: Role Mining Management Suggestion type: object - x-speakeasy-name-override: ReviewsPreference - c1.api.settings.v1.SearchEmailAuditEventsRequest: - description: The SearchEmailAuditEventsRequest message. + x-speakeasy-name-override: RoleMiningManagementSuggestion + c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest: + description: The RoleMiningSearchSuggestionsRequest message. properties: + cohortTypes: + description: Filter by cohort type (e.g. "department", "job_title", "manager"). + items: + type: string + type: + - array + - "null" + matchTypes: + description: Filter by match type against existing access profiles. + items: + enum: + - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED + - ACCESS_PROFILE_MATCH_TYPE_EXACT + - ACCESS_PROFILE_MATCH_TYPE_SUPERSET + - ACCESS_PROFILE_MATCH_TYPE_PARTIAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" pageSize: - description: Maximum results per page (0 = server default, max 100). + description: Maximum number of suggestions to return per page. format: int32 type: integer pageToken: - description: Pagination token from previous response. + description: Pagination token from a previous response. type: string - title: Search Email Audit Events Request + query: + description: Text search — matches against suggested_name, description, and cohort filter values. + type: string + states: + description: Filter by suggestion state. + items: + enum: + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Role Mining Search Suggestions Request type: object - x-speakeasy-name-override: SearchEmailAuditEventsRequest - c1.api.settings.v1.SearchEmailAuditEventsResponse: - description: The SearchEmailAuditEventsResponse message. + x-speakeasy-name-override: RoleMiningSearchSuggestionsRequest + c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse: + description: The RoleMiningSearchSuggestionsResponse message. properties: list: - description: OCSF EmailActivity events as Struct for frontend rendering. + description: The list of matching role mining suggestions. items: - additionalProperties: true - type: object + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' type: - array - "null" nextPageToken: - description: Token for next page. Empty when no more pages. + description: Token to retrieve the next page of results, empty if no more results. type: string - title: Search Email Audit Events Response + title: Role Mining Search Suggestions Response type: object - x-speakeasy-name-override: SearchEmailAuditEventsResponse - c1.api.settings.v1.SendGridProviderConfig: - description: SendGridProviderConfig configures sending via a customer's SendGrid account. + x-speakeasy-name-override: RoleMiningSearchSuggestionsResponse + c1.api.role_mining_management.v1.SearchCohortUsersRequestInput: + description: The SearchCohortUsersRequest message. properties: - apiKey: - description: |- - Customer's SendGrid API key. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing key". + pageSize: + description: Maximum number of users to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response. type: string - title: Send Grid Provider Config + profileFilters: + description: Additional profile filters to narrow the cohort user search. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + selectedEntitlements: + deprecated: true + description: |- + Deprecated. This endpoint no longer computes per-user coverage and + ignores this field. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EntitlementRef' + type: + - array + - "null" + title: Search Cohort Users Request type: object - x-speakeasy-name-override: SendGridProviderConfig - c1.api.settings.v1.SessionSettings: - description: SessionSettings configures session security for the tenant, including timeouts and per-role IP restrictions. + x-speakeasy-name-override: SearchCohortUsersRequest + c1.api.role_mining_management.v1.SearchCohortUsersResponse: + description: The SearchCohortUsersResponse message. properties: - clientIdApprovalRequestPolicyId: - description: Policy ID for REQUESTABLE mode approval routing. - type: string - clientIdMetadataDocumentPolicy: - description: Policy for metadata document client_id URLs. - enum: - - CLIENT_ID_METADATA_DOCUMENT_POLICY_UNSPECIFIED - - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOW_ALL - - CLIENT_ID_METADATA_DOCUMENT_POLICY_REQUESTABLE - - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOWLIST_ONLY + list: + description: The list of users matching the cohort and optional filters. + items: + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty if no more results. type: string - x-speakeasy-unknown-values: allow - connectorSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - externalClientSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - externalClientsEnabled: + usersWithCoverage: + deprecated: true description: |- - Enable external client registration (OAuth 2.0 DCR) for MCP clients - like Claude Desktop, Cursor, and other AI assistants. - type: boolean - maxSessionLength: - format: duration + Deprecated. This endpoint no longer computes per-user coverage; this + list is always empty. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortUserWithCoverage' type: - - string + - array - "null" - pccAdminSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - pccUserSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - ssoAdminSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - ssoUserSource: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - - type: "null" - title: Session Settings + title: Search Cohort Users Response type: object - x-speakeasy-name-override: SessionSettings - c1.api.settings.v1.SlackChannelSettings: - description: The SlackChannelSettings message. - properties: - accessProvisioned: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - - type: "null" - approvalNeeded: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - - type: "null" - commentOnRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - - type: "null" - completion: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - - type: "null" - connectorIssues: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - - type: "null" - digest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - - type: "null" - enabled: - description: The enabled field. - type: boolean - expiringAccess: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - - type: "null" - isConfigured: - description: The isConfigured field. - type: boolean - provisioningRequest: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - - type: "null" - reviews: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - - type: "null" - taskReminders: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' - - type: "null" - title: Slack Channel Settings + x-speakeasy-name-override: SearchCohortUsersResponse + c1.api.role_mining_management.v1.TriggerAnalysisRequest: + description: The TriggerAnalysisRequest message. + title: Trigger Analysis Request type: object - x-speakeasy-name-override: SlackChannelSettings - c1.api.settings.v1.TaskRemindersPreference: - description: The TaskRemindersPreference message. + x-speakeasy-name-override: TriggerAnalysisRequest + c1.api.role_mining_management.v1.TriggerAnalysisResponse: + description: The TriggerAnalysisResponse message. properties: - enabled: - description: The enabled field. - type: boolean - locked: - description: The locked field. - type: boolean - title: Task Reminders Preference + runId: + description: The ID of the newly created analysis run. + type: string + title: Trigger Analysis Response type: object - x-speakeasy-name-override: TaskRemindersPreference - c1.api.settings.v1.TenantEmailProvider: - description: | - TenantEmailProvider is the API representation of the tenant's email provider. - - This message contains a oneof named provider. Only a single field of the following list may be set at a time: - - c1Builtin - - awsSes - - sendgrid - - microsoftGraph - - googleWorkspace + x-speakeasy-name-override: TriggerAnalysisResponse + c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest: + description: The TriggerCustomAnalysisRequest message. properties: - awsSes: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.AWSSESProviderConfig' - - type: "null" - c1Builtin: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.C1BuiltInProviderConfig' - - type: "null" - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - fromAddress: - description: |- - Sender email address. Must be verified with the provider. - Ignored when using the C1 built-in provider (uses no-reply@conductorone.com). - type: string - fromName: - description: |- - Sender display name shown in the recipient's inbox (e.g., "Acme Corp IT"). - Used as the RFC 5322 display-name: "Acme Corp IT" . - Ignored when using the C1 built-in provider. - type: string - googleWorkspace: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.GoogleWorkspaceProviderConfig' - - type: "null" - microsoftGraph: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.MicrosoftGraphProviderConfig' - - type: "null" - replyToAddress: - description: Optional reply-to address. - type: string - sendgrid: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.SendGridProviderConfig' - - type: "null" - updatedAt: - format: date-time - readOnly: true + profileFilters: + description: The profileFilters field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' type: - - string + - array - "null" - title: Tenant Email Provider + title: Trigger Custom Analysis Request type: object - x-speakeasy-name-override: TenantEmailProvider - c1.api.settings.v1.TerraformPreferences: - description: |- - TerraformPreferences groups the user's preferences for the "Show - Terraform code" feature. + x-speakeasy-name-override: TriggerCustomAnalysisRequest + c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse: + description: The TriggerCustomAnalysisResponse message. properties: - showCode: - description: |- - When true, the user sees the "Show Terraform code" trigger on - supported detail pages and list rows. Defaults to false. - - Visibility is also role-gated: the trigger is shown only to users - with one of the SystemOwner, SystemOwnerReadOnly, IntegrationAdmin, - ApplicationAdmin, CampaignAdmin, or AccessRequestAdmin roles. Users - without one of these roles will not see the trigger even when this - flag is true. - type: boolean - title: Terraform Preferences + id: + description: The id field. + type: string + title: Trigger Custom Analysis Response type: object - x-speakeasy-name-override: TerraformPreferences - c1.api.settings.v1.TestSourceIPRequest: - description: The TestSourceIPRequest message. + x-speakeasy-name-override: TriggerCustomAnalysisResponse + c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest: + description: The UpdateRoleMiningConfigRequest message. properties: - allowCidr: - description: |- - The CIDR allowlist rules to test against. If empty, uses the tenant's current allowlist. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + cohortHints: + description: Hints that guide the analysis to prioritize specific user attributes and values when forming cohorts. items: - type: string + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintInput' type: - array - "null" - sourceIp: - description: |- - if unset, uses the source IP of the request. - Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. - type: string - title: Test Source Ip Request + maxSuggestions: + description: Maximum number of suggestions the analysis should produce per run. + format: int32 + type: integer + minCohortSize: + description: Minimum number of users a cohort must contain to generate a suggestion. + format: int32 + type: integer + title: Update Role Mining Config Request type: object - x-speakeasy-name-override: TestSourceIPRequest - c1.api.settings.v1.TestSourceIPResponse: - description: The TestSourceIPResponse message. + x-speakeasy-name-override: UpdateRoleMiningConfigRequest + c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse: + description: The UpdateRoleMiningConfigResponse message. properties: - allowed: - description: Whether the tested IP address is allowed by the CIDR rules. - type: boolean - checkedIp: - description: The IP address that was checked, either from the request or inferred from the caller. - type: string - details: + config: oneOf: - - $ref: '#/components/schemas/google.rpc.Status' + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' - type: "null" - title: Test Source Ip Response + title: Update Role Mining Config Response type: object - x-speakeasy-name-override: TestSourceIPResponse - c1.api.settings.v1.TestTenantEmailProviderRequest: - description: The TestTenantEmailProviderRequest message. + x-speakeasy-name-override: UpdateRoleMiningConfigResponse + c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput: + description: The UpdateSuggestionStateRequest message. properties: - testRecipientEmail: - description: The email address to send the test email to. + createdCatalogId: + description: The ID of the access profile created from this suggestion, set when accepting. type: string - title: Test Tenant Email Provider Request - type: object - x-speakeasy-name-override: TestTenantEmailProviderRequest - c1.api.settings.v1.TestTenantEmailProviderResponse: - description: The TestTenantEmailProviderResponse message. - properties: - message: - description: Human-readable detail about the result. + state: + description: The new state to transition the suggestion to. + enum: + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED type: string - success: - description: Whether the test email was sent successfully. - type: boolean - title: Test Tenant Email Provider Response + x-speakeasy-unknown-values: allow + title: Update Suggestion State Request type: object - x-speakeasy-name-override: TestTenantEmailProviderResponse - c1.api.settings.v1.UpdateContactsRequest: - description: The UpdateContactsRequest message. + x-speakeasy-name-override: UpdateSuggestionStateRequest + c1.api.role_mining_management.v1.UpdateSuggestionStateResponse: + description: The UpdateSuggestionStateResponse message. properties: - contacts: + suggestion: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - type: "null" - updateMask: - type: - - string - - "null" - title: Update Contacts Request + title: Update Suggestion State Response type: object - x-speakeasy-name-override: UpdateContactsRequest - c1.api.settings.v1.UpdateContactsResponse: - description: The UpdateContactsResponse message. + x-speakeasy-name-override: UpdateSuggestionStateResponse + c1.api.search.v1.FacetCategory: + description: | + The FacetCategory indicates a grouping of facets by type. For example, facets "OnePassword" and "Okta" would group under an "Apps" category. + + This message contains a oneof named item. Only a single field of the following list may be set at a time: + - value + - range properties: - contacts: + displayName: + description: The display name of the category. + type: string + iconUrl: + description: An icon for the category. + type: string + param: + description: The param that is being set when checking a facet in this category. + type: string + range: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - $ref: '#/components/schemas/c1.api.search.v1.FacetRangeItem' - type: "null" - title: Update Contacts Response - type: object - x-speakeasy-name-override: UpdateContactsResponse - c1.api.settings.v1.UpdateOnboardingSettingsRequest: - description: The UpdateOnboardingSettingsRequest message. - properties: - conversationId: - description: The identifier of the onboarding conversation thread to associate. - type: string - mcpOnboardingGoal: - description: The admin's AIAM onboarding goal. Omit to leave unchanged; set to "" to clear. - type: - - string - - "null" - mcpOnboardingStatus: - description: |- - The new MCP onboarding status to set. Omit (or UNSPECIFIED) to leave it - unchanged. Setting NOT_STARTED restarts the briefing and clears the stored - mcp_onboarding_goal and mcp_onboarding_targets, unless this same request also - sets them (those win). - enum: - - MCP_ONBOARDING_STATUS_UNSPECIFIED - - MCP_ONBOARDING_STATUS_NOT_STARTED - - MCP_ONBOARDING_STATUS_IN_PROGRESS - - MCP_ONBOARDING_STATUS_COMPLETE - - MCP_ONBOARDING_STATUS_DISMISSED - type: - - string - - "null" - x-speakeasy-unknown-values: allow - mcpOnboardingTargets: + value: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTargetList' + - $ref: '#/components/schemas/c1.api.search.v1.FacetValueItem' - type: "null" - status: - description: |- - The new onboarding status to set. UNSPECIFIED leaves the core onboarding - status unchanged (set mcp_onboarding_status alone to retire the AIAM - briefing without touching the core wizard). - enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED - type: string - x-speakeasy-unknown-values: allow - title: Update Onboarding Settings Request + title: Facet Category type: object - x-speakeasy-name-override: UpdateOnboardingSettingsRequest - c1.api.settings.v1.UpdateOnboardingSettingsResponse: - description: The UpdateOnboardingSettingsResponse message. + x-speakeasy-name-override: FacetCategory + c1.api.search.v1.FacetRange: + description: The FacetRange message. properties: - mcpOnboardingGoal: - description: The updated AIAM onboarding goal. + count: + description: The count of items in the range. + format: int64 type: string - mcpOnboardingStatus: - description: The updated AIAM MCP onboarding status. - enum: - - MCP_ONBOARDING_STATUS_UNSPECIFIED - - MCP_ONBOARDING_STATUS_NOT_STARTED - - MCP_ONBOARDING_STATUS_IN_PROGRESS - - MCP_ONBOARDING_STATUS_COMPLETE - - MCP_ONBOARDING_STATUS_DISMISSED + displayName: + description: The display name of the range. type: string - x-speakeasy-unknown-values: allow - mcpOnboardingTargets: - description: The updated AIAM onboarding targets. + from: + description: The starting value of the range. + format: int64 + type: string + iconUrl: + description: The icon of the range. + type: string + to: + description: The ending value of the range. + format: int64 + type: string + title: Facet Range + type: object + x-speakeasy-name-override: FacetRange + c1.api.search.v1.FacetRangeItem: + description: The FacetRangeItem message. + properties: + ranges: + description: An array of facet ranges. items: - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + $ref: '#/components/schemas/c1.api.search.v1.FacetRange' type: - array - "null" - status: - description: The updated onboarding status. - enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED + title: Facet Range Item + type: object + x-speakeasy-name-override: FacetRangeItem + c1.api.search.v1.FacetValue: + description: A FacetValue message contains count and value of the facet entry. + properties: + count: + description: The count of the values in this facet. + format: int64 type: string - x-speakeasy-unknown-values: allow - title: Update Onboarding Settings Response + displayName: + description: The name of this facet. + type: string + iconUrl: + description: The icon for this facet. + type: string + value: + description: The value of this facet. + type: string + title: Facet Value type: object - x-speakeasy-name-override: UpdateOnboardingSettingsResponse - c1.api.settings.v1.UpdateOrgDomainRequest: - description: The UpdateOrgDomainRequest message. + x-speakeasy-name-override: FacetValue + c1.api.search.v1.FacetValueItem: + description: The FacetValueItem message. properties: - newDomains: - description: The complete list of domain names that should be set as the tenant's verified domains. + values: + description: An array of facet values. items: - type: string + $ref: '#/components/schemas/c1.api.search.v1.FacetValue' type: - array - "null" - title: Update Org Domain Request + title: Facet Value Item type: object - x-speakeasy-name-override: UpdateOrgDomainRequest - c1.api.settings.v1.UpdateOrgDomainResponse: - description: The UpdateOrgDomainResponse message. + x-speakeasy-name-override: FacetValueItem + c1.api.search.v1.Facets: + description: Indicates one value of a facet. properties: - list: - description: The resulting list of verified domains after the update. + count: + description: The count of items in this facet. + format: int64 + type: string + facets: + description: The facet being referenced. items: - $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' + $ref: '#/components/schemas/c1.api.search.v1.FacetCategory' type: - array - "null" - title: Update Org Domain Response + title: Facets type: object - x-speakeasy-name-override: UpdateOrgDomainResponse - c1.api.settings.v1.UpdateOrgNotificationSettingsRequest: - description: The UpdateOrgNotificationSettingsRequest message. + x-speakeasy-name-override: Facets + c1.api.secrets.v1.PaperSecret: + description: |- + PaperSecret is the API view of a secret (combines Vault + PaperVault fields). + The vault_id is the primary identifier (Vault.id). properties: - channelSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - - type: "null" - title: Update Org Notification Settings Request - type: object - x-speakeasy-name-override: UpdateOrgNotificationSettingsRequest - c1.api.settings.v1.UpdateOrgNotificationSettingsResponse: - description: The UpdateOrgNotificationSettingsResponse message. - properties: - orgNotificationSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' - - type: "null" - title: Update Org Notification Settings Response - type: object - x-speakeasy-name-override: UpdateOrgNotificationSettingsResponse - c1.api.settings.v1.UpdateRequestSettingsRequest: - description: The UpdateRequestSettingsRequest message. - properties: - requestSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' - - type: "null" - updateMask: + ageSuite: + description: Exact Age suite used by the stored ciphertext. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + allowedEmails: + description: The allowedEmails field. + items: + type: string + type: + - array + - "null" + allowedUserIds: + description: Access control + items: + type: string + type: + - array + - "null" + contentDeleted: + description: The contentDeleted field. + type: boolean + contentExpiresAt: + format: date-time type: - string - "null" - title: Update Request Settings Request - type: object - x-speakeasy-name-override: UpdateRequestSettingsRequest - c1.api.settings.v1.UpdateRequestSettingsResponse: - description: The UpdateRequestSettingsResponse message. - properties: - requestSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' - - type: "null" - title: Update Request Settings Response - type: object - x-speakeasy-name-override: UpdateRequestSettingsResponse - c1.api.settings.v1.UpdateSessionSettingsRequest: - description: The UpdateSessionSettingsRequest message. - properties: - sessionSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - - type: "null" - updateMask: + contentReady: + description: Whether content has been set (text uploaded or file uploaded) + type: boolean + contentType: + description: The contentType field. + type: string + createdAt: + format: date-time + readOnly: true type: - string - "null" - title: Update Session Settings Request - type: object - x-speakeasy-name-override: UpdateSessionSettingsRequest - c1.api.settings.v1.UpdateSessionSettingsResponse: - description: The UpdateSessionSettingsResponse message. - properties: - sessionSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - - type: "null" - title: Update Session Settings Response - type: object - x-speakeasy-name-override: UpdateSessionSettingsResponse - c1.api.settings.v1.UpdateTenantEmailProviderRequest: - description: The UpdateTenantEmailProviderRequest message. - properties: - emailProvider: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - - type: "null" - updateMask: + creatorUserId: + description: Creator + type: string + currentViews: + description: The currentViews field. + format: uint32 + type: integer + deletedAt: + format: date-time + readOnly: true type: - string - "null" - title: Update Tenant Email Provider Request - type: object - x-speakeasy-name-override: UpdateTenantEmailProviderRequest - c1.api.settings.v1.UpdateTenantEmailProviderResponse: - description: The UpdateTenantEmailProviderResponse message. - properties: - emailProvider: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - - type: "null" - title: Update Tenant Email Provider Response - type: object - x-speakeasy-name-override: UpdateTenantEmailProviderResponse - c1.api.settings.v1.UpdateUserDeveloperPreferencesRequest: - description: The UpdateUserDeveloperPreferencesRequest message. - properties: - terraform: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' - - type: "null" - title: Update User Developer Preferences Request - type: object - x-speakeasy-name-override: UpdateUserDeveloperPreferencesRequest - c1.api.settings.v1.UpdateUserDeveloperPreferencesResponse: - description: The UpdateUserDeveloperPreferencesResponse message. - properties: - userDeveloperPreferences: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' - - type: "null" - title: Update User Developer Preferences Response - type: object - x-speakeasy-name-override: UpdateUserDeveloperPreferencesResponse - c1.api.settings.v1.UpdateUserNotificationSettingsRequest: - description: The UpdateUserNotificationSettingsRequest message. - properties: - channelSettings: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - - type: "null" - title: Update User Notification Settings Request + displayName: + description: From Vault + type: string + fileSize: + description: File metadata + format: int64 + type: string + filename: + description: 'For FILE secrets: original filename (sanitized)' + type: string + inputFormat: + description: The inputFormat field. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + maxViews: + description: View tracking + format: uint32 + type: integer + secretType: + description: The secretType field. + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + shareCode: + description: Human-friendly share code (XXXX-XXXX-XXXX) for shareable URLs + type: string + shareUrl: + description: URL to share with recipients (populated when content_ready is true) + type: string + sharingMode: + description: From PaperVault + enum: + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + status: + description: Computed status + enum: + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + vaultId: + description: Vault.id - primary identifier for the secret + type: string + title: Paper Secret type: object - x-speakeasy-name-override: UpdateUserNotificationSettingsRequest - c1.api.settings.v1.UpdateUserNotificationSettingsResponse: - description: The UpdateUserNotificationSettingsResponse message. + x-speakeasy-name-override: PaperSecret + c1.api.secrets.v1.PaperSecretAdminServiceGetResponse: + description: The PaperSecretAdminServiceGetResponse message. properties: - userNotificationSettings: + secret: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - type: "null" - title: Update User Notification Settings Response + title: Paper Secret Admin Service Get Response type: object - x-speakeasy-name-override: UpdateUserNotificationSettingsResponse - c1.api.settings.v1.UserDeveloperPreferences: - description: |- - UserDeveloperPreferences holds a user's developer-tooling preferences, - organized into per-feature clusters. - properties: - terraform: - oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' - - type: "null" - title: User Developer Preferences + x-speakeasy-name-override: PaperSecretAdminServiceGetResponse + c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput: + description: The PaperSecretAdminServiceRevokeRequest message. + title: Paper Secret Admin Service Revoke Request type: object - x-speakeasy-name-override: UserDeveloperPreferences - c1.api.settings.v1.UserNotificationSettings: - description: UserNotificationSettings contains the calling user's personal notification preferences. + x-speakeasy-name-override: PaperSecretAdminServiceRevokeRequest + c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse: + description: The PaperSecretAdminServiceRevokeResponse message. properties: - channelSettings: + secret: oneOf: - - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - type: "null" - title: User Notification Settings + title: Paper Secret Admin Service Revoke Response type: object - x-speakeasy-name-override: UserNotificationSettings - c1.api.sign_in_policy.v1.Allow: - description: Allow permits the sign-in. + x-speakeasy-name-override: PaperSecretAdminServiceRevokeResponse + c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest: + description: The PaperSecretAdminServiceSearchAuditEventsRequest message. properties: - floorLevel: - description: |- - The minimum assurance level that satisfies this rule. Required on enforced - Allow rules. - enum: - - AUTH_LEVEL_UNSPECIFIED - - AUTH_LEVEL_NONE - - AUTH_LEVEL_SINGLE_FACTOR - - AUTH_LEVEL_MULTI_FACTOR - - AUTH_LEVEL_PHR - - AUTH_LEVEL_PHRH + actorEmail: + description: Filter by external email (partial match via full-text search) type: string - x-speakeasy-unknown-values: allow - title: Allow + actorUserId: + description: Filter by C1 user ID (internal users) + type: string + clientIp: + description: Filter by client IP (exact match) + type: string + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + vaultId: + description: Filter by specific vault + type: string + title: Paper Secret Admin Service Search Audit Events Request type: object - x-speakeasy-name-override: Allow - c1.api.sign_in_policy.v1.ChallengeRequired: - description: ChallengeRequired asks for an additional factor before the sign-in completes. + x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsRequest + c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse: + description: The PaperSecretAdminServiceSearchAuditEventsResponse message. properties: - types: - description: The credential types that may satisfy the challenge. + list: + description: |- + List contains OCSF events directly as JSON structs. + Follows the same pattern as SystemLogServiceListEventsResponse. items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + additionalProperties: true + type: object type: - array - "null" - title: Challenge Required - type: object - x-speakeasy-name-override: ChallengeRequired - c1.api.sign_in_policy.v1.Deny: - description: Deny rejects the sign-in. - properties: - reasonAdmin: - description: Reason shown in admin-only audit. - type: string - reasonUser: - description: Reason safe to show the end user. + nextPageToken: + description: The nextPageToken field. type: string - title: Deny + title: Paper Secret Admin Service Search Audit Events Response type: object - x-speakeasy-name-override: Deny - c1.api.sign_in_policy.v1.EnrollmentRequired: - description: EnrollmentRequired tells the user to enroll a credential before continuing. + x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsResponse + c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest: + description: Admin search request - can filter by any user's secrets. properties: - credentialTypes: - description: |- - The credential types the user may enroll. Empty means "complete identity - verification first". + createdAfter: + format: date-time + type: + - string + - "null" + createdBefore: + format: date-time + type: + - string + - "null" + creatorUserIds: + description: Filter by creator user ID (admin can see all users' secrets) items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - x-speakeasy-unknown-values: allow type: - array - "null" - title: Enrollment Required - type: object - x-speakeasy-name-override: EnrollmentRequired - c1.api.sign_in_policy.v1.PolicyOutcome: - description: | - PolicyOutcome is the effect of a matched rule. Exactly one kind is set. - - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - allow - - deny - - stepUpRequired - - challengeRequired - - enrollmentRequired - properties: - allow: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Allow' - - type: "null" - challengeRequired: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.ChallengeRequired' - - type: "null" - deny: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Deny' - - type: "null" - enrollmentRequired: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.EnrollmentRequired' - - type: "null" - stepUpRequired: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.StepUpRequired' - - type: "null" - title: Policy Outcome - type: object - x-speakeasy-name-override: PolicyOutcome - c1.api.sign_in_policy.v1.PolicyRule: - description: |- - PolicyRule is one rung of the ordered sign-in cascade. Rules are evaluated - top to bottom; the first enforced rule whose condition matches supplies the - outcome. - properties: - description: - description: A human-readable description shown in the admin UI. + includeDeleted: + description: Include deleted secrets + type: boolean + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - id: - description: A stable identifier for the rule, surfaced in audit. + query: + description: Fuzzy search by display name type: string - matchCel: - description: A boolean condition expression evaluated against the sign-in context. + secretType: + description: Filter by secret type (optional) + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE type: string - mode: - description: Whether the rule is live, evaluated-only, or skipped. + x-speakeasy-unknown-values: allow + sharingMode: + description: Filter by sharing mode (optional) enum: - - POLICY_RULE_MODE_UNSPECIFIED - - POLICY_RULE_MODE_ENFORCE - - POLICY_RULE_MODE_OBSERVE - - POLICY_RULE_MODE_DISABLED + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL type: string x-speakeasy-unknown-values: allow - outcome: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' - - type: "null" - title: Policy Rule - type: object - x-speakeasy-name-override: PolicyRule - c1.api.sign_in_policy.v1.SignInPolicy: - description: SignInPolicy defines how users sign in. - properties: - allowedMfaTypes: - description: |- - The credential types accepted as a second factor. Must be a subset of the - credential types their inventory policy permits. + sortBy: + description: Sort order + enum: + - SEARCH_SORT_BY_UNSPECIFIED + - SEARCH_SORT_BY_CREATED_DESC + - SEARCH_SORT_BY_CREATED_ASC + - SEARCH_SORT_BY_EXPIRES_ASC + - SEARCH_SORT_BY_NAME_ASC + type: string + x-speakeasy-unknown-values: allow + statuses: + description: Filter by status (optional) items: enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED type: string x-speakeasy-unknown-values: allow type: - array - "null" - allowedPrimaryTypes: - description: |- - The primary credential types users may sign in with. Must be a subset of - the credential types their inventory policy permits. + title: Paper Secret Admin Service Search Request + type: object + x-speakeasy-name-override: PaperSecretAdminServiceSearchRequest + c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse: + description: The PaperSecretAdminServiceSearchResponse message. + properties: + list: + description: The list field. items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' type: - array - "null" - createdAt: - format: date-time - readOnly: true - type: - - string + nextPageToken: + description: The nextPageToken field. + type: string + title: Paper Secret Admin Service Search Response + type: object + x-speakeasy-name-override: PaperSecretAdminServiceSearchResponse + c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest: + description: The PaperSecretServiceCreateExternalRequest message. + properties: + allowedEmails: + description: |- + External email addresses allowed to view this secret (1 to 64). + Recipients authenticate via email magic link or Google OAuth. + items: + type: string + type: + - array - "null" - defaultOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' - - type: "null" - deletedAt: - format: date-time - readOnly: true + contentType: + description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' + type: string + displayName: + description: |- + Optional cleartext label visible to the creator in "My Secrets" view. + Not encrypted — do not put sensitive data here. + type: string + expiresIn: + format: duration type: - string - "null" - displayName: - description: A human-readable name for the policy. + fileSize: + description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' + format: int64 type: string - id: - description: Unique identifier for the policy. - readOnly: true + filename: + description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' type: string - isBuiltin: - description: |- - True for built-in policies provided by ConductorOne. Built-in policies - cannot be edited or deleted. - readOnly: true - type: boolean - priority: + inputFormat: description: |- - When a user matches more than one policy, the policy with the highest - priority applies. - format: int32 + For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). + Used by the viewer UI for syntax highlighting. Does not affect encryption. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + maxViews: + description: Maximum number of views before the secret is burned (0 = unlimited). + format: uint32 type: integer - rules: - description: The ordered rule cascade, evaluated top to bottom. + requiredAgeSuite: + description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secretType: + description: |- + Secret type: TEXT or FILE. + TEXT secrets use SetTextContent to upload encrypted content (max 64KB). + FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + title: Paper Secret Service Create External Request + type: object + x-speakeasy-name-override: PaperSecretServiceCreateExternalRequest + c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest: + description: The PaperSecretServiceCreateInternalRequest message. + properties: + allowedUserIds: + description: C1 User IDs allowed to view this secret (1 to 128). items: - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + type: string type: - array - "null" - updatedAt: - format: date-time - readOnly: true + contentType: + description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' + type: string + displayName: + description: |- + Optional cleartext label visible to the creator in "My Secrets" view. + Not encrypted — do not put sensitive data here. + type: string + expiresIn: + format: duration type: - string - "null" - title: Sign In Policy + fileSize: + description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' + format: int64 + type: string + filename: + description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' + type: string + inputFormat: + description: |- + For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). + Used by the viewer UI for syntax highlighting. Does not affect encryption. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + maxViews: + description: Maximum number of views before the secret is burned (0 = unlimited). + format: uint32 + type: integer + requiredAgeSuite: + description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secretType: + description: |- + Secret type: TEXT or FILE. + TEXT secrets use SetTextContent to upload encrypted content (max 64KB). + FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + title: Paper Secret Service Create Internal Request type: object - x-speakeasy-entity: SignInPolicy - x-speakeasy-name-override: SignInPolicy - c1.api.sign_in_policy.v1.SignInPolicyRef: - description: SignInPolicyRef is a lightweight reference to a sign-in policy by ID. + x-speakeasy-name-override: PaperSecretServiceCreateInternalRequest + c1.api.secrets.v1.PaperSecretServiceCreateResponse: + description: The PaperSecretServiceCreateResponse message. properties: - id: - description: The id field. + ageRecipient: + description: |- + Canonical recipient public key for the exact age_suite returned below. + All content MUST be encrypted to this recipient using the Age encryption format + before calling SetTextContent or uploading to upload_url. + See: https://age-encryption.org type: string - title: Sign In Policy Ref + ageSuite: + description: Exact Age suite required for this submission. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + uploadUrl: + description: |- + For FILE secrets: capability URL for uploading the Age-encrypted file. + Send an HTTP PUT request with the Age-encrypted file bytes as the body + and Content-Type: application/octet-stream. The payload MUST begin with + the Age header "age-encryption.org/v1\n". Maximum file size: 1GB. + Empty for TEXT secrets. + type: string + vaultId: + description: Vault ID - primary identifier for this secret. + type: string + title: Paper Secret Service Create Response type: object - x-speakeasy-name-override: SignInPolicyRef - c1.api.sign_in_policy.v1.SignInPolicyServiceCreateRequest: - description: The SignInPolicyServiceCreateRequest message. + x-speakeasy-name-override: PaperSecretServiceCreateResponse + c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput: + description: The PaperSecretServiceGetContentRequest message. properties: - allowedMfaTypes: - description: The credential types accepted as a second factor. - items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + readerRecipient: + description: |- + Client's ephemeral Age recipient (age1...) for re-encryption + Server re-encrypts the content to this recipient + type: string + title: Paper Secret Service Get Content Request + type: object + x-speakeasy-name-override: PaperSecretServiceGetContentRequest + c1.api.secrets.v1.PaperSecretServiceGetContentResponse: + description: | + The PaperSecretServiceGetContentResponse message. + + This message contains a oneof named content. Only a single field of the following list may be set at a time: + - encryptedContent + - downloadUrl + properties: + createdAt: + format: date-time type: - - array + - string - "null" - allowedPrimaryTypes: - description: The primary credential types users may sign in with. - items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + creatorUserId: + description: The creatorUserId field. + type: string + downloadUrl: + description: |- + For file secrets: presigned S3 download URL (5 minute expiry) + File is still E2E encrypted - client must decrypt after download + This field is part of the `content` oneof. + See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. type: - - array + - string - "null" - defaultOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' - - type: "null" - displayName: - description: A human-readable name for the policy. - type: string - priority: + encryptedContent: description: |- - When a user matches more than one policy, the policy with the highest - priority applies. - format: int32 - type: integer - rules: - description: The ordered rule cascade. - items: - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + For text secrets: Age-encrypted content (encrypted to reader's recipient) + This field is part of the `content` oneof. + See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. + format: base64 type: - - array + - string - "null" - required: - - displayName - title: Sign In Policy Service Create Request + filename: + description: Original filename (file secrets only) + type: string + inputFormat: + description: Input format hint for rendering (text secrets only) + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + secretType: + description: Secret metadata + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + viewsRemaining: + description: Views remaining after this view (-1 = unlimited) + format: int32 + type: integer + title: Paper Secret Service Get Content Response type: object - x-speakeasy-entity: SignInPolicy - x-speakeasy-name-override: SignInPolicyServiceCreateRequest - c1.api.sign_in_policy.v1.SignInPolicyServiceCreateResponse: - description: The SignInPolicyServiceCreateResponse message. + x-speakeasy-name-override: PaperSecretServiceGetContentResponse + c1.api.secrets.v1.PaperSecretServiceGetResponse: + description: The PaperSecretServiceGetResponse message. properties: - signInPolicy: + secret: oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - type: "null" - title: Sign In Policy Service Create Response - type: object - x-speakeasy-name-override: SignInPolicyServiceCreateResponse - c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteRequestInput: - description: The SignInPolicyServiceDeleteRequest message. - title: Sign In Policy Service Delete Request + title: Paper Secret Service Get Response type: object - x-speakeasy-entity: SignInPolicy - x-speakeasy-name-override: SignInPolicyServiceDeleteRequest - c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteResponse: - description: The SignInPolicyServiceDeleteResponse message. - title: Sign In Policy Service Delete Response + x-speakeasy-name-override: PaperSecretServiceGetResponse + c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput: + description: The PaperSecretServiceRevokeRequest message. + title: Paper Secret Service Revoke Request type: object - x-speakeasy-name-override: SignInPolicyServiceDeleteResponse - c1.api.sign_in_policy.v1.SignInPolicyServiceGetResponse: - description: The SignInPolicyServiceGetResponse message. + x-speakeasy-name-override: PaperSecretServiceRevokeRequest + c1.api.secrets.v1.PaperSecretServiceRevokeResponse: + description: The PaperSecretServiceRevokeResponse message. properties: - signInPolicy: + secret: oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - type: "null" - title: Sign In Policy Service Get Response + title: Paper Secret Service Revoke Response type: object - x-speakeasy-name-override: SignInPolicyServiceGetResponse - c1.api.sign_in_policy.v1.SignInPolicyServiceListResponse: - description: The SignInPolicyServiceListResponse message. + x-speakeasy-name-override: PaperSecretServiceRevokeResponse + c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest: + description: |- + PaperSecretServiceSearchAuditEventsRequest searches audit events for a secret + owned by the calling user. Only the secret creator may query events. Results + are sanitized to include only time, event type, and actor information. + properties: + pageSize: + description: Maximum number of results per page (0 uses server default, max 100). + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response's next_page_token. + type: string + vaultId: + description: Required. The vault ID of the secret whose audit events to retrieve. + type: string + title: Paper Secret Service Search Audit Events Request + type: object + x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsRequest + c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse: + description: |- + PaperSecretServiceSearchAuditEventsResponse contains a page of audit events + for the requested secret. properties: list: - description: The page of policies. + description: |- + Sanitized OCSF events containing only time, event type, and actor fields. + Sensitive fields such as IP addresses, messages, and raw payloads are removed. items: - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + additionalProperties: true + type: object type: - array - "null" nextPageToken: - description: A token to fetch the next page, or empty if there are no more results. + description: Token to retrieve the next page of results. Empty when no more pages exist. type: string - title: Sign In Policy Service List Response + title: Paper Secret Service Search Audit Events Response type: object - x-speakeasy-name-override: SignInPolicyServiceListResponse - c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest: - description: The SignInPolicyServiceSearchRequest message. + x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsResponse + c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest: + description: |- + SearchMySecrets request - for end users viewing their own secrets. + Automatically scoped to current user. properties: pageSize: - description: The maximum number of results to return per page. + description: The pageSize field. format: int32 type: integer pageToken: - description: A pagination token from a previous Search response. + description: The pageToken field. type: string query: - description: Free-text search over the policy name. Empty matches all policies. + description: Fuzzy search by display name type: string - refs: - description: Restrict results to these specific policies. Empty matches all policies. + secretType: + description: Filter by secret type (optional) + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + sharingMode: + description: Filter by sharing mode (optional) + enum: + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + sortBy: + description: Sort order + enum: + - SEARCH_SORT_BY_UNSPECIFIED + - SEARCH_SORT_BY_CREATED_DESC + - SEARCH_SORT_BY_CREATED_ASC + - SEARCH_SORT_BY_EXPIRES_ASC + - SEARCH_SORT_BY_NAME_ASC + type: string + x-speakeasy-unknown-values: allow + statuses: + description: Filter by status (optional) items: - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyRef' + enum: + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - title: Sign In Policy Service Search Request + title: Paper Secret Service Search My Secrets Request type: object - x-speakeasy-name-override: SignInPolicyServiceSearchRequest - c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse: - description: The SignInPolicyServiceSearchResponse message. + x-speakeasy-name-override: PaperSecretServiceSearchMySecretsRequest + c1.api.secrets.v1.PaperSecretServiceSearchResponse: + description: Search response for user's own secrets properties: list: - description: The page of matching policies. + description: The list field. items: - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' type: - array - "null" nextPageToken: - description: A token to fetch the next page, or empty if there are no more results. + description: The nextPageToken field. type: string - title: Sign In Policy Service Search Response + title: Paper Secret Service Search Response type: object - x-speakeasy-name-override: SignInPolicyServiceSearchResponse - c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput: - description: The SignInPolicyServiceUpdateRequest message. + x-speakeasy-name-override: PaperSecretServiceSearchResponse + c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput: + description: The PaperSecretServiceSetTextContentRequest message. properties: - signInPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' - - type: "null" - updateMask: - type: - - string - - "null" - title: Sign In Policy Service Update Request + encryptedContent: + description: |- + Age-encrypted content bytes. The plaintext MUST be encrypted using the Age + encryption format to the age_recipient returned by CreateInternal/CreateExternal. + The resulting bytes begin with "age-encryption.org/v1\n" followed by the + encrypted payload. Maximum 64KB after encryption — for larger content, create + a FILE secret and use the upload_url instead. + format: base64 + type: string + inputFormat: + description: |- + Input format hint for the viewer UI when the secret is decrypted. + Does not affect encryption — this is metadata only. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + title: Paper Secret Service Set Text Content Request type: object - x-speakeasy-name-override: SignInPolicyServiceUpdateRequest - c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse: - description: The SignInPolicyServiceUpdateResponse message. + x-speakeasy-name-override: PaperSecretServiceSetTextContentRequest + c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse: + description: The PaperSecretServiceSetTextContentResponse message. properties: - signInPolicy: + secret: oneOf: - - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - type: "null" - title: Sign In Policy Service Update Response + title: Paper Secret Service Set Text Content Response type: object - x-speakeasy-name-override: SignInPolicyServiceUpdateResponse - c1.api.sign_in_policy.v1.StepUpRequired: - description: StepUpRequired demands a stronger re-authentication before access is granted. + x-speakeasy-name-override: PaperSecretServiceSetTextContentResponse + c1.api.service_principal.v1.ServicePrincipal: + description: ServicePrincipal represents a tenant-managed non-human identity. properties: - level: - description: The assurance level the step-up must reach. - enum: - - AUTH_LEVEL_UNSPECIFIED - - AUTH_LEVEL_NONE - - AUTH_LEVEL_SINGLE_FACTOR - - AUTH_LEVEL_MULTI_FACTOR - - AUTH_LEVEL_PHR - - AUTH_LEVEL_PHRH - type: string - x-speakeasy-unknown-values: allow - maxAgeSeconds: - description: How fresh the step-up must be, in seconds. - format: int32 - type: integer - types: - description: The credential types that may satisfy the step-up. - items: - enum: - - CREDENTIAL_TYPE_UNSPECIFIED - - CREDENTIAL_TYPE_PASSKEY - - CREDENTIAL_TYPE_PASSWORD - - CREDENTIAL_TYPE_TOTP - - CREDENTIAL_TYPE_EMAIL_OTP - - CREDENTIAL_TYPE_RECOVERY_CODE - - CREDENTIAL_TYPE_DELEGATED_GOOGLE - - CREDENTIAL_TYPE_DELEGATED_MICROSOFT - - CREDENTIAL_TYPE_UPSTREAM_IDP - type: string - x-speakeasy-unknown-values: allow + createdAt: + format: date-time + readOnly: true type: - - array + - string - "null" - title: Step Up Required - type: object - x-speakeasy-name-override: StepUpRequired - c1.api.ssf_receiver.v1.SSFOutboundAuthBearer: - description: |- - SSFOutboundAuthBearer is a static bearer token for outbound auth. - Token is write-only: accepted on create/update, never returned. - properties: - token: - description: The token field. - type: string - title: Ssf Outbound Auth Bearer - type: object - x-speakeasy-name-override: SSFOutboundAuthBearer - c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2: - description: |- - SSFOutboundAuthOAuth2 uses OAuth2 client credentials for outbound auth. - client_secret is write-only: accepted on create/update, never returned. - properties: - clientId: - description: The clientId field. + displayName: + description: The display name of the service principal. type: string - clientSecret: - description: The clientSecret field. + id: + description: The unique user ID of the service principal. + readOnly: true type: string - scopes: - description: The scopes field. - items: - type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + updatedAt: + format: date-time + readOnly: true type: - - array + - string - "null" - tokenUrl: - description: The tokenUrl field. - type: string - title: Ssf Outbound Auth O Auth 2 + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Service Principal type: object - x-speakeasy-name-override: SSFOutboundAuthOAuth2 - c1.api.ssf_receiver.v1.SSFReceiverEvent: - description: SSFReceiverEvent shows both wire-level data and C1 canonical outcome. + x-speakeasy-name-override: ServicePrincipal + c1.api.service_principal.v1.ServicePrincipalBinding: + description: |- + ServicePrincipalBinding is one row in the binding store, naming a + subject's link to a single service principal. properties: - canonicalType: - description: |- - C1 canonical outcome (what C1 understood and did). - The normalized event type after mapping from the wire event type. - enum: - - SSF_CANONICAL_EVENT_TYPE_UNSPECIFIED - - SSF_CANONICAL_EVENT_TYPE_UNRECOGNIZED - - SSF_CANONICAL_EVENT_TYPE_SESSION_REVOKED - - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_TOKEN_CLAIMS_CHANGED - - SSF_CANONICAL_EVENT_TYPE_ASSURANCE_LEVEL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_DEVICE_COMPLIANCE_CHANGED - - SSF_CANONICAL_EVENT_TYPE_RISK_LEVEL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_SESSION_ESTABLISHED - - SSF_CANONICAL_EVENT_TYPE_SESSION_PRESENTED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_DISABLED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_ENABLED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_PURGED - - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_COMPROMISE - - SSF_CANONICAL_EVENT_TYPE_RECOVERY_ACTIVATED - - SSF_CANONICAL_EVENT_TYPE_IDENTIFIER_CHANGED - - SSF_CANONICAL_EVENT_TYPE_VERIFICATION - - SSF_CANONICAL_EVENT_TYPE_STREAM_UPDATED - type: string - x-speakeasy-unknown-values: allow - id: - description: The unique identifier of this event. - type: string - matchMethod: - description: How the upstream subject was resolved to a ConductorOne user. - enum: - - SSF_SUBJECT_MATCH_METHOD_UNSPECIFIED - - SSF_SUBJECT_MATCH_METHOD_IDP_USER - - SSF_SUBJECT_MATCH_METHOD_EMAIL - - SSF_SUBJECT_MATCH_METHOD_NOT_FOUND - - SSF_SUBJECT_MATCH_METHOD_NOT_APPLICABLE - type: string - x-speakeasy-unknown-values: allow - matchedUserId: - description: The ConductorOne user ID that the event subject was resolved to, if any. - type: string - outcome: - description: The action ConductorOne took in response to this event. - enum: - - SSF_EVENT_OUTCOME_UNSPECIFIED - - SSF_EVENT_OUTCOME_SESSIONS_REVOKED - - SSF_EVENT_OUTCOME_LOGGED - - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND - - SSF_EVENT_OUTCOME_VERIFIED - - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED - - SSF_EVENT_OUTCOME_UNRECOGNIZED - - SSF_EVENT_OUTCOME_ERROR - type: string - x-speakeasy-unknown-values: allow - outcomeDetail: - description: Human-readable details about the outcome (e.g., error message or revocation summary). - type: string - receivedAt: + createdAt: format: date-time type: - string - "null" - sessionsRevoked: - description: Number of sessions that were revoked as a result of this event. - format: int32 - type: integer - setJti: - description: |- - Wire-level data (what the transmitter sent). - The SET (Security Event Token) JWT ID claim, uniquely identifying the token. - type: string - streamId: - description: The SSF receiver stream that received this event. - type: string - wireEventProfile: - description: The event profile URI from the SET, if present. - type: string - wireEventType: - description: The raw event type URI from the SET (e.g., "https://schemas.openid.net/secevent/caep/event-type/session-revoked"). - type: string - wireInitiatingEntity: - description: The entity that initiated the event, as reported by the transmitter. - type: string - wireReasonAdmin: - description: The admin-facing reason string from the SET, if provided by the transmitter. - type: string - wireSubjectFormat: - description: The subject identifier format from the SET (e.g., "email", "iss_sub"). - type: string - wireSubjectIdentifier: - description: The raw subject identifier value from the SET. - type: string - title: Ssf Receiver Event - type: object - x-speakeasy-name-override: SSFReceiverEvent - c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest: - description: SSFReceiverEventSearchServiceSearchRequest carries the search query and optional filters for narrowing results. - properties: - eventType: - description: Restricts results to events matching this wire event type URI. Optional. - type: string - matchedUserId: - description: Restricts results to events matched to this ConductorOne user ID. Optional. - type: string - outcome: - description: Restricts results to events with this processing outcome. Optional. - enum: - - SSF_EVENT_OUTCOME_UNSPECIFIED - - SSF_EVENT_OUTCOME_SESSIONS_REVOKED - - SSF_EVENT_OUTCOME_LOGGED - - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND - - SSF_EVENT_OUTCOME_VERIFIED - - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED - - SSF_EVENT_OUTCOME_UNRECOGNIZED - - SSF_EVENT_OUTCOME_ERROR - type: string - x-speakeasy-unknown-values: allow - pageSize: - description: Maximum number of events to return per page. - format: int32 - type: integer - pageToken: - description: Token from a previous SearchResponse to fetch the next page of results. - type: string - query: - description: Full-text search query matched against event fields. - type: string - streamId: - description: Restricts results to events from this SSF receiver stream. Optional. + servicePrincipalId: + description: The servicePrincipalId field. type: string - title: Ssf Receiver Event Search Service Search Request + updatedAt: + format: date-time + type: + - string + - "null" + title: Service Principal Binding type: object - x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchRequest - c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse: - description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. + x-speakeasy-name-override: ServicePrincipalBinding + c1.api.service_principal.v1.ServicePrincipalBindingSubject: + description: | + ServicePrincipalBindingSubject identifies the entity that is bound to a + service principal. Open-ended oneof so future subject kinds (workflows, + connectors, etc.) can be added without changing the RPC shape. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - functionId properties: - list: - description: The SSF events matching the search criteria. - items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + functionId: + description: |- + Function ID. The function authenticates outbound c1-api calls as + user: instead of function:. + This field is part of the `kind` oneof. + See the documentation for `c1.api.service_principal.v1.ServicePrincipalBindingSubject` for more details. type: - - array + - string - "null" - nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. - type: string - title: Ssf Receiver Event Search Service Search Response + title: Service Principal Binding Subject type: object - x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchResponse - c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse: - description: SSFReceiverEventServiceListResponse contains a page of received SSF events. + x-speakeasy-name-override: ServicePrincipalBindingSubject + c1.api.service_principal.v1.ServicePrincipalCredential: + description: ServicePrincipalCredential represents a client credential for a service principal. properties: - list: - description: The SSF events in the current page. + allowSourceCidrs: + description: CIDR restrictions for this credential. items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + type: string + readOnly: true type: - array - "null" - nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. - type: string - title: Ssf Receiver Event Service List Response - type: object - x-speakeasy-name-override: SSFReceiverEventServiceListResponse - c1.api.ssf_receiver.v1.SSFReceiverStream: - description: | - SSFReceiverStream is the public API representation. - Secrets (push_auth_token, outbound credentials) are write-only. - - This message contains a oneof named outbound_auth. Only a single field of the following list may be set at a time: - - outboundAuthBearer - - outboundAuthOauth2 - properties: - accountDisabledAction: - description: Action to take when an account-disabled event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY + clientId: + description: 'The full client ID in format: ${cutename}@${tenant}.${installation}/spc' + readOnly: true type: string - x-speakeasy-unknown-values: allow createdAt: format: date-time readOnly: true type: - string - "null" - credentialChangeAction: - description: Action to take when a credential-change event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - credentialCompromiseAction: - description: Action to take when a credential-compromise event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY + displayName: + description: The display name of the credential. type: string - x-speakeasy-unknown-values: allow - deletedAt: + expiresAt: format: date-time readOnly: true type: - string - "null" - deliveryMethod: - description: Controls whether events are received via push (transmitter POSTs to C1) or poll (C1 fetches from transmitter). - enum: - - SSF_DELIVERY_METHOD_UNSPECIFIED - - SSF_DELIVERY_METHOD_PUSH - - SSF_DELIVERY_METHOD_POLL - type: string - x-speakeasy-unknown-values: allow - description: - description: Optional description of the stream's purpose or source. - type: string - displayName: - description: Human-readable name for the stream shown in the UI. + id: + description: The unique ID of the credential (cutename format). + readOnly: true type: string - enabled: - description: Controls whether this stream actively processes incoming events. When false, events are ignored. + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + requireDpop: + description: Whether DPoP proof-of-possession is required for this credential. + readOnly: true type: boolean - eventTypesEnabled: - description: SSF/CAEP/RISC event type URIs that this stream is configured to accept. + scopedRoleIds: + description: Scoped role IDs for this credential (intersection with SP roles at token issuance). items: type: string + readOnly: true type: - array - "null" - expectedAudience: - description: Expected audience (aud) claim in incoming SETs. Optional. - type: string - id: - description: The unique identifier of this SSF receiver stream. - type: string - issuerUrl: - description: Upstream IdP identification. - type: string - jwksUrl: - description: The jwksUrl field. + servicePrincipalId: + description: The service principal user ID this credential belongs to. + readOnly: true type: string - lastErrorAt: - format: date-time - type: - - string - - "null" - lastErrorMessage: - description: The lastErrorMessage field. + title: Service Principal Credential + type: object + x-speakeasy-name-override: ServicePrincipalCredential + c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest: + description: The ServicePrincipalServiceAddBindingRequest message. + properties: + servicePrincipalId: + description: The servicePrincipalId field. type: string - lastVerifiedAt: - format: date-time - type: - - string - - "null" - outboundAuthBearer: - oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthBearer' - - type: "null" - outboundAuthOauth2: + subject: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - type: "null" - pollEndpointUrl: - description: URL of the transmitter's poll endpoint where C1 fetches events from. + title: Service Principal Service Add Binding Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceAddBindingRequest + c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse: + description: The ServicePrincipalServiceAddBindingResponse message. + title: Service Principal Service Add Binding Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceAddBindingResponse + c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput: + description: The ServicePrincipalServiceCreateCredentialRequest message. + properties: + allowSourceCidrs: + description: |- + A list of CIDRs to restrict this credential to. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + displayName: + description: The display name for the new credential. type: string - pollInterval: + expires: format: duration type: - string - "null" - pushAuthToken: - description: 'Push auth token: write-only. Accepted on create, never returned in get/list.' - type: string - pushEndpointUrl: - description: 'Push delivery: C1 generates a unique endpoint URL.' - readOnly: true - type: string - sessionRevokedAction: - description: |- - Per-canonical-type action configuration. - Event types without a config here default to LOG_ONLY. - Action to take when a session-revoked event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true + requireDpop: + description: If true, requires DPoP proof-of-possession for token exchange using this credential. + type: boolean + scopedRoles: + description: The list of roles to restrict the credential to. + items: + type: string type: - - string + - array - "null" - title: Ssf Receiver Stream + title: Service Principal Service Create Credential Request type: object - x-speakeasy-name-override: SSFReceiverStream - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest: - description: SSFReceiverStreamServiceCreateRequest contains the configuration for a new SSF receiver stream. + x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse: + description: The ServicePrincipalServiceCreateCredentialResponse message. properties: - accountDisabledAction: - description: Action to take when an account-disabled event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - credentialChangeAction: - description: Action to take when a credential-change event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - credentialCompromiseAction: - description: Action to take when a credential-compromise event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - deliveryMethod: - description: Controls whether events are received via push or poll delivery. - enum: - - SSF_DELIVERY_METHOD_UNSPECIFIED - - SSF_DELIVERY_METHOD_PUSH - - SSF_DELIVERY_METHOD_POLL - type: string - x-speakeasy-unknown-values: allow - description: - description: Optional description of the stream's purpose or source. + clientSecret: + description: The client secret. Shown exactly once at creation -- cannot be retrieved again. type: string + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - type: "null" + title: Service Principal Service Create Credential Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest: + description: The ServicePrincipalServiceCreateRequest message. + properties: displayName: - description: Human-readable name for the stream. - type: string - enabled: - description: Controls whether the stream starts processing events immediately after creation. - type: boolean - expectedAudience: - description: Expected audience claim in incoming SETs. If set, SETs with a different audience are rejected. + description: The display name for the new service principal. type: string - issuerUrl: - description: The issuer URL of the upstream SSF transmitter, used for token validation. - type: string - jwksUrl: - description: URL to fetch the transmitter's JSON Web Key Set for SET signature verification. - type: string - pollEndpointUrl: - description: URL of the transmitter's poll endpoint. Required when delivery_method is POLL. - type: string - pollInterval: - format: duration - type: - - string - - "null" - sessionRevokedAction: - description: |- - Per-event-type action configuration. - Action to take when a session-revoked event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - required: - - displayName - - issuerUrl - title: Ssf Receiver Stream Service Create Request + title: Service Principal Service Create Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceCreateRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse: - description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + x-speakeasy-name-override: ServicePrincipalServiceCreateRequest + c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse: + description: The ServicePrincipalServiceCreateResponse message. properties: - pushAuthTokenPlaintext: - description: Push auth token returned in plaintext ONLY on create. + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + title: Service Principal Service Create Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceCreateResponse + c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest: + description: The ServicePrincipalServiceDeleteBindingRequest message. + properties: + servicePrincipalId: + description: The servicePrincipalId field. type: string - ssfReceiverStream: + subject: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - type: "null" - title: Ssf Receiver Stream Service Create Response + title: Service Principal Service Delete Binding Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceCreateResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput: - description: SSFReceiverStreamServiceDeleteRequest identifies the SSF receiver stream to delete. - title: Ssf Receiver Stream Service Delete Request + x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingRequest + c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse: + description: The ServicePrincipalServiceDeleteBindingResponse message. + title: Service Principal Service Delete Binding Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceDeleteRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse: - description: SSFReceiverStreamServiceDeleteResponse is empty on success. - title: Ssf Receiver Stream Service Delete Response + x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingResponse + c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput: + description: The ServicePrincipalServiceDeleteRequest message. + title: Service Principal Service Delete Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceDeleteResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse: - description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. + x-speakeasy-name-override: ServicePrincipalServiceDeleteRequest + c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse: + description: The ServicePrincipalServiceDeleteResponse message. + title: Service Principal Service Delete Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceDeleteResponse + c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse: + description: The ServicePrincipalServiceGetCredentialResponse message. properties: - ssfReceiverStream: + credential: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - type: "null" - title: Ssf Receiver Stream Service Get Response + title: Service Principal Service Get Credential Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceGetResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse: - description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. + x-speakeasy-name-override: ServicePrincipalServiceGetCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceGetResponse: + description: The ServicePrincipalServiceGetResponse message. properties: - stats: + servicePrincipal: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamStats' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - type: "null" - title: Ssf Receiver Stream Service Get Stats Response + title: Service Principal Service Get Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceGetStatsResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse: - description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. + x-speakeasy-name-override: ServicePrincipalServiceGetResponse + c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest: + description: The ServicePrincipalServiceListBindingsRequest message. properties: - list: - description: The SSF receiver streams in the current page. + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + subject: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - type: "null" + title: Service Principal Service List Bindings Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceListBindingsRequest + c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse: + description: The ServicePrincipalServiceListBindingsResponse message. + properties: + bindings: + description: |- + Active bindings held by the subject in this page. Empty when the + subject is unbound. Order is unspecified. items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBinding' type: - array - "null" nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. + description: The nextPageToken field. type: string - title: Ssf Receiver Stream Service List Response + title: Service Principal Service List Bindings Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceListResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput: - description: SSFReceiverStreamServiceTestRequest identifies the stream to test and an optional subject for identity resolution validation. + x-speakeasy-name-override: ServicePrincipalServiceListBindingsResponse + c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse: + description: The ServicePrincipalServiceListCredentialsResponse message. properties: - testSubject: - description: |- - The upstream identifier to test resolution with. Typically an email address - (e.g., "alice@company.com") — the same value the IdP would send in a SET subject. - The Test RPC runs resolveSubject on this to verify the identity mapping works. - Optional: upstream identifier (email) to test identity resolution. - If empty, only JWKS reachability is tested. + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Ssf Receiver Stream Service Test Request + title: Service Principal Service List Credentials Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceTestRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse: - description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. + x-speakeasy-name-override: ServicePrincipalServiceListCredentialsResponse + c1.api.service_principal.v1.ServicePrincipalServiceListResponse: + description: The ServicePrincipalServiceListResponse message. properties: - activeRefreshTokenCount: - description: Number of active refresh tokens for the matched user that would be affected. - format: int32 - type: integer - activeSessionCount: - description: Number of active sessions for the matched user that would be affected. - format: int32 - type: integer - configuredSessionRevokedAction: - description: |- - Step 3: Action preview. - The action configured for session-revoked events on this stream. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - type: string - x-speakeasy-unknown-values: allow - identityLinkFound: - description: |- - Step 2: Identity mapping. - Whether the test subject was resolved to a ConductorOne user. - type: boolean - jwksError: - description: Error message if the JWKS endpoint could not be reached or returned invalid data. - type: string - jwksKeyCount: - description: Number of signing keys found at the JWKS endpoint. - format: int32 - type: integer - jwksReachable: - description: |- - Step 1: JWKS reachability. - Whether the JWKS endpoint was reachable and returned valid keys. - type: boolean - matchedUserId: - description: The ConductorOne user ID the test subject maps to, if an identity link was found. - type: string - ready: - description: |- - Overall readiness. - Whether the stream passed all test checks and is ready to process events. - type: boolean - upstreamSubject: - description: The upstream IdP subject identifier (e.g., Okta user ID "00u1234") resolved from the test subject. + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Ssf Receiver Stream Service Test Response + title: Service Principal Service List Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceTestResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput: - description: SSFReceiverStreamServiceUpdateRequest carries the stream to update and the mask of fields to modify. + x-speakeasy-name-override: ServicePrincipalServiceListResponse + c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput: + description: The ServicePrincipalServiceRevokeCredentialRequest message. + title: Service Principal Service Revoke Credential Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse: + description: The ServicePrincipalServiceRevokeCredentialResponse message. + title: Service Principal Service Revoke Credential Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput: + description: The ServicePrincipalServiceUpdateCredentialRequest message. properties: - ssfReceiverStream: + credential: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - type: "null" updateMask: type: - string - "null" - title: Ssf Receiver Stream Service Update Request + title: Service Principal Service Update Credential Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceUpdateRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse: - description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. + x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse: + description: The ServicePrincipalServiceUpdateCredentialResponse message. properties: - ssfReceiverStream: + credential: oneOf: - - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - type: "null" - title: Ssf Receiver Stream Service Update Response + title: Service Principal Service Update Credential Response type: object - x-speakeasy-name-override: SSFReceiverStreamServiceUpdateResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamStats: - description: SSFReceiverStreamStats is a lightweight read-only stats object. + x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput: + description: The ServicePrincipalServiceUpdateRequest message. properties: - eventsActedOnCount: - description: Number of events that triggered an action (e.g., session revocation). - format: int64 - type: string - eventsFailedCount: - description: Number of events that failed processing. - format: int64 - type: string - eventsReceivedCount: - description: Total number of events received on this stream. - format: int64 - type: string - lastErrorAt: - format: date-time - type: - - string - - "null" - lastErrorMessage: - description: Human-readable description of the most recent processing error. - type: string - lastEventReceivedAt: - format: date-time - type: - - string - - "null" - lastVerifiedAt: - format: date-time + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + updateMask: type: - string - "null" - streamId: - description: The SSF receiver stream these stats belong to. - type: string - transmitterStatus: - description: Current status reported by the transmitter (e.g., "enabled", "paused"). - type: string - transmitterStatusReason: - description: Reason provided by the transmitter for its current status. - type: string - title: Ssf Receiver Stream Stats - type: object - x-speakeasy-name-override: SSFReceiverStreamStats - c1.api.stepup.v1.CreateStepUpProviderRequest: - description: | - The CreateStepUpProviderRequest message. - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oauth2 - - microsoft - properties: - clientId: - description: The OAuth2 client ID used to authenticate with the step-up provider. - type: string - clientSecret: - description: The OAuth2 client secret. Write-only; never returned in responses. - type: string - displayName: - description: The human-readable name for the new step-up provider. - type: string - issuerUrl: - description: The OIDC issuer URL for the step-up provider. - type: string - microsoft: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' - - type: "null" - oauth2: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' - - type: "null" - title: Create Step Up Provider Request + title: Service Principal Service Update Request type: object - x-speakeasy-name-override: CreateStepUpProviderRequest - c1.api.stepup.v1.CreateStepUpProviderResponse: - description: The CreateStepUpProviderResponse message. + x-speakeasy-name-override: ServicePrincipalServiceUpdateRequest + c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse: + description: The ServicePrincipalServiceUpdateResponse message. properties: - stepUpProvider: + servicePrincipal: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - type: "null" - title: Create Step Up Provider Response - type: object - x-speakeasy-name-override: CreateStepUpProviderResponse - c1.api.stepup.v1.DeleteStepUpProviderRequestInput: - description: The DeleteStepUpProviderRequest message. - title: Delete Step Up Provider Request - type: object - x-speakeasy-name-override: DeleteStepUpProviderRequest - c1.api.stepup.v1.DeleteStepUpProviderResponse: - description: The DeleteStepUpProviderResponse message. - title: Delete Step Up Provider Response + title: Service Principal Service Update Response type: object - x-speakeasy-name-override: DeleteStepUpProviderResponse - c1.api.stepup.v1.GetStepUpProviderResponse: - description: The GetStepUpProviderResponse message. + x-speakeasy-name-override: ServicePrincipalServiceUpdateResponse + c1.api.session_policy.v1.Allow: + description: Allow continues the session. properties: - stepUpProvider: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - - type: "null" - title: Get Step Up Provider Response + floorLevel: + description: The minimum assurance level that satisfies this rule. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH + type: string + x-speakeasy-unknown-values: allow + title: Allow type: object - x-speakeasy-name-override: GetStepUpProviderResponse - c1.api.stepup.v1.GetStepUpTransactionResponse: - description: Response message containing the requested step-up transaction + x-speakeasy-name-override: SessionPolicyAllow + c1.api.session_policy.v1.Assignment: + description: Assignment is one principal (user) assigned to a session policy. properties: - transaction: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' - - type: "null" - title: Get Step Up Transaction Response + source: + description: Whether the assignment is direct or conferred through a group. + enum: + - ASSIGNMENT_SOURCE_UNSPECIFIED + - ASSIGNMENT_SOURCE_DIRECT + - ASSIGNMENT_SOURCE_GROUP + type: string + x-speakeasy-unknown-values: allow + userId: + description: The assigned user's ID. + type: string + title: Assignment type: object - x-speakeasy-name-override: GetStepUpTransactionResponse - c1.api.stepup.v1.ListStepUpProvidersResponse: - description: The ListStepUpProvidersResponse message. + x-speakeasy-name-override: Assignment + c1.api.session_policy.v1.ChallengeRequired: + description: ChallengeRequired asks for an additional factor. properties: - list: - description: The list of step-up authentication providers. + types: + description: The types field. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - type: string - title: List Step Up Providers Response + title: Challenge Required type: object - x-speakeasy-name-override: ListStepUpProvidersResponse - c1.api.stepup.v1.SearchStepUpProvidersRequest: - description: Request message for searching step-up providers + x-speakeasy-name-override: SessionPolicyChallengeRequired + c1.api.session_policy.v1.Deny: + description: Deny terminates the session. properties: - pageSize: - description: Maximum number of results to return - format: int32 - type: integer - pageToken: - description: Token for pagination - type: string - providerType: - description: The providerType field. - enum: - - PROVIDER_TYPE_UNSPECIFIED - - PROVIDER_TYPE_OAUTH2 - - PROVIDER_TYPE_MICROSOFT + reasonAdmin: + description: Reason shown in admin-only audit. type: string - x-speakeasy-unknown-values: allow - query: - description: Filter by name (partial match) + reasonUser: + description: Reason safe to show the end user. type: string - refs: - description: Filter to specific providers by their references. - items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProviderRef' - type: - - array - - "null" - title: Search Step Up Providers Request + title: Deny type: object - x-speakeasy-name-override: SearchStepUpProvidersRequest - c1.api.stepup.v1.SearchStepUpProvidersResponse: - description: Response message for searching step-up providers + x-speakeasy-name-override: SessionPolicyDeny + c1.api.session_policy.v1.EnrollmentRequired: + description: EnrollmentRequired tells the user to enroll a credential before continuing. properties: - list: - description: List of providers matching the search criteria + credentialTypes: + description: The credentialTypes field. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - nextPageToken: - description: Token for retrieving the next page of results - type: string - title: Search Step Up Providers Response + title: Enrollment Required type: object - x-speakeasy-name-override: SearchStepUpProvidersResponse - c1.api.stepup.v1.SearchStepUpTransactionsRequest: - description: Request message for searching step-up transactions + x-speakeasy-name-override: SessionPolicyEnrollmentRequired + c1.api.session_policy.v1.PerCredentialDuration: + description: |- + PerCredentialDuration overrides session lifetimes for sessions established + with a particular credential type — stronger credentials can earn longer + sessions. properties: - createdAfter: - format: date-time - type: - - string - - "null" - createdBefore: - format: date-time - type: - - string - - "null" - pageSize: - description: Maximum number of results to return + accessTokenTtlSeconds: + description: Access-token lifetime for this credential type, in seconds. format: int32 type: integer - pageToken: - description: Token for pagination - type: string - providerId: - description: Filter by provider ID - type: string - state: - description: Filter by transaction state - enum: - - STEP_UP_TRANSACTION_STATE_UNSPECIFIED - - STEP_UP_TRANSACTION_STATE_PENDING - - STEP_UP_TRANSACTION_STATE_VERIFIED - - STEP_UP_TRANSACTION_STATE_ERROR - type: string - x-speakeasy-unknown-values: allow - targetType: - description: The targetType field. + credentialType: + description: The credentialType field. enum: - - TARGET_TYPE_UNSPECIFIED - - TARGET_TYPE_TICKET - - TARGET_TYPE_TEST + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string x-speakeasy-unknown-values: allow - taskId: - description: Filter by task ID (only applicable if target_type is TICKET) - type: string - userId: - description: Filter by user ID - type: string - title: Search Step Up Transactions Request + maxSessionDurationSeconds: + description: Maximum total session duration for this credential type, in seconds. + format: int32 + type: integer + title: Per Credential Duration type: object - x-speakeasy-name-override: SearchStepUpTransactionsRequest - c1.api.stepup.v1.SearchStepUpTransactionsResponse: - description: Response message for searching step-up transactions + x-speakeasy-name-override: PerCredentialDuration + c1.api.session_policy.v1.PolicyOutcome: + description: | + PolicyOutcome is the effect of a matched rule. Exactly one kind is set. For + session continuous-evaluation, the meaningful kinds are Allow (continue), + Deny (terminate), and StepUpRequired. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - allow + - deny + - stepUpRequired + - challengeRequired + - enrollmentRequired properties: - list: - description: List of transactions matching the search criteria - items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' - type: - - array - - "null" - nextPageToken: - description: Token for retrieving the next page of results - type: string - title: Search Step Up Transactions Response + allow: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.Allow' + - type: "null" + challengeRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.ChallengeRequired' + - type: "null" + deny: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.Deny' + - type: "null" + enrollmentRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.EnrollmentRequired' + - type: "null" + stepUpRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.StepUpRequired' + - type: "null" + title: Policy Outcome type: object - x-speakeasy-name-override: SearchStepUpTransactionsResponse - c1.api.stepup.v1.StepUpMicrosoftSettings: - description: StepUpMicrosoftSettings configures a Microsoft Entra step-up provider using Conditional Access. + x-speakeasy-name-override: SessionPolicyPolicyOutcome + c1.api.session_policy.v1.PolicyRule: + description: |- + PolicyRule is one rung of the ordered continuous-evaluation cascade. Rules + are evaluated top to bottom on every request; the first enforced rule whose + condition matches supplies the outcome. properties: - conditionalAccessIds: - description: Authentication context IDs (C1-C99). Required for ACRS mode; ignored for OIDC mode. - items: - type: string - type: - - array - - "null" - tenant: - description: Microsoft Entra tenant ID (GUID or domain). Used for response validation. + description: + description: The description field. type: string - validationMode: - description: Validation approach. See MicrosoftValidationMode for details on each mode. + id: + description: The id field. + type: string + matchCel: + description: The matchCel field. + type: string + mode: + description: The mode field. enum: - - MICROSOFT_VALIDATION_MODE_UNSPECIFIED - - MICROSOFT_VALIDATION_MODE_ACRS - - MICROSOFT_VALIDATION_MODE_OIDC + - POLICY_RULE_MODE_UNSPECIFIED + - POLICY_RULE_MODE_ENFORCE + - POLICY_RULE_MODE_OBSERVE + - POLICY_RULE_MODE_DISABLED type: string x-speakeasy-unknown-values: allow - title: Step Up Microsoft Settings + outcome: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' + - type: "null" + title: Policy Rule type: object - x-speakeasy-name-override: StepUpMicrosoftSettings - c1.api.stepup.v1.StepUpOAuth2Settings: + x-speakeasy-name-override: SessionPolicyPolicyRule + c1.api.session_policy.v1.SSFReceiverConfig: description: |- - StepUpOAuth2Settings repersents an OAuth2 provider that supports RFC 9470 - - Common ACR values for OAuth2 providers include: - - "urn:okta:loa:1fa:any" (okta) - - "urn:okta:loa:1fa:pwd" (okta) - - "urn:okta:loa:2fa:any" (okta) - - "urn:okta:loa:2fa:any:ifpossible" (okta) - - "phr" (okta) - - "phrh" (okta) + SSFReceiverConfig selects which inbound shared-signals streams this session + trusts. Each stream's issuer, keys, expected audience, and per-event actions + are configured on the stream itself; this policy just lists the stream IDs. properties: - acrValues: - description: The acrValues field. + enabled: + description: Whether inbound shared-signals consumption is enabled for this policy. + type: boolean + ssfReceiverStreamIds: + description: The inbound stream IDs this policy trusts. items: type: string type: - array - "null" - title: Step Up O Auth 2 Settings + title: Ssf Receiver Config type: object - x-speakeasy-name-override: StepUpOAuth2Settings - c1.api.stepup.v1.StepUpProvider: - description: | - StepUpProvider represents a configured step-up authentication integration (e.g., Duo, custom OIDC). - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oauth2 - - microsoft + x-speakeasy-name-override: SSFReceiverConfig + c1.api.session_policy.v1.SSFTransmitterConfig: + description: |- + SSFTransmitterConfig selects which outbound shared-signals streams this + session emits security events to. Each stream's delivery endpoint, + authentication, and per-event allowlist are configured on the stream itself; + this policy just lists the stream IDs and the event types to emit. properties: - clientId: - description: The OAuth2 client ID used to authenticate with the step-up provider. - type: string - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - displayName: - description: The human-readable name of the step-up provider. - type: string enabled: - description: Whether the step-up provider is active and available for use. + description: Whether outbound shared-signals emission is enabled for this policy. type: boolean - id: - description: The unique identifier of the step-up provider. - readOnly: true - type: string - issuerUrl: - description: The OIDC issuer URL for the step-up provider. - type: string - lastTestedAt: - format: date-time - readOnly: true + eventTypes: + description: The shared-signals event types to emit at the policy level. + items: + type: string type: - - string + - array - "null" - microsoft: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' - - type: "null" - oauth2: - oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' - - type: "null" - updatedAt: - format: date-time - readOnly: true + ssfTransmitterStreamIds: + description: The outbound stream IDs this policy emits to. + items: + type: string type: - - string + - array - "null" - title: Step Up Provider - type: object - x-speakeasy-name-override: StepUpProvider - c1.api.stepup.v1.StepUpProviderRef: - description: StepUpProviderRef is a lightweight reference to a step-up authentication provider. - properties: - id: - description: The unique identifier of the step-up provider. - type: string - title: Step Up Provider Ref + title: Ssf Transmitter Config type: object - x-speakeasy-name-override: StepUpProviderRef - c1.api.stepup.v1.StepUpTransaction: - description: | - StepUpTransaction represents a record of a step-up authentication attempt - - This message contains a oneof named target. Only a single field of the following list may be set at a time: - - approveTask - - test + x-speakeasy-name-override: SSFTransmitterConfig + c1.api.session_policy.v1.SessionPolicy: + description: SessionPolicy defines session lifetime and continuous-evaluation behavior. properties: - approveTask: + accessTokenTtlSeconds: + description: How long an access token is valid, in seconds. + format: int32 + type: integer + continuousDefaultOutcome: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTask' + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' - type: "null" - claims: - additionalProperties: true + continuousRules: + description: |- + The continuous-evaluation rule cascade, re-checked on every request and on + inbound shared-signals events. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' type: - - object + - array - "null" createdAt: format: date-time @@ -33003,35 +34241,75 @@ components: type: - string - "null" - errorMessage: - description: Error message if the transaction failed - readOnly: true - type: string - expiresAt: + credentialDurations: + description: Per-credential-type lifetime overrides. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + type: + - array + - "null" + deletedAt: format: date-time readOnly: true type: - string - "null" - id: - description: Unique identifier for the transaction + displayName: + description: A human-readable name for the policy. type: string - providerId: - description: ID of the provider used for this step-up authentication + id: + description: Unique identifier for the policy. + readOnly: true type: string - state: - description: Current state of the transaction - enum: - - STEP_UP_TRANSACTION_STATE_UNSPECIFIED - - STEP_UP_TRANSACTION_STATE_PENDING - - STEP_UP_TRANSACTION_STATE_VERIFIED - - STEP_UP_TRANSACTION_STATE_ERROR + idleTimeoutSeconds: + description: How long a session may be idle before it ends, in seconds. + format: int32 + type: integer + isBuiltin: + description: |- + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. readOnly: true + type: boolean + maxSessionDurationSeconds: + description: The maximum total lifetime of a session, in seconds. + format: int32 + type: integer + persistence: + description: Whether sessions may persist across browser restarts. + enum: + - PERSISTENCE_MODE_UNSPECIFIED + - PERSISTENCE_MODE_ALLOW_USER_CHOICE + - PERSISTENCE_MODE_ALWAYS_PERSIST + - PERSISTENCE_MODE_SESSION_ONLY type: string x-speakeasy-unknown-values: allow - test: + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + refreshRotationWindowSeconds: + description: |- + Grace window after rotation during which the previous refresh token is + still accepted, in seconds (covers in-flight client retries). + format: int32 + type: integer + refreshTokenTtlSeconds: + description: How long a refresh token is valid, in seconds. + format: int32 + type: integer + rotateRefreshOnUse: + description: Whether to issue a new refresh token each time one is used. + type: boolean + ssfReceive: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTest' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' + - type: "null" + ssfTransmit: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' - type: "null" updatedAt: format: date-time @@ -33039,135 +34317,190 @@ components: type: - string - "null" - userId: - description: ID of the user who performed the step-up authentication - type: string - title: Step Up Transaction + title: Session Policy type: object - x-speakeasy-name-override: StepUpTransaction - c1.api.stepup.v1.StepUpTransaction.TargetTask: - description: Target for approving a task + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicy + c1.api.session_policy.v1.SessionPolicyRef: + description: SessionPolicyRef is a lightweight reference to a session policy by ID. properties: - policyStepId: - description: ID of the policy step requiring step-up authentication - type: string - taskId: - description: ID of the task being approved + id: + description: The id field. type: string - title: Target Task + title: Session Policy Ref type: object - x-speakeasy-name-override: TargetTask - c1.api.stepup.v1.StepUpTransaction.TargetTest: - description: Target for testing a provider - title: Target Test + x-speakeasy-name-override: SessionPolicyRef + c1.api.session_policy.v1.SessionPolicyServiceAssignGroupRequestInput: + description: The SessionPolicyServiceAssignGroupRequest message. + properties: + groupAppEntitlementId: + description: The group's app-entitlement ID. Every member of the group becomes assigned. + type: string + required: + - groupAppEntitlementId + title: Session Policy Service Assign Group Request type: object - x-speakeasy-name-override: TargetTest - c1.api.stepup.v1.TestStepUpProviderRequestInput: - description: The TestStepUpProviderRequest message. - title: Test Step Up Provider Request + x-speakeasy-name-override: SessionPolicyServiceAssignGroupRequest + c1.api.session_policy.v1.SessionPolicyServiceAssignGroupResponse: + description: The SessionPolicyServiceAssignGroupResponse message. + title: Session Policy Service Assign Group Response type: object - x-speakeasy-name-override: TestStepUpProviderRequest - c1.api.stepup.v1.TestStepUpProviderResponse: - description: The TestStepUpProviderResponse message. + x-speakeasy-name-override: SessionPolicyServiceAssignGroupResponse + c1.api.session_policy.v1.SessionPolicyServiceAssignUserRequestInput: + description: The SessionPolicyServiceAssignUserRequest message. properties: - redirectUrl: - description: The URL to redirect the user to for testing the Step Up flow + userId: + description: The user to assign. type: string - title: Test Step Up Provider Response + required: + - userId + title: Session Policy Service Assign User Request type: object - x-speakeasy-name-override: TestStepUpProviderResponse - c1.api.stepup.v1.UpdateStepUpProviderRequestInput: - description: The UpdateStepUpProviderRequest message. + x-speakeasy-name-override: SessionPolicyServiceAssignUserRequest + c1.api.session_policy.v1.SessionPolicyServiceAssignUserResponse: + description: The SessionPolicyServiceAssignUserResponse message. + title: Session Policy Service Assign User Response + type: object + x-speakeasy-name-override: SessionPolicyServiceAssignUserResponse + c1.api.session_policy.v1.SessionPolicyServiceCreateRequest: + description: The SessionPolicyServiceCreateRequest message. properties: - stepUpProvider: + accessTokenTtlSeconds: + description: The accessTokenTtlSeconds field. + format: int32 + type: integer + continuousDefaultOutcome: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' - type: "null" - updateMask: + continuousRules: + description: The continuousRules field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' type: - - string + - array - "null" - title: Update Step Up Provider Request - type: object - x-speakeasy-name-override: UpdateStepUpProviderRequest - c1.api.stepup.v1.UpdateStepUpProviderResponse: - description: The UpdateStepUpProviderResponse message. - properties: - stepUpProvider: + credentialDurations: + description: The credentialDurations field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + type: + - array + - "null" + displayName: + description: The displayName field. + type: string + idleTimeoutSeconds: + description: The idleTimeoutSeconds field. + format: int32 + type: integer + maxSessionDurationSeconds: + description: The maxSessionDurationSeconds field. + format: int32 + type: integer + persistence: + description: The persistence field. + enum: + - PERSISTENCE_MODE_UNSPECIFIED + - PERSISTENCE_MODE_ALLOW_USER_CHOICE + - PERSISTENCE_MODE_ALWAYS_PERSIST + - PERSISTENCE_MODE_SESSION_ONLY + type: string + x-speakeasy-unknown-values: allow + priority: + description: The priority field. + format: int32 + type: integer + refreshRotationWindowSeconds: + description: The refreshRotationWindowSeconds field. + format: int32 + type: integer + refreshTokenTtlSeconds: + description: The refreshTokenTtlSeconds field. + format: int32 + type: integer + rotateRefreshOnUse: + description: The rotateRefreshOnUse field. + type: boolean + ssfReceive: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' - type: "null" - title: Update Step Up Provider Response - type: object - x-speakeasy-name-override: UpdateStepUpProviderResponse - c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput: - description: The UpdateStepUpProviderSecretRequest message. - properties: - clientSecret: - description: The new OAuth2 client secret. Write-only; never returned in responses. - type: string - title: Update Step Up Provider Secret Request + ssfTransmit: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' + - type: "null" + required: + - displayName + title: Session Policy Service Create Request type: object - x-speakeasy-name-override: UpdateStepUpProviderSecretRequest - c1.api.stepup.v1.UpdateStepUpProviderSecretResponse: - description: The UpdateStepUpProviderSecretResponse message. + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicyServiceCreateRequest + c1.api.session_policy.v1.SessionPolicyServiceCreateResponse: + description: The SessionPolicyServiceCreateResponse message. properties: - stepUpProvider: + sessionPolicy: oneOf: - - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - type: "null" - title: Update Step Up Provider Secret Response + title: Session Policy Service Create Response type: object - x-speakeasy-name-override: UpdateStepUpProviderSecretResponse - c1.api.systemlog.v1.ExportServiceCreateRequest: - description: | - The ExportServiceCreateRequest message is used to create a new system log exporter. - - This message contains a oneof named export_to. Only a single field of the following list may be set at a time: - - datasource - properties: - datasource: - oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' - - type: "null" - displayName: - description: The display name of the new system log exporter. - type: string - title: Export Service Create Request + x-speakeasy-name-override: SessionPolicyServiceCreateResponse + c1.api.session_policy.v1.SessionPolicyServiceDeleteRequestInput: + description: The SessionPolicyServiceDeleteRequest message. + title: Session Policy Service Delete Request type: object - x-speakeasy-name-override: ExportServiceCreateRequest - c1.api.systemlog.v1.ExportServiceCreateResponse: - description: The ExportServiceCreateResponse message. + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicyServiceDeleteRequest + c1.api.session_policy.v1.SessionPolicyServiceDeleteResponse: + description: The SessionPolicyServiceDeleteResponse message. + title: Session Policy Service Delete Response + type: object + x-speakeasy-name-override: SessionPolicyServiceDeleteResponse + c1.api.session_policy.v1.SessionPolicyServiceGetResponse: + description: The SessionPolicyServiceGetResponse message. properties: - exporter: + sessionPolicy: oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - type: "null" - title: Export Service Create Response - type: object - x-speakeasy-name-override: ExportServiceCreateResponse - c1.api.systemlog.v1.ExportServiceDeleteRequestInput: - description: The ExportServiceDeleteRequest message. - title: Export Service Delete Request + title: Session Policy Service Get Response type: object - x-speakeasy-name-override: ExportServiceDeleteRequest - c1.api.systemlog.v1.ExportServiceDeleteResponse: - description: The ExportServiceDeleteResponse message. - title: Export Service Delete Response + x-speakeasy-name-override: SessionPolicyServiceGetResponse + c1.api.session_policy.v1.SessionPolicyServiceListAssignmentsResponse: + description: The SessionPolicyServiceListAssignmentsResponse message. + properties: + assignments: + description: The assignments field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.Assignment' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Session Policy Service List Assignments Response type: object - x-speakeasy-name-override: ExportServiceDeleteResponse - c1.api.systemlog.v1.ExportServiceGetResponse: - description: The ExportServiceGetResponse message contains the system log exporter object. + x-speakeasy-name-override: SessionPolicyServiceListAssignmentsResponse + c1.api.session_policy.v1.SessionPolicyServiceListResponse: + description: The SessionPolicyServiceListResponse message. properties: - exporter: - oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - - type: "null" - title: Export Service Get Response + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Session Policy Service List Response type: object - x-speakeasy-name-override: ExportServiceGetResponse - c1.api.systemlog.v1.ExportServiceListEventsRequestInput: - description: ExportServiceListEventsRequest is the request for listing audit events within a specific export. + x-speakeasy-name-override: SessionPolicyServiceListResponse + c1.api.session_policy.v1.SessionPolicyServiceSearchRequest: + description: The SessionPolicyServiceSearchRequest message. properties: pageSize: description: The pageSize field. @@ -33176,668 +34509,1038 @@ components: pageToken: description: The pageToken field. type: string - title: Export Service List Events Request - type: object - x-speakeasy-name-override: ExportServiceListEventsRequest - c1.api.systemlog.v1.ExportServiceListEventsResponse: - description: ExportServiceListEventsResponse is the response containing audit events for an export. - properties: - list: - description: List contains an array of JSON OCSF events. + query: + description: Free-text search over the policy name. Empty matches all policies. + type: string + refs: + description: Restrict results to these specific policies. Empty matches all policies. items: - additionalProperties: true - type: object + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyRef' type: - array - "null" - nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - type: string - title: Export Service List Events Response + title: Session Policy Service Search Request type: object - x-speakeasy-name-override: ExportServiceListEventsResponse - c1.api.systemlog.v1.ExportServiceListResponse: - description: The ExportServiceListResponse message. + x-speakeasy-name-override: SessionPolicyServiceSearchRequest + c1.api.session_policy.v1.SessionPolicyServiceSearchResponse: + description: The SessionPolicyServiceSearchResponse message. properties: list: - description: The list of results containing up to X results, where X is the page size defined in the request + description: The list field. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' type: - array - "null" nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + description: The nextPageToken field. type: string - title: Export Service List Response + title: Session Policy Service Search Response type: object - x-speakeasy-name-override: ExportServiceListResponse - c1.api.systemlog.v1.ExportServiceUpdateRequestInput: - description: The ExportServiceUpdateRequest message. + x-speakeasy-name-override: SessionPolicyServiceSearchResponse + c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupRequestInput: + description: The SessionPolicyServiceUnassignGroupRequest message. + title: Session Policy Service Unassign Group Request + type: object + x-speakeasy-name-override: SessionPolicyServiceUnassignGroupRequest + c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupResponse: + description: The SessionPolicyServiceUnassignGroupResponse message. + title: Session Policy Service Unassign Group Response + type: object + x-speakeasy-name-override: SessionPolicyServiceUnassignGroupResponse + c1.api.session_policy.v1.SessionPolicyServiceUnassignUserRequestInput: + description: The SessionPolicyServiceUnassignUserRequest message. + title: Session Policy Service Unassign User Request + type: object + x-speakeasy-name-override: SessionPolicyServiceUnassignUserRequest + c1.api.session_policy.v1.SessionPolicyServiceUnassignUserResponse: + description: The SessionPolicyServiceUnassignUserResponse message. + title: Session Policy Service Unassign User Response + type: object + x-speakeasy-name-override: SessionPolicyServiceUnassignUserResponse + c1.api.session_policy.v1.SessionPolicyServiceUpdateRequestInput: + description: The SessionPolicyServiceUpdateRequest message. properties: - exporter: + sessionPolicy: oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - type: "null" updateMask: type: - string - "null" - title: Export Service Update Request + title: Session Policy Service Update Request type: object - x-speakeasy-name-override: ExportServiceUpdateRequest - c1.api.systemlog.v1.ExportServiceUpdateResponse: - description: The ExportServiceUpdateResponse message. + x-speakeasy-name-override: SessionPolicyServiceUpdateRequest + c1.api.session_policy.v1.SessionPolicyServiceUpdateResponse: + description: The SessionPolicyServiceUpdateResponse message. properties: - exporter: + sessionPolicy: oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' - type: "null" - title: Export Service Update Response - type: object - x-speakeasy-name-override: ExportServiceUpdateResponse - c1.api.systemlog.v1.ExportToDatasource: - description: The ExportToDatasource message. - properties: - datasourceId: - description: The datasourceId field. - type: string - format: - description: The format field. - enum: - - EXPORT_FORMAT_UNSPECIFIED - - EXPORT_FORMAT_OCSF_JSON_ZSTD - - EXPORT_FORMAT_OCSF_JSON_GZIP - type: string - x-speakeasy-unknown-values: allow - prefix: - description: The prefix field. - type: string - title: Export To Datasource + title: Session Policy Service Update Response type: object - x-speakeasy-name-override: ExportToDatasource - c1.api.systemlog.v1.Exporter: - description: | - The Exporter message. - - This message contains a oneof named export_to. Only a single field of the following list may be set at a time: - - datasource + x-speakeasy-name-override: SessionPolicyServiceUpdateResponse + c1.api.session_policy.v1.StepUpRequired: + description: |- + StepUpRequired demands a stronger re-authentication before the session may + continue. properties: - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - datasource: - oneOf: - - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' - - type: "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - displayName: - description: The displayName field. - type: string - exportId: - description: The exportId field. - readOnly: true - type: string - state: - description: The state field. + level: + description: The level field. enum: - - EXPORT_STATE_UNSPECIFIED - - EXPORT_STATE_EXPORTING - - EXPORT_STATE_WAITING - - EXPORT_STATE_ERROR - readOnly: true + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true + maxAgeSeconds: + description: How fresh the step-up must be, in seconds. + format: int32 + type: integer + types: + description: The types field. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow type: - - string + - array - "null" - watermarkEventId: - description: we've synchorized this far - readOnly: true - type: string - title: Exporter + title: Step Up Required type: object - x-speakeasy-name-override: Exporter - c1.api.systemlog.v1.ExporterRef: - description: The ExporterRef message. + x-speakeasy-name-override: SessionPolicyStepUpRequired + c1.api.settings.v1.AWSExternalID: + description: AWSExternalID contains the tenant's external ID for AWS IAM role trust policies. properties: - exportId: - description: The exportId field. + externalId: + description: The external ID value to include in the AWS IAM role trust policy condition. type: string - title: Exporter Ref + title: Aws External Id type: object - x-speakeasy-name-override: ExporterRef - c1.api.systemlog.v1.ExportsSearchServiceSearchRequest: - description: ExportsSearchServiceSearchRequest is the request for searching system log exports. + x-speakeasy-entity: AWS_EXTERNAL_ID + x-speakeasy-name-override: AWSExternalID + c1.api.settings.v1.AWSSESProviderConfig: + description: AWSSESProviderConfig configures sending via a customer's AWS SES account. properties: - displayName: - description: Search for system log exporters with a case insensitive match on the display name. + configurationSetName: + description: Optional SES configuration set name for tracking/metrics. type: string - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. + region: + description: AWS region where SES identities are verified (e.g., "us-east-1"). type: string - query: - description: The query field. + roleArn: + description: |- + IAM role ARN for sts:AssumeRole. The trust policy should require the + tenant's AWS External ID (GET /api/v1/settings/aws-external-id). type: string - refs: - description: The refs field. + title: Awsses Provider Config + type: object + x-speakeasy-name-override: AWSSESProviderConfig + c1.api.settings.v1.AccessProvisionedPreference: + description: The AccessProvisionedPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Access Provisioned Preference + type: object + x-speakeasy-name-override: AccessProvisionedPreference + c1.api.settings.v1.ApprovalNeededPreference: + description: The ApprovalNeededPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Approval Needed Preference + type: object + x-speakeasy-name-override: ApprovalNeededPreference + c1.api.settings.v1.C1BuiltInProviderConfig: + description: |- + C1BuiltInProviderConfig selects the ConductorOne built-in email provider. + Emails are sent from no-reply@conductorone.com via the platform SendGrid account. + Only supports sending to C1 users — external email addresses are not supported. + No configuration fields required. + title: C 1 Built In Provider Config + type: object + x-speakeasy-name-override: C1BuiltInProviderConfig + c1.api.settings.v1.CIDRRestriction: + description: CIDRRestriction defines an IP-based access restriction with an enable toggle and a list of allowed CIDRs. + properties: + enabled: + description: Whether this CIDR restriction is enforced. + type: boolean + sourceCidr: + description: |- + The list of CIDR ranges that are allowed when the restriction is enabled. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExporterRef' + type: string type: - array - "null" - title: Exports Search Service Search Request + title: Cidr Restriction type: object - x-speakeasy-name-override: ExportsSearchServiceSearchRequest - c1.api.systemlog.v1.ExportsSearchServiceSearchResponse: - description: ExportsSearchServiceSearchResponse is the response for searching system log exports. + x-speakeasy-name-override: CIDRRestriction + c1.api.settings.v1.ChannelSettings: + description: ChannelSettings groups notification preferences for all supported channels. properties: - list: - description: The list of system log exports matching the search criteria. + email: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.EmailChannelSettings' + - type: "null" + slack: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SlackChannelSettings' + - type: "null" + teams: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.MSTeamsChannelSettings' + - type: "null" + title: Channel Settings + type: object + x-speakeasy-name-override: ChannelSettings + c1.api.settings.v1.CommentOnRequestPreference: + description: The CommentOnRequestPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Comment On Request Preference + type: object + x-speakeasy-name-override: CommentOnRequestPreference + c1.api.settings.v1.CompletionPreference: + description: The CompletionPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Completion Preference + type: object + x-speakeasy-name-override: CompletionPreference + c1.api.settings.v1.ConnectorIssuesPreference: + description: The ConnectorIssuesPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Connector Issues Preference + type: object + x-speakeasy-name-override: ConnectorIssuesPreference + c1.api.settings.v1.Contacts: + description: Contacts represents the contact configuration for an organization. + properties: + billingEmails: + description: Email addresses of billing contacts for this organization. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + type: string type: - array - "null" - nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - type: string - title: Exports Search Service Search Response - type: object - x-speakeasy-name-override: ExportsSearchServiceSearchResponse - c1.api.systemlog.v1.SystemLogServiceListEventsRequest: - description: The SystemLogServiceListEventsRequest message. - properties: - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - since: + createdAt: format: date-time + readOnly: true type: - string - "null" - sinceEventUid: - description: The sinceEventUid field. - type: string - sortDirection: - description: The sortDirection field. - enum: - - SORT_DIRECTION_UNSPECIFIED - - SORT_DIRECTION_ASC - - SORT_DIRECTION_DESC - type: string - x-speakeasy-unknown-values: allow - until: - format: date-time + operationsEmails: + description: Email addresses of operations contacts for this organization. + items: + type: string type: - - string + - array - "null" - untilEventUid: - description: The untilEventUid field. - type: string - title: System Log Service List Events Request - type: object - x-speakeasy-name-override: SystemLogServiceListEventsRequest - c1.api.systemlog.v1.SystemLogServiceListEventsResponse: - description: The SystemLogServiceListEventsResponse message. - properties: - list: - description: List contains an array of JSON OCSF events. + securityEmails: + description: Email addresses of security contacts for this organization. items: - additionalProperties: true - type: object + type: string type: - array - "null" - nextPageToken: - description: The nextPageToken field. - type: string - title: System Log Service List Events Response - type: object - x-speakeasy-name-override: SystemLogServiceListEventsResponse - c1.api.task.v1.ActionInstance: - description: | - ActionInstance is the API mirror of the internal immutable snapshot of an - Action captured on a TaskTypeAction at ticket-creation time. - - This message contains a oneof named target_ref. Only a single field of the following list may be set at a time: - - batonResourceActionRef - - connectorActionRef - properties: - batonResourceActionRef: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.BatonResourceActionRef' - - type: "null" - connectorActionRef: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.ConnectorActionRef' - - type: "null" - displayName: - description: |- - Display label at ticket-creation time. Same value as - TaskTypeAction.display_name; repeated here so clients that walk the - instance see a self-contained view. + updatedAt: + format: date-time readOnly: true - type: string - title: Action Instance + type: + - string + - "null" + title: Contacts type: object - x-speakeasy-name-override: TaskActionInstance - c1.api.task.v1.BatonResourceActionRef: - description: |- - BatonResourceActionRef describes dispatch to a connector resource-create - action (for example, a group template that creates a group in the connected - application). + x-speakeasy-name-override: Contacts + c1.api.settings.v1.DigestPreference: + description: DigestPreference controls whether summary digest notifications are sent and how often. properties: - appId: - description: The app the resource is created in. - readOnly: true + dayOfWeek: + description: The day of the week to send weekly digests. + enum: + - WEEKDAY_UNSPECIFIED + - WEEKDAY_MONDAY + - WEEKDAY_TUESDAY + - WEEKDAY_WEDNESDAY + - WEEKDAY_THURSDAY + - WEEKDAY_FRIDAY + - WEEKDAY_SATURDAY + - WEEKDAY_SUNDAY type: string - batonActionDisplayName: - description: The connector-defined display name of the resource-create action. - readOnly: true + x-speakeasy-unknown-values: allow + enabled: + description: Whether digest notifications are enabled. + type: boolean + frequency: + description: How often digest notifications are sent. + enum: + - DIGEST_FREQUENCY_UNSPECIFIED + - DIGEST_FREQUENCY_DAILY + - DIGEST_FREQUENCY_WEEKLY type: string - batonActionName: - description: The connector-defined name of the resource-create action. - readOnly: true + x-speakeasy-unknown-values: allow + locked: + description: Whether this preference is locked by org-level settings, preventing users from overriding it. + type: boolean + title: Digest Preference + type: object + x-speakeasy-name-override: DigestPreference + c1.api.settings.v1.EmailChannelSettings: + description: The EmailChannelSettings message. + properties: + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + requestCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestCreatedPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + system: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SystemPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Email Channel Settings + type: object + x-speakeasy-name-override: EmailChannelSettings + c1.api.settings.v1.ExpiringAccessPreference: + description: The ExpiringAccessPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Expiring Access Preference + type: object + x-speakeasy-name-override: ExpiringAccessPreference + c1.api.settings.v1.GetAWSExternalIDResponse: + description: The GetAWSExternalIDResponse message. + properties: + awsExternalId: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AWSExternalID' + - type: "null" + title: Get Aws External Id Response + type: object + x-speakeasy-name-override: GetAWSExternalIDResponse + c1.api.settings.v1.GetContactsResponse: + description: The GetContactsResponse message. + properties: + contacts: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - type: "null" + title: Get Contacts Response + type: object + x-speakeasy-name-override: GetContactsResponse + c1.api.settings.v1.GetEmailCapabilitiesResponse: + description: The GetEmailCapabilitiesResponse message. + properties: + externalEmailSupported: + description: |- + True when external email addresses (outside C1 users) can be used as + recipients in automation email steps. False when only the C1 built-in + provider is configured (C1 users only). + type: boolean + title: Get Email Capabilities Response + type: object + x-speakeasy-name-override: GetEmailCapabilitiesResponse + c1.api.settings.v1.GetOnboardingSettingsResponse: + description: The GetOnboardingSettingsResponse message. + properties: + conversationId: + description: The identifier of the onboarding conversation thread, if one is in progress. type: string - connectorId: - description: The connector that executes the resource-create action. - readOnly: true + intents: + description: The intents field. + items: + type: string + type: + - array + - "null" + mcpOnboardingGoal: + description: The admin's free-form AIAM onboarding goal, captured at the Goals step. type: string - resourceTypeId: - description: The type of resource the action creates (for example, "group"). - readOnly: true + mcpOnboardingStatus: + description: |- + The current status of the AIAM MCP onboarding briefing, tracked + independently of `status`. + enum: + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED type: string - title: Baton Resource Action Ref + x-speakeasy-unknown-values: allow + mcpOnboardingTargets: + description: |- + Per-target progress of the AIAM briefing: the servers/apps the admin chose + to govern and how far each got. + items: + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + type: + - array + - "null" + orgContext: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.OnboardingOrgContext' + - type: "null" + status: + description: The current status of the tenant onboarding process. + enum: + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED + type: string + x-speakeasy-unknown-values: allow + title: Get Onboarding Settings Response type: object - x-speakeasy-name-override: BatonResourceActionRef - c1.api.task.v1.ConnectorActionRef: + x-speakeasy-name-override: GetOnboardingSettingsResponse + c1.api.settings.v1.GetOrgNotificationSettingsResponse: + description: The GetOrgNotificationSettingsResponse message. + properties: + orgNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' + - type: "null" + title: Get Org Notification Settings Response + type: object + x-speakeasy-name-override: GetOrgNotificationSettingsResponse + c1.api.settings.v1.GetRequestSettingsResponse: + description: The GetRequestSettingsResponse message. + properties: + requestSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' + - type: "null" + title: Get Request Settings Response + type: object + x-speakeasy-name-override: GetRequestSettingsResponse + c1.api.settings.v1.GetSessionSettingsResponse: + description: The GetSessionSettingsResponse message. + properties: + sessionSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' + - type: "null" + title: Get Session Settings Response + type: object + x-speakeasy-name-override: GetSessionSettingsResponse + c1.api.settings.v1.GetTenantEmailProviderResponse: + description: The GetTenantEmailProviderResponse message. + properties: + emailProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' + - type: "null" + title: Get Tenant Email Provider Response + type: object + x-speakeasy-name-override: GetTenantEmailProviderResponse + c1.api.settings.v1.GetUserDeveloperPreferencesResponse: + description: The GetUserDeveloperPreferencesResponse message. + properties: + userDeveloperPreferences: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' + - type: "null" + title: Get User Developer Preferences Response + type: object + x-speakeasy-name-override: GetUserDeveloperPreferencesResponse + c1.api.settings.v1.GetUserNotificationSettingsResponse: + description: The GetUserNotificationSettingsResponse message. + properties: + userNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' + - type: "null" + title: Get User Notification Settings Response + type: object + x-speakeasy-name-override: GetUserNotificationSettingsResponse + c1.api.settings.v1.GoogleWorkspaceProviderConfig: description: |- - ConnectorActionRef describes dispatch through a connector's built-in - GrantManagerService Grant / Revoke RPC — i.e. the default connector - operation, used for synthesized tickets like scope-role requests. + GoogleWorkspaceProviderConfig configures sending via Google Workspace Gmail API + using domain-wide delegation with a service account. + Requires: customer Workspace super admin grants DWD to the service account's + OAuth client ID for the gmail.send scope. properties: - appId: - description: The app whose connector handles the operation. - readOnly: true + delegatedUser: + description: |- + The Workspace user email to impersonate via domain-wide delegation. + Typically a dedicated sender like noreply@customer.com. type: string - connectorId: - description: The connector that will execute the Grant / Revoke. - readOnly: true + serviceAccountJson: + description: |- + Service account JSON credentials. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing credentials". type: string - operation: - description: Which connector RPC this dispatches to. - enum: - - OPERATION_UNSPECIFIED - - OPERATION_GRANT - readOnly: true + title: Google Workspace Provider Config + type: object + x-speakeasy-name-override: GoogleWorkspaceProviderConfig + c1.api.settings.v1.ListOrgDomainsResponse: + description: The ListOrgDomainsResponse message. + properties: + list: + description: The list of verified domains. + items: + $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - x-speakeasy-unknown-values: allow - title: Connector Action Ref + title: List Org Domains Response type: object - x-speakeasy-name-override: ConnectorActionRef - c1.api.task.v1.ExternalRef: - description: A reference to an external source. This value is unused currently, but may be brought back. + x-speakeasy-name-override: ListOrgDomainsResponse + c1.api.settings.v1.MSTeamsChannelSettings: + description: The MSTeamsChannelSettings message. properties: - externalRefSource: - description: The source of the external reference. + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + isConfigured: + description: The isConfigured field. + type: boolean + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + requestCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestCreatedPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + system: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SystemPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Ms Teams Channel Settings + type: object + x-speakeasy-name-override: MSTeamsChannelSettings + c1.api.settings.v1.McpOnboardingTarget: + description: |- + McpOnboardingTarget is one server/app the admin chose to govern during the + AIAM briefing, plus its progress. + properties: + displayName: + description: Snapshot of the human label at selection time. + type: string + id: + description: Identifies the target within the id space named by kind. + type: string + kind: + description: The kind field. enum: - - UNSPECIFIED - - JIRA - readOnly: true + - MCP_ONBOARDING_TARGET_KIND_UNSPECIFIED + - MCP_ONBOARDING_TARGET_KIND_APP + - MCP_ONBOARDING_TARGET_KIND_CATALOG_ENTRY + - MCP_ONBOARDING_TARGET_KIND_MCP_SERVER type: string x-speakeasy-unknown-values: allow - name: - description: The name of the external reference. - readOnly: true + mcpServerId: + description: The registered MCP server a CATALOG_ENTRY target became, once registered. type: string - url: - description: The URL to the external reference. - readOnly: true + status: + description: The status field. + enum: + - MCP_ONBOARDING_TARGET_STATUS_UNSPECIFIED + - MCP_ONBOARDING_TARGET_STATUS_PENDING + - MCP_ONBOARDING_TARGET_STATUS_DONE + - MCP_ONBOARDING_TARGET_STATUS_SKIPPED type: string - title: External Ref + x-speakeasy-unknown-values: allow + title: Mcp Onboarding Target type: object - x-speakeasy-name-override: ExternalRef - c1.api.task.v1.FindingTarget: - description: The finding an inert TYPE_MANUAL action ticket remediates. + x-speakeasy-name-override: McpOnboardingTarget + c1.api.settings.v1.McpOnboardingTargetList: + description: |- + McpOnboardingTargetList wraps the target list so an update can distinguish + replace (present, even if empty) from leave-unchanged (omitted). properties: - findingId: - description: Reference to the source finding. - readOnly: true - type: string - findingType: - description: The finding type discriminator. - readOnly: true - type: string - title: Finding Target + targets: + description: The targets field. + items: + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + type: + - array + - "null" + title: Mcp Onboarding Target List type: object - x-speakeasy-name-override: FindingTarget - c1.api.task.v1.GatedToolCallTarget: - description: The GatedToolCallTarget message. + x-speakeasy-name-override: McpOnboardingTargetList + c1.api.settings.v1.MicrosoftGraphProviderConfig: + description: |- + MicrosoftGraphProviderConfig configures sending via Microsoft Graph sendMail API. + Requires an Azure AD app registration with Mail.Send application permission (admin-consented). properties: - appEntitlementId: - description: The appEntitlementId field. - readOnly: true - type: string - appId: - description: The appId field. - readOnly: true - type: string - callerKind: - description: The callerKind field. - readOnly: true + azureTenantId: + description: Customer's Azure AD tenant ID (directory ID). type: string - connectorId: - description: The connectorId field. - readOnly: true + clientId: + description: App registration client ID with Mail.Send application permission. type: string - gateId: - description: The gateId field. - readOnly: true + clientSecret: + description: |- + Client secret. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing secret". type: string - inputSizeBytes: - description: The inputSizeBytes field. - format: int32 - readOnly: true - type: integer - toolError: - description: The toolError field. - readOnly: true + title: Microsoft Graph Provider Config + type: object + x-speakeasy-name-override: MicrosoftGraphProviderConfig + c1.api.settings.v1.OnboardingOrgContext: + description: The OnboardingOrgContext message. + properties: + industry: + description: The industry field. type: string - toolId: - description: The toolId field. - readOnly: true + organizationSize: + description: The organizationSize field. type: string - toolInput: - additionalProperties: true + title: Onboarding Org Context + type: object + x-speakeasy-name-override: OnboardingOrgContext + c1.api.settings.v1.OrgDomain: + description: OrgDomain represents a verified email domain associated with the tenant. + properties: + createdAt: + format: date-time readOnly: true type: - - object + - string - "null" - toolKind: - description: The toolKind field. + deletedAt: + format: date-time readOnly: true + type: + - string + - "null" + domain: + description: The verified domain name (e.g., "example.com"). type: string - toolName: - description: The toolName field. - readOnly: true + id: + description: The unique identifier of the domain record. type: string - toolOutput: + updatedAt: + format: date-time readOnly: true type: - string - - number - - object - - array - - boolean - "null" - title: Gated Tool Call Target + title: Org Domain type: object - x-speakeasy-name-override: GatedToolCallTarget - c1.api.task.v1.ScopeRole: - description: |- - Scope-role variant of TaskTypeAction.target_object. The UI uses the - embedded identifiers to build links and title strings without a separate - Action fetch. + x-speakeasy-name-override: OrgDomain + c1.api.settings.v1.OrgNotificationSettings: + description: OrgNotificationSettings contains organization-wide notification channel configurations and default preferences. properties: - appId: - description: The IaaS/sparse-ACL app the (scope, role) pair lives on. - readOnly: true - type: string - grantDuration: - format: duration - readOnly: true - type: - - string - - "null" - roleResourceId: - description: The roleResourceId field. - readOnly: true - type: string - roleResourceTypeId: - description: The roleResourceTypeId field. - readOnly: true - type: string - scopeResourceId: - description: The scopeResourceId field. - readOnly: true - type: string - scopeResourceTypeId: - description: The scopeResourceTypeId field. - readOnly: true - type: string - title: Scope Role + channelSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - type: "null" + title: Org Notification Settings type: object - x-speakeasy-name-override: ScopeRole - c1.api.task.v1.Task: - description: A fully-fleged task object. Includes its policy, references to external apps, its type, its processing history, and more. + x-speakeasy-name-override: OrgNotificationSettings + c1.api.settings.v1.ProvisioningRequestPreference: + description: The ProvisioningRequestPreference message. properties: - actions: - description: The actions that can be performed on the task by the current user. - items: - enum: - - TASK_ACTION_TYPE_UNSPECIFIED - - TASK_ACTION_TYPE_CLOSE - - TASK_ACTION_TYPE_APPROVE - - TASK_ACTION_TYPE_DENY - - TASK_ACTION_TYPE_COMMENT - - TASK_ACTION_TYPE_DELETE - - TASK_ACTION_TYPE_REASSIGN - - TASK_ACTION_TYPE_RESTART - - TASK_ACTION_TYPE_SEND_REMINDER - - TASK_ACTION_TYPE_PROVISION_COMPLETE - - TASK_ACTION_TYPE_PROVISION_CANCELLED - - TASK_ACTION_TYPE_PROVISION_ERRORED - - TASK_ACTION_TYPE_ROLLBACK_SKIPPED - - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED - - TASK_ACTION_TYPE_HARD_RESET - - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS - - TASK_ACTION_TYPE_CHANGE_POLICY - - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS - - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION - - TASK_ACTION_TYPE_SET_ANALYSIS_ID - - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST - - TASK_ACTION_TYPE_PROCESS_NOW - - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP - - TASK_ACTION_TYPE_SKIP_STEP - - TASK_ACTION_TYPE_ROLLBACK_CANCELLED - - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA - - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION - type: string - x-speakeasy-unknown-values: allow - readOnly: true - type: - - array - - "null" - analysisId: - description: The ID of the analysis object associated with this task created by an analysis workflow if the analysis feature is enabled for your tenant. - readOnly: true + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Provisioning Request Preference + type: object + x-speakeasy-name-override: ProvisioningRequestPreference + c1.api.settings.v1.RequestCreatedPreference: + description: The RequestCreatedPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Request Created Preference + type: object + x-speakeasy-name-override: RequestCreatedPreference + c1.api.settings.v1.RequestSettings: + description: RequestSettings holds tenant-wide configuration for the access-request flow. + properties: + maxBulkEntitlementSelection: + description: |- + MaxBulkEntitlementSelection caps the number of entitlements a requester + may select in a single bulk access request. Reads always return the + effective value — an unset (0) value is presented as the system default of + 10. Writing 0 resets the field to unset in storage. Maximum 100. + format: int32 + type: integer + skipJustification: + description: |- + When true, request surfaces (webapp, Slack, MS Teams) skip prompting the + requester for a justification. + type: boolean + title: Request Settings + type: object + x-speakeasy-name-override: RequestSettings + c1.api.settings.v1.ReviewsPreference: + description: The ReviewsPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Reviews Preference + type: object + x-speakeasy-name-override: ReviewsPreference + c1.api.settings.v1.SearchEmailAuditEventsRequest: + description: The SearchEmailAuditEventsRequest message. + properties: + pageSize: + description: Maximum results per page (0 = server default, max 100). + format: int32 + type: integer + pageToken: + description: Pagination token from previous response. type: string - annotations: - description: An array of `google.protobuf.Any` annotations with various base64-encoded data. + title: Search Email Audit Events Request + type: object + x-speakeasy-name-override: SearchEmailAuditEventsRequest + c1.api.settings.v1.SearchEmailAuditEventsResponse: + description: The SearchEmailAuditEventsResponse message. + properties: + list: + description: OCSF EmailActivity events as Struct for frontend rendering. items: additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true type: object - readOnly: true - type: - - array - - "null" - approverIds: - description: An array of IDs belonging to Identity Users that have approved or denied any step in this task. - items: - type: string - readOnly: true type: - array - "null" - commentCount: - description: The count of comments. - format: int32 - readOnly: true - type: integer - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - createdByUserId: - description: The ID of the user that is the creator of this task. This may not always match the userId field. - readOnly: true + nextPageToken: + description: Token for next page. Empty when no more pages. type: string - data: - additionalProperties: true - readOnly: true - type: - - object - - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - description: - description: The description of the task. This is also known as justification. - readOnly: true + title: Search Email Audit Events Response + type: object + x-speakeasy-name-override: SearchEmailAuditEventsResponse + c1.api.settings.v1.SendGridProviderConfig: + description: SendGridProviderConfig configures sending via a customer's SendGrid account. + properties: + apiKey: + description: |- + Customer's SendGrid API key. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing key". type: string - displayName: - description: The display name of the task. - readOnly: true + title: Send Grid Provider Config + type: object + x-speakeasy-name-override: SendGridProviderConfig + c1.api.settings.v1.SessionSettings: + description: SessionSettings configures session security for the tenant, including timeouts and per-role IP restrictions. + properties: + clientIdApprovalRequestPolicyId: + description: Policy ID for REQUESTABLE mode approval routing. type: string - emergencyAccess: - description: A field indicating whether this task was created using an emergency access flow, or escalated to emergency access. On task creation, it will also use the app entitlement's emergency policy when possible. - readOnly: true + clientIdMetadataDocumentPolicy: + description: Policy for metadata document client_id URLs. + enum: + - CLIENT_ID_METADATA_DOCUMENT_POLICY_UNSPECIFIED + - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOW_ALL + - CLIENT_ID_METADATA_DOCUMENT_POLICY_REQUESTABLE + - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOWLIST_ONLY + type: string + x-speakeasy-unknown-values: allow + connectorSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + externalClientSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + externalClientsEnabled: + description: |- + Enable external client registration (OAuth 2.0 DCR) for MCP clients + like Claude Desktop, Cursor, and other AI assistants. type: boolean - externalRefs: - description: An array of external references to the task. Historically that has been items like Jira task IDs. This is currently unused, but may come back in the future for integrations. - items: - $ref: '#/components/schemas/c1.api.task.v1.ExternalRef' - readOnly: true + maxSessionLength: + format: duration type: - - array + - string - "null" - form: + pccAdminSource: oneOf: - - $ref: '#/components/schemas/c1.api.form.v1.Form' + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - type: "null" - id: - description: The ID of the task. + pccUserSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + ssoAdminSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + ssoUserSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + title: Session Settings + type: object + x-speakeasy-name-override: SessionSettings + c1.api.settings.v1.SlackChannelSettings: + description: The SlackChannelSettings message. + properties: + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + isConfigured: + description: The isConfigured field. + type: boolean + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + requestCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestCreatedPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + system: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SystemPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Slack Channel Settings + type: object + x-speakeasy-name-override: SlackChannelSettings + c1.api.settings.v1.SystemPreference: + description: The SystemPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: System Preference + type: object + x-speakeasy-name-override: SystemPreference + c1.api.settings.v1.TaskRemindersPreference: + description: The TaskRemindersPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Task Reminders Preference + type: object + x-speakeasy-name-override: TaskRemindersPreference + c1.api.settings.v1.TenantEmailProvider: + description: | + TenantEmailProvider is the API representation of the tenant's email provider. + + This message contains a oneof named provider. Only a single field of the following list may be set at a time: + - c1Builtin + - awsSes + - sendgrid + - microsoftGraph + - googleWorkspace + properties: + awsSes: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AWSSESProviderConfig' + - type: "null" + c1Builtin: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.C1BuiltInProviderConfig' + - type: "null" + createdAt: + format: date-time readOnly: true - type: string - insightIds: - description: The insightIds field. - items: - type: string type: - - array + - string - "null" - numericId: - description: A human-usable numeric ID of a task which can be included in place of the fully qualified task id in path parmeters (but not search queries). - format: int64 - readOnly: true + fromAddress: + description: |- + Sender email address. Must be verified with the provider. + Ignored when using the C1 built-in provider (uses no-reply@conductorone.com). type: string - origin: - description: The origin field. - enum: - - TASK_ORIGIN_UNSPECIFIED - - TASK_ORIGIN_PROFILE_MEMBERSHIP_AUTOMATION - - TASK_ORIGIN_SLACK - - TASK_ORIGIN_API - - TASK_ORIGIN_JIRA - - TASK_ORIGIN_COPILOT - - TASK_ORIGIN_WEBAPP - - TASK_ORIGIN_TIME_REVOKE - - TASK_ORIGIN_NON_USAGE_REVOKE - - TASK_ORIGIN_PROFILE_MEMBERSHIP_MANUAL - - TASK_ORIGIN_PROFILE_MEMBERSHIP - - TASK_ORIGIN_AUTOMATION - - TASK_ORIGIN_ACCESS_REVIEW - - TASK_ORIGIN_CASCADE_DELETE + fromName: + description: |- + Sender display name shown in the recipient's inbox (e.g., "Acme Corp IT"). + Used as the RFC 5322 display-name: "Acme Corp IT" . + Ignored when using the C1 built-in provider. type: string - x-speakeasy-unknown-values: allow - policy: + googleWorkspace: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.PolicyInstance' + - $ref: '#/components/schemas/c1.api.settings.v1.GoogleWorkspaceProviderConfig' - type: "null" - policyGenerationId: - description: The policy generation id refers to the current policy's generation ID. This is changed when the policy is changed on a task. - readOnly: true - type: string - processing: - description: The processing state of a task as defined by the `processing_enum` - enum: - - TASK_PROCESSING_TYPE_UNSPECIFIED - - TASK_PROCESSING_TYPE_PROCESSING - - TASK_PROCESSING_TYPE_WAITING - - TASK_PROCESSING_TYPE_DONE - readOnly: true - type: string - x-speakeasy-unknown-values: allow - recommendation: - description: The recommendation field. - enum: - - INSIGHT_RECOMMENDATION_UNSPECIFIED - - INSIGHT_RECOMMENDATION_APPROVE - - INSIGHT_RECOMMENDATION_DENY - - INSIGHT_RECOMMENDATION_REVIEW - type: string - x-speakeasy-unknown-values: allow - revocationTargets: - description: |- - Ancestor entitlements that will also be revoked when this revoke task is approved. - Populated at ticket creation time for inherited grant revocations. - items: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevocationTarget' - readOnly: true - type: - - array - - "null" - state: - description: The current state of the task as defined by the `state_enum` - enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED - readOnly: true + microsoftGraph: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.MicrosoftGraphProviderConfig' + - type: "null" + replyToAddress: + description: Optional reply-to address. type: string - x-speakeasy-unknown-values: allow - stepApproverIds: - description: An array of IDs belonging to Identity Users that are allowed to review this step in a task. - items: - type: string - readOnly: true - type: - - array - - "null" - type: + sendgrid: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskType' + - $ref: '#/components/schemas/c1.api.settings.v1.SendGridProviderConfig' - type: "null" updatedAt: format: date-time @@ -33845,4091 +35548,3557 @@ components: type: - string - "null" - userId: - description: The ID of the user that is the target of this task. This may be empty if we're targeting a specific app user that has no known identity user. - readOnly: true - type: string - title: Task + title: Tenant Email Provider type: object - x-speakeasy-name-override: Task - c1.api.task.v1.TaskAction: - description: Represents a single action that was performed on a task. + x-speakeasy-name-override: TenantEmailProvider + c1.api.settings.v1.TerraformPreferences: + description: |- + TerraformPreferences groups the user's preferences for the "Show + Terraform code" feature. properties: - actionType: - description: The type of action that was performed. - enum: - - TASK_ACTION_TYPE_UNSPECIFIED - - TASK_ACTION_TYPE_CLOSE - - TASK_ACTION_TYPE_APPROVE - - TASK_ACTION_TYPE_DENY - - TASK_ACTION_TYPE_COMMENT - - TASK_ACTION_TYPE_DELETE - - TASK_ACTION_TYPE_REASSIGN - - TASK_ACTION_TYPE_RESTART - - TASK_ACTION_TYPE_SEND_REMINDER - - TASK_ACTION_TYPE_PROVISION_COMPLETE - - TASK_ACTION_TYPE_PROVISION_CANCELLED - - TASK_ACTION_TYPE_PROVISION_ERRORED - - TASK_ACTION_TYPE_ROLLBACK_SKIPPED - - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED - - TASK_ACTION_TYPE_HARD_RESET - - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS - - TASK_ACTION_TYPE_CHANGE_POLICY - - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS - - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION - - TASK_ACTION_TYPE_SET_ANALYSIS_ID - - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST - - TASK_ACTION_TYPE_PROCESS_NOW - - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP - - TASK_ACTION_TYPE_SKIP_STEP - - TASK_ACTION_TYPE_ROLLBACK_CANCELLED - - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA - - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION - type: string - x-speakeasy-unknown-values: allow - bulkActionId: - description: The ID of the bulk action this action belongs to, if it was part of a bulk operation. - type: string - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - deletedAt: - format: date-time - readOnly: true - type: - - string - - "null" - id: - description: The unique ID of this action. - type: string - policyStepId: - description: The ID of the policy step this action was performed on. - type: string - updatedAt: - format: date-time - readOnly: true + showCode: + description: |- + When true, the user sees the "Show Terraform code" trigger on + supported detail pages and list rows. Defaults to false. + + Visibility is also role-gated: the trigger is shown only to users + with one of the SystemOwner, SystemOwnerReadOnly, IntegrationAdmin, + ApplicationAdmin, CampaignAdmin, or AccessRequestAdmin roles. Users + without one of these roles will not see the trigger even when this + flag is true. + type: boolean + title: Terraform Preferences + type: object + x-speakeasy-name-override: TerraformPreferences + c1.api.settings.v1.TestSourceIPRequest: + description: The TestSourceIPRequest message. + properties: + allowCidr: + description: |- + The CIDR allowlist rules to test against. If empty, uses the tenant's current allowlist. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string type: - - string + - array - "null" - userId: - description: The ID of the user who performed the action. + sourceIp: + description: |- + if unset, uses the source IP of the request. + Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. type: string - title: Task Action + title: Test Source Ip Request type: object - x-speakeasy-name-override: SubmittedTaskAction - c1.api.task.v1.TaskActionsServiceApproveRequestInput: - description: The TaskActionsServiceApproveRequest object lets you approve a task. + x-speakeasy-name-override: TestSourceIPRequest + c1.api.settings.v1.TestSourceIPResponse: + description: The TestSourceIPResponse message. properties: - comment: - description: The comment attached to the request. + allowed: + description: Whether the tested IP address is allowed by the CIDR rules. + type: boolean + checkedIp: + description: The IP address that was checked, either from the request or inferred from the caller. type: string - expandMask: + details: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/google.rpc.Status' - type: "null" - policyStepId: - description: The ID of the policy step on the given task to approve. + title: Test Source Ip Response + type: object + x-speakeasy-name-override: TestSourceIPResponse + c1.api.settings.v1.TestTenantEmailProviderRequest: + description: The TestTenantEmailProviderRequest message. + properties: + testRecipientEmail: + description: The email address to send the test email to. type: string - required: - - policyStepId - title: Task Actions Service Approve Request + title: Test Tenant Email Provider Request type: object - x-speakeasy-name-override: TaskActionsServiceApproveRequest - c1.api.task.v1.TaskActionsServiceApproveResponse: - description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: TestTenantEmailProviderRequest + c1.api.settings.v1.TestTenantEmailProviderResponse: + description: The TestTenantEmailProviderResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true + message: + description: Human-readable detail about the result. + type: string + success: + description: Whether the test email was sent successfully. + type: boolean + title: Test Tenant Email Provider Response + type: object + x-speakeasy-name-override: TestTenantEmailProviderResponse + c1.api.settings.v1.UpdateContactsRequest: + description: The UpdateContactsRequest message. + properties: + contacts: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - type: "null" + updateMask: type: - - array + - string - "null" - taskView: + title: Update Contacts Request + type: object + x-speakeasy-name-override: UpdateContactsRequest + c1.api.settings.v1.UpdateContactsResponse: + description: The UpdateContactsResponse message. + properties: + contacts: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' - type: "null" - ticketActionId: - description: The ID of the task approve action created by this request. - readOnly: true - type: string - title: Task Actions Service Approve Response + title: Update Contacts Response type: object - x-speakeasy-name-override: TaskActionsServiceApproveResponse - c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput: - description: TaskActionsServiceApproveWithStepUpRequest is used to approve a task with step-up authentication + x-speakeasy-name-override: UpdateContactsResponse + c1.api.settings.v1.UpdateOnboardingSettingsRequest: + description: The UpdateOnboardingSettingsRequest message. properties: - comment: - description: The comment attached to the request. + conversationId: + description: The identifier of the onboarding conversation thread to associate. type: string - expandMask: + mcpOnboardingGoal: + description: The admin's AIAM onboarding goal. Omit to leave unchanged; set to "" to clear. + type: + - string + - "null" + mcpOnboardingStatus: + description: |- + The new MCP onboarding status to set. Omit (or UNSPECIFIED) to leave it + unchanged. Setting NOT_STARTED restarts the briefing and clears the stored + mcp_onboarding_goal and mcp_onboarding_targets, unless this same request also + sets them (those win). + enum: + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED + type: + - string + - "null" + x-speakeasy-unknown-values: allow + mcpOnboardingTargets: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTargetList' - type: "null" - policyStepId: - description: The ID of the policy step on the given task to approve. - type: string - stepUpTransactionId: + status: description: |- - The step-up transaction ID that was verified. - If unset, the response will include a redirect URL to - complete the step-up authentication. + The new onboarding status to set. UNSPECIFIED leaves the core onboarding + status unchanged (set mcp_onboarding_status alone to retire the AIAM + briefing without touching the core wizard). + enum: + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED type: string - required: - - policyStepId - - stepUpTransactionId - title: Task Actions Service Approve With Step Up Request + x-speakeasy-unknown-values: allow + title: Update Onboarding Settings Request type: object - x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpRequest - c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse: - description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication + x-speakeasy-name-override: UpdateOnboardingSettingsRequest + c1.api.settings.v1.UpdateOnboardingSettingsResponse: + description: The UpdateOnboardingSettingsResponse message. properties: - expanded: - description: List of serialized related objects. + mcpOnboardingGoal: + description: The updated AIAM onboarding goal. + type: string + mcpOnboardingStatus: + description: The updated AIAM MCP onboarding status. + enum: + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED + type: string + x-speakeasy-unknown-values: allow + mcpOnboardingTargets: + description: The updated AIAM onboarding targets. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' type: - array - "null" - redirectUrl: - description: The redirect URL the client must visit to complete the step-up authentication. - type: string - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - ticketActionId: - description: The ID of the task approve action created by this request. - readOnly: true + status: + description: The updated onboarding status. + enum: + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED type: string - title: Task Actions Service Approve With Step Up Response + x-speakeasy-unknown-values: allow + title: Update Onboarding Settings Response type: object - x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpResponse - c1.api.task.v1.TaskActionsServiceCloseRequestInput: - description: The TaskActionsServiceCloseRequest object lets you close or cancel a task. + x-speakeasy-name-override: UpdateOnboardingSettingsResponse + c1.api.settings.v1.UpdateOrgDomainRequest: + description: The UpdateOrgDomainRequest message. properties: - comment: - description: An optional comment attached to the close action. - type: string - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - - type: "null" - title: Task Actions Service Close Request + newDomains: + description: The complete list of domain names that should be set as the tenant's verified domains. + items: + type: string + type: + - array + - "null" + title: Update Org Domain Request type: object - x-speakeasy-name-override: TaskActionsServiceCloseRequest - c1.api.task.v1.TaskActionsServiceCloseResponse: - description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: UpdateOrgDomainRequest + c1.api.settings.v1.UpdateOrgDomainResponse: + description: The UpdateOrgDomainResponse message. properties: - expanded: - description: List of serialized related objects. + list: + description: The resulting list of verified domains after the update. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true + $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' type: - array - "null" - taskActionId: - description: The ID of the task close action created by this request. - readOnly: true - type: string - taskView: + title: Update Org Domain Response + type: object + x-speakeasy-name-override: UpdateOrgDomainResponse + c1.api.settings.v1.UpdateOrgNotificationSettingsRequest: + description: The UpdateOrgNotificationSettingsRequest message. + properties: + channelSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - type: "null" - title: Task Actions Service Close Response + title: Update Org Notification Settings Request type: object - x-speakeasy-name-override: TaskActionsServiceCloseResponse - c1.api.task.v1.TaskActionsServiceCommentRequestInput: - description: The TaskActionsServiceCommentRequest object lets you create a new comment on a task. + x-speakeasy-name-override: UpdateOrgNotificationSettingsRequest + c1.api.settings.v1.UpdateOrgNotificationSettingsResponse: + description: The UpdateOrgNotificationSettingsResponse message. properties: - comment: - description: The comment to be posted to the task. - type: string - expandMask: + orgNotificationSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' - type: "null" - title: Task Actions Service Comment Request + title: Update Org Notification Settings Response type: object - x-speakeasy-name-override: TaskActionsServiceCommentRequest - c1.api.task.v1.TaskActionsServiceCommentResponse: - description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. + x-speakeasy-name-override: UpdateOrgNotificationSettingsResponse + c1.api.settings.v1.UpdateRequestSettingsRequest: + description: The UpdateRequestSettingsRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: + requestSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' - type: "null" - title: Task Actions Service Comment Response + updateMask: + type: + - string + - "null" + title: Update Request Settings Request type: object - x-speakeasy-name-override: TaskActionsServiceCommentResponse - c1.api.task.v1.TaskActionsServiceDenyRequestInput: - description: The TaskActionsServiceDenyRequest object lets you deny a task. + x-speakeasy-name-override: UpdateRequestSettingsRequest + c1.api.settings.v1.UpdateRequestSettingsResponse: + description: The UpdateRequestSettingsResponse message. properties: - comment: - description: The comment attached to the request. - type: string - expandMask: + requestSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' - type: "null" - policyStepId: - description: The ID of the current policy step. This is the step you want to deny. - type: string - title: Task Actions Service Deny Request + title: Update Request Settings Response type: object - x-speakeasy-name-override: TaskActionsServiceDenyRequest - c1.api.task.v1.TaskActionsServiceDenyResponse: - description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: UpdateRequestSettingsResponse + c1.api.settings.v1.UpdateSessionSettingsRequest: + description: The UpdateSessionSettingsRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true + sessionSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' + - type: "null" + updateMask: type: - - array + - string - "null" - taskView: + title: Update Session Settings Request + type: object + x-speakeasy-name-override: UpdateSessionSettingsRequest + c1.api.settings.v1.UpdateSessionSettingsResponse: + description: The UpdateSessionSettingsResponse message. + properties: + sessionSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - type: "null" - ticketActionId: - description: The ID of the task deny action created by this request. - readOnly: true - type: string - title: Task Actions Service Deny Response + title: Update Session Settings Response type: object - x-speakeasy-name-override: TaskActionsServiceDenyResponse - c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput: - description: The TaskActionsServiceEscalateToEmergencyAccessRequest object lets you escalate a task to the emergency access workflow. + x-speakeasy-name-override: UpdateSessionSettingsResponse + c1.api.settings.v1.UpdateTenantEmailProviderRequest: + description: The UpdateTenantEmailProviderRequest message. properties: - comment: - description: An optional comment attached to the escalation. - type: string - expandMask: + emailProvider: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - type: "null" - policyStepId: - description: The ID of the current policy step being escalated from. - type: string - title: Task Actions Service Escalate To Emergency Access Request + updateMask: + type: + - string + - "null" + title: Update Tenant Email Provider Request type: object - x-speakeasy-name-override: TaskActionsServiceEscalateToEmergencyAccessRequest - c1.api.task.v1.TaskActionsServiceHardResetRequestInput: - description: The TaskActionsServiceHardResetRequest object lets you reset a task and recalculate its policy. + x-speakeasy-name-override: UpdateTenantEmailProviderRequest + c1.api.settings.v1.UpdateTenantEmailProviderResponse: + description: The UpdateTenantEmailProviderResponse message. properties: - comment: - description: The comment attached to the request. - type: string - expandMask: + emailProvider: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - type: "null" - title: Task Actions Service Hard Reset Request + title: Update Tenant Email Provider Response type: object - x-speakeasy-name-override: TaskActionsServiceHardResetRequest - c1.api.task.v1.TaskActionsServiceHardResetResponse: - description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. + x-speakeasy-name-override: UpdateTenantEmailProviderResponse + c1.api.settings.v1.UpdateUserDeveloperPreferencesRequest: + description: The UpdateUserDeveloperPreferencesRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: + terraform: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' - type: "null" - ticketActionId: - description: The ID of the task reset action created by this request. - type: string - title: Task Actions Service Hard Reset Response + title: Update User Developer Preferences Request type: object - x-speakeasy-name-override: TaskActionsServiceHardResetResponse - c1.api.task.v1.TaskActionsServiceProcessNowRequestInput: - description: The TaskActionsServiceProcessNowRequest object lets you trigger processing of a task immediately. + x-speakeasy-name-override: UpdateUserDeveloperPreferencesRequest + c1.api.settings.v1.UpdateUserDeveloperPreferencesResponse: + description: The UpdateUserDeveloperPreferencesResponse message. properties: - expandMask: + userDeveloperPreferences: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' - type: "null" - title: Task Actions Service Process Now Request + title: Update User Developer Preferences Response type: object - x-speakeasy-name-override: TaskActionsServiceProcessNowRequest - c1.api.task.v1.TaskActionsServiceProcessNowResponse: - description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. + x-speakeasy-name-override: UpdateUserDeveloperPreferencesResponse + c1.api.settings.v1.UpdateUserNotificationSettingsRequest: + description: The UpdateUserNotificationSettingsRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: + channelSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - type: "null" - title: Task Actions Service Process Now Response + title: Update User Notification Settings Request type: object - x-speakeasy-name-override: TaskActionsServiceProcessNowResponse - c1.api.task.v1.TaskActionsServiceReassignRequestInput: - description: The TaskActionsServiceReassignRequest object lets you reassign a task's current policy step to different users. + x-speakeasy-name-override: UpdateUserNotificationSettingsRequest + c1.api.settings.v1.UpdateUserNotificationSettingsResponse: + description: The UpdateUserNotificationSettingsResponse message. properties: - comment: - description: An optional comment attached to the reassignment. - type: string - expandMask: + userNotificationSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' - type: "null" - newStepUserIds: - description: The IDs of the users to reassign the current policy step to. Must be from the allowed reassignees list. - items: - type: string - type: - - array - - "null" - policyStepId: - description: The ID of the current policy step to reassign. Must match the task's active step. - type: string - title: Task Actions Service Reassign Request + title: Update User Notification Settings Response type: object - x-speakeasy-name-override: TaskActionsServiceReassignRequest - c1.api.task.v1.TaskActionsServiceReassignResponse: - description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: UpdateUserNotificationSettingsResponse + c1.api.settings.v1.UserDeveloperPreferences: + description: |- + UserDeveloperPreferences holds a user's developer-tooling preferences, + organized into per-feature clusters. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true - type: - - array - - "null" - taskView: + terraform: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' - type: "null" - ticketActionId: - description: The ID of the task reassign action created by this request. - readOnly: true - type: string - title: Task Actions Service Reassign Response + title: User Developer Preferences type: object - x-speakeasy-name-override: TaskActionsServiceReassignResponse - c1.api.task.v1.TaskActionsServiceRestartRequestInput: - description: The TaskActionsServiceRestartRequest object lets you restart a task. + x-speakeasy-name-override: UserDeveloperPreferences + c1.api.settings.v1.UserNotificationSettings: + description: UserNotificationSettings contains the calling user's personal notification preferences. properties: - comment: - description: The comment attached to the request. - type: string - expandMask: + channelSettings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - type: "null" - policyStepId: - description: Deprecated. This field is accepted but does not affect behavior. + title: User Notification Settings + type: object + x-speakeasy-name-override: UserNotificationSettings + c1.api.sign_in_policy.v1.Allow: + description: Allow permits the sign-in. + properties: + floorLevel: + description: |- + The minimum assurance level that satisfies this rule. Required on enforced + Allow rules. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - title: Task Actions Service Restart Request + x-speakeasy-unknown-values: allow + title: Allow type: object - x-speakeasy-name-override: TaskActionsServiceRestartRequest - c1.api.task.v1.TaskActionsServiceRestartResponse: - description: The TaskActionsServiceRestartResponse returns the updated task after restarting. + x-speakeasy-name-override: Allow + c1.api.sign_in_policy.v1.ChallengeRequired: + description: ChallengeRequired asks for an additional factor before the sign-in completes. properties: - expanded: - description: List of serialized related objects. + types: + description: The credential types that may satisfy the challenge. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - ticketActionId: - description: The ID of the task restart action created by this request. - type: string - title: Task Actions Service Restart Response + title: Challenge Required type: object - x-speakeasy-name-override: TaskActionsServiceRestartResponse - c1.api.task.v1.TaskActionsServiceSkipStepRequestInput: - description: The TaskActionsServiceSkipStepRequest object lets you skip a policy step in a task. + x-speakeasy-name-override: ChallengeRequired + c1.api.sign_in_policy.v1.Deny: + description: Deny rejects the sign-in. properties: - comment: - description: The comment attached to the request. + reasonAdmin: + description: Reason shown in admin-only audit. type: string - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - - type: "null" - policyStepId: - description: The ID of the policy step to skip. + reasonUser: + description: Reason safe to show the end user. type: string - required: - - policyStepId - title: Task Actions Service Skip Step Request - type: object - x-speakeasy-name-override: TaskActionsServiceSkipStepRequest - c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput: - description: The TaskActionsServiceUpdateGrantDurationRequest object lets you change the grant duration on a grant task. - properties: - duration: - format: duration - type: - - string - - "null" - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - - type: "null" - required: - - duration - title: Task Actions Service Update Grant Duration Request + title: Deny type: object - x-speakeasy-name-override: TaskActionsServiceUpdateGrantDurationRequest - c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput: - description: The TaskActionsServiceUpdateRequestDataRequest object lets you submit form data for a task that is in a form policy step. + x-speakeasy-name-override: Deny + c1.api.sign_in_policy.v1.EnrollmentRequired: + description: EnrollmentRequired tells the user to enroll a credential before continuing. properties: - data: - additionalProperties: true + credentialTypes: + description: |- + The credential types the user may enroll. Empty means "complete identity + verification first". + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow type: - - object + - array - "null" - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - - type: "null" - title: Task Actions Service Update Request Data Request - type: object - x-speakeasy-name-override: TaskActionsServiceUpdateRequestDataRequest - c1.api.task.v1.TaskAuditAccessRequestOutcome: - description: The TaskAuditAccessRequestOutcome message. - properties: - outcome: - description: The outcome field. - enum: - - ACCESS_REQUEST_OUTCOME_UNSPECIFIED - - ACCESS_REQUEST_OUTCOME_APPROVED - - ACCESS_REQUEST_OUTCOME_DENIED - - ACCESS_REQUEST_OUTCOME_ERROR - - ACCESS_REQUEST_OUTCOME_CANCELLED - type: string - x-speakeasy-unknown-values: allow - title: Task Audit Access Request Outcome - type: object - x-speakeasy-name-override: TaskAuditAccessRequestOutcome - c1.api.task.v1.TaskAuditAccountLifecycleActionCreated: - description: The TaskAuditAccountLifecycleActionCreated message. - properties: - batonActionDisplayName: - description: The batonActionDisplayName field. - type: string - batonActionInvocationId: - description: The batonActionInvocationId field. - type: string - batonActionName: - description: The batonActionName field. - type: string - batonAppId: - description: The batonAppId field. - type: string - batonConnectorId: - description: The batonConnectorId field. - type: string - title: Task Audit Account Lifecycle Action Created - type: object - x-speakeasy-name-override: TaskAuditAccountLifecycleActionCreated - c1.api.task.v1.TaskAuditAccountLifecycleActionFailed: - description: The TaskAuditAccountLifecycleActionFailed message. - properties: - batonActionDisplayName: - description: The batonActionDisplayName field. - type: string - batonActionInvocationId: - description: The batonActionInvocationId field. - type: string - batonActionName: - description: The batonActionName field. - type: string - batonAppId: - description: The batonAppId field. - type: string - batonConnectorId: - description: The batonConnectorId field. - type: string - error: - description: The error field. - type: string - title: Task Audit Account Lifecycle Action Failed + title: Enrollment Required type: object - x-speakeasy-name-override: TaskAuditAccountLifecycleActionFailed - c1.api.task.v1.TaskAuditActionInstanceCreated: - description: The TaskAuditActionInstanceCreated message. + x-speakeasy-name-override: EnrollmentRequired + c1.api.sign_in_policy.v1.PolicyOutcome: + description: | + PolicyOutcome is the effect of a matched rule. Exactly one kind is set. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - allow + - deny + - stepUpRequired + - challengeRequired + - enrollmentRequired properties: - instance: + allow: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Allow' - type: "null" - title: Task Audit Action Instance Created - type: object - x-speakeasy-name-override: TaskAuditActionInstanceCreated - c1.api.task.v1.TaskAuditActionInstanceFailed: - description: The TaskAuditActionInstanceFailed message. - properties: - instance: + challengeRequired: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.ChallengeRequired' - type: "null" - title: Task Audit Action Instance Failed - type: object - x-speakeasy-name-override: TaskAuditActionInstanceFailed - c1.api.task.v1.TaskAuditActionInstanceSucceeded: - description: The TaskAuditActionInstanceSucceeded message. - properties: - instance: + deny: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Deny' - type: "null" - title: Task Audit Action Instance Succeeded - type: object - x-speakeasy-name-override: TaskAuditActionInstanceSucceeded - c1.api.task.v1.TaskAuditActionSubmitted: - description: The TaskAuditActionSubmitted message. - properties: - action: + enrollmentRequired: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAction' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.EnrollmentRequired' - type: "null" - title: Task Audit Action Submitted - type: object - x-speakeasy-name-override: TaskAuditActionSubmitted - c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy: - description: The TaskAuditApprovalAutoAcceptedByPolicy message. - title: Task Audit Approval Auto Accepted By Policy - type: object - x-speakeasy-name-override: TaskAuditApprovalAutoAcceptedByPolicy - c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy: - description: The TaskAuditApprovalAutoRejectedByPolicy message. - title: Task Audit Approval Auto Rejected By Policy - type: object - x-speakeasy-name-override: TaskAuditApprovalAutoRejectedByPolicy - c1.api.task.v1.TaskAuditApprovalHappenedAutomatically: - description: The TaskAuditApprovalHappenedAutomatically message. - title: Task Audit Approval Happened Automatically - type: object - x-speakeasy-name-override: TaskAuditApprovalHappenedAutomatically - c1.api.task.v1.TaskAuditApprovalInstanceChange: - description: The TaskAuditApprovalInstanceChange message. - properties: - instance: + stepUpRequired: oneOf: - - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.StepUpRequired' - type: "null" - title: Task Audit Approval Instance Change + title: Policy Outcome type: object - x-speakeasy-name-override: TaskAuditApprovalInstanceChange - c1.api.task.v1.TaskAuditBulkActionError: - description: The TaskAuditBulkActionError message. + x-speakeasy-name-override: PolicyOutcome + c1.api.sign_in_policy.v1.PolicyRule: + description: |- + PolicyRule is one rung of the ordered sign-in cascade. Rules are evaluated + top to bottom; the first enforced rule whose condition matches supplies the + outcome. properties: - error: - description: The error field. + description: + description: A human-readable description shown in the admin UI. type: string - title: Task Audit Bulk Action Error - type: object - x-speakeasy-name-override: TaskAuditBulkActionError - c1.api.task.v1.TaskAuditCertifyOutcome: - description: The TaskAuditCertifyOutcome message. - properties: - outcome: - description: The outcome field. + id: + description: A stable identifier for the rule, surfaced in audit. + type: string + matchCel: + description: A boolean condition expression evaluated against the sign-in context. + type: string + mode: + description: Whether the rule is live, evaluated-only, or skipped. enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT + - POLICY_RULE_MODE_UNSPECIFIED + - POLICY_RULE_MODE_ENFORCE + - POLICY_RULE_MODE_OBSERVE + - POLICY_RULE_MODE_DISABLED type: string x-speakeasy-unknown-values: allow - title: Task Audit Certify Outcome + outcome: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' + - type: "null" + title: Policy Rule type: object - x-speakeasy-name-override: TaskAuditCertifyOutcome - c1.api.task.v1.TaskAuditComment: - description: The TaskAuditComment message. + x-speakeasy-name-override: PolicyRule + c1.api.sign_in_policy.v1.SignInPolicy: + description: SignInPolicy defines how users sign in. properties: - comment: - description: The comment field. + allowedMfaTypes: + description: |- + The credential types accepted as a second factor. Must be a subset of the + credential types their inventory policy permits. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + allowedPrimaryTypes: + description: |- + The primary credential types users may sign in with. Must be a subset of + the credential types their inventory policy permits. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + defaultOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' + - type: "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: A human-readable name for the policy. + type: string + id: + description: Unique identifier for the policy. + readOnly: true type: string + isBuiltin: + description: |- + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. + readOnly: true + type: boolean + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + rules: + description: The ordered rule cascade, evaluated top to bottom. + items: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + type: + - array + - "null" updatedAt: format: date-time + readOnly: true type: - string - "null" - updatedBy: - description: The updatedBy field. - type: string - title: Task Audit Comment + title: Sign In Policy type: object - x-speakeasy-name-override: TaskAuditComment - c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult: - description: The TaskAuditConditionalPolicyExecutionResult message. + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicy + c1.api.sign_in_policy.v1.SignInPolicyRef: + description: SignInPolicyRef is a lightweight reference to a sign-in policy by ID. properties: - condition: - description: The condition field. - type: string - conditionMatched: - description: The conditionMatched field. - type: boolean - defaultCondition: - description: The defaultCondition field. - type: boolean - error: - description: The error field. + id: + description: The id field. type: string - policyKey: - description: The policyKey field. - type: string - title: Task Audit Conditional Policy Execution Result + title: Sign In Policy Ref type: object - x-speakeasy-name-override: TaskAuditConditionalPolicyExecutionResult - c1.api.task.v1.TaskAuditConnectorActionResult: - description: | - The TaskAuditConnectorActionResult message. - - This message contains a oneof named result. Only a single field of the following list may be set at a time: - - success - - error - - cancelled - - pending + x-speakeasy-name-override: SignInPolicyRef + c1.api.sign_in_policy.v1.SignInPolicyServiceCreateRequest: + description: The SignInPolicyServiceCreateRequest message. properties: - appEntitlementId: - description: The appEntitlementId field. - type: string - appId: - description: The appId field. - type: string - cancelled: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditCancelledResult' - - type: "null" - connectorActionId: - description: The connectorActionId field. - type: string - connectorId: - description: The connectorId field. - type: string - error: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditErrorResult' - - type: "null" - pending: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditPendingResult' - - type: "null" - success: + allowedMfaTypes: + description: The credential types accepted as a second factor. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + allowedPrimaryTypes: + description: The primary credential types users may sign in with. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + defaultOutcome: oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditSuccessResult' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' - type: "null" - title: Task Audit Connector Action Result - type: object - x-speakeasy-name-override: TaskAuditConnectorActionResult - c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask: - description: |- - TaskAuditCreatedReplacementExtensionGrantTask is used when a replacement extension grant task is created - (e.g. when an extension grant task is cancelled due to app user deletion). - properties: - newTaskId: - description: The ID of the newly created replacement task - type: string - newTaskNumericId: - description: The numeric ID of the newly created replacement task (for display) - format: int64 - type: string - title: Task Audit Created Replacement Extension Grant Task - type: object - x-speakeasy-name-override: TaskAuditCreatedReplacementExtensionGrantTask - c1.api.task.v1.TaskAuditEscalateToEmergencyAccess: - description: The TaskAuditEscalateToEmergencyAccess message. - properties: - oldPolicyId: - description: The oldPolicyId field. - type: string - oldPolicyStepId: - description: The oldPolicyStepId field. - type: string - title: Task Audit Escalate To Emergency Access - type: object - x-speakeasy-name-override: TaskAuditEscalateToEmergencyAccess - c1.api.task.v1.TaskAuditExpressionPolicyStepError: - description: The TaskAuditExpressionPolicyStepError message. - properties: - error: - description: The error field. - type: string - title: Task Audit Expression Policy Step Error - type: object - x-speakeasy-name-override: TaskAuditExpressionPolicyStepError - c1.api.task.v1.TaskAuditExternalTicketCreated: - description: The TaskAuditExternalTicketCreated message. - properties: - appId: - description: The appId field. - type: string - connectorId: - description: The connectorId field. - type: string - externalTicketId: - description: The externalTicketId field. - type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - type: string - externalTicketProvisionerConfigName: - description: The externalTicketProvisionerConfigName field. - type: string - externalTicketUrl: - description: The externalTicketUrl field. - type: string - title: Task Audit External Ticket Created - type: object - x-speakeasy-name-override: TaskAuditExternalTicketCreated - c1.api.task.v1.TaskAuditExternalTicketError: - description: The TaskAuditExternalTicketError message. - properties: - errorMessage: - description: The errorMessage field. + displayName: + description: A human-readable name for the policy. type: string - title: Task Audit External Ticket Error + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + rules: + description: The ordered rule cascade. + items: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + type: + - array + - "null" + required: + - displayName + title: Sign In Policy Service Create Request type: object - x-speakeasy-name-override: TaskAuditExternalTicketError - c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved: - description: The TaskAuditExternalTicketProvisionStepResolved message. + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicyServiceCreateRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceCreateResponse: + description: The SignInPolicyServiceCreateResponse message. properties: - appId: - description: The appId field. - type: string - connectorId: - description: The connectorId field. - type: string - externalTicketId: - description: The externalTicketId field. - type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - type: string - externalTicketUrl: - description: The externalTicketUrl field. - type: string - title: Task Audit External Ticket Provision Step Resolved + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Create Response type: object - x-speakeasy-name-override: TaskAuditExternalTicketProvisionStepResolved - c1.api.task.v1.TaskAuditExternalTicketTriggered: - description: The TaskAuditExternalTicketTriggered message. - properties: - appId: - description: The appId field. - type: string - connectorId: - description: The connectorId field. - type: string - externalTicketId: - description: The externalTicketId field. - type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - type: string - externalTicketProvisionerConfigName: - description: The externalTicketProvisionerConfigName field. - type: string - title: Task Audit External Ticket Triggered + x-speakeasy-name-override: SignInPolicyServiceCreateResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteRequestInput: + description: The SignInPolicyServiceDeleteRequest message. + title: Sign In Policy Service Delete Request type: object - x-speakeasy-name-override: TaskAuditExternalTicketTriggered - c1.api.task.v1.TaskAuditFinishedConnectorActions: - description: The TaskAuditFinishedConnectorActions message. - properties: - policyStepId: - description: The policyStepId field. - type: string - title: Task Audit Finished Connector Actions + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicyServiceDeleteRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteResponse: + description: The SignInPolicyServiceDeleteResponse message. + title: Sign In Policy Service Delete Response type: object - x-speakeasy-name-override: TaskAuditFinishedConnectorActions - c1.api.task.v1.TaskAuditFormInstanceChange: - description: The TaskAuditFormInstanceChange message. + x-speakeasy-name-override: SignInPolicyServiceDeleteResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceGetResponse: + description: The SignInPolicyServiceGetResponse message. properties: - isValid: - description: The isValid field. - type: boolean - title: Task Audit Form Instance Change + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Get Response type: object - x-speakeasy-name-override: TaskAuditFormInstanceChange - c1.api.task.v1.TaskAuditGrantDurationUpdated: - description: The TaskAuditGrantDurationUpdated message. + x-speakeasy-name-override: SignInPolicyServiceGetResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceListResponse: + description: The SignInPolicyServiceListResponse message. properties: - duration: - format: duration + list: + description: The page of policies. + items: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' type: - - string + - array - "null" - title: Task Audit Grant Duration Updated - type: object - x-speakeasy-name-override: TaskAuditGrantDurationUpdated - c1.api.task.v1.TaskAuditGrantOutcome: - description: The TaskAuditGrantOutcome message. - properties: - outcome: - description: The outcome field. - enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT - type: string - x-speakeasy-unknown-values: allow - title: Task Audit Grant Outcome - type: object - x-speakeasy-name-override: TaskAuditGrantOutcome - c1.api.task.v1.TaskAuditHardReset: - description: The TaskAuditHardReset message. - properties: - oldPolicyStepId: - description: The oldPolicyStepId field. + nextPageToken: + description: A token to fetch the next page, or empty if there are no more results. type: string - title: Task Audit Hard Reset + title: Sign In Policy Service List Response type: object - x-speakeasy-name-override: TaskAuditHardReset - c1.api.task.v1.TaskAuditListRequest: - description: The TaskAuditListRequest message. + x-speakeasy-name-override: SignInPolicyServiceListResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest: + description: The SignInPolicyServiceSearchRequest message. properties: - commentsOnly: - description: |- - When true, only comment events are returned, so a page of page_size holds - page_size comments rather than a mix of comments and state-change events. - type: boolean - newestFirst: - description: |- - When true, events are returned newest-first (descending created_at) instead - of the default chronological (ascending) order. - type: boolean pageSize: - description: The maximum number of audit events to return per page. + description: The maximum number of results to return per page. format: int32 type: integer pageToken: - description: A pagination token from a previous response to retrieve the next page. + description: A pagination token from a previous Search response. + type: string + query: + description: Free-text search over the policy name. Empty matches all policies. type: string refs: - description: References to specific audit events to retrieve. If provided, only these events are returned. + description: Restrict results to these specific policies. Empty matches all policies. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditViewRef' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyRef' type: - array - "null" - taskId: - description: The ID of the task to list audit events for. - type: string - title: Task Audit List Request + title: Sign In Policy Service Search Request type: object - x-speakeasy-name-override: TaskAuditListRequest - c1.api.task.v1.TaskAuditListResponse: - description: The TaskAuditListResponse message. + x-speakeasy-name-override: SignInPolicyServiceSearchRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse: + description: The SignInPolicyServiceSearchResponse message. properties: list: - description: The list of audit events for the task. + description: The page of matching policies. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditView' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' type: - array - "null" nextPageToken: - description: A pagination token to retrieve the next page of results. + description: A token to fetch the next page, or empty if there are no more results. type: string - title: Task Audit List Response + title: Sign In Policy Service Search Response type: object - x-speakeasy-name-override: TaskAuditListResponse - c1.api.task.v1.TaskAuditMetaData: - description: The TaskAuditMetaData message. + x-speakeasy-name-override: SignInPolicyServiceSearchResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput: + description: The SignInPolicyServiceUpdateRequest message. properties: - user: + signInPolicy: oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' - type: "null" - title: Task Audit Meta Data - type: object - x-speakeasy-name-override: TaskAuditMetaData - c1.api.task.v1.TaskAuditNewTask: - description: The TaskAuditNewTask message. - title: Task Audit New Task + updateMask: + type: + - string + - "null" + title: Sign In Policy Service Update Request type: object - x-speakeasy-name-override: TaskAuditNewTask - c1.api.task.v1.TaskAuditNewTaskCreatedFrom: - description: |- - TaskAuditNewTaskCreatedFrom is used when a task is created from another task - (e.g. when a replacement extension grant task is created after the original is cancelled). - This is set on the NEW task to indicate its origin. + x-speakeasy-name-override: SignInPolicyServiceUpdateRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse: + description: The SignInPolicyServiceUpdateResponse message. properties: - originalTaskId: - description: The originalTaskId field. - type: string - originalTaskNumericId: - description: The originalTaskNumericId field. - format: int64 - type: string - originalTaskType: - description: The task type of the original task (e.g. "grant", "revoke", "certify"). - type: string - title: Task Audit New Task Created From + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Update Response type: object - x-speakeasy-name-override: TaskAuditNewTaskCreatedFrom - c1.api.task.v1.TaskAuditPolicyApprovalReassigned: - description: The TaskAuditPolicyApprovalReassigned message. + x-speakeasy-name-override: SignInPolicyServiceUpdateResponse + c1.api.sign_in_policy.v1.StepUpRequired: + description: StepUpRequired demands a stronger re-authentication before access is granted. properties: - newPolicyStepId: - description: The newPolicyStepId field. + level: + description: The assurance level the step-up must reach. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - newUsers: - description: The newUsers field. + x-speakeasy-unknown-values: allow + maxAgeSeconds: + description: How fresh the step-up must be, in seconds. + format: int32 + type: integer + types: + description: The credential types that may satisfy the step-up. items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string + x-speakeasy-unknown-values: allow type: - array - "null" - oldPolicyStepId: - description: The oldPolicyStepId field. - type: string - users: - description: The users field. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - type: - - array - - "null" - title: Task Audit Policy Approval Reassigned - type: object - x-speakeasy-name-override: TaskAuditPolicyApprovalReassigned - c1.api.task.v1.TaskAuditPolicyChanged: - description: The TaskAuditPolicyChanged message. - properties: - newPolicyId: - description: The newPolicyId field. - type: string - oldPolicyId: - description: The oldPolicyId field. - type: string - title: Task Audit Policy Changed - type: object - x-speakeasy-name-override: TaskAuditPolicyChanged - c1.api.task.v1.TaskAuditPolicyEvaluationStep: - description: The TaskAuditPolicyEvaluationStep message. - properties: - stepComment: - description: The stepComment field. - type: string - title: Task Audit Policy Evaluation Step + title: Step Up Required type: object - x-speakeasy-name-override: TaskAuditPolicyEvaluationStep - c1.api.task.v1.TaskAuditPolicyProvisionCancelled: - description: The TaskAuditPolicyProvisionCancelled message. + x-speakeasy-name-override: StepUpRequired + c1.api.ssf_receiver.v1.SSFOutboundAuthBearer: + description: |- + SSFOutboundAuthBearer is a static bearer token for outbound auth. + Token is write-only: accepted on create/update, never returned. properties: - cancelReason: - description: The cancelReason field. + token: + description: The token field. type: string - title: Task Audit Policy Provision Cancelled + title: Ssf Outbound Auth Bearer type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionCancelled - c1.api.task.v1.TaskAuditPolicyProvisionError: - description: The TaskAuditPolicyProvisionError message. + x-speakeasy-name-override: SSFOutboundAuthBearer + c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2: + description: |- + SSFOutboundAuthOAuth2 uses OAuth2 client credentials for outbound auth. + client_secret is write-only: accepted on create/update, never returned. properties: - error: - description: The error field. + clientId: + description: The clientId field. type: string - title: Task Audit Policy Provision Error - type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionError - c1.api.task.v1.TaskAuditPolicyProvisionReassigned: - description: The TaskAuditPolicyProvisionReassigned message. - properties: - newPolicyStepId: - description: The newPolicyStepId field. + clientSecret: + description: The clientSecret field. type: string - newUsers: - description: The newUsers field. + scopes: + description: The scopes field. items: type: string type: - array - "null" - oldPolicyStepId: - description: The oldPolicyStepId field. + tokenUrl: + description: The tokenUrl field. type: string - users: - description: The users field. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - type: - - array - - "null" - title: Task Audit Policy Provision Reassigned + title: Ssf Outbound Auth O Auth 2 type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionReassigned - c1.api.task.v1.TaskAuditReassignedToDelegate: - description: The TaskAuditReassignedToDelegate message. + x-speakeasy-name-override: SSFOutboundAuthOAuth2 + c1.api.ssf_receiver.v1.SSFReceiverEvent: + description: SSFReceiverEvent shows both wire-level data and C1 canonical outcome. properties: - delegatedAssigneeUser: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' - - type: "null" - delegatedAssigneeUserId: - description: The delegatedAssigneeUserId field. + canonicalType: + description: |- + C1 canonical outcome (what C1 understood and did). + The normalized event type after mapping from the wire event type. + enum: + - SSF_CANONICAL_EVENT_TYPE_UNSPECIFIED + - SSF_CANONICAL_EVENT_TYPE_UNRECOGNIZED + - SSF_CANONICAL_EVENT_TYPE_SESSION_REVOKED + - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_TOKEN_CLAIMS_CHANGED + - SSF_CANONICAL_EVENT_TYPE_ASSURANCE_LEVEL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_DEVICE_COMPLIANCE_CHANGED + - SSF_CANONICAL_EVENT_TYPE_RISK_LEVEL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_SESSION_ESTABLISHED + - SSF_CANONICAL_EVENT_TYPE_SESSION_PRESENTED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_DISABLED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_ENABLED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_PURGED + - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_COMPROMISE + - SSF_CANONICAL_EVENT_TYPE_RECOVERY_ACTIVATED + - SSF_CANONICAL_EVENT_TYPE_IDENTIFIER_CHANGED + - SSF_CANONICAL_EVENT_TYPE_VERIFICATION + - SSF_CANONICAL_EVENT_TYPE_STREAM_UPDATED type: string - originalAssigneeUser: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' - - type: "null" - originalAssigneeUserId: - description: The originalAssigneeUserId field. + x-speakeasy-unknown-values: allow + id: + description: The unique identifier of this event. type: string - title: Task Audit Reassigned To Delegate - type: object - x-speakeasy-name-override: TaskAuditReassignedToDelegate - c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin: - description: |- - TaskAuditReassignmentFallbackToAdmin is used when no eligible reviewers are found - from the policy configuration and the task falls back to system administrators - without creating a new policy step. This prevents reassignment loops. - properties: - adminUserIds: - description: The IDs of the system administrator users that the task is being assigned to - items: - type: string - type: - - array - - "null" - adminUsers: - description: The system administrator users (populated for display) - items: - $ref: '#/components/schemas/c1.api.user.v1.User' + matchMethod: + description: How the upstream subject was resolved to a ConductorOne user. + enum: + - SSF_SUBJECT_MATCH_METHOD_UNSPECIFIED + - SSF_SUBJECT_MATCH_METHOD_IDP_USER + - SSF_SUBJECT_MATCH_METHOD_EMAIL + - SSF_SUBJECT_MATCH_METHOD_NOT_FOUND + - SSF_SUBJECT_MATCH_METHOD_NOT_APPLICABLE + type: string + x-speakeasy-unknown-values: allow + matchedUserId: + description: The ConductorOne user ID that the event subject was resolved to, if any. + type: string + outcome: + description: The action ConductorOne took in response to this event. + enum: + - SSF_EVENT_OUTCOME_UNSPECIFIED + - SSF_EVENT_OUTCOME_SESSIONS_REVOKED + - SSF_EVENT_OUTCOME_LOGGED + - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND + - SSF_EVENT_OUTCOME_VERIFIED + - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED + - SSF_EVENT_OUTCOME_UNRECOGNIZED + - SSF_EVENT_OUTCOME_ERROR + type: string + x-speakeasy-unknown-values: allow + outcomeDetail: + description: Human-readable details about the outcome (e.g., error message or revocation summary). + type: string + receivedAt: + format: date-time type: - - array + - string - "null" - title: Task Audit Reassignment Fallback To Admin - type: object - x-speakeasy-name-override: TaskAuditReassignmentFallbackToAdmin - c1.api.task.v1.TaskAuditReassignmentListError: - description: The TaskAuditReassignmentListError message. - properties: - errorMessage: - description: The errorMessage field. + sessionsRevoked: + description: Number of sessions that were revoked as a result of this event. + format: int32 + type: integer + setJti: + description: |- + Wire-level data (what the transmitter sent). + The SET (Security Event Token) JWT ID claim, uniquely identifying the token. type: string - title: Task Audit Reassignment List Error - type: object - x-speakeasy-name-override: TaskAuditReassignmentListError - c1.api.task.v1.TaskAuditRequestDefaultsApplied: - description: |- - TaskAuditRequestDefaultsApplied records which tier of the request-settings - precedence chain supplied the defaults for a grant request. The rule ID, not - its name, is stored; consumers resolve the current display name via - (app_id, routing_rule_id). - properties: - appId: - description: The appId field. + streamId: + description: The SSF receiver stream that received this event. type: string - routingRuleId: - description: The routingRuleId field. + wireEventProfile: + description: The event profile URI from the SET, if present. type: string - source: - description: The source field. - enum: - - APPLIED_SETTINGS_SOURCE_UNSPECIFIED - - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_OVERRIDE - - APPLIED_SETTINGS_SOURCE_ROUTING_RULE - - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_DEFAULT - - APPLIED_SETTINGS_SOURCE_APP_DEFAULT - - APPLIED_SETTINGS_SOURCE_ACCESS_PROFILE_DEFAULT + wireEventType: + description: The raw event type URI from the SET (e.g., "https://schemas.openid.net/secevent/caep/event-type/session-revoked"). type: string - x-speakeasy-unknown-values: allow - title: Task Audit Request Defaults Applied - type: object - x-speakeasy-name-override: TaskAuditRequestDefaultsApplied - c1.api.task.v1.TaskAuditRestart: - description: The TaskAuditRestart message. - properties: - oldPolicyStepId: - description: The oldPolicyStepId field. + wireInitiatingEntity: + description: The entity that initiated the event, as reported by the transmitter. type: string - title: Task Audit Restart + wireReasonAdmin: + description: The admin-facing reason string from the SET, if provided by the transmitter. + type: string + wireSubjectFormat: + description: The subject identifier format from the SET (e.g., "email", "iss_sub"). + type: string + wireSubjectIdentifier: + description: The raw subject identifier value from the SET. + type: string + title: Ssf Receiver Event type: object - x-speakeasy-name-override: TaskAuditRestart - c1.api.task.v1.TaskAuditRevokeOutcome: - description: The TaskAuditRevokeOutcome message. + x-speakeasy-name-override: SSFReceiverEvent + c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest: + description: SSFReceiverEventSearchServiceSearchRequest carries the search query and optional filters for narrowing results. properties: + eventType: + description: Restricts results to events matching this wire event type URI. Optional. + type: string + matchedUserId: + description: Restricts results to events matched to this ConductorOne user ID. Optional. + type: string outcome: - description: The outcome field. + description: Restricts results to events with this processing outcome. Optional. enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT + - SSF_EVENT_OUTCOME_UNSPECIFIED + - SSF_EVENT_OUTCOME_SESSIONS_REVOKED + - SSF_EVENT_OUTCOME_LOGGED + - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND + - SSF_EVENT_OUTCOME_VERIFIED + - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED + - SSF_EVENT_OUTCOME_UNRECOGNIZED + - SSF_EVENT_OUTCOME_ERROR type: string x-speakeasy-unknown-values: allow - title: Task Audit Revoke Outcome - type: object - x-speakeasy-name-override: TaskAuditRevokeOutcome - c1.api.task.v1.TaskAuditSLAEscalation: - description: The TaskAuditSLAEscalation message. - properties: - message: - description: The message field. + pageSize: + description: Maximum number of events to return per page. + format: int32 + type: integer + pageToken: + description: Token from a previous SearchResponse to fetch the next page of results. type: string - title: Task Audit Sla Escalation - type: object - x-speakeasy-name-override: TaskAuditSLAEscalation - c1.api.task.v1.TaskAuditStartedConnectorActions: - description: The TaskAuditStartedConnectorActions message. - properties: - policyStepId: - description: The policyStepId field. + query: + description: Full-text search query matched against event fields. type: string - title: Task Audit Started Connector Actions - type: object - x-speakeasy-name-override: TaskAuditStartedConnectorActions - c1.api.task.v1.TaskAuditStateChange: - description: The TaskAuditStateChange message. - properties: - previousState: - description: The previousState field. - enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED + streamId: + description: Restricts results to events from this SSF receiver stream. Optional. type: string - x-speakeasy-unknown-values: allow - title: Task Audit State Change + title: Ssf Receiver Event Search Service Search Request type: object - x-speakeasy-name-override: TaskAuditStateChange - c1.api.task.v1.TaskAuditStepSkipped: - description: The TaskAuditStepSkipped message. + x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchRequest + c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse: + description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. properties: - skippedBy: - description: The skippedBy field. + list: + description: The SSF events matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - title: Task Audit Step Skipped + title: Ssf Receiver Event Search Service Search Response type: object - x-speakeasy-name-override: TaskAuditStepSkipped - c1.api.task.v1.TaskAuditStepUpApproval: - description: The TaskAuditStepUpApproval message. + x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchResponse + c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse: + description: SSFReceiverEventServiceListResponse contains a page of received SSF events. properties: - stepUpTransactionId: - description: The stepUpTransactionId field. + list: + description: The SSF events in the current page. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - title: Task Audit Step Up Approval + title: Ssf Receiver Event Service List Response type: object - x-speakeasy-name-override: TaskAuditStepUpApproval - c1.api.task.v1.TaskAuditView: + x-speakeasy-name-override: SSFReceiverEventServiceListResponse + c1.api.ssf_receiver.v1.SSFReceiverStream: description: | - The TaskAuditView message. + SSFReceiverStream is the public API representation. + Secrets (push_auth_token, outbound credentials) are write-only. - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - comment - - stateChange - - approvalInstanceChange - - connectorActionsStart - - connectorActionsEnd - - actionResult - - taskCreated - - certifyOutcome - - actionSubmitted - - grantOutcome - - revokeOutcome - - approvalReassigned - - taskRestarted - - accessRequestOutcome - - provisionReassigned - - provisionError - - approvedAutomatically - - reassignedToDelegate - - hardReset - - taskEscalated - - conditionalPolicyExecutionResult - - expressionPolicyStepError - - approvalAutoAcceptedByPolicy - - approvalAutoRejectedByPolicy - - bulkActionError - - webhookTriggered - - webhookAttempt - - webhookSuccess - - policyEvaluationStep - - waitStepSuccess - - waitStepWaiting - - waitStepTimedOut - - webhookApprovalTriggered - - webhookApprovalAttempt - - webhookApprovalSuccess - - webhookApprovalBadResponse - - externalTicketTriggered - - externalTicketCreated - - externalTicketError - - waitStepAnalysisSuccess - - waitStepAnalysisWaiting - - waitStepAnalysisTimedOut - - stepUpApproval - - externalTicketProvisionStepResolved - - stepSkipped - - reassignmentListError - - slaEscalation - - policyChanged - - formInstanceChange - - grantDurationUpdated - - waitStepUntilTime - - webhookApprovalFatalError - - accountLifecycleActionCreated - - accountLifecycleActionFailed - - provisionCancelled - - actionInstanceCreated - - actionInstanceSucceeded - - actionInstanceFailed - - createdReplacementExtensionGrantTask - - taskCreatedFrom - - reassignmentFallbackToAdmin - - requestDefaultsApplied + This message contains a oneof named outbound_auth. Only a single field of the following list may be set at a time: + - outboundAuthBearer + - outboundAuthOauth2 properties: - accessRequestOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccessRequestOutcome' - - type: "null" - accountLifecycleActionCreated: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionCreated' - - type: "null" - accountLifecycleActionFailed: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionFailed' - - type: "null" - actionInstanceCreated: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceCreated' - - type: "null" - actionInstanceFailed: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceFailed' - - type: "null" - actionInstanceSucceeded: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceSucceeded' - - type: "null" - actionResult: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConnectorActionResult' - - type: "null" - actionSubmitted: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionSubmitted' - - type: "null" - approvalAutoAcceptedByPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy' - - type: "null" - approvalAutoRejectedByPolicy: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy' - - type: "null" - approvalInstanceChange: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalInstanceChange' - - type: "null" - approvalReassigned: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyApprovalReassigned' - - type: "null" - approvedAutomatically: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalHappenedAutomatically' - - type: "null" - bulkActionError: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditBulkActionError' - - type: "null" - certifyOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCertifyOutcome' - - type: "null" - comment: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditComment' - - type: "null" - conditionalPolicyExecutionResult: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult' - - type: "null" - connectorActionsEnd: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFinishedConnectorActions' - - type: "null" - connectorActionsStart: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStartedConnectorActions' - - type: "null" - created: + accountDisabledAction: + description: Action to take when an account-disabled event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY + type: string + x-speakeasy-unknown-values: allow + createdAt: format: date-time + readOnly: true type: - string - "null" - createdReplacementExtensionGrantTask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask' - - type: "null" - currentState: - description: The currentState field. + credentialChangeAction: + description: Action to take when a credential-change event is received. enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - eventType: - description: The eventType field. + credentialCompromiseAction: + description: Action to take when a credential-compromise event is received. enum: - - TASK_AUDIT_EVENT_TYPE_UNSPECIFIED - - TASK_AUDIT_EVENT_TYPE_NEUTRAL - - TASK_AUDIT_EVENT_TYPE_ERROR + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - expressionPolicyStepError: + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + deliveryMethod: + description: Controls whether events are received via push (transmitter POSTs to C1) or poll (C1 fetches from transmitter). + enum: + - SSF_DELIVERY_METHOD_UNSPECIFIED + - SSF_DELIVERY_METHOD_PUSH + - SSF_DELIVERY_METHOD_POLL + type: string + x-speakeasy-unknown-values: allow + description: + description: Optional description of the stream's purpose or source. + type: string + displayName: + description: Human-readable name for the stream shown in the UI. + type: string + enabled: + description: Controls whether this stream actively processes incoming events. When false, events are ignored. + type: boolean + eventTypesEnabled: + description: SSF/CAEP/RISC event type URIs that this stream is configured to accept. + items: + type: string + type: + - array + - "null" + expectedAudience: + description: Expected audience (aud) claim in incoming SETs. Optional. + type: string + id: + description: The unique identifier of this SSF receiver stream. + type: string + issuerUrl: + description: Upstream IdP identification. + type: string + jwksUrl: + description: The jwksUrl field. + type: string + lastErrorAt: + format: date-time + type: + - string + - "null" + lastErrorMessage: + description: The lastErrorMessage field. + type: string + lastVerifiedAt: + format: date-time + type: + - string + - "null" + outboundAuthBearer: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExpressionPolicyStepError' + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthBearer' - type: "null" - externalTicketCreated: + outboundAuthOauth2: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketCreated' + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2' - type: "null" - externalTicketError: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketError' - - type: "null" - externalTicketProvisionStepResolved: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved' - - type: "null" - externalTicketTriggered: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketTriggered' - - type: "null" - formInstanceChange: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFormInstanceChange' - - type: "null" - grantDurationUpdated: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantDurationUpdated' - - type: "null" - grantOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantOutcome' - - type: "null" - hardReset: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditHardReset' - - type: "null" - id: - description: The id field. + pollEndpointUrl: + description: URL of the transmitter's poll endpoint where C1 fetches events from. type: string - metadata: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditMetaData' - - type: "null" - policyChanged: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyChanged' - - type: "null" - policyEvaluationStep: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyEvaluationStep' - - type: "null" - provisionCancelled: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionCancelled' - - type: "null" - provisionError: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionError' - - type: "null" - provisionReassigned: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionReassigned' - - type: "null" - reassignedToDelegate: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignedToDelegate' - - type: "null" - reassignmentFallbackToAdmin: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin' - - type: "null" - reassignmentListError: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentListError' - - type: "null" - requestDefaultsApplied: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRequestDefaultsApplied' - - type: "null" - revokeOutcome: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRevokeOutcome' - - type: "null" - slaEscalation: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditSLAEscalation' - - type: "null" - source: - description: The source field. + pollInterval: + format: duration + type: + - string + - "null" + pushAuthToken: + description: 'Push auth token: write-only. Accepted on create, never returned in get/list.' + type: string + pushEndpointUrl: + description: 'Push delivery: C1 generates a unique endpoint URL.' + readOnly: true + type: string + sessionRevokedAction: + description: |- + Per-canonical-type action configuration. + Event types without a config here default to LOG_ONLY. + Action to take when a session-revoked event is received. enum: - - SOURCE_UNSPECIFIED - - SOURCE_C1 - - SOURCE_JIRA - - SOURCE_SLACK - - SOURCE_COPILOT_AGENTS + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - stateChange: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStateChange' - - type: "null" - stepSkipped: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepSkipped' - - type: "null" - stepUpApproval: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepUpApproval' - - type: "null" - taskCreated: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTask' - - type: "null" - taskCreatedFrom: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTaskCreatedFrom' - - type: "null" - taskEscalated: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditEscalateToEmergencyAccess' - - type: "null" - taskRestarted: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRestart' - - type: "null" - ticketId: - description: The ticketId field. + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Ssf Receiver Stream + type: object + x-speakeasy-name-override: SSFReceiverStream + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest: + description: SSFReceiverStreamServiceCreateRequest contains the configuration for a new SSF receiver stream. + properties: + accountDisabledAction: + description: Action to take when an account-disabled event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - userId: - description: The userId field. + x-speakeasy-unknown-values: allow + credentialChangeAction: + description: Action to take when a credential-change event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - waitStepAnalysisSuccess: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess' - - type: "null" - waitStepAnalysisTimedOut: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut' - - type: "null" - waitStepAnalysisWaiting: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting' - - type: "null" - waitStepSuccess: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepSuccess' - - type: "null" - waitStepTimedOut: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepTimedOut' - - type: "null" - waitStepUntilTime: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepUntilTime' - - type: "null" - waitStepWaiting: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepWaiting' - - type: "null" - webhookApprovalAttempt: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalAttempt' - - type: "null" - webhookApprovalBadResponse: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalBadResponse' - - type: "null" - webhookApprovalFatalError: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalFatalError' - - type: "null" - webhookApprovalSuccess: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalSuccess' - - type: "null" - webhookApprovalTriggered: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalTriggered' - - type: "null" - webhookAttempt: + x-speakeasy-unknown-values: allow + credentialCompromiseAction: + description: Action to take when a credential-compromise event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY + type: string + x-speakeasy-unknown-values: allow + deliveryMethod: + description: Controls whether events are received via push or poll delivery. + enum: + - SSF_DELIVERY_METHOD_UNSPECIFIED + - SSF_DELIVERY_METHOD_PUSH + - SSF_DELIVERY_METHOD_POLL + type: string + x-speakeasy-unknown-values: allow + description: + description: Optional description of the stream's purpose or source. + type: string + displayName: + description: Human-readable name for the stream. + type: string + enabled: + description: Controls whether the stream starts processing events immediately after creation. + type: boolean + expectedAudience: + description: Expected audience claim in incoming SETs. If set, SETs with a different audience are rejected. + type: string + issuerUrl: + description: The issuer URL of the upstream SSF transmitter, used for token validation. + type: string + jwksUrl: + description: URL to fetch the transmitter's JSON Web Key Set for SET signature verification. + type: string + pollEndpointUrl: + description: URL of the transmitter's poll endpoint. Required when delivery_method is POLL. + type: string + pollInterval: + format: duration + type: + - string + - "null" + sessionRevokedAction: + description: |- + Per-event-type action configuration. + Action to take when a session-revoked event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY + type: string + x-speakeasy-unknown-values: allow + required: + - displayName + - issuerUrl + title: Ssf Receiver Stream Service Create Request + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceCreateRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse: + description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + properties: + pushAuthTokenPlaintext: + description: Push auth token returned in plaintext ONLY on create. + type: string + ssfReceiverStream: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookAttempt' + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - type: "null" - webhookSuccess: + title: Ssf Receiver Stream Service Create Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceCreateResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput: + description: SSFReceiverStreamServiceDeleteRequest identifies the SSF receiver stream to delete. + title: Ssf Receiver Stream Service Delete Request + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceDeleteRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse: + description: SSFReceiverStreamServiceDeleteResponse is empty on success. + title: Ssf Receiver Stream Service Delete Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceDeleteResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse: + description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. + properties: + ssfReceiverStream: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookSuccess' + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - type: "null" - webhookTriggered: + title: Ssf Receiver Stream Service Get Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceGetResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse: + description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. + properties: + stats: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookTriggered' + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamStats' - type: "null" - workflowStep: - description: The workflowStep field. - format: int32 - type: integer - title: Task Audit View + title: Ssf Receiver Stream Service Get Stats Response type: object - x-speakeasy-name-override: TaskAuditView - c1.api.task.v1.TaskAuditViewRef: - description: The TaskAuditViewRef message. + x-speakeasy-name-override: SSFReceiverStreamServiceGetStatsResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse: + description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. properties: - id: - description: The ID of the audit event. + list: + description: The SSF receiver streams in the current page. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - title: Task Audit View Ref + title: Ssf Receiver Stream Service List Response type: object - x-speakeasy-name-override: TaskAuditViewRef - c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess: - description: The TaskAuditWaitForAnalysisStepSuccess message. + x-speakeasy-name-override: SSFReceiverStreamServiceListResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput: + description: SSFReceiverStreamServiceTestRequest identifies the stream to test and an optional subject for identity resolution validation. properties: - stepId: - description: The stepId field. + testSubject: + description: |- + The upstream identifier to test resolution with. Typically an email address + (e.g., "alice@company.com") — the same value the IdP would send in a SET subject. + The Test RPC runs resolveSubject on this to verify the identity mapping works. + Optional: upstream identifier (email) to test identity resolution. + If empty, only JWKS reachability is tested. type: string - succeededAt: - format: date-time - type: - - string - - "null" - title: Task Audit Wait For Analysis Step Success + title: Ssf Receiver Stream Service Test Request type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepSuccess - c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut: - description: The TaskAuditWaitForAnalysisStepTimedOut message. + x-speakeasy-name-override: SSFReceiverStreamServiceTestRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse: + description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. properties: - stepId: - description: The stepId field. + activeRefreshTokenCount: + description: Number of active refresh tokens for the matched user that would be affected. + format: int32 + type: integer + activeSessionCount: + description: Number of active sessions for the matched user that would be affected. + format: int32 + type: integer + configuredSessionRevokedAction: + description: |- + Step 3: Action preview. + The action configured for session-revoked events on this stream. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - timedOutAt: - format: date-time + x-speakeasy-unknown-values: allow + identityLinkFound: + description: |- + Step 2: Identity mapping. + Whether the test subject was resolved to a ConductorOne user. + type: boolean + jwksError: + description: Error message if the JWKS endpoint could not be reached or returned invalid data. + type: string + jwksKeyCount: + description: Number of signing keys found at the JWKS endpoint. + format: int32 + type: integer + jwksReachable: + description: |- + Step 1: JWKS reachability. + Whether the JWKS endpoint was reachable and returned valid keys. + type: boolean + matchedUserId: + description: The ConductorOne user ID the test subject maps to, if an identity link was found. + type: string + ready: + description: |- + Overall readiness. + Whether the stream passed all test checks and is ready to process events. + type: boolean + upstreamSubject: + description: The upstream IdP subject identifier (e.g., Okta user ID "00u1234") resolved from the test subject. + type: string + title: Ssf Receiver Stream Service Test Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceTestResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput: + description: SSFReceiverStreamServiceUpdateRequest carries the stream to update and the mask of fields to modify. + properties: + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + updateMask: type: - string - "null" - title: Task Audit Wait For Analysis Step Timed Out + title: Ssf Receiver Stream Service Update Request type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepTimedOut - c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting: - description: The TaskAuditWaitForAnalysisStepWaiting message. + x-speakeasy-name-override: SSFReceiverStreamServiceUpdateRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse: + description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. properties: - stepId: - description: The stepId field. - type: string - title: Task Audit Wait For Analysis Step Waiting + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + title: Ssf Receiver Stream Service Update Response type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepWaiting - c1.api.task.v1.TaskAuditWaitStepSuccess: - description: The TaskAuditWaitStepSuccess message. + x-speakeasy-name-override: SSFReceiverStreamServiceUpdateResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamStats: + description: SSFReceiverStreamStats is a lightweight read-only stats object. properties: - condition: - description: The condition field. + eventsActedOnCount: + description: Number of events that triggered an action (e.g., session revocation). + format: int64 type: string - stepId: - description: The stepId field. + eventsFailedCount: + description: Number of events that failed processing. + format: int64 type: string - succeededAt: + eventsReceivedCount: + description: Total number of events received on this stream. + format: int64 + type: string + lastErrorAt: format: date-time type: - string - "null" - title: Task Audit Wait Step Success - type: object - x-speakeasy-name-override: TaskAuditWaitStepSuccess - c1.api.task.v1.TaskAuditWaitStepTimedOut: - description: The TaskAuditWaitStepTimedOut message. - properties: - condition: - description: The condition field. - type: string - stepId: - description: The stepId field. + lastErrorMessage: + description: Human-readable description of the most recent processing error. type: string - timedOutAt: + lastEventReceivedAt: format: date-time type: - string - "null" - title: Task Audit Wait Step Timed Out - type: object - x-speakeasy-name-override: TaskAuditWaitStepTimedOut - c1.api.task.v1.TaskAuditWaitStepUntilTime: - description: The TaskAuditWaitStepUntilTime message. - properties: - stepId: - description: The stepId field. - type: string - untilTime: + lastVerifiedAt: format: date-time type: - string - "null" - title: Task Audit Wait Step Until Time + streamId: + description: The SSF receiver stream these stats belong to. + type: string + transmitterStatus: + description: Current status reported by the transmitter (e.g., "enabled", "paused"). + type: string + transmitterStatusReason: + description: Reason provided by the transmitter for its current status. + type: string + title: Ssf Receiver Stream Stats type: object - x-speakeasy-name-override: TaskAuditWaitStepUntilTime - c1.api.task.v1.TaskAuditWaitStepWaiting: - description: The TaskAuditWaitStepWaiting message. + x-speakeasy-name-override: SSFReceiverStreamStats + c1.api.sso.v1.OIDCClaimMapping: + description: |- + OIDCClaimMapping releases one user attribute to the application as one + OIDC claim. properties: - condition: - description: The condition field. + claimName: + description: |- + The name of the claim as the application sees it. Namespace custom claims + so they cannot collide with the registered OIDC claim set. type: string - stepId: - description: The stepId field. + destination: + description: Where the claim is released. + enum: + - OIDC_CLAIM_DESTINATION_UNSPECIFIED + - OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY + - OIDC_CLAIM_DESTINATION_USERINFO_ONLY type: string - title: Task Audit Wait Step Waiting - type: object - x-speakeasy-name-override: TaskAuditWaitStepWaiting - c1.api.task.v1.TaskAuditWebhookApprovalAttempt: - description: The TaskAuditWebhookApprovalAttempt message. - properties: - webhookId: - description: The webhookId field. - type: string - webhookInstanceId: - description: The webhookInstanceId field. - type: string - webhookName: - description: The webhookName field. - type: string - webhookUrl: - description: The webhookUrl field. - type: string - title: Task Audit Webhook Approval Attempt - type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalAttempt - c1.api.task.v1.TaskAuditWebhookApprovalBadResponse: - description: The TaskAuditWebhookApprovalBadResponse message. - properties: - error: - description: The error field. - type: string - webhookId: - description: The webhookId field. - type: string - webhookInstanceId: - description: The webhookInstanceId field. - type: string - webhookName: - description: The webhookName field. - type: string - webhookUrl: - description: The webhookUrl field. + x-speakeasy-unknown-values: allow + userAttributeMappingId: + description: |- + The user attribute mapping that resolves the value, including its fallback + chain. type: string - title: Task Audit Webhook Approval Bad Response + required: + - userAttributeMappingId + - claimName + title: Oidc Claim Mapping type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalBadResponse - c1.api.task.v1.TaskAuditWebhookApprovalFatalError: - description: The TaskAuditWebhookApprovalFatalError message. + x-speakeasy-name-override: OIDCClaimMapping + c1.api.sso.v1.SAMLAttributeMapping: + description: |- + SAMLAttributeMapping releases one user attribute to the service provider + as one Attribute in the assertion's AttributeStatement. properties: - error: - description: The error field. - type: string - webhookId: - description: The webhookId field. + friendlyName: + description: Optional FriendlyName, for service providers that display it. type: string - webhookInstanceId: - description: The webhookInstanceId field. + name: + description: The Name attribute, dictated by the service provider. type: string - webhookName: - description: The webhookName field. + nameFormat: + description: The NameFormat attribute. + enum: + - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED + - SAML_ATTRIBUTE_NAME_FORMAT_URI + - SAML_ATTRIBUTE_NAME_FORMAT_BASIC + - SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN type: string - webhookUrl: - description: The webhookUrl field. + x-speakeasy-unknown-values: allow + userAttributeMappingId: + description: |- + The user attribute mapping that resolves the value, including its fallback + chain. type: string - title: Task Audit Webhook Approval Fatal Error + required: + - userAttributeMappingId + - name + title: Saml Attribute Mapping type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalFatalError - c1.api.task.v1.TaskAuditWebhookApprovalSuccess: - description: The TaskAuditWebhookApprovalSuccess message. + x-speakeasy-name-override: SAMLAttributeMapping + c1.api.sso.v1.SAMLMetadataFinding: + description: |- + SAMLMetadataFinding is one thing ConductorOne noticed while parsing a service + provider's metadata document. properties: - webhookId: - description: The webhookId field. - type: string - webhookInstanceId: - description: The webhookInstanceId field. + component: + description: Where the finding fits in the parsed document. + enum: + - COMPONENT_UNSPECIFIED + - COMPONENT_DOCUMENT + - COMPONENT_ENTITY_ID + - COMPONENT_ACS_URL + - COMPONENT_NAME_ID_FORMAT + - COMPONENT_SIGNING_CERTIFICATE + - COMPONENT_ENCRYPTION_CERTIFICATE + - COMPONENT_REQUIREMENT + - COMPONENT_BINDING type: string - webhookName: - description: The webhookName field. + x-speakeasy-unknown-values: allow + level: + description: The severity of this finding. + enum: + - LEVEL_UNSPECIFIED + - LEVEL_BLOCKING + - LEVEL_WARNING type: string - webhookUrl: - description: The webhookUrl field. + x-speakeasy-unknown-values: allow + reason: + description: Plain-language explanation of why the finding was raised. type: string - title: Task Audit Webhook Approval Success + title: Saml Metadata Finding type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalSuccess - c1.api.task.v1.TaskAuditWebhookApprovalTriggered: - description: The TaskAuditWebhookApprovalTriggered message. + x-speakeasy-name-override: SAMLMetadataFinding + c1.api.sso.v1.SSOApplication: + description: | + SSOApplication is one application your users sign in to through ConductorOne. + + This message contains a oneof named protocol. Only a single field of the following list may be set at a time: + - oidc + - saml properties: - webhookId: - description: The webhookId field. - type: string - webhookInstanceId: - description: The webhookInstanceId field. + appEntitlementId: + description: |- + The entitlement a user must hold to sign in. Created with the SSO + application and not settable by the caller. type: string - webhookName: - description: The webhookName field. + appId: + description: |- + The application in your catalog that owns this sign-in configuration. Its + owners, entitlements, and access reviews govern who may sign in. type: string - webhookUrl: - description: The webhookUrl field. + assertionLifetime: + format: duration + type: + - string + - "null" + createdAt: + format: date-time + type: + - string + - "null" + description: + description: Description of the SSO application. type: string - title: Task Audit Webhook Approval Triggered - type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalTriggered - c1.api.task.v1.TaskAuditWebhookAttempt: - description: The TaskAuditWebhookAttempt message. - properties: - webhookId: - description: The webhookId field. + disabled: + description: |- + When true, sign-in through this application is refused. The application + and its entitlement are left in place. + type: boolean + displayName: + description: Display name for the SSO application. type: string - webhookInstanceId: - description: The webhookInstanceId field. + id: + description: Unique identifier for this SSO application. type: string - webhookName: - description: The webhookName field. + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCConfig' + - type: "null" + saml: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig' + - type: "null" + sectorId: + description: |- + The pairwise sector this application belongs to. Empty means the + application is its own sector and shares linkability with nothing; set a + shared value to issue one identifier across applications a user should + appear the same to. Ignored when the subject type resolves to PUBLIC. + Immutable once set. type: string - webhookUrl: - description: The webhookUrl field. + subjectCompatibility: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSubjectCompatibility' + - type: "null" + subjectType: + description: How the user's identifier reaches this application. + enum: + - SSO_SUBJECT_TYPE_UNSPECIFIED + - SSO_SUBJECT_TYPE_PAIRWISE + - SSO_SUBJECT_TYPE_PUBLIC + - SSO_SUBJECT_TYPE_COMPATIBILITY type: string - title: Task Audit Webhook Attempt + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + title: Sso Application type: object - x-speakeasy-name-override: TaskAuditWebhookAttempt - c1.api.task.v1.TaskAuditWebhookSuccess: - description: The TaskAuditWebhookSuccess message. + x-speakeasy-name-override: SSOApplication + c1.api.sso.v1.SSOApplicationHistoryEntry: + description: |- + SSOApplicationHistoryEntry is one version of an SSO application and its + history metadata. properties: - webhookId: - description: The webhookId field. - type: string - webhookInstanceId: - description: The webhookInstanceId field. - type: string - webhookName: - description: The webhookName field. - type: string - webhookUrl: - description: The webhookUrl field. - type: string - title: Task Audit Webhook Success + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' + - type: "null" + title: Sso Application History Entry type: object - x-speakeasy-name-override: TaskAuditWebhookSuccess - c1.api.task.v1.TaskAuditWebhookTriggered: - description: The TaskAuditWebhookTriggered message. + x-speakeasy-name-override: SSOApplicationHistoryEntry + c1.api.sso.v1.SSOApplicationOIDCClient: + description: SSOApplicationOIDCClient is an App-owned OAuth client minted by C1. properties: - webhookId: - description: The webhookId field. + appId: + description: Application that owns this client. type: string - webhookInstanceId: - description: The webhookInstanceId field. + authentication: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthentication' + - type: "null" + clientId: + description: Client ID generated by ConductorOne. type: string - webhookName: - description: The webhookName field. + createdAt: + format: date-time + type: + - string + - "null" + displayName: + description: Human-readable client name. type: string - webhookUrl: - description: The webhookUrl field. + pkcePolicy: + description: Effective PKCE policy. + enum: + - SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED + - SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256 + - SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY type: string - title: Task Audit Webhook Triggered - type: object - x-speakeasy-name-override: TaskAuditWebhookTriggered - c1.api.task.v1.TaskExpandMask: - description: The task expand mask is an array of strings that specifes the related objects the requester wishes to have returned when making a request where the expand mask is part of the input. Use '*' to view all possible responses. - properties: - paths: - description: A list of paths to expand in the response. May be any combination of "*", "access_review_id", "user_id", "created_by_user_id", "app_id", "app_user_id", "app_entitlement_ids", "step_approver_ids", "approver_ids", "identity_user_id", "insight_ids", "app_user_last_usage", "entitlement_scope_bindings", "scope_role_resources", and "resource". + x-speakeasy-unknown-values: allow + redirectUris: + description: Exact callback URLs registered for this client. items: type: string type: - array - "null" - title: Task Expand Mask - type: object - x-speakeasy-name-override: TaskExpandMask - c1.api.task.v1.TaskGrantSource: - description: The TaskGrantSource message tracks which external URL was the source of the specificed grant ticket. - properties: - conversationId: - description: The ID of the conversation that created this ticket - type: string - externalUrl: - description: The external url source of the grant ticket. - type: string - integrationId: - description: The integration id for the source of tickets. - type: string - isExtension: - description: Whether the grant task is an extension task. - type: boolean - requestId: - description: the request id for the grant ticket if the source is external + ssoApplicationId: + description: SSO application whose identity policy applies to this client. type: string - title: Task Grant Source + updatedAt: + format: date-time + type: + - string + - "null" + title: Sso Application Oidc Client type: object - x-speakeasy-name-override: TaskGrantSource - c1.api.task.v1.TaskRef: - description: This object references a task by ID. - properties: - id: - description: The ID of the referenced Task - type: string - title: Task Ref + x-speakeasy-name-override: SSOApplicationOIDCClient + c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretBasic: + description: RFC 6749 client_secret_basic. C1 generates and returns the secret once. + title: Sso Application Oidc Client Auth Client Secret Basic type: object - x-speakeasy-name-override: TaskRef - c1.api.task.v1.TaskRevocationTarget: - description: An ancestor entitlement that will be revoked as part of an inheritance revocation. + x-speakeasy-name-override: SSOApplicationOIDCClientAuthClientSecretBasic + c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretPost: + description: RFC 6749 client_secret_post. C1 generates and returns the secret once. + title: Sso Application Oidc Client Auth Client Secret Post + type: object + x-speakeasy-name-override: SSOApplicationOIDCClientAuthClientSecretPost + c1.api.sso.v1.SSOApplicationOIDCClientAuthNone: + description: Public client authentication. No client credential is issued. + title: Sso Application Oidc Client Auth None + type: object + x-speakeasy-name-override: SSOApplicationOIDCClientAuthNone + c1.api.sso.v1.SSOApplicationOIDCClientAuthPrivateKeyJWT: + description: |- + RFC 7523 private_key_jwt using an inline RFC 7517 JWK Set. Multiple public + signing keys allow overlap during relying-party key rotation; C1 selects by + the assertion's `kid`. The relying party retains every private key. properties: - entitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - title: Task Revocation Target + publicJwks: + description: The publicJwks field. + format: base64 + type: string + required: + - publicJwks + title: Sso Application Oidc Client Auth Private Key Jwt type: object - x-speakeasy-name-override: TaskRevocationTarget - c1.api.task.v1.TaskRevokeSource: + x-speakeasy-name-override: SSOApplicationOIDCClientAuthPrivateKeyJWT + c1.api.sso.v1.SSOApplicationOIDCClientAuthentication: description: | - The TaskRevokeSource message indicates the source of the revoke task is one of expired, nonUsage, request, or review. + SSOApplicationOIDCClientAuthentication is the exact token-endpoint client + authentication method assigned to an OIDC client. - This message contains a oneof named origin. Only a single field of the following list may be set at a time: - - review - - request - - expired - - nonUsage + This message contains a oneof named method. Only a single field of the following list may be set at a time: + - none + - clientSecretBasic + - clientSecretPost + - privateKeyJwt properties: - expired: + clientSecretBasic: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceExpired' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretBasic' - type: "null" - nonUsage: + clientSecretPost: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceNonUsage' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthClientSecretPost' - type: "null" - request: + none: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceRequest' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthNone' - type: "null" - review: + privateKeyJwt: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceReview' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthPrivateKeyJWT' - type: "null" - title: Task Revoke Source - type: object - x-speakeasy-name-override: TaskRevokeSource - c1.api.task.v1.TaskRevokeSourceExpired: - description: The TaskRevokeSourceExpired message indicates that the source of the revoke task is due to a grant expiring. - properties: - expiredAt: - format: date-time - type: - - string - - "null" - title: Task Revoke Source Expired - type: object - x-speakeasy-name-override: TaskRevokeSourceExpired - c1.api.task.v1.TaskRevokeSourceNonUsage: - description: The TaskRevokeSourceNonUsage message indicates that the source of the revoke task is due to the grant not being used. - properties: - expiresAt: - format: date-time - type: - - string - - "null" - lastLogin: - format: date-time - type: - - string - - "null" - title: Task Revoke Source Non Usage - type: object - x-speakeasy-name-override: TaskRevokeSourceNonUsage - c1.api.task.v1.TaskRevokeSourceRequest: - description: The TaskRevokeSourceRequest message indicates that the source of the revoke task was a request. - properties: - requestUserId: - description: The ID of the user who initiated the revoke request. - type: string - title: Task Revoke Source Request + title: Sso Application Oidc Client Authentication type: object - x-speakeasy-name-override: TaskRevokeSourceRequest - c1.api.task.v1.TaskRevokeSourceReview: - description: The TaskRevokeSourceReview message tracks which access review was the source of the specificed revoke ticket. + x-speakeasy-name-override: SSOApplicationOIDCClientAuthentication + c1.api.sso.v1.SSOApplicationOIDCClientConfig: + description: |- + SSOApplicationOIDCClientConfig is the administrator-supplied configuration + from which C1 mints an App-owned OAuth client. The client ID is never input. properties: - accessReviewId: - description: The ID of the access review associated with the revoke task. + authentication: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientAuthentication' + - type: "null" + displayName: + description: Human-readable client name shown to administrators. type: string - certTicketId: - description: The ID of the certify ticket that was denied and created this revoke task. + pkcePolicy: + description: |- + PKCE is required by default on create. On update, UNSPECIFIED preserves + the current policy; set REQUIRED_S256 explicitly to tighten a legacy + confidential client. + enum: + - SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED + - SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256 + - SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY type: string - title: Task Revoke Source Review - type: object - x-speakeasy-name-override: TaskRevokeSourceReview - c1.api.task.v1.TaskSearchRequest: - description: Search for tasks based on a plethora filters. - properties: - accessReviewIds: - description: Search tasks that belong to any of the access reviews included in this list. - items: - type: string - type: - - array - - "null" - accountOwnerIds: - description: Search tasks that have any of these account owners. + x-speakeasy-unknown-values: allow + redirectUris: + description: |- + Exact redirect URIs the client may use after authorization. HTTPS and + loopback HTTP are accepted; public clients may also use a reversed-DNS + private-use scheme for native-app redirects. items: type: string type: - array - "null" - accountTypes: - description: The accountTypes field. + required: + - displayName + - authentication + title: Sso Application Oidc Client Config + type: object + x-speakeasy-name-override: SSOApplicationOIDCClientConfig + c1.api.sso.v1.SSOApplicationOIDCConfig: + description: SSOApplicationOIDCConfig is the OIDC-specific sign-in configuration. + properties: + claimMappings: + description: |- + Custom claims released to this application, in addition to the standard + claims its granted scopes already release. items: - enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.sso.v1.OIDCClaimMapping' type: - array - "null" - actorId: - description: Search tasks that have this actor ID. + idTokenSignedResponseAlg: + description: The algorithm used to sign this application's id_token. + enum: + - OIDC_SIGNING_ALGORITHM_UNSPECIFIED + - OIDC_SIGNING_ALGORITHM_EDDSA + - OIDC_SIGNING_ALGORITHM_ES256 + - OIDC_SIGNING_ALGORITHM_RS256 type: string - appEntitlementIds: - description: Search tasks that have any of these app entitlement IDs. + x-speakeasy-unknown-values: allow + title: Sso Application Oidc Config + type: object + x-speakeasy-name-override: SSOApplicationOIDCConfig + c1.api.sso.v1.SSOApplicationSAMLConfig: + description: SSOApplicationSAMLConfig is the SAML-specific sign-in configuration. + properties: + acsUrls: + description: |- + The Assertion Consumer Service URLs the assertion may be posted to. + Matched exactly; a URL that is not in this list is refused. items: type: string type: - array - "null" - appResourceIds: - description: Search tasks that have any of these app resource IDs. + attributeMappings: + description: |- + The attributes released in the assertion's AttributeStatement. SAML has no + scopes, so this list is the whole release: the NameID carries the + identifier and these carry everything else. items: - type: string + $ref: '#/components/schemas/c1.api.sso.v1.SAMLAttributeMapping' type: - array - "null" - appResourceTypeIds: - description: Search tasks that have any of these app resource type IDs. + encryptAssertions: + description: Encrypt the assertion. + type: boolean + encryptionAlgorithm: + description: The algorithm used when encrypt_assertions is set. + enum: + - SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED + - SAML_ENCRYPTION_ALGORITHM_AES256_GCM + - SAML_ENCRYPTION_ALGORITHM_AES128_GCM + - SAML_ENCRYPTION_ALGORITHM_AES256_CBC + type: string + x-speakeasy-unknown-values: allow + nameIdFormat: + description: |- + Set this when the service provider requires a specific NameID format. This + also selects the NameID value semantics: EMAIL_ADDRESS uses the user's + primary email, TRANSIENT creates a new value for each sign-in, and + PERSISTENT uses the application's pairwise subject. Immutable once set. + enum: + - SAML_NAME_ID_FORMAT_UNSPECIFIED + - SAML_NAME_ID_FORMAT_PERSISTENT + - SAML_NAME_ID_FORMAT_EMAIL_ADDRESS + - SAML_NAME_ID_FORMAT_UNSPECIFIED_URN + - SAML_NAME_ID_FORMAT_TRANSIENT + type: string + x-speakeasy-unknown-values: allow + requireSignedAuthnRequests: + description: |- + Reject any AuthnRequest that is not signed by one of + sp_signing_certificates. At least one signing certificate is required when + this is set. + type: boolean + signAssertions: + description: |- + Sign the assertion. At least one of sign_assertions or sign_responses must + be set. + type: boolean + signResponses: + description: |- + Sign the response envelope. At least one of sign_assertions or + sign_responses must be set. + type: boolean + spEncryptionCertificate: + description: |- + The service provider's DER-encoded encryption certificate, taken from the + encryption KeyDescriptor in its metadata. Required when encrypt_assertions + is set. + format: base64 + type: string + spEntityId: + description: |- + The service provider's entity ID, taken from its metadata. It is the + audience every assertion this application issues is restricted to, and it + is what the service provider presents at sign-in. Set it at creation: it is + fixed for the life of the application, because changing it re-points every + assertion already issued. An entity ID already in use by another SSO + application in the tenant is rejected. + type: string + spSigningCertificates: + description: |- + The service provider's DER-encoded signing certificates, taken from the + signing KeyDescriptors in its metadata. items: + format: base64 type: string type: - array - "null" - appUserSubjectIds: - description: Search tasks that have any of these app users as subjects. + required: + - spEntityId + - acsUrls + title: Sso Application Saml Config + type: object + x-speakeasy-name-override: SSOApplicationSAMLConfig + c1.api.sso.v1.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequestInput: + description: |- + SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest deletes a + bounded batch of compatibility-subject bindings. + properties: + userIds: + description: The userIds field. items: type: string type: - array - "null" - applicationIds: - description: Search tasks that have any of these apps as targets. + title: Sso Application Service Batch Delete Subject Compatibility Request + type: object + x-speakeasy-name-override: SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest + c1.api.sso.v1.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse: + description: |- + SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded + recovery progress. + properties: + deletedRows: + description: The deletedRows field. + format: int32 + type: integer + issues: + description: The issues field. items: - type: string + $ref: '#/components/schemas/c1.api.sso.v1.SSOSubjectCompatibilityDeleteIssue' type: - array - "null" - assignedOrStepApproverUserId: - description: Search tasks that are currently assigned to this user, or that are closed and were previously approved by this user. - type: string - assigneesInIds: - description: Search tasks by List of UserIDs which are currently assigned these Tasks + title: Sso Application Service Batch Delete Subject Compatibility Response + type: object + x-speakeasy-name-override: SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse + c1.api.sso.v1.SSOApplicationServiceBatchImportSubjectCompatibilityRequestInput: + description: |- + SSOApplicationServiceBatchImportSubjectCompatibilityRequest validates or + imports a bounded batch of per-user subject bindings. + properties: + apply: + description: |- + When false, validate without writing. Clients should validate every batch + before beginning the apply pass. + type: boolean + entries: + description: Client-parsed rows. Each request is bounded to 50 entries. items: - type: string + $ref: '#/components/schemas/c1.api.sso.v1.SSOSubjectCompatibilityImportEntry' type: - array - "null" - certifyOutcomes: - description: Search tasks by certify outcome + importId: + description: Client-generated identifier shared by every batch from one source file. + type: string + title: Sso Application Service Batch Import Subject Compatibility Request + type: object + x-speakeasy-name-override: SSOApplicationServiceBatchImportSubjectCompatibilityRequest + c1.api.sso.v1.SSOApplicationServiceBatchImportSubjectCompatibilityResponse: + description: |- + SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one + bounded validation or apply batch. + properties: + blockingUserIds: + description: |- + Import-created binding owners that block one or more submitted corrections. + This is a subset of recoverable_user_ids. items: - enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT type: string - x-speakeasy-unknown-values: allow type: - array - "null" - createdAfter: - format: date-time - type: - - string - - "null" - createdBefore: - format: date-time - type: - - string - - "null" - currentStep: - description: Search tasks that have this type of step as the current step. - enum: - - TASK_SEARCH_CURRENT_STEP_UNSPECIFIED - - TASK_SEARCH_CURRENT_STEP_APPROVAL - - TASK_SEARCH_CURRENT_STEP_PROVISION - type: string - x-speakeasy-unknown-values: allow - emergencyStatus: - description: Search tasks that are or are not emergency access. - enum: - - UNSPECIFIED - - ALL - - NON_EMERGENCY - - EMERGENCY - type: string - x-speakeasy-unknown-values: allow - excludeAppEntitlementIds: - description: Search tasks that do not have any of these app entitlement IDs. + importedRows: + description: |- + Number of bindings successfully written. Zero for validation-only + requests; may be less than valid_rows if apply stops on a write failure. + format: int32 + type: integer + importedUserIds: + description: |- + Users whose bindings were created by this import, or were already created + by an earlier retry carrying the same import_id. items: type: string type: - array - "null" - excludeAppResourceTypeIds: - description: Search tasks that do not have any of these app resource type IDs. + issues: + description: Row-level validation or apply failures. items: - type: string + $ref: '#/components/schemas/c1.api.sso.v1.SSOSubjectCompatibilityImportIssue' type: - array - "null" - excludeApplicationIds: - description: Search tasks that do NOT have any of these apps as targets. + recoverableUserIds: + description: |- + Users whose import-created binding is implicated by a submitted row. This + may include the current owner of a submitted subject even when that owner + was not itself submitted. items: type: string type: - array - "null" - excludeIds: - description: Exclude Specific TaskIDs from this serach result. - items: - type: string + totalRows: + description: Number of entries in this batch. + format: int32 + type: integer + validRows: + description: Number of rows that can be imported. + format: int32 + type: integer + title: Sso Application Service Batch Import Subject Compatibility Response + type: object + x-speakeasy-name-override: SSOApplicationServiceBatchImportSubjectCompatibilityResponse + c1.api.sso.v1.SSOApplicationServiceCreateClientRequestInput: + description: |- + SSOApplicationServiceCreateClientRequest mints an additional App-owned + client. The caller supplies configuration, never a client ID. + properties: + client: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientConfig' + - type: "null" + required: + - client + title: Sso Application Service Create Client Request + type: object + x-speakeasy-name-override: SSOApplicationServiceCreateClientRequest + c1.api.sso.v1.SSOApplicationServiceCreateClientResponse: + description: |- + SSOApplicationServiceCreateClientResponse contains the generated client and + its one-time secret, when applicable. + properties: + client: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClient' + - type: "null" + clientSecret: + description: |- + Returned once for client_secret_basic/client_secret_post; empty for + none/private_key_jwt. + type: string + title: Sso Application Service Create Client Response + type: object + x-speakeasy-name-override: SSOApplicationServiceCreateClientResponse + c1.api.sso.v1.SSOApplicationServiceCreateRequestInput: + description: | + SSOApplicationServiceCreateRequest creates an SSO application. + + This message contains a oneof named protocol. Only a single field of the following list may be set at a time: + - oidc + - saml + properties: + assertionLifetime: + format: duration type: - - array + - string - "null" - expandMask: + description: + description: Description of the SSO application. + type: string + displayName: + description: Display name for the SSO application. + type: string + initialClient: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientConfig' - type: "null" - grantOutcomes: - description: Search tasks by grant outcome - items: - enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" - includeActedAfter: - format: date-time - type: - - string - - "null" - includeDeleted: - description: Whether or not to include deleted tasks. - type: boolean - myWorkUserIds: - description: Search tasks where the user would see this task in the My Work section - items: - type: string - type: - - array - - "null" - olderThanDuration: - format: duration - type: - - string - - "null" - openerIds: - description: Search tasks that were created by any of the users in this array. - items: - type: string - type: - - array - - "null" - openerOrSubjectUserId: - description: Search tasks that were opened by this user, or that the user is the subject of. - type: string - outcomeAfter: - format: date-time - type: - - string - - "null" - outcomeBefore: - format: date-time - type: - - string - - "null" - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - type: integer - pageToken: - description: The pageToken field. + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCConfig' + - type: "null" + saml: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig' + - type: "null" + sectorId: + description: |- + The pairwise sector this application belongs to. Empty means the + application is its own sector. Immutable after creation. type: string - pendingActionFilter: + subjectCompatibility: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSubjectCompatibility' + - type: "null" + subjectType: description: |- - Filter tasks by pending action status. Only applies when exactly one access_review_id is specified. - Requires the REVIEWS_PENDING_ACTIONS feature flag to be enabled. + How the user's identifier reaches this application. Leave unset to use the + tenant default. enum: - - PENDING_ACTION_FILTER_UNSPECIFIED - - PENDING_ACTION_FILTER_WITH_PENDING - - PENDING_ACTION_FILTER_WITHOUT_PENDING + - SSO_SUBJECT_TYPE_UNSPECIFIED + - SSO_SUBJECT_TYPE_PAIRWISE + - SSO_SUBJECT_TYPE_PUBLIC + - SSO_SUBJECT_TYPE_COMPATIBILITY type: string x-speakeasy-unknown-values: allow - previouslyActedOnIds: - description: Search tasks that were acted on by any of these users. - items: - type: string - type: - - array - - "null" - query: - description: Fuzzy search tasks by display name, description, or ID. + required: + - displayName + title: Sso Application Service Create Request + type: object + x-speakeasy-name-override: SSOApplicationServiceCreateRequest + c1.api.sso.v1.SSOApplicationServiceCreateResponse: + description: SSOApplicationServiceCreateResponse returns the created SSO application. + properties: + application: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' + - type: "null" + client: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClient' + - type: "null" + clientSecret: + description: |- + Confidential-client secret returned once. Empty for SAML and public OIDC + clients. C1 stores only its hash. type: string - refs: - description: Query tasks by display name, description, or numeric ID. - items: - $ref: '#/components/schemas/c1.api.task.v1.TaskRef' - type: - - array - - "null" - requireApprovalReason: - description: Filter tasks where the current approval step requires an approval reason. - type: boolean - requireDenialReason: - description: Filter tasks where the current approval step requires a denial reason. - type: boolean - revokeOutcomes: - description: Search tasks by revoke outcome - items: - enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" - sortBy: - description: Sort tasks in a specific order. - enum: - - TASK_SEARCH_SORT_BY_UNSPECIFIED - - TASK_SEARCH_SORT_BY_ACCOUNT - - TASK_SEARCH_SORT_BY_RESOURCE - - TASK_SEARCH_SORT_BY_ACCOUNT_OWNER - - TASK_SEARCH_SORT_BY_REVERSE_TICKET_ID - - TASK_SEARCH_SORT_BY_TICKET_ID - - TASK_SEARCH_SORT_BY_CREATED_AT - - TASK_SEARCH_SORT_BY_REVERSE_CREATED_AT - - TASK_SEARCH_SORT_BY_APP_RESOURCE_ID_AND_APP_ENTITLEMENT + title: Sso Application Service Create Response + type: object + x-speakeasy-name-override: SSOApplicationServiceCreateResponse + c1.api.sso.v1.SSOApplicationServiceDeleteClientRequestInput: + description: SSOApplicationServiceDeleteClientRequest deletes one App-owned OAuth client. + properties: + clientId: + description: Generated client ID to delete. type: string - x-speakeasy-unknown-values: allow - stepApprovalTypes: - description: Search tasks that have a current policy step of this type + required: + - clientId + title: Sso Application Service Delete Client Request + type: object + x-speakeasy-name-override: SSOApplicationServiceDeleteClientRequest + c1.api.sso.v1.SSOApplicationServiceDeleteClientResponse: + description: SSOApplicationServiceDeleteClientResponse confirms deletion. + title: Sso Application Service Delete Client Response + type: object + x-speakeasy-name-override: SSOApplicationServiceDeleteClientResponse + c1.api.sso.v1.SSOApplicationServiceDeleteRequestInput: + description: SSOApplicationServiceDeleteRequest deletes an SSO application. + title: Sso Application Service Delete Request + type: object + x-speakeasy-name-override: SSOApplicationServiceDeleteRequest + c1.api.sso.v1.SSOApplicationServiceDeleteResponse: + description: SSOApplicationServiceDeleteResponse confirms deletion. + title: Sso Application Service Delete Response + type: object + x-speakeasy-name-override: SSOApplicationServiceDeleteResponse + c1.api.sso.v1.SSOApplicationServiceGetResponse: + description: SSOApplicationServiceGetResponse returns a single SSO application. + properties: + application: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' + - type: "null" + title: Sso Application Service Get Response + type: object + x-speakeasy-name-override: SSOApplicationServiceGetResponse + c1.api.sso.v1.SSOApplicationServiceListClientsResponse: + description: |- + SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth + clients. + properties: + list: + description: App-owned clients in this page. items: - enum: - - STEP_APPROVAL_TYPE_UNSPECIFIED - - STEP_APPROVAL_TYPE_USERS - - STEP_APPROVAL_TYPE_MANAGER - - STEP_APPROVAL_TYPE_APP_OWNERS - - STEP_APPROVAL_TYPE_GROUP - - STEP_APPROVAL_TYPE_SELF - - STEP_APPROVAL_TYPE_ENTITLEMENT_OWNERS - - STEP_APPROVAL_TYPE_EXPRESSION - - STEP_APPROVAL_TYPE_WEBHOOK - - STEP_APPROVAL_TYPE_RESOURCE_OWNERS - - STEP_APPROVAL_TYPE_AGENT - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClient' type: - array - "null" - subjectIds: - description: Search tasks where these users are the subject. + nextPageToken: + description: Pagination token for the next page, or empty when complete. + type: string + title: Sso Application Service List Clients Response + type: object + x-speakeasy-name-override: SSOApplicationServiceListClientsResponse + c1.api.sso.v1.SSOApplicationServiceListHistoryResponse: + description: |- + SSOApplicationServiceListHistoryResponse returns SSO application history + entries. + properties: + list: + description: The page of history entries, newest first. items: - type: string + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationHistoryEntry' type: - array - "null" - taskStates: - description: Search tasks with this task state. + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: Sso Application Service List History Response + type: object + x-speakeasy-name-override: SSOApplicationServiceListHistoryResponse + c1.api.sso.v1.SSOApplicationServiceListResponse: + description: SSOApplicationServiceListResponse returns a page of SSO applications. + properties: + list: + description: The page of SSO applications. items: - enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' type: - array - "null" - taskTypes: - description: Search tasks with this task type. This is a oneOf, and needs an object, which can be empty, to sort. + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: Sso Application Service List Response + type: object + x-speakeasy-name-override: SSOApplicationServiceListResponse + c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest: + description: |- + SSOApplicationServiceParseSAMLServiceProviderMetadataRequest carries one + SAML service-provider metadata document to parse. + properties: + metadataXml: + description: |- + The SP metadata XML document, exactly as downloaded or exported from the + service provider. Maximum 1 MiB. The document is parsed, never stored. + format: base64 + type: string + required: + - metadataXml + title: Sso Application Service Parse Saml Service Provider Metadata Request + type: object + x-speakeasy-name-override: SSOApplicationServiceParseSAMLServiceProviderMetadataRequest + c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse: + description: |- + SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the + SAML configuration derived from one metadata document and every finding the + parser raised about it. + properties: + config: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationSAMLConfig' + - type: "null" + findings: + description: |- + Everything the parser noticed about the document, including requirements + it could not map into the configuration. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskType' + $ref: '#/components/schemas/c1.api.sso.v1.SAMLMetadataFinding' type: - array - "null" - userEmploymentStatuses: - description: The userEmploymentStatuses field. + title: Sso Application Service Parse Saml Service Provider Metadata Response + type: object + x-speakeasy-name-override: SSOApplicationServiceParseSAMLServiceProviderMetadataResponse + c1.api.sso.v1.SSOApplicationServiceRotateClientSecretRequestInput: + description: |- + SSOApplicationServiceRotateClientSecretRequest rotates one confidential + App-owned client's secret. + properties: + clientId: + description: Generated client ID whose secret will be rotated. + type: string + required: + - clientId + title: Sso Application Service Rotate Client Secret Request + type: object + x-speakeasy-name-override: SSOApplicationServiceRotateClientSecretRequest + c1.api.sso.v1.SSOApplicationServiceRotateClientSecretResponse: + description: |- + SSOApplicationServiceRotateClientSecretResponse contains the replacement + secret. The value cannot be retrieved again. + properties: + clientSecret: + description: New client secret, shown exactly once. + type: string + title: Sso Application Service Rotate Client Secret Response + type: object + x-speakeasy-name-override: SSOApplicationServiceRotateClientSecretResponse + c1.api.sso.v1.SSOApplicationServiceSearchRequest: + description: SSOApplicationServiceSearchRequest searches SSO applications with filters. + properties: + appIds: + description: |- + Optional filter by applications in your catalog. Empty matches any + application. items: type: string type: - array - "null" - title: Task Search Request + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response. + type: string + query: + description: Optional text query matched against display_name and description. + type: string + title: Sso Application Service Search Request type: object - x-speakeasy-name-override: TaskSearchRequest - c1.api.task.v1.TaskSearchResponse: - description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: SSOApplicationServiceSearchRequest + c1.api.sso.v1.SSOApplicationServiceSearchResponse: + description: SSOApplicationServiceSearchResponse returns matching SSO applications. properties: - expanded: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" list: - description: List of serialized related objects. + description: Matching SSO applications. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' type: - array - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + description: Token for the next page. type: string - title: Task Search Response + title: Sso Application Service Search Response type: object - x-speakeasy-name-override: TaskSearchResponse - c1.api.task.v1.TaskServiceActionResponse: - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + x-speakeasy-name-override: SSOApplicationServiceSearchResponse + c1.api.sso.v1.SSOApplicationServiceUpdateClientRequestInput: + description: |- + SSOApplicationServiceUpdateClientRequest replaces display name, redirect + URIs, private-key JWKS, or tightens legacy PKCE to required. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: + client: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClientConfig' - type: "null" - ticketActionId: - description: The ID of the task action created by this request. + clientId: + description: Generated client ID to update. type: string - title: Task Service Action Response + required: + - clientId + - client + title: Sso Application Service Update Client Request type: object - x-speakeasy-name-override: TaskServiceActionResponse - c1.api.task.v1.TaskServiceCreateActionRequest: - description: The TaskServiceCreateActionRequest message submits a request action (requestable automation). + x-speakeasy-name-override: SSOApplicationServiceUpdateClientRequest + c1.api.sso.v1.SSOApplicationServiceUpdateClientResponse: + description: SSOApplicationServiceUpdateClientResponse contains the updated client. properties: - actionId: - description: The ID of the action to request. - type: string - description: - description: An optional description of the request. - type: string - expandMask: + client: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationOIDCClient' - type: "null" - formValues: - additionalProperties: true - type: - - object - - "null" - title: Task Service Create Action Request + title: Sso Application Service Update Client Response type: object - x-speakeasy-name-override: TaskServiceCreateActionRequest - c1.api.task.v1.TaskServiceCreateActionResponse: - description: The TaskServiceCreateActionResponse returns the created action task with optional expanded related objects. + x-speakeasy-name-override: SSOApplicationServiceUpdateClientResponse + c1.api.sso.v1.SSOApplicationServiceUpdateRequestInput: + description: SSOApplicationServiceUpdateRequest updates an SSO application. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true - type: - - array - - "null" - taskView: + application: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' - type: "null" - title: Task Service Create Action Response + updateMask: + type: + - string + - "null" + required: + - application + - updateMask + title: Sso Application Service Update Request type: object - x-speakeasy-name-override: TaskServiceCreateActionResponse - c1.api.task.v1.TaskServiceCreateGrantRequest: - description: Create a grant task. + x-speakeasy-name-override: SSOApplicationServiceUpdateRequest + c1.api.sso.v1.SSOApplicationServiceUpdateResponse: + description: SSOApplicationServiceUpdateResponse returns the updated SSO application. properties: - appEntitlementId: - description: The ID of the app entitlement to grant access to. - type: string - appId: - description: The ID of the app that is associated with the entitlement. - type: string - appUserId: - description: The ID of the app user to grant access for. This field and identityUserId cannot both be set for a given request. - type: string - description: - description: The description of the request. - type: string - emergencyAccess: - description: Boolean stating whether or not the task is marked as emergency access. - type: boolean - expandMask: + application: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplication' - type: "null" - grantDuration: + title: Sso Application Service Update Response + type: object + x-speakeasy-name-override: SSOApplicationServiceUpdateResponse + c1.api.sso.v1.SSOSettings: + description: |- + SSOSettings is the per-tenant configuration for ConductorOne acting as an SSO + provider. + properties: + createdAt: + format: date-time + type: + - string + - "null" + defaultAssertionLifetime: format: duration type: - string - "null" - identityUserId: - description: The ID of the user associated with the app user we are granting access for. This field cannot be set if appUserID is also set. + defaultIdTokenSignedResponseAlg: + description: |- + The id_token signing algorithm applied to OIDC applications that do not + choose one. When unset, the server uses EdDSA. + enum: + - OIDC_SIGNING_ALGORITHM_UNSPECIFIED + - OIDC_SIGNING_ALGORITHM_EDDSA + - OIDC_SIGNING_ALGORITHM_ES256 + - OIDC_SIGNING_ALGORITHM_RS256 type: string - requestData: - additionalProperties: true + x-speakeasy-unknown-values: allow + defaultSubjectType: + description: |- + The subject type materialized onto new SSO applications that do not choose + one. Changing this default does not change existing applications. When + unset, the server uses pairwise subjects. + enum: + - SSO_SUBJECT_TYPE_UNSPECIFIED + - SSO_SUBJECT_TYPE_PAIRWISE + - SSO_SUBJECT_TYPE_PUBLIC + - SSO_SUBJECT_TYPE_COMPATIBILITY + type: string + x-speakeasy-unknown-values: allow + enabled: + description: |- + Master switch for the SSO provider. ConductorOne also gates the feature + behind an operator-controlled rollout flag; this is the tenant + administrator's intent. Individual SSO applications can still be disabled + one at a time. + type: boolean + updatedAt: + format: date-time type: - - object + - string - "null" - source: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' - - type: "null" - required: - - appId - - appEntitlementId - title: Task Service Create Grant Request + title: Sso Settings type: object - x-speakeasy-name-override: TaskServiceCreateGrantRequest - c1.api.task.v1.TaskServiceCreateGrantResponse: - description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SSOSettings + c1.api.sso.v1.SSOSettingsHistoryEntry: + description: |- + SSOSettingsHistoryEntry is one version of the tenant's SSO settings and its + change metadata. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true - type: - - array - - "null" - taskView: + metadata: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' - type: "null" - title: Task Service Create Grant Response + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSettings' + - type: "null" + title: Sso Settings History Entry type: object - x-speakeasy-name-override: TaskServiceCreateGrantResponse - c1.api.task.v1.TaskServiceCreateOffboardingRequest: - description: Create an offboarding task. + x-speakeasy-name-override: SSOSettingsHistoryEntry + c1.api.sso.v1.SSOSettingsServiceGetResponse: + description: SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. properties: - description: - description: The description of the offboarding request. - type: string - expandMask: + settings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSettings' - type: "null" - subjectUserId: - description: The ID of the user to offboard. - type: string - title: Task Service Create Offboarding Request + title: Sso Settings Service Get Response type: object - x-speakeasy-name-override: TaskServiceCreateOffboardingRequest - c1.api.task.v1.TaskServiceCreateOffboardingResponse: - description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. + x-speakeasy-name-override: SSOSettingsServiceGetResponse + c1.api.sso.v1.SSOSettingsServiceListHistoryResponse: + description: SSOSettingsServiceListHistoryResponse returns SSO settings history entries. properties: - expanded: - description: List of serialized related objects. + list: + description: The page of history entries, newest first. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true + $ref: '#/components/schemas/c1.api.sso.v1.SSOSettingsHistoryEntry' type: - array - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Task Service Create Offboarding Response + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: Sso Settings Service List History Response type: object - x-speakeasy-name-override: TaskServiceCreateOffboardingResponse - c1.api.task.v1.TaskServiceCreateResourceActionRequest: - description: The TaskServiceCreateResourceActionRequest submits a request to execute a connector resource-create action, for example creating a group from a group template. + x-speakeasy-name-override: SSOSettingsServiceListHistoryResponse + c1.api.sso.v1.SSOSettingsServiceUpdateRequest: + description: SSOSettingsServiceUpdateRequest updates the tenant's SSO provider settings. properties: - actionId: - description: The ID of the resource-create action to execute. - type: string - expandMask: + settings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSettings' - type: "null" - formValues: - additionalProperties: true + updateMask: type: - - object + - string - "null" required: - - actionId - title: Task Service Create Resource Action Request + - settings + - updateMask + title: Sso Settings Service Update Request type: object - x-speakeasy-name-override: TaskServiceCreateResourceActionRequest - c1.api.task.v1.TaskServiceCreateResourceActionResponse: - description: The TaskServiceCreateResourceActionResponse returns the created action task with optional expanded related objects. + x-speakeasy-name-override: SSOSettingsServiceUpdateRequest + c1.api.sso.v1.SSOSettingsServiceUpdateResponse: + description: SSOSettingsServiceUpdateResponse returns the updated settings. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true - type: - - array - - "null" - taskView: + settings: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - $ref: '#/components/schemas/c1.api.sso.v1.SSOSettings' - type: "null" - title: Task Service Create Resource Action Response + title: Sso Settings Service Update Response type: object - x-speakeasy-name-override: TaskServiceCreateResourceActionResponse - c1.api.task.v1.TaskServiceCreateRevokeRequest: - description: Create a revoke task. + x-speakeasy-name-override: SSOSettingsServiceUpdateResponse + c1.api.sso.v1.SSOSubjectCompatibility: + description: |- + SSOSubjectCompatibility configures preservation of subjects issued by a + previous identity provider. properties: - appEntitlementId: - description: The ID of the app entitlement to revoke access to. - type: string - appId: - description: The ID of the app associated with the entitlement. + userAttributeMappingId: + description: |- + Optional user-attribute mapping used to resolve a legacy subject on first + sign-in. The resolved value is frozen in an immutable per-user binding. + Correct the source attribute before deleting an attribute-derived binding; + otherwise the next sign-in resolves and freezes the same value again. type: string - appUserId: - description: The ID of the app user to revoke access from. This field and identityUserId cannot both be set for a given request. + title: Sso Subject Compatibility + type: object + x-speakeasy-name-override: SSOSubjectCompatibility + c1.api.sso.v1.SSOSubjectCompatibilityDeleteIssue: + description: |- + SSOSubjectCompatibilityDeleteIssue describes one compatibility binding that + could not be deleted. + properties: + reason: + description: The reason field. type: string - description: - description: The description of the request. + userId: + description: The userId field. type: string - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - - type: "null" - identityUserId: - description: The ID of the user associated with the app user we are revoking access from. This field cannot be set if appUserID is also set. - type: string - required: - - appId - - appEntitlementId - title: Task Service Create Revoke Request + title: Sso Subject Compatibility Delete Issue type: object - x-speakeasy-name-override: TaskServiceCreateRevokeRequest - c1.api.task.v1.TaskServiceCreateRevokeResponse: - description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SSOSubjectCompatibilityDeleteIssue + c1.api.sso.v1.SSOSubjectCompatibilityImportEntry: + description: SSOSubjectCompatibilityImportEntry is one client-parsed source row. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Task Service Create Revoke Response + row: + description: One-based row number in the source file, including its header. + format: int32 + type: integer + subject: + description: Exact legacy subject. C1 preserves these UTF-8 bytes without trimming. + type: string + userId: + description: ConductorOne user ID resolved by the client before this batch is sent. + type: string + title: Sso Subject Compatibility Import Entry type: object - x-speakeasy-name-override: TaskServiceCreateRevokeResponse - c1.api.task.v1.TaskServiceGetResponse: - description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SSOSubjectCompatibilityImportEntry + c1.api.sso.v1.SSOSubjectCompatibilityImportIssue: + description: |- + SSOSubjectCompatibilityImportIssue describes one CSV row that cannot be + imported. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - readOnly: true - type: - - array - - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Task Service Get Response + reason: + description: Human-readable reason this row cannot be imported. + type: string + row: + description: One-based CSV row number, including the header row. + format: int32 + type: integer + subject: + description: Legacy subject supplied by the batch entry. + type: string + userId: + description: ConductorOne user ID supplied by the batch entry. + type: string + title: Sso Subject Compatibility Import Issue type: object - x-speakeasy-name-override: TaskServiceGetResponse - c1.api.task.v1.TaskType: + x-speakeasy-name-override: SSOSubjectCompatibilityImportIssue + c1.api.stepup.v1.CreateStepUpProviderRequest: description: | - Task Type provides configuration for the type of task: certify, grant, or revoke + The CreateStepUpProviderRequest message. - This message contains a oneof named task_type. Only a single field of the following list may be set at a time: - - grant - - revoke - - certify - - offboarding - - action - - finding + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oauth2 + - microsoft properties: - action: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeAction' - - type: "null" - certify: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeCertify' - - type: "null" - finding: + clientId: + description: The OAuth2 client ID used to authenticate with the step-up provider. + type: string + clientSecret: + description: The OAuth2 client secret. Write-only; never returned in responses. + type: string + displayName: + description: The human-readable name for the new step-up provider. + type: string + issuerUrl: + description: The OIDC issuer URL for the step-up provider. + type: string + microsoft: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeFinding' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' - type: "null" - grant: + oauth2: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeGrant' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' - type: "null" - offboarding: + title: Create Step Up Provider Request + type: object + x-speakeasy-name-override: CreateStepUpProviderRequest + c1.api.stepup.v1.CreateStepUpProviderResponse: + description: The CreateStepUpProviderResponse message. + properties: + stepUpProvider: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeOffboarding' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - type: "null" - revoke: + title: Create Step Up Provider Response + type: object + x-speakeasy-name-override: CreateStepUpProviderResponse + c1.api.stepup.v1.DeleteStepUpProviderRequestInput: + description: The DeleteStepUpProviderRequest message. + title: Delete Step Up Provider Request + type: object + x-speakeasy-name-override: DeleteStepUpProviderRequest + c1.api.stepup.v1.DeleteStepUpProviderResponse: + description: The DeleteStepUpProviderResponse message. + title: Delete Step Up Provider Response + type: object + x-speakeasy-name-override: DeleteStepUpProviderResponse + c1.api.stepup.v1.GetStepUpProviderResponse: + description: The GetStepUpProviderResponse message. + properties: + stepUpProvider: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeRevoke' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - type: "null" - title: Task Type + title: Get Step Up Provider Response type: object - x-speakeasy-name-override: TaskType - c1.api.task.v1.TaskTypeAction: - description: | - The TaskTypeAction message. - - This message contains a oneof named target_object. Only a single field of the following list may be set at a time: - - scopeRole - - toolCall - - finding + x-speakeasy-name-override: GetStepUpProviderResponse + c1.api.stepup.v1.GetStepUpTransactionResponse: + description: Response message containing the requested step-up transaction properties: - actionId: - description: |- - The ID of the admin-authored action to execute. Empty for synthesized - action tickets (e.g. scope-role grants) — those carry dispatch - configuration on action_instance and target_object instead. - readOnly: true - type: string - actionInstance: + transaction: oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.ActionInstance' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' - type: "null" - createdAppEntitlementIds: - description: |- - The C1 IDs of the AppEntitlements materialized from the connector response - (for a group, typically its members and owners entitlements). Use these to - request access, attach a virtual entitlement, or otherwise manage the new - resource. Empty until outcome is SUCCESS; may be empty on SUCCESS if - materialization was skipped or failed, in which case the entitlements - appear after the next connector sync. + title: Get Step Up Transaction Response + type: object + x-speakeasy-name-override: GetStepUpTransactionResponse + c1.api.stepup.v1.ListStepUpProvidersResponse: + description: The ListStepUpProvidersResponse message. + properties: + list: + description: The list of step-up authentication providers. items: - type: string - readOnly: true + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' type: - array - "null" - createdAppResourceId: - description: |- - Populated when a resource-create action completes: the C1 ID of the - AppResource materialized from the connector response. - readOnly: true + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - createdAppResourceTypeId: - description: The resource type ID of the materialized AppResource. - readOnly: true + title: List Step Up Providers Response + type: object + x-speakeasy-name-override: ListStepUpProvidersResponse + c1.api.stepup.v1.SearchStepUpProvidersRequest: + description: Request message for searching step-up providers + properties: + pageSize: + description: Maximum number of results to return + format: int32 + type: integer + pageToken: + description: Token for pagination type: string - displayName: - description: |- - Display label captured on the action snapshot at ticket-creation time. - Stable under admin renames to a referenced Action row and populated for - synthesized tickets that have no Action row at all. UI reads this to - render the task title without an Action fetch. - readOnly: true + providerType: + description: The providerType field. + enum: + - PROVIDER_TYPE_UNSPECIFIED + - PROVIDER_TYPE_OAUTH2 + - PROVIDER_TYPE_MICROSOFT type: string - finding: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.FindingTarget' - - type: "null" - formValues: - additionalProperties: true - readOnly: true + x-speakeasy-unknown-values: allow + query: + description: Filter by name (partial match) + type: string + refs: + description: Filter to specific providers by their references. + items: + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProviderRef' type: - - object + - array - "null" - outcome: - description: The outcome field. - enum: - - ACTION_OUTCOME_UNSPECIFIED - - ACTION_OUTCOME_SUCCESS - - ACTION_OUTCOME_DENIED - - ACTION_OUTCOME_ERROR - - ACTION_OUTCOME_CANCELLED - readOnly: true + title: Search Step Up Providers Request + type: object + x-speakeasy-name-override: SearchStepUpProvidersRequest + c1.api.stepup.v1.SearchStepUpProvidersResponse: + description: Response message for searching step-up providers + properties: + list: + description: List of providers matching the search criteria + items: + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + type: + - array + - "null" + nextPageToken: + description: Token for retrieving the next page of results type: string - x-speakeasy-unknown-values: allow - outcomeTime: + title: Search Step Up Providers Response + type: object + x-speakeasy-name-override: SearchStepUpProvidersResponse + c1.api.stepup.v1.SearchStepUpTransactionsRequest: + description: Request message for searching step-up transactions + properties: + createdAfter: format: date-time - readOnly: true type: - string - "null" - scopeRole: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.ScopeRole' - - type: "null" - toolCall: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.GatedToolCallTarget' - - type: "null" - type: - description: |- - Flavor of action the ticket represents — mirrors the snapshot's - target_ref variant. + createdBefore: + format: date-time + type: + - string + - "null" + pageSize: + description: Maximum number of results to return + format: int32 + type: integer + pageToken: + description: Token for pagination + type: string + providerId: + description: Filter by provider ID + type: string + state: + description: Filter by transaction state enum: - - TYPE_UNSPECIFIED - - TYPE_GRANT - - TYPE_WORKFLOW - - TYPE_RESOURCE_ACTION - - TYPE_TOOL_CALL - - TYPE_MANUAL - readOnly: true + - STEP_UP_TRANSACTION_STATE_UNSPECIFIED + - STEP_UP_TRANSACTION_STATE_PENDING + - STEP_UP_TRANSACTION_STATE_VERIFIED + - STEP_UP_TRANSACTION_STATE_ERROR type: string x-speakeasy-unknown-values: allow - title: Task Type Action - type: object - x-speakeasy-name-override: TaskTypeAction - c1.api.task.v1.TaskTypeCertify: - description: | - The TaskTypeCertify message indicates that a task is a certify task and all related details. - - This message contains a oneof named principal. Only a single field of the following list may be set at a time: - - resource - properties: - accessReviewId: - description: The ID of the access review. - readOnly: true - type: string - accessReviewSelection: - description: The ID of the specific access review object that owns this certify task. This is also set on a revoke task if the revoke task is created from the denied outcome of a certify task. - readOnly: true + targetType: + description: The targetType field. + enum: + - TARGET_TYPE_UNSPECIFIED + - TARGET_TYPE_TICKET + - TARGET_TYPE_TEST type: string - appEntitlementId: - description: The ID of the app entitlement. - readOnly: true + x-speakeasy-unknown-values: allow + taskId: + description: Filter by task ID (only applicable if target_type is TICKET) type: string - appId: - description: The ID of the app. - readOnly: true + userId: + description: Filter by user ID type: string - appUserId: - description: The ID of the app user. - readOnly: true + title: Search Step Up Transactions Request + type: object + x-speakeasy-name-override: SearchStepUpTransactionsRequest + c1.api.stepup.v1.SearchStepUpTransactionsResponse: + description: Response message for searching step-up transactions + properties: + list: + description: List of transactions matching the search criteria + items: + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' + type: + - array + - "null" + nextPageToken: + description: Token for retrieving the next page of results type: string - identityUserId: - description: The ID of the user. - readOnly: true + title: Search Step Up Transactions Response + type: object + x-speakeasy-name-override: SearchStepUpTransactionsResponse + c1.api.stepup.v1.StepUpMicrosoftSettings: + description: StepUpMicrosoftSettings configures a Microsoft Entra step-up provider using Conditional Access. + properties: + conditionalAccessIds: + description: Authentication context IDs (C1-C99). Required for ACRS mode; ignored for OIDC mode. + items: + type: string + type: + - array + - "null" + tenant: + description: Microsoft Entra tenant ID (GUID or domain). Used for response validation. type: string - outcome: - description: The outcome of the certification. + validationMode: + description: Validation approach. See MicrosoftValidationMode for details on each mode. enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT - readOnly: true + - MICROSOFT_VALIDATION_MODE_UNSPECIFIED + - MICROSOFT_VALIDATION_MODE_ACRS + - MICROSOFT_VALIDATION_MODE_OIDC type: string x-speakeasy-unknown-values: allow - outcomeTime: - format: date-time - readOnly: true + title: Step Up Microsoft Settings + type: object + x-speakeasy-name-override: StepUpMicrosoftSettings + c1.api.stepup.v1.StepUpOAuth2Settings: + description: |- + StepUpOAuth2Settings repersents an OAuth2 provider that supports RFC 9470 + + Common ACR values for OAuth2 providers include: + - "urn:okta:loa:1fa:any" (okta) + - "urn:okta:loa:1fa:pwd" (okta) + - "urn:okta:loa:2fa:any" (okta) + - "urn:okta:loa:2fa:any:ifpossible" (okta) + - "phr" (okta) + - "phrh" (okta) + properties: + acrValues: + description: The acrValues field. + items: + type: string type: - - string + - array - "null" - resource: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' - - type: "null" - title: Task Type Certify + title: Step Up O Auth 2 Settings type: object - x-speakeasy-name-override: TaskTypeCertify - c1.api.task.v1.TaskTypeFinding: - description: The TaskTypeFinding message. + x-speakeasy-name-override: StepUpOAuth2Settings + c1.api.stepup.v1.StepUpProvider: + description: | + StepUpProvider represents a configured step-up authentication integration (e.g., Duo, custom OIDC). + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oauth2 + - microsoft properties: - findingId: - description: Reference to the source finding. - readOnly: true - type: string - findingType: - description: The finding type discriminator. - readOnly: true - type: string - outcome: - description: The outcome field. - enum: - - FINDING_TASK_OUTCOME_UNSPECIFIED - - FINDING_TASK_OUTCOME_REMEDIATED - - FINDING_TASK_OUTCOME_RISK_ACCEPTED - - FINDING_TASK_OUTCOME_CANCELLED - readOnly: true + clientId: + description: The OAuth2 client ID used to authenticate with the step-up provider. type: string - x-speakeasy-unknown-values: allow - outcomeTime: + createdAt: format: date-time readOnly: true type: - string - "null" - title: Task Type Finding - type: object - x-speakeasy-name-override: TaskTypeFinding - c1.api.task.v1.TaskTypeGrant: - description: The TaskTypeGrant message indicates that a task is a grant task and all related details. - properties: - appEntitlementId: - description: The ID of the app entitlement. - readOnly: true + displayName: + description: The human-readable name of the step-up provider. type: string - appId: - description: The ID of the app. + enabled: + description: Whether the step-up provider is active and available for use. + type: boolean + id: + description: The unique identifier of the step-up provider. readOnly: true type: string - appUserId: - description: The ID of the app user. - readOnly: true + issuerUrl: + description: The OIDC issuer URL for the step-up provider. type: string - grantDuration: - format: duration + lastTestedAt: + format: date-time readOnly: true type: - string - "null" - identityUserId: - description: The ID of the user. - readOnly: true - type: string - outcome: - description: The outcome of the grant. - enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT - readOnly: true - type: string - x-speakeasy-unknown-values: allow - outcomeTime: + microsoft: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' + - type: "null" + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' + - type: "null" + updatedAt: format: date-time readOnly: true type: - string - "null" - source: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' - - type: "null" - title: Task Type Grant + title: Step Up Provider type: object - x-speakeasy-name-override: TaskTypeGrant - c1.api.task.v1.TaskTypeOffboarding: - description: The TaskTypeOffboarding message. + x-speakeasy-name-override: StepUpProvider + c1.api.stepup.v1.StepUpProviderRef: + description: StepUpProviderRef is a lightweight reference to a step-up authentication provider. properties: - outcome: - description: The outcome field. - enum: - - OFFBOARDING_OUTCOME_UNSPECIFIED - - OFFBOARDING_OUTCOME_IN_PROGRESS - - OFFBOARDING_OUTCOME_DONE - - OFFBOARDING_OUTCOME_ERROR - - OFFBOARDING_OUTCOME_CANCELLED - readOnly: true - type: string - x-speakeasy-unknown-values: allow - outcomeTime: - format: date-time - readOnly: true - type: - - string - - "null" - subjectUserId: - description: The subjectUserId field. - readOnly: true + id: + description: The unique identifier of the step-up provider. type: string - title: Task Type Offboarding + title: Step Up Provider Ref type: object - x-speakeasy-name-override: TaskTypeOffboarding - c1.api.task.v1.TaskTypeRevoke: + x-speakeasy-name-override: StepUpProviderRef + c1.api.stepup.v1.StepUpTransaction: description: | - The TaskTypeRevoke message indicates that a task is a revoke task and all related details. + StepUpTransaction represents a record of a step-up authentication attempt - This message contains a oneof named principal. Only a single field of the following list may be set at a time: - - resource + This message contains a oneof named target. Only a single field of the following list may be set at a time: + - approveTask + - test properties: - appEntitlementId: - description: The ID of the app entitlement. + approveTask: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTask' + - type: "null" + claims: + additionalProperties: true + type: + - object + - "null" + createdAt: + format: date-time readOnly: true - type: string - appId: - description: The ID of the app. + type: + - string + - "null" + errorMessage: + description: Error message if the transaction failed readOnly: true type: string - appUserId: - description: The ID of the app user. + expiresAt: + format: date-time readOnly: true + type: + - string + - "null" + id: + description: Unique identifier for the transaction type: string - identityUserId: - description: The ID of the user. - readOnly: true + providerId: + description: ID of the provider used for this step-up authentication type: string - outcome: - description: The outcome of the revoke. + state: + description: Current state of the transaction enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT + - STEP_UP_TRANSACTION_STATE_UNSPECIFIED + - STEP_UP_TRANSACTION_STATE_PENDING + - STEP_UP_TRANSACTION_STATE_VERIFIED + - STEP_UP_TRANSACTION_STATE_ERROR readOnly: true type: string x-speakeasy-unknown-values: allow - outcomeTime: + test: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTest' + - type: "null" + updatedAt: format: date-time readOnly: true type: - string - "null" - resource: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' - - type: "null" - source: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSource' - - type: "null" - title: Task Type Revoke + userId: + description: ID of the user who performed the step-up authentication + type: string + title: Step Up Transaction type: object - x-speakeasy-name-override: TaskTypeRevoke - c1.api.task.v1.TaskView: - description: Contains a task and JSONPATH expressions that describe where in the expanded array related objects are located. This view can be used to display a fully-detailed dashboard of task information. + x-speakeasy-name-override: StepUpTransaction + c1.api.stepup.v1.StepUpTransaction.TargetTask: + description: Target for approving a task properties: - accessReviewPath: - description: JSONPATH expression indicating the location of the AccessReview object in the expanded array - readOnly: true - type: string - appPath: - description: JSONPATH expression indicating the location of the App object in the expanded array - readOnly: true - type: string - appUserLastUsagePath: - description: JSONPATH expression indicating the location of the AppUser last usage timestamp in the expanded array - readOnly: true - type: string - appUserPath: - description: JSONPATH expression indicating the location of the AppUser object in the expanded array - readOnly: true - type: string - approversPath: - description: JSONPATH expression indicating the location of the ApproverUsers objects in the expanded array. These are the users who have approved or denied this task. - readOnly: true - type: string - createdByUserPath: - description: JSONPATH expression indicating the location of the object of the User that created the ticket in the expanded array - readOnly: true - type: string - entitlementsPath: - description: JSONPATH expression indicating the location of the Entitlements objects in the expanded array - readOnly: true - type: string - identityUserPath: - description: JSONPATH expression indicating the location of the User object of the User that this task is targeting in the expanded array. This is the user that is the identity when the target of a task is an app user. - readOnly: true - type: string - insightsPath: - description: JSONPATH expression indicating the location of the Insights objects in the expanded array - readOnly: true - type: string - objectPermissions: - oneOf: - - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' - - type: "null" - principalResourcePath: - description: JSONPATH expression indicating the location of the AppResource under review for a resource-principal certify task in the expanded array. - readOnly: true - type: string - resourceBindingsPath: - description: JSONPATH expression indicating the location of the EntitlementScopeBindingList object in the expanded array. - readOnly: true - type: string - roleResourcePath: - description: JSONPATH expression indicating the location of the role AppResource for a scope-role action task in the expanded array. - readOnly: true - type: string - scopeResourcePath: - description: JSONPATH expression indicating the location of the scope AppResource for a scope-role action task in the expanded array. - readOnly: true - type: string - stepApproversPath: - description: JSONPATH expression indicating the location of the StepApproverUsers objects in the expanded array - readOnly: true + policyStepId: + description: ID of the policy step requiring step-up authentication type: string - task: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.Task' - - type: "null" - userPath: - description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. - readOnly: true + taskId: + description: ID of the task being approved type: string - title: Task View + title: Target Task type: object - x-speakeasy-name-override: TaskView - c1.api.terraform_export.v1.CompositeKeyField: - description: |- - CompositeKeyField names one sibling component of a composite-key - reference lookup. + x-speakeasy-name-override: TargetTask + c1.api.stepup.v1.StepUpTransaction.TargetTest: + description: Target for testing a provider + title: Target Test + type: object + x-speakeasy-name-override: TargetTest + c1.api.stepup.v1.TestStepUpProviderRequestInput: + description: The TestStepUpProviderRequest message. + title: Test Step Up Provider Request + type: object + x-speakeasy-name-override: TestStepUpProviderRequest + c1.api.stepup.v1.TestStepUpProviderResponse: + description: The TestStepUpProviderResponse message. properties: - c1Field: - description: |- - C1 API field name on the parent message (snake_case proto - field). The collector reads the runtime value at this path. - type: string - tfField: - description: |- - Attribute name in the Terraform data source's `refs[]` struct. - Usually identical to c1_field (the conductorone provider - matches them 1:1 today). Distinct fields anyway so a future - provider rename is wire-safe — no migration needed. + redirectUrl: + description: The URL to redirect the user to for testing the Step Up flow type: string - title: Composite Key Field + title: Test Step Up Provider Response type: object - x-speakeasy-name-override: CompositeKeyField - c1.api.terraform_export.v1.CompositeKeyFieldSet: - description: |- - CompositeKeyFieldSet groups a non-empty set of composite-key - fields as declared by one or more consumer reference sites that - target the same Terraform type. Used in `TFSchemaMapping - .referer_shapes` (the "inverted index" of composite-key shapes - targeting this kind) so a multi-root producer can register - canonical lookup keys for every shape its consumers might - compute. - - Invariant: `fields` MUST be non-empty. The bare-id (single-id) - form is implicit — every producer registers under - `canonicalRefKey(id, {})` unconditionally, and consumer sites - with empty composite_key_fields are not represented here. The - backend's inverted-index computation skips them; including an - empty `fields` would just round-trip to the bare-id form and - produce a duplicate registration. + x-speakeasy-name-override: TestStepUpProviderResponse + c1.api.stepup.v1.UpdateStepUpProviderRequestInput: + description: The UpdateStepUpProviderRequest message. properties: - fields: - description: The fields field. - items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + updateMask: type: - - array + - string - "null" - title: Composite Key Field Set + title: Update Step Up Provider Request type: object - x-speakeasy-name-override: CompositeKeyFieldSet - c1.api.terraform_export.v1.EnumValue: - description: EnumValue is one declared variant of a proto enum. + x-speakeasy-name-override: UpdateStepUpProviderRequest + c1.api.stepup.v1.UpdateStepUpProviderResponse: + description: The UpdateStepUpProviderResponse message. properties: - name: - description: |- - Full proto enum value name (e.g. "POLICY_TYPE_GRANT"). The - conductorone provider accepts this verbatim as a quoted-string HCL - literal. + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + title: Update Step Up Provider Response + type: object + x-speakeasy-name-override: UpdateStepUpProviderResponse + c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput: + description: The UpdateStepUpProviderSecretRequest message. + properties: + clientSecret: + description: The new OAuth2 client secret. Write-only; never returned in responses. type: string - number: - description: |- - Proto enum number — the value on the wire (e.g. 1 for - POLICY_TYPE_GRANT). - format: int32 - type: integer - title: Enum Value + title: Update Step Up Provider Secret Request type: object - x-speakeasy-name-override: EnumValue - c1.api.terraform_export.v1.GetSchemaResponse: - description: The GetSchemaResponse message. + x-speakeasy-name-override: UpdateStepUpProviderSecretRequest + c1.api.stepup.v1.UpdateStepUpProviderSecretResponse: + description: The UpdateStepUpProviderSecretResponse message. properties: - schema: + stepUpProvider: oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping' + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - type: "null" - title: Get Schema Response + title: Update Step Up Provider Secret Response type: object - x-speakeasy-name-override: GetSchemaResponse - c1.api.terraform_export.v1.ImportIDShape: + x-speakeasy-name-override: UpdateStepUpProviderSecretResponse + c1.api.systemlog.v1.ExportServiceCreateRequest: description: | - ImportIDShape describes the structure of the `id` value in a - Terraform `import { to = ..., id = "..." }` block. Most resources use - a single string; binding-style resources (App_Owner, - App_Entitlement_Owner, …) use a composite of multiple field values. + The ExportServiceCreateRequest message is used to create a new system log exporter. - This message contains a oneof named shape. Only a single field of the following list may be set at a time: - - singleString - - composite + This message contains a oneof named export_to. Only a single field of the following list may be set at a time: + - datasource properties: - composite: + datasource: oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.Composite' + - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' - type: "null" - singleString: + displayName: + description: The display name of the new system log exporter. + type: string + title: Export Service Create Request + type: object + x-speakeasy-name-override: ExportServiceCreateRequest + c1.api.systemlog.v1.ExportServiceCreateResponse: + description: The ExportServiceCreateResponse message. + properties: + exporter: oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.SingleString' + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - type: "null" - title: Import Id Shape + title: Export Service Create Response type: object - x-speakeasy-name-override: ImportIDShape - c1.api.terraform_export.v1.ImportIDShape.Composite: - description: |- - Composite import IDs combine values from multiple component fields - per the declared `format`. + x-speakeasy-name-override: ExportServiceCreateResponse + c1.api.systemlog.v1.ExportServiceDeleteRequestInput: + description: The ExportServiceDeleteRequest message. + title: Export Service Delete Request + type: object + x-speakeasy-name-override: ExportServiceDeleteRequest + c1.api.systemlog.v1.ExportServiceDeleteResponse: + description: The ExportServiceDeleteResponse message. + title: Export Service Delete Response + type: object + x-speakeasy-name-override: ExportServiceDeleteResponse + c1.api.systemlog.v1.ExportServiceGetResponse: + description: The ExportServiceGetResponse message contains the system log exporter object. properties: - fields: - description: |- - Component fields, in the order they participate in the import - ID. - items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.CompositeField' - type: - - array - - "null" - format: - description: |- - Wire format the provider expects. Defaults to - FORMAT_JSON_OBJECT. - enum: - - FORMAT_JSON_OBJECT - - FORMAT_COLON_SEPARATED - - FORMAT_UNDERSCORE_SEPARATED - type: string - x-speakeasy-unknown-values: allow - title: Composite + exporter: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - type: "null" + title: Export Service Get Response type: object - x-speakeasy-name-override: Composite - c1.api.terraform_export.v1.ImportIDShape.CompositeField: - description: CompositeField names one component of a composite import ID. + x-speakeasy-name-override: ExportServiceGetResponse + c1.api.systemlog.v1.ExportServiceListEventsRequestInput: + description: ExportServiceListEventsRequest is the request for listing audit events within a specific export. properties: - c1Field: - description: The C1 API field whose value supplies this component. - type: string - tfType: - description: The TF attribute type of the component value. - enum: - - TF_TYPE_UNSPECIFIED - - TF_TYPE_STRING - - TF_TYPE_NUMBER - - TF_TYPE_BOOL - - TF_TYPE_LIST - - TF_TYPE_SET - - TF_TYPE_MAP - - TF_TYPE_OBJECT - - TF_TYPE_TUPLE + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - x-speakeasy-unknown-values: allow - title: Composite Field - type: object - x-speakeasy-name-override: CompositeField - c1.api.terraform_export.v1.ImportIDShape.SingleString: - description: Single-string import IDs use the resource's id value verbatim. - title: Single String + title: Export Service List Events Request type: object - x-speakeasy-name-override: SingleString - c1.api.terraform_export.v1.TFFieldMapping: - description: |- - TFFieldMapping describes how one field of a C1 API object maps to one - attribute of a Terraform block. + x-speakeasy-name-override: ExportServiceListEventsRequest + c1.api.systemlog.v1.ExportServiceListEventsResponse: + description: ExportServiceListEventsResponse is the response containing audit events for an export. properties: - c1Field: - description: The C1 API field name (proto field name, snake_case). - type: string - computed: - description: |- - Whether the server populates this field. A field that is - `computed` and neither `optional` nor `required` is server-only — - do not emit it in user-authored HCL. - type: boolean - elementTfType: - description: |- - For collection fields (list/set/tuple/map) whose elements are - primitives (string/number/bool), the TF type of those elements. - TF_TYPE_UNSPECIFIED for non-collection fields and for collections - of objects (where `nested_fields` describes the element shape). - enum: - - TF_TYPE_UNSPECIFIED - - TF_TYPE_STRING - - TF_TYPE_NUMBER - - TF_TYPE_BOOL - - TF_TYPE_LIST - - TF_TYPE_SET - - TF_TYPE_MAP - - TF_TYPE_OBJECT - - TF_TYPE_TUPLE - type: string - x-speakeasy-unknown-values: allow - enumValues: - description: |- - Declared variants for fields whose C1-side proto type is an enum. - Empty for non-enum fields. The conductorone provider accepts the - full proto enum name as a quoted string (e.g. - `policy_type = "POLICY_TYPE_GRANT"`); emit `EnumValue.name` as the - literal value. + list: + description: List contains an array of JSON OCSF events. items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.EnumValue' + additionalProperties: true + type: object type: - array - "null" - nestedFields: - description: |- - For object-typed fields and list/set/tuple fields whose elements - are objects, the shape of the nested attributes. Empty for - primitive scalars and primitive-element collections. + nextPageToken: + description: The token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Export Service List Events Response + type: object + x-speakeasy-name-override: ExportServiceListEventsResponse + c1.api.systemlog.v1.ExportServiceListResponse: + description: The ExportServiceListResponse message. + properties: + list: + description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' + $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' type: - array - "null" - oneofField: - description: |- - When this Terraform attribute corresponds to one variant of a - proto `oneof`, `oneof_field` names the proto oneof and - `oneof_variant` names the active case. Both unset for regular - (non-oneof) fields, which is the common case. - - Example: a oneof `target` with variant `automation` on message - `Action` exposed as the TF attribute `action_target_automation`: - - oneof_field = "target" - oneof_variant = "automation" - type: string - oneofVariant: - description: The oneofVariant field. + nextPageToken: + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - optional: - description: |- - Whether the user may supply this field. May co-occur with - `computed` (i.e. either the user or the server can set the value). - type: boolean - references: + title: Export Service List Response + type: object + x-speakeasy-name-override: ExportServiceListResponse + c1.api.systemlog.v1.ExportServiceUpdateRequestInput: + description: The ExportServiceUpdateRequest message. + properties: + exporter: oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFReference' + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - type: "null" - required: - description: Whether the user must supply this field in HCL. - type: boolean - sensitive: - description: |- - Whether the value is a secret. Sensitive values must not be - rendered verbatim; emit a placeholder so callers wire the value - through a Terraform variable or vault data source. - type: boolean - tfField: - description: |- - The Terraform attribute name. Usually matches c1_field but may - differ in casing or pluralization. - type: string - tfType: - description: |- - The Terraform attribute type. For collections of structured - objects, the element shape is in `nested_fields`. For collections - of primitives, the element type is in `element_tf_type`. - enum: - - TF_TYPE_UNSPECIFIED - - TF_TYPE_STRING - - TF_TYPE_NUMBER - - TF_TYPE_BOOL - - TF_TYPE_LIST - - TF_TYPE_SET - - TF_TYPE_MAP - - TF_TYPE_OBJECT - - TF_TYPE_TUPLE - type: string - x-speakeasy-unknown-values: allow - title: Tf Field Mapping - type: object - x-speakeasy-name-override: TFFieldMapping - c1.api.terraform_export.v1.TFReference: - description: |- - TFReference describes the Terraform type(s) an ID-shaped field may - reference, plus any sibling fields needed to disambiguate a - composite-key lookup. - - `tf_type_names` covers the polymorphic / preferred-default - dimension. `composite_key_fields` covers the multi-key dimension — - some referents can't be resolved with a single id (every - `conductorone_app_entitlement` lookup needs `(app_id, id)`, - every `conductorone_app_entitlement_user_binding` needs three - keys, etc.). - properties: - compositeKeyFields: - description: |- - Sibling fields on the SAME parent message whose runtime values - must be paired with this reference's id to look the referent up - via its Terraform data source. - - Examples (each entry's c1_field is the C1 proto field name on - the parent message; tf_field is the attribute name in the data - source's `refs[]` struct): - - `AppEntitlementAutomation.app_entitlement_id` → - `[{c1_field: "app_id", tf_field: "app_id"}]` (2 keys total) - - `AppEntitlementUserBinding.app_user_id` → - `[{c1_field: "app_id", tf_field: "app_id"}, - {c1_field: "app_entitlement_id", tf_field: "app_entitlement_id"}]` - (3 keys total) - - `AppResourceOwner.user_id` → - `[{c1_field: "app_id", tf_field: "app_id"}, - {c1_field: "app_resource_type_id", tf_field: "app_resource_type_id"}, - {c1_field: "app_resource_id", tf_field: "app_resource_id"}]` - (4 keys total) - - The reference id field itself is always emitted as `id` in the - data source's ref struct (provider convention) — it is NOT - re-listed here. - - Empty/unset means single-id lookup is sufficient (User, Policy, - App today). Mirrors `ImportIDShape.Composite.fields`'s - structured shape. - items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' - type: - - array - - "null" - tfTypeNames: - description: |- - Candidate Terraform types this field may reference. The first - entry is the preferred default when no other signal disambiguates. - Empty means the field is not a reference. - items: - type: string + updateMask: type: - - array + - string - "null" - title: Tf Reference + title: Export Service Update Request type: object - x-speakeasy-name-override: TFReference - c1.api.terraform_export.v1.TFSchemaMapping: - description: | - TFSchemaMapping describes how to translate one C1 API object into a - single Terraform block. Variant-specific metadata (e.g. `import_id` for - resources) lives on the `block` oneof. - - This message contains a oneof named block. Only a single field of the following list may be set at a time: - - resource - - dataSource + x-speakeasy-name-override: ExportServiceUpdateRequest + c1.api.systemlog.v1.ExportServiceUpdateResponse: + description: The ExportServiceUpdateResponse message. properties: - dataSource: - oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.DataSource' - - type: "null" - fields: - description: |- - Per-attribute mapping. Order matches the provider schema; preserve - it when emitting for stable output. - items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' - type: - - array - - "null" - providerVersion: - description: |- - The conductorone provider version this schema was derived from - (e.g. "1.0.40"). - type: string - refererShapes: - description: |- - The set of distinct composite-key-field shapes that consumers - declare when referencing this target via a TFReference. Used by - the FE multi-root producer to enumerate canonical lookup keys for - its `addressByImportId` registration so cross-root references - collapse correctly to direct expressions regardless of which - consumer site does the lookup. - - Each entry is one distinct shape (one `CompositeKeyFieldSet` - with non-empty `fields`). The single-id (bare-id) form is - implicit and is NOT represented here — every producer registers - under `canonicalRefKey(id, {})` unconditionally as a baseline. - - Computed at schema-load time from `references_table.go` by - grouping consumer-site `composite_key_fields` declarations - by target tf_type and de-duplicating distinct shapes. Targets - with no composite-key consumers (User, Policy, App today) - ship an empty list. - items: - $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyFieldSet' - type: - - array - - "null" - resource: + exporter: oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.Resource' + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - type: "null" - tfTypeName: - description: |- - The Terraform type identifier — the string immediately after the - `resource` or `data` keyword in HCL (e.g. "conductorone_app"). - type: string - title: Tf Schema Mapping - type: object - x-speakeasy-name-override: TFSchemaMapping - c1.api.terraform_export.v1.TFSchemaMapping.DataSource: - description: |- - Data-source-specific schema metadata. Reserved for future use; empty - in v1. - title: Data Source + title: Export Service Update Response type: object - x-speakeasy-name-override: DataSource - c1.api.terraform_export.v1.TFSchemaMapping.Resource: - description: Resource-specific schema metadata. + x-speakeasy-name-override: ExportServiceUpdateResponse + c1.api.systemlog.v1.ExportToDatasource: + description: The ExportToDatasource message. properties: - importId: - oneOf: - - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape' - - type: "null" - title: Resource + datasourceId: + description: The datasourceId field. + type: string + format: + description: The format field. + enum: + - EXPORT_FORMAT_UNSPECIFIED + - EXPORT_FORMAT_OCSF_JSON_ZSTD + - EXPORT_FORMAT_OCSF_JSON_GZIP + type: string + x-speakeasy-unknown-values: allow + prefix: + description: The prefix field. + type: string + title: Export To Datasource type: object - x-speakeasy-name-override: Resource - c1.api.user.v1.ExpiringUserDelegationBinding: - description: The ExpiringUserDelegationBinding message. + x-speakeasy-name-override: ExportToDatasource + c1.api.systemlog.v1.Exporter: + description: | + The Exporter message. + + This message contains a oneof named export_to. Only a single field of the following list may be set at a time: + - datasource properties: createdAt: format: date-time + readOnly: true type: - string - "null" - delegatedUserId: - description: The delegatedUserId field. - type: string + datasource: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' + - type: "null" deletedAt: format: date-time + readOnly: true type: - string - "null" - expirationAt: - format: date-time - type: - - string - - "null" - startAt: - format: date-time - type: - - string - - "null" + displayName: + description: The displayName field. + type: string + exportId: + description: The exportId field. + readOnly: true + type: string + state: + description: The state field. + enum: + - EXPORT_STATE_UNSPECIFIED + - EXPORT_STATE_EXPORTING + - EXPORT_STATE_WAITING + - EXPORT_STATE_ERROR + readOnly: true + type: string + x-speakeasy-unknown-values: allow updatedAt: format: date-time + readOnly: true type: - string - "null" - userId: - description: The userId field. + watermarkEventId: + description: we've synchorized this far + readOnly: true type: string - title: Expiring User Delegation Binding - type: object - x-speakeasy-name-override: ExpiringUserDelegationBinding - c1.api.user.v1.GetUserProfileTypesResponse: - description: GetUserProfileTypesResponse is the response containing the profile types for a user. - properties: - profileTypes: - description: The list of profile types associated with the user across their connected apps. - items: - $ref: '#/components/schemas/c1.api.profiletype.v1.ProfileType' - type: - - array - - "null" - title: Get User Profile Types Response - type: object - x-speakeasy-name-override: GetUserProfileTypesResponse - c1.api.user.v1.IntrospectRequest: - description: The IntrospectRequest message. - properties: - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' - - type: "null" - title: Introspect Request + title: Exporter type: object - x-speakeasy-name-override: UserIntrospectRequest - c1.api.user.v1.IntrospectResponse: - description: The IntrospectResponse message. + x-speakeasy-name-override: Exporter + c1.api.systemlog.v1.ExporterRef: + description: The ExporterRef message. properties: - expanded: - description: The expanded field. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - userView: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserView' - - type: "null" - title: Introspect Response + exportId: + description: The exportId field. + type: string + title: Exporter Ref type: object - x-speakeasy-name-override: UserIntrospectResponse - c1.api.user.v1.SearchUsersRequest: - description: Search for users based on some filters. + x-speakeasy-name-override: ExporterRef + c1.api.systemlog.v1.ExportsSearchServiceSearchRequest: + description: ExportsSearchServiceSearchRequest is the request for searching system log exports. properties: - delegateStatus: - description: Filter for users based on their delegate status. - enum: - - DELEGATE_STATUS_UNSPECIFIED - - DELEGATE_STATUS_HAS_DELEGATE - - DELEGATE_STATUS_NO_DELEGATE - type: string - x-speakeasy-unknown-values: allow - delegatedUserIds: - description: Filter for users that have any of the delegated user IDs on this list. - items: - type: string - type: - - array - - "null" - departments: - description: Search for users that have any of the departments on this list. - items: - type: string - type: - - array - - "null" - email: - description: Search for users based on their email (exact match). + displayName: + description: Search for system log exporters with a case insensitive match on the display name. type: string - excludeIds: - description: An array of users IDs to exclude from the results. - items: - type: string - type: - - array - - "null" - excludeOrigins: - description: Filter to exclude users with these origins. - items: - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" - excludeTypes: - description: An array of types to exclude from the results. - items: - enum: - - USER_TYPE_UNSPECIFIED - - USER_TYPE_SYSTEM - - USER_TYPE_HUMAN - - USER_TYPE_SERVICE - - USER_TYPE_AGENT - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" - expandMask: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' - - type: "null" - ids: - description: Deprecated. Use refs array instead. - items: - type: string - type: - - array - - "null" - isDelegate: - description: Filter for users who are delegates of at least one other user. - type: boolean - jobTitles: - description: Search for users that have any of the job titles on this list. - items: - type: string - type: - - array - - "null" - managerIds: - description: Search for users that have any of the manager IDs on this list. - items: - type: string - type: - - array - - "null" - origins: - description: Filter to include only users with these origins. - items: - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM - type: string - x-speakeasy-unknown-values: allow - type: - - array - - "null" pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: The pageSize field. format: int32 type: integer pageToken: description: The pageToken field. type: string query: - description: Query the apps with a fuzzy search on display name and emails. + description: The query field. type: string refs: - description: An array of user refs to restrict the return values to by ID. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - type: - - array - - "null" - roleIds: - description: Search for users that have any of the role IDs on this list. - items: - type: string - type: - - array - - "null" - userStatuses: - description: Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED + description: The refs field. items: - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED - type: string - x-speakeasy-unknown-values: allow + $ref: '#/components/schemas/c1.api.systemlog.v1.ExporterRef' type: - array - "null" - title: Search Users Request + title: Exports Search Service Search Request type: object - x-speakeasy-name-override: SearchUsersRequest - c1.api.user.v1.SearchUsersResponse: - description: The SearchUsersResponse message. + x-speakeasy-name-override: ExportsSearchServiceSearchRequest + c1.api.systemlog.v1.ExportsSearchServiceSearchResponse: + description: ExportsSearchServiceSearchResponse is the response for searching system log exports. properties: - expanded: - description: List of related objects - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" list: - description: The list of results containing up to X results, where X is the page size defined in the request + description: The list of system log exports matching the search criteria. items: - $ref: '#/components/schemas/c1.api.user.v1.UserView' + $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' type: - array - "null" nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + description: The token to retrieve the next page of results, or empty if there are no more results. type: string - title: Search Users Response + title: Exports Search Service Search Response type: object - x-speakeasy-name-override: SearchUsersResponse - c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput: - description: SetExpiringUserDelegationBindingByAdminRequest is the request for an admin to set a temporary delegation binding for a user. + x-speakeasy-name-override: ExportsSearchServiceSearchResponse + c1.api.systemlog.v1.SystemLogServiceListEventsRequest: + description: The SystemLogServiceListEventsRequest message. properties: - delegatedUserId: - description: The ID of the user who will act as delegate. Empty string removes the delegation. + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - delegationExpireAt: + since: format: date-time type: - string - "null" - delegationStartAt: + sinceEventUid: + description: The sinceEventUid field. + type: string + sortDirection: + description: The sortDirection field. + enum: + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC + type: string + x-speakeasy-unknown-values: allow + until: format: date-time type: - string - "null" - title: Set Expiring User Delegation Binding By Admin Request - type: object - x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminRequest - c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse: - description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. - properties: - item: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.ExpiringUserDelegationBinding' - - type: "null" - title: Set Expiring User Delegation Binding By Admin Response + untilEventUid: + description: The untilEventUid field. + type: string + title: System Log Service List Events Request type: object - x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminResponse - c1.api.user.v1.User: - description: The User object provides all of the details for an user, as well as some configuration. + x-speakeasy-name-override: SystemLogServiceListEventsRequest + c1.api.systemlog.v1.SystemLogServiceListEventsResponse: + description: The SystemLogServiceListEventsResponse message. properties: - createdAt: - format: date-time - readOnly: true + list: + description: List contains an array of JSON OCSF events. + items: + additionalProperties: true + type: object type: - - string + - array - "null" - delegatedUserId: - description: The id of the user to whom tasks will be automatically reassigned to. + nextPageToken: + description: The nextPageToken field. type: string - deletedAt: - format: date-time + title: System Log Service List Events Response + type: object + x-speakeasy-name-override: SystemLogServiceListEventsResponse + c1.api.task.v1.ActionInstance: + description: | + ActionInstance is the API mirror of the internal immutable snapshot of an + Action captured on a TaskTypeAction at ticket-creation time. + + This message contains a oneof named target_ref. Only a single field of the following list may be set at a time: + - batonResourceActionRef + - connectorActionRef + properties: + batonResourceActionRef: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.BatonResourceActionRef' + - type: "null" + connectorActionRef: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ConnectorActionRef' + - type: "null" + displayName: + description: |- + Display label at ticket-creation time. Same value as + TaskTypeAction.display_name; repeated here so clients that walk the + instance see a self-contained view. readOnly: true - type: - - string - - "null" - department: - description: The department which the user belongs to in the organization. + type: string + title: Action Instance + type: object + x-speakeasy-name-override: TaskActionInstance + c1.api.task.v1.BatonResourceActionRef: + description: |- + BatonResourceActionRef describes dispatch to a connector resource-create + action (for example, a group template that creates a group in the connected + application). + properties: + appId: + description: The app the resource is created in. readOnly: true type: string - departmentSources: - description: A list of objects mapped based on department attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + batonActionDisplayName: + description: The connector-defined display name of the resource-create action. readOnly: true - type: - - array - - "null" - directoryIds: - description: A list of unique ids that represent different directories. - items: - type: string + type: string + batonActionName: + description: The connector-defined name of the resource-create action. readOnly: true - type: - - array - - "null" - directoryStatus: - description: The status of the user in the directory. - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED + type: string + connectorId: + description: The connector that executes the resource-create action. readOnly: true type: string - x-speakeasy-unknown-values: allow - directoryStatusSources: - description: A list of objects mapped based on directoryStatus attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + resourceTypeId: + description: The type of resource the action creates (for example, "group"). readOnly: true - type: - - array - - "null" - displayName: - description: The display name of the user. + type: string + title: Baton Resource Action Ref + type: object + x-speakeasy-name-override: BatonResourceActionRef + c1.api.task.v1.ConnectorActionRef: + description: |- + ConnectorActionRef describes dispatch through a connector's built-in + GrantManagerService Grant / Revoke RPC — i.e. the default connector + operation, used for synthesized tickets like scope-role requests. + properties: + appId: + description: The app whose connector handles the operation. readOnly: true type: string - email: - description: This is the user's email. + connectorId: + description: The connector that will execute the Grant / Revoke. readOnly: true type: string - emailSources: - description: A list of source data for the email attribute. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + operation: + description: Which connector RPC this dispatches to. + enum: + - OPERATION_UNSPECIFIED + - OPERATION_GRANT readOnly: true - type: - - array - - "null" - emails: - description: This is a list of all of the user's emails from app users. - items: - type: string + type: string + x-speakeasy-unknown-values: allow + title: Connector Action Ref + type: object + x-speakeasy-name-override: ConnectorActionRef + c1.api.task.v1.ExternalRef: + description: A reference to an external source. This value is unused currently, but may be brought back. + properties: + externalRefSource: + description: The source of the external reference. + enum: + - UNSPECIFIED + - JIRA readOnly: true - type: - - array - - "null" - employeeIdSources: - description: A list of source data for the employee IDs attribute. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + type: string + x-speakeasy-unknown-values: allow + name: + description: The name of the external reference. readOnly: true - type: - - array - - "null" - employeeIds: - description: This is a list of all of the user's employee IDs from app users. - items: - type: string + type: string + url: + description: The URL to the external reference. readOnly: true - type: - - array - - "null" - employmentStatus: - description: The users employment status. + type: string + title: External Ref + type: object + x-speakeasy-name-override: ExternalRef + c1.api.task.v1.FindingTarget: + description: The finding an inert TYPE_MANUAL action ticket remediates. + properties: + findingId: + description: Reference to the source finding. readOnly: true type: string - employmentStatusSources: - description: A list of objects mapped based on employmentStatus attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + findingType: + description: The finding type discriminator. readOnly: true - type: - - array - - "null" - employmentType: - description: The employment type of the user. + type: string + title: Finding Target + type: object + x-speakeasy-name-override: FindingTarget + c1.api.task.v1.GatedToolCallTarget: + description: The GatedToolCallTarget message. + properties: + appEntitlementId: + description: The appEntitlementId field. readOnly: true type: string - employmentTypeSources: - description: A list of objects mapped based on employmentType attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + appId: + description: The appId field. readOnly: true - type: - - array - - "null" - id: - description: A unique identifier of the user. + type: string + callerKind: + description: The callerKind field. readOnly: true type: string - jobTitle: - description: The job title of the user. + connectorId: + description: The connectorId field. readOnly: true type: string - jobTitleSources: - description: A list of objects mapped based on jobTitle attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + gateId: + description: The gateId field. readOnly: true - type: - - array - - "null" - managerIds: - description: A list of ids of the user's managers. - items: - type: string + type: string + inputSizeBytes: + description: The inputSizeBytes field. + format: int32 readOnly: true - type: - - array - - "null" - managerSources: - description: A list of objects mapped based on managerId attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + type: integer + toolError: + description: The toolError field. readOnly: true - type: - - array - - "null" - origin: - description: The origin of the user, describing who owns the user's lifecycle. - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM + type: string + toolId: + description: The toolId field. readOnly: true type: string - x-speakeasy-unknown-values: allow - profile: + toolInput: additionalProperties: true readOnly: true type: - object - "null" - roleIds: - description: A list of unique identifiers that maps to ConductorOne's user roles let you assign users permissions tailored to the work they do in the software. - items: - type: string - type: - - array - - "null" - status: - description: The status of the user in the system. - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED + toolKind: + description: The toolKind field. + readOnly: true type: string - x-speakeasy-unknown-values: allow - type: - description: The type of the user. - enum: - - USER_TYPE_UNSPECIFIED - - USER_TYPE_SYSTEM - - USER_TYPE_HUMAN - - USER_TYPE_SERVICE - - USER_TYPE_AGENT + toolName: + description: The toolName field. readOnly: true type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time + toolOutput: readOnly: true type: - string + - number + - object + - array + - boolean - "null" - username: - description: This is the user's primary username. Typically sourced from the primary directory. + title: Gated Tool Call Target + type: object + x-speakeasy-name-override: GatedToolCallTarget + c1.api.task.v1.ScopeRole: + description: |- + Scope-role variant of TaskTypeAction.target_object. The UI uses the + embedded identifiers to build links and title strings without a separate + Action fetch. + properties: + appId: + description: The IaaS/sparse-ACL app the (scope, role) pair lives on. readOnly: true type: string - usernameSources: - description: A list of source data for the usernames attribute. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + grantDuration: + format: duration readOnly: true type: - - array + - string - "null" - usernames: - description: This is a list of all of the user's usernames from app users. - items: - type: string + roleResourceId: + description: The roleResourceId field. readOnly: true - type: - - array - - "null" - title: User - type: object - x-speakeasy-name-override: User - c1.api.user.v1.UserAttributeMappingSource: - description: The UserAttributeMappingSource message. - properties: - appId: - description: The appId field. - type: string - appUserId: - description: The appUserId field. type: string - appUserProfileAttributeKey: - description: The appUserProfileAttributeKey field. + roleResourceTypeId: + description: The roleResourceTypeId field. + readOnly: true type: string - priority: - description: Lower number = higher precedence; sources[0] is the winning source. - format: uint32 + scopeResourceId: + description: The scopeResourceId field. readOnly: true - type: integer - userAttributeMappingId: - description: The userAttributeMappingId field. type: string - value: - description: The value field. + scopeResourceTypeId: + description: The scopeResourceTypeId field. + readOnly: true type: string - title: User Attribute Mapping Source + title: Scope Role type: object - x-speakeasy-name-override: UserAttributeMappingSource - c1.api.user.v1.UserExpandMask: - description: |- - The user expand mask is used to indicate which related objects should be expanded in the response. - The supported paths are 'role_ids', 'manager_ids', 'delegated_user_id', 'directory_ids', and '*'. + x-speakeasy-name-override: ScopeRole + c1.api.task.v1.Task: + description: A fully-fleged task object. Includes its policy, references to external apps, its type, its processing history, and more. properties: - paths: - description: An array of paths to be expanded in the response. + actions: + description: The actions that can be performed on the task by the current user. items: + enum: + - TASK_ACTION_TYPE_UNSPECIFIED + - TASK_ACTION_TYPE_CLOSE + - TASK_ACTION_TYPE_APPROVE + - TASK_ACTION_TYPE_DENY + - TASK_ACTION_TYPE_COMMENT + - TASK_ACTION_TYPE_DELETE + - TASK_ACTION_TYPE_REASSIGN + - TASK_ACTION_TYPE_RESTART + - TASK_ACTION_TYPE_SEND_REMINDER + - TASK_ACTION_TYPE_PROVISION_COMPLETE + - TASK_ACTION_TYPE_PROVISION_CANCELLED + - TASK_ACTION_TYPE_PROVISION_ERRORED + - TASK_ACTION_TYPE_ROLLBACK_SKIPPED + - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED + - TASK_ACTION_TYPE_HARD_RESET + - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS + - TASK_ACTION_TYPE_CHANGE_POLICY + - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS + - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION + - TASK_ACTION_TYPE_SET_ANALYSIS_ID + - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST + - TASK_ACTION_TYPE_PROCESS_NOW + - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP + - TASK_ACTION_TYPE_SKIP_STEP + - TASK_ACTION_TYPE_ROLLBACK_CANCELLED + - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA + - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION + - TASK_ACTION_TYPE_RETRY_PROVISIONING type: string + x-speakeasy-unknown-values: allow + readOnly: true type: - array - "null" - title: User Expand Mask - type: object - x-speakeasy-name-override: UserExpandMask - c1.api.user.v1.UserRef: - description: A reference to a user. - properties: - id: - description: The id of the user. + analysisId: + description: The ID of the analysis object associated with this task created by an analysis workflow if the analysis feature is enabled for your tenant. + readOnly: true type: string - title: User Ref - type: object - x-speakeasy-name-override: UserRef - c1.api.user.v1.UserServiceGetResponse: - description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. - properties: - expanded: - description: List of serialized related objects. + annotations: + description: An array of `google.protobuf.Any` annotations with various base64-encoded data. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -37937,4248 +39106,11048 @@ components: '@type': description: The type of the serialized message. type: string + readOnly: true type: object + readOnly: true type: - array - "null" - userView: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserView' - - type: "null" - title: User Service Get Response - type: object - x-speakeasy-name-override: UserServiceGetResponse - c1.api.user.v1.UserServiceListResponse: - description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. - properties: - expanded: - description: List of serialized related objects. + approverIds: + description: An array of IDs belonging to Identity Users that have approved or denied any step in this task. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + type: string + readOnly: true type: - array - "null" - list: - description: The list of results containing up to X results, where X is the page size defined in the request - items: - $ref: '#/components/schemas/c1.api.user.v1.UserView' + commentCount: + description: The count of comments. + format: int32 + readOnly: true + type: integer + createdAt: + format: date-time + readOnly: true type: - - array + - string - "null" - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - type: string - title: User Service List Response - type: object - x-speakeasy-name-override: UserServiceListResponse - c1.api.user.v1.UserView: - description: The UserView object provides a user response object, as well as JSONPATHs to related objects provided by expanders. - properties: - delegatedUserPath: - description: JSONPATH expression indicating the location of the user objects of delegates of the current user in the expanded array. + createdByUserId: + description: The ID of the user that is the creator of this task. This may not always match the userId field. readOnly: true type: string - directoriesPath: - description: JSONPATH expression indicating the location of directory objects in the expanded array. + data: + additionalProperties: true readOnly: true - type: string - managersPath: - description: JSONPATH expression indicating the location of the user objects that managed the current user in the expanded array. + type: + - object + - "null" + deletedAt: + format: date-time readOnly: true - type: string - objectPermissions: - oneOf: - - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' - - type: "null" - rolesPath: - description: JSONPATH expression indicating the location of the roles of the current user in the expanded array. + type: + - string + - "null" + description: + description: The description of the task. This is also known as justification. readOnly: true type: string - user: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' - - type: "null" - userId: - description: The id of the user. + displayName: + description: The display name of the task. readOnly: true type: string - title: User View - type: object - x-speakeasy-name-override: UserView - c1.api.user.v2.CreateUserEntitlementOwnerRequestInput: - description: CreateUserEntitlementOwnerRequest is the request for creating an entitlement ownership source on a user (service account). - properties: - appEntitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - title: Create User Entitlement Owner Request - type: object - x-speakeasy-name-override: CreateUserEntitlementOwnerRequest - c1.api.user.v2.CreateUserEntitlementOwnerResponse: - description: CreateUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on a user (service account). - properties: - userOwnerEntitlement: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' - - type: "null" - title: Create User Entitlement Owner Response - type: object - x-speakeasy-name-override: CreateUserEntitlementOwnerResponse - c1.api.user.v2.CreateUserUserOwnerRequestInput: - description: CreateUserUserOwnerRequest is the request for creating a user ownership source on a user (service account). - properties: - userRef: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - - type: "null" - title: Create User User Owner Request - type: object - x-speakeasy-name-override: CreateUserUserOwnerRequest - c1.api.user.v2.CreateUserUserOwnerResponse: - description: CreateUserUserOwnerResponse is the response for creating a user ownership source on a user (service account). - properties: - userOwnerUser: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' - - type: "null" - title: Create User User Owner Response - type: object - x-speakeasy-name-override: CreateUserUserOwnerResponse - c1.api.user.v2.DeleteUserEntitlementOwnerRequestInput: - description: DeleteUserEntitlementOwnerRequest is the request for deleting an entitlement ownership source on a user (service account). - properties: - appEntitlementRef: - oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - - type: "null" - title: Delete User Entitlement Owner Request - type: object - x-speakeasy-name-override: DeleteUserEntitlementOwnerRequest - c1.api.user.v2.DeleteUserEntitlementOwnerResponse: - description: DeleteUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a user (service account). - title: Delete User Entitlement Owner Response - type: object - x-speakeasy-name-override: DeleteUserEntitlementOwnerResponse - c1.api.user.v2.DeleteUserUserOwnerRequestInput: - description: DeleteUserUserOwnerRequest is the request for deleting a user ownership source on a user (service account). - properties: - userRef: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - - type: "null" - title: Delete User User Owner Request - type: object - x-speakeasy-name-override: DeleteUserUserOwnerRequest - c1.api.user.v2.DeleteUserUserOwnerResponse: - description: DeleteUserUserOwnerResponse is the empty response for deleting a user ownership source on a user (service account). - title: Delete User User Owner Response - type: object - x-speakeasy-name-override: DeleteUserUserOwnerResponse - c1.api.user.v2.SearchUserEntitlementOwnersResponse: - description: SearchUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on a user (service account). - properties: - list: - description: The list field. + emergencyAccess: + description: A field indicating whether this task was created using an emergency access flow, or escalated to emergency access. On task creation, it will also use the app entitlement's emergency policy when possible. + readOnly: true + type: boolean + externalRefs: + description: An array of external references to the task. Historically that has been items like Jira task IDs. This is currently unused, but may come back in the future for integrations. items: - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' + $ref: '#/components/schemas/c1.api.task.v1.ExternalRef' + readOnly: true type: - array - "null" - nextPageToken: - description: The nextPageToken field. + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + id: + description: The ID of the task. + readOnly: true type: string - title: Search User Entitlement Owners Response - type: object - x-speakeasy-name-override: SearchUserEntitlementOwnersResponse - c1.api.user.v2.SearchUserOwnersResponse: - description: SearchUserOwnersResponse is the response for searching user ownership sources on a user (service account). - properties: - list: - description: The list field. + insightIds: + description: The insightIds field. items: - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' + type: string type: - array - "null" - nextPageToken: - description: The nextPageToken field. + numericId: + description: A human-usable numeric ID of a task which can be included in place of the fully qualified task id in path parmeters (but not search queries). + format: int64 + readOnly: true type: string - title: Search User Owners Response - type: object - x-speakeasy-name-override: SearchUserOwnersResponse - c1.api.user.v2.SetUserOwnersV2RequestInput: - description: SetUserOwnersV2Request is the request for setting the owners of a user (service account) for a given role. - properties: - appEntitlementRefs: - description: The appEntitlementRefs field. + origin: + description: The origin field. + enum: + - TASK_ORIGIN_UNSPECIFIED + - TASK_ORIGIN_PROFILE_MEMBERSHIP_AUTOMATION + - TASK_ORIGIN_SLACK + - TASK_ORIGIN_API + - TASK_ORIGIN_JIRA + - TASK_ORIGIN_COPILOT + - TASK_ORIGIN_WEBAPP + - TASK_ORIGIN_TIME_REVOKE + - TASK_ORIGIN_NON_USAGE_REVOKE + - TASK_ORIGIN_PROFILE_MEMBERSHIP_MANUAL + - TASK_ORIGIN_PROFILE_MEMBERSHIP + - TASK_ORIGIN_AUTOMATION + - TASK_ORIGIN_ACCESS_REVIEW + - TASK_ORIGIN_CASCADE_DELETE + type: string + x-speakeasy-unknown-values: allow + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyInstance' + - type: "null" + policyGenerationId: + description: The policy generation id refers to the current policy's generation ID. This is changed when the policy is changed on a task. + readOnly: true + type: string + processing: + description: The processing state of a task as defined by the `processing_enum` + enum: + - TASK_PROCESSING_TYPE_UNSPECIFIED + - TASK_PROCESSING_TYPE_PROCESSING + - TASK_PROCESSING_TYPE_WAITING + - TASK_PROCESSING_TYPE_DONE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + recommendation: + description: The recommendation field. + enum: + - INSIGHT_RECOMMENDATION_UNSPECIFIED + - INSIGHT_RECOMMENDATION_APPROVE + - INSIGHT_RECOMMENDATION_DENY + - INSIGHT_RECOMMENDATION_REVIEW + type: string + x-speakeasy-unknown-values: allow + revocationTargets: + description: |- + Ancestor entitlements that will also be revoked when this revoke task is approved. + Populated at ticket creation time for inherited grant revocations. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + $ref: '#/components/schemas/c1.api.task.v1.TaskRevocationTarget' + readOnly: true type: - array - "null" - roleSlug: - description: The roleSlug field. + state: + description: The current state of the task as defined by the `state_enum` + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED + readOnly: true type: string - userRefs: - description: The userRefs field. + x-speakeasy-unknown-values: allow + stepApproverIds: + description: An array of IDs belonging to Identity Users that are allowed to review this step in a task. items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: string + readOnly: true type: - array - "null" - title: Set User Owners V 2 Request - type: object - x-speakeasy-name-override: SetUserOwnersV2Request - c1.api.user.v2.SetUserOwnersV2Response: - description: SetUserOwnersV2Response is the empty response for setting user owners. - title: Set User Owners V 2 Response - type: object - x-speakeasy-name-override: SetUserOwnersV2Response - c1.api.user.v2.UserOwnerEntitlement: - description: UserOwnerEntitlement represents an entitlement ownership source for a canonical User (a service account). - properties: - appEntitlement: + type: oneOf: - - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - $ref: '#/components/schemas/c1.api.task.v1.TaskType' - type: "null" - createdAt: + updatedAt: format: date-time + readOnly: true type: - string - "null" - roleSlug: - description: The roleSlug field. - type: string userId: - description: The userId field. + description: The ID of the user that is the target of this task. This may be empty if we're targeting a specific app user that has no known identity user. + readOnly: true type: string - title: User Owner Entitlement + title: Task type: object - x-speakeasy-name-override: UserOwnerEntitlement - c1.api.user.v2.UserOwnerUser: - description: UserOwnerUser represents a user ownership source for a canonical User (a service account). + x-speakeasy-name-override: Task + c1.api.task.v1.TaskAction: + description: Represents a single action that was performed on a task. properties: - createdAt: - format: date-time - type: - - string - - "null" - roleSlug: - description: The roleSlug field. + actionType: + description: The type of action that was performed. + enum: + - TASK_ACTION_TYPE_UNSPECIFIED + - TASK_ACTION_TYPE_CLOSE + - TASK_ACTION_TYPE_APPROVE + - TASK_ACTION_TYPE_DENY + - TASK_ACTION_TYPE_COMMENT + - TASK_ACTION_TYPE_DELETE + - TASK_ACTION_TYPE_REASSIGN + - TASK_ACTION_TYPE_RESTART + - TASK_ACTION_TYPE_SEND_REMINDER + - TASK_ACTION_TYPE_PROVISION_COMPLETE + - TASK_ACTION_TYPE_PROVISION_CANCELLED + - TASK_ACTION_TYPE_PROVISION_ERRORED + - TASK_ACTION_TYPE_ROLLBACK_SKIPPED + - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED + - TASK_ACTION_TYPE_HARD_RESET + - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS + - TASK_ACTION_TYPE_CHANGE_POLICY + - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS + - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION + - TASK_ACTION_TYPE_SET_ANALYSIS_ID + - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST + - TASK_ACTION_TYPE_PROCESS_NOW + - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP + - TASK_ACTION_TYPE_SKIP_STEP + - TASK_ACTION_TYPE_ROLLBACK_CANCELLED + - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA + - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION + - TASK_ACTION_TYPE_RETRY_PROVISIONING type: string - user: - oneOf: - - $ref: '#/components/schemas/c1.api.user.v1.User' - - type: "null" - userId: - description: The userId field. + x-speakeasy-unknown-values: allow + bulkActionId: + description: The ID of the bulk action this action belongs to, if it was part of a bulk operation. type: string - title: User Owner User - type: object - x-speakeasy-name-override: UserOwnerUser - c1.api.vault.v1.GroupAuthzVault: - description: GroupAuthzVault configures a vault that uses group-based authorization to control access to stored credentials. - title: Group Authz Vault - type: object - x-speakeasy-name-override: GroupAuthzVault - c1.api.vault.v1.MagicVault: - description: MagicVault configures a vault that grants time-limited credential access via magic links. - properties: - allowUnauthedViews: - description: Controls whether unauthenticated users can view credentials via a magic link. - type: boolean - allowedViews: - description: The maximum number of times a credential in this vault may be viewed. - format: uint32 - type: integer - title: Magic Vault - type: object - x-speakeasy-name-override: MagicVault - c1.api.vault.v1.Vault: - description: | - Vault represents an external secret storage integration used to store connector credentials securely. - - This message contains a oneof named vault. Only a single field of the following list may be set at a time: - - groupAuthzVault - - magicVault - properties: createdAt: format: date-time readOnly: true type: - string - "null" - credentialExpirationDuration: - format: duration - type: - - string - - "null" deletedAt: format: date-time readOnly: true type: - string - "null" - description: - description: A free-text description of the vault's purpose or configuration. - type: string - displayName: - description: The human-readable name of the vault. - type: string - groupAuthzVault: - oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' - - type: "null" id: - description: The unique identifier of the vault. + description: The unique ID of this action. + type: string + policyStepId: + description: The ID of the policy step this action was performed on. type: string - magicVault: - oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' - - type: "null" updatedAt: format: date-time readOnly: true type: - string - "null" - title: Vault + userId: + description: The ID of the user who performed the action. + type: string + title: Task Action type: object - x-speakeasy-entity: Vault - x-speakeasy-name-override: Vault - c1.api.vault.v1.VaultServiceCreateRequest: - description: | - VaultServiceCreateRequest is the request message for creating a new vault. - - This message contains a oneof named vault. Only a single field of the following list may be set at a time: - - groupAuthzVault - - magicVault + x-speakeasy-name-override: SubmittedTaskAction + c1.api.task.v1.TaskActionsServiceApproveRequestInput: + description: The TaskActionsServiceApproveRequest object lets you approve a task. properties: - description: - description: A free-text description of the vault's purpose or configuration. - type: string - displayName: - description: The human-readable name for the new vault. + comment: + description: The comment attached to the request. type: string - groupAuthzVault: - oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' - - type: "null" - magicVault: + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - ownerIds: - description: The IDs of users to assign as owners of this vault. + policyStepId: + description: The ID of the policy step on the given task to approve. + type: string + required: + - policyStepId + title: Task Actions Service Approve Request + type: object + x-speakeasy-name-override: TaskActionsServiceApproveRequest + c1.api.task.v1.TaskActionsServiceApproveResponse: + description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. + properties: + expanded: + description: List of serialized related objects. items: - type: string + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true type: - array - "null" - required: - - displayName - title: Vault Service Create Request - type: object - x-speakeasy-name-override: VaultServiceCreateRequest - c1.api.vault.v1.VaultServiceCreateResponse: - description: VaultServiceCreateResponse is the response message for creating a new vault. - properties: - vault: + taskView: oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - type: "null" - title: Vault Service Create Response - type: object - x-speakeasy-name-override: VaultServiceCreateResponse - c1.api.vault.v1.VaultServiceDeleteRequestInput: - description: VaultServiceDeleteRequest is the request message for deleting a vault. - title: Vault Service Delete Request - type: object - x-speakeasy-name-override: VaultServiceDeleteRequest - c1.api.vault.v1.VaultServiceDeleteResponse: - description: Empty response body. Status code indicates success. - title: Vault Service Delete Response + ticketActionId: + description: The ID of the task approve action created by this request. + readOnly: true + type: string + title: Task Actions Service Approve Response type: object - x-speakeasy-name-override: VaultServiceDeleteResponse - c1.api.vault.v1.VaultServiceGetResponse: - description: VaultServiceGetResponse is the response message containing the requested vault. + x-speakeasy-name-override: TaskActionsServiceApproveResponse + c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput: + description: TaskActionsServiceApproveWithStepUpRequest is used to approve a task with step-up authentication properties: - vault: + comment: + description: The comment attached to the request. + type: string + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Vault Service Get Response + policyStepId: + description: The ID of the policy step on the given task to approve. + type: string + stepUpTransactionId: + description: |- + The step-up transaction ID that was verified. + If unset, the response will include a redirect URL to + complete the step-up authentication. + type: string + required: + - policyStepId + - stepUpTransactionId + title: Task Actions Service Approve With Step Up Request type: object - x-speakeasy-name-override: VaultServiceGetResponse - c1.api.vault.v1.VaultServiceUpdateRequestInput: - description: The VaultServiceUpdateRequest message contains the vault object to update and a field mask to indicate which fields to update. + x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpRequest + c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse: + description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication properties: - updateMask: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true type: - - string + - array - "null" - vault: + redirectUrl: + description: The redirect URL the client must visit to complete the step-up authentication. + type: string + taskView: oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - type: "null" - title: Vault Service Update Request + ticketActionId: + description: The ID of the task approve action created by this request. + readOnly: true + type: string + title: Task Actions Service Approve With Step Up Response type: object - x-speakeasy-name-override: VaultServiceUpdateRequest - c1.api.vault.v1.VaultServiceUpdateResponse: - description: VaultServiceUpdateResponse is the response message containing the updated vault. + x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpResponse + c1.api.task.v1.TaskActionsServiceCloseRequestInput: + description: The TaskActionsServiceCloseRequest object lets you close or cancel a task. properties: - vault: + comment: + description: An optional comment attached to the close action. + type: string + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Vault Service Update Response + title: Task Actions Service Close Request type: object - x-speakeasy-name-override: VaultServiceUpdateResponse - c1.api.webhooks.v1.Webhook: - description: The Webhook message. + x-speakeasy-name-override: TaskActionsServiceCloseRequest + c1.api.task.v1.TaskActionsServiceCloseResponse: + description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. properties: - callbackTimeout: - format: duration - type: - - string - - "null" - createdAt: - format: date-time + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object readOnly: true type: - - string + - array - "null" - deletedAt: - format: date-time + taskActionId: + description: The ID of the task close action created by this request. readOnly: true - type: - - string - - "null" - description: - description: An optional description of the webhook's purpose. - type: string - displayName: - description: The human-readable name of the webhook. - type: string - id: - description: The unique identifier of the webhook. - type: string - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - url: - description: The destination URL that receives event notification HTTP callbacks. type: string - title: Webhook + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Actions Service Close Response type: object - x-speakeasy-entity: Webhook - x-speakeasy-name-override: WebhookEndpoint - c1.api.webhooks.v1.WebhookInstance: - description: The WebhookInstance message. + x-speakeasy-name-override: TaskActionsServiceCloseResponse + c1.api.task.v1.TaskActionsServiceCommentRequestInput: + description: The TaskActionsServiceCommentRequest object lets you create a new comment on a task. properties: - attempts: - description: The attempts field. - format: int32 - type: integer - completedAt: - format: date-time - readOnly: true - type: - - string - - "null" - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - expiresAt: - format: date-time - readOnly: true - type: - - string - - "null" - id: - description: The id field. + comment: + description: The comment to be posted to the task. type: string - lastAttemptedAt: - format: date-time - readOnly: true + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Comment Request + type: object + x-speakeasy-name-override: TaskActionsServiceCommentRequest + c1.api.task.v1.TaskActionsServiceCommentResponse: + description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - - string + - array - "null" - source: + taskView: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource' + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - type: "null" - spec: + title: Task Actions Service Comment Response + type: object + x-speakeasy-name-override: TaskActionsServiceCommentResponse + c1.api.task.v1.TaskActionsServiceDenyRequestInput: + description: The TaskActionsServiceDenyRequest object lets you deny a task. + properties: + comment: + description: The comment attached to the request. + type: string + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSpec' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - state: - description: The state field. - enum: - - WEBHOOK_STATE_UNSPECIFIED - - WEBHOOK_STATE_PENDING - - WEBHOOK_STATE_RUNNING - - WEBHOOK_STATE_ERROR - - WEBHOOK_STATE_WAITING_CALLBACK - - WEBHOOK_STATE_PROCESS_RESPONSE - - WEBHOOK_STATE_SUCCESS - - WEBHOOK_STATE_FATAL_ERROR + policyStepId: + description: The ID of the current policy step. This is the step you want to deny. type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time + title: Task Actions Service Deny Request + type: object + x-speakeasy-name-override: TaskActionsServiceDenyRequest + c1.api.task.v1.TaskActionsServiceDenyResponse: + description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object readOnly: true type: - - string + - array - "null" - webhookId: - description: The webhookId field. + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task deny action created by this request. + readOnly: true type: string - title: Webhook Instance + title: Task Actions Service Deny Response type: object - x-speakeasy-name-override: WebhookInstance - c1.api.webhooks.v1.WebhookRef: - description: The WebhookRef message. + x-speakeasy-name-override: TaskActionsServiceDenyResponse + c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput: + description: The TaskActionsServiceEscalateToEmergencyAccessRequest object lets you escalate a task to the emergency access workflow. properties: - id: - description: The ID of the referenced webhook. + comment: + description: An optional comment attached to the escalation. type: string - title: Webhook Ref - type: object - x-speakeasy-name-override: WebhookRef - c1.api.webhooks.v1.WebhookSource: - description: | - The WebhookSource message. - - This message contains a oneof named source. Only a single field of the following list may be set at a time: - - test - - policyPostAction - - approvalStep - - provisionStep - - workflowStep - properties: - approvalStep: - oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep' - - type: "null" - policyPostAction: - oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction' - - type: "null" - provisionStep: - oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep' - - type: "null" - test: - oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceTest' - - type: "null" - workflowStep: + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Webhook Source - type: object - x-speakeasy-name-override: WebhookSource - c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep: - description: The WebhookSourceApprovalStep message. - properties: - ticketId: - description: The ticketId field. - type: string - title: Webhook Source Approval Step - type: object - x-speakeasy-name-override: WebhookSourceApprovalStep - c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction: - description: The WebhookSourcePolicyPostAction message. - properties: - ticketId: - description: The ticketId field. + policyStepId: + description: The ID of the current policy step being escalated from. type: string - title: Webhook Source Policy Post Action + title: Task Actions Service Escalate To Emergency Access Request type: object - x-speakeasy-name-override: WebhookSourcePolicyPostAction - c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep: - description: The WebhookSourceProvisionStep message. + x-speakeasy-name-override: TaskActionsServiceEscalateToEmergencyAccessRequest + c1.api.task.v1.TaskActionsServiceHardResetRequestInput: + description: The TaskActionsServiceHardResetRequest object lets you reset a task and recalculate its policy. properties: - ticketId: - description: The ticketId field. + comment: + description: The comment attached to the request. type: string - title: Webhook Source Provision Step - type: object - x-speakeasy-name-override: WebhookSourceProvisionStep - c1.api.webhooks.v1.WebhookSource.WebhookSourceTest: - description: The WebhookSourceTest message. - title: Webhook Source Test + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Hard Reset Request type: object - x-speakeasy-name-override: WebhookSourceTest - c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep: - description: The WebhookSourceWorkflowStep message. + x-speakeasy-name-override: TaskActionsServiceHardResetRequest + c1.api.task.v1.TaskActionsServiceHardResetResponse: + description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. properties: - workflowExecutionId: - description: The workflowExecutionId field. - format: int64 - type: string - workflowStepId: - description: The workflowStepId field. + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task reset action created by this request. type: string - title: Webhook Source Workflow Step + title: Task Actions Service Hard Reset Response type: object - x-speakeasy-name-override: WebhookSourceWorkflowStep - c1.api.webhooks.v1.WebhookSpec: - description: The WebhookSpec message. + x-speakeasy-name-override: TaskActionsServiceHardResetResponse + c1.api.task.v1.TaskActionsServiceProcessNowRequestInput: + description: The TaskActionsServiceProcessNowRequest object lets you trigger processing of a task immediately. properties: - destination: - description: The destination field. - type: string - title: Webhook Spec + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Process Now Request type: object - x-speakeasy-name-override: WebhookSpec - c1.api.webhooks.v1.WebhooksSearchRequest: - description: The WebhooksSearchRequest message. + x-speakeasy-name-override: TaskActionsServiceProcessNowRequest + c1.api.task.v1.TaskActionsServiceProcessNowResponse: + description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. properties: - pageSize: - description: The maximum number of webhooks to return per page. - format: int32 - type: integer - pageToken: - description: The pagination token from a previous search response to fetch the next page. - type: string - query: - description: A text query to match against webhook names and descriptions. - type: string - refs: - description: Optional set of webhook references to restrict the search to specific webhooks. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookRef' + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - title: Webhooks Search Request + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Actions Service Process Now Response type: object - x-speakeasy-name-override: WebhooksSearchRequest - c1.api.webhooks.v1.WebhooksSearchResponse: - description: The WebhooksSearchResponse message. + x-speakeasy-name-override: TaskActionsServiceProcessNowResponse + c1.api.task.v1.TaskActionsServiceReassignRequestInput: + description: The TaskActionsServiceReassignRequest object lets you reassign a task's current policy step to different users. properties: - list: - description: The list of webhooks matching the search criteria. + comment: + description: An optional comment attached to the reassignment. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + newStepUserIds: + description: The IDs of the users to reassign the current policy step to. Must be from the allowed reassignees list. items: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + type: string type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. + policyStepId: + description: The ID of the current policy step to reassign. Must match the task's active step. type: string - title: Webhooks Search Response + title: Task Actions Service Reassign Request type: object - x-speakeasy-name-override: WebhooksSearchResponse - c1.api.webhooks.v1.WebhooksServiceCreateRequest: - description: The WebhooksServiceCreateRequest message. + x-speakeasy-name-override: TaskActionsServiceReassignRequest + c1.api.task.v1.TaskActionsServiceReassignResponse: + description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. properties: - callbackTimeout: - format: duration + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true type: - - string + - array - "null" - description: - description: An optional description of the webhook's purpose. - type: string - displayName: - description: The human-readable name for the new webhook. - type: string - url: - description: The destination URL that will receive event notification HTTP callbacks. - type: string - required: - - displayName - - url - title: Webhooks Service Create Request - type: object - x-speakeasy-name-override: WebhooksServiceCreateRequest - c1.api.webhooks.v1.WebhooksServiceCreateResponse: - description: The WebhooksServiceCreateResponse message. - properties: - webhook: + taskView: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - type: "null" - title: Webhooks Service Create Response - type: object - x-speakeasy-name-override: WebhooksServiceCreateResponse - c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput: - description: The WebhooksServiceDeleteRequest message. - title: Webhooks Service Delete Request - type: object - x-speakeasy-name-override: WebhooksServiceDeleteRequest - c1.api.webhooks.v1.WebhooksServiceDeleteResponse: - description: Empty response body. Status code indicates success. - title: Webhooks Service Delete Response + ticketActionId: + description: The ID of the task reassign action created by this request. + readOnly: true + type: string + title: Task Actions Service Reassign Response type: object - x-speakeasy-name-override: WebhooksServiceDeleteResponse - c1.api.webhooks.v1.WebhooksServiceGetResponse: - description: The WebhooksServiceGetResponse message. + x-speakeasy-name-override: TaskActionsServiceReassignResponse + c1.api.task.v1.TaskActionsServiceRestartRequestInput: + description: The TaskActionsServiceRestartRequest object lets you restart a task. properties: - webhook: + comment: + description: The comment attached to the request. + type: string + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Webhooks Service Get Response + policyStepId: + description: Deprecated. This field is accepted but does not affect behavior. + type: string + title: Task Actions Service Restart Request type: object - x-speakeasy-name-override: WebhooksServiceGetResponse - c1.api.webhooks.v1.WebhooksServiceListResponse: - description: The WebhooksServiceListResponse message. + x-speakeasy-name-override: TaskActionsServiceRestartRequest + c1.api.task.v1.TaskActionsServiceRestartResponse: + description: The TaskActionsServiceRestartResponse returns the updated task after restarting. properties: - list: - description: The list of webhooks for the current page. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object type: - array - "null" - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task restart action created by this request. type: string - title: Webhooks Service List Response + title: Task Actions Service Restart Response type: object - x-speakeasy-name-override: WebhooksServiceListResponse - c1.api.webhooks.v1.WebhooksServiceTestRequestInput: - description: The WebhooksServiceTestRequest message. - title: Webhooks Service Test Request + x-speakeasy-name-override: TaskActionsServiceRestartResponse + c1.api.task.v1.TaskActionsServiceRetryProvisioningRequestInput: + description: Request to retry a task's failed connector provisioning. + properties: + comment: + description: An optional comment attached to the action. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the provision policy step to retry. + type: string + title: Task Actions Service Retry Provisioning Request type: object - x-speakeasy-name-override: WebhooksServiceTestRequest - c1.api.webhooks.v1.WebhooksServiceTestResponse: - description: The WebhooksServiceTestResponse message. + x-speakeasy-name-override: TaskActionsServiceRetryProvisioningRequest + c1.api.task.v1.TaskActionsServiceSkipStepRequestInput: + description: The TaskActionsServiceSkipStepRequest object lets you skip a policy step in a task. properties: - webhook: + comment: + description: The comment attached to the request. + type: string + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookInstance' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Webhooks Service Test Response + policyStepId: + description: The ID of the policy step to skip. + type: string + required: + - policyStepId + title: Task Actions Service Skip Step Request type: object - x-speakeasy-name-override: WebhooksServiceTestResponse - c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput: - description: The WebhooksServiceUpdateRequest message contains the webhook object to update and a field mask to indicate which fields to update. It uses URL value for input. + x-speakeasy-name-override: TaskActionsServiceSkipStepRequest + c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput: + description: The TaskActionsServiceUpdateGrantDurationRequest object lets you change the grant duration on a grant task. properties: - updateMask: + duration: + format: duration type: - string - "null" - webhook: + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Webhooks Service Update Request + required: + - duration + title: Task Actions Service Update Grant Duration Request type: object - x-speakeasy-name-override: WebhooksServiceUpdateRequest - c1.api.webhooks.v1.WebhooksServiceUpdateResponse: - description: The WebhooksServiceUpdateResponse message. + x-speakeasy-name-override: TaskActionsServiceUpdateGrantDurationRequest + c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput: + description: The TaskActionsServiceUpdateRequestDataRequest object lets you submit form data for a task that is in a form policy step. properties: - webhook: + data: + additionalProperties: true + type: + - object + - "null" + expandMask: oneOf: - - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - type: "null" - title: Webhooks Service Update Response + title: Task Actions Service Update Request Data Request type: object - x-speakeasy-name-override: WebhooksServiceUpdateResponse - c1.api.workload_federation.v1.OIDCSettings: - description: |- - OIDCSettings is the kind-specific configuration block for classic OIDC - providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, - any CUSTOM provider). Empty for now; future fields like custom_jwks_url, - audience overrides, and required_claims land here. - title: Oidc Settings - type: object - x-speakeasy-name-override: OIDCSettings - c1.api.workload_federation.v1.SPIFFESettings: - description: |- - SPIFFESettings is the kind-specific configuration block for SPIFFE - trust-domain providers (issuer_url = spiffe://). + x-speakeasy-name-override: TaskActionsServiceUpdateRequestDataRequest + c1.api.task.v1.TaskAuditAccessRequestOutcome: + description: The TaskAuditAccessRequestOutcome message. properties: - bundleEndpointUrl: - description: |- - HTTPS URL of the JWKS endpoint serving the trust domain's signing keys. - Required: the spiffe:// scheme has no discovery mechanism. - Typically the SPIRE OIDC Discovery Provider's /keys endpoint. - - Mutable: updates re-validate the new URL by fetching its JWKS before - persisting; the issuer (trust domain) itself remains immutable. + outcome: + description: The outcome field. + enum: + - ACCESS_REQUEST_OUTCOME_UNSPECIFIED + - ACCESS_REQUEST_OUTCOME_APPROVED + - ACCESS_REQUEST_OUTCOME_DENIED + - ACCESS_REQUEST_OUTCOME_ERROR + - ACCESS_REQUEST_OUTCOME_CANCELLED type: string - title: Spiffe Settings + x-speakeasy-unknown-values: allow + title: Task Audit Access Request Outcome type: object - x-speakeasy-name-override: SPIFFESettings - c1.api.workload_federation.v1.TestTokenStepResult: - description: TestTokenStepResult represents the result of a single validation step. + x-speakeasy-name-override: TaskAuditAccessRequestOutcome + c1.api.task.v1.TaskAuditAccountDeleted: + description: |- + TaskAuditAccountDeleted records an account deletion reported by a connector + while completing a revoke action. properties: - actual: - description: Actual value from the token. + appId: + description: The appId field. type: string - detail: - description: Human-readable detail message. + appUserId: + description: The appUserId field. type: string - expected: - description: Expected value (for comparison steps). + connectorResourceId: + description: The connectorResourceId field. type: string - passed: - description: Whether this step passed. - type: boolean - skipped: - description: Whether this step was skipped (e.g., CIDR check when no allowlist configured). - type: boolean - stepName: - description: Step name for display (e.g., "JWT decode", "Issuer match"). + displayName: + description: The displayName field. type: string - title: Test Token Step Result + email: + description: The email field. + type: string + username: + description: The username field. + type: string + title: Task Audit Account Deleted type: object - x-speakeasy-name-override: TestTokenStepResult - c1.api.workload_federation.v1.WorkloadFederationProvider: - description: | - WorkloadFederationProvider represents a tenant-level workload identity - issuer registration. Two issuer schemes are supported: - - - https://... classic OIDC issuer; `settings.oidc` MUST be set. - - spiffe://... SPIFFE trust-domain URI; `settings.spiffe` MUST be set. - - The (well_known_provider, issuer_url scheme, settings oneof) tuple is a - tri-invariant: SPIFFE wkp ⟺ spiffe:// issuer ⟺ settings.spiffe set; any - other wkp ⟺ https:// issuer ⟺ settings.oidc set. Issuer URLs are unique - within tenant. - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oidc - - spiffe + x-speakeasy-name-override: TaskAuditAccountDeleted + c1.api.task.v1.TaskAuditAccountLifecycleActionCreated: + description: The TaskAuditAccountLifecycleActionCreated message. properties: - createdAt: - format: date-time - readOnly: true - type: - - string - - "null" - description: - description: A description of what this provider is for. + batonActionDisplayName: + description: The batonActionDisplayName field. type: string - disabled: - description: Whether the provider is disabled. Disabled providers reject all token exchanges. - type: boolean - displayName: - description: The display name of the provider. + batonActionInvocationId: + description: The batonActionInvocationId field. type: string - id: - description: The unique ID of the provider. - readOnly: true + batonActionName: + description: The batonActionName field. type: string - issuerUrl: - description: |- - Canonical issuer URL. https:// for OIDC providers, spiffe:// for SPIFFE - trust domains. Unique within tenant. Immutable after creation. - readOnly: true + batonAppId: + description: The batonAppId field. type: string - oidc: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' - - type: "null" - spiffe: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' - - type: "null" - updatedAt: - format: date-time - readOnly: true - type: - - string - - "null" - wellKnownProvider: - description: |- - Well-known provider type. Drives UX (wizard presets, docs, icons). - Set at creation time, immutable. - enum: - - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED - - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM - - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS - - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI - - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM - - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND - - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE - readOnly: true + batonConnectorId: + description: The batonConnectorId field. type: string - x-speakeasy-unknown-values: allow - title: Workload Federation Provider + title: Task Audit Account Lifecycle Action Created type: object - x-speakeasy-name-override: WorkloadFederationProvider - c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest: - description: | - The WorkloadFederationServiceCreateProviderRequest message. - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oidc - - spiffe + x-speakeasy-name-override: TaskAuditAccountLifecycleActionCreated + c1.api.task.v1.TaskAuditAccountLifecycleActionFailed: + description: The TaskAuditAccountLifecycleActionFailed message. properties: - description: - description: A description of what this provider is for. + batonActionDisplayName: + description: The batonActionDisplayName field. type: string - displayName: - description: The display name for the new provider. + batonActionInvocationId: + description: The batonActionInvocationId field. type: string - issuerUrl: - description: |- - The issuer URL. For OIDC providers, this is an HTTPS URL validated via - OIDC discovery. For SPIFFE providers, this is the SPIFFE trust-domain URI - (e.g., spiffe://prod.example.com). Normalized on write: lowercase - scheme/host, no trailing slash. Unique within tenant. + batonActionName: + description: The batonActionName field. type: string - oidc: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' - - type: "null" - spiffe: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' - - type: "null" - wellKnownProvider: - description: |- - Well-known provider type. Required -- UNSPECIFIED is rejected. - When set to a named source, the backend validates issuer_url consistency. - SPIFFE wkp requires `settings.spiffe`; all other wkp values require - `settings.oidc`. - enum: - - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED - - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM - - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS - - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI - - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM - - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND - - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE + batonAppId: + description: The batonAppId field. type: string - x-speakeasy-unknown-values: allow - title: Workload Federation Service Create Provider Request + batonConnectorId: + description: The batonConnectorId field. + type: string + error: + description: The error field. + type: string + title: Task Audit Account Lifecycle Action Failed type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse: - description: The WorkloadFederationServiceCreateProviderResponse message. + x-speakeasy-name-override: TaskAuditAccountLifecycleActionFailed + c1.api.task.v1.TaskAuditActionInstanceCreated: + description: The TaskAuditActionInstanceCreated message. properties: - provider: + instance: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - type: "null" - title: Workload Federation Service Create Provider Response + title: Task Audit Action Instance Created type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput: - description: The WorkloadFederationServiceCreateTrustRequest message. + x-speakeasy-name-override: TaskAuditActionInstanceCreated + c1.api.task.v1.TaskAuditActionInstanceFailed: + description: The TaskAuditActionInstanceFailed message. properties: - allowSourceCidrs: - description: |- - IP allowlist for token exchange requests matching this trust. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. - items: - type: string - type: - - array - - "null" - conditionExpression: - description: |- - CEL expression evaluated against JWT claims. Must return bool. - Compiled and validated before storage. - type: string - description: - description: A description of what this trust policy matches. - type: string - displayName: - description: The display name for the trust. - type: string - passthroughClaims: - description: JWT claim names from the subject token to copy into the issued C1 token. - items: - type: string - type: - - array - - "null" - providerId: - description: The provider this trust references. - type: string - scopedRoleIds: - description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). - items: - type: string - type: - - array - - "null" - title: Workload Federation Service Create Trust Request + instance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + title: Task Audit Action Instance Failed type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse: - description: The WorkloadFederationServiceCreateTrustResponse message. + x-speakeasy-name-override: TaskAuditActionInstanceFailed + c1.api.task.v1.TaskAuditActionInstanceSucceeded: + description: The TaskAuditActionInstanceSucceeded message. properties: - trust: + instance: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - type: "null" - title: Workload Federation Service Create Trust Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput: - description: The WorkloadFederationServiceDeleteProviderRequest message. - title: Workload Federation Service Delete Provider Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse: - description: The WorkloadFederationServiceDeleteProviderResponse message. - title: Workload Federation Service Delete Provider Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput: - description: The WorkloadFederationServiceDeleteTrustRequest message. - title: Workload Federation Service Delete Trust Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse: - description: The WorkloadFederationServiceDeleteTrustResponse message. - title: Workload Federation Service Delete Trust Response + title: Task Audit Action Instance Succeeded type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse: - description: The WorkloadFederationServiceGetProviderResponse message. + x-speakeasy-name-override: TaskAuditActionInstanceSucceeded + c1.api.task.v1.TaskAuditActionSubmitted: + description: The TaskAuditActionSubmitted message. properties: - provider: + action: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAction' - type: "null" - title: Workload Federation Service Get Provider Response + title: Task Audit Action Submitted type: object - x-speakeasy-name-override: WorkloadFederationServiceGetProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse: - description: The WorkloadFederationServiceGetTrustResponse message. + x-speakeasy-name-override: TaskAuditActionSubmitted + c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy: + description: The TaskAuditApprovalAutoAcceptedByPolicy message. + title: Task Audit Approval Auto Accepted By Policy + type: object + x-speakeasy-name-override: TaskAuditApprovalAutoAcceptedByPolicy + c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy: + description: The TaskAuditApprovalAutoRejectedByPolicy message. + title: Task Audit Approval Auto Rejected By Policy + type: object + x-speakeasy-name-override: TaskAuditApprovalAutoRejectedByPolicy + c1.api.task.v1.TaskAuditApprovalHappenedAutomatically: + description: The TaskAuditApprovalHappenedAutomatically message. + title: Task Audit Approval Happened Automatically + type: object + x-speakeasy-name-override: TaskAuditApprovalHappenedAutomatically + c1.api.task.v1.TaskAuditApprovalInstanceChange: + description: The TaskAuditApprovalInstanceChange message. properties: - trust: + instance: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' - type: "null" - title: Workload Federation Service Get Trust Response + title: Task Audit Approval Instance Change type: object - x-speakeasy-name-override: WorkloadFederationServiceGetTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse: - description: The WorkloadFederationServiceListProvidersResponse message. + x-speakeasy-name-override: TaskAuditApprovalInstanceChange + c1.api.task.v1.TaskAuditAutomationTriggered: + description: |- + TaskAuditAutomationTriggered attributes a system-created task to the + automation execution that created it. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - type: - - array - - "null" - nextPageToken: - description: The nextPageToken field. + automationExecutionId: + description: The specific execution of the automation that created the task. + format: int64 type: string - title: Workload Federation Service List Providers Response + automationId: + description: The automation that created the task. + type: string + automationName: + description: |- + The automation's display name as of task creation, so the event stays + readable after the automation is renamed or deleted. + type: string + title: Task Audit Automation Triggered type: object - x-speakeasy-name-override: WorkloadFederationServiceListProvidersResponse - c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse: - description: The WorkloadFederationServiceListTrustsResponse message. + x-speakeasy-name-override: TaskAuditAutomationTriggered + c1.api.task.v1.TaskAuditBulkActionError: + description: The TaskAuditBulkActionError message. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - type: - - array - - "null" - nextPageToken: - description: The nextPageToken field. + error: + description: The error field. type: string - title: Workload Federation Service List Trusts Response + title: Task Audit Bulk Action Error type: object - x-speakeasy-name-override: WorkloadFederationServiceListTrustsResponse - c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest: - description: The WorkloadFederationServiceSearchTrustsRequest message. + x-speakeasy-name-override: TaskAuditBulkActionError + c1.api.task.v1.TaskAuditCertifyOutcome: + description: The TaskAuditCertifyOutcome message. properties: - pageSize: - description: The pageSize field. - format: int32 - type: integer - pageToken: - description: The pageToken field. - type: string - providerId: - description: 'Optional: filter trusts by provider ID.' - type: string - query: - description: 'Optional: full-text search on trust display name and description.' - type: string - servicePrincipalId: - description: 'Optional: filter trusts by service principal ID.' + outcome: + description: The outcome field. + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT type: string - title: Workload Federation Service Search Trusts Request + x-speakeasy-unknown-values: allow + title: Task Audit Certify Outcome type: object - x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsRequest - c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse: - description: The WorkloadFederationServiceSearchTrustsResponse message. + x-speakeasy-name-override: TaskAuditCertifyOutcome + c1.api.task.v1.TaskAuditComment: + description: The TaskAuditComment message. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + comment: + description: The comment field. + type: string + updatedAt: + format: date-time type: - - array + - string - "null" - nextPageToken: - description: The nextPageToken field. + updatedBy: + description: The updatedBy field. type: string - title: Workload Federation Service Search Trusts Response + title: Task Audit Comment type: object - x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsResponse - c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest: - description: The WorkloadFederationServiceTestCELRequest message. + x-speakeasy-name-override: TaskAuditComment + c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult: + description: The TaskAuditConditionalPolicyExecutionResult message. properties: - claimsJson: - description: |- - The claims to evaluate against, as a JSON string. - Parsed into map[string]any for CEL evaluation. - type: string - expression: - description: The CEL expression to evaluate. Must return bool. + chainDepth: + description: The depth of this policy in the chain (0 = root, 1 = first hop, etc.). + format: int32 + type: integer + condition: + description: The condition field. type: string - title: Workload Federation Service Test Cel Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceTestCELRequest - c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse: - description: The WorkloadFederationServiceTestCELResponse message. - properties: + conditionMatched: + description: The conditionMatched field. + type: boolean + defaultCondition: + description: The defaultCondition field. + type: boolean error: - description: Error message if compilation or evaluation failed. + description: The error field. type: string - expression: - description: The expression that was evaluated (echo back). + outcomePolicyId: + description: |- + When this rule's outcome is a reference to another Policy, the ID of + that referenced policy. Empty when the outcome is an inline policy_key. type: string - matched: - description: Whether the expression matched (returned true). - type: boolean - title: Workload Federation Service Test Cel Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceTestCELResponse - c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput: - description: The WorkloadFederationServiceTestTokenRequest message. - properties: - sourceIp: + policyId: description: |- - Optional: override source IP for CIDR testing. - If empty, uses the request's source IP. - Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. + The policy in which this rule was evaluated. Empty for results recorded + before chained policy references existed; populated for every result + emitted by recursive evaluation. type: string - subjectToken: - description: The raw JWT to validate (the subject_token from a CI job). + policyKey: + description: The policyKey field. type: string - title: Workload Federation Service Test Token Request + title: Task Audit Conditional Policy Execution Result type: object - x-speakeasy-name-override: WorkloadFederationServiceTestTokenRequest - c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse: - description: The WorkloadFederationServiceTestTokenResponse message. + x-speakeasy-name-override: TaskAuditConditionalPolicyExecutionResult + c1.api.task.v1.TaskAuditConnectorActionResult: + description: | + The TaskAuditConnectorActionResult message. + + This message contains a oneof named result. Only a single field of the following list may be set at a time: + - success + - error + - cancelled + - pending properties: - audienceValidation: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - - type: "null" - celEvaluation: + appEntitlementId: + description: The appEntitlementId field. + type: string + appId: + description: The appId field. + type: string + cancelled: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditCancelledResult' - type: "null" - cidrCheck: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - - type: "null" - decodedClaimsJson: - description: |- - The decoded JWT claims (best-effort, even if signature fails). - Returned as JSON string for display. + connectorActionId: + description: The connectorActionId field. type: string - issuerMatch: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - - type: "null" - jwtDecode: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - - type: "null" - overallResult: - description: 'Overall result: true only if ALL steps passed.' - type: boolean - signatureValidation: + connectorId: + description: The connectorId field. + type: string + error: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditErrorResult' - type: "null" - subjectValidation: + pending: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditPendingResult' - type: "null" - tokenFreshness: + success: oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditSuccessResult' - type: "null" - title: Workload Federation Service Test Token Response + title: Task Audit Connector Action Result type: object - x-speakeasy-name-override: WorkloadFederationServiceTestTokenResponse - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput: - description: The WorkloadFederationServiceUpdateProviderRequest message. + x-speakeasy-name-override: TaskAuditConnectorActionResult + c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask: + description: |- + TaskAuditCreatedReplacementExtensionGrantTask is used when a replacement extension grant task is created + (e.g. when an extension grant task is cancelled due to app user deletion). properties: - provider: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - - type: "null" - updateMask: - type: - - string - - "null" - title: Workload Federation Service Update Provider Request + newTaskId: + description: The ID of the newly created replacement task + type: string + newTaskNumericId: + description: The numeric ID of the newly created replacement task (for display) + format: int64 + type: string + title: Task Audit Created Replacement Extension Grant Task type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse: - description: The WorkloadFederationServiceUpdateProviderResponse message. + x-speakeasy-name-override: TaskAuditCreatedReplacementExtensionGrantTask + c1.api.task.v1.TaskAuditEscalateToEmergencyAccess: + description: The TaskAuditEscalateToEmergencyAccess message. properties: - provider: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - - type: "null" - title: Workload Federation Service Update Provider Response + oldPolicyId: + description: The oldPolicyId field. + type: string + oldPolicyStepId: + description: The oldPolicyStepId field. + type: string + title: Task Audit Escalate To Emergency Access type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput: - description: The WorkloadFederationServiceUpdateTrustRequest message. + x-speakeasy-name-override: TaskAuditEscalateToEmergencyAccess + c1.api.task.v1.TaskAuditExpressionPolicyStepError: + description: The TaskAuditExpressionPolicyStepError message. properties: - trust: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - - type: "null" - updateMask: - type: - - string - - "null" - title: Workload Federation Service Update Trust Request + error: + description: The error field. + type: string + title: Task Audit Expression Policy Step Error type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse: - description: The WorkloadFederationServiceUpdateTrustResponse message. + x-speakeasy-name-override: TaskAuditExpressionPolicyStepError + c1.api.task.v1.TaskAuditExternalTicketCreated: + description: The TaskAuditExternalTicketCreated message. properties: - trust: - oneOf: - - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - - type: "null" - title: Workload Federation Service Update Trust Response + appId: + description: The appId field. + type: string + connectorId: + description: The connectorId field. + type: string + externalTicketId: + description: The externalTicketId field. + type: string + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. + type: string + externalTicketProvisionerConfigName: + description: The externalTicketProvisionerConfigName field. + type: string + externalTicketUrl: + description: The externalTicketUrl field. + type: string + title: Task Audit External Ticket Created type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustResponse - c1.api.workload_federation.v1.WorkloadFederationTrust: - description: |- - WorkloadFederationTrust represents a per-SP trust policy that references - a tenant-level provider and defines a CEL condition for claim matching. + x-speakeasy-name-override: TaskAuditExternalTicketCreated + c1.api.task.v1.TaskAuditExternalTicketError: + description: The TaskAuditExternalTicketError message. properties: - allowSourceCidrs: - description: IP allowlist for token exchange requests matching this trust. - items: - type: string - type: - - array - - "null" - clientId: - description: |- - The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). - Used as the client_id parameter in RFC 8693 token exchange requests. - readOnly: true + errorMessage: + description: The errorMessage field. type: string - conditionExpression: - description: |- - CEL expression evaluated against JWT claims. Must return bool. - Example: claims.sub.startsWith("repo:acme/infra:") && claims.environment == "production" + title: Task Audit External Ticket Error + type: object + x-speakeasy-name-override: TaskAuditExternalTicketError + c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved: + description: The TaskAuditExternalTicketProvisionStepResolved message. + properties: + appId: + description: The appId field. type: string - createdAt: - format: date-time - readOnly: true + connectorId: + description: The connectorId field. + type: string + externalTicketId: + description: The externalTicketId field. + type: string + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. + type: string + externalTicketUrl: + description: The externalTicketUrl field. + type: string + title: Task Audit External Ticket Provision Step Resolved + type: object + x-speakeasy-name-override: TaskAuditExternalTicketProvisionStepResolved + c1.api.task.v1.TaskAuditExternalTicketTriggered: + description: The TaskAuditExternalTicketTriggered message. + properties: + appId: + description: The appId field. + type: string + connectorId: + description: The connectorId field. + type: string + externalTicketId: + description: The externalTicketId field. + type: string + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. + type: string + externalTicketProvisionerConfigName: + description: The externalTicketProvisionerConfigName field. + type: string + title: Task Audit External Ticket Triggered + type: object + x-speakeasy-name-override: TaskAuditExternalTicketTriggered + c1.api.task.v1.TaskAuditFinishedConnectorActions: + description: The TaskAuditFinishedConnectorActions message. + properties: + policyStepId: + description: The policyStepId field. + type: string + title: Task Audit Finished Connector Actions + type: object + x-speakeasy-name-override: TaskAuditFinishedConnectorActions + c1.api.task.v1.TaskAuditFormInstanceChange: + description: The TaskAuditFormInstanceChange message. + properties: + isValid: + description: The isValid field. + type: boolean + title: Task Audit Form Instance Change + type: object + x-speakeasy-name-override: TaskAuditFormInstanceChange + c1.api.task.v1.TaskAuditGrantDurationUpdated: + description: The TaskAuditGrantDurationUpdated message. + properties: + duration: + format: duration type: - string - "null" - description: - description: A description of what this trust policy matches. + title: Task Audit Grant Duration Updated + type: object + x-speakeasy-name-override: TaskAuditGrantDurationUpdated + c1.api.task.v1.TaskAuditGrantOutcome: + description: The TaskAuditGrantOutcome message. + properties: + outcome: + description: The outcome field. + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT type: string - disabled: - description: Whether the trust is disabled. - type: boolean - displayName: - description: The display name of the trust. + x-speakeasy-unknown-values: allow + title: Task Audit Grant Outcome + type: object + x-speakeasy-name-override: TaskAuditGrantOutcome + c1.api.task.v1.TaskAuditHardReset: + description: The TaskAuditHardReset message. + properties: + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - passthroughClaims: + title: Task Audit Hard Reset + type: object + x-speakeasy-name-override: TaskAuditHardReset + c1.api.task.v1.TaskAuditListRequest: + description: The TaskAuditListRequest message. + properties: + commentsOnly: description: |- - JWT claim names from the subject token to copy into the issued C1 token. - Values are placed in the "c1wfc" claim as a map[string]string. - Only string-valued claims are copied; non-string claims are silently skipped. - Example: ["repository", "repository_owner", "job_workflow_ref"] + When true, only comment events are returned, so a page of page_size holds + page_size comments rather than a mix of comments and state-change events. + type: boolean + excludeComments: + description: |- + When true, comment events are excluded from the response and the count, so + a page of page_size holds page_size non-comment events. Mutually exclusive + with comments_only. + type: boolean + newestFirst: + description: |- + When true, events are returned newest-first (descending created_at) instead + of the default chronological (ascending) order. + type: boolean + pageSize: + description: The maximum number of audit events to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token from a previous response to retrieve the next page. + type: string + refs: + description: References to specific audit events to retrieve. If provided, only these events are returned. items: - type: string + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditViewRef' type: - array - "null" - providerId: - description: The provider ID this trust references. Immutable after creation. - readOnly: true + taskId: + description: The ID of the task to list audit events for. type: string - scopedRoleIds: - description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + title: Task Audit List Request + type: object + x-speakeasy-name-override: TaskAuditListRequest + c1.api.task.v1.TaskAuditListResponse: + description: The TaskAuditListResponse message. + properties: + list: + description: The list of audit events for the task. items: - type: string + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditView' type: - array - "null" - servicePrincipalId: - description: The service principal user ID this trust belongs to. - readOnly: true + nextPageToken: + description: A pagination token to retrieve the next page of results. type: string - updatedAt: - format: date-time - readOnly: true + totalCount: + description: |- + The total number of audit events the list returns for this request: + comment events when comments_only is true, non-comment events when + exclude_comments is true, all events otherwise. This is an upper bound: + a small number of internal-only events (e.g. connector-action results + with no pending reason) are omitted from list, so the count can exceed + the rows reachable by paging. Only returned for the first page (a request + with no page_token). Unset when the request filters by refs (the count is + undefined for ref lookups) or when the count could not be computed. + format: int64 type: - string - "null" - title: Workload Federation Trust + title: Task Audit List Response type: object - x-speakeasy-name-override: WorkloadFederationTrust - c1.mcp.role_mining.v1.AccessProfileMatch: - description: The AccessProfileMatch message. + x-speakeasy-name-override: TaskAuditListResponse + c1.api.task.v1.TaskAuditMetaData: + description: The TaskAuditMetaData message. properties: - catalogDisplayName: - description: The catalogDisplayName field. + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Task Audit Meta Data + type: object + x-speakeasy-name-override: TaskAuditMetaData + c1.api.task.v1.TaskAuditNewTask: + description: The TaskAuditNewTask message. + title: Task Audit New Task + type: object + x-speakeasy-name-override: TaskAuditNewTask + c1.api.task.v1.TaskAuditNewTaskCreatedFrom: + description: |- + TaskAuditNewTaskCreatedFrom is used when a task is created from another task + (e.g. when a replacement extension grant task is created after the original is cancelled). + This is set on the NEW task to indicate its origin. + properties: + originalTaskId: + description: The originalTaskId field. type: string - catalogId: - description: The catalogId field. + originalTaskNumericId: + description: The originalTaskNumericId field. + format: int64 type: string - matchType: - description: The matchType field. - enum: - - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED - - ACCESS_PROFILE_MATCH_TYPE_EXACT - - ACCESS_PROFILE_MATCH_TYPE_SUPERSET - - ACCESS_PROFILE_MATCH_TYPE_PARTIAL + originalTaskType: + description: The task type of the original task (e.g. "grant", "revoke", "certify"). type: string - x-speakeasy-unknown-values: allow - missingEntitlements: - description: The missingEntitlements field. + title: Task Audit New Task Created From + type: object + x-speakeasy-name-override: TaskAuditNewTaskCreatedFrom + c1.api.task.v1.TaskAuditPolicyApprovalReassigned: + description: The TaskAuditPolicyApprovalReassigned message. + properties: + newPolicyStepId: + description: The newPolicyStepId field. + type: string + newUsers: + description: The newUsers field. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: string type: - array - "null" - overlapRatio: - description: The overlapRatio field. - type: number - title: Access Profile Match - type: object - x-speakeasy-name-override: AccessProfileMatch - c1.mcp.role_mining.v1.AttributeFacet: - description: AttributeFacet represents a filterable user profile attribute with its available values. - properties: - attribute: - description: The attribute field. - type: string - displayName: - description: The displayName field. + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - values: - description: The values field. + users: + description: The users field. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeValue' + $ref: '#/components/schemas/c1.api.user.v1.User' type: - array - "null" - title: Attribute Facet + title: Task Audit Policy Approval Reassigned type: object - x-speakeasy-name-override: AttributeFacet - c1.mcp.role_mining.v1.AttributeValue: - description: AttributeValue represents a single value within a facet. + x-speakeasy-name-override: TaskAuditPolicyApprovalReassigned + c1.api.task.v1.TaskAuditPolicyChanged: + description: The TaskAuditPolicyChanged message. properties: - displayName: - description: The displayName field. + newPolicyId: + description: The newPolicyId field. type: string - userCount: - description: The userCount field. - format: int32 - type: integer - value: - description: The value field. + oldPolicyId: + description: The oldPolicyId field. type: string - title: Attribute Value + title: Task Audit Policy Changed type: object - x-speakeasy-name-override: RoleMiningAttributeValue - c1.mcp.role_mining.v1.CohortEntitlement: - description: The CohortEntitlement message. + x-speakeasy-name-override: TaskAuditPolicyChanged + c1.api.task.v1.TaskAuditPolicyEvaluationStep: + description: The TaskAuditPolicyEvaluationStep message. properties: - appDisplayName: - description: The appDisplayName field. - type: string - appId: - description: The appId field. - type: string - appResourceDisplayName: - description: The appResourceDisplayName field. - type: string - appResourceTypeDisplayName: - description: The appResourceTypeDisplayName field. - type: string - coverage: - description: The coverage field. - type: number - entitlementDisplayName: - description: The entitlementDisplayName field. - type: string - entitlementId: - description: The entitlementId field. + stepComment: + description: The stepComment field. type: string - grantedCount: - description: The grantedCount field. - format: int32 - type: integer - riskLevelValueId: - description: The riskLevelValueId field. + title: Task Audit Policy Evaluation Step + type: object + x-speakeasy-name-override: TaskAuditPolicyEvaluationStep + c1.api.task.v1.TaskAuditPolicyProvisionCancelled: + description: The TaskAuditPolicyProvisionCancelled message. + properties: + cancelReason: + description: The cancelReason field. type: string - title: Cohort Entitlement + title: Task Audit Policy Provision Cancelled type: object - x-speakeasy-name-override: CohortEntitlement - c1.mcp.role_mining.v1.EntitlementCluster: - description: The EntitlementCluster message. + x-speakeasy-name-override: TaskAuditPolicyProvisionCancelled + c1.api.task.v1.TaskAuditPolicyProvisionError: + description: The TaskAuditPolicyProvisionError message. properties: - avgCoverage: - description: The avgCoverage field. - type: number - avgSimilarity: - description: The avgSimilarity field. - type: number - entitlements: - description: The entitlements field. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - type: - - array - - "null" - userCount: - description: The userCount field. - format: int32 - type: integer - title: Entitlement Cluster + error: + description: The error field. + type: string + title: Task Audit Policy Provision Error type: object - x-speakeasy-name-override: EntitlementCluster - c1.mcp.role_mining.v1.ProfileFilter: - description: |- - ProfileFilter defines a filter on a user profile attribute. - Use GetOrgOverview to discover available attribute keys and their values. + x-speakeasy-name-override: TaskAuditPolicyProvisionError + c1.api.task.v1.TaskAuditPolicyProvisionReassigned: + description: The TaskAuditPolicyProvisionReassigned message. properties: - attribute: - description: The attribute field. + newPolicyStepId: + description: The newPolicyStepId field. type: string - values: - description: The values field. + newUsers: + description: The newUsers field. items: type: string type: - array - "null" - title: Profile Filter - type: object - x-speakeasy-name-override: ProfileFilter - c1.webhooks.v1.Body: - description: The Body message. - properties: - callbackUrl: - description: |- - If your receiver returns HTTP Status Code 202 Accepted, it MUST send its resposne to this URL as a POST - message body. - - If your receiver returns any other status code, it is expected to not use the callback url. - - This value will match the "Webhook-Callback-Url" header. - type: string - event: - description: |- - The type of event that triggered this Webhook. - - This value will match the "Webhook-Event" header. - - The value will be one of: - - "c1.webhooks.v1.PayloadTest" - - "c1.webhooks.v1.PayloadPolicyApprovalStep" - - "c1.webhooks.v1.PayloadPolicyPostAction" - - "c1.webhooks.v1.PayloadProvisionStep" - type: string - payload: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: - - object - - "null" - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook body will use a different string. - - This value will match the "Webhook-Version" header. - type: string - webhookId: - description: |- - Unique ID for this Webhook. Your receiver should only process this ID once. - - This value will match the "Webhook-Id" header. + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - title: Body - type: object - x-speakeasy-include: true - x-speakeasy-name-override: Body - c1.webhooks.v1.PayloadPolicyApprovalStep: - description: The PayloadPolicyApprovalStep message. - properties: - expanded: - description: List of serialized related objects. + users: + description: The users field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object + $ref: '#/components/schemas/c1.api.user.v1.User' type: - array - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Payload Policy Approval Step + title: Task Audit Policy Provision Reassigned type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadPolicyApprovalStep - c1.webhooks.v1.PayloadPolicyPostAction: - description: The PayloadPolicyPostAction message. + x-speakeasy-name-override: TaskAuditPolicyProvisionReassigned + c1.api.task.v1.TaskAuditProvisionEntitlementMergeCompleted: + description: The TaskAuditProvisionEntitlementMergeCompleted message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Payload Policy Post Action + appEntitlementId: + description: The appEntitlementId field. + type: string + appId: + description: The appId field. + type: string + title: Task Audit Provision Entitlement Merge Completed type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadPolicyPostAction - c1.webhooks.v1.PayloadProvisionStep: - description: The PayloadProvisionStep message. + x-speakeasy-name-override: TaskAuditProvisionEntitlementMergeCompleted + c1.api.task.v1.TaskAuditProvisionEntitlementMergeTimedOut: + description: The TaskAuditProvisionEntitlementMergeTimedOut message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - taskView: - oneOf: - - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - - type: "null" - title: Payload Provision Step - type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadProvisionStep - c1.webhooks.v1.PayloadTest: - description: The PayloadTest message. - title: Payload Test + appEntitlementId: + description: The appEntitlementId field. + type: string + appId: + description: The appId field. + type: string + title: Task Audit Provision Entitlement Merge Timed Out type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadTest - c1.webhooks.v1.PayloadWorkflowStep: - description: The PayloadWorkflowStep message. + x-speakeasy-name-override: TaskAuditProvisionEntitlementMergeTimedOut + c1.api.task.v1.TaskAuditProvisionWaitingForEntitlementMerge: + description: The TaskAuditProvisionWaitingForEntitlementMerge message. properties: - context: - additionalProperties: true - type: - - object - - "null" - workflowExecutionId: - description: The workflow execution ID - format: int64 - type: string - workflowExecutionStepId: - description: The workflow execution step ID + appEntitlementId: + description: The appEntitlementId field. type: string - workflowId: - description: The workflow template ID + appId: + description: The appId field. type: string - title: Payload Workflow Step + fallbackAt: + format: date-time + type: + - string + - "null" + title: Task Audit Provision Waiting For Entitlement Merge type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadWorkflowStep - c1.webhooks.v1.ResponsePolicyApprovalStep: - description: | - The ResponsePolicyApprovalStep message. - - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - approve - - deny - - reassign - - replacePolicy + x-speakeasy-name-override: TaskAuditProvisionWaitingForEntitlementMerge + c1.api.task.v1.TaskAuditReassignedToDelegate: + description: The TaskAuditReassignedToDelegate message. properties: - approve: - oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove' - - type: "null" - deny: - oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny' - - type: "null" - reassign: + delegatedAssigneeUser: oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign' + - $ref: '#/components/schemas/c1.api.user.v1.User' - type: "null" - replacePolicy: + delegatedAssigneeUserId: + description: The delegatedAssigneeUserId field. + type: string + originalAssigneeUser: oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy' + - $ref: '#/components/schemas/c1.api.user.v1.User' - type: "null" - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. + originalAssigneeUserId: + description: The originalAssigneeUserId field. type: string - title: Response Policy Approval Step + title: Task Audit Reassigned To Delegate type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponsePolicyApprovalStep - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy: - description: The ResponsePolicyApprovalReplacePolicy message. + x-speakeasy-name-override: TaskAuditReassignedToDelegate + c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin: + description: |- + TaskAuditReassignmentFallbackToAdmin is used when no eligible reviewers are found + from the policy configuration and the task falls back to system administrators + without creating a new policy step. This prevents reassignment loops. properties: - comment: - description: The comment field. - type: string - policySteps: - description: The policySteps field. + adminUserIds: + description: The IDs of the system administrator users that the task is being assigned to items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + type: string type: - array - "null" - title: Response Policy Approval Replace Policy - type: object - x-speakeasy-name-override: ResponsePolicyApprovalReplacePolicy - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove: - description: The ResponsePolicyApprovalStepApprove message. - properties: - comment: - description: optional comment - type: string - title: Response Policy Approval Step Approve - type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepApprove - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny: - description: The ResponsePolicyApprovalStepDeny message. - properties: - comment: - description: optional comment - type: string - title: Response Policy Approval Step Deny - type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepDeny - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign: - description: The ResponsePolicyApprovalStepReassign message. - properties: - comment: - description: optional comment - type: string - newStepUserIds: - description: The newStepUserIds field. + adminUsers: + description: The system administrator users (populated for display) items: - type: string + $ref: '#/components/schemas/c1.api.user.v1.User' type: - array - "null" - title: Response Policy Approval Step Reassign + title: Task Audit Reassignment Fallback To Admin type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepReassign - c1.webhooks.v1.ResponsePolicyPostAction: - description: The ResponsePolicyPostAction message. + x-speakeasy-name-override: TaskAuditReassignmentFallbackToAdmin + c1.api.task.v1.TaskAuditReassignmentListError: + description: The TaskAuditReassignmentListError message. properties: - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. + errorMessage: + description: The errorMessage field. type: string - title: Response Policy Post Action + title: Task Audit Reassignment List Error type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponsePolicyPostAction - c1.webhooks.v1.ResponseProvisionStep: - description: | - The ResponseProvisionStep message. - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - complete - - errored + x-speakeasy-name-override: TaskAuditReassignmentListError + c1.api.task.v1.TaskAuditRequestDefaultsApplied: + description: |- + TaskAuditRequestDefaultsApplied records which tier of the request-settings + precedence chain supplied the defaults for a grant request. The rule ID, not + its name, is stored; consumers resolve the current display name via + (app_id, routing_rule_id). properties: - complete: - oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete' - - type: "null" - errored: - oneOf: - - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored' - - type: "null" - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. + appId: + description: The appId field. type: string - title: Response Provision Step + routingRuleId: + description: The routingRuleId field. + type: string + source: + description: The source field. + enum: + - APPLIED_SETTINGS_SOURCE_UNSPECIFIED + - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_OVERRIDE + - APPLIED_SETTINGS_SOURCE_ROUTING_RULE + - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_DEFAULT + - APPLIED_SETTINGS_SOURCE_APP_DEFAULT + - APPLIED_SETTINGS_SOURCE_ACCESS_PROFILE_DEFAULT + type: string + x-speakeasy-unknown-values: allow + title: Task Audit Request Defaults Applied type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseProvisionStep - c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete: - description: The ResponseProvisionStepComplete message. + x-speakeasy-name-override: TaskAuditRequestDefaultsApplied + c1.api.task.v1.TaskAuditRestart: + description: The TaskAuditRestart message. properties: - comment: - description: optional comment + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - title: Response Provision Step Complete + title: Task Audit Restart type: object - x-speakeasy-name-override: ResponseProvisionStepComplete - c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored: - description: The ResponseProvisionStepErrored message. + x-speakeasy-name-override: TaskAuditRestart + c1.api.task.v1.TaskAuditRevokeOutcome: + description: The TaskAuditRevokeOutcome message. properties: - comment: - description: optional comment + outcome: + description: The outcome field. + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT type: string - title: Response Provision Step Errored + x-speakeasy-unknown-values: allow + title: Task Audit Revoke Outcome type: object - x-speakeasy-name-override: ResponseProvisionStepErrored - c1.webhooks.v1.ResponseTest: - description: The ResponseTest message. + x-speakeasy-name-override: TaskAuditRevokeOutcome + c1.api.task.v1.TaskAuditSLAEscalation: + description: The TaskAuditSLAEscalation message. properties: - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. + message: + description: The message field. type: string - title: Response Test + title: Task Audit Sla Escalation type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseTest - c1.webhooks.v1.ResponseWorkflowStep: - description: The ResponseWorkflowStep message. + x-speakeasy-name-override: TaskAuditSLAEscalation + c1.api.task.v1.TaskAuditStartedConnectorActions: + description: The TaskAuditStartedConnectorActions message. properties: - context: - additionalProperties: true - type: - - object - - "null" - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. + policyStepId: + description: The policyStepId field. type: string - title: Response Workflow Step + title: Task Audit Started Connector Actions type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseWorkflowStep - google.rpc.Status: - description: |- - The `Status` type defines a logical error model that is suitable for - different programming environments, including REST APIs and RPC APIs. It is - used by [gRPC](https://github.com/grpc). Each `Status` message contains - three pieces of data: error code, error message, and error details. - - You can find out more about this error model and how to work with it in the - [API Design Guide](https://cloud.google.com/apis/design/errors). + x-speakeasy-name-override: TaskAuditStartedConnectorActions + c1.api.task.v1.TaskAuditStateChange: + description: The TaskAuditStateChange message. properties: - code: - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - format: int32 - type: integer - details: - description: |- - A list of messages that carry the error details. There is a common set of - message types for APIs to use. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - type: object - type: - - array - - "null" - message: - description: |- - A developer-facing error message, which should be in English. Any - user-facing error message should be localized and sent in the - [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. + previousState: + description: The previousState field. + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED type: string - title: Status + x-speakeasy-unknown-values: allow + title: Task Audit State Change type: object - x-speakeasy-name-override: Status - validate.AnyRules: - description: |- - AnyRules describe constraints applied exclusively to the - `google.protobuf.Any` well-known type + x-speakeasy-name-override: TaskAuditStateChange + c1.api.task.v1.TaskAuditStepSkipped: + description: The TaskAuditStepSkipped message. properties: - in: - description: |- - In specifies that this field's `type_url` must be equal to one of the - specified values. - items: - type: string - type: - - array - - "null" - notIn: - description: |- - NotIn specifies that this field's `type_url` must not be equal to any of - the specified values. - items: - type: string - type: - - array - - "null" - required: - description: Required specifies that this field must be set - type: boolean - title: Any Rules + skippedBy: + description: The skippedBy field. + type: string + title: Task Audit Step Skipped type: object - x-speakeasy-name-override: AnyRules - validate.BoolRules: - description: BoolRules describes the constraints applied to `bool` values + x-speakeasy-name-override: TaskAuditStepSkipped + c1.api.task.v1.TaskAuditStepUpApproval: + description: The TaskAuditStepUpApproval message. properties: - const: - description: Const specifies that this field must be exactly the specified value - type: boolean - title: Bool Rules + stepUpTransactionId: + description: The stepUpTransactionId field. + type: string + title: Task Audit Step Up Approval type: object - x-speakeasy-name-override: BoolRules - validate.BytesRules: + x-speakeasy-name-override: TaskAuditStepUpApproval + c1.api.task.v1.TaskAuditView: description: | - BytesRules describe the constraints applied to `bytes` values + The TaskAuditView message. - This message contains a oneof named well_known. Only a single field of the following list may be set at a time: - - ip - - ipv4 - - ipv6 - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: base64 - type: string - contains: - description: |- - Contains specifies that this field must have the specified bytes - anywhere in the string. - format: base64 - type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: base64 - type: string - type: - - array - - "null" - ip: - description: |- - Ip specifies that the field must be a valid IP (v4 or v6) address in - byte format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - type: - - boolean - - "null" - ipv4: - description: |- - Ipv4 specifies that the field must be a valid IPv4 address in byte - format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - type: - - boolean - - "null" - ipv6: - description: |- - Ipv6 specifies that the field must be a valid IPv6 address in byte - format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - type: - - boolean - - "null" - len: - description: Len specifies that this field must be the specified number of bytes - format: uint64 - type: string - maxLen: - description: |- - MaxLen specifies that this field must be the specified number of bytes - at a maximum - format: uint64 - type: string - minLen: - description: |- - MinLen specifies that this field must be the specified number of bytes - at a minimum - format: uint64 - type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: base64 - type: string - type: - - array - - "null" - pattern: - description: |- - Pattern specifes that this field must match against the specified - regular expression (RE2 syntax). The included expression should elide - any delimiters. - type: string - prefix: - description: |- - Prefix specifies that this field must have the specified bytes at the - beginning of the string. - format: base64 - type: string - suffix: - description: |- - Suffix specifies that this field must have the specified bytes at the - end of the string. - format: base64 - type: string - title: Bytes Rules - type: object - x-speakeasy-name-override: BytesRules - validate.DoubleRules: - description: DoubleRules describes the constraints applied to `double` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - type: number - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - type: number - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - type: number - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - type: number - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - type: number - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - type: number - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - type: number - type: - - array - - "null" - title: Double Rules - type: object - x-speakeasy-name-override: DoubleRules - validate.DurationRules: - description: |- - DurationRules describe the constraints applied exclusively to the - `google.protobuf.Duration` well-known type + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - comment + - stateChange + - approvalInstanceChange + - connectorActionsStart + - connectorActionsEnd + - actionResult + - taskCreated + - certifyOutcome + - actionSubmitted + - grantOutcome + - revokeOutcome + - approvalReassigned + - taskRestarted + - accessRequestOutcome + - provisionReassigned + - provisionError + - approvedAutomatically + - reassignedToDelegate + - hardReset + - taskEscalated + - conditionalPolicyExecutionResult + - expressionPolicyStepError + - approvalAutoAcceptedByPolicy + - approvalAutoRejectedByPolicy + - bulkActionError + - webhookTriggered + - webhookAttempt + - webhookSuccess + - policyEvaluationStep + - waitStepSuccess + - waitStepWaiting + - waitStepTimedOut + - webhookApprovalTriggered + - webhookApprovalAttempt + - webhookApprovalSuccess + - webhookApprovalBadResponse + - externalTicketTriggered + - externalTicketCreated + - externalTicketError + - waitStepAnalysisSuccess + - waitStepAnalysisWaiting + - waitStepAnalysisTimedOut + - stepUpApproval + - externalTicketProvisionStepResolved + - stepSkipped + - reassignmentListError + - slaEscalation + - policyChanged + - formInstanceChange + - grantDurationUpdated + - waitStepUntilTime + - webhookApprovalFatalError + - accountLifecycleActionCreated + - accountLifecycleActionFailed + - provisionCancelled + - actionInstanceCreated + - actionInstanceSucceeded + - actionInstanceFailed + - createdReplacementExtensionGrantTask + - taskCreatedFrom + - reassignmentFallbackToAdmin + - requestDefaultsApplied + - provisionWaitingForEntitlementMerge + - provisionEntitlementMergeCompleted + - provisionEntitlementMergeTimedOut + - accountDeleted + - automationTriggered properties: - const: - format: duration - type: - - string - - "null" - gt: - format: duration - type: - - string - - "null" - gte: - format: duration - type: - - string - - "null" - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: duration - type: string - type: - - array - - "null" - lt: - format: duration - type: - - string - - "null" - lte: - format: duration + accessRequestOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccessRequestOutcome' + - type: "null" + accountDeleted: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountDeleted' + - type: "null" + accountLifecycleActionCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionCreated' + - type: "null" + accountLifecycleActionFailed: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionFailed' + - type: "null" + actionInstanceCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceCreated' + - type: "null" + actionInstanceFailed: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceFailed' + - type: "null" + actionInstanceSucceeded: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceSucceeded' + - type: "null" + actionResult: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConnectorActionResult' + - type: "null" + actionSubmitted: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionSubmitted' + - type: "null" + approvalAutoAcceptedByPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy' + - type: "null" + approvalAutoRejectedByPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy' + - type: "null" + approvalInstanceChange: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalInstanceChange' + - type: "null" + approvalReassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyApprovalReassigned' + - type: "null" + approvedAutomatically: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalHappenedAutomatically' + - type: "null" + automationTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAutomationTriggered' + - type: "null" + bulkActionError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditBulkActionError' + - type: "null" + certifyOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCertifyOutcome' + - type: "null" + comment: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditComment' + - type: "null" + conditionalPolicyExecutionResult: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult' + - type: "null" + connectorActionsEnd: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFinishedConnectorActions' + - type: "null" + connectorActionsStart: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStartedConnectorActions' + - type: "null" + created: + format: date-time type: - string - "null" - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: duration - type: string - type: - - array - - "null" - required: - description: Required specifies that this field must be set - type: boolean - title: Duration Rules - type: object - x-speakeasy-name-override: DurationRules - validate.EnumRules: - description: EnumRules describe the constraints applied to enum values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - type: integer - definedOnly: - description: |- - DefinedOnly specifies that this field must be only one of the defined - values for this enum, failing on any undefined value. - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - type: - - array - - "null" - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int32 - type: integer - type: - - array - - "null" - title: Enum Rules - type: object - x-speakeasy-name-override: EnumRules - validate.FieldRules: - description: | - FieldRules encapsulates the rules for each type of field. Depending on the - field, the correct set should be used to ensure proper validations. - - This message contains a oneof named type. Only a single field of the following list may be set at a time: - - float - - double - - int32 - - int64 - - uint32 - - uint64 - - sint32 - - sint64 - - fixed32 - - fixed64 - - sfixed32 - - sfixed64 - - bool - - string - - bytes - - enum - - repeated - - map - - any - - duration - - timestamp - properties: - any: + createdReplacementExtensionGrantTask: oneOf: - - $ref: '#/components/schemas/validate.AnyRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask' - type: "null" - bool: + currentState: + description: The currentState field. + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED + type: string + x-speakeasy-unknown-values: allow + eventType: + description: The eventType field. + enum: + - TASK_AUDIT_EVENT_TYPE_UNSPECIFIED + - TASK_AUDIT_EVENT_TYPE_NEUTRAL + - TASK_AUDIT_EVENT_TYPE_ERROR + type: string + x-speakeasy-unknown-values: allow + expressionPolicyStepError: oneOf: - - $ref: '#/components/schemas/validate.BoolRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExpressionPolicyStepError' - type: "null" - bytes: + externalTicketCreated: oneOf: - - $ref: '#/components/schemas/validate.BytesRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketCreated' - type: "null" - double: + externalTicketError: oneOf: - - $ref: '#/components/schemas/validate.DoubleRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketError' - type: "null" - duration: + externalTicketProvisionStepResolved: oneOf: - - $ref: '#/components/schemas/validate.DurationRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved' - type: "null" - enum: + externalTicketTriggered: oneOf: - - $ref: '#/components/schemas/validate.EnumRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketTriggered' - type: "null" - fixed32: + formInstanceChange: oneOf: - - $ref: '#/components/schemas/validate.Fixed32Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFormInstanceChange' - type: "null" - fixed64: + grantDurationUpdated: oneOf: - - $ref: '#/components/schemas/validate.Fixed64Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantDurationUpdated' - type: "null" - float: + grantOutcome: oneOf: - - $ref: '#/components/schemas/validate.FloatRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantOutcome' - type: "null" - int32: + hardReset: oneOf: - - $ref: '#/components/schemas/validate.Int32Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditHardReset' - type: "null" - int64: + id: + description: The id field. + type: string + metadata: oneOf: - - $ref: '#/components/schemas/validate.Int64Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditMetaData' - type: "null" - map: + policyChanged: oneOf: - - $ref: '#/components/schemas/validate.MapRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyChanged' - type: "null" - message: + policyEvaluationStep: oneOf: - - $ref: '#/components/schemas/validate.MessageRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyEvaluationStep' - type: "null" - repeated: + provisionCancelled: oneOf: - - $ref: '#/components/schemas/validate.RepeatedRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionCancelled' - type: "null" - sfixed32: + provisionEntitlementMergeCompleted: oneOf: - - $ref: '#/components/schemas/validate.SFixed32Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditProvisionEntitlementMergeCompleted' - type: "null" - sfixed64: + provisionEntitlementMergeTimedOut: oneOf: - - $ref: '#/components/schemas/validate.SFixed64Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditProvisionEntitlementMergeTimedOut' - type: "null" - sint32: + provisionError: oneOf: - - $ref: '#/components/schemas/validate.SInt32Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionError' - type: "null" - sint64: + provisionReassigned: oneOf: - - $ref: '#/components/schemas/validate.SInt64Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionReassigned' - type: "null" - string: + provisionWaitingForEntitlementMerge: oneOf: - - $ref: '#/components/schemas/validate.StringRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditProvisionWaitingForEntitlementMerge' - type: "null" - timestamp: + reassignedToDelegate: oneOf: - - $ref: '#/components/schemas/validate.TimestampRules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignedToDelegate' - type: "null" - uint32: + reassignmentFallbackToAdmin: oneOf: - - $ref: '#/components/schemas/validate.UInt32Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin' - type: "null" - uint64: + reassignmentListError: oneOf: - - $ref: '#/components/schemas/validate.UInt64Rules' + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentListError' - type: "null" - title: Field Rules - type: object - x-speakeasy-name-override: FieldRules - validate.Fixed32Rules: - description: Fixed32Rules describes the constraints applied to `fixed32` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint32 - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint32 - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint32 - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint32 - type: integer - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint32 - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint32 + requestDefaultsApplied: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRequestDefaultsApplied' + - type: "null" + revokeOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRevokeOutcome' + - type: "null" + slaEscalation: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditSLAEscalation' + - type: "null" + source: + description: The source field. + enum: + - SOURCE_UNSPECIFIED + - SOURCE_C1 + - SOURCE_JIRA + - SOURCE_SLACK + - SOURCE_COPILOT_AGENTS + type: string + x-speakeasy-unknown-values: allow + stateChange: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStateChange' + - type: "null" + stepSkipped: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepSkipped' + - type: "null" + stepUpApproval: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepUpApproval' + - type: "null" + taskCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTask' + - type: "null" + taskCreatedFrom: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTaskCreatedFrom' + - type: "null" + taskEscalated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditEscalateToEmergencyAccess' + - type: "null" + taskRestarted: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRestart' + - type: "null" + ticketId: + description: The ticketId field. + type: string + userId: + description: The userId field. + type: string + waitStepAnalysisSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess' + - type: "null" + waitStepAnalysisTimedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut' + - type: "null" + waitStepAnalysisWaiting: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting' + - type: "null" + waitStepSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepSuccess' + - type: "null" + waitStepTimedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepTimedOut' + - type: "null" + waitStepUntilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepUntilTime' + - type: "null" + waitStepWaiting: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepWaiting' + - type: "null" + webhookApprovalAttempt: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalAttempt' + - type: "null" + webhookApprovalBadResponse: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalBadResponse' + - type: "null" + webhookApprovalFatalError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalFatalError' + - type: "null" + webhookApprovalSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalSuccess' + - type: "null" + webhookApprovalTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalTriggered' + - type: "null" + webhookAttempt: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookAttempt' + - type: "null" + webhookSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookSuccess' + - type: "null" + webhookTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookTriggered' + - type: "null" + workflowStep: + description: The workflowStep field. + format: int32 type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint32 - type: integer - type: - - array - - "null" - title: Fixed 32 Rules + title: Task Audit View type: object - x-speakeasy-name-override: Fixed32Rules - validate.Fixed64Rules: - description: Fixed64Rules describes the constraints applied to `fixed64` values + x-speakeasy-name-override: TaskAuditView + c1.api.task.v1.TaskAuditViewRef: + description: The TaskAuditViewRef message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint64 - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint64 + id: + description: The ID of the audit event. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint64 + title: Task Audit View Ref + type: object + x-speakeasy-name-override: TaskAuditViewRef + c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess: + description: The TaskAuditWaitForAnalysisStepSuccess message. + properties: + stepId: + description: The stepId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint64 - type: string + succeededAt: + format: date-time type: - - array + - string - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint64 - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint64 + title: Task Audit Wait For Analysis Step Success + type: object + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepSuccess + c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut: + description: The TaskAuditWaitForAnalysisStepTimedOut message. + properties: + stepId: + description: The stepId field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint64 - type: string + timedOutAt: + format: date-time type: - - array + - string - "null" - title: Fixed 64 Rules + title: Task Audit Wait For Analysis Step Timed Out type: object - x-speakeasy-name-override: Fixed64Rules - validate.FloatRules: - description: FloatRules describes the constraints applied to `float` values + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepTimedOut + c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting: + description: The TaskAuditWaitForAnalysisStepWaiting message. properties: - const: - description: Const specifies that this field must be exactly the specified value - type: number - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - type: number - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - type: number - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - type: number - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - type: number - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - type: number - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - type: number - type: - - array - - "null" - title: Float Rules + stepId: + description: The stepId field. + type: string + title: Task Audit Wait For Analysis Step Waiting type: object - x-speakeasy-name-override: FloatRules - validate.Int32Rules: - description: Int32Rules describes the constraints applied to `int32` values + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepWaiting + c1.api.task.v1.TaskAuditWaitStepSuccess: + description: The TaskAuditWaitStepSuccess message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int32 - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int32 - type: integer + condition: + description: The condition field. + type: string + stepId: + description: The stepId field. + type: string + succeededAt: + format: date-time type: - - array + - string - "null" - title: Int 32 Rules + title: Task Audit Wait Step Success type: object - x-speakeasy-name-override: Int32Rules - validate.Int64Rules: - description: Int64Rules describes the constraints applied to `int64` values + x-speakeasy-name-override: TaskAuditWaitStepSuccess + c1.api.task.v1.TaskAuditWaitStepTimedOut: + description: The TaskAuditWaitStepTimedOut message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 + condition: + description: The condition field. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int64 + stepId: + description: The stepId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int64 - type: string + timedOutAt: + format: date-time type: - - array + - string - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 + title: Task Audit Wait Step Timed Out + type: object + x-speakeasy-name-override: TaskAuditWaitStepTimedOut + c1.api.task.v1.TaskAuditWaitStepUntilTime: + description: The TaskAuditWaitStepUntilTime message. + properties: + stepId: + description: The stepId field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int64 - type: string + untilTime: + format: date-time type: - - array + - string - "null" - title: Int 64 Rules + title: Task Audit Wait Step Until Time type: object - x-speakeasy-name-override: Int64Rules - validate.MapRules: - description: MapRules describe the constraints applied to `map` values + x-speakeasy-name-override: TaskAuditWaitStepUntilTime + c1.api.task.v1.TaskAuditWaitStepWaiting: + description: The TaskAuditWaitStepWaiting message. properties: - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - keys: - oneOf: - - $ref: '#/components/schemas/validate.FieldRules' - - type: "null" - maxPairs: - description: |- - MaxPairs specifies that this field must have the specified number of - KVs at a maximum - format: uint64 + condition: + description: The condition field. type: string - minPairs: - description: |- - MinPairs specifies that this field must have the specified number of - KVs at a minimum - format: uint64 + stepId: + description: The stepId field. type: string - noSparse: - description: |- - NoSparse specifies values in this field cannot be unset. This only - applies to map's with message value types. - type: boolean - values: - oneOf: - - $ref: '#/components/schemas/validate.FieldRules' - - type: "null" - title: Map Rules + title: Task Audit Wait Step Waiting type: object - x-speakeasy-name-override: MapRules - validate.MessageRules: - description: |- - MessageRules describe the constraints applied to embedded message values. - For message-type fields, validation is performed recursively. + x-speakeasy-name-override: TaskAuditWaitStepWaiting + c1.api.task.v1.TaskAuditWebhookApprovalAttempt: + description: The TaskAuditWebhookApprovalAttempt message. properties: - required: - description: Required specifies that this field must be set - type: boolean - skip: - description: |- - Skip specifies that the validation rules of this field should not be - evaluated - type: boolean - title: Message Rules + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Attempt type: object - x-speakeasy-name-override: MessageRules - validate.RepeatedRules: - description: RepeatedRules describe the constraints applied to `repeated` values + x-speakeasy-name-override: TaskAuditWebhookApprovalAttempt + c1.api.task.v1.TaskAuditWebhookApprovalBadResponse: + description: The TaskAuditWebhookApprovalBadResponse message. properties: - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - items: - oneOf: - - $ref: '#/components/schemas/validate.FieldRules' - - type: "null" - maxItems: - description: |- - MaxItems specifies that this field must have the specified number of - items at a maximum - format: uint64 + error: + description: The error field. type: string - minItems: - description: |- - MinItems specifies that this field must have the specified number of - items at a minimum - format: uint64 + webhookId: + description: The webhookId field. type: string - unique: - description: |- - Unique specifies that all elements in this field must be unique. This - contraint is only applicable to scalar and enum types (messages are not - supported). - type: boolean - title: Repeated Rules + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Bad Response type: object - x-speakeasy-name-override: RepeatedRules - validate.SFixed32Rules: - description: SFixed32Rules describes the constraints applied to `sfixed32` values + x-speakeasy-name-override: TaskAuditWebhookApprovalBadResponse + c1.api.task.v1.TaskAuditWebhookApprovalFatalError: + description: The TaskAuditWebhookApprovalFatalError message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + error: + description: The error field. + type: string + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Fatal Error + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalFatalError + c1.api.task.v1.TaskAuditWebhookApprovalSuccess: + description: The TaskAuditWebhookApprovalSuccess message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Success + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalSuccess + c1.api.task.v1.TaskAuditWebhookApprovalTriggered: + description: The TaskAuditWebhookApprovalTriggered message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Triggered + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalTriggered + c1.api.task.v1.TaskAuditWebhookAttempt: + description: The TaskAuditWebhookAttempt message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Attempt + type: object + x-speakeasy-name-override: TaskAuditWebhookAttempt + c1.api.task.v1.TaskAuditWebhookSuccess: + description: The TaskAuditWebhookSuccess message. + properties: + comment: + description: Optional comment supplied by the provisioning callback. + type: string + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Success + type: object + x-speakeasy-name-override: TaskAuditWebhookSuccess + c1.api.task.v1.TaskAuditWebhookTriggered: + description: The TaskAuditWebhookTriggered message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Triggered + type: object + x-speakeasy-name-override: TaskAuditWebhookTriggered + c1.api.task.v1.TaskExpandMask: + description: The task expand mask is an array of strings that specifes the related objects the requester wishes to have returned when making a request where the expand mask is part of the input. Use '*' to view all possible responses. + properties: + paths: + description: A list of paths to expand in the response. May be any combination of "*", "access_review_id", "user_id", "created_by_user_id", "app_id", "app_user_id", "app_entitlement_ids", "step_approver_ids", "approver_ids", "identity_user_id", "insight_ids", "app_user_last_usage", "entitlement_scope_bindings", "scope_role_resources", and "resource". items: - format: int32 - type: integer + type: string type: - array - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int32 - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int32 - type: integer + title: Task Expand Mask + type: object + x-speakeasy-name-override: TaskExpandMask + c1.api.task.v1.TaskGrantSource: + description: The TaskGrantSource message tracks which external URL was the source of the specificed grant ticket. + properties: + conversationId: + description: The ID of the conversation that created this ticket + type: string + externalUrl: + description: The external url source of the grant ticket. + type: string + integrationId: + description: The integration id for the source of tickets. + type: string + isExtension: + description: Whether the grant task is an extension task. + type: boolean + requestId: + description: the request id for the grant ticket if the source is external + type: string + title: Task Grant Source + type: object + x-speakeasy-name-override: TaskGrantSource + c1.api.task.v1.TaskRef: + description: This object references a task by ID. + properties: + id: + description: The ID of the referenced Task + type: string + title: Task Ref + type: object + x-speakeasy-name-override: TaskRef + c1.api.task.v1.TaskRevocationTarget: + description: An ancestor entitlement that will be revoked as part of an inheritance revocation. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Task Revocation Target + type: object + x-speakeasy-name-override: TaskRevocationTarget + c1.api.task.v1.TaskRevokeSource: + description: | + The TaskRevokeSource message indicates the source of the revoke task is one of expired, nonUsage, request, or review. + + This message contains a oneof named origin. Only a single field of the following list may be set at a time: + - review + - request + - expired + - nonUsage + properties: + expired: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceExpired' + - type: "null" + nonUsage: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceNonUsage' + - type: "null" + request: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceRequest' + - type: "null" + review: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceReview' + - type: "null" + title: Task Revoke Source + type: object + x-speakeasy-name-override: TaskRevokeSource + c1.api.task.v1.TaskRevokeSourceExpired: + description: The TaskRevokeSourceExpired message indicates that the source of the revoke task is due to a grant expiring. + properties: + expiredAt: + format: date-time type: - - array + - string - "null" - title: S Fixed 32 Rules + title: Task Revoke Source Expired type: object - x-speakeasy-name-override: SFixed32Rules - validate.SFixed64Rules: - description: SFixed64Rules describes the constraints applied to `sfixed64` values + x-speakeasy-name-override: TaskRevokeSourceExpired + c1.api.task.v1.TaskRevokeSourceNonUsage: + description: The TaskRevokeSourceNonUsage message indicates that the source of the revoke task is due to the grant not being used. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 + expiresAt: + format: date-time + type: + - string + - "null" + lastLogin: + format: date-time + type: + - string + - "null" + title: Task Revoke Source Non Usage + type: object + x-speakeasy-name-override: TaskRevokeSourceNonUsage + c1.api.task.v1.TaskRevokeSourceRequest: + description: The TaskRevokeSourceRequest message indicates that the source of the revoke task was a request. + properties: + requestUserId: + description: The ID of the user who initiated the revoke request. type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 + title: Task Revoke Source Request + type: object + x-speakeasy-name-override: TaskRevokeSourceRequest + c1.api.task.v1.TaskRevokeSourceReview: + description: The TaskRevokeSourceReview message tracks which access review was the source of the specificed revoke ticket. + properties: + accessReviewId: + description: The ID of the access review associated with the revoke task. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int64 + certTicketId: + description: The ID of the certify ticket that was denied and created this revoke task. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + title: Task Revoke Source Review + type: object + x-speakeasy-name-override: TaskRevokeSourceReview + c1.api.task.v1.TaskSearchRequest: + description: Search for tasks based on a plethora filters. + properties: + accessReviewIds: + description: Search tasks that belong to any of the access reviews included in this list. items: - format: int64 type: string type: - array - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 - type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + accountOwnerIds: + description: Search tasks that have any of these account owners. items: - format: int64 type: string type: - array - "null" - title: S Fixed 64 Rules - type: object - x-speakeasy-name-override: SFixed64Rules - validate.SInt32Rules: - description: SInt32Rules describes the constraints applied to `sint32` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + accountStatuses: + description: Search tasks by the account status of the app user subject. items: - format: int32 - type: integer + enum: + - STATUS_UNSPECIFIED + - STATUS_ENABLED + - STATUS_DISABLED + - STATUS_DELETED + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int32 - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + accountTypes: + description: The accountTypes field. items: - format: int32 - type: integer + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT + type: string + x-speakeasy-unknown-values: allow type: - array - "null" - title: S Int 32 Rules - type: object - x-speakeasy-name-override: SInt32Rules - validate.SInt64Rules: - description: SInt64Rules describes the constraints applied to `sint64` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 - type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int64 + actorId: + description: Search tasks that have this actor ID. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + appEntitlementIds: + description: Search tasks that have any of these app entitlement IDs. items: - format: int64 type: string type: - array - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 - type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + appResourceIds: + description: Search tasks that have any of these app resource IDs. items: - format: int64 type: string type: - array - "null" - title: S Int 64 Rules - type: object - x-speakeasy-name-override: SInt64Rules - validate.StringRules: - description: | - StringRules describe the constraints applied to `string` values - - This message contains a oneof named well_known. Only a single field of the following list may be set at a time: - - email - - hostname - - ip - - ipv4 - - ipv6 - - uri - - uriRef - - address - - uuid - - wellKnownRegex - properties: - address: - description: |- - Address specifies that the field must be either a valid hostname as - defined by RFC 1034 (which does not support internationalized domain - names or IDNs), or it can be a valid IP (v4 or v6). - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + appResourceTypeIds: + description: Search tasks that have any of these app resource type IDs. + items: + type: string type: - - boolean + - array - "null" - const: - description: Const specifies that this field must be exactly the specified value + appUserSubjectIds: + description: Search tasks that have any of these app users as subjects. + items: + type: string + type: + - array + - "null" + applicationIds: + description: Search tasks that have any of these apps as targets. + items: + type: string + type: + - array + - "null" + assignedOrStepApproverUserId: + description: Search tasks that are currently assigned to this user, or that are closed and were previously approved by this user. type: string - contains: - description: |- - Contains specifies that this field must have the specified substring - anywhere in the string. + assigneesInIds: + description: Search tasks by List of UserIDs which are currently assigned these Tasks + items: + type: string + type: + - array + - "null" + certifyOutcomes: + description: Search tasks by certify outcome + items: + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + createdAfter: + format: date-time + type: + - string + - "null" + createdBefore: + format: date-time + type: + - string + - "null" + currentStep: + description: Search tasks that have this type of step as the current step. + enum: + - TASK_SEARCH_CURRENT_STEP_UNSPECIFIED + - TASK_SEARCH_CURRENT_STEP_APPROVAL + - TASK_SEARCH_CURRENT_STEP_PROVISION type: string - email: - description: |- - Email specifies that the field must be a valid email address as - defined by RFC 5322 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + x-speakeasy-unknown-values: allow + emergencyStatus: + description: Search tasks that are or are not emergency access. + enum: + - UNSPECIFIED + - ALL + - NON_EMERGENCY + - EMERGENCY + type: string + x-speakeasy-unknown-values: allow + excludeAppEntitlementIds: + description: Search tasks that do not have any of these app entitlement IDs. + items: + type: string type: - - boolean + - array - "null" - hostname: - description: |- - Hostname specifies that the field must be a valid hostname as - defined by RFC 1034. This constraint does not support - internationalized domain names (IDNs). - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + excludeAppResourceTypeIds: + description: Search tasks that do not have any of these app resource type IDs. + items: + type: string type: - - boolean + - array - "null" - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty + excludeApplicationIds: + description: Search tasks that do NOT have any of these apps as targets. + items: + type: string + type: + - array + - "null" + excludeIds: + description: Exclude Specific TaskIDs from this serach result. + items: + type: string + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + grantOutcomes: + description: Search tasks by grant outcome + items: + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + includeActedAfter: + format: date-time + type: + - string + - "null" + includeDeleted: + description: Whether or not to include deleted tasks. type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + myWorkUserIds: + description: Search tasks where the user would see this task in the My Work section items: type: string type: - array - "null" - ip: - description: |- - Ip specifies that the field must be a valid IP (v4 or v6) address. - Valid IPv6 addresses should not include surrounding square brackets. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + olderThanDuration: + format: duration type: - - boolean + - string - "null" - ipv4: - description: |- - Ipv4 specifies that the field must be a valid IPv4 address. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + openerIds: + description: Search tasks that were created by any of the users in this array. + items: + type: string type: - - boolean + - array - "null" - ipv6: - description: |- - Ipv6 specifies that the field must be a valid IPv6 address. Valid - IPv6 addresses should not include surrounding square brackets. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + openerOrSubjectUserId: + description: Search tasks that were opened by this user, or that the user is the subject of. + type: string + outcomeAfter: + format: date-time type: - - boolean + - string - "null" - len: - description: |- - Len specifies that this field must be the specified number of - characters (Unicode code points). Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 + outcomeBefore: + format: date-time + type: + - string + - "null" + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - lenBytes: + pendingActionFilter: description: |- - LenBytes specifies that this field must be the specified number of bytes - at a minimum - format: uint64 + Filter tasks by pending action status. Only applies when exactly one access_review_id is specified. + Requires the REVIEWS_PENDING_ACTIONS feature flag to be enabled. + enum: + - PENDING_ACTION_FILTER_UNSPECIFIED + - PENDING_ACTION_FILTER_WITH_PENDING + - PENDING_ACTION_FILTER_WITHOUT_PENDING type: string - maxBytes: - description: |- - MaxBytes specifies that this field must be the specified number of bytes - at a maximum - format: uint64 + x-speakeasy-unknown-values: allow + previouslyActedOnIds: + description: Search tasks that were acted on by any of these users. + items: + type: string + type: + - array + - "null" + query: + description: Fuzzy search tasks by display name, description, or ID. type: string - maxLen: - description: |- - MaxLen specifies that this field must be the specified number of - characters (Unicode code points) at a maximum. Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 + refs: + description: Query tasks by display name, description, or numeric ID. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskRef' + type: + - array + - "null" + requireApprovalReason: + description: Filter tasks where the current approval step requires an approval reason. + type: boolean + requireDenialReason: + description: Filter tasks where the current approval step requires a denial reason. + type: boolean + revokeOutcomes: + description: Search tasks by revoke outcome + items: + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + sortBy: + description: Sort tasks in a specific order. + enum: + - TASK_SEARCH_SORT_BY_UNSPECIFIED + - TASK_SEARCH_SORT_BY_ACCOUNT + - TASK_SEARCH_SORT_BY_RESOURCE + - TASK_SEARCH_SORT_BY_ACCOUNT_OWNER + - TASK_SEARCH_SORT_BY_REVERSE_TICKET_ID + - TASK_SEARCH_SORT_BY_TICKET_ID + - TASK_SEARCH_SORT_BY_CREATED_AT + - TASK_SEARCH_SORT_BY_REVERSE_CREATED_AT + - TASK_SEARCH_SORT_BY_APP_RESOURCE_ID_AND_APP_ENTITLEMENT type: string - minBytes: + x-speakeasy-unknown-values: allow + stepApprovalTypes: + description: Search tasks that have a current policy step of this type + items: + enum: + - STEP_APPROVAL_TYPE_UNSPECIFIED + - STEP_APPROVAL_TYPE_USERS + - STEP_APPROVAL_TYPE_MANAGER + - STEP_APPROVAL_TYPE_APP_OWNERS + - STEP_APPROVAL_TYPE_GROUP + - STEP_APPROVAL_TYPE_SELF + - STEP_APPROVAL_TYPE_ENTITLEMENT_OWNERS + - STEP_APPROVAL_TYPE_EXPRESSION + - STEP_APPROVAL_TYPE_WEBHOOK + - STEP_APPROVAL_TYPE_RESOURCE_OWNERS + - STEP_APPROVAL_TYPE_AGENT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + subjectIds: + description: Search tasks where these users are the subject. + items: + type: string + type: + - array + - "null" + taskStates: + description: Search tasks with this task state. + items: + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + taskTypes: + description: Search tasks with this task type. This is a oneOf, and needs an object, which can be empty, to sort. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskType' + type: + - array + - "null" + userEmploymentStatuses: + description: The userEmploymentStatuses field. + items: + type: string + type: + - array + - "null" + title: Task Search Request + type: object + x-speakeasy-name-override: TaskSearchRequest + c1.api.task.v1.TaskSearchResponse: + description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. + properties: + expanded: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: List of serialized related objects. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskView' + type: + - array + - "null" + nextPageToken: description: |- - MinBytes specifies that this field must be the specified number of bytes - at a minimum - format: uint64 + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - minLen: - description: |- - MinLen specifies that this field must be the specified number of - characters (Unicode code points) at a minimum. Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 + title: Task Search Response + type: object + x-speakeasy-name-override: TaskSearchResponse + c1.api.task.v1.TaskServiceActionResponse: + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task action created by this request. type: string - notContains: - description: |- - NotContains specifies that this field cannot have the specified substring - anywhere in the string. + title: Task Service Action Response + type: object + x-speakeasy-name-override: TaskServiceActionResponse + c1.api.task.v1.TaskServiceCreateActionRequest: + description: The TaskServiceCreateActionRequest message submits a request action (requestable automation). + properties: + actionId: + description: The ID of the action to request. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + description: + description: An optional description of the request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + formValues: + additionalProperties: true + type: + - object + - "null" + title: Task Service Create Action Request + type: object + x-speakeasy-name-override: TaskServiceCreateActionRequest + c1.api.task.v1.TaskServiceCreateActionResponse: + description: The TaskServiceCreateActionResponse returns the created action task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. items: - type: string + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true type: - array - "null" - pattern: - description: |- - Pattern specifes that this field must match against the specified - regular expression (RE2 syntax). The included expression should elide - any delimiters. + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Action Response + type: object + x-speakeasy-name-override: TaskServiceCreateActionResponse + c1.api.task.v1.TaskServiceCreateGrantRequest: + description: Create a grant task. + properties: + appEntitlementId: + description: The ID of the app entitlement to grant access to. + type: string + appId: + description: The ID of the app that is associated with the entitlement. + type: string + appUserId: + description: The ID of the app user to grant access for. This field and identityUserId cannot both be set for a given request. + type: string + description: + description: The description of the request. + type: string + emergencyAccess: + description: Boolean stating whether or not the task is marked as emergency access. + type: boolean + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + grantDuration: + format: duration + type: + - string + - "null" + identityUserId: + description: The ID of the user associated with the app user we are granting access for. This field cannot be set if appUserID is also set. + type: string + requestData: + additionalProperties: true + type: + - object + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' + - type: "null" + required: + - appId + - appEntitlementId + title: Task Service Create Grant Request + type: object + x-speakeasy-name-override: TaskServiceCreateGrantRequest + c1.api.task.v1.TaskServiceCreateGrantResponse: + description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Grant Response + type: object + x-speakeasy-name-override: TaskServiceCreateGrantResponse + c1.api.task.v1.TaskServiceCreateOffboardingRequest: + description: Create an offboarding task. + properties: + description: + description: The description of the offboarding request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + subjectUserId: + description: The ID of the user to offboard. + type: string + title: Task Service Create Offboarding Request + type: object + x-speakeasy-name-override: TaskServiceCreateOffboardingRequest + c1.api.task.v1.TaskServiceCreateOffboardingResponse: + description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Offboarding Response + type: object + x-speakeasy-name-override: TaskServiceCreateOffboardingResponse + c1.api.task.v1.TaskServiceCreateResourceActionRequest: + description: The TaskServiceCreateResourceActionRequest submits a request to execute a connector resource-create action, for example creating a group from a group template. + properties: + actionId: + description: The ID of the resource-create action to execute. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + formValues: + additionalProperties: true + type: + - object + - "null" + required: + - actionId + title: Task Service Create Resource Action Request + type: object + x-speakeasy-name-override: TaskServiceCreateResourceActionRequest + c1.api.task.v1.TaskServiceCreateResourceActionResponse: + description: The TaskServiceCreateResourceActionResponse returns the created action task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Resource Action Response + type: object + x-speakeasy-name-override: TaskServiceCreateResourceActionResponse + c1.api.task.v1.TaskServiceCreateRevokeRequest: + description: Create a revoke task. + properties: + appEntitlementId: + description: The ID of the app entitlement to revoke access to. + type: string + appId: + description: The ID of the app associated with the entitlement. + type: string + appUserId: + description: The ID of the app user to revoke access from. This field and identityUserId cannot both be set for a given request. + type: string + description: + description: The description of the request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + identityUserId: + description: The ID of the user associated with the app user we are revoking access from. This field cannot be set if appUserID is also set. + type: string + required: + - appId + - appEntitlementId + title: Task Service Create Revoke Request + type: object + x-speakeasy-name-override: TaskServiceCreateRevokeRequest + c1.api.task.v1.TaskServiceCreateRevokeResponse: + description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Revoke Response + type: object + x-speakeasy-name-override: TaskServiceCreateRevokeResponse + c1.api.task.v1.TaskServiceGetResponse: + description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Get Response + type: object + x-speakeasy-name-override: TaskServiceGetResponse + c1.api.task.v1.TaskType: + description: | + Task Type provides configuration for the type of task: certify, grant, or revoke + + This message contains a oneof named task_type. Only a single field of the following list may be set at a time: + - grant + - revoke + - certify + - offboarding + - action + - finding + properties: + action: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeAction' + - type: "null" + certify: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeCertify' + - type: "null" + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeFinding' + - type: "null" + grant: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeGrant' + - type: "null" + offboarding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeOffboarding' + - type: "null" + revoke: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeRevoke' + - type: "null" + title: Task Type + type: object + x-speakeasy-name-override: TaskType + c1.api.task.v1.TaskTypeAction: + description: | + The TaskTypeAction message. + + This message contains a oneof named target_object. Only a single field of the following list may be set at a time: + - scopeRole + - toolCall + - finding + properties: + actionId: + description: |- + The ID of the admin-authored action to execute. Empty for synthesized + action tickets (e.g. scope-role grants) — those carry dispatch + configuration on action_instance and target_object instead. + readOnly: true + type: string + actionInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ActionInstance' + - type: "null" + createdAppEntitlementIds: + description: |- + The C1 IDs of the AppEntitlements materialized from the connector response + (for a group, typically its members and owners entitlements). Use these to + request access, attach a virtual entitlement, or otherwise manage the new + resource. Empty until outcome is SUCCESS; may be empty on SUCCESS if + materialization was skipped or failed, in which case the entitlements + appear after the next connector sync. + items: + type: string + readOnly: true + type: + - array + - "null" + createdAppResourceId: + description: |- + Populated when a resource-create action completes: the C1 ID of the + AppResource materialized from the connector response. + readOnly: true + type: string + createdAppResourceTypeId: + description: The resource type ID of the materialized AppResource. + readOnly: true + type: string + displayName: + description: |- + Display label captured on the action snapshot at ticket-creation time. + Stable under admin renames to a referenced Action row and populated for + synthesized tickets that have no Action row at all. UI reads this to + render the task title without an Action fetch. + readOnly: true + type: string + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.FindingTarget' + - type: "null" + formValues: + additionalProperties: true + readOnly: true + type: + - object + - "null" + outcome: + description: The outcome field. + enum: + - ACTION_OUTCOME_UNSPECIFIED + - ACTION_OUTCOME_SUCCESS + - ACTION_OUTCOME_DENIED + - ACTION_OUTCOME_ERROR + - ACTION_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + scopeRole: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ScopeRole' + - type: "null" + toolCall: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.GatedToolCallTarget' + - type: "null" + type: + description: |- + Flavor of action the ticket represents — mirrors the snapshot's + target_ref variant. + enum: + - TYPE_UNSPECIFIED + - TYPE_GRANT + - TYPE_WORKFLOW + - TYPE_RESOURCE_ACTION + - TYPE_TOOL_CALL + - TYPE_MANUAL + readOnly: true + type: string + x-speakeasy-unknown-values: allow + title: Task Type Action + type: object + x-speakeasy-name-override: TaskTypeAction + c1.api.task.v1.TaskTypeCertify: + description: | + The TaskTypeCertify message indicates that a task is a certify task and all related details. + + This message contains a oneof named principal. Only a single field of the following list may be set at a time: + - resource + properties: + accessReviewId: + description: The ID of the access review. + readOnly: true + type: string + accessReviewSelection: + description: The ID of the specific access review object that owns this certify task. This is also set on a revoke task if the revoke task is created from the denied outcome of a certify task. + readOnly: true + type: string + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the certification. + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' + - type: "null" + title: Task Type Certify + type: object + x-speakeasy-name-override: TaskTypeCertify + c1.api.task.v1.TaskTypeFinding: + description: The TaskTypeFinding message. + properties: + findingId: + description: Reference to the source finding. + readOnly: true + type: string + findingType: + description: The finding type discriminator. + readOnly: true + type: string + outcome: + description: The outcome field. + enum: + - FINDING_TASK_OUTCOME_UNSPECIFIED + - FINDING_TASK_OUTCOME_REMEDIATED + - FINDING_TASK_OUTCOME_RISK_ACCEPTED + - FINDING_TASK_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + title: Task Type Finding + type: object + x-speakeasy-name-override: TaskTypeFinding + c1.api.task.v1.TaskTypeGrant: + description: The TaskTypeGrant message indicates that a task is a grant task and all related details. + properties: + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + grantDuration: + format: duration + readOnly: true + type: + - string + - "null" + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the grant. + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' + - type: "null" + title: Task Type Grant + type: object + x-speakeasy-name-override: TaskTypeGrant + c1.api.task.v1.TaskTypeOffboarding: + description: The TaskTypeOffboarding message. + properties: + outcome: + description: The outcome field. + enum: + - OFFBOARDING_OUTCOME_UNSPECIFIED + - OFFBOARDING_OUTCOME_IN_PROGRESS + - OFFBOARDING_OUTCOME_DONE + - OFFBOARDING_OUTCOME_ERROR + - OFFBOARDING_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + subjectUserId: + description: The subjectUserId field. + readOnly: true + type: string + title: Task Type Offboarding + type: object + x-speakeasy-name-override: TaskTypeOffboarding + c1.api.task.v1.TaskTypeRevoke: + description: | + The TaskTypeRevoke message indicates that a task is a revoke task and all related details. + + This message contains a oneof named principal. Only a single field of the following list may be set at a time: + - resource + properties: + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the revoke. + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' + - type: "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSource' + - type: "null" + title: Task Type Revoke + type: object + x-speakeasy-name-override: TaskTypeRevoke + c1.api.task.v1.TaskView: + description: Contains a task and JSONPATH expressions that describe where in the expanded array related objects are located. This view can be used to display a fully-detailed dashboard of task information. + properties: + accessReviewPath: + description: JSONPATH expression indicating the location of the AccessReview object in the expanded array + readOnly: true + type: string + appPath: + description: JSONPATH expression indicating the location of the App object in the expanded array + readOnly: true + type: string + appUserLastUsagePath: + description: JSONPATH expression indicating the location of the AppUser last usage timestamp in the expanded array + readOnly: true + type: string + appUserPath: + description: JSONPATH expression indicating the location of the AppUser object in the expanded array + readOnly: true + type: string + approversPath: + description: JSONPATH expression indicating the location of the ApproverUsers objects in the expanded array. These are the users who have approved or denied this task. + readOnly: true + type: string + createdByUserPath: + description: JSONPATH expression indicating the location of the object of the User that created the ticket in the expanded array + readOnly: true + type: string + entitlementsPath: + description: JSONPATH expression indicating the location of the Entitlements objects in the expanded array + readOnly: true + type: string + identityUserPath: + description: JSONPATH expression indicating the location of the User object of the User that this task is targeting in the expanded array. This is the user that is the identity when the target of a task is an app user. + readOnly: true + type: string + insightsPath: + description: JSONPATH expression indicating the location of the Insights objects in the expanded array + readOnly: true + type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + principalResourcePath: + description: JSONPATH expression indicating the location of the AppResource under review for a resource-principal certify task in the expanded array. + readOnly: true + type: string + resourceBindingsPath: + description: JSONPATH expression indicating the location of the EntitlementScopeBindingList object in the expanded array. + readOnly: true + type: string + roleResourcePath: + description: JSONPATH expression indicating the location of the role AppResource for a scope-role action task in the expanded array. + readOnly: true + type: string + scopeResourcePath: + description: JSONPATH expression indicating the location of the scope AppResource for a scope-role action task in the expanded array. + readOnly: true + type: string + stepApproversPath: + description: JSONPATH expression indicating the location of the StepApproverUsers objects in the expanded array + readOnly: true + type: string + task: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.Task' + - type: "null" + userPath: + description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. + readOnly: true + type: string + title: Task View + type: object + x-speakeasy-name-override: TaskView + c1.api.terraform_export.v1.CompositeKeyField: + description: |- + CompositeKeyField names one sibling component of a composite-key + reference lookup. + properties: + c1Field: + description: |- + C1 API field name on the parent message (snake_case proto + field). The collector reads the runtime value at this path. + type: string + tfField: + description: |- + Attribute name in the Terraform data source's `refs[]` struct. + Usually identical to c1_field (the conductorone provider + matches them 1:1 today). Distinct fields anyway so a future + provider rename is wire-safe — no migration needed. + type: string + title: Composite Key Field + type: object + x-speakeasy-name-override: CompositeKeyField + c1.api.terraform_export.v1.CompositeKeyFieldSet: + description: |- + CompositeKeyFieldSet groups a non-empty set of composite-key + fields as declared by one or more consumer reference sites that + target the same Terraform type. Used in `TFSchemaMapping + .referer_shapes` (the "inverted index" of composite-key shapes + targeting this kind) so a multi-root producer can register + canonical lookup keys for every shape its consumers might + compute. + + Invariant: `fields` MUST be non-empty. The bare-id (single-id) + form is implicit — every producer registers under + `canonicalRefKey(id, {})` unconditionally, and consumer sites + with empty composite_key_fields are not represented here. The + backend's inverted-index computation skips them; including an + empty `fields` would just round-trip to the bare-id form and + produce a duplicate registration. + properties: + fields: + description: The fields field. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' + type: + - array + - "null" + title: Composite Key Field Set + type: object + x-speakeasy-name-override: CompositeKeyFieldSet + c1.api.terraform_export.v1.EnumValue: + description: EnumValue is one declared variant of a proto enum. + properties: + name: + description: |- + Full proto enum value name (e.g. "POLICY_TYPE_GRANT"). The + conductorone provider accepts this verbatim as a quoted-string HCL + literal. + type: string + number: + description: |- + Proto enum number — the value on the wire (e.g. 1 for + POLICY_TYPE_GRANT). + format: int32 + type: integer + title: Enum Value + type: object + x-speakeasy-name-override: EnumValue + c1.api.terraform_export.v1.GetSchemaResponse: + description: The GetSchemaResponse message. + properties: + schema: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping' + - type: "null" + title: Get Schema Response + type: object + x-speakeasy-name-override: GetSchemaResponse + c1.api.terraform_export.v1.ImportIDShape: + description: | + ImportIDShape describes the structure of the `id` value in a + Terraform `import { to = ..., id = "..." }` block. Most resources use + a single string; binding-style resources (App_Owner, + App_Entitlement_Owner, …) use a composite of multiple field values. + + This message contains a oneof named shape. Only a single field of the following list may be set at a time: + - singleString + - composite + properties: + composite: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.Composite' + - type: "null" + singleString: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.SingleString' + - type: "null" + title: Import Id Shape + type: object + x-speakeasy-name-override: ImportIDShape + c1.api.terraform_export.v1.ImportIDShape.Composite: + description: |- + Composite import IDs combine values from multiple component fields + per the declared `format`. + properties: + fields: + description: |- + Component fields, in the order they participate in the import + ID. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.CompositeField' + type: + - array + - "null" + format: + description: |- + Wire format the provider expects. Defaults to + FORMAT_JSON_OBJECT. + enum: + - FORMAT_JSON_OBJECT + - FORMAT_COLON_SEPARATED + - FORMAT_UNDERSCORE_SEPARATED + type: string + x-speakeasy-unknown-values: allow + title: Composite + type: object + x-speakeasy-name-override: Composite + c1.api.terraform_export.v1.ImportIDShape.CompositeField: + description: CompositeField names one component of a composite import ID. + properties: + c1Field: + description: The C1 API field whose value supplies this component. + type: string + tfType: + description: The TF attribute type of the component value. + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + title: Composite Field + type: object + x-speakeasy-name-override: CompositeField + c1.api.terraform_export.v1.ImportIDShape.SingleString: + description: Single-string import IDs use the resource's id value verbatim. + title: Single String + type: object + x-speakeasy-name-override: SingleString + c1.api.terraform_export.v1.TFFieldMapping: + description: |- + TFFieldMapping describes how one field of a C1 API object maps to one + attribute of a Terraform block. + properties: + c1Field: + description: The C1 API field name (proto field name, snake_case). + type: string + computed: + description: |- + Whether the server populates this field. A field that is + `computed` and neither `optional` nor `required` is server-only — + do not emit it in user-authored HCL. + type: boolean + elementTfType: + description: |- + For collection fields (list/set/tuple/map) whose elements are + primitives (string/number/bool), the TF type of those elements. + TF_TYPE_UNSPECIFIED for non-collection fields and for collections + of objects (where `nested_fields` describes the element shape). + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + enumValues: + description: |- + Declared variants for fields whose C1-side proto type is an enum. + Empty for non-enum fields. The conductorone provider accepts the + full proto enum name as a quoted string (e.g. + `policy_type = "POLICY_TYPE_GRANT"`); emit `EnumValue.name` as the + literal value. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.EnumValue' + type: + - array + - "null" + nestedFields: + description: |- + For object-typed fields and list/set/tuple fields whose elements + are objects, the shape of the nested attributes. Empty for + primitive scalars and primitive-element collections. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' + type: + - array + - "null" + oneofField: + description: |- + When this Terraform attribute corresponds to one variant of a + proto `oneof`, `oneof_field` names the proto oneof and + `oneof_variant` names the active case. Both unset for regular + (non-oneof) fields, which is the common case. + + Example: a oneof `target` with variant `automation` on message + `Action` exposed as the TF attribute `action_target_automation`: + + oneof_field = "target" + oneof_variant = "automation" + type: string + oneofVariant: + description: The oneofVariant field. + type: string + optional: + description: |- + Whether the user may supply this field. May co-occur with + `computed` (i.e. either the user or the server can set the value). + type: boolean + references: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFReference' + - type: "null" + required: + description: Whether the user must supply this field in HCL. + type: boolean + sensitive: + description: |- + Whether the value is a secret. Sensitive values must not be + rendered verbatim; emit a placeholder so callers wire the value + through a Terraform variable or vault data source. + type: boolean + tfField: + description: |- + The Terraform attribute name. Usually matches c1_field but may + differ in casing or pluralization. + type: string + tfType: + description: |- + The Terraform attribute type. For collections of structured + objects, the element shape is in `nested_fields`. For collections + of primitives, the element type is in `element_tf_type`. + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + title: Tf Field Mapping + type: object + x-speakeasy-name-override: TFFieldMapping + c1.api.terraform_export.v1.TFReference: + description: |- + TFReference describes the Terraform type(s) an ID-shaped field may + reference, plus any sibling fields needed to disambiguate a + composite-key lookup. + + `tf_type_names` covers the polymorphic / preferred-default + dimension. `composite_key_fields` covers the multi-key dimension — + some referents can't be resolved with a single id (every + `conductorone_app_entitlement` lookup needs `(app_id, id)`, + every `conductorone_app_entitlement_user_binding` needs three + keys, etc.). + properties: + compositeKeyFields: + description: |- + Sibling fields on the SAME parent message whose runtime values + must be paired with this reference's id to look the referent up + via its Terraform data source. + + Examples (each entry's c1_field is the C1 proto field name on + the parent message; tf_field is the attribute name in the data + source's `refs[]` struct): + + `AppEntitlementAutomation.app_entitlement_id` → + `[{c1_field: "app_id", tf_field: "app_id"}]` (2 keys total) + + `AppEntitlementUserBinding.app_user_id` → + `[{c1_field: "app_id", tf_field: "app_id"}, + {c1_field: "app_entitlement_id", tf_field: "app_entitlement_id"}]` + (3 keys total) + + `AppResourceOwner.user_id` → + `[{c1_field: "app_id", tf_field: "app_id"}, + {c1_field: "app_resource_type_id", tf_field: "app_resource_type_id"}, + {c1_field: "app_resource_id", tf_field: "app_resource_id"}]` + (4 keys total) + + The reference id field itself is always emitted as `id` in the + data source's ref struct (provider convention) — it is NOT + re-listed here. + + Empty/unset means single-id lookup is sufficient (User, Policy, + App today). Mirrors `ImportIDShape.Composite.fields`'s + structured shape. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' + type: + - array + - "null" + tfTypeNames: + description: |- + Candidate Terraform types this field may reference. The first + entry is the preferred default when no other signal disambiguates. + Empty means the field is not a reference. + items: + type: string + type: + - array + - "null" + title: Tf Reference + type: object + x-speakeasy-name-override: TFReference + c1.api.terraform_export.v1.TFSchemaMapping: + description: | + TFSchemaMapping describes how to translate one C1 API object into a + single Terraform block. Variant-specific metadata (e.g. `import_id` for + resources) lives on the `block` oneof. + + This message contains a oneof named block. Only a single field of the following list may be set at a time: + - resource + - dataSource + properties: + dataSource: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.DataSource' + - type: "null" + fields: + description: |- + Per-attribute mapping. Order matches the provider schema; preserve + it when emitting for stable output. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' + type: + - array + - "null" + providerVersion: + description: |- + The conductorone provider version this schema was derived from + (e.g. "1.0.40"). + type: string + refererShapes: + description: |- + The set of distinct composite-key-field shapes that consumers + declare when referencing this target via a TFReference. Used by + the FE multi-root producer to enumerate canonical lookup keys for + its `addressByImportId` registration so cross-root references + collapse correctly to direct expressions regardless of which + consumer site does the lookup. + + Each entry is one distinct shape (one `CompositeKeyFieldSet` + with non-empty `fields`). The single-id (bare-id) form is + implicit and is NOT represented here — every producer registers + under `canonicalRefKey(id, {})` unconditionally as a baseline. + + Computed at schema-load time from `references_table.go` by + grouping consumer-site `composite_key_fields` declarations + by target tf_type and de-duplicating distinct shapes. Targets + with no composite-key consumers (User, Policy, App today) + ship an empty list. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyFieldSet' + type: + - array + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.Resource' + - type: "null" + tfTypeName: + description: |- + The Terraform type identifier — the string immediately after the + `resource` or `data` keyword in HCL (e.g. "conductorone_app"). + type: string + title: Tf Schema Mapping + type: object + x-speakeasy-name-override: TFSchemaMapping + c1.api.terraform_export.v1.TFSchemaMapping.DataSource: + description: |- + Data-source-specific schema metadata. Reserved for future use; empty + in v1. + title: Data Source + type: object + x-speakeasy-name-override: DataSource + c1.api.terraform_export.v1.TFSchemaMapping.Resource: + description: Resource-specific schema metadata. + properties: + importId: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape' + - type: "null" + title: Resource + type: object + x-speakeasy-name-override: Resource + c1.api.user.v1.ExpiringUserDelegationBinding: + description: The ExpiringUserDelegationBinding message. + properties: + createdAt: + format: date-time + type: + - string + - "null" + delegatedUserId: + description: The delegatedUserId field. + type: string + deletedAt: + format: date-time + type: + - string + - "null" + expirationAt: + format: date-time + type: + - string + - "null" + startAt: + format: date-time + type: + - string + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + userId: + description: The userId field. + type: string + title: Expiring User Delegation Binding + type: object + x-speakeasy-name-override: ExpiringUserDelegationBinding + c1.api.user.v1.GetUserProfileTypesResponse: + description: GetUserProfileTypesResponse is the response containing the profile types for a user. + properties: + profileTypes: + description: The list of profile types associated with the user across their connected apps. + items: + $ref: '#/components/schemas/c1.api.profiletype.v1.ProfileType' + type: + - array + - "null" + title: Get User Profile Types Response + type: object + x-speakeasy-name-override: GetUserProfileTypesResponse + c1.api.user.v1.IntrospectRequest: + description: The IntrospectRequest message. + properties: + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' + - type: "null" + title: Introspect Request + type: object + x-speakeasy-name-override: UserIntrospectRequest + c1.api.user.v1.IntrospectResponse: + description: The IntrospectResponse message. + properties: + expanded: + description: The expanded field. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + userView: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserView' + - type: "null" + title: Introspect Response + type: object + x-speakeasy-name-override: UserIntrospectResponse + c1.api.user.v1.SearchUsersRequest: + description: Search for users based on some filters. + properties: + delegateStatus: + description: Filter for users based on their delegate status. + enum: + - DELEGATE_STATUS_UNSPECIFIED + - DELEGATE_STATUS_HAS_DELEGATE + - DELEGATE_STATUS_NO_DELEGATE + type: string + x-speakeasy-unknown-values: allow + delegatedUserIds: + description: Filter for users that have any of the delegated user IDs on this list. + items: + type: string + type: + - array + - "null" + departments: + description: Search for users that have any of the departments on this list. + items: + type: string + type: + - array + - "null" + email: + description: Search for users based on their email (exact match). + type: string + excludeIds: + description: An array of users IDs to exclude from the results. + items: + type: string + type: + - array + - "null" + excludeOrigins: + description: Filter to exclude users with these origins. + items: + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + excludeTypes: + description: An array of types to exclude from the results. + items: + enum: + - USER_TYPE_UNSPECIFIED + - USER_TYPE_SYSTEM + - USER_TYPE_HUMAN + - USER_TYPE_SERVICE + - USER_TYPE_AGENT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' + - type: "null" + ids: + description: Deprecated. Use refs array instead. + items: + type: string + type: + - array + - "null" + isDelegate: + description: Filter for users who are delegates of at least one other user. + type: boolean + jobTitles: + description: Search for users that have any of the job titles on this list. + items: + type: string + type: + - array + - "null" + managerIds: + description: Search for users that have any of the manager IDs on this list. + items: + type: string + type: + - array + - "null" + origins: + description: Filter to include only users with these origins. + items: + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + query: + description: Query the apps with a fuzzy search on display name and emails. + type: string + refs: + description: An array of user refs to restrict the return values to by ID. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + roleIds: + description: Search for users that have any of the role IDs on this list. + items: + type: string + type: + - array + - "null" + sourceAppIds: + description: |- + Filter to include only users sourced from any of these apps (directories). + Each value is an app ID; a user matches when its source_app_ids map + contains any of the listed app IDs. Combined with `origins` using OR. + items: + type: string + type: + - array + - "null" + userStatuses: + description: Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED + items: + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Search Users Request + type: object + x-speakeasy-name-override: SearchUsersRequest + c1.api.user.v1.SearchUsersResponse: + description: The SearchUsersResponse message. + properties: + expanded: + description: List of related objects + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request + items: + $ref: '#/components/schemas/c1.api.user.v1.UserView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: Search Users Response + type: object + x-speakeasy-name-override: SearchUsersResponse + c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput: + description: SetExpiringUserDelegationBindingByAdminRequest is the request for an admin to set a temporary delegation binding for a user. + properties: + delegatedUserId: + description: The ID of the user who will act as delegate. Empty string removes the delegation. + type: string + delegationExpireAt: + format: date-time + type: + - string + - "null" + delegationStartAt: + format: date-time + type: + - string + - "null" + title: Set Expiring User Delegation Binding By Admin Request + type: object + x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminRequest + c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse: + description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. + properties: + item: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.ExpiringUserDelegationBinding' + - type: "null" + title: Set Expiring User Delegation Binding By Admin Response + type: object + x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminResponse + c1.api.user.v1.User: + description: The User object provides all of the details for an user, as well as some configuration. + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + delegatedUserId: + description: The id of the user to whom tasks will be automatically reassigned to. + type: string + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + department: + description: The department which the user belongs to in the organization. + readOnly: true + type: string + departmentSources: + description: A list of objects mapped based on department attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + directoryIds: + description: A list of unique ids that represent different directories. + items: + type: string + readOnly: true + type: + - array + - "null" + directoryStatus: + description: The status of the user in the directory. + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + directoryStatusSources: + description: A list of objects mapped based on directoryStatus attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + displayName: + description: The display name of the user. + readOnly: true + type: string + email: + description: This is the user's email. + readOnly: true + type: string + emailSources: + description: A list of source data for the email attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + emails: + description: This is a list of all of the user's emails from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + employeeIdSources: + description: A list of source data for the employee IDs attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + employeeIds: + description: This is a list of all of the user's employee IDs from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + employmentStatus: + description: The users employment status. + readOnly: true + type: string + employmentStatusSources: + description: A list of objects mapped based on employmentStatus attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + employmentType: + description: The employment type of the user. + readOnly: true + type: string + employmentTypeSources: + description: A list of objects mapped based on employmentType attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + id: + description: A unique identifier of the user. + readOnly: true + type: string + jobTitle: + description: The job title of the user. + readOnly: true + type: string + jobTitleSources: + description: A list of objects mapped based on jobTitle attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + managerIds: + description: A list of ids of the user's managers. + items: + type: string + readOnly: true + type: + - array + - "null" + managerSources: + description: A list of objects mapped based on managerId attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + origin: + description: The origin of the user, describing who owns the user's lifecycle. + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + readOnly: true + type: string + x-speakeasy-unknown-values: allow + profile: + additionalProperties: true + readOnly: true + type: + - object + - "null" + roleIds: + description: A list of unique identifiers that maps to ConductorOne's user roles let you assign users permissions tailored to the work they do in the software. + items: + type: string + type: + - array + - "null" + status: + description: The status of the user in the system. + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + type: string + x-speakeasy-unknown-values: allow + type: + description: The type of the user. + enum: + - USER_TYPE_UNSPECIFIED + - USER_TYPE_SYSTEM + - USER_TYPE_HUMAN + - USER_TYPE_SERVICE + - USER_TYPE_AGENT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + username: + description: This is the user's primary username. Typically sourced from the primary directory. + readOnly: true + type: string + usernameSources: + description: A list of source data for the usernames attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + usernames: + description: This is a list of all of the user's usernames from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + title: User + type: object + x-speakeasy-name-override: User + c1.api.user.v1.UserAttributeMappingSource: + description: The UserAttributeMappingSource message. + properties: + appId: + description: The appId field. + type: string + appUserId: + description: The appUserId field. + type: string + appUserProfileAttributeKey: + description: The appUserProfileAttributeKey field. + type: string + priority: + description: Lower number = higher precedence; sources[0] is the winning source. + format: uint32 + readOnly: true + type: integer + userAttributeMappingId: + description: The userAttributeMappingId field. + type: string + value: + description: The value field. + type: string + title: User Attribute Mapping Source + type: object + x-speakeasy-name-override: UserAttributeMappingSource + c1.api.user.v1.UserExpandMask: + description: |- + The user expand mask is used to indicate which related objects should be expanded in the response. + The supported paths are 'role_ids', 'manager_ids', 'delegated_user_id', 'directory_ids', and '*'. + properties: + paths: + description: An array of paths to be expanded in the response. + items: + type: string + type: + - array + - "null" + title: User Expand Mask + type: object + x-speakeasy-name-override: UserExpandMask + c1.api.user.v1.UserRef: + description: A reference to a user. + properties: + id: + description: The id of the user. + type: string + title: User Ref + type: object + x-speakeasy-name-override: UserRef + c1.api.user.v1.UserServiceGetResponse: + description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + userView: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserView' + - type: "null" + title: User Service Get Response + type: object + x-speakeasy-name-override: UserServiceGetResponse + c1.api.user.v1.UserServiceListResponse: + description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request + items: + $ref: '#/components/schemas/c1.api.user.v1.UserView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: User Service List Response + type: object + x-speakeasy-name-override: UserServiceListResponse + c1.api.user.v1.UserView: + description: The UserView object provides a user response object, as well as JSONPATHs to related objects provided by expanders. + properties: + delegatedUserPath: + description: JSONPATH expression indicating the location of the user objects of delegates of the current user in the expanded array. + readOnly: true + type: string + directoriesPath: + description: JSONPATH expression indicating the location of directory objects in the expanded array. + readOnly: true + type: string + managersPath: + description: JSONPATH expression indicating the location of the user objects that managed the current user in the expanded array. + readOnly: true + type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + rolesPath: + description: JSONPATH expression indicating the location of the roles of the current user in the expanded array. + readOnly: true + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + userId: + description: The id of the user. + readOnly: true + type: string + title: User View + type: object + x-speakeasy-name-override: UserView + c1.api.user.v2.CreateUserEntitlementOwnerRequestInput: + description: CreateUserEntitlementOwnerRequest is the request for creating an entitlement ownership source on a user (service account). + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create User Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateUserEntitlementOwnerRequest + c1.api.user.v2.CreateUserEntitlementOwnerResponse: + description: CreateUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on a user (service account). + properties: + userOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' + - type: "null" + title: Create User Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateUserEntitlementOwnerResponse + c1.api.user.v2.CreateUserUserOwnerRequestInput: + description: CreateUserUserOwnerRequest is the request for creating a user ownership source on a user (service account). + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create User User Owner Request + type: object + x-speakeasy-name-override: CreateUserUserOwnerRequest + c1.api.user.v2.CreateUserUserOwnerResponse: + description: CreateUserUserOwnerResponse is the response for creating a user ownership source on a user (service account). + properties: + userOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' + - type: "null" + title: Create User User Owner Response + type: object + x-speakeasy-name-override: CreateUserUserOwnerResponse + c1.api.user.v2.DeleteUserEntitlementOwnerRequestInput: + description: DeleteUserEntitlementOwnerRequest is the request for deleting an entitlement ownership source on a user (service account). + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete User Entitlement Owner Request + type: object + x-speakeasy-name-override: DeleteUserEntitlementOwnerRequest + c1.api.user.v2.DeleteUserEntitlementOwnerResponse: + description: DeleteUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a user (service account). + title: Delete User Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteUserEntitlementOwnerResponse + c1.api.user.v2.DeleteUserUserOwnerRequestInput: + description: DeleteUserUserOwnerRequest is the request for deleting a user ownership source on a user (service account). + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete User User Owner Request + type: object + x-speakeasy-name-override: DeleteUserUserOwnerRequest + c1.api.user.v2.DeleteUserUserOwnerResponse: + description: DeleteUserUserOwnerResponse is the empty response for deleting a user ownership source on a user (service account). + title: Delete User User Owner Response + type: object + x-speakeasy-name-override: DeleteUserUserOwnerResponse + c1.api.user.v2.SearchUserEntitlementOwnersResponse: + description: SearchUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on a user (service account). + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search User Entitlement Owners Response + type: object + x-speakeasy-name-override: SearchUserEntitlementOwnersResponse + c1.api.user.v2.SearchUserOwnersResponse: + description: SearchUserOwnersResponse is the response for searching user ownership sources on a user (service account). + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search User Owners Response + type: object + x-speakeasy-name-override: SearchUserOwnersResponse + c1.api.user.v2.SetUserOwnersV2RequestInput: + description: SetUserOwnersV2Request is the request for setting the owners of a user (service account) for a given role. + properties: + appEntitlementRefs: + description: The appEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + roleSlug: + description: The roleSlug field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set User Owners V 2 Request + type: object + x-speakeasy-name-override: SetUserOwnersV2Request + c1.api.user.v2.SetUserOwnersV2Response: + description: SetUserOwnersV2Response is the empty response for setting user owners. + title: Set User Owners V 2 Response + type: object + x-speakeasy-name-override: SetUserOwnersV2Response + c1.api.user.v2.UserOwnerEntitlement: + description: UserOwnerEntitlement represents an entitlement ownership source for a canonical User (a service account). + properties: + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + userId: + description: The userId field. + type: string + title: User Owner Entitlement + type: object + x-speakeasy-name-override: UserOwnerEntitlement + c1.api.user.v2.UserOwnerUser: + description: UserOwnerUser represents a user ownership source for a canonical User (a service account). + properties: + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + userId: + description: The userId field. + type: string + title: User Owner User + type: object + x-speakeasy-name-override: UserOwnerUser + c1.api.vault.v1.GroupAuthzVault: + description: GroupAuthzVault configures a vault that uses group-based authorization to control access to stored credentials. + title: Group Authz Vault + type: object + x-speakeasy-name-override: GroupAuthzVault + c1.api.vault.v1.MagicVault: + description: MagicVault configures a vault that grants time-limited credential access via magic links. + properties: + allowUnauthedViews: + description: Controls whether unauthenticated users can view credentials via a magic link. + type: boolean + allowedViews: + description: The maximum number of times a credential in this vault may be viewed. + format: uint32 + type: integer + title: Magic Vault + type: object + x-speakeasy-name-override: MagicVault + c1.api.vault.v1.Vault: + description: | + Vault represents an external secret storage integration used to store connector credentials securely. + + This message contains a oneof named vault. Only a single field of the following list may be set at a time: + - groupAuthzVault + - magicVault + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + credentialExpirationDuration: + format: duration + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A free-text description of the vault's purpose or configuration. + type: string + displayName: + description: The human-readable name of the vault. + type: string + groupAuthzVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' + - type: "null" + id: + description: The unique identifier of the vault. + type: string + magicVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Vault + type: object + x-speakeasy-entity: Vault + x-speakeasy-name-override: Vault + c1.api.vault.v1.VaultServiceCreateRequest: + description: | + VaultServiceCreateRequest is the request message for creating a new vault. + + This message contains a oneof named vault. Only a single field of the following list may be set at a time: + - groupAuthzVault + - magicVault + properties: + description: + description: A free-text description of the vault's purpose or configuration. + type: string + displayName: + description: The human-readable name for the new vault. + type: string + groupAuthzVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' + - type: "null" + magicVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + - type: "null" + ownerIds: + description: The IDs of users to assign as owners of this vault. + items: + type: string + type: + - array + - "null" + required: + - displayName + title: Vault Service Create Request + type: object + x-speakeasy-name-override: VaultServiceCreateRequest + c1.api.vault.v1.VaultServiceCreateResponse: + description: VaultServiceCreateResponse is the response message for creating a new vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Create Response + type: object + x-speakeasy-name-override: VaultServiceCreateResponse + c1.api.vault.v1.VaultServiceDeleteRequestInput: + description: VaultServiceDeleteRequest is the request message for deleting a vault. + title: Vault Service Delete Request + type: object + x-speakeasy-name-override: VaultServiceDeleteRequest + c1.api.vault.v1.VaultServiceDeleteResponse: + description: Empty response body. Status code indicates success. + title: Vault Service Delete Response + type: object + x-speakeasy-name-override: VaultServiceDeleteResponse + c1.api.vault.v1.VaultServiceGetResponse: + description: VaultServiceGetResponse is the response message containing the requested vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Get Response + type: object + x-speakeasy-name-override: VaultServiceGetResponse + c1.api.vault.v1.VaultServiceUpdateRequestInput: + description: The VaultServiceUpdateRequest message contains the vault object to update and a field mask to indicate which fields to update. + properties: + updateMask: + type: + - string + - "null" + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Update Request + type: object + x-speakeasy-name-override: VaultServiceUpdateRequest + c1.api.vault.v1.VaultServiceUpdateResponse: + description: VaultServiceUpdateResponse is the response message containing the updated vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Update Response + type: object + x-speakeasy-name-override: VaultServiceUpdateResponse + c1.api.webhooks.v1.Webhook: + description: The Webhook message. + properties: + callbackTimeout: + format: duration + type: + - string + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: An optional description of the webhook's purpose. + type: string + displayName: + description: The human-readable name of the webhook. + type: string + id: + description: The unique identifier of the webhook. + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + url: + description: The destination URL that receives event notification HTTP callbacks. + type: string + title: Webhook + type: object + x-speakeasy-entity: Webhook + x-speakeasy-name-override: WebhookEndpoint + c1.api.webhooks.v1.WebhookInstance: + description: The WebhookInstance message. + properties: + attempts: + description: The attempts field. + format: int32 + type: integer + completedAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + expiresAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The id field. + type: string + lastAttemptedAt: + format: date-time + readOnly: true + type: + - string + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource' + - type: "null" + spec: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSpec' + - type: "null" + state: + description: The state field. + enum: + - WEBHOOK_STATE_UNSPECIFIED + - WEBHOOK_STATE_PENDING + - WEBHOOK_STATE_RUNNING + - WEBHOOK_STATE_ERROR + - WEBHOOK_STATE_WAITING_CALLBACK + - WEBHOOK_STATE_PROCESS_RESPONSE + - WEBHOOK_STATE_SUCCESS + - WEBHOOK_STATE_FATAL_ERROR + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + webhookId: + description: The webhookId field. + type: string + title: Webhook Instance + type: object + x-speakeasy-name-override: WebhookInstance + c1.api.webhooks.v1.WebhookRef: + description: The WebhookRef message. + properties: + id: + description: The ID of the referenced webhook. + type: string + title: Webhook Ref + type: object + x-speakeasy-name-override: WebhookRef + c1.api.webhooks.v1.WebhookSource: + description: | + The WebhookSource message. + + This message contains a oneof named source. Only a single field of the following list may be set at a time: + - test + - policyPostAction + - approvalStep + - provisionStep + - workflowStep + properties: + approvalStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep' + - type: "null" + policyPostAction: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction' + - type: "null" + provisionStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep' + - type: "null" + test: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceTest' + - type: "null" + workflowStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep' + - type: "null" + title: Webhook Source + type: object + x-speakeasy-name-override: WebhookSource + c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep: + description: The WebhookSourceApprovalStep message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Approval Step + type: object + x-speakeasy-name-override: WebhookSourceApprovalStep + c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction: + description: The WebhookSourcePolicyPostAction message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Policy Post Action + type: object + x-speakeasy-name-override: WebhookSourcePolicyPostAction + c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep: + description: The WebhookSourceProvisionStep message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Provision Step + type: object + x-speakeasy-name-override: WebhookSourceProvisionStep + c1.api.webhooks.v1.WebhookSource.WebhookSourceTest: + description: The WebhookSourceTest message. + title: Webhook Source Test + type: object + x-speakeasy-name-override: WebhookSourceTest + c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep: + description: The WebhookSourceWorkflowStep message. + properties: + workflowExecutionId: + description: The workflowExecutionId field. + format: int64 + type: string + workflowStepId: + description: The workflowStepId field. + type: string + title: Webhook Source Workflow Step + type: object + x-speakeasy-name-override: WebhookSourceWorkflowStep + c1.api.webhooks.v1.WebhookSpec: + description: The WebhookSpec message. + properties: + destination: + description: The destination field. + type: string + title: Webhook Spec + type: object + x-speakeasy-name-override: WebhookSpec + c1.api.webhooks.v1.WebhooksSearchRequest: + description: The WebhooksSearchRequest message. + properties: + pageSize: + description: The maximum number of webhooks to return per page. + format: int32 + type: integer + pageToken: + description: The pagination token from a previous search response to fetch the next page. + type: string + query: + description: A text query to match against webhook names and descriptions. + type: string + refs: + description: Optional set of webhook references to restrict the search to specific webhooks. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookRef' + type: + - array + - "null" + title: Webhooks Search Request + type: object + x-speakeasy-name-override: WebhooksSearchRequest + c1.api.webhooks.v1.WebhooksSearchResponse: + description: The WebhooksSearchResponse message. + properties: + list: + description: The list of webhooks matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Webhooks Search Response + type: object + x-speakeasy-name-override: WebhooksSearchResponse + c1.api.webhooks.v1.WebhooksServiceCreateRequest: + description: The WebhooksServiceCreateRequest message. + properties: + callbackTimeout: + format: duration + type: + - string + - "null" + description: + description: An optional description of the webhook's purpose. + type: string + displayName: + description: The human-readable name for the new webhook. + type: string + url: + description: The destination URL that will receive event notification HTTP callbacks. + type: string + required: + - displayName + - url + title: Webhooks Service Create Request + type: object + x-speakeasy-name-override: WebhooksServiceCreateRequest + c1.api.webhooks.v1.WebhooksServiceCreateResponse: + description: The WebhooksServiceCreateResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Create Response + type: object + x-speakeasy-name-override: WebhooksServiceCreateResponse + c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput: + description: The WebhooksServiceDeleteRequest message. + title: Webhooks Service Delete Request + type: object + x-speakeasy-name-override: WebhooksServiceDeleteRequest + c1.api.webhooks.v1.WebhooksServiceDeleteResponse: + description: Empty response body. Status code indicates success. + title: Webhooks Service Delete Response + type: object + x-speakeasy-name-override: WebhooksServiceDeleteResponse + c1.api.webhooks.v1.WebhooksServiceGetResponse: + description: The WebhooksServiceGetResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Get Response + type: object + x-speakeasy-name-override: WebhooksServiceGetResponse + c1.api.webhooks.v1.WebhooksServiceListResponse: + description: The WebhooksServiceListResponse message. + properties: + list: + description: The list of webhooks for the current page. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Webhooks Service List Response + type: object + x-speakeasy-name-override: WebhooksServiceListResponse + c1.api.webhooks.v1.WebhooksServiceTestRequestInput: + description: The WebhooksServiceTestRequest message. + title: Webhooks Service Test Request + type: object + x-speakeasy-name-override: WebhooksServiceTestRequest + c1.api.webhooks.v1.WebhooksServiceTestResponse: + description: The WebhooksServiceTestResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookInstance' + - type: "null" + title: Webhooks Service Test Response + type: object + x-speakeasy-name-override: WebhooksServiceTestResponse + c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput: + description: The WebhooksServiceUpdateRequest message contains the webhook object to update and a field mask to indicate which fields to update. It uses URL value for input. + properties: + updateMask: + type: + - string + - "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Update Request + type: object + x-speakeasy-name-override: WebhooksServiceUpdateRequest + c1.api.webhooks.v1.WebhooksServiceUpdateResponse: + description: The WebhooksServiceUpdateResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Update Response + type: object + x-speakeasy-name-override: WebhooksServiceUpdateResponse + c1.api.workload_federation.v1.OIDCSettings: + description: |- + OIDCSettings is the kind-specific configuration block for classic OIDC + providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, + any CUSTOM provider). Empty for now; future fields like custom_jwks_url, + audience overrides, and required_claims land here. + title: Oidc Settings + type: object + x-speakeasy-name-override: OIDCSettings + c1.api.workload_federation.v1.SPIFFESettings: + description: |- + SPIFFESettings is the kind-specific configuration block for SPIFFE + trust-domain providers (issuer_url = spiffe://). + properties: + bundleEndpointUrl: + description: |- + HTTPS URL of the JWKS endpoint serving the trust domain's signing keys. + Required: the spiffe:// scheme has no discovery mechanism. + Typically the SPIRE OIDC Discovery Provider's /keys endpoint. + + Mutable: updates re-validate the new URL by fetching its JWKS before + persisting; the issuer (trust domain) itself remains immutable. + type: string + title: Spiffe Settings + type: object + x-speakeasy-name-override: SPIFFESettings + c1.api.workload_federation.v1.TestTokenStepResult: + description: TestTokenStepResult represents the result of a single validation step. + properties: + actual: + description: Actual value from the token. + type: string + detail: + description: Human-readable detail message. + type: string + expected: + description: Expected value (for comparison steps). + type: string + passed: + description: Whether this step passed. + type: boolean + skipped: + description: Whether this step was skipped (e.g., CIDR check when no allowlist configured). + type: boolean + stepName: + description: Step name for display (e.g., "JWT decode", "Issuer match"). + type: string + title: Test Token Step Result + type: object + x-speakeasy-name-override: TestTokenStepResult + c1.api.workload_federation.v1.WorkloadFederationProvider: + description: | + WorkloadFederationProvider represents a tenant-level workload identity + issuer registration. Two issuer schemes are supported: + + - https://... classic OIDC issuer; `settings.oidc` MUST be set. + - spiffe://... SPIFFE trust-domain URI; `settings.spiffe` MUST be set. + + The (well_known_provider, issuer_url scheme, settings oneof) tuple is a + tri-invariant: SPIFFE wkp ⟺ spiffe:// issuer ⟺ settings.spiffe set; any + other wkp ⟺ https:// issuer ⟺ settings.oidc set. Issuer URLs are unique + within tenant. + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oidc + - spiffe + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A description of what this provider is for. + type: string + disabled: + description: Whether the provider is disabled. Disabled providers reject all token exchanges. + type: boolean + displayName: + description: The display name of the provider. + type: string + id: + description: The unique ID of the provider. + readOnly: true + type: string + issuerUrl: + description: |- + Canonical issuer URL. https:// for OIDC providers, spiffe:// for SPIFFE + trust domains. Unique within tenant. Immutable after creation. + readOnly: true + type: string + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' + - type: "null" + spiffe: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + wellKnownProvider: + description: |- + Well-known provider type. Drives UX (wizard presets, docs, icons). + Set at creation time, immutable. + enum: + - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED + - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM + - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS + - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI + - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM + - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND + - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + title: Workload Federation Provider + type: object + x-speakeasy-name-override: WorkloadFederationProvider + c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest: + description: | + The WorkloadFederationServiceCreateProviderRequest message. + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oidc + - spiffe + properties: + description: + description: A description of what this provider is for. + type: string + displayName: + description: The display name for the new provider. + type: string + issuerUrl: + description: |- + The issuer URL. For OIDC providers, this is an HTTPS URL validated via + OIDC discovery. For SPIFFE providers, this is the SPIFFE trust-domain URI + (e.g., spiffe://prod.example.com). Normalized on write: lowercase + scheme/host, no trailing slash. Unique within tenant. + type: string + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' + - type: "null" + spiffe: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' + - type: "null" + wellKnownProvider: + description: |- + Well-known provider type. Required -- UNSPECIFIED is rejected. + When set to a named source, the backend validates issuer_url consistency. + SPIFFE wkp requires `settings.spiffe`; all other wkp values require + `settings.oidc`. + enum: + - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED + - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM + - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS + - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI + - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM + - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND + - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE + type: string + x-speakeasy-unknown-values: allow + title: Workload Federation Service Create Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse: + description: The WorkloadFederationServiceCreateProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Create Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput: + description: The WorkloadFederationServiceCreateTrustRequest message. + properties: + allowSourceCidrs: + description: |- + IP allowlist for token exchange requests matching this trust. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + conditionExpression: + description: |- + CEL expression evaluated against JWT claims. Must return bool. + Compiled and validated before storage. + type: string + description: + description: A description of what this trust policy matches. + type: string + displayName: + description: The display name for the trust. + type: string + passthroughClaims: + description: JWT claim names from the subject token to copy into the issued C1 token. + items: + type: string + type: + - array + - "null" + providerId: + description: The provider this trust references. + type: string + scopedRoleIds: + description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + items: + type: string + type: + - array + - "null" + title: Workload Federation Service Create Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse: + description: The WorkloadFederationServiceCreateTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Create Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput: + description: The WorkloadFederationServiceDeleteProviderRequest message. + title: Workload Federation Service Delete Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse: + description: The WorkloadFederationServiceDeleteProviderResponse message. + title: Workload Federation Service Delete Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput: + description: The WorkloadFederationServiceDeleteTrustRequest message. + title: Workload Federation Service Delete Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse: + description: The WorkloadFederationServiceDeleteTrustResponse message. + title: Workload Federation Service Delete Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse: + description: The WorkloadFederationServiceGetProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Get Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceGetProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse: + description: The WorkloadFederationServiceGetTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Get Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceGetTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse: + description: The WorkloadFederationServiceListProvidersResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service List Providers Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceListProvidersResponse + c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse: + description: The WorkloadFederationServiceListTrustsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service List Trusts Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceListTrustsResponse + c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest: + description: The WorkloadFederationServiceSearchTrustsRequest message. + properties: + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + providerId: + description: 'Optional: filter trusts by provider ID.' + type: string + query: + description: 'Optional: full-text search on trust display name and description.' + type: string + servicePrincipalId: + description: 'Optional: filter trusts by service principal ID.' + type: string + title: Workload Federation Service Search Trusts Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsRequest + c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse: + description: The WorkloadFederationServiceSearchTrustsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service Search Trusts Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsResponse + c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest: + description: The WorkloadFederationServiceTestCELRequest message. + properties: + claimsJson: + description: |- + The claims to evaluate against, as a JSON string. + Parsed into map[string]any for CEL evaluation. + type: string + expression: + description: The CEL expression to evaluate. Must return bool. + type: string + title: Workload Federation Service Test Cel Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestCELRequest + c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse: + description: The WorkloadFederationServiceTestCELResponse message. + properties: + error: + description: Error message if compilation or evaluation failed. + type: string + expression: + description: The expression that was evaluated (echo back). + type: string + matched: + description: Whether the expression matched (returned true). + type: boolean + title: Workload Federation Service Test Cel Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestCELResponse + c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput: + description: The WorkloadFederationServiceTestTokenRequest message. + properties: + sourceIp: + description: |- + Optional: override source IP for CIDR testing. + If empty, uses the request's source IP. + Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. + type: string + subjectToken: + description: The raw JWT to validate (the subject_token from a CI job). + type: string + title: Workload Federation Service Test Token Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestTokenRequest + c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse: + description: The WorkloadFederationServiceTestTokenResponse message. + properties: + audienceValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + celEvaluation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + cidrCheck: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + decodedClaimsJson: + description: |- + The decoded JWT claims (best-effort, even if signature fails). + Returned as JSON string for display. + type: string + issuerMatch: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + jwtDecode: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + overallResult: + description: 'Overall result: true only if ALL steps passed.' + type: boolean + signatureValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + subjectValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + tokenFreshness: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + title: Workload Federation Service Test Token Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestTokenResponse + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput: + description: The WorkloadFederationServiceUpdateProviderRequest message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + updateMask: + type: + - string + - "null" + title: Workload Federation Service Update Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse: + description: The WorkloadFederationServiceUpdateProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Update Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput: + description: The WorkloadFederationServiceUpdateTrustRequest message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + updateMask: + type: + - string + - "null" + title: Workload Federation Service Update Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse: + description: The WorkloadFederationServiceUpdateTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Update Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustResponse + c1.api.workload_federation.v1.WorkloadFederationTrust: + description: |- + WorkloadFederationTrust represents a per-SP trust policy that references + a tenant-level provider and defines a CEL condition for claim matching. + properties: + allowSourceCidrs: + description: IP allowlist for token exchange requests matching this trust. + items: + type: string + type: + - array + - "null" + clientId: + description: |- + The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). + Used as the client_id parameter in RFC 8693 token exchange requests. + readOnly: true + type: string + conditionExpression: + description: |- + CEL expression evaluated against JWT claims. Must return bool. + Example: claims.sub.startsWith("repo:acme/infra:") && claims.environment == "production" + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A description of what this trust policy matches. + type: string + disabled: + description: Whether the trust is disabled. + type: boolean + displayName: + description: The display name of the trust. + type: string + passthroughClaims: + description: |- + JWT claim names from the subject token to copy into the issued C1 token. + Values are placed in the "c1wfc" claim as a map[string]string. + Only string-valued claims are copied; non-string claims are silently skipped. + Example: ["repository", "repository_owner", "job_workflow_ref"] + items: + type: string + type: + - array + - "null" + providerId: + description: The provider ID this trust references. Immutable after creation. + readOnly: true + type: string + scopedRoleIds: + description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + items: + type: string + type: + - array + - "null" + servicePrincipalId: + description: The service principal user ID this trust belongs to. + readOnly: true + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Workload Federation Trust + type: object + x-speakeasy-name-override: WorkloadFederationTrust + c1.mcp.role_mining.v1.AccessProfileMatch: + description: The AccessProfileMatch message. + properties: + catalogDisplayName: + description: The catalogDisplayName field. + type: string + catalogId: + description: The catalogId field. + type: string + matchType: + description: The matchType field. + enum: + - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED + - ACCESS_PROFILE_MATCH_TYPE_EXACT + - ACCESS_PROFILE_MATCH_TYPE_SUPERSET + - ACCESS_PROFILE_MATCH_TYPE_PARTIAL + type: string + x-speakeasy-unknown-values: allow + missingEntitlements: + description: The missingEntitlements field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + overlapRatio: + description: The overlapRatio field. + type: number + title: Access Profile Match + type: object + x-speakeasy-name-override: AccessProfileMatch + c1.mcp.role_mining.v1.AttributeFacet: + description: AttributeFacet represents a filterable user profile attribute with its available values. + properties: + attribute: + description: The attribute field. + type: string + displayName: + description: The displayName field. + type: string + values: + description: The values field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeValue' + type: + - array + - "null" + title: Attribute Facet + type: object + x-speakeasy-name-override: AttributeFacet + c1.mcp.role_mining.v1.AttributeValue: + description: AttributeValue represents a single value within a facet. + properties: + displayName: + description: The displayName field. + type: string + userCount: + description: The userCount field. + format: int32 + type: integer + value: + description: The value field. + type: string + title: Attribute Value + type: object + x-speakeasy-name-override: RoleMiningAttributeValue + c1.mcp.role_mining.v1.CohortEntitlement: + description: The CohortEntitlement message. + properties: + appDisplayName: + description: The appDisplayName field. + type: string + appId: + description: The appId field. + type: string + appResourceDisplayName: + description: The appResourceDisplayName field. + type: string + appResourceTypeDisplayName: + description: The appResourceTypeDisplayName field. + type: string + coverage: + description: The coverage field. + type: number + entitlementDisplayName: + description: The entitlementDisplayName field. + type: string + entitlementId: + description: The entitlementId field. + type: string + grantedCount: + description: The grantedCount field. + format: int32 + type: integer + riskLevelValueId: + description: The riskLevelValueId field. + type: string + title: Cohort Entitlement + type: object + x-speakeasy-name-override: CohortEntitlement + c1.mcp.role_mining.v1.EntitlementCluster: + description: The EntitlementCluster message. + properties: + avgCoverage: + description: The avgCoverage field. + type: number + avgSimilarity: + description: The avgSimilarity field. + type: number + entitlements: + description: The entitlements field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + userCount: + description: The userCount field. + format: int32 + type: integer + title: Entitlement Cluster + type: object + x-speakeasy-name-override: EntitlementCluster + c1.mcp.role_mining.v1.EntitlementCutoffImpactPoint: + description: |- + EntitlementCutoffImpactPoint reports the exact effect of an inclusive + entitlement coverage cutoff on the analyzed cohort. + properties: + entitlementCount: + description: Number of analyzed entitlements included at this cutoff. + format: int32 + type: integer + minimumCoverageBasisPoints: + description: Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. + format: int32 + type: integer + usersWithAllEntitlements: + description: Exact number of cohort users who hold every included entitlement. + format: int32 + type: integer + title: Entitlement Cutoff Impact Point + type: object + x-speakeasy-name-override: EntitlementCutoffImpactPoint + c1.mcp.role_mining.v1.ProfileFilter: + description: |- + ProfileFilter defines a filter on a user profile attribute. + Use GetOrgOverview to discover available attribute keys and their values. + properties: + attribute: + description: The attribute field. + type: string + values: + description: The values field. + items: + type: string + type: + - array + - "null" + title: Profile Filter + type: object + x-speakeasy-name-override: ProfileFilter + c1.models.funds.v1.Money: + description: |- + Money is wire-compatible with google.type.Money field-for-field, so the public + API converts with a field copy. Declared here rather than imported because + protoc-gen-pgdb mirrors a nested message by calling its generated DBReflect, + which only exists for messages this repo generates. + properties: + currencyCode: + description: ISO 4217 currency code. Must equal the tenant's FundPolicy.currency_code. + type: string + nanos: + description: |- + Nano-unit remainder, 0 <= nanos < 10^9. Non-negative for the same reason + as units, which also keeps the (units, nanos) pair unambiguous. + format: int32 + type: integer + units: + description: |- + Non-negative — grants, never debts — and bounded so units * 10^9 + nanos + always fits int64. Without the ceiling a large value wraps positive and + installs a limit nobody granted. The pair check spans two fields, so + pkg/funds re-checks it on every conversion. + format: int64 + type: string + title: Money + type: object + x-speakeasy-name-override: Money + c1.models.funds.v1.SpendControls: + description: |- + SpendControls is the one control shape carried by every authority scope. + Per-row resolution, identical everywhere: suspension present -> deny; + unexpired extension -> extension.limit; limit present -> limit; + otherwise this row states no opinion and resolution falls through. + + Not a oneof: two transitions need the losing field to survive. Unsuspending + restores the limit it froze, and a lapsed extension falls back to its base + rather than to the next layer. Pinned by + TestControlsCoPresenceSurvivesEveryTransition in pkg/funds. + properties: + extension: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendExtension' + - type: "null" + limit: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + period: + description: |- + Only valid together with limit: a period without its amount would + reinterpret some other layer's number in a cadence that layer never + agreed to. + enum: + - PERIOD_KIND_UNSPECIFIED + - PERIOD_KIND_DAILY + - PERIOD_KIND_WEEKLY + - PERIOD_KIND_MONTHLY + - PERIOD_KIND_QUARTERLY + - PERIOD_KIND_YEARLY + type: string + x-speakeasy-unknown-values: allow + suspension: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendSuspension' + - type: "null" + title: Spend Controls + type: object + x-speakeasy-name-override: SpendControls + c1.models.funds.v1.SpendExtension: + description: |- + SpendExtension replaces the row's total with a temporary one until + expires_at. It never changes the period, and it never expresses a refusal — + a temporary refusal is a SpendSuspension. + properties: + expiresAt: + format: date-time + type: + - string + - "null" + limit: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimit' + - type: "null" + reason: + description: |- + Subject-visible: "why do I have this bump". Mutation rationale rides the + history change_reason annotation instead. + type: string + title: Spend Extension + type: object + x-speakeasy-name-override: SpendExtension + c1.models.funds.v1.SpendLimit: + description: | + SpendLimit is the three-way behavior fork. Which arms are legal depends on the + scope carrying it; pkg/funds enforces that matrix, not the schema, because one + SpendControls shape is shared by every scope. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - unlimited + - amount + - blocked + properties: + amount: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimitAmount' + - type: "null" + blocked: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimitBlocked' + - type: "null" + unlimited: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.SpendLimitUnlimited' + - type: "null" + title: Spend Limit + type: object + x-speakeasy-name-override: SpendLimit + c1.models.funds.v1.SpendLimitAmount: + description: SpendLimitAmount caps spend at money per resolved period. + properties: + money: + oneOf: + - $ref: '#/components/schemas/c1.models.funds.v1.Money' + - type: "null" + title: Spend Limit Amount + type: object + x-speakeasy-name-override: SpendLimitAmount + c1.models.funds.v1.SpendLimitBlocked: + description: |- + SpendLimitBlocked refuses supply at this scope. Distinct from suspension: + blocked is a stated policy posture, suspension is a reversible freeze that + preserves the numbers underneath it. + title: Spend Limit Blocked + type: object + x-speakeasy-name-override: SpendLimitBlocked + c1.models.funds.v1.SpendLimitUnlimited: + description: |- + SpendLimitUnlimited is a tracking limit: full accounting, no admission + condition. The maximum element, so an unlimited default makes grant rules + no-ops. + title: Spend Limit Unlimited + type: object + x-speakeasy-name-override: SpendLimitUnlimited + c1.models.funds.v1.SpendSuspension: + description: |- + SpendSuspension freezes a scope without erasing the limit it must restore + on unsuspend, which is why it lives beside the SpendLimit oneof rather than + inside it. + properties: + reason: + description: The reason field. + type: string + suspendedAt: + format: date-time + type: + - string + - "null" + title: Spend Suspension + type: object + x-speakeasy-name-override: SpendSuspension + c1.webhooks.v1.Body: + description: The Body message. + properties: + callbackUrl: + description: |- + If your receiver returns HTTP Status Code 202 Accepted, it MUST send its resposne to this URL as a POST + message body. + + If your receiver returns any other status code, it is expected to not use the callback url. + + This value will match the "Webhook-Callback-Url" header. + type: string + event: + description: |- + The type of event that triggered this Webhook. + + This value will match the "Webhook-Event" header. + + The value will be one of: + - "c1.webhooks.v1.PayloadTest" + - "c1.webhooks.v1.PayloadPolicyApprovalStep" + - "c1.webhooks.v1.PayloadPolicyPostAction" + - "c1.webhooks.v1.PayloadProvisionStep" + type: string + payload: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: + - object + - "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook body will use a different string. + + This value will match the "Webhook-Version" header. + type: string + webhookId: + description: |- + Unique ID for this Webhook. Your receiver should only process this ID once. + + This value will match the "Webhook-Id" header. + type: string + title: Body + type: object + x-speakeasy-include: true + x-speakeasy-name-override: Body + c1.webhooks.v1.PayloadFindingDispatch: + description: The PayloadFindingDispatch message. + properties: + dispatchId: + description: The FindingDispatch row recording this execution. + type: string + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.Finding' + - type: "null" + findingId: + description: The finding that matched the routing rule. + type: string + payloadTemplate: + description: |- + The dispatcher's rendered payload template. Empty when the dispatcher used + the default finding payload. + type: string + ruleId: + description: The routing rule whose match caused this dispatch. + type: string + title: Payload Finding Dispatch + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadFindingDispatch + c1.webhooks.v1.PayloadPolicyApprovalStep: + description: The PayloadPolicyApprovalStep message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Policy Approval Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadPolicyApprovalStep + c1.webhooks.v1.PayloadPolicyPostAction: + description: The PayloadPolicyPostAction message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Policy Post Action + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadPolicyPostAction + c1.webhooks.v1.PayloadProvisionStep: + description: The PayloadProvisionStep message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Provision Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadProvisionStep + c1.webhooks.v1.PayloadTest: + description: The PayloadTest message. + title: Payload Test + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadTest + c1.webhooks.v1.PayloadWorkflowStep: + description: The PayloadWorkflowStep message. + properties: + context: + additionalProperties: true + type: + - object + - "null" + workflowExecutionId: + description: The workflow execution ID + format: int64 + type: string + workflowExecutionStepId: + description: The workflow execution step ID + type: string + workflowId: + description: The workflow template ID + type: string + title: Payload Workflow Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadWorkflowStep + c1.webhooks.v1.ResponsePolicyApprovalStep: + description: | + The ResponsePolicyApprovalStep message. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - approve + - deny + - reassign + - replacePolicy + properties: + approve: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove' + - type: "null" + deny: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny' + - type: "null" + reassign: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy' + - type: "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Policy Approval Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponsePolicyApprovalStep + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy: + description: The ResponsePolicyApprovalReplacePolicy message. + properties: + comment: + description: The comment field. + type: string + policySteps: + description: The policySteps field. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + type: + - array + - "null" + title: Response Policy Approval Replace Policy + type: object + x-speakeasy-name-override: ResponsePolicyApprovalReplacePolicy + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove: + description: The ResponsePolicyApprovalStepApprove message. + properties: + comment: + description: optional comment + type: string + title: Response Policy Approval Step Approve + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepApprove + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny: + description: The ResponsePolicyApprovalStepDeny message. + properties: + comment: + description: optional comment + type: string + title: Response Policy Approval Step Deny + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepDeny + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign: + description: The ResponsePolicyApprovalStepReassign message. + properties: + comment: + description: optional comment + type: string + newStepUserIds: + description: The newStepUserIds field. + items: + type: string + type: + - array + - "null" + title: Response Policy Approval Step Reassign + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepReassign + c1.webhooks.v1.ResponsePolicyPostAction: + description: The ResponsePolicyPostAction message. + properties: + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Policy Post Action + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponsePolicyPostAction + c1.webhooks.v1.ResponseProvisionStep: + description: | + The ResponseProvisionStep message. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - complete + - errored + properties: + complete: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete' + - type: "null" + errored: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored' + - type: "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Provision Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseProvisionStep + c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete: + description: The ResponseProvisionStepComplete message. + properties: + comment: + description: optional comment + type: string + title: Response Provision Step Complete + type: object + x-speakeasy-name-override: ResponseProvisionStepComplete + c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored: + description: The ResponseProvisionStepErrored message. + properties: + comment: + description: optional comment + type: string + title: Response Provision Step Errored + type: object + x-speakeasy-name-override: ResponseProvisionStepErrored + c1.webhooks.v1.ResponseTest: + description: The ResponseTest message. + properties: + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Test + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseTest + c1.webhooks.v1.ResponseWorkflowStep: + description: The ResponseWorkflowStep message. + properties: + context: + additionalProperties: true + type: + - object + - "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Workflow Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseWorkflowStep + google.rpc.Status: + description: |- + The `Status` type defines a logical error model that is suitable for + different programming environments, including REST APIs and RPC APIs. It is + used by [gRPC](https://github.com/grpc). Each `Status` message contains + three pieces of data: error code, error message, and error details. + + You can find out more about this error model and how to work with it in the + [API Design Guide](https://cloud.google.com/apis/design/errors). + properties: + code: + description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. + format: int32 + type: integer + details: + description: |- + A list of messages that carry the error details. There is a common set of + message types for APIs to use. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + message: + description: |- + A developer-facing error message, which should be in English. Any + user-facing error message should be localized and sent in the + [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. + type: string + title: Status + type: object + x-speakeasy-name-override: Status + validate.AnyRules: + description: |- + AnyRules describe constraints applied exclusively to the + `google.protobuf.Any` well-known type + properties: + in: + description: |- + In specifies that this field's `type_url` must be equal to one of the + specified values. + items: + type: string + type: + - array + - "null" + notIn: + description: |- + NotIn specifies that this field's `type_url` must not be equal to any of + the specified values. + items: + type: string + type: + - array + - "null" + required: + description: Required specifies that this field must be set + type: boolean + title: Any Rules + type: object + x-speakeasy-name-override: AnyRules + validate.BoolRules: + description: BoolRules describes the constraints applied to `bool` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: boolean + title: Bool Rules + type: object + x-speakeasy-name-override: BoolRules + validate.BytesRules: + description: | + BytesRules describe the constraints applied to `bytes` values + + This message contains a oneof named well_known. Only a single field of the following list may be set at a time: + - ip + - ipv4 + - ipv6 + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: base64 + type: string + contains: + description: |- + Contains specifies that this field must have the specified bytes + anywhere in the string. + format: base64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: base64 + type: string + type: + - array + - "null" + ip: + description: |- + Ip specifies that the field must be a valid IP (v4 or v6) address in + byte format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + ipv4: + description: |- + Ipv4 specifies that the field must be a valid IPv4 address in byte + format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + ipv6: + description: |- + Ipv6 specifies that the field must be a valid IPv6 address in byte + format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + len: + description: Len specifies that this field must be the specified number of bytes + format: uint64 + type: string + maxLen: + description: |- + MaxLen specifies that this field must be the specified number of bytes + at a maximum + format: uint64 + type: string + minLen: + description: |- + MinLen specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: base64 + type: string + type: + - array + - "null" + pattern: + description: |- + Pattern specifes that this field must match against the specified + regular expression (RE2 syntax). The included expression should elide + any delimiters. + type: string + prefix: + description: |- + Prefix specifies that this field must have the specified bytes at the + beginning of the string. + format: base64 + type: string + suffix: + description: |- + Suffix specifies that this field must have the specified bytes at the + end of the string. + format: base64 + type: string + title: Bytes Rules + type: object + x-speakeasy-name-override: BytesRules + validate.DoubleRules: + description: DoubleRules describes the constraints applied to `double` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: number + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + type: number + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + type: number + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + type: number + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + type: number + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + title: Double Rules + type: object + x-speakeasy-name-override: DoubleRules + validate.DurationRules: + description: |- + DurationRules describe the constraints applied exclusively to the + `google.protobuf.Duration` well-known type + properties: + const: + format: duration + type: + - string + - "null" + gt: + format: duration + type: + - string + - "null" + gte: + format: duration + type: + - string + - "null" + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: duration + type: string + type: + - array + - "null" + lt: + format: duration + type: + - string + - "null" + lte: + format: duration + type: + - string + - "null" + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: duration + type: string + type: + - array + - "null" + required: + description: Required specifies that this field must be set + type: boolean + title: Duration Rules + type: object + x-speakeasy-name-override: DurationRules + validate.EnumRules: + description: EnumRules describe the constraints applied to enum values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + definedOnly: + description: |- + DefinedOnly specifies that this field must be only one of the defined + values for this enum, failing on any undefined value. + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: Enum Rules + type: object + x-speakeasy-name-override: EnumRules + validate.FieldRules: + description: | + FieldRules encapsulates the rules for each type of field. Depending on the + field, the correct set should be used to ensure proper validations. + + This message contains a oneof named type. Only a single field of the following list may be set at a time: + - float + - double + - int32 + - int64 + - uint32 + - uint64 + - sint32 + - sint64 + - fixed32 + - fixed64 + - sfixed32 + - sfixed64 + - bool + - string + - bytes + - enum + - repeated + - map + - any + - duration + - timestamp + properties: + any: + oneOf: + - $ref: '#/components/schemas/validate.AnyRules' + - type: "null" + bool: + oneOf: + - $ref: '#/components/schemas/validate.BoolRules' + - type: "null" + bytes: + oneOf: + - $ref: '#/components/schemas/validate.BytesRules' + - type: "null" + double: + oneOf: + - $ref: '#/components/schemas/validate.DoubleRules' + - type: "null" + duration: + oneOf: + - $ref: '#/components/schemas/validate.DurationRules' + - type: "null" + enum: + oneOf: + - $ref: '#/components/schemas/validate.EnumRules' + - type: "null" + fixed32: + oneOf: + - $ref: '#/components/schemas/validate.Fixed32Rules' + - type: "null" + fixed64: + oneOf: + - $ref: '#/components/schemas/validate.Fixed64Rules' + - type: "null" + float: + oneOf: + - $ref: '#/components/schemas/validate.FloatRules' + - type: "null" + int32: + oneOf: + - $ref: '#/components/schemas/validate.Int32Rules' + - type: "null" + int64: + oneOf: + - $ref: '#/components/schemas/validate.Int64Rules' + - type: "null" + map: + oneOf: + - $ref: '#/components/schemas/validate.MapRules' + - type: "null" + message: + oneOf: + - $ref: '#/components/schemas/validate.MessageRules' + - type: "null" + repeated: + oneOf: + - $ref: '#/components/schemas/validate.RepeatedRules' + - type: "null" + sfixed32: + oneOf: + - $ref: '#/components/schemas/validate.SFixed32Rules' + - type: "null" + sfixed64: + oneOf: + - $ref: '#/components/schemas/validate.SFixed64Rules' + - type: "null" + sint32: + oneOf: + - $ref: '#/components/schemas/validate.SInt32Rules' + - type: "null" + sint64: + oneOf: + - $ref: '#/components/schemas/validate.SInt64Rules' + - type: "null" + string: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + timestamp: + oneOf: + - $ref: '#/components/schemas/validate.TimestampRules' + - type: "null" + uint32: + oneOf: + - $ref: '#/components/schemas/validate.UInt32Rules' + - type: "null" + uint64: + oneOf: + - $ref: '#/components/schemas/validate.UInt64Rules' + - type: "null" + title: Field Rules + type: object + x-speakeasy-name-override: FieldRules + validate.Fixed32Rules: + description: Fixed32Rules describes the constraints applied to `fixed32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + title: Fixed 32 Rules + type: object + x-speakeasy-name-override: Fixed32Rules + validate.Fixed64Rules: + description: Fixed64Rules describes the constraints applied to `fixed64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + title: Fixed 64 Rules + type: object + x-speakeasy-name-override: Fixed64Rules + validate.FloatRules: + description: FloatRules describes the constraints applied to `float` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: number + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + type: number + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + type: number + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + type: number + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + type: number + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + title: Float Rules + type: object + x-speakeasy-name-override: FloatRules + validate.Int32Rules: + description: Int32Rules describes the constraints applied to `int32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: Int 32 Rules + type: object + x-speakeasy-name-override: Int32Rules + validate.Int64Rules: + description: Int64Rules describes the constraints applied to `int64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: Int 64 Rules + type: object + x-speakeasy-name-override: Int64Rules + validate.MapRules: + description: MapRules describe the constraints applied to `map` values + properties: + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + keys: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + maxPairs: + description: |- + MaxPairs specifies that this field must have the specified number of + KVs at a maximum + format: uint64 + type: string + minPairs: + description: |- + MinPairs specifies that this field must have the specified number of + KVs at a minimum + format: uint64 + type: string + noSparse: + description: |- + NoSparse specifies values in this field cannot be unset. This only + applies to map's with message value types. + type: boolean + values: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + title: Map Rules + type: object + x-speakeasy-name-override: MapRules + validate.MessageRules: + description: |- + MessageRules describe the constraints applied to embedded message values. + For message-type fields, validation is performed recursively. + properties: + required: + description: Required specifies that this field must be set + type: boolean + skip: + description: |- + Skip specifies that the validation rules of this field should not be + evaluated + type: boolean + title: Message Rules + type: object + x-speakeasy-name-override: MessageRules + validate.RepeatedRules: + description: RepeatedRules describe the constraints applied to `repeated` values + properties: + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + items: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + maxItems: + description: |- + MaxItems specifies that this field must have the specified number of + items at a maximum + format: uint64 + type: string + minItems: + description: |- + MinItems specifies that this field must have the specified number of + items at a minimum + format: uint64 + type: string + unique: + description: |- + Unique specifies that all elements in this field must be unique. This + contraint is only applicable to scalar and enum types (messages are not + supported). + type: boolean + title: Repeated Rules + type: object + x-speakeasy-name-override: RepeatedRules + validate.SFixed32Rules: + description: SFixed32Rules describes the constraints applied to `sfixed32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: S Fixed 32 Rules + type: object + x-speakeasy-name-override: SFixed32Rules + validate.SFixed64Rules: + description: SFixed64Rules describes the constraints applied to `sfixed64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: S Fixed 64 Rules + type: object + x-speakeasy-name-override: SFixed64Rules + validate.SInt32Rules: + description: SInt32Rules describes the constraints applied to `sint32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: S Int 32 Rules + type: object + x-speakeasy-name-override: SInt32Rules + validate.SInt64Rules: + description: SInt64Rules describes the constraints applied to `sint64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: S Int 64 Rules + type: object + x-speakeasy-name-override: SInt64Rules + validate.StringRules: + description: | + StringRules describe the constraints applied to `string` values + + This message contains a oneof named well_known. Only a single field of the following list may be set at a time: + - email + - hostname + - ip + - ipv4 + - ipv6 + - uri + - uriRef + - address + - uuid + - wellKnownRegex + properties: + address: + description: |- + Address specifies that the field must be either a valid hostname as + defined by RFC 1034 (which does not support internationalized domain + names or IDNs), or it can be a valid IP (v4 or v6). + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + const: + description: Const specifies that this field must be exactly the specified value + type: string + contains: + description: |- + Contains specifies that this field must have the specified substring + anywhere in the string. + type: string + email: + description: |- + Email specifies that the field must be a valid email address as + defined by RFC 5322 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + hostname: + description: |- + Hostname specifies that the field must be a valid hostname as + defined by RFC 1034. This constraint does not support + internationalized domain names (IDNs). + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: string + type: + - array + - "null" + ip: + description: |- + Ip specifies that the field must be a valid IP (v4 or v6) address. + Valid IPv6 addresses should not include surrounding square brackets. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ipv4: + description: |- + Ipv4 specifies that the field must be a valid IPv4 address. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ipv6: + description: |- + Ipv6 specifies that the field must be a valid IPv6 address. Valid + IPv6 addresses should not include surrounding square brackets. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + len: + description: |- + Len specifies that this field must be the specified number of + characters (Unicode code points). Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + lenBytes: + description: |- + LenBytes specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + maxBytes: + description: |- + MaxBytes specifies that this field must be the specified number of bytes + at a maximum + format: uint64 + type: string + maxLen: + description: |- + MaxLen specifies that this field must be the specified number of + characters (Unicode code points) at a maximum. Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + minBytes: + description: |- + MinBytes specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + minLen: + description: |- + MinLen specifies that this field must be the specified number of + characters (Unicode code points) at a minimum. Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + notContains: + description: |- + NotContains specifies that this field cannot have the specified substring + anywhere in the string. + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: string + type: + - array + - "null" + pattern: + description: |- + Pattern specifes that this field must match against the specified + regular expression (RE2 syntax). The included expression should elide + any delimiters. + type: string + prefix: + description: |- + Prefix specifies that this field must have the specified substring at + the beginning of the string. + type: string + strict: + description: |- + This applies to regexes HTTP_HEADER_NAME and HTTP_HEADER_VALUE to enable + strict header validation. + By default, this is true, and HTTP header validations are RFC-compliant. + Setting to false will enable a looser validations that only disallows + \r\n\0 characters, which can be used to bypass header matching rules. + type: boolean + suffix: + description: |- + Suffix specifies that this field must have the specified substring at + the end of the string. + type: string + uri: + description: |- + Uri specifies that the field must be a valid, absolute URI as defined + by RFC 3986 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + uriRef: + description: |- + UriRef specifies that the field must be a valid URI as defined by RFC + 3986 and may be relative or absolute. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + uuid: + description: |- + Uuid specifies that the field must be a valid UUID as defined by + RFC 4122 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + wellKnownRegex: + description: |- + WellKnownRegex specifies a common well known pattern defined as a regex. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + enum: + - UNKNOWN + - HTTP_HEADER_NAME + - HTTP_HEADER_VALUE + type: + - string + - "null" + x-speakeasy-unknown-values: allow + title: String Rules + type: object + x-speakeasy-name-override: StringRules + validate.TimestampRules: + description: |- + TimestampRules describe the constraints applied exclusively to the + `google.protobuf.Timestamp` well-known type + properties: + const: + format: date-time + type: + - string + - "null" + gt: + format: date-time + type: + - string + - "null" + gtNow: + description: |- + GtNow specifies that this must be greater than the current time. GtNow + can only be used with the Within rule. + type: boolean + gte: + format: date-time + type: + - string + - "null" + lt: + format: date-time + type: + - string + - "null" + ltNow: + description: |- + LtNow specifies that this must be less than the current time. LtNow + can only be used with the Within rule. + type: boolean + lte: + format: date-time + type: + - string + - "null" + required: + description: Required specifies that this field must be set + type: boolean + within: + format: duration + type: + - string + - "null" + title: Timestamp Rules + type: object + x-speakeasy-name-override: TimestampRules + validate.UInt32Rules: + description: UInt32Rules describes the constraints applied to `uint32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + title: U Int 32 Rules + type: object + x-speakeasy-name-override: UInt32Rules + validate.UInt64Rules: + description: UInt64Rules describes the constraints applied to `uint64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + title: U Int 64 Rules + type: object + x-speakeasy-name-override: UInt64Rules + securitySchemes: + bearerAuth: + scheme: bearer + type: http + oauth: + description: |- + This API uses OAuth2 with the Client Credential flow. + Client Credentials must be sent in the BODY, not the headers. + For an example of how to implement this, refer to the [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187) function. + flows: + clientCredentials: + scopes: {} + tokenUrl: /auth/v1/token + type: oauth2 +info: + description: The C1 API is a HTTP API for managing C1 resources. + title: C1 API + version: 0.1.0-alpha +openapi: 3.1.0 +paths: + /api/v1/a2ui/conversations/{conversation_id}/surfaces: + get: + description: ListSurfaces returns active surfaces for a conversation. + operationId: c1.api.a2ui.v1.A2UIService.ListSurfaces + parameters: + - in: path + name: conversation_id + required: true + schema: + description: The conversationId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfacesResponse' + description: A2UIServiceListSurfacesResponse returns active surfaces. + summary: List Surfaces + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: ListSurfaces + /api/v1/a2ui/conversations/{conversation_id}/surfaces/{surface_id}/provenance: + get: + description: |- + GetSurfaceProvenance returns, in plain terms, what the surface's report + was built from: every record its program touched, in the order it touched + them. + operationId: c1.api.a2ui.v1.A2UIService.GetSurfaceProvenance + parameters: + - in: path + name: conversation_id + required: true + schema: + description: The conversationId field. + type: string + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceGetSurfaceProvenanceResponse' + description: |- + A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built + from: the steps its program ran, and the sources its components report. + summary: Get Surface Provenance + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: GetSurfaceProvenance + /api/v1/a2ui/surfaces/{surface_id}/actions: + post: + description: SubmitAction handles user actions on A2UI surfaces. + operationId: c1.api.a2ui.v1.A2UIService.SubmitAction + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionResponse' + description: A2UIServiceSubmitActionResponse returns the result of an action. + summary: Submit Action + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: SubmitAction + /api/v1/a2ui/surfaces/{surface_id}/feedback: + get: + description: ListSurfaceFeedback lists feedback for a surface. + operationId: c1.api.a2ui.v1.A2UIService.ListSurfaceFeedback + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfaceFeedbackResponse' + description: A2UIServiceListSurfaceFeedbackResponse returns feedback for a surface. + summary: List Surface Feedback + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: ListSurfaceFeedback + post: + description: CreateSurfaceFeedback submits feedback for a surface with a snapshot. + operationId: c1.api.a2ui.v1.A2UIService.CreateSurfaceFeedback + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackResponse' + description: A2UIServiceCreateSurfaceFeedbackResponse returns the created feedback. + summary: Create Surface Feedback + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: CreateSurfaceFeedback + /api/v1/access_review: + post: + description: Create creates a new access review campaign with the specified name, policy, and owners. + operationId: c1.api.accessreview.v1.AccessReviewService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#create + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Create + x-stability-level: draft + /api/v1/access_review/{access_review_id}/report: + get: + description: |- + List the generated reports for an access review campaign, each with a + time-limited download_url and its output format. + operationId: c1.api.accessreview.v1.AccessReviewReportService.List + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The accessReviewId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewReportServiceListResponse' + description: Successful response + summary: List + tags: + - Access Review + x-speakeasy-group: AccessReviewReport + x-speakeasy-name-override: List + x-stability-level: draft + post: + description: |- + Generate a report of the campaign's reviews and decisions. The format + defaults to JSON (also available: CSV, XLSX). Works on in-flight (OPEN) + and closed campaigns. Asynchronous — the report record is created + immediately; the file is materialized in the background. + operationId: c1.api.accessreview.v1.AccessReviewActionsService.GenerateReport + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The accessReviewId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewActionsServiceGenerateReportRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewActionsServiceGenerateReportResponse' + description: Successful response + summary: Generate Report + tags: + - Access Review + x-speakeasy-group: AccessReviewActions + x-speakeasy-name-override: GenerateReport + x-stability-level: draft + /api/v1/access_review/{access_review_id}/scope_and_entitlements: + get: + description: GetCampaignScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review campaign. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.GetCampaignScopeAndEntitlements + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to retrieve scope and entitlements for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + description: Successful response + summary: Get Campaign Scope And Entitlements + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Setup#read + terraform-resource: Access Review Setup#read + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: GetCampaignScopeAndEntitlements + x-stability-level: stable + post: + description: SetCampaignScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review campaign. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeAndEntitlements + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + description: Successful response + summary: Set Campaign Scope And Entitlements + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: + - Access Review Setup#create + - Access Review Setup#update + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: SetCampaignScopeAndEntitlements + x-stability-level: stable + /api/v1/access_review/{access_review_id}/scope_by_resource_type: + post: + description: SetCampaignScopeByResourceType sets the campaign scope by selecting specific resource types to include in the review. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeByResourceType + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeResponse' + description: Successful response + summary: Set Campaign Scope By Resource Type + tags: + - Access Review + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: SetCampaignScopeByResourceType + x-stability-level: draft + /api/v1/access_review/{id}: + delete: + description: Delete transitions an access review campaign to the deleted state, along with its dependent objects. + operationId: c1.api.accessreview.v1.AccessReviewService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review campaign to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#delete + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Delete + x-stability-level: draft + get: + description: Get retrieves a single access review campaign by ID. + operationId: c1.api.accessreview.v1.AccessReviewService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review campaign to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceGetResponse' + description: Successful response + summary: Get + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review#read + terraform-resource: Access Review#read + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Get + x-stability-level: draft + post: + description: Update modifies an existing access review campaign. Use the update_mask to specify which fields to change. + operationId: c1.api.accessreview.v1.AccessReviewService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of this access review campaign. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#update + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Update + x-stability-level: draft + /api/v1/access_review_template: + post: + description: Create creates a new access review template that defines a reusable configuration for launching campaigns. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#create + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Create + x-stability-level: draft + /api/v1/access_review_template/{access_review_template_id}/scope_and_entitlements: + get: + description: GetScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.GetScopeAndEntitlements + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to retrieve scope and entitlements for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + description: Successful response + summary: Get Scope And Entitlements + tags: + - Access Review Templates + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Template Setup#read + terraform-resource: Access Review Template Setup#read + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: GetScopeAndEntitlements + x-stability-level: stable + post: + description: SetScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeAndEntitlements + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + description: Successful response + summary: Set Scope And Entitlements + tags: + - Access Review Templates + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: + - Access Review Template Setup#create + - Access Review Template Setup#update + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: SetScopeAndEntitlements + x-stability-level: stable + /api/v1/access_review_template/{access_review_template_id}/scope_by_resource_type: + post: + description: SetScopeByResourceType sets the template scope by selecting specific resource types to include in campaigns created from this template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeByResourceType + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeResponse' + description: Successful response + summary: Set Scope By Resource Type + tags: + - Access Review Templates + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: SetScopeByResourceType + x-stability-level: draft + /api/v1/access_review_template/{id}: + delete: + description: Delete an access review template. The template can no longer be used to create campaigns. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review template to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#delete + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Delete + x-stability-level: draft + get: + description: Get retrieves a single access review template by ID. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review template to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceGetResponse' + description: Successful response + summary: Get + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Template#read + terraform-resource: Access Review Template#read + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Get + x-stability-level: draft + post: + description: Update modifies an existing access review template. Use the update_mask to specify which fields to change. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of this template. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#update + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Update + x-stability-level: draft + /api/v1/access_reviews: + get: + description: List returns a paginated list of access review campaigns. + operationId: c1.api.accessreview.v1.AccessReviewService.List + parameters: + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. Maximum 100. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Pagination token from a previous List response to fetch the next page. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceListResponse' + description: Successful response + summary: List + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Reviews#read + terraform-resource: Access Reviews#read + x-speakeasy-group: AccessReview + x-speakeasy-name-override: List + x-stability-level: draft + /api/v1/accessconflict: + post: + description: Create a new conflict monitor for defining a Separation of Duty rule. Entitlement sets are bound separately via AppEntitlementMonitorBindingService. + operationId: c1.api.accessconflict.v1.AccessConflictService.CreateMonitor + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Create Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#create + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: CreateMonitor + /api/v1/accessconflict/{id}: + delete: + description: Delete a conflict monitor and its associated entitlement set bindings. + operationId: c1.api.accessconflict.v1.AccessConflictService.DeleteMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteResponse' + description: The response message for deleting a conflict monitor. + summary: Delete Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#delete + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: DeleteMonitor + get: + description: Retrieve a single conflict monitor by ID. + operationId: c1.api.accessconflict.v1.AccessConflictService.GetMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Get Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Access_Conflict#read + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: GetMonitor + post: + description: Update the display name, description, or notification settings of a conflict monitor. + operationId: c1.api.accessconflict.v1.AccessConflictService.UpdateMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to update. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Update Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#update + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: UpdateMonitor + /api/v1/app_users/owned_service_accounts: + post: + description: |- + ListOwnedServiceAccounts returns the service accounts owned by the calling + user. The owner is the authenticated caller; it is not accepted as an input. + operationId: c1.api.app.v1.AppUserService.ListOwnedServiceAccounts + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsResponse' + description: Successful response + summary: List Owned Service Accounts + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListOwnedServiceAccounts + x-stability-level: draft + /api/v1/appentitlementmonitorbinding: + delete: + description: Remove an app entitlement from a conflict monitor's entitlement set. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.DeleteAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingResponse' + description: The response message for deleting an app entitlement monitor binding. + summary: Delete App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Monitor_Binding#delete + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: DeleteAppEntitlementMonitorBinding + post: + description: Bind an app entitlement to one side (A or B) of a conflict monitor. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.CreateAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.CreateAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' + description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. + summary: Create App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Monitor_Binding#create + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: CreateAppEntitlementMonitorBinding + /api/v1/appentitlementmonitorbinding/get: + post: + description: Retrieve a single binding that associates an app entitlement with one side of a conflict monitor. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.GetAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.GetAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' + description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. + summary: Get App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Entitlement_Monitor_Binding#read + terraform-resource: App_Entitlement_Monitor_Binding#read + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: GetAppEntitlementMonitorBinding + /api/v1/apps: + get: + description: List all apps. + operationId: c1.api.app.v1.Apps.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppsResponse' + description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App + x-speakeasy-group: Apps + x-speakeasy-name-override: List + post: + description: Create a new manual app without a connector. + operationId: c1.api.app.v1.Apps.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppResponse' + description: CreateAppResponse contains the newly created application. + summary: Create + tags: + - App + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App#create + x-speakeasy-group: Apps + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/access_request_defaults: + get: + description: Retrieve the current access request default settings for an app. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.GetAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to retrieve access request defaults for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Get App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: GetAppAccessRequestsDefaults + post: + description: Create or replace the access request default settings for an app. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CreateAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The app id for the app access request rule + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaultsInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Create App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: CreateAppAccessRequestsDefaults + /api/v1/apps/{app_id}/access_request_defaults/cancel: + post: + description: Cancel an in-progress apply operation for the app's access request defaults. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CancelAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app whose access request defaults apply operation should be cancelled. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CancelAccessRequestDefaultsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Cancel App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: CancelAppAccessRequestsDefaults + /api/v1/apps/{app_id}/app_users: + get: + description: List app user accounts within a specific app, with pagination support. + operationId: c1.api.app.v1.AppUserService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to list users for. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListResponse' + description: The response message for listing app users. + summary: List + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/app_users/{app_user_id}/credentials: + get: + description: List credentials associated with a specific app user account. + operationId: c1.api.app.v1.AppUserService.ListAppUserCredentials + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that the user belongs to. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The ID of the app user whose credentials to list. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListCredentialsResponse' + description: The response message for listing credentials of an app user. + summary: List App User Credentials + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListAppUserCredentials + /api/v1/apps/{app_id}/connectors: + get: + description: List connectors for an app. + operationId: c1.api.app.v1.ConnectorService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceListResponse' + description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable + summary: List + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: List + post: + description: Create a connector that is pending a connector config. + operationId: c1.api.app.v1.ConnectorService.CreateDelegated + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' + description: The ConnectorServiceCreateResponse is the response returned from creating a connector. + summary: Create Delegated + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: CreateDelegated + /api/v1/apps/{app_id}/connectors/{connector_id}/confirm_sync_valid/{sync_lifecycle_id}: + post: + description: Confirm that a sync which errored due to a data drop is valid, overriding the error and triggering a new sync. Only applicable when the sync status is ERRORED_NO_DATA. + operationId: c1.api.app.v1.ConnectorService.ConfirmSyncValid + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are confirming the sync for. + type: string + - in: path + name: sync_lifecycle_id + required: true + schema: + description: The completed lifecycle id of the most recent sync we want to validate + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidResponse' + description: Empty response body. Status code indicates success. + summary: Confirm Sync Valid + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ConfirmSyncValid + /api/v1/apps/{app_id}/connectors/{connector_id}/credentials/{id}: + get: + description: Get credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.GetCredentials + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector that we are getting the credentials for. + type: string + - in: path + name: id + required: true + schema: + description: The id of the ConnectorCredential. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetCredentialsResponse' + description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. + summary: Get Credentials + tags: + - Connector + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: ConnectorCredential#read + terraform-resource: ConnectorCredential#read + x-speakeasy-group: Connector + x-speakeasy-name-override: GetCredentials + post: + description: Revoke credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.RevokeCredential + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector that we are revoking the credentials for. + type: string + - in: path + name: id + required: true + schema: + description: The id of the ConnectorCredential. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialResponse' + description: Empty response body. Status code indicates success. + summary: Revoke Credential + tags: + - Connector + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: ConnectorCredential#delete + x-speakeasy-group: Connector + x-speakeasy-name-override: RevokeCredential + /api/v1/apps/{app_id}/connectors/{connector_id}/force_sync: + post: + description: |- + Trigger an immediate sync for a connector. The sync is queued and may not start + instantly. Poll the connector's sync_status (or GetConnector) for progress; an empty + success response means the sync was accepted onto the queue, not that it has finished. + operationId: c1.api.app.v1.ConnectorService.ForceSync + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are forcing to sync. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ForceSyncRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ForceSyncResponse' + description: |- + Empty response body. Status code indicates success. Poll the connector sync status + for progress after ForceSync accepts the request. + summary: Force Sync + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ForceSync + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources: + get: + description: |- + List returns the MCP resources discovered for a single (app_id, + connector_id), paginated. To filter by kind or state, use Search. + operationId: c1.api.ai_governance.v1.MCPResourceService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceListResponse' + description: MCPResourceServiceListResponse returns a list of MCP resources. + summary: List + tags: + - MCP Resources + x-speakeasy-group: MCPResource + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/{id}: + get: + description: |- + Get retrieves a single discovered MCP resource by app_id + connector_id + + id, including its approval state, kind, URI or URI template, and bound + app_entitlement_id. + operationId: c1.api.ai_governance.v1.MCPResourceService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP resource. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceGetResponse' + description: MCPResourceServiceGetResponse returns a single MCP resource. + summary: Get + tags: + - MCP Resources + x-speakeasy-group: MCPResource + x-speakeasy-name-override: Get + post: + description: |- + Update modifies a resource's lifecycle state via update_mask. Set + resource.state = MCP_RESOURCE_STATE_APPROVED with update_mask "state" to + move it out of PENDING_REVIEW (or DISABLED to block it). Resource metadata + is discovery-owned and read-only. resource must include id, app_id, and + connector_id. + operationId: c1.api.ai_governance.v1.MCPResourceService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (app that owns the connector). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this MCP resource record. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceUpdateResponse' + description: MCPResourceServiceUpdateResponse returns the updated MCP resource. + summary: Update + tags: + - MCP Resources + x-speakeasy-group: MCPResource + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single MCP + resource — each entry is a snapshot plus who/when metadata. + operationId: c1.api.ai_governance.v1.MCPResourceService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP resource. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceListHistoryResponse' + description: MCPResourceServiceListHistoryResponse returns MCP resource history entries. + summary: List History + tags: + - MCP Resources + x-speakeasy-group: MCPResource + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/search: + post: + description: |- + Search returns a connector's MCP resources filtered by kind, state, or + text query. Filter on MCP_RESOURCE_STATE_PENDING_REVIEW to find resources + awaiting approval, then approve them with Update. + operationId: c1.api.ai_governance.v1.MCPResourceService.Search + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceSearchRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPResourceServiceSearchResponse' + description: MCPResourceServiceSearchResponse returns matching MCP resources. + summary: Search + tags: + - MCP Resources + x-speakeasy-group: MCPResource + x-speakeasy-name-override: Search + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools: + get: + description: |- + List returns the MCP tools discovered for a single (app_id, connector_id), + paginated. To filter by state, classification, or visibility, use Search. + operationId: c1.api.ai_governance.v1.MCPToolService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListResponse' + description: MCPToolServiceListResponse returns a list of MCP tools. + summary: List + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}: + delete: + description: |- + Delete soft-deletes an MCP tool. It reappears as PENDING_REVIEW if the + connector rediscovers it on the next sync. + operationId: c1.api.ai_governance.v1.MCPToolService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteResponse' + description: MCPToolServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Delete + get: + description: |- + Get retrieves a single discovered MCP tool by app_id + connector_id + id, + including its approval state, classification, visibility, input schema, and + bound app_entitlement_id. + operationId: c1.api.ai_governance.v1.MCPToolService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceGetResponse' + description: MCPToolServiceGetResponse returns a single MCP tool. + summary: Get + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Get + post: + description: |- + Update modifies an MCP tool's admin-editable fields via update_mask. This + is how a tool is approved: set tool.state = MCP_TOOL_STATE_APPROVED with + update_mask "state" to move it out of PENDING_REVIEW (or DISABLED to block + it). Editable paths: display_name, description, classification, state, + allowed_client_types, visibility. tool must include id, app_id, connector_id. + operationId: c1.api.ai_governance.v1.MCPToolService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (app that owns the connector). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this MCP tool record. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateResponse' + description: MCPToolServiceUpdateResponse returns the updated MCP tool. + summary: Update + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single MCP + tool — each entry is a snapshot plus who/when metadata. + operationId: c1.api.ai_governance.v1.MCPToolService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListHistoryResponse' + description: MCPToolServiceListHistoryResponse returns MCP tool history entries. + summary: List History + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/search: + post: + description: |- + Search returns a connector's MCP tools filtered by state, classification, + visibility, access-profile binding, or text query. Filter on + MCP_TOOL_STATE_PENDING_REVIEW to find tools awaiting approval, then approve + them with Update. + operationId: c1.api.ai_governance.v1.MCPToolService.Search + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchResponse' + description: MCPToolServiceSearchResponse returns matching MCP tools. + summary: Search + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Search + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets: + get: + description: |- + List returns the MCP toolsets (access profiles) defined for a single + (app_id, connector_id), paginated. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceListResponse' + description: MCPAccessProfileServiceListResponse returns a list of MCP access profiles. + summary: List + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: List + post: + description: |- + Create creates a new MCP toolset (access profile) under a connector. The + backend also provisions a backing AppEntitlement that users request in + order to be granted the toolset's tools. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateResponse' + description: MCPAccessProfileServiceCreateResponse returns the created MCP access profile. + summary: Create + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings: + get: + description: |- + List returns the tool bindings for a single toolset (access profile) — + i.e. which MCP tools belong to the toolset — paginated. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListResponse' + description: MCPAccessProfileToolBindingServiceListResponse returns tool bindings. + summary: List + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: List + post: + description: CreateBindings adds one or more MCP tools (mcp_tool_ids) to a toolset. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.CreateBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateResponse' + description: MCPAccessProfileToolBindingServiceCreateResponse returns created bindings. + summary: Create Bindings + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: CreateBindings + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/delete: + post: + description: |- + DeleteBindings removes one or more MCP tools (mcp_tool_ids) from a toolset. + Uses a POST .../delete action route because the tool IDs travel in the + request body, which HTTP DELETE does not reliably support. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.DeleteBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. type: string - prefix: - description: |- - Prefix specifies that this field must have the specified substring at - the beginning of the string. + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. type: string - strict: - description: |- - This applies to regexes HTTP_HEADER_NAME and HTTP_HEADER_VALUE to enable - strict header validation. - By default, this is true, and HTTP header validations are RFC-compliant. - Setting to false will enable a looser validations that only disallows - \r\n\0 characters, which can be used to bypass header matching rules. - type: boolean - suffix: - description: |- - Suffix specifies that this field must have the specified substring at - the end of the string. + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. type: string - uri: - description: |- - Uri specifies that the field must be a valid, absolute URI as defined - by RFC 3986 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - type: - - boolean - - "null" - uriRef: - description: |- - UriRef specifies that the field must be a valid URI as defined by RFC - 3986 and may be relative or absolute. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - type: - - boolean - - "null" - uuid: - description: |- - Uuid specifies that the field must be a valid UUID as defined by - RFC 4122 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - type: - - boolean - - "null" - wellKnownRegex: - description: |- - WellKnownRegex specifies a common well known pattern defined as a regex. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - enum: - - UNKNOWN - - HTTP_HEADER_NAME - - HTTP_HEADER_VALUE - type: - - string - - "null" - x-speakeasy-unknown-values: allow - title: String Rules - type: object - x-speakeasy-name-override: StringRules - validate.TimestampRules: + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteResponse' + description: MCPAccessProfileToolBindingServiceDeleteResponse confirms deletion. + summary: Delete Bindings + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: DeleteBindings + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/history: + get: description: |- - TimestampRules describe the constraints applied exclusively to the - `google.protobuf.Timestamp` well-known type - properties: - const: - format: date-time - type: - - string - - "null" - gt: - format: date-time - type: - - string - - "null" - gtNow: - description: |- - GtNow specifies that this must be greater than the current time. GtNow - can only be used with the Within rule. - type: boolean - gte: - format: date-time - type: - - string - - "null" - lt: - format: date-time - type: - - string - - "null" - ltNow: - description: |- - LtNow specifies that this must be less than the current time. LtNow - can only be used with the Within rule. - type: boolean - lte: - format: date-time - type: - - string - - "null" - required: - description: Required specifies that this field must be set - type: boolean - within: - format: duration - type: - - string - - "null" - title: Timestamp Rules - type: object - x-speakeasy-name-override: TimestampRules - validate.UInt32Rules: - description: UInt32Rules describes the constraints applied to `uint32` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint32 - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint32 - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint32 - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint32 - type: integer - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint32 - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint32 - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint32 - type: integer - type: - - array - - "null" - title: U Int 32 Rules - type: object - x-speakeasy-name-override: UInt32Rules - validate.UInt64Rules: - description: UInt64Rules describes the constraints applied to `uint64` values - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint64 - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint64 + ListToolsByProfileHistory returns the transactional history of + tools bound to (app, connector, access_profile). Newest first. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListToolsByProfileHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint64 + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint64 - type: string - type: - - array - - "null" - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint64 + - in: path + name: access_profile_id + required: true + schema: + description: Toolset (access profile) identifier. type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint64 + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string - notIn: + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListToolsByProfileHistoryResponse' description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint64 - type: string - type: - - array - - "null" - title: U Int 64 Rules - type: object - x-speakeasy-name-override: UInt64Rules - securitySchemes: - bearerAuth: - scheme: bearer - type: http - oauth: + Contains a page of change-history entries for the tools bound to one toolset + sorted newest first. + summary: List Tools By Profile History + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: ListToolsByProfileHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{id}: + delete: description: |- - This API uses OAuth2 with the Client Credential flow. - Client Credentials must be sent in the BODY, not the headers. - For an example of how to implement this, refer to the [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187) function. - flows: - clientCredentials: - scopes: {} - tokenUrl: /auth/v1/token - type: oauth2 -info: - description: The C1 API is a HTTP API for managing C1 resources. - title: C1 API - version: 0.1.0-alpha -openapi: 3.1.0 -paths: - /api/v1/a2ui/conversations/{conversation_id}/surfaces: + Delete soft-deletes a toolset (access profile) and cascades to its tool + bindings and backing entitlement. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP access profile. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteResponse' + description: MCPAccessProfileServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Delete get: - description: ListSurfaces returns active surfaces for a conversation. - operationId: c1.api.a2ui.v1.A2UIService.ListSurfaces + description: |- + Get retrieves a single MCP toolset (access profile) by app_id + + connector_id + id, including its display name, description, linked + app_entitlement_id, and bound tool count. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Get parameters: - in: path - name: conversation_id + name: app_id required: true schema: - description: The conversationId field. + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP access profile. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfacesResponse' - description: A2UIServiceListSurfacesResponse returns active surfaces. - summary: List Surfaces + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetResponse' + description: MCPAccessProfileServiceGetResponse returns a single MCP access profile. + summary: Get tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: ListSurfaces - /api/v1/a2ui/surfaces/{surface_id}/actions: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Get post: - description: SubmitAction handles user actions on A2UI surfaces. - operationId: c1.api.a2ui.v1.A2UIService.SubmitAction + description: |- + Update modifies a toolset's admin-editable fields via update_mask. + Editable paths: display_name, description. profile must include id, + app_id, and connector_id. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Update parameters: - in: path - name: surface_id + name: app_id required: true schema: - description: The surfaceId field. + description: App identifier (app that owns the connector). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this access profile. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionResponse' - description: A2UIServiceSubmitActionResponse returns the result of an action. - summary: Submit Action + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateResponse' + description: MCPAccessProfileServiceUpdateResponse returns the updated MCP access profile. + summary: Update tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: SubmitAction - /api/v1/a2ui/surfaces/{surface_id}/feedback: - get: - description: ListSurfaceFeedback lists feedback for a surface. - operationId: c1.api.a2ui.v1.A2UIService.ListSurfaceFeedback + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/{connector_id}/pause: + post: + description: Pause syncing and provisioning for a connector. No new syncs or grant/revoke operations will run until the connector is resumed. + operationId: c1.api.app.v1.ConnectorService.PauseSync parameters: - in: path - name: surface_id + name: app_id required: true schema: - description: The surfaceId field. + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are pausing the sync for. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.PauseSyncRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfaceFeedbackResponse' - description: A2UIServiceListSurfaceFeedbackResponse returns feedback for a surface. - summary: List Surface Feedback + $ref: '#/components/schemas/c1.api.app.v1.PauseSyncResponse' + description: Empty response body. Status code indicates success. + summary: Pause Sync tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: ListSurfaceFeedback + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: PauseSync + /api/v1/apps/{app_id}/connectors/{connector_id}/resume: post: - description: CreateSurfaceFeedback submits feedback for a surface with a snapshot. - operationId: c1.api.a2ui.v1.A2UIService.CreateSurfaceFeedback + description: Resume syncing and provisioning for a connector that was previously paused. Clears the paused state and triggers a new sync. + operationId: c1.api.app.v1.ConnectorService.ResumeSync parameters: - in: path - name: surface_id + name: app_id required: true schema: - description: The surfaceId field. + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are resuming the sync for. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackResponse' - description: A2UIServiceCreateSurfaceFeedbackResponse returns the created feedback. - summary: Create Surface Feedback + $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncResponse' + description: Empty response body. Status code indicates success. + summary: Resume Sync tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: CreateSurfaceFeedback - /api/v1/access_review: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ResumeSync + /api/v1/apps/{app_id}/connectors/{connector_id}/schedule: post: - description: Create creates a new access review campaign with the specified name, policy, and owners. - operationId: c1.api.accessreview.v1.AccessReviewService.Create + description: Update the sync schedule for a connector. + operationId: c1.api.app.v1.ConnectorService.UpdateConnectorSchedule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector whose schedule is being updated. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateRequest' + $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleResponse' + description: Empty response body. Status code indicates success. + summary: Update Connector Schedule tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review#create - x-speakeasy-group: AccessReview - x-speakeasy-name-override: Create - x-stability-level: draft - /api/v1/access_review/{access_review_id}/scope_and_entitlements: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: UpdateConnectorSchedule + x-stability-level: alpha + /api/v1/apps/{app_id}/connectors/{connector_id}/syncs/{sync_id}/download_url: get: - description: GetCampaignScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review campaign. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.GetCampaignScopeAndEntitlements + description: GetConnectorSyncDownloadURL generates a short-lived download URL for a completed connector sync artifact. + operationId: c1.api.app.v1.ConnectorService.GetConnectorSyncDownloadURL parameters: - in: path - name: access_review_id + name: app_id required: true schema: - description: The ID of the access review campaign to retrieve scope and entitlements for. + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: sync_id + required: true + schema: + description: The syncId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + $ref: '#/components/schemas/c1.api.app.v1.GetConnectorSyncDownloadURLResponse' description: Successful response - summary: Get Campaign Scope And Entitlements + summary: Get Connector Sync Download Url tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Review Setup#read - terraform-resource: Access Review Setup#read - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: GetCampaignScopeAndEntitlements - x-stability-level: stable - post: - description: SetCampaignScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review campaign. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeAndEntitlements + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: GetConnectorSyncDownloadURL + /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tool/{mcp_tool_id}/history: + get: + description: |- + ListProfilesByToolHistory returns the transactional history of + profiles bound to (app, connector, mcp_tool). Newest first. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListProfilesByToolHistory parameters: - in: path - name: access_review_id + name: app_id required: true schema: - description: The ID of the access review campaign to configure. + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: mcp_tool_id + required: true + schema: + description: MCP tool identifier. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' - description: Successful response - summary: Set Campaign Scope And Entitlements + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListProfilesByToolHistoryResponse' + description: |- + Contains a page of change-history entries for the toolsets one tool has belonged to, + sorted newest first. + summary: List Profiles By Tool History tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: - - Access Review Setup#create - - Access Review Setup#update - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: SetCampaignScopeAndEntitlements - x-stability-level: stable - /api/v1/access_review/{access_review_id}/scope_by_resource_type: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: ListProfilesByToolHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tools: post: - description: SetCampaignScopeByResourceType sets the campaign scope by selecting specific resource types to include in the review. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeByResourceType + description: |- + GetAccessProfilesForTools returns the access profiles bound to each + of the given MCP tools, hydrated with display_name. Used by the tools + list to render the "toolset" column for visible rows. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.GetAccessProfilesForTools parameters: - in: path - name: access_review_id + name: app_id required: true schema: - description: The ID of the access review campaign to configure. + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeResponse' - description: Successful response - summary: Set Campaign Scope By Resource Type + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse' + description: |- + MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse returns + access profiles grouped by MCP tool. + summary: Get Access Profiles For Tools tags: - - Access Review - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: SetCampaignScopeByResourceType - x-stability-level: draft - /api/v1/access_review/{id}: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: GetAccessProfilesForTools + /api/v1/apps/{app_id}/connectors/{id}: delete: - description: Delete transitions an access review campaign to the deleted state, along with its dependent objects. - operationId: c1.api.accessreview.v1.AccessReviewService.Delete + description: Delete a connector. + operationId: c1.api.app.v1.ConnectorService.Delete parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string - in: path name: id required: true schema: - description: The ID of the access review campaign to delete. + description: The id of the connector. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteResponse' + description: Empty response body. Status code indicates success. summary: Delete tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review#delete - x-speakeasy-group: AccessReview + - Connector + x-speakeasy-group: Connector x-speakeasy-name-override: Delete - x-stability-level: draft get: - description: Get retrieves a single access review campaign by ID. - operationId: c1.api.accessreview.v1.AccessReviewService.Get + description: Get a connector. + operationId: c1.api.app.v1.ConnectorService.Get parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string - in: path name: id required: true schema: - description: The ID of the access review campaign to retrieve. + description: The id of the connector. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceGetResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetResponse' + description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. summary: Get tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Review#read - terraform-resource: Access Review#read - x-speakeasy-group: AccessReview + - Connector + x-speakeasy-group: Connector x-speakeasy-name-override: Get - x-stability-level: draft post: - description: Update modifies an existing access review campaign. Use the update_mask to specify which fields to change. - operationId: c1.api.accessreview.v1.AccessReviewService.Update + description: Update a connector. + operationId: c1.api.app.v1.ConnectorService.Update parameters: + - in: path + name: app_id + required: true + schema: + description: The id of the app the connector is associated with. + type: string - in: path name: id required: true schema: - description: The unique identifier of this access review campaign. + description: The id of the connector. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' + description: ConnectorServiceUpdateResponse is the response returned by the update method. summary: Update tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review#update - x-speakeasy-group: AccessReview + - Connector + x-speakeasy-group: Connector x-speakeasy-name-override: Update - x-stability-level: draft - /api/v1/access_review_template: + /api/v1/apps/{app_id}/connectors/create: post: - description: Create creates a new access review template that defines a reusable configuration for launching campaigns. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Create + description: Create a configured connector. + operationId: c1.api.app.v1.ConnectorService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateRequest' + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' + description: The ConnectorServiceCreateResponse is the response returned from creating a connector. summary: Create tags: - - Access Review Template - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review Template#create - x-speakeasy-group: AccessReviewTemplate + - Connector + x-speakeasy-group: Connector x-speakeasy-name-override: Create - x-stability-level: draft - /api/v1/access_review_template/{access_review_template_id}/scope_and_entitlements: + /api/v1/apps/{app_id}/entitlement_configuration_rules: get: - description: GetScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.GetScopeAndEntitlements + description: |- + ListAppEntitlementRoutingRules returns an application's entitlement + configuration rules in evaluation order, by priority then by ID. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules parameters: - in: path - name: access_review_template_id + name: app_id required: true schema: - description: The ID of the access review template to retrieve scope and entitlements for. + description: The appId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementRoutingRulesResponse' description: Successful response - summary: Get Scope And Entitlements + summary: List App Entitlement Routing Rules tags: - - Access Review Templates - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Review Template Setup#read - terraform-resource: Access Review Template Setup#read - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: GetScopeAndEntitlements - x-stability-level: stable + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: ListAppEntitlementRoutingRules post: - description: SetScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeAndEntitlements + description: |- + CreateAppEntitlementRoutingRule creates an entitlement configuration rule + for an application. Rules are evaluated in priority order and the first + rule whose condition matches supplies the entitlement's request settings. + An app can have at most 5 rules. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule parameters: - in: path - name: access_review_template_id + name: app_id required: true schema: - description: The ID of the access review template to configure. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleResponse' description: Successful response - summary: Set Scope And Entitlements + summary: Create App Entitlement Routing Rule tags: - - Access Review Templates - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: - - Access Review Template Setup#create - - Access Review Template Setup#update - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: SetScopeAndEntitlements - x-stability-level: stable - /api/v1/access_review_template/{access_review_template_id}/scope_by_resource_type: - post: - description: SetScopeByResourceType sets the template scope by selecting specific resource types to include in campaigns created from this template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeByResourceType + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: CreateAppEntitlementRoutingRule + /api/v1/apps/{app_id}/entitlement_configuration_rules/{id}: + delete: + description: |- + DeleteAppEntitlementRoutingRule deletes an entitlement configuration rule + by ID. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule parameters: - in: path - name: access_review_template_id + name: app_id required: true schema: - description: The ID of the access review template to configure. + description: The appId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeResponse' - description: Successful response - summary: Set Scope By Resource Type - tags: - - Access Review Templates - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: SetScopeByResourceType - x-stability-level: draft - /api/v1/access_review_template/{id}: - delete: - description: Delete an access review template. The template can no longer be used to create campaigns. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Delete - parameters: - in: path name: id required: true schema: - description: The ID of the access review template to delete. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleResponse' description: Successful response - summary: Delete + summary: Delete App Entitlement Routing Rule tags: - - Access Review Template - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review Template#delete - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Delete - x-stability-level: draft + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: DeleteAppEntitlementRoutingRule get: - description: Get retrieves a single access review template by ID. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Get + description: |- + GetAppEntitlementRoutingRule returns a single entitlement configuration + rule by ID. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string - in: path name: id required: true schema: - description: The ID of the access review template to retrieve. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceGetResponse' + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementRoutingRuleResponse' description: Successful response - summary: Get + summary: Get App Entitlement Routing Rule tags: - - Access Review Template - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Review Template#read - terraform-resource: Access Review Template#read - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Get - x-stability-level: draft + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: GetAppEntitlementRoutingRule post: - description: Update modifies an existing access review template. Use the update_mask to specify which fields to change. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Update + description: |- + Update an existing app entitlement configuration rule. The app_id field is + immutable; moving a rule between apps is modeled as delete + create. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.UpdateAppEntitlementRoutingRule parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string - in: path name: id required: true schema: - description: The unique identifier of this template. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateResponse' - description: Successful response - summary: Update - tags: - - Access Review Template - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review Template#update - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Update - x-stability-level: draft - /api/v1/access_reviews: - get: - description: List returns a paginated list of access review campaigns. - operationId: c1.api.accessreview.v1.AccessReviewService.List - parameters: - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. Maximum 100. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Pagination token from a previous List response to fetch the next page. - type: string + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceListResponse' + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleResponse' description: Successful response - summary: List + summary: Update App Entitlement Routing Rule tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Reviews#read - terraform-resource: Access Reviews#read - x-speakeasy-group: AccessReview - x-speakeasy-name-override: List - x-stability-level: draft - /api/v1/accessconflict: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: UpdateAppEntitlementRoutingRule + /api/v1/apps/{app_id}/entitlement_configuration_rules/reorder: post: - description: Create a new conflict monitor for defining a Separation of Duty rule. Entitlement sets are bound separately via AppEntitlementMonitorBindingService. - operationId: c1.api.accessconflict.v1.AccessConflictService.CreateMonitor - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorCreateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Create Monitor - tags: - - Access Conflict - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#create - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: CreateMonitor - /api/v1/accessconflict/{id}: - delete: - description: Delete a conflict monitor and its associated entitlement set bindings. - operationId: c1.api.accessconflict.v1.AccessConflictService.DeleteMonitor + description: |- + Reorder all configuration rules for an app in a single call. The caller + supplies the full ordered list of rule IDs; the server assigns dense + priorities (1..N) in that order. The request must be a permutation of every + active rule in the app — missing or extra IDs are rejected. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ReorderAppEntitlementRoutingRules parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the conflict monitor to delete. + description: The ID of the app whose rules should be reordered. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteResponse' - description: The response message for deleting a conflict monitor. - summary: Delete Monitor + $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesResponse' + description: Successful response + summary: Reorder App Entitlement Routing Rules tags: - - Access Conflict - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#delete - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: DeleteMonitor + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: ReorderAppEntitlementRoutingRules + /api/v1/apps/{app_id}/entitlements: get: - description: Retrieve a single conflict monitor by ID. - operationId: c1.api.accessconflict.v1.AccessConflictService.GetMonitor + description: |- + List app entitlements associated with an app. Query parameters are + accepted in snake_case (page_size, page_token, app_user_id) and, as a + compatibility shim, their camelCase equivalents (pageSize, pageToken, + appUserId). + operationId: c1.api.app.v1.AppEntitlements.List parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the conflict monitor to retrieve. + description: The appId field. + type: string + - in: query + name: app_user_id + schema: + description: Filter to entitlements granted to the given app user. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: q + schema: + description: Fuzzy search on display name and description. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Get Monitor + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List tags: - - Access Conflict - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Access_Conflict#read - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: GetMonitor + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: List post: - description: Update the display name, description, or notification settings of a conflict monitor. - operationId: c1.api.accessconflict.v1.AccessConflictService.UpdateMonitor + description: Create a new app entitlement for an app. This is used to define a custom permission, group, or role within the app. + operationId: c1.api.app.v1.AppEntitlements.Create parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the conflict monitor to update. + description: The ID of the app to create the entitlement in. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Update Monitor + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementResponse' + description: Successful response + summary: Create tags: - - Access Conflict + - App Entitlement x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#update - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: UpdateMonitor - /api/v1/app_users/owned_service_accounts: + terraform-resource: Custom App Entitlement#create + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/add-manual-user: post: description: |- - ListOwnedServiceAccounts returns the service accounts owned by the calling - user. The owner is the authenticated caller; it is not accepted as an input. - operationId: c1.api.app.v1.AppUserService.ListOwnedServiceAccounts + Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. + Adding members to an access profile's enrollment entitlement requires the JML feature; without it the request fails with a failed-precondition error. + operationId: c1.api.app.v1.AppEntitlements.AddManuallyManagedMembers + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to add manually managed members to. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsRequest' + $ref: '#/components/schemas/c1.api.app.v1.AddManuallyManagedUsersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsResponse' + $ref: '#/components/schemas/c1.api.app.v1.ManuallyManagedUsersResponse' description: Successful response - summary: List Owned Service Accounts + summary: Add Manually Managed Members tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: ListOwnedServiceAccounts - x-stability-level: draft - /api/v1/appentitlementmonitorbinding: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: AddManuallyManagedMembers + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation: delete: - description: Remove an app entitlement from a conflict monitor's entitlement set. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.DeleteAppEntitlementMonitorBinding + description: Delete the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.DeleteAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement whose automation to delete. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingRequest' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingResponse' - description: The response message for deleting an app entitlement monitor binding. - summary: Delete App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationResponse' + description: Successful response + summary: Delete Automation tags: - - App Entitlement Monitor Binding + - App Entitlement Automation x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Monitor_Binding#delete - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: DeleteAppEntitlementMonitorBinding - post: - description: Bind an app entitlement to one side (A or B) of a conflict monitor. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.CreateAppEntitlementMonitorBinding - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.CreateAppEntitlementMonitorBindingRequest' + terraform-resource: App Entitlement Automation#delete + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: DeleteAutomation + get: + description: Get the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.GetAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that is associated with the app entitlement. + readOnly: true + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The unique ID for the App Entitlement. + readOnly: true + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' - description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. - summary: Create App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceGetAutomationResponse' + description: Successful response + summary: Get Automation tags: - - App Entitlement Monitor Binding + - App Entitlement Automation x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Monitor_Binding#create - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: CreateAppEntitlementMonitorBinding - /api/v1/appentitlementmonitorbinding/get: + terraform-datasource: App Entitlement Automation#read + terraform-resource: App Entitlement Automation#read + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: GetAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/create: post: - description: Retrieve a single binding that associates an app entitlement with one side of a conflict monitor. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.GetAppEntitlementMonitorBinding + description: Create an automation rule for an app entitlement. Automations automatically provision or revoke access based on defined conditions. + operationId: c1.api.app.v1.AppEntitlements.CreateAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to create an automation for. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.GetAppEntitlementMonitorBindingRequest' + $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' - description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. - summary: Get App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationResponse' + description: Successful response + summary: Create Automation tags: - - App Entitlement Monitor Binding + - App Entitlement Automation x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App_Entitlement_Monitor_Binding#read - terraform-resource: App_Entitlement_Monitor_Binding#read - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: GetAppEntitlementMonitorBinding - /api/v1/apps: - get: - description: List all apps. - operationId: c1.api.app.v1.Apps.List + terraform-resource: App Entitlement Automation#create + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: CreateAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/exclusions: + delete: + description: Remove users from the automation exclusion list for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.RemoveAutomationExclusion parameters: - - in: query - name: page_size + - in: path + name: app_id + required: true schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true schema: - description: The pageToken field. + description: The ID of the app entitlement whose automation exclusion list to update. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppsResponse' - description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. - summary: List - tags: - - App - x-speakeasy-group: Apps - x-speakeasy-name-override: List - post: - description: Create a new manual app without a connector. - operationId: c1.api.app.v1.Apps.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppRequest' + $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppResponse' - description: Returns the new app's values. - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionResponse' + description: Empty response with a status code indicating success. + summary: Remove Automation Exclusion tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App#create - x-speakeasy-group: Apps - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/access_request_defaults: + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: RemoveAutomationExclusion get: - description: Retrieve the current access request default settings for an app. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.GetAppAccessRequestsDefaults + description: List users who are excluded from the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.ListAutomationExclusions parameters: - in: path name: app_id required: true schema: - description: The ID of the app to retrieve access request defaults for. + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to list exclusions for. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + $ref: '#/components/schemas/c1.api.app.v1.ListAutomationExclusionsResponse' description: Successful response - summary: Get App Access Requests Defaults + summary: List Automation Exclusions tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: GetAppAccessRequestsDefaults + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListAutomationExclusions post: - description: Create or replace the access request default settings for an app. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CreateAppAccessRequestsDefaults + description: Add users to the automation exclusion list for an app entitlement. Excluded users are not affected by the automation rule. + operationId: c1.api.app.v1.AppEntitlements.AddAutomationExclusion parameters: - in: path name: app_id required: true schema: - description: The app id for the app access request rule + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement whose automation exclusion list to update. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaultsInput' + $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' - description: Successful response - summary: Create App Access Requests Defaults + $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionResponse' + description: Empty response with a status code indicating success. + summary: Add Automation Exclusion tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: CreateAppAccessRequestsDefaults - /api/v1/apps/{app_id}/access_request_defaults/cancel: + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: AddAutomationExclusion + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/update: post: - description: Cancel an in-progress apply operation for the app's access request defaults. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CancelAppAccessRequestsDefaults + description: Update the automation rule for an app entitlement, including its display name, description, and conditions. + operationId: c1.api.app.v1.AppEntitlements.UpdateAutomation parameters: - in: path name: app_id required: true schema: - description: The ID of the app whose access request defaults apply operation should be cancelled. + description: The ID of the app that is associated with the app entitlement. + readOnly: true + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The unique ID for the App Entitlement. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CancelAccessRequestDefaultsRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse' description: Successful response - summary: Cancel App Access Requests Defaults + summary: Update Automation tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: CancelAppAccessRequestsDefaults - /api/v1/apps/{app_id}/app_users: + - App Entitlement Automation + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Automation#update + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: UpdateAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/grants: get: - description: List app user accounts within a specific app, with pagination support. - operationId: c1.api.app.v1.AppUserService.List + description: |- + Search app entitlements, include app users, users, expires, discovered. + Response rows are large — request a small page_size (≤10) to keep responses small. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsWithExpired parameters: - in: path name: app_id required: true schema: - description: The ID of the app to list users for. + description: The appId field. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The appEntitlementId field. type: string - in: query name: page_size schema: - description: The maximum number of results to return per page. + description: The pageSize field. format: int32 type: integer - in: query name: page_token schema: - description: The token for fetching the next page of results. + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListResponse' - description: The response message for listing app users. - summary: List + $ref: '#/components/schemas/c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse' + description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. + summary: Search App Entitlements With Expired tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: List - /api/v1/apps/{app_id}/app_users/{app_user_id}/credentials: - get: - description: List credentials associated with a specific app user account. - operationId: c1.api.app.v1.AppUserService.ListAppUserCredentials + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchAppEntitlementsWithExpired + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/remove-membership: + delete: + description: |- + Remove a user from a manually managed entitlement. For ConductorOne + catalogs, groups, and profile types, the existing resource-specific + removal behavior applies. When the SSO provider feature is enabled, an SSO + application's sign-in entitlement removes only direct manual access and + preserves independent requested, connector, and group-derived access. + Removing a member from an access profile requires the JML feature; without + it the request fails with a failed-precondition error. + operationId: c1.api.app.v1.AppEntitlements.RemoveEntitlementMembership parameters: - in: path name: app_id required: true schema: - description: The ID of the app that the user belongs to. + description: The ID of the app that contains the entitlement. type: string - in: path - name: app_user_id + name: app_entitlement_id required: true schema: - description: The ID of the app user whose credentials to list. - type: string - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The token for fetching the next page of results. + description: The ID of the app entitlement to remove the membership from. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListCredentialsResponse' - description: The response message for listing credentials of an app user. - summary: List App User Credentials + $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipResponse' + description: Successful response + summary: Remove Entitlement Membership tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: ListAppUserCredentials - /api/v1/apps/{app_id}/connectors: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: RemoveEntitlementMembership + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users: get: - description: List connectors for an app. - operationId: c1.api.app.v1.ConnectorService.List + deprecated: true + description: List the users, as AppEntitlementUsers objects, of an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.ListUsers parameters: - in: path name: app_id @@ -42186,6 +50155,12 @@ paths: schema: description: The appId field. type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The appEntitlementId field. + type: string - in: query name: page_size schema: @@ -42202,685 +50177,569 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceListResponse' - description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable - summary: List + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementUsersResponse' + description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. + summary: List Users tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: List + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppEntitlementUsers#read + terraform-resource: null + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListUsers + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/remove-grant-duration: post: - description: Create a connector that is pending a connector config. - operationId: c1.api.app.v1.ConnectorService.CreateDelegated + description: Remove the expiration time from a grant, converting it to an indefinite (standing) grant. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.RemoveGrantDuration parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. + description: The ID of the app that owns the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the entitlement whose grant duration is being removed. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The ID of the app user whose grant expiration is being removed. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' - description: The ConnectorServiceCreateResponse is the response returned from creating a connector. - summary: Create Delegated - tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: CreateDelegated - /api/v1/apps/{app_id}/connectors/{connector_id}/confirm_sync_valid/{sync_lifecycle_id}: + $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationResponse' + description: The response message for removing the expiration time from a grant. + summary: Remove Grant Duration + tags: + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: RemoveGrantDuration + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/update-grant-duration: post: - description: Confirm that a sync which errored due to a data drop is valid, overriding the error and triggering a new sync. Only applicable when the sync status is ERRORED_NO_DATA. - operationId: c1.api.app.v1.ConnectorService.ConfirmSyncValid + description: Update the expiration time of an existing grant, changing when automatic revocation will occur. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.UpdateGrantDuration parameters: - in: path name: app_id required: true schema: - description: The AppID of the app the connector is attached to. + description: The ID of the app that owns the entitlement. type: string - in: path - name: connector_id + name: app_entitlement_id required: true schema: - description: The ConnectorID of the connector that we are confirming the sync for. + description: The ID of the entitlement whose grant duration is being updated. type: string - in: path - name: sync_lifecycle_id + name: app_user_id required: true schema: - description: The completed lifecycle id of the most recent sync we want to validate + description: The ID of the app user whose grant is being updated. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidResponse' - description: Empty response body. Status code indicates success. - summary: Confirm Sync Valid + $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationResponse' + description: The response message for updating the duration of a grant. + summary: Update Grant Duration tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ConfirmSyncValid - /api/v1/apps/{app_id}/connectors/{connector_id}/credentials/{id}: + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: UpdateGrantDuration + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{identity_user_id}/grants: get: - description: Get credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.GetCredentials + description: Returns a list of app users for the identity in the app. If that app user also has a grant to the entitlement from the request, data about the grant is also returned. It will always return ALL app users for this identity, but only SOME may have grant data. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.ListAppUsersForIdentityWithGrant parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. + description: The appId field. type: string - in: path - name: connector_id + name: app_entitlement_id required: true schema: - description: The connectorId of the connector that we are getting the credentials for. + description: The appEntitlementId field. type: string - in: path - name: id + name: identity_user_id required: true schema: - description: The id of the ConnectorCredential. + description: The identityUserId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetCredentialsResponse' - description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. - summary: Get Credentials + $ref: '#/components/schemas/c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse' + description: Successful response + summary: List App Users For Identity With Grant tags: - - Connector - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: ConnectorCredential#read - terraform-resource: ConnectorCredential#read - x-speakeasy-group: Connector - x-speakeasy-name-override: GetCredentials - post: - description: Revoke credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.RevokeCredential + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: ListAppUsersForIdentityWithGrant + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/ownerids: + get: + description: ListUserIDs lists owner IDs for a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.ListOwnerIDs parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId of the connector that we are revoking the credentials for. + description: The app_id field for the app entitlement to list owners of. type: string - in: path - name: id + name: entitlement_id required: true schema: - description: The id of the ConnectorCredential. + description: The entitlement_id field for the app entitlement to list owners of. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialResponse' - description: Empty response body. Status code indicates success. - summary: Revoke Credential + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnerIDsResponse' + description: The response message for listing app entitlement owners IDs. + summary: List Owner I Ds tags: - - Connector + - App Entitlement Owner x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: ConnectorCredential#delete - x-speakeasy-group: Connector - x-speakeasy-name-override: RevokeCredential - /api/v1/apps/{app_id}/connectors/{connector_id}/force_sync: - post: - description: Trigger an immediate sync for a connector. The sync is queued and may not start instantly. - operationId: c1.api.app.v1.ConnectorService.ForceSync + terraform-datasource: null + terraform-resource: App_Entitlement_Owner#read + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners: + delete: + description: Delete deletes the owners from a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Delete parameters: - in: path name: app_id required: true schema: - description: The AppID of the app the connector is attached to. + description: The app_id field for the app entitlement to remove the owner of. type: string - in: path - name: connector_id + name: entitlement_id required: true schema: - description: The ConnectorID of the connector that we are forcing to sync. + description: The entitlement_id field for the app entitlement to remove the owner of. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ForceSyncRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ForceSyncResponse' - description: Empty response body. Status code indicates success. - summary: Force Sync + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersResponse' + description: the empty response message for deleting app entitlement owners. + summary: Delete tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ForceSync - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools: + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner#delete + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Delete get: - description: |- - List returns the MCP tools discovered for a single (app_id, connector_id), - paginated. To filter by state, classification, or visibility, use Search. - operationId: c1.api.ai_governance.v1.MCPToolService.List + description: List owners for a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.List parameters: - in: path name: app_id required: true schema: - description: App identifier (required). + description: The app_id field for the app entitlement to list owners of. type: string - in: path - name: connector_id + name: entitlement_id required: true schema: - description: Connector ID (required). + description: The entitlement_id field for the app entitlement to list owners of. type: string - in: query name: page_size schema: - description: Page size (max 100). + description: The page_size field for pagination. format: int32 type: integer - in: query name: page_token schema: - description: Page token for pagination. + description: The page_token field for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListResponse' - description: MCPToolServiceListResponse returns a list of MCP tools. + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnersResponse' + description: The response message for listing app entitlement owners. summary: List tags: - - MCP Tools - x-speakeasy-group: MCPTool + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppEntitlementOwners#read + terraform-resource: null + x-speakeasy-group: AppEntitlementOwners x-speakeasy-name-override: List - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}: - delete: - description: |- - Delete soft-deletes an MCP tool. It reappears as PENDING_REVIEW if the - connector rediscovers it on the next sync. - operationId: c1.api.ai_governance.v1.MCPToolService.Delete + post: + description: Add an owner to a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Add parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. + description: The app_id field for the app entitlement to add the owner to. type: string - in: path - name: id + name: entitlement_id required: true schema: - description: Unique identifier for the MCP tool. + description: The entitlement_id field for the app entitlement to add the owner to. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteResponse' - description: MCPToolServiceDeleteResponse confirms deletion. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerResponse' + description: The empty response message for adding an app entitlement owner. + summary: Add tags: - - MCP Tools - x-speakeasy-group: MCPTool - x-speakeasy-name-override: Delete - get: - description: |- - Get retrieves a single discovered MCP tool by app_id + connector_id + id, - including its approval state, classification, visibility, input schema, and - bound app_entitlement_id. - operationId: c1.api.ai_governance.v1.MCPToolService.Get + - App Entitlement Owner + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Add + put: + description: Sets the owners for a given app entitlement to the specified list of users. + operationId: c1.api.app.v1.AppEntitlementOwners.Set parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. + description: The app_id field for the app entitlement to set the owners of. type: string - in: path - name: id + name: entitlement_id required: true schema: - description: Unique identifier for the MCP tool. + description: The entitlement_id field for the app entitlement to set the owners of. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceGetResponse' - description: MCPToolServiceGetResponse returns a single MCP tool. - summary: Get + $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersResponse' + description: The empty response message for setting the app entitlement owners. + summary: Set tags: - - MCP Tools - x-speakeasy-group: MCPTool - x-speakeasy-name-override: Get - post: - description: |- - Update modifies an MCP tool's admin-editable fields via update_mask. This - is how a tool is approved: set tool.state = MCP_TOOL_STATE_APPROVED with - update_mask "state" to move it out of PENDING_REVIEW (or DISABLED to block - it). Editable paths: display_name, description, classification, state, - allowed_client_types, visibility. tool must include id, app_id, connector_id. - operationId: c1.api.ai_governance.v1.MCPToolService.Update + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner#create + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners/{user_id}: + delete: + description: Remove an owner from a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Remove parameters: - in: path name: app_id required: true schema: - description: App identifier (app that owns the connector). + description: The app_id field for the app entitlement to remove the owner of. type: string - in: path - name: connector_id + name: entitlement_id required: true schema: - description: Connector identifier. + description: The entitlement_id field for the app entitlement to remove the owner of. type: string - in: path - name: id + name: user_id required: true schema: - description: Unique identifier for this MCP tool record. + description: The user_id field for the user to remove as an owner of the app entitlement. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateResponse' - description: MCPToolServiceUpdateResponse returns the updated MCP tool. - summary: Update + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerResponse' + description: The empty response message for removing an app entitlement owner. + summary: Remove tags: - - MCP Tools - x-speakeasy-group: MCPTool - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}/history: - get: - description: |- - ListHistory returns the change history (newest first) for a single MCP - tool — each entry is a snapshot plus who/when metadata. - operationId: c1.api.ai_governance.v1.MCPToolService.ListHistory + - App Entitlement Owner + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Remove + /api/v1/apps/{app_id}/entitlements/{id}: + delete: + description: Delete an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Delete parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. + description: The ID of the app that contains the entitlement. type: string - in: path name: id required: true schema: - description: Unique identifier for the MCP tool. - type: string - - in: query - name: page_size - schema: - description: Page size (max 200). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListHistoryResponse' - description: MCPToolServiceListHistoryResponse returns MCP tool history entries. - summary: List History - tags: - - MCP Tools - x-speakeasy-group: MCPTool - x-speakeasy-name-override: ListHistory - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/search: - post: - description: |- - Search returns a connector's MCP tools filtered by state, classification, - visibility, access-profile binding, or text query. Filter on - MCP_TOOL_STATE_PENDING_REVIEW to find tools awaiting approval, then approve - them with Update. - operationId: c1.api.ai_governance.v1.MCPToolService.Search - parameters: - - in: path - name: app_id - required: true - schema: - description: App identifier (required). - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector ID (required). + description: The ID of the app entitlement to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchResponse' - description: MCPToolServiceSearchResponse returns matching MCP tools. - summary: Search + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementResponse' + description: Successful response + summary: Delete tags: - - MCP Tools - x-speakeasy-group: MCPTool - x-speakeasy-name-override: Search - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Custom App Entitlement#delete + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Delete get: - description: |- - List returns the MCP toolsets (access profiles) defined for a single - (app_id, connector_id), paginated. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.List + description: Get an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Get parameters: - in: path name: app_id required: true schema: - description: App identifier (required). + description: The appId field. type: string - in: path - name: connector_id + name: id required: true schema: - description: Connector ID (required). - type: string - - in: query - name: page_size - schema: - description: Page size (max 100). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceListResponse' - description: MCPAccessProfileServiceListResponse returns a list of MCP access profiles. - summary: List + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementResponse' + description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. + summary: Get tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile - x-speakeasy-name-override: List + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Custom App Entitlement#read + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Get post: - description: |- - Create creates a new MCP toolset (access profile) under a connector. The - backend also provisions a backing AppEntitlement that users request in - order to be granted the toolset's tools. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Create + description: Update an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Update parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The ID of the app that is associated with the app entitlement. type: string - in: path - name: connector_id + name: id required: true schema: - description: Connector identifier. + description: The unique ID for the App Entitlement. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateResponse' - description: MCPAccessProfileServiceCreateResponse returns the created MCP access profile. - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementResponse' + description: Successful response + summary: Update tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Custom App Entitlement#update + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/entitlements/resource_types/{app_resource_type_id}/resources/{app_resource_id}: get: - description: |- - List returns the tool bindings for a single toolset (access profile) — - i.e. which MCP tools belong to the toolset — paginated. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.List + description: List app entitlements associated with an app resource. + operationId: c1.api.app.v1.AppEntitlements.ListForAppResource parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The appId field. type: string - in: path - name: connector_id + name: app_resource_type_id required: true schema: - description: Connector identifier. + description: The appResourceTypeId field. type: string - in: path - name: access_profile_id + name: app_resource_id required: true schema: - description: Access profile identifier. + description: The appResourceId field. type: string - in: query name: page_size schema: - description: Page size (max 100). + description: The pageSize field. format: int32 type: integer - in: query name: page_token schema: - description: Page token for pagination. - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListResponse' - description: MCPAccessProfileToolBindingServiceListResponse returns tool bindings. - summary: List - tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: List - post: - description: CreateBindings adds one or more MCP tools (mcp_tool_ids) to a toolset. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.CreateBindings - parameters: - - in: path - name: app_id - required: true - schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. - type: string - - in: path - name: access_profile_id - required: true - schema: - description: Access profile identifier. + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateResponse' - description: MCPAccessProfileToolBindingServiceCreateResponse returns created bindings. - summary: Create Bindings - tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: CreateBindings - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/delete: - post: - description: |- - DeleteBindings removes one or more MCP tools (mcp_tool_ids) from a toolset. - Uses a POST .../delete action route because the tool IDs travel in the - request body, which HTTP DELETE does not reliably support. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.DeleteBindings + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List For App Resource + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListForAppResource + /api/v1/apps/{app_id}/entitlements/users/{app_user_id}: + get: + description: List app entitlements associated with an app user. + operationId: c1.api.app.v1.AppEntitlements.ListForAppUser parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The appId field. type: string - in: path - name: connector_id + name: app_user_id required: true schema: - description: Connector identifier. + description: The appUserId field. type: string - - in: path - name: access_profile_id - required: true + - in: query + name: page_size schema: - description: Access profile identifier. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteResponse' - description: MCPAccessProfileToolBindingServiceDeleteResponse confirms deletion. - summary: Delete Bindings + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List For App User tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: DeleteBindings - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/history: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListForAppUser + /api/v1/apps/{app_id}/mcp_servers: get: - description: |- - ListToolsByProfileHistory returns the transactional history of - tools bound to (app, connector, access_profile). Newest first. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListToolsByProfileHistory + description: List retrieves MCP servers for an app. + operationId: c1.api.ai_governance.v1.MCPServerService.List parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. - type: string - - in: path - name: access_profile_id - required: true - schema: - description: Toolset (access profile) identifier. + description: App identifier (required). type: string - in: query name: page_size schema: - description: Page size (max 200). + description: Page size (max 100). format: int32 type: integer - in: query @@ -42893,63 +50752,85 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListToolsByProfileHistoryResponse' - description: |- - Contains a page of change-history entries for the tools bound to one toolset - sorted newest first. - summary: List Tools By Profile History + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceListResponse' + description: MCPServerServiceListResponse returns a paginated list of MCP servers. + summary: List tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: ListToolsByProfileHistory - /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{id}: - delete: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: List + post: description: |- - Delete soft-deletes a toolset (access profile) and cascades to its tool - bindings and backing entitlement. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Delete + Register a new MCP server under an application. Set server_type to HOSTED + (C1 runs a catalog integration) or EXTERNAL (a third-party MCP server you + point C1 at by URL). Auth credentials are validated and stored securely. + operationId: c1.api.ai_governance.v1.MCPServerService.Register parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: |- + App to register the MCP server under. When empty and app_managed_state_binding_ref + is not set, a new managed app is created automatically. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterResponse' + description: MCPServerServiceRegisterResponse returns the newly created MCP server. + summary: Register + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: Register + /api/v1/apps/{app_id}/mcp_servers/{connector_id}: + delete: + description: |- + Delete an MCP server. Its connector stops and it is soft-deleted from this + tenant's MCP catalog, and any per-user credentials issued against it are + revoked. + operationId: c1.api.ai_governance.v1.MCPServerService.Delete + parameters: - in: path - name: connector_id + name: app_id required: true schema: - description: Connector identifier. + description: App identifier. type: string - in: path - name: id + name: connector_id required: true schema: - description: Unique identifier for the MCP access profile. + description: MCP server identifier (connector ID). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteResponse' - description: MCPAccessProfileServiceDeleteResponse confirms deletion. + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteResponse' + description: MCPServerServiceDeleteResponse confirms deletion. summary: Delete tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile + - MCP Servers + x-speakeasy-group: MCPServer x-speakeasy-name-override: Delete get: - description: |- - Get retrieves a single MCP toolset (access profile) by app_id + - connector_id + id, including its display name, description, linked - app_entitlement_id, and bound tool count. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Get + description: Get retrieves a single MCP server. + operationId: c1.api.ai_governance.v1.MCPServerService.Get parameters: - in: path name: app_id @@ -42961,422 +50842,385 @@ paths: name: connector_id required: true schema: - description: Connector identifier. - type: string - - in: path - name: id - required: true - schema: - description: Unique identifier for the MCP access profile. + description: MCP server identifier (connector ID). type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetResponse' - description: MCPAccessProfileServiceGetResponse returns a single MCP access profile. + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceGetResponse' + description: MCPServerServiceGetResponse returns a single MCP server. summary: Get tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile + - MCP Servers + x-speakeasy-group: MCPServer x-speakeasy-name-override: Get post: - description: |- - Update modifies a toolset's admin-editable fields via update_mask. - Editable paths: display_name, description. profile must include id, - app_id, and connector_id. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Update + description: Update modifies an existing MCP server's editable fields. + operationId: c1.api.ai_governance.v1.MCPServerService.Update parameters: - in: path name: app_id required: true schema: - description: App identifier (app that owns the connector). + description: App identifier. type: string - in: path name: connector_id required: true schema: - description: Connector identifier. - type: string - - in: path - name: id - required: true - schema: - description: Unique identifier for this access profile. + description: MCP server identifier (connector ID). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateResponse' - description: MCPAccessProfileServiceUpdateResponse returns the updated MCP access profile. + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateResponse' + description: MCPServerServiceUpdateResponse returns the updated MCP server. summary: Update tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile + - MCP Servers + x-speakeasy-group: MCPServer x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/connectors/{connector_id}/pause: + /api/v1/apps/{app_id}/mcp_servers/{connector_id}/credentials: post: - description: Pause syncing and provisioning for a connector. No new syncs or grant/revoke operations will run until the connector is resumed. - operationId: c1.api.app.v1.ConnectorService.PauseSync + description: UpdateCredentials replaces the auth config and/or config fields for an MCP server. + operationId: c1.api.ai_governance.v1.MCPServerService.UpdateCredentials parameters: - in: path name: app_id required: true schema: - description: The AppID of the app the connector is attached to. + description: App identifier. type: string - in: path name: connector_id required: true schema: - description: The ConnectorID of the connector that we are pausing the sync for. + description: MCP server identifier (connector ID). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.PauseSyncRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.PauseSyncResponse' - description: Empty response body. Status code indicates success. - summary: Pause Sync + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsResponse' + description: MCPServerServiceUpdateCredentialsResponse returns the updated MCP server. + summary: Update Credentials tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: PauseSync - /api/v1/apps/{app_id}/connectors/{connector_id}/resume: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: UpdateCredentials + /api/v1/apps/{app_id}/mcp_servers/{connector_id}/resync_tools: post: - description: Resume syncing and provisioning for a connector that was previously paused. Clears the paused state and triggers a new sync. - operationId: c1.api.app.v1.ConnectorService.ResumeSync + description: |- + ResyncTools re-runs per-identity tool discovery for the calling user's + own credential on a per-user MCP server, so a session opened before the + user connected (or after their visible tools changed) doesn't have to + wait for the next unrelated MCPTool/AppEntitlementUserBinding change to + pick it up. + operationId: c1.api.ai_governance.v1.MCPServerService.ResyncTools parameters: - in: path name: app_id required: true schema: - description: The AppID of the app the connector is attached to. + description: App identifier. type: string - in: path name: connector_id required: true schema: - description: The ConnectorID of the connector that we are resuming the sync for. + description: MCP server identifier (connector ID). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncResponse' - description: Empty response body. Status code indicates success. - summary: Resume Sync + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsResponse' + description: MCPServerServiceResyncToolsResponse is empty on success. + summary: Resync Tools tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ResumeSync - /api/v1/apps/{app_id}/connectors/{connector_id}/schedule: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: ResyncTools + /api/v1/apps/{app_id}/mcp_servers/search: post: - description: Update the sync schedule for a connector. - operationId: c1.api.app.v1.ConnectorService.UpdateConnectorSchedule + description: SearchWithToolCount searches MCP servers with filtering and returns per-server tool state counts. + operationId: c1.api.ai_governance.v1.MCPServerService.SearchWithToolCount parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId of the connector whose schedule is being updated. + description: App identifier (required). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleRequestInput' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleResponse' - description: Empty response body. Status code indicates success. - summary: Update Connector Schedule + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountResponse' + description: MCPServerServiceSearchWithToolCountResponse returns matching MCP servers with tool counts. + summary: Search With Tool Count tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: UpdateConnectorSchedule - x-stability-level: alpha - /api/v1/apps/{app_id}/connectors/{connector_id}/syncs/{sync_id}/download_url: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: SearchWithToolCount + /api/v1/apps/{app_id}/mcp_toolsets/by_app_entitlement_id/{app_entitlement_id}: get: - description: GetConnectorSyncDownloadURL generates a short-lived download URL for a completed connector sync artifact. - operationId: c1.api.app.v1.ConnectorService.GetConnectorSyncDownloadURL + description: |- + GetByAppEntitlementId looks up the toolset (access profile) linked to a + synced role entitlement, by app_id + app_entitlement_id. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.GetByAppEntitlementId parameters: - in: path name: app_id required: true schema: - description: The appId field. - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId field. + description: App identifier. type: string - in: path - name: sync_id + name: app_entitlement_id required: true schema: - description: The syncId field. + description: AppEntitlement ID to look up. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetConnectorSyncDownloadURLResponse' - description: Successful response - summary: Get Connector Sync Download Url + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetByAppEntitlementIdResponse' + description: MCPAccessProfileServiceGetByAppEntitlementIdResponse returns the matched profile. + summary: Get By App Entitlement Id tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: GetConnectorSyncDownloadURL - /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tool/{mcp_tool_id}/history: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: GetByAppEntitlementId + /api/v1/apps/{app_id}/ownerids: get: - description: |- - ListProfilesByToolHistory returns the transactional history of - profiles bound to (app, connector, mcp_tool). Newest first. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListProfilesByToolHistory + description: ListOwnerIDs lists owner IDs for a given app. + operationId: c1.api.app.v1.AppOwners.ListOwnerIDs parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. - type: string - - in: path - name: mcp_tool_id - required: true - schema: - description: MCP tool identifier. - type: string - - in: query - name: page_size - schema: - description: Page size (max 200). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The app_id field for the app to list owners of. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListProfilesByToolHistoryResponse' - description: |- - Contains a page of change-history entries for the toolsets one tool has belonged to, - sorted newest first. - summary: List Profiles By Tool History + $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnerIDsResponse' + description: The response message for listing app owners IDs. + summary: List Owner I Ds tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: ListProfilesByToolHistory - /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tools: - post: - description: |- - GetAccessProfilesForTools returns the access profiles bound to each - of the given MCP tools, hydrated with display_name. Used by the tools - list to render the "toolset" column for visible rows. - operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.GetAccessProfilesForTools + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Owner#read + x-speakeasy-group: AppOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/owners: + delete: + description: Delete deletes the owners from a given app. + operationId: c1.api.app.v1.AppOwners.Delete parameters: - in: path name: app_id required: true schema: - description: App identifier. - type: string - - in: path - name: connector_id - required: true - schema: - description: Connector identifier. + description: The app_id field for the app to remove the owner of. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse' - description: |- - MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse returns - access profiles grouped by MCP tool. - summary: Get Access Profiles For Tools + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersResponse' + description: the empty response message for deleting app owners. + summary: Delete tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfileToolBinding - x-speakeasy-name-override: GetAccessProfilesForTools - /api/v1/apps/{app_id}/connectors/{id}: - delete: - description: Delete a connector. - operationId: c1.api.app.v1.ConnectorService.Delete + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner#delete + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Delete + get: + description: List owners of an app. + operationId: c1.api.app.v1.AppOwners.List parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. + description: The appId field. type: string - - in: path - name: id - required: true + - in: query + name: page_size schema: - description: The id of the connector. + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteResponse' - description: Empty response body. Status code indicates success. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnersResponse' + description: Successful response + summary: List tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: Delete - get: - description: Get a connector. - operationId: c1.api.app.v1.ConnectorService.Get + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppOwners#read + terraform-resource: null + x-speakeasy-group: AppOwners + x-speakeasy-name-override: List + put: + description: Sets the owners for a given app to the specified list of users. + operationId: c1.api.app.v1.AppOwners.Set parameters: - in: path name: app_id required: true schema: - description: The appId of the app the connector is attached to. - type: string - - in: path - name: id - required: true - schema: - description: The id of the connector. + description: The app_id field for the app to set the owners of. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetResponse' - description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. - summary: Get + $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersResponse' + description: The empty response message for setting the app owners. + summary: Set tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: Get - post: - description: Update a connector. - operationId: c1.api.app.v1.ConnectorService.Update + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner#create + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/owners/{user_id}: + delete: + description: Removes an owner from an app. + operationId: c1.api.app.v1.AppOwners.Remove parameters: - in: path name: app_id required: true schema: - description: The id of the app the connector is associated with. + description: App ID of the app to remove the owner from. type: string - in: path - name: id + name: user_id required: true schema: - description: The id of the connector. + description: User ID of the user to remove as an owner. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' - description: ConnectorServiceUpdateResponse is the response returned by the update method. - summary: Update + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerResponse' + description: Empty response with a status code indicating success. + summary: Remove tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/connectors/create: + - App Owner + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Remove post: - description: Create a configured connector. - operationId: c1.api.app.v1.ConnectorService.Create + description: Adds an owner to an app. + operationId: c1.api.app.v1.AppOwners.Add parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The appId field. + type: string + - in: path + name: user_id + required: true + schema: + description: The userId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' - description: The ConnectorServiceCreateResponse is the response returned from creating a connector. - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerResponse' + description: Empty response with a status code indicating success + summary: Add tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/entitlement_configuration_rules: + - App Owner + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Add + /api/v1/apps/{app_id}/report: get: - description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules method. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules + description: Get a list of reports for the given app. + operationId: c1.api.app.v1.AppReportService.List parameters: - in: path name: app_id @@ -43384,21 +51228,32 @@ paths: schema: description: The appId field. type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementRoutingRulesResponse' - description: Successful response - summary: List App Entitlement Routing Rules + $ref: '#/components/schemas/c1.api.app.v1.AppReportServiceListResponse' + description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: ListAppEntitlementRoutingRules + - App Reports + x-speakeasy-group: AppReport + x-speakeasy-name-override: List post: - description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule method. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule + description: Generate a report for the given app. + operationId: c1.api.app.v1.AppReportActionService.GenerateReport parameters: - in: path name: app_id @@ -43410,23 +51265,23 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleResponse' - description: Successful response - summary: Create App Entitlement Routing Rule + $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportResponse' + description: Empty response body. Status code indicates success. + summary: Generate Report tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: CreateAppEntitlementRoutingRule - /api/v1/apps/{app_id}/entitlement_configuration_rules/{id}: - delete: - description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule method. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule + - App Reports + x-speakeasy-group: AppReportAction + x-speakeasy-name-override: GenerateReport + /api/v1/apps/{app_id}/resource_types: + get: + description: List app resource types. + operationId: c1.api.app.v1.AppResourceTypeService.List parameters: - in: path name: app_id @@ -43434,475 +51289,540 @@ paths: schema: description: The appId field. type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceListResponse' + description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App Resource Type + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: List + post: + description: Create a manually managed resource type that classifies resources within an app. + operationId: c1.api.app.v1.AppResourceTypeService.CreateManuallyManagedResourceType + parameters: - in: path - name: id + name: app_id required: true schema: - description: The id field. + description: The ID of the app to create the resource type under. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleResponse' - description: Successful response - summary: Delete App Entitlement Routing Rule + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeResponse' + description: The response message for creating a manually managed resource type. + summary: Create Manually Managed Resource Type tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: DeleteAppEntitlementRoutingRule + - App Resource Type + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource Type#create + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: CreateManuallyManagedResourceType + /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources: get: - description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule method. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule + description: List app resources for a given app and optionally filter by resource type. + operationId: c1.api.app.v1.AppResourceService.List parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The ID of the app to list resources for. type: string - in: path - name: id + name: app_resource_type_id required: true schema: - description: The id field. + description: Optional resource type ID to filter results by. If empty, resources of all types are returned. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementRoutingRuleResponse' - description: Successful response - summary: Get App Entitlement Routing Rule + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceListResponse' + description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: GetAppEntitlementRoutingRule + - App Resource + x-speakeasy-group: AppResource + x-speakeasy-name-override: List post: - description: |- - Update an existing app entitlement configuration rule. The app_id field is - immutable; moving a rule between apps is modeled as delete + create. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.UpdateAppEntitlementRoutingRule + description: Create a manually managed app resource tracked directly by ConductorOne under an existing resource type. + operationId: c1.api.app.v1.AppResourceService.CreateManuallyManagedAppResource parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The ID of the app to create the resource under. type: string - in: path - name: id + name: app_resource_type_id required: true schema: - description: The id field. + description: The resource type ID that classifies this resource. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleResponse' - description: Successful response - summary: Update App Entitlement Routing Rule + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceResponse' + description: The response message for creating a manually managed app resource. + summary: Create Manually Managed App Resource tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: UpdateAppEntitlementRoutingRule - /api/v1/apps/{app_id}/entitlement_configuration_rules/reorder: - post: - description: |- - Reorder all configuration rules for an app in a single call. The caller - supplies the full ordered list of rule IDs; the server assigns dense - priorities (1..N) in that order. The request must be a permutation of every - active rule in the app — missing or extra IDs are rejected. - operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ReorderAppEntitlementRoutingRules + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#create + x-speakeasy-group: AppResource + x-speakeasy-name-override: CreateManuallyManagedAppResource + /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources/{id}: + delete: + description: Delete a manually managed app resource and its associated entitlements from an app. + operationId: c1.api.app.v1.AppResourceService.DeleteManuallyManagedAppResource parameters: - in: path name: app_id required: true schema: - description: The ID of the app whose rules should be reordered. + description: The ID of the app that owns the resource. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The ID of the resource type that classifies the resource. + type: string + - in: path + name: id + required: true + schema: + description: The ID of the app resource to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesResponse' - description: Successful response - summary: Reorder App Entitlement Routing Rules + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceResponse' + description: The empty response message for deleting a manually managed app resource. + summary: Delete Manually Managed App Resource tags: - - App Entitlement Configuration Rule - x-speakeasy-group: AppEntitlementRoutingRule - x-speakeasy-name-override: ReorderAppEntitlementRoutingRules - /api/v1/apps/{app_id}/entitlements: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#delete + x-speakeasy-group: AppResource + x-speakeasy-name-override: DeleteManuallyManagedAppResource get: - description: List app entitlements associated with an app. - operationId: c1.api.app.v1.AppEntitlements.List + description: Retrieve a single app resource by its app, resource type, and resource ID. + operationId: c1.api.app.v1.AppResourceService.Get parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The ID of the app that owns the resource. type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + - in: path + name: app_resource_type_id + required: true schema: - description: The pageToken field. + description: The ID of the resource type that classifies this resource. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: List - tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: List - post: - description: Create a new app entitlement for an app. This is used to define a custom permission, group, or role within the app. - operationId: c1.api.app.v1.AppEntitlements.Create - parameters: - in: path - name: app_id + name: id required: true schema: - description: The ID of the app to create the entitlement in. + description: The unique ID of the app resource to retrieve. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceGetResponse' + description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. + summary: Get tags: - - App Entitlement + - App Resource x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#create - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/add-manual-user: + terraform-datasource: App Resource#read + terraform-resource: App Resource#read + x-speakeasy-group: AppResource + x-speakeasy-name-override: Get post: - description: Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. - operationId: c1.api.app.v1.AppEntitlements.AddManuallyManagedMembers + description: Update an app resource's fields. Only the fields specified in the update mask are modified. + operationId: c1.api.app.v1.AppResourceService.Update parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: The app that this resource belongs to. type: string - in: path - name: app_entitlement_id + name: app_resource_type_id required: true schema: - description: The ID of the app entitlement to add manually managed members to. + description: The resource type that this resource is. + type: string + - in: path + name: id + required: true + schema: + description: The id of the resource. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddManuallyManagedUsersRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ManuallyManagedUsersResponse' - description: Successful response - summary: Add Manually Managed Members + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateResponse' + description: The response message for updating an app resource. + summary: Update tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: AddManuallyManagedMembers - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#update + x-speakeasy-group: AppResource + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/resource_types/{id}: delete: - description: Delete the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.DeleteAutomation + description: Delete a manually managed resource type and all its associated resources from an app. + operationId: c1.api.app.v1.AppResourceTypeService.DeleteManuallyManagedResourceType parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: The ID of the app that owns the resource type. type: string - in: path - name: app_entitlement_id + name: id required: true schema: - description: The ID of the app entitlement whose automation to delete. + description: The ID of the resource type to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationResponse' - description: Successful response - summary: Delete Automation + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse' + description: The empty response message for deleting a manually managed resource type. + summary: Delete Manually Managed Resource Type tags: - - App Entitlement Automation + - App Resource Type x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#delete - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: DeleteAutomation + terraform-resource: App Resource Type#delete + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: DeleteManuallyManagedResourceType get: - description: Get the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.GetAutomation + description: Get an app resource type. + operationId: c1.api.app.v1.AppResourceTypeService.Get parameters: - in: path name: app_id required: true schema: - description: The ID of the app that is associated with the app entitlement. - readOnly: true + description: The appId field. type: string - in: path - name: app_entitlement_id + name: id required: true schema: - description: The unique ID for the App Entitlement. - readOnly: true + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceGetAutomationResponse' - description: Successful response - summary: Get Automation + $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceGetResponse' + description: |- + The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask + in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. + summary: Get tags: - - App Entitlement Automation + - App Resource Type x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App Entitlement Automation#read - terraform-resource: App Entitlement Automation#read - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: GetAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/create: + terraform-datasource: null + terraform-resource: App Resource Type#read + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: Get post: - description: Create an automation rule for an app entitlement. Automations automatically provision or revoke access based on defined conditions. - operationId: c1.api.app.v1.AppEntitlements.CreateAutomation + description: Update a manually managed resource type's fields. Only the fields specified in the update mask are modified. + operationId: c1.api.app.v1.AppResourceTypeService.UpdateManuallyManagedResourceType parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: The ID of the app that is associated with the app resource type + readOnly: true type: string - in: path - name: app_entitlement_id + name: id required: true schema: - description: The ID of the app entitlement to create an automation for. + description: The unique ID for the app resource type. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationResponse' - description: Successful response - summary: Create Automation + $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse' + description: The response message for updating a manually managed resource type. + summary: Update Manually Managed Resource Type tags: - - App Entitlement Automation + - App Resource Type x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#create - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: CreateAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/exclusions: - delete: - description: Remove users from the automation exclusion list for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.RemoveAutomationExclusion + terraform-resource: App Resource Type#update + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: UpdateManuallyManagedResourceType + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings: + get: + description: List the managed states of applications discovered by a connector. + operationId: c1.api.app.v1.AppManagedStateService.List parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: ID of the application that owns the connector. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the app entitlement whose automation exclusion list to update. + description: ID of the resource type used for discovered applications. + type: string + - in: query + name: page_size + schema: + description: Maximum number of results to return. The maximum is 100. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Pagination token from a previous response. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionResponse' - description: Empty response with a status code indicating success. - summary: Remove Automation Exclusion + $ref: '#/components/schemas/c1.api.app.v1.ListAppManagedStateBindingsResponse' + description: ListAppManagedStateBindingsResponse contains one page of discovered application managed states. + summary: List tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: RemoveAutomationExclusion + - Application Managed State + x-speakeasy-group: AppManagedState + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings/{resource_id}: get: - description: List users who are excluded from the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.ListAutomationExclusions + description: Get the managed state of a discovered application. + operationId: c1.api.app.v1.AppManagedStateService.Get parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: ID of the application that owns the connector. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the app entitlement to list exclusions for. + description: ID of the resource type used for discovered applications. + type: string + - in: path + name: resource_id + required: true + schema: + description: Resource ID of the discovered application. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAutomationExclusionsResponse' - description: Successful response - summary: List Automation Exclusions + $ref: '#/components/schemas/c1.api.app.v1.GetAppManagedStateBindingResponse' + description: GetAppManagedStateBindingResponse contains the managed state of a discovered application. + summary: Get tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListAutomationExclusions + - Application Managed State + x-speakeasy-group: AppManagedState + x-speakeasy-name-override: Get + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings/{resource_id}/promote: post: - description: Add users to the automation exclusion list for an app entitlement. Excluded users are not affected by the automation rule. - operationId: c1.api.app.v1.AppEntitlements.AddAutomationExclusion + description: |- + Promote an unmanaged application into a managed application. + Returns AlreadyExists when the application is already managed. The new application inherits source owners when user_ids is omitted. + Concurrent promotion requests are not supported. + operationId: c1.api.app.v1.AppManagedStateService.Promote parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: ID of the application that owns the connector. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the app entitlement whose automation exclusion list to update. + description: ID of the resource type used for discovered applications. + type: string + - in: path + name: resource_id + required: true + schema: + description: Resource ID of the unmanaged application. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.PromoteAppManagedStateBindingRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionResponse' - description: Empty response with a status code indicating success. - summary: Add Automation Exclusion + $ref: '#/components/schemas/c1.api.app.v1.GetAppManagedStateBindingResponse' + description: GetAppManagedStateBindingResponse contains the managed state of a discovered application. + summary: Promote tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: AddAutomationExclusion - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/update: - post: - description: Update the automation rule for an app entitlement, including its display name, description, and conditions. - operationId: c1.api.app.v1.AppEntitlements.UpdateAutomation + - Application Managed State + x-speakeasy-group: AppManagedState + x-speakeasy-name-override: Promote + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/ownerids: + delete: + description: Delete deletes the owners from a given app resource. + operationId: c1.api.app.v1.AppResourceOwners.Delete parameters: - in: path name: app_id required: true schema: - description: The ID of the app that is associated with the app entitlement. - readOnly: true + description: The appId field. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The unique ID for the App Entitlement. - readOnly: true + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse' - description: Successful response - summary: Update Automation + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersResponse' + description: the empty response message for deleting app resource owners. + summary: Delete tags: - - App Entitlement Automation + - App Resource Owner x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#update - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: UpdateAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/grants: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner#delete + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Delete get: - description: |- - Search app entitlements, include app users, users, expires, discovered. - Response rows are large — request a small page_size (≤10) to keep responses small. - operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsWithExpired + description: ListOwnerIDs lists owner IDs for a given app resource. + operationId: c1.api.app.v1.AppResourceOwners.ListOwnerIDs parameters: - in: path name: app_id @@ -43911,73 +51831,77 @@ paths: description: The appId field. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The appEntitlementId field. + description: The resourceTypeId field. type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + - in: path + name: resource_id + required: true schema: - description: The pageToken field. + description: The resourceId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse' - description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. - summary: Search App Entitlements With Expired + $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnerIDsResponse' + description: The response message for listing app resource owners IDs. + summary: List Owner I Ds tags: - - App Entitlement - x-speakeasy-group: AppEntitlementSearch - x-speakeasy-name-override: SearchAppEntitlementsWithExpired - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/remove-membership: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Resource_Owner#read + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/owners: delete: - description: Remove a user from a ConductorOne-managed entitlement (catalog, group, or profile type). For access profiles, this creates a revoke task to deprovision access. - operationId: c1.api.app.v1.AppEntitlements.RemoveEntitlementMembership + description: Remove a user from the owners of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.Remove parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: The ID of the app that owns the resource. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the app entitlement to remove the membership from. + description: The ID of the resource type that classifies the resource. + type: string + - in: path + name: resource_id + required: true + schema: + description: The ID of the app resource to remove an owner from. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipResponse' - description: Successful response - summary: Remove Entitlement Membership + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerResponse' + description: The empty response message for removing an owner from an app resource. + summary: Remove tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: RemoveEntitlementMembership - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users: + - App Resource Owner + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Remove get: - deprecated: true - description: List the users, as AppEntitlementUsers objects, of an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.ListUsers + description: List all owners of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.List parameters: - in: path name: app_id @@ -43986,10 +51910,16 @@ paths: description: The appId field. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The appEntitlementId field. + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. type: string - in: query name: page_size @@ -44007,564 +51937,689 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementUsersResponse' - description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. - summary: List Users + $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnersResponse' + description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable + summary: List tags: - - App Entitlement + - App Resource Owner x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: AppEntitlementUsers#read + terraform-datasource: AppResourceOwners#read terraform-resource: null - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListUsers - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/remove-grant-duration: + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: List post: - description: Remove the expiration time from a grant, converting it to an indefinite (standing) grant. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.RemoveGrantDuration + description: Add a user as an owner of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.Add parameters: - in: path name: app_id required: true schema: - description: The ID of the app that owns the entitlement. + description: The ID of the app that owns the resource. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the entitlement whose grant duration is being removed. + description: The ID of the resource type that classifies the resource. type: string - in: path - name: app_user_id + name: resource_id required: true schema: - description: The ID of the app user whose grant expiration is being removed. + description: The ID of the app resource to add an owner to. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationResponse' - description: The response message for removing the expiration time from a grant. - summary: Remove Grant Duration + $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerResponse' + description: The empty response message for adding an owner to an app resource. + summary: Add tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: RemoveGrantDuration - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/update-grant-duration: - post: - description: Update the expiration time of an existing grant, changing when automatic revocation will occur. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.UpdateGrantDuration + - App Resource Owner + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Add + put: + description: Sets the owners for a given app resource to the specified list of users. + operationId: c1.api.app.v1.AppResourceOwners.Set parameters: - in: path name: app_id required: true schema: - description: The ID of the app that owns the entitlement. + description: The appId field. type: string - in: path - name: app_entitlement_id + name: resource_type_id required: true schema: - description: The ID of the entitlement whose grant duration is being updated. + description: The resourceTypeId field. type: string - in: path - name: app_user_id + name: resource_id required: true schema: - description: The ID of the app user whose grant is being updated. + description: The resourceId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationResponse' - description: The response message for updating the duration of a grant. - summary: Update Grant Duration + $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersResponse' + description: The empty response message for setting the app resource owners. + summary: Set tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: UpdateGrantDuration - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{identity_user_id}/grants: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner#create + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/sso/applications: get: - description: Returns a list of app users for the identity in the app. If that app user also has a grant to the entitlement from the request, data about the grant is also returned. It will always return ALL app users for this identity, but only SOME may have grant data. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.ListAppUsersForIdentityWithGrant + description: |- + List returns the SSO applications configured for an application, one page + at a time. + operationId: c1.api.sso.v1.SSOApplicationService.List parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application in your catalog to list SSO applications for. + type: string + - in: query + name: page_size + schema: + description: Maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Pagination token from a previous response. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceListResponse' + description: SSOApplicationServiceListResponse returns a page of SSO applications. + summary: List + tags: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: List + post: + description: |- + Create an SSO application for an application in your catalog. The + entitlement that governs sign-in is created alongside it. OIDC creation + also server-mints the required initial client and returns its secret once + when the client is confidential. SAML creation has no OAuth-client step. + operationId: c1.api.sso.v1.SSOApplicationService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The application in your catalog to attach this sign-in configuration to. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateResponse' + description: SSOApplicationServiceCreateResponse returns the created SSO application. + summary: Create + tags: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/sso/applications/{id}: + delete: + description: |- + Delete retires an SSO application and its sign-in entitlement, stopping + OIDC and SAML sign-in through it. OAuth clients and locator bindings remain + so administrators can list and delete retained clients; the bindings are + inert while their parent application is deleted. + operationId: c1.api.sso.v1.SSOApplicationService.Delete + parameters: - in: path - name: app_entitlement_id + name: app_id required: true schema: - description: The appEntitlementId field. + description: The application in your catalog that owns the SSO application. type: string - in: path - name: identity_user_id + name: id required: true schema: - description: The identityUserId field. + description: Unique identifier for the SSO application. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse' - description: Successful response - summary: List App Users For Identity With Grant + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceDeleteResponse' + description: SSOApplicationServiceDeleteResponse confirms deletion. + summary: Delete tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: ListAppUsersForIdentityWithGrant - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/ownerids: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: Delete get: - description: ListUserIDs lists owner IDs for a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.ListOwnerIDs + description: Get returns a single SSO application by app_id + id. + operationId: c1.api.sso.v1.SSOApplicationService.Get parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to list owners of. + description: The application in your catalog that owns the SSO application. type: string - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to list owners of. + description: Unique identifier for the SSO application. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnerIDsResponse' - description: The response message for listing app entitlement owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceGetResponse' + description: SSOApplicationServiceGetResponse returns a single SSO application. + summary: Get tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Entitlement_Owner#read - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners: - delete: - description: Delete deletes the owners from a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Delete + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: Get + post: + description: |- + Update changes an SSO application's mutable display, lifetime, enablement, + OIDC claim/signing settings, or SAML endpoint/signing/encryption settings. + Protocol, subject type, sector, SAML entity ID, and NameID format remain + immutable; requests that would change them are rejected. + operationId: c1.api.sso.v1.SSOApplicationService.Update parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to remove the owner of. + description: |- + The application in your catalog that owns this sign-in configuration. Its + owners, entitlements, and access reviews govern who may sign in. type: string - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to remove the owner of. + description: Unique identifier for this SSO application. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersResponse' - description: the empty response message for deleting app entitlement owners. - summary: Delete + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceUpdateResponse' + description: SSOApplicationServiceUpdateResponse returns the updated SSO application. + summary: Update tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Owner#delete - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Delete + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/sso/applications/{id}/clients: get: - description: List owners for a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.List + description: |- + ListClients returns the App-owned OAuth clients minted for an OIDC + application, one page at a time. Results hydrate from the PostgreSQL + projection, so a newly created client may appear after a brief delay. + operationId: c1.api.sso.v1.SSOApplicationService.ListClients parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to list owners of. + description: Application that owns the SSO application. type: string - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to list owners of. + description: SSO application whose clients to list. type: string - in: query name: page_size schema: - description: The page_size field for pagination. + description: Maximum number of clients to return. format: int32 type: integer - in: query name: page_token schema: - description: The page_token field for pagination. + description: Pagination token from a previous response. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnersResponse' - description: The response message for listing app entitlement owners. - summary: List + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceListClientsResponse' + description: |- + SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth + clients. + summary: List Clients tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: AppEntitlementOwners#read - terraform-resource: null - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: List + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: ListClients post: - description: Add an owner to a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Add + description: |- + CreateClient mints an additional App-owned OAuth client for an OIDC + application. C1 generates the client ID and any confidential-client secret. + operationId: c1.api.sso.v1.SSOApplicationService.CreateClient parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to add the owner to. + description: Application that owns the SSO application. type: string - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to add the owner to. + description: SSO application that will govern this client. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateClientRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerResponse' - description: The empty response message for adding an app entitlement owner. - summary: Add + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceCreateClientResponse' + description: |- + SSOApplicationServiceCreateClientResponse contains the generated client and + its one-time secret, when applicable. + summary: Create Client tags: - - App Entitlement Owner - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Add - put: - description: Sets the owners for a given app entitlement to the specified list of users. - operationId: c1.api.app.v1.AppEntitlementOwners.Set + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: CreateClient + /api/v1/apps/{app_id}/sso/applications/{id}/clients/delete: + post: + description: DeleteClient deletes one App-owned OAuth client and its sign-in binding. + operationId: c1.api.sso.v1.SSOApplicationService.DeleteClient parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to set the owners of. + description: Application that owns the client. type: string - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to set the owners of. + description: SSO application that governs the client. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceDeleteClientRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersResponse' - description: The empty response message for setting the app entitlement owners. - summary: Set + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceDeleteClientResponse' + description: SSOApplicationServiceDeleteClientResponse confirms deletion. + summary: Delete Client tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Owner#create - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners/{user_id}: - delete: - description: Remove an owner from a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Remove + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: DeleteClient + /api/v1/apps/{app_id}/sso/applications/{id}/clients/rotate-secret: + post: + description: |- + RotateClientSecret replaces a confidential App-owned client's secret and + returns the new value once. The old secret stops working immediately; for + an overlap window, create a second client, migrate, then delete the first. + Public clients have no secret to rotate. + operationId: c1.api.sso.v1.SSOApplicationService.RotateClientSecret parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app entitlement to remove the owner of. - type: string - - in: path - name: entitlement_id - required: true - schema: - description: The entitlement_id field for the app entitlement to remove the owner of. + description: Application that owns the client. type: string - in: path - name: user_id + name: id required: true schema: - description: The user_id field for the user to remove as an owner of the app entitlement. + description: SSO application that governs the client. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceRotateClientSecretRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerResponse' - description: The empty response message for removing an app entitlement owner. - summary: Remove + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceRotateClientSecretResponse' + description: |- + SSOApplicationServiceRotateClientSecretResponse contains the replacement + secret. The value cannot be retrieved again. + summary: Rotate Client Secret tags: - - App Entitlement Owner - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Remove - /api/v1/apps/{app_id}/entitlements/{id}: - delete: - description: Delete an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Delete + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: RotateClientSecret + /api/v1/apps/{app_id}/sso/applications/{id}/clients/update: + post: + description: |- + UpdateClient replaces mutable client configuration. The authentication + method and generated ID are immutable; private-key JWKS may rotate and a + legacy PKCE policy may tighten to required. + operationId: c1.api.sso.v1.SSOApplicationService.UpdateClient parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. + description: Application that owns the client. type: string - in: path name: id required: true schema: - description: The ID of the app entitlement to delete. + description: SSO application that governs the client. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceUpdateClientRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementResponse' - description: Successful response - summary: Delete + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceUpdateClientResponse' + description: SSOApplicationServiceUpdateClientResponse contains the updated client. + summary: Update Client tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#delete - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Delete + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: UpdateClient + /api/v1/apps/{app_id}/sso/applications/{id}/history: get: - description: Get an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Get + description: |- + ListHistory returns the change history (newest first) for a single SSO + application — each entry is a snapshot plus who/when metadata. + operationId: c1.api.sso.v1.SSOApplicationService.ListHistory parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application in your catalog that owns the SSO application. type: string - in: path name: id required: true schema: - description: The id field. + description: Unique identifier for the SSO application. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementResponse' - description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. - summary: Get + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceListHistoryResponse' + description: |- + SSOApplicationServiceListHistoryResponse returns SSO application history + entries. + summary: List History tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Custom App Entitlement#read - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Get + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/sso/applications/{id}/subjects/delete: post: - description: Update an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Update + description: |- + Deletes one bounded batch of compatibility bindings. Imported and + user-attribute-derived bindings are recoverable so corrected source data + can be applied on the next import or sign-in. Correct attribute source data + before deleting its binding so a concurrent sign-in cannot recreate the + stale value. + operationId: c1.api.sso.v1.SSOApplicationService.BatchDeleteSubjectCompatibility parameters: - in: path name: app_id required: true schema: - description: The ID of the app that is associated with the app entitlement. + description: The appId field. type: string - in: path name: id required: true schema: - description: The unique ID for the App Entitlement. - readOnly: true + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRequestInput' + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse' + description: |- + SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded + recovery progress. + summary: Batch Delete Subject Compatibility tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#update - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/entitlements/resource_types/{app_resource_type_id}/resources/{app_resource_id}: - get: - description: List app entitlements associated with an app resource. - operationId: c1.api.app.v1.AppEntitlements.ListForAppResource + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: BatchDeleteSubjectCompatibility + /api/v1/apps/{app_id}/sso/applications/{id}/subjects/import: + post: + description: |- + Validates or imports one bounded batch of compatibility-subject bindings. + Clients parse source files and submit at most 50 rows per request so they + can expose progress and retry from a known boundary. + operationId: c1.api.sso.v1.SSOApplicationService.BatchImportSubjectCompatibility parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application in your catalog that owns the SSO application. type: string - in: path - name: app_resource_type_id + name: id required: true schema: - description: The appResourceTypeId field. + description: Unique identifier for the SSO application. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceBatchImportSubjectCompatibilityRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceBatchImportSubjectCompatibilityResponse' + description: |- + SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one + bounded validation or apply batch. + summary: Batch Import Subject Compatibility + tags: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: BatchImportSubjectCompatibility + /api/v1/apps/{app_id}/usage_controls: + get: + description: Get usage controls, as an AppUsageControls object which describes some peripheral configuration, for an app. + operationId: c1.api.app.v1.AppUsageControlsService.Get + parameters: - in: path - name: app_resource_id + name: app_id required: true schema: - description: The appResourceId field. + description: The appId field. type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppUsageControlsResponse' + description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. + summary: Get + tags: + - App Usage Controls + x-speakeasy-group: AppUsageControls + x-speakeasy-name-override: Get + post: + description: Update usage controls for an app. + operationId: c1.api.app.v1.AppUsageControlsService.Update + parameters: + - in: path + name: app_id + required: true schema: - description: The pageToken field. + description: The app that this object belongs to. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: List For App Resource + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsResponse' + description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. + summary: Update tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListForAppResource - /api/v1/apps/{app_id}/entitlements/users/{app_user_id}: + - App Usage Controls + x-speakeasy-group: AppUsageControls + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/users/{user_id}/app_users: get: - description: List app entitlements associated with an app user. - operationId: c1.api.app.v1.AppEntitlements.ListForAppUser + description: List app user accounts within a specific app that are correlated to a given C1 user. + operationId: c1.api.app.v1.AppUserService.ListAppUsersForUser parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The ID of the app to list users for. type: string - in: path - name: app_user_id + name: user_id required: true schema: - description: The appUserId field. + description: The C1 user ID to filter app users by identity correlation. type: string - in: query name: page_size schema: - description: The pageSize field. + description: The maximum number of results to return per page. format: int32 type: integer - in: query name: page_token schema: - description: The pageToken field. + description: The token for fetching the next page of results. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: List For App User + $ref: '#/components/schemas/c1.api.app.v1.AppUsersForUserServiceListResponse' + description: The response message for listing app users correlated to a specific C1 user. + summary: List App Users For User tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListForAppUser - /api/v1/apps/{app_id}/mcp_servers: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListAppUsersForUser + /api/v1/apps/{app_id}/xaa/access_profiles: get: - description: List retrieves MCP servers for an app. - operationId: c1.api.ai_governance.v1.MCPServerService.List + description: List the access profiles defined for an application, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.List parameters: - in: path name: app_id required: true schema: - description: App identifier (required). + description: The application to list access profiles for. type: string - in: query name: page_size @@ -44582,256 +52637,310 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceListResponse' - description: MCPServerServiceListResponse returns a paginated list of MCP servers. + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListResponse' + description: XAAAccessProfileServiceListResponse returns a page of access profiles. summary: List tags: - - MCP Servers - x-speakeasy-group: MCPServer + - Cross-App Access + x-speakeasy-group: XAAAccessProfile x-speakeasy-name-override: List post: description: |- - Register a new MCP server under an application. Set server_type to HOSTED - (C1 runs a catalog integration) or EXTERNAL (a third-party MCP server you - point C1 at by URL). Auth credentials are validated and stored securely. - operationId: c1.api.ai_governance.v1.MCPServerService.Register + Create an access profile under a resource server. The backend also + provisions a backing AppEntitlement that users request to be granted the + profile's scopes. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Create parameters: - in: path name: app_id required: true schema: - description: |- - App to register the MCP server under. When empty and app_managed_state_binding_ref - is not set, a new managed app is created automatically. + description: The application that owns the resource server. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterResponse' - description: MCPServerServiceRegisterResponse returns the newly created MCP server. - summary: Register + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateResponse' + description: XAAAccessProfileServiceCreateResponse returns the created access profile. + summary: Create tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: Register - /api/v1/apps/{app_id}/mcp_servers/{connector_id}: - delete: - description: |- - Delete an MCP server. Its connector stops and it is soft-deleted from this - tenant's MCP catalog, and any per-user credentials issued against it are - revoked. - operationId: c1.api.ai_governance.v1.MCPServerService.Delete + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings: + get: + description: List the scopes bound to an access profile, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.List parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path - name: connector_id + name: access_profile_id required: true schema: - description: MCP server identifier (connector ID). + description: The access profile to list bindings for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteResponse' - description: MCPServerServiceDeleteResponse confirms deletion. - summary: Delete + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceListResponse' + description: XAAAccessProfileScopeBindingServiceListResponse returns scope bindings. + summary: List tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: Delete - get: - description: Get retrieves a single MCP server. - operationId: c1.api.ai_governance.v1.MCPServerService.Get + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: List + post: + description: |- + CreateBindings binds one or more scopes (xaa_scope_ids) to an access + profile. Every scope must belong to the profile's resource server. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.CreateBindings parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path - name: connector_id + name: access_profile_id required: true schema: - description: MCP server identifier (connector ID). + description: The access profile to bind scopes to. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceGetResponse' - description: MCPServerServiceGetResponse returns a single MCP server. - summary: Get + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse' + description: XAAAccessProfileScopeBindingServiceCreateResponse returns created bindings. + summary: Create Bindings tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: Get + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: CreateBindings + /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings/delete: post: - description: Update modifies an existing MCP server's editable fields. - operationId: c1.api.ai_governance.v1.MCPServerService.Update + description: |- + DeleteBindings unbinds one or more scopes (xaa_scope_ids) from an access + profile. Uses a POST .../delete action route because the scope IDs travel + in the request body, which HTTP DELETE does not reliably support. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.DeleteBindings parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path - name: connector_id + name: access_profile_id required: true schema: - description: MCP server identifier (connector ID). + description: The access profile to unbind scopes from. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateResponse' - description: MCPServerServiceUpdateResponse returns the updated MCP server. - summary: Update + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteResponse' + description: XAAAccessProfileScopeBindingServiceDeleteResponse confirms deletion. + summary: Delete Bindings tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/mcp_servers/{connector_id}/credentials: - post: - description: UpdateCredentials replaces the auth config and/or config fields for an MCP server. - operationId: c1.api.ai_governance.v1.MCPServerService.UpdateCredentials + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: DeleteBindings + /api/v1/apps/{app_id}/xaa/access_profiles/{id}: + delete: + description: |- + Delete an access profile (soft delete). Cascades to its scope bindings and + backing entitlement; outstanding grants end with the entitlement. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Delete parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path - name: connector_id + name: id required: true schema: - description: MCP server identifier (connector ID). + description: Unique identifier for the access profile. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsResponse' - description: MCPServerServiceUpdateCredentialsResponse returns the updated MCP server. - summary: Update Credentials + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteResponse' + description: XAAAccessProfileServiceDeleteResponse confirms deletion. + summary: Delete tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: UpdateCredentials - /api/v1/apps/{app_id}/mcp_servers/{connector_id}/resync_tools: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Delete + get: + description: Get an access profile by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the access profile. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetResponse' + description: XAAAccessProfileServiceGetResponse returns a single access profile. + summary: Get + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Get post: description: |- - ResyncTools re-runs per-identity tool discovery for the calling user's - own credential on a per-user MCP server, so a session opened before the - user connected (or after their visible tools changed) doesn't have to - wait for the next unrelated MCPTool/AppEntitlementUserBinding change to - pick it up. - operationId: c1.api.ai_governance.v1.MCPServerService.ResyncTools + Update an access profile's editable fields via update_mask. Editable + paths: display_name, description. The profile must include id and app_id. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Update parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path - name: connector_id + name: id required: true schema: - description: MCP server identifier (connector ID). + description: Unique identifier for this access profile. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsResponse' - description: MCPServerServiceResyncToolsResponse is empty on success. - summary: Resync Tools + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateResponse' + description: XAAAccessProfileServiceUpdateResponse returns the updated access profile. + summary: Update tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: ResyncTools - /api/v1/apps/{app_id}/mcp_servers/search: - post: - description: SearchWithToolCount searches MCP servers with filtering and returns per-server tool state counts. - operationId: c1.api.ai_governance.v1.MCPServerService.SearchWithToolCount + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/access_profiles/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single access + profile — each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.ListHistory parameters: - in: path name: app_id required: true schema: - description: App identifier (required). + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the access profile. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountResponse' - description: MCPServerServiceSearchWithToolCountResponse returns matching MCP servers with tool counts. - summary: Search With Tool Count + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListHistoryResponse' + description: |- + XAAAccessProfileServiceListHistoryResponse returns access profile history + entries. + summary: List History tags: - - MCP Servers - x-speakeasy-group: MCPServer - x-speakeasy-name-override: SearchWithToolCount - /api/v1/apps/{app_id}/mcp_toolsets/by_app_entitlement_id/{app_entitlement_id}: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/xaa/access_profiles/by_app_entitlement_id/{app_entitlement_id}: get: description: |- - GetByAppEntitlementId looks up the toolset (access profile) linked to a - synced role entitlement, by app_id + app_entitlement_id. - operationId: c1.api.ai_governance.v1.MCPAccessProfileService.GetByAppEntitlementId + GetByAppEntitlementId looks up the access profile linked to an + entitlement, by app_id + app_entitlement_id. Used by the request catalog. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.GetByAppEntitlementId parameters: - in: path name: app_id required: true schema: - description: App identifier. + description: The application that owns the resource server. type: string - in: path name: app_entitlement_id @@ -44844,795 +52953,866 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetByAppEntitlementIdResponse' - description: MCPAccessProfileServiceGetByAppEntitlementIdResponse returns the matched profile. + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetByAppEntitlementIdResponse' + description: |- + XAAAccessProfileServiceGetByAppEntitlementIdResponse returns the matched + profile. summary: Get By App Entitlement Id tags: - - MCP Toolsets - x-speakeasy-group: MCPAccessProfile + - Cross-App Access + x-speakeasy-group: XAAAccessProfile x-speakeasy-name-override: GetByAppEntitlementId - /api/v1/apps/{app_id}/ownerids: + /api/v1/apps/{app_id}/xaa/resource_servers: get: - description: ListOwnerIDs lists owner IDs for a given app. - operationId: c1.api.app.v1.AppOwners.ListOwnerIDs + description: List the resource servers registered for an application, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.List parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app to list owners of. + description: The application to list resource servers for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnerIDsResponse' - description: The response message for listing app owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListResponse' + description: XAAResourceServerServiceListResponse returns a page of resource servers. + summary: List tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Owner#read - x-speakeasy-group: AppOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/owners: - delete: - description: Delete deletes the owners from a given app. - operationId: c1.api.app.v1.AppOwners.Delete + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: List + post: + description: |- + Register a resource server (a third-party authorization server) as a + permitted cross-app-access audience for an application. The audience must + be unique within the application and must not equal your own tenant's + issuer — C1 cannot be both the granting IdP and the resource server in the + same flow. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Create parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app to remove the owner of. + description: The application this resource server fronts. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersResponse' - description: the empty response message for deleting app owners. - summary: Delete + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse' + description: XAAResourceServerServiceCreateResponse returns the registered resource server. + summary: Create tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner#delete - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Delete - get: - description: List owners of an app. - operationId: c1.api.app.v1.AppOwners.List + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/resource_servers/{id}: + delete: + description: |- + Delete a resource server (soft delete). Cascades to its scopes, access + profiles, and client audience mappings. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Delete parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application this resource server fronts. type: string - - in: query - name: page_size - schema: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - type: integer - - in: query - name: page_token + - in: path + name: id + required: true schema: - description: The pageToken field. + description: Unique identifier for the resource server. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnersResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteResponse' + description: XAAResourceServerServiceDeleteResponse confirms deletion. + summary: Delete tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: AppOwners#read - terraform-resource: null - x-speakeasy-group: AppOwners - x-speakeasy-name-override: List - put: - description: Sets the owners for a given app to the specified list of users. - operationId: c1.api.app.v1.AppOwners.Set + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Delete + get: + description: Get a registered resource server by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Get parameters: - in: path name: app_id required: true schema: - description: The app_id field for the app to set the owners of. + description: The application this resource server fronts. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the resource server. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersResponse' - description: The empty response message for setting the app owners. - summary: Set + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceGetResponse' + description: XAAResourceServerServiceGetResponse returns a single resource server. + summary: Get tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner#create - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/owners/{user_id}: - delete: - description: Removes an owner from an app. - operationId: c1.api.app.v1.AppOwners.Remove + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Get + post: + description: |- + Update a resource server's editable fields via update_mask. The audience + is immutable (delete and recreate to change it); supplying a different + audience is rejected. Editable paths: display_name, description, + resource_uris, max_grant_lifetime, signing_algorithm, + require_proof_of_possession, modify_claims_hook, disabled. sector_id is + immutable once set (delete and recreate to change it). + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Update parameters: - in: path name: app_id required: true schema: - description: App ID of the app to remove the owner from. + description: The application this resource server fronts. type: string - in: path - name: user_id + name: id required: true schema: - description: User ID of the user to remove as an owner. + description: Unique identifier for this resource server. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerResponse' - description: Empty response with a status code indicating success. - summary: Remove + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateResponse' + description: XAAResourceServerServiceUpdateResponse returns the updated resource server. + summary: Update tags: - - App Owner - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Remove - post: - description: Adds an owner to an app. - operationId: c1.api.app.v1.AppOwners.Add + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/resource_servers/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single + resource server — each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.ListHistory parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application this resource server fronts. type: string - in: path - name: user_id + name: id required: true schema: - description: The userId field. + description: Unique identifier for the resource server. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerResponse' - description: Empty response with a status code indicating success - summary: Add + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListHistoryResponse' + description: |- + XAAResourceServerServiceListHistoryResponse returns resource server history + entries. + summary: List History tags: - - App Owner - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Add - /api/v1/apps/{app_id}/report: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/xaa/scopes: get: - description: Get a list of reports for the given app. - operationId: c1.api.app.v1.AppReportService.List + description: |- + List the scopes defined for an application, one page at a time. To filter + by resource server, state, or classification, use Search. + operationId: c1.api.cross_app_access.v1.XAAScopeService.List parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application to list scopes for. type: string - in: query name: page_size schema: - description: The pageSize field. + description: Page size (max 100). format: int32 type: integer - in: query name: page_token schema: - description: The pageToken field. + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppReportServiceListResponse' - description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListResponse' + description: XAAScopeServiceListResponse returns a page of scopes. summary: List tags: - - App Reports - x-speakeasy-group: AppReport + - Cross-App Access + x-speakeasy-group: XAAScope x-speakeasy-name-override: List post: - description: Generate a report for the given app. - operationId: c1.api.app.v1.AppReportActionService.GenerateReport + description: |- + Declare a scope under a resource server. The scope value is the literal + OAuth scope string and is immutable after creation. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Create parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application that owns the resource server. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportResponse' - description: Empty response body. Status code indicates success. - summary: Generate Report + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateResponse' + description: XAAScopeServiceCreateResponse returns the created scope. + summary: Create tags: - - App Reports - x-speakeasy-group: AppReportAction - x-speakeasy-name-override: GenerateReport - /api/v1/apps/{app_id}/resource_types: - get: - description: List app resource types. - operationId: c1.api.app.v1.AppResourceTypeService.List + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/scopes/{id}: + delete: + description: |- + Delete a scope (soft delete). Cascades to its backing entitlement and to + any access-profile bindings that reference it. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Delete parameters: - in: path name: app_id required: true schema: - description: The appId field. + description: The application that owns the resource server. type: string - - in: query - name: page_size + - in: path + name: id + required: true schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + description: Unique identifier for the scope. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteResponse' + description: XAAScopeServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Delete + get: + description: Get a scope by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Get + parameters: + - in: path + name: app_id + required: true schema: - description: The pageToken field. + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the scope. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceListResponse' - description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceGetResponse' + description: XAAScopeServiceGetResponse returns a single scope. + summary: Get tags: - - App Resource Type - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: List + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Get post: - description: Create a manually managed resource type that classifies resources within an app. - operationId: c1.api.app.v1.AppResourceTypeService.CreateManuallyManagedResourceType + description: |- + Update a scope's editable fields via update_mask. This is how a scope is + approved: set state to ENABLED to make it mintable, or DISABLED to block + it. The scope value is immutable. Editable paths: display_name, + description, state, classification. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Update parameters: - in: path name: app_id required: true schema: - description: The ID of the app to create the resource type under. + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this scope. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeResponse' - description: The response message for creating a manually managed resource type. - summary: Create Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateResponse' + description: XAAScopeServiceUpdateResponse returns the updated scope. + summary: Update tags: - - App Resource Type - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource Type#create - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: CreateManuallyManagedResourceType - /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/scopes/{id}/history: get: - description: List app resources for a given app and optionally filter by resource type. - operationId: c1.api.app.v1.AppResourceService.List + description: |- + ListHistory returns the change history (newest first) for a single scope — + each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAScopeService.ListHistory parameters: - in: path name: app_id required: true schema: - description: The ID of the app to list resources for. + description: The application this scope belongs to. type: string - in: path - name: app_resource_type_id + name: id required: true schema: - description: Optional resource type ID to filter results by. If empty, resources of all types are returned. + description: Unique identifier for the scope. type: string - in: query name: page_size schema: - description: The maximum number of results to return per page. + description: Page size (max 200). format: int32 type: integer - in: query name: page_token schema: - description: The token for fetching the next page of results. + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceListResponse' - description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse' + description: XAAScopeServiceListHistoryResponse returns scope history entries. + summary: List History tags: - - App Resource - x-speakeasy-group: AppResource - x-speakeasy-name-override: List + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_user_app_id}/app_users/{app_user_id}: post: - description: Create a manually managed app resource tracked directly by ConductorOne under an existing resource type. - operationId: c1.api.app.v1.AppResourceService.CreateManuallyManagedAppResource + description: |- + Update an app user by ID. Only the fields specified in the update mask are updated. + Currently, only the appUserType, and identityUserId fields can be updated. + operationId: c1.api.app.v1.AppUserService.Update parameters: - in: path - name: app_id + name: app_user_app_id required: true schema: - description: The ID of the app to create the resource under. + description: The ID of the application. + readOnly: true type: string - in: path - name: app_resource_type_id + name: app_user_id required: true schema: - description: The resource type ID that classifies this resource. + description: A unique idenditfier of the application user. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceResponse' - description: The response message for creating a manually managed app resource. - summary: Create Manually Managed App Resource + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateResponse' + description: Successful response + summary: Update tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource#create - x-speakeasy-group: AppResource - x-speakeasy-name-override: CreateManuallyManagedAppResource - /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources/{id}: - delete: - description: Delete a manually managed app resource and its associated entitlements from an app. - operationId: c1.api.app.v1.AppResourceService.DeleteManuallyManagedAppResource + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: Update + /api/v1/apps/{connector_app_id}/connectors/{connector_id}/delegated: + post: + description: Update a delegated connector. + operationId: c1.api.app.v1.ConnectorService.UpdateDelegated parameters: - in: path - name: app_id + name: connector_app_id required: true schema: - description: The ID of the app that owns the resource. + description: The id of the app the connector is associated with. type: string - in: path - name: app_resource_type_id + name: connector_id required: true schema: - description: The ID of the resource type that classifies the resource. + description: The id of the connector. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' + description: ConnectorServiceUpdateResponse is the response returned by the update method. + summary: Update Delegated + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: UpdateDelegated + /api/v1/apps/{id}: + delete: + description: Delete an app. + operationId: c1.api.app.v1.Apps.Delete + parameters: - in: path name: id required: true schema: - description: The ID of the app resource to delete. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceResponse' - description: The empty response message for deleting a manually managed app resource. - summary: Delete Manually Managed App Resource + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResponse' + description: Empty response body. Status code indicates success. + summary: Delete tags: - - App Resource + - App x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Resource#delete - x-speakeasy-group: AppResource - x-speakeasy-name-override: DeleteManuallyManagedAppResource + terraform-resource: App#delete + x-speakeasy-group: Apps + x-speakeasy-name-override: Delete get: - description: Retrieve a single app resource by its app, resource type, and resource ID. - operationId: c1.api.app.v1.AppResourceService.Get + description: Get an app by ID. + operationId: c1.api.app.v1.Apps.Get parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The ID of the resource type that classifies this resource. - type: string - in: path name: id required: true schema: - description: The unique ID of the app resource to retrieve. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceGetResponse' - description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. + $ref: '#/components/schemas/c1.api.app.v1.GetAppResponse' + description: The GetAppResponse message contains the details of the requested app in the app field. summary: Get tags: - - App Resource + - App x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App Resource#read - terraform-resource: App Resource#read - x-speakeasy-group: AppResource + terraform-datasource: null + terraform-resource: App#read + x-speakeasy-group: Apps x-speakeasy-name-override: Get post: - description: Update an app resource's fields. Only the fields specified in the update mask are modified. - operationId: c1.api.app.v1.AppResourceService.Update + description: Update an existing app. + operationId: c1.api.app.v1.Apps.Update parameters: - - in: path - name: app_id - required: true - schema: - description: The app that this resource belongs to. - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The resource type that this resource is. - type: string - in: path name: id required: true schema: - description: The id of the resource. + description: The ID of the app. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateResponse' - description: The response message for updating an app resource. + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppResponse' + description: Returns the updated app's new values. summary: Update tags: - - App Resource + - App x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Resource#update - x-speakeasy-group: AppResource + terraform-resource: App#update + x-speakeasy-group: Apps x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/resource_types/{id}: + /api/v1/apps/{src_app_id}/{src_app_entitlement_id}/bindings/{dst_app_id}/{dst_app_entitlement_id}: delete: - description: Delete a manually managed resource type and all its associated resources from an app. - operationId: c1.api.app.v1.AppResourceTypeService.DeleteManuallyManagedResourceType + description: Delete a proxy binding between a source and destination entitlement. + operationId: c1.api.app.v1.AppEntitlementsProxy.Delete parameters: - in: path - name: app_id + name: src_app_id required: true schema: - description: The ID of the app that owns the resource type. + description: The ID of the app that owns the source entitlement. type: string - in: path - name: id + name: src_app_entitlement_id required: true schema: - description: The ID of the resource type to delete. + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse' - description: The empty response message for deleting a manually managed resource type. - summary: Delete Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyResponse' + description: The empty response message for deleting an entitlement proxy binding. + summary: Delete tags: - - App Resource Type + - App Entitlement Proxy Binding x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Resource Type#delete - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: DeleteManuallyManagedResourceType + terraform-resource: App Entitlement Proxy Binding#delete + x-speakeasy-group: AppEntitlementsProxy + x-speakeasy-name-override: Delete get: - description: Get an app resource type. - operationId: c1.api.app.v1.AppResourceTypeService.Get + description: Retrieve a specific proxy binding between a source and destination entitlement. + operationId: c1.api.app.v1.AppEntitlementsProxy.Get parameters: - in: path - name: app_id + name: src_app_id required: true schema: - description: The appId field. + description: The ID of the app that owns the source entitlement. type: string - in: path - name: id + name: src_app_entitlement_id required: true schema: - description: The id field. + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceGetResponse' - description: |- - The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask - in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementProxyResponse' + description: The response message for getting a specific entitlement proxy binding. summary: Get tags: - - App Resource Type + - App Entitlement Proxy Binding x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App Resource Type#read - x-speakeasy-group: AppResourceType + terraform-datasource: App Entitlement Proxy Binding#read + terraform-resource: App Entitlement Proxy Binding#read + x-speakeasy-group: AppEntitlementsProxy x-speakeasy-name-override: Get post: - description: Update a manually managed resource type's fields. Only the fields specified in the update mask are modified. - operationId: c1.api.app.v1.AppResourceTypeService.UpdateManuallyManagedResourceType + description: Create a proxy binding between a source and destination entitlement, establishing a hierarchical relationship. + operationId: c1.api.app.v1.AppEntitlementsProxy.Create parameters: - in: path - name: app_id + name: src_app_id required: true schema: - description: The ID of the app that is associated with the app resource type - readOnly: true + description: The ID of the app that owns the source entitlement. type: string - in: path - name: id + name: src_app_entitlement_id required: true schema: - description: The unique ID for the app resource type. - readOnly: true + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse' - description: The response message for updating a manually managed resource type. - summary: Update Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyResponse' + description: The response message for creating an entitlement proxy binding. + summary: Create tags: - - App Resource Type + - App Entitlement Proxy Binding x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Resource Type#update - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: UpdateManuallyManagedResourceType - /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/ownerids: - delete: - description: Delete deletes the owners from a given app resource. - operationId: c1.api.app.v1.AppResourceOwners.Delete - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - type: string - - in: path - name: resource_id - required: true - schema: - description: The resourceId field. - type: string + terraform-resource: App Entitlement Proxy Binding#create + x-speakeasy-group: AppEntitlementsProxy + x-speakeasy-name-override: Create + /api/v1/apps/connectors/credentials: + post: + description: Rotate credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.RotateCredential requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersResponse' - description: the empty response message for deleting app resource owners. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialResponse' + description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. + summary: Rotate Credential tags: - - App Resource Owner + - Connector x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Resource_Owner#delete - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Delete - get: - description: ListOwnerIDs lists owner IDs for a given app resource. - operationId: c1.api.app.v1.AppResourceOwners.ListOwnerIDs - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - type: string - - in: path - name: resource_id - required: true - schema: - description: The resourceId field. - type: string + terraform-resource: ConnectorCredential#create + x-speakeasy-group: Connector + x-speakeasy-name-override: RotateCredential + /api/v1/apps/connectors/validate_config/http: + post: + description: Validate an HTTP connector configuration and return any diagnostics or errors found. + operationId: c1.api.app.v1.ConnectorService.ValidateHTTPConnectorConfig + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.EditorValidateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnerIDsResponse' - description: The response message for listing app resource owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.app.v1.EditorValidateResponse' + description: The EditorValidateResponse message contains validation results. + summary: Validate Http Connector Config tags: - - App Resource Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Resource_Owner#read - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/owners: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ValidateHTTPConnectorConfig + /api/v1/attribute/{id}: delete: - description: Remove a user from the owners of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.Remove + description: Delete an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteAttributeValue parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The ID of the resource type that classifies the resource. - type: string - - in: path - name: resource_id + name: id required: true schema: - description: The ID of the app resource to remove an owner from. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerRequestInput' + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerResponse' - description: The empty response message for removing an owner from an app resource. - summary: Remove + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueResponse' + description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. + summary: Delete Attribute Value tags: - - App Resource Owner - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Remove + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteAttributeValue + /api/v1/attributes: + post: + description: Create a new attribute value. + operationId: c1.api.attribute.v1.Attributes.CreateAttributeValue + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueResponse' + description: CreateAttributeValueResponse is the response for creating an attribute value. + summary: Create Attribute Value + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateAttributeValue + /api/v1/attributes/{id}: get: - description: List all owners of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.List + description: Get an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetAttributeValue parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - type: string - - in: path - name: resource_id + name: id required: true schema: - description: The resourceId field. + description: The id field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.GetAttributeValueResponse' + description: GetAttributeValueResponse is the response for getting an attribute value by id. + summary: Get Attribute Value + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetAttributeValue + /api/v1/attributes/compliance_frameworks: + get: + description: List all compliance framework attribute values (e.g., SOC 2, HIPAA) with pagination. + operationId: c1.api.attribute.v1.Attributes.ListComplianceFrameworks + parameters: - in: query name: page_size schema: @@ -45649,1070 +53829,1193 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnersResponse' - description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable - summary: List + $ref: '#/components/schemas/c1.api.attribute.v1.ListComplianceFrameworksResponse' + description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. + summary: List Compliance Frameworks tags: - - App Resource Owner + - Compliance Framework x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: AppResourceOwners#read + terraform-datasource: Compliance Frameworks#read terraform-resource: null - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: List + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListComplianceFrameworks post: - description: Add a user as an owner of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.Add - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The ID of the resource type that classifies the resource. - type: string - - in: path - name: resource_id - required: true - schema: - description: The ID of the app resource to add an owner to. - type: string + description: Create a compliance framework value. + operationId: c1.api.attribute.v1.Attributes.CreateComplianceFrameworkAttributeValue requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerRequestInput' + $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerResponse' - description: The empty response message for adding an owner to an app resource. - summary: Add + $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Create Compliance Framework Attribute Value tags: - - App Resource Owner - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Add - put: - description: Sets the owners for a given app resource to the specified list of users. - operationId: c1.api.app.v1.AppResourceOwners.Set + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Compliance Framework#create + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateComplianceFrameworkAttributeValue + /api/v1/attributes/compliance_frameworks/{id}: + delete: + description: Delete an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteComplianceFrameworkAttributeValue parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - type: string - - in: path - name: resource_id + name: id required: true schema: - description: The resourceId field. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersRequestInput' + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersResponse' - description: The empty response message for setting the app resource owners. - summary: Set + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Delete Compliance Framework Attribute Value tags: - - App Resource Owner + - Compliance Framework x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Resource_Owner#create - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/usage_controls: + terraform-resource: Compliance Framework#delete + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValue get: - description: Get usage controls, as an AppUsageControls object which describes some peripheral configuration, for an app. - operationId: c1.api.app.v1.AppUsageControlsService.Get + description: Get an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetComplianceFrameworkAttributeValue parameters: - in: path - name: app_id + name: id required: true schema: - description: The appId field. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppUsageControlsResponse' - description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. - summary: Get + $ref: '#/components/schemas/c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Get Compliance Framework Attribute Value tags: - - App Usage Controls - x-speakeasy-group: AppUsageControls - x-speakeasy-name-override: Get - post: - description: Update usage controls for an app. - operationId: c1.api.app.v1.AppUsageControlsService.Update + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Compliance Framework#read + terraform-resource: Compliance Framework#read + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetComplianceFrameworkAttributeValue + /api/v1/attributes/risk_levels: + get: + description: List all risk level attribute values with pagination. + operationId: c1.api.attribute.v1.Attributes.ListRiskLevels parameters: - - in: path - name: app_id - required: true + - in: query + name: page_size schema: - description: The app that this object belongs to. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.ListRiskLevelsResponse' + description: ListRiskLevelsResponse is the response for listing risk level attribute values. + summary: List Risk Levels + tags: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Risk Levels#read + terraform-resource: null + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListRiskLevels + post: + description: Create a risk level attribute. + operationId: c1.api.attribute.v1.Attributes.CreateRiskLevelAttributeValue requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsRequestInput' + $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsResponse' - description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. - summary: Update + $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse' + description: Successful response + summary: Create Risk Level Attribute Value tags: - - App Usage Controls - x-speakeasy-group: AppUsageControls - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/users/{user_id}/app_users: - get: - description: List app user accounts within a specific app that are correlated to a given C1 user. - operationId: c1.api.app.v1.AppUserService.ListAppUsersForUser + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Risk Level#create + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateRiskLevelAttributeValue + /api/v1/attributes/risk_levels/{id}: + delete: + description: Delete a risk level attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteRiskLevelAttributeValue parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app to list users for. - type: string - - in: path - name: user_id + name: id required: true schema: - description: The C1 user ID to filter app users by identity correlation. - type: string - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The token for fetching the next page of results. + description: The id field. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUsersForUserServiceListResponse' - description: The response message for listing app users correlated to a specific C1 user. - summary: List App Users For User + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse' + description: Successful response + summary: Delete Risk Level Attribute Value tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: ListAppUsersForUser - /api/v1/apps/{app_id}/xaa/access_profiles: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Risk Level#delete + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteRiskLevelAttributeValue get: - description: List the access profiles defined for an application, one page at a time. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.List + description: Get a risk level attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetRiskLevelAttributeValue parameters: - in: path - name: app_id + name: id required: true schema: - description: The application to list access profiles for. - type: string - - in: query - name: page_size - schema: - description: Page size (max 100). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListResponse' - description: XAAAccessProfileServiceListResponse returns a page of access profiles. - summary: List + $ref: '#/components/schemas/c1.api.attribute.v1.GetRiskLevelAttributeValueResponse' + description: Successful response + summary: Get Risk Level Attribute Value tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile - x-speakeasy-name-override: List - post: - description: |- - Create an access profile under a resource server. The backend also - provisions a backing AppEntitlement that users request to be granted the - profile's scopes. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Create + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Risk Level#read + terraform-resource: Risk Level#read + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetRiskLevelAttributeValue + /api/v1/attributes/types: + get: + description: List all attribute types. + operationId: c1.api.attribute.v1.Attributes.ListAttributeTypes parameters: - - in: path - name: app_id - required: true + - in: query + name: page_size schema: - description: The application that owns the resource server. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateResponse' - description: XAAAccessProfileServiceCreateResponse returns the created access profile. - summary: Create + $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeTypesResponse' + description: ListAttributeTypesResponse is the response for listing attribute types. + summary: List Attribute Types tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListAttributeTypes + /api/v1/attributes/types/{attribute_type_id}/values: get: - description: List the scopes bound to an access profile, one page at a time. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.List + description: List all attribute values for a given attribute type. + operationId: c1.api.attribute.v1.Attributes.ListAttributeValues parameters: - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - - in: path - name: access_profile_id + name: attribute_type_id required: true schema: - description: The access profile to list bindings for. + description: The attributeTypeId field. type: string - in: query name: page_size schema: - description: Page size (max 100). + description: The pageSize field. format: int32 type: integer - in: query name: page_token schema: - description: Page token for pagination. + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceListResponse' - description: XAAAccessProfileScopeBindingServiceListResponse returns scope bindings. - summary: List + $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeValuesResponse' + description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. + summary: List Attribute Values tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfileScopeBinding - x-speakeasy-name-override: List - post: - description: |- - CreateBindings binds one or more scopes (xaa_scope_ids) to an access - profile. Every scope must belong to the profile's resource server. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.CreateBindings + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListAttributeValues + /api/v1/auth-configs: + get: + description: List returns all authentication provider configurations for the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.List parameters: - - in: path - name: app_id - required: true + - in: query + name: page_size schema: - description: The application that owns the resource server. - type: string - - in: path - name: access_profile_id - required: true + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token schema: - description: The access profile to bind scopes to. + description: A pagination token returned from a previous List call. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse' - description: XAAAccessProfileScopeBindingServiceCreateResponse returns created bindings. - summary: Create Bindings + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceListResponse' + description: Successful response + summary: List tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfileScopeBinding - x-speakeasy-name-override: CreateBindings - /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings/delete: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: List post: - description: |- - DeleteBindings unbinds one or more scopes (xaa_scope_ids) from an access - profile. Uses a POST .../delete action route because the scope IDs travel - in the request body, which HTTP DELETE does not reliably support. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.DeleteBindings - parameters: - - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - - in: path - name: access_profile_id - required: true - schema: - description: The access profile to unbind scopes from. - type: string + description: Create registers a new authentication provider configuration for the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteResponse' - description: XAAAccessProfileScopeBindingServiceDeleteResponse confirms deletion. - summary: Delete Bindings + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse' + description: Successful response + summary: Create tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfileScopeBinding - x-speakeasy-name-override: DeleteBindings - /api/v1/apps/{app_id}/xaa/access_profiles/{id}: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: Create + /api/v1/auth-configs/{id}: delete: - description: |- - Delete an access profile (soft delete). Cascades to its scope bindings and - backing entitlement; outstanding grants end with the entitlement. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Delete + description: Delete removes an authentication provider configuration from the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Delete parameters: - - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - in: path name: id required: true schema: - description: Unique identifier for the access profile. + description: The unique identifier of the authentication provider configuration to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteResponse' - description: XAAAccessProfileServiceDeleteResponse confirms deletion. + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse' + description: Successful response summary: Delete tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile + - Auth Config + x-speakeasy-group: TenantAuthConfig x-speakeasy-name-override: Delete get: - description: Get an access profile by app_id + id. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Get + description: Get retrieves a single authentication provider configuration by its ID. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Get parameters: - - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - in: path name: id required: true schema: - description: Unique identifier for the access profile. + description: The unique identifier of the authentication provider configuration to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetResponse' - description: XAAAccessProfileServiceGetResponse returns a single access profile. + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse' + description: Successful response summary: Get tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile + - Auth Config + x-speakeasy-group: TenantAuthConfig x-speakeasy-name-override: Get post: - description: |- - Update an access profile's editable fields via update_mask. Editable - paths: display_name, description. The profile must include id and app_id. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Update + description: Update modifies an existing authentication provider configuration. Use the update mask to specify which fields to change. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Update parameters: - - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - in: path name: id required: true schema: - description: Unique identifier for this access profile. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateResponse' - description: XAAAccessProfileServiceUpdateResponse returns the updated access profile. + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse' + description: Successful response summary: Update tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile + - Auth Config + x-speakeasy-group: TenantAuthConfig x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/xaa/access_profiles/{id}/history: + /api/v1/auth/introspect: get: - description: |- - ListHistory returns the change history (newest first) for a single access - profile — each entry is a snapshot plus who/when metadata. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.ListHistory + description: Introspect returns the current user's principle_id, user_id and a list of roles, permissions, and enabled features. + operationId: c1.api.auth.v1.Auth.Introspect + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth.v1.IntrospectResponse' + description: IntrospectResponse contains information about the current user who is authenticated. + summary: Introspect + tags: + - Auth + x-speakeasy-group: Auth + x-speakeasy-name-override: Introspect + /api/v1/automation_executions: + get: + description: List all automation executions in the tenant with pagination support. + operationId: c1.api.automations.v1.AutomationExecutionService.ListAutomationExecutions + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationExecutionsResponse' + description: Successful response + summary: List Automation Executions + tags: + - Automations + x-speakeasy-group: AutomationExecution + x-speakeasy-name-override: ListAutomationExecutions + /api/v1/automation_executions/{id}: + get: + description: Retrieve a single automation execution by its unique identifier, with optional expanded related objects. + operationId: c1.api.automations.v1.AutomationExecutionService.GetAutomationExecution parameters: - in: path - name: app_id + name: id required: true schema: - description: The application that owns the resource server. + description: The unique identifier of the automation execution to retrieve. + format: int64 type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationExecutionResponse' + description: Successful response + summary: Get Automation Execution + tags: + - Automations + x-speakeasy-group: AutomationExecution + x-speakeasy-name-override: GetAutomationExecution + /api/v1/automation_executions/{id}/actions/terminate: + post: + description: Terminate a running automation execution asynchronously, stopping it and marking it as terminated. + operationId: c1.api.automations.v1.AutomationExecutionActionsService.TerminateAutomation + parameters: - in: path name: id required: true schema: - description: Unique identifier for the access profile. - type: string - - in: query - name: page_size - schema: - description: Page size (max 200). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The unique identifier of the automation execution to terminate. + format: int64 type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListHistoryResponse' - description: |- - XAAAccessProfileServiceListHistoryResponse returns access profile history - entries. - summary: List History + $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationResponse' + description: Successful response + summary: Terminate Automation tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile - x-speakeasy-name-override: ListHistory - /api/v1/apps/{app_id}/xaa/access_profiles/by_app_entitlement_id/{app_entitlement_id}: + - Automations + x-speakeasy-group: AutomationExecutionActions + x-speakeasy-name-override: TerminateAutomation + /api/v1/automations: get: + description: List all automations in the tenant with pagination support. + operationId: c1.api.automations.v1.AutomationService.ListAutomations + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationsResponse' + description: Successful response + summary: List Automations + tags: + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ListAutomations + post: description: |- - GetByAppEntitlementId looks up the access profile linked to an - entitlement, by app_id + app_entitlement_id. Used by the request catalog. - operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.GetByAppEntitlementId + Create a new automation with the specified steps, triggers, and + configuration. See get_authoring_guide for the AutomationStep contract + (step kinds and their required fields, CEL identifier scope). + + At create time, draft_automation_steps and draft_triggers default to + their published counterparts when omitted — callers writing a single + working version don't need to populate both. The draft/publish + distinction matters only on subsequent edits. + operationId: c1.api.automations.v1.AutomationService.CreateAutomation + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationResponse' + description: Successful response + summary: Create Automation + tags: + - Automations + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Automation#create + x-speakeasy-group: Automation + x-speakeasy-name-override: CreateAutomation + /api/v1/automations/{id}: + delete: + description: Delete an automation by its unique identifier, removing it and its associated triggers. + operationId: c1.api.automations.v1.AutomationService.DeleteAutomation parameters: - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - - in: path - name: app_entitlement_id + name: id required: true schema: - description: AppEntitlement ID to look up. + description: The unique identifier of the automation to delete. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetByAppEntitlementIdResponse' - description: |- - XAAAccessProfileServiceGetByAppEntitlementIdResponse returns the matched - profile. - summary: Get By App Entitlement Id + $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationResponse' + description: Successful response + summary: Delete Automation tags: - - Cross-App Access - x-speakeasy-group: XAAAccessProfile - x-speakeasy-name-override: GetByAppEntitlementId - /api/v1/apps/{app_id}/xaa/resource_servers: + - Automations + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Automation#delete + x-speakeasy-group: Automation + x-speakeasy-name-override: DeleteAutomation get: - description: List the resource servers registered for an application, one page at a time. - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.List + description: Retrieve a single automation by its unique identifier. + operationId: c1.api.automations.v1.AutomationService.GetAutomation parameters: - in: path - name: app_id + name: id required: true schema: - description: The application to list resource servers for. - type: string - - in: query - name: page_size - schema: - description: Page size (max 100). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The unique identifier of the automation to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListResponse' - description: XAAResourceServerServiceListResponse returns a page of resource servers. - summary: List + $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationResponse' + description: Successful response + summary: Get Automation tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: List + - Automations + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Automation#read + x-speakeasy-group: Automation + x-speakeasy-name-override: GetAutomation post: - description: |- - Register a resource server (a third-party authorization server) as a - permitted cross-app-access audience for an application. The audience must - be unique within the application and must not equal your own tenant's - issuer — C1 cannot be both the granting IdP and the resource server in the - same flow. - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Create + description: Update an existing automation's properties, steps, or triggers using a field mask. + operationId: c1.api.automations.v1.AutomationService.UpdateAutomation parameters: - in: path - name: app_id + name: id required: true schema: - description: The application this resource server fronts. + description: The id field. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse' - description: XAAResourceServerServiceCreateResponse returns the registered resource server. - summary: Create + $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationResponse' + description: Successful response + summary: Update Automation tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/xaa/resource_servers/{id}: - delete: + - Automations + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Automation#update + x-speakeasy-group: Automation + x-speakeasy-name-override: UpdateAutomation + /api/v1/automations/{id}/circuit_breaker/clear: + post: description: |- - Delete a resource server (soft delete). Cascades to its scopes, access - profiles, and client audience mappings. - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Delete + Clear the circuit breaker on an automation that was auto-disabled by the + rate cap. Future events flow normally; existing paused executions are not + affected (use ResolvePausedAutomationExecutions to run or cancel them). + operationId: c1.api.automations.v1.AutomationService.ClearAutomationCircuitBreaker parameters: - - in: path - name: app_id - required: true - schema: - description: The application this resource server fronts. - type: string - in: path name: id required: true schema: - description: Unique identifier for the resource server. + description: |- + The unique identifier of the automation whose circuit breaker should + be cleared. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteResponse' - description: XAAResourceServerServiceDeleteResponse confirms deletion. - summary: Delete + $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerResponse' + description: Successful response + summary: Clear Automation Circuit Breaker tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: Delete - get: - description: Get a registered resource server by app_id + id. - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Get + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ClearAutomationCircuitBreaker + /api/v1/automations/{id}/circuit_breaker/resolve_paused: + post: + description: |- + Decide what to do with the executions that were paused while the + automation's circuit breaker was tripped. Idempotent. + operationId: c1.api.automations.v1.AutomationService.ResolvePausedAutomationExecutions parameters: - - in: path - name: app_id - required: true - schema: - description: The application this resource server fronts. - type: string - in: path name: id required: true schema: - description: Unique identifier for the resource server. + description: |- + The unique identifier of the automation whose paused executions should + be resolved. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceGetResponse' - description: XAAResourceServerServiceGetResponse returns a single resource server. - summary: Get + $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse' + description: Successful response + summary: Resolve Paused Automation Executions tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: Get + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ResolvePausedAutomationExecutions + /api/v1/automations/{id}/execute: post: - description: |- - Update a resource server's editable fields via update_mask. The audience - is immutable (delete and recreate to change it); supplying a different - audience is rejected. Editable paths: display_name, description, - resource_uris, max_grant_lifetime, signing_algorithm, - require_proof_of_possession, modify_claims_hook, disabled. sector_id is - immutable once set (delete and recreate to change it). - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Update + description: Trigger an on-demand execution of an automation, returning the new execution's identifier. + operationId: c1.api.automations.v1.AutomationService.ExecuteAutomation parameters: - in: path - name: app_id + name: id required: true schema: - description: The application this resource server fronts. + description: The unique identifier of the automation to execute. type: string - - in: path - name: id - required: true + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationResponse' + description: Successful response + summary: Execute Automation + tags: + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ExecuteAutomation + /api/v1/catalogs: + get: + description: Get a list of request catalogs. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.List + parameters: + - in: query + name: page_size schema: - description: Unique identifier for this resource server. + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The page_token field for pagination. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse' + description: Successful response + summary: List + tags: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Request Catalogs#read + terraform-resource: null + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: List + post: + description: Creates a new request catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateResponse' - description: XAAResourceServerServiceUpdateResponse returns the updated resource server. - summary: Update + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. + summary: Create tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/xaa/resource_servers/{id}/history: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: Create + /api/v1/catalogs/{catalog_id}/requestable_entitlementIDs: get: - description: |- - ListHistory returns the change history (newest first) for a single - resource server — each entry is a snapshot plus who/when metadata. - operationId: c1.api.cross_app_access.v1.XAAResourceServerService.ListHistory + description: List all requestable entitlement IDs in a catalog without pagination. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListAllEntitlementIdsPerApp parameters: - in: path - name: app_id - required: true - schema: - description: The application this resource server fronts. - type: string - - in: path - name: id + name: catalog_id required: true schema: - description: Unique identifier for the resource server. - type: string - - in: query - name: page_size - schema: - description: Page size (max 200). - format: int32 - type: integer - - in: query - name: page_token - schema: - description: Page token for pagination. + description: The unique identifier of the access profile. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListHistoryResponse' - description: |- - XAAResourceServerServiceListHistoryResponse returns resource server history - entries. - summary: List History + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse' + description: The response message containing all requestable entitlement references in the catalog. + summary: List All Entitlement Ids Per App tags: - - Cross-App Access - x-speakeasy-group: XAAResourceServer - x-speakeasy-name-override: ListHistory - /api/v1/apps/{app_id}/xaa/scopes: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Access_Profile_Requestable_Entries#read + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListAllEntitlementIdsPerApp + /api/v1/catalogs/{catalog_id}/requestable_entitlements: get: - description: |- - List the scopes defined for an application, one page at a time. To filter - by resource server, state, or classification, use Search. - operationId: c1.api.cross_app_access.v1.XAAScopeService.List + description: List entitlements in a catalog that are requestable. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsPerCatalog parameters: - in: path - name: app_id + name: catalog_id required: true schema: - description: The application to list scopes for. + description: The catalogId field. type: string - in: query name: page_size schema: - description: Page size (max 100). + description: The pageSize field. format: int32 type: integer - in: query name: page_token schema: - description: Page token for pagination. + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListResponse' - description: XAAScopeServiceListResponse returns a page of scopes. - summary: List + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse' + description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. + summary: List Entitlements Per Catalog tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: List + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListEntitlementsPerCatalog + /api/v1/catalogs/{catalog_id}/requestable_entitlements/update: post: - description: |- - Declare a scope under a resource server. The scope value is the literal - OAuth scope string and is immutable after creation. - operationId: c1.api.cross_app_access.v1.XAAScopeService.Create + description: Replace the full set of requestable entitlements in a catalog with the provided list. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.UpdateAppEntitlements parameters: - in: path - name: app_id + name: catalog_id required: true schema: - description: The application that owns the resource server. + description: The Id of the request catalog to get app entitlement to. This is a URL value. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateResponse' - description: XAAScopeServiceCreateResponse returns the created scope. - summary: Create + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse' + description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. + summary: Update App Entitlements tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/xaa/scopes/{id}: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entries#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: UpdateAppEntitlements + /api/v1/catalogs/{catalog_id}/requestable_entries: delete: - description: |- - Delete a scope (soft delete). Cascades to its backing entitlement and to - any access-profile bindings that reference it. - operationId: c1.api.cross_app_access.v1.XAAScopeService.Delete + description: Remove requestable entitlements from a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAppEntitlements parameters: - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - - in: path - name: id + name: catalog_id required: true schema: - description: Unique identifier for the scope. + description: The catalogId for the catalog to remove entitlements from. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteResponse' - description: XAAScopeServiceDeleteResponse confirms deletion. - summary: Delete + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse' + description: Empty response with a status code indicating success + summary: Remove App Entitlements tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: Delete - get: - description: Get a scope by app_id + id. - operationId: c1.api.cross_app_access.v1.XAAScopeService.Get + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entries#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: RemoveAppEntitlements + post: + description: Add requestable entitlements to a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAppEntitlements parameters: - in: path - name: app_id - required: true - schema: - description: The application that owns the resource server. - type: string - - in: path - name: id + name: catalog_id required: true schema: - description: Unique identifier for the scope. + description: The Id of the request catalog to add app entitlements to. This is a URL value. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceGetResponse' - description: XAAScopeServiceGetResponse returns a single scope. - summary: Get + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Add App Entitlements tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: Get - post: - description: |- - Update a scope's editable fields via update_mask. This is how a scope is - approved: set state to ENABLED to make it mintable, or DISABLED to block - it. The scope value is immutable. Editable paths: display_name, - description, state, classification. - operationId: c1.api.cross_app_access.v1.XAAScopeService.Update + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entries#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: AddAppEntitlements + /api/v1/catalogs/{catalog_id}/requestable_entries/{app_id}/{entitlement_id}: + delete: + description: Delete a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteRequestableEntry parameters: + - in: path + name: catalog_id + required: true + schema: + description: The ID of the access profile (catalog) + type: string - in: path name: app_id required: true schema: - description: The application that owns the resource server. + description: The ID of the app that contains the entitlement type: string - in: path - name: id + name: entitlement_id required: true schema: - description: Unique identifier for this scope. + description: The ID of the entitlement type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateResponse' - description: XAAScopeServiceUpdateResponse returns the updated scope. - summary: Update + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse' + description: Empty response for delete operation + summary: Delete Requestable Entry tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/xaa/scopes/{id}/history: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entry#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: DeleteRequestableEntry get: - description: |- - ListHistory returns the change history (newest first) for a single scope — - each entry is a snapshot plus who/when metadata. - operationId: c1.api.cross_app_access.v1.XAAScopeService.ListHistory + description: Get a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetRequestableEntry parameters: - in: path - name: app_id + name: catalog_id required: true schema: - description: The application this scope belongs to. + description: The ID of the access profile (catalog) type: string - in: path - name: id + name: app_id required: true schema: - description: Unique identifier for the scope. + description: The ID of the app that contains the entitlement type: string - - in: query - name: page_size - schema: - description: Page size (max 200). - format: int32 - type: integer - - in: query - name: page_token + - in: path + name: entitlement_id + required: true schema: - description: Page token for pagination. + description: The ID of the entitlement type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse' - description: XAAScopeServiceListHistoryResponse returns scope history entries. - summary: List History + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse' + description: Response containing the requested entry + summary: Get Requestable Entry tags: - - Cross-App Access - x-speakeasy-group: XAAScope - x-speakeasy-name-override: ListHistory - /api/v1/apps/{app_user_app_id}/app_users/{app_user_id}: - post: - description: |- - Update an app user by ID. Only the fields specified in the update mask are updated. - Currently, only the appUserType, and identityUserId fields can be updated. - operationId: c1.api.app.v1.AppUserService.Update + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access_Profile_Requestable_Entry#read + terraform-resource: null + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: GetRequestableEntry + put: + description: Create a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateRequestableEntry parameters: - in: path - name: app_user_app_id + name: catalog_id required: true schema: - description: The ID of the application. - readOnly: true + description: The ID of the access profile (catalog) to add the entitlement to type: string - in: path - name: app_user_id + name: app_id required: true schema: - description: A unique idenditfier of the application user. - readOnly: true + description: The ID of the app that contains the entitlement + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The ID of the entitlement to add to the request catalog type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse' + description: Response containing the created requestable entry + summary: Create Requestable Entry tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: Update - /api/v1/apps/{connector_app_id}/connectors/{connector_id}/delegated: - post: - description: Update a delegated connector. - operationId: c1.api.app.v1.ConnectorService.UpdateDelegated + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entry#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: CreateRequestableEntry + /api/v1/catalogs/{catalog_id}/visibility_bindings: + delete: + description: Remove visibility bindings (access entitlements) from a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAccessEntitlements parameters: - in: path - name: connector_app_id + name: catalog_id required: true schema: - description: The id of the app the connector is associated with. + description: The catalogId for the catalog to remove access entitlements from. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Remove Access Entitlements + tags: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Visibility_Bindings#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: RemoveAccessEntitlements + post: + description: Add visibility bindings (access entitlements) to a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAccessEntitlements + parameters: - in: path - name: connector_id + name: catalog_id required: true schema: - description: The id of the connector. + description: The Id of the request catalog to add access entitlements to. This is a URL value. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' - description: ConnectorServiceUpdateResponse is the response returned by the update method. - summary: Update Delegated + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Add Access Entitlements tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: UpdateDelegated - /api/v1/apps/{id}: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Visibility_Bindings#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: AddAccessEntitlements + /api/v1/catalogs/{catalog_id}/visibility_entitlements: + get: + description: List visibility bindings (access entitlements) for a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsForAccess + parameters: + - in: path + name: catalog_id + required: true + schema: + description: The catalogId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse' + description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. + summary: List Entitlements For Access + tags: + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListEntitlementsForAccess + /api/v1/catalogs/{id}: delete: - description: Delete an app. - operationId: c1.api.app.v1.Apps.Delete + description: Delete a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Delete parameters: - in: path name: id required: true schema: - description: The id field. + description: The Id of the RequestCatalog to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResponse' - description: Empty response body. Status code indicates success. + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse' + description: Empty response with a status code indicating success. summary: Delete tags: - - App + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App#delete - x-speakeasy-group: Apps + terraform-resource: Access_Profile#delete + x-speakeasy-group: RequestCatalogManagement x-speakeasy-name-override: Delete get: - description: Get an app by ID. - operationId: c1.api.app.v1.Apps.Get + description: Get a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Get parameters: - in: path name: id @@ -46725,2149 +55028,1726 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppResponse' - description: The GetAppResponse message contains the details of the requested app in the app field. + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. summary: Get tags: - - App + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App#read - x-speakeasy-group: Apps + terraform-datasource: Access_Profile#read + terraform-resource: Access_Profile#read + x-speakeasy-group: RequestCatalogManagement x-speakeasy-name-override: Get post: - description: Update an existing app. - operationId: c1.api.app.v1.Apps.Update + description: Update a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Update parameters: - in: path name: id required: true schema: - description: The ID of the app. - readOnly: true + description: The id of the request catalog. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppResponse' - description: Returns the updated app's new values. - summary: Update - tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App#update - x-speakeasy-group: Apps - x-speakeasy-name-override: Update - /api/v1/apps/{src_app_id}/{src_app_entitlement_id}/bindings/{dst_app_id}/{dst_app_entitlement_id}: - delete: - description: Delete a proxy binding between a source and destination entitlement. - operationId: c1.api.app.v1.AppEntitlementsProxy.Delete - parameters: - - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - type: string + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. + summary: Update + tags: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: Update + /api/v1/catalogs/{request_catalog_id}/bundle_automation: + delete: + description: Delete the bundle automation rule for a catalog, stopping automatic membership syncing. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteBundleAutomation + parameters: - in: path - name: dst_app_entitlement_id + name: request_catalog_id required: true schema: - description: The ID of the destination (child) entitlement. + description: The unique identifier of the access profile whose automation should be deleted. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyResponse' - description: The empty response message for deleting an entitlement proxy binding. - summary: Delete + $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationResponse' + description: The response message for deleting a bundle automation. + summary: Delete Bundle Automation tags: - - App Entitlement Proxy Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Entitlement Proxy Binding#delete - x-speakeasy-group: AppEntitlementsProxy - x-speakeasy-name-override: Delete + terraform-resource: BundleAutomation#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: DeleteBundleAutomation get: - description: Retrieve a specific proxy binding between a source and destination entitlement. - operationId: c1.api.app.v1.AppEntitlementsProxy.Get + description: Get bundle automation + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetBundleAutomation parameters: - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - type: string - - in: path - name: dst_app_entitlement_id + name: request_catalog_id required: true schema: - description: The ID of the destination (child) entitlement. + description: The requestCatalogId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementProxyResponse' - description: The response message for getting a specific entitlement proxy binding. - summary: Get + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + description: Successful response + summary: Get Bundle Automation tags: - - App Entitlement Proxy Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App Entitlement Proxy Binding#read - terraform-resource: App Entitlement Proxy Binding#read - x-speakeasy-group: AppEntitlementsProxy - x-speakeasy-name-override: Get + terraform-datasource: BundleAutomation#read + terraform-resource: BundleAutomation#read + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: GetBundleAutomation post: - description: Create a proxy binding between a source and destination entitlement, establishing a hierarchical relationship. - operationId: c1.api.app.v1.AppEntitlementsProxy.Create + description: Create or update the bundle automation rule for a catalog that automatically syncs catalog membership. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.SetBundleAutomation parameters: - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - type: string - - in: path - name: dst_app_entitlement_id + name: request_catalog_id required: true schema: - description: The ID of the destination (child) entitlement. + description: The unique identifier of the access profile to set the automation on. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.SetBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyResponse' - description: The response message for creating an entitlement proxy binding. - summary: Create + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + description: Successful response + summary: Set Bundle Automation tags: - - App Entitlement Proxy Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Entitlement Proxy Binding#create - x-speakeasy-group: AppEntitlementsProxy - x-speakeasy-name-override: Create - /api/v1/apps/connectors/credentials: + terraform-resource: BundleAutomation#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: SetBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/create: post: - description: Rotate credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.RotateCredential + description: Create a new bundle automation rule for a catalog that automatically syncs catalog membership from a query. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateBundleAutomation + parameters: + - in: path + name: request_catalog_id + required: true + schema: + description: The unique identifier of the access profile to create the automation for. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialResponse' - description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. - summary: Rotate Credential + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + description: Successful response + summary: Create Bundle Automation tags: - - Connector + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: ConnectorCredential#create - x-speakeasy-group: Connector - x-speakeasy-name-override: RotateCredential - /api/v1/apps/connectors/validate_config/http: + terraform-resource: BundleAutomation#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: CreateBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/resume: post: - description: Validate an HTTP connector configuration and return any diagnostics or errors found. - operationId: c1.api.app.v1.ConnectorService.ValidateHTTPConnectorConfig + description: Resume a bundle automation that was paused by the circuit breaker after detecting excessive membership changes. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ResumePausedBundleAutomation + parameters: + - in: path + name: request_catalog_id + required: true + schema: + description: The unique identifier of the access profile whose automation should be resumed. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.EditorValidateRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.EditorValidateResponse' - description: The EditorValidateResponse message contains validation results. - summary: Validate Http Connector Config + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse' + description: The response message for resuming a paused bundle automation. + summary: Resume Paused Bundle Automation tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ValidateHTTPConnectorConfig - /api/v1/attribute/{id}: - delete: - description: Delete an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteAttributeValue + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ResumePausedBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/run: + post: + description: Trigger an immediate execution of a catalog's bundle automation, bypassing the normal schedule. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ForceRunBundleAutomation parameters: - in: path - name: id + name: request_catalog_id required: true schema: - description: The id field. + description: The unique identifier of the access profile whose automation should be run. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueResponse' - description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. - summary: Delete Attribute Value + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse' + description: The response message for triggering a bundle automation run. + summary: Force Run Bundle Automation tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteAttributeValue - /api/v1/attributes: + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ForceRunBundleAutomation + /api/v1/connector-authoring/activations: post: - description: Create a new attribute value. - operationId: c1.api.attribute.v1.Attributes.CreateAttributeValue + description: |- + ActivateRevision redeems a one-time approval token to activate a built + connector revision onto its instance connector. It is OWNER-only. + Double-activate protection is the single-use approval token itself: redeeming + it is a compare-and-swap that rejects a second redemption of the same token. + idempotency_key is optional and reserved for a future replay-result cache. + operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.ActivateRevision requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueResponse' - description: CreateAttributeValueResponse is the response for creating an attribute value. - summary: Create Attribute Value - tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateAttributeValue - /api/v1/attributes/{id}: - get: - description: Get an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetAttributeValue - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetAttributeValueResponse' - description: GetAttributeValueResponse is the response for getting an attribute value by id. - summary: Get Attribute Value - tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetAttributeValue - /api/v1/attributes/compliance_frameworks: - get: - description: List all compliance framework attribute values (e.g., SOC 2, HIPAA) with pagination. - operationId: c1.api.attribute.v1.Attributes.ListComplianceFrameworks - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - type: string + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListComplianceFrameworksResponse' - description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. - summary: List Compliance Frameworks + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionResponse' + description: Successful response + summary: Activate Revision tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Compliance Frameworks#read - terraform-resource: null - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListComplianceFrameworks + - Connector Authoring Activation + x-speakeasy-group: ConnectorAuthoringActivation + x-speakeasy-name-override: ActivateRevision + /api/v1/connector-authoring/rollbacks: post: - description: Create a compliance framework value. - operationId: c1.api.attribute.v1.Attributes.CreateComplianceFrameworkAttributeValue + description: |- + RollbackRevision redeems a one-time approval token (bound to the rollback + target's integrity root) to re-point the published + instance pointers at a + previously activated, still-servable revision under a strictly greater + activation epoch. It is OWNER-only. The rolled-back-FROM revision's serve + state is untouched — the pointer move alone stops it serving; permanently + ending a revision's serve eligibility is a platform kill-switch operation, + not a tenant API verb. + operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.RollbackRevision requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest' + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse' + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionResponse' description: Successful response - summary: Create Compliance Framework Attribute Value + summary: Rollback Revision tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Compliance Framework#create - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateComplianceFrameworkAttributeValue - /api/v1/attributes/compliance_frameworks/{id}: - delete: - description: Delete an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteComplianceFrameworkAttributeValue - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - type: string + - Connector Authoring Activation + x-speakeasy-group: ConnectorAuthoringActivation + x-speakeasy-name-override: RollbackRevision + /api/v1/connectorcatalog: + post: + description: Return the configuration schema describing the fields required to set up a connector of the specified type. + operationId: c1.api.integration.connector.v1.ConnectorCatalogService.ConfigurationSchema requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput' + $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse' - description: Successful response - summary: Delete Compliance Framework Attribute Value + $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse' + description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. + summary: Configuration Schema tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Compliance Framework#delete - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValue - get: - description: Get an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetComplianceFrameworkAttributeValue - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - type: string + - Connector Catalog + x-speakeasy-group: ConnectorCatalog + x-speakeasy-name-override: ConfigurationSchema + /api/v1/conversations/onboarding:ensure: + post: + description: |- + EnsureOnboardingSession returns the tenant's active onboarding conversation, + or creates and starts it once. Retries converge on the stored conversation. + operationId: c1.api.conversations.v1.UIConversationsService.EnsureOnboardingSession + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.conversations.v1.EnsureOnboardingSessionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse' - description: Successful response - summary: Get Compliance Framework Attribute Value + $ref: '#/components/schemas/c1.api.conversations.v1.EnsureOnboardingSessionResponse' + description: Returns the active onboarding conversation and whether this call created it. + summary: Ensure Onboarding Session tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Compliance Framework#read - terraform-resource: Compliance Framework#read - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetComplianceFrameworkAttributeValue - /api/v1/attributes/risk_levels: + - Conversations + x-speakeasy-group: UIConversations + x-speakeasy-name-override: EnsureOnboardingSession + /api/v1/credential-inventory-policies: get: - description: List all risk level attribute values with pagination. - operationId: c1.api.attribute.v1.Attributes.ListRiskLevels + description: List all credential inventory policies in your tenant, one page at a time. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.List parameters: - in: query name: page_size schema: - description: The pageSize field. + description: The maximum number of results to return per page. format: int32 type: integer - in: query name: page_token schema: - description: The pageToken field. + description: A pagination token from a previous List response. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListRiskLevelsResponse' - description: ListRiskLevelsResponse is the response for listing risk level attribute values. - summary: List Risk Levels + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceListResponse' + description: Successful response + summary: List tags: - - Risk Level - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Risk Levels#read - terraform-resource: null - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListRiskLevels + - Credential Inventory + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: List post: - description: Create a risk level attribute. - operationId: c1.api.attribute.v1.Attributes.CreateRiskLevelAttributeValue + description: Create a credential inventory policy. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateResponse' description: Successful response - summary: Create Risk Level Attribute Value + summary: Create tags: - - Risk Level + - Credential Inventory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Risk Level#create - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateRiskLevelAttributeValue - /api/v1/attributes/risk_levels/{id}: + terraform-resource: CredentialInventoryPolicy#create + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Create + /api/v1/credential-inventory-policies/{id}: delete: - description: Delete a risk level attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteRiskLevelAttributeValue + description: Delete a credential inventory policy by ID. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Delete parameters: - in: path name: id required: true schema: - description: The id field. + description: The ID of the policy to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteResponse' description: Successful response - summary: Delete Risk Level Attribute Value + summary: Delete tags: - - Risk Level + - Credential Inventory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Risk Level#delete - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteRiskLevelAttributeValue + terraform-resource: CredentialInventoryPolicy#delete + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Delete get: - description: Get a risk level attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetRiskLevelAttributeValue + description: Get a credential inventory policy by ID. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Get parameters: - in: path name: id required: true schema: - description: The id field. + description: The ID of the policy to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetRiskLevelAttributeValueResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceGetResponse' description: Successful response - summary: Get Risk Level Attribute Value + summary: Get tags: - - Risk Level + - Credential Inventory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Risk Level#read - terraform-resource: Risk Level#read - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetRiskLevelAttributeValue - /api/v1/attributes/types: - get: - description: List all attribute types. - operationId: c1.api.attribute.v1.Attributes.ListAttributeTypes - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeTypesResponse' - description: ListAttributeTypesResponse is the response for listing attribute types. - summary: List Attribute Types - tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListAttributeTypes - /api/v1/attributes/types/{attribute_type_id}/values: - get: - description: List all attribute values for a given attribute type. - operationId: c1.api.attribute.v1.Attributes.ListAttributeValues + terraform-datasource: null + terraform-resource: CredentialInventoryPolicy#read + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Get + post: + description: |- + Update a credential inventory policy. Supply the policy object and an + update mask listing the fields to change; omitted fields are left as-is. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Update parameters: - in: path - name: attribute_type_id + name: id required: true schema: - description: The attributeTypeId field. - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. + description: Unique identifier for the policy. + readOnly: true type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeValuesResponse' - description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. - summary: List Attribute Values + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateResponse' + description: Successful response + summary: Update tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListAttributeValues - /api/v1/auth-configs: + - Credential Inventory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: CredentialInventoryPolicy#update + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Update + /api/v1/decoys: get: - description: List returns all authentication provider configurations for the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.List - parameters: - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: A pagination token returned from a previous List call. - type: string + description: List returns decoys for the tenant, paginated. + operationId: c1.api.decoy.v1.DecoyService.List responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceListResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceListResponse' description: Successful response summary: List tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: List post: - description: Create registers a new authentication provider configuration for the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Create + description: |- + Create mints a decoy credential and returns the one-time vending + material exactly once. The Decoy id is server-set; the credential's + secret cannot be retrieved again after this response. + operationId: c1.api.decoy.v1.DecoyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateResponse' description: Successful response summary: Create tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Create - /api/v1/auth-configs/{id}: + /api/v1/decoys/{id}: delete: - description: Delete removes an authentication provider configuration from the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Delete + description: Delete soft-deletes a decoy and disables the paired credential row. + operationId: c1.api.decoy.v1.DecoyService.Delete parameters: - in: path name: id required: true schema: - description: The unique identifier of the authentication provider configuration to delete. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteResponse' description: Successful response summary: Delete tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Delete get: - description: Get retrieves a single authentication provider configuration by its ID. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Get + description: Get returns a decoy by id. + operationId: c1.api.decoy.v1.DecoyService.Get parameters: - in: path name: id required: true schema: - description: The unique identifier of the authentication provider configuration to retrieve. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceGetResponse' description: Successful response summary: Get tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Get - post: - description: Update modifies an existing authentication provider configuration. Use the update mask to specify which fields to change. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Update + patch: + description: |- + Update modifies mutable metadata on a decoy. The decoy variant is + fixed at Create -- rotate the secret with Rotate instead. + operationId: c1.api.decoy.v1.DecoyService.Update parameters: - in: path name: id required: true schema: description: The id field. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateResponse' description: Successful response summary: Update tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Update - /api/v1/auth/introspect: - get: - description: Introspect returns the current user's principle_id, user_id and a list of roles, permissions, and enabled features. - operationId: c1.api.auth.v1.Auth.Introspect - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.auth.v1.IntrospectResponse' - description: IntrospectResponse contains information about the current user who is authenticated. - summary: Introspect - tags: - - Auth - x-speakeasy-group: Auth - x-speakeasy-name-override: Introspect - /api/v1/automation_executions: - get: - description: List all automation executions in the tenant with pagination support. - operationId: c1.api.automations.v1.AutomationExecutionService.ListAutomationExecutions - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationExecutionsResponse' - description: Successful response - summary: List Automation Executions - tags: - - Automations - x-speakeasy-group: AutomationExecution - x-speakeasy-name-override: ListAutomationExecutions - /api/v1/automation_executions/{id}: - get: - description: Retrieve a single automation execution by its unique identifier, with optional expanded related objects. - operationId: c1.api.automations.v1.AutomationExecutionService.GetAutomationExecution + /api/v1/decoys/{id}/rotate: + post: + description: |- + Rotate re-mints the paired credential's secret material, preserves + the decoy_id binding, and returns the new one-time vending material. + operationId: c1.api.decoy.v1.DecoyService.Rotate parameters: - in: path name: id required: true schema: - description: The unique identifier of the automation execution to retrieve. - format: int64 + description: The id field. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationExecutionResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateResponse' description: Successful response - summary: Get Automation Execution + summary: Rotate tags: - - Automations - x-speakeasy-group: AutomationExecution - x-speakeasy-name-override: GetAutomationExecution - /api/v1/automation_executions/{id}/actions/terminate: + - Decoy + x-speakeasy-group: Decoy + x-speakeasy-name-override: Rotate + /api/v1/decoys/search: post: - description: Terminate a running automation execution asynchronously, stopping it and marking it as terminated. - operationId: c1.api.automations.v1.AutomationExecutionActionsService.TerminateAutomation - parameters: - - in: path - name: id - required: true - schema: - description: The unique identifier of the automation execution to terminate. - format: int64 - type: string + description: |- + Search decoys with free-text query and filters for kind, status, + and annotation key. + operationId: c1.api.decoy.v1.DecoySearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchResponse' description: Successful response - summary: Terminate Automation + summary: Search tags: - - Automations - x-speakeasy-group: AutomationExecutionActions - x-speakeasy-name-override: TerminateAutomation - /api/v1/automations: + - Decoy + x-speakeasy-group: DecoySearch + x-speakeasy-name-override: Search + /api/v1/directories: get: - description: List all automations in the tenant with pagination support. - operationId: c1.api.automations.v1.AutomationService.ListAutomations + description: List directories. + operationId: c1.api.directory.v1.DirectoryService.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationsResponse' - description: Successful response - summary: List Automations + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceListResponse' + description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ListAutomations + - Directory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: + - Directory#read + - Directories#read + terraform-resource: null + x-speakeasy-group: Directory + x-speakeasy-name-override: List post: - description: |- - Create a new automation with the specified steps, triggers, and - configuration. See get_authoring_guide for the AutomationStep contract - (step kinds, evaluate_expressions shape, CEL identifier scope). - - At create time, draft_automation_steps and draft_triggers default to - their published counterparts when omitted — callers writing a single - working version don't need to populate both. The draft/publish - distinction matters only on subsequent edits. - operationId: c1.api.automations.v1.AutomationService.CreateAutomation + description: Create a directory. + operationId: c1.api.directory.v1.DirectoryService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationRequest' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationResponse' - description: Successful response - summary: Create Automation + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateResponse' + description: The DirectoryServiceCreateResponse message. + summary: Create tags: - - Automations + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Automation#create - x-speakeasy-group: Automation - x-speakeasy-name-override: CreateAutomation - /api/v1/automations/{id}: + terraform-resource: Directory#create + x-speakeasy-group: Directory + x-speakeasy-name-override: Create + /api/v1/directories/{app_id}: delete: - description: Delete an automation by its unique identifier, removing it and its associated triggers. - operationId: c1.api.automations.v1.AutomationService.DeleteAutomation + description: Delete a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Delete parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the automation to delete. + description: The app_id of the directory to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationRequestInput' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationResponse' - description: Successful response - summary: Delete Automation + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteResponse' + description: Empty response with a status code indicating success. + summary: Delete tags: - - Automations - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Automation#delete - x-speakeasy-group: Automation - x-speakeasy-name-override: DeleteAutomation + - Directory + x-speakeasy-group: Directory + x-speakeasy-name-override: Delete get: - description: Retrieve a single automation by its unique identifier. - operationId: c1.api.automations.v1.AutomationService.GetAutomation + description: Get a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Get parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the automation to retrieve. + description: The appId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationResponse' - description: Successful response - summary: Get Automation + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceGetResponse' + description: |- + The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the + location in the expanded array that items are expanded as indicated by the expand mask in the request. + summary: Get tags: - - Automations + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: terraform-datasource: null - terraform-resource: Automation#read - x-speakeasy-group: Automation - x-speakeasy-name-override: GetAutomation - post: - description: Update an existing automation's properties, steps, or triggers using a field mask. - operationId: c1.api.automations.v1.AutomationService.UpdateAutomation + terraform-resource: Directory#read + x-speakeasy-group: Directory + x-speakeasy-name-override: Get + put: + description: Update a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Update parameters: - in: path - name: id + name: app_id required: true schema: - description: The id field. - readOnly: true + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationResponse' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateResponse' description: Successful response - summary: Update Automation + summary: Update tags: - - Automations + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Automation#update - x-speakeasy-group: Automation - x-speakeasy-name-override: UpdateAutomation - /api/v1/automations/{id}/circuit_breaker/clear: + terraform-resource: Directory#update + x-speakeasy-group: Directory + x-speakeasy-name-override: Update + /api/v1/findings: post: - description: |- - Clear the circuit breaker on an automation that was auto-disabled by the - rate cap. Future events flow normally; existing paused executions are not - affected (use ResolvePausedAutomationExecutions to run or cancel them). - operationId: c1.api.automations.v1.AutomationService.ClearAutomationCircuitBreaker - parameters: - - in: path - name: id - required: true - schema: - description: |- - The unique identifier of the automation whose circuit breaker should - be cleared. - type: string + description: Create a user-authored custom finding. + operationId: c1.api.finding.v1.FindingService.CreateFinding requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerResponse' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingResponse' description: Successful response - summary: Clear Automation Circuit Breaker + summary: Create Finding tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ClearAutomationCircuitBreaker - /api/v1/automations/{id}/circuit_breaker/resolve_paused: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: CreateFinding + /api/v1/findings/{finding_id}/state: post: - description: |- - Decide what to do with the executions that were paused while the - automation's circuit breaker was tripped. Idempotent. - operationId: c1.api.automations.v1.AutomationService.ResolvePausedAutomationExecutions + description: Update finding workflow state (snooze, accept risk, suppress, reopen, resolve). + operationId: c1.api.finding.v1.FindingService.UpdateFindingState parameters: - in: path - name: id + name: finding_id required: true schema: - description: |- - The unique identifier of the automation whose paused executions should - be resolved. + description: The ID of the finding whose state to update. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateResponse' description: Successful response - summary: Resolve Paused Automation Executions + summary: Update Finding State tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ResolvePausedAutomationExecutions - /api/v1/automations/{id}/execute: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: UpdateFindingState + /api/v1/findings/{finding_id}/task: post: - description: Trigger an on-demand execution of an automation, returning the new execution's identifier. - operationId: c1.api.automations.v1.AutomationService.ExecuteAutomation + description: Create a task for a finding. + operationId: c1.api.finding.v1.FindingService.CreateFindingTask parameters: - in: path - name: id + name: finding_id required: true schema: - description: The unique identifier of the automation to execute. + description: The ID of the finding to create a remediation task for. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationResponse' - description: Successful response - summary: Execute Automation - tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ExecuteAutomation - /api/v1/catalogs: - get: - description: Get a list of request catalogs. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The page_token field for pagination. - type: string + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskResponse' description: Successful response - summary: List - tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Request Catalogs#read - terraform-resource: null - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: List - post: - description: Creates a new request catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Create - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Create - tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Create - /api/v1/catalogs/{catalog_id}/requestable_entitlementIDs: - get: - description: List all requestable entitlement IDs in a catalog without pagination. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListAllEntitlementIdsPerApp - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The unique identifier of the access profile. - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse' - description: The response message containing all requestable entitlement references in the catalog. - summary: List All Entitlement Ids Per App + summary: Create Finding Task tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Access_Profile_Requestable_Entries#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListAllEntitlementIdsPerApp - /api/v1/catalogs/{catalog_id}/requestable_entitlements: - get: - description: List entitlements in a catalog that are requestable. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsPerCatalog - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId field. - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: CreateFindingTask + /api/v1/findings/{id}: + get: + description: Get a single finding by ID. + operationId: c1.api.finding.v1.FindingService.GetFinding + parameters: + - in: path + name: id + required: true schema: - description: The pageToken field. + description: The ID of the finding to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse' - description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. - summary: List Entitlements Per Catalog + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingResponse' + description: Successful response + summary: Get Finding tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListEntitlementsPerCatalog - /api/v1/catalogs/{catalog_id}/requestable_entitlements/update: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: GetFinding + /api/v1/findings/bulk/state: post: - description: Replace the full set of requestable entitlements in a catalog with the provided list. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.UpdateAppEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The Id of the request catalog to get app entitlement to. This is a URL value. - type: string + description: Bulk update finding states. + operationId: c1.api.finding.v1.FindingService.BulkUpdateFindingState requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse' - description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. - summary: Update App Entitlements + $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateResponse' + description: Successful response + summary: Bulk Update Finding State tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: UpdateAppEntitlements - /api/v1/catalogs/{catalog_id}/requestable_entries: - delete: - description: Remove requestable entitlements from a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAppEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId for the catalog to remove entitlements from. - type: string + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: BulkUpdateFindingState + /api/v1/findings/bulk/tasks: + post: + description: Bulk create tasks for findings. + operationId: c1.api.finding.v1.FindingService.BulkCreateFindingTasks requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse' - description: Empty response with a status code indicating success - summary: Remove App Entitlements + $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksResponse' + description: Successful response + summary: Bulk Create Finding Tasks tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: RemoveAppEntitlements + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: BulkCreateFindingTasks + /api/v1/findings/routing-rules: + get: + description: List finding routing rules, optionally filtered to a specific app. + operationId: c1.api.finding.v1.FindingRoutingRuleService.ListFindingRoutingRules + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.ListFindingRoutingRulesResponse' + description: Successful response + summary: List Finding Routing Rules + tags: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: ListFindingRoutingRules post: - description: Add requestable entitlements to a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAppEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The Id of the request catalog to add app entitlements to. This is a URL value. - type: string + description: Create a new finding routing rule that defines which policy to use for auto-routing matching findings. + operationId: c1.api.finding.v1.FindingRoutingRuleService.CreateFindingRoutingRule requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Add App Entitlements + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleResponse' + description: Successful response + summary: Create Finding Routing Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: AddAppEntitlements - /api/v1/catalogs/{catalog_id}/requestable_entries/{app_id}/{entitlement_id}: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: CreateFindingRoutingRule + /api/v1/findings/routing-rules/{id}: delete: - description: Delete a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteRequestableEntry + description: Delete a finding routing rule. Findings already routed by this rule are not affected. + operationId: c1.api.finding.v1.FindingRoutingRuleService.DeleteFindingRoutingRule parameters: - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - type: string - - in: path - name: entitlement_id + name: id required: true schema: - description: The ID of the entitlement + description: The ID of the finding routing rule to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse' - description: Empty response for delete operation - summary: Delete Requestable Entry + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleResponse' + description: Successful response + summary: Delete Finding Routing Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entry#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: DeleteRequestableEntry + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: DeleteFindingRoutingRule get: - description: Get a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetRequestableEntry + description: Retrieve a single finding routing rule by ID. + operationId: c1.api.finding.v1.FindingRoutingRuleService.GetFindingRoutingRule parameters: - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - type: string - - in: path - name: entitlement_id + name: id required: true schema: - description: The ID of the entitlement + description: The ID of the finding routing rule to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse' - description: Response containing the requested entry - summary: Get Requestable Entry + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingRoutingRuleResponse' + description: Successful response + summary: Get Finding Routing Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access_Profile_Requestable_Entry#read - terraform-resource: null - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: GetRequestableEntry - put: - description: Create a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateRequestableEntry + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: GetFindingRoutingRule + /api/v1/findings/routing-rules/{routing_rule_id}/update: + post: + description: Update an existing finding routing rule's match criteria or target policy. + operationId: c1.api.finding.v1.FindingRoutingRuleService.UpdateFindingRoutingRule parameters: - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) to add the entitlement to - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - type: string - - in: path - name: entitlement_id + name: routing_rule_id required: true schema: - description: The ID of the entitlement to add to the request catalog + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse' - description: Response containing the created requestable entry - summary: Create Requestable Entry + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleResponse' + description: Successful response + summary: Update Finding Routing Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entry#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: CreateRequestableEntry - /api/v1/catalogs/{catalog_id}/visibility_bindings: - delete: - description: Remove visibility bindings (access entitlements) from a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAccessEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId for the catalog to remove access entitlements from. - type: string + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: UpdateFindingRoutingRule + /api/v1/findings/search: + post: + description: |- + Search findings using full-text query and filters for severity, state, type, and app. + Each Finding row is large (risk factors, evidence, target, tags) — request a small page_size (≤10) to keep responses small. + operationId: c1.api.finding.v1.FindingSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Remove Access Entitlements + $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchResponse' + description: Successful response + summary: Search tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Visibility_Bindings#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: RemoveAccessEntitlements + - Findings + x-speakeasy-group: FindingSearch + x-speakeasy-name-override: Search + /api/v1/findings/settings: + get: + description: List every configurable finding type and whether detection is enabled. + operationId: c1.api.finding.v1.FindingSettingsService.ListFindingSettings + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.ListFindingSettingsResponse' + description: Successful response + summary: List Finding Settings + tags: + - Finding Settings + x-speakeasy-group: FindingSettings + x-speakeasy-name-override: ListFindingSettings + /api/v1/findings/settings/update: post: - description: Add visibility bindings (access entitlements) to a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAccessEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The Id of the request catalog to add access entitlements to. This is a URL value. - type: string + description: |- + Enable or disable detection for one or more finding types in a single + write. Enabling a type whose detector is a scheduled job also queues an + immediate run. + operationId: c1.api.finding.v1.FindingSettingsService.UpdateFindingSettings requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Add Access Entitlements + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingSettingsResponse' + description: Successful response + summary: Update Finding Settings tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Visibility_Bindings#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: AddAccessEntitlements - /api/v1/catalogs/{catalog_id}/visibility_entitlements: + - Finding Settings + x-speakeasy-group: FindingSettings + x-speakeasy-name-override: UpdateFindingSettings + /api/v1/findings/transformation-rules: get: - description: List visibility bindings (access entitlements) for a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsForAccess - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId field. - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - type: string + description: List finding transformation rules, optionally filtered to a specific app. + operationId: c1.api.finding.v1.FindingTransformationRuleService.ListFindingTransformationRules responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse' - description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. - summary: List Entitlements For Access + $ref: '#/components/schemas/c1.api.finding.v1.ListFindingTransformationRulesResponse' + description: Successful response + summary: List Finding Transformation Rules tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListEntitlementsForAccess - /api/v1/catalogs/{id}: - delete: - description: Delete a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Delete - parameters: - - in: path - name: id - required: true - schema: - description: The Id of the RequestCatalog to delete. - type: string + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: ListFindingTransformationRules + post: + description: Create a new finding transformation rule. + operationId: c1.api.finding.v1.FindingTransformationRuleService.CreateFindingTransformationRule requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse' - description: Empty response with a status code indicating success. - summary: Delete + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleResponse' + description: Successful response + summary: Create Finding Transformation Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Delete - get: - description: Get a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Get + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: CreateFindingTransformationRule + /api/v1/findings/transformation-rules/{id}: + delete: + description: Delete a finding transformation rule. Findings already transformed by this rule are not affected. + operationId: c1.api.finding.v1.FindingTransformationRuleService.DeleteFindingTransformationRule parameters: - in: path name: id required: true schema: - description: The id field. + description: The ID of the finding transformation rule to delete. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Get + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleResponse' + description: Successful response + summary: Delete Finding Transformation Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access_Profile#read - terraform-resource: Access_Profile#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Get - post: - description: Update a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Update + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: DeleteFindingTransformationRule + get: + description: Retrieve a single finding transformation rule by ID. + operationId: c1.api.finding.v1.FindingTransformationRuleService.GetFindingTransformationRule parameters: - in: path name: id required: true schema: - description: The id of the request catalog. + description: The ID of the finding transformation rule to retrieve. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Update + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingTransformationRuleResponse' + description: Successful response + summary: Get Finding Transformation Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Update - /api/v1/catalogs/{request_catalog_id}/bundle_automation: - delete: - description: Delete the bundle automation rule for a catalog, stopping automatic membership syncing. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteBundleAutomation + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: GetFindingTransformationRule + /api/v1/findings/transformation-rules/{transformation_rule_id}/update: + post: + description: Update an existing finding transformation rule's match criteria or transforms. + operationId: c1.api.finding.v1.FindingTransformationRuleService.UpdateFindingTransformationRule parameters: - in: path - name: request_catalog_id + name: transformation_rule_id required: true schema: - description: The unique identifier of the access profile whose automation should be deleted. + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationResponse' - description: The response message for deleting a bundle automation. - summary: Delete Bundle Automation + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleResponse' + description: Successful response + summary: Update Finding Transformation Rule tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: DeleteBundleAutomation + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: UpdateFindingTransformationRule + /api/v1/functions: get: - description: Get bundle automation - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The requestCatalogId field. - type: string + description: List retrieves all functions with pagination + operationId: c1.api.functions.v1.FunctionsService.ListFunctions responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListFunctionsResponse' description: Successful response - summary: Get Bundle Automation + summary: List Functions tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: BundleAutomation#read - terraform-resource: BundleAutomation#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: GetBundleAutomation - post: - description: Create or update the bundle automation rule for a catalog that automatically syncs catalog membership. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.SetBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile to set the automation on. - type: string + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: ListFunctions + x-stability-level: draft + post: + description: |- + CreateFunction registers a new serverless function and creates its + initial code commit. Functions run as TypeScript modules in a sandboxed + runtime; see initial_content for the entry-file signature and SDK import. + + The new function is unpublished. To make the commit the default + runnable version (and have the function appear as runnable in the + Functions UI), call UpdateFunction with function.published_commit_id + set and update_mask=["published_commit_id"]. + operationId: c1.api.functions.v1.FunctionsService.CreateFunction requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.SetBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionResponse' description: Successful response - summary: Set Bundle Automation + summary: Create Function tags: - - Request Catalog + - Function x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: SetBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/create: - post: - description: Create a new bundle automation rule for a catalog that automatically syncs catalog membership from a query. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateBundleAutomation + terraform-resource: Function#create + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateFunction + /api/v1/functions/{function_id}/commits: + get: + description: ListCommits retrieves the commit history + operationId: c1.api.functions.v1.FunctionsService.ListCommits parameters: - in: path - name: request_catalog_id + name: function_id required: true schema: - description: The unique identifier of the access profile to create the automation for. + description: The functionId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListCommitsResponse' description: Successful response - summary: Create Bundle Automation + summary: List Commits tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: CreateBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/resume: + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: ListCommits + x-stability-level: draft post: - description: Resume a bundle automation that was paused by the circuit breaker after detecting excessive membership changes. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ResumePausedBundleAutomation + description: CreateInitialCommit starts a new commit and returns upload URLs for files + operationId: c1.api.functions.v1.FunctionsService.CreateInitialCommit parameters: - in: path - name: request_catalog_id + name: function_id required: true schema: - description: The unique identifier of the access profile whose automation should be resumed. + description: The functionId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse' - description: The response message for resuming a paused bundle automation. - summary: Resume Paused Bundle Automation + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse' + description: Successful response + summary: Create Initial Commit tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ResumePausedBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/run: + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateInitialCommit + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{commit_id}/finalize: post: - description: Trigger an immediate execution of a catalog's bundle automation, bypassing the normal schedule. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ForceRunBundleAutomation + description: CreateFinalCommit completes a commit after files are uploaded + operationId: c1.api.functions.v1.FunctionsService.CreateFinalCommit parameters: - in: path - name: request_catalog_id + name: function_id required: true schema: - description: The unique identifier of the access profile whose automation should be run. + description: The functionId field. + type: string + - in: path + name: commit_id + required: true + schema: + description: The commitId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse' - description: The response message for triggering a bundle automation run. - summary: Force Run Bundle Automation + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse' + description: Successful response + summary: Create Final Commit tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ForceRunBundleAutomation - /api/v1/connector-authoring/activations: - post: - description: |- - ActivateRevision redeems a one-time approval token to activate a built - connector revision onto its instance connector. It is OWNER-only. - Double-activate protection is the single-use approval token itself: redeeming - it is a compare-and-swap that rejects a second redemption of the same token. - idempotency_key is optional and reserved for a future replay-result cache. - operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.ActivateRevision - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionRequest' + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateFinalCommit + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{commit_id}/lockfile: + get: + description: GetLockFile retrieves the deno lock file for a specific commit, if it exists. + operationId: c1.api.functions.v1.FunctionsService.GetLockFile + parameters: + - in: path + name: function_id + required: true + schema: + description: The functionId field. + type: string + - in: path + name: commit_id + required: true + schema: + description: The commitId field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionResponse' - description: Successful response - summary: Activate Revision + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetLockFileResponse' + description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. + summary: Get Lock File tags: - - Connector Authoring Activation - x-speakeasy-group: ConnectorAuthoringActivation - x-speakeasy-name-override: ActivateRevision - /api/v1/connector-authoring/rollbacks: - post: + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: GetLockFile + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{id}: + get: description: |- - RollbackRevision redeems a one-time approval token (bound to the rollback - target's integrity root) to re-point the published + instance pointers at a - previously activated, still-servable revision under a strictly greater - activation epoch. It is OWNER-only. The rolled-back-FROM revision's serve - state is untouched — the pointer move alone stops it serving; permanently - ending a revision's serve eligibility is a platform kill-switch operation, - not a tenant API verb. - operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.RollbackRevision - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionRequest' + GetCommitContent retrieves a commit and all its file contents in a single unary response. + This is a non-streaming alternative to GetCommit for REST API consumers. + operationId: c1.api.functions.v1.FunctionsService.GetCommitContent + parameters: + - in: path + name: function_id + required: true + schema: + description: The function ID (KSUID). + type: string + - in: path + name: id + required: true + schema: + description: The commit reference to retrieve. Accepts a KSUID, "HEAD", or a tag reference like "refs/tags/v1.0". + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionResponse' - description: Successful response - summary: Rollback Revision + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetCommitContentResponse' + description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. + summary: Get Commit Content tags: - - Connector Authoring Activation - x-speakeasy-group: ConnectorAuthoringActivation - x-speakeasy-name-override: RollbackRevision - /api/v1/connectorcatalog: - post: - description: Return the configuration schema describing the fields required to set up a connector of the specified type. - operationId: c1.api.integration.connector.v1.ConnectorCatalogService.ConfigurationSchema - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest' + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: GetCommitContent + x-stability-level: draft + /api/v1/functions/{function_id}/invocations: + get: + description: List retrieves the invocation history for a function + operationId: c1.api.functions.v1.FunctionsInvocationService.List + parameters: + - in: path + name: function_id + required: true + schema: + description: The functionId field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse' - description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. - summary: Configuration Schema + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceListResponse' + description: Successful response + summary: List tags: - - Connector Catalog - x-speakeasy-group: ConnectorCatalog - x-speakeasy-name-override: ConfigurationSchema - /api/v1/credential-inventory-policies: + - Function Invocation + x-speakeasy-group: FunctionsInvocation + x-speakeasy-name-override: List + x-stability-level: draft + /api/v1/functions/{function_id}/invocations/{id}: get: - description: List all credential inventory policies in your tenant, one page at a time. - operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.List + description: Get retrieves a specific invocation by ID + operationId: c1.api.functions.v1.FunctionsInvocationService.Get parameters: - - in: query - name: page_size + - in: path + name: function_id + required: true schema: - description: The maximum number of results to return per page. - format: int32 - type: integer - - in: query - name: page_token + description: The functionId field. + type: string + - in: path + name: id + required: true schema: - description: A pagination token from a previous List response. + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceListResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceGetResponse' description: Successful response - summary: List + summary: Get tags: - - Credential Inventory - x-speakeasy-group: CredentialInventoryPolicy - x-speakeasy-name-override: List + - Function Invocation + x-speakeasy-group: FunctionsInvocation + x-speakeasy-name-override: Get + x-stability-level: draft + /api/v1/functions/{function_id}/invocations/search: post: - description: Create a credential inventory policy. - operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Create + description: |- + Search searches for function invocations with filtering and ordering support + Each invocation carries its input/output payloads, which can be large — request a small page_size (≤10) to keep responses small. + operationId: c1.api.functions.v1.FunctionsInvocationSearchService.Search + parameters: + - in: path + name: function_id + required: true + schema: + description: The function ID to search invocations for. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateRequest' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchResponse' + description: FunctionsInvocationSearchResponse is the response for searching function invocations. + summary: Search tags: - - Credential Inventory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: CredentialInventoryPolicy#create - x-speakeasy-group: CredentialInventoryPolicy - x-speakeasy-name-override: Create - /api/v1/credential-inventory-policies/{id}: - delete: - description: Delete a credential inventory policy by ID. - operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Delete + - Function Invocation + x-speakeasy-group: FunctionsInvocationSearch + x-speakeasy-name-override: Search + x-stability-level: draft + /api/v1/functions/{function_id}/invoke: + post: + description: Invoke executes a function at a specific commit with the provided input data. + operationId: c1.api.functions.v1.FunctionsService.Invoke parameters: - in: path - name: id + name: function_id required: true schema: - description: The ID of the policy to delete. + description: The ID of the function to invoke. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeResponse' description: Successful response - summary: Delete + summary: Invoke tags: - - Credential Inventory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: CredentialInventoryPolicy#delete - x-speakeasy-group: CredentialInventoryPolicy - x-speakeasy-name-override: Delete + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: Invoke + x-stability-level: draft + /api/v1/functions/{function_id}/tags: get: - description: Get a credential inventory policy by ID. - operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Get + description: ListTags lists all tags for a function + operationId: c1.api.functions.v1.FunctionsService.ListTags parameters: - in: path - name: id + name: function_id required: true schema: - description: The ID of the policy to retrieve. + description: The functionId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceGetResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListTagsResponse' description: Successful response - summary: Get + summary: List Tags tags: - - Credential Inventory + - Function Tag x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: CredentialInventoryPolicy#read - x-speakeasy-group: CredentialInventoryPolicy - x-speakeasy-name-override: Get + terraform-datasource: Function_Tag#read + terraform-resource: Function_Tag#read + x-speakeasy-group: Functions + x-speakeasy-name-override: ListTags + x-stability-level: draft post: - description: |- - Update a credential inventory policy. Supply the policy object and an - update mask listing the fields to change; omitted fields are left as-is. - operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Update + description: CreateTag creates a named reference to a specific commit + operationId: c1.api.functions.v1.FunctionsService.CreateTag parameters: - in: path - name: id + name: function_id required: true schema: - description: Unique identifier for the policy. - readOnly: true + description: The functionId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagResponse' description: Successful response - summary: Update + summary: Create Tag tags: - - Credential Inventory + - Function Tag x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: CredentialInventoryPolicy#update - x-speakeasy-group: CredentialInventoryPolicy - x-speakeasy-name-override: Update - /api/v1/decoys: - get: - description: List returns decoys for the tenant, paginated. - operationId: c1.api.decoy.v1.DecoyService.List - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceListResponse' - description: Successful response - summary: List - tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: List + terraform-resource: Function_Tag#create + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateTag + x-stability-level: draft + /api/v1/functions/{function_id}/test: post: - description: |- - Create mints a decoy credential and returns the one-time vending - material exactly once. The Decoy id is server-set; the credential's - secret cannot be retrieved again after this response. - operationId: c1.api.decoy.v1.DecoyService.Create - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateResponse' - description: Successful response - summary: Create - tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: Create - /api/v1/decoys/{id}: - delete: - description: Delete soft-deletes a decoy and disables the paired credential row. - operationId: c1.api.decoy.v1.DecoyService.Delete + description: Test runs a function's test suite in a sandboxed environment and returns the results. + operationId: c1.api.functions.v1.FunctionsService.Test parameters: - in: path - name: id + name: function_id required: true schema: - description: The id field. + description: The function ID to test. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteResponse' - description: Successful response - summary: Delete - tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: Delete - get: - description: Get returns a decoy by id. - operationId: c1.api.decoy.v1.DecoyService.Get - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - type: string + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceGetResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestResponse' + description: FunctionsServiceTestResponse contains test execution results. + summary: Test tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: Get - patch: - description: |- - Update modifies mutable metadata on a decoy. The decoy variant is - fixed at Create -- rotate the secret with Rotate instead. - operationId: c1.api.decoy.v1.DecoyService.Update + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: Test + x-stability-level: draft + /api/v1/functions/{id}: + delete: + description: Delete removes a function + operationId: c1.api.functions.v1.FunctionsService.DeleteFunction parameters: - in: path name: id required: true schema: description: The id field. - readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse' description: Successful response - summary: Update + summary: Delete Function tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: Update - /api/v1/decoys/{id}/rotate: - post: - description: |- - Rotate re-mints the paired credential's secret material, preserves - the decoy_id binding, and returns the new one-time vending material. - operationId: c1.api.decoy.v1.DecoyService.Rotate + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Function#delete + x-speakeasy-group: Functions + x-speakeasy-name-override: DeleteFunction + x-stability-level: draft + get: + description: Get retrieves a specific function by ID + operationId: c1.api.functions.v1.FunctionsService.GetFunction parameters: - in: path name: id - required: true - schema: - description: The id field. - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateRequestInput' + required: true + schema: + description: The id field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetFunctionResponse' description: Successful response - summary: Rotate + summary: Get Function tags: - - Decoy - x-speakeasy-group: Decoy - x-speakeasy-name-override: Rotate - /api/v1/decoys/search: + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Function#read + x-speakeasy-group: Functions + x-speakeasy-name-override: GetFunction + x-stability-level: draft + /api/v1/functions/update: post: description: |- - Search decoys with free-text query and filters for kind, status, - and annotation key. - operationId: c1.api.decoy.v1.DecoySearchService.Search + Update an existing function's metadata, code, or both. Also the publish + path: set function.published_commit_id and include "published_commit_id" + in update_mask to make a commit the default runnable version. To push a + new code commit, set content (and optionally commit_message); this is + independent of update_mask, since commits are versioned separately from + function metadata. A single request cannot publish the commit it just + created, since published_commit_id is validated against existing commits + before content is committed: publishing new code takes two calls, push + then publish with the returned commit.id. + operationId: c1.api.functions.v1.FunctionsService.UpdateFunction requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchRequest' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse' description: Successful response - summary: Search + summary: Update Function tags: - - Decoy - x-speakeasy-group: DecoySearch - x-speakeasy-name-override: Search - /api/v1/directories: + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Function#update + x-speakeasy-group: Functions + x-speakeasy-name-override: UpdateFunction + x-stability-level: draft + /api/v1/funds/app-caps: get: - description: List directories. - operationId: c1.api.directory.v1.DirectoryService.List + description: |- + List every capped app in the tenant. Cardinality is the tenant's installed + App count, so this is one runtime-plane query. + operationId: c1.api.funds.v1.AppCapService.List parameters: - in: query name: page_size @@ -48885,75 +56765,47 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceListResponse' - description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceListResponse' + description: Successful response summary: List tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - Directory#read - - Directories#read - terraform-resource: null - x-speakeasy-group: Directory + - Fund App Caps + x-speakeasy-group: AppCap x-speakeasy-name-override: List - post: - description: Create a directory. - operationId: c1.api.directory.v1.DirectoryService.Create - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateResponse' - description: The DirectoryServiceCreateResponse message. - summary: Create - tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Directory#create - x-speakeasy-group: Directory - x-speakeasy-name-override: Create - /api/v1/directories/{app_id}: + /api/v1/funds/app-caps/{app_id}: delete: - description: Delete a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Delete + description: Delete the cap entirely. The app is no longer bounded tenant-wide. + operationId: c1.api.funds.v1.AppCapService.Delete parameters: - in: path name: app_id required: true schema: - description: The app_id of the directory to delete. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteResponse' - description: Empty response with a status code indicating success. + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceDeleteResponse' + description: Successful response summary: Delete tags: - - Directory - x-speakeasy-group: Directory + - Fund App Caps + x-speakeasy-group: AppCap x-speakeasy-name-override: Delete get: - description: Get a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Get + description: |- + Get returns the tenant's ceiling for one app, together with any suspension + acting as that app's kill switch. An app with no cap is not found, meaning + nothing bounds it beyond the fund the spender already has. + operationId: c1.api.funds.v1.AppCapService.Get parameters: - in: path name: app_id @@ -48966,23 +56818,20 @@ paths: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceGetResponse' - description: |- - The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the - location in the expanded array that items are expanded as indicated by the expand mask in the request. + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceGetResponse' + description: Successful response summary: Get tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Directory#read - x-speakeasy-group: Directory + - Fund App Caps + x-speakeasy-group: AppCap x-speakeasy-name-override: Get - put: - description: Update a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Update + /api/v1/funds/app-caps/{app_id}/history: + get: + description: |- + List the change history for one app's cap, newest first. Admin-tier per the + object-history convention. A cap cleared down to nothing is deleted, and its + history is where the kill switch that preceded the delete is still readable. + operationId: c1.api.funds.v1.AppCapService.ListHistory parameters: - in: path name: app_id @@ -48990,912 +56839,945 @@ paths: schema: description: The appId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateRequestInput' + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceListHistoryResponse' description: Successful response - summary: Update + summary: List History tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Directory#update - x-speakeasy-group: Directory - x-speakeasy-name-override: Update - /api/v1/findings: + - Fund App Caps + x-speakeasy-group: AppCap + x-speakeasy-name-override: ListHistory + /api/v1/funds/app-caps/{app_id}/limit: post: - description: Create a user-authored custom finding. - operationId: c1.api.finding.v1.FindingService.CreateFinding + description: |- + Set the app's tenant-wide ceiling, creating the cap if absent. Leaves any + suspension in place. + operationId: c1.api.funds.v1.AppCapService.SetLimit + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRequest' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceSetLimitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingResponse' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceSetLimitResponse' description: Successful response - summary: Create Finding + summary: Set Limit tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: CreateFinding - /api/v1/findings/{finding_id}/state: - post: - description: Update finding workflow state (snooze, accept risk, suppress, reopen, resolve). - operationId: c1.api.finding.v1.FindingService.UpdateFindingState + - Fund App Caps + x-speakeasy-group: AppCap + x-speakeasy-name-override: SetLimit + /api/v1/funds/app-caps/{app_id}/suspension: + delete: + description: Bring the app back, restoring the cap it froze. + operationId: c1.api.funds.v1.AppCapService.Unsuspend parameters: - in: path - name: finding_id + name: app_id required: true schema: - description: The ID of the finding whose state to update. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceUnsuspendRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateResponse' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceUnsuspendResponse' description: Successful response - summary: Update Finding State + summary: Unsuspend tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: UpdateFindingState - /api/v1/findings/{finding_id}/task: + - Fund App Caps + x-speakeasy-group: AppCap + x-speakeasy-name-override: Unsuspend post: - description: Create a task for a finding. - operationId: c1.api.finding.v1.FindingService.CreateFindingTask + description: |- + Kill the app tenant-wide. The cap amount underneath is preserved and + restored by Unsuspend. + operationId: c1.api.funds.v1.AppCapService.Suspend parameters: - in: path - name: finding_id + name: app_id required: true schema: - description: The ID of the finding to create a remediation task for. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceSuspendRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskResponse' + $ref: '#/components/schemas/c1.api.funds.v1.AppCapServiceSuspendResponse' description: Successful response - summary: Create Finding Task + summary: Suspend tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: CreateFindingTask - /api/v1/findings/{id}: - get: - description: Get a single finding by ID. - operationId: c1.api.finding.v1.FindingService.GetFinding + - Fund App Caps + x-speakeasy-group: AppCap + x-speakeasy-name-override: Suspend + /api/v1/funds/assignments/{user_id}: + delete: + description: |- + Delete the whole assignment. The subject falls back to the rules and the + tenant default. + operationId: c1.api.funds.v1.FundAssignmentService.Delete parameters: - in: path - name: id + name: user_id required: true schema: - description: The ID of the finding to retrieve. + description: The userId field. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.GetFindingResponse' - description: Successful response - summary: Get Finding - tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: GetFinding - /api/v1/findings/bulk/state: - post: - description: Bulk update finding states. - operationId: c1.api.finding.v1.FindingService.BulkUpdateFindingState - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateResponse' - description: Successful response - summary: Bulk Update Finding State - tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: BulkUpdateFindingState - /api/v1/findings/bulk/tasks: - post: - description: Bulk create tasks for findings. - operationId: c1.api.finding.v1.FindingService.BulkCreateFindingTasks requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksRequest' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceDeleteResponse' description: Successful response - summary: Bulk Create Finding Tasks + summary: Delete tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: BulkCreateFindingTasks - /api/v1/findings/routing-rules: + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: Delete get: - description: List finding routing rules, optionally filtered to a specific app. - operationId: c1.api.finding.v1.FindingRoutingRuleService.ListFindingRoutingRules + description: |- + Get returns one subject's exception: their own limit, any extension + running on top of it, and any suspension. A subject with no exception is + not found rather than reported at the tenant default, because no row is + what "this subject is governed by the layers above" looks like. + operationId: c1.api.funds.v1.FundAssignmentService.Get + parameters: + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.ListFindingRoutingRulesResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceGetResponse' description: Successful response - summary: List Finding Routing Rules + summary: Get tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: ListFindingRoutingRules - post: - description: Create a new finding routing rule that defines which policy to use for auto-routing matching findings. - operationId: c1.api.finding.v1.FindingRoutingRuleService.CreateFindingRoutingRule + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: Get + /api/v1/funds/assignments/{user_id}/extension: + delete: + description: Revoke the extension early. The base limit underneath is untouched. + operationId: c1.api.funds.v1.FundAssignmentService.ClearExtension + parameters: + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleRequest' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceClearExtensionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceClearExtensionResponse' description: Successful response - summary: Create Finding Routing Rule + summary: Clear Extension tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: CreateFindingRoutingRule - /api/v1/findings/routing-rules/{id}: - delete: - description: Delete a finding routing rule. Findings already routed by this rule are not affected. - operationId: c1.api.finding.v1.FindingRoutingRuleService.DeleteFindingRoutingRule + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: ClearExtension + post: + description: |- + Grant a temporary total until expires_at. Never changes the period, and + never expresses a refusal — a temporary refusal is a suspension. + operationId: c1.api.funds.v1.FundAssignmentService.GrantExtension parameters: - in: path - name: id + name: user_id required: true schema: - description: The ID of the finding routing rule to delete. + description: The userId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceGrantExtensionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceGrantExtensionResponse' description: Successful response - summary: Delete Finding Routing Rule + summary: Grant Extension tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: DeleteFindingRoutingRule + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: GrantExtension + /api/v1/funds/assignments/{user_id}/history: get: - description: Retrieve a single finding routing rule by ID. - operationId: c1.api.finding.v1.FindingRoutingRuleService.GetFindingRoutingRule + description: List the change history for one subject's assignment, newest first. + operationId: c1.api.funds.v1.FundAssignmentService.ListHistory parameters: - in: path - name: id + name: user_id required: true schema: - description: The ID of the finding routing rule to retrieve. + description: The userId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.GetFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceListHistoryResponse' description: Successful response - summary: Get Finding Routing Rule + summary: List History tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: GetFindingRoutingRule - /api/v1/findings/routing-rules/{routing_rule_id}/update: + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: ListHistory + /api/v1/funds/assignments/{user_id}/limit: post: - description: Update an existing finding routing rule's match criteria or target policy. - operationId: c1.api.finding.v1.FindingRoutingRuleService.UpdateFindingRoutingRule + description: |- + Set the subject's base limit, creating the assignment if absent. Leaves any + extension and any suspension in place. + operationId: c1.api.funds.v1.FundAssignmentService.SetLimit parameters: - in: path - name: routing_rule_id + name: user_id required: true schema: - description: The id field. + description: The userId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSetLimitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSetLimitResponse' description: Successful response - summary: Update Finding Routing Rule + summary: Set Limit tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: UpdateFindingRoutingRule - /api/v1/findings/search: - post: - description: |- - Search findings using full-text query and filters for severity, state, type, and app. - Each Finding row is large (risk factors, evidence, target, tags) — request a small page_size (≤10) to keep responses small. - operationId: c1.api.finding.v1.FindingSearchService.Search + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: SetLimit + /api/v1/funds/assignments/{user_id}/suspension: + delete: + description: Lift the suspension, restoring the numbers it froze. + operationId: c1.api.funds.v1.FundAssignmentService.Unsuspend + parameters: + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchResponse' - description: Successful response - summary: Search - tags: - - Findings - x-speakeasy-group: FindingSearch - x-speakeasy-name-override: Search - /api/v1/findings/transformation-rules: - get: - description: List finding transformation rules, optionally filtered to a specific app. - operationId: c1.api.finding.v1.FindingTransformationRuleService.ListFindingTransformationRules + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceUnsuspendRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.ListFindingTransformationRulesResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceUnsuspendResponse' description: Successful response - summary: List Finding Transformation Rules + summary: Unsuspend tags: - - Finding Transformation Rules - x-speakeasy-group: FindingTransformationRule - x-speakeasy-name-override: ListFindingTransformationRules + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: Unsuspend post: - description: Create a new finding transformation rule. - operationId: c1.api.finding.v1.FindingTransformationRuleService.CreateFindingTransformationRule + description: |- + Freeze the subject's fund. The limit and any extension underneath are + preserved and restored by Unsuspend. + operationId: c1.api.funds.v1.FundAssignmentService.Suspend + parameters: + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleRequest' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSuspendRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSuspendResponse' description: Successful response - summary: Create Finding Transformation Rule + summary: Suspend tags: - - Finding Transformation Rules - x-speakeasy-group: FindingTransformationRule - x-speakeasy-name-override: CreateFindingTransformationRule - /api/v1/findings/transformation-rules/{id}: - delete: - description: Delete a finding transformation rule. Findings already transformed by this rule are not affected. - operationId: c1.api.finding.v1.FindingTransformationRuleService.DeleteFindingTransformationRule - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the finding transformation rule to delete. - type: string + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: Suspend + /api/v1/funds/assignments/search: + post: + description: |- + Search the tenant's assignments. Reads the Postgres mirror: the runtime + row is keyed on (tenant, user), so there is no cross-subject query on the + runtime plane at all. + operationId: c1.api.funds.v1.FundAssignmentService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundAssignmentServiceSearchResponse' description: Successful response - summary: Delete Finding Transformation Rule + summary: Search tags: - - Finding Transformation Rules - x-speakeasy-group: FindingTransformationRule - x-speakeasy-name-override: DeleteFindingTransformationRule + - Fund Assignments + x-speakeasy-group: FundAssignment + x-speakeasy-name-override: Search + /api/v1/funds/my/app-limits: get: - description: Retrieve a single finding transformation rule by ID. - operationId: c1.api.finding.v1.FindingTransformationRuleService.GetFindingTransformationRule + description: List the caller's own per-app limits. + operationId: c1.api.funds.v1.MyFundLimitsService.List parameters: - - in: path - name: id - required: true + - in: query + name: page_size schema: - description: The ID of the finding transformation rule to retrieve. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.GetFindingTransformationRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceListResponse' description: Successful response - summary: Get Finding Transformation Rule + summary: List tags: - - Finding Transformation Rules - x-speakeasy-group: FindingTransformationRule - x-speakeasy-name-override: GetFindingTransformationRule - /api/v1/findings/transformation-rules/{transformation_rule_id}/update: - post: - description: Update an existing finding transformation rule's match criteria or transforms. - operationId: c1.api.finding.v1.FindingTransformationRuleService.UpdateFindingTransformationRule + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: List + /api/v1/funds/my/app-limits/{app_id}: + delete: + description: |- + Remove the caller's limit on this app entirely. The app is then bounded + only by the fund and by any tenant-wide cap. + operationId: c1.api.funds.v1.MyFundLimitsService.Delete parameters: - in: path - name: transformation_rule_id + name: app_id required: true schema: - description: The id field. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceDeleteResponse' description: Successful response - summary: Update Finding Transformation Rule + summary: Delete tags: - - Finding Transformation Rules - x-speakeasy-group: FindingTransformationRule - x-speakeasy-name-override: UpdateFindingTransformationRule - /api/v1/functions: + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: Delete + /api/v1/funds/my/app-limits/{app_id}/history: get: - description: List retrieves all functions with pagination - operationId: c1.api.functions.v1.FunctionsService.ListFunctions - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListFunctionsResponse' - description: Successful response - summary: List Functions - tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: ListFunctions - x-stability-level: draft - post: description: |- - CreateFunction registers a new serverless function and creates its - initial code commit. Functions run as TypeScript modules in a sandboxed - runtime; see initial_content for the entry-file signature and SDK import. + List the change history for one of the caller's own per-app limits, newest + first. Removing the last control deletes the row, so this is where a subject + reads back the pause they lifted and when they lifted it. - The new function is unpublished. To make the commit the default - runnable version (and have the function appear as runnable in the - Functions UI), call UpdateFunction with function.published_commit_id - set and update_mask=["published_commit_id"]. - operationId: c1.api.functions.v1.FunctionsService.CreateFunction - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionRequest' + VIEWER, not the OWNER the two admin-plane history RPCs use. This service + carries no user id in any request, so it can only ever return the caller's + own rows: gating it at OWNER would put an owner role in front of the + caller's own data and still return nothing but that. An admin auditing + another subject's app limits needs an admin-plane read, which this service + is not and deliberately does not become. + operationId: c1.api.funds.v1.MyFundLimitsService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceListHistoryResponse' description: Successful response - summary: Create Function + summary: List History tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#create - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateFunction - /api/v1/functions/{function_id}/commits: - get: - description: ListCommits retrieves the commit history - operationId: c1.api.functions.v1.FunctionsService.ListCommits + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: ListHistory + /api/v1/funds/my/app-limits/{app_id}/limit: + post: + description: Cap what one app may take from the caller's own fund. Amount arm only. + operationId: c1.api.funds.v1.MyFundLimitsService.SetLimit parameters: - in: path - name: function_id + name: app_id required: true schema: - description: The functionId field. + description: The appId field. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceSetLimitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListCommitsResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceSetLimitResponse' description: Successful response - summary: List Commits + summary: Set Limit tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: ListCommits - x-stability-level: draft - post: - description: CreateInitialCommit starts a new commit and returns upload URLs for files - operationId: c1.api.functions.v1.FunctionsService.CreateInitialCommit + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: SetLimit + /api/v1/funds/my/app-limits/{app_id}/suspension: + delete: + description: Un-pause the app, restoring the limit it froze. + operationId: c1.api.funds.v1.MyFundLimitsService.Resume parameters: - in: path - name: function_id + name: app_id required: true schema: - description: The functionId field. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceResumeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServiceResumeResponse' description: Successful response - summary: Create Initial Commit + summary: Resume tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateInitialCommit - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{commit_id}/finalize: + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: Resume post: - description: CreateFinalCommit completes a commit after files are uploaded - operationId: c1.api.functions.v1.FunctionsService.CreateFinalCommit + description: |- + Pause one app on the caller's own fund. The limit underneath is preserved + and restored by Resume. Denials name this as paused by you. + operationId: c1.api.funds.v1.MyFundLimitsService.Pause parameters: - in: path - name: function_id - required: true - schema: - description: The functionId field. - type: string - - in: path - name: commit_id + name: app_id required: true schema: - description: The commitId field. + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServicePauseRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse' + $ref: '#/components/schemas/c1.api.funds.v1.MyFundLimitsServicePauseResponse' description: Successful response - summary: Create Final Commit + summary: Pause tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateFinalCommit - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{commit_id}/lockfile: - get: - description: GetLockFile retrieves the deno lock file for a specific commit, if it exists. - operationId: c1.api.functions.v1.FunctionsService.GetLockFile - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - type: string - - in: path - name: commit_id - required: true - schema: - description: The commitId field. - type: string + - My Fund Limits + x-speakeasy-group: MyFundLimits + x-speakeasy-name-override: Pause + /api/v1/funds/policy: + delete: + description: |- + Delete the tenant's fund policy, opting the tenant back out of spend + governance. Rules, assignments and app caps are left in place and go + dormant; a later Create restores every one of them. + operationId: c1.api.funds.v1.FundPolicyService.Delete + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceDeleteRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetLockFileResponse' - description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. - summary: Get Lock File + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceDeleteResponse' + description: Successful response + summary: Delete tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: GetLockFile - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{id}: + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: Delete get: description: |- - GetCommitContent retrieves a commit and all its file contents in a single unary response. - This is a non-streaming alternative to GetCommit for REST API consumers. - operationId: c1.api.functions.v1.FunctionsService.GetCommitContent - parameters: - - in: path - name: function_id - required: true - schema: - description: The function ID (KSUID). - type: string - - in: path - name: id - required: true - schema: - description: The commit reference to retrieve. Accepts a KSUID, "HEAD", or a tag reference like "refs/tags/v1.0". - type: string + Get the tenant's fund policy. An absent policy in the response means the + tenant has not opted in to spend governance, which is an ordinary state + rather than an error. + operationId: c1.api.funds.v1.FundPolicyService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetCommitContentResponse' - description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. - summary: Get Commit Content + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceGetResponse' + description: Successful response + summary: Get tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: GetCommitContent - x-stability-level: draft - /api/v1/functions/{function_id}/invocations: - get: - description: List retrieves the invocation history for a function - operationId: c1.api.functions.v1.FunctionsInvocationService.List - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - type: string + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: Get + post: + description: |- + Create the tenant's fund policy, opting the tenant in to spend governance. + default_limit is required: a tenant states its posture explicitly, and + there is no implicit default anywhere in the write path. + operationId: c1.api.funds.v1.FundPolicyService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceListResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceCreateResponse' description: Successful response - summary: List + summary: Create tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocation - x-speakeasy-name-override: List - x-stability-level: draft - /api/v1/functions/{function_id}/invocations/{id}: - get: - description: Get retrieves a specific invocation by ID - operationId: c1.api.functions.v1.FunctionsInvocationService.Get - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - type: string - - in: path - name: id - required: true - schema: - description: The id field. - type: string + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: Create + /api/v1/funds/policy/ceiling/limit: + post: + description: |- + Set the org-wide ceiling: the bound on the tenant's total regardless of + what any principal was granted. Amount arm only. Clears the ceiling when + limit is absent. + operationId: c1.api.funds.v1.FundPolicyService.SetOrgCeiling + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceSetOrgCeilingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceGetResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceSetOrgCeilingResponse' description: Successful response - summary: Get + summary: Set Org Ceiling tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocation - x-speakeasy-name-override: Get - x-stability-level: draft - /api/v1/functions/{function_id}/invocations/search: + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: SetOrgCeiling + /api/v1/funds/policy/ceiling/suspension: + delete: + description: Lift the tenant freeze, restoring the ceiling it froze. + operationId: c1.api.funds.v1.FundPolicyService.UnfreezeTenant + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceUnfreezeTenantRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceUnfreezeTenantResponse' + description: Successful response + summary: Unfreeze Tenant + tags: + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: UnfreezeTenant post: description: |- - Search searches for function invocations with filtering and ordering support - Each invocation carries its input/output payloads, which can be large — request a small page_size (≤10) to keep responses small. - operationId: c1.api.functions.v1.FunctionsInvocationSearchService.Search - parameters: - - in: path - name: function_id - required: true - schema: - description: The function ID to search invocations for. - type: string + Freeze the whole tenant. The ceiling amount underneath is preserved and + restored by Unfreeze. + operationId: c1.api.funds.v1.FundPolicyService.FreezeTenant requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceFreezeTenantRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchResponse' - description: FunctionsInvocationSearchResponse is the response for searching function invocations. - summary: Search + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceFreezeTenantResponse' + description: Successful response + summary: Freeze Tenant tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocationSearch - x-speakeasy-name-override: Search - x-stability-level: draft - /api/v1/functions/{function_id}/invoke: - post: - description: Invoke executes a function at a specific commit with the provided input data. - operationId: c1.api.functions.v1.FunctionsService.Invoke + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: FreezeTenant + /api/v1/funds/policy/history: + get: + description: |- + List the change history for the fund policy, newest first. Admin-tier per + the object-history convention. + operationId: c1.api.funds.v1.FundPolicyService.ListHistory parameters: - - in: path - name: function_id - required: true + - in: query + name: page_size schema: - description: The ID of the function to invoke. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceListHistoryResponse' + description: Successful response + summary: List History + tags: + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: ListHistory + /api/v1/funds/policy/update: + post: + description: |- + Update the period or the default limit. currency_code is immutable after + Create and update_mask rejects it: an amount denominated in a currency the + policy no longer names faults the acquire path rather than denying it. + operationId: c1.api.funds.v1.FundPolicyService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceUpdateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundPolicyServiceUpdateResponse' description: Successful response - summary: Invoke + summary: Update tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: Invoke - x-stability-level: draft - /api/v1/functions/{function_id}/tags: + - Fund Policy + x-speakeasy-group: FundPolicy + x-speakeasy-name-override: Update + /api/v1/funds/rules: get: - description: ListTags lists all tags for a function - operationId: c1.api.functions.v1.FunctionsService.ListTags + description: |- + List every rule in the tenant. Reads the runtime plane: rule cardinality + is the tenant's rule count, so this is the same one-partition read + resolution does. + operationId: c1.api.funds.v1.FundRuleService.List parameters: - - in: path - name: function_id - required: true + - in: query + name: page_size schema: - description: The functionId field. + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListTagsResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceListResponse' description: Successful response - summary: List Tags + summary: List tags: - - Function Tag - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Function_Tag#read - terraform-resource: Function_Tag#read - x-speakeasy-group: Functions - x-speakeasy-name-override: ListTags - x-stability-level: draft + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: List post: - description: CreateTag creates a named reference to a specific commit - operationId: c1.api.functions.v1.FunctionsService.CreateTag + description: |- + Create funds a group. The group is an AppEntitlement, so membership + resolves through that entitlement's bindings on every acquire rather than + being captured here. Creating the tenant's first rule is what turns group + resolution on for that tenant. + operationId: c1.api.funds.v1.FundRuleService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: Create + /api/v1/funds/rules/{rule_id}: + delete: + description: |- + Delete withdraws a group grant. The cohort keeps whatever the tenant + default and any other rule matching them still allow, so this narrows their + fund rather than necessarily cutting it off. The rule's history survives. + operationId: c1.api.funds.v1.FundRuleService.Delete parameters: - in: path - name: function_id + name: rule_id required: true schema: - description: The functionId field. + description: The ruleId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceDeleteResponse' description: Successful response - summary: Create Tag + summary: Delete tags: - - Function Tag - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function_Tag#create - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateTag - x-stability-level: draft - /api/v1/functions/{function_id}/test: - post: - description: Test runs a function's test suite in a sandboxed environment and returns the results. - operationId: c1.api.functions.v1.FunctionsService.Test + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: Delete + get: + description: |- + Get returns one rule: the group it funds, the grant it carries, and the + label and reason an admin reads it by. A deleted rule is not found. + operationId: c1.api.funds.v1.FundRuleService.Get parameters: - in: path - name: function_id + name: rule_id required: true schema: - description: The function ID to test. + description: The ruleId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestResponse' - description: FunctionsServiceTestResponse contains test execution results. - summary: Test + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceGetResponse' + description: Successful response + summary: Get tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: Test - x-stability-level: draft - /api/v1/functions/{id}: - delete: - description: Delete removes a function - operationId: c1.api.functions.v1.FunctionsService.DeleteFunction + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: Get + post: + description: |- + Update replaces the group, grant, label or reason on one rule, whichever + the field mask names. The new grant governs the next acquire; spend already + accounted for against the old one is not revisited. + operationId: c1.api.funds.v1.FundRuleService.Update parameters: - in: path - name: id + name: rule_id required: true schema: - description: The id field. + description: The ruleId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceUpdateResponse' description: Successful response - summary: Delete Function + summary: Update tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#delete - x-speakeasy-group: Functions - x-speakeasy-name-override: DeleteFunction - x-stability-level: draft + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: Update + /api/v1/funds/rules/{rule_id}/history: get: - description: Get retrieves a specific function by ID - operationId: c1.api.functions.v1.FunctionsService.GetFunction + description: |- + List the change history for one rule, newest first. Admin-tier per the + object-history convention. A deleted rule keeps its history: the delete is + the last entry, and the one before it is the rule as it last stood. + operationId: c1.api.funds.v1.FundRuleService.ListHistory parameters: - in: path - name: id + name: rule_id required: true schema: - description: The id field. + description: The ruleId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetFunctionResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceListHistoryResponse' description: Successful response - summary: Get Function + summary: List History tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Function#read - x-speakeasy-group: Functions - x-speakeasy-name-override: GetFunction - x-stability-level: draft - /api/v1/functions/update: + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: ListHistory + /api/v1/funds/rules/search: post: - description: |- - Update an existing function's metadata. Also the publish path: set - function.published_commit_id and include "published_commit_id" in - update_mask to make a commit the default runnable version. - operationId: c1.api.functions.v1.FunctionsService.UpdateFunction + description: Search rules by display name. Reads the Postgres mirror. + operationId: c1.api.funds.v1.FundRuleService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse' + $ref: '#/components/schemas/c1.api.funds.v1.FundRuleServiceSearchResponse' description: Successful response - summary: Update Function + summary: Search tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#update - x-speakeasy-group: Functions - x-speakeasy-name-override: UpdateFunction - x-stability-level: draft + - Fund Rules + x-speakeasy-group: FundRule + x-speakeasy-name-override: Search /api/v1/grants/feed: post: description: Search a chronological feed of grant and revoke events, filtered by app user, entitlement, or time range. @@ -49919,7 +57801,7 @@ paths: x-speakeasy-name-override: SearchGrantFeed /api/v1/hooks: get: - description: Invokes the c1.api.hooks.v1.HooksService.List method. + description: List returns all hooks for the tenant, paginated. operationId: c1.api.hooks.v1.HooksService.List parameters: - in: query @@ -49946,7 +57828,10 @@ paths: x-speakeasy-group: Hooks x-speakeasy-name-override: List post: - description: Invokes the c1.api.hooks.v1.HooksService.Create method. + description: |- + Create creates a hook. The hook fires on the configured event, optionally + filtered by a CEL expression. Creating a Patch tool input hook requires the + preview feature to be enabled for the tenant. operationId: c1.api.hooks.v1.HooksService.Create requestBody: content: @@ -49967,7 +57852,9 @@ paths: x-speakeasy-name-override: Create /api/v1/hooks/{id}: delete: - description: Invokes the c1.api.hooks.v1.HooksService.Delete method. + description: |- + Delete removes a hook by ID. A hook referenced by a guardrail rule cannot + be deleted until the reference is removed. operationId: c1.api.hooks.v1.HooksService.Delete parameters: - in: path @@ -49994,7 +57881,7 @@ paths: x-speakeasy-group: Hooks x-speakeasy-name-override: Delete get: - description: Invokes the c1.api.hooks.v1.HooksService.Get method. + description: Get returns a hook by ID. operationId: c1.api.hooks.v1.HooksService.Get parameters: - in: path @@ -50016,7 +57903,10 @@ paths: x-speakeasy-group: Hooks x-speakeasy-name-override: Get post: - description: Invokes the c1.api.hooks.v1.HooksService.Update method. + description: |- + Update modifies a hook's display name, description, event, filter, priority, + or configuration. A hook referenced by a guardrail rule cannot stop being + managed by guardrails until the reference is removed. operationId: c1.api.hooks.v1.HooksService.Update parameters: - in: path @@ -50633,6 +58523,160 @@ paths: - Tunnel x-speakeasy-group: TunnelCredentials x-speakeasy-name-override: RevokeBridgeCredential + /api/v1/llm-gateway/keys: + get: + description: |- + List returns the tenant's LLM gateway API keys. Only key metadata and a + key prefix are returned, never the full key. + operationId: c1.api.llm_gateway.v1.GatewayKeyService.List + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.ListGatewayKeysResponse' + description: Successful response + summary: List + tags: + - LLM Gateway Keys + x-speakeasy-group: GatewayKey + x-speakeasy-name-override: List + post: + description: |- + Mint creates a new LLM gateway API key. The key value is shown only in + this response and cannot be retrieved again; store it immediately. + operationId: c1.api.llm_gateway.v1.GatewayKeyService.Mint + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.MintGatewayKeyRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.MintGatewayKeyResponse' + description: Successful response + summary: Mint + tags: + - LLM Gateway Keys + x-speakeasy-group: GatewayKey + x-speakeasy-name-override: Mint + /api/v1/llm-gateway/keys/{id}: + delete: + description: |- + Revoke revokes an LLM gateway API key by ID. The key immediately stops + authenticating gateway requests. + operationId: c1.api.llm_gateway.v1.GatewayKeyService.Revoke + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.RevokeGatewayKeyRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.RevokeGatewayKeyResponse' + description: Successful response + summary: Revoke + tags: + - LLM Gateway Keys + x-speakeasy-group: GatewayKey + x-speakeasy-name-override: Revoke + /api/v1/llm-gateway/provider-credentials/{slot_id}: + delete: + description: Clear deletes the provider credential stored in the given slot. + operationId: c1.api.llm_gateway.v1.ProviderCredentialService.Clear + parameters: + - in: path + name: slot_id + required: true + schema: + description: The slotId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.ClearProviderCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.ClearProviderCredentialResponse' + description: Successful response + summary: Clear + tags: + - LLM Gateway Provider Credentials + x-speakeasy-group: ProviderCredential + x-speakeasy-name-override: Clear + get: + description: |- + Get returns metadata for the provider credential in the given slot. The + stored API key is never returned. Returns an empty response if no + credential has ever been set for the slot; a cleared slot returns + FAILED_PRECONDITION. + operationId: c1.api.llm_gateway.v1.ProviderCredentialService.Get + parameters: + - in: path + name: slot_id + required: true + schema: + description: The slotId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.GetProviderCredentialResponse' + description: Successful response + summary: Get + tags: + - LLM Gateway Provider Credentials + x-speakeasy-group: ProviderCredential + x-speakeasy-name-override: Get + put: + description: |- + Set stores or replaces the provider API key used by the LLM gateway for + the given slot. The API key is stored encrypted and is never returned by + the API. + operationId: c1.api.llm_gateway.v1.ProviderCredentialService.Set + parameters: + - in: path + name: slot_id + required: true + schema: + description: The slotId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.SetProviderCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.llm_gateway.v1.SetProviderCredentialResponse' + description: Successful response + summary: Set + tags: + - LLM Gateway Provider Credentials + x-speakeasy-group: ProviderCredential + x-speakeasy-name-override: Set /api/v1/local-directory-configs: get: description: List local directory configs for the tenant. @@ -50987,6 +59031,45 @@ paths: - MCP Servers x-speakeasy-group: MCPServer x-speakeasy-name-override: TestConnection + /api/v1/mcp_toolsets/search: + get: + description: |- + SearchAccessProfiles returns the tenant's MCP toolsets (access profiles) + across every (app_id, connector_id), filtered by a case-insensitive search + over display_name and paginated. Backs the agent-config multi-select that + binds toolsets to a ClawAgent. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.SearchAccessProfiles + parameters: + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + - in: query + name: query + schema: + description: Case-insensitive search over the profile display name; empty returns all. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceSearchAccessProfilesResponse' + description: |- + MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of + tenant-wide MCP access profiles. + summary: Search Access Profiles + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: SearchAccessProfiles /api/v1/policies: get: description: List policies. @@ -51317,6 +59400,206 @@ paths: terraform-resource: RecoveryPolicy#update x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: Update + /api/v1/reporting/reports: + get: + description: List returns reports created by the caller, newest first. + operationId: c1.api.reporting.v1.ReportingService.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceListResponse' + description: Successful response + summary: List + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: List + post: + description: |- + Save promotes the program behind an already-rendered reporting surface into + a report. The caller identifies the surface; the server resolves which + program produced it. There is no create-from-prompt: the prompt has already + been answered by the time a report is worth keeping. + operationId: c1.api.reporting.v1.ReportingService.Save + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceSaveRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceSaveResponse' + description: Successful response + summary: Save + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: Save + /api/v1/reporting/reports/{id}: + delete: + description: |- + Delete removes a report by ID. The report's saved program is removed with + it, so the report can no longer be re-run. Only the report's creator can + delete it. + operationId: c1.api.reporting.v1.ReportingService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: Delete + get: + description: |- + Get returns a report by ID, including its latest run and latest successful + run. Reports are visible only to the user who created them. + operationId: c1.api.reporting.v1.ReportingService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceGetResponse' + description: Successful response + summary: Get + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: Get + post: + description: |- + Update modifies a report's display name, prompt, or parameter values. + Only the report's creator can update it. + operationId: c1.api.reporting.v1.ReportingService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: Update + /api/v1/reporting/reports/{id}/run: + post: + description: |- + Run re-executes the report's pinned program against today's data. It never + re-plans: the commit is fixed, so a rerun can only change the numbers, not + the question. Returns as soon as the invocation starts — see the response. + operationId: c1.api.reporting.v1.ReportingService.Run + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceRunRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceRunResponse' + description: Successful response + summary: Run + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: Run + /api/v1/reporting/reports/{id}/runs/{run_id}/provenance: + get: + description: |- + GetRunProvenance explains a run: what it read, what its program looked at, + and the program itself. A2UIService.GetSurfaceProvenance answers the same + question for a surface, but needs a live one — and a rerun is headless, so + a report would become less explainable every time it refreshed. + operationId: c1.api.reporting.v1.ReportingService.GetRunProvenance + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + - in: path + name: run_id + required: true + schema: + description: The runId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.reporting.v1.ReportingServiceGetRunProvenanceResponse' + description: Successful response + summary: Get Run Provenance + tags: + - Report + x-speakeasy-group: Reporting + x-speakeasy-name-override: GetRunProvenance /api/v1/request_schema_entitlement_binding: delete: description: Remove the link between a request schema and a single app entitlement. @@ -51582,9 +59865,45 @@ paths: - Role Mining x-speakeasy-group: RoleMiningManagement x-speakeasy-name-override: ListCustomAnalysisResults + /api/v1/role-mining/custom-analysis/{analysis_id}/evaluate-entitlement-selection: + post: + description: |- + Evaluate the exact cohort impact of an entitlement cutoff and manual overrides. + The analysis determines the eligible entitlements and cohort definition. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.EvaluateEntitlementSelection + parameters: + - in: path + name: analysis_id + required: true + schema: + description: Custom analysis whose cohort and entitlement results define the selection. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EvaluateEntitlementSelectionRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EvaluateEntitlementSelectionResponse' + description: |- + EvaluateEntitlementSelectionResponse contains the exact impact of the + resolved entitlement selection. + summary: Evaluate Entitlement Selection + tags: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: EvaluateEntitlementSelection /api/v1/role-mining/custom-analysis/{id}: get: - description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult method. + description: |- + GetCustomAnalysisResult returns the status and results of a custom cohort + analysis started with TriggerCustomAnalysis, including entitlement + coverage, entitlement clusters, attribute facets, and cutoff impact + points. Requires the agentic role mining feature. operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult parameters: - in: path @@ -51607,7 +59926,11 @@ paths: x-speakeasy-name-override: GetCustomAnalysisResult /api/v1/role-mining/custom-analysis/trigger: post: - description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis method. + description: |- + TriggerCustomAnalysis starts an asynchronous custom cohort analysis defined + by the given profile filters and returns the ID of the analysis result. + Requires the agentic role mining feature. Poll GetCustomAnalysisResult + until the analysis completes. operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis requestBody: content: @@ -52250,9 +60573,39 @@ paths: - App Entitlement x-speakeasy-group: AppEntitlementSearch x-speakeasy-name-override: CountGrantsForUserByApp + /api/v1/search/graph/resources: + post: + description: |- + SearchReachableResourcesForUser returns the distinct app resources a user + can reach through any of their grants, deduplicated across entitlements + (a resource reachable via more than one grant appears once). Powers the + Resources lane of the access graph's list view: supports free-text search + over resource display name and narrowing to specific applications. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchReachableResourcesForUser + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchReachableResourcesForUserRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse' + description: |- + SearchReachableResourcesForUser response. Resources are deduplicated: a + resource reachable through more than one grant or entitlement appears once. + summary: Search Reachable Resources For User + tags: + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchReachableResourcesForUser /api/v1/search/hooks: post: - description: Invokes the c1.api.hooks.v1.HooksSearch.Search method. + description: |- + Search returns hooks for the tenant, paginated. Setting query or refs + returns UNIMPLEMENTED; filtering is not yet supported. operationId: c1.api.hooks.v1.HooksSearch.Search requestBody: content: @@ -52672,6 +61025,29 @@ paths: - SSF Receiver x-speakeasy-group: SSFReceiverEventSearch x-speakeasy-name-override: Search + /api/v1/search/sso/applications: + post: + description: |- + Search SSO applications across the tenant. Supports filtering by the + applications in your catalog and by display-name or description text. + operationId: c1.api.sso.v1.SSOApplicationService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceSearchRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceSearchResponse' + description: SSOApplicationServiceSearchResponse returns matching SSO applications. + summary: Search + tags: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: Search /api/v1/search/step-up/providers: post: description: Search allows searching for step-up providers with various filters @@ -54086,7 +62462,8 @@ paths: /admin/settings/ai-governance page. Returns the full AIGovernanceSettings: allowed MCP client types, default client lifecycle, require_tool_approval, default tool classification, audit verbosity, auto-discovery toggle + - interval, prefer_code_mode_over_direct_tools, and surface_requestable_tools. + interval, prefer_code_mode_over_direct_tools, surface_requestable_tools, + and untrusted_judge_disable. operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.Get responses: "200": @@ -54106,7 +62483,8 @@ paths: which fields to apply (e.g. require_tool_approval, default_tool_classification, audit_verbosity, auto_discovery_enabled, discovery_interval, prefer_code_mode_over_direct_tools, - surface_requestable_tools, allowed_client_types, default_client_lifecycle). + surface_requestable_tools, untrusted_judge_disable, allowed_client_types, + default_client_lifecycle). Only masked fields change. Returns the updated settings. operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.Update requestBody: @@ -54190,7 +62568,9 @@ paths: x-speakeasy-name-override: Get /api/v1/settings/contacts: get: - description: Invokes the c1.api.settings.v1.ContactsService.GetContacts method. + description: |- + GetContacts returns the organization's security, billing, and operations + contact email addresses. operationId: c1.api.settings.v1.ContactsService.GetContacts responses: "200": @@ -54205,7 +62585,11 @@ paths: x-speakeasy-group: Contacts x-speakeasy-name-override: GetContacts post: - description: Invokes the c1.api.settings.v1.ContactsService.UpdateContacts method. + description: |- + UpdateContacts updates the organization's security, billing, and + operations contact email addresses. If update_mask is set, only the + selected fields are changed; otherwise all contact fields are replaced + with the values in the request. operationId: c1.api.settings.v1.ContactsService.UpdateContacts requestBody: content: @@ -54751,6 +63135,74 @@ paths: - Session Settings x-speakeasy-group: SessionSettings x-speakeasy-name-override: TestSourceIP + /api/v1/settings/sso: + get: + description: Get returns the tenant's SSO provider settings. + operationId: c1.api.sso.v1.SSOSettingsService.Get + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOSettingsServiceGetResponse' + description: SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. + summary: Get + tags: + - SSO + x-speakeasy-group: SSOSettings + x-speakeasy-name-override: Get + post: + description: |- + Update changes the tenant's SSO provider settings. Supply the settings + object and an update mask listing the fields to change; only masked fields + are applied. Editable paths: enabled, default_subject_type, + default_assertion_lifetime, default_id_token_signed_response_alg. + operationId: c1.api.sso.v1.SSOSettingsService.Update + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOSettingsServiceUpdateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOSettingsServiceUpdateResponse' + description: SSOSettingsServiceUpdateResponse returns the updated settings. + summary: Update + tags: + - SSO + x-speakeasy-group: SSOSettings + x-speakeasy-name-override: Update + /api/v1/settings/sso/history: + get: + description: ListHistory returns the SSO settings change history, newest first. + operationId: c1.api.sso.v1.SSOSettingsService.ListHistory + parameters: + - in: query + name: page_size + schema: + description: Maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Pagination token from a previous response. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOSettingsServiceListHistoryResponse' + description: SSOSettingsServiceListHistoryResponse returns SSO settings history entries. + summary: List History + tags: + - SSO + x-speakeasy-group: SSOSettings + x-speakeasy-name-override: ListHistory /api/v1/sign-in-policies: get: description: List all sign-in policies in your tenant, one page at a time. @@ -55106,6 +63558,36 @@ paths: - SSF Receiver x-speakeasy-group: SSFReceiverStream x-speakeasy-name-override: GetStats + /api/v1/sso/applications/saml/parse-sp-metadata: + post: + description: |- + ParseSAMLServiceProviderMetadata parses one uploaded SAML service-provider + metadata document and returns the SAML configuration it implies, without + creating or changing anything. The document is not stored. Use it to + preview an SP's capabilities before creating a SAML application; edit the + returned configuration before passing it to Create. Only upload or paste a + customer-supplied document -- C1 does not fetch metadata URLs. + operationId: c1.api.sso.v1.SSOApplicationService.ParseSAMLServiceProviderMetadata + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse' + description: |- + SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the + SAML configuration derived from one metadata document and every finding the + parser raised about it. + summary: Parse Saml Service Provider Metadata + tags: + - SSO + x-speakeasy-group: SSOApplication + x-speakeasy-name-override: ParseSAMLServiceProviderMetadata /api/v1/step-up/providers: get: description: List returns all step-up authentication providers configured for the tenant. @@ -55935,6 +64417,37 @@ paths: - Task x-speakeasy-group: TaskActions x-speakeasy-name-override: Restart + /api/v1/tasks/{task_id}/action/retry-provisioning: + post: + description: |- + Retry the provisioning of a task whose connector provisioning failed. Resets the + failed connector actions and re-drives the connector, preserving the already-collected + approvals. Only valid when the task's current provision step ended in an error. + operationId: c1.api.task.v1.TaskActionsService.RetryProvisioning + parameters: + - in: path + name: task_id + required: true + schema: + description: The ID of the task to retry provisioning for. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceRetryProvisioningRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + summary: Retry Provisioning + tags: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: RetryProvisioning /api/v1/tasks/{task_id}/action/skip-step: post: description: Skip a specific policy step in a task, advancing the task to the next step in the workflow. diff --git a/.speakeasy/logs/changes/old.openapi.yaml b/.speakeasy/logs/changes/old.openapi.yaml index 6e5c568af..cdbbfc6b9 100644 --- a/.speakeasy/logs/changes/old.openapi.yaml +++ b/.speakeasy/logs/changes/old.openapi.yaml @@ -30,63 +30,114 @@ components: - c1OnboardingWelcome - c1OnboardingPlan - c1ConnectorSyncDetail + - c1Chart properties: button: - $ref: '#/components/schemas/c1.api.a2ui.v1.ButtonComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ButtonComponent' + - type: "null" + c1Chart: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartComponent' + - type: "null" c1CodeBlock: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1CodeBlockComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1CodeBlockComponent' + - type: "null" c1ConnectorConfigForm: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorConfigFormComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorConfigFormComponent' + - type: "null" c1ConnectorSyncDetail: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorSyncDetailComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorSyncDetailComponent' + - type: "null" c1ConnectorSyncProgress: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorSyncProgressComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ConnectorSyncProgressComponent' + - type: "null" c1DurationPicker: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1DurationPickerComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1DurationPickerComponent' + - type: "null" c1MsTeamsNotifications: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1MSTeamsNotificationsComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1MSTeamsNotificationsComponent' + - type: "null" c1OnboardingPlan: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingPlanComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingPlanComponent' + - type: "null" c1OnboardingWelcome: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingWelcomeComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingWelcomeComponent' + - type: "null" c1ResourcePicker: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ResourcePickerComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ResourcePickerComponent' + - type: "null" c1SlackNotifications: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1SlackNotificationsComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1SlackNotificationsComponent' + - type: "null" c1StatusIndicator: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1StatusIndicatorComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1StatusIndicatorComponent' + - type: "null" c1TodoList: - $ref: '#/components/schemas/c1.api.a2ui.v1.C1TodoListComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1TodoListComponent' + - type: "null" card: - $ref: '#/components/schemas/c1.api.a2ui.v1.CardComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.CardComponent' + - type: "null" checkBox: - $ref: '#/components/schemas/c1.api.a2ui.v1.CheckBoxComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.CheckBoxComponent' + - type: "null" choicePicker: - $ref: '#/components/schemas/c1.api.a2ui.v1.ChoicePickerComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ChoicePickerComponent' + - type: "null" column: - $ref: '#/components/schemas/c1.api.a2ui.v1.ColumnComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ColumnComponent' + - type: "null" dateTimeInput: - $ref: '#/components/schemas/c1.api.a2ui.v1.DateTimeInputComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DateTimeInputComponent' + - type: "null" divider: - $ref: '#/components/schemas/c1.api.a2ui.v1.DividerComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DividerComponent' + - type: "null" id: description: The id field. - readOnly: false type: string progressBar: - $ref: '#/components/schemas/c1.api.a2ui.v1.ProgressBarComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ProgressBarComponent' + - type: "null" row: - $ref: '#/components/schemas/c1.api.a2ui.v1.RowComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.RowComponent' + - type: "null" slider: - $ref: '#/components/schemas/c1.api.a2ui.v1.SliderComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.SliderComponent' + - type: "null" text: - $ref: '#/components/schemas/c1.api.a2ui.v1.TextComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.TextComponent' + - type: "null" textField: - $ref: '#/components/schemas/c1.api.a2ui.v1.TextFieldComponent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.TextFieldComponent' + - type: "null" weight: description: The weight field. format: int32 - readOnly: false type: integer title: A 2 Ui Component type: object @@ -96,7 +147,6 @@ components: properties: conversationId: description: The conversationId field. - readOnly: false type: string sentiment: description: The sentiment field. @@ -104,12 +154,10 @@ components: - A2UI_SURFACE_FEEDBACK_SENTIMENT_UNSPECIFIED - A2UI_SURFACE_FEEDBACK_SENTIMENT_POSITIVE - A2UI_SURFACE_FEEDBACK_SENTIMENT_NEGATIVE - readOnly: false type: string x-speakeasy-unknown-values: allow text: description: The text field. - readOnly: false type: string title: A 2 Ui Service Create Surface Feedback Request type: object @@ -118,7 +166,9 @@ components: description: A2UIServiceCreateSurfaceFeedbackResponse returns the created feedback. properties: feedback: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UISurfaceFeedback' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UISurfaceFeedback' + - type: "null" title: A 2 Ui Service Create Surface Feedback Response type: object x-speakeasy-name-override: A2UIServiceCreateSurfaceFeedbackResponse @@ -129,9 +179,9 @@ components: description: The feedback field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.A2UISurfaceFeedback' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: A 2 Ui Service List Surface Feedback Response type: object x-speakeasy-name-override: A2UIServiceListSurfaceFeedbackResponse @@ -142,9 +192,9 @@ components: description: The surfaces field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.A2UISurface' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: A 2 Ui Service List Surfaces Response type: object x-speakeasy-name-override: A2UIServiceListSurfacesResponse @@ -153,29 +203,25 @@ components: properties: actionName: description: The actionName field. - readOnly: false type: string clientTimestamp: format: date-time - readOnly: false - type: string + type: + - string + - "null" context: additionalProperties: type: string description: The context field. - readOnly: false type: object conversationId: description: The conversationId field. - readOnly: false type: string dataModelJson: description: The dataModelJson field. - readOnly: false type: string sourceComponentId: description: The sourceComponentId field. - readOnly: false type: string title: A 2 Ui Service Submit Action Request type: object @@ -185,11 +231,9 @@ components: properties: accepted: description: The accepted field. - readOnly: false type: boolean errorMessage: description: The errorMessage field. - readOnly: false type: string title: A 2 Ui Service Submit Action Response type: object @@ -199,39 +243,45 @@ components: properties: catalogId: description: The catalogId field. - readOnly: false type: string components: description: The components field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIComponent' - nullable: true - readOnly: false - type: array + type: + - array + - "null" conversationId: description: The conversationId field. - readOnly: false type: string createdAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" dataModelJson: description: The dataModelJson field. - readOnly: false type: string deletedAt: format: date-time - readOnly: false + type: + - string + - "null" + role: + description: The role field. + enum: + - SURFACE_ROLE_UNSPECIFIED + - SURFACE_ROLE_PRIMARY + - SURFACE_ROLE_STATUS + - SURFACE_ROLE_PROMPT type: string + x-speakeasy-unknown-values: allow schemaVersion: description: The schemaVersion field. format: int64 - readOnly: false type: string sendDataModel: description: The sendDataModel field. - readOnly: false type: boolean state: description: The state field. @@ -240,21 +290,19 @@ components: - SURFACE_LIFECYCLE_STATE_ACTIVE - SURFACE_LIFECYCLE_STATE_COMPLETE - SURFACE_LIFECYCLE_STATE_DELETED - readOnly: false type: string x-speakeasy-unknown-values: allow surfaceId: description: The surfaceId field. - readOnly: false type: string tenantId: description: The tenantId field. - readOnly: false type: string updatedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" title: A 2 Ui Surface type: object x-speakeasy-name-override: A2UISurface @@ -263,32 +311,27 @@ components: properties: actionName: description: The actionName field. - readOnly: false type: string componentsSnapshot: description: The componentsSnapshot field. - readOnly: false type: string conversationId: description: The conversationId field. - readOnly: false type: string createdAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" dataModelSnapshot: description: The dataModelSnapshot field. - readOnly: false type: string id: description: The id field. - readOnly: false type: string schemaVersion: description: The schemaVersion field. format: int64 - readOnly: false type: string sentiment: description: The sentiment field. @@ -296,16 +339,13 @@ components: - A2UI_SURFACE_FEEDBACK_SENTIMENT_UNSPECIFIED - A2UI_SURFACE_FEEDBACK_SENTIMENT_POSITIVE - A2UI_SURFACE_FEEDBACK_SENTIMENT_NEGATIVE - readOnly: false type: string x-speakeasy-unknown-values: allow surfaceId: description: The surfaceId field. - readOnly: false type: string text: description: The text field. - readOnly: false type: string title: A 2 Ui Surface Feedback type: object @@ -319,43 +359,51 @@ components: - functionCall properties: event: - $ref: '#/components/schemas/c1.api.a2ui.v1.ServerEvent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ServerEvent' + - type: "null" functionCall: - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + - type: "null" title: Action type: object x-speakeasy-name-override: A2UIAction c1.api.a2ui.v1.AndCheck: description: AndCheck requires all checks to pass. - nullable: true properties: checks: description: The checks field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.ValidationCheck' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: And Check type: object x-speakeasy-name-override: AndCheck c1.api.a2ui.v1.ButtonComponent: description: ButtonComponent triggers actions. - nullable: true properties: action: - $ref: '#/components/schemas/c1.api.a2ui.v1.Action' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.Action' + - type: "null" checks: description: The checks field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.ValidationCheck' - nullable: true - readOnly: false - type: array + type: + - array + - "null" disabled: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + - type: "null" label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" variant: description: The variant field. enum: @@ -363,26 +411,197 @@ components: - BUTTON_VARIANT_PRIMARY - BUTTON_VARIANT_SECONDARY - BUTTON_VARIANT_TEXT - readOnly: false type: string x-speakeasy-unknown-values: allow title: Button Component type: object x-speakeasy-name-override: ButtonComponent + c1.api.a2ui.v1.C1ChartCategoricalData: + description: C1ChartCategoricalData is (label, value) slices for part-to-whole charts. + properties: + slices: + description: The slices field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartSlice' + type: + - array + - "null" + style: + description: The style field. + enum: + - C1_CHART_CATEGORICAL_STYLE_UNSPECIFIED + - C1_CHART_CATEGORICAL_STYLE_PIE + - C1_CHART_CATEGORICAL_STYLE_DONUT + type: string + x-speakeasy-unknown-values: allow + title: C 1 Chart Categorical Data + type: object + x-speakeasy-name-override: C1ChartCategoricalData + c1.api.a2ui.v1.C1ChartComponent: + description: | + C1ChartComponent renders a chart from typed data. The data oneof is keyed by + shape — each shape carries its own style enum, so an invalid combination + (e.g. a pie chart with a time axis) is unrepresentable. + + This message contains a oneof named data. Only a single field of the following list may be set at a time: + - timeSeries + - categorical + properties: + artifactUrl: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + categorical: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartCategoricalData' + - type: "null" + sources: + description: 'Provenance: the queries the producing function ran.' + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartSource' + type: + - array + - "null" + timeSeries: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartTimeSeriesData' + - type: "null" + title: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + title: C 1 Chart Component + type: object + x-speakeasy-name-override: C1ChartComponent + c1.api.a2ui.v1.C1ChartPoint: + description: C1ChartPoint is a single (timestamp, value) observation. + properties: + ts: + format: date-time + type: + - string + - "null" + value: + description: 'Bounds double as a NaN/Inf rejection: NaN fails every comparison.' + type: number + title: C 1 Chart Point + type: object + x-speakeasy-name-override: C1ChartPoint + c1.api.a2ui.v1.C1ChartSeries: + description: C1ChartSeries is one named line/bar series. + properties: + displayName: + description: The displayName field. + type: string + key: + description: The key field. + type: string + points: + description: The points field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartPoint' + type: + - array + - "null" + title: C 1 Chart Series + type: object + x-speakeasy-name-override: C1ChartSeries + c1.api.a2ui.v1.C1ChartSlice: + description: C1ChartSlice is a single categorical slice. + properties: + label: + description: The label field. + type: string + value: + description: The value field. + type: number + title: C 1 Chart Slice + type: object + x-speakeasy-name-override: C1ChartSlice + c1.api.a2ui.v1.C1ChartSource: + description: |- + C1ChartSource records one query the producing function ran, for the + provenance chips rendered under the chart. + properties: + count: + description: The count field. + format: int64 + type: string + kind: + description: The kind field. + type: string + label: + description: The label field. + type: string + ref: + description: The ref field. + type: string + title: C 1 Chart Source + type: object + x-speakeasy-name-override: C1ChartSource + c1.api.a2ui.v1.C1ChartTimeRange: + description: C1ChartTimeRange is the window the series cover, with a display label. + properties: + end: + format: date-time + type: + - string + - "null" + label: + description: The label field. + type: string + start: + format: date-time + type: + - string + - "null" + title: C 1 Chart Time Range + type: object + x-speakeasy-name-override: C1ChartTimeRange + c1.api.a2ui.v1.C1ChartTimeSeriesData: + description: C1ChartTimeSeriesData is named series of (timestamp, value) points. + properties: + range: + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartTimeRange' + - type: "null" + series: + description: The series field. + items: + $ref: '#/components/schemas/c1.api.a2ui.v1.C1ChartSeries' + type: + - array + - "null" + style: + description: The style field. + enum: + - C1_CHART_TIME_SERIES_STYLE_UNSPECIFIED + - C1_CHART_TIME_SERIES_STYLE_LINE + - C1_CHART_TIME_SERIES_STYLE_STACKED_BAR + - C1_CHART_TIME_SERIES_STYLE_STACKED_AREA + type: string + x-speakeasy-unknown-values: allow + title: C 1 Chart Time Series Data + type: object + x-speakeasy-name-override: C1ChartTimeSeriesData c1.api.a2ui.v1.C1CodeBlockComponent: description: C1CodeBlockComponent displays code with syntax highlighting. - nullable: true properties: code: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" copyable: description: The copyable field. - readOnly: false type: boolean language: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: C 1 Code Block Component type: object x-speakeasy-name-override: C1CodeBlockComponent @@ -392,23 +611,18 @@ components: A2UI surface. The frontend resolves the catalog, connector, and config schema itself from the ids below, keeping the configuration field values out of the agent's data model — the agent never receives API keys, passwords, or other secrets entered by the user. - nullable: true properties: appId: description: The appId field. - readOnly: false type: string connectorId: description: The connectorId field. - readOnly: false type: string skipActionName: description: The skipActionName field. - readOnly: false type: string submitActionName: description: The submitActionName field. - readOnly: false type: string title: C 1 Connector Config Form Component type: object @@ -421,19 +635,15 @@ components: paint. Intended for message-body placement — emit one after each `submit_app_config` so the transcript carries a clear "this is what just happened" receipt for the connector the user just connected. - nullable: true properties: appId: description: The appId field. - readOnly: false type: string connectorId: description: The connectorId field. - readOnly: false type: string title: description: The title field. - readOnly: false type: string title: C 1 Connector Sync Detail Component type: object @@ -442,19 +652,15 @@ components: description: |- C1ConnectorSyncProgressComponent renders a live connector sync status card. Subscribes to WebSocket updates for real-time sync lifecycle status. - nullable: true properties: appId: description: The appId field. - readOnly: false type: string connectorId: description: The connectorId field. - readOnly: false type: string title: description: The title field. - readOnly: false type: string title: C 1 Connector Sync Progress Component type: object @@ -463,14 +669,19 @@ components: description: |- C1DurationPickerComponent is the access-request duration picker (presets + custom with number/unit). Value is duration in seconds bound to the given path. - nullable: true properties: label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" maxDurationSeconds: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" title: C 1 Duration Picker Component type: object x-speakeasy-name-override: C1DurationPickerComponent @@ -478,7 +689,6 @@ components: description: |- C1MSTeamsNotificationsComponent renders a self-contained Microsoft Teams integration card. Fetches status and consent URLs via frontend API calls. - nullable: true title: C 1 Ms Teams Notifications Component type: object x-speakeasy-name-override: C1MSTeamsNotificationsComponent @@ -487,18 +697,16 @@ components: properties: id: description: The id field. - readOnly: false type: string steps: description: The steps field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingPlanStep' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: description: The title field. - readOnly: false type: string title: C 1 Onboarding Plan Category type: object @@ -507,15 +715,14 @@ components: description: |- C1OnboardingPlanComponent renders a personalized onboarding plan with categorized steps. The agent dynamically populates categories and steps based on user intent and context. - nullable: true properties: categories: description: The categories field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.C1OnboardingPlanCategory' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: C 1 Onboarding Plan Component type: object x-speakeasy-name-override: C1OnboardingPlanComponent @@ -524,19 +731,15 @@ components: properties: agentAssisted: description: The agentAssisted field. - readOnly: false type: boolean description: description: The description field. - readOnly: false type: string id: description: The id field. - readOnly: false type: string title: description: The title field. - readOnly: false type: string title: C 1 Onboarding Plan Step type: object @@ -546,35 +749,46 @@ components: C1OnboardingWelcomeComponent renders the onboarding welcome screen with org context and intent collection. Backend pre-populates recommended_catalog_id / recommended_display_name from detected IDP. Frontend detects auth backend via introspect for contextual UI text. - nullable: true properties: recommendedCatalogId: description: The recommendedCatalogId field. - readOnly: false type: string recommendedDisplayName: description: The recommendedDisplayName field. - readOnly: false type: string title: C 1 Onboarding Welcome Component type: object x-speakeasy-name-override: C1OnboardingWelcomeComponent c1.api.a2ui.v1.C1ResourcePickerComponent: description: C1ResourcePickerComponent allows selecting C1 resources. - nullable: true properties: + appId: + description: |- + Scoping for resource_type "mcp_tool": the app and connector whose tools the + paginated picker searches, and an optional tool-state filter (the + MCPToolState enum name, e.g. "MCP_TOOL_STATE_PENDING_REVIEW"; empty = no + filter). Ignored by other resource types. + type: string + connectorId: + description: The connectorId field. + type: string label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" + mcpToolState: + description: The mcpToolState field. + type: string multiSelect: description: The multiSelect field. - readOnly: false type: boolean resourceType: description: The resourceType field. - readOnly: false type: string value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: C 1 Resource Picker Component type: object x-speakeasy-name-override: C1ResourcePickerComponent @@ -582,22 +796,28 @@ components: description: |- C1SlackNotificationsComponent renders a self-contained Slack integration card. Fetches status and OAuth URLs via frontend API calls. - nullable: true title: C 1 Slack Notifications Component type: object x-speakeasy-name-override: C1SlackNotificationsComponent c1.api.a2ui.v1.C1StatusIndicatorComponent: description: C1StatusIndicatorComponent shows agent progress status. - nullable: true properties: message: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" showSpinner: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + - type: "null" status: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" toolName: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: C 1 Status Indicator Component type: object x-speakeasy-name-override: C1StatusIndicatorComponent @@ -605,61 +825,71 @@ components: description: The C1TodoItem message. properties: description: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" id: description: The id field. - readOnly: false type: string label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" section: description: The section field. - readOnly: false type: string status: description: The status field. - readOnly: false type: string trailingAction: - $ref: '#/components/schemas/c1.api.a2ui.v1.ServerEvent' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ServerEvent' + - type: "null" trailingActionLabel: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: C 1 Todo Item type: object x-speakeasy-name-override: C1TodoItem c1.api.a2ui.v1.C1TodoListComponent: description: C1TodoListComponent renders a phase/step checklist with progress tracking. - nullable: true properties: items: description: The items field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.C1TodoItem' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: C 1 Todo List Component type: object x-speakeasy-name-override: C1TodoListComponent c1.api.a2ui.v1.CardComponent: description: CardComponent is a container with styling. - nullable: true properties: children: - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + - type: "null" title: Card Component type: object x-speakeasy-name-override: CardComponent c1.api.a2ui.v1.CheckBoxComponent: description: CheckBoxComponent is a boolean checkbox. - nullable: true properties: label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicBool' + - type: "null" title: Check Box Component type: object x-speakeasy-name-override: CheckBoxComponent @@ -670,9 +900,9 @@ components: description: The ids field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Child List type: object x-speakeasy-name-override: ChildList @@ -680,64 +910,75 @@ components: description: Choice represents a single option in a choice picker. properties: description: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" id: description: The id field. - readOnly: false type: string label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: Choice type: object x-speakeasy-name-override: Choice c1.api.a2ui.v1.ChoicePickerComponent: description: ChoicePickerComponent allows selection from predefined choices. - nullable: true properties: choices: description: The choices field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.Choice' - nullable: true - readOnly: false - type: array + type: + - array + - "null" + hideLabel: + description: |- + When true, the label slot is omitted entirely (no label text, no + "(optional)" suffix, no reserved space). Use when the picker sits under + or beside another control that already names the field — e.g. stacked + under a check_box in a per-attribute mapping row. + type: boolean label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" multiSelect: description: The multiSelect field. - readOnly: false type: boolean required: description: The required field. - readOnly: false type: boolean value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: Choice Picker Component type: object x-speakeasy-name-override: ChoicePickerComponent c1.api.a2ui.v1.ColumnComponent: description: ColumnComponent arranges children vertically. - nullable: true properties: alignment: description: The alignment field. - readOnly: false type: string children: - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + - type: "null" distribution: description: The distribution field. - readOnly: false type: string gap: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" title: Column Component type: object x-speakeasy-name-override: ColumnComponent c1.api.a2ui.v1.DateTimeInputComponent: description: DateTimeInputComponent for date/time selection. - nullable: true properties: inputType: description: The inputType field. @@ -746,27 +987,32 @@ components: - DATE_TIME_INPUT_TYPE_DATE - DATE_TIME_INPUT_TYPE_TIME - DATE_TIME_INPUT_TYPE_DATE_TIME - readOnly: false type: string x-speakeasy-unknown-values: allow label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" max: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" min: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: Date Time Input Component type: object x-speakeasy-name-override: DateTimeInputComponent c1.api.a2ui.v1.DividerComponent: description: DividerComponent is a visual separator. - nullable: true properties: orientation: description: The orientation field. - readOnly: false type: string title: Divider Component type: object @@ -781,23 +1027,25 @@ components: - call properties: call: - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + - type: "null" literal: description: |- The literal field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicBool` for more details. - nullable: true - readOnly: false - type: boolean + type: + - boolean + - "null" path: description: |- The path field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicBool` for more details. - nullable: true - readOnly: false - type: string + type: + - string + - "null" title: Dynamic Bool type: object x-speakeasy-name-override: DynamicBool @@ -811,23 +1059,25 @@ components: - call properties: call: - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + - type: "null" literal: description: |- The literal field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicNumber` for more details. - nullable: true - readOnly: false - type: number + type: + - number + - "null" path: description: |- The path field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicNumber` for more details. - nullable: true - readOnly: false - type: string + type: + - string + - "null" title: Dynamic Number type: object x-speakeasy-name-override: DynamicNumber @@ -841,161 +1091,179 @@ components: - call properties: call: - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + - type: "null" literal: description: |- The literal field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicString` for more details. - nullable: true - readOnly: false - type: string + type: + - string + - "null" path: description: |- The path field. This field is part of the `value` oneof. See the documentation for `c1.api.a2ui.v1.DynamicString` for more details. - nullable: true - readOnly: false - type: string + type: + - string + - "null" title: Dynamic String type: object x-speakeasy-name-override: DynamicString c1.api.a2ui.v1.FunctionCall: description: FunctionCall represents a client-side function invocation. - nullable: true properties: args: additionalProperties: type: string description: The args field. - readOnly: false type: object call: description: The call field. - readOnly: false type: string message: description: The message field. - readOnly: false type: string title: Function Call type: object x-speakeasy-name-override: FunctionCall c1.api.a2ui.v1.OrCheck: description: OrCheck requires at least one check to pass. - nullable: true properties: checks: description: The checks field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.ValidationCheck' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Or Check type: object x-speakeasy-name-override: OrCheck c1.api.a2ui.v1.ProgressBarComponent: description: ProgressBarComponent shows a read-only progress bar (label, value %, min/max). - nullable: true properties: label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" max: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" min: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" step: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" title: Progress Bar Component type: object x-speakeasy-name-override: ProgressBarComponent c1.api.a2ui.v1.RowComponent: description: RowComponent arranges children horizontally. - nullable: true properties: alignment: description: The alignment field. - readOnly: false type: string children: - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.ChildList' + - type: "null" distribution: description: The distribution field. - readOnly: false type: string gap: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" title: Row Component type: object x-speakeasy-name-override: RowComponent c1.api.a2ui.v1.ServerEvent: description: ServerEvent triggers a server-side action. - nullable: true properties: context: additionalProperties: type: string description: The context field. - readOnly: false type: object name: description: The name field. - readOnly: false type: string title: Server Event type: object x-speakeasy-name-override: ServerEvent c1.api.a2ui.v1.SliderComponent: description: SliderComponent is an interactive numeric range input (e.g. for forms). - nullable: true properties: label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" max: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" min: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" step: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicNumber' + - type: "null" title: Slider Component type: object x-speakeasy-name-override: SliderComponent c1.api.a2ui.v1.TextComponent: description: TextComponent displays text content. - nullable: true properties: markdown: description: The markdown field. - readOnly: false type: boolean text: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" title: Text Component type: object x-speakeasy-name-override: TextComponent c1.api.a2ui.v1.TextFieldComponent: description: TextFieldComponent is a text input field. - nullable: true properties: checks: description: The checks field. items: $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' - nullable: true - readOnly: false - type: array + type: + - array + - "null" label: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" placeholder: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" value: - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.DynamicString' + - type: "null" variant: description: The variant field. enum: @@ -1004,7 +1272,6 @@ components: - TEXT_FIELD_VARIANT_LONG_TEXT - TEXT_FIELD_VARIANT_NUMBER - TEXT_FIELD_VARIANT_OBSCURED - readOnly: false type: string x-speakeasy-unknown-values: allow title: Text Field Component @@ -1020,11 +1287,17 @@ components: - or properties: and: - $ref: '#/components/schemas/c1.api.a2ui.v1.AndCheck' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.AndCheck' + - type: "null" call: - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.FunctionCall' + - type: "null" or: - $ref: '#/components/schemas/c1.api.a2ui.v1.OrCheck' + oneOf: + - $ref: '#/components/schemas/c1.api.a2ui.v1.OrCheck' + - type: "null" title: Validation Check type: object x-speakeasy-name-override: ValidationCheck @@ -1033,37 +1306,36 @@ components: properties: appEntitlementId: description: The unique identifier of the bound app entitlement. - readOnly: false type: string appId: description: The unique identifier of the application containing the entitlement. - readOnly: false type: string createdAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" deletedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" entitlementGroup: description: Which side of the conflict monitor (A or B) this entitlement is assigned to. enum: - ENTITLEMENT_GROUP_UNSPECIFIED - ENTITLEMENT_GROUP_A - ENTITLEMENT_GROUP_B - readOnly: false type: string x-speakeasy-unknown-values: allow monitorId: description: The unique identifier of the conflict monitor this binding belongs to. - readOnly: false type: string updatedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" title: App Entitlement Monitor Binding type: object x-speakeasy-name-override: AppEntitlementMonitorBinding @@ -1074,42 +1346,46 @@ components: properties: createdAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" deletedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" description: description: A description explaining the purpose of this Separation of Duty rule. - readOnly: false type: string displayName: description: The human-readable name of the conflict monitor. - readOnly: false type: string enabled: description: Whether the conflict monitor is actively scanning for violations. - readOnly: false type: boolean entitlementSetAId: description: The identifier of entitlement set A in the conflict rule. - readOnly: false type: string entitlementSetBId: description: The identifier of entitlement set B in the conflict rule. - readOnly: false type: string id: description: The unique identifier of this conflict monitor. - readOnly: false type: string + negateGroupB: + description: |- + When true, the rule flags users who are in set A but NOT in set B ("is not + in"), instead of the default A-and-B intersection. + type: boolean notificationConfig: - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + - type: "null" updatedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" title: Conflict Monitor type: object x-speakeasy-name-override: ConflictMonitor @@ -1118,14 +1394,14 @@ components: properties: description: description: An optional description explaining the purpose of this Separation of Duty rule. - readOnly: false type: string displayName: description: The human-readable name for the conflict monitor. - readOnly: false type: string notificationConfig: - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + - type: "null" required: - displayName title: Conflict Monitor Create Request @@ -1146,7 +1422,6 @@ components: properties: id: description: The id field. - readOnly: false type: string title: Conflict Monitor Ref type: object @@ -1156,14 +1431,19 @@ components: properties: description: description: The updated description for the conflict monitor. - readOnly: false type: string displayName: description: The updated human-readable name for the conflict monitor. - readOnly: false type: string + negateGroupB: + description: |- + When true, the rule flags users who are in set A but NOT in set B ("is not + in"), instead of the default A-and-B intersection. + type: boolean notificationConfig: - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessconflict.v1.NotificationConfig' + - type: "null" title: Conflict Monitor Update Request type: object x-speakeasy-name-override: ConflictMonitorUpdateRequest @@ -1172,11 +1452,9 @@ components: properties: appEntitlementId: description: The unique identifier of the app entitlement to bind. - readOnly: false type: string appId: description: The unique identifier of the application containing the entitlement. - readOnly: false type: string entitlementGroup: description: Which side of the conflict monitor (A or B) to place this entitlement in. @@ -1184,12 +1462,10 @@ components: - ENTITLEMENT_GROUP_UNSPECIFIED - ENTITLEMENT_GROUP_A - ENTITLEMENT_GROUP_B - readOnly: false type: string x-speakeasy-unknown-values: allow monitorId: description: The unique identifier of the conflict monitor to bind the entitlement to. - readOnly: false type: string title: Create App Entitlement Monitor Binding Request type: object @@ -1199,11 +1475,9 @@ components: properties: appEntitlementId: description: The unique identifier of the app entitlement to unbind. - readOnly: false type: string appId: description: The unique identifier of the application containing the entitlement. - readOnly: false type: string entitlementGroup: description: Which side of the conflict monitor (A or B) the binding belongs to. @@ -1211,12 +1485,10 @@ components: - ENTITLEMENT_GROUP_UNSPECIFIED - ENTITLEMENT_GROUP_A - ENTITLEMENT_GROUP_B - readOnly: false type: string x-speakeasy-unknown-values: allow monitorId: description: The unique identifier of the conflict monitor. - readOnly: false type: string title: Delete App Entitlement Monitor Binding Request type: object @@ -1231,15 +1503,14 @@ components: properties: enabled: description: The enabled field. - readOnly: false type: boolean identityUserIds: description: The identityUserIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Email Notifications type: object x-speakeasy-name-override: EmailNotifications @@ -1248,11 +1519,9 @@ components: properties: appEntitlementId: description: The unique identifier of the app entitlement bound to the monitor. - readOnly: false type: string appId: description: The unique identifier of the application containing the entitlement. - readOnly: false type: string entitlementGroup: description: Which side of the conflict monitor (A or B) this binding belongs to. @@ -1260,12 +1529,10 @@ components: - ENTITLEMENT_GROUP_UNSPECIFIED - ENTITLEMENT_GROUP_A - ENTITLEMENT_GROUP_B - readOnly: false type: string x-speakeasy-unknown-values: allow monitorId: description: The unique identifier of the conflict monitor. - readOnly: false type: string title: Get App Entitlement Monitor Binding Request type: object @@ -1274,9 +1541,13 @@ components: description: The NotificationConfig message. properties: emailNotifications: - $ref: '#/components/schemas/c1.api.accessconflict.v1.EmailNotifications' + oneOf: + - $ref: '#/components/schemas/c1.api.accessconflict.v1.EmailNotifications' + - type: "null" slackNotifications: - $ref: '#/components/schemas/c1.api.accessconflict.v1.SlackNotifications' + oneOf: + - $ref: '#/components/schemas/c1.api.accessconflict.v1.SlackNotifications' + - type: "null" title: Notification Config type: object x-speakeasy-name-override: AccessConflictNotificationConfig @@ -1285,15 +1556,12 @@ components: properties: channelId: description: The channelId field. - readOnly: false type: string channelName: description: The channelName field. - readOnly: false type: string enabled: description: The enabled field. - readOnly: false type: boolean title: Slack Notifications type: object @@ -1309,7 +1577,6 @@ components: properties: accessReviewTemplateId: description: The ID of the template if the campaign was created from one - readOnly: false type: string accuracyIssueAction: description: The accuracyIssueAction field. @@ -1317,14 +1584,12 @@ components: - ACCURACY_ISSUE_ACTION_UNSPECIFIED - ACCURACY_ISSUE_ACTION_CONTINUE - ACCURACY_ISSUE_ACTION_WAIT - readOnly: false type: string x-speakeasy-unknown-values: allow autoCloseCampaign: description: |- Auto-close configuration completion_date is used as the scheduled close date - readOnly: false type: boolean autoCloseDecision: description: The autoCloseDecision field. @@ -1333,48 +1598,56 @@ components: - CLOSE_DECISION_REVOKED - CLOSE_DECISION_SKIP - CLOSE_DECISION_NO_ACTION - readOnly: false type: string x-speakeasy-unknown-values: allow autoGenerateReport: description: The autoGenerateReport field. - readOnly: false type: boolean autoResolve: description: When true, selections are automatically resolved if the entitlement grant no longer exists. - readOnly: false type: boolean autoStartCampaign: description: Auto-start configuration - readOnly: false type: boolean bindings: - $ref: '#/components/schemas/c1.api.accessreview.v1.BindingObjectSetup' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.BindingObjectSetup' + - type: "null" campaignHealth: - $ref: '#/components/schemas/c1.api.accessreview.v1.CampaignHealthSnapshot' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.CampaignHealthSnapshot' + - type: "null" campaignInsights: - $ref: '#/components/schemas/c1.api.accessreview.v1.CampaignInsights' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.CampaignInsights' + - type: "null" closedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" columnConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + - type: "null" completionDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" connectorSourcesFrozenAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" createdById: description: The ID of the user who created this campaign. - readOnly: false type: string defaultView: description: the default view that reviewers will see when they complete their access reviews @@ -1384,16 +1657,13 @@ components: - ACCESS_REVIEW_VIEW_TYPE_BY_USER - ACCESS_REVIEW_VIEW_TYPE_UNSTRUCTURED - ACCESS_REVIEW_VIEW_TYPE_BY_RESOURCE - readOnly: false type: string x-speakeasy-unknown-values: allow description: description: An optional description providing context about this campaign. - readOnly: false type: string displayName: description: The human-readable name of this campaign. - readOnly: false type: string errorState: description: |- @@ -1406,44 +1676,53 @@ components: type: string x-speakeasy-unknown-values: allow exclusionScope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExclusionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExclusionScope' + - type: "null" exemptCertifiedAccessConflicts: description: this setting is used for access conflict type scope - readOnly: false type: boolean expectedTicketCount: description: The estimated number of review tasks that will be generated when the campaign starts. format: int32 - readOnly: false type: integer hasAccuracySupport: description: Whether the connectors in this campaign support accuracy checking. - readOnly: false type: boolean id: description: The unique identifier of this access review campaign. - readOnly: false type: string inclusionScope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewInclusionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewInclusionScope' + - type: "null" multiApp: - $ref: '#/components/schemas/c1.api.accessreview.v1.MultiAppSetup' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.MultiAppSetup' + - type: "null" notificationConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + - type: "null" policyId: description: The ID of the review policy that governs how review tasks are assigned and resolved. - readOnly: false type: string reviewInstructions: description: Optional instructions displayed to reviewers when completing their review tasks. - readOnly: false type: string + reviewerAttributeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewerAttributeConfig' + - type: "null" scheduledStartDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScope' + - type: "null" scopeType: description: this sets the scope type for the access review enum: @@ -1452,24 +1731,30 @@ components: - ACCESS_REVIEW_SCOPE_TYPE_BY_ACCESS_CONFLICTS - ACCESS_REVIEW_SCOPE_TYPE_BY_RESOURCE - ACCESS_REVIEW_SCOPE_TYPE_BY_INHERITANCE - readOnly: false + - ACCESS_REVIEW_SCOPE_TYPE_BY_USERS type: string x-speakeasy-unknown-values: allow scopeV2: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" scopingVersion: description: Internal version counter incremented when the campaign scope changes. format: int64 - readOnly: false type: string signatureConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + - type: "null" singleApp: - $ref: '#/components/schemas/c1.api.accessreview.v1.SingleAppSetup' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SingleAppSetup' + - type: "null" startedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" state: description: The current lifecycle state of the campaign (e.g., draft, open, closed). enum: @@ -1486,18 +1771,18 @@ components: - ACCESS_REVIEW_STATE_RESETTING_POLICIES - ACCESS_REVIEW_STATE_COPYING_SETUP_ENTITLEMENTS - ACCESS_REVIEW_STATE_COPYING_RESOURCE_TYPE_SELECTIONS - readOnly: false type: string x-speakeasy-unknown-values: allow updatedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" usePolicyOverride: description: |- Determines the policy applied to the campaign. Default is false, using the campaign policy. If true, the order of precedence is entitlement → app → campaign policy. - readOnly: false type: boolean title: Access Review type: object @@ -1539,11 +1824,15 @@ components: - ACCESS_REVIEW_TASK_COLUMN_LAST_LOGIN - ACCESS_REVIEW_TASK_COLUMN_RESOURCE_PARENT - ACCESS_REVIEW_TASK_COLUMN_RESOURCE_CHILDREN + - ACCESS_REVIEW_TASK_COLUMN_APP_USER_USERNAME + - ACCESS_REVIEW_TASK_COLUMN_ACCESS_HOLDER_TYPE + - ACCESS_REVIEW_TASK_COLUMN_RISK_LEVEL + - ACCESS_REVIEW_TASK_COLUMN_COMPLIANCE_FRAMEWORK type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Column Config type: object x-speakeasy-name-override: AccessReviewColumnConfig @@ -1560,9 +1849,9 @@ components: - APP_USER_STATUS_DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" appUserTypes: description: The appUserTypes field. items: @@ -1573,9 +1862,9 @@ components: - APP_USER_TYPE_SYSTEM_ACCOUNT type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Exclusion Scope type: object x-speakeasy-name-override: AccessReviewExclusionScope @@ -1586,9 +1875,9 @@ components: description: The paths field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Expand Mask type: object x-speakeasy-name-override: AccessReviewExpandMask @@ -1605,9 +1894,9 @@ components: - APP_USER_STATUS_DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" appUserTypes: description: The appUserTypes field. items: @@ -1618,33 +1907,31 @@ components: - APP_USER_TYPE_SYSTEM_ACCOUNT type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" managerIds: description: The managerIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" multiUserProfileAttributes: additionalProperties: $ref: '#/components/schemas/c1.api.accessreview.v1.IncludedUserAttributeValues' description: The multiUserProfileAttributes field. - readOnly: false type: object noAccountOwners: description: The noAccountOwners field. - readOnly: false type: boolean userIds: description: The userIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" userStatuses: description: The userStatuses field. items: @@ -1655,9 +1942,9 @@ components: - USER_DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Inclusion Scope type: object x-speakeasy-name-override: AccessReviewInclusionScope @@ -1674,9 +1961,9 @@ components: - APP_USER_STATUS_DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" appUserTypes: description: The appUserTypes field. items: @@ -1687,9 +1974,9 @@ components: - APP_USER_TYPE_SYSTEM_ACCOUNT type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Scope type: object x-speakeasy-name-override: AccessReviewScope @@ -1729,39 +2016,97 @@ components: This message contains a oneof named resource_scope. Only a single field of the following list may be set at a time: - resourceSelection + + + This message contains a oneof named excluded_apps_and_resources_scope. Only a single field of the following list may be set at a time: + - excludedSpecificResources + - excludedResourceTypeSelections properties: accountCelExpression: - $ref: '#/components/schemas/c1.api.accessreview.v1.CelExpressionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.CelExpressionScope' + - type: "null" accountCriteria: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccountCriteriaScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccountCriteriaScope' + - type: "null" allAccessConflicts: - $ref: '#/components/schemas/c1.api.accessreview.v1.AllAccessConflictsScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AllAccessConflictsScope' + - type: "null" allAccounts: - $ref: '#/components/schemas/c1.api.accessreview.v1.AllAccountsScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AllAccountsScope' + - type: "null" allGrants: - $ref: '#/components/schemas/c1.api.accessreview.v1.AllGrantsScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AllGrantsScope' + - type: "null" allUsers: - $ref: '#/components/schemas/c1.api.accessreview.v1.AllUsersScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AllUsersScope' + - type: "null" appAccess: - $ref: '#/components/schemas/c1.api.accessreview.v1.ApplicationAccessScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ApplicationAccessScope' + - type: "null" appSelectionCriteria: - $ref: '#/components/schemas/c1.api.accessreview.v1.AppSelectionCriteriaScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AppSelectionCriteriaScope' + - type: "null" celExpression: - $ref: '#/components/schemas/c1.api.accessreview.v1.CelExpressionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.CelExpressionScope' + - type: "null" + excludedResourceTypeSelections: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceTypeSelectionScope' + - type: "null" + excludedSpecificResources: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SpecificResourcesScope' + - type: "null" grantsByCriteria: - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantsByCriteriaScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantsByCriteriaScope' + - type: "null" + principalTypeFilter: + description: Filters principals included in the scope. Unspecified is treated as users. + enum: + - PRINCIPAL_TYPE_FILTER_UNSPECIFIED + - PRINCIPAL_TYPE_FILTER_USERS + - PRINCIPAL_TYPE_FILTER_RESOURCES + - PRINCIPAL_TYPE_FILTER_USERS_AND_RESOURCES + type: string + x-speakeasy-unknown-values: allow resourceSelection: - $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceSelectionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceSelectionScope' + - type: "null" resourceTypeSelections: - $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceTypeSelectionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceTypeSelectionScope' + - type: "null" + scopeRoleSelection: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ScopeRoleSelectionScope' + - type: "null" selectedUsers: - $ref: '#/components/schemas/c1.api.accessreview.v1.SelectedUsersScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SelectedUsersScope' + - type: "null" specificAccessConflicts: - $ref: '#/components/schemas/c1.api.accessreview.v1.SpecificAccessConflictsScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SpecificAccessConflictsScope' + - type: "null" specificResources: - $ref: '#/components/schemas/c1.api.accessreview.v1.SpecificResourcesScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SpecificResourcesScope' + - type: "null" userCriteria: - $ref: '#/components/schemas/c1.api.accessreview.v1.UserCriteriaScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.UserCriteriaScope' + - type: "null" title: Access Review Scope V 2 type: object x-speakeasy-name-override: AccessReviewScopeV2 @@ -1770,34 +2115,35 @@ components: properties: completionDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" description: description: An optional description providing context about the campaign. - readOnly: false type: string displayName: description: The display name for the new campaign. - readOnly: false type: string duplicateFrom: description: The ID of an existing campaign to copy scope and entitlement configuration from. Optional. - readOnly: false type: string expandMask: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExpandMask' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExpandMask' + - type: "null" notificationConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + - type: "null" ownerIds: description: The IDs of the users who own and manage this campaign. At least one owner is required. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" policyId: description: The ID of the review policy that governs task assignment and resolution. - readOnly: false type: string scopeType: description: The type of scoping method for the campaign (e.g., by entitlements, by access conflicts, or by resource). @@ -1807,11 +2153,13 @@ components: - ACCESS_REVIEW_SCOPE_TYPE_BY_ACCESS_CONFLICTS - ACCESS_REVIEW_SCOPE_TYPE_BY_RESOURCE - ACCESS_REVIEW_SCOPE_TYPE_BY_INHERITANCE - readOnly: false + - ACCESS_REVIEW_SCOPE_TYPE_BY_USERS type: string x-speakeasy-unknown-values: allow scopeV2: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Service Create Request type: object x-speakeasy-name-override: AccessReviewServiceCreateRequest @@ -1819,7 +2167,9 @@ components: description: The AccessReviewServiceCreateResponse message. properties: accessReview: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + - type: "null" expanded: description: Related objects requested via the expand mask. items: @@ -1829,11 +2179,10 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Service Create Response type: object x-speakeasy-name-override: AccessReviewServiceCreateResponse @@ -1851,7 +2200,9 @@ components: description: The AccessReviewServiceGetResponse message. properties: accessReview: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + - type: "null" expanded: description: Related objects requested via the expand mask. items: @@ -1861,11 +2212,10 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Service Get Response type: object x-speakeasy-name-override: AccessReviewServiceGetResponse @@ -1881,21 +2231,19 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" list: description: The list of access review campaigns for the current page. items: $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' - nullable: true - readOnly: false - type: array + type: + - array + - "null" nextPageToken: description: Token to retrieve the next page, or empty if there are no more results. - readOnly: false type: string title: Access Review Service List Response type: object @@ -1904,13 +2252,17 @@ components: description: The AccessReviewServiceUpdateRequest message. properties: accessReview: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReview' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReview' + - type: "null" expandMask: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExpandMask' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewExpandMask' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string + type: + - string + - "null" title: Access Review Service Update Request type: object x-speakeasy-name-override: AccessReviewServiceUpdateRequest @@ -1918,7 +2270,9 @@ components: description: The AccessReviewServiceUpdateResponse message. properties: accessReview: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewView' + - type: "null" expanded: description: Related objects requested via the expand mask. items: @@ -1928,11 +2282,10 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Service Update Response type: object x-speakeasy-name-override: AccessReviewServiceUpdateResponse @@ -1943,11 +2296,13 @@ components: description: The resource types to include in the campaign scope. Replaces all previously selected resource types. items: $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceTypeIdRef' - nullable: true - readOnly: false - type: array + type: + - array + - "null" scopeV2: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Set Scope By Resource Type Request type: object x-speakeasy-name-override: AccessReviewSetScopeByResourceTypeRequest @@ -1961,48 +2316,46 @@ components: properties: accessReviewId: description: The ID of the access review campaign this entitlement belongs to. - readOnly: false type: string appEntitlementId: description: The ID of the entitlement being reviewed. - readOnly: false type: string appId: description: The ID of the application that owns the entitlement. - readOnly: false type: string appResourceId: description: The ID of the specific resource associated with this entitlement, if applicable. - readOnly: false type: string appResourceTypeId: description: The ID of the resource type associated with this entitlement, if applicable. - readOnly: false type: string createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" customPolicyId: description: An override policy ID for this specific entitlement. Populated when use_policy_override is enabled on the campaign. - readOnly: false type: string deletedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" policyId: description: The ID of the review policy applied to this entitlement. Defaults to the campaign policy. - readOnly: false type: string tenantId: description: The tenant that owns this setup entitlement. - readOnly: false type: string updatedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" title: Access Review Setup Entitlement type: object x-speakeasy-name-override: AccessReviewSetupEntitlement @@ -2013,13 +2366,17 @@ components: description: The entitlements to include in the campaign. Replaces all previously selected entitlements. items: $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementInput' - nullable: true - readOnly: false - type: array + type: + - array + - "null" expandMask: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementExpandMask' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementExpandMask' + - type: "null" scopeV2: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Setup Entitlement And Scope Service Set Request type: object x-speakeasy-name-override: AccessReviewSetupEntitlementAndScopeServiceSetRequest @@ -2035,20 +2392,21 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" list: description: The current list of setup entitlements for the campaign. items: $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementView' - nullable: true - readOnly: false - type: array + type: + - array + - "null" scopeV2: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Setup Entitlement And Scope Service Set Response type: object x-speakeasy-name-override: AccessReviewSetupEntitlementAndScopeServiceSetResponse @@ -2059,9 +2417,9 @@ components: description: The paths field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Setup Entitlement Expand Mask type: object x-speakeasy-name-override: AccessReviewSetupEntitlementExpandMask @@ -2070,11 +2428,9 @@ components: properties: appEntitlementId: description: The ID of the entitlement. - readOnly: false type: string appId: description: The ID of the application that owns the entitlement. - readOnly: false type: string title: Access Review Setup Entitlement Input type: object @@ -2083,18 +2439,17 @@ components: description: The AccessReviewSetupEntitlementView message. properties: accessReviewEntitlement: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlement' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlement' + - type: "null" appPath: description: The appPath field. - readOnly: false type: string entitlementPath: description: The entitlementPath field. - readOnly: false type: string policyPath: description: The policyPath field. - readOnly: false type: string title: Access Review Setup Entitlement View type: object @@ -2109,22 +2464,38 @@ components: properties: accessReviewDuration: format: duration - readOnly: false - type: string + type: + - string + - "null" accuracyIssueAction: description: The accuracyIssueAction field. enum: - ACCURACY_ISSUE_ACTION_UNSPECIFIED - ACCURACY_ISSUE_ACTION_CONTINUE - ACCURACY_ISSUE_ACTION_WAIT - readOnly: false type: string x-speakeasy-unknown-values: allow + annotations: + additionalProperties: + type: string + description: |- + Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256 + chars; URL-safe ASCII. Keys starting with `c1/` are reserved. + + Updates have PATCH semantics: keys absent from the request are + preserved; an empty value deletes the key. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() autoCloseCampaign: description: |- Auto-close configuration start date and access_review_duration will be used to calculate the scheduled close date - readOnly: false type: boolean autoCloseDecision: description: The autoCloseDecision field. @@ -2133,25 +2504,26 @@ components: - CLOSE_DECISION_REVOKED - CLOSE_DECISION_SKIP - CLOSE_DECISION_NO_ACTION - readOnly: false type: string x-speakeasy-unknown-values: allow autoGenerateReport: description: auto generate report when campaign is closed - readOnly: false type: boolean autoStartCampaign: description: |- Auto-start configuration next_scheduled_campaign_at will be used as the scheduled start date - readOnly: false type: boolean columnConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + - type: "null" createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" defaultView: description: The defaultView field. enum: @@ -2160,58 +2532,64 @@ components: - ACCESS_REVIEW_VIEW_TYPE_BY_USER - ACCESS_REVIEW_VIEW_TYPE_UNSTRUCTURED - ACCESS_REVIEW_VIEW_TYPE_BY_RESOURCE - readOnly: false type: string x-speakeasy-unknown-values: allow deletedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" description: description: An optional description providing context about this template. - readOnly: false type: string displayName: description: The human-readable name of this template. - readOnly: false type: string exemptCertifiedAccessConflicts: description: The exemptCertifiedAccessConflicts field. - readOnly: false type: boolean id: description: The unique identifier of this template. - readOnly: false type: string inclusionScope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewInclusionScope' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewInclusionScope' + - type: "null" isCampaignScheduleEnabled: description: Whether automatic campaign creation on the recurrence schedule is enabled. - readOnly: false type: boolean nextScheduledCampaignAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" notificationConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + - type: "null" occurrences: description: The number of campaigns that have been created from this template. format: int32 - readOnly: false type: integer policyId: description: The ID of the default review policy applied to campaigns created from this template. - readOnly: false type: string recurrenceRule: - $ref: '#/components/schemas/c1.api.accessreview.v1.RecurrenceRule' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.RecurrenceRule' + - type: "null" reviewInstructions: description: The reviewInstructions field. - readOnly: false type: string + reviewerAttributeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewerAttributeConfig' + - type: "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" scopeType: description: The scopeType field. enum: @@ -2220,20 +2598,25 @@ components: - ACCESS_REVIEW_SCOPE_TYPE_BY_ACCESS_CONFLICTS - ACCESS_REVIEW_SCOPE_TYPE_BY_RESOURCE - ACCESS_REVIEW_SCOPE_TYPE_BY_INHERITANCE - readOnly: false + - ACCESS_REVIEW_SCOPE_TYPE_BY_USERS type: string x-speakeasy-unknown-values: allow signatureConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + - type: "null" slackChannel: - $ref: '#/components/schemas/c1.api.accessreview.v1.SlackChannel' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.SlackChannel' + - type: "null" updatedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" usePolicyOverride: description: The usePolicyOverride field. - readOnly: false type: boolean title: Access Review Template type: object @@ -2244,20 +2627,36 @@ components: properties: accessReviewDuration: format: duration - readOnly: false - type: string + type: + - string + - "null" accuracyIssueAction: description: The accuracyIssueAction field. enum: - ACCURACY_ISSUE_ACTION_UNSPECIFIED - ACCURACY_ISSUE_ACTION_CONTINUE - ACCURACY_ISSUE_ACTION_WAIT - readOnly: false type: string x-speakeasy-unknown-values: allow + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() autoCloseCampaign: description: The autoCloseCampaign field. - readOnly: false type: boolean autoCloseDecision: description: The autoCloseDecision field. @@ -2266,19 +2665,18 @@ components: - CLOSE_DECISION_REVOKED - CLOSE_DECISION_SKIP - CLOSE_DECISION_NO_ACTION - readOnly: false type: string x-speakeasy-unknown-values: allow autoGenerateReport: description: auto generate report when campaign is closed - readOnly: false type: boolean autoStartCampaign: description: The autoStartCampaign field. - readOnly: false type: boolean columnConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewColumnConfig' + - type: "null" defaultView: description: The defaultView field. enum: @@ -2287,46 +2685,49 @@ components: - ACCESS_REVIEW_VIEW_TYPE_BY_USER - ACCESS_REVIEW_VIEW_TYPE_UNSTRUCTURED - ACCESS_REVIEW_VIEW_TYPE_BY_RESOURCE - readOnly: false type: string x-speakeasy-unknown-values: allow description: description: An optional description providing context about the template. - readOnly: false type: string displayName: description: The display name for the new template. - readOnly: false type: string exemptCertifiedAccessConflicts: description: The exemptCertifiedAccessConflicts field. - readOnly: false type: boolean isCampaignScheduleEnabled: description: The isCampaignScheduleEnabled field. - readOnly: false type: boolean notificationConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.NotificationConfig' + - type: "null" ownerIds: description: The IDs of the users who own this template. At least one owner is required. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" policyId: description: The ID of the default review policy for campaigns created from this template. - readOnly: false type: string recurrenceRule: - $ref: '#/components/schemas/c1.api.accessreview.v1.RecurrenceRule' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.RecurrenceRule' + - type: "null" reviewInstructions: description: The reviewInstructions field. - readOnly: false type: string + reviewerAttributeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewerAttributeConfig' + - type: "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" scopeType: description: The scopeType field. enum: @@ -2335,14 +2736,15 @@ components: - ACCESS_REVIEW_SCOPE_TYPE_BY_ACCESS_CONFLICTS - ACCESS_REVIEW_SCOPE_TYPE_BY_RESOURCE - ACCESS_REVIEW_SCOPE_TYPE_BY_INHERITANCE - readOnly: false + - ACCESS_REVIEW_SCOPE_TYPE_BY_USERS type: string x-speakeasy-unknown-values: allow signatureConfig: - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewSignatureConfig' + - type: "null" usePolicyOverride: description: The usePolicyOverride field. - readOnly: false type: boolean title: Access Review Template Service Create Request type: object @@ -2351,7 +2753,9 @@ components: description: The AccessReviewTemplateServiceCreateResponse message. properties: accessReviewTemplate: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + - type: "null" title: Access Review Template Service Create Response type: object x-speakeasy-name-override: AccessReviewTemplateServiceCreateResponse @@ -2369,7 +2773,9 @@ components: description: The AccessReviewTemplateServiceGetResponse message. properties: accessReviewTemplate: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + - type: "null" title: Access Review Template Service Get Response type: object x-speakeasy-name-override: AccessReviewTemplateServiceGetResponse @@ -2377,11 +2783,13 @@ components: description: The AccessReviewTemplateServiceUpdateRequest message. properties: accessReviewTemplate: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string + type: + - string + - "null" title: Access Review Template Service Update Request type: object x-speakeasy-name-override: AccessReviewTemplateServiceUpdateRequest @@ -2389,7 +2797,9 @@ components: description: The AccessReviewTemplateServiceUpdateResponse message. properties: accessReviewTemplate: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplate' + - type: "null" title: Access Review Template Service Update Response type: object x-speakeasy-name-override: AccessReviewTemplateServiceUpdateResponse @@ -2400,11 +2810,13 @@ components: description: The resource types to include in the template scope. Replaces all previously selected resource types. items: $ref: '#/components/schemas/c1.api.accessreview.v1.ResourceTypeIdRef' - nullable: true - readOnly: false - type: array + type: + - array + - "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Template Set Scope By Resource Type Request type: object x-speakeasy-name-override: AccessReviewTemplateSetScopeByResourceTypeRequest @@ -2418,48 +2830,46 @@ components: properties: accessReviewTemplateId: description: The ID of the access review template this entitlement belongs to. - readOnly: false type: string appEntitlementId: description: The ID of the entitlement to be reviewed. - readOnly: false type: string appId: description: The ID of the application that owns the entitlement. - readOnly: false type: string appResourceId: description: The ID of the specific resource associated with this entitlement, if applicable. - readOnly: false type: string appResourceTypeId: description: The ID of the resource type associated with this entitlement, if applicable. - readOnly: false type: string createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" customPolicyId: description: An override policy ID for this specific entitlement. Populated when use_policy_override is enabled on the template. - readOnly: false type: string deletedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" policyId: description: The ID of the review policy applied to this entitlement. Defaults to the template policy. - readOnly: false type: string tenantId: description: The tenant that owns this setup entitlement. - readOnly: false type: string updatedAt: format: date-time readOnly: true - type: string + type: + - string + - "null" title: Access Review Template Setup Entitlement type: object x-speakeasy-name-override: AccessReviewTemplateSetupEntitlement @@ -2470,9 +2880,9 @@ components: description: The paths field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Access Review Template Setup Entitlement Expand Mask type: object x-speakeasy-name-override: AccessReviewTemplateSetupEntitlementExpandMask @@ -2481,11 +2891,9 @@ components: properties: appEntitlementId: description: The ID of the entitlement. - readOnly: false type: string appId: description: The ID of the application that owns the entitlement. - readOnly: false type: string title: Access Review Template Setup Entitlement Input type: object @@ -2497,13 +2905,17 @@ components: description: The entitlements to include in the template. Replaces all previously selected entitlements. items: $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementInput' - nullable: true - readOnly: false - type: array + type: + - array + - "null" expandMask: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementExpandMask' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementExpandMask' + - type: "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Template Setup Entitlement Service Set Request type: object x-speakeasy-name-override: AccessReviewTemplateSetupEntitlementServiceSetRequest @@ -2519,20 +2931,21 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" list: description: The current list of setup entitlements for the template. items: $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementView' - nullable: true - readOnly: false - type: array + type: + - array + - "null" scope: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewScopeV2' + - type: "null" title: Access Review Template Setup Entitlement Service Set Response type: object x-speakeasy-name-override: AccessReviewTemplateSetupEntitlementServiceSetResponse @@ -2540,18 +2953,17 @@ components: description: The AccessReviewTemplateSetupEntitlementView message. properties: accessReviewTemplateEntitlement: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlement' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlement' + - type: "null" appPath: description: The appPath field. - readOnly: false type: string entitlementPath: description: The entitlementPath field. - readOnly: false type: string policyPath: description: The policyPath field. - readOnly: false type: string title: Access Review Template Setup Entitlement View type: object @@ -2560,23 +2972,24 @@ components: description: The AccessReviewView message. properties: accessReview: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReview' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReview' + - type: "null" createdByUserPath: description: The createdByUserPath field. - readOnly: false type: string objectPermissions: - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' + - type: "null" policyPath: description: The policyPath field. - readOnly: false type: string title: Access Review View type: object x-speakeasy-name-override: AccessReviewView c1.api.accessreview.v1.AccountCriteriaScope: description: The AccountCriteriaScope message. - nullable: true properties: accountDomain: description: The accountDomain field. @@ -2584,7 +2997,6 @@ components: - APP_USER_DOMAIN_UNSPECIFIED - APP_USER_DOMAIN_EXTERNAL - APP_USER_DOMAIN_TRUSTED - readOnly: false type: string x-speakeasy-unknown-values: allow accountTypes: @@ -2597,9 +3009,9 @@ components: - APP_USER_TYPE_SYSTEM_ACCOUNT type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" appUserStatuses: description: The appUserStatuses field. items: @@ -2610,70 +3022,62 @@ components: - APP_USER_STATUS_DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" noAccountOwner: description: The noAccountOwner field. - readOnly: false type: boolean title: Account Criteria Scope type: object x-speakeasy-name-override: AccountCriteriaScope c1.api.accessreview.v1.AllAccessConflictsScope: description: The AllAccessConflictsScope message. - nullable: true title: All Access Conflicts Scope type: object x-speakeasy-name-override: AllAccessConflictsScope c1.api.accessreview.v1.AllAccountsScope: description: The AllAccountsScope message. - nullable: true title: All Accounts Scope type: object x-speakeasy-name-override: AllAccountsScope c1.api.accessreview.v1.AllGrantsScope: description: The AllGrantsScope message. - nullable: true title: All Grants Scope type: object x-speakeasy-name-override: AllGrantsScope c1.api.accessreview.v1.AllUsersScope: description: The AllUsersScope message. - nullable: true title: All Users Scope type: object x-speakeasy-name-override: AllUsersScope c1.api.accessreview.v1.AppSelectionCriteriaScope: description: The AppSelectionCriteriaScope message. - nullable: true properties: complianceFrameworkAttributeValueIds: description: The complianceFrameworkAttributeValueIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" riskLevelAttributeValueIds: description: The riskLevelAttributeValueIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: App Selection Criteria Scope type: object x-speakeasy-name-override: AppSelectionCriteriaScope c1.api.accessreview.v1.ApplicationAccessScope: description: The ApplicationAccessScope message. - nullable: true title: Application Access Scope type: object x-speakeasy-name-override: ApplicationAccessScope c1.api.accessreview.v1.BindingObjectSetup: description: The BindingObjectSetup message. - nullable: true title: Binding Object Setup type: object x-speakeasy-name-override: BindingObjectSetup @@ -2682,15 +3086,12 @@ components: properties: appId: description: The appId field. - readOnly: false type: string entitlementId: description: The entitlementId field. - readOnly: false type: string policyId: description: The policyId field. - readOnly: false type: string title: Campaign Entitlement Details type: object @@ -2700,12 +3101,12 @@ components: properties: checkedAt: format: date-time - readOnly: false - type: string + type: + - string + - "null" phantomLockedCount: description: Number of pending actions locked by terminal (dead) submissions. format: int32 - readOnly: false type: integer title: Campaign Health Snapshot type: object @@ -2715,18 +3116,15 @@ components: properties: markdown: description: The markdown field. - readOnly: false type: string title: Campaign Insights type: object x-speakeasy-name-override: CampaignInsights c1.api.accessreview.v1.CelExpressionScope: description: The CelExpressionScope message. - nullable: true properties: expression: description: The expression field. - readOnly: false type: string title: Cel Expression Scope type: object @@ -2738,7 +3136,6 @@ components: additionalProperties: $ref: '#/components/schemas/c1.api.accessreview.v1.CampaignEntitlementDetails' description: The entitlementDetails field. - readOnly: false type: object title: Entitlement To Details type: object @@ -2753,9 +3150,9 @@ components: Max 32 profile IDs items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" filterType: description: The filterType field. enum: @@ -2764,7 +3161,6 @@ components: - ACCESS_PROFILE_FILTER_TYPE_EXCLUDE_ALL - ACCESS_PROFILE_FILTER_TYPE_EXCLUDE_SPECIFIC - ACCESS_PROFILE_FILTER_TYPE_INCLUDE_SPECIFIC - readOnly: false type: string x-speakeasy-unknown-values: allow includedAccessProfileIds: @@ -2774,24 +3170,25 @@ components: Max 32 profile IDs items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Grant Access Profile Filter type: object x-speakeasy-name-override: GrantAccessProfileFilter c1.api.accessreview.v1.GrantsAddedBetween: description: The GrantsAddedBetween message. - nullable: true properties: endDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" startDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" title: Grants Added Between type: object x-speakeasy-name-override: GrantsAddedBetween @@ -2803,31 +3200,36 @@ components: - daysSinceAdded - daysSinceReviewed - grantsAddedBetween - nullable: true properties: accessProfileFilter: - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantAccessProfileFilter' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantAccessProfileFilter' + - type: "null" daysSinceAdded: format: duration - readOnly: false - type: string + type: + - string + - "null" daysSinceLastUsed: format: duration - readOnly: false - type: string + type: + - string + - "null" daysSinceReviewed: format: duration - readOnly: false - type: string + type: + - string + - "null" grantsAddedBetween: - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantsAddedBetween' + oneOf: + - $ref: '#/components/schemas/c1.api.accessreview.v1.GrantsAddedBetween' + - type: "null" sourceFilter: description: The sourceFilter field. enum: - GRANT_SOURCE_FILTER_UNSPECIFIED - GRANT_SOURCE_FILTER_DIRECT - GRANT_SOURCE_FILTER_INHERITED - readOnly: false type: string x-speakeasy-unknown-values: allow typeFilter: @@ -2836,7 +3238,6 @@ components: - GRANT_FILTER_TYPE_UNSPECIFIED - GRANT_FILTER_TYPE_PERMANENT - GRANT_FILTER_TYPE_TEMPORARY - readOnly: false type: string x-speakeasy-unknown-values: allow title: Grants By Criteria Scope @@ -2847,7 +3248,6 @@ components: properties: value: description: The value field. - readOnly: false type: string title: Included User Attribute Value type: object @@ -2859,9 +3259,9 @@ components: description: The values field. items: $ref: '#/components/schemas/c1.api.accessreview.v1.IncludedUserAttributeValue' - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Included User Attribute Values type: object x-speakeasy-name-override: IncludedUserAttributeValues @@ -2870,33 +3270,29 @@ components: properties: appId: description: The appId field. - readOnly: false type: string entitlementIds: description: The entitlementIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Multi App Entitlement type: object x-speakeasy-name-override: MultiAppEntitlement c1.api.accessreview.v1.MultiAppSetup: description: The MultiAppSetup message. - nullable: true properties: appEntitlementDetails: additionalProperties: $ref: '#/components/schemas/c1.api.accessreview.v1.EntitlementToDetails' description: The appEntitlementDetails field. - readOnly: false type: object appEntitlements: additionalProperties: $ref: '#/components/schemas/c1.api.accessreview.v1.MultiAppEntitlement' description: The appEntitlements field. - readOnly: false type: object title: Multi App Setup type: object @@ -2906,15 +3302,12 @@ components: properties: sendClose: description: Whether to send a notification when the campaign is closed. - readOnly: false type: boolean sendKickoff: description: Whether to send a notification when the campaign is started. - readOnly: false type: boolean sendReminders: description: Whether to send periodic reminder emails to reviewers with outstanding tasks. - readOnly: false type: boolean title: Notification Config type: object @@ -2929,8 +3322,9 @@ components: properties: endDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" frequency: description: The frequency field. enum: @@ -2940,13 +3334,11 @@ components: - FREQUENCY_WEEKLY - FREQUENCY_MONTHLY - FREQUENCY_YEARLY - readOnly: false type: string x-speakeasy-unknown-values: allow interval: description: The interval field. format: int32 - readOnly: false type: integer occurrences: description: |- @@ -2954,19 +3346,19 @@ components: This field is part of the `end_condition` oneof. See the documentation for `c1.api.accessreview.v1.RecurrenceRule` for more details. format: int32 - nullable: true - readOnly: false - type: integer + type: + - integer + - "null" startDate: format: date-time - readOnly: false - type: string + type: + - string + - "null" title: Recurrence Rule type: object x-speakeasy-name-override: RecurrenceRule c1.api.accessreview.v1.ResourceSelectionScope: description: The ResourceSelectionScope message. - nullable: true title: Resource Selection Scope type: object x-speakeasy-name-override: ResourceSelectionScope @@ -2975,18 +3367,15 @@ components: properties: appId: description: The ID of the application that owns the resource type. - readOnly: false type: string resourceTypeId: description: The ID of the resource type. - readOnly: false type: string title: Resource Type Id Ref type: object x-speakeasy-name-override: ResourceTypeIdRef c1.api.accessreview.v1.ResourceTypeSelectionScope: description: The ResourceTypeSelectionScope message. - nullable: true title: Resource Type Selection Scope type: object x-speakeasy-name-override: ResourceTypeSelectionScope @@ -2995,98 +3384,130 @@ components: properties: meaningOfSignature: description: The meaningOfSignature field. - readOnly: false type: string requireSignature: description: The requireSignature field. - readOnly: false type: boolean stepUpProviderId: description: The stepUpProviderId field. - readOnly: false type: string tspUrl: description: The tspUrl field. - readOnly: false type: string title: Review Signature Config type: object x-speakeasy-name-override: ReviewSignatureConfig + c1.api.accessreview.v1.ReviewerAttributeBinding: + description: Pair of an app and one of that app's user profile attribute keys. + properties: + appId: + description: The appId field. + type: string + attributeKey: + description: The attributeKey field. + type: string + title: Reviewer Attribute Binding + type: object + x-speakeasy-name-override: ReviewerAttributeBinding + c1.api.accessreview.v1.ReviewerAttributeConfig: + description: |- + Allowlist of AppUser.profile keys visible to reviewers, scoped per app. + Empty = reviewers see no profile attributes in the AppUser tooltip. + properties: + bindings: + description: The bindings field. + items: + $ref: '#/components/schemas/c1.api.accessreview.v1.ReviewerAttributeBinding' + type: + - array + - "null" + title: Reviewer Attribute Config + type: object + x-speakeasy-name-override: ReviewerAttributeConfig + c1.api.accessreview.v1.ScopeRoleSelectionScope: + description: |- + Empty marker for scope+role pair scoping on IaaS-type apps. + Actual selections stored in AccessReviewScopeRoleSelection rows. + May coexist with ResourceSelectionScope on the same campaign; prepare unions both. + title: Scope Role Selection Scope + type: object + x-speakeasy-name-override: ScopeRoleSelectionScope c1.api.accessreview.v1.SelectedUsersScope: description: The SelectedUsersScope message. - nullable: true properties: userIds: description: The userIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: Selected Users Scope type: object x-speakeasy-name-override: SelectedUsersScope c1.api.accessreview.v1.SingleAppSetup: description: The SingleAppSetup message. - nullable: true properties: appId: description: The appId field. - readOnly: false type: string title: Single App Setup type: object x-speakeasy-name-override: SingleAppSetup c1.api.accessreview.v1.SlackChannel: description: The SlackChannel message. - nullable: true properties: + channelId: + description: |- + Existing Slack channel ID (e.g. "C0123ABCD"). Set with is_channel_id=true to + target an existing channel instead of creating one by name. + type: string description: description: The description field. - readOnly: false type: string + isChannelId: + description: |- + When true, channel_id identifies an existing channel to use as-is: the + backend resolves it by ID (conversations.info) and fails if it is missing or + the bot cannot access it. It never creates or searches by name. + type: boolean name: - description: The name field. - readOnly: false + description: Channel name to create/resolve. Required unless is_channel_id is true. type: string title: Slack Channel type: object x-speakeasy-name-override: SlackChannel c1.api.accessreview.v1.SpecificAccessConflictsScope: description: The SpecificAccessConflictsScope message. - nullable: true title: Specific Access Conflicts Scope type: object x-speakeasy-name-override: SpecificAccessConflictsScope c1.api.accessreview.v1.SpecificResourcesScope: description: The SpecificResourcesScope message. - nullable: true title: Specific Resources Scope type: object x-speakeasy-name-override: SpecificResourcesScope c1.api.accessreview.v1.UserCriteriaScope: description: The UserCriteriaScope message. - nullable: true properties: groupAppEntitlementsRef: description: The groupAppEntitlementsRef field. items: $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array + type: + - array + - "null" managerUserIds: description: The managerUserIds field. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" multiUserProfileAttributes: additionalProperties: $ref: '#/components/schemas/c1.api.accessreview.v1.IncludedUserAttributeValues' description: The multiUserProfileAttributes field. - readOnly: false type: object userStatus: description: The userStatus field. @@ -3098,2146 +3519,3537 @@ components: - DELETED type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + type: + - array + - "null" title: User Criteria Scope type: object x-speakeasy-name-override: UserCriteriaScope - c1.api.app.v1.AddAppEntitlementOwnerRequestInput: - description: The request message for adding an app entitlement owner. + c1.api.ai_governance.v1.AIGovernanceSettings: + description: |- + AIGovernanceSettings holds the tenant-wide AI governance policy that controls + MCP client access, tool approval, classification defaults, audit detail, and + automatic tool discovery. There is one settings object per tenant. properties: - userId: - description: The user_id field for the user to add as an owner of the app entitlement. - readOnly: false + allowedClientTypes: + description: MCP client types permitted to connect. An empty list allows all types. + items: + enum: + - MCP_CLIENT_TYPE_UNSPECIFIED + - MCP_CLIENT_TYPE_PERSONAL + - MCP_CLIENT_TYPE_SHARED + - MCP_CLIENT_TYPE_SERVICE + - MCP_CLIENT_TYPE_EPHEMERAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + auditVerbosity: + description: How much detail is captured in the audit log for MCP tool calls. + enum: + - AUDIT_VERBOSITY_UNSPECIFIED + - AUDIT_VERBOSITY_MINIMAL + - AUDIT_VERBOSITY_STANDARD + - AUDIT_VERBOSITY_FULL type: string - title: Add App Entitlement Owner Request - type: object - x-speakeasy-name-override: AddAppEntitlementOwnerRequest - c1.api.app.v1.AddAppEntitlementOwnerResponse: - description: The empty response message for adding an app entitlement owner. - title: Add App Entitlement Owner Response - type: object - x-speakeasy-name-override: AddAppEntitlementOwnerResponse - c1.api.app.v1.AddAppOwnerRequestInput: - description: Empty request body. Just placeholder for the add app owner request which uses URL values for input. - title: Add App Owner Request - type: object - x-speakeasy-name-override: AddAppOwnerRequest - c1.api.app.v1.AddAppOwnerResponse: - description: Empty response with a status code indicating success - title: Add App Owner Response - type: object - x-speakeasy-name-override: AddAppOwnerResponse - c1.api.app.v1.AddAppResourceOwnerRequestInput: - description: The request message for adding an owner to an app resource. - properties: - userId: - description: The C1 user ID to add as an owner. - readOnly: false + x-speakeasy-unknown-values: allow + autoDiscoveryEnabled: + description: |- + When true, C1 periodically re-discovers tools from registered MCP servers + on the discovery_interval schedule. + type: boolean + c1awAutospillDisabled: + deprecated: true + description: |- + Deprecated. Set QUOTA_REF_TENANT_C1AW_AUTOSPILL_THRESHOLD_KB to 0 to + disable C1AW autospill. + type: boolean + c1awAutospillThresholdBytes: + deprecated: true + description: |- + Deprecated. C1AW autospill is configured with + QUOTA_REF_TENANT_C1AW_AUTOSPILL_THRESHOLD_KB. + format: uint32 + type: integer + codeModeConcurrency: + description: |- + Number of pre-warmed Lambda instances for the per-tenant code-mode + function. 0 (default) leaves the Lambda cold-started on first call; + > 0 keeps that many execution environments warm via AWS Lambda + provisioned concurrency, redeploying the function on change. + format: int32 + type: integer + createdAt: + format: date-time + type: + - string + - "null" + defaultClientLifecycle: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPClientLifecycleConfig' + - type: "null" + defaultToolClassification: + description: |- + Classification assigned to newly discovered tools that do not declare their + own classification (for example, read, write, or destructive). + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS type: string - title: Add App Resource Owner Request - type: object - x-speakeasy-name-override: AddAppResourceOwnerRequest - c1.api.app.v1.AddAppResourceOwnerResponse: - description: The empty response message for adding an owner to an app resource. - title: Add App Resource Owner Response + x-speakeasy-unknown-values: allow + discoveryInterval: + format: duration + type: + - string + - "null" + enabled: + deprecated: true + description: Legacy master switch. + type: boolean + preferCodeModeOverDirectTools: + description: |- + When true, the MCP server hides direct tool listings from capable clients + whenever the code-mode entrypoints (describe + execute) are registered, so + agents discover and invoke MCP tools through TypeScript code mode instead + of direct tool calls. A small allowlist of high-traffic direct tools + remains exposed. Incapable clients (e.g. SERVICE, EPHEMERAL) see the + normal tool set regardless. Defaults to false. + type: boolean + requireToolApproval: + description: |- + When true, newly discovered tools start in a pending state and must be + approved by an admin before they can be granted or invoked. + type: boolean + surfaceRequestableTools: + description: |- + When true, MCP discovery surfaces tools the caller could request (no + active grant, but reachable through a request catalog) alongside granted + tools — both on the classic tools/list path and inside the code-mode + describe entrypoint. Invoking such a tool opens (or reuses) an + access-request ticket and returns a request_created envelope instead of + executing. Defaults to true. + type: boolean + updatedAt: + format: date-time + type: + - string + - "null" + title: Ai Governance Settings type: object - x-speakeasy-name-override: AddAppResourceOwnerResponse - c1.api.app.v1.AddAutomationExclusionRequestInput: - description: The AddAutomationExclusionRequest message. + x-speakeasy-name-override: AIGovernanceSettings + c1.api.ai_governance.v1.AIGovernanceSettingsHistoryEntry: + description: |- + AIGovernanceSettingsHistoryEntry is a single change-history record capturing a + snapshot of the settings and who changed them. properties: - userIds: - description: The IDs of users to add to the automation exclusion list. - items: - type: string - nullable: true - readOnly: false - type: array - title: Add Automation Exclusion Request - type: object - x-speakeasy-name-override: AddAutomationExclusionRequest - c1.api.app.v1.AddAutomationExclusionResponse: - description: Empty response with a status code indicating success. - title: Add Automation Exclusion Response + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.AIGovernanceSettings' + - type: "null" + title: Ai Governance Settings History Entry + type: object + x-speakeasy-name-override: AIGovernanceSettingsHistoryEntry + c1.api.ai_governance.v1.AccessProfilesForTool: + description: AccessProfilesForTool groups access profiles by the MCP tool they are bound to. + properties: + accessProfiles: + description: Access profiles bound to this tool. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + type: + - array + - "null" + mcpToolId: + description: The MCP tool identifier. + type: string + title: Access Profiles For Tool + type: object + x-speakeasy-name-override: AccessProfilesForTool + c1.api.ai_governance.v1.GetAIGovernanceSettingsResponse: + description: GetAIGovernanceSettingsResponse contains the tenant's AI governance settings. + properties: + aiGovernanceSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.AIGovernanceSettings' + - type: "null" + title: Get Ai Governance Settings Response + type: object + x-speakeasy-name-override: GetAIGovernanceSettingsResponse + c1.api.ai_governance.v1.GetTenantDefaultsResponse: + description: |- + GetTenantDefaultsResponse contains the tenant-default subset of AI governance + settings applied to newly registered MCP servers and tools. + properties: + requireToolApproval: + description: |- + Whether newly discovered tools require admin approval before they can be + granted or invoked. + type: boolean + title: Get Tenant Defaults Response type: object - x-speakeasy-name-override: AddAutomationExclusionResponse - c1.api.app.v1.AddManuallyManagedUsersRequestInput: - description: The AddManuallyManagedUsersRequest message. + x-speakeasy-name-override: GetTenantDefaultsResponse + c1.api.ai_governance.v1.ListAIGovernanceSettingsHistoryResponse: + description: |- + ListAIGovernanceSettingsHistoryResponse contains a page of AI governance + settings change-history entries, newest first. properties: - userIds: - description: The IDs of users to add as manually managed members. + list: + description: The page of history entries, newest first. items: - type: string - nullable: true - readOnly: false - type: array - title: Add Manually Managed Users Request + $ref: '#/components/schemas/c1.api.ai_governance.v1.AIGovernanceSettingsHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: List Ai Governance Settings History Response type: object - x-speakeasy-name-override: AddManuallyManagedUsersRequest - c1.api.app.v1.App: - description: The App object provides all of the details for an app, as well as some configuration. + x-speakeasy-name-override: ListAIGovernanceSettingsHistoryResponse + c1.api.ai_governance.v1.MCPAccessProfile: + description: MCPAccessProfile represents an admin-curated grouping of MCP tools. properties: - accessModel: - description: |- - How this app models access. Derived during uplift from the app's resource type traits. - Sparse ACL feature. - enum: - - APP_ACCESS_MODEL_UNSPECIFIED - - APP_ACCESS_MODEL_CLASSIC - - APP_ACCESS_MODEL_HYBRID - - APP_ACCESS_MODEL_SPARSE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - appAccountId: - description: The ID of the Account named by AccountName. - readOnly: true + appEntitlementId: + description: The ID of the AppEntitlement created for this profile. type: string - appAccountName: - description: The AccountName of the app. For example, AWS is AccountID, Github is Org Name, and Okta is Okta Subdomain. - readOnly: true + appId: + description: App identifier (app that owns the connector). type: string - appOwners: - description: The owners of the app. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: true - type: array - appUserMapper: - $ref: '#/components/schemas/c1.api.app.v1.AppUserMapper' - certifyPolicyId: - description: The ID of the Certify Policy associated with this App. - readOnly: false + connectorId: + description: Connector identifier. type: string - connectorVersion: - description: The connectorVersion field. - format: uint32 - readOnly: false - type: integer createdAt: format: date-time - readOnly: true - type: string - defaultRequestCatalogId: - description: The ID for the default request catalog for this app. - readOnly: false - type: string + type: + - string + - "null" deletedAt: format: date-time - readOnly: true - type: string + type: + - string + - "null" description: - description: The app's description. - readOnly: false + description: Description of what access this profile grants. type: string displayName: - description: The app's display name. - readOnly: false - type: string - enableConnectorSourcedOwnership: - description: When enabled, resource ownership is sourced from the connector. - readOnly: false - type: boolean - fieldMask: - nullable: true - readOnly: true - type: string - grantPolicyId: - description: The ID of the Grant Policy associated with this App. - readOnly: false - type: string - iconUrl: - description: The URL of an icon to display for the app. - readOnly: false + description: Display name for the profile. type: string id: - description: The ID of the app. - readOnly: true - type: string - identityMatching: - description: The identityMatching field. - enum: - - APP_USER_IDENTITY_MATCHING_UNSPECIFIED - - APP_USER_IDENTITY_MATCHING_STRICT - - APP_USER_IDENTITY_MATCHING_DISPLAY_NAME - - APP_USER_IDENTITY_MATCHING_CUSTOM - readOnly: false - type: string - x-speakeasy-unknown-values: allow - instructions: - description: If you add instructions here, they will be shown to users in the access request form when requesting access for this app. - readOnly: false - type: string - isDirectory: - description: Specifies if the app is a directory. - readOnly: true - type: boolean - isManuallyManaged: - description: The isManuallyManaged field. - readOnly: false - type: boolean - logoUri: - description: The URL of a logo to display for the app. - readOnly: true + description: Unique identifier for this access profile. type: string - monthlyCostUsd: - description: The cost of an app per-seat, so that total cost can be calculated by the grant count. + toolCount: + description: The number of tools currently bound to this profile. format: int32 - readOnly: false type: integer - parentAppId: - description: The ID of the app that created this app, if any. - readOnly: true - type: string - revokePolicyId: - description: The ID of the Revoke Policy associated with this App. - readOnly: false - type: string - strictAccessEntitlementProvisioning: - description: The strictAccessEntitlementProvisioning field. - readOnly: false - type: boolean updatedAt: format: date-time - readOnly: true + type: + - string + - "null" + title: Mcp Access Profile + type: object + x-speakeasy-name-override: MCPAccessProfile + c1.api.ai_governance.v1.MCPAccessProfileServiceCreateRequestInput: + description: MCPAccessProfileServiceCreateRequest creates a new MCP access profile. + properties: + description: + description: Description of what access this profile grants. type: string - userCount: - description: The number of users with grants to this app. - format: int64 - readOnly: true + displayName: + description: Display name for the profile. type: string - title: App + title: Mcp Access Profile Service Create Request type: object - x-speakeasy-entity: App - x-speakeasy-name-override: App - c1.api.app.v1.AppAccessRequestDefaults: - description: | - The AppAccessRequestDefaults message. - - This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: - - durationUnset - - durationGrant + x-speakeasy-name-override: MCPAccessProfileServiceCreateRequest + c1.api.ai_governance.v1.MCPAccessProfileServiceCreateResponse: + description: MCPAccessProfileServiceCreateResponse returns the created MCP access profile. properties: - appId: - description: The app id for the app access request rule - readOnly: false - type: string - catalogIds: - description: The request catalog ids for the app access request rule. + profile: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + - type: "null" + title: Mcp Access Profile Service Create Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceCreateResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteRequestInput: + description: MCPAccessProfileServiceDeleteRequest deletes an MCP access profile (soft delete). + title: Mcp Access Profile Service Delete Request + type: object + x-speakeasy-name-override: MCPAccessProfileServiceDeleteRequest + c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteResponse: + description: MCPAccessProfileServiceDeleteResponse confirms deletion. + title: Mcp Access Profile Service Delete Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceDeleteResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceGetByAppEntitlementIdResponse: + description: MCPAccessProfileServiceGetByAppEntitlementIdResponse returns the matched profile. + properties: + profile: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + - type: "null" + title: Mcp Access Profile Service Get By App Entitlement Id Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceGetByAppEntitlementIdResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceGetResponse: + description: MCPAccessProfileServiceGetResponse returns a single MCP access profile. + properties: + profile: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + - type: "null" + title: Mcp Access Profile Service Get Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceGetResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceListRequestableConnectorsResponse: + description: |- + MCPAccessProfileServiceListRequestableConnectorsResponse returns connector references + that have requestable MCP access profiles. + properties: + connectors: + description: List of connectors with requestable MCP access profiles. items: - type: string - nullable: true - readOnly: false - type: array - defaultsEnabled: - description: If true the app level request configuration will be applied to specified resource types. - readOnly: false - type: boolean - durationGrant: - format: duration - readOnly: false - type: string - durationUnset: - nullable: true - readOnly: false - type: object - emergencyGrantEnabled: - description: If emergency grants are enabled for this app access request rule. - readOnly: false - type: boolean - emergencyGrantPolicyId: - description: The policy id for the emergency grant policy. - readOnly: false - type: string - requestPolicyId: - description: The ID of the request policy to apply to entitlements matching this rule. - readOnly: false - type: string - requestSchemaId: - description: The ID of the request schema to apply to entitlements matching this rule. - readOnly: false + $ref: '#/components/schemas/c1.api.ai_governance.v1.RequestableConnector' + type: + - array + - "null" + title: Mcp Access Profile Service List Requestable Connectors Response + type: object + x-speakeasy-name-override: MCPAccessProfileServiceListRequestableConnectorsResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceListResponse: + description: MCPAccessProfileServiceListResponse returns a list of MCP access profiles. + properties: + nextPageToken: + description: Token for next page. type: string - resourceTypeIds: - description: The app resource type ids for which the app access request defaults are applied. + profiles: + description: List of MCP access profiles. items: - type: string - nullable: true - readOnly: false - type: array - state: - description: The last applied state of the app access request defaults. - enum: - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_UNSPECIFIED - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_RUNNING - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_SUCCESS - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_FAILED - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCELING - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_SUCCESS - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_ERROR - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: App Access Request Defaults + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + type: + - array + - "null" + title: Mcp Access Profile Service List Response type: object - x-speakeasy-name-override: AppAccessRequestDefaults - c1.api.app.v1.AppAccessRequestDefaultsInput: - description: | - The AppAccessRequestDefaults message. - - This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: - - durationUnset - - durationGrant + x-speakeasy-name-override: MCPAccessProfileServiceListResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceSearchRequestableConnectorsResponse: + description: |- + MCPAccessProfileServiceSearchRequestableConnectorsResponse returns one page + of card-ready requestable-connector entries. properties: - catalogIds: - description: The request catalog ids for the app access request rule. - items: - type: string - nullable: true - readOnly: false - type: array - defaultsEnabled: - description: If true the app level request configuration will be applied to specified resource types. - readOnly: false - type: boolean - durationGrant: - format: duration - readOnly: false - type: string - durationUnset: - nullable: true - readOnly: false - type: object - emergencyGrantEnabled: - description: If emergency grants are enabled for this app access request rule. - readOnly: false - type: boolean - emergencyGrantPolicyId: - description: The policy id for the emergency grant policy. - readOnly: false - type: string - requestPolicyId: - description: The ID of the request policy to apply to entitlements matching this rule. - readOnly: false - type: string - requestSchemaId: - description: The ID of the request schema to apply to entitlements matching this rule. - readOnly: false - type: string - resourceTypeIds: - description: The app resource type ids for which the app access request defaults are applied. + list: + description: The page of connector cards. items: - type: string - nullable: true - readOnly: false - type: array - state: - description: The last applied state of the app access request defaults. - enum: - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_UNSPECIFIED - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_RUNNING - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_SUCCESS - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_FAILED - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCELING - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_SUCCESS - - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_ERROR - readOnly: false + $ref: '#/components/schemas/c1.api.ai_governance.v1.RequestableConnectorView' + type: + - array + - "null" + nextPageToken: + description: Token for next page. type: string - x-speakeasy-unknown-values: allow - title: App Access Request Defaults + title: Mcp Access Profile Service Search Requestable Connectors Response type: object - x-speakeasy-name-override: AppAccessRequestDefaults - c1.api.app.v1.AppActionsServiceGenerateReportRequestInput: - description: Empty request body. Just placeholder for the generate app report request which uses URL values for input. - title: App Actions Service Generate Report Request + x-speakeasy-name-override: MCPAccessProfileServiceSearchRequestableConnectorsResponse + c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateRequestInput: + description: MCPAccessProfileServiceUpdateRequest updates an existing MCP access profile. + properties: + profile: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + - type: "null" + updateMask: + type: + - string + - "null" + title: Mcp Access Profile Service Update Request type: object - x-speakeasy-name-override: AppActionsServiceGenerateReportRequest - c1.api.app.v1.AppActionsServiceGenerateReportResponse: - description: Empty response body. Status code indicates success. - title: App Actions Service Generate Report Response + x-speakeasy-name-override: MCPAccessProfileServiceUpdateRequest + c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateResponse: + description: MCPAccessProfileServiceUpdateResponse returns the updated MCP access profile. + properties: + profile: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfile' + - type: "null" + title: Mcp Access Profile Service Update Response type: object - x-speakeasy-name-override: AppActionsServiceGenerateReportResponse - c1.api.app.v1.AppEntitlement: - description: | - The app entitlement represents one permission in a downstream App (SAAS) that can be granted. For example, GitHub Read vs GitHub Write. - - This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: - - durationUnset - - durationGrant + x-speakeasy-name-override: MCPAccessProfileServiceUpdateResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBinding: + description: MCPAccessProfileToolBinding represents a binding between an access profile and a tool. properties: - alias: - description: The alias of the app entitlement used by Cone. Also exact-match queryable. - readOnly: false + accessProfileId: + description: Access profile identifier. type: string appId: - description: The ID of the app that is associated with the app entitlement. - readOnly: false - type: string - appResourceId: - description: The ID of the app resource that is associated with the app entitlement - readOnly: false - type: string - appResourceTypeId: - description: The ID of the app resource type that is associated with the app entitlement - readOnly: false + description: App identifier. type: string - certifyPolicyId: - description: The ID of the policy that will be used for certify tickets related to the app entitlement. - readOnly: false + connectorId: + description: Connector identifier. type: string - complianceFrameworkValueIds: - description: The IDs of different compliance frameworks associated with this app entitlement ex (SOX, HIPAA, PCI, etc.) - items: - type: string - nullable: true - readOnly: false - type: array createdAt: format: date-time - readOnly: true - type: string - defaultValuesApplied: - description: Flag to indicate if app-level access request defaults have been applied to the entitlement - readOnly: false - type: boolean + type: + - string + - "null" deletedAt: format: date-time - readOnly: true - type: string - deprovisionerPolicy: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - description: - description: The description of the app entitlement. - readOnly: false - type: string - displayName: - description: The display name of the app entitlement. - readOnly: false + type: + - string + - "null" + mcpToolId: + description: MCP tool identifier. type: string - durationGrant: - format: duration - readOnly: false - type: string - durationUnset: - nullable: true - readOnly: false - type: object - emergencyGrantEnabled: - description: This enables tasks to be created in an emergency and use a selected emergency access policy. - readOnly: false - type: boolean - emergencyGrantPolicyId: - description: The ID of the policy that will be used for emergency access grant tasks. - readOnly: false + updatedAt: + format: date-time + type: + - string + - "null" + title: Mcp Access Profile Tool Binding + type: object + x-speakeasy-name-override: MCPAccessProfileToolBinding + c1.api.ai_governance.v1.MCPAccessProfileToolBindingHistoryEntry: + description: |- + MCPAccessProfileToolBindingHistoryEntry is a single change-history record + capturing the tool bindings added or removed in one transaction. + properties: + items: + description: The bindings added or removed in this change. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingHistoryItem' + type: + - array + - "null" + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.ListHistoryEntryMetadata' + - type: "null" + title: Mcp Access Profile Tool Binding History Entry + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingHistoryEntry + c1.api.ai_governance.v1.MCPAccessProfileToolBindingHistoryItem: + description: |- + MCPAccessProfileToolBindingHistoryItem is a single binding added or removed in + a transaction. + properties: + changeKind: + description: Whether this binding was added or removed. + enum: + - LIST_CHANGE_KIND_UNSPECIFIED + - LIST_CHANGE_KIND_ADDED + - LIST_CHANGE_KIND_REMOVED type: string - externalId: + x-speakeasy-unknown-values: allow + listIndex: description: |- - The upstream product's native external ID for this entitlement (e.g. an Okta group ID). - Populated from the connector's external ID during sync. - readOnly: true + The identifier of the other side of the binding: the tool ID when viewing a + toolset's history, or the toolset ID when viewing a tool's history. type: string - grantCount: - description: The amount of grants open for this entitlement - format: int64 - readOnly: true + title: Mcp Access Profile Tool Binding History Item + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingHistoryItem + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateRequestInput: + description: MCPAccessProfileToolBindingServiceCreateRequest creates tool bindings. + properties: + mcpToolIds: + description: MCP tool IDs to bind to the access profile. + items: + type: string + type: + - array + - "null" + title: Mcp Access Profile Tool Binding Service Create Request + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceCreateRequest + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateResponse: + description: MCPAccessProfileToolBindingServiceCreateResponse returns created bindings. + properties: + bindings: + description: Created tool bindings. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBinding' + type: + - array + - "null" + title: Mcp Access Profile Tool Binding Service Create Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceCreateResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteRequestInput: + description: MCPAccessProfileToolBindingServiceDeleteRequest deletes tool bindings. + properties: + mcpToolIds: + description: MCP tool IDs to unbind from the access profile. + items: + type: string + type: + - array + - "null" + title: Mcp Access Profile Tool Binding Service Delete Request + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceDeleteRequest + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteResponse: + description: MCPAccessProfileToolBindingServiceDeleteResponse confirms deletion. + title: Mcp Access Profile Tool Binding Service Delete Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceDeleteResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequestInput: + description: |- + MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequest requests + the access profiles bound to a batch of MCP tools. + properties: + mcpToolIds: + description: MCP tool IDs to look up. Sized to match frontend MultiGet batch size. + items: + type: string + type: + - array + - "null" + title: Mcp Access Profile Tool Binding Service Get Access Profiles For Tools Request + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequest + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse: + description: |- + MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse returns + access profiles grouped by MCP tool. + properties: + accessProfilesForTools: + description: |- + One entry per requested MCP tool. Tools with no bindings are still + included with an empty access_profiles list, so callers can distinguish + "no bindings" from "tool not requested" in the multi-get cache. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.AccessProfilesForTool' + type: + - array + - "null" + title: Mcp Access Profile Tool Binding Service Get Access Profiles For Tools Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListProfilesByToolHistoryResponse: + description: |- + Contains a page of change-history entries for the toolsets one tool has belonged to, + sorted newest first. + properties: + list: + description: The page of history entries, newest first. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. type: string - grantPolicyId: - description: The ID of the policy that will be used for grant tickets related to the app entitlement. - readOnly: false + title: Mcp Access Profile Tool Binding Service List Profiles By Tool History Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceListProfilesByToolHistoryResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListResponse: + description: MCPAccessProfileToolBindingServiceListResponse returns tool bindings. + properties: + bindings: + description: List of tool bindings. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBinding' + type: + - array + - "null" + nextPageToken: + description: Token for next page. type: string - id: - description: The unique ID for the App Entitlement. - readOnly: true + title: Mcp Access Profile Tool Binding Service List Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceListResponse + c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListToolsByProfileHistoryResponse: + description: |- + Contains a page of change-history entries for the tools bound to one toolset + sorted newest first. + properties: + list: + description: The page of history entries, newest first. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. type: string - isAutomationEnabled: - description: Flag to indicate whether automation (for adding users to entitlement based on rules) has been enabled. - readOnly: true - type: boolean - isManuallyManaged: - description: Flag to indicate if the app entitlement is manually managed. - readOnly: false - type: boolean - matchBatonId: - description: An identifier used to match this entitlement to a connector-synced entitlement during sync. - readOnly: false + title: Mcp Access Profile Tool Binding Service List Tools By Profile History Response + type: object + x-speakeasy-name-override: MCPAccessProfileToolBindingServiceListToolsByProfileHistoryResponse + c1.api.ai_governance.v1.MCPClientLifecycleConfig: + description: |- + MCPClientLifecycleConfig controls how long inactive MCP clients remain + visible, when their access is closed, and when their records are removed. + Durations are measured from the client's last activity. Any duration left at + zero disables that transition. + properties: + inactivityCloseAfter: + format: duration + type: + - string + - "null" + inactivityHideAfter: + format: duration + type: + - string + - "null" + retentionDeleteAfter: + format: duration + type: + - string + - "null" + title: Mcp Client Lifecycle Config + type: object + x-speakeasy-name-override: MCPClientLifecycleConfig + c1.api.ai_governance.v1.MCPConnectionView: + description: |- + MCPConnectionView is the user-facing representation of a per-user MCP + server, including whether the calling user has an active credential. + Covers both OAuth2 authorization-code passthrough (where the user + connects via an IdP redirect) and bearer-token / custom-header + passthrough (where the user submits a value via SubmitUserCredential). + The frontend branches on auth_method to decide which flow to drive. + properties: + appId: + description: App that owns this MCP server. type: string - overrideAccessRequestsDefaults: - description: Flag to indicate if the app-level access request settings have been overridden for the entitlement - readOnly: false - type: boolean - provisionerPolicy: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - purpose: - description: The purpose of this entitlement (e.g., assignment, permission, ownership). + authMethod: + description: |- + Auth method on the connector. Drives the FE connect-flow choice: + OAUTH2 → redirect via CreateAuthorizeURL; BEARER_TOKEN / CUSTOM_HEADER + → form dialog via SubmitUserCredential. enum: - - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED - - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT - - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION - - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP - readOnly: false + - MCP_SERVER_AUTH_METHOD_UNSPECIFIED + - MCP_SERVER_AUTH_METHOD_NONE + - MCP_SERVER_AUTH_METHOD_BEARER_TOKEN + - MCP_SERVER_AUTH_METHOD_OAUTH2 + - MCP_SERVER_AUTH_METHOD_CUSTOM_HEADER + - MCP_SERVER_AUTH_METHOD_AWS_SIGV4 + - MCP_SERVER_AUTH_METHOD_BASIC_AUTH type: string x-speakeasy-unknown-values: allow - requestSchemaId: - description: The ID of the request schema associated with this app entitlement. - readOnly: false - type: string - revokePolicyId: - description: The ID of the policy that will be used for revoke tickets related to the app entitlement - readOnly: false - type: string - riskLevelValueId: - description: The ID of the risk level assigned to this entitlement. - readOnly: false + authorizedAsEmail: + description: |- + Email of the external identity (from OAuth ID token). Empty for + non-OAuth connections (no upstream identity to surface). type: string - slug: - description: The slug is displayed as an oval next to the name in the frontend of C1, it tells you what permission the entitlement grants. See https://www.conductorone.com/docs/product/admin/entitlements/ - readOnly: false + authorizedAsName: + description: |- + Display name of the external identity (from OAuth ID token). Empty + for non-OAuth connections. type: string - sourceConnectorIds: - additionalProperties: - type: string - description: Map to tell us which connector the entitlement came from. - readOnly: false - type: object - systemBuiltin: - description: This field indicates if this is a system builtin entitlement. - readOnly: true + connected: + description: Whether the calling user has an active credential. type: boolean - updatedAt: + connectedAt: format: date-time - readOnly: true + type: + - string + - "null" + connectorId: + description: MCP server connector ID. type: string - userEditedMask: - nullable: true - readOnly: false + description: + description: Description of the MCP server. type: string - title: App Entitlement + displayName: + description: Display name of the MCP server. + type: string + serverType: + description: Server type (hosted or external). + enum: + - MCP_SERVER_TYPE_UNSPECIFIED + - MCP_SERVER_TYPE_HOSTED + - MCP_SERVER_TYPE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + title: Mcp Connection View type: object - x-speakeasy-entity: Custom App Entitlement - x-speakeasy-name-override: AppEntitlement - c1.api.app.v1.AppEntitlementAutomation: - description: | - The AppEntitlementAutomation message. + x-speakeasy-name-override: MCPConnectionView + c1.api.ai_governance.v1.MCPServerAuthAWSSigV4: + description: |- + MCPServerAuthAWSSigV4 provides AWS Signature Version 4 authentication. + Used for hosted MCP servers backed by AWS service impls (the + amazonaws_com_* catalog entries). Outbound requests from the gateway are + signed per-request with the supplied access key + secret, against the + service+region scope sourced from the impl bundle's connect.auth. - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - none - - entitlements - - cel - - basic + Only the SHARED token-sharing model is supported — every caller in the + tenant signs with the same admin-configured credentials. Per-user AWS + (STS / Web Identity / IAM Identity Center) is a separate future surface. properties: - appEntitlementId: - description: The unique ID for the App Entitlement. - readOnly: true - type: string - appId: - description: The ID of the app that is associated with the app entitlement. - readOnly: true - type: string - basic: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleBasic' - cel: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleCEL' - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time - readOnly: true - type: string - description: - description: The description of the app entitlement. - readOnly: false - type: string - displayName: - description: The display name of the app entitlement. - readOnly: false + accessKeyId: + description: |- + AWS access key ID (the IAM user / role's public identifier, e.g. + "AKIAIOSFODNN7EXAMPLE"). Persisted in plaintext form; the secret half + is sealed. type: string - entitlements: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleEntitlement' - lastRunStatus: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationLastRunStatus' - managedByRequestCatalogId: + secretAccessKey: description: |- - When set, this automation is managed by an access profile's bundle automation. - Read-only. Not settable via this API. - readOnly: true + AWS secret access key. Sealed by the backend on write; never returned on + read. type: string - none: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleNone' - updatedAt: - format: date-time - readOnly: true + sessionToken: + description: |- + Optional AWS session token. Set only when the credential is a + short-lived STS temporary credential. Static IAM-user keys leave this + empty. type: string - title: App Entitlement Automation + title: Mcp Server Auth Aws Sig V 4 type: object - x-speakeasy-entity: App Entitlement Automation - x-speakeasy-name-override: AppEntitlementAutomation - c1.api.app.v1.AppEntitlementAutomationLastRunStatus: - description: The AppEntitlementAutomationLastRunStatus message. + x-speakeasy-name-override: MCPServerAuthAWSSigV4 + c1.api.ai_governance.v1.MCPServerAuthBasicAuth: + description: |- + MCPServerAuthBasicAuth provides HTTP Basic authentication (RFC 7617). + The gateway encodes `username:password` as base64 and sends it as + `Authorization: Basic ` on every outbound request. properties: - errorMessage: - description: The errorMessage field. - readOnly: true - type: string - lastCompletedAt: - format: date-time - readOnly: true + password: + description: |- + Password. Sealed before storage; never returned on read. + ignore_empty for the same PER_USER reason as username above. type: string - status: - description: The status field. - enum: - - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_UNSPECIFIED - - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_SUCCESS - - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_FAILED - - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_IN_PROGRESS - readOnly: true + username: + description: |- + Username. Sent in plaintext over TLS; stored unsealed on the + connector config (mirrors how MCPAuthOAuth2.client_id is plaintext). + ignore_empty mirrors MCPServerAuthBearerToken.token — PER_USER admin + submits don't carry a username; the handler enforces non-empty for + SHARED. type: string - x-speakeasy-unknown-values: allow - title: App Entitlement Automation Last Run Status + title: Mcp Server Auth Basic Auth type: object - x-speakeasy-name-override: AppEntitlementAutomationLastRunStatus - c1.api.app.v1.AppEntitlementAutomationRuleBasic: - description: The AppEntitlementAutomationRuleBasic message. - nullable: true + x-speakeasy-name-override: MCPServerAuthBasicAuth + c1.api.ai_governance.v1.MCPServerAuthBearerToken: + description: MCPServerAuthBearerToken provides bearer token authentication. properties: - expression: - description: The expression field. - readOnly: false + token: + description: The bearer token value. type: string - title: App Entitlement Automation Rule Basic + title: Mcp Server Auth Bearer Token type: object - x-speakeasy-name-override: AppEntitlementAutomationRuleBasic - c1.api.app.v1.AppEntitlementAutomationRuleCEL: - description: The AppEntitlementAutomationRuleCEL message. - nullable: true + x-speakeasy-name-override: MCPServerAuthBearerToken + c1.api.ai_governance.v1.MCPServerAuthCustomHeader: + description: MCPServerAuthCustomHeader provides custom header authentication. properties: - expression: - description: The expression field. - readOnly: false + headerName: + description: HTTP header name. type: string - title: App Entitlement Automation Rule Cel + headerValue: + description: HTTP header value. + type: string + title: Mcp Server Auth Custom Header type: object - x-speakeasy-name-override: AppEntitlementAutomationRuleCEL - c1.api.app.v1.AppEntitlementAutomationRuleEntitlement: - description: The AppEntitlementAutomationRuleEntitlement message. - nullable: true + x-speakeasy-name-override: MCPServerAuthCustomHeader + c1.api.ai_governance.v1.MCPServerAuthGoogleServiceAccount: + description: |- + MCPServerAuthGoogleServiceAccount provides Google service account authentication. + The admin uploads the raw JSON key file from the GCP console; the backend parses + it to extract the private key, client email (issuer), and token URI. properties: - entitlementRefs: - description: The entitlementRefs field. + credentialsJson: + description: Raw JSON content of the Google service account key file. + type: string + scopes: + description: OAuth2 scopes to request when exchanging the JWT for an access token. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: App Entitlement Automation Rule Entitlement + type: string + type: + - array + - "null" + title: Mcp Server Auth Google Service Account type: object - x-speakeasy-name-override: AppEntitlementAutomationRuleEntitlement - c1.api.app.v1.AppEntitlementAutomationRuleNone: - description: The AppEntitlementAutomationRuleNone message. - nullable: true - title: App Entitlement Automation Rule None + x-speakeasy-name-override: MCPServerAuthGoogleServiceAccount + c1.api.ai_governance.v1.MCPServerAuthNone: + description: MCPServerAuthNone indicates no authentication is required. + title: Mcp Server Auth None type: object - x-speakeasy-name-override: AppEntitlementAutomationRuleNone - c1.api.app.v1.AppEntitlementExpandMask: - description: The app entitlement expand mask allows the user to get additional information when getting responses containing app entitlement views. + x-speakeasy-name-override: MCPServerAuthNone + c1.api.ai_governance.v1.MCPServerAuthOAuth2: + description: MCPServerAuthOAuth2 provides OAuth2 client credentials or JWT Bearer authentication. properties: - paths: - description: Array of strings to describe which items to expand on the return value. Can be any combination of "*", "app_id", "app_resource_type_id", or "app_resource_id". + authorizeUrl: + description: OAuth2 authorization endpoint URL (for service and passthrough modes). + type: string + clientId: + description: OAuth2 client identifier. Required for CLIENT_CREDENTIALS mode; not used for JWT_BEARER mode. + type: string + clientIdMode: + description: |- + How the client_id is acquired for authorization_code mode. When DCR (or + CIMD), client_id / client_secret are not required on input — the gateway + registers itself with the authorization server during Register and injects + the result. UNSPECIFIED means manual (admin-entered client_id). + enum: + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_UNSPECIFIED + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_DCR + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_CIMD + type: string + x-speakeasy-unknown-values: allow + clientSecret: + description: OAuth2 client secret. Required for CLIENT_CREDENTIALS mode; not used for JWT_BEARER mode. + type: string + codeChallengeMethodsSupported: + description: |- + PKCE code challenge methods supported by the authorization server, as + returned by DiscoverOIDCEndpoints. Optional registration-time shortcut + that lets the gateway skip the per-flow xjwks.Cache lookup. Capped at + 8 entries because RFC 7636 / RFC 8414 only define a tiny enumerated + set ("plain", "S256") and we don't want to be a dumping ground for + arbitrary strings the IdP might emit. items: type: string - nullable: true - readOnly: false - type: array - title: App Entitlement Expand Mask - type: object - x-speakeasy-name-override: AppEntitlementExpandMask - c1.api.app.v1.AppEntitlementProxy: - description: An entitlement proxy binding that defines a hierarchical relationship between two entitlements. - properties: - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time - readOnly: true + type: + - array + - "null" + extraAuthorizeParams: + additionalProperties: + type: string + description: |- + Static query params appended to the authorize URL on top of the standard + OAuth2 fields (e.g. Notion "owner=user"). Applies to authorization_code + mode only. Inherited from MCPServerCatalogAuthMode.extra_authorize_params + at registration time. + type: object + extraTokenParams: + additionalProperties: + type: string + description: |- + Extra body params POSTed to the token endpoint on top of the standard + OAuth2 fields. Provider-specific (e.g. Auth0/Wiz "audience"). Applies + to client_credentials mode only; other modes ignore it. Inherited from + MCPServerCatalogAuthMode.extra_token_params at registration time; + admins can add, edit, or remove entries on the edit form. + type: object + issuerUrl: + description: |- + OIDC issuer URL (no trailing path). Used as the cache key for live + PKCE-methods discovery via xjwks.Cache on the gateway. Populated by + the Discover button or hand-entered alongside authorize_url/token_url. + Required for SERVICE / PASSTHROUGH modes. type: string - disabledAt: - format: date-time - readOnly: false + jwtAudience: + description: Audience claim for the JWT. When empty, token_url is used as the audience. type: string - dstAppEntitlementId: - description: The ID of the destination (child) entitlement. - readOnly: false + jwtIssuer: + description: The service account email / issuer claim. type: string - dstAppId: - description: The ID of the app that owns the destination entitlement. - readOnly: false + jwtPrivateKey: + description: PEM-encoded RSA private key (plaintext in API; sealed before storage). type: string - implicit: - description: If true, the binding does not exist yet and is inferred from the entitlements of the parent app. - nullable: true - readOnly: false - type: boolean - srcAppEntitlementId: - description: The ID of the source (parent) entitlement. - readOnly: false + jwtSubject: + description: Optional subject for domain-wide delegation. type: string - srcAppId: - description: The ID of the app that owns the source entitlement. - readOnly: false + mode: + description: OAuth2 mode. + enum: + - MCP_SERVER_AUTH_OAUTH2_MODE_UNSPECIFIED + - MCP_SERVER_AUTH_OAUTH2_MODE_SERVICE + - MCP_SERVER_AUTH_OAUTH2_MODE_PASSTHROUGH + - MCP_SERVER_AUTH_OAUTH2_MODE_CLIENT_CREDENTIALS + - MCP_SERVER_AUTH_OAUTH2_MODE_JWT_BEARER + - MCP_SERVER_AUTH_OAUTH2_MODE_GOOGLE_SERVICE_ACCOUNT + - MCP_SERVER_AUTH_OAUTH2_MODE_AUTHORIZATION_CODE type: string - systemBuiltin: - description: If true, this binding was created by the system and cannot be removed by the user. - readOnly: false - type: boolean - updatedAt: - format: date-time - readOnly: true + x-speakeasy-unknown-values: allow + pkce: + description: |- + PKCE behavior for authorization_code mode: "discover" (or empty), + "s256", or "disabled". Inherited from MCPServerCatalogAuthMode.pkce. type: string - title: App Entitlement Proxy - type: object - x-speakeasy-entity: App Entitlement Proxy Binding - x-speakeasy-name-override: AppEntitlementProxy - c1.api.app.v1.AppEntitlementProxyExpandMask: - description: The AppEntitlementProxyExpandMask message. - properties: - paths: - description: The paths field. + scopes: + description: OAuth2 scopes to request. items: type: string - nullable: true - readOnly: false - type: array - title: App Entitlement Proxy Expand Mask + type: + - array + - "null" + scopesSupported: + description: |- + Full list of OAuth scopes the IdP advertises in its discovery doc + (`scopes_supported`). Distinct from the `scopes` field above, which is + the curated subset the admin wants requested on the authorize URL. + Captured at registration time so the edit form can offer autocomplete + suggestions on the Scopes input without forcing the admin to re-run + Discover. Capped at 256 because providers like Salesforce return ~36; + 256 leaves headroom without inviting abuse. + items: + type: string + type: + - array + - "null" + tokenEndpointAuthMethod: + description: |- + RFC 7591 token_endpoint_auth_method the authorization server assigned. + Read-only / ignored on write: server-set from the DCR result, never copied + from the API request into the stored model. Surfaced for display only. + type: string + tokenUrl: + description: |- + OAuth2 token endpoint URL. Required for all modes when creating or + rotating; uses ignore_empty so partial UpdateCredentials calls that omit + this path pass protovalidate. The handler enforces required-on-create. + type: string + title: Mcp Server Auth O Auth 2 type: object - x-speakeasy-name-override: AppEntitlementProxyExpandMask - c1.api.app.v1.AppEntitlementProxyView: - description: The AppEntitlementProxyView message. + x-speakeasy-name-override: MCPServerAuthOAuth2 + c1.api.ai_governance.v1.MCPServerCatalogAuthMode: + description: |- + MCPServerCatalogAuthMode describes a single authentication method an impl + supports. Multiple modes mean the user/admin can pick at registration time + (e.g., GitHub: bearer PAT or OAuth2). Sourced from the bundle's + connect.supported_auth_modes via the model-side mirror. properties: - appProxyEntitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxy' - dstAppEntitlementPath: - description: The dstAppEntitlementPath field. - readOnly: false - type: string - dstAppPath: - description: The dstAppPath field. - readOnly: false + authMethod: + description: Authentication method enum. UNSPECIFIED entries are dropped on the way out. + enum: + - MCP_SERVER_AUTH_METHOD_UNSPECIFIED + - MCP_SERVER_AUTH_METHOD_NONE + - MCP_SERVER_AUTH_METHOD_BEARER_TOKEN + - MCP_SERVER_AUTH_METHOD_OAUTH2 + - MCP_SERVER_AUTH_METHOD_CUSTOM_HEADER + - MCP_SERVER_AUTH_METHOD_AWS_SIGV4 + - MCP_SERVER_AUTH_METHOD_BASIC_AUTH type: string - srcAppEntitlementPath: - description: The srcAppEntitlementPath field. - readOnly: false + x-speakeasy-unknown-values: allow + authStyle: + description: |- + Credential placement on the OAuth2 token request. Allowed values: + "in_params" (form body), "in_header" (HTTP Basic), or empty + (autodetect). Set by the impl bundle and shown read-only on the form. type: string - srcAppPath: - description: The srcAppPath field. - readOnly: false + authorizeUrl: + description: OAuth2 authorization endpoint URL. Empty for non-OAuth2 methods. type: string - title: App Entitlement Proxy View - type: object - x-speakeasy-name-override: AppEntitlementProxyView - c1.api.app.v1.AppEntitlementRef: - description: The AppEntitlementRef message. - properties: - appId: - description: The appId field. - readOnly: false + credentialUrl: + description: |- + Documentation URL where the user can obtain a credential for this method + (e.g., a link to the SaaS app's "create API token" page). Empty if not set. type: string - id: - description: The id field. - readOnly: false + description: + description: |- + Optional admin-facing hint describing the use case this mode targets + (e.g. "Per user OAuth option"). type: string - title: App Entitlement Ref - type: object - x-speakeasy-name-override: AppEntitlementRef - c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsRequest: - description: The AppEntitlementSearchServiceSearchGrantsRequest message. - properties: - appIds: - description: Search for grants contained in any of these apps. - items: - type: string - nullable: true - readOnly: false - type: array - appUserIds: - description: Search for grants that are granted to any of these app user ids. - items: + extraAuthorizeParams: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - entitlementRefs: - description: Search for grants of an entitlement - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - entitlementSlugs: - description: Filter for entitlements whose slug is in this list (e.g. "enrollment" for access profiles) - items: + description: |- + Static query params the bundle declares for the authorize URL + (e.g. Notion `owner=user`). authorization_code grant only. Surfaced + read-only so the form can pre-populate its editable copy. + type: object + extraTokenParams: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + description: |- + Extra body params the bundle declares for the OAuth2 token request + (e.g. Auth0/Wiz `audience`). Surfaced read-only so the registration + form can pre-populate its editable copy on MCPServerAuthOAuth2. + type: object + header: + description: |- + Header name for api_key / custom-header methods. Prefills the form's + header-name field. Empty falls back to the C1 default. type: string - purpose: - description: Filter for entitlements with these purposes (e.g., ASSIGNMENT for membership entitlements) - items: - enum: - - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED - - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT - - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION - - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - resourceIds: - description: Search for grants within a resource. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeIds: - description: Search grants for given resource types. + issuerUrl: + description: OAuth2 issuer URL (used for OIDC discovery). Empty when not an OIDC issuer. + type: string + jwtAudience: + description: JWT-bearer assertion audience when it differs from token_url. + type: string + oauth2Grant: + description: |- + OAuth2 grant for this mode. Prefills the form's OAuth2 mode selection. + Raw bundle string: "client_credentials", "authorization_code", + "jwt_bearer", "google_service_account", or empty (infer from authorize_url). + type: string + passthrough: + description: |- + Per-user OAuth: each user authorizes individually instead of sharing a + service-level credential. Only meaningful for OAuth2. + type: boolean + pkce: + description: |- + PKCE behavior for authorization_code: "discover" (or empty), "s256", or + "disabled". Set by the impl bundle and shown read-only on the form. + type: string + scopes: + description: OAuth2 scopes requested by this method. Empty for non-OAuth2 methods. items: type: string - nullable: true - readOnly: false - type: array - userId: - description: Search for grants of a user - readOnly: false + type: + - array + - "null" + tokenUrl: + description: OAuth2 token endpoint URL. Empty for non-OAuth2 methods. type: string - title: App Entitlement Search Service Search Grants Request + title: Mcp Server Catalog Auth Mode type: object - x-speakeasy-name-override: AppEntitlementSearchServiceSearchGrantsRequest - c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsResponse: - description: The AppEntitlementSearchServiceSearchGrantsResponse message. + x-speakeasy-name-override: MCPServerCatalogAuthMode + c1.api.ai_governance.v1.MCPServerCatalogConfigField: + description: MCPServerCatalogConfigField describes a single extra configuration field for an MCP server catalog entry. properties: - expanded: - description: The expanded field. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementWithUserBinding' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + default: + description: Default value the registration form prefills. Ignored when secret. type: string - title: App Entitlement Search Service Search Grants Response - type: object - x-speakeasy-name-override: AppEntitlementSearchServiceSearchGrantsResponse - c1.api.app.v1.AppEntitlementSearchServiceSearchRequest: - description: Search app entitlements by a variety of filters. - properties: - accessReviewId: - description: Search for app entitlements that are being reviewed as part of this access review campaign. - readOnly: false + description: + description: Help text describing the field. type: string - alias: - description: Search for app entitlements that have this alias (exact match). - readOnly: false + displayName: + description: Human-readable label for the field. type: string - appIds: - description: Search for app entitlements contained in any of these apps. + name: + description: Machine-readable field name (used as the map key in config_fields). + type: string + placeholder: + description: Placeholder text shown in an empty input. + type: string + required: + description: Whether this field must be provided. + type: boolean + secret: + description: Whether the field value should be treated as a secret (e.g. masked in UI). + type: boolean + title: Mcp Server Catalog Config Field + type: object + x-speakeasy-name-override: MCPServerCatalogConfigField + c1.api.ai_governance.v1.MCPServerCatalogConfigSchema: + description: MCPServerCatalogConfigSchema describes extra configuration fields beyond auth. + properties: + fields: + description: The fields field. items: - type: string - nullable: true - readOnly: false - type: array - appUserIds: - description: Search for app entitlements that are granted to any of these app user ids. + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerCatalogConfigField' + type: + - array + - "null" + title: Mcp Server Catalog Config Schema + type: object + x-speakeasy-name-override: MCPServerCatalogConfigSchema + c1.api.ai_governance.v1.MCPServerCatalogEntry: + description: MCPServerCatalogEntry describes a supported MCP server in the catalog. + properties: + authModes: + description: |- + Authentication methods this server supports. The first entry is the + catalog-prescribed default. Empty when the impl declares no auth. items: - type: string - nullable: true - readOnly: false - type: array - complianceFrameworkIds: - description: Search for app entitlements that are part of these compliance frameworks. + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerCatalogAuthMode' + type: + - array + - "null" + baseUrl: + description: |- + Connection base URL declared by the impl. May be a ${VAR} template over + config_schema fields (e.g. "https://${workspace}.app.n8n.cloud/mcp-server/http"); + the UI substitutes the admin's config-field values to preview the resolved + endpoint. Empty when the impl declares no base URL. + type: string + channel: + description: Release channel for this catalog entry. + enum: + - MCP_SERVER_CATALOG_CHANNEL_UNSPECIFIED + - MCP_SERVER_CATALOG_CHANNEL_STABLE + - MCP_SERVER_CATALOG_CHANNEL_BETA + - MCP_SERVER_CATALOG_CHANNEL_ALPHA + type: string + x-speakeasy-unknown-values: allow + configSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerCatalogConfigSchema' + - type: "null" + defaultAuthMethod: + deprecated: true + description: 'Deprecated: read auth_modes instead.' + enum: + - MCP_SERVER_AUTH_METHOD_UNSPECIFIED + - MCP_SERVER_AUTH_METHOD_NONE + - MCP_SERVER_AUTH_METHOD_BEARER_TOKEN + - MCP_SERVER_AUTH_METHOD_OAUTH2 + - MCP_SERVER_AUTH_METHOD_CUSTOM_HEADER + - MCP_SERVER_AUTH_METHOD_AWS_SIGV4 + - MCP_SERVER_AUTH_METHOD_BASIC_AUTH + type: string + x-speakeasy-unknown-values: allow + defaultAuthorizeUrl: + deprecated: true + description: 'Deprecated: read the OAUTH2 entry''s authorize_url from auth_modes instead.' + type: string + defaultScopes: + deprecated: true + description: 'Deprecated: read the OAUTH2 entry''s scopes from auth_modes instead.' items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" + defaultTokenUrl: + deprecated: true + description: 'Deprecated: read the OAUTH2 entry''s token_url from auth_modes instead.' + type: string + description: + description: Short description of what the MCP server does. + type: string displayName: - description: Filter results to entitlements with this exact display name. - readOnly: false + description: Human-readable display name. type: string - excludeAppIds: - description: Exclude app entitlements from the results that are in these app IDs. + iconUrl: + description: Icon URL (e.g. "/static/app-icons/datadog.svg"). + type: string + id: + description: Opaque catalog entry identifier (27-character KSUID). + type: string + maturity: + description: Implementation maturity level. + enum: + - MCP_SERVER_CATALOG_MATURITY_UNSPECIFIED + - MCP_SERVER_CATALOG_MATURITY_STUB + - MCP_SERVER_CATALOG_MATURITY_GENERATED + - MCP_SERVER_CATALOG_MATURITY_VERIFIED + - MCP_SERVER_CATALOG_MATURITY_CURATED + type: string + x-speakeasy-unknown-values: allow + scope: + description: Implementation scope classification. + enum: + - MCP_SERVER_CATALOG_SCOPE_UNSPECIFIED + - MCP_SERVER_CATALOG_SCOPE_BUSINESS + - MCP_SERVER_CATALOG_SCOPE_EXCLUDED + - MCP_SERVER_CATALOG_SCOPE_UNDETERMINED + type: string + x-speakeasy-unknown-values: allow + serviceName: + description: |- + mcpgw impl service name (e.g., "datadog", "github"). Stable across + display-name changes; suitable for grouping entries that share an impl + and for matching catalog entries to a host app. For tunneled HOSTED + registrations the appliance must announce a HOSTED port whose Name field + matches this string — that's how the wormhole DialByName at runtime + resolves the right port on the appliance. + type: string + stable: + deprecated: true + description: |- + Whether this catalog entry is stable (true) or early access (false/default). + Deprecated: use channel instead. + type: boolean + supportedOauth2Modes: + description: |- + OAuth2 modes supported by this server. When non-empty, the frontend shows + only these modes in the dropdown. When empty, all modes are shown. items: + enum: + - MCP_SERVER_AUTH_OAUTH2_MODE_UNSPECIFIED + - MCP_SERVER_AUTH_OAUTH2_MODE_SERVICE + - MCP_SERVER_AUTH_OAUTH2_MODE_PASSTHROUGH + - MCP_SERVER_AUTH_OAUTH2_MODE_CLIENT_CREDENTIALS + - MCP_SERVER_AUTH_OAUTH2_MODE_JWT_BEARER + - MCP_SERVER_AUTH_OAUTH2_MODE_GOOGLE_SERVICE_ACCOUNT + - MCP_SERVER_AUTH_OAUTH2_MODE_AUTHORIZATION_CODE type: string - nullable: true - readOnly: false - type: array - excludeAppUserIds: - description: Exclude entitlements from results that are granted to any of these app users. + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Mcp Server Catalog Entry + type: object + x-speakeasy-name-override: MCPServerCatalogEntry + c1.api.ai_governance.v1.MCPServerExternalConfig: + description: | + MCPServerExternalConfig configures an external MCP server accessed via HTTP transport. + The server is routed through the MCP gateway for credential decryption. + + This message contains a oneof named auth_config. Only a single field of the following list may be set at a time: + - none + - bearerToken + - oauth2 + - customHeader + - basicAuth + properties: + basicAuth: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthBasicAuth' + - type: "null" + bearerToken: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthBearerToken' + - type: "null" + customHeader: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthCustomHeader' + - type: "null" + none: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthNone' + - type: "null" + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthOAuth2' + - type: "null" + requireToolApproval: + description: |- + Optional per-server override for tool auto-approval. See + MCPServerView.require_tool_approval for semantics. + enum: + - OPTIONAL_BOOL_UNSPECIFIED + - OPTIONAL_BOOL_TRUE + - OPTIONAL_BOOL_FALSE + type: string + x-speakeasy-unknown-values: allow + tokenSharing: + description: |- + Token sharing model. SHARED = admin authorizes once; PER_USER = each user + authenticates independently. PER_USER is supported for OAuth2 + authorization_code, bearer_token, custom_header, and basic_auth. Defaults + to SHARED at runtime. + enum: + - MCP_SERVER_TOKEN_SHARING_UNSPECIFIED + - MCP_SERVER_TOKEN_SHARING_SHARED + - MCP_SERVER_TOKEN_SHARING_PER_USER + type: string + x-speakeasy-unknown-values: allow + transportType: + description: Transport type for the MCP connection. + enum: + - MCP_SERVER_TRANSPORT_TYPE_UNSPECIFIED + - MCP_SERVER_TRANSPORT_TYPE_STREAMABLE_HTTP + - MCP_SERVER_TRANSPORT_TYPE_SSE + type: string + x-speakeasy-unknown-values: allow + url: + description: The HTTP endpoint URL of the external MCP server (HTTPS required). + type: string + title: Mcp Server External Config + type: object + x-speakeasy-name-override: MCPServerExternalConfig + c1.api.ai_governance.v1.MCPServerHostedConfig: + description: | + MCPServerHostedConfig configures a hosted MCP server backed by the MCP gateway. + + This message contains a oneof named auth_config. Only a single field of the following list may be set at a time: + - none + - bearerToken + - oauth2 + - customHeader + - googleServiceAccount + - awsSigv4 + - basicAuth + properties: + awsSigv4: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthAWSSigV4' + - type: "null" + basicAuth: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthBasicAuth' + - type: "null" + bearerToken: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthBearerToken' + - type: "null" + configFields: + additionalProperties: + type: string + description: |- + Extra config field values keyed by catalog config field name. + Sent as plaintext over TLS; the backend seals secret fields based on catalog schema. + type: object + customHeader: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthCustomHeader' + - type: "null" + googleServiceAccount: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthGoogleServiceAccount' + - type: "null" + mcpServerCatalogId: + description: |- + Opaque catalog entry ID (27-character KSUID). Obtain valid IDs from the + ListCatalog or GetCatalog RPCs. + type: string + none: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthNone' + - type: "null" + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerAuthOAuth2' + - type: "null" + requireToolApproval: + description: |- + Optional per-server override for tool auto-approval. See + MCPServerView.require_tool_approval for semantics. + enum: + - OPTIONAL_BOOL_UNSPECIFIED + - OPTIONAL_BOOL_TRUE + - OPTIONAL_BOOL_FALSE + type: string + x-speakeasy-unknown-values: allow + sourceAppId: + description: Source app ID (optional, for connector-backed servers). + type: string + tokenSharing: + description: |- + Token sharing model for the configured auth method. SHARED means the + admin authorizes once and the credential applies to every tool call; + PER_USER means each user authenticates independently. PER_USER is + supported for OAuth2 authorization-code, bearer_token, custom_header, + and basic_auth methods; sending PER_USER alongside any other auth + method is rejected with InvalidArgument. + enum: + - MCP_SERVER_TOKEN_SHARING_UNSPECIFIED + - MCP_SERVER_TOKEN_SHARING_SHARED + - MCP_SERVER_TOKEN_SHARING_PER_USER + type: string + x-speakeasy-unknown-values: allow + title: Mcp Server Hosted Config + type: object + x-speakeasy-name-override: MCPServerHostedConfig + c1.api.ai_governance.v1.MCPServerSearchWithToolCountResult: + description: MCPServerSearchWithToolCountResult wraps a server view with per-state tool counts. + properties: + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + toolCount: + description: The toolCount field. + format: int64 + type: string + title: Mcp Server Search With Tool Count Result + type: object + x-speakeasy-name-override: MCPServerSearchWithToolCountResult + c1.api.ai_governance.v1.MCPServerServiceDeleteRequestInput: + description: MCPServerServiceDeleteRequest soft-deletes an MCP server. + title: Mcp Server Service Delete Request + type: object + x-speakeasy-name-override: MCPServerServiceDeleteRequest + c1.api.ai_governance.v1.MCPServerServiceDeleteResponse: + description: MCPServerServiceDeleteResponse confirms deletion. + title: Mcp Server Service Delete Response + type: object + x-speakeasy-name-override: MCPServerServiceDeleteResponse + c1.api.ai_governance.v1.MCPServerServiceDiscoverOIDCEndpointsRequest: + description: |- + MCPServerServiceDiscoverOIDCEndpointsRequest fetches the OpenID Connect discovery + document for a given issuer URL. + properties: + issuerUrl: + description: |- + The issuer URL (e.g. "https://accounts.google.com"). The server appends + /.well-known/openid-configuration to this URL. + type: string + title: Mcp Server Service Discover Oidc Endpoints Request + type: object + x-speakeasy-name-override: MCPServerServiceDiscoverOIDCEndpointsRequest + c1.api.ai_governance.v1.MCPServerServiceDiscoverOIDCEndpointsResponse: + description: MCPServerServiceDiscoverOIDCEndpointsResponse returns the discovered OAuth2 endpoints. + properties: + authorizationEndpoint: + description: The authorization endpoint URL. + type: string + codeChallengeMethodsSupported: + description: |- + PKCE code challenge methods supported by the authorization server (RFC 8414). + Typical values: "plain", "S256". Empty when the discovery doc omits this + field. The frontend should pass the array back unchanged on save so the + backend can persist it on the connector and skip per-flow re-discovery. items: type: string - nullable: true - readOnly: false - type: array - excludeImmutable: - description: If true, exclude immutable entitlements (e.g., system-managed entitlements that cannot be modified). - readOnly: false - type: boolean - excludeResourceTypeIds: - description: Exclude entitlements with any of these resource type IDs from results. + type: + - array + - "null" + scopesSupported: + description: Scopes supported by the authorization server. items: type: string - nullable: true - readOnly: false - type: array - excludedEntitlementRefs: - description: Exclude these specific entitlements from results. + type: + - array + - "null" + tokenEndpoint: + description: The token endpoint URL. + type: string + title: Mcp Server Service Discover Oidc Endpoints Response + type: object + x-speakeasy-name-override: MCPServerServiceDiscoverOIDCEndpointsResponse + c1.api.ai_governance.v1.MCPServerServiceGetCatalogResponse: + description: MCPServerServiceGetCatalogResponse returns a single catalog entry. + properties: + catalogEntry: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerCatalogEntry' + - type: "null" + title: Mcp Server Service Get Catalog Response + type: object + x-speakeasy-name-override: MCPServerServiceGetCatalogResponse + c1.api.ai_governance.v1.MCPServerServiceGetResponse: + description: MCPServerServiceGetResponse returns a single MCP server. + properties: + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + title: Mcp Server Service Get Response + type: object + x-speakeasy-name-override: MCPServerServiceGetResponse + c1.api.ai_governance.v1.MCPServerServiceListCatalogResponse: + description: MCPServerServiceListCatalogResponse returns a paginated list of catalog entries. + properties: + list: + description: List of catalog entries. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - includeDeleted: - description: Include deleted app entitlements, this includes app entitlements that have a deleted parent object (app, app resource, app resource type) - readOnly: false - type: boolean - isAutomated: - description: If true, restrict results to entitlements that have an automation rule configured. - readOnly: false + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerCatalogEntry' + type: + - array + - "null" + nextPageToken: + description: Token for next page. + type: string + title: Mcp Server Service List Catalog Response + type: object + x-speakeasy-name-override: MCPServerServiceListCatalogResponse + c1.api.ai_governance.v1.MCPServerServiceListConnectionsResponse: + description: |- + MCPServerServiceListConnectionsResponse returns a list of passthrough-mode + MCP servers with per-user connection status. + properties: + list: + description: List of passthrough MCP servers with connection status. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPConnectionView' + type: + - array + - "null" + nextPageToken: + description: Token for next page. + type: string + title: Mcp Server Service List Connections Response + type: object + x-speakeasy-name-override: MCPServerServiceListConnectionsResponse + c1.api.ai_governance.v1.MCPServerServiceListResponse: + description: MCPServerServiceListResponse returns a paginated list of MCP servers. + properties: + list: + description: List of MCP servers. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + type: + - array + - "null" + nextPageToken: + description: Token for next page. + type: string + title: Mcp Server Service List Response + type: object + x-speakeasy-name-override: MCPServerServiceListResponse + c1.api.ai_governance.v1.MCPServerServiceRegisterRequestInput: + description: MCPServerServiceRegisterRequest creates a new MCP server (Connector + config). + properties: + acknowledgedFindingIds: + description: |- + finding_ids from the diagnostic the admin acknowledged. Each must cover a + blocking-relaxable finding on oauth_diagnostic_id. + items: + type: string + type: + - array + - "null" + appManagedStateBindingRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingRef' + - type: "null" + dataSensitivity: + description: Data sensitivity classification. + enum: + - MCP_SERVER_DATA_SENSITIVITY_UNSPECIFIED + - MCP_SERVER_DATA_SENSITIVITY_PUBLIC + - MCP_SERVER_DATA_SENSITIVITY_INTERNAL + - MCP_SERVER_DATA_SENSITIVITY_CONFIDENTIAL + - MCP_SERVER_DATA_SENSITIVITY_RESTRICTED + type: string + x-speakeasy-unknown-values: allow + description: + description: Admin-provided description. + type: string + displayName: + description: Admin-provided display name. + type: string + externalConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerExternalConfig' + - type: "null" + hostedConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerHostedConfig' + - type: "null" + oauthDiagnosticId: + description: |- + When registering a DCR (client_id_mode=DCR) hosted server, the id of the + diagnostic returned by DiscoverMCPOAuthConfig that the admin reviewed. When + set, the server uses that diagnostic as the canonical discovery result and + relaxes only the acknowledged findings. Empty preserves the strict path. + type: string + serverType: + description: The type of MCP server being registered. + enum: + - MCP_SERVER_TYPE_UNSPECIFIED + - MCP_SERVER_TYPE_HOSTED + - MCP_SERVER_TYPE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + toolPrefix: + description: |- + Optional prefix for tool names in the C1 MCP server. + Tools are exposed as "_". + When empty, the system uses an auto-derived prefix (service name or hostname). + type: string + tunnelApplianceId: + description: |- + ID of the bridge (TunnelBridge.id, a KSUID) that proxies this server. + Only set when tunneled == true; must match a bridge enrolled for this + tenant. The server resolves this at register time to an active + credential and persists that on the connector config; runtime routing + through the wormhole requester is keyed on the resolved credential. + + Cross-field invariant: proto validation uses ignore_empty:true so an + empty value passes the regex check. The service layer enforces that this + field is non-empty whenever tunneled==true (see applyTunneledRegisterResolution). + type: string + tunnelPath: + description: |- + Endpoint path on the appliance-side MCP server (e.g. "/sse", "/mcp"). + Only used for EXTERNAL servers when tunneled == true: the service + synthesizes external_config.url as http://, + since the tunnel host is the announced service name and only the admin + knows the path. Empty defaults to "/". Ignored for HOSTED and non-tunneled. + type: string + tunnelServiceName: + description: |- + Service name as declared by the appliance via AnnounceServices. Required + when tunneled == true (for both EXTERNAL and HOSTED). The frontend + populates this from a dropdown of services the picked appliance has + announced. At runtime, mcp-gateway uses this name as the wormhole + port-name argument to DialByName. + type: string + tunneled: + description: |- + Whether the MCP server is reached over a tunnel to a private appliance + instead of a public URL. type: boolean - membershipType: - description: Filter results to entitlements where the user has any of these membership types (e.g., member, owner, admin). + userIds: + description: Integration owners for the MCP server connector. items: - enum: - - APP_ENTITLEMENT_MEMBERSHIP_TYPE_UNSPECIFIED - - APP_ENTITLEMENT_MEMBERSHIP_TYPE_MEMBER - - APP_ENTITLEMENT_MEMBERSHIP_TYPE_OWNER - - APP_ENTITLEMENT_MEMBERSHIP_TYPE_EXCLUSION - - APP_ENTITLEMENT_MEMBERSHIP_TYPE_ADMIN type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - onlyGetExpiring: - description: If true, restrict results to entitlements that have at least one expiring grant. - readOnly: false + type: + - array + - "null" + title: Mcp Server Service Register Request + type: object + x-speakeasy-name-override: MCPServerServiceRegisterRequest + c1.api.ai_governance.v1.MCPServerServiceRegisterResponse: + description: MCPServerServiceRegisterResponse returns the newly created MCP server. + properties: + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + title: Mcp Server Service Register Response + type: object + x-speakeasy-name-override: MCPServerServiceRegisterResponse + c1.api.ai_governance.v1.MCPServerServiceResyncToolsRequestInput: + description: |- + MCPServerServiceResyncToolsRequest re-runs tool discovery for the calling + user's own credential on a per-user MCP server. + title: Mcp Server Service Resync Tools Request + type: object + x-speakeasy-name-override: MCPServerServiceResyncToolsRequest + c1.api.ai_governance.v1.MCPServerServiceResyncToolsResponse: + description: MCPServerServiceResyncToolsResponse is empty on success. + title: Mcp Server Service Resync Tools Response + type: object + x-speakeasy-name-override: MCPServerServiceResyncToolsResponse + c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountRequestInput: + description: |- + MCPServerServiceSearchWithToolCountRequest searches MCP servers for an app with + filters and returns per-server tool counts by state. + properties: + includeLastCalledAt: + description: |- + When true, the server populates MCPServerView.last_called_at on each + returned row by querying TSDB for the most recent `mcp_tool_calls` + raw emit time per (app_id, connector_id). Costs one Dynamo Limit(1) + read per row; callers that don't render the "Last used" value should + leave false. type: boolean pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: Page size (max 100). format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: Page token for pagination. type: string - policyRefs: - description: Search for app entitlements that use any of these policies. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' - nullable: true - readOnly: false - type: array query: - description: Query the app entitlements with a fuzzy search on display name and description. - readOnly: false + description: Optional text query matched against display_name. type: string - refs: - description: Filter results to only these specific entitlements. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - resourceIds: - description: Search for app entitlements that belongs to these resources. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTraitIds: - description: Filter results to entitlements whose resource types have any of these trait IDs. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeIds: - description: Search for app entitlements that are for items with resources types that have matching names. Example names are "group", "role", and "app". - items: - type: string - nullable: true - readOnly: false - type: array - riskLevelIds: - description: Search for app entitlements with these risk levels. - items: - type: string - nullable: true - readOnly: false - type: array - sourceConnectorId: - description: Filter results to entitlements synced from this connector. - readOnly: false + toolState: + description: Which tool state to return count for on each server. + enum: + - MCP_TOOL_STATE_UNSPECIFIED + - MCP_TOOL_STATE_PENDING_REVIEW + - MCP_TOOL_STATE_APPROVED + - MCP_TOOL_STATE_DISABLED + - MCP_TOOL_STATE_REMOVED type: string - title: App Entitlement Search Service Search Request + x-speakeasy-unknown-values: allow + title: Mcp Server Service Search With Tool Count Request type: object - x-speakeasy-name-override: AppEntitlementSearchServiceSearchRequest - c1.api.app.v1.AppEntitlementSearchServiceSearchResponse: - description: The AppEntitlementSearchServiceSearchResponse message. + x-speakeasy-name-override: MCPServerServiceSearchWithToolCountRequest + c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountResponse: + description: MCPServerServiceSearchWithToolCountResponse returns matching MCP servers with tool counts. properties: - expanded: - description: List of related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - facets: - $ref: '#/components/schemas/c1.api.search.v1.Facets' list: - description: List of app entitlement view objects. + description: Matching servers with counts. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerSearchWithToolCountResult' + type: + - array + - "null" nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: Token for next page. type: string - title: App Entitlement Search Service Search Response + title: Mcp Server Service Search With Tool Count Response type: object - x-speakeasy-name-override: AppEntitlementSearchServiceSearchResponse - c1.api.app.v1.AppEntitlementServiceGetAutomationResponse: - description: The AppEntitlementServiceGetAutomationResponse message. + x-speakeasy-name-override: MCPServerServiceSearchWithToolCountResponse + c1.api.ai_governance.v1.MCPServerServiceTestConnectionRequest: + description: |- + MCPServerServiceTestConnectionRequest exercises an + MCPServerExternalConfig against the upstream server and reports whether + the supplied URL + transport + credentials accept a real MCP + initialize + tools/list. properties: - AppEntitlementAutomation: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' - title: App Entitlement Service Get Automation Response + appId: + description: |- + App ID of an existing external MCP connector. When set together with + connector_id, the request runs in edit mode (see above). + type: string + connectorId: + description: |- + Connector ID of an existing external MCP connector. When set together + with app_id, the request runs in edit mode (see above). + type: string + externalConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerExternalConfig' + - type: "null" + updateMask: + type: + - string + - "null" + title: Mcp Server Service Test Connection Request type: object - x-speakeasy-name-override: AppEntitlementServiceGetAutomationResponse - c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput: - description: | - The AppEntitlementServiceUpdateAutomationRequest message. - - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - none - - entitlements - - cel - - basic + x-speakeasy-name-override: MCPServerServiceTestConnectionRequest + c1.api.ai_governance.v1.MCPServerServiceTestConnectionResponse: + description: The MCPServerServiceTestConnectionResponse message. properties: - basic: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleBasic' - cel: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleCEL' - description: - description: The description of the app entitlement. - readOnly: false + failureReason: + description: |- + Sanitized, human-readable explanation of why the probe failed, set + only when reachable=false (e.g. "MCP server unreachable or rejected + the credentials (HTTP 401 Unauthorized)"). Empty when reachable=true. + Never contains raw upstream response bytes. type: string - displayName: - description: The display name of the app entitlement. - readOnly: false + reachable: + description: |- + True when the MCP initialize handshake AND a tools/list call both + succeeded against the upstream with the supplied credentials. False + when the probe ran but the upstream was unreachable or rejected the + request — see failure_reason. Malformed requests (missing/invalid + config, bad permissions) are returned as a gRPC error, not + reachable=false. + type: boolean + toolCount: + description: |- + Number of tools advertised by the upstream's tools/list response. + Zero when reachable=false; can also legitimately be zero when the + server is reachable but exposes no tools. int64 to match + MCPServerSearchWithToolCountResult.tool_count. + format: int64 type: string - entitlements: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleEntitlement' - none: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleNone' + title: Mcp Server Service Test Connection Response + type: object + x-speakeasy-name-override: MCPServerServiceTestConnectionResponse + c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsRequestInput: + description: |- + MCPServerServiceUpdateCredentialsRequest updates the auth credentials and config fields + for an existing MCP server. Secrets are sealed before storage. + properties: + externalConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerExternalConfig' + - type: "null" + hostedConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerHostedConfig' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string - title: App Entitlement Service Update Automation Request + type: + - string + - "null" + title: Mcp Server Service Update Credentials Request + type: object + x-speakeasy-name-override: MCPServerServiceUpdateCredentialsRequest + c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsResponse: + description: MCPServerServiceUpdateCredentialsResponse returns the updated MCP server. + properties: + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + title: Mcp Server Service Update Credentials Response + type: object + x-speakeasy-name-override: MCPServerServiceUpdateCredentialsResponse + c1.api.ai_governance.v1.MCPServerServiceUpdateRequestInput: + description: MCPServerServiceUpdateRequest updates an existing MCP server's editable fields. + properties: + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + updateMask: + type: + - string + - "null" + title: Mcp Server Service Update Request type: object - x-speakeasy-name-override: AppEntitlementServiceUpdateAutomationRequest - c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse: - description: The AppEntitlementServiceUpdateAutomationResponse message. + x-speakeasy-name-override: MCPServerServiceUpdateRequest + c1.api.ai_governance.v1.MCPServerServiceUpdateResponse: + description: MCPServerServiceUpdateResponse returns the updated MCP server. properties: - AppEntitlementAutomation: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' - title: App Entitlement Service Update Automation Response + mcpServer: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerView' + - type: "null" + title: Mcp Server Service Update Response type: object - x-speakeasy-name-override: AppEntitlementServiceUpdateAutomationResponse - c1.api.app.v1.AppEntitlementUserBinding: - description: The AppEntitlementUserBinding represents the relationship that gives an app user access to an app entitlement + x-speakeasy-name-override: MCPServerServiceUpdateResponse + c1.api.ai_governance.v1.MCPServerView: + description: MCPServerView is the API representation of an MCP server (backed by a Connector). properties: - appEntitlementId: - description: The ID of the app entitlement that the app user has access to - readOnly: false - type: string appId: - description: The ID of the app associated with the app entitlement - readOnly: false + description: App identifier that owns this MCP server. type: string - appUserId: - description: The ID of the app user that has access to the app entitlement - readOnly: false + authMethod: + description: Authentication method in use. Read-only; derived from stored config. + enum: + - MCP_SERVER_AUTH_METHOD_UNSPECIFIED + - MCP_SERVER_AUTH_METHOD_NONE + - MCP_SERVER_AUTH_METHOD_BEARER_TOKEN + - MCP_SERVER_AUTH_METHOD_OAUTH2 + - MCP_SERVER_AUTH_METHOD_CUSTOM_HEADER + - MCP_SERVER_AUTH_METHOD_AWS_SIGV4 + - MCP_SERVER_AUTH_METHOD_BASIC_AUTH + type: string + x-speakeasy-unknown-values: allow + awsAccessKeyId: + description: |- + AWS SigV4 access key ID (the public half of the credential pair). + Read-only; derived from stored config. Surfaced so the edit form can + pre-fill the field on load without exposing the sealed secret. + readOnly: true + type: string + awsSecretAccessKeyConfigured: + description: Whether an AWS SigV4 secret access key is configured. Read-only. + readOnly: true + type: boolean + awsSessionTokenConfigured: + description: |- + Whether an AWS SigV4 session token is configured (optional, only for + STS temporary credentials). Read-only. + readOnly: true + type: boolean + basicAuthPasswordConfigured: + description: |- + Whether a basic-auth password is configured (admin-supplied for SHARED, + irrelevant for PER_USER). Read-only; derived from stored config. + readOnly: true + type: boolean + basicAuthUsername: + description: The username configured for basic-auth. Read-only. + readOnly: true + type: string + bearerTokenConfigured: + description: |- + Whether a bearer-token credential is configured (admin-supplied for + SHARED, irrelevant for PER_USER). Read-only; derived from stored config. + Mirrors oauth2_credentials_configured for the bearer-token auth method + so the edit form can render the password input as "configured" without + exposing the sealed bytes. + readOnly: true + type: boolean + configFieldValues: + additionalProperties: + type: string + description: |- + Non-secret configuration field values keyed by catalog config field name. + Read-only; populated from the stored config. Secret fields are omitted. + readOnly: true + type: object + connectorId: + description: Unique identifier (connector ID). type: string createdAt: format: date-time readOnly: true + type: + - string + - "null" + credentialsSetupUrl: + description: |- + Deep link to the server's detail page in the C1 admin UI, where an admin + enters or rotates credentials in the browser. Lets an agent hand its human + a clickable link for credential entry so the secret value never transits + the agent transcript. Empty when the tenant frontend URL can't be resolved. + Read-only. + readOnly: true type: string - deletedAt: - format: date-time + customHeaderName: + description: |- + The HTTP header name configured for custom-header auth. Read-only; + derived from stored config. Surfaced so the admin edit form can + pre-fill the field on load — without this, the form shows blank and + the admin has to retype it on every edit (which loses the value if + they only meant to flip token_sharing). readOnly: true type: string - deprovisionAt: - format: date-time + customHeaderValueConfigured: + description: |- + Whether a custom-header value is configured (admin-supplied for SHARED, + irrelevant for PER_USER). Read-only; derived from stored config. readOnly: true + type: boolean + dataSensitivity: + description: Data sensitivity classification. + enum: + - MCP_SERVER_DATA_SENSITIVITY_UNSPECIFIED + - MCP_SERVER_DATA_SENSITIVITY_PUBLIC + - MCP_SERVER_DATA_SENSITIVITY_INTERNAL + - MCP_SERVER_DATA_SENSITIVITY_CONFIDENTIAL + - MCP_SERVER_DATA_SENSITIVITY_RESTRICTED type: string - grantSources: - description: The grantSources field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: App Entitlement User Binding - type: object - x-speakeasy-name-override: AppEntitlementUserBinding - c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask: - description: The AppEntitlementUserBindingExpandHistoryMask message. - properties: - paths: - description: The paths field. - items: - type: string - nullable: true - readOnly: false - type: array - title: App Entitlement User Binding Expand History Mask - type: object - x-speakeasy-name-override: AppEntitlementUserBindingExpandHistoryMask - c1.api.app.v1.AppEntitlementUserBindingFeed: - description: The AppEntitlementUserBindingFeed message. - properties: - appEntitlementId: - description: The ID of the app entitlement that the app user has access to - readOnly: false + x-speakeasy-unknown-values: allow + defaultToolPrefix: + description: |- + Default tool-name prefix used when tool_prefix is unset (the hosted impl's + server_prefix / service name); empty for external or legacy servers. Read-only. + readOnly: true type: string - appId: - description: The ID of the app associated with the app entitlement - readOnly: false + description: + description: Admin-provided description. type: string - appUserId: - description: The ID of the app user that has access to the app entitlement - readOnly: false + displayName: + description: Admin-provided display name. type: string - date: + endpointUrl: + description: Endpoint URL for external MCP servers. Read-only. + readOnly: true + type: string + lastCalledAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + mcpServerCatalogId: + description: |- + Opaque catalog entry ID for hosted MCP servers (27-character KSUID). + Obtain valid IDs from the ListCatalog or GetCatalog RPCs. type: string - eventType: - description: The eventType field. + oauth2AuthorizeUrl: + description: OAuth2 authorization URL. Read-only; derived from stored config. + readOnly: true + type: string + oauth2ClientId: + description: OAuth2 client ID (non-secret). Read-only; derived from stored config. + readOnly: true + type: string + oauth2ClientIdMode: + description: |- + How the OAuth2 client_id was acquired (manual / DCR / CIMD). Read-only; + derived from stored config. Empty for non-authorization_code servers. enum: - - GRANT_EVENT_TYPE_UNSPECIFIED - - GRANT_EVENT_TYPE_ADDED - - GRANT_EVENT_TYPE_REMOVED - readOnly: false + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_UNSPECIFIED + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_DCR + - MCP_SERVER_AUTH_OAUTH2_CLIENT_ID_MODE_CIMD + readOnly: true type: string x-speakeasy-unknown-values: allow - ticketId: - description: The ticketId field. - readOnly: false + oauth2ClientSecretExpiresAt: + description: |- + RFC 7591 client_secret expiry (unix seconds; 0 = never). Read-only; + derived from stored config. Surfaced for display only. + format: int64 + readOnly: true type: string - title: App Entitlement User Binding Feed - type: object - x-speakeasy-name-override: AppEntitlementUserBindingFeed - c1.api.app.v1.AppEntitlementUserBindingFeedView: - description: The AppEntitlementUserBindingFeedView message. - properties: - appPath: - description: The appPath field. - readOnly: false + oauth2CodeChallengeMethodsSupported: + description: |- + PKCE code-challenge methods the IdP advertised at registration. + Read-only; derived from stored config. Surfaced so the edit form's + change detection can compare against the saved value rather than an + implicit empty default — without this, re-running Discover on a + server with stable methods always reports the field as changed and + fires a spurious UpdateCredentials. + items: + type: string + readOnly: true + type: + - array + - "null" + oauth2CredentialsConfigured: + description: Whether OAuth2 client credentials (client_id + client_secret) are configured. Read-only. + readOnly: true + type: boolean + oauth2ExtraAuthorizeParams: + additionalProperties: + type: string + description: |- + Static query params appended to the OAuth2 authorize URL. Read-only on the + view; the edit form surfaces this as an editable key/value list. Empty for + non-authorization_code servers. + readOnly: true + type: object + oauth2ExtraTokenParams: + additionalProperties: + type: string + description: |- + Extra body params POSTed to the OAuth2 token endpoint. Read-only on the + view; the edit form takes this value and surfaces it as an editable + key/value list. Empty for non-OAuth2 / non-client-credentials servers. + readOnly: true + type: object + oauth2IssuerUrl: + description: |- + OAuth2 issuer URL. Read-only; derived from stored config. Surfaced so + the registration UI can prefill the Discover input box on edit. + readOnly: true type: string - appUserPath: - description: The appUserPath field. - readOnly: false + oauth2JwtAudience: + description: JWT audience claim. Read-only. + readOnly: true type: string - entitlementPath: - description: The entitlementPath field. - readOnly: false + oauth2JwtIssuer: + description: JWT issuer (service account email). Read-only. + readOnly: true type: string - feed: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingFeed' - ticketPath: - description: The ticketPath field. - readOnly: false + oauth2JwtPrivateKeyConfigured: + description: Whether a JWT private key is configured. Read-only. + readOnly: true + type: boolean + oauth2JwtSubject: + description: JWT subject (domain-wide delegation). Read-only. + readOnly: true type: string - title: App Entitlement User Binding Feed View - type: object - x-speakeasy-name-override: AppEntitlementUserBindingFeedView - c1.api.app.v1.AppEntitlementUserBindingHistory: - description: The AppEntitlementUserBindingHistory message. - properties: - appEntitlementId: - description: The ID of the app entitlement that the app user has access to - readOnly: false + oauth2Mode: + description: OAuth2 mode in use. Read-only; derived from stored config. + enum: + - MCP_SERVER_AUTH_OAUTH2_MODE_UNSPECIFIED + - MCP_SERVER_AUTH_OAUTH2_MODE_SERVICE + - MCP_SERVER_AUTH_OAUTH2_MODE_PASSTHROUGH + - MCP_SERVER_AUTH_OAUTH2_MODE_CLIENT_CREDENTIALS + - MCP_SERVER_AUTH_OAUTH2_MODE_JWT_BEARER + - MCP_SERVER_AUTH_OAUTH2_MODE_GOOGLE_SERVICE_ACCOUNT + - MCP_SERVER_AUTH_OAUTH2_MODE_AUTHORIZATION_CODE + readOnly: true type: string - appId: - description: The ID of the app associated with the app entitlement - readOnly: false + x-speakeasy-unknown-values: allow + oauth2Pkce: + description: |- + PKCE behavior for authorization_code mode: "discover" (or empty), "s256", + or "disabled". Read-only on the view. Empty for non-authorization_code servers. + readOnly: true type: string - appUserId: - description: The ID of the app user that has access to the app entitlement - readOnly: false + oauth2Scopes: + description: OAuth2 scopes. Read-only; derived from stored config. + items: + type: string + readOnly: true + type: + - array + - "null" + oauth2ScopesSupported: + description: |- + OAuth scopes the IdP advertised in its discovery doc at the most + recent Discover. Read-only; derived from stored config. Surfaced so + the edit form can populate the Scopes chips-input autocomplete from + a previously-discovered list without forcing the admin to re-run + Discover. Distinct from oauth2_scopes (= the requested subset). + items: + type: string + readOnly: true + type: + - array + - "null" + oauth2ServiceAuthorized: + description: Whether a service-mode OAuth2 credential exists. Read-only. + readOnly: true + type: boolean + oauth2ServiceAuthorizedAsEmail: + description: Email of the external identity authorized (from ID token). Read-only. + readOnly: true type: string - grantedAt: - format: date-time + oauth2ServiceAuthorizedAsName: + description: Display name of the external identity authorized (from ID token). Read-only. readOnly: true type: string - revokedAt: + oauth2ServiceAuthorizedAt: format: date-time readOnly: true + type: + - string + - "null" + oauth2ServiceAuthorizedBy: + description: Passport user ID of who authorized the service-mode OAuth2 credential. Read-only. + readOnly: true type: string - title: App Entitlement User Binding History - type: object - x-speakeasy-name-override: AppEntitlementUserBindingHistory - c1.api.app.v1.AppEntitlementUserBindingHistoryView: - description: The AppEntitlementUserBindingHistoryView message. - properties: - appPath: - description: The appPath field. - readOnly: false + oauth2TokenEndpointAuthMethod: + description: |- + RFC 7591 token_endpoint_auth_method the authorization server assigned + ("none" for public PKCE-only clients). Read-only; server-set from the DCR + result. Empty for manual / non-DCR servers. + readOnly: true type: string - appUserPath: - description: The appUserPath field. - readOnly: false + oauth2TokenUrl: + description: OAuth2 token URL. Read-only; derived from stored config. + readOnly: true type: string - entitlementPath: - description: The entitlementPath field. - readOnly: false + requireToolApproval: + description: Per-server override for tool auto-approval. + enum: + - OPTIONAL_BOOL_UNSPECIFIED + - OPTIONAL_BOOL_TRUE + - OPTIONAL_BOOL_FALSE type: string - history: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingHistory' - title: App Entitlement User Binding History View - type: object - x-speakeasy-name-override: AppEntitlementUserBindingHistoryView - c1.api.app.v1.AppEntitlementUserView: - description: The AppEntitlementUserView (aka grant view) describes the relationship between an app user and an entitlement. They have more recently been referred to as grants. - properties: - appEntitlementUserBindingCreatedAt: - format: date-time - readOnly: true + x-speakeasy-unknown-values: allow + serverType: + description: Whether this is a hosted MCP server. + enum: + - MCP_SERVER_TYPE_UNSPECIFIED + - MCP_SERVER_TYPE_HOSTED + - MCP_SERVER_TYPE_EXTERNAL type: string - appEntitlementUserBindingDeprovisionAt: - format: date-time + x-speakeasy-unknown-values: allow + sourceAppId: + description: Source app ID (hosted servers only). + type: string + tokenSharing: + description: |- + Token sharing model in use. Read-only; derived from stored config. + For rows stored under the legacy SERVICE/PASSTHROUGH OAuth2 modes, + this is synthesized as SHARED/PER_USER respectively. + enum: + - MCP_SERVER_TOKEN_SHARING_UNSPECIFIED + - MCP_SERVER_TOKEN_SHARING_SHARED + - MCP_SERVER_TOKEN_SHARING_PER_USER readOnly: true type: string - appUser: - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' - grantSources: - description: List of sources for the grant, ie. groups, roles, etc. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - originatingTicketId: - description: The originating ticket ID for the grant (e.g. from a request ticket). - readOnly: false + x-speakeasy-unknown-values: allow + toolPrefix: + description: |- + Admin-configured prefix for tool names in the C1 MCP server. + Tools are exposed as "_". + When empty, the system uses an auto-derived prefix (service name or hostname). type: string - title: App Entitlement User View - type: object - x-speakeasy-name-override: AppEntitlementUserView - c1.api.app.v1.AppEntitlementView: - description: The app entitlement view contains the serialized app entitlement and paths to objects referenced by the app entitlement. - properties: - appEntitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' - appPath: - description: JSONPATH expression indicating the location of the App object in the array. - readOnly: false + transportType: + description: Transport type for external MCP servers. Read-only. + enum: + - MCP_SERVER_TRANSPORT_TYPE_UNSPECIFIED + - MCP_SERVER_TRANSPORT_TYPE_STREAMABLE_HTTP + - MCP_SERVER_TRANSPORT_TYPE_SSE + readOnly: true type: string - appResourcePath: - description: JSONPATH expression indicating the location of the App Resource Type object in the expanded array. - readOnly: false + x-speakeasy-unknown-values: allow + tunnelApplianceId: + description: |- + Credential id (cutename) used to route tool calls through the bridge. + Set only when tunneled == true. Read-only. + readOnly: true type: string - appResourceTypePath: - description: JSONPATH expression indicating the location of the App Resource object in the array. - readOnly: false + tunnelBridgeId: + description: |- + ID of the bridge (TunnelConnection.id, a KSUID) that proxies this server. + Set only when tunneled == true. Read-only. + readOnly: true type: string - objectPermissions: - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' - title: App Entitlement View + tunnelServiceName: + description: |- + Bridge-announced service name used to route to this server. Set only + when tunneled == true. Read-only. + readOnly: true + type: string + tunneled: + description: |- + Whether the MCP server is reached over a tunnel to a private bridge + appliance instead of a public URL. Read-only. + readOnly: true + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Mcp Server View type: object - x-speakeasy-name-override: AppEntitlementView - c1.api.app.v1.AppEntitlementWithExpired: - description: A grant with its expiry and discovery timestamps, along with the associated app user and ConductorOne user. + x-speakeasy-name-override: MCPServerView + c1.api.ai_governance.v1.MCPTool: + description: MCPTool represents metadata about individual tools discovered from an MCP server. properties: + allowedClientTypes: + description: |- + Which client types may use this tool. + Empty = all allowed types from tenant config. + items: + enum: + - MCP_CLIENT_TYPE_UNSPECIFIED + - MCP_CLIENT_TYPE_PERSONAL + - MCP_CLIENT_TYPE_SHARED + - MCP_CLIENT_TYPE_SERVICE + - MCP_CLIENT_TYPE_EPHEMERAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" appEntitlementId: - description: The ID of the app entitlement. - readOnly: false + description: Bound AppEntitlement created during sync. type: string appId: - description: The ID of the app that contains the entitlement. - readOnly: false + description: App identifier (app that owns the connector). type: string - appUser: - $ref: '#/components/schemas/c1.api.app.v1.AppUser' - appUserId: - description: The ID of the app user who holds the grant. - readOnly: false + classification: + description: Tool risk classification for policy decisions. + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS type: string - discovered: + x-speakeasy-unknown-values: allow + connectorId: + description: Connector identifier. + type: string + createdAt: format: date-time - readOnly: false + type: + - string + - "null" + defaultClassification: + description: Default tool classification from MCP config (system-managed during discovery). + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS type: string - expired: + x-speakeasy-unknown-values: allow + defaultDisplayName: + description: Default display name from MCP tool spec (title field). + type: string + defaultVisibility: + description: System-managed default visibility from MCP config (set during discovery). + enum: + - TOOL_VISIBILITY_UNSPECIFIED + - TOOL_VISIBILITY_FEATURED + - TOOL_VISIBILITY_AVAILABLE + - TOOL_VISIBILITY_BYPASSED + type: string + x-speakeasy-unknown-values: allow + deletedAt: format: date-time - readOnly: false + type: + - string + - "null" + description: + description: Admin-editable description. type: string - grantReasons: - description: The reasons this grant was given (e.g., access request, automation). - items: - $ref: '#/components/schemas/c1.api.app.v1.GrantReason' - nullable: true - readOnly: false - type: array - grantSources: - description: Entitlements that are the source of this grant (e.g., a group membership that implies a role). - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: App Entitlement With Expired - type: object - x-speakeasy-name-override: AppEntitlementWithExpired - c1.api.app.v1.AppEntitlementWithUserBinding: - description: The AppEntitlementWithUserBinding message. - properties: - appEntitlementUserBinding: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserView' - entitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - title: App Entitlement With User Binding - type: object - x-speakeasy-name-override: AppEntitlementWithUserBinding - c1.api.app.v1.AppManagedStateBindingRef: - description: The AppManagedStateBindingRef message. - properties: - appId: - description: The appId field. - readOnly: false + discoveryHash: + description: Hash of tool definition for change detection. type: string - resourceId: - description: The resourceId field. - readOnly: false + displayName: + description: Admin-editable display name (overrides default_display_name when set). type: string - resourceTypeId: - description: The resourceTypeId field. - readOnly: false + id: + description: Unique identifier for this MCP tool record. type: string - title: App Managed State Binding Ref - type: object - x-speakeasy-name-override: AppManagedStateBindingRef - c1.api.app.v1.AppPopulationReport: - description: The AppPopulationReport is a generated report for a specific app that gives details about the app's users. These details include what groups, roles, and other entitlements the users have access to. - properties: - appId: - description: The appId is the Id of the app which the report is generated for. - readOnly: false + inputSchemaJson: + description: JSON-encoded input schema from MCP discovery. type: string - createdAt: + lastCalledAt: format: date-time readOnly: true + type: + - string + - "null" + state: + description: Tool approval/lifecycle state. + enum: + - MCP_TOOL_STATE_UNSPECIFIED + - MCP_TOOL_STATE_PENDING_REVIEW + - MCP_TOOL_STATE_APPROVED + - MCP_TOOL_STATE_DISABLED + - MCP_TOOL_STATE_REMOVED type: string - downloadUrl: - description: The downloadUrl is the url used for downloading the AppPopulationReport. - readOnly: false - type: string - hashes: - additionalProperties: - type: string - description: The hashes field contains the file hashes of the report. - readOnly: false - type: object - id: - description: The id field. - readOnly: false + x-speakeasy-unknown-values: allow + toolName: + description: Native MCP tool name (unique within an MCP server). type: string - state: - description: The state field tracks the state of the AppPopulationReport. This state field can be one of REPORT_STATE_PENDING, REPORT_STATE_UNSPECIFIED, REPORT_STATE_OK, REPORT_STATE_ERROR. + updatedAt: + format: date-time + type: + - string + - "null" + visibility: + description: Admin-settable visibility override (how this tool is surfaced to users). enum: - - REPORT_STATE_UNSPECIFIED - - REPORT_STATE_PENDING - - REPORT_STATE_OK - - REPORT_STATE_ERROR - readOnly: false + - TOOL_VISIBILITY_UNSPECIFIED + - TOOL_VISIBILITY_FEATURED + - TOOL_VISIBILITY_AVAILABLE + - TOOL_VISIBILITY_BYPASSED type: string x-speakeasy-unknown-values: allow - title: App Population Report + title: Mcp Tool type: object - x-speakeasy-name-override: AppPopulationReport - c1.api.app.v1.AppRef: - description: The AppRef message. + x-speakeasy-name-override: MCPTool + c1.api.ai_governance.v1.MCPToolHistoryEntry: + description: MCPToolHistoryEntry is one version of an MCP tool and its history metadata. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + - type: "null" + title: Mcp Tool History Entry + type: object + x-speakeasy-name-override: MCPToolHistoryEntry + c1.api.ai_governance.v1.MCPToolRef: + description: MCPToolRef is a reference to a specific MCP tool. properties: + appId: + description: The application the tool belongs to. + type: string + connectorId: + description: The connector the tool was discovered through. + type: string id: - description: The id field. - readOnly: false + description: Unique identifier for the MCP tool. type: string - title: App Ref + title: Mcp Tool Ref type: object - x-speakeasy-name-override: AppRef - c1.api.app.v1.AppReportServiceListResponse: - description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: MCPToolRef + c1.api.ai_governance.v1.MCPToolServiceDeleteRequestInput: + description: MCPToolServiceDeleteRequest deletes an MCP tool (soft delete). + title: Mcp Tool Service Delete Request + type: object + x-speakeasy-name-override: MCPToolServiceDeleteRequest + c1.api.ai_governance.v1.MCPToolServiceDeleteResponse: + description: MCPToolServiceDeleteResponse confirms deletion. + title: Mcp Tool Service Delete Response + type: object + x-speakeasy-name-override: MCPToolServiceDeleteResponse + c1.api.ai_governance.v1.MCPToolServiceGetResponse: + description: MCPToolServiceGetResponse returns a single MCP tool. + properties: + tool: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + - type: "null" + title: Mcp Tool Service Get Response + type: object + x-speakeasy-name-override: MCPToolServiceGetResponse + c1.api.ai_governance.v1.MCPToolServiceListHistoryResponse: + description: MCPToolServiceListHistoryResponse returns MCP tool history entries. properties: list: - description: The list of results containing up to X results, where X is the page size defined in the request. + description: The page of history entries, newest first. items: - $ref: '#/components/schemas/c1.api.app.v1.AppPopulationReport' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolHistoryEntry' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: Pagination token for the next page, or empty if there are no more results. type: string - title: App Report Service List Response + title: Mcp Tool Service List History Response type: object - x-speakeasy-name-override: AppReportServiceListResponse - c1.api.app.v1.AppResource: - description: | - The app resource message is a single resource that can have entitlements. - - This message contains a oneof named metadata. Only a single field of the following list may be set at a time: - - secretTrait + x-speakeasy-name-override: MCPToolServiceListHistoryResponse + c1.api.ai_governance.v1.MCPToolServiceListResponse: + description: MCPToolServiceListResponse returns a list of MCP tools. properties: - accessConfigId: - description: |- - The access config ID for this resource. May be empty. - Must be one of the builtin access config IDs or empty. - readOnly: false - type: string - appId: - description: The app that this resource belongs to. - readOnly: false - type: string - appResourceTypeId: - description: The resource type that this resource is. - readOnly: false - type: string - createdAt: - format: date-time - readOnly: true - type: string - customDescription: - description: A custom description that can be set for a resource. - readOnly: false - type: string - deletedAt: - format: date-time - readOnly: true - type: string - description: - description: The description set for the resource. - readOnly: false + nextPageToken: + description: Token for next page. type: string - displayName: - description: The display name for this resource. - readOnly: false + tools: + description: List of MCP tools. + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + type: + - array + - "null" + title: Mcp Tool Service List Response + type: object + x-speakeasy-name-override: MCPToolServiceListResponse + c1.api.ai_governance.v1.MCPToolServiceSearchRequestInput: + description: MCPToolServiceSearchRequest searches MCP tools with filters. + properties: + accessProfileId: + deprecated: true + description: 'Deprecated: use access_profile_ids instead.' type: string - externalId: + accessProfileIds: + description: 'Optional: only return tools that are bound to at least one of these access profiles.' + items: + type: string + type: + - array + - "null" + classificationFilter: description: |- - The upstream product's native external ID for this resource (e.g. an Okta group ID). - Populated from the connector's external ID during sync. - readOnly: true - type: string - grantCount: - description: The number of grants to this resource. - format: int64 - readOnly: false - type: string - id: - description: The id of the resource. - readOnly: false + Optional filter by classification. An empty list means no filter. + Including TOOL_CLASSIFICATION_UNSPECIFIED matches unclassified tools. + items: + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + excludeAccessProfileId: + deprecated: true + description: 'Deprecated: use exclude_access_profile_ids instead.' type: string - matchBatonId: - description: The matchBatonId field. - readOnly: false + excludeAccessProfileIds: + description: 'Optional: exclude tools that are bound to any of these access profiles.' + items: + type: string + type: + - array + - "null" + includeLastCalledAt: + description: |- + When true, the server populates MCPTool.last_called_at on each + returned row by querying TSDB for the most recent `mcp_tool_calls` + raw emit time per tool. Costs one Dynamo Limit(1) read per row; + callers that don't render the "Last used" column should leave false. + type: boolean + pageSize: + description: Page size (max 100). + format: int32 + type: integer + pageToken: + description: Page token for pagination. type: string - parentAppResourceId: - description: The parent resource id, if this resource is a child of another resource. - readOnly: false + query: + description: Optional text query matched against tool_name and display_name type: string - parentAppResourceTypeId: - description: The parent resource type id, if this resource is a child of another resource. - readOnly: false + refs: + description: 'Optional: filter by specific tool refs (used by websocket notify to re-fetch individual tools).' + items: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolRef' + type: + - array + - "null" + sortBy: + description: Sort order for results. UNSPECIFIED sorts by tool name ascending. + enum: + - MCP_TOOL_SORT_BY_UNSPECIFIED + - MCP_TOOL_SORT_BY_TOOL_NAME + - MCP_TOOL_SORT_BY_VISIBILITY + - MCP_TOOL_SORT_BY_CLASSIFICATION + - MCP_TOOL_SORT_BY_STATE + - MCP_TOOL_SORT_BY_UPDATED_AT type: string - profile: - additionalProperties: true - readOnly: true - type: object - secretTrait: - $ref: '#/components/schemas/c1.api.app.v1.SecretTrait' - updatedAt: - format: date-time - readOnly: true + x-speakeasy-unknown-values: allow + sortDirection: + description: Direction for sort_by. UNSPECIFIED means ascending. + enum: + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC type: string - title: App Resource - type: object - x-speakeasy-entity: App Resource - x-speakeasy-name-override: AppResource - c1.api.app.v1.AppResourceExpandMask: - description: The app resource expand mask lets you get information about related objects from the request. - properties: - paths: - description: The app resource expanded fields. Maybe be any combination of "*", "app_id", "app_resource_type_id". + x-speakeasy-unknown-values: allow + stateFilter: + description: Optional filter by tool state. 0 (UNSPECIFIED) means no filter. items: + enum: + - MCP_TOOL_STATE_UNSPECIFIED + - MCP_TOOL_STATE_PENDING_REVIEW + - MCP_TOOL_STATE_APPROVED + - MCP_TOOL_STATE_DISABLED + - MCP_TOOL_STATE_REMOVED type: string - nullable: true - readOnly: false - type: array - title: App Resource Expand Mask - type: object - x-speakeasy-name-override: AppResourceExpandMask - c1.api.app.v1.AppResourceRef: - description: A reference to a specific app resource by its composite key. - properties: - appId: - description: The ID of the app that owns the resource. - readOnly: false - type: string - appResourceTypeId: - description: The ID of the resource type that classifies this resource. - readOnly: false - type: string - id: - description: The unique ID of the app resource. - readOnly: false - type: string - title: App Resource Ref - type: object - x-speakeasy-name-override: AppResourceRef - c1.api.app.v1.AppResourceServiceGetResponse: - description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. - properties: - appResourceView: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' - expanded: - description: List of serialized related objects. + x-speakeasy-unknown-values: allow + type: + - array + - "null" + visibilityFilter: + description: Optional filter by visibility. 0 (UNSPECIFIED) means no filter. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: App Resource Service Get Response + enum: + - TOOL_VISIBILITY_UNSPECIFIED + - TOOL_VISIBILITY_FEATURED + - TOOL_VISIBILITY_AVAILABLE + - TOOL_VISIBILITY_BYPASSED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Mcp Tool Service Search Request type: object - x-speakeasy-name-override: AppResourceServiceGetResponse - c1.api.app.v1.AppResourceServiceListResponse: - description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: MCPToolServiceSearchRequest + c1.api.ai_governance.v1.MCPToolServiceSearchResponse: + description: MCPToolServiceSearchResponse returns matching MCP tools. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: - description: The list of results containing up to X results, where X is the page size defined in the request. + description: Matching MCP tools. items: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: Token for next page. type: string - title: App Resource Service List Response + title: Mcp Tool Service Search Response type: object - x-speakeasy-name-override: AppResourceServiceListResponse - c1.api.app.v1.AppResourceServiceUpdateRequestInput: - description: The request message for updating an app resource. + x-speakeasy-name-override: MCPToolServiceSearchResponse + c1.api.ai_governance.v1.MCPToolServiceUpdateRequestInput: + description: MCPToolServiceUpdateRequest updates an existing MCP tool. properties: - appResource: - $ref: '#/components/schemas/c1.api.app.v1.AppResource' - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceExpandMask' + tool: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string - title: App Resource Service Update Request + type: + - string + - "null" + title: Mcp Tool Service Update Request type: object - x-speakeasy-name-override: AppResourceServiceUpdateRequest - c1.api.app.v1.AppResourceServiceUpdateResponse: - description: The response message for updating an app resource. + x-speakeasy-name-override: MCPToolServiceUpdateRequest + c1.api.ai_governance.v1.MCPToolServiceUpdateResponse: + description: MCPToolServiceUpdateResponse returns the updated MCP tool. properties: - appResourceView: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: App Resource Service Update Response + tool: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPTool' + - type: "null" + title: Mcp Tool Service Update Response type: object - x-speakeasy-name-override: AppResourceServiceUpdateResponse - c1.api.app.v1.AppResourceType: - description: The AppResourceType is referenced by an app entitlement defining its resource types. Commonly things like Group or Role. + x-speakeasy-name-override: MCPToolServiceUpdateResponse + c1.api.ai_governance.v1.RequestableConnector: + description: RequestableConnector identifies a connector that has requestable MCP access profiles. properties: appId: - description: The ID of the app that is associated with the app resource type - readOnly: true + description: App identifier. type: string - createdAt: - format: date-time - readOnly: true + connectorId: + description: Connector identifier. type: string - deletedAt: - format: date-time - readOnly: true + title: Requestable Connector + type: object + x-speakeasy-name-override: RequestableConnector + c1.api.ai_governance.v1.RequestableConnectorView: + description: RequestableConnectorView is a card-ready MCP connector entry. + properties: + appId: + description: App identifier. type: string - displayName: - description: The display name of the app resource type. - readOnly: false + connectorId: + description: Connector identifier. type: string - id: - description: The unique ID for the app resource type. - readOnly: true + description: + description: Connector description. type: string - traitIds: - description: Associated trait ids - items: - type: string - nullable: true - readOnly: false - type: array - updatedAt: - format: date-time - readOnly: true + displayName: + description: Connector display name (falls back to the owning app's display name). type: string - title: App Resource Type + granted: + description: |- + True when the user actively holds a grant on at least one of this + connector's MCP entitlements. + type: boolean + toolCount: + description: |- + Count of ALL approved tools bound under this connector (connector-wide), + NOT scoped to the tools this user can request. 0 when unknown. + format: int32 + type: integer + title: Requestable Connector View type: object - x-speakeasy-entity: App Resource Type - x-speakeasy-name-override: AppResourceType - c1.api.app.v1.AppResourceTypeServiceGetResponse: + x-speakeasy-name-override: RequestableConnectorView + c1.api.ai_governance.v1.UpdateAIGovernanceSettingsRequest: description: |- - The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask - in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. + UpdateAIGovernanceSettingsRequest is the request to update the tenant's AI + governance settings. properties: - appResourceTypeView: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeView' - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: App Resource Type Service Get Response - type: object - x-speakeasy-name-override: AppResourceTypeServiceGetResponse - c1.api.app.v1.AppResourceTypeServiceListResponse: - description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. + aiGovernanceSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.AIGovernanceSettings' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Ai Governance Settings Request + type: object + x-speakeasy-name-override: UpdateAIGovernanceSettingsRequest + c1.api.ai_governance.v1.UpdateAIGovernanceSettingsResponse: + description: UpdateAIGovernanceSettingsResponse contains the updated AI governance settings. + properties: + aiGovernanceSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.ai_governance.v1.AIGovernanceSettings' + - type: "null" + title: Update Ai Governance Settings Response + type: object + x-speakeasy-name-override: UpdateAIGovernanceSettingsResponse + c1.api.app.v1.AddAppEntitlementOwnerRequestInput: + description: The request message for adding an app entitlement owner. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + userId: + description: The user_id field for the user to add as an owner of the app entitlement. type: string - title: App Resource Type Service List Response + title: Add App Entitlement Owner Request type: object - x-speakeasy-name-override: AppResourceTypeServiceListResponse - c1.api.app.v1.AppResourceTypeView: - description: The AppResourceTypeView message. + x-speakeasy-name-override: AddAppEntitlementOwnerRequest + c1.api.app.v1.AddAppEntitlementOwnerResponse: + description: The empty response message for adding an app entitlement owner. + title: Add App Entitlement Owner Response + type: object + x-speakeasy-name-override: AddAppEntitlementOwnerResponse + c1.api.app.v1.AddAppOwnerRequestInput: + description: Empty request body. Just placeholder for the add app owner request which uses URL values for input. + title: Add App Owner Request + type: object + x-speakeasy-name-override: AddAppOwnerRequest + c1.api.app.v1.AddAppOwnerResponse: + description: Empty response with a status code indicating success + title: Add App Owner Response + type: object + x-speakeasy-name-override: AddAppOwnerResponse + c1.api.app.v1.AddAppResourceOwnerRequestInput: + description: The request message for adding an owner to an app resource. properties: - appPath: - description: JSONPATH expression indicating the location of the App object in the array - readOnly: false + userId: + description: The C1 user ID to add as an owner. type: string - appResourceType: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' - title: App Resource Type View + title: Add App Resource Owner Request type: object - x-speakeasy-name-override: AppResourceTypeView - c1.api.app.v1.AppResourceView: - description: The app resource view returns an app resource with paths for items in the expand mask filled in when this response is returned and a request expand mask has "*" or "app_id" or "resource_type_id". + x-speakeasy-name-override: AddAppResourceOwnerRequest + c1.api.app.v1.AddAppResourceOwnerResponse: + description: The empty response message for adding an owner to an app resource. + title: Add App Resource Owner Response + type: object + x-speakeasy-name-override: AddAppResourceOwnerResponse + c1.api.app.v1.AddAutomationExclusionRequestInput: + description: The AddAutomationExclusionRequest message. properties: - appPath: - description: JSONPATH expression indicating the location of the App object in the array - readOnly: false - type: string - appResource: - $ref: '#/components/schemas/c1.api.app.v1.AppResource' - objectPermissions: - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' - parentResourcePath: - description: JSONPATH expression indicating the location of the Parent Resource object in the array - readOnly: false - type: string - parentResourceTypePath: - description: JSONPATH expression indicating the location of the Parent Resource Type object in the array - readOnly: false - type: string - resourceTypePath: - description: JSONPATH expression indicating the location of the Resource Type object in the array - readOnly: false - type: string - title: App Resource View + userIds: + description: The IDs of users to add to the automation exclusion list. + items: + type: string + type: + - array + - "null" + title: Add Automation Exclusion Request type: object - x-speakeasy-name-override: AppResourceView - c1.api.app.v1.AppUsageControls: - description: The AppUsageControls object describes some peripheral configuration for an app. + x-speakeasy-name-override: AddAutomationExclusionRequest + c1.api.app.v1.AddAutomationExclusionResponse: + description: Empty response with a status code indicating success. + title: Add Automation Exclusion Response + type: object + x-speakeasy-name-override: AddAutomationExclusionResponse + c1.api.app.v1.AddManuallyManagedUsersRequestInput: + description: The AddManuallyManagedUsersRequest message. properties: - appId: - description: The app that this object belongs to. - readOnly: false - type: string - notify: - description: Whether or not to notify some if they have access to the app, but has not used it within a configurable amount of time. - readOnly: false - type: boolean - notifyAfterDays: - description: The duration in days after which we notify users of nonusage. - format: uint32 - readOnly: false - type: integer - revoke: - description: Whether or not to revoke a grant if they have access to the app, but has not used it within a configurable amount of time. - readOnly: false - type: boolean - revokeAfterDays: - description: The duration in days after which we revoke users that have not used that grant. - format: uint32 - readOnly: false - type: integer - title: App Usage Controls + userIds: + description: The IDs of users to add as manually managed members. + items: + type: string + type: + - array + - "null" + title: Add Manually Managed Users Request type: object - x-speakeasy-name-override: AppUsageControls - c1.api.app.v1.AppUser: - description: Application User that represents an account in the application. + x-speakeasy-name-override: AddManuallyManagedUsersRequest + c1.api.app.v1.AgentTrait: + description: AgentTrait carries metadata for AI-agent resources surfaced in the Inventory. properties: - appId: - description: The ID of the application. - readOnly: true + identityAppUserId: + description: |- + The C1 app user ID of the service-account identity this agent authenticates as. + Empty if the backing identity has not yet been resolved. type: string - appUserType: - description: The appplication user type. Type can be user, system or service. + status: + description: The agent's lifecycle status (READY, DISABLED, DELETED). enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - readOnly: false + - AGENT_STATUS_UNSPECIFIED + - AGENT_STATUS_READY + - AGENT_STATUS_DISABLED + - AGENT_STATUS_DELETED + type: string + x-speakeasy-unknown-values: allow + title: Agent Trait + type: object + x-speakeasy-name-override: AgentTrait + c1.api.app.v1.App: + description: The App object provides all of the details for an app, as well as some configuration. + properties: + accessModel: + description: |- + How this app models access. Derived during uplift from the app's resource type traits. + Sparse ACL feature. + enum: + - APP_ACCESS_MODEL_UNSPECIFIED + - APP_ACCESS_MODEL_CLASSIC + - APP_ACCESS_MODEL_HYBRID + - APP_ACCESS_MODEL_SPARSE type: string x-speakeasy-unknown-values: allow + annotations: + additionalProperties: + type: string + description: |- + Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256 + chars; URL-safe ASCII. Keys starting with `c1/` are reserved. + + Updates have PATCH semantics: keys absent from the request are + preserved; an empty value deletes the key. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appAccountId: + description: The ID of the Account named by AccountName. + readOnly: true + type: string + appAccountName: + description: The AccountName of the app. For example, AWS is AccountID, Github is Org Name, and Okta is Okta Subdomain. + readOnly: true + type: string + appOwners: + description: The owners of the app. + items: + $ref: '#/components/schemas/c1.api.user.v1.User' + readOnly: true + type: + - array + - "null" + appUserMapper: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserMapper' + - type: "null" + certifyPolicyId: + description: The ID of the Certify Policy associated with this App. + type: string + connectorVersion: + description: The connectorVersion field. + format: uint32 + type: integer createdAt: format: date-time readOnly: true + type: + - string + - "null" + defaultRequestCatalogId: + description: The ID for the default request catalog for this app. type: string deletedAt: format: date-time readOnly: true + type: + - string + - "null" + description: + description: The app's description. type: string displayName: - description: The display name of the application user. - readOnly: true - type: string - email: - description: The email field of the application user. - readOnly: true + description: The app's display name. type: string - emails: - description: The emails field of the application user. - items: - type: string - nullable: true - readOnly: true - type: array - employeeIds: - description: The employee IDs field of the application user. - items: - type: string - nullable: true + enableConnectorSourcedOwnership: + description: When enabled, resource ownership is sourced from the connector. + type: boolean + fieldMask: readOnly: true - type: array + type: + - string + - "null" + grantPolicyId: + description: The ID of the Grant Policy associated with this App. + type: string + iconUrl: + description: The URL of an icon to display for the app. + type: string id: - description: A unique idenditfier of the application user. + description: The ID of the app. readOnly: true type: string - identityUserId: - description: The conductor one user ID of the account owner. + identityMatching: + description: The identityMatching field. + enum: + - APP_USER_IDENTITY_MATCHING_UNSPECIFIED + - APP_USER_IDENTITY_MATCHING_STRICT + - APP_USER_IDENTITY_MATCHING_DISPLAY_NAME + - APP_USER_IDENTITY_MATCHING_CUSTOM + type: string + x-speakeasy-unknown-values: allow + instructions: + description: If you add instructions here, they will be shown to users in the access request form when requesting access for this app. + type: string + isDirectory: + description: Specifies if the app is a directory. + readOnly: true + type: boolean + isManuallyManaged: + description: The isManuallyManaged field. + type: boolean + logoUri: + description: The URL of a logo to display for the app. readOnly: true type: string - isExternal: - description: The isExternal field. + monthlyCostUsd: + description: The cost of an app per-seat, so that total cost can be calculated by the grant count. + format: int32 + type: integer + parentAppId: + description: The ID of the app that created this app, if any. readOnly: true + type: string + revokeGrantSources: + description: When enabled, revoking a grant also revokes the grants that source it. type: boolean - profile: - additionalProperties: true + revokePolicyId: + description: The ID of the Revoke Policy associated with this App. + type: string + strictAccessEntitlementProvisioning: + description: The strictAccessEntitlementProvisioning field. + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userCount: + description: The number of users with grants to this app. + format: int64 readOnly: true + type: string + title: App + type: object + x-speakeasy-entity: App + x-speakeasy-name-override: App + c1.api.app.v1.AppAccessRequestDefaults: + description: | + The AppAccessRequestDefaults message. + + This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: + - durationUnset + - durationGrant + properties: + appId: + description: The app id for the app access request rule + type: string + catalogIds: + description: The request catalog ids for the app access request rule. + items: + type: string + type: + - array + - "null" + defaultsEnabled: + description: If true the app level request configuration will be applied to specified resource types. + type: boolean + durationGrant: + format: duration + type: + - string + - "null" + durationUnset: + type: + - object + - "null" + emergencyGrantEnabled: + description: If emergency grants are enabled for this app access request rule. + type: boolean + emergencyGrantPolicyId: + description: The policy id for the emergency grant policy. + type: string + requestPolicyId: + description: The ID of the request policy to apply to entitlements matching this rule. + type: string + requestSchemaId: + description: The ID of the request schema to apply to entitlements matching this rule. + type: string + resourceTypeIds: + description: The app resource type ids for which the app access request defaults are applied. + items: + type: string + type: + - array + - "null" + state: + description: The last applied state of the app access request defaults. + enum: + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_UNSPECIFIED + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_RUNNING + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_SUCCESS + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_FAILED + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCELING + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_SUCCESS + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_ERROR + type: string + x-speakeasy-unknown-values: allow + title: App Access Request Defaults + type: object + x-speakeasy-name-override: AppAccessRequestDefaults + c1.api.app.v1.AppAccessRequestDefaultsInput: + description: | + The AppAccessRequestDefaults message. + + This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: + - durationUnset + - durationGrant + properties: + catalogIds: + description: The request catalog ids for the app access request rule. + items: + type: string + type: + - array + - "null" + defaultsEnabled: + description: If true the app level request configuration will be applied to specified resource types. + type: boolean + durationGrant: + format: duration + type: + - string + - "null" + durationUnset: + type: + - object + - "null" + emergencyGrantEnabled: + description: If emergency grants are enabled for this app access request rule. + type: boolean + emergencyGrantPolicyId: + description: The policy id for the emergency grant policy. + type: string + requestPolicyId: + description: The ID of the request policy to apply to entitlements matching this rule. + type: string + requestSchemaId: + description: The ID of the request schema to apply to entitlements matching this rule. + type: string + resourceTypeIds: + description: The app resource type ids for which the app access request defaults are applied. + items: + type: string + type: + - array + - "null" + state: + description: The last applied state of the app access request defaults. + enum: + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_UNSPECIFIED + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_RUNNING + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_SUCCESS + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_FAILED + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCELING + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_SUCCESS + - APP_ACCESS_REQUEST_DEFAULTS_LAST_APPLY_STATE_CANCEL_ERROR + type: string + x-speakeasy-unknown-values: allow + title: App Access Request Defaults + type: object + x-speakeasy-name-override: AppAccessRequestDefaults + c1.api.app.v1.AppActionsServiceGenerateReportRequestInput: + description: Empty request body. Just placeholder for the generate app report request which uses URL values for input. + title: App Actions Service Generate Report Request + type: object + x-speakeasy-name-override: AppActionsServiceGenerateReportRequest + c1.api.app.v1.AppActionsServiceGenerateReportResponse: + description: Empty response body. Status code indicates success. + title: App Actions Service Generate Report Response + type: object + x-speakeasy-name-override: AppActionsServiceGenerateReportResponse + c1.api.app.v1.AppEntitlement: + description: | + The app entitlement represents one permission in a downstream App (SAAS) that can be granted. For example, GitHub Read vs GitHub Write. + + This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: + - durationUnset + - durationGrant + properties: + alias: + description: The alias of the app entitlement used by Cone. Also exact-match queryable. + type: string + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ + are reserved. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. type: object - status: - $ref: '#/components/schemas/c1.api.app.v1.AppUserStatus' - updatedAt: + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appId: + description: The ID of the app that is associated with the app entitlement. + type: string + appResourceId: + description: The ID of the app resource that is associated with the app entitlement + type: string + appResourceTypeId: + description: The ID of the app resource type that is associated with the app entitlement + type: string + certifyPolicyId: + description: The ID of the policy that will be used for certify tickets related to the app entitlement. + type: string + complianceFrameworkValueIds: + description: The IDs of different compliance frameworks associated with this app entitlement ex (SOX, HIPAA, PCI, etc.) + items: + type: string + type: + - array + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + defaultValuesApplied: + description: Flag to indicate if app-level access request defaults have been applied to the entitlement + type: boolean + deletedAt: format: date-time readOnly: true + type: + - string + - "null" + deprovisionerPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + - type: "null" + description: + description: The description of the app entitlement. type: string - username: - description: The username field of the application user. + displayName: + description: The display name of the app entitlement. + type: string + durationGrant: + format: duration + type: + - string + - "null" + durationUnset: + type: + - object + - "null" + emergencyGrantEnabled: + description: This enables tasks to be created in an emergency and use a selected emergency access policy. + type: boolean + emergencyGrantPolicyId: + description: The ID of the policy that will be used for emergency access grant tasks. + type: string + externalId: + description: |- + The upstream product's native external ID for this entitlement (e.g. an Okta group ID). + Populated from the connector's external ID during sync. readOnly: true type: string - usernames: - description: The usernames field of the application user. - items: + grantCount: + description: The amount of grants open for this entitlement + format: int64 + readOnly: true + type: string + grantPolicyId: + description: The ID of the policy that will be used for grant tickets related to the app entitlement. + type: string + id: + description: The unique ID for the App Entitlement. + readOnly: true + type: string + isAutomationEnabled: + description: Flag to indicate whether automation (for adding users to entitlement based on rules) has been enabled. + readOnly: true + type: boolean + isManuallyManaged: + description: Flag to indicate if the app entitlement is manually managed. + type: boolean + matchBatonId: + description: An identifier used to match this entitlement to a connector-synced entitlement during sync. + type: string + overrideAccessRequestsDefaults: + description: Flag to indicate if the app-level access request settings have been overridden for the entitlement + type: boolean + provisionerPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + - type: "null" + purpose: + description: The purpose of this entitlement (e.g., assignment, permission, ownership). + enum: + - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED + - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT + - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION + - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP + type: string + x-speakeasy-unknown-values: allow + requestSchemaId: + description: The ID of the request schema associated with this app entitlement. + type: string + revokePolicyId: + description: The ID of the policy that will be used for revoke tickets related to the app entitlement + type: string + riskLevelValueId: + description: The ID of the risk level assigned to this entitlement. + type: string + slug: + description: The slug is displayed as an oval next to the name in the frontend of C1, it tells you what permission the entitlement grants. See https://www.conductorone.com/docs/product/admin/entitlements/ + type: string + sourceConnectorIds: + additionalProperties: type: string - nullable: true + description: Map to tell us which connector the entitlement came from. + type: object + systemBuiltin: + description: This field indicates if this is a system builtin entitlement. readOnly: true - type: array - title: App User + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userEditedMask: + type: + - string + - "null" + title: App Entitlement type: object - x-speakeasy-name-override: AppUser - c1.api.app.v1.AppUserCredential: + x-speakeasy-entity: Custom App Entitlement + x-speakeasy-name-override: AppEntitlement + c1.api.app.v1.AppEntitlementAutomation: description: | - A credentials for the Application User that represents an account in the application. + The AppEntitlementAutomation message. - This message contains a oneof named credential. Only a single field of the following list may be set at a time: - - encryptedData + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - none + - entitlements + - cel + - basic properties: - appId: - description: The ID of the application. + appEntitlementId: + description: The unique ID for the App Entitlement. readOnly: true type: string - appUserId: - description: A unique identifier of the application user. + appId: + description: The ID of the app that is associated with the app entitlement. readOnly: true type: string + basic: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleBasic' + - type: "null" + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleCEL' + - type: "null" createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" deletedAt: format: date-time readOnly: true + type: + - string + - "null" + description: + description: The description of the app entitlement. type: string - encryptedData: - $ref: '#/components/schemas/c1.api.app.v1.EncryptedData' - expiresAt: - format: date-time - readOnly: false + displayName: + description: The display name of the app entitlement. type: string - id: - description: A unique identifier of the credential. + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleEntitlement' + - type: "null" + lastRunStatus: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationLastRunStatus' + - type: "null" + managedByRequestCatalogId: + description: |- + When set, this automation is managed by an access profile's bundle automation. + Read-only. Not settable via this API. readOnly: true type: string + none: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleNone' + - type: "null" updatedAt: format: date-time readOnly: true + type: + - string + - "null" + title: App Entitlement Automation + type: object + x-speakeasy-entity: App Entitlement Automation + x-speakeasy-name-override: AppEntitlementAutomation + c1.api.app.v1.AppEntitlementAutomationLastRunStatus: + description: The AppEntitlementAutomationLastRunStatus message. + properties: + errorMessage: + description: The errorMessage field. + readOnly: true + type: string + lastCompletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + status: + description: The status field. + enum: + - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_UNSPECIFIED + - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_SUCCESS + - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_FAILED + - APP_ENTITLEMENT_AUTOMATION_RUN_STATUS_IN_PROGRESS + readOnly: true type: string - title: App User Credential + x-speakeasy-unknown-values: allow + title: App Entitlement Automation Last Run Status type: object - x-speakeasy-name-override: AppUserCredential - c1.api.app.v1.AppUserExpandMask: - description: The AppUserExpandMask message contains a list of paths to expand in the response. + x-speakeasy-name-override: AppEntitlementAutomationLastRunStatus + c1.api.app.v1.AppEntitlementAutomationRuleBasic: + description: The AppEntitlementAutomationRuleBasic message. + properties: + expression: + description: The expression field. + type: string + title: App Entitlement Automation Rule Basic + type: object + x-speakeasy-name-override: AppEntitlementAutomationRuleBasic + c1.api.app.v1.AppEntitlementAutomationRuleCEL: + description: The AppEntitlementAutomationRuleCEL message. + properties: + expression: + description: The expression field. + type: string + title: App Entitlement Automation Rule Cel + type: object + x-speakeasy-name-override: AppEntitlementAutomationRuleCEL + c1.api.app.v1.AppEntitlementAutomationRuleEntitlement: + description: The AppEntitlementAutomationRuleEntitlement message. + properties: + entitlementRefs: + description: The entitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: App Entitlement Automation Rule Entitlement + type: object + x-speakeasy-name-override: AppEntitlementAutomationRuleEntitlement + c1.api.app.v1.AppEntitlementAutomationRuleNone: + description: The AppEntitlementAutomationRuleNone message. + title: App Entitlement Automation Rule None + type: object + x-speakeasy-name-override: AppEntitlementAutomationRuleNone + c1.api.app.v1.AppEntitlementExpandMask: + description: The app entitlement expand mask allows the user to get additional information when getting responses containing app entitlement views. properties: paths: - description: The paths to expand in the response. May be any combination of "*", "identity_user_id", "app_id", and "last_usage". + description: Array of strings to describe which items to expand on the return value. Can be any combination of "*", "app_id", "app_resource_type_id", or "app_resource_id". items: type: string - nullable: true - readOnly: false - type: array - title: App User Expand Mask + type: + - array + - "null" + title: App Entitlement Expand Mask type: object - x-speakeasy-name-override: AppUserExpandMask - c1.api.app.v1.AppUserMapper: - description: AppUserMapper configures custom account mapping for uplift. + x-speakeasy-name-override: AppEntitlementExpandMask + c1.api.app.v1.AppEntitlementProxy: + description: An entitlement proxy binding that defines a hierarchical relationship between two entitlements. properties: - mappingCases: - description: Ordered list of match cases. Each case defines a pair of CEL key extractors. + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + disabledAt: + format: date-time + type: + - string + - "null" + dstAppEntitlementId: + description: The ID of the destination (child) entitlement. + type: string + dstAppId: + description: The ID of the app that owns the destination entitlement. + type: string + implicit: + description: If true, the binding does not exist yet and is inferred from the entitlements of the parent app. + type: + - boolean + - "null" + srcAppEntitlementId: + description: The ID of the source (parent) entitlement. + type: string + srcAppId: + description: The ID of the app that owns the source entitlement. + type: string + systemBuiltin: + description: If true, this binding was created by the system and cannot be removed by the user. + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App Entitlement Proxy + type: object + x-speakeasy-entity: App Entitlement Proxy Binding + x-speakeasy-name-override: AppEntitlementProxy + c1.api.app.v1.AppEntitlementProxyExpandMask: + description: The AppEntitlementProxyExpandMask message. + properties: + paths: + description: The paths field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserMapperMatchCase' - nullable: true - readOnly: false - type: array - title: App User Mapper + type: string + type: + - array + - "null" + title: App Entitlement Proxy Expand Mask type: object - x-speakeasy-name-override: AppUserMapper - c1.api.app.v1.AppUserMapperMatchCase: - description: AppUserMapperMatchCase defines a single matching rule for uplift account mapping. + x-speakeasy-name-override: AppEntitlementProxyExpandMask + c1.api.app.v1.AppEntitlementProxyView: + description: The AppEntitlementProxyView message. properties: - appUserKeyCel: - description: CEL expression evaluated against an AppUser to produce match key(s). - readOnly: false + appProxyEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxy' + - type: "null" + dstAppEntitlementPath: + description: The dstAppEntitlementPath field. type: string - userKeyCel: - description: CEL expression evaluated against a User to produce match key(s). - readOnly: false + dstAppPath: + description: The dstAppPath field. type: string - title: App User Mapper Match Case + srcAppEntitlementPath: + description: The srcAppEntitlementPath field. + type: string + srcAppPath: + description: The srcAppPath field. + type: string + title: App Entitlement Proxy View type: object - x-speakeasy-name-override: AppUserMapperMatchCase - c1.api.app.v1.AppUserRef: - description: The AppUserRef message. + x-speakeasy-name-override: AppEntitlementProxyView + c1.api.app.v1.AppEntitlementRef: + description: The AppEntitlementRef message. properties: appId: - description: The ID of the application. - readOnly: false + description: The appId field. type: string id: - description: The ID of the app user. - readOnly: false + description: The id field. type: string - title: App User Ref + title: App Entitlement Ref type: object - x-speakeasy-name-override: AppUserRef - c1.api.app.v1.AppUserServiceListCredentialsResponse: - description: The response message for listing credentials of an app user. + x-speakeasy-name-override: AppEntitlementRef + c1.api.app.v1.AppEntitlementRoutingRule: + description: The AppEntitlementRoutingRule message. properties: - list: - description: The list of credential results. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserCredential' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The token for fetching the next page of results. - readOnly: false - type: string - title: App User Service List Credentials Response + appId: + description: The appId field. + readOnly: true + type: string + condition: + description: |- + CEL expression evaluated against the entitlement routing rule context. + Empty string is valid and matches every target not matched earlier. + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: The description field. + type: string + displayName: + description: The displayName field. + type: string + enabled: + description: The enabled field. + type: boolean + id: + description: The id field. + readOnly: true + type: string + priority: + description: |- + Evaluation order: lower numbers evaluate first; rules are sorted by + (priority asc, id asc). On create, this is a 1-indexed insertion slot and + the server re-packs siblings densely; omit it to append last. Ignored on + update — use ReorderAppEntitlementRoutingRules (list order = priority order) + to change an existing rule's position. + format: int32 + type: integer + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRuleSettings' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App Entitlement Routing Rule type: object - x-speakeasy-name-override: AppUserServiceListCredentialsResponse - c1.api.app.v1.AppUserServiceListResponse: - description: The response message for listing app users. + x-speakeasy-name-override: AppEntitlementRoutingRule + c1.api.app.v1.AppEntitlementRoutingRuleSettings: + description: The AppEntitlementRoutingRuleSettings message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list of app user results. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The token for fetching the next page of results. - readOnly: false + emergencyGrantEnabled: + description: The emergencyGrantEnabled field. + type: boolean + emergencyGrantPolicyId: + description: The emergencyGrantPolicyId field. type: string - title: App User Service List Response + maxGrantDuration: + format: duration + type: + - string + - "null" + requestPolicyId: + description: The requestPolicyId field. + type: string + requestSchemaId: + description: The requestSchemaId field. + type: string + title: App Entitlement Routing Rule Settings type: object - x-speakeasy-name-override: AppUserServiceListResponse - c1.api.app.v1.AppUserServiceSearchRequest: - description: Search App users based on filters specified in the request body + x-speakeasy-name-override: AppEntitlementRoutingRuleSettings + c1.api.app.v1.AppEntitlementSearchServiceCountGrantsForUserByAppRequest: + description: CountGrantsForUserByApp request. properties: - appId: - description: The app ID to restrict the search to. - readOnly: false - type: string - appUserDomains: - description: A list of account domains to restrict the search to. + appIds: + description: |- + Restrict the count to these applications. Empty counts grants across all + applications the user has access to. items: - enum: - - APP_USER_DOMAIN_UNSPECIFIED - - APP_USER_DOMAIN_EXTERNAL - - APP_USER_DOMAIN_TRUSTED type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - appUserIds: - description: A list of app user IDs to restrict the search to. + type: + - array + - "null" + userId: + description: The user whose grants to count. + type: string + title: App Entitlement Search Service Count Grants For User By App Request + type: object + x-speakeasy-name-override: AppEntitlementSearchServiceCountGrantsForUserByAppRequest + c1.api.app.v1.AppEntitlementSearchServiceCountGrantsForUserByAppResponse: + description: |- + CountGrantsForUserByApp response. Grant counts are computed directly from + grant bindings and are an upper bound on what SearchGraph renders for the + same user and app filter — SearchGraph applies additional filters that + these counts do not. + properties: + appCount: + description: The number of applications represented in app_grant_counts. + format: int32 + type: integer + appGrantCounts: + description: |- + Grant counts, one entry per application the user has at least one grant + in (or per requested app_id, if narrower). items: - type: string - nullable: true - readOnly: false - type: array - appUserStatusDetails: - description: A list of app user status details to restrict the search to. + $ref: '#/components/schemas/c1.api.app.v1.GraphAppGrantCount' + type: + - array + - "null" + appUsers: + description: |- + The user's accounts, scoped by the app_ids filter when provided. Includes + accounts with zero counted grants. Lets callers filter a subsequent access + graph by account without a second lookup. items: - type: string - nullable: true - readOnly: false - type: array - appUserStatuses: - description: A list of app user statuses to restrict the search to. + $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' + type: + - array + - "null" + band: + description: |- + Advisory size classification for the user's access graph. See + GraphSizeBand. + enum: + - GRAPH_SIZE_BAND_UNSPECIFIED + - GRAPH_SIZE_BAND_NORMAL + - GRAPH_SIZE_BAND_SUMMARIZED + - GRAPH_SIZE_BAND_TOO_LARGE + type: string + x-speakeasy-unknown-values: allow + totalGrants: + description: The sum of grant_count across all app_grant_counts. + format: int64 + type: string + title: App Entitlement Search Service Count Grants For User By App Response + type: object + x-speakeasy-name-override: AppEntitlementSearchServiceCountGrantsForUserByAppResponse + c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsRequest: + description: The AppEntitlementSearchServiceSearchGrantsRequest message. + properties: + appIds: + description: Search for grants contained in any of these apps. items: - enum: - - STATUS_UNSPECIFIED - - STATUS_ENABLED - - STATUS_DISABLED - - STATUS_DELETED type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - appUserTypes: - description: A list of app user types to restrict the search to. + type: + - array + - "null" + appUserIds: + description: Search for grants that are granted to any of these app user ids. items: - enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - excludeAppUserIds: - description: A list of app user IDs to remove from the results. + type: + - array + - "null" + entitlementRefs: + description: Search for grants of an entitlement + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + entitlementSlugs: + description: Filter for entitlements whose slug is in this list (e.g. "enrollment" for access profiles) items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" pageSize: description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 - readOnly: false type: integer pageToken: description: The pageToken field. - readOnly: false - type: string - query: - description: Query the apps with a fuzzy search on display name and description. - readOnly: false type: string - refs: - description: A list of app users to limit the search to. + purpose: + description: Filter for entitlements with these purposes (e.g., ASSIGNMENT for membership entitlements) items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' - nullable: true - readOnly: false - type: array - userIds: - description: A list of user IDs to restrict the search by. + enum: + - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED + - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT + - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION + - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + resourceIds: + description: Search for grants within a resource. items: type: string - nullable: true - readOnly: false - type: array - title: App User Service Search Request + type: + - array + - "null" + resourceTypeIds: + description: Search grants for given resource types. + items: + type: string + type: + - array + - "null" + userId: + description: Search for grants of a user + type: string + title: App Entitlement Search Service Search Grants Request type: object - x-speakeasy-name-override: AppUserServiceSearchRequest - c1.api.app.v1.AppUserServiceSearchResponse: - description: The AppUserServiceSearchResponse message. + x-speakeasy-name-override: AppEntitlementSearchServiceSearchGrantsRequest + c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsResponse: + description: The AppEntitlementSearchServiceSearchGrantsResponse message. properties: expanded: - description: List of related objects. + description: The expanded field. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5245,109 +7057,304 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" list: - description: The list of results containing up to X results, where X is the page size defined in the request. + description: The list field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementWithUserBinding' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retrieved. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: The nextPageToken field. type: string - title: App User Service Search Response + title: App Entitlement Search Service Search Grants Response type: object - x-speakeasy-name-override: AppUserServiceSearchResponse - c1.api.app.v1.AppUserServiceUpdateRequestInput: - description: The AppUserServiceUpdateRequest message contains the app user and the fields to be updated. + x-speakeasy-name-override: AppEntitlementSearchServiceSearchGrantsResponse + c1.api.app.v1.AppEntitlementSearchServiceSearchGraphRequest: + description: |- + SearchGraph request. Builds a filtered access graph starting from a root entity. + Exactly one of user_id, app_id, or resource_id must be set. + Server validates this constraint and returns InvalidArgument if violated. properties: - appUser: - $ref: '#/components/schemas/c1.api.app.v1.AppUser' - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' - updateMask: - nullable: true - readOnly: false + appId: + description: The appId field. type: string - title: App User Service Update Request + appIds: + description: Filters — all optional, applied at every traversal hop + items: + type: string + type: + - array + - "null" + entitlementIds: + description: The entitlementIds field. + items: + type: string + type: + - array + - "null" + entitlementNameQuery: + description: The entitlementNameQuery field. + type: string + maxDepth: + description: Traversal controls + format: int32 + type: integer + maxFanOut: + description: |- + Legacy per-parent fan-out limit. Superseded by max_nodes and server-computed + per-parent budgets, but still honored for callers that set it. + format: int32 + type: integer + maxNodes: + description: Overall node budget for the returned subgraph. 0 uses the server default. + format: int32 + type: integer + pageSize: + description: |- + Legacy traversal page size. Superseded by max_nodes, but still honored for + callers that set it. + format: int32 + type: integer + pageToken: + description: |- + Legacy pagination token. Superseded by max_nodes-based traversal, but still + honored for callers that set it. + type: string + resourceId: + description: The resourceId field. + type: string + resourceIds: + description: The resourceIds field. + items: + type: string + type: + - array + - "null" + resourceNameQuery: + description: The resourceNameQuery field. + type: string + resourceTypeIds: + description: The resourceTypeIds field. + items: + type: string + type: + - array + - "null" + userId: + description: Root entity — exactly one must be set + type: string + title: App Entitlement Search Service Search Graph Request type: object - x-speakeasy-name-override: AppUserServiceUpdateRequest - c1.api.app.v1.AppUserServiceUpdateResponse: - description: The AppUserServiceUpdateResponse message. + x-speakeasy-name-override: AppEntitlementSearchServiceSearchGraphRequest + c1.api.app.v1.AppEntitlementSearchServiceSearchGraphResponse: + description: SearchGraph response. Contains a subgraph of nodes and edges. properties: - appUserView: - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' - expanded: - description: The expanded field. + edges: + description: The edges field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: App User Service Update Response + $ref: '#/components/schemas/c1.api.app.v1.GraphEdge' + type: + - array + - "null" + hasMore: + description: The hasMore field. + type: boolean + nodeCeilingHit: + description: |- + True if the server-side node budget stopped the traversal before it + finished walking the graph. Distinct from has_more, which can also be set + by a request timeout or scan limit. + type: boolean + nodes: + description: The nodes field. + items: + $ref: '#/components/schemas/c1.api.app.v1.GraphNode' + type: + - array + - "null" + pageToken: + description: The pageToken field. + type: string + pathsReturned: + description: The pathsReturned field. + format: int32 + type: integer + truncatedNodeIds: + description: The truncatedNodeIds field. + items: + type: string + type: + - array + - "null" + title: App Entitlement Search Service Search Graph Response type: object - x-speakeasy-name-override: AppUserServiceUpdateResponse - c1.api.app.v1.AppUserStatus: - description: The satus of the applicaiton user. + x-speakeasy-name-override: AppEntitlementSearchServiceSearchGraphResponse + c1.api.app.v1.AppEntitlementSearchServiceSearchRequest: + description: Search app entitlements by a variety of filters. properties: - details: - description: The details of applicaiton user status. - readOnly: true + accessReviewId: + description: Search for app entitlements that are being reviewed as part of this access review campaign. type: string - status: - description: The application user status field. - enum: - - STATUS_UNSPECIFIED - - STATUS_ENABLED - - STATUS_DISABLED - - STATUS_DELETED - readOnly: true + alias: + description: Search for app entitlements that have this alias (exact match). type: string - x-speakeasy-unknown-values: allow - title: App User Status - type: object - x-speakeasy-name-override: AppUserStatus - c1.api.app.v1.AppUserView: - description: The AppUserView contains an app user as well as paths for apps, identity users, and last usage in expanded arrays. - properties: - appPath: - description: JSONPATH expression indicating where the app is expanded in expanded arrays indicated in the request. - readOnly: false + appIds: + description: Search for app entitlements contained in any of these apps. + items: + type: string + type: + - array + - "null" + appUserIds: + description: Search for app entitlements that are granted to any of these app user ids. + items: + type: string + type: + - array + - "null" + complianceFrameworkIds: + description: Search for app entitlements that are part of these compliance frameworks. + items: + type: string + type: + - array + - "null" + displayName: + description: Filter results to entitlements with this exact display name. type: string - appUser: - $ref: '#/components/schemas/c1.api.app.v1.AppUser' - identityUserPath: - description: JSONPATH expression indicating where the identity user is expanded in expanded arrays indicated in the request. - readOnly: false + excludeAppIds: + description: Exclude app entitlements from the results that are in these app IDs. + items: + type: string + type: + - array + - "null" + excludeAppUserIds: + description: Exclude entitlements from results that are granted to any of these app users. + items: + type: string + type: + - array + - "null" + excludeImmutable: + description: If true, exclude immutable entitlements (e.g., system-managed entitlements that cannot be modified). + type: boolean + excludeResourceTypeIds: + description: Exclude entitlements with any of these resource type IDs from results. + items: + type: string + type: + - array + - "null" + excludedEntitlementRefs: + description: Exclude these specific entitlements from results. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" + includeDeleted: + description: Include deleted app entitlements, this includes app entitlements that have a deleted parent object (app, app resource, app resource type) + type: boolean + isAutomated: + description: If true, restrict results to entitlements that have an automation rule configured. + type: boolean + membershipType: + description: Filter results to entitlements where the user has any of these membership types (e.g., member, owner, admin). + items: + enum: + - APP_ENTITLEMENT_MEMBERSHIP_TYPE_UNSPECIFIED + - APP_ENTITLEMENT_MEMBERSHIP_TYPE_MEMBER + - APP_ENTITLEMENT_MEMBERSHIP_TYPE_OWNER + - APP_ENTITLEMENT_MEMBERSHIP_TYPE_EXCLUSION + - APP_ENTITLEMENT_MEMBERSHIP_TYPE_ADMIN + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + onlyGetExpiring: + description: If true, restrict results to entitlements that have at least one expiring grant. + type: boolean + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - lastUsagePath: - description: JSONPATH expression indicating where the last usage information is expanded in expanded arrays indicated in the request. - readOnly: false + policyRefs: + description: Search for app entitlements that use any of these policies. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' + type: + - array + - "null" + query: + description: Query the app entitlements with a fuzzy search on display name and description. type: string - title: App User View + refs: + description: Filter results to only these specific entitlements. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + requestSchemaIds: + description: Search for app entitlements that are bound to any of these request schemas. + items: + type: string + type: + - array + - "null" + resourceIds: + description: Search for app entitlements that belongs to these resources. + items: + type: string + type: + - array + - "null" + resourceTraitIds: + description: Filter results to entitlements whose resource types have any of these trait IDs. + items: + type: string + type: + - array + - "null" + resourceTypeIds: + description: Search for app entitlements that are for items with resources types that have matching names. Example names are "group", "role", and "app". + items: + type: string + type: + - array + - "null" + riskLevelIds: + description: Search for app entitlements with these risk levels. + items: + type: string + type: + - array + - "null" + sourceConnectorId: + description: Filter results to entitlements synced from this connector. + type: string + title: App Entitlement Search Service Search Request type: object - x-speakeasy-name-override: AppUserView - c1.api.app.v1.AppUsersForUserServiceListResponse: - description: The response message for listing app users correlated to a specific C1 user. + x-speakeasy-name-override: AppEntitlementSearchServiceSearchRequest + c1.api.app.v1.AppEntitlementSearchServiceSearchResponse: + description: The AppEntitlementSearchServiceSearchResponse message. properties: expanded: - description: List of serialized related objects. + description: List of related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5355,324 +7362,604 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" + facets: + oneOf: + - $ref: '#/components/schemas/c1.api.search.v1.Facets' + - type: "null" list: - description: The list of app user results. + description: List of app entitlement view objects. items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + type: + - array + - "null" nextPageToken: - description: The token for fetching the next page of results. - readOnly: false + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: App Users For User Service List Response + title: App Entitlement Search Service Search Response type: object - x-speakeasy-name-override: AppUsersForUserServiceListResponse - c1.api.app.v1.CancelAccessRequestDefaultsRequestInput: - description: The CancelAccessRequestDefaultsRequest message. - title: Cancel Access Request Defaults Request + x-speakeasy-name-override: AppEntitlementSearchServiceSearchResponse + c1.api.app.v1.AppEntitlementServiceGetAutomationResponse: + description: The AppEntitlementServiceGetAutomationResponse message. + properties: + AppEntitlementAutomation: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' + - type: "null" + title: App Entitlement Service Get Automation Response type: object - x-speakeasy-name-override: CancelAccessRequestDefaultsRequest - c1.api.app.v1.ConfirmSyncValidRequestInput: - description: The ConfirmSyncValidRequest message contains the fields required to confirm a sync as valid. - title: Confirm Sync Valid Request + x-speakeasy-name-override: AppEntitlementServiceGetAutomationResponse + c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput: + description: | + The AppEntitlementServiceUpdateAutomationRequest message. + + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - none + - entitlements + - cel + - basic + properties: + basic: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleBasic' + - type: "null" + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleCEL' + - type: "null" + description: + description: The description of the app entitlement. + type: string + displayName: + description: The display name of the app entitlement. + type: string + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleEntitlement' + - type: "null" + none: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomationRuleNone' + - type: "null" + updateMask: + type: + - string + - "null" + title: App Entitlement Service Update Automation Request type: object - x-speakeasy-name-override: ConfirmSyncValidRequest - c1.api.app.v1.ConfirmSyncValidResponse: - description: Empty response body. Status code indicates success. - title: Confirm Sync Valid Response + x-speakeasy-name-override: AppEntitlementServiceUpdateAutomationRequest + c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse: + description: The AppEntitlementServiceUpdateAutomationResponse message. + properties: + AppEntitlementAutomation: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' + - type: "null" + title: App Entitlement Service Update Automation Response type: object - x-speakeasy-name-override: ConfirmSyncValidResponse - c1.api.app.v1.Connector: - description: A Connector is used to sync objects into Apps + x-speakeasy-name-override: AppEntitlementServiceUpdateAutomationResponse + c1.api.app.v1.AppEntitlementUserBinding: + description: The AppEntitlementUserBinding represents the relationship that gives an app user access to an app entitlement properties: - appId: - description: The id of the app the connector is associated with. - readOnly: false + appEntitlementId: + description: The ID of the app entitlement that the app user has access to type: string - canResumeSync: - description: The canResumeSync field. - readOnly: false - type: boolean - catalogId: - description: The catalogId describes which catalog entry this connector is an instance of. For example, every Okta connector will have the same catalogId indicating it is an Okta connector. - readOnly: false + appId: + description: The ID of the app associated with the app entitlement type: string - config: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - configUpdatedAt: - format: date-time - readOnly: true + appUserId: + description: The ID of the app user that has access to the app entitlement type: string - connectorApiVersion: - description: The connectorApiVersion field. - format: uint32 - readOnly: true - type: integer - connectorSyncCronSchedule: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorSyncCronSchedule' createdAt: format: date-time readOnly: true - type: string + type: + - string + - "null" deletedAt: format: date-time readOnly: true - type: string - description: - description: The description of the connector. - readOnly: false - type: string - disableCheckBadSync: - description: The disableCheckBadSync field. - readOnly: false - type: boolean - displayName: - description: The display name of the connector. - readOnly: false - type: string - downloadUrl: - description: The downloadUrl for a spreadsheet if the connector was created from uploading a file. - readOnly: true - type: string - id: - description: The id of the connector. - readOnly: false - type: string - oauthAuthorizedAs: - $ref: '#/components/schemas/c1.api.app.v1.OAuth2AuthorizedAs' - parallelSyncWorkerCount: - description: 'Number of sync workers to use for parallel sync, when the PARALLEL_SYNC feature is enabled. Zero disables parallel sync. Optional on write: omit the field in UpdateAdvancedConfig to leave the stored value unchanged. The public API allows setting up to 4.' - format: int32 - nullable: true - readOnly: false - type: integer - profileAllowList: - description: List of profile attributes to sync, when set only these attributes will be synced - items: - type: string - nullable: true - readOnly: false - type: array - profileIgnoreList: - description: List of profile attributes to ignore (not sync), when set other attributes will be synced, but these will not. - items: - type: string - nullable: true - readOnly: false - type: array - status: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorStatus' - syncConfig: - $ref: '#/components/schemas/c1.api.app.v1.SyncConfig' - syncDisabledAt: + type: + - string + - "null" + deprovisionAt: format: date-time readOnly: true + type: + - string + - "null" + grantSources: + description: The grantSources field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: App Entitlement User Binding + type: object + x-speakeasy-name-override: AppEntitlementUserBinding + c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask: + description: The AppEntitlementUserBindingExpandHistoryMask message. + properties: + paths: + description: The paths field. + items: + type: string + type: + - array + - "null" + title: App Entitlement User Binding Expand History Mask + type: object + x-speakeasy-name-override: AppEntitlementUserBindingExpandHistoryMask + c1.api.app.v1.AppEntitlementUserBindingFeed: + description: The AppEntitlementUserBindingFeed message. + properties: + appEntitlementId: + description: The ID of the app entitlement that the app user has access to type: string - syncDisabledCategory: - description: The category of the connector sync that was disabled. - readOnly: false - type: string - syncDisabledReason: - description: The reason the connector sync was disabled. - readOnly: false + appId: + description: The ID of the app associated with the app entitlement type: string - updatedAt: + appUserId: + description: The ID of the app user that has access to the app entitlement + type: string + date: format: date-time - readOnly: true + type: + - string + - "null" + eventType: + description: The eventType field. + enum: + - GRANT_EVENT_TYPE_UNSPECIFIED + - GRANT_EVENT_TYPE_ADDED + - GRANT_EVENT_TYPE_REMOVED type: string - userIds: - description: The userIds field is used to define the integration owners of the connector. - items: - type: string - nullable: true - readOnly: false - type: array - title: Connector + x-speakeasy-unknown-values: allow + ticketId: + description: The ticketId field. + type: string + title: App Entitlement User Binding Feed type: object - x-speakeasy-name-override: Connector - c1.api.app.v1.ConnectorCredential: - description: ConnectorCredential is used by a connector to authenticate with conductor one. + x-speakeasy-name-override: AppEntitlementUserBindingFeed + c1.api.app.v1.AppEntitlementUserBindingFeedView: + description: The AppEntitlementUserBindingFeedView message. properties: - appId: - description: The appId of the app the connector is attached to. - readOnly: false + appPath: + description: The appPath field. type: string - clientId: - description: The client id of the ConnectorCredential. - readOnly: false + appUserPath: + description: The appUserPath field. type: string - clientSecret: - description: The client secret of the ConnectorCredential. It's only returned on creation. - readOnly: false + entitlementPath: + description: The entitlementPath field. type: string - connectorId: - description: The connectorId of the connector the credential is associated with. - readOnly: false + feed: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingFeed' + - type: "null" + ticketPath: + description: The ticketPath field. type: string - createdAt: + title: App Entitlement User Binding Feed View + type: object + x-speakeasy-name-override: AppEntitlementUserBindingFeedView + c1.api.app.v1.AppEntitlementUserBindingHistory: + description: The AppEntitlementUserBindingHistory message. + properties: + appEntitlementId: + description: The ID of the app entitlement that the app user has access to + type: string + appId: + description: The ID of the app associated with the app entitlement + type: string + appUserId: + description: The ID of the app user that has access to the app entitlement + type: string + grantedAt: format: date-time readOnly: true - type: string - deletedAt: + type: + - string + - "null" + revokedAt: format: date-time readOnly: true + type: + - string + - "null" + title: App Entitlement User Binding History + type: object + x-speakeasy-name-override: AppEntitlementUserBindingHistory + c1.api.app.v1.AppEntitlementUserBindingHistoryView: + description: The AppEntitlementUserBindingHistoryView message. + properties: + appPath: + description: The appPath field. type: string - displayName: - description: The display name of the ConnectorCredential. - readOnly: false + appUserPath: + description: The appUserPath field. type: string - expiresTime: - format: date-time - readOnly: true + entitlementPath: + description: The entitlementPath field. type: string - id: - description: The id of the ConnectorCredential. - readOnly: false + history: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingHistory' + - type: "null" + title: App Entitlement User Binding History View + type: object + x-speakeasy-name-override: AppEntitlementUserBindingHistoryView + c1.api.app.v1.AppEntitlementUserView: + description: The AppEntitlementUserView (aka grant view) describes the relationship between an app user and an entitlement. They have more recently been referred to as grants. + properties: + appEntitlementId: + description: The ID of the app entitlement that the app user has access to. type: string - lastUsedAt: + appEntitlementUserBindingCreatedAt: format: date-time readOnly: true - type: string - updatedAt: + type: + - string + - "null" + appEntitlementUserBindingDeprovisionAt: format: date-time readOnly: true + type: + - string + - "null" + appId: + description: The ID of the app associated with the grant. type: string - title: Connector Credential + appUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + - type: "null" + appUserId: + description: The ID of the app user that has access to the app entitlement. + type: string + grantSources: + description: List of sources for the grant, ie. groups, roles, etc. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + originatingTicketId: + description: The originating ticket ID for the grant (e.g. from a request ticket). + type: string + title: App Entitlement User View type: object - x-speakeasy-entity: ConnectorCredential - x-speakeasy-name-override: ConnectorCredential - c1.api.app.v1.ConnectorExpandMask: - description: The ConnectorExpandMask is used to expand related objects on a connector. + x-speakeasy-name-override: AppEntitlementUserView + c1.api.app.v1.AppEntitlementView: + description: The app entitlement view contains the serialized app entitlement and paths to objects referenced by the app entitlement. properties: - paths: - description: Paths that you want expanded in the response. Possible values are "app_id" and "*". + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appPath: + description: JSONPATH expression indicating the location of the App object in the array. + type: string + appResourcePath: + description: JSONPATH expression indicating the location of the App Resource Type object in the expanded array. + type: string + appResourceTypePath: + description: JSONPATH expression indicating the location of the App Resource object in the array. + type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' + - type: "null" + title: App Entitlement View + type: object + x-speakeasy-name-override: AppEntitlementView + c1.api.app.v1.AppEntitlementWithExpired: + description: A grant with its expiry and discovery timestamps, along with the associated app user and ConductorOne user. + properties: + appEntitlementId: + description: The ID of the app entitlement. + type: string + appId: + description: The ID of the app that contains the entitlement. + type: string + appUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUser' + - type: "null" + appUserId: + description: The ID of the app user who holds the grant. + type: string + discovered: + format: date-time + type: + - string + - "null" + expired: + format: date-time + type: + - string + - "null" + grantReasons: + description: The reasons this grant was given (e.g., access request, automation). items: - type: string - nullable: true - readOnly: false - type: array - title: Connector Expand Mask + $ref: '#/components/schemas/c1.api.app.v1.GrantReason' + type: + - array + - "null" + grantSources: + description: Entitlements that are the source of this grant (e.g., a group membership that implies a role). + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: App Entitlement With Expired type: object - x-speakeasy-name-override: ConnectorExpandMask - c1.api.app.v1.ConnectorRef: - description: The ConnectorRef message. - nullable: true + x-speakeasy-name-override: AppEntitlementWithExpired + c1.api.app.v1.AppEntitlementWithUserBinding: + description: The AppEntitlementWithUserBinding message. + properties: + appEntitlementUserBinding: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserView' + - type: "null" + entitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" + title: App Entitlement With User Binding + type: object + x-speakeasy-name-override: AppEntitlementWithUserBinding + c1.api.app.v1.AppManagedStateBindingRef: + description: The AppManagedStateBindingRef message. properties: appId: description: The appId field. - readOnly: false type: string + resourceId: + description: The resourceId field. + type: string + resourceTypeId: + description: The resourceTypeId field. + type: string + title: App Managed State Binding Ref + type: object + x-speakeasy-name-override: AppManagedStateBindingRef + c1.api.app.v1.AppPopulationReport: + description: The AppPopulationReport is a generated report for a specific app that gives details about the app's users. These details include what groups, roles, and other entitlements the users have access to. + properties: + appId: + description: The appId is the Id of the app which the report is generated for. + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + downloadUrl: + description: The downloadUrl is the url used for downloading the AppPopulationReport. + type: string + hashes: + additionalProperties: + type: string + description: The hashes field contains the file hashes of the report. + type: object id: description: The id field. - readOnly: false type: string - title: Connector Ref + state: + description: The state field tracks the state of the AppPopulationReport. This state field can be one of REPORT_STATE_PENDING, REPORT_STATE_UNSPECIFIED, REPORT_STATE_OK, REPORT_STATE_ERROR. + enum: + - REPORT_STATE_UNSPECIFIED + - REPORT_STATE_PENDING + - REPORT_STATE_OK + - REPORT_STATE_ERROR + type: string + x-speakeasy-unknown-values: allow + title: App Population Report type: object - x-speakeasy-name-override: ConnectorRef - c1.api.app.v1.ConnectorScheduleCron: - description: A cron-based schedule definition for connector syncs. - nullable: true + x-speakeasy-name-override: AppPopulationReport + c1.api.app.v1.AppRef: + description: The AppRef message. properties: - cronSpec: - description: The cron expression defining the sync schedule. - readOnly: false - type: string - timezone: - description: The IANA timezone name for the cron schedule (e.g., "America/Los_Angeles"). - readOnly: false + id: + description: The id field. type: string - title: Connector Schedule Cron + title: App Ref type: object - x-speakeasy-name-override: ConnectorScheduleCron - c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput: - description: The ConnectorServiceCreateDelegatedRequest message contains the fields required to create a connector. + x-speakeasy-name-override: AppRef + c1.api.app.v1.AppReportServiceListResponse: + description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. properties: - appEntitlementOwnerRefs: - description: Sets entitlement owners on the app. + list: + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - appManagedStateBindingRef: - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingRef' - catalogId: - description: The catalogId describes which catalog entry this connector is an instance of. For example, every Okta connector will have the same catalogId indicating it is an Okta connector. - readOnly: false + $ref: '#/components/schemas/c1.api.app.v1.AppPopulationReport' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: App Report Service List Response + type: object + x-speakeasy-name-override: AppReportServiceListResponse + c1.api.app.v1.AppResource: + description: | + The app resource message is a single resource that can have entitlements. + + This message contains a oneof named metadata. Only a single field of the following list may be set at a time: + - secretTrait + properties: + accessConfigId: + description: |- + The access config ID for this resource. May be empty. + Must be one of the builtin access config IDs or empty. + type: string + agentTrait: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AgentTrait' + - type: "null" + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ + are reserved. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + + Most AppResources are connector-synced; user-supplied annotations on + a synced resource will be overwritten by the next sync. The + annotations bag is most useful on user-created groups (the + `conductorone_app_resource` TF resource). + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appId: + description: The app that this resource belongs to. + type: string + appResourceTypeId: + description: The resource type that this resource is. + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + customDescription: + description: A custom description that can be set for a resource. type: string + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" description: - description: The description of the connector. - readOnly: false + description: The description set for the resource. type: string displayName: - description: The displayName of the connector. - readOnly: false + description: The display name for this resource. type: string - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' - userIds: - description: The userIds field is used to define the integration owners of the connector. + externalId: + description: |- + The upstream product's native external ID for this resource (e.g. an Okta group ID). + Populated from the connector's external ID during sync. + readOnly: true + type: string + grantCount: + description: The number of grants to this resource. + format: int64 + type: string + id: + description: The id of the resource. + type: string + matchBatonId: + description: The matchBatonId field. + type: string + nhiDetail: + description: |- + Axis-2 detail refining nhi_type (e.g. "aws.role.lambda"). Read-only; + translated from the model. + readOnly: true + type: string + nhiType: + description: |- + The NHI classification (K3 spine) for this resource. Populated for + non-human-identity resources; UNSPECIFIED for everything else. Mirrors + agent_trait: read-only and translated from the model enum at the API boundary. + enum: + - NHI_TYPE_UNSPECIFIED + - NHI_TYPE_APP_REGISTRATION + - NHI_TYPE_ASSUMABLE_ROLE + - NHI_TYPE_MANAGED_IDENTITY + readOnly: true + type: string + x-speakeasy-unknown-values: allow + parentAppResourceId: + description: The parent resource id, if this resource is a child of another resource. + type: string + parentAppResourceTypeId: + description: The parent resource type id, if this resource is a child of another resource. + type: string + profile: + additionalProperties: true + readOnly: true + type: + - object + - "null" + secretTrait: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.SecretTrait' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App Resource + type: object + x-speakeasy-entity: App Resource + x-speakeasy-name-override: AppResource + c1.api.app.v1.AppResourceExpandMask: + description: The app resource expand mask lets you get information about related objects from the request. + properties: + paths: + description: The app resource expanded fields. Maybe be any combination of "*", "app_id", "app_resource_type_id". items: type: string - nullable: true - readOnly: false - type: array - title: Connector Service Create Delegated Request + type: + - array + - "null" + title: App Resource Expand Mask type: object - x-speakeasy-name-override: ConnectorServiceCreateDelegatedRequest - c1.api.app.v1.ConnectorServiceCreateRequestInput: - description: The ConnectorServiceCreateRequest message. + x-speakeasy-name-override: AppResourceExpandMask + c1.api.app.v1.AppResourceRef: + description: A reference to a specific app resource by its composite key. properties: - catalogId: - description: The catalogId field. - readOnly: false + appId: + description: The ID of the app that owns the resource. type: string - config: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - description: - description: The description field. - readOnly: false + appResourceTypeId: + description: The ID of the resource type that classifies this resource. type: string - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' - userIds: - description: The userIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Connector Service Create Request + id: + description: The unique ID of the app resource. + type: string + title: App Resource Ref type: object - x-speakeasy-name-override: ConnectorServiceCreateRequest - c1.api.app.v1.ConnectorServiceCreateResponse: - description: The ConnectorServiceCreateResponse is the response returned from creating a connector. + x-speakeasy-name-override: AppResourceRef + c1.api.app.v1.AppResourceServiceGetResponse: + description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. properties: - connectorView: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' + appResourceView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' + - type: "null" expanded: - description: The array of expanded items indicated by the request. + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5680,39 +7967,18 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Connector Service Create Response - type: object - x-speakeasy-name-override: ConnectorServiceCreateResponse - c1.api.app.v1.ConnectorServiceDeleteRequestInput: - description: ConnectorServiceDeleteRequest is a request for deleting a connector. It uses URL values for input. - title: Connector Service Delete Request - type: object - x-speakeasy-name-override: ConnectorServiceDeleteRequest - c1.api.app.v1.ConnectorServiceDeleteResponse: - description: Empty response body. Status code indicates success. - title: Connector Service Delete Response - type: object - x-speakeasy-name-override: ConnectorServiceDeleteResponse - c1.api.app.v1.ConnectorServiceGetCredentialsResponse: - description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. - properties: - credential: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorCredential' - title: Connector Service Get Credentials Response + type: + - array + - "null" + title: App Resource Service Get Response type: object - x-speakeasy-name-override: ConnectorServiceGetCredentialsResponse - c1.api.app.v1.ConnectorServiceGetResponse: - description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. + x-speakeasy-name-override: AppResourceServiceGetResponse + c1.api.app.v1.AppResourceServiceListResponse: + description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. properties: - connectorView: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' expanded: - description: The array of expanded items indicated by the request. + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5720,19 +7986,53 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Connector Service Get Response + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: App Resource Service List Response type: object - x-speakeasy-name-override: ConnectorServiceGetResponse - c1.api.app.v1.ConnectorServiceListResponse: - description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable + x-speakeasy-name-override: AppResourceServiceListResponse + c1.api.app.v1.AppResourceServiceUpdateRequestInput: + description: The request message for updating an app resource. + properties: + appResource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResource' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: App Resource Service Update Request + type: object + x-speakeasy-name-override: AppResourceServiceUpdateRequest + c1.api.app.v1.AppResourceServiceUpdateResponse: + description: The response message for updating an app resource. properties: + appResourceView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' + - type: "null" expanded: - description: List of serialized related objects + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5740,95 +8040,86 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request - items: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: Connector Service List Response - type: object - x-speakeasy-name-override: ConnectorServiceListResponse - c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput: - description: ConnectorServiceRevokeCredentialRequest is a request for revoking connector credentials. It uses URL values for input. - title: Connector Service Revoke Credential Request - type: object - x-speakeasy-entity: ConnectorCredential - x-speakeasy-name-override: ConnectorServiceRevokeCredentialRequest - c1.api.app.v1.ConnectorServiceRevokeCredentialResponse: - description: Empty response body. Status code indicates success. - title: Connector Service Revoke Credential Response + type: + - array + - "null" + title: App Resource Service Update Response type: object - x-speakeasy-entity: ConnectorCredential - x-speakeasy-name-override: ConnectorServiceRevokeCredentialResponse - c1.api.app.v1.ConnectorServiceRotateCredentialRequest: - description: ConnectorServiceRotateCredentialRequest is a request for rotating connector credentials. It uses URL values for input. + x-speakeasy-name-override: AppResourceServiceUpdateResponse + c1.api.app.v1.AppResourceType: + description: The AppResourceType is referenced by an app entitlement defining its resource types. Commonly things like Group or Role. properties: appId: - description: The appId of the app the connector is attached to. - readOnly: false + description: The ID of the app that is associated with the app resource type + readOnly: true type: string - connectorId: - description: The connectorId of the connector that we are rotating the credentials for. - readOnly: false + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the app resource type. type: string - title: Connector Service Rotate Credential Request - type: object - x-speakeasy-entity: ConnectorCredential - x-speakeasy-name-override: ConnectorServiceRotateCredentialRequest - c1.api.app.v1.ConnectorServiceRotateCredentialResponse: - description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. - properties: - credential: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorCredential' - title: Connector Service Rotate Credential Response - type: object - x-speakeasy-name-override: ConnectorServiceRotateCredentialResponse - c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput: - description: The ConnectorServiceUpdateDelegatedRequest message contains the fields required to update a connector. - properties: - connector: - $ref: '#/components/schemas/c1.api.app.v1.Connector' - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' - updateMask: - nullable: true - readOnly: false + id: + description: The unique ID for the app resource type. + readOnly: true type: string - title: Connector Service Update Delegated Request + traitIds: + description: Associated trait ids + items: + type: string + type: + - array + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App Resource Type type: object - x-speakeasy-name-override: ConnectorServiceUpdateDelegatedRequest - c1.api.app.v1.ConnectorServiceUpdateRequestInput: - description: The ConnectorServiceUpdateRequest message contains the fields required to update a connector. + x-speakeasy-entity: App Resource Type + x-speakeasy-name-override: AppResourceType + c1.api.app.v1.AppResourceTypeServiceGetResponse: + description: |- + The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask + in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. properties: - connector: - $ref: '#/components/schemas/c1.api.app.v1.Connector' - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' - updateMask: - nullable: true - readOnly: false - type: string - title: Connector Service Update Request + appResourceTypeView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeView' + - type: "null" + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: App Resource Type Service Get Response type: object - x-speakeasy-name-override: ConnectorServiceUpdateRequest - c1.api.app.v1.ConnectorServiceUpdateResponse: - description: ConnectorServiceUpdateResponse is the response returned by the update method. + x-speakeasy-name-override: AppResourceTypeServiceGetResponse + c1.api.app.v1.AppResourceTypeServiceListResponse: + description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. properties: - connectorView: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' expanded: - description: The array of expanded items indicated by the request. + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -5836,98 +8127,314 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Connector Service Update Response + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: App Resource Type Service List Response type: object - x-speakeasy-name-override: ConnectorServiceUpdateResponse - c1.api.app.v1.ConnectorStatus: - description: The status field on the connector is used to track the status of the connectors sync, and when syncing last started, completed, or caused the connector to update. + x-speakeasy-name-override: AppResourceTypeServiceListResponse + c1.api.app.v1.AppResourceTypeView: + description: The AppResourceTypeView message. properties: - completedAt: - format: date-time - readOnly: false + appPath: + description: JSONPATH expression indicating the location of the App object in the array type: string - lastError: - description: The last error encountered by the connector. - readOnly: false + appResourceType: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' + - type: "null" + title: App Resource Type View + type: object + x-speakeasy-name-override: AppResourceTypeView + c1.api.app.v1.AppResourceView: + description: The app resource view returns an app resource with paths for items in the expand mask filled in when this response is returned and a request expand mask has "*" or "app_id" or "resource_type_id". + properties: + appPath: + description: JSONPATH expression indicating the location of the App object in the array type: string - startedAt: - format: date-time - readOnly: false + appResource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResource' + - type: "null" + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions' + - type: "null" + parentResourcePath: + description: JSONPATH expression indicating the location of the Parent Resource object in the array type: string - status: - description: The status of the connector sync. + parentResourceTypePath: + description: JSONPATH expression indicating the location of the Parent Resource Type object in the array + type: string + resourceTypePath: + description: JSONPATH expression indicating the location of the Resource Type object in the array + type: string + title: App Resource View + type: object + x-speakeasy-name-override: AppResourceView + c1.api.app.v1.AppUsageControls: + description: The AppUsageControls object describes some peripheral configuration for an app. + properties: + appId: + description: The app that this object belongs to. + type: string + notify: + description: Whether or not to notify some if they have access to the app, but has not used it within a configurable amount of time. + type: boolean + notifyAfterDays: + description: The duration in days after which we notify users of nonusage. + format: uint32 + type: integer + revoke: + description: Whether or not to revoke a grant if they have access to the app, but has not used it within a configurable amount of time. + type: boolean + revokeAfterDays: + description: The duration in days after which we revoke users that have not used that grant. + format: uint32 + type: integer + title: App Usage Controls + type: object + x-speakeasy-name-override: AppUsageControls + c1.api.app.v1.AppUser: + description: Application User that represents an account in the application. + properties: + appId: + description: The ID of the application. + readOnly: true + type: string + appUserType: + description: The appplication user type. Type can be user, system or service. enum: - - SYNC_STATUS_UNSPECIFIED - - SYNC_STATUS_RUNNING - - SYNC_STATUS_DONE - - SYNC_STATUS_ERROR - - SYNC_STATUS_DISABLED - readOnly: false + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT type: string x-speakeasy-unknown-values: allow + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the application user. + readOnly: true + type: string + email: + description: The email field of the application user. + readOnly: true + type: string + emails: + description: The emails field of the application user. + items: + type: string + readOnly: true + type: + - array + - "null" + employeeIds: + description: The employee IDs field of the application user. + items: + type: string + readOnly: true + type: + - array + - "null" + id: + description: A unique idenditfier of the application user. + readOnly: true + type: string + identityUserId: + description: The conductor one user ID of the account owner. + readOnly: true + type: string + isExternal: + description: The isExternal field. + readOnly: true + type: boolean + profile: + additionalProperties: true + readOnly: true + type: + - object + - "null" + status: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserStatus' + - type: "null" updatedAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + username: + description: The username field of the application user. + readOnly: true type: string - title: Connector Status + usernames: + description: The usernames field of the application user. + items: + type: string + readOnly: true + type: + - array + - "null" + title: App User type: object - x-speakeasy-name-override: ConnectorStatus - c1.api.app.v1.ConnectorSyncCronSchedule: - description: The ConnectorSyncCronSchedule message. + x-speakeasy-name-override: AppUser + c1.api.app.v1.AppUserCredential: + description: | + A credentials for the Application User that represents an account in the application. + + This message contains a oneof named credential. Only a single field of the following list may be set at a time: + - encryptedData properties: - cronSpec: - description: The cronSpec field. - readOnly: false + appId: + description: The ID of the application. + readOnly: true type: string - start: + appUserId: + description: A unique identifier of the application user. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + encryptedData: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.EncryptedData' + - type: "null" + expiresAt: format: date-time - readOnly: false + type: + - string + - "null" + id: + description: A unique identifier of the credential. + readOnly: true type: string - timezone: - description: The timezone field. - readOnly: false + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: App User Credential + type: object + x-speakeasy-name-override: AppUserCredential + c1.api.app.v1.AppUserExpandMask: + description: The AppUserExpandMask message contains a list of paths to expand in the response. + properties: + paths: + description: The paths to expand in the response. May be any combination of "*", "identity_user_id", "app_id", and "last_usage". + items: + type: string + type: + - array + - "null" + title: App User Expand Mask + type: object + x-speakeasy-name-override: AppUserExpandMask + c1.api.app.v1.AppUserMapper: + description: AppUserMapper configures custom account mapping for uplift. + properties: + appId: + description: The app this mapper belongs to. + readOnly: true type: string - title: Connector Sync Cron Schedule + mappingCases: + description: Ordered list of match cases. Each case defines a pair of CEL key extractors. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserMapperMatchCase' + type: + - array + - "null" + title: App User Mapper type: object - x-speakeasy-name-override: ConnectorSyncCronSchedule - c1.api.app.v1.ConnectorView: - description: The ConnectorView object provides a connector response object, as well as JSONPATHs to related objects provided by expanders. + x-speakeasy-name-override: AppUserMapper + c1.api.app.v1.AppUserMapperMatchCase: + description: AppUserMapperMatchCase defines a single matching rule for uplift account mapping. properties: - appPath: - description: JSONPATH expression indicating the location of the App object in the expanded array. - readOnly: false + appId: + description: The app this match case belongs to. + readOnly: true type: string - capabilitiesPath: - description: JSONPATH expression indicating the location of the ConnectorCapabilities object in the expanded array. - readOnly: false + appUserKeyCel: + description: CEL expression evaluated against an AppUser to produce match key(s). type: string - connector: - $ref: '#/components/schemas/c1.api.app.v1.Connector' - usersPath: - description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. - readOnly: false + caseIndex: + description: The ordered index of this match case within the mapper. + format: uint32 + readOnly: true + type: integer + userKeyCel: + description: CEL expression evaluated against a User to produce match key(s). type: string - title: Connector View + title: App User Mapper Match Case type: object - x-speakeasy-name-override: ConnectorView - c1.api.app.v1.CreateAppEntitlementProxyRequestInput: - description: The request message for creating an entitlement proxy binding. + x-speakeasy-name-override: AppUserMapperMatchCase + c1.api.app.v1.AppUserRef: + description: The AppUserRef message. properties: - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyExpandMask' - title: Create App Entitlement Proxy Request + appId: + description: The ID of the application. + type: string + id: + description: The ID of the app user. + type: string + title: App User Ref type: object - x-speakeasy-name-override: CreateAppEntitlementProxyRequest - c1.api.app.v1.CreateAppEntitlementProxyResponse: - description: The response message for creating an entitlement proxy binding. + x-speakeasy-name-override: AppUserRef + c1.api.app.v1.AppUserServiceListCredentialsResponse: + description: The response message for listing credentials of an app user. + properties: + list: + description: The list of credential results. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserCredential' + type: + - array + - "null" + nextPageToken: + description: The token for fetching the next page of results. + type: string + title: App User Service List Credentials Response + type: object + x-speakeasy-name-override: AppUserServiceListCredentialsResponse + c1.api.app.v1.AppUserServiceListResponse: + description: The response message for listing app users. properties: - appProxyEntitlementView: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyView' expanded: description: List of serialized related objects. items: @@ -5937,124 +8444,203 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Create App Entitlement Proxy Response + type: + - array + - "null" + list: + description: The list of app user results. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + type: + - array + - "null" + nextPageToken: + description: The token for fetching the next page of results. + type: string + title: App User Service List Response type: object - x-speakeasy-name-override: CreateAppEntitlementProxyResponse - c1.api.app.v1.CreateAppEntitlementRequestInput: - description: | - The CreateAppEntitlementRequest message. - - This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: - - durationUnset - - durationGrant + x-speakeasy-name-override: AppUserServiceListResponse + c1.api.app.v1.AppUserServiceSearchRequest: + description: Search App users based on filters specified in the request body properties: - alias: - description: A unique alias for the entitlement, used for programmatic lookups and Cone. - readOnly: false + appId: + description: The app ID to restrict the search to. type: string - appEntitlementOwnerIds: - description: The IDs of users to set as owners of this entitlement. + appIds: + description: A list of app IDs to restrict the search to. items: type: string - nullable: true - readOnly: false - type: array - appResourceId: - description: The ID of the resource that this entitlement belongs to. - readOnly: false - type: string - appResourceTypeId: - description: The ID of the resource type that this entitlement belongs to. - readOnly: false - type: string - certifyPolicyId: - description: The ID of the policy to use for certification tasks. - readOnly: false - type: string - complianceFrameworkValueIds: - description: The IDs of compliance frameworks to associate with this entitlement (e.g., SOX, HIPAA). + type: + - array + - "null" + appUserDomains: + description: A list of account domains to restrict the search to. items: + enum: + - APP_USER_DOMAIN_UNSPECIFIED + - APP_USER_DOMAIN_EXTERNAL + - APP_USER_DOMAIN_TRUSTED type: string - nullable: true - readOnly: false - type: array - description: - description: The description of the new entitlement. - readOnly: false - type: string - displayName: - description: The display name of the new entitlement. - readOnly: false - type: string - durationGrant: - format: duration - readOnly: false - type: string - durationUnset: - nullable: true - readOnly: false - type: object - emergencyGrantEnabled: - description: Whether emergency grant requests are enabled for this entitlement. - readOnly: false + x-speakeasy-unknown-values: allow + type: + - array + - "null" + appUserIds: + description: A list of app user IDs to restrict the search to. + items: + type: string + type: + - array + - "null" + appUserStatusDetails: + description: A list of app user status details to restrict the search to. + items: + type: string + type: + - array + - "null" + appUserStatuses: + description: A list of app user statuses to restrict the search to. + items: + enum: + - STATUS_UNSPECIFIED + - STATUS_ENABLED + - STATUS_DISABLED + - STATUS_DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + appUserTypes: + description: A list of app user types to restrict the search to. + items: + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + excludeAppUserIds: + description: A list of app user IDs to remove from the results. + items: + type: string + type: + - array + - "null" + excludeDeletedApps: + description: When true, excludes app users belonging to soft-deleted apps. type: boolean - emergencyGrantPolicyId: - description: The ID of the policy to use for emergency grant tasks. Required if emergency_grant_enabled is true. - readOnly: false - type: string expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - grantPolicyId: - description: The ID of the policy to use for grant request tasks. - readOnly: false + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' + - type: "null" + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - matchBatonId: - description: If supplied, it's implied that the entitlement is created before sync and needs to be merged with connector entitlement. - readOnly: false + query: + description: Query the apps with a fuzzy search on display name and description. type: string - overrideAccessRequestsDefaults: - description: Whether to override the app-level access request defaults for this entitlement. - readOnly: false - type: boolean - provisionPolicy: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - purpose: - description: The purpose of the entitlement (e.g., assignment, permission, ownership). + refs: + description: A list of app users to limit the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' + type: + - array + - "null" + sortBy: + description: Ordering of the results. Defaults to display-name ordering. enum: - - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED - - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT - - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION - - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP - readOnly: false + - APP_USER_SEARCH_SORT_BY_UNSPECIFIED + - APP_USER_SEARCH_SORT_BY_APP type: string x-speakeasy-unknown-values: allow - revokePolicyId: - description: The ID of the policy to use for revoke request tasks. - readOnly: false - type: string - riskLevelValueId: - description: The ID of the risk level to assign to this entitlement. - readOnly: false - type: string - slug: - description: A short label describing the permission the entitlement grants (e.g., "Admin", "Read"). - readOnly: false + userIds: + description: A list of user IDs to restrict the search by. + items: + type: string + type: + - array + - "null" + withOpenFindings: + description: |- + When true, restrict results to app users that have at least one open finding + (index-backed EXISTS semi-join). When false/unset, results are unfiltered. + type: boolean + withoutResponsibleParty: + description: |- + When true, restrict results to app users with no responsible party + (identity_user_id empty) — i.e. unowned, for any app-user type. + type: boolean + title: App User Service Search Request + type: object + x-speakeasy-name-override: AppUserServiceSearchRequest + c1.api.app.v1.AppUserServiceSearchResponse: + description: The AppUserServiceSearchResponse message. + properties: + expanded: + description: List of related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retrieved. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - required: - - displayName - title: Create App Entitlement Request + title: App User Service Search Response type: object - x-speakeasy-name-override: CreateAppEntitlementRequest - c1.api.app.v1.CreateAppEntitlementResponse: - description: The CreateAppEntitlementResponse message. + x-speakeasy-name-override: AppUserServiceSearchResponse + c1.api.app.v1.AppUserServiceUpdateRequestInput: + description: The AppUserServiceUpdateRequest message contains the app user and the fields to be updated. properties: - appEntitlementView: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + appUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUser' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: App User Service Update Request + type: object + x-speakeasy-name-override: AppUserServiceUpdateRequest + c1.api.app.v1.AppUserServiceUpdateResponse: + description: The AppUserServiceUpdateResponse message. + properties: + appUserView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + - type: "null" expanded: description: The expanded field. items: @@ -6064,171 +8650,55 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Create App Entitlement Response + type: + - array + - "null" + title: App User Service Update Response type: object - x-speakeasy-name-override: CreateAppEntitlementResponse - c1.api.app.v1.CreateAppRequest: - description: The CreateAppRequest message is used to create a new app. + x-speakeasy-name-override: AppUserServiceUpdateResponse + c1.api.app.v1.AppUserStatus: + description: The satus of the applicaiton user. properties: - appEntitlementOwnerRefs: - description: Sets entitlement owners on the app. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - certifyPolicyId: - description: Creates the app with this certify policy. - readOnly: false - type: string - description: - description: Creates the app with this description. - readOnly: false - type: string - displayName: - description: Creates the app with this display name. - readOnly: false - type: string - grantPolicyId: - description: Creates the app with this grant policy. - readOnly: false + details: + description: The details of applicaiton user status. + readOnly: true type: string - identityMatching: - description: Define the app user identity matching strategy for this app. + status: + description: The application user status field. enum: - - APP_USER_IDENTITY_MATCHING_UNSPECIFIED - - APP_USER_IDENTITY_MATCHING_STRICT - - APP_USER_IDENTITY_MATCHING_DISPLAY_NAME - - APP_USER_IDENTITY_MATCHING_CUSTOM - readOnly: false + - STATUS_UNSPECIFIED + - STATUS_ENABLED + - STATUS_DISABLED + - STATUS_DELETED + readOnly: true type: string x-speakeasy-unknown-values: allow - instructions: - description: Instructions shown to users in the access request form when requesting access for this app. - readOnly: false - type: string - monthlyCostUsd: - description: Creates the app with this monthly cost per seat. - format: int32 - readOnly: false - type: integer - owners: - description: Creates the app with this array of user owners. - items: - type: string - nullable: true - readOnly: false - type: array - revokePolicyId: - description: Creates the app with this revoke policy. - readOnly: false - type: string - strictAccessEntitlementProvisioning: - description: This flag enforces a provisioning mode where the access entitlement is always included in the provisioning flow, if the app user doesn't exist - readOnly: false - type: boolean - required: - - displayName - title: Create App Request - type: object - x-speakeasy-entity: App - x-speakeasy-name-override: CreateAppRequest - c1.api.app.v1.CreateAppResponse: - description: Returns the new app's values. - properties: - app: - $ref: '#/components/schemas/c1.api.app.v1.App' - title: Create App Response - type: object - x-speakeasy-name-override: CreateAppResponse - c1.api.app.v1.CreateAutomationRequestInput: - description: The CreateAutomationRequest message. - properties: - automation: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' - title: Create Automation Request - type: object - x-speakeasy-name-override: CreateAutomationRequest - c1.api.app.v1.CreateAutomationResponse: - description: The CreateAutomationResponse message. - properties: - automation: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' - title: Create Automation Response + title: App User Status type: object - x-speakeasy-name-override: CreateAutomationResponse - c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput: - description: The request message for creating a manually managed app resource. + x-speakeasy-name-override: AppUserStatus + c1.api.app.v1.AppUserView: + description: The AppUserView contains an app user as well as paths for apps, identity users, and last usage in expanded arrays. properties: - description: - description: An optional description for the new resource. - readOnly: false - type: string - displayName: - description: The display name for the new resource. - readOnly: false - type: string - matchBatonId: - description: If supplied, it's implied that the resource is created before sync and needs to be merged with connector resource. - readOnly: false + appPath: + description: JSONPATH expression indicating where the app is expanded in expanded arrays indicated in the request. type: string - resourceOwnerUserIds: - description: C1 user IDs to assign as owners of this resource. - items: - type: string - nullable: true - readOnly: false - type: array - required: - - displayName - title: Create Manually Managed App Resource Request - type: object - x-speakeasy-name-override: CreateManuallyManagedAppResourceRequest - c1.api.app.v1.CreateManuallyManagedAppResourceResponse: - description: The response message for creating a manually managed app resource. - properties: - appResource: - $ref: '#/components/schemas/c1.api.app.v1.AppResource' - title: Create Manually Managed App Resource Response - type: object - x-speakeasy-name-override: CreateManuallyManagedAppResourceResponse - c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput: - description: The request message for creating a manually managed resource type. - properties: - displayName: - description: The display name for the new resource type. - readOnly: false + appUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUser' + - type: "null" + identityUserPath: + description: JSONPATH expression indicating where the identity user is expanded in expanded arrays indicated in the request. type: string - resourceType: - description: The category of the resource type (e.g., ROLE, GROUP, LICENSE). - enum: - - ROLE - - GROUP - - LICENSE - - PROJECT - - CATALOG - - CUSTOM - - VAULT - - PROFILE_TYPE - readOnly: false + lastUsagePath: + description: JSONPATH expression indicating where the last usage information is expanded in expanded arrays indicated in the request. type: string - x-speakeasy-unknown-values: allow - required: - - resourceType - - displayName - title: Create Manually Managed Resource Type Request + title: App User View type: object - x-speakeasy-name-override: CreateManuallyManagedResourceTypeRequest - c1.api.app.v1.CreateManuallyManagedResourceTypeResponse: - description: The response message for creating a manually managed resource type. + x-speakeasy-name-override: AppUserView + c1.api.app.v1.AppUsersForUserServiceListResponse: + description: The response message for listing app users correlated to a specific C1 user. properties: - appResourceType: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' expanded: description: List of serialized related objects. items: @@ -6238,343 +8708,388 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Create Manually Managed Resource Type Response - type: object - x-speakeasy-name-override: CreateManuallyManagedResourceTypeResponse - c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput: - description: The request message for deleting app entitlement owners. - title: Delete App Entitlement Owners Request - type: object - x-speakeasy-name-override: DeleteAppEntitlementOwnersRequest - c1.api.app.v1.DeleteAppEntitlementOwnersResponse: - description: the empty response message for deleting app entitlement owners. - title: Delete App Entitlement Owners Response - type: object - x-speakeasy-name-override: DeleteAppEntitlementOwnersResponse - c1.api.app.v1.DeleteAppEntitlementProxyRequestInput: - description: The request message for deleting an entitlement proxy binding. - title: Delete App Entitlement Proxy Request - type: object - x-speakeasy-name-override: DeleteAppEntitlementProxyRequest - c1.api.app.v1.DeleteAppEntitlementProxyResponse: - description: The empty response message for deleting an entitlement proxy binding. - title: Delete App Entitlement Proxy Response - type: object - x-speakeasy-name-override: DeleteAppEntitlementProxyResponse - c1.api.app.v1.DeleteAppEntitlementRequestInput: - description: The DeleteAppEntitlementRequest message. - title: Delete App Entitlement Request - type: object - x-speakeasy-name-override: DeleteAppEntitlementRequest - c1.api.app.v1.DeleteAppEntitlementResponse: - description: The DeleteAppEntitlementResponse message. - title: Delete App Entitlement Response - type: object - x-speakeasy-name-override: DeleteAppEntitlementResponse - c1.api.app.v1.DeleteAppOwnersRequestInput: - description: The request message for deleting app owners. - properties: - userIds: - description: The user_ids field for the users to set as an owner of the app. + type: + - array + - "null" + list: + description: The list of app user results. items: - type: string - nullable: true - readOnly: false - type: array - title: Delete App Owners Request - type: object - x-speakeasy-name-override: DeleteAppOwnersRequest - c1.api.app.v1.DeleteAppOwnersResponse: - description: the empty response message for deleting app owners. - title: Delete App Owners Response - type: object - x-speakeasy-name-override: DeleteAppOwnersResponse - c1.api.app.v1.DeleteAppRequestInput: - description: Empty request body - title: Delete App Request + $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + type: + - array + - "null" + nextPageToken: + description: The token for fetching the next page of results. + type: string + title: App Users For User Service List Response type: object - x-speakeasy-entity: App - x-speakeasy-name-override: DeleteAppRequest - c1.api.app.v1.DeleteAppResourceOwnersRequestInput: - description: The request message for deleting app resource owners. - title: Delete App Resource Owners Request + x-speakeasy-name-override: AppUsersForUserServiceListResponse + c1.api.app.v1.CancelAccessRequestDefaultsRequestInput: + description: The CancelAccessRequestDefaultsRequest message. + title: Cancel Access Request Defaults Request type: object - x-speakeasy-name-override: DeleteAppResourceOwnersRequest - c1.api.app.v1.DeleteAppResourceOwnersResponse: - description: the empty response message for deleting app resource owners. - title: Delete App Resource Owners Response + x-speakeasy-name-override: CancelAccessRequestDefaultsRequest + c1.api.app.v1.ConfirmSyncValidRequestInput: + description: The ConfirmSyncValidRequest message contains the fields required to confirm a sync as valid. + title: Confirm Sync Valid Request type: object - x-speakeasy-name-override: DeleteAppResourceOwnersResponse - c1.api.app.v1.DeleteAppResponse: + x-speakeasy-name-override: ConfirmSyncValidRequest + c1.api.app.v1.ConfirmSyncValidResponse: description: Empty response body. Status code indicates success. - title: Delete App Response - type: object - x-speakeasy-name-override: DeleteAppResponse - c1.api.app.v1.DeleteAutomationRequestInput: - description: The DeleteAutomationRequest message. - title: Delete Automation Request - type: object - x-speakeasy-name-override: DeleteAutomationRequest - c1.api.app.v1.DeleteAutomationResponse: - description: The DeleteAutomationResponse message. - title: Delete Automation Response - type: object - x-speakeasy-name-override: DeleteAutomationResponse - c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput: - description: The request message for deleting a manually managed app resource. - title: Delete Manually Managed App Resource Request - type: object - x-speakeasy-name-override: DeleteManuallyManagedAppResourceRequest - c1.api.app.v1.DeleteManuallyManagedAppResourceResponse: - description: The empty response message for deleting a manually managed app resource. - title: Delete Manually Managed App Resource Response - type: object - x-speakeasy-name-override: DeleteManuallyManagedAppResourceResponse - c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput: - description: The request message for deleting a manually managed resource type. - title: Delete Manually Managed Resource Type Request - type: object - x-speakeasy-name-override: DeleteManuallyManagedResourceTypeRequest - c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse: - description: The empty response message for deleting a manually managed resource type. - title: Delete Manually Managed Resource Type Response + title: Confirm Sync Valid Response type: object - x-speakeasy-name-override: DeleteManuallyManagedResourceTypeResponse - c1.api.app.v1.EditorValidateRequest: - description: The EditorValidateRequest message contains the configuration text to validate. + x-speakeasy-name-override: ConfirmSyncValidResponse + c1.api.app.v1.Connector: + description: A Connector is used to sync objects into Apps properties: - text: - description: The configuration text to validate. - readOnly: false + appId: + description: The id of the app the connector is associated with. type: string - title: Editor Validate Request - type: object - x-speakeasy-name-override: EditorValidateRequest - c1.api.app.v1.EditorValidateResponse: - description: The EditorValidateResponse message contains validation results. - properties: - markers: - description: The list of diagnostic markers found during validation. - items: - $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' - nullable: true + canResumeSync: + description: The canResumeSync field. + type: boolean + catalogId: + description: The catalogId describes which catalog entry this connector is an instance of. For example, every Okta connector will have the same catalogId indicating it is an Okta connector. + type: string + config: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: + - object + - "null" + configUpdatedAt: + format: date-time readOnly: true - type: array - title: Editor Validate Response - type: object - x-speakeasy-name-override: EditorValidateResponse - c1.api.app.v1.EncryptedData: - description: EncryptedData is a message that contains encrypted bytes and metadata. - nullable: true - properties: - description: - description: The human-readable description of the encrypted data. + type: + - string + - "null" + connectorApiVersion: + description: The connectorApiVersion field. + format: uint32 readOnly: true - type: string - encryptedBytes: - description: The encrypted bytes. - format: base64 + type: integer + connectorSyncCronSchedule: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorSyncCronSchedule' + - type: "null" + createdAt: + format: date-time readOnly: true - type: string - keyId: - description: The key ID used to encrypt the data. + type: + - string + - "null" + deletedAt: + format: date-time readOnly: true + type: + - string + - "null" + description: + description: The description of the connector. type: string - name: - description: The human-readable name of the encrypted data. - readOnly: true + disableCheckBadSync: + description: The disableCheckBadSync field. + type: boolean + displayName: + description: The display name of the connector. type: string - provider: - description: The encryption provider used to encrypt the data. + downloadUrl: + description: The downloadUrl for a spreadsheet if the connector was created from uploading a file. readOnly: true type: string - schema: - description: The (optional) JSON schema of the encrypted data. - readOnly: true + id: + description: The id of the connector. type: string - title: Encrypted Data - type: object - x-speakeasy-name-override: EncryptedData - c1.api.app.v1.ForceSyncRequestInput: - description: Signal the connector to start syncing. This puts the sync on the queue. It does not guarantee immediate sync. Long syncs still take minutes to hours. - title: Force Sync Request - type: object - x-speakeasy-name-override: ForceSyncRequest - c1.api.app.v1.ForceSyncResponse: - description: Empty response body. Status code indicates success. - title: Force Sync Response - type: object - x-speakeasy-name-override: ForceSyncResponse - c1.api.app.v1.GetAppEntitlementProxyResponse: - description: The response message for getting a specific entitlement proxy binding. - properties: - appProxyEntitlementView: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyView' - expanded: - description: List of serialized related objects. + oauthAuthorizedAs: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.OAuth2AuthorizedAs' + - type: "null" + parallelSyncWorkerCount: + description: 'Number of sync workers to use for parallel sync, when the PARALLEL_SYNC feature is enabled. Zero disables parallel sync. Optional on write: omit the field in UpdateAdvancedConfig to leave the stored value unchanged. The public API allows setting up to 4.' + format: int32 + type: + - integer + - "null" + profileAllowList: + description: List of profile attributes to sync, when set only these attributes will be synced items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Get App Entitlement Proxy Response - type: object - x-speakeasy-name-override: GetAppEntitlementProxyResponse - c1.api.app.v1.GetAppEntitlementResponse: - description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. - properties: - appEntitlementView: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - expanded: - description: List of serialized related objects. + type: string + type: + - array + - "null" + profileIgnoreList: + description: List of profile attributes to ignore (not sync), when set other attributes will be synced, but these will not. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Get App Entitlement Response - type: object - x-speakeasy-name-override: GetAppEntitlementResponse - c1.api.app.v1.GetAppResponse: - description: The GetAppResponse message contains the details of the requested app in the app field. - properties: - app: - $ref: '#/components/schemas/c1.api.app.v1.App' - title: Get App Response - type: object - x-speakeasy-name-override: GetAppResponse - c1.api.app.v1.GetAppUsageControlsResponse: - description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. - properties: - appUsageControls: - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' - hasUsageData: - description: HasUsageData is false if the access entitlement for this app has no usage data. - readOnly: false - type: boolean - title: Get App Usage Controls Response - type: object - x-speakeasy-name-override: GetAppUsageControlsResponse - c1.api.app.v1.GetConnectorSyncDownloadURLResponse: - description: The GetConnectorSyncDownloadURLResponse message. - properties: - downloadUrl: - description: Short-lived download URL for the connector sync artifact - readOnly: false + type: string + type: + - array + - "null" + status: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorStatus' + - type: "null" + syncConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.SyncConfig' + - type: "null" + syncDisabledAt: + format: date-time + readOnly: true + type: + - string + - "null" + syncDisabledCategory: + description: The category of the connector sync that was disabled. type: string - title: Get Connector Sync Download Url Response + syncDisabledReason: + description: The reason the connector sync was disabled. + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userIds: + description: The userIds field is used to define the integration owners of the connector. + items: + type: string + type: + - array + - "null" + title: Connector type: object - x-speakeasy-name-override: GetConnectorSyncDownloadURLResponse - c1.api.app.v1.GrantReason: - description: The GrantReason message. + x-speakeasy-name-override: Connector + c1.api.app.v1.ConnectorActionEffect: + description: The ConnectorActionEffect message. properties: appEntitlementId: - description: The ID of the app entitlement that is associated with the grant reason. - readOnly: false + description: The appEntitlementId field. type: string appId: - description: The ID of the app that is associated with the grant reason. - readOnly: false + description: The appId field. type: string appUserId: - description: The ID of the app user that is associated with the grant reason. - readOnly: false + description: The appUserId field. type: string - createdAt: - format: date-time - readOnly: false + connectorActionId: + description: The connectorActionId field. type: string - deletedAt: - format: date-time - readOnly: false + connectorEntitlementId: + description: The connectorEntitlementId field. type: string - derivedIdData: - description: This is the other part of the derived ID which include the details like ticket_id, group_id, etc. This provides the uniqueness. - readOnly: false + connectorGrantId: + description: The connectorGrantId field. type: string - derivedIdType: - description: This is one part of the derived ID, indicating the type, like "ticket" or "group" - readOnly: false + connectorId: + description: The connectorId field. type: string - reasonExpiresAt: - format: date-time - readOnly: false + effectSource: + description: The effectSource field. + enum: + - CONNECTOR_ACTION_EFFECT_SOURCE_UNSPECIFIED + - CONNECTOR_ACTION_EFFECT_SOURCE_ACTION_TARGET + - CONNECTOR_ACTION_EFFECT_SOURCE_CONNECTOR_RESPONSE + - CONNECTOR_ACTION_EFFECT_SOURCE_GRANT_REPLACED + - CONNECTOR_ACTION_EFFECT_SOURCE_DEFAULT_REPLACEMENT type: string - referenceStrength: - description: |- - GrantReasonReferenceStrength is used to indicate the strength of the reference to the reason. - This is used to determine if a grant should be removed when all strong reasons are removed. + x-speakeasy-unknown-values: allow + effectType: + description: The effectType field. enum: - - GRANT_REASON_REFERENCE_STRENGTH_UNSPECIFIED - - GRANT_REASON_REFERENCE_STRENGTH_WEAK - - GRANT_REASON_REFERENCE_STRENGTH_STRONG - readOnly: false + - CONNECTOR_ACTION_EFFECT_TYPE_UNSPECIFIED + - CONNECTOR_ACTION_EFFECT_TYPE_GRANT + - CONNECTOR_ACTION_EFFECT_TYPE_REVOKE type: string x-speakeasy-unknown-values: allow - updatedAt: + exclusionGroupId: + description: The exclusionGroupId field. + type: string + replacedConnectorGrantId: + description: The replacedConnectorGrantId field. + type: string + unresolvedReason: + description: The unresolvedReason field. + type: string + title: Connector Action Effect + type: object + x-speakeasy-name-override: ConnectorActionEffect + c1.api.app.v1.ConnectorCredential: + description: ConnectorCredential is used by a connector to authenticate with conductor one. + properties: + appId: + description: The appId of the app the connector is attached to. + type: string + clientId: + description: The client id of the ConnectorCredential. + type: string + clientSecret: + description: The client secret of the ConnectorCredential. It's only returned on creation. + type: string + connectorId: + description: The connectorId of the connector the credential is associated with. + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the ConnectorCredential. type: string - title: Grant Reason + expiresTime: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The id of the ConnectorCredential. + type: string + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Connector Credential type: object - x-speakeasy-name-override: GrantReason - c1.api.app.v1.ListAppEntitlementOwnerIDsResponse: - description: The response message for listing app entitlement owners IDs. + x-speakeasy-entity: ConnectorCredential + x-speakeasy-name-override: ConnectorCredential + c1.api.app.v1.ConnectorExpandMask: + description: The ConnectorExpandMask is used to expand related objects on a connector. properties: - userIds: - description: The list of owner IDs for the app entitlement. + paths: + description: Paths that you want expanded in the response. Possible values are "app_id" and "*". items: type: string - nullable: true - readOnly: false - type: array - title: List App Entitlement Owner I Ds Response + type: + - array + - "null" + title: Connector Expand Mask type: object - x-speakeasy-name-override: ListAppEntitlementOwnerIDsResponse - c1.api.app.v1.ListAppEntitlementOwnersResponse: - description: The response message for listing app entitlement owners. + x-speakeasy-name-override: ConnectorExpandMask + c1.api.app.v1.ConnectorRef: + description: The ConnectorRef message. properties: - list: - description: The list of owners for the app entitlement. + appId: + description: The appId field. + type: string + id: + description: The id field. + type: string + title: Connector Ref + type: object + x-speakeasy-name-override: ConnectorRef + c1.api.app.v1.ConnectorScheduleCron: + description: A cron-based schedule definition for connector syncs. + properties: + cronSpec: + description: The cron expression defining the sync schedule. + type: string + timezone: + description: The IANA timezone name for the cron schedule (e.g., "America/Los_Angeles"). + type: string + title: Connector Schedule Cron + type: object + x-speakeasy-name-override: ConnectorScheduleCron + c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput: + description: The ConnectorServiceCreateDelegatedRequest message contains the fields required to create a connector. + properties: + appEntitlementOwnerRefs: + description: Sets entitlement owners on the app. items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + appManagedStateBindingRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppManagedStateBindingRef' + - type: "null" + catalogId: + description: The catalogId describes which catalog entry this connector is an instance of. For example, every Okta connector will have the same catalogId indicating it is an Okta connector. type: string - title: List App Entitlement Owners Response + description: + description: The description of the connector. + type: string + displayName: + description: The displayName of the connector. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' + - type: "null" + userIds: + description: The userIds field is used to define the integration owners of the connector. + items: + type: string + type: + - array + - "null" + title: Connector Service Create Delegated Request type: object - x-speakeasy-name-override: ListAppEntitlementOwnersResponse - c1.api.app.v1.ListAppEntitlementUsersResponse: - description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ConnectorServiceCreateDelegatedRequest + c1.api.app.v1.ConnectorServiceCreateRequestInput: + description: The ConnectorServiceCreateRequest message. + properties: + catalogId: + description: The catalogId field. + type: string + config: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: + - object + - "null" + description: + description: The description field. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' + - type: "null" + userIds: + description: The userIds field. + items: + type: string + type: + - array + - "null" + title: Connector Service Create Request + type: object + x-speakeasy-name-override: ConnectorServiceCreateRequest + c1.api.app.v1.ConnectorServiceCreateResponse: + description: The ConnectorServiceCreateResponse is the response returned from creating a connector. properties: + connectorView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' + - type: "null" expanded: - description: List of related objects + description: The array of expanded items indicated by the request. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -6582,30 +9097,42 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: List App Entitlement Users Response + type: + - array + - "null" + title: Connector Service Create Response type: object - x-speakeasy-name-override: ListAppEntitlementUsersResponse - c1.api.app.v1.ListAppEntitlementsResponse: - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ConnectorServiceCreateResponse + c1.api.app.v1.ConnectorServiceDeleteRequestInput: + description: ConnectorServiceDeleteRequest is a request for deleting a connector. It uses URL values for input. + title: Connector Service Delete Request + type: object + x-speakeasy-name-override: ConnectorServiceDeleteRequest + c1.api.app.v1.ConnectorServiceDeleteResponse: + description: Empty response body. Status code indicates success. + title: Connector Service Delete Response + type: object + x-speakeasy-name-override: ConnectorServiceDeleteResponse + c1.api.app.v1.ConnectorServiceGetCredentialsResponse: + description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. + properties: + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorCredential' + - type: "null" + title: Connector Service Get Credentials Response + type: object + x-speakeasy-name-override: ConnectorServiceGetCredentialsResponse + c1.api.app.v1.ConnectorServiceGetResponse: + description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. properties: + connectorView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' + - type: "null" expanded: - description: List of related objects + description: The array of expanded items indicated by the request. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -6613,477 +9140,360 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: List App Entitlements Response + type: + - array + - "null" + title: Connector Service Get Response type: object - x-speakeasy-name-override: ListAppEntitlementsResponse - c1.api.app.v1.ListAppOwnerIDsResponse: - description: The response message for listing app owners IDs. + x-speakeasy-name-override: ConnectorServiceGetResponse + c1.api.app.v1.ConnectorServiceListResponse: + description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable properties: - userIds: - description: The list of owner IDs for the app. + expanded: + description: List of serialized related objects items: - type: string - nullable: true - readOnly: false - type: array - title: List App Owner I Ds Response - type: object - x-speakeasy-name-override: ListAppOwnerIDsResponse - c1.api.app.v1.ListAppOwnersResponse: - description: The ListAppOwnersResponse message. - properties: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" list: description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' + type: + - array + - "null" nextPageToken: description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false type: string - title: List App Owners Response + title: Connector Service List Response type: object - x-speakeasy-name-override: ListAppOwnersResponse - c1.api.app.v1.ListAppResourceOwnerIDsResponse: - description: The response message for listing app resource owners IDs. - properties: - userIds: - description: The list of owner IDs for the app resource. - items: - type: string - nullable: true - readOnly: false - type: array - title: List App Resource Owner I Ds Response + x-speakeasy-name-override: ConnectorServiceListResponse + c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput: + description: ConnectorServiceRevokeCredentialRequest is a request for revoking connector credentials. It uses URL values for input. + title: Connector Service Revoke Credential Request type: object - x-speakeasy-name-override: ListAppResourceOwnerIDsResponse - c1.api.app.v1.ListAppResourceOwnersResponse: - description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable + x-speakeasy-entity: ConnectorCredential + x-speakeasy-name-override: ConnectorServiceRevokeCredentialRequest + c1.api.app.v1.ConnectorServiceRevokeCredentialResponse: + description: Empty response body. Status code indicates success. + title: Connector Service Revoke Credential Response + type: object + x-speakeasy-entity: ConnectorCredential + x-speakeasy-name-override: ConnectorServiceRevokeCredentialResponse + c1.api.app.v1.ConnectorServiceRotateCredentialRequest: + description: ConnectorServiceRotateCredentialRequest is a request for rotating connector credentials. It uses URL values for input. properties: - immutableUserIds: - description: |- - User IDs of owners that are immutable and cannot be removed by the user. - These owners are managed by the system (e.g., connector-sourced) and will be updated automatically. - items: - type: string - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + appId: + description: The appId of the app the connector is attached to. type: string - title: List App Resource Owners Response + connectorId: + description: The connectorId of the connector that we are rotating the credentials for. + type: string + title: Connector Service Rotate Credential Request type: object - x-speakeasy-name-override: ListAppResourceOwnersResponse - c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse: - description: The ListAppUsersForIdentityWithGrantResponse message. + x-speakeasy-entity: ConnectorCredential + x-speakeasy-name-override: ConnectorServiceRotateCredentialRequest + c1.api.app.v1.ConnectorServiceRotateCredentialResponse: + description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. properties: - bindings: - description: |- - The list of app users that may also have grant information. - Without a grant, only the tenant, app, and app user ID will be set. With a grant, the whole struct is populated - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' - nullable: true - readOnly: false - type: array - title: List App Users For Identity With Grant Response + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorCredential' + - type: "null" + title: Connector Service Rotate Credential Response type: object - x-speakeasy-name-override: ListAppUsersForIdentityWithGrantResponse - c1.api.app.v1.ListAppsResponse: - description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ConnectorServiceRotateCredentialResponse + c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput: + description: The ConnectorServiceUpdateDelegatedRequest message contains the fields required to update a connector. properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.App' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: List Apps Response + connector: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.Connector' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: Connector Service Update Delegated Request type: object - x-speakeasy-name-override: ListAppsResponse - c1.api.app.v1.ListAutomationExclusionsResponse: - description: The ListAutomationExclusionsResponse message. + x-speakeasy-name-override: ConnectorServiceUpdateDelegatedRequest + c1.api.app.v1.ConnectorServiceUpdateRequestInput: + description: The ConnectorServiceUpdateRequest message contains the fields required to update a connector. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.app.v1.UserWithAppEntitlementUserBindingView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: List Automation Exclusions Response + connector: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.Connector' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: Connector Service Update Request type: object - x-speakeasy-name-override: ListAutomationExclusionsResponse - c1.api.app.v1.ManuallyManagedUsersResponse: - description: The ManuallyManagedUsersResponse message. + x-speakeasy-name-override: ConnectorServiceUpdateRequest + c1.api.app.v1.ConnectorServiceUpdateResponse: + description: ConnectorServiceUpdateResponse is the response returned by the update method. properties: - bulkActionId: - description: The ID of the bulk action created to process the membership additions. - readOnly: false - type: string - failedUsersErrorMap: - additionalProperties: - type: string - description: A map of user IDs to error messages for users that could not be added. - readOnly: false - type: object - title: Manually Managed Users Response + connectorView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorView' + - type: "null" + expanded: + description: The array of expanded items indicated by the request. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Connector Service Update Response type: object - x-speakeasy-name-override: ManuallyManagedUsersResponse - c1.api.app.v1.OAuth2AuthorizedAs: - description: OAuth2AuthorizedAs tracks the user that OAuthed with the connector. + x-speakeasy-name-override: ConnectorServiceUpdateResponse + c1.api.app.v1.ConnectorStatus: + description: The status field on the connector is used to track the status of the connectors sync, and when syncing last started, completed, or caused the connector to update. properties: - authEmail: - description: authEmail is the email of the user that authorized the connector using OAuth. - readOnly: true + completedAt: + format: date-time + type: + - string + - "null" + lastError: + description: The last error encountered by the connector. type: string - authorizedAt: + startedAt: format: date-time - readOnly: true + type: + - string + - "null" + status: + description: The status of the connector sync. + enum: + - SYNC_STATUS_UNSPECIFIED + - SYNC_STATUS_RUNNING + - SYNC_STATUS_DONE + - SYNC_STATUS_ERROR + - SYNC_STATUS_DISABLED type: string - title: O Auth 2 Authorized As - type: object - x-speakeasy-name-override: OAuth2AuthorizedAs - c1.api.app.v1.PauseSyncRequestInput: - description: The PauseSyncRequest message contains the fields required to pause syncing for a connector. - title: Pause Sync Request - type: object - x-speakeasy-name-override: PauseSyncRequest - c1.api.app.v1.PauseSyncResponse: - description: Empty response body. Status code indicates success. - title: Pause Sync Response - type: object - x-speakeasy-name-override: PauseSyncResponse - c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput: - description: The request message for removing an app entitlement owner. - title: Remove App Entitlement Owner Request - type: object - x-speakeasy-name-override: RemoveAppEntitlementOwnerRequest - c1.api.app.v1.RemoveAppEntitlementOwnerResponse: - description: The empty response message for removing an app entitlement owner. - title: Remove App Entitlement Owner Response - type: object - x-speakeasy-name-override: RemoveAppEntitlementOwnerResponse - c1.api.app.v1.RemoveAppOwnerRequestInput: - description: RemoveAppOwnerRequest is the request body for removing an app owner. It uses URL values for input. - title: Remove App Owner Request - type: object - x-speakeasy-name-override: RemoveAppOwnerRequest - c1.api.app.v1.RemoveAppOwnerResponse: - description: Empty response with a status code indicating success. - title: Remove App Owner Response + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + title: Connector Status type: object - x-speakeasy-name-override: RemoveAppOwnerResponse - c1.api.app.v1.RemoveAppResourceOwnerRequestInput: - description: The request message for removing an owner from an app resource. + x-speakeasy-name-override: ConnectorStatus + c1.api.app.v1.ConnectorSyncCronSchedule: + description: The ConnectorSyncCronSchedule message. properties: - userId: - description: The C1 user ID to remove as an owner. - readOnly: false + cronSpec: + description: The cronSpec field. type: string - title: Remove App Resource Owner Request - type: object - x-speakeasy-name-override: RemoveAppResourceOwnerRequest - c1.api.app.v1.RemoveAppResourceOwnerResponse: - description: The empty response message for removing an owner from an app resource. - title: Remove App Resource Owner Response - type: object - x-speakeasy-name-override: RemoveAppResourceOwnerResponse - c1.api.app.v1.RemoveAutomationExclusionRequestInput: - description: The RemoveAutomationExclusionRequest message. - properties: - userIds: - description: The IDs of users to remove from the automation exclusion list. - items: - type: string - nullable: true - readOnly: false - type: array - title: Remove Automation Exclusion Request - type: object - x-speakeasy-name-override: RemoveAutomationExclusionRequest - c1.api.app.v1.RemoveAutomationExclusionResponse: - description: Empty response with a status code indicating success. - title: Remove Automation Exclusion Response - type: object - x-speakeasy-name-override: RemoveAutomationExclusionResponse - c1.api.app.v1.RemoveEntitlementMembershipRequestInput: - description: The RemoveEntitlementMembershipRequest message. - properties: - appUserId: - description: The ID of the app user whose membership to remove. - readOnly: false + start: + format: date-time + type: + - string + - "null" + timezone: + description: The timezone field. type: string - title: Remove Entitlement Membership Request + title: Connector Sync Cron Schedule type: object - x-speakeasy-name-override: RemoveEntitlementMembershipRequest - c1.api.app.v1.RemoveEntitlementMembershipResponse: - description: The RemoveEntitlementMembershipResponse message. + x-speakeasy-name-override: ConnectorSyncCronSchedule + c1.api.app.v1.ConnectorView: + description: The ConnectorView object provides a connector response object, as well as JSONPATHs to related objects provided by expanders. properties: - revokeTaskId: - description: |- - The ID of the revoke task created to remove the user from the entitlement, if the entitlement is an access profile (aka. catalog). - It's aka. the JML task. - readOnly: false + appPath: + description: JSONPATH expression indicating the location of the App object in the expanded array. type: string - title: Remove Entitlement Membership Response - type: object - x-speakeasy-name-override: RemoveEntitlementMembershipResponse - c1.api.app.v1.RemoveGrantDurationRequestInput: - description: The request message for removing the expiration time from a grant. - title: Remove Grant Duration Request + capabilitiesPath: + description: JSONPATH expression indicating the location of the ConnectorCapabilities object in the expanded array. + type: string + connector: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.Connector' + - type: "null" + usersPath: + description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. + type: string + title: Connector View type: object - x-speakeasy-name-override: RemoveGrantDurationRequest - c1.api.app.v1.RemoveGrantDurationResponse: - description: The response message for removing the expiration time from a grant. + x-speakeasy-name-override: ConnectorView + c1.api.app.v1.CreateAppEntitlementProxyRequestInput: + description: The request message for creating an entitlement proxy binding. properties: - binding: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' - title: Remove Grant Duration Response - type: object - x-speakeasy-name-override: RemoveGrantDurationResponse - c1.api.app.v1.ResumeSyncRequestInput: - description: The ResumeSyncRequest message contains the fields required to resume syncing for a connector. - title: Resume Sync Request - type: object - x-speakeasy-name-override: ResumeSyncRequest - c1.api.app.v1.ResumeSyncResponse: - description: Empty response body. Status code indicates success. - title: Resume Sync Response + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyExpandMask' + - type: "null" + title: Create App Entitlement Proxy Request type: object - x-speakeasy-name-override: ResumeSyncResponse - c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse: - description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: CreateAppEntitlementProxyRequest + c1.api.app.v1.CreateAppEntitlementProxyResponse: + description: The response message for creating an entitlement proxy binding. properties: - list: - description: The list field. + appProxyEntitlementView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyView' + - type: "null" + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementWithExpired' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Search App Entitlements With Expired Response + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Create App Entitlement Proxy Response type: object - x-speakeasy-name-override: SearchAppEntitlementsWithExpiredResponse - c1.api.app.v1.SearchAppResourceTypesRequest: - description: Search for app resources based on some filters. + x-speakeasy-name-override: CreateAppEntitlementProxyResponse + c1.api.app.v1.CreateAppEntitlementRequestInput: + description: | + The CreateAppEntitlementRequest message. + + This message contains a oneof named max_grant_duration. Only a single field of the following list may be set at a time: + - durationUnset + - durationGrant properties: - appIds: - description: A list of app IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - appUserIds: - description: A list of app user IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - displayName: - description: Exact match on display name - readOnly: false + alias: + description: A unique alias for the entitlement, used for programmatic lookups and Cone. type: string - excludeResourceTypeIds: - description: A list of resource type IDs to exclude from the search. - items: + annotations: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - excludeResourceTypeTraitIds: - description: A list of resource type trait IDs to exclude from the search. + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appEntitlementOwnerIds: + description: The IDs of users to set as owners of this entitlement. items: type: string - nullable: true - readOnly: false - type: array - pageSize: - description: The pageSize where 10 <= pageSize <= 100, default 25. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + type: + - array + - "null" + appResourceId: + description: The ID of the resource that this entitlement belongs to. type: string - query: - description: Fuzzy search the display name of resource types. - readOnly: false + appResourceTypeId: + description: The ID of the resource type that this entitlement belongs to. type: string - resourceTypeIds: - description: A list of resource type IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeTraitIds: - description: A list of resource type trait IDs to restrict the search by. + certifyPolicyId: + description: The ID of the policy to use for certification tasks. + type: string + complianceFrameworkValueIds: + description: The IDs of compliance frameworks to associate with this entitlement (e.g., SOX, HIPAA). items: type: string - nullable: true - readOnly: false - type: array - title: Search App Resource Types Request - type: object - x-speakeasy-name-override: SearchAppResourceTypesRequest - c1.api.app.v1.SearchAppResourceTypesResponse: - description: The SearchAppResourceTypesResponse message contains a list of results and a nextPageToken if applicable. - properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + type: + - array + - "null" + description: + description: The description of the new entitlement. type: string - title: Search App Resource Types Response - type: object - x-speakeasy-name-override: SearchAppResourceTypesResponse - c1.api.app.v1.SearchAppResourcesRequest: - description: Search app resources based on filters specified in the request body. - properties: - appId: - description: The app ID to restrict the search to. - readOnly: false + displayName: + description: The display name of the new entitlement. type: string - appUserIds: - description: A list of app user IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - excludeDeletedResourceBindings: - description: If true, exclude resources whose bindings have been deleted. - readOnly: false + durationGrant: + format: duration + type: + - string + - "null" + durationUnset: + type: + - object + - "null" + emergencyGrantEnabled: + description: Whether emergency grant requests are enabled for this entitlement. type: boolean - excludeResourceIds: - description: A list of resource IDs to exclude from the search results. - items: - type: string - nullable: true - readOnly: false - type: array - excludeResourceTypeTraitIds: - description: A list of resource type trait IDs to exclude from the search. - items: - type: string - nullable: true - readOnly: false - type: array - ownerUserIds: - description: A list of C1 user IDs to filter resources by ownership. - items: - type: string - nullable: true - readOnly: false - type: array - pageSize: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: The token for fetching the next page of results. - readOnly: false + emergencyGrantPolicyId: + description: The ID of the policy to use for emergency grant tasks. Required if emergency_grant_enabled is true. type: string - query: - description: Fuzzy search the display name of resources. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" + grantPolicyId: + description: The ID of the policy to use for grant request tasks. type: string - refs: - description: A list of specific app resource references to restrict the search to. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' - nullable: true - readOnly: false - type: array - resourceIds: - description: A list of resource IDs to restrict the search to. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeIds: - description: A list of resource type IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeTraitIds: - description: A list of resource type trait IDs to restrict the search by. - items: - type: string - nullable: true - readOnly: false - type: array - title: Search App Resources Request + matchBatonId: + description: If supplied, it's implied that the entitlement is created before sync and needs to be merged with connector entitlement. + type: string + overrideAccessRequestsDefaults: + description: Whether to override the app-level access request defaults for this entitlement. + type: boolean + provisionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + - type: "null" + purpose: + description: The purpose of the entitlement (e.g., assignment, permission, ownership). + enum: + - APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED + - APP_ENTITLEMENT_PURPOSE_VALUE_ASSIGNMENT + - APP_ENTITLEMENT_PURPOSE_VALUE_PERMISSION + - APP_ENTITLEMENT_PURPOSE_VALUE_OWNERSHIP + type: string + x-speakeasy-unknown-values: allow + revokePolicyId: + description: The ID of the policy to use for revoke request tasks. + type: string + riskLevelValueId: + description: The ID of the risk level to assign to this entitlement. + type: string + slug: + description: A short label describing the permission the entitlement grants (e.g., "Admin", "Read"). + type: string + required: + - displayName + title: Create App Entitlement Request type: object - x-speakeasy-name-override: SearchAppResourcesRequest - c1.api.app.v1.SearchAppResourcesResponse: - description: The SearchAppResourcesResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: CreateAppEntitlementRequest + c1.api.app.v1.CreateAppEntitlementResponse: + description: The CreateAppEntitlementResponse message. properties: + appEntitlementView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" expanded: - description: List of serialized related objects. + description: The expanded field. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -7091,223 +9501,243 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - list: - description: The list of app resource results. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The token for fetching the next page of results. - readOnly: false - type: string - title: Search App Resources Response + type: + - array + - "null" + title: Create App Entitlement Response type: object - x-speakeasy-name-override: SearchAppResourcesResponse - c1.api.app.v1.SearchAppsRequest: - description: Search Apps by a few properties. + x-speakeasy-name-override: CreateAppEntitlementResponse + c1.api.app.v1.CreateAppEntitlementRoutingRuleRequestInput: + description: The CreateAppEntitlementRoutingRuleRequest message. properties: - appIds: - description: A list of app IDs to restrict the search to. - items: - type: string - nullable: true - readOnly: false - type: array + condition: + description: |- + CEL expression evaluated against the entitlement routing rule context. + Empty string is valid and matches every target not matched earlier. + type: string + description: + description: The description field. + type: string displayName: - description: Search for apps with a case insensitive match on the display name. - readOnly: false + description: The displayName field. type: string - excludeAppIds: - description: A list of app IDs to remove from the results. - items: - type: string - nullable: true - readOnly: false - type: array - onlyDirectories: - description: Only return apps which are directories - readOnly: false + enabled: + description: The enabled field. type: boolean - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + priority: + description: |- + A 1-indexed insertion slot; the server clamps it into [1, N+1] and re-packs + siblings densely. Omit (or 0) to append the rule last. format: int32 - readOnly: false type: integer - pageToken: - description: The pageToken field. - readOnly: false - type: string - policyRefs: - description: Search for apps that use any of these policies. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' - nullable: true - readOnly: false - type: array - query: - description: Query the apps with a fuzzy search on display name and description. - readOnly: false - type: string - title: Search Apps Request + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRuleSettings' + - type: "null" + title: Create App Entitlement Routing Rule Request type: object - x-speakeasy-name-override: SearchAppsRequest - c1.api.app.v1.SearchAppsResponse: - description: The SearchAppsResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: CreateAppEntitlementRoutingRuleRequest + c1.api.app.v1.CreateAppEntitlementRoutingRuleResponse: + description: The CreateAppEntitlementRoutingRuleResponse message. properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.App' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: Search Apps Response + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRule' + - type: "null" + title: Create App Entitlement Routing Rule Response type: object - x-speakeasy-name-override: SearchAppsResponse - c1.api.app.v1.SearchGrantFeedRequest: - description: The SearchGrantFeedRequest message. + x-speakeasy-name-override: CreateAppEntitlementRoutingRuleResponse + c1.api.app.v1.CreateAppRequest: + description: The CreateAppRequest message is used to create a new app. properties: - after: - format: date-time - readOnly: false - type: string - appEntitlementRefs: - description: The list of app entitlements to limit the search to. + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appEntitlementOwnerRefs: + description: Sets entitlement owners on the app. items: $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - appRefs: - description: The list of apps to limit the search to. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppRef' - nullable: true - readOnly: false - type: array - appUserRefs: - description: The list of app users to limit the search to. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' - nullable: true - readOnly: false - type: array - before: - format: date-time - readOnly: false + type: + - array + - "null" + certifyPolicyId: + description: Creates the app with this certify policy. type: string - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask' - pageSize: - description: The pageSize where 10 <= pageSize <= 100, default 25. + description: + description: Creates the app with this description. + type: string + displayName: + description: Creates the app with this display name. + type: string + grantPolicyId: + description: Creates the app with this grant policy. + type: string + identityMatching: + description: Define the app user identity matching strategy for this app. + enum: + - APP_USER_IDENTITY_MATCHING_UNSPECIFIED + - APP_USER_IDENTITY_MATCHING_STRICT + - APP_USER_IDENTITY_MATCHING_DISPLAY_NAME + - APP_USER_IDENTITY_MATCHING_CUSTOM + type: string + x-speakeasy-unknown-values: allow + instructions: + description: Instructions shown to users in the access request form when requesting access for this app. + type: string + monthlyCostUsd: + description: Creates the app with this monthly cost per seat. format: int32 - readOnly: false type: integer - pageToken: - description: The page_token field for pagination. - readOnly: false - type: string - userRefs: - description: The list of C1 users to limit the search to. + owners: + description: Creates the app with this array of user owners. items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Search Grant Feed Request + type: string + type: + - array + - "null" + revokePolicyId: + description: Creates the app with this revoke policy. + type: string + strictAccessEntitlementProvisioning: + description: This flag enforces a provisioning mode where the access entitlement is always included in the provisioning flow, if the app user doesn't exist + type: boolean + required: + - displayName + title: Create App Request type: object - x-speakeasy-name-override: SearchGrantFeedRequest - c1.api.app.v1.SearchGrantFeedResponse: - description: The SearchGrantFeedResponse message contains a list of grant event results and a nextPageToken if applicable. + x-speakeasy-entity: App + x-speakeasy-name-override: CreateAppRequest + c1.api.app.v1.CreateAppResponse: + description: Returns the new app's values. properties: - expanded: - description: The expanded field. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingFeedView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retrieved. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: Search Grant Feed Response + app: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.App' + - type: "null" + title: Create App Response type: object - x-speakeasy-name-override: SearchGrantFeedResponse - c1.api.app.v1.SearchPastGrantsRequest: - description: The request message for searching historical grants. + x-speakeasy-name-override: CreateAppResponse + c1.api.app.v1.CreateAutomationRequestInput: + description: The CreateAutomationRequest message. properties: - appEntitlementRefs: - description: A list of entitlement references to restrict the search to. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - appIds: - description: A list of app IDs to restrict the search to. - items: + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' + - type: "null" + title: Create Automation Request + type: object + x-speakeasy-name-override: CreateAutomationRequest + c1.api.app.v1.CreateAutomationResponse: + description: The CreateAutomationResponse message. + properties: + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementAutomation' + - type: "null" + title: Create Automation Response + type: object + x-speakeasy-name-override: CreateAutomationResponse + c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput: + description: The request message for creating a manually managed app resource. + properties: + annotations: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - appUserRefs: - description: A list of app user references to restrict the search to. + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + description: + description: An optional description for the new resource. + type: string + displayName: + description: The display name for the new resource. + type: string + matchBatonId: + description: If supplied, it's implied that the resource is created before sync and needs to be merged with connector resource. + type: string + resourceOwnerUserIds: + description: C1 user IDs to assign as owners of this resource. items: - $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask' - pageSize: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: The token for fetching the next page of results. - readOnly: false + type: string + type: + - array + - "null" + required: + - displayName + title: Create Manually Managed App Resource Request + type: object + x-speakeasy-name-override: CreateManuallyManagedAppResourceRequest + c1.api.app.v1.CreateManuallyManagedAppResourceResponse: + description: The response message for creating a manually managed app resource. + properties: + appResource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResource' + - type: "null" + title: Create Manually Managed App Resource Response + type: object + x-speakeasy-name-override: CreateManuallyManagedAppResourceResponse + c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput: + description: The request message for creating a manually managed resource type. + properties: + displayName: + description: The display name for the new resource type. type: string - title: Search Past Grants Request + resourceType: + description: The category of the resource type (e.g., ROLE, GROUP, LICENSE). + enum: + - ROLE + - GROUP + - LICENSE + - PROJECT + - CATALOG + - CUSTOM + - VAULT + - PROFILE_TYPE + - SESSION_POLICY + type: string + x-speakeasy-unknown-values: allow + required: + - resourceType + - displayName + title: Create Manually Managed Resource Type Request type: object - x-speakeasy-name-override: SearchPastGrantsRequest - c1.api.app.v1.SearchPastGrantsResponse: - description: The SearchPastGrantsResponse message contains a list of past grants and a nextPageToken if applicable. + x-speakeasy-name-override: CreateManuallyManagedResourceTypeRequest + c1.api.app.v1.CreateManuallyManagedResourceTypeResponse: + description: The response message for creating a manually managed resource type. properties: + appResourceType: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' + - type: "null" expanded: - description: The expanded field. + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -7315,225 +9745,195 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingHistoryView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retrieved. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: Search Past Grants Response + type: + - array + - "null" + title: Create Manually Managed Resource Type Response type: object - x-speakeasy-name-override: SearchPastGrantsResponse - c1.api.app.v1.SearchUserOwnershipRequest: - description: |- - Search for all ownership assignments for a given user. Returns apps, resources, and - entitlements the user owns, each tagged with a UserOwnershipType discriminator. - Filter by ownership_types to restrict results to specific kinds of ownership. - properties: - ownershipTypes: - description: Filter results to only include these ownership types. If empty, all types are returned. - items: - enum: - - USER_OWNERSHIP_TYPE_UNSPECIFIED - - USER_OWNERSHIP_TYPE_APP - - USER_OWNERSHIP_TYPE_RESOURCE - - USER_OWNERSHIP_TYPE_ENTITLEMENT - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - pageSize: - description: Maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous response. - readOnly: false - type: string - userId: - description: The ID of the ConductorOne user whose ownership to search. - readOnly: false - type: string - title: Search User Ownership Request + x-speakeasy-name-override: CreateManuallyManagedResourceTypeResponse + c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput: + description: The request message for deleting app entitlement owners. + title: Delete App Entitlement Owners Request type: object - x-speakeasy-name-override: SearchUserOwnershipRequest - c1.api.app.v1.SearchUserOwnershipResponse: - description: The SearchUserOwnershipResponse message contains a paginated list of ownership entries. - properties: - list: - description: The list of ownership entries for the requested user. - items: - $ref: '#/components/schemas/c1.api.app.v1.UserOwnershipEntry' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Pagination token for the next page of results. Empty when there are no more results. - readOnly: false - type: string - title: Search User Ownership Response + x-speakeasy-name-override: DeleteAppEntitlementOwnersRequest + c1.api.app.v1.DeleteAppEntitlementOwnersResponse: + description: the empty response message for deleting app entitlement owners. + title: Delete App Entitlement Owners Response type: object - x-speakeasy-name-override: SearchUserOwnershipResponse - c1.api.app.v1.SecretTrait: - description: The SecretTrait message. - nullable: true - properties: - identityAppUserId: - description: The identityAppUserId field. - readOnly: false - type: string - lastUsedAt: - format: date-time - readOnly: false - type: string - secretCreatedAt: - format: date-time - readOnly: false - type: string - secretExpiresAt: - format: date-time - readOnly: false - type: string - title: Secret Trait + x-speakeasy-name-override: DeleteAppEntitlementOwnersResponse + c1.api.app.v1.DeleteAppEntitlementProxyRequestInput: + description: The request message for deleting an entitlement proxy binding. + title: Delete App Entitlement Proxy Request type: object - x-speakeasy-name-override: SecretTrait - c1.api.app.v1.SetAppEntitlementOwnersRequestInput: - description: The request message for setting the app entitlement owners. - properties: - userIds: - description: The user_ids field for the users to set as an owner of the app entitlement. - items: - type: string - nullable: true - readOnly: false - type: array - title: Set App Entitlement Owners Request + x-speakeasy-name-override: DeleteAppEntitlementProxyRequest + c1.api.app.v1.DeleteAppEntitlementProxyResponse: + description: The empty response message for deleting an entitlement proxy binding. + title: Delete App Entitlement Proxy Response type: object - x-speakeasy-entity: App_Entitlement_Owner - x-speakeasy-name-override: SetAppEntitlementOwnersRequest - c1.api.app.v1.SetAppEntitlementOwnersResponse: - description: The empty response message for setting the app entitlement owners. - title: Set App Entitlement Owners Response + x-speakeasy-name-override: DeleteAppEntitlementProxyResponse + c1.api.app.v1.DeleteAppEntitlementRequestInput: + description: The DeleteAppEntitlementRequest message. + title: Delete App Entitlement Request type: object - x-speakeasy-name-override: SetAppEntitlementOwnersResponse - c1.api.app.v1.SetAppOwnersRequestInput: - description: The request message for setting the app owners. + x-speakeasy-name-override: DeleteAppEntitlementRequest + c1.api.app.v1.DeleteAppEntitlementResponse: + description: The DeleteAppEntitlementResponse message. + title: Delete App Entitlement Response + type: object + x-speakeasy-name-override: DeleteAppEntitlementResponse + c1.api.app.v1.DeleteAppEntitlementRoutingRuleRequestInput: + description: The DeleteAppEntitlementRoutingRuleRequest message. + title: Delete App Entitlement Routing Rule Request + type: object + x-speakeasy-name-override: DeleteAppEntitlementRoutingRuleRequest + c1.api.app.v1.DeleteAppEntitlementRoutingRuleResponse: + description: The DeleteAppEntitlementRoutingRuleResponse message. + title: Delete App Entitlement Routing Rule Response + type: object + x-speakeasy-name-override: DeleteAppEntitlementRoutingRuleResponse + c1.api.app.v1.DeleteAppOwnersRequestInput: + description: The request message for deleting app owners. properties: userIds: description: The user_ids field for the users to set as an owner of the app. items: type: string - nullable: true - readOnly: false - type: array - title: Set App Owners Request + type: + - array + - "null" + title: Delete App Owners Request type: object - x-speakeasy-entity: App_Owner - x-speakeasy-name-override: SetAppOwnersRequest - c1.api.app.v1.SetAppOwnersResponse: - description: The empty response message for setting the app owners. - title: Set App Owners Response + x-speakeasy-name-override: DeleteAppOwnersRequest + c1.api.app.v1.DeleteAppOwnersResponse: + description: the empty response message for deleting app owners. + title: Delete App Owners Response type: object - x-speakeasy-name-override: SetAppOwnersResponse - c1.api.app.v1.SetAppResourceOwnersRequestInput: - description: The SetAppResourceOwnersRequest message. - properties: - userIds: - description: The userIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Set App Resource Owners Request + x-speakeasy-name-override: DeleteAppOwnersResponse + c1.api.app.v1.DeleteAppRequestInput: + description: Empty request body + title: Delete App Request type: object - x-speakeasy-entity: App_Resource_Owner - x-speakeasy-name-override: SetAppResourceOwnersRequest - c1.api.app.v1.SetAppResourceOwnersResponse: - description: The empty response message for setting the app resource owners. - title: Set App Resource Owners Response + x-speakeasy-entity: App + x-speakeasy-name-override: DeleteAppRequest + c1.api.app.v1.DeleteAppResourceOwnersRequestInput: + description: The request message for deleting app resource owners. + title: Delete App Resource Owners Request type: object - x-speakeasy-name-override: SetAppResourceOwnersResponse - c1.api.app.v1.SyncConfig: - description: The SyncConfig message. - properties: - syncResourceTypeIds: - description: The syncResourceTypeIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Sync Config + x-speakeasy-name-override: DeleteAppResourceOwnersRequest + c1.api.app.v1.DeleteAppResourceOwnersResponse: + description: the empty response message for deleting app resource owners. + title: Delete App Resource Owners Response type: object - x-speakeasy-name-override: SyncConfig - c1.api.app.v1.TaskAuditCancelledResult: - description: The TaskAuditCancelledResult message. - nullable: true + x-speakeasy-name-override: DeleteAppResourceOwnersResponse + c1.api.app.v1.DeleteAppResponse: + description: Empty response body. Status code indicates success. + title: Delete App Response + type: object + x-speakeasy-name-override: DeleteAppResponse + c1.api.app.v1.DeleteAutomationRequestInput: + description: The DeleteAutomationRequest message. + title: Delete Automation Request + type: object + x-speakeasy-name-override: DeleteAutomationRequest + c1.api.app.v1.DeleteAutomationResponse: + description: The DeleteAutomationResponse message. + title: Delete Automation Response + type: object + x-speakeasy-name-override: DeleteAutomationResponse + c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput: + description: The request message for deleting a manually managed app resource. + title: Delete Manually Managed App Resource Request + type: object + x-speakeasy-name-override: DeleteManuallyManagedAppResourceRequest + c1.api.app.v1.DeleteManuallyManagedAppResourceResponse: + description: The empty response message for deleting a manually managed app resource. + title: Delete Manually Managed App Resource Response + type: object + x-speakeasy-name-override: DeleteManuallyManagedAppResourceResponse + c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput: + description: The request message for deleting a manually managed resource type. + title: Delete Manually Managed Resource Type Request + type: object + x-speakeasy-name-override: DeleteManuallyManagedResourceTypeRequest + c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse: + description: The empty response message for deleting a manually managed resource type. + title: Delete Manually Managed Resource Type Response + type: object + x-speakeasy-name-override: DeleteManuallyManagedResourceTypeResponse + c1.api.app.v1.EditorValidateRequest: + description: The EditorValidateRequest message contains the configuration text to validate. properties: - cancelReason: - description: |- - Human-readable reason the action was cancelled. Already populated on the - model-side CanceledResult (e.g., "action is invalid - ticket is closed"); - this surfaces it to the UI. - readOnly: false + text: + description: The configuration text to validate. type: string - title: Task Audit Cancelled Result + title: Editor Validate Request type: object - x-speakeasy-name-override: TaskAuditCancelledResult - c1.api.app.v1.TaskAuditErrorResult: - description: The TaskAuditErrorResult message. - nullable: true + x-speakeasy-name-override: EditorValidateRequest + c1.api.app.v1.EditorValidateResponse: + description: The EditorValidateResponse message contains validation results. properties: - errorCount: - description: 'TODO(pquerna): expand' - format: int64 - readOnly: false - type: string - errorReason: - description: The errorReason field. - readOnly: false - type: string - title: Task Audit Error Result + markers: + description: The list of diagnostic markers found during validation. + items: + $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' + readOnly: true + type: + - array + - "null" + title: Editor Validate Response type: object - x-speakeasy-name-override: TaskAuditErrorResult - c1.api.app.v1.TaskAuditPendingResult: - description: The TaskAuditPendingResult message. - nullable: true + x-speakeasy-name-override: EditorValidateResponse + c1.api.app.v1.EncryptedData: + description: EncryptedData is a message that contains encrypted bytes and metadata. properties: - pendingReason: - description: |- - Human-readable explanation of why the action is pending. Rendered in the - ticket audit log so admins can see what the action is waiting on (e.g., - "GitHub org invite sent. User must accept the invitation before team - membership can be granted."). Naming mirrors TaskAuditErrorResult.error_reason - and TaskAuditCancelledResult.cancel_reason for consistency. - readOnly: false + description: + description: The human-readable description of the encrypted data. + readOnly: true type: string - title: Task Audit Pending Result + encryptedBytes: + description: The encrypted bytes. + format: base64 + readOnly: true + type: string + keyId: + description: The key ID used to encrypt the data. + readOnly: true + type: string + name: + description: The human-readable name of the encrypted data. + readOnly: true + type: string + provider: + description: The encryption provider used to encrypt the data. + readOnly: true + type: string + schema: + description: The (optional) JSON schema of the encrypted data. + readOnly: true + type: string + title: Encrypted Data type: object - x-speakeasy-name-override: TaskAuditPendingResult - c1.api.app.v1.TaskAuditSuccessResult: - description: The TaskAuditSuccessResult message. - nullable: true + x-speakeasy-name-override: EncryptedData + c1.api.app.v1.ForceSyncRequestInput: + description: Signal the connector to start syncing. This puts the sync on the queue. It does not guarantee immediate sync. Long syncs still take minutes to hours. + title: Force Sync Request + type: object + x-speakeasy-name-override: ForceSyncRequest + c1.api.app.v1.ForceSyncResponse: + description: Empty response body. Status code indicates success. + title: Force Sync Response + type: object + x-speakeasy-name-override: ForceSyncResponse + c1.api.app.v1.GetAppEntitlementProxyResponse: + description: The response message for getting a specific entitlement proxy binding. properties: - annotations: - description: The annotations field. + appProxyEntitlementView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementProxyView' + - type: "null" + expanded: + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -7541,48 +9941,22 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - successReason: - description: |- - Optional human-readable note about the successful action. Rendered in - the ticket audit log when present (e.g., "Account already existed; no - change made." for the AlreadyExistsResult path). Naming mirrors - TaskAuditErrorResult.error_reason and TaskAuditCancelledResult.cancel_reason - for consistency. - readOnly: false - type: string - title: Task Audit Success Result - type: object - x-speakeasy-name-override: TaskAuditSuccessResult - c1.api.app.v1.UpdateAppEntitlementRequestInput: - description: The UpdateAppEntitlementRequest message contains the app entitlement and the fields to be updated. - properties: - entitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - overrideAccessRequestsDefaults: - description: Flag to indicate that access request defaults, if any are applied to these entitlements, should be overridden. - readOnly: false - type: boolean - updateMask: - nullable: true - readOnly: false - type: string - title: Update App Entitlement Request + type: + - array + - "null" + title: Get App Entitlement Proxy Response type: object - x-speakeasy-name-override: UpdateAppEntitlementRequest - c1.api.app.v1.UpdateAppEntitlementResponse: - description: The UpdateAppEntitlementResponse message. + x-speakeasy-name-override: GetAppEntitlementProxyResponse + c1.api.app.v1.GetAppEntitlementResponse: + description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. properties: appEntitlementView: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" expanded: - description: List of related objects + description: List of serialized related objects. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -7590,4869 +9964,4721 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - title: Update App Entitlement Response + type: + - array + - "null" + title: Get App Entitlement Response type: object - x-speakeasy-name-override: UpdateAppEntitlementResponse - c1.api.app.v1.UpdateAppRequestInput: - description: The UpdateAppRequest message contains the app to update and the fields to update. + x-speakeasy-name-override: GetAppEntitlementResponse + c1.api.app.v1.GetAppEntitlementRoutingRuleResponse: + description: The GetAppEntitlementRoutingRuleResponse message. properties: - app: - $ref: '#/components/schemas/c1.api.app.v1.App' - updateMask: - nullable: true - readOnly: false - type: string - title: Update App Request + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRule' + - type: "null" + title: Get App Entitlement Routing Rule Response type: object - x-speakeasy-name-override: UpdateAppRequest - c1.api.app.v1.UpdateAppResponse: - description: Returns the updated app's new values. + x-speakeasy-name-override: GetAppEntitlementRoutingRuleResponse + c1.api.app.v1.GetAppResponse: + description: The GetAppResponse message contains the details of the requested app in the app field. properties: app: - $ref: '#/components/schemas/c1.api.app.v1.App' - title: Update App Response - type: object - x-speakeasy-name-override: UpdateAppResponse - c1.api.app.v1.UpdateAppUsageControlsRequestInput: - description: The UpdateAppUsageControlsRequest message contains the AppUsageControls object to update and the update mask. - properties: - appUsageControls: - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' - updateMask: - nullable: true - readOnly: false - type: string - title: Update App Usage Controls Request + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.App' + - type: "null" + title: Get App Response type: object - x-speakeasy-name-override: UpdateAppUsageControlsRequest - c1.api.app.v1.UpdateAppUsageControlsResponse: - description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. + x-speakeasy-name-override: GetAppResponse + c1.api.app.v1.GetAppUsageControlsResponse: + description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. properties: appUsageControls: - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' - title: Update App Usage Controls Response - type: object - x-speakeasy-name-override: UpdateAppUsageControlsResponse - c1.api.app.v1.UpdateConnectorScheduleRequestInput: - description: | - The UpdateConnectorScheduleRequest message contains the fields required to update a connector's sync schedule. - - This message contains a oneof named schedule. Only a single field of the following list may be set at a time: - - cron - properties: - cron: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorScheduleCron' - title: Update Connector Schedule Request - type: object - x-speakeasy-name-override: UpdateConnectorScheduleRequest - c1.api.app.v1.UpdateConnectorScheduleResponse: - description: Empty response body. Status code indicates success. - title: Update Connector Schedule Response - type: object - x-speakeasy-name-override: UpdateConnectorScheduleResponse - c1.api.app.v1.UpdateGrantDurationRequestInput: - description: The request message for updating the duration of an existing grant. - properties: - newDeprovisionAt: - format: date-time - readOnly: false - type: string - title: Update Grant Duration Request - type: object - x-speakeasy-name-override: UpdateGrantDurationRequest - c1.api.app.v1.UpdateGrantDurationResponse: - description: The response message for updating the duration of a grant. - properties: - binding: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' - title: Update Grant Duration Response + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' + - type: "null" + hasUsageData: + description: HasUsageData is false if the access entitlement for this app has no usage data. + type: boolean + title: Get App Usage Controls Response type: object - x-speakeasy-name-override: UpdateGrantDurationResponse - c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput: - description: The request message for updating a manually managed resource type. + x-speakeasy-name-override: GetAppUsageControlsResponse + c1.api.app.v1.GetConnectorSyncDownloadURLResponse: + description: The GetConnectorSyncDownloadURLResponse message. properties: - appResourceType: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' - updateMask: - nullable: true - readOnly: false + downloadUrl: + description: Short-lived download URL for the connector sync artifact type: string - title: Update Manually Managed Resource Type Request - type: object - x-speakeasy-name-override: UpdateManuallyManagedResourceTypeRequest - c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse: - description: The response message for updating a manually managed resource type. - properties: - appResourceType: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Update Manually Managed Resource Type Response + title: Get Connector Sync Download Url Response type: object - x-speakeasy-name-override: UpdateManuallyManagedResourceTypeResponse - c1.api.app.v1.UserOwnershipEntry: - description: |- - A single ownership entry. Fields are populated based on ownership_type: - APP — only app_id and app_display_name are set. - RESOURCE — app_id, app_display_name, resource_type_id, resource_id, and resource_display_name are set. - ENTITLEMENT — app_id, app_display_name, resource_type_id, entitlement_id, and entitlement_display_name are set. + x-speakeasy-name-override: GetConnectorSyncDownloadURLResponse + c1.api.app.v1.GrantReason: + description: The GrantReason message. properties: - appDisplayName: - description: The app display name. - readOnly: false + appEntitlementId: + description: The ID of the app entitlement that is associated with the grant reason. type: string appId: - description: The app ID. - readOnly: false + description: The ID of the app that is associated with the grant reason. type: string - entitlementDisplayName: - description: The entitlement display name, if applicable. - readOnly: false + appUserId: + description: The ID of the app user that is associated with the grant reason. type: string - entitlementId: - description: The entitlement ID, if applicable. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + derivedIdData: + description: This is the other part of the derived ID which include the details like ticket_id, group_id, etc. This provides the uniqueness. type: string - ownershipType: - description: The type of ownership. + derivedIdType: + description: This is one part of the derived ID, indicating the type, like "ticket" or "group" + type: string + reasonExpiresAt: + format: date-time + type: + - string + - "null" + referenceStrength: + description: |- + GrantReasonReferenceStrength is used to indicate the strength of the reference to the reason. + This is used to determine if a grant should be removed when all strong reasons are removed. enum: - - USER_OWNERSHIP_TYPE_UNSPECIFIED - - USER_OWNERSHIP_TYPE_APP - - USER_OWNERSHIP_TYPE_RESOURCE - - USER_OWNERSHIP_TYPE_ENTITLEMENT - readOnly: false + - GRANT_REASON_REFERENCE_STRENGTH_UNSPECIFIED + - GRANT_REASON_REFERENCE_STRENGTH_WEAK + - GRANT_REASON_REFERENCE_STRENGTH_STRONG type: string x-speakeasy-unknown-values: allow - resourceDisplayName: - description: The resource display name, if applicable. - readOnly: false - type: string - resourceId: - description: The resource ID, if applicable. - readOnly: false - type: string - resourceTypeId: - description: The resource type ID, if applicable. - readOnly: false - type: string - title: User Ownership Entry + updatedAt: + format: date-time + type: + - string + - "null" + title: Grant Reason type: object - x-speakeasy-name-override: UserOwnershipEntry - c1.api.app.v1.UserWithAppEntitlementUserBindingView: - description: The UserWithAppEntitlementUserBindingView message. + x-speakeasy-name-override: GrantReason + c1.api.app.v1.GraphAppGrantCount: + description: The number of grants a user holds in a single application. properties: - appEntitlementId: - description: The ID of the app entitlement. - readOnly: false - type: string appId: - description: The ID of the app that contains the entitlement. - readOnly: false + description: The ID of the application. type: string - appUserId: - description: The ID of the app user associated with this binding. - readOnly: false + grantCount: + description: The number of grants the user holds in this application. + format: int64 type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: User With App Entitlement User Binding View + title: Graph App Grant Count type: object - x-speakeasy-name-override: UserWithAppEntitlementUserBindingView - c1.api.app.v2.AppEntitlementOwnerEntitlement: - description: AppEntitlementOwnerEntitlement represents an entitlement ownership source for an app entitlement. + x-speakeasy-name-override: GraphAppGrantCount + c1.api.app.v1.GraphEdge: + description: An edge in the access graph. properties: - appEntitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' - createdAt: - format: date-time - readOnly: false - type: string - roleSlug: - description: The roleSlug field. - readOnly: false + hiddenChildren: + description: The hiddenChildren field. + format: int32 + type: integer + isTruncated: + description: The isTruncated field. + type: boolean + sourceId: + description: The sourceId field. type: string - title: App Entitlement Owner Entitlement - type: object - x-speakeasy-name-override: AppEntitlementOwnerEntitlement - c1.api.app.v2.AppEntitlementOwnerUser: - description: AppEntitlementOwnerUser represents a user ownership source for an app entitlement. - properties: - createdAt: - format: date-time - readOnly: false + targetId: + description: The targetId field. type: string - roleSlug: - description: The roleSlug field. - readOnly: false + type: + description: The type field. + enum: + - GRAPH_EDGE_TYPE_UNSPECIFIED + - GRAPH_EDGE_TYPE_IDENTITY_LINK + - GRAPH_EDGE_TYPE_DIRECT_GRANT + - GRAPH_EDGE_TYPE_APP_HIERARCHY + - GRAPH_EDGE_TYPE_RESOURCE_HIERARCHY + - GRAPH_EDGE_TYPE_PROXY_BINDING type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: App Entitlement Owner User + x-speakeasy-unknown-values: allow + title: Graph Edge type: object - x-speakeasy-name-override: AppEntitlementOwnerUser - c1.api.app.v2.AppOwnerEntitlement: - description: AppOwnerEntitlement represents an entitlement ownership source for an app. + x-speakeasy-name-override: GraphEdge + c1.api.app.v1.GraphNode: + description: A node in the access graph. properties: - appEntitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' appId: description: The appId field. - readOnly: false type: string - createdAt: - format: date-time - readOnly: false + displayName: + description: The displayName field. type: string - roleSlug: - description: The roleSlug field. - readOnly: false + id: + description: The id field. type: string - title: App Owner Entitlement - type: object - x-speakeasy-entity: App_Owner_Entitlement - x-speakeasy-name-override: AppOwnerEntitlement - c1.api.app.v2.AppOwnerUser: - description: AppOwnerUser represents a user ownership source for an app. - properties: - appId: - description: The appId field. - readOnly: false + resourceTypeId: + description: The resourceTypeId field. type: string - createdAt: - format: date-time - readOnly: false + secondaryText: + description: |- + Optional secondary line shown under the display name (e.g. an account's + email/username, or an identity's email). type: string - roleSlug: - description: The roleSlug field. - readOnly: false + type: + description: The type field. + enum: + - GRAPH_NODE_TYPE_UNSPECIFIED + - GRAPH_NODE_TYPE_USER + - GRAPH_NODE_TYPE_APP_USER + - GRAPH_NODE_TYPE_APP + - GRAPH_NODE_TYPE_RESOURCE_TYPE + - GRAPH_NODE_TYPE_RESOURCE + - GRAPH_NODE_TYPE_ENTITLEMENT + - GRAPH_NODE_TYPE_GRANT type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: App Owner User + x-speakeasy-unknown-values: allow + title: Graph Node type: object - x-speakeasy-entity: App_Owner_User - x-speakeasy-name-override: AppOwnerUser - c1.api.app.v2.ConnectorOwnerEntitlement: - description: ConnectorOwnerEntitlement represents an entitlement ownership source for a connector. + x-speakeasy-name-override: GraphNode + c1.api.app.v1.ListAppEntitlementOwnerIDsResponse: + description: The response message for listing app entitlement owners IDs. properties: - appEntitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' - createdAt: - format: date-time - readOnly: false - type: string - roleSlug: - description: The roleSlug field. - readOnly: false - type: string - title: Connector Owner Entitlement + userIds: + description: The list of owner IDs for the app entitlement. + items: + type: string + type: + - array + - "null" + title: List App Entitlement Owner I Ds Response type: object - x-speakeasy-name-override: ConnectorOwnerEntitlement - c1.api.app.v2.ConnectorOwnerUser: - description: ConnectorOwnerUser represents a user ownership source for a connector. + x-speakeasy-name-override: ListAppEntitlementOwnerIDsResponse + c1.api.app.v1.ListAppEntitlementOwnersResponse: + description: The response message for listing app entitlement owners. properties: - createdAt: - format: date-time - readOnly: false - type: string - roleSlug: - description: The roleSlug field. - readOnly: false + list: + description: The list of owners for the app entitlement. + items: + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: Connector Owner User + title: List App Entitlement Owners Response type: object - x-speakeasy-name-override: ConnectorOwnerUser - c1.api.app.v2.CreateEntitlementOwnerRequestInput: - description: CreateEntitlementOwnerRequest is the request for creating an entitlement ownership source. + x-speakeasy-name-override: ListAppEntitlementOwnersResponse + c1.api.app.v1.ListAppEntitlementRoutingRulesResponse: + description: The ListAppEntitlementRoutingRulesResponse message. properties: - appEntitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - title: Create Entitlement Owner Request + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRule' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: List App Entitlement Routing Rules Response type: object - x-speakeasy-name-override: CreateEntitlementOwnerRequest - c1.api.app.v2.CreateEntitlementOwnerResponse: - description: CreateEntitlementOwnerResponse is the response for creating an entitlement ownership source. + x-speakeasy-name-override: ListAppEntitlementRoutingRulesResponse + c1.api.app.v1.ListAppEntitlementUsersResponse: + description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. properties: - appOwnerEntitlement: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' - title: Create Entitlement Owner Response + expanded: + description: List of related objects + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: List App Entitlement Users Response type: object - x-speakeasy-name-override: CreateEntitlementOwnerResponse - c1.api.app.v2.CreateUserOwnerRequestInput: - description: CreateUserOwnerRequest is the request for creating a user ownership source. - properties: - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Create User Owner Request - type: object - x-speakeasy-name-override: CreateUserOwnerRequest - c1.api.app.v2.CreateUserOwnerResponse: - description: CreateUserOwnerResponse is the response for creating a user ownership source. - properties: - appOwnerUser: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' - title: Create User Owner Response - type: object - x-speakeasy-name-override: CreateUserOwnerResponse - c1.api.app.v2.DeleteEntitlementOwnerRequestInput: - description: DeleteEntitlementOwnerRequest is the request for deleting an entitlement ownership source. - properties: - appEntitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - title: Delete Entitlement Owner Request - type: object - x-speakeasy-name-override: DeleteEntitlementOwnerRequest - c1.api.app.v2.DeleteEntitlementOwnerResponse: - description: DeleteEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source. - title: Delete Entitlement Owner Response - type: object - x-speakeasy-name-override: DeleteEntitlementOwnerResponse - c1.api.app.v2.DeleteUserOwnerRequestInput: - description: DeleteUserOwnerRequest is the request for deleting a user ownership source. - properties: - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Delete User Owner Request - type: object - x-speakeasy-name-override: DeleteUserOwnerRequest - c1.api.app.v2.DeleteUserOwnerResponse: - description: DeleteUserOwnerResponse is the empty response for deleting a user ownership source. - title: Delete User Owner Response - type: object - x-speakeasy-name-override: DeleteUserOwnerResponse - c1.api.app.v2.GetEntitlementOwnerResponse: - description: GetEntitlementOwnerResponse is the response for getting an entitlement ownership source. + x-speakeasy-name-override: ListAppEntitlementUsersResponse + c1.api.app.v1.ListAppEntitlementsResponse: + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. properties: - appOwnerEntitlement: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' - title: Get Entitlement Owner Response + expanded: + description: List of related objects + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: List App Entitlements Response type: object - x-speakeasy-name-override: GetEntitlementOwnerResponse - c1.api.app.v2.GetUserOwnerResponse: - description: GetUserOwnerResponse is the response for getting a user ownership source. + x-speakeasy-name-override: ListAppEntitlementsResponse + c1.api.app.v1.ListAppOwnerIDsResponse: + description: The response message for listing app owners IDs. properties: - appOwnerUser: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' - title: Get User Owner Response + userIds: + description: The list of owner IDs for the app. + items: + type: string + type: + - array + - "null" + title: List App Owner I Ds Response type: object - x-speakeasy-name-override: GetUserOwnerResponse - c1.api.app.v2.SearchAppEntitlementEntitlementOwnersResponse: - description: SearchAppEntitlementEntitlementOwnersResponse is the response for searching entitlement ownership sources on an entitlement. + x-speakeasy-name-override: ListAppOwnerIDsResponse + c1.api.app.v1.ListAppOwnersResponse: + description: The ListAppOwnersResponse message. properties: list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerEntitlement' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search App Entitlement Entitlement Owners Response + title: List App Owners Response type: object - x-speakeasy-name-override: SearchAppEntitlementEntitlementOwnersResponse - c1.api.app.v2.SearchAppEntitlementUserOwnersResponse: - description: SearchAppEntitlementUserOwnersResponse is the response for searching user ownership sources on an entitlement. + x-speakeasy-name-override: ListAppOwnersResponse + c1.api.app.v1.ListAppResourceOwnerIDsResponse: + description: The response message for listing app resource owners IDs. properties: - list: - description: The list field. + userIds: + description: The list of owner IDs for the app resource. items: - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerUser' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Search App Entitlement User Owners Response + type: string + type: + - array + - "null" + title: List App Resource Owner I Ds Response type: object - x-speakeasy-name-override: SearchAppEntitlementUserOwnersResponse - c1.api.app.v2.SearchConnectorEntitlementOwnersResponse: - description: SearchConnectorEntitlementOwnersResponse is the response for searching entitlement ownership sources on a connector. + x-speakeasy-name-override: ListAppResourceOwnerIDsResponse + c1.api.app.v1.ListAppResourceOwnersResponse: + description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable properties: + immutableUserIds: + description: |- + User IDs of owners that are immutable and cannot be removed by the user. + These owners are managed by the system (e.g., connector-sourced) and will be updated automatically. + items: + type: string + type: + - array + - "null" list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerEntitlement' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search Connector Entitlement Owners Response + title: List App Resource Owners Response type: object - x-speakeasy-name-override: SearchConnectorEntitlementOwnersResponse - c1.api.app.v2.SearchConnectorUserOwnersResponse: - description: SearchConnectorUserOwnersResponse is the response for searching user ownership sources on a connector. + x-speakeasy-name-override: ListAppResourceOwnersResponse + c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse: + description: The ListAppUsersForIdentityWithGrantResponse message. properties: - list: - description: The list field. + bindings: + description: |- + The list of app users that may also have grant information. + Without a grant, only the tenant, app, and app user ID will be set. With a grant, the whole struct is populated items: - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerUser' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Search Connector User Owners Response + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' + type: + - array + - "null" + title: List App Users For Identity With Grant Response type: object - x-speakeasy-name-override: SearchConnectorUserOwnersResponse - c1.api.app.v2.SearchEntitlementOwnersResponse: - description: SearchEntitlementOwnersResponse is the response for searching entitlement ownership sources. + x-speakeasy-name-override: ListAppUsersForIdentityWithGrantResponse + c1.api.app.v1.ListAppsResponse: + description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. properties: list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.App' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search Entitlement Owners Response + title: List Apps Response type: object - x-speakeasy-name-override: SearchEntitlementOwnersResponse - c1.api.app.v2.SearchUserOwnersResponse: - description: SearchUserOwnersResponse is the response for searching user ownership sources. + x-speakeasy-name-override: ListAppsResponse + c1.api.app.v1.ListAutomationExclusionsResponse: + description: The ListAutomationExclusionsResponse message. properties: list: description: The list field. items: - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.UserWithAppEntitlementUserBindingView' + type: + - array + - "null" nextPageToken: description: The nextPageToken field. - readOnly: false type: string - title: Search User Owners Response + title: List Automation Exclusions Response type: object - x-speakeasy-name-override: SearchUserOwnersResponse - c1.api.app.v2.SetAppEntitlementOwnersV2RequestInput: - description: SetAppEntitlementOwnersV2Request is the request for setting the owners of an app entitlement for a given role. + x-speakeasy-name-override: ListAutomationExclusionsResponse + c1.api.app.v1.ListOwnedServiceAccountsRequest: + description: The ListOwnedServiceAccountsRequest message. properties: - appEntitlementRefs: - description: The appEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - roleSlug: - description: Empty defaults to the "primary" role on the server side. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUserExpandMask' + - type: "null" + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: The token for fetching the next page of results. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Set App Entitlement Owners V 2 Request + title: List Owned Service Accounts Request type: object - x-speakeasy-name-override: SetAppEntitlementOwnersV2Request - c1.api.app.v2.SetAppEntitlementOwnersV2Response: - description: SetAppEntitlementOwnersV2Response is the empty response for setting app entitlement owners. - title: Set App Entitlement Owners V 2 Response - type: object - x-speakeasy-name-override: SetAppEntitlementOwnersV2Response - c1.api.app.v2.SetAppOwnersRequestInput: - description: SetAppOwnersRequest is the request for setting user owners for an app and role. + x-speakeasy-name-override: ListOwnedServiceAccountsRequest + c1.api.app.v1.ListOwnedServiceAccountsResponse: + description: The ListOwnedServiceAccountsResponse message. properties: - appEntitlementRefs: - description: The appEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - roleSlug: - description: The roleSlug field. - readOnly: false - type: string - userRefs: - description: The userRefs field. + expanded: + description: List of related objects. items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Set App Owners Request - type: object - x-speakeasy-name-override: SetAppOwnersRequestV2 - c1.api.app.v2.SetAppOwnersResponse: - description: SetAppOwnersResponse is the empty response for setting app owners. - title: Set App Owners Response - type: object - x-speakeasy-name-override: SetAppOwnersResponseV2 - c1.api.app.v2.SetConnectorOwnersV2RequestInput: - description: SetConnectorOwnersV2Request is the request for setting the owners of a connector for a given role. - properties: - appEntitlementRefs: - description: The appEntitlementRefs field. + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The service accounts owned by the calling user, up to one page of results. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - roleSlug: - description: The role slug for this ownership grant. Required. - readOnly: false + $ref: '#/components/schemas/c1.api.app.v1.AppUserView' + type: + - array + - "null" + nextPageToken: + description: The token for fetching the next page of results, empty when there are no more pages. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Set Connector Owners V 2 Request - type: object - x-speakeasy-name-override: SetConnectorOwnersV2Request - c1.api.app.v2.SetConnectorOwnersV2Response: - description: SetConnectorOwnersV2Response is the empty response for setting connector owners. - title: Set Connector Owners V 2 Response + title: List Owned Service Accounts Response type: object - x-speakeasy-name-override: SetConnectorOwnersV2Response - c1.api.attribute.v1.AttributeType: - description: AttributeType defines the type of an attribute. + x-speakeasy-name-override: ListOwnedServiceAccountsResponse + c1.api.app.v1.ManuallyManagedUsersResponse: + description: The ManuallyManagedUsersResponse message. properties: - id: - description: The ID of the AttributeType. - readOnly: false - type: string - name: - description: The name of the AttributeType. - readOnly: false + bulkActionId: + description: The ID of the bulk action created to process the membership additions. type: string - title: Attribute Type + failedUsersErrorMap: + additionalProperties: + type: string + description: A map of user IDs to error messages for users that could not be added. + type: object + title: Manually Managed Users Response type: object - x-speakeasy-name-override: AttributeType - c1.api.attribute.v1.AttributeValue: - description: AttributeValue is the value of an attribute of a defined type. + x-speakeasy-name-override: ManuallyManagedUsersResponse + c1.api.app.v1.OAuth2AuthorizedAs: + description: OAuth2AuthorizedAs tracks the user that OAuthed with the connector. properties: - attributeTypeId: - description: The ID of the AttributeType that this AttributeValue belongs to. - readOnly: false - type: string - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time + authEmail: + description: authEmail is the email of the user that authorized the connector using OAuth. readOnly: true type: string - id: - description: The ID of the AttributeValue. - readOnly: false - type: string - updatedAt: + authorizedAt: format: date-time readOnly: true - type: string - value: - description: The value of the AttributeValue. This is the string that will be displayed to the user. - readOnly: false - type: string - title: Attribute Value - type: object - x-speakeasy-name-override: AttributeValue - c1.api.attribute.v1.CreateAttributeValueRequest: - description: The CreateAttributeValueRequest message. - properties: - attributeTypeId: - description: The attributeTypeId field. - readOnly: false - type: string - value: - description: The value field. - readOnly: false - type: string - title: Create Attribute Value Request - type: object - x-speakeasy-name-override: CreateAttributeValueRequest - c1.api.attribute.v1.CreateAttributeValueResponse: - description: CreateAttributeValueResponse is the response for creating an attribute value. - properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Create Attribute Value Response - type: object - x-speakeasy-name-override: CreateAttributeValueResponse - c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest: - description: The CreateComplianceFrameworkAttributeValueRequest message. - properties: - value: - description: The value field. - readOnly: false - type: string - title: Create Compliance Framework Attribute Value Request - type: object - x-speakeasy-name-override: CreateComplianceFrameworkAttributeValueRequest - c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse: - description: The CreateComplianceFrameworkAttributeValueResponse message. - properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Create Compliance Framework Attribute Value Response + type: + - string + - "null" + title: O Auth 2 Authorized As type: object - x-speakeasy-name-override: CreateComplianceFrameworkAttributeValueResponse - c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest: - description: The CreateRiskLevelAttributeValueRequest message. - properties: - value: - description: The value field. - readOnly: false - type: string - title: Create Risk Level Attribute Value Request + x-speakeasy-name-override: OAuth2AuthorizedAs + c1.api.app.v1.PauseSyncRequestInput: + description: The PauseSyncRequest message contains the fields required to pause syncing for a connector. + title: Pause Sync Request type: object - x-speakeasy-name-override: CreateRiskLevelAttributeValueRequest - c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse: - description: The CreateRiskLevelAttributeValueResponse message. - properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Create Risk Level Attribute Value Response + x-speakeasy-name-override: PauseSyncRequest + c1.api.app.v1.PauseSyncResponse: + description: Empty response body. Status code indicates success. + title: Pause Sync Response type: object - x-speakeasy-name-override: CreateRiskLevelAttributeValueResponse - c1.api.attribute.v1.DeleteAttributeValueRequestInput: - description: The DeleteAttributeValueRequest message. - title: Delete Attribute Value Request + x-speakeasy-name-override: PauseSyncResponse + c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput: + description: The request message for removing an app entitlement owner. + title: Remove App Entitlement Owner Request type: object - x-speakeasy-name-override: DeleteAttributeValueRequest - c1.api.attribute.v1.DeleteAttributeValueResponse: - description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. - title: Delete Attribute Value Response + x-speakeasy-name-override: RemoveAppEntitlementOwnerRequest + c1.api.app.v1.RemoveAppEntitlementOwnerResponse: + description: The empty response message for removing an app entitlement owner. + title: Remove App Entitlement Owner Response type: object - x-speakeasy-name-override: DeleteAttributeValueResponse - c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput: - description: The DeleteComplianceFrameworkAttributeValueRequest message. - title: Delete Compliance Framework Attribute Value Request + x-speakeasy-name-override: RemoveAppEntitlementOwnerResponse + c1.api.app.v1.RemoveAppOwnerRequestInput: + description: RemoveAppOwnerRequest is the request body for removing an app owner. It uses URL values for input. + title: Remove App Owner Request type: object - x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValueRequest - c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse: - description: The DeleteComplianceFrameworkAttributeValueResponse message. - title: Delete Compliance Framework Attribute Value Response + x-speakeasy-name-override: RemoveAppOwnerRequest + c1.api.app.v1.RemoveAppOwnerResponse: + description: Empty response with a status code indicating success. + title: Remove App Owner Response type: object - x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValueResponse - c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput: - description: The DeleteRiskLevelAttributeValueRequest message. - title: Delete Risk Level Attribute Value Request + x-speakeasy-name-override: RemoveAppOwnerResponse + c1.api.app.v1.RemoveAppResourceOwnerRequestInput: + description: The request message for removing an owner from an app resource. + properties: + userId: + description: The C1 user ID to remove as an owner. + type: string + title: Remove App Resource Owner Request type: object - x-speakeasy-name-override: DeleteRiskLevelAttributeValueRequest - c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse: - description: The DeleteRiskLevelAttributeValueResponse message. - title: Delete Risk Level Attribute Value Response + x-speakeasy-name-override: RemoveAppResourceOwnerRequest + c1.api.app.v1.RemoveAppResourceOwnerResponse: + description: The empty response message for removing an owner from an app resource. + title: Remove App Resource Owner Response type: object - x-speakeasy-name-override: DeleteRiskLevelAttributeValueResponse - c1.api.attribute.v1.GetAttributeValueResponse: - description: GetAttributeValueResponse is the response for getting an attribute value by id. + x-speakeasy-name-override: RemoveAppResourceOwnerResponse + c1.api.app.v1.RemoveAutomationExclusionRequestInput: + description: The RemoveAutomationExclusionRequest message. properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Get Attribute Value Response + userIds: + description: The IDs of users to remove from the automation exclusion list. + items: + type: string + type: + - array + - "null" + title: Remove Automation Exclusion Request type: object - x-speakeasy-name-override: GetAttributeValueResponse - c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse: - description: The GetComplianceFrameworkAttributeValueResponse message. - properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Get Compliance Framework Attribute Value Response + x-speakeasy-name-override: RemoveAutomationExclusionRequest + c1.api.app.v1.RemoveAutomationExclusionResponse: + description: Empty response with a status code indicating success. + title: Remove Automation Exclusion Response type: object - x-speakeasy-name-override: GetComplianceFrameworkAttributeValueResponse - c1.api.attribute.v1.GetRiskLevelAttributeValueResponse: - description: The GetRiskLevelAttributeValueResponse message. + x-speakeasy-name-override: RemoveAutomationExclusionResponse + c1.api.app.v1.RemoveEntitlementMembershipRequestInput: + description: The RemoveEntitlementMembershipRequest message. properties: - value: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - title: Get Risk Level Attribute Value Response + appUserId: + description: The ID of the app user whose membership to remove. + type: string + title: Remove Entitlement Membership Request type: object - x-speakeasy-name-override: GetRiskLevelAttributeValueResponse - c1.api.attribute.v1.ListAttributeTypesResponse: - description: ListAttributeTypesResponse is the response for listing attribute types. + x-speakeasy-name-override: RemoveEntitlementMembershipRequest + c1.api.app.v1.RemoveEntitlementMembershipResponse: + description: The RemoveEntitlementMembershipResponse message. properties: - list: - description: The list of AttributeTypes. - items: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeType' - nullable: true - readOnly: false - type: array - nextPageToken: + revokeTaskId: description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + The ID of the revoke task created to remove the user from the entitlement, if the entitlement is an access profile (aka. catalog). + It's aka. the JML task. type: string - title: List Attribute Types Response + title: Remove Entitlement Membership Response type: object - x-speakeasy-name-override: ListAttributeTypesResponse - c1.api.attribute.v1.ListAttributeValuesResponse: - description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. + x-speakeasy-name-override: RemoveEntitlementMembershipResponse + c1.api.app.v1.RemoveGrantDurationRequestInput: + description: The request message for removing the expiration time from a grant. + title: Remove Grant Duration Request + type: object + x-speakeasy-name-override: RemoveGrantDurationRequest + c1.api.app.v1.RemoveGrantDurationResponse: + description: The response message for removing the expiration time from a grant. properties: - list: - description: The list of AttributeValues. - items: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - nullable: true - readOnly: false - type: array - nextPageToken: + binding: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' + - type: "null" + title: Remove Grant Duration Response + type: object + x-speakeasy-name-override: RemoveGrantDurationResponse + c1.api.app.v1.ReorderAppEntitlementRoutingRulesRequestInput: + description: The ReorderAppEntitlementRoutingRulesRequest message. + properties: + ruleIds: description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false - type: string - title: List Attribute Values Response + The full set of routing-rule IDs for the app, in the desired evaluation + order. The first entry receives priority 1, the second priority 2, and so + on. The list must be a permutation of every active rule in the app. + items: + type: string + type: + - array + - "null" + title: Reorder App Entitlement Routing Rules Request type: object - x-speakeasy-name-override: ListAttributeValuesResponse - c1.api.attribute.v1.ListComplianceFrameworksResponse: - description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. + x-speakeasy-name-override: ReorderAppEntitlementRoutingRulesRequest + c1.api.app.v1.ReorderAppEntitlementRoutingRulesResponse: + description: The ReorderAppEntitlementRoutingRulesResponse message. properties: list: - description: The list of compliance framework attribute values. + description: The rules in their new evaluation order, with priorities reassigned to 1..N. items: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - readOnly: false - type: string - title: List Compliance Frameworks Response + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRule' + type: + - array + - "null" + title: Reorder App Entitlement Routing Rules Response type: object - x-speakeasy-name-override: ListComplianceFrameworksResponse - c1.api.attribute.v1.ListRiskLevelsResponse: - description: ListRiskLevelsResponse is the response for listing risk level attribute values. + x-speakeasy-name-override: ReorderAppEntitlementRoutingRulesResponse + c1.api.app.v1.ResumeSyncRequestInput: + description: The ResumeSyncRequest message contains the fields required to resume syncing for a connector. + title: Resume Sync Request + type: object + x-speakeasy-name-override: ResumeSyncRequest + c1.api.app.v1.ResumeSyncResponse: + description: Empty response body. Status code indicates success. + title: Resume Sync Response + type: object + x-speakeasy-name-override: ResumeSyncResponse + c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse: + description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. properties: list: - description: The list of risk level attribute values. + description: The list field. items: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementWithExpired' + type: + - array + - "null" nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + description: The nextPageToken field. type: string - title: List Risk Levels Response + title: Search App Entitlements With Expired Response type: object - x-speakeasy-name-override: ListRiskLevelsResponse - c1.api.attribute.v1.SearchAttributeValuesRequest: - description: Search Attributes by a few properties. + x-speakeasy-name-override: SearchAppEntitlementsWithExpiredResponse + c1.api.app.v1.SearchAppResourceTypesRequest: + description: Search for app resources based on some filters. properties: - attributeTypeIds: - description: The attribute type ids for what type of attributes to search for. + appIds: + description: A list of app IDs to restrict the search by. items: type: string - nullable: true - readOnly: false - type: array - excludeIds: - description: Exclude attributes with these ids from the search results. + type: + - array + - "null" + appUserIds: + description: A list of app user IDs to restrict the search by. items: type: string - nullable: true - readOnly: false - type: array - ids: - description: Include attributes with these ids in the search results. + type: + - array + - "null" + displayName: + description: Exact match on display name + type: string + excludeResourceTypeIds: + description: A list of resource type IDs to exclude from the search. + items: + type: string + type: + - array + - "null" + excludeResourceTypeTraitIds: + description: A list of resource type trait IDs to exclude from the search. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: The pageSize where 10 <= pageSize <= 100, default 25. format: int32 - readOnly: false type: integer pageToken: description: The pageToken field. - readOnly: false type: string query: - description: Query the attributes with a fuzzy search on display name and description. - readOnly: false - type: string - value: - description: Search for attributes with a case insensitive match on the attribute value which is the attribute name. - readOnly: false + description: Fuzzy search the display name of resource types. type: string - title: Search Attribute Values Request + resourceTypeIds: + description: A list of resource type IDs to restrict the search by. + items: + type: string + type: + - array + - "null" + resourceTypeTraitIds: + description: A list of resource type trait IDs to restrict the search by. + items: + type: string + type: + - array + - "null" + title: Search App Resource Types Request type: object - x-speakeasy-name-override: SearchAttributeValuesRequest - c1.api.attribute.v1.SearchAttributeValuesResponse: - description: SearchAttributeValuesResponse is the response for searching AttributeValues. + x-speakeasy-name-override: SearchAppResourceTypesRequest + c1.api.app.v1.SearchAppResourceTypesResponse: + description: The SearchAppResourceTypesResponse message contains a list of results and a nextPageToken if applicable. properties: list: - description: The list of returned AttributeValues. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' + type: + - array + - "null" nextPageToken: description: |- The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false type: string - title: Search Attribute Values Response + title: Search App Resource Types Response type: object - x-speakeasy-name-override: SearchAttributeValuesResponse - c1.api.auth.v1.IntrospectResponse: - description: IntrospectResponse contains information about the current user who is authenticated. + x-speakeasy-name-override: SearchAppResourceTypesResponse + c1.api.app.v1.SearchAppResourcesRequest: + description: Search app resources based on filters specified in the request body. properties: - features: - description: The list of feature flags enabled for the tenant the logged in user belongs to. + agentStatuses: + description: |- + Restrict the search to AI-agent resources with one of the given agent + lifecycle statuses (READY, DISABLED, DELETED). When empty, agent status is + not used as a filter. items: + enum: + - AGENT_STATUS_UNSPECIFIED + - AGENT_STATUS_READY + - AGENT_STATUS_DISABLED + - AGENT_STATUS_DELETED type: string - nullable: true - readOnly: false - type: array - permissions: - description: The list of permissions that the current logged in user has. + x-speakeasy-unknown-values: allow + type: + - array + - "null" + appId: + description: The app ID to restrict the search to. + type: string + appIds: + description: |- + A list of app IDs to restrict the search to. Mirrors the singular app_id; + both fold into the same filter, so callers may set either or both. items: type: string - nullable: true - readOnly: false - type: array - principleId: - description: The principleID of the current logged in user. - readOnly: false - type: string - roles: - description: The list of roles that the current logged in user has. + type: + - array + - "null" + appUserIds: + description: A list of app user IDs to restrict the search by. items: type: string - nullable: true - readOnly: false - type: array - userId: - description: The userID of the current logged in user. - readOnly: false + type: + - array + - "null" + credentialTypes: + description: |- + Restrict the search to resources whose credential material spine (K1) matches + one of the given CredentialType values. Applies to resources with a + secret_trait. When empty, credential_type is not used as a filter. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_STATIC_SECRET + - CREDENTIAL_TYPE_ASYMMETRIC_KEY + - CREDENTIAL_TYPE_CERTIFICATE + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + direction: + description: |- + Direction to sort in. Unspecified falls back to ASC when sort_field is set. + No defined_only validation here: protoc-gen-validate mis-resolves the + cross-package enum name map to this file's c1.models.app.v1 import alias + instead of c1.api.search.v1, which fails to compile. The query builder + already treats any unrecognized value as ASC, so this is safe to omit. + enum: + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC type: string - title: Introspect Response - type: object - x-speakeasy-name-override: IntrospectResponse - c1.api.auth_config.v1.AuthConfigC1Local: - description: The AuthConfigC1Local message. - nullable: true - properties: - delegatedVerifiers: - description: The delegatedVerifiers field. + x-speakeasy-unknown-values: allow + excludeDeletedApps: + description: When true, excludes resources belonging to soft-deleted apps. + type: boolean + excludeDeletedResourceBindings: + description: If true, exclude resources whose bindings have been deleted. + type: boolean + excludeResourceIds: + description: A list of resource IDs to exclude from the search results. + items: + type: string + type: + - array + - "null" + excludeResourceTypeTraitIds: + description: A list of resource type trait IDs to exclude from the search. + items: + type: string + type: + - array + - "null" + nhiTypes: + description: |- + Restrict the search to resources whose NHI classification spine (K3) is one + of the given NhiType values. When empty, nhi_type is not used as a filter. items: enum: - - DELEGATED_VERIFIER_TYPE_UNSPECIFIED - - DELEGATED_VERIFIER_TYPE_GOOGLE - - DELEGATED_VERIFIER_TYPE_MICROSOFT - - DELEGATED_VERIFIER_TYPE_GITHUB + - NHI_TYPE_UNSPECIFIED + - NHI_TYPE_APP_REGISTRATION + - NHI_TYPE_ASSUMABLE_ROLE + - NHI_TYPE_MANAGED_IDENTITY type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Auth Config C 1 Local - type: object - x-speakeasy-name-override: AuthConfigC1Local - c1.api.auth_config.v1.AuthConfigGoogle: - description: The AuthConfigGoogle message. - nullable: true - properties: - hostedDomains: - description: The hostedDomains field. + type: + - array + - "null" + ownerUserIds: + description: |- + A list of C1 user IDs to filter resources by ownership. The sentinel + value "none" matches resources with no owner. Mutually exclusive with + unowned_only — combine "none" with real owner IDs instead of setting + unowned_only alongside them. items: type: string - nullable: true - readOnly: false - type: array - title: Auth Config Google - type: object - x-speakeasy-name-override: AuthConfigGoogle - c1.api.auth_config.v1.AuthConfigJumpCloud: - description: The AuthConfigJumpCloud message. - nullable: true - properties: - oidcClientId: - description: The oidcClientId field. - readOnly: false + type: + - array + - "null" + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: The token for fetching the next page of results. type: string - oidcClientSecret: - description: Write-only. Never returned in get/list. - readOnly: false + query: + description: Fuzzy search the display name of resources. type: string - title: Auth Config Jump Cloud - type: object - x-speakeasy-name-override: AuthConfigJumpCloud - c1.api.auth_config.v1.AuthConfigMicrosoft: - description: The AuthConfigMicrosoft message. - nullable: true - properties: - tenantIds: - description: The tenantIds field. + refs: + description: A list of specific app resource references to restrict the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' + type: + - array + - "null" + resourceIds: + description: A list of resource IDs to restrict the search to. items: type: string - nullable: true - readOnly: false - type: array - title: Auth Config Microsoft - type: object - x-speakeasy-name-override: AuthConfigMicrosoft - c1.api.auth_config.v1.AuthConfigOIDC: - description: The AuthConfigOIDC message. - nullable: true - properties: - exactMatchClaims: - additionalProperties: + type: + - array + - "null" + resourceTypeIds: + description: A list of resource type IDs to restrict the search by. + items: type: string - description: The exactMatchClaims field. - readOnly: false - type: object - issuerId: - description: The issuerId field. - readOnly: false - type: string - oidcClientId: - description: The oidcClientId field. - readOnly: false - type: string - oidcClientSecret: - description: The oidcClientSecret field. - readOnly: false - type: string - scopes: - description: The scopes field. + type: + - array + - "null" + resourceTypeTraitIds: + description: A list of resource type trait IDs to restrict the search by. items: type: string - nullable: true - readOnly: false - type: array - title: Auth Config Oidc - type: object - x-speakeasy-name-override: AuthConfigOIDC - c1.api.auth_config.v1.AuthConfigOkta: - description: The AuthConfigOkta message. - nullable: true - properties: - domain: - description: The domain field. - readOnly: false - type: string - oidcClientId: - description: The oidcClientId field. - readOnly: false - type: string - oidcClientSecret: - description: Write-only. Never returned in get/list. - readOnly: false - type: string - title: Auth Config Okta - type: object - x-speakeasy-name-override: AuthConfigOkta - c1.api.auth_config.v1.AuthConfigOneLogin: - description: The AuthConfigOneLogin message. - nullable: true - properties: - domain: - description: The domain field. - readOnly: false - type: string - oidcClientId: - description: The oidcClientId field. - readOnly: false - type: string - oidcClientSecret: - description: The oidcClientSecret field. - readOnly: false + type: + - array + - "null" + secretAging: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.SecretAgingFilter' + - type: "null" + sortField: + description: Column to sort by. Unspecified (0) keeps the server's default order (app, then display name). + enum: + - APP_RESOURCE_SORT_FIELD_UNSPECIFIED + - APP_RESOURCE_SORT_FIELD_SECRET_CREATED_AT + - APP_RESOURCE_SORT_FIELD_SECRET_EXPIRES_AT + - APP_RESOURCE_SORT_FIELD_LAST_USED_AT type: string - title: Auth Config One Login + x-speakeasy-unknown-values: allow + unownedOnly: + description: |- + When true, restrict results to resources with no ownership-v2 primary-role + owner. Mutually exclusive with owner_user_ids — use owner_user_ids: + ["none"] instead if you also need to combine it with real owner IDs. + type: boolean + withOpenFindings: + description: |- + When true, restrict results to resources that have at least one open finding + (index-backed EXISTS semi-join). When false/unset, results are unfiltered. + type: boolean + title: Search App Resources Request type: object - x-speakeasy-name-override: AuthConfigOneLogin - c1.api.auth_config.v1.AuthConfigPingOne: - description: The AuthConfigPingOne message. - nullable: true + x-speakeasy-name-override: SearchAppResourcesRequest + c1.api.app.v1.SearchAppResourcesResponse: + description: The SearchAppResourcesResponse message contains a list of results and a nextPageToken if applicable. properties: - environmentId: - description: The environmentId field. - readOnly: false - type: string - oidcClientId: - description: The oidcClientId field. - readOnly: false - type: string - oidcClientSecret: - description: The oidcClientSecret field. - readOnly: false + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of app resource results. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceView' + type: + - array + - "null" + nextPageToken: + description: The token for fetching the next page of results. type: string - title: Auth Config Ping One + title: Search App Resources Response type: object - x-speakeasy-name-override: AuthConfigPingOne - c1.api.auth_config.v1.TenantAuthConfig: - description: | - The TenantAuthConfig message. - - This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: - - google - - microsoft - - okta - - onelogin - - jumpcloud - - pingone - - oidc - - c1Local + x-speakeasy-name-override: SearchAppResourcesResponse + c1.api.app.v1.SearchAppsRequest: + description: Search Apps by a few properties. properties: - bootstrapDomains: - description: 'Bootstrap routing: email domains that route unknown users to this config.' + appIds: + description: A list of app IDs to restrict the search to. items: type: string - nullable: true - readOnly: false - type: array - c1Local: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigC1Local' - createdAt: - format: date-time - readOnly: true - type: string - deprecationDeadline: - format: date-time - readOnly: false - type: string - deprecationMessage: - description: User-visible message shown when status=DEPRECATED. - readOnly: false - type: string + type: + - array + - "null" displayName: - description: The displayName field. - readOnly: false - type: string - google: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigGoogle' - id: - description: The id field. - readOnly: false + description: Search for apps with a case insensitive match on the display name. type: string - isDefaultBootstrap: - description: The isDefaultBootstrap field. - readOnly: false + excludeAppIds: + description: A list of app IDs to remove from the results. + items: + type: string + type: + - array + - "null" + onlyDirectories: + description: Only return apps which are directories type: boolean - jumpcloud: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigJumpCloud' - microsoft: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigMicrosoft' - oidc: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOIDC' - okta: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOkta' - onelogin: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOneLogin' - pingone: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigPingOne' - providerType: - description: Provider type (read-only after creation — provider config determines type). - enum: - - AUTH_CONFIG_PROVIDER_TYPE_UNSPECIFIED - - AUTH_CONFIG_PROVIDER_TYPE_GOOGLE - - AUTH_CONFIG_PROVIDER_TYPE_MICROSOFT - - AUTH_CONFIG_PROVIDER_TYPE_OKTA - - AUTH_CONFIG_PROVIDER_TYPE_ONELOGIN - - AUTH_CONFIG_PROVIDER_TYPE_JUMPCLOUD - - AUTH_CONFIG_PROVIDER_TYPE_PINGONE - - AUTH_CONFIG_PROVIDER_TYPE_OIDC - - AUTH_CONFIG_PROVIDER_TYPE_C1_LOCAL - readOnly: true - type: string - x-speakeasy-unknown-values: allow - status: - description: The status field. - enum: - - AUTH_CONFIG_STATUS_UNSPECIFIED - - AUTH_CONFIG_STATUS_ACTIVE - - AUTH_CONFIG_STATUS_DEPRECATED - - AUTH_CONFIG_STATUS_DISABLED - readOnly: false + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true + policyRefs: + description: Search for apps that use any of these policies. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' + type: + - array + - "null" + query: + description: Query the apps with a fuzzy search on display name and description. type: string - title: Tenant Auth Config + title: Search Apps Request type: object - x-speakeasy-name-override: TenantAuthConfig - c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest: - description: | - The TenantAuthConfigServiceCreateRequest message. - - This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: - - google - - microsoft - - okta - - onelogin - - jumpcloud - - pingone - - oidc - - c1Local + x-speakeasy-name-override: SearchAppsRequest + c1.api.app.v1.SearchAppsResponse: + description: The SearchAppsResponse message contains a list of results and a nextPageToken if applicable. properties: - bootstrapDomains: - description: Email domains that route unknown users to this authentication provider during login. + list: + description: The list of results containing up to X results, where X is the page size defined in the request. items: - type: string - nullable: true - readOnly: false - type: array - c1Local: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigC1Local' - deprecationDeadline: - format: date-time - readOnly: false - type: string - deprecationMessage: - description: A user-visible message explaining why the provider is deprecated. - readOnly: false - type: string - displayName: - description: The human-readable name for this authentication provider. - readOnly: false - type: string - google: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigGoogle' - isDefaultBootstrap: - description: Whether this provider is the default for users whose email domain has no explicit mapping. - readOnly: false - type: boolean - jumpcloud: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigJumpCloud' - microsoft: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigMicrosoft' - oidc: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOIDC' - okta: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOkta' - onelogin: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOneLogin' - pingone: - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigPingOne' - status: - description: The initial status of the authentication provider. - enum: - - AUTH_CONFIG_STATUS_UNSPECIFIED - - AUTH_CONFIG_STATUS_ACTIVE - - AUTH_CONFIG_STATUS_DEPRECATED - - AUTH_CONFIG_STATUS_DISABLED - readOnly: false + $ref: '#/components/schemas/c1.api.app.v1.App' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - x-speakeasy-unknown-values: allow - required: - - displayName - title: Tenant Auth Config Service Create Request - type: object - x-speakeasy-name-override: TenantAuthConfigServiceCreateRequest - c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse: - description: The TenantAuthConfigServiceCreateResponse message. - properties: - authConfig: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' - title: Tenant Auth Config Service Create Response - type: object - x-speakeasy-name-override: TenantAuthConfigServiceCreateResponse - c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput: - description: The TenantAuthConfigServiceDeleteRequest message. - title: Tenant Auth Config Service Delete Request - type: object - x-speakeasy-name-override: TenantAuthConfigServiceDeleteRequest - c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse: - description: The TenantAuthConfigServiceDeleteResponse message. - title: Tenant Auth Config Service Delete Response + title: Search Apps Response type: object - x-speakeasy-name-override: TenantAuthConfigServiceDeleteResponse - c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse: - description: The TenantAuthConfigServiceGetResponse message. + x-speakeasy-name-override: SearchAppsResponse + c1.api.app.v1.SearchGrantFeedRequest: + description: The SearchGrantFeedRequest message. properties: - authConfig: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' - title: Tenant Auth Config Service Get Response + after: + format: date-time + type: + - string + - "null" + appEntitlementRefs: + description: The list of app entitlements to limit the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + appRefs: + description: The list of apps to limit the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppRef' + type: + - array + - "null" + appUserRefs: + description: The list of app users to limit the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' + type: + - array + - "null" + before: + format: date-time + type: + - string + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask' + - type: "null" + pageSize: + description: The pageSize where 10 <= pageSize <= 100, default 25. + format: int32 + type: integer + pageToken: + description: The page_token field for pagination. + type: string + userRefs: + description: The list of C1 users to limit the search to. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Search Grant Feed Request type: object - x-speakeasy-name-override: TenantAuthConfigServiceGetResponse - c1.api.auth_config.v1.TenantAuthConfigServiceListResponse: - description: The TenantAuthConfigServiceListResponse message. + x-speakeasy-name-override: SearchGrantFeedRequest + c1.api.app.v1.SearchGrantFeedResponse: + description: The SearchGrantFeedResponse message contains a list of grant event results and a nextPageToken if applicable. properties: + expanded: + description: The expanded field. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" list: - description: The list of authentication provider configurations. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingFeedView' + type: + - array + - "null" nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retrieved. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Tenant Auth Config Service List Response + title: Search Grant Feed Response type: object - x-speakeasy-name-override: TenantAuthConfigServiceListResponse - c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput: - description: The TenantAuthConfigServiceUpdateRequest message. + x-speakeasy-name-override: SearchGrantFeedResponse + c1.api.app.v1.SearchPastGrantsRequest: + description: The request message for searching historical grants. properties: - authConfig: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' - updateMask: - nullable: true - readOnly: false + appEntitlementRefs: + description: A list of entitlement references to restrict the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + appIds: + description: A list of app IDs to restrict the search to. + items: + type: string + type: + - array + - "null" + appUserRefs: + description: A list of app user references to restrict the search to. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppUserRef' + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingExpandHistoryMask' + - type: "null" + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: The token for fetching the next page of results. type: string - title: Tenant Auth Config Service Update Request - type: object - x-speakeasy-name-override: TenantAuthConfigServiceUpdateRequest - c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse: - description: The TenantAuthConfigServiceUpdateResponse message. - properties: - authConfig: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' - title: Tenant Auth Config Service Update Response + title: Search Past Grants Request type: object - x-speakeasy-name-override: TenantAuthConfigServiceUpdateResponse - c1.api.automations.v1.AccessConflictTrigger: - description: | - The AccessConflictTrigger message. - - This message contains a oneof named conflict_monitor_selector. Only a single field of the following list may be set at a time: - - conflictMonitorRefs - - allConflictMonitors - nullable: true + x-speakeasy-name-override: SearchPastGrantsRequest + c1.api.app.v1.SearchPastGrantsResponse: + description: The SearchPastGrantsResponse message contains a list of past grants and a nextPageToken if applicable. properties: - allConflictMonitors: + expanded: + description: The expanded field. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBindingHistoryView' + type: + - array + - "null" + nextPageToken: description: |- - The allConflictMonitors field. - This field is part of the `conflict_monitor_selector` oneof. - See the documentation for `c1.api.automations.v1.AccessConflictTrigger` for more details. - nullable: true - readOnly: false - type: boolean - conflictMonitorRefs: - $ref: '#/components/schemas/c1.api.automations.v1.ConflictMonitorRefs' - title: Access Conflict Trigger - type: object - x-speakeasy-name-override: AccessConflictTrigger - c1.api.automations.v1.AccountInContext: - description: The AccountInContext message. - nullable: true - title: Account In Context + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retrieved. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: Search Past Grants Response type: object - x-speakeasy-name-override: AccountInContext - c1.api.automations.v1.AccountLifecycleAction: - description: | - The AccountLifecycleAction message. - - This message contains a oneof named account_identifier. Only a single field of the following list may be set at a time: - - accountRef - - accountInContext - nullable: true + x-speakeasy-name-override: SearchPastGrantsResponse + c1.api.app.v1.SearchUserOwnershipRequest: + description: |- + Search for all ownership assignments for a given user. Returns apps, resources, and + entitlements the user owns, each tagged with a UserOwnershipType discriminator. + Filter by ownership_types to restrict results to specific kinds of ownership. properties: - accountInContext: - $ref: '#/components/schemas/c1.api.automations.v1.AccountInContext' - accountRef: - $ref: '#/components/schemas/c1.api.automations.v1.AccountRef' - actionName: - description: The actionName field. - readOnly: false + ownershipTypes: + description: Filter results to only include these ownership types. If empty, all types are returned. + items: + enum: + - USER_OWNERSHIP_TYPE_UNSPECIFIED + - USER_OWNERSHIP_TYPE_APP + - USER_OWNERSHIP_TYPE_RESOURCE + - USER_OWNERSHIP_TYPE_ENTITLEMENT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response. type: string - connectorRef: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' - title: Account Lifecycle Action + userId: + description: The ID of the ConductorOne user whose ownership to search. + type: string + title: Search User Ownership Request type: object - x-speakeasy-name-override: AccountLifecycleAction - c1.api.automations.v1.AccountRef: - description: The AccountRef message. - nullable: true + x-speakeasy-name-override: SearchUserOwnershipRequest + c1.api.app.v1.SearchUserOwnershipResponse: + description: The SearchUserOwnershipResponse message contains a paginated list of ownership entries. properties: - accountIdCel: - description: The accountIdCel field. - readOnly: false + list: + description: The list of ownership entries for the requested user. + items: + $ref: '#/components/schemas/c1.api.app.v1.UserOwnershipEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page of results. Empty when there are no more results. type: string - title: Account Ref + title: Search User Ownership Response type: object - x-speakeasy-name-override: AccountRef - c1.api.automations.v1.AppUserCreatedTrigger: - description: | - The AppUserCreatedTrigger message. - - This message contains a oneof named app_identifier. Only a single field of the following list may be set at a time: - - appId - - appIdCel - nullable: true + x-speakeasy-name-override: SearchUserOwnershipResponse + c1.api.app.v1.SecretAgingFilter: + description: |- + SecretAgingFilter restricts a resource search to secrets (credential_type != 0) + whose secret-trait timestamps fall in the given half-open ranges. Each bound is + optional; leave one unset for an open-ended range. All set bounds are ANDed. + Callers pass absolute timestamps (computed against their reference "now"). + properties: + lastUsedAfter: + format: date-time + type: + - string + - "null" + lastUsedBefore: + format: date-time + type: + - string + - "null" + secretCreatedAfter: + format: date-time + type: + - string + - "null" + secretCreatedBefore: + format: date-time + type: + - string + - "null" + secretExpiresAfter: + format: date-time + type: + - string + - "null" + secretExpiresBefore: + format: date-time + type: + - string + - "null" + title: Secret Aging Filter + type: object + x-speakeasy-name-override: SecretAgingFilter + c1.api.app.v1.SecretTrait: + description: The SecretTrait message. properties: - appId: + createdByAppUserId: description: |- - The appId field. - This field is part of the `app_identifier` oneof. - See the documentation for `c1.api.automations.v1.AppUserCreatedTrigger` for more details. - nullable: true - readOnly: false + The AppUser id that created this credential. Read-only; resolved from + the model during uplift. Distinct from identity_app_user_id (the + holder) and from the resource's Owner (a separate assignment, not + part of this message). type: string - appIdCel: + credentialDetail: description: |- - The appIdCel field. - This field is part of the `app_identifier` oneof. - See the documentation for `c1.api.automations.v1.AppUserCreatedTrigger` for more details. - nullable: true - readOnly: false + Platform-specific credential subtype detail, finer than credential_type + (e.g. "GCP service-account key"). Read-only; translated from the model. type: string - condition: - description: The condition field. - readOnly: false + identityAppUserId: + description: The identityAppUserId field. type: string - title: App User Created Trigger + lastUsedAt: + format: date-time + type: + - string + - "null" + secretCreatedAt: + format: date-time + type: + - string + - "null" + secretExpiresAt: + format: date-time + type: + - string + - "null" + title: Secret Trait type: object - x-speakeasy-name-override: AppUserCreatedTrigger - c1.api.automations.v1.AppUserUpdatedTrigger: - description: | - The AppUserUpdatedTrigger message. - - This message contains a oneof named app_identifier. Only a single field of the following list may be set at a time: - - appId - - appIdCel - nullable: true + x-speakeasy-name-override: SecretTrait + c1.api.app.v1.SetAppEntitlementOwnersRequestInput: + description: The request message for setting the app entitlement owners. properties: - appId: + userIds: + description: The user_ids field for the users to set as an owner of the app entitlement. + items: + type: string + type: + - array + - "null" + title: Set App Entitlement Owners Request + type: object + x-speakeasy-entity: App_Entitlement_Owner + x-speakeasy-name-override: SetAppEntitlementOwnersRequest + c1.api.app.v1.SetAppEntitlementOwnersResponse: + description: The empty response message for setting the app entitlement owners. + title: Set App Entitlement Owners Response + type: object + x-speakeasy-name-override: SetAppEntitlementOwnersResponse + c1.api.app.v1.SetAppOwnersRequestInput: + description: The request message for setting the app owners. + properties: + userIds: + description: The user_ids field for the users to set as an owner of the app. + items: + type: string + type: + - array + - "null" + title: Set App Owners Request + type: object + x-speakeasy-entity: App_Owner + x-speakeasy-name-override: SetAppOwnersRequest + c1.api.app.v1.SetAppOwnersResponse: + description: The empty response message for setting the app owners. + title: Set App Owners Response + type: object + x-speakeasy-name-override: SetAppOwnersResponse + c1.api.app.v1.SetAppResourceOwnersRequestInput: + description: The SetAppResourceOwnersRequest message. + properties: + userIds: + description: The userIds field. + items: + type: string + type: + - array + - "null" + title: Set App Resource Owners Request + type: object + x-speakeasy-entity: App_Resource_Owner + x-speakeasy-name-override: SetAppResourceOwnersRequest + c1.api.app.v1.SetAppResourceOwnersResponse: + description: The empty response message for setting the app resource owners. + title: Set App Resource Owners Response + type: object + x-speakeasy-name-override: SetAppResourceOwnersResponse + c1.api.app.v1.SyncConfig: + description: The SyncConfig message. + properties: + syncResourceTypeIds: + description: The syncResourceTypeIds field. + items: + type: string + type: + - array + - "null" + title: Sync Config + type: object + x-speakeasy-name-override: SyncConfig + c1.api.app.v1.TaskAuditCancelledResult: + description: The TaskAuditCancelledResult message. + properties: + cancelReason: description: |- - The appId field. - This field is part of the `app_identifier` oneof. - See the documentation for `c1.api.automations.v1.AppUserUpdatedTrigger` for more details. - nullable: true - readOnly: false + Human-readable reason the action was cancelled. Already populated on the + model-side CanceledResult (e.g., "action is invalid - ticket is closed"); + this surfaces it to the UI. type: string - appIdCel: - description: |- - The appIdCel field. - This field is part of the `app_identifier` oneof. - See the documentation for `c1.api.automations.v1.AppUserUpdatedTrigger` for more details. - nullable: true - readOnly: false + title: Task Audit Cancelled Result + type: object + x-speakeasy-name-override: TaskAuditCancelledResult + c1.api.app.v1.TaskAuditErrorResult: + description: The TaskAuditErrorResult message. + properties: + errorCount: + description: 'TODO(pquerna): expand' + format: int64 type: string - condition: - description: The condition field. - readOnly: false + errorReason: + description: The errorReason field. type: string - title: App User Updated Trigger + title: Task Audit Error Result type: object - x-speakeasy-name-override: AppUserUpdatedTrigger - c1.api.automations.v1.Automation: - description: | - The Automation message. - - This message contains a oneof named disabled_reason. Only a single field of the following list may be set at a time: - - circuitBreaker + x-speakeasy-name-override: TaskAuditErrorResult + c1.api.app.v1.TaskAuditPendingResult: + description: The TaskAuditPendingResult message. properties: - appId: - description: the app id this workflow_template belongs to - readOnly: false + pendingReason: + description: |- + Human-readable explanation of why the action is pending. Rendered in the + ticket audit log so admins can see what the action is waiting on (e.g., + "GitHub org invite sent. User must accept the invitation before team + membership can be granted."). Naming mirrors TaskAuditErrorResult.error_reason + and TaskAuditCancelledResult.cancel_reason for consistency. type: string - automationSteps: - description: The automationSteps field. + title: Task Audit Pending Result + type: object + x-speakeasy-name-override: TaskAuditPendingResult + c1.api.app.v1.TaskAuditSuccessResult: + description: The TaskAuditSuccessResult message. + properties: + annotations: + description: The annotations field. items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' - nullable: true - readOnly: false - type: array - circuitBreaker: - $ref: '#/components/schemas/c1.api.automations.v1.DisabledReasonCircuitBreaker' - circuitBreakerMax: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + effects: + description: The effects field. + items: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorActionEffect' + type: + - array + - "null" + successReason: description: |- - Circuit breaker rate cap: disable this automation if it executes more - than circuit_breaker_max times in the trailing circuit_breaker_period. - 0 = circuit breaker off (default). - format: uint32 - readOnly: false - type: integer - circuitBreakerPeriod: - description: The circuitBreakerPeriod field. - enum: - - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED - - CIRCUIT_BREAKER_PERIOD_HOUR - - CIRCUIT_BREAKER_PERIOD_DAY - - CIRCUIT_BREAKER_PERIOD_WEEK - - CIRCUIT_BREAKER_PERIOD_MONTH - readOnly: false - type: string - x-speakeasy-unknown-values: allow - context: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' - createdAt: - format: date-time - readOnly: false + Optional human-readable note about the successful action. Rendered in + the ticket audit log when present (e.g., "Account already existed; no + change made." for the AlreadyExistsResult path). Naming mirrors + TaskAuditErrorResult.error_reason and TaskAuditCancelledResult.cancel_reason + for consistency. type: string - currentVersion: - description: The currentVersion field. - format: int64 - readOnly: false + title: Task Audit Success Result + type: object + x-speakeasy-name-override: TaskAuditSuccessResult + c1.api.app.v1.UpdateAppEntitlementRequestInput: + description: The UpdateAppEntitlementRequest message contains the app entitlement and the fields to be updated. + properties: + entitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" + overrideAccessRequestsDefaults: + description: Flag to indicate that access request defaults, if any are applied to these entitlements, should be overridden. + type: boolean + updateMask: + type: + - string + - "null" + title: Update App Entitlement Request + type: object + x-speakeasy-name-override: UpdateAppEntitlementRequest + c1.api.app.v1.UpdateAppEntitlementResponse: + description: The UpdateAppEntitlementResponse message. + properties: + appEntitlementView: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" + expanded: + description: List of related objects + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Update App Entitlement Response + type: object + x-speakeasy-name-override: UpdateAppEntitlementResponse + c1.api.app.v1.UpdateAppEntitlementRoutingRuleRequestInput: + description: The UpdateAppEntitlementRoutingRuleRequest message. + properties: + condition: + description: |- + CEL expression evaluated against the entitlement routing rule context. + Empty string is valid and matches every target not matched earlier. type: string description: description: The description field. - readOnly: false type: string displayName: description: The displayName field. - readOnly: false type: string - draftAutomationSteps: - description: The draftAutomationSteps field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' - nullable: true - readOnly: false - type: array - draftTriggers: - description: The draftTriggers field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' - nullable: true - readOnly: false - type: array enabled: description: The enabled field. - readOnly: false - type: boolean - id: - description: The id field. - readOnly: true - type: string - isDraft: - description: The isDraft field. - readOnly: false type: boolean - lastExecutedAt: - format: date-time - readOnly: false - type: string - primaryTriggerType: - description: The primaryTriggerType field. - enum: - - TRIGGER_TYPE_UNSPECIFIED - - TRIGGER_TYPE_USER_PROFILE_CHANGE - - TRIGGER_TYPE_APP_USER_CREATE - - TRIGGER_TYPE_APP_USER_UPDATE - - TRIGGER_TYPE_UNUSED_ACCESS - - TRIGGER_TYPE_USER_CREATED - - TRIGGER_TYPE_GRANT_FOUND - - TRIGGER_TYPE_GRANT_DELETED - - TRIGGER_TYPE_WEBHOOK - - TRIGGER_TYPE_SCHEDULE - - TRIGGER_TYPE_FORM - - TRIGGER_TYPE_SCHEDULE_APP_USER - - TRIGGER_TYPE_ACCESS_CONFLICT - - TRIGGER_TYPE_SCHEDULE_NO_USER - readOnly: false - type: string - x-speakeasy-unknown-values: allow - triggers: - description: The triggers field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' - nullable: true - readOnly: false - type: array - title: Automation + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRuleSettings' + - type: "null" + title: Update App Entitlement Routing Rule Request type: object - x-speakeasy-entity: Automation - x-speakeasy-name-override: Automation - c1.api.automations.v1.AutomationContext: - description: The AutomationContext message. + x-speakeasy-name-override: UpdateAppEntitlementRoutingRuleRequest + c1.api.app.v1.UpdateAppEntitlementRoutingRuleResponse: + description: The UpdateAppEntitlementRoutingRuleResponse message. properties: - context: - additionalProperties: true - readOnly: false - type: object - title: Automation Context + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRoutingRule' + - type: "null" + title: Update App Entitlement Routing Rule Response type: object - x-speakeasy-name-override: AutomationContext - c1.api.automations.v1.AutomationExecution: - description: The AutomationExecution message. + x-speakeasy-name-override: UpdateAppEntitlementRoutingRuleResponse + c1.api.app.v1.UpdateAppRequestInput: + description: The UpdateAppRequest message contains the app to update and the fields to update. properties: - automationTemplateId: - description: The automationTemplateId field. - readOnly: false - type: string - completedAt: - format: date-time - readOnly: false - type: string - context: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' - createdAt: - format: date-time - readOnly: false - type: string - currentVersion: - description: The currentVersion field. - format: int32 - readOnly: false - type: integer - deletedAt: - format: date-time - readOnly: false - type: string - duration: - format: duration - readOnly: false - type: string - id: - description: The id field. - format: int64 - readOnly: false - type: string - isDraft: - description: The isDraft field. - readOnly: false - type: boolean - state: - description: The state field. - enum: - - AUTOMATION_EXECUTION_STATE_UNSPECIFIED - - AUTOMATION_EXECUTION_STATE_PENDING - - AUTOMATION_EXECUTION_STATE_CREATING - - AUTOMATION_EXECUTION_STATE_GET_STEP - - AUTOMATION_EXECUTION_STATE_PROCESS_STEP - - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP - - AUTOMATION_EXECUTION_STATE_DONE - - AUTOMATION_EXECUTION_STATE_ERROR - - AUTOMATION_EXECUTION_STATE_TERMINATE - - AUTOMATION_EXECUTION_STATE_WAITING - readOnly: false - type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: false - type: string - title: Automation Execution + app: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.App' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update App Request type: object - x-speakeasy-name-override: AutomationExecution - c1.api.automations.v1.AutomationExecutionExpandMask: - description: The AutomationExecutionExpandMask message. + x-speakeasy-name-override: UpdateAppRequest + c1.api.app.v1.UpdateAppResponse: + description: Returns the updated app's new values. properties: - paths: - description: The paths field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Automation Execution Expand Mask + app: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.App' + - type: "null" + title: Update App Response type: object - x-speakeasy-name-override: AutomationExecutionExpandMask - c1.api.automations.v1.AutomationExecutionRef: - description: The AutomationExecutionRef message. + x-speakeasy-name-override: UpdateAppResponse + c1.api.app.v1.UpdateAppUsageControlsRequestInput: + description: The UpdateAppUsageControlsRequest message contains the AppUsageControls object to update and the update mask. properties: - id: - description: The id field. - format: int64 - readOnly: false - type: string - title: Automation Execution Ref + appUsageControls: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update App Usage Controls Request type: object - x-speakeasy-name-override: AutomationExecutionRef - c1.api.automations.v1.AutomationExecutionView: - description: The AutomationExecutionView message. + x-speakeasy-name-override: UpdateAppUsageControlsRequest + c1.api.app.v1.UpdateAppUsageControlsResponse: + description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. properties: - automationExecution: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' - automationExecutionTriggerPath: - description: The automationExecutionTriggerPath field. - readOnly: false - type: string - automationPath: - description: The automationPath field. - readOnly: false - type: string - title: Automation Execution View + appUsageControls: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppUsageControls' + - type: "null" + title: Update App Usage Controls Response type: object - x-speakeasy-name-override: AutomationExecutionView - c1.api.automations.v1.AutomationStep: + x-speakeasy-name-override: UpdateAppUsageControlsResponse + c1.api.app.v1.UpdateConnectorScheduleRequestInput: description: | - The AutomationStep message. + The UpdateConnectorScheduleRequest message contains the fields required to update a connector's sync schedule. - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - createAccessReview - - waitForDuration - - unenrollFromAllAccessProfiles - - createRevokeTasks - - createRevokeTasksV2 - - sendEmail - - removeFromDelegation - - runAutomation - - updateUser - - taskAction - - webhook - - connectorAction - - connectorCreateAccount - - grantEntitlements - - sendSlackMessage - - callFunction - - accountLifecycleAction - - generatePassword - - evaluateExpressions - - setCredential - - storeCredential + This message contains a oneof named schedule. Only a single field of the following list may be set at a time: + - cron properties: - accountLifecycleAction: - $ref: '#/components/schemas/c1.api.automations.v1.AccountLifecycleAction' - callFunction: - $ref: '#/components/schemas/c1.api.automations.v1.CallFunction' - connectorAction: - $ref: '#/components/schemas/c1.api.automations.v1.ConnectorAction' - connectorCreateAccount: - $ref: '#/components/schemas/c1.api.automations.v1.ConnectorCreateAccount' - createAccessReview: - $ref: '#/components/schemas/c1.api.automations.v1.CreateAccessReview' - createRevokeTasks: - $ref: '#/components/schemas/c1.api.automations.v1.CreateRevokeTasks' - createRevokeTasksV2: - $ref: '#/components/schemas/c1.api.automations.v1.CreateRevokeTasksV2' - evaluateExpressions: - $ref: '#/components/schemas/c1.api.automations.v1.EvaluateExpressions' - generatePassword: - $ref: '#/components/schemas/c1.api.automations.v1.GeneratePassword' - grantEntitlements: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlements' - removeFromDelegation: - $ref: '#/components/schemas/c1.api.automations.v1.RemoveFromDelegation' - runAutomation: - $ref: '#/components/schemas/c1.api.automations.v1.RunAutomation' - sendEmail: - $ref: '#/components/schemas/c1.api.automations.v1.SendEmail' - sendSlackMessage: - $ref: '#/components/schemas/c1.api.automations.v1.SendSlackMessage' - setCredential: - $ref: '#/components/schemas/c1.api.automations.v1.SetCredential' - skipIfTrueCel: - description: The skipIfTrueCel field. - readOnly: false + cron: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorScheduleCron' + - type: "null" + title: Update Connector Schedule Request + type: object + x-speakeasy-name-override: UpdateConnectorScheduleRequest + c1.api.app.v1.UpdateConnectorScheduleResponse: + description: Empty response body. Status code indicates success. + title: Update Connector Schedule Response + type: object + x-speakeasy-name-override: UpdateConnectorScheduleResponse + c1.api.app.v1.UpdateGrantDurationRequestInput: + description: The request message for updating the duration of an existing grant. + properties: + newDeprovisionAt: + format: date-time + type: + - string + - "null" + title: Update Grant Duration Request + type: object + x-speakeasy-name-override: UpdateGrantDurationRequest + c1.api.app.v1.UpdateGrantDurationResponse: + description: The response message for updating the duration of a grant. + properties: + binding: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' + - type: "null" + title: Update Grant Duration Response + type: object + x-speakeasy-name-override: UpdateGrantDurationResponse + c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput: + description: The request message for updating a manually managed resource type. + properties: + appResourceType: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Manually Managed Resource Type Request + type: object + x-speakeasy-name-override: UpdateManuallyManagedResourceTypeRequest + c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse: + description: The response message for updating a manually managed resource type. + properties: + appResourceType: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceType' + - type: "null" + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Update Manually Managed Resource Type Response + type: object + x-speakeasy-name-override: UpdateManuallyManagedResourceTypeResponse + c1.api.app.v1.UserOwnershipEntry: + description: |- + A single ownership entry. Fields are populated based on ownership_type: + APP — only app_id and app_display_name are set. + RESOURCE — app_id, app_display_name, resource_type_id, resource_id, and resource_display_name are set. + ENTITLEMENT — app_id, app_display_name, resource_type_id, entitlement_id, and entitlement_display_name are set. + properties: + appDisplayName: + description: The app display name. type: string - stepDisplayName: - description: The stepDisplayName field. - readOnly: false + appId: + description: The app ID. type: string - stepName: - description: The stepName field. - readOnly: false + entitlementDisplayName: + description: The entitlement display name, if applicable. type: string - storeCredential: - $ref: '#/components/schemas/c1.api.automations.v1.StoreCredential' - taskAction: - $ref: '#/components/schemas/c1.api.automations.v1.TaskAction' - unenrollFromAllAccessProfiles: - $ref: '#/components/schemas/c1.api.automations.v1.UnenrollFromAllAccessProfiles' - updateUser: - $ref: '#/components/schemas/c1.api.automations.v1.UpdateUser' - waitForDuration: - $ref: '#/components/schemas/c1.api.automations.v1.WaitForDuration' - webhook: - $ref: '#/components/schemas/c1.api.automations.v1.Webhook' - title: Automation Step + entitlementId: + description: The entitlement ID, if applicable. + type: string + ownershipType: + description: The type of ownership. + enum: + - USER_OWNERSHIP_TYPE_UNSPECIFIED + - USER_OWNERSHIP_TYPE_APP + - USER_OWNERSHIP_TYPE_RESOURCE + - USER_OWNERSHIP_TYPE_ENTITLEMENT + type: string + x-speakeasy-unknown-values: allow + resourceDisplayName: + description: The resource display name, if applicable. + type: string + resourceId: + description: The resource ID, if applicable. + type: string + resourceTypeId: + description: The resource type ID, if applicable. + type: string + title: User Ownership Entry type: object - x-speakeasy-name-override: AutomationStep - c1.api.automations.v1.AutomationTemplateRef: - description: The AutomationTemplateRef message. - nullable: true + x-speakeasy-name-override: UserOwnershipEntry + c1.api.app.v1.UserWithAppEntitlementUserBindingView: + description: The UserWithAppEntitlementUserBindingView message. properties: - id: - description: The id field. - readOnly: false + appEntitlementId: + description: The ID of the app entitlement. type: string - title: Automation Template Ref + appId: + description: The ID of the app that contains the entitlement. + type: string + appUserId: + description: The ID of the app user associated with this binding. + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: User With App Entitlement User Binding View type: object - x-speakeasy-name-override: AutomationTemplateRef - c1.api.automations.v1.AutomationTemplateVersion: - description: The AutomationTemplateVersion message. + x-speakeasy-name-override: UserWithAppEntitlementUserBindingView + c1.api.app.v2.AppEntitlementOwnerEntitlement: + description: AppEntitlementOwnerEntitlement represents an entitlement ownership source for an app entitlement. properties: - automationSteps: - description: The automationSteps field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' - nullable: true - readOnly: false - type: array - automationTemplateId: - description: The automationTemplateId field. - readOnly: false + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appId: + description: The appId field. type: string createdAt: format: date-time - readOnly: false + type: + - string + - "null" + entitlementId: + description: The entitlementId field. type: string - deletedAt: - format: date-time - readOnly: false + roleSlug: + description: The roleSlug field. type: string - triggers: - description: The triggers field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' - nullable: true - readOnly: false - type: array - updatedAt: + title: App Entitlement Owner Entitlement + type: object + x-speakeasy-entity: App_Entitlement_Owner_Entitlement + x-speakeasy-name-override: AppEntitlementOwnerEntitlement + c1.api.app.v2.AppEntitlementOwnerUser: + description: AppEntitlementOwnerUser represents a user ownership source for an app entitlement. + properties: + appId: + description: The appId field. + type: string + createdAt: format: date-time - readOnly: false + type: + - string + - "null" + entitlementId: + description: The entitlementId field. type: string - version: - description: The version field. - format: int64 - readOnly: false + roleSlug: + description: The roleSlug field. type: string - title: Automation Template Version - type: object - x-speakeasy-name-override: AutomationTemplateVersion - c1.api.automations.v1.AutomationTrigger: - description: | - Automation Triggers - - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - userProfileChange - - appUserCreated - - appUserUpdated - - usageBasedRevocation - - userCreated - - grantFound - - grantDeleted - - webhook - - schedule - - scheduleAppUser - - accessConflict - - scheduleNoUser - properties: - accessConflict: - $ref: '#/components/schemas/c1.api.automations.v1.AccessConflictTrigger' - appUserCreated: - $ref: '#/components/schemas/c1.api.automations.v1.AppUserCreatedTrigger' - appUserUpdated: - $ref: '#/components/schemas/c1.api.automations.v1.AppUserUpdatedTrigger' - grantDeleted: - $ref: '#/components/schemas/c1.api.automations.v1.GrantDeletedTrigger' - grantFound: - $ref: '#/components/schemas/c1.api.automations.v1.GrantFoundTrigger' - schedule: - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTrigger' - scheduleAppUser: - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTriggerAppUser' - scheduleNoUser: - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTriggerNoUser' - usageBasedRevocation: - $ref: '#/components/schemas/c1.api.automations.v1.UsageBasedRevocationTrigger' - userCreated: - $ref: '#/components/schemas/c1.api.automations.v1.UserCreatedTrigger' - userProfileChange: - $ref: '#/components/schemas/c1.api.automations.v1.UserProfileChangeTrigger' - webhook: - $ref: '#/components/schemas/c1.api.automations.v1.WebhookAutomationTrigger' - title: Automation Trigger + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: App Entitlement Owner User type: object - x-speakeasy-name-override: AutomationTrigger - c1.api.automations.v1.CallFunction: - description: The CallFunction message. - nullable: true + x-speakeasy-entity: App_Entitlement_Owner_User + x-speakeasy-name-override: AppEntitlementOwnerUser + c1.api.app.v2.AppOwnerEntitlement: + description: AppOwnerEntitlement represents an entitlement ownership source for an app. properties: - args: - additionalProperties: - type: string - description: The args field. - readOnly: false - type: object - functionId: - description: The functionId field. - readOnly: false + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appId: + description: The appId field. type: string - title: Call Function - type: object - x-speakeasy-name-override: CallFunction - c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput: - description: The ClearAutomationCircuitBreakerRequest message. - title: Clear Automation Circuit Breaker Request - type: object - x-speakeasy-name-override: ClearAutomationCircuitBreakerRequest - c1.api.automations.v1.ClearAutomationCircuitBreakerResponse: - description: The ClearAutomationCircuitBreakerResponse message. - title: Clear Automation Circuit Breaker Response - type: object - x-speakeasy-name-override: ClearAutomationCircuitBreakerResponse - c1.api.automations.v1.CloseAction: - description: | - The CloseAction message. - - This message contains a oneof named user_identifier. Only a single field of the following list may be set at a time: - - userIdCel - - userRef - nullable: true - properties: - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdCel: - description: |- - The userIdCel field. - This field is part of the `user_identifier` oneof. - See the documentation for `c1.api.automations.v1.CloseAction` for more details. - nullable: true - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. type: string - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Close Action + title: App Owner Entitlement type: object - x-speakeasy-name-override: CloseAction - c1.api.automations.v1.ConflictMonitorRefs: - description: The ConflictMonitorRefs message. - nullable: true + x-speakeasy-entity: App_Owner_Entitlement + x-speakeasy-name-override: AppOwnerEntitlement + c1.api.app.v2.AppOwnerUser: + description: AppOwnerUser represents a user ownership source for an app. properties: - conflictMonitorRefs: - description: The conflictMonitorRefs field. - items: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorRef' - nullable: true - readOnly: false - type: array - title: Conflict Monitor Refs + appId: + description: The appId field. + type: string + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: App Owner User type: object - x-speakeasy-name-override: ConflictMonitorRefs - c1.api.automations.v1.ConnectorAction: - description: | - The ConnectorAction message. - - This message contains a oneof named connector_identifier. Only a single field of the following list may be set at a time: - - connectorRef - nullable: true + x-speakeasy-entity: App_Owner_User + x-speakeasy-name-override: AppOwnerUser + c1.api.app.v2.AppResourceOwnerEntitlement: + description: AppResourceOwnerEntitlement represents an entitlement ownership source for an app resource. properties: - actionName: - description: The actionName field. - readOnly: false + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appId: + description: The appId field. + type: string + createdAt: + format: date-time + type: + - string + - "null" + resourceId: + description: The resourceId field. type: string - argsTemplate: - additionalProperties: true - readOnly: false - type: object - connectorRef: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' resourceTypeId: description: The resourceTypeId field. - readOnly: false type: string - title: Connector Action + roleSlug: + description: The roleSlug field. + type: string + title: App Resource Owner Entitlement type: object - x-speakeasy-name-override: ConnectorAction - c1.api.automations.v1.ConnectorCreateAccount: - description: | - The ConnectorCreateAccount message. - - This message contains a oneof named create_account_arguments. Only a single field of the following list may be set at a time: - - userIdCel - - userProperties - nullable: true + x-speakeasy-entity: App_Resource_Owner_Entitlement + x-speakeasy-name-override: AppResourceOwnerEntitlement + c1.api.app.v2.AppResourceOwnerUser: + description: AppResourceOwnerUser represents a user ownership source for an app resource. properties: - connectorRef: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' - passwordCel: - description: |- - CEL expression referencing a GeneratePassword step output (e.g. "genStep.password"). - When set, the resolved password is encrypted for the connector and sent as CredentialOptions.EncryptedPassword. - readOnly: false + appId: + description: The appId field. type: string - userIdCel: - description: |- - The userIdCel field. - This field is part of the `create_account_arguments` oneof. - See the documentation for `c1.api.automations.v1.ConnectorCreateAccount` for more details. - nullable: true - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + resourceId: + description: The resourceId field. type: string - userProperties: - $ref: '#/components/schemas/c1.api.automations.v1.UserProperties' - title: Connector Create Account + resourceTypeId: + description: The resourceTypeId field. + type: string + roleSlug: + description: The roleSlug field. + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: App Resource Owner User type: object - x-speakeasy-name-override: ConnectorCreateAccount - c1.api.automations.v1.CreateAccessReview: - description: The CreateAccessReview message. - nullable: true + x-speakeasy-entity: App_Resource_Owner_User + x-speakeasy-name-override: AppResourceOwnerUser + c1.api.app.v2.AppUserOwnerEntitlement: + description: AppUserOwnerEntitlement represents an entitlement ownership source for an app user. properties: - accessReviewTemplateCel: - description: The accessReviewTemplateCel field. - readOnly: false - type: string - accessReviewTemplateId: - description: The accessReviewTemplateId field. - readOnly: false + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appId: + description: The appId field. type: string - campaignName: - description: Optional campaign name. If not provided, the campaign name will be the access review template name. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. type: string - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdsCel: - description: The userIdsCel field. - readOnly: false + userId: + description: The userId field. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Create Access Review + title: App User Owner Entitlement type: object - x-speakeasy-name-override: CreateAccessReview - c1.api.automations.v1.CreateAutomationRequest: - description: The CreateAutomationRequest message. + x-speakeasy-name-override: AppUserOwnerEntitlement + c1.api.app.v2.AppUserOwnerUser: + description: AppUserOwnerUser represents a user ownership source for an app user. properties: appId: - description: the app id this workflow_template belongs to - readOnly: false - type: string - automationSteps: - description: Ordered list of steps that the automation executes. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' - nullable: true - readOnly: false - type: array - circuitBreakerMax: - description: Circuit breaker rate cap. See Automation.circuit_breaker_max for semantics. - format: uint32 - readOnly: false - type: integer - circuitBreakerPeriod: - description: The circuitBreakerPeriod field. - enum: - - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED - - CIRCUIT_BREAKER_PERIOD_HOUR - - CIRCUIT_BREAKER_PERIOD_DAY - - CIRCUIT_BREAKER_PERIOD_WEEK - - CIRCUIT_BREAKER_PERIOD_MONTH - readOnly: false + description: The appId field. type: string - x-speakeasy-unknown-values: allow - context: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' - description: - description: Optional description explaining the automation's purpose. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. type: string - displayName: - description: Human-readable name for the automation. - readOnly: false + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + userId: + description: The userId field. type: string - draftAutomationSteps: - description: Steps saved as a draft that have not yet been published. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' - nullable: true - readOnly: false - type: array - draftTriggers: - description: Triggers saved as a draft that have not yet been published. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' - nullable: true - readOnly: false - type: array - enabled: - description: Whether the automation is active and eligible for execution. - readOnly: false - type: boolean - isDraft: - description: Whether this automation is in draft mode. Draft automations are not eligible for trigger-based execution. - readOnly: false - type: boolean - triggers: - description: Triggers that determine when the automation runs. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' - nullable: true - readOnly: false - type: array - title: Create Automation Request + title: App User Owner User type: object - x-speakeasy-name-override: AutomationsCreateAutomationRequest - c1.api.automations.v1.CreateAutomationResponse: - description: The CreateAutomationResponse message. + x-speakeasy-name-override: AppUserOwnerUser + c1.api.app.v2.ConnectorOwnerEntitlement: + description: ConnectorOwnerEntitlement represents an entitlement ownership source for a connector. properties: - automation: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' - webhookCapabilityUrl: - description: |- - One-time absolute webhook URL for capability URL authentication, shown once at creation time. - Contains the full URL including the embedded token (e.g. https://tenant.conductorone.com/api/v1/webhooks/incoming/{id}/t/{token}). - Populated only when the webhook trigger uses capability URL authentication. - readOnly: false + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + appId: + description: The appId field. type: string - webhookHmacSecret: - description: |- - One-time HMAC shared secret, shown once at creation time. - Populated only when the webhook trigger uses HMAC authentication. - readOnly: false + connectorId: + description: The connectorId field. type: string - title: Create Automation Response + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + title: Connector Owner Entitlement type: object - x-speakeasy-name-override: AutomationsCreateAutomationResponse - c1.api.automations.v1.CreateRevokeTasks: - description: The CreateRevokeTasks message. - nullable: true + x-speakeasy-entity: Connector_Owner_Entitlement + x-speakeasy-name-override: ConnectorOwnerEntitlement + c1.api.app.v2.ConnectorOwnerUser: + description: ConnectorOwnerUser represents a user ownership source for a connector. properties: - appEntitlementRefs: - description: The appEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - appEntitlementRefsCel: - description: The appEntitlementRefsCel field. - readOnly: false + appId: + description: The appId field. type: string - excludedAppEntitlementRefs: - description: The excludedAppEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - excludedAppEntitlementRefsCel: - description: The excludedAppEntitlementRefsCel field. - readOnly: false + connectorId: + description: The connectorId field. type: string - revokeAll: - description: The revokeAll field. - readOnly: false - type: boolean - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdCel: - description: The userIdCel field. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Connector Owner User + type: object + x-speakeasy-entity: Connector_Owner_User + x-speakeasy-name-override: ConnectorOwnerUser + c1.api.app.v2.CreateAppEntitlementEntitlementOwnerRequestInput: + description: CreateAppEntitlementEntitlementOwnerRequest is the request for creating an entitlement ownership source on an entitlement. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create App Entitlement Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateAppEntitlementEntitlementOwnerRequest + c1.api.app.v2.CreateAppEntitlementEntitlementOwnerResponse: + description: CreateAppEntitlementEntitlementOwnerResponse is the response for creating an entitlement ownership source on an entitlement. + properties: + appEntitlementOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerEntitlement' + - type: "null" + title: Create App Entitlement Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateAppEntitlementEntitlementOwnerResponse + c1.api.app.v2.CreateAppEntitlementOwnerRequestInput: + description: CreateEntitlementOwnerRequest is the request for creating an entitlement ownership source. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create App Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateAppEntitlementOwnerRequest + c1.api.app.v2.CreateAppEntitlementOwnerResponse: + description: CreateEntitlementOwnerResponse is the response for creating an entitlement ownership source. + properties: + appOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' + - type: "null" + title: Create App Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateAppEntitlementOwnerResponse + c1.api.app.v2.CreateAppEntitlementUserOwnerRequestInput: + description: CreateAppEntitlementUserOwnerRequest is the request for creating a user ownership source on an entitlement. + properties: userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Create Revoke Tasks + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create App Entitlement User Owner Request type: object - x-speakeasy-name-override: CreateRevokeTasks - c1.api.automations.v1.CreateRevokeTasksV2: - description: | - The CreateRevokeTasksV2 message. - - This message contains a oneof named user. Only a single field of the following list may be set at a time: - - userIdCel - - userRef - - useSubjectUser - - - This message contains a oneof named inclusion. Only a single field of the following list may be set at a time: - - inclusionList - - inclusionAll - - inclusionCriteria - - inclusionListCel - - - This message contains a oneof named exclusion. Only a single field of the following list may be set at a time: - - exclusionNone - - exclusionList - - exclusionCriteria - - exclusionListCel - nullable: true + x-speakeasy-name-override: CreateAppEntitlementUserOwnerRequest + c1.api.app.v2.CreateAppEntitlementUserOwnerResponse: + description: CreateAppEntitlementUserOwnerResponse is the response for creating a user ownership source on an entitlement. + properties: + appEntitlementOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerUser' + - type: "null" + title: Create App Entitlement User Owner Response + type: object + x-speakeasy-name-override: CreateAppEntitlementUserOwnerResponse + c1.api.app.v2.CreateAppResourceEntitlementOwnerRequestInput: + description: CreateAppResourceEntitlementOwnerRequest is the request for creating an entitlement ownership source on a resource. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create App Resource Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateAppResourceEntitlementOwnerRequest + c1.api.app.v2.CreateAppResourceEntitlementOwnerResponse: + description: CreateAppResourceEntitlementOwnerResponse is the response for creating an entitlement ownership source on a resource. + properties: + appResourceOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerEntitlement' + - type: "null" + title: Create App Resource Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateAppResourceEntitlementOwnerResponse + c1.api.app.v2.CreateAppResourceUserOwnerRequestInput: + description: CreateAppResourceUserOwnerRequest is the request for creating a user ownership source on a resource. properties: - exclusionCriteria: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionCriteria' - exclusionList: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionList' - exclusionListCel: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionListCel' - exclusionNone: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionNone' - inclusionAll: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAll' - inclusionCriteria: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionCriteria' - inclusionList: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionList' - inclusionListCel: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionListCel' - useSubjectUser: - description: |- - The useSubjectUser field. - This field is part of the `user` oneof. - See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. - nullable: true - readOnly: false - type: boolean - userIdCel: - description: |- - The userIdCel field. - This field is part of the `user` oneof. - See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. - nullable: true - readOnly: false - type: string userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Create Revoke Tasks V 2 + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create App Resource User Owner Request type: object - x-speakeasy-name-override: CreateRevokeTasksV2 - c1.api.automations.v1.DeleteAutomationRequestInput: - description: The DeleteAutomationRequest message. - title: Delete Automation Request + x-speakeasy-name-override: CreateAppResourceUserOwnerRequest + c1.api.app.v2.CreateAppResourceUserOwnerResponse: + description: CreateAppResourceUserOwnerResponse is the response for creating a user ownership source on a resource. + properties: + appResourceOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerUser' + - type: "null" + title: Create App Resource User Owner Response type: object - x-speakeasy-name-override: AutomationsDeleteAutomationRequest - c1.api.automations.v1.DeleteAutomationResponse: - description: The DeleteAutomationResponse message. - title: Delete Automation Response + x-speakeasy-name-override: CreateAppResourceUserOwnerResponse + c1.api.app.v2.CreateAppUserEntitlementOwnerRequestInput: + description: CreateAppUserEntitlementOwnerRequest is the request for creating an entitlement ownership source on an app user. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create App User Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateAppUserEntitlementOwnerRequest + c1.api.app.v2.CreateAppUserEntitlementOwnerResponse: + description: CreateAppUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on an app user. + properties: + appUserOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppUserOwnerEntitlement' + - type: "null" + title: Create App User Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateAppUserEntitlementOwnerResponse + c1.api.app.v2.CreateAppUserOwnerRequestInput: + description: CreateUserOwnerRequest is the request for creating a user ownership source. + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create App User Owner Request type: object - x-speakeasy-name-override: AutomationsDeleteAutomationResponse - c1.api.automations.v1.DisabledReasonCircuitBreaker: - description: |- - DisabledReasonCircuitBreaker carries the trip context when an automation - has been auto-disabled by its rate cap. Returned on the parent Automation - when read; not directly settable. - nullable: true + x-speakeasy-name-override: CreateAppUserOwnerRequest + c1.api.app.v2.CreateAppUserOwnerResponse: + description: CreateUserOwnerResponse is the response for creating a user ownership source. properties: - observedCount: - description: Observed execution count in the period at trip time. - format: uint32 - readOnly: false - type: integer - period: - description: Snapshot of the period at trip time. - enum: - - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED - - CIRCUIT_BREAKER_PERIOD_HOUR - - CIRCUIT_BREAKER_PERIOD_DAY - - CIRCUIT_BREAKER_PERIOD_WEEK - - CIRCUIT_BREAKER_PERIOD_MONTH - readOnly: false - type: string - x-speakeasy-unknown-values: allow - threshold: - description: Snapshot of the threshold at trip time. - format: uint32 - readOnly: false - type: integer - trippedAt: - format: date-time - readOnly: false - type: string - title: Disabled Reason Circuit Breaker + appOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' + - type: "null" + title: Create App User Owner Response type: object - x-speakeasy-name-override: DisabledReasonCircuitBreaker - c1.api.automations.v1.EntitlementExclusionCriteria: - description: The EntitlementExclusionCriteria message. - nullable: true + x-speakeasy-name-override: CreateAppUserOwnerResponse + c1.api.app.v2.CreateAppUserUserOwnerRequestInput: + description: CreateAppUserUserOwnerRequest is the request for creating a user ownership source on an app user. properties: - excludedAppIds: - description: The excludedAppIds field. - items: - type: string - nullable: true - readOnly: false - type: array - excludedComplianceFrameworkIds: - description: The excludedComplianceFrameworkIds field. - items: - type: string - nullable: true - readOnly: false - type: array - excludedResourceTypeIds: - description: The excludedResourceTypeIds field. - items: - type: string - nullable: true - readOnly: false - type: array - excludedRiskLevelIds: - description: The excludedRiskLevelIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Entitlement Exclusion Criteria + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create App User User Owner Request type: object - x-speakeasy-name-override: EntitlementExclusionCriteria - c1.api.automations.v1.EntitlementExclusionList: - description: The EntitlementExclusionList message. - nullable: true + x-speakeasy-name-override: CreateAppUserUserOwnerRequest + c1.api.app.v2.CreateAppUserUserOwnerResponse: + description: CreateAppUserUserOwnerResponse is the response for creating a user ownership source on an app user. properties: - excludedAppEntitlementRefs: - description: The excludedAppEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Entitlement Exclusion List + appUserOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppUserOwnerUser' + - type: "null" + title: Create App User User Owner Response type: object - x-speakeasy-name-override: EntitlementExclusionList - c1.api.automations.v1.EntitlementExclusionListCel: - description: The EntitlementExclusionListCel message. - nullable: true + x-speakeasy-name-override: CreateAppUserUserOwnerResponse + c1.api.app.v2.CreateConnectorEntitlementOwnerRequestInput: + description: CreateConnectorEntitlementOwnerRequest is the request for creating an entitlement ownership source on a connector. properties: - excludedAppEntitlementRefsCel: - description: The excludedAppEntitlementRefsCel field. - readOnly: false - type: string - title: Entitlement Exclusion List Cel + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create Connector Entitlement Owner Request type: object - x-speakeasy-name-override: EntitlementExclusionListCel - c1.api.automations.v1.EntitlementExclusionNone: - description: The EntitlementExclusionNone message. - nullable: true - title: Entitlement Exclusion None + x-speakeasy-name-override: CreateConnectorEntitlementOwnerRequest + c1.api.app.v2.CreateConnectorEntitlementOwnerResponse: + description: CreateConnectorEntitlementOwnerResponse is the response for creating an entitlement ownership source on a connector. + properties: + connectorOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerEntitlement' + - type: "null" + title: Create Connector Entitlement Owner Response type: object - x-speakeasy-name-override: EntitlementExclusionNone - c1.api.automations.v1.EntitlementInclusionAll: - description: The EntitlementInclusionAll message. - nullable: true - title: Entitlement Inclusion All + x-speakeasy-name-override: CreateConnectorEntitlementOwnerResponse + c1.api.app.v2.CreateConnectorUserOwnerRequestInput: + description: CreateConnectorUserOwnerRequest is the request for creating a user ownership source on a connector. + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create Connector User Owner Request type: object - x-speakeasy-name-override: EntitlementInclusionAll - c1.api.automations.v1.EntitlementInclusionCriteria: - description: The EntitlementInclusionCriteria message. - nullable: true + x-speakeasy-name-override: CreateConnectorUserOwnerRequest + c1.api.app.v2.CreateConnectorUserOwnerResponse: + description: CreateConnectorUserOwnerResponse is the response for creating a user ownership source on a connector. properties: - appIds: - description: The appIds field. - items: - type: string - nullable: true - readOnly: false - type: array - complianceFrameworkIds: - description: The complianceFrameworkIds field. - items: - type: string - nullable: true - readOnly: false - type: array - resourceTypeIds: - description: The resourceTypeIds field. - items: - type: string - nullable: true - readOnly: false - type: array - riskLevelIds: - description: The riskLevelIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Entitlement Inclusion Criteria + connectorOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerUser' + - type: "null" + title: Create Connector User Owner Response type: object - x-speakeasy-name-override: EntitlementInclusionCriteria - c1.api.automations.v1.EntitlementInclusionList: - description: The EntitlementInclusionList message. - nullable: true + x-speakeasy-name-override: CreateConnectorUserOwnerResponse + c1.api.app.v2.DeleteAppEntitlementEntitlementOwnerRequestInput: + description: DeleteAppEntitlementEntitlementOwnerRequest is the request for deleting an entitlement ownership source on an entitlement. properties: - appEntitlementRefs: - description: The appEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Entitlement Inclusion List + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete App Entitlement Entitlement Owner Request + type: object + x-speakeasy-name-override: DeleteAppEntitlementEntitlementOwnerRequest + c1.api.app.v2.DeleteAppEntitlementEntitlementOwnerResponse: + description: DeleteAppEntitlementEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on an entitlement. + title: Delete App Entitlement Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteAppEntitlementEntitlementOwnerResponse + c1.api.app.v2.DeleteAppEntitlementOwnerRequestInput: + description: DeleteEntitlementOwnerRequest is the request for deleting an entitlement ownership source. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete App Entitlement Owner Request type: object - x-speakeasy-name-override: EntitlementInclusionList - c1.api.automations.v1.EntitlementInclusionListCel: - description: The EntitlementInclusionListCel message. - nullable: true + x-speakeasy-name-override: DeleteAppEntitlementOwnerRequest + c1.api.app.v2.DeleteAppEntitlementOwnerResponse: + description: DeleteEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source. + title: Delete App Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteAppEntitlementOwnerResponse + c1.api.app.v2.DeleteAppEntitlementUserOwnerRequestInput: + description: DeleteAppEntitlementUserOwnerRequest is the request for deleting a user ownership source on an entitlement. properties: - appEntitlementRefsCel: - description: The appEntitlementRefsCel field. - readOnly: false - type: string - title: Entitlement Inclusion List Cel + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete App Entitlement User Owner Request type: object - x-speakeasy-name-override: EntitlementInclusionListCel - c1.api.automations.v1.EvaluateExpressions: - description: The EvaluateExpressions message. - nullable: true + x-speakeasy-name-override: DeleteAppEntitlementUserOwnerRequest + c1.api.app.v2.DeleteAppEntitlementUserOwnerResponse: + description: DeleteAppEntitlementUserOwnerResponse is the empty response for deleting a user ownership source on an entitlement. + title: Delete App Entitlement User Owner Response + type: object + x-speakeasy-name-override: DeleteAppEntitlementUserOwnerResponse + c1.api.app.v2.DeleteAppResourceEntitlementOwnerRequestInput: + description: DeleteAppResourceEntitlementOwnerRequest is the request for deleting an entitlement ownership source on a resource. properties: - expressions: - description: The expressions field. - items: - $ref: '#/components/schemas/c1.api.automations.v1.Expression' - nullable: true - readOnly: false - type: array - title: Evaluate Expressions + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete App Resource Entitlement Owner Request type: object - x-speakeasy-name-override: EvaluateExpressions - c1.api.automations.v1.ExecuteAutomationRequestInput: - description: The ExecuteAutomationRequest message. + x-speakeasy-name-override: DeleteAppResourceEntitlementOwnerRequest + c1.api.app.v2.DeleteAppResourceEntitlementOwnerResponse: + description: DeleteAppResourceEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a resource. + title: Delete App Resource Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteAppResourceEntitlementOwnerResponse + c1.api.app.v2.DeleteAppResourceUserOwnerRequestInput: + description: DeleteAppResourceUserOwnerRequest is the request for deleting a user ownership source on a resource. properties: - context: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' - title: Execute Automation Request + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete App Resource User Owner Request type: object - x-speakeasy-name-override: ExecuteAutomationRequest - c1.api.automations.v1.ExecuteAutomationResponse: - description: The ExecuteAutomationResponse message. + x-speakeasy-name-override: DeleteAppResourceUserOwnerRequest + c1.api.app.v2.DeleteAppResourceUserOwnerResponse: + description: DeleteAppResourceUserOwnerResponse is the empty response for deleting a user ownership source on a resource. + title: Delete App Resource User Owner Response + type: object + x-speakeasy-name-override: DeleteAppResourceUserOwnerResponse + c1.api.app.v2.DeleteAppUserEntitlementOwnerRequestInput: + description: DeleteAppUserEntitlementOwnerRequest is the request for deleting an entitlement ownership source on an app user. properties: - executionId: - description: The unique identifier of the newly created execution. - format: int64 - readOnly: false + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete App User Entitlement Owner Request + type: object + x-speakeasy-name-override: DeleteAppUserEntitlementOwnerRequest + c1.api.app.v2.DeleteAppUserEntitlementOwnerResponse: + description: DeleteAppUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on an app user. + title: Delete App User Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteAppUserEntitlementOwnerResponse + c1.api.app.v2.DeleteAppUserOwnerRequestInput: + description: DeleteUserOwnerRequest is the request for deleting a user ownership source. + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete App User Owner Request + type: object + x-speakeasy-name-override: DeleteAppUserOwnerRequest + c1.api.app.v2.DeleteAppUserOwnerResponse: + description: DeleteUserOwnerResponse is the empty response for deleting a user ownership source. + title: Delete App User Owner Response + type: object + x-speakeasy-name-override: DeleteAppUserOwnerResponse + c1.api.app.v2.DeleteAppUserUserOwnerRequestInput: + description: DeleteAppUserUserOwnerRequest is the request for deleting a user ownership source on an app user. + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete App User User Owner Request + type: object + x-speakeasy-name-override: DeleteAppUserUserOwnerRequest + c1.api.app.v2.DeleteAppUserUserOwnerResponse: + description: DeleteAppUserUserOwnerResponse is the empty response for deleting a user ownership source on an app user. + title: Delete App User User Owner Response + type: object + x-speakeasy-name-override: DeleteAppUserUserOwnerResponse + c1.api.app.v2.DeleteConnectorEntitlementOwnerRequestInput: + description: DeleteConnectorEntitlementOwnerRequest is the request for deleting an entitlement ownership source on a connector. + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete Connector Entitlement Owner Request + type: object + x-speakeasy-name-override: DeleteConnectorEntitlementOwnerRequest + c1.api.app.v2.DeleteConnectorEntitlementOwnerResponse: + description: DeleteConnectorEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a connector. + title: Delete Connector Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteConnectorEntitlementOwnerResponse + c1.api.app.v2.DeleteConnectorUserOwnerRequestInput: + description: DeleteConnectorUserOwnerRequest is the request for deleting a user ownership source on a connector. + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete Connector User Owner Request + type: object + x-speakeasy-name-override: DeleteConnectorUserOwnerRequest + c1.api.app.v2.DeleteConnectorUserOwnerResponse: + description: DeleteConnectorUserOwnerResponse is the empty response for deleting a user ownership source on a connector. + title: Delete Connector User Owner Response + type: object + x-speakeasy-name-override: DeleteConnectorUserOwnerResponse + c1.api.app.v2.GetAppEntitlementEntitlementOwnerResponse: + description: GetAppEntitlementEntitlementOwnerResponse is the response for getting an entitlement ownership source on an entitlement. + properties: + appEntitlementOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerEntitlement' + - type: "null" + title: Get App Entitlement Entitlement Owner Response + type: object + x-speakeasy-name-override: GetAppEntitlementEntitlementOwnerResponse + c1.api.app.v2.GetAppEntitlementOwnerResponse: + description: GetEntitlementOwnerResponse is the response for getting an entitlement ownership source. + properties: + appOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' + - type: "null" + title: Get App Entitlement Owner Response + type: object + x-speakeasy-name-override: GetAppEntitlementOwnerResponse + c1.api.app.v2.GetAppEntitlementUserOwnerResponse: + description: GetAppEntitlementUserOwnerResponse is the response for getting a user ownership source on an entitlement. + properties: + appEntitlementOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerUser' + - type: "null" + title: Get App Entitlement User Owner Response + type: object + x-speakeasy-name-override: GetAppEntitlementUserOwnerResponse + c1.api.app.v2.GetAppResourceEntitlementOwnerResponse: + description: GetAppResourceEntitlementOwnerResponse is the response for getting an entitlement ownership source on a resource. + properties: + appResourceOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerEntitlement' + - type: "null" + title: Get App Resource Entitlement Owner Response + type: object + x-speakeasy-name-override: GetAppResourceEntitlementOwnerResponse + c1.api.app.v2.GetAppResourceUserOwnerResponse: + description: GetAppResourceUserOwnerResponse is the response for getting a user ownership source on a resource. + properties: + appResourceOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerUser' + - type: "null" + title: Get App Resource User Owner Response + type: object + x-speakeasy-name-override: GetAppResourceUserOwnerResponse + c1.api.app.v2.GetAppUserOwnerResponse: + description: GetUserOwnerResponse is the response for getting a user ownership source. + properties: + appOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' + - type: "null" + title: Get App User Owner Response + type: object + x-speakeasy-name-override: GetAppUserOwnerResponse + c1.api.app.v2.GetConnectorEntitlementOwnerResponse: + description: GetConnectorEntitlementOwnerResponse is the response for getting an entitlement ownership source on a connector. + properties: + connectorOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerEntitlement' + - type: "null" + title: Get Connector Entitlement Owner Response + type: object + x-speakeasy-name-override: GetConnectorEntitlementOwnerResponse + c1.api.app.v2.GetConnectorUserOwnerResponse: + description: GetConnectorUserOwnerResponse is the response for getting a user ownership source on a connector. + properties: + connectorOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerUser' + - type: "null" + title: Get Connector User Owner Response + type: object + x-speakeasy-name-override: GetConnectorUserOwnerResponse + c1.api.app.v2.SearchAppEntitlementEntitlementOwnersResponse: + description: SearchAppEntitlementEntitlementOwnersResponse is the response for searching entitlement ownership sources on an entitlement. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Execute Automation Response + title: Search App Entitlement Entitlement Owners Response type: object - x-speakeasy-name-override: ExecuteAutomationResponse - c1.api.automations.v1.Expression: - description: The Expression message. + x-speakeasy-name-override: SearchAppEntitlementEntitlementOwnersResponse + c1.api.app.v2.SearchAppEntitlementOwnersResponse: + description: SearchEntitlementOwnersResponse is the response for searching entitlement ownership sources. properties: - expressionCel: - description: The expressionCel field. - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - isSecret: - description: The isSecret field. - readOnly: false - type: boolean - key: - description: The key field. - readOnly: false + title: Search App Entitlement Owners Response + type: object + x-speakeasy-name-override: SearchAppEntitlementOwnersResponse + c1.api.app.v2.SearchAppEntitlementUserOwnersResponse: + description: SearchAppEntitlementUserOwnersResponse is the response for searching user ownership sources on an entitlement. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppEntitlementOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Expression + title: Search App Entitlement User Owners Response type: object - x-speakeasy-name-override: Expression - c1.api.automations.v1.GeneratePassword: - description: The GeneratePassword message. - nullable: true + x-speakeasy-name-override: SearchAppEntitlementUserOwnersResponse + c1.api.app.v2.SearchAppResourceEntitlementOwnersResponse: + description: SearchAppResourceEntitlementOwnersResponse is the response for searching entitlement ownership sources on a resource. properties: - passwordPolicyId: - deprecated: true - description: 'Deprecated: password policy ID lookup is no longer used.' - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - policy: - $ref: '#/components/schemas/c1.api.automations.v1.GeneratePasswordPolicy' - title: Generate Password + title: Search App Resource Entitlement Owners Response type: object - x-speakeasy-name-override: GeneratePassword - c1.api.automations.v1.GeneratePasswordPolicy: - description: | - GeneratePasswordPolicy defines inline password generation rules. - - This message contains a oneof named character_rules. Only a single field of the following list may be set at a time: - - noRestrictions - - customCharacters - - excludedCharacters + x-speakeasy-name-override: SearchAppResourceEntitlementOwnersResponse + c1.api.app.v2.SearchAppResourceUserOwnersResponse: + description: SearchAppResourceUserOwnersResponse is the response for searching user ownership sources on a resource. properties: - customCharacters: - description: |- - The customCharacters field. - This field is part of the `character_rules` oneof. - See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. - nullable: true - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppResourceOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - excludedCharacters: - description: |- - The excludedCharacters field. - This field is part of the `character_rules` oneof. - See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. - nullable: true - readOnly: false + title: Search App Resource User Owners Response + type: object + x-speakeasy-name-override: SearchAppResourceUserOwnersResponse + c1.api.app.v2.SearchAppUserEntitlementOwnersResponse: + description: SearchAppUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on an app user. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppUserOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - maxCharacterCount: - description: The maxCharacterCount field. - format: int32 - readOnly: false - type: integer - minCharacterCount: - description: The minCharacterCount field. - format: int32 - readOnly: false - type: integer - noRestrictions: - description: |- - The noRestrictions field. - This field is part of the `character_rules` oneof. - See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. - nullable: true - readOnly: false - type: boolean - requireLowercase: - description: The requireLowercase field. - readOnly: false - type: boolean - requireNumbers: - description: The requireNumbers field. - readOnly: false - type: boolean - requireSpecialCharacters: - description: The requireSpecialCharacters field. - readOnly: false - type: boolean - requireUppercase: - description: The requireUppercase field. - readOnly: false - type: boolean - title: Generate Password Policy + title: Search App User Entitlement Owners Response type: object - x-speakeasy-name-override: GeneratePasswordPolicy - c1.api.automations.v1.GetAutomationExecutionResponse: - description: The GetAutomationExecutionResponse message. + x-speakeasy-name-override: SearchAppUserEntitlementOwnersResponse + c1.api.app.v2.SearchAppUserOwnersResponse: + description: SearchUserOwnersResponse is the response for searching user ownership sources. properties: - automationExecution: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' - expanded: - description: Related objects requested via the expand mask. + list: + description: The list field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - view: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' - title: Get Automation Execution Response + $ref: '#/components/schemas/c1.api.app.v2.AppOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search App User Owners Response type: object - x-speakeasy-name-override: GetAutomationExecutionResponse - c1.api.automations.v1.GetAutomationResponse: - description: The GetAutomationResponse message. + x-speakeasy-name-override: SearchAppUserOwnersResponse + c1.api.app.v2.SearchAppUserUserOwnersResponse: + description: SearchAppUserUserOwnersResponse is the response for searching user ownership sources on an app user. properties: - automation: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' - title: Get Automation Response + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.AppUserOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search App User User Owners Response type: object - x-speakeasy-name-override: GetAutomationResponse - c1.api.automations.v1.GrantDeletedTrigger: - description: The GrantDeletedTrigger message. - nullable: true + x-speakeasy-name-override: SearchAppUserUserOwnersResponse + c1.api.app.v2.SearchConnectorEntitlementOwnersResponse: + description: SearchConnectorEntitlementOwnersResponse is the response for searching entitlement ownership sources on a connector. properties: - grantTriggerFilter: - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter' - title: Grant Deleted Trigger + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search Connector Entitlement Owners Response type: object - x-speakeasy-name-override: GrantDeletedTrigger - c1.api.automations.v1.GrantEntitlementExclusionCriteria: - description: The GrantEntitlementExclusionCriteria message. - nullable: true + x-speakeasy-name-override: SearchConnectorEntitlementOwnersResponse + c1.api.app.v2.SearchConnectorUserOwnersResponse: + description: SearchConnectorUserOwnersResponse is the response for searching user ownership sources on a connector. properties: - excludedAppIds: - description: The excludedAppIds field. + list: + description: The list field. items: - type: string - nullable: true - readOnly: false - type: array - excludedComplianceFrameworkIds: - description: The excludedComplianceFrameworkIds field. + $ref: '#/components/schemas/c1.api.app.v2.ConnectorOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search Connector User Owners Response + type: object + x-speakeasy-name-override: SearchConnectorUserOwnersResponse + c1.api.app.v2.SetAppEntitlementOwnersRequestInput: + description: SetAppEntitlementOwnersRequest is the request for setting the owners of an app entitlement for a given role. + properties: + appEntitlementRefs: + description: The appEntitlementRefs field. items: - type: string - nullable: true - readOnly: false - type: array - excludedRiskLevelIds: - description: The excludedRiskLevelIds field. + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + roleSlug: + description: The roleSlug field. + type: string + userRefs: + description: The userRefs field. items: - type: string - nullable: true - readOnly: false - type: array - title: Grant Entitlement Exclusion Criteria + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set App Entitlement Owners Request type: object - x-speakeasy-name-override: GrantEntitlementExclusionCriteria - c1.api.automations.v1.GrantEntitlementExclusionList: - description: The GrantEntitlementExclusionList message. - nullable: true + x-speakeasy-name-override: SetAppEntitlementOwnersRequestV2 + c1.api.app.v2.SetAppEntitlementOwnersResponse: + description: SetAppEntitlementOwnersResponse is the empty response for setting app entitlement owners. + title: Set App Entitlement Owners Response + type: object + x-speakeasy-name-override: SetAppEntitlementOwnersResponseV2 + c1.api.app.v2.SetAppOwnersRequestInput: + description: SetAppOwnersRequest is the request for setting user owners for an app and role. properties: - excludedAppEntitlementRefs: - description: The excludedAppEntitlementRefs field. + appEntitlementRefs: + description: The appEntitlementRefs field. items: $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Grant Entitlement Exclusion List + type: + - array + - "null" + roleSlug: + description: The roleSlug field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set App Owners Request type: object - x-speakeasy-name-override: GrantEntitlementExclusionList - c1.api.automations.v1.GrantEntitlementExclusionListCel: - description: The GrantEntitlementExclusionListCel message. - nullable: true + x-speakeasy-name-override: SetAppOwnersRequestV2 + c1.api.app.v2.SetAppOwnersResponse: + description: SetAppOwnersResponse is the empty response for setting app owners. + title: Set App Owners Response + type: object + x-speakeasy-name-override: SetAppOwnersResponseV2 + c1.api.app.v2.SetAppResourceOwnersV2RequestInput: + description: SetAppResourceOwnersV2Request is the request for setting the owners of an app resource for a given role. properties: - excludedAppEntitlementRefsCel: - description: The excludedAppEntitlementRefsCel field. - readOnly: false + appEntitlementRefs: + description: The appEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + roleSlug: + description: The roleSlug field. type: string - title: Grant Entitlement Exclusion List Cel + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set App Resource Owners V 2 Request type: object - x-speakeasy-name-override: GrantEntitlementExclusionListCel - c1.api.automations.v1.GrantEntitlementExclusionNone: - description: The GrantEntitlementExclusionNone message. - nullable: true - title: Grant Entitlement Exclusion None + x-speakeasy-name-override: SetAppResourceOwnersV2Request + c1.api.app.v2.SetAppResourceOwnersV2Response: + description: SetAppResourceOwnersV2Response is the empty response for setting app resource owners. + title: Set App Resource Owners V 2 Response type: object - x-speakeasy-name-override: GrantEntitlementExclusionNone - c1.api.automations.v1.GrantEntitlementInclusionCriteria: - description: The GrantEntitlementInclusionCriteria message. - nullable: true + x-speakeasy-name-override: SetAppResourceOwnersV2Response + c1.api.app.v2.SetAppUserOwnersV2RequestInput: + description: SetAppUserOwnersV2Request is the request for setting the owners of an app user for a given role. properties: - appIds: - description: The appIds field. - items: - type: string - nullable: true - readOnly: false - type: array - complianceFrameworkIds: - description: The complianceFrameworkIds field. + appEntitlementRefs: + description: The appEntitlementRefs field. items: - type: string - nullable: true - readOnly: false - type: array - riskLevelIds: - description: The riskLevelIds field. + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + roleSlug: + description: The roleSlug field. + type: string + userRefs: + description: The userRefs field. items: - type: string - nullable: true - readOnly: false - type: array - title: Grant Entitlement Inclusion Criteria + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set App User Owners V 2 Request type: object - x-speakeasy-name-override: GrantEntitlementInclusionCriteria - c1.api.automations.v1.GrantEntitlementInclusionList: - description: The GrantEntitlementInclusionList message. - nullable: true + x-speakeasy-name-override: SetAppUserOwnersV2Request + c1.api.app.v2.SetAppUserOwnersV2Response: + description: SetAppUserOwnersV2Response is the empty response for setting app user owners. + title: Set App User Owners V 2 Response + type: object + x-speakeasy-name-override: SetAppUserOwnersV2Response + c1.api.app.v2.SetConnectorOwnersV2RequestInput: + description: SetConnectorOwnersV2Request is the request for setting the owners of a connector for a given role. properties: appEntitlementRefs: description: The appEntitlementRefs field. items: $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Grant Entitlement Inclusion List + type: + - array + - "null" + roleSlug: + description: The role slug for this ownership grant. Required. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set Connector Owners V 2 Request type: object - x-speakeasy-name-override: GrantEntitlementInclusionList - c1.api.automations.v1.GrantEntitlementInclusionListCel: - description: The GrantEntitlementInclusionListCel message. - nullable: true + x-speakeasy-name-override: SetConnectorOwnersV2Request + c1.api.app.v2.SetConnectorOwnersV2Response: + description: SetConnectorOwnersV2Response is the empty response for setting connector owners. + title: Set Connector Owners V 2 Response + type: object + x-speakeasy-name-override: SetConnectorOwnersV2Response + c1.api.attribute.v1.AttributeType: + description: AttributeType defines the type of an attribute. properties: - appEntitlementRefsCel: - description: The appEntitlementRefsCel field. - readOnly: false + id: + description: The ID of the AttributeType. type: string - title: Grant Entitlement Inclusion List Cel + name: + description: The name of the AttributeType. + type: string + title: Attribute Type type: object - x-speakeasy-name-override: GrantEntitlementInclusionListCel - c1.api.automations.v1.GrantEntitlements: - description: | - The GrantEntitlements message. - - This message contains a oneof named inclusion. Only a single field of the following list may be set at a time: - - inclusionList - - inclusionCriteria - - inclusionListCel - - - This message contains a oneof named exclusion. Only a single field of the following list may be set at a time: - - exclusionNone - - exclusionList - - exclusionCriteria - - exclusionListCel - nullable: true + x-speakeasy-name-override: AttributeType + c1.api.attribute.v1.AttributeValue: + description: AttributeValue is the value of an attribute of a defined type. properties: - exclusionCriteria: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionCriteria' - exclusionList: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionList' - exclusionListCel: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionListCel' - exclusionNone: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionNone' - inclusionCriteria: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionCriteria' - inclusionList: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionList' - inclusionListCel: - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionListCel' - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdCel: - description: The userIdCel field. - readOnly: false + attributeTypeId: + description: The ID of the AttributeType that this AttributeValue belongs to. type: string - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Grant Entitlements + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The ID of the AttributeValue. + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + value: + description: The value of the AttributeValue. This is the string that will be displayed to the user. + type: string + title: Attribute Value type: object - x-speakeasy-name-override: GrantEntitlements - c1.api.automations.v1.GrantFoundTrigger: - description: The GrantFoundTrigger message. - nullable: true + x-speakeasy-name-override: AttributeValue + c1.api.attribute.v1.CreateAttributeValueRequest: + description: The CreateAttributeValueRequest message. properties: - grantTriggerFilter: - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter' - title: Grant Found Trigger + attributeTypeId: + description: The attributeTypeId field. + type: string + value: + description: The value field. + type: string + title: Create Attribute Value Request type: object - x-speakeasy-name-override: GrantFoundTrigger - c1.api.automations.v1.GrantTriggerFilter: - description: | - The GrantTriggerFilter message. - - This message contains a oneof named entitlement_inclusion. Only a single field of the following list may be set at a time: - - inclusionList - - inclusionAll - - inclusionCriteria - - inclusionListCel + x-speakeasy-name-override: CreateAttributeValueRequest + c1.api.attribute.v1.CreateAttributeValueResponse: + description: CreateAttributeValueResponse is the response for creating an attribute value. properties: - accountFilter: - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter.AccountFilter' - grantFilter: - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter.GrantFilter' - inclusionAll: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAll' - inclusionCriteria: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionCriteria' - inclusionList: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionList' - inclusionListCel: - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionListCel' - title: Grant Trigger Filter + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Create Attribute Value Response type: object - x-speakeasy-name-override: GrantTriggerFilter - c1.api.automations.v1.GrantTriggerFilter.AccountFilter: - description: The AccountFilter message. + x-speakeasy-name-override: CreateAttributeValueResponse + c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest: + description: The CreateComplianceFrameworkAttributeValueRequest message. properties: - accountType: - description: The accountType field. - enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - readOnly: false + value: + description: The value field. type: string - x-speakeasy-unknown-values: allow - title: Account Filter + title: Create Compliance Framework Attribute Value Request type: object - x-speakeasy-name-override: AccountFilter - c1.api.automations.v1.GrantTriggerFilter.GrantFilter: - description: The GrantFilter message. + x-speakeasy-name-override: CreateComplianceFrameworkAttributeValueRequest + c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse: + description: The CreateComplianceFrameworkAttributeValueResponse message. properties: - grantFilterType: - description: The grantFilterType field. - enum: - - GRANT_FILTER_TYPE_UNSPECIFIED - - GRANT_FILTER_TYPE_PERMANENT - - GRANT_FILTER_TYPE_TEMPORARY - readOnly: false - type: string - x-speakeasy-unknown-values: allow - grantJustificationType: - description: The grantJustificationType field. - enum: - - GRANT_JUSTIFICATION_TYPE_UNSPECIFIED - - GRANT_JUSTIFICATION_TYPE_ALL - - GRANT_JUSTIFICATION_TYPE_CONDUCTOR_ONE - - GRANT_JUSTIFICATION_TYPE_DIRECT - readOnly: false - type: string - x-speakeasy-unknown-values: allow - grantSourceFilter: - description: The grantSourceFilter field. - enum: - - GRANT_SOURCE_FILTER_UNSPECIFIED - - GRANT_SOURCE_FILTER_DIRECT - - GRANT_SOURCE_FILTER_INHERITED - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: Grant Filter + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Create Compliance Framework Attribute Value Response type: object - x-speakeasy-name-override: GrantFilter - c1.api.automations.v1.ListAutomationExecutionsResponse: - description: The ListAutomationExecutionsResponse message. + x-speakeasy-name-override: CreateComplianceFrameworkAttributeValueResponse + c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest: + description: The CreateRiskLevelAttributeValueRequest message. properties: - automationExecutions: - description: The page of automation executions. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false + value: + description: The value field. type: string - title: List Automation Executions Response + title: Create Risk Level Attribute Value Request type: object - x-speakeasy-name-override: ListAutomationExecutionsResponse - c1.api.automations.v1.ListAutomationsResponse: - description: The ListAutomationsResponse message. + x-speakeasy-name-override: CreateRiskLevelAttributeValueRequest + c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse: + description: The CreateRiskLevelAttributeValueResponse message. properties: - list: - description: The page of automations. - items: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false - type: string - title: List Automations Response + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Create Risk Level Attribute Value Response type: object - x-speakeasy-name-override: ListAutomationsResponse - c1.api.automations.v1.ReassignAction: - description: | - The ReassignAction message. - - This message contains a oneof named assignee_user_identifier. Only a single field of the following list may be set at a time: - - assigneeUserIdCel - - assigneeUserRef - - - This message contains a oneof named subject_user_identifier. Only a single field of the following list may be set at a time: - - subjectUserIdCel - - subjectUserRef - nullable: true - properties: - assigneeUserIdCel: - description: |- - The assigneeUserIdCel field. - This field is part of the `assignee_user_identifier` oneof. - See the documentation for `c1.api.automations.v1.ReassignAction` for more details. - nullable: true - readOnly: false - type: string - assigneeUserRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - subjectUserIdCel: - description: |- - The subjectUserIdCel field. - This field is part of the `subject_user_identifier` oneof. - See the documentation for `c1.api.automations.v1.ReassignAction` for more details. - nullable: true - readOnly: false - type: string - subjectUserRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - title: Reassign Action + x-speakeasy-name-override: CreateRiskLevelAttributeValueResponse + c1.api.attribute.v1.DeleteAttributeValueRequestInput: + description: The DeleteAttributeValueRequest message. + title: Delete Attribute Value Request type: object - x-speakeasy-name-override: ReassignAction - c1.api.automations.v1.RemoveFromDelegation: - description: | - RemoveFromDelegation: find all users that have the target user as their delegated user, and modify the delegation. - - This message contains a oneof named replacement_user. Only a single field of the following list may be set at a time: - - replacementUserIdCel - - replacementUserRef - nullable: true + x-speakeasy-name-override: DeleteAttributeValueRequest + c1.api.attribute.v1.DeleteAttributeValueResponse: + description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. + title: Delete Attribute Value Response + type: object + x-speakeasy-name-override: DeleteAttributeValueResponse + c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput: + description: The DeleteComplianceFrameworkAttributeValueRequest message. + title: Delete Compliance Framework Attribute Value Request + type: object + x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValueRequest + c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse: + description: The DeleteComplianceFrameworkAttributeValueResponse message. + title: Delete Compliance Framework Attribute Value Response + type: object + x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValueResponse + c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput: + description: The DeleteRiskLevelAttributeValueRequest message. + title: Delete Risk Level Attribute Value Request + type: object + x-speakeasy-name-override: DeleteRiskLevelAttributeValueRequest + c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse: + description: The DeleteRiskLevelAttributeValueResponse message. + title: Delete Risk Level Attribute Value Response + type: object + x-speakeasy-name-override: DeleteRiskLevelAttributeValueResponse + c1.api.attribute.v1.GetAttributeValueResponse: + description: GetAttributeValueResponse is the response for getting an attribute value by id. properties: - replacementUserIdCel: - description: |- - The user who will replace the target user's delegation - This field is part of the `replacement_user` oneof. - See the documentation for `c1.api.automations.v1.RemoveFromDelegation` for more details. - nullable: true - readOnly: false - type: string - replacementUserRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdCel: - description: The userIdCel field. - readOnly: false - type: string - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Remove From Delegation + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Get Attribute Value Response type: object - x-speakeasy-name-override: RemoveFromDelegation - c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput: - description: The ResolvePausedAutomationExecutionsRequest message. + x-speakeasy-name-override: GetAttributeValueResponse + c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse: + description: The GetComplianceFrameworkAttributeValueResponse message. properties: - decision: - description: Whether to run or cancel the paused executions. - enum: - - PAUSED_EXECUTION_DECISION_UNSPECIFIED - - PAUSED_EXECUTION_DECISION_RUN - - PAUSED_EXECUTION_DECISION_CANCEL - readOnly: false - type: string - x-speakeasy-unknown-values: allow - reason: - description: |- - Optional human-readable reason for the resolution decision. Stored on - the audit row (paused_run / paused_cancelled events) for post-mortem - and compliance use. Surfaced in the FE as a required field on CANCEL - so admins capture why bulk-cancellation happened. Up to 1024 bytes. - readOnly: false - type: string - title: Resolve Paused Automation Executions Request + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Get Compliance Framework Attribute Value Response type: object - x-speakeasy-name-override: ResolvePausedAutomationExecutionsRequest - c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse: - description: The ResolvePausedAutomationExecutionsResponse message. + x-speakeasy-name-override: GetComplianceFrameworkAttributeValueResponse + c1.api.attribute.v1.GetRiskLevelAttributeValueResponse: + description: The GetRiskLevelAttributeValueResponse message. properties: - erroredCount: - description: |- - The number of paused executions that were attempted but failed to - resolve (e.g., a transient Dynamo error during the per-execution - mutate). Per-execution failures do not abort the run — the loop - continues, the failures are recorded on the audit row, and the - affected executions remain in PAUSED_BY_CIRCUIT_BREAKER state so a - subsequent call can retry them. Always 0 in the happy path. - format: uint32 - readOnly: false - type: integer - pausedCount: - description: |- - The number of paused executions successfully resolved by this call - (transitioned to PENDING for RUN, TERMINATE for CANCEL). Paused - executions are processed inline, paginated server-side. For very large - paused sets (10K+) this RPC may take seconds to minutes; callers should - treat the request as long-running. - format: uint32 - readOnly: false - type: integer - title: Resolve Paused Automation Executions Response + value: + oneOf: + - $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + - type: "null" + title: Get Risk Level Attribute Value Response type: object - x-speakeasy-name-override: ResolvePausedAutomationExecutionsResponse - c1.api.automations.v1.RunAutomation: - description: | - RunAutomation: kick off the execution of an automation template. - - This message contains a oneof named automation_template. Only a single field of the following list may be set at a time: - - automationTemplateRef - - automationTemplateIdCel - nullable: true + x-speakeasy-name-override: GetRiskLevelAttributeValueResponse + c1.api.attribute.v1.ListAttributeTypesResponse: + description: ListAttributeTypesResponse is the response for listing attribute types. properties: - automationTemplateIdCel: + list: + description: The list of AttributeTypes. + items: + $ref: '#/components/schemas/c1.api.attribute.v1.AttributeType' + type: + - array + - "null" + nextPageToken: description: |- - The automationTemplateIdCel field. - This field is part of the `automation_template` oneof. - See the documentation for `c1.api.automations.v1.RunAutomation` for more details. - nullable: true - readOnly: false + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - automationTemplateRef: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateRef' - context: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' - title: Run Automation - type: object - x-speakeasy-name-override: RunAutomation - c1.api.automations.v1.RunDelayed: - description: The RunDelayed message. - nullable: true - properties: - coldStartDelayDays: - description: The coldStartDelayDays field. - format: uint32 - readOnly: false - type: integer - required: - - coldStartDelayDays - title: Run Delayed - type: object - x-speakeasy-name-override: RunDelayed - c1.api.automations.v1.RunImmediately: - description: No fields needed; this just indicates the trigger should run immediately - nullable: true - title: Run Immediately + title: List Attribute Types Response type: object - x-speakeasy-name-override: RunImmediately - c1.api.automations.v1.ScheduleTrigger: - description: The ScheduleTrigger message. - nullable: true + x-speakeasy-name-override: ListAttributeTypesResponse + c1.api.attribute.v1.ListAttributeValuesResponse: + description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. properties: - advanced: - description: The advanced field. - readOnly: false - type: boolean - condition: - description: The condition field. - readOnly: false - type: string - cronSpec: - description: The cronSpec field. - readOnly: false - type: string - skipIfTrueCel: - deprecated: true - description: The skipIfTrueCel field. - readOnly: false - type: string - start: - format: date-time - readOnly: false - type: string - timezone: - description: The timezone field. - readOnly: false + list: + description: The list of AttributeValues. + items: + $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Schedule Trigger + title: List Attribute Values Response type: object - x-speakeasy-name-override: ScheduleTrigger - c1.api.automations.v1.ScheduleTriggerAppUser: - description: The ScheduleTriggerAppUser message. - nullable: true + x-speakeasy-name-override: ListAttributeValuesResponse + c1.api.attribute.v1.ListComplianceFrameworksResponse: + description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. properties: - appId: - description: The appId field. - readOnly: false - type: string - condition: - description: The condition field. - readOnly: false - type: string - cronSpec: - description: The cronSpec field. - readOnly: false - type: string - start: - format: date-time - readOnly: false - type: string - timezone: - description: The timezone field. - readOnly: false + list: + description: The list of compliance framework attribute values. + items: + $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + type: + - array + - "null" + nextPageToken: + description: The token to retrieve the next page of results, or empty if there are no more results. type: string - title: Schedule Trigger App User + title: List Compliance Frameworks Response type: object - x-speakeasy-name-override: ScheduleTriggerAppUser - c1.api.automations.v1.ScheduleTriggerNoUser: - description: |- - ScheduleTriggerNoUser fires on a cron schedule with no subject user (e.g. reports, syncs, orchestration). - Minimum cron interval is enforced at 1 hour in validation. - nullable: true + x-speakeasy-name-override: ListComplianceFrameworksResponse + c1.api.attribute.v1.ListRiskLevelsResponse: + description: ListRiskLevelsResponse is the response for listing risk level attribute values. properties: - advanced: - description: The advanced field. - readOnly: false - type: boolean - cronSpec: - description: The cronSpec field. - readOnly: false - type: string - start: - format: date-time - readOnly: false - type: string - timezone: - description: The timezone field. - readOnly: false + list: + description: The list of risk level attribute values. + items: + $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + type: + - array + - "null" + nextPageToken: + description: The token to retrieve the next page of results, or empty if there are no more results. type: string - title: Schedule Trigger No User + title: List Risk Levels Response type: object - x-speakeasy-name-override: ScheduleTriggerNoUser - c1.api.automations.v1.SearchAllAutomationExecutionsRequest: - description: The SearchAllAutomationExecutionsRequest message. + x-speakeasy-name-override: ListRiskLevelsResponse + c1.api.attribute.v1.SearchAttributeValuesRequest: + description: Search Attributes by a few properties. properties: - appIds: - description: Filter to executions associated with one or more apps. + attributeTypeIds: + description: The attribute type ids for what type of attributes to search for. items: type: string - nullable: true - readOnly: false - type: array - automationTemplateIds: - description: Filter to one or more specific automation templates. + type: + - array + - "null" + excludeIds: + description: Exclude attributes with these ids from the search results. items: type: string - nullable: true - readOnly: false - type: array - executionStates: - description: Filter by execution state (e.g. DONE, ERROR). + type: + - array + - "null" + ids: + description: Include attributes with these ids in the search results. items: - enum: - - AUTOMATION_EXECUTION_STATE_UNSPECIFIED - - AUTOMATION_EXECUTION_STATE_PENDING - - AUTOMATION_EXECUTION_STATE_CREATING - - AUTOMATION_EXECUTION_STATE_GET_STEP - - AUTOMATION_EXECUTION_STATE_PROCESS_STEP - - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP - - AUTOMATION_EXECUTION_STATE_DONE - - AUTOMATION_EXECUTION_STATE_ERROR - - AUTOMATION_EXECUTION_STATE_TERMINATE - - AUTOMATION_EXECUTION_STATE_WAITING type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionExpandMask' + type: + - array + - "null" pageSize: - description: Maximum number of results to return per page. + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 - readOnly: false type: integer pageToken: - description: Pagination token from a previous SearchAllAutomationExecutionsResponse. - readOnly: false + description: The pageToken field. type: string - subjectUserIds: - description: Filter to executions where one or more C1 users are subjects. - items: - type: string - nullable: true - readOnly: false - type: array - title: Search All Automation Executions Request + query: + description: Query the attributes with a fuzzy search on display name and description. + type: string + value: + description: Search for attributes with a case insensitive match on the attribute value which is the attribute name. + type: string + title: Search Attribute Values Request type: object - x-speakeasy-name-override: SearchAllAutomationExecutionsRequest - c1.api.automations.v1.SearchAllAutomationExecutionsResponse: - description: The SearchAllAutomationExecutionsResponse message. + x-speakeasy-name-override: SearchAttributeValuesRequest + c1.api.attribute.v1.SearchAttributeValuesResponse: + description: SearchAttributeValuesResponse is the response for searching AttributeValues. properties: - expanded: - description: Related objects requested via the expand mask. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: - description: The page of execution views matching the search criteria. + description: The list of returned AttributeValues. items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.attribute.v1.AttributeValue' + type: + - array + - "null" nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search All Automation Executions Response + title: Search Attribute Values Response type: object - x-speakeasy-name-override: SearchAllAutomationExecutionsResponse - c1.api.automations.v1.SearchAutomationExecutionsRequest: - description: The SearchAutomationExecutionsRequest message. + x-speakeasy-name-override: SearchAttributeValuesResponse + c1.api.auth.v1.IntrospectResponse: + description: IntrospectResponse contains information about the current user who is authenticated. properties: - automationTemplateId: - description: Filter results to executions of this automation template. - readOnly: false + deviceClientId: + description: |- + The OAuth client_id of the device client registered for this token. Present + only on tokens issued by the device registration grant; the client reads it + once and presents it on the subsequent token exchange. Empty for all other + tokens. type: string - executionId: - description: Filter results to a specific execution by its numeric identifier. - format: int64 - readOnly: false + features: + description: The list of feature flags enabled for the tenant the logged in user belongs to. + items: + type: string + type: + - array + - "null" + permissions: + description: The list of permissions that the current logged in user has. + items: + type: string + type: + - array + - "null" + principleId: + description: The principleID of the current logged in user. type: string - executionStepStates: - description: Filter results to executions in any of the specified states. + roles: + description: The list of roles that the current logged in user has. items: - enum: - - AUTOMATION_EXECUTION_STATE_UNSPECIFIED - - AUTOMATION_EXECUTION_STATE_PENDING - - AUTOMATION_EXECUTION_STATE_CREATING - - AUTOMATION_EXECUTION_STATE_GET_STEP - - AUTOMATION_EXECUTION_STATE_PROCESS_STEP - - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP - - AUTOMATION_EXECUTION_STATE_DONE - - AUTOMATION_EXECUTION_STATE_ERROR - - AUTOMATION_EXECUTION_STATE_TERMINATE - - AUTOMATION_EXECUTION_STATE_WAITING type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionExpandMask' - pageSize: - description: Maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous SearchAutomationExecutionsResponse. - readOnly: false + type: + - array + - "null" + tenantId: + description: The tenantID from the authenticated caller's passport. type: string - query: - description: Free-text search query to filter executions. - readOnly: false + userId: + description: The userID of the current logged in user. type: string - refs: - description: Restrict results to specific execution references. + title: Introspect Response + type: object + x-speakeasy-name-override: IntrospectResponse + c1.api.auth_config.v1.AuthConfigC1Local: + description: The AuthConfigC1Local message. + properties: + delegatedVerifiers: + description: The delegatedVerifiers field. items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionRef' - nullable: true - readOnly: false - type: array - title: Search Automation Executions Request + enum: + - DELEGATED_VERIFIER_TYPE_UNSPECIFIED + - DELEGATED_VERIFIER_TYPE_GOOGLE + - DELEGATED_VERIFIER_TYPE_MICROSOFT + - DELEGATED_VERIFIER_TYPE_GITHUB + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Auth Config C 1 Local type: object - x-speakeasy-name-override: SearchAutomationExecutionsRequest - c1.api.automations.v1.SearchAutomationExecutionsResponse: - description: The SearchAutomationExecutionsResponse message. + x-speakeasy-name-override: AuthConfigC1Local + c1.api.auth_config.v1.AuthConfigGoogle: + description: The AuthConfigGoogle message. properties: - expanded: - description: Related objects requested via the expand mask. + additionalHostedDomains: + description: Additional hosted domains accepted at login beyond hosted_domains. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The page of execution views matching the search criteria. + type: string + readOnly: true + type: + - array + - "null" + hostedDomains: + description: The hostedDomains field. items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false - type: string - title: Search Automation Executions Response + type: string + type: + - array + - "null" + title: Auth Config Google type: object - x-speakeasy-name-override: SearchAutomationExecutionsResponse - c1.api.automations.v1.SearchAutomationTemplateVersionsRequest: - description: The SearchAutomationTemplateVersionsRequest message. + x-speakeasy-name-override: AuthConfigGoogle + c1.api.auth_config.v1.AuthConfigJumpCloud: + description: The AuthConfigJumpCloud message. properties: - automationTemplateId: - description: The automation template whose version history to search. - readOnly: false + oidcClientId: + description: The oidcClientId field. type: string - pageSize: - description: Maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous SearchAutomationTemplateVersionsResponse. - readOnly: false + oidcClientSecret: + description: Write-only. Never returned in get/list. type: string - title: Search Automation Template Versions Request + title: Auth Config Jump Cloud type: object - x-speakeasy-name-override: SearchAutomationTemplateVersionsRequest - c1.api.automations.v1.SearchAutomationTemplateVersionsResponse: - description: The SearchAutomationTemplateVersionsResponse message. + x-speakeasy-name-override: AuthConfigJumpCloud + c1.api.auth_config.v1.AuthConfigMicrosoft: + description: The AuthConfigMicrosoft message. properties: - list: - description: The page of template versions matching the search criteria. + tenantIds: + description: The tenantIds field. items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateVersion' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false - type: string - title: Search Automation Template Versions Response + type: string + type: + - array + - "null" + title: Auth Config Microsoft type: object - x-speakeasy-name-override: SearchAutomationTemplateVersionsResponse - c1.api.automations.v1.SearchAutomationsRequest: - description: The SearchAutomationsRequest message. + x-speakeasy-name-override: AuthConfigMicrosoft + c1.api.auth_config.v1.AuthConfigOIDC: + description: The AuthConfigOIDC message. properties: - appId: - description: Filter results to automations belonging to this application. - readOnly: false - type: string - appIds: - description: |- - Filter results to automations belonging to any of the specified apps. - Supersedes the singular `app_id` field when non-empty; when empty, the - server falls back to `app_id` for backward compatibility. - items: + exactMatchClaims: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - direction: - description: |- - Direction to sort in. Unspecified falls back to ASC when sort_field is set; - when sort_field is also unspecified, the server default order (created_at - DESC) applies. - enum: - - SORT_DIRECTION_UNSPECIFIED - - SORT_DIRECTION_ASC - - SORT_DIRECTION_DESC - readOnly: false - type: string - x-speakeasy-unknown-values: allow - isDraft: - description: |- - Tri-state draft filter. Unset = include both drafts and published; - `true` = drafts only; `false` = published only. - nullable: true - readOnly: false - type: boolean - pageSize: - description: Maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous SearchAutomationsResponse. - readOnly: false + description: The exactMatchClaims field. + type: object + issuerId: + description: The issuerId field. type: string - query: - description: Free-text search query to filter automations by name or description. - readOnly: false + oidcClientId: + description: The oidcClientId field. type: string - refs: - description: Restrict results to automations matching these template references. - items: - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateRef' - nullable: true - readOnly: false - type: array - sortField: - description: Column to sort by. Unspecified (0) means sort by created_at desc (server default). - enum: - - AUTOMATION_SORT_FIELD_UNSPECIFIED - - AUTOMATION_SORT_FIELD_DISPLAY_NAME - - AUTOMATION_SORT_FIELD_CREATED_AT - - AUTOMATION_SORT_FIELD_LAST_EXECUTED_AT - - AUTOMATION_SORT_FIELD_ENABLED - - AUTOMATION_SORT_FIELD_PRIMARY_TRIGGER_TYPE - readOnly: false + oidcClientSecret: + description: The oidcClientSecret field. type: string - x-speakeasy-unknown-values: allow - statuses: - description: |- - Filter results by automation status. Empty or containing both ON and OFF - applies no status filter. - items: - enum: - - AUTOMATION_STATUS_FILTER_UNSPECIFIED - - AUTOMATION_STATUS_FILTER_ON - - AUTOMATION_STATUS_FILTER_OFF - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - triggerTypes: - description: Filter results to automations with any of the specified trigger types. + scopes: + description: The scopes field. items: - enum: - - TRIGGER_TYPE_UNSPECIFIED - - TRIGGER_TYPE_USER_PROFILE_CHANGE - - TRIGGER_TYPE_APP_USER_CREATE - - TRIGGER_TYPE_APP_USER_UPDATE - - TRIGGER_TYPE_UNUSED_ACCESS - - TRIGGER_TYPE_USER_CREATED - - TRIGGER_TYPE_GRANT_FOUND - - TRIGGER_TYPE_GRANT_DELETED - - TRIGGER_TYPE_WEBHOOK - - TRIGGER_TYPE_SCHEDULE - - TRIGGER_TYPE_FORM - - TRIGGER_TYPE_SCHEDULE_APP_USER - - TRIGGER_TYPE_ACCESS_CONFLICT - - TRIGGER_TYPE_SCHEDULE_NO_USER type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Search Automations Request - type: object - x-speakeasy-name-override: SearchAutomationsRequest - c1.api.automations.v1.SearchAutomationsResponse: - description: The SearchAutomationsResponse message. - properties: - list: - description: The page of automations matching the search criteria. - items: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty when no more results exist. - readOnly: false - type: string - title: Search Automations Response + type: + - array + - "null" + title: Auth Config Oidc type: object - x-speakeasy-name-override: SearchAutomationsResponse - c1.api.automations.v1.SendEmail: - description: The SendEmail message. - nullable: true + x-speakeasy-name-override: AuthConfigOIDC + c1.api.auth_config.v1.AuthConfigOkta: + description: The AuthConfigOkta message. properties: - body: - description: The body field. - readOnly: false + domain: + description: The domain field. type: string - email: - deprecated: true - description: |- - Deprecated: use email_cel instead. Static email field shipped behind FF 541 (SKU_MANUAL) - with zero tenant enablement. CEL subsumes static: '"ops@example.com"' is valid CEL. - readOnly: false + oidcClientId: + description: The oidcClientId field. type: string - emailCel: - description: |- - CEL expression resolving to one or more email addresses (string or list). - Evaluated against the workflow execution context (trigger + completed steps). - Static emails work too: '"ops@example.com"' is valid CEL. - Supports list for multiple recipients: '["a@x.com", "b@x.com"]'. - Requires the tenant to have a TenantEmailProvider configured. - readOnly: false + oidcClientSecret: + description: Write-only. Never returned in get/list. type: string - subject: - description: The subject field. - readOnly: false + title: Auth Config Okta + type: object + x-speakeasy-name-override: AuthConfigOkta + c1.api.auth_config.v1.AuthConfigOneLogin: + description: The AuthConfigOneLogin message. + properties: + domain: + description: The domain field. type: string - title: - description: The title field. - readOnly: false + oidcClientId: + description: The oidcClientId field. type: string - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdsCel: - description: The userIdsCel field. - readOnly: false + oidcClientSecret: + description: The oidcClientSecret field. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Send Email + title: Auth Config One Login type: object - x-speakeasy-name-override: SendEmail - c1.api.automations.v1.SendSlackMessage: - description: | - SendSlackMessage posts to a channel or DMs one or more users. Delivery mode is - inferred from which fields are populated: DM if any user field is set - (use_subject_user, user_ids_cel, user_refs), otherwise channel. Priority for DM - recipient resolution: use_subject_user > user_ids_cel > user_refs. - - This message contains a oneof named channel. Only a single field of the following list may be set at a time: - - channelName - - channelNameCel - nullable: true + x-speakeasy-name-override: AuthConfigOneLogin + c1.api.auth_config.v1.AuthConfigPingOne: + description: The AuthConfigPingOne message. properties: - body: - description: The body field. - readOnly: false - type: string - channelName: - description: |- - The channelName field. - This field is part of the `channel` oneof. - See the documentation for `c1.api.automations.v1.SendSlackMessage` for more details. - nullable: true - readOnly: false + environmentId: + description: The environmentId field. type: string - channelNameCel: - description: |- - The channelNameCel field. - This field is part of the `channel` oneof. - See the documentation for `c1.api.automations.v1.SendSlackMessage` for more details. - nullable: true - readOnly: false + oidcClientId: + description: The oidcClientId field. type: string - useSubjectUser: - description: The useSubjectUser field. - readOnly: false - type: boolean - userIdsCel: - description: The userIdsCel field. - readOnly: false + oidcClientSecret: + description: The oidcClientSecret field. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Send Slack Message + title: Auth Config Ping One type: object - x-speakeasy-name-override: SendSlackMessage - c1.api.automations.v1.SetCredential: + x-speakeasy-name-override: AuthConfigPingOne + c1.api.auth_config.v1.TenantAuthConfig: description: | - SetCredential submits a RotateCredentials baton task to the target connector, - re-encrypting the given password CEL expression with the connector's public JWK. + The TenantAuthConfig message. - This message contains a oneof named connector_identifier. Only a single field of the following list may be set at a time: - - connectorRef - nullable: true + This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: + - google + - microsoft + - okta + - onelogin + - jumpcloud + - pingone + - oidc + - c1Local properties: - accountIdCel: - description: The accountIdCel field. - readOnly: false + bootstrapDomains: + description: 'Bootstrap routing: email domains that route unknown users to this config.' + items: + type: string + type: + - array + - "null" + c1Local: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigC1Local' + - type: "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deprecationDeadline: + format: date-time + type: + - string + - "null" + deprecationMessage: + description: User-visible message shown when status=DEPRECATED. type: string - connectorRef: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' - passwordCel: - description: The passwordCel field. - readOnly: false + displayName: + description: The displayName field. type: string - title: Set Credential - type: object - x-speakeasy-name-override: SetCredential - c1.api.automations.v1.StoreCredential: - description: |- - StoreCredential stores a credential from GeneratePassword in a vault. - Supports Paper Vault (SSO/email) and App Vault (entitlement-bound). - nullable: true - properties: - appIdCel: - description: CEL expression that resolves to app ID (App Vault only) - readOnly: false + google: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigGoogle' + - type: "null" + id: + description: The id field. type: string - authType: - description: Authentication type for the paper vault recipient (Paper Vault only) + isDefaultBootstrap: + description: The isDefaultBootstrap field. + type: boolean + jumpcloud: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigJumpCloud' + - type: "null" + microsoft: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigMicrosoft' + - type: "null" + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOIDC' + - type: "null" + okta: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOkta' + - type: "null" + onelogin: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOneLogin' + - type: "null" + pingone: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigPingOne' + - type: "null" + providerType: + description: Provider type (read-only after creation — provider config determines type). enum: - - STORE_CREDENTIAL_AUTH_TYPE_UNSPECIFIED - - STORE_CREDENTIAL_AUTH_TYPE_SSO_INTERNAL - - STORE_CREDENTIAL_AUTH_TYPE_VERIFY_EMAIL - readOnly: false + - AUTH_CONFIG_PROVIDER_TYPE_UNSPECIFIED + - AUTH_CONFIG_PROVIDER_TYPE_GOOGLE + - AUTH_CONFIG_PROVIDER_TYPE_MICROSOFT + - AUTH_CONFIG_PROVIDER_TYPE_OKTA + - AUTH_CONFIG_PROVIDER_TYPE_ONELOGIN + - AUTH_CONFIG_PROVIDER_TYPE_JUMPCLOUD + - AUTH_CONFIG_PROVIDER_TYPE_PINGONE + - AUTH_CONFIG_PROVIDER_TYPE_OIDC + - AUTH_CONFIG_PROVIDER_TYPE_C1_LOCAL + readOnly: true type: string x-speakeasy-unknown-values: allow - credentialCel: - description: CEL expression that resolves to the encrypted credential from GeneratePassword - readOnly: false - type: string - expiry: - format: duration - readOnly: false - type: string - labelCel: - description: Optional display label for the vault - readOnly: false - type: string - maxViews: - description: Maximum number of views (0 = unlimited, default 1) (Paper Vault only) - format: uint32 - readOnly: false - type: integer - recipientCel: - description: CEL expression resolving to the C1 user ID of the recipient (SSO_INTERNAL / App Vault) - readOnly: false - type: string - recipientEmailCel: - description: CEL expression resolving to a recipient email address (Paper Vault + VERIFY_EMAIL only) - readOnly: false - type: string - ttl: - format: duration - readOnly: false - type: string - vaultType: - description: 'Vault type selector (default: PAPER_VAULT for backward compatibility)' + status: + description: The status field. enum: - - STORE_CREDENTIAL_VAULT_TYPE_UNSPECIFIED - - STORE_CREDENTIAL_VAULT_TYPE_PAPER_VAULT - - STORE_CREDENTIAL_VAULT_TYPE_APP_VAULT - readOnly: false + - AUTH_CONFIG_STATUS_UNSPECIFIED + - AUTH_CONFIG_STATUS_ACTIVE + - AUTH_CONFIG_STATUS_DEPRECATED + - AUTH_CONFIG_STATUS_DISABLED type: string x-speakeasy-unknown-values: allow - title: Store Credential + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Tenant Auth Config type: object - x-speakeasy-name-override: StoreCredential - c1.api.automations.v1.TaskAction: + x-speakeasy-name-override: TenantAuthConfig + c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest: description: | - The TaskAction message. + The TenantAuthConfigServiceCreateRequest message. - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - close - - reassign - nullable: true + This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: + - google + - microsoft + - okta + - onelogin + - jumpcloud + - pingone + - oidc + - c1Local properties: - close: - $ref: '#/components/schemas/c1.api.automations.v1.CloseAction' - reassign: - $ref: '#/components/schemas/c1.api.automations.v1.ReassignAction' - taskTypes: - description: The taskTypes field. + bootstrapDomains: + description: Email domains that route unknown users to this authentication provider during login. items: - enum: - - TASK_TYPE_UNSPECIFIED - - TASK_TYPE_REQUEST - - TASK_TYPE_REVOKE - - TASK_TYPE_REVIEW type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - taskUserRelation: - description: The taskUserRelation field. + type: + - array + - "null" + c1Local: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigC1Local' + - type: "null" + deprecationDeadline: + format: date-time + type: + - string + - "null" + deprecationMessage: + description: A user-visible message explaining why the provider is deprecated. + type: string + displayName: + description: The human-readable name for this authentication provider. + type: string + google: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigGoogle' + - type: "null" + isDefaultBootstrap: + description: Whether this provider is the default for users whose email domain has no explicit mapping. + type: boolean + jumpcloud: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigJumpCloud' + - type: "null" + microsoft: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigMicrosoft' + - type: "null" + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOIDC' + - type: "null" + okta: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOkta' + - type: "null" + onelogin: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigOneLogin' + - type: "null" + pingone: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.AuthConfigPingOne' + - type: "null" + status: + description: The initial status of the authentication provider. enum: - - TASK_USER_RELATION_UNSPECIFIED - - TASK_USER_RELATION_ASSIGNEE - - TASK_USER_RELATION_SUBJECT - readOnly: false + - AUTH_CONFIG_STATUS_UNSPECIFIED + - AUTH_CONFIG_STATUS_ACTIVE + - AUTH_CONFIG_STATUS_DEPRECATED + - AUTH_CONFIG_STATUS_DISABLED type: string x-speakeasy-unknown-values: allow - title: Task Action + required: + - displayName + title: Tenant Auth Config Service Create Request type: object - x-speakeasy-name-override: TaskAction - c1.api.automations.v1.TerminateAutomationRequestInput: - description: The TerminateAutomationRequest message. - title: Terminate Automation Request + x-speakeasy-name-override: TenantAuthConfigServiceCreateRequest + c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse: + description: The TenantAuthConfigServiceCreateResponse message. + properties: + authConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' + - type: "null" + title: Tenant Auth Config Service Create Response type: object - x-speakeasy-name-override: TerminateAutomationRequest - c1.api.automations.v1.TerminateAutomationResponse: - description: The TerminateAutomationResponse message. - title: Terminate Automation Response + x-speakeasy-name-override: TenantAuthConfigServiceCreateResponse + c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput: + description: The TenantAuthConfigServiceDeleteRequest message. + title: Tenant Auth Config Service Delete Request type: object - x-speakeasy-name-override: TerminateAutomationResponse - c1.api.automations.v1.UnenrollFromAllAccessProfiles: - description: The UnenrollFromAllAccessProfiles message. - nullable: true + x-speakeasy-name-override: TenantAuthConfigServiceDeleteRequest + c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse: + description: The TenantAuthConfigServiceDeleteResponse message. + title: Tenant Auth Config Service Delete Response + type: object + x-speakeasy-name-override: TenantAuthConfigServiceDeleteResponse + c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse: + description: The TenantAuthConfigServiceGetResponse message. properties: - catalogIds: - description: Optional list of catalog IDs to unenroll from. If empty, unenroll from all catalogs. + authConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' + - type: "null" + title: Tenant Auth Config Service Get Response + type: object + x-speakeasy-name-override: TenantAuthConfigServiceGetResponse + c1.api.auth_config.v1.TenantAuthConfigServiceListResponse: + description: The TenantAuthConfigServiceListResponse message. + properties: + list: + description: The list of authentication provider configurations. items: - type: string - nullable: true - readOnly: false - type: array - catalogIdsCel: - description: CEL expression to dynamically select catalog IDs. If provided, overrides catalog_ids. - readOnly: false - type: string - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false - type: boolean - userIdsCel: - description: The userIdsCel field. - readOnly: false + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - userRefs: - description: The userRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Unenroll From All Access Profiles + title: Tenant Auth Config Service List Response type: object - x-speakeasy-name-override: UnenrollFromAllAccessProfiles - c1.api.automations.v1.UpdateAutomationRequestInput: - description: The UpdateAutomationRequest message. + x-speakeasy-name-override: TenantAuthConfigServiceListResponse + c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput: + description: The TenantAuthConfigServiceUpdateRequest message. properties: - automation: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' + authConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string - title: Update Automation Request + type: + - string + - "null" + title: Tenant Auth Config Service Update Request type: object - x-speakeasy-name-override: UpdateAutomationRequest - c1.api.automations.v1.UpdateAutomationResponse: - description: The UpdateAutomationResponse message. + x-speakeasy-name-override: TenantAuthConfigServiceUpdateRequest + c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse: + description: The TenantAuthConfigServiceUpdateResponse message. properties: - automation: - $ref: '#/components/schemas/c1.api.automations.v1.Automation' - webhookCapabilityUrl: - description: |- - One-time absolute webhook URL for capability URL authentication, shown once when the trigger is saved. - Contains the full URL including the embedded token (e.g. https://tenant.conductorone.com/api/v1/webhooks/incoming/{id}/t/{token}). - Populated only when the webhook trigger uses capability URL authentication. - readOnly: false - type: string - webhookHmacSecret: - description: |- - One-time HMAC shared secret, shown once when the trigger is saved. - Populated only when the webhook trigger uses HMAC authentication. - readOnly: false - type: string - title: Update Automation Response + authConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfig' + - type: "null" + title: Tenant Auth Config Service Update Response type: object - x-speakeasy-name-override: UpdateAutomationResponse - c1.api.automations.v1.UpdateUser: - description: | - The UpdateUser message. - - This message contains a oneof named user. Only a single field of the following list may be set at a time: - - userIdCel - - userRef - - - This message contains a oneof named user_status. Only a single field of the following list may be set at a time: - - userStatusEnum - - userStatusCel - nullable: true + x-speakeasy-name-override: TenantAuthConfigServiceUpdateResponse + c1.api.authorization.v1.ActorObjectPermissions: + description: ActorObjectPermissions describes which actions the calling user is permitted to perform on an object, as determined by policy. properties: - useSubjectUser: - description: If true, the step will use the subject user of the automation as the subject. - readOnly: false + delete: + description: The delete field. type: boolean - userIdCel: - description: |- - The userIdCel field. - This field is part of the `user` oneof. - See the documentation for `c1.api.automations.v1.UpdateUser` for more details. - nullable: true - readOnly: false - type: string - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - userStatusCel: - description: |- - The userStatusCel field. - This field is part of the `user_status` oneof. - See the documentation for `c1.api.automations.v1.UpdateUser` for more details. - nullable: true - readOnly: false - type: string - userStatusEnum: - description: |- - The userStatusEnum field. - This field is part of the `user_status` oneof. - See the documentation for `c1.api.automations.v1.UpdateUser` for more details. - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED - nullable: true - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: Update User + edit: + description: The edit field. + type: boolean + extra: + additionalProperties: + type: boolean + description: The extra field. + type: object + read: + description: The read field. + type: boolean + title: Actor Object Permissions type: object - x-speakeasy-name-override: UpdateUser - c1.api.automations.v1.UsageBasedRevocationTrigger: + x-speakeasy-name-override: UserActorObjectPermissions + c1.api.automations.v1.AccessConflictTrigger: description: | - The UsageBasedRevocationTrigger message. + The AccessConflictTrigger message. - This message contains a oneof named cold_start_schedule. Only a single field of the following list may be set at a time: - - runImmediately - - runDelayed - nullable: true - properties: - appId: - description: The appId field. - readOnly: false - type: string - enabledAt: - format: date-time - readOnly: false - type: string - excludedGroupRefs: - description: The excludedGroupRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - excludedUserRefs: - description: The excludedUserRefs field. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - includeUsersWithNoActivity: - description: The includeUsersWithNoActivity field. - readOnly: false - type: boolean - runDelayed: - $ref: '#/components/schemas/c1.api.automations.v1.RunDelayed' - runImmediately: - $ref: '#/components/schemas/c1.api.automations.v1.RunImmediately' - targetedAppUserTypes: - description: The targetedAppUserTypes field. - items: - enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - targetedEntitlementRefs: - description: The targetedEntitlementRefs field. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - unusedForDays: - description: The unusedForDays field. - format: uint32 - readOnly: false - type: integer - title: Usage Based Revocation Trigger - type: object - x-speakeasy-name-override: UsageBasedRevocationTrigger - c1.api.automations.v1.UserCreatedTrigger: - description: The UserCreatedTrigger message. - nullable: true + This message contains a oneof named conflict_monitor_selector. Only a single field of the following list may be set at a time: + - conflictMonitorRefs + - allConflictMonitors properties: - condition: - description: The condition field. - readOnly: false - type: string - title: User Created Trigger + allConflictMonitors: + description: |- + The allConflictMonitors field. + This field is part of the `conflict_monitor_selector` oneof. + See the documentation for `c1.api.automations.v1.AccessConflictTrigger` for more details. + type: + - boolean + - "null" + conflictMonitorRefs: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ConflictMonitorRefs' + - type: "null" + title: Access Conflict Trigger type: object - x-speakeasy-name-override: UserCreatedTrigger - c1.api.automations.v1.UserProfileChangeTrigger: - description: The UserProfileChangeTrigger message. - nullable: true - properties: - condition: - description: The condition field. - readOnly: false - type: string - title: User Profile Change Trigger + x-speakeasy-name-override: AccessConflictTrigger + c1.api.automations.v1.AccountInContext: + description: The AccountInContext message. + title: Account In Context type: object - x-speakeasy-name-override: UserProfileChangeTrigger - c1.api.automations.v1.UserProperties: - description: The UserProperties message. - nullable: true + x-speakeasy-name-override: AccountInContext + c1.api.automations.v1.AccountLifecycleAction: + description: | + The AccountLifecycleAction message. + + This message contains a oneof named account_identifier. Only a single field of the following list may be set at a time: + - accountRef + - accountInContext properties: - displayNameCel: - description: The displayNameCel field. - readOnly: false - type: string - emailCel: - description: The emailCel field. - readOnly: false - type: string - profileAttributeCel: - description: The profileAttributeCel field. - readOnly: false - type: string - usernameCel: - description: The usernameCel field. - readOnly: false + accountInContext: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AccountInContext' + - type: "null" + accountRef: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AccountRef' + - type: "null" + actionName: + description: The actionName field. type: string - title: User Properties + connectorRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' + - type: "null" + title: Account Lifecycle Action type: object - x-speakeasy-name-override: UserProperties - c1.api.automations.v1.WaitForDuration: - description: The WaitForDuration message. - nullable: true + x-speakeasy-name-override: AccountLifecycleAction + c1.api.automations.v1.AccountRef: + description: The AccountRef message. properties: - duration: - format: duration - readOnly: false + accountIdCel: + description: The accountIdCel field. type: string - title: Wait For Duration + title: Account Ref type: object - x-speakeasy-name-override: WaitForDuration - c1.api.automations.v1.Webhook: + x-speakeasy-name-override: AccountRef + c1.api.automations.v1.AppUserCreatedTrigger: description: | - The Webhook message. + The AppUserCreatedTrigger message. - This message contains a oneof named webhook_identifier. Only a single field of the following list may be set at a time: - - webhookId - - webhookIdCel - nullable: true + This message contains a oneof named app_identifier. Only a single field of the following list may be set at a time: + - appId + - appIdCel properties: - payload: - additionalProperties: true - readOnly: false - type: object - webhookId: + appId: description: |- - The webhookId field. - This field is part of the `webhook_identifier` oneof. - See the documentation for `c1.api.automations.v1.Webhook` for more details. - nullable: true - readOnly: false - type: string - webhookIdCel: + The appId field. + This field is part of the `app_identifier` oneof. + See the documentation for `c1.api.automations.v1.AppUserCreatedTrigger` for more details. + type: + - string + - "null" + appIdCel: description: |- - The webhookIdCel field. - This field is part of the `webhook_identifier` oneof. - See the documentation for `c1.api.automations.v1.Webhook` for more details. - nullable: true - readOnly: false + The appIdCel field. + This field is part of the `app_identifier` oneof. + See the documentation for `c1.api.automations.v1.AppUserCreatedTrigger` for more details. + type: + - string + - "null" + condition: + description: The condition field. type: string - title: Webhook + title: App User Created Trigger type: object - x-speakeasy-name-override: Webhook - c1.api.automations.v1.WebhookAutomationTrigger: + x-speakeasy-name-override: AppUserCreatedTrigger + c1.api.automations.v1.AppUserUpdatedTrigger: description: | - The WebhookAutomationTrigger message. + The AppUserUpdatedTrigger message. - This message contains a oneof named auth_config. Only a single field of the following list may be set at a time: - - jwt - - hmac - - capabilityUrl - nullable: true - properties: - capabilityUrl: - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthCapabilityURL' - hmac: - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthHMAC' - jwt: - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthJWT' - listenerId: - description: Optional existing listener ID (hidden field from frontend) - readOnly: false - type: string - title: Webhook Automation Trigger - type: object - x-speakeasy-name-override: WebhookAutomationTrigger - c1.api.automations.v1.WebhookListenerAuthCapabilityURL: - description: |- - Capability URL authentication: the URL itself contains an unguessable token that acts - as the credential. This is simpler to integrate but less secure than JWT or HMAC because - the token can leak via server logs, referrer headers, and URL sharing. - See https://www.w3.org/TR/capability-urls/ for background. - nullable: true - title: Webhook Listener Auth Capability Url - type: object - x-speakeasy-name-override: WebhookListenerAuthCapabilityURL - c1.api.automations.v1.WebhookListenerAuthHMAC: - description: The WebhookListenerAuthHMAC message. - nullable: true - title: Webhook Listener Auth Hmac - type: object - x-speakeasy-name-override: WebhookListenerAuthHMAC - c1.api.automations.v1.WebhookListenerAuthJWT: - description: The WebhookListenerAuthJWT message. - nullable: true + This message contains a oneof named app_identifier. Only a single field of the following list may be set at a time: + - appId + - appIdCel properties: - jwksUrl: - description: The jwksUrl field. - readOnly: false + appId: + description: |- + The appId field. + This field is part of the `app_identifier` oneof. + See the documentation for `c1.api.automations.v1.AppUserUpdatedTrigger` for more details. + type: + - string + - "null" + appIdCel: + description: |- + The appIdCel field. + This field is part of the `app_identifier` oneof. + See the documentation for `c1.api.automations.v1.AppUserUpdatedTrigger` for more details. + type: + - string + - "null" + condition: + description: The condition field. type: string - title: Webhook Listener Auth Jwt + title: App User Updated Trigger type: object - x-speakeasy-name-override: WebhookListenerAuthJWT - c1.api.directory.v1.Directory: + x-speakeasy-name-override: AppUserUpdatedTrigger + c1.api.automations.v1.Automation: description: | - This object indicates that an app is also a directory. + The Automation message. - This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: - - all - - celExpression + This message contains a oneof named disabled_reason. Only a single field of the following list may be set at a time: + - circuitBreaker properties: - all: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ + are reserved. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() appId: - description: The ID of the app associated with the directory. - readOnly: true + description: the app id this workflow_template belongs to type: string - celExpression: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' + automationSteps: + description: The automationSteps field. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' + type: + - array + - "null" + circuitBreaker: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.DisabledReasonCircuitBreaker' + - type: "null" + circuitBreakerMax: + description: |- + Circuit breaker rate cap: disable this automation if it executes more + than circuit_breaker_max times in the trailing circuit_breaker_period. + 0 = circuit breaker off (default). + format: uint32 + type: integer + circuitBreakerPeriod: + description: The circuitBreakerPeriod field. + enum: + - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED + - CIRCUIT_BREAKER_PERIOD_HOUR + - CIRCUIT_BREAKER_PERIOD_DAY + - CIRCUIT_BREAKER_PERIOD_WEEK + - CIRCUIT_BREAKER_PERIOD_MONTH + type: string + x-speakeasy-unknown-values: allow + context: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' + - type: "null" createdAt: format: date-time - readOnly: true + type: + - string + - "null" + currentVersion: + description: The currentVersion field. + format: int64 type: string - deletedAt: - format: date-time - readOnly: true + description: + description: The description field. type: string - mergeConfig: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' - updatedAt: - format: date-time + displayName: + description: The displayName field. + type: string + draftAutomationSteps: + description: The draftAutomationSteps field. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' + type: + - array + - "null" + draftTriggers: + description: The draftTriggers field. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' + type: + - array + - "null" + enabled: + description: The enabled field. + type: boolean + id: + description: The id field. readOnly: true type: string - title: Directory - type: object - x-speakeasy-name-override: Directory - c1.api.directory.v1.DirectoryAccountFilterAll: - description: The DirectoryAccountFilterAll message. - nullable: true - title: Directory Account Filter All - type: object - x-speakeasy-name-override: DirectoryAccountFilterAll - c1.api.directory.v1.DirectoryAccountFilterCel: - description: The DirectoryAccountFilterCel message. - nullable: true - properties: - expression: - description: The expression field. - readOnly: false + isDraft: + description: The isDraft field. + type: boolean + lastExecutedAt: + format: date-time + type: + - string + - "null" + primaryTriggerType: + description: The primaryTriggerType field. + enum: + - TRIGGER_TYPE_UNSPECIFIED + - TRIGGER_TYPE_USER_PROFILE_CHANGE + - TRIGGER_TYPE_APP_USER_CREATE + - TRIGGER_TYPE_APP_USER_UPDATE + - TRIGGER_TYPE_UNUSED_ACCESS + - TRIGGER_TYPE_USER_CREATED + - TRIGGER_TYPE_GRANT_FOUND + - TRIGGER_TYPE_GRANT_DELETED + - TRIGGER_TYPE_WEBHOOK + - TRIGGER_TYPE_SCHEDULE + - TRIGGER_TYPE_FORM + - TRIGGER_TYPE_SCHEDULE_APP_USER + - TRIGGER_TYPE_ACCESS_CONFLICT + - TRIGGER_TYPE_SCHEDULE_NO_USER type: string - title: Directory Account Filter Cel - type: object - x-speakeasy-name-override: DirectoryAccountFilterCel - c1.api.directory.v1.DirectoryExpandMask: - description: The fields to be included in the directory response. - properties: - paths: - description: An array of fields to be included in the directory response. + x-speakeasy-unknown-values: allow + triggers: + description: The triggers field. items: - type: string - nullable: true - readOnly: false - type: array - title: Directory Expand Mask + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' + type: + - array + - "null" + title: Automation type: object - x-speakeasy-name-override: DirectoryExpandMask - c1.api.directory.v1.DirectoryMergeConfig: - description: DirectoryMergeConfig configures how AppUsers from this directory are matched to C1 Users. + x-speakeasy-entity: Automation + x-speakeasy-name-override: Automation + c1.api.automations.v1.AutomationContext: + description: The AutomationContext message. properties: - matchCases: - description: Ordered list of match cases evaluated in sequence. First match wins. - items: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeMatchCase' - nullable: true - readOnly: false - type: array - title: Directory Merge Config + context: + additionalProperties: true + type: + - object + - "null" + title: Automation Context type: object - x-speakeasy-name-override: DirectoryMergeConfig - c1.api.directory.v1.DirectoryMergeMatchCase: - description: DirectoryMergeMatchCase defines a pair of CEL key extractors for matching. + x-speakeasy-name-override: AutomationContext + c1.api.automations.v1.AutomationExecution: + description: The AutomationExecution message. properties: - appUserKeyCel: - description: CEL expression evaluated against an AppUser to produce match key(s). - readOnly: false - type: string - userKeyCel: - description: CEL expression evaluated against a User to produce match key(s). - readOnly: false + automationTemplateId: + description: The automationTemplateId field. type: string - title: Directory Merge Match Case - type: object - x-speakeasy-name-override: DirectoryMergeMatchCase - c1.api.directory.v1.DirectoryServiceCreateRequest: - description: | - Uplevel an app into a full directory. - - This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: - - all - - celExpression - properties: - all: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' - appId: - description: The AppID to make into a directory, providing identities and more for the C1 app. - readOnly: false + completedAt: + format: date-time + type: + - string + - "null" + context: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' + - type: "null" + createdAt: + format: date-time + type: + - string + - "null" + currentVersion: + description: The currentVersion field. + format: int32 + type: integer + deletedAt: + format: date-time + type: + - string + - "null" + duration: + format: duration + type: + - string + - "null" + id: + description: The id field. + format: int64 type: string - celExpression: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' - expandMask: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryExpandMask' - mergeConfig: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' - title: Directory Service Create Request + isDraft: + description: The isDraft field. + type: boolean + state: + description: The state field. + enum: + - AUTOMATION_EXECUTION_STATE_UNSPECIFIED + - AUTOMATION_EXECUTION_STATE_PENDING + - AUTOMATION_EXECUTION_STATE_CREATING + - AUTOMATION_EXECUTION_STATE_GET_STEP + - AUTOMATION_EXECUTION_STATE_PROCESS_STEP + - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP + - AUTOMATION_EXECUTION_STATE_DONE + - AUTOMATION_EXECUTION_STATE_ERROR + - AUTOMATION_EXECUTION_STATE_TERMINATE + - AUTOMATION_EXECUTION_STATE_WAITING + - AUTOMATION_EXECUTION_STATE_PAUSED_BY_CIRCUIT_BREAKER + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + title: Automation Execution type: object - x-speakeasy-name-override: DirectoryServiceCreateRequest - c1.api.directory.v1.DirectoryServiceCreateResponse: - description: The DirectoryServiceCreateResponse message. + x-speakeasy-name-override: AutomationExecution + c1.api.automations.v1.AutomationExecutionExpandMask: + description: The AutomationExecutionExpandMask message. properties: - directoryView: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' - expanded: - description: List of serialized related objects. + paths: + description: The paths field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Directory Service Create Response - type: object - x-speakeasy-name-override: DirectoryServiceCreateResponse - c1.api.directory.v1.DirectoryServiceDeleteRequestInput: - description: DirectoryServiceDeleteRequest is the request message for deleting a directory. It uses URL values for input. - title: Directory Service Delete Request - type: object - x-speakeasy-name-override: DirectoryServiceDeleteRequest - c1.api.directory.v1.DirectoryServiceDeleteResponse: - description: Empty response with a status code indicating success. - title: Directory Service Delete Response + type: string + type: + - array + - "null" + title: Automation Execution Expand Mask type: object - x-speakeasy-name-override: DirectoryServiceDeleteResponse - c1.api.directory.v1.DirectoryServiceGetResponse: - description: |- - The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the - location in the expanded array that items are expanded as indicated by the expand mask in the request. + x-speakeasy-name-override: AutomationExecutionExpandMask + c1.api.automations.v1.AutomationExecutionRef: + description: The AutomationExecutionRef message. properties: - directoryView: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Directory Service Get Response + id: + description: The id field. + format: int64 + type: string + title: Automation Execution Ref type: object - x-speakeasy-name-override: DirectoryServiceGetResponse - c1.api.directory.v1.DirectoryServiceListResponse: - description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: AutomationExecutionRef + c1.api.automations.v1.AutomationExecutionView: + description: The AutomationExecutionView message. properties: - expanded: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' - nullable: true - readOnly: false - type: array - nextPageToken: - description: List of serialized related objects. - readOnly: false + automationExecution: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' + - type: "null" + automationExecutionTriggerPath: + description: The automationExecutionTriggerPath field. type: string - title: Directory Service List Response + automationPath: + description: The automationPath field. + type: string + title: Automation Execution View type: object - x-speakeasy-name-override: DirectoryServiceListResponse - c1.api.directory.v1.DirectoryServiceUpdateRequestInput: + x-speakeasy-name-override: AutomationExecutionView + c1.api.automations.v1.AutomationStep: description: | - Update a directory by app_id. + The AutomationStep message. - This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: - - all - - celExpression - properties: - all: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' - celExpression: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' - expandMask: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryExpandMask' - mergeConfig: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' - title: Directory Service Update Request - type: object - x-speakeasy-name-override: DirectoryServiceUpdateRequest - c1.api.directory.v1.DirectoryServiceUpdateResponse: - description: The DirectoryServiceUpdateResponse message. - properties: - directoryView: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - title: Directory Service Update Response - type: object - x-speakeasy-name-override: DirectoryServiceUpdateResponse - c1.api.directory.v1.DirectoryView: - description: The directory view contains a directory and an app_path which is a JSONPATH set to the location in the expand mask that the expanded app will live if requested by the expander. + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - createAccessReview + - waitForDuration + - unenrollFromAllAccessProfiles + - createRevokeTasks + - createRevokeTasksV2 + - sendEmail + - removeFromDelegation + - runAutomation + - updateUser + - taskAction + - webhook + - connectorAction + - connectorCreateAccount + - grantEntitlements + - sendSlackMessage + - callFunction + - accountLifecycleAction + - generatePassword + - evaluateExpressions + - setCredential + - storeCredential properties: - appPath: - description: JSONPATH expression indicating the location of the App object in the array. - readOnly: false + accountLifecycleAction: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AccountLifecycleAction' + - type: "null" + callFunction: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.CallFunction' + - type: "null" + connectorAction: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ConnectorAction' + - type: "null" + connectorCreateAccount: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ConnectorCreateAccount' + - type: "null" + createAccessReview: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.CreateAccessReview' + - type: "null" + createRevokeTasks: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.CreateRevokeTasks' + - type: "null" + createRevokeTasksV2: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.CreateRevokeTasksV2' + - type: "null" + evaluateExpressions: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EvaluateExpressions' + - type: "null" + generatePassword: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GeneratePassword' + - type: "null" + grantEntitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlements' + - type: "null" + removeFromDelegation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.RemoveFromDelegation' + - type: "null" + runAutomation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.RunAutomation' + - type: "null" + sendEmail: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.SendEmail' + - type: "null" + sendSlackMessage: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.SendSlackMessage' + - type: "null" + setCredential: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.SetCredential' + - type: "null" + skipIfTrueCel: + description: The skipIfTrueCel field. type: string - directory: - $ref: '#/components/schemas/c1.api.directory.v1.Directory' - title: Directory View - type: object - x-speakeasy-name-override: DirectoryView - c1.api.editor.v1.EditorMarker: - description: The EditorMarker message. - properties: - endColumn: - description: The endColumn field. - format: int32 - readOnly: false - type: integer - endLineNumber: - description: The endLineNumber field. - format: int32 - readOnly: false - type: integer - message: - description: The message field. - readOnly: false + stepDisplayName: + description: The stepDisplayName field. type: string - severity: - description: The severity field. - enum: - - UNKNOWN - - HINT - - INFO - - WARNING - - ERROR - readOnly: false + stepName: + description: The stepName field. type: string - x-speakeasy-unknown-values: allow - startColumn: - description: The startColumn field. - format: int32 - readOnly: false - type: integer - startLineNumber: - description: The startLineNumber field. - format: int32 - readOnly: false - type: integer - title: Editor Marker + storeCredential: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.StoreCredential' + - type: "null" + taskAction: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.TaskAction' + - type: "null" + unenrollFromAllAccessProfiles: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UnenrollFromAllAccessProfiles' + - type: "null" + updateUser: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UpdateUser' + - type: "null" + waitForDuration: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.WaitForDuration' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.Webhook' + - type: "null" + title: Automation Step type: object - x-speakeasy-name-override: EditorMarker - c1.api.finding.v1.AcceptRiskAction: - description: AcceptRiskAction parameters for UpdateFindingState. - nullable: true + x-speakeasy-name-override: AutomationStep + c1.api.automations.v1.AutomationTemplateRef: + description: The AutomationTemplateRef message. properties: - expiresAt: - format: date-time - readOnly: false - type: string - justification: - description: The justification field. - readOnly: false + id: + description: The id field. type: string - title: Accept Risk Action + title: Automation Template Ref type: object - x-speakeasy-name-override: AcceptRiskAction - c1.api.finding.v1.AppUserTarget: - description: The AppUserTarget message. - nullable: true + x-speakeasy-name-override: AutomationTemplateRef + c1.api.automations.v1.AutomationTemplateVersion: + description: The AutomationTemplateVersion message. properties: - appId: - description: The appId field. - readOnly: false - type: string - appUserId: - description: The appUserId field. - readOnly: false + automationSteps: + description: The automationSteps field. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' + type: + - array + - "null" + automationTemplateId: + description: The automationTemplateId field. type: string - title: App User Target - type: object - x-speakeasy-name-override: AppUserTarget - c1.api.finding.v1.BulkAcceptRiskAction: - description: The BulkAcceptRiskAction message. - nullable: true - properties: - expiresAt: + createdAt: format: date-time - readOnly: false - type: string - justification: - description: The justification field. - readOnly: false + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + triggers: + description: The triggers field. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' + type: + - array + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + version: + description: The version field. + format: int64 type: string - title: Bulk Accept Risk Action + title: Automation Template Version type: object - x-speakeasy-name-override: BulkAcceptRiskAction - c1.api.finding.v1.BulkAssignOwnerAction: - description: The BulkAssignOwnerAction message. - nullable: true + x-speakeasy-name-override: AutomationTemplateVersion + c1.api.automations.v1.AutomationTrigger: + description: | + Automation Triggers + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - userProfileChange + - appUserCreated + - appUserUpdated + - usageBasedRevocation + - userCreated + - grantFound + - grantDeleted + - webhook + - schedule + - scheduleAppUser + - accessConflict + - scheduleNoUser properties: - owner: - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' - title: Bulk Assign Owner Action + accessConflict: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AccessConflictTrigger' + - type: "null" + appUserCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AppUserCreatedTrigger' + - type: "null" + appUserUpdated: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AppUserUpdatedTrigger' + - type: "null" + grantDeleted: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantDeletedTrigger' + - type: "null" + grantFound: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantFoundTrigger' + - type: "null" + schedule: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTrigger' + - type: "null" + scheduleAppUser: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTriggerAppUser' + - type: "null" + scheduleNoUser: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ScheduleTriggerNoUser' + - type: "null" + usageBasedRevocation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UsageBasedRevocationTrigger' + - type: "null" + userCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UserCreatedTrigger' + - type: "null" + userProfileChange: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UserProfileChangeTrigger' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.WebhookAutomationTrigger' + - type: "null" + title: Automation Trigger type: object - x-speakeasy-name-override: BulkAssignOwnerAction - c1.api.finding.v1.BulkCreateFindingTasksRequest: - description: The BulkCreateFindingTasksRequest message. + x-speakeasy-name-override: AutomationTrigger + c1.api.automations.v1.CallFunction: + description: The CallFunction message. properties: - policyId: - description: Optional policy ID to use for the created tasks. Defaults to the app's grant policy. - readOnly: false + args: + additionalProperties: + type: string + description: |- + Arg name → CEL expression. Each value is evaluated against the + workflow execution context (subject + completed step outputs) and the + resolved values are passed to the function as JSON. Plain literals + must be quoted as CEL strings (e.g. "'static-value'"). + type: object + functionId: + description: The functionId field. type: string - refs: - description: Individual finding references to create tasks for (by-ID mode). - items: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRef' - nullable: true - readOnly: false - type: array - searchRequest: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' - title: Bulk Create Finding Tasks Request + title: Call Function type: object - x-speakeasy-name-override: BulkCreateFindingTasksRequest - c1.api.finding.v1.BulkCreateFindingTasksResponse: - description: The BulkCreateFindingTasksResponse message. + x-speakeasy-name-override: CallFunction + c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput: + description: The ClearAutomationCircuitBreakerRequest message. properties: - bulkActionId: - description: The ID of the asynchronous bulk action, which can be used to track progress. - readOnly: false + decision: + description: |- + What to do with paused executions. UNSPECIFIED means clear the breaker + only (backward-compatible default). RUN or CANCEL creates a bulk action + to resolve them asynchronously. + enum: + - PAUSED_EXECUTION_DECISION_UNSPECIFIED + - PAUSED_EXECUTION_DECISION_RUN + - PAUSED_EXECUTION_DECISION_CANCEL type: string - title: Bulk Create Finding Tasks Response - type: object - x-speakeasy-name-override: BulkCreateFindingTasksResponse - c1.api.finding.v1.BulkReopenAction: - description: The BulkReopenAction message. - nullable: true - title: Bulk Reopen Action - type: object - x-speakeasy-name-override: BulkReopenAction - c1.api.finding.v1.BulkSnoozeAction: - description: The BulkSnoozeAction message. - nullable: true - properties: + x-speakeasy-unknown-values: allow reason: - description: The reason field. - readOnly: false - type: string - snoozeUntil: - format: date-time - readOnly: false + description: Admin-supplied reason when decision is CANCEL. Up to 1024 bytes. type: string - title: Bulk Snooze Action + title: Clear Automation Circuit Breaker Request type: object - x-speakeasy-name-override: BulkSnoozeAction - c1.api.finding.v1.BulkSuppressAction: - description: The BulkSuppressAction message. - nullable: true + x-speakeasy-name-override: ClearAutomationCircuitBreakerRequest + c1.api.automations.v1.ClearAutomationCircuitBreakerResponse: + description: The ClearAutomationCircuitBreakerResponse message. properties: - reason: - description: The reason field. - readOnly: false + bulkActionId: + description: |- + The bulk action ID if a bulk action was created to resolve paused + executions. Empty when decision is UNSPECIFIED or there were no + paused executions. type: string - title: Bulk Suppress Action - type: object - x-speakeasy-name-override: BulkSuppressAction - c1.api.finding.v1.BulkUnsuppressAction: - deprecated: true - description: The BulkUnsuppressAction message. - nullable: true - title: Bulk Unsuppress Action + title: Clear Automation Circuit Breaker Response type: object - x-speakeasy-name-override: BulkUnsuppressAction - c1.api.finding.v1.BulkUpdateFindingStateRequest: + x-speakeasy-name-override: ClearAutomationCircuitBreakerResponse + c1.api.automations.v1.CloseAction: description: | - The BulkUpdateFindingStateRequest message. + The CloseAction message. - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - snooze - - suppress - - acceptRisk - - unsuppress - - assignOwner - - reopen + This message contains a oneof named user_identifier. Only a single field of the following list may be set at a time: + - userIdCel + - userRef properties: - acceptRisk: - $ref: '#/components/schemas/c1.api.finding.v1.BulkAcceptRiskAction' - assignOwner: - $ref: '#/components/schemas/c1.api.finding.v1.BulkAssignOwnerAction' - refs: - description: 'By-ID mode: specify individual finding refs.' - items: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRef' - nullable: true - readOnly: false - type: array - reopen: - $ref: '#/components/schemas/c1.api.finding.v1.BulkReopenAction' - searchRequest: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' - snooze: - $ref: '#/components/schemas/c1.api.finding.v1.BulkSnoozeAction' - suppress: - $ref: '#/components/schemas/c1.api.finding.v1.BulkSuppressAction' - unsuppress: - $ref: '#/components/schemas/c1.api.finding.v1.BulkUnsuppressAction' - title: Bulk Update Finding State Request + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdCel: + description: |- + The userIdCel field. + This field is part of the `user_identifier` oneof. + See the documentation for `c1.api.automations.v1.CloseAction` for more details. + type: + - string + - "null" + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Close Action type: object - x-speakeasy-name-override: BulkUpdateFindingStateRequest - c1.api.finding.v1.BulkUpdateFindingStateResponse: - description: The BulkUpdateFindingStateResponse message. + x-speakeasy-name-override: CloseAction + c1.api.automations.v1.ConflictMonitorRefs: + description: The ConflictMonitorRefs message. properties: - bulkActionId: - description: The ID of the asynchronous bulk action, which can be used to track progress. - readOnly: false - type: string - title: Bulk Update Finding State Response + conflictMonitorRefs: + description: The conflictMonitorRefs field. + items: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorRef' + type: + - array + - "null" + title: Conflict Monitor Refs type: object - x-speakeasy-name-override: BulkUpdateFindingStateResponse - c1.api.finding.v1.CreateFindingRoutingRuleRequest: - description: The CreateFindingRoutingRuleRequest message. + x-speakeasy-name-override: ConflictMonitorRefs + c1.api.automations.v1.ConnectorAction: + description: | + The ConnectorAction message. + + This message contains a oneof named connector_identifier. Only a single field of the following list may be set at a time: + - connectorRef properties: - routingRule: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - title: Create Finding Routing Rule Request + actionName: + description: The actionName field. + type: string + argsTemplate: + additionalProperties: true + type: + - object + - "null" + connectorRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' + - type: "null" + resourceTypeId: + description: The resourceTypeId field. + type: string + title: Connector Action type: object - x-speakeasy-name-override: CreateFindingRoutingRuleRequest - c1.api.finding.v1.CreateFindingRoutingRuleResponse: - description: The CreateFindingRoutingRuleResponse message. + x-speakeasy-name-override: ConnectorAction + c1.api.automations.v1.ConnectorCreateAccount: + description: | + The ConnectorCreateAccount message. + + This message contains a oneof named create_account_arguments. Only a single field of the following list may be set at a time: + - userIdCel + - userProperties properties: - routingRule: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - title: Create Finding Routing Rule Response - type: object - x-speakeasy-name-override: CreateFindingRoutingRuleResponse - c1.api.finding.v1.CreateFindingTaskRequestInput: - description: The CreateFindingTaskRequest message. - properties: - policyId: + connectorRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' + - type: "null" + passwordCel: description: |- - Optional policy ID. Defaults to the app's grant policy or the built-in - "Finding Review" policy. - readOnly: false + CEL expression referencing a GeneratePassword step output (e.g. "genStep.password"). + When set, the resolved password is encrypted for the connector and sent as CredentialOptions.EncryptedPassword. type: string - title: Create Finding Task Request + userIdCel: + description: |- + The userIdCel field. + This field is part of the `create_account_arguments` oneof. + See the documentation for `c1.api.automations.v1.ConnectorCreateAccount` for more details. + type: + - string + - "null" + userProperties: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.UserProperties' + - type: "null" + title: Connector Create Account type: object - x-speakeasy-name-override: CreateFindingTaskRequest - c1.api.finding.v1.CreateFindingTaskResponse: - description: The CreateFindingTaskResponse message. + x-speakeasy-name-override: ConnectorCreateAccount + c1.api.automations.v1.CreateAccessReview: + description: The CreateAccessReview message. properties: - finding: - $ref: '#/components/schemas/c1.api.finding.v1.Finding' - taskId: - description: The ID of the created task. - readOnly: false + accessReviewTemplateCel: + description: The accessReviewTemplateCel field. type: string - title: Create Finding Task Response - type: object - x-speakeasy-name-override: CreateFindingTaskResponse - c1.api.finding.v1.CreateTaskAction: - description: The CreateTaskAction message. - nullable: true - properties: - policyId: - description: The policyId field. - readOnly: false + accessReviewTemplateId: + description: The accessReviewTemplateId field. type: string - title: Create Task Action - type: object - x-speakeasy-name-override: CreateTaskAction - c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput: - description: The DeleteFindingRoutingRuleRequest message. - title: Delete Finding Routing Rule Request - type: object - x-speakeasy-name-override: DeleteFindingRoutingRuleRequest - c1.api.finding.v1.DeleteFindingRoutingRuleResponse: - description: The DeleteFindingRoutingRuleResponse message. - title: Delete Finding Routing Rule Response - type: object - x-speakeasy-name-override: DeleteFindingRoutingRuleResponse - c1.api.finding.v1.Finding: - description: | - The Finding message. - - This message contains a oneof named finding_type. Only a single field of the following list may be set at a time: - - similarUsernameMatch - - serviceAccountMisclassification - - - This message contains a oneof named target. Only a single field of the following list may be set at a time: - - identityUserTarget - - appUserTarget - - - This message contains a oneof named evidence. Only a single field of the following list may be set at a time: - - similarUsernameMatchEvidence - - serviceAccountMisclassificationEvidence - properties: - appId: - description: The appId field. - readOnly: false + campaignName: + description: Optional campaign name. If not provided, the campaign name will be the access review template name. type: string - appUserTarget: - $ref: '#/components/schemas/c1.api.finding.v1.AppUserTarget' - assignedOwner: - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' - computedOwner: - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' - createdAt: - format: date-time - readOnly: false + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdsCel: + description: The userIdsCel field. type: string - customTags: + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Create Access Review + type: object + x-speakeasy-name-override: CreateAccessReview + c1.api.automations.v1.CreateAutomationRequest: + description: The CreateAutomationRequest message. + properties: + annotations: additionalProperties: type: string - description: The customTags field. - readOnly: false + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. type: object - fingerprint: - description: The fingerprint field. - readOnly: false - type: string - firstObservedAt: - format: date-time - readOnly: false - type: string - id: - description: The id field. - readOnly: false - type: string - identityUserTarget: - $ref: '#/components/schemas/c1.api.finding.v1.IdentityUserTarget' - lastObservedAt: - format: date-time - readOnly: false + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + appId: + description: the app id this workflow_template belongs to type: string - recurrenceCount: - description: The recurrenceCount field. + automationSteps: + description: Ordered list of steps that the automation executes. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' + type: + - array + - "null" + circuitBreakerMax: + description: Circuit breaker rate cap. See Automation.circuit_breaker_max for semantics. format: uint32 - readOnly: false type: integer - remediationDescription: - description: The remediationDescription field. - readOnly: false - type: string - resolvedAt: - format: date-time - readOnly: false - type: string - riskAcceptanceExpiresAt: - format: date-time - readOnly: false - type: string - riskAcceptanceJustification: - description: The riskAcceptanceJustification field. - readOnly: false - type: string - riskScore: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRiskScore' - serviceAccountMisclassification: - $ref: '#/components/schemas/c1.api.finding.v1.ServiceAccountMisclassificationType' - serviceAccountMisclassificationEvidence: - $ref: '#/components/schemas/c1.api.finding.v1.ServiceAccountMisclassificationEvidence' - severity: - description: The severity field. + circuitBreakerPeriod: + description: The circuitBreakerPeriod field. enum: - - FINDING_SEVERITY_UNSPECIFIED - - FINDING_SEVERITY_INFO - - FINDING_SEVERITY_LOW - - FINDING_SEVERITY_MEDIUM - - FINDING_SEVERITY_HIGH - - FINDING_SEVERITY_CRITICAL - readOnly: false + - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED + - CIRCUIT_BREAKER_PERIOD_HOUR + - CIRCUIT_BREAKER_PERIOD_DAY + - CIRCUIT_BREAKER_PERIOD_WEEK + - CIRCUIT_BREAKER_PERIOD_MONTH type: string x-speakeasy-unknown-values: allow - similarUsernameMatch: - $ref: '#/components/schemas/c1.api.finding.v1.SimilarUsernameMatchType' - similarUsernameMatchEvidence: - $ref: '#/components/schemas/c1.api.finding.v1.SimilarUsernameMatchEvidence' - snoozeReason: - description: The snoozeReason field. - readOnly: false - type: string - snoozeUntil: - format: date-time - readOnly: false + context: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' + - type: "null" + description: + description: Optional description explaining the automation's purpose. type: string - sourceDetectorId: - description: The sourceDetectorId field. - readOnly: false + displayName: + description: Human-readable name for the automation. type: string - state: - description: The state field. - enum: - - FINDING_STATE_UNSPECIFIED - - FINDING_STATE_OPEN - - FINDING_STATE_IN_PROGRESS - - FINDING_STATE_RESOLVED - - FINDING_STATE_SNOOZED - - FINDING_STATE_RISK_ACCEPTED - - FINDING_STATE_SUPPRESSED - readOnly: false + draftAutomationSteps: + description: Steps saved as a draft that have not yet been published. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationStep' + type: + - array + - "null" + draftTriggers: + description: Triggers saved as a draft that have not yet been published. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' + type: + - array + - "null" + enabled: + description: Whether the automation is active and eligible for execution. + type: boolean + isDraft: + description: Whether this automation is in draft mode. Draft automations are not eligible for trigger-based execution. + type: boolean + triggers: + description: Triggers that determine when the automation runs. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTrigger' + type: + - array + - "null" + title: Create Automation Request + type: object + x-speakeasy-name-override: AutomationsCreateAutomationRequest + c1.api.automations.v1.CreateAutomationResponse: + description: The CreateAutomationResponse message. + properties: + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.Automation' + - type: "null" + webhookCapabilityUrl: + description: |- + One-time absolute webhook URL for capability URL authentication, shown once at creation time. + Contains the full URL including the embedded token (e.g. https://tenant.conductorone.com/api/v1/webhooks/incoming/{id}/t/{token}). + Populated only when the webhook trigger uses capability URL authentication. type: string - x-speakeasy-unknown-values: allow - stateUpdatedById: - description: The stateUpdatedById field. - readOnly: false + webhookHmacSecret: + description: |- + One-time HMAC shared secret, shown once at creation time. + Populated only when the webhook trigger uses HMAC authentication. type: string - suppressReason: - description: The suppressReason field. - readOnly: false + title: Create Automation Response + type: object + x-speakeasy-name-override: AutomationsCreateAutomationResponse + c1.api.automations.v1.CreateRevokeTasks: + description: The CreateRevokeTasks message. + properties: + appEntitlementRefs: + description: The appEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + appEntitlementRefsCel: + description: The appEntitlementRefsCel field. type: string - taskId: - description: The taskId field. - readOnly: false + excludedAppEntitlementRefs: + description: The excludedAppEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + excludedAppEntitlementRefsCel: + description: The excludedAppEntitlementRefsCel field. type: string - updatedAt: - format: date-time - readOnly: false + revokeAll: + description: The revokeAll field. + type: boolean + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdCel: + description: The userIdCel field. type: string - title: Finding + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create Revoke Tasks type: object - x-speakeasy-name-override: Finding - c1.api.finding.v1.FindingOwnerRef: + x-speakeasy-name-override: CreateRevokeTasks + c1.api.automations.v1.CreateRevokeTasksV2: description: | - The FindingOwnerRef message. + The CreateRevokeTasksV2 message. - This message contains a oneof named owner. Only a single field of the following list may be set at a time: - - identityUserId - - appOwnerAppId - - managerOfUserId - - userSetId + This message contains a oneof named user. Only a single field of the following list may be set at a time: + - userIdCel + - userRef + - useSubjectUser + + + This message contains a oneof named inclusion. Only a single field of the following list may be set at a time: + - inclusionList + - inclusionAll + - inclusionCriteria + - inclusionListCel + - inclusionAccessOnly + + + This message contains a oneof named exclusion. Only a single field of the following list may be set at a time: + - exclusionNone + - exclusionList + - exclusionCriteria + - exclusionListCel properties: - appOwnerAppId: - description: |- - The appOwnerAppId field. - This field is part of the `owner` oneof. - See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. - nullable: true - readOnly: false - type: string - identityUserId: - description: |- - The identityUserId field. - This field is part of the `owner` oneof. - See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. - nullable: true - readOnly: false - type: string - managerOfUserId: + exclusionCriteria: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionCriteria' + - type: "null" + exclusionList: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionList' + - type: "null" + exclusionListCel: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionListCel' + - type: "null" + exclusionNone: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementExclusionNone' + - type: "null" + inclusionAccessOnly: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAccessOnly' + - type: "null" + inclusionAll: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAll' + - type: "null" + inclusionCriteria: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionCriteria' + - type: "null" + inclusionList: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionList' + - type: "null" + inclusionListCel: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionListCel' + - type: "null" + useSubjectUser: description: |- - The managerOfUserId field. - This field is part of the `owner` oneof. - See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. - nullable: true - readOnly: false - type: string - userSetId: + The useSubjectUser field. + This field is part of the `user` oneof. + See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. + type: + - boolean + - "null" + userIdCel: description: |- - The userSetId field. - This field is part of the `owner` oneof. - See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. - nullable: true - readOnly: false - type: string - title: Finding Owner Ref + The userIdCel field. + This field is part of the `user` oneof. + See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. + type: + - string + - "null" + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create Revoke Tasks V 2 type: object - x-speakeasy-name-override: FindingOwnerRef - c1.api.finding.v1.FindingRef: - description: The FindingRef message. - properties: - id: - description: The ID of the finding. - readOnly: false - type: string - title: Finding Ref + x-speakeasy-name-override: CreateRevokeTasksV2 + c1.api.automations.v1.DeleteAutomationRequestInput: + description: The DeleteAutomationRequest message. + title: Delete Automation Request type: object - x-speakeasy-name-override: FindingRef - c1.api.finding.v1.FindingRiskFactor: - description: The FindingRiskFactor message. + x-speakeasy-name-override: AutomationsDeleteAutomationRequest + c1.api.automations.v1.DeleteAutomationResponse: + description: The DeleteAutomationResponse message. + title: Delete Automation Response + type: object + x-speakeasy-name-override: AutomationsDeleteAutomationResponse + c1.api.automations.v1.DisabledReasonCircuitBreaker: + description: |- + DisabledReasonCircuitBreaker carries the trip context when an automation + has been auto-disabled by its rate cap. Returned on the parent Automation + when read; not directly settable. properties: - description: - description: The description field. - readOnly: false - type: string - name: - description: The name field. - readOnly: false - type: string - severity: - description: The severity field. + observedCount: + description: Observed execution count in the period at trip time. + format: uint32 + type: integer + period: + description: Snapshot of the period at trip time. enum: - - FINDING_SEVERITY_UNSPECIFIED - - FINDING_SEVERITY_INFO - - FINDING_SEVERITY_LOW - - FINDING_SEVERITY_MEDIUM - - FINDING_SEVERITY_HIGH - - FINDING_SEVERITY_CRITICAL - readOnly: false + - CIRCUIT_BREAKER_PERIOD_UNSPECIFIED + - CIRCUIT_BREAKER_PERIOD_HOUR + - CIRCUIT_BREAKER_PERIOD_DAY + - CIRCUIT_BREAKER_PERIOD_WEEK + - CIRCUIT_BREAKER_PERIOD_MONTH type: string x-speakeasy-unknown-values: allow - weight: - description: The weight field. + threshold: + description: Snapshot of the threshold at trip time. format: uint32 - readOnly: false type: integer - title: Finding Risk Factor + trippedAt: + format: date-time + type: + - string + - "null" + title: Disabled Reason Circuit Breaker type: object - x-speakeasy-name-override: FindingRiskFactor - c1.api.finding.v1.FindingRiskScore: - description: The FindingRiskScore message. + x-speakeasy-name-override: DisabledReasonCircuitBreaker + c1.api.automations.v1.EntitlementExclusionCriteria: + description: The EntitlementExclusionCriteria message. properties: - originalScore: - description: The originalScore field. - format: uint32 - readOnly: false - type: integer - overrideByUserId: - description: The overrideByUserId field. - readOnly: false - type: string - overrideScore: - description: The overrideScore field. - format: uint32 - readOnly: false - type: integer - riskFactors: - description: The riskFactors field. + excludedAppIds: + description: The excludedAppIds field. items: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRiskFactor' - nullable: true - readOnly: false - type: array - score: - description: The score field. - format: uint32 - readOnly: false - type: integer - systemScore: - description: The systemScore field. - format: uint32 - readOnly: false - type: integer - title: Finding Risk Score + type: string + type: + - array + - "null" + excludedComplianceFrameworkIds: + description: The excludedComplianceFrameworkIds field. + items: + type: string + type: + - array + - "null" + excludedResourceTypeIds: + description: The excludedResourceTypeIds field. + items: + type: string + type: + - array + - "null" + excludedRiskLevelIds: + description: The excludedRiskLevelIds field. + items: + type: string + type: + - array + - "null" + title: Entitlement Exclusion Criteria type: object - x-speakeasy-name-override: FindingRiskScore - c1.api.finding.v1.FindingRoutingRule: - description: The FindingRoutingRule message. + x-speakeasy-name-override: EntitlementExclusionCriteria + c1.api.automations.v1.EntitlementExclusionList: + description: The EntitlementExclusionList message. properties: - action: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRuleAction' - appId: - description: The appId field. - readOnly: false - type: string - condition: - description: The condition field. - readOnly: false - type: string - createdAt: - format: date-time - readOnly: false - type: string - description: - description: The description field. - readOnly: false - type: string - displayName: - description: The displayName field. - readOnly: false - type: string - enabled: - description: The enabled field. - readOnly: false - type: boolean - id: - description: The id field. - readOnly: false - type: string - priority: - description: The priority field. - format: int32 - readOnly: false - type: integer - templateId: - description: The templateId field. - readOnly: false - type: string - updatedAt: - format: date-time - readOnly: false - type: string - title: Finding Routing Rule + excludedAppEntitlementRefs: + description: The excludedAppEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Entitlement Exclusion List type: object - x-speakeasy-name-override: FindingRoutingRule - c1.api.finding.v1.FindingRoutingRuleAction: - description: | - The FindingRoutingRuleAction message. - - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - createTask - - suppress - - notify + x-speakeasy-name-override: EntitlementExclusionList + c1.api.automations.v1.EntitlementExclusionListCel: + description: The EntitlementExclusionListCel message. properties: - createTask: - $ref: '#/components/schemas/c1.api.finding.v1.CreateTaskAction' - notify: - $ref: '#/components/schemas/c1.api.finding.v1.NotifyAction' - suppress: - $ref: '#/components/schemas/c1.api.finding.v1.SuppressRoutingAction' - title: Finding Routing Rule Action + excludedAppEntitlementRefsCel: + description: The excludedAppEntitlementRefsCel field. + type: string + title: Entitlement Exclusion List Cel type: object - x-speakeasy-name-override: FindingRoutingRuleAction - c1.api.finding.v1.FindingSearchRequest: - description: The FindingSearchRequest message. + x-speakeasy-name-override: EntitlementExclusionListCel + c1.api.automations.v1.EntitlementExclusionNone: + description: The EntitlementExclusionNone message. + title: Entitlement Exclusion None + type: object + x-speakeasy-name-override: EntitlementExclusionNone + c1.api.automations.v1.EntitlementInclusionAccessOnly: + description: |- + EntitlementInclusionAccessOnly resolves to the system-managed access + entitlement on every app the subject user has an AppUser on. Use this to + deprovision app accounts without fanning out to every group, role, or + permission inside each app — produces at most one revoke ticket per app. + title: Entitlement Inclusion Access Only + type: object + x-speakeasy-name-override: EntitlementInclusionAccessOnly + c1.api.automations.v1.EntitlementInclusionAll: + description: The EntitlementInclusionAll message. + title: Entitlement Inclusion All + type: object + x-speakeasy-name-override: EntitlementInclusionAll + c1.api.automations.v1.EntitlementInclusionCriteria: + description: The EntitlementInclusionCriteria message. properties: appIds: - description: Filter by app IDs (OR within field). + description: The appIds field. items: type: string - nullable: true - readOnly: false - type: array - appUserIds: - description: |- - Filter by app user IDs (OR within field). Matches findings whose - target.app_user_target.app_user_id is in this list. + type: + - array + - "null" + complianceFrameworkIds: + description: The complianceFrameworkIds field. items: type: string - nullable: true - readOnly: false - type: array - findingTypes: - description: Filter by finding type discriminators (OR within field). + type: + - array + - "null" + resourceTypeIds: + description: The resourceTypeIds field. items: type: string - nullable: true - readOnly: false - type: array - pageSize: - description: Maximum number of findings to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous response. - readOnly: false - type: string - query: - description: Free text search query. - readOnly: false - type: string - severities: - description: Filter by severities (OR within field). + type: + - array + - "null" + riskLevelIds: + description: The riskLevelIds field. items: - enum: - - FINDING_SEVERITY_UNSPECIFIED - - FINDING_SEVERITY_INFO - - FINDING_SEVERITY_LOW - - FINDING_SEVERITY_MEDIUM - - FINDING_SEVERITY_HIGH - - FINDING_SEVERITY_CRITICAL type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - states: - description: Filter by states (OR within field). + type: + - array + - "null" + title: Entitlement Inclusion Criteria + type: object + x-speakeasy-name-override: EntitlementInclusionCriteria + c1.api.automations.v1.EntitlementInclusionList: + description: The EntitlementInclusionList message. + properties: + appEntitlementRefs: + description: The appEntitlementRefs field. items: - enum: - - FINDING_STATE_UNSPECIFIED - - FINDING_STATE_OPEN - - FINDING_STATE_IN_PROGRESS - - FINDING_STATE_RESOLVED - - FINDING_STATE_SNOOZED - - FINDING_STATE_RISK_ACCEPTED - - FINDING_STATE_SUPPRESSED - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Finding Search Request + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Entitlement Inclusion List type: object - x-speakeasy-name-override: FindingSearchRequest - c1.api.finding.v1.FindingSearchResponse: - description: The FindingSearchResponse message. + x-speakeasy-name-override: EntitlementInclusionList + c1.api.automations.v1.EntitlementInclusionListCel: + description: The EntitlementInclusionListCel message. properties: - list: - description: The list field. + appEntitlementRefsCel: + description: The appEntitlementRefsCel field. + type: string + title: Entitlement Inclusion List Cel + type: object + x-speakeasy-name-override: EntitlementInclusionListCel + c1.api.automations.v1.EvaluateExpressions: + description: The EvaluateExpressions message. + properties: + expressions: + description: The expressions field. items: - $ref: '#/components/schemas/c1.api.finding.v1.Finding' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + $ref: '#/components/schemas/c1.api.automations.v1.Expression' + type: + - array + - "null" + title: Evaluate Expressions + type: object + x-speakeasy-name-override: EvaluateExpressions + c1.api.automations.v1.ExecuteAutomationRequestInput: + description: The ExecuteAutomationRequest message. + properties: + context: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' + - type: "null" + title: Execute Automation Request + type: object + x-speakeasy-name-override: ExecuteAutomationRequest + c1.api.automations.v1.ExecuteAutomationResponse: + description: The ExecuteAutomationResponse message. + properties: + executionId: + description: The unique identifier of the newly created execution. + format: int64 type: string - title: Finding Search Response + title: Execute Automation Response type: object - x-speakeasy-name-override: FindingSearchResponse - c1.api.finding.v1.GetFindingResponse: - description: The GetFindingResponse message. + x-speakeasy-name-override: ExecuteAutomationResponse + c1.api.automations.v1.Expression: + description: The Expression message. + properties: + expressionCel: + description: The expressionCel field. + type: string + isSecret: + description: The isSecret field. + type: boolean + key: + description: The key field. + type: string + title: Expression + type: object + x-speakeasy-name-override: Expression + c1.api.automations.v1.GeneratePassword: + description: The GeneratePassword message. + properties: + passwordPolicyId: + deprecated: true + description: 'Deprecated: password policy ID lookup is no longer used.' + type: string + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GeneratePasswordPolicy' + - type: "null" + title: Generate Password + type: object + x-speakeasy-name-override: GeneratePassword + c1.api.automations.v1.GeneratePasswordPolicy: + description: | + GeneratePasswordPolicy defines inline password generation rules. + + This message contains a oneof named character_rules. Only a single field of the following list may be set at a time: + - noRestrictions + - customCharacters + - excludedCharacters + properties: + customCharacters: + description: |- + The customCharacters field. + This field is part of the `character_rules` oneof. + See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. + type: + - string + - "null" + excludedCharacters: + description: |- + The excludedCharacters field. + This field is part of the `character_rules` oneof. + See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. + type: + - string + - "null" + maxCharacterCount: + description: The maxCharacterCount field. + format: int32 + type: integer + minCharacterCount: + description: The minCharacterCount field. + format: int32 + type: integer + noRestrictions: + description: |- + The noRestrictions field. + This field is part of the `character_rules` oneof. + See the documentation for `c1.api.automations.v1.GeneratePasswordPolicy` for more details. + type: + - boolean + - "null" + requireLowercase: + description: The requireLowercase field. + type: boolean + requireNumbers: + description: The requireNumbers field. + type: boolean + requireSpecialCharacters: + description: The requireSpecialCharacters field. + type: boolean + requireUppercase: + description: The requireUppercase field. + type: boolean + title: Generate Password Policy + type: object + x-speakeasy-name-override: GeneratePasswordPolicy + c1.api.automations.v1.GetAutomationExecutionResponse: + description: The GetAutomationExecutionResponse message. properties: + automationExecution: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' + - type: "null" expanded: - description: The expanded field. + description: Related objects requested via the expand mask. items: additionalProperties: true description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. @@ -12460,15553 +14686,19498 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - finding: - $ref: '#/components/schemas/c1.api.finding.v1.Finding' - title: Get Finding Response + type: + - array + - "null" + view: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' + - type: "null" + title: Get Automation Execution Response type: object - x-speakeasy-name-override: GetFindingResponse - c1.api.finding.v1.GetFindingRoutingRuleResponse: - description: The GetFindingRoutingRuleResponse message. + x-speakeasy-name-override: GetAutomationExecutionResponse + c1.api.automations.v1.GetAutomationResponse: + description: The GetAutomationResponse message. properties: - routingRule: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - title: Get Finding Routing Rule Response + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.Automation' + - type: "null" + title: Get Automation Response type: object - x-speakeasy-name-override: GetFindingRoutingRuleResponse - c1.api.finding.v1.IdentityUserTarget: - description: The IdentityUserTarget message. - nullable: true + x-speakeasy-name-override: GetAutomationResponse + c1.api.automations.v1.GrantDeletedTrigger: + description: The GrantDeletedTrigger message. properties: - identityUserId: - description: The identityUserId field. - readOnly: false - type: string - title: Identity User Target + grantTriggerFilter: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter' + - type: "null" + title: Grant Deleted Trigger type: object - x-speakeasy-name-override: IdentityUserTarget - c1.api.finding.v1.ListFindingRoutingRulesResponse: - description: The ListFindingRoutingRulesResponse message. + x-speakeasy-name-override: GrantDeletedTrigger + c1.api.automations.v1.GrantEntitlementExclusionCriteria: + description: The GrantEntitlementExclusionCriteria message. properties: - list: - description: The list field. + excludedAppIds: + description: The excludedAppIds field. items: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + type: string + type: + - array + - "null" + excludedComplianceFrameworkIds: + description: The excludedComplianceFrameworkIds field. + items: + type: string + type: + - array + - "null" + excludedRiskLevelIds: + description: The excludedRiskLevelIds field. + items: + type: string + type: + - array + - "null" + title: Grant Entitlement Exclusion Criteria + type: object + x-speakeasy-name-override: GrantEntitlementExclusionCriteria + c1.api.automations.v1.GrantEntitlementExclusionList: + description: The GrantEntitlementExclusionList message. + properties: + excludedAppEntitlementRefs: + description: The excludedAppEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Grant Entitlement Exclusion List + type: object + x-speakeasy-name-override: GrantEntitlementExclusionList + c1.api.automations.v1.GrantEntitlementExclusionListCel: + description: The GrantEntitlementExclusionListCel message. + properties: + excludedAppEntitlementRefsCel: + description: The excludedAppEntitlementRefsCel field. type: string - title: List Finding Routing Rules Response + title: Grant Entitlement Exclusion List Cel type: object - x-speakeasy-name-override: ListFindingRoutingRulesResponse - c1.api.finding.v1.NotifyAction: - description: The NotifyAction message. - nullable: true - title: Notify Action + x-speakeasy-name-override: GrantEntitlementExclusionListCel + c1.api.automations.v1.GrantEntitlementExclusionNone: + description: The GrantEntitlementExclusionNone message. + title: Grant Entitlement Exclusion None type: object - x-speakeasy-name-override: NotifyAction - c1.api.finding.v1.ReopenAction: - description: ReopenAction parameters for UpdateFindingState. - nullable: true - title: Reopen Action + x-speakeasy-name-override: GrantEntitlementExclusionNone + c1.api.automations.v1.GrantEntitlementInclusionCriteria: + description: The GrantEntitlementInclusionCriteria message. + properties: + appIds: + description: The appIds field. + items: + type: string + type: + - array + - "null" + complianceFrameworkIds: + description: The complianceFrameworkIds field. + items: + type: string + type: + - array + - "null" + riskLevelIds: + description: The riskLevelIds field. + items: + type: string + type: + - array + - "null" + title: Grant Entitlement Inclusion Criteria type: object - x-speakeasy-name-override: ReopenAction - c1.api.finding.v1.ResolveAction: - description: ResolveAction parameters for UpdateFindingState (manual resolve). - nullable: true + x-speakeasy-name-override: GrantEntitlementInclusionCriteria + c1.api.automations.v1.GrantEntitlementInclusionList: + description: The GrantEntitlementInclusionList message. properties: - reason: - description: The reason field. - readOnly: false + appEntitlementRefs: + description: The appEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Grant Entitlement Inclusion List + type: object + x-speakeasy-name-override: GrantEntitlementInclusionList + c1.api.automations.v1.GrantEntitlementInclusionListCel: + description: The GrantEntitlementInclusionListCel message. + properties: + appEntitlementRefsCel: + description: The appEntitlementRefsCel field. type: string - title: Resolve Action + title: Grant Entitlement Inclusion List Cel type: object - x-speakeasy-name-override: ResolveAction - c1.api.finding.v1.ServiceAccountMisclassificationEvidence: - description: The ServiceAccountMisclassificationEvidence message. - nullable: true + x-speakeasy-name-override: GrantEntitlementInclusionListCel + c1.api.automations.v1.GrantEntitlements: + description: | + The GrantEntitlements message. + + This message contains a oneof named inclusion. Only a single field of the following list may be set at a time: + - inclusionList + - inclusionCriteria + - inclusionListCel + + + This message contains a oneof named exclusion. Only a single field of the following list may be set at a time: + - exclusionNone + - exclusionList + - exclusionCriteria + - exclusionListCel properties: - detectionReason: - description: The detectionReason field. - readOnly: false + exclusionCriteria: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionCriteria' + - type: "null" + exclusionList: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionList' + - type: "null" + exclusionListCel: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionListCel' + - type: "null" + exclusionNone: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementExclusionNone' + - type: "null" + inclusionCriteria: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionCriteria' + - type: "null" + inclusionList: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionList' + - type: "null" + inclusionListCel: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantEntitlementInclusionListCel' + - type: "null" + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdCel: + description: The userIdCel field. type: string - title: Service Account Misclassification Evidence + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Grant Entitlements type: object - x-speakeasy-name-override: ServiceAccountMisclassificationEvidence - c1.api.finding.v1.ServiceAccountMisclassificationType: - description: The ServiceAccountMisclassificationType message. - nullable: true + x-speakeasy-name-override: GrantEntitlements + c1.api.automations.v1.GrantFoundTrigger: + description: The GrantFoundTrigger message. properties: - currentAccountType: - description: The currentAccountType field. + grantTriggerFilter: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter' + - type: "null" + title: Grant Found Trigger + type: object + x-speakeasy-name-override: GrantFoundTrigger + c1.api.automations.v1.GrantTriggerFilter: + description: | + The GrantTriggerFilter message. + + This message contains a oneof named entitlement_inclusion. Only a single field of the following list may be set at a time: + - inclusionList + - inclusionAll + - inclusionCriteria + - inclusionListCel + properties: + accountFilter: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter.AccountFilter' + - type: "null" + grantFilter: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.GrantTriggerFilter.GrantFilter' + - type: "null" + inclusionAll: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionAll' + - type: "null" + inclusionCriteria: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionCriteria' + - type: "null" + inclusionList: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionList' + - type: "null" + inclusionListCel: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.EntitlementInclusionListCel' + - type: "null" + title: Grant Trigger Filter + type: object + x-speakeasy-name-override: GrantTriggerFilter + c1.api.automations.v1.GrantTriggerFilter.AccountFilter: + description: The AccountFilter message. + properties: + accountType: + description: The accountType field. enum: - APP_USER_TYPE_UNSPECIFIED - APP_USER_TYPE_USER - APP_USER_TYPE_SERVICE_ACCOUNT - APP_USER_TYPE_SYSTEM_ACCOUNT - readOnly: false type: string x-speakeasy-unknown-values: allow - detectedAccountType: - description: The detectedAccountType field. + title: Account Filter + type: object + x-speakeasy-name-override: AccountFilter + c1.api.automations.v1.GrantTriggerFilter.GrantFilter: + description: The GrantFilter message. + properties: + grantFilterType: + description: The grantFilterType field. enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - readOnly: false + - GRANT_FILTER_TYPE_UNSPECIFIED + - GRANT_FILTER_TYPE_PERMANENT + - GRANT_FILTER_TYPE_TEMPORARY type: string x-speakeasy-unknown-values: allow - title: Service Account Misclassification Type - type: object - x-speakeasy-name-override: ServiceAccountMisclassificationType - c1.api.finding.v1.SimilarUsernameMatchEvidence: - description: The SimilarUsernameMatchEvidence message. - nullable: true - properties: - appUsername: - description: The appUsername field. - readOnly: false + grantJustificationType: + description: The grantJustificationType field. + enum: + - GRANT_JUSTIFICATION_TYPE_UNSPECIFIED + - GRANT_JUSTIFICATION_TYPE_ALL + - GRANT_JUSTIFICATION_TYPE_CONDUCTOR_ONE + - GRANT_JUSTIFICATION_TYPE_DIRECT type: string - identityUsername: - description: The identityUsername field. - readOnly: false + x-speakeasy-unknown-values: allow + grantSourceFilter: + description: The grantSourceFilter field. + enum: + - GRANT_SOURCE_FILTER_UNSPECIFIED + - GRANT_SOURCE_FILTER_DIRECT + - GRANT_SOURCE_FILTER_INHERITED type: string - similarityScore: - description: The similarityScore field. - readOnly: false - type: number - title: Similar Username Match Evidence + x-speakeasy-unknown-values: allow + title: Grant Filter type: object - x-speakeasy-name-override: SimilarUsernameMatchEvidence - c1.api.finding.v1.SimilarUsernameMatchType: - description: The SimilarUsernameMatchType message. - nullable: true + x-speakeasy-name-override: GrantFilter + c1.api.automations.v1.ListAutomationExecutionsResponse: + description: The ListAutomationExecutionsResponse message. properties: - proposedIdentityUserId: - description: The proposedIdentityUserId field. - readOnly: false + automationExecutions: + description: The page of automation executions. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecution' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. type: string - title: Similar Username Match Type + title: List Automation Executions Response type: object - x-speakeasy-name-override: SimilarUsernameMatchType - c1.api.finding.v1.SnoozeAction: - description: SnoozeAction parameters for UpdateFindingState. - nullable: true + x-speakeasy-name-override: ListAutomationExecutionsResponse + c1.api.automations.v1.ListAutomationsResponse: + description: The ListAutomationsResponse message. properties: - reason: - description: The reason field. - readOnly: false - type: string - snoozeUntil: - format: date-time - readOnly: false + list: + description: The page of automations. + items: + $ref: '#/components/schemas/c1.api.automations.v1.Automation' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. type: string - title: Snooze Action + title: List Automations Response type: object - x-speakeasy-name-override: SnoozeAction - c1.api.finding.v1.SuppressRoutingAction: - description: The SuppressRoutingAction message. - nullable: true + x-speakeasy-name-override: ListAutomationsResponse + c1.api.automations.v1.ReassignAction: + description: | + The ReassignAction message. + + This message contains a oneof named assignee_user_identifier. Only a single field of the following list may be set at a time: + - assigneeUserIdCel + - assigneeUserRef + + + This message contains a oneof named subject_user_identifier. Only a single field of the following list may be set at a time: + - subjectUserIdCel + - subjectUserRef properties: - reason: - description: The reason field. - readOnly: false - type: string - title: Suppress Routing Action + assigneeUserIdCel: + description: |- + The assigneeUserIdCel field. + This field is part of the `assignee_user_identifier` oneof. + See the documentation for `c1.api.automations.v1.ReassignAction` for more details. + type: + - string + - "null" + assigneeUserRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + subjectUserIdCel: + description: |- + The subjectUserIdCel field. + This field is part of the `subject_user_identifier` oneof. + See the documentation for `c1.api.automations.v1.ReassignAction` for more details. + type: + - string + - "null" + subjectUserRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + title: Reassign Action type: object - x-speakeasy-name-override: SuppressRoutingAction - c1.api.finding.v1.SuppressStateAction: - description: SuppressStateAction parameters for UpdateFindingState. - nullable: true + x-speakeasy-name-override: ReassignAction + c1.api.automations.v1.RemoveFromDelegation: + description: | + RemoveFromDelegation: find all users that have the target user as their delegated user, and modify the delegation. + + This message contains a oneof named replacement_user. Only a single field of the following list may be set at a time: + - replacementUserIdCel + - replacementUserRef properties: - reason: - description: The reason field. - readOnly: false + replacementUserIdCel: + description: |- + The user who will replace the target user's delegation + This field is part of the `replacement_user` oneof. + See the documentation for `c1.api.automations.v1.RemoveFromDelegation` for more details. + type: + - string + - "null" + replacementUserRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdCel: + description: The userIdCel field. type: string - title: Suppress State Action - type: object - x-speakeasy-name-override: SuppressStateAction - c1.api.finding.v1.UnsuppressAction: - deprecated: true - description: UnsuppressAction parameters for UpdateFindingState. - nullable: true - title: Unsuppress Action + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Remove From Delegation type: object - x-speakeasy-name-override: UnsuppressAction - c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput: - description: The UpdateFindingRoutingRuleRequest message. + x-speakeasy-name-override: RemoveFromDelegation + c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput: + description: The ResolvePausedAutomationExecutionsRequest message. properties: - routingRule: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - title: Update Finding Routing Rule Request + decision: + description: Whether to run or cancel the paused executions. + enum: + - PAUSED_EXECUTION_DECISION_UNSPECIFIED + - PAUSED_EXECUTION_DECISION_RUN + - PAUSED_EXECUTION_DECISION_CANCEL + type: string + x-speakeasy-unknown-values: allow + reason: + description: |- + Optional human-readable reason for the resolution decision. Stored on + the audit row (paused_run / paused_cancelled events) for post-mortem + and compliance use. Surfaced in the FE as a required field on CANCEL + so admins capture why bulk-cancellation happened. Up to 1024 bytes. + type: string + title: Resolve Paused Automation Executions Request type: object - x-speakeasy-name-override: UpdateFindingRoutingRuleRequest - c1.api.finding.v1.UpdateFindingRoutingRuleResponse: - description: The UpdateFindingRoutingRuleResponse message. + x-speakeasy-name-override: ResolvePausedAutomationExecutionsRequest + c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse: + description: The ResolvePausedAutomationExecutionsResponse message. properties: - routingRule: - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' - title: Update Finding Routing Rule Response + bulkActionId: + description: |- + The bulk action ID created to resolve the paused executions. Track + progress via the BulkAction API. + type: string + erroredCount: + deprecated: true + description: 'Deprecated: see paused_count.' + format: uint32 + type: integer + pausedCount: + deprecated: true + description: |- + Deprecated: previously returned inline resolution counts. Now returns + the bulk action ID for async tracking. + format: uint32 + type: integer + title: Resolve Paused Automation Executions Response type: object - x-speakeasy-name-override: UpdateFindingRoutingRuleResponse - c1.api.finding.v1.UpdateFindingStateRequestInput: + x-speakeasy-name-override: ResolvePausedAutomationExecutionsResponse + c1.api.automations.v1.RunAutomation: description: | - The UpdateFindingStateRequest message. + RunAutomation: kick off the execution of an automation template. - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - snooze - - suppress - - acceptRisk - - unsuppress - - resolve - - reopen + This message contains a oneof named automation_template. Only a single field of the following list may be set at a time: + - automationTemplateRef + - automationTemplateIdCel properties: - acceptRisk: - $ref: '#/components/schemas/c1.api.finding.v1.AcceptRiskAction' - reopen: - $ref: '#/components/schemas/c1.api.finding.v1.ReopenAction' - resolve: - $ref: '#/components/schemas/c1.api.finding.v1.ResolveAction' - snooze: - $ref: '#/components/schemas/c1.api.finding.v1.SnoozeAction' - suppress: - $ref: '#/components/schemas/c1.api.finding.v1.SuppressStateAction' - unsuppress: - $ref: '#/components/schemas/c1.api.finding.v1.UnsuppressAction' - title: Update Finding State Request + automationTemplateIdCel: + description: |- + The automationTemplateIdCel field. + This field is part of the `automation_template` oneof. + See the documentation for `c1.api.automations.v1.RunAutomation` for more details. + type: + - string + - "null" + automationTemplateRef: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateRef' + - type: "null" + context: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationContext' + - type: "null" + title: Run Automation type: object - x-speakeasy-name-override: UpdateFindingStateRequest - c1.api.finding.v1.UpdateFindingStateResponse: - description: The UpdateFindingStateResponse message. + x-speakeasy-name-override: RunAutomation + c1.api.automations.v1.RunDelayed: + description: The RunDelayed message. properties: - finding: - $ref: '#/components/schemas/c1.api.finding.v1.Finding' - title: Update Finding State Response + coldStartDelayDays: + description: The coldStartDelayDays field. + format: uint32 + type: integer + required: + - coldStartDelayDays + title: Run Delayed type: object - x-speakeasy-name-override: UpdateFindingStateResponse - c1.api.form.v1.AdminProviderConfig: - description: The AdminProviderConfig message. - nullable: true - properties: - defaultValueCel: - description: The defaultValueCel field. - readOnly: false - type: string - showToUser: - description: The showToUser field. - readOnly: false - type: boolean - title: Admin Provider Config + x-speakeasy-name-override: RunDelayed + c1.api.automations.v1.RunImmediately: + description: No fields needed; this just indicates the trigger should run immediately + title: Run Immediately type: object - x-speakeasy-name-override: AdminProviderConfig - c1.api.form.v1.AppResourceFilter: - description: The AppResourceFilter message. - nullable: true + x-speakeasy-name-override: RunImmediately + c1.api.automations.v1.ScheduleTrigger: + description: The ScheduleTrigger message. properties: - appId: - description: The appId field. - readOnly: false + advanced: + description: The advanced field. + type: boolean + condition: + description: The condition field. type: string - resourceTypeId: - description: The resourceTypeId field. - readOnly: false + cronSpec: + description: The cronSpec field. type: string - title: App Resource Filter + skipIfTrueCel: + deprecated: true + description: The skipIfTrueCel field. + type: string + start: + format: date-time + type: + - string + - "null" + timezone: + description: The timezone field. + type: string + title: Schedule Trigger type: object - x-speakeasy-name-override: AppResourceFilter - c1.api.form.v1.AppUserFilter: - description: The AppUserFilter message. - nullable: true + x-speakeasy-name-override: ScheduleTrigger + c1.api.automations.v1.ScheduleTriggerAppUser: + description: The ScheduleTriggerAppUser message. properties: appId: description: The appId field. - readOnly: false type: string - title: App User Filter - type: object - x-speakeasy-name-override: AppUserFilter - c1.api.form.v1.AtLeastOne: - description: The AtLeastOne message. - nullable: true - title: At Least One - type: object - x-speakeasy-name-override: AtLeastOne - c1.api.form.v1.BoolField: - description: | - The BoolField message. - - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - checkboxField - - toggleField - nullable: true - properties: - checkboxField: - $ref: '#/components/schemas/c1.api.form.v1.CheckboxField' - defaultValue: - description: The defaultValue field. - readOnly: false - type: boolean - rules: - $ref: '#/components/schemas/validate.BoolRules' - toggleField: - $ref: '#/components/schemas/c1.api.form.v1.ToggleField' - title: Bool Field - type: object - x-speakeasy-name-override: BoolField - c1.api.form.v1.C1UserFilter: - description: |- - C1UserFilter is used to configure a picker for selecting ConductorOne users. - This is distinct from AppUserFilter which selects accounts within a connected app. - nullable: true - title: C 1 User Filter - type: object - x-speakeasy-name-override: C1UserFilter - c1.api.form.v1.CheckboxField: - description: The CheckboxField message. - nullable: true - title: Checkbox Field - type: object - x-speakeasy-name-override: CheckboxField - c1.api.form.v1.ChipsField: - description: The ChipsField message. - nullable: true - title: Chips Field - type: object - x-speakeasy-name-override: ChipsField - c1.api.form.v1.DependentOn: - description: |- - DependentOn means the fields in field_names are only valid if all fields - in dependency_field_names are also present - nullable: true - properties: - dependencyFieldNames: - description: The fields that must be present for the primary field_names to be valid - items: - type: string - nullable: true - readOnly: false - type: array - title: Dependent On - type: object - x-speakeasy-name-override: DependentOn - c1.api.form.v1.Field: - description: | - A field is a single input meant to collect a piece of data from a user - - This message contains a oneof named type. Only a single field of the following list may be set at a time: - - stringField - - boolField - - stringSliceField - - int64Field - - fileField - - oauth2Field - - stringMapField - - - This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: - - userConfig - - adminConfig - - sharedConfig - properties: - adminConfig: - $ref: '#/components/schemas/c1.api.form.v1.AdminProviderConfig' - boolField: - $ref: '#/components/schemas/c1.api.form.v1.BoolField' - description: - description: The description field. - readOnly: false + condition: + description: The condition field. type: string - displayName: - description: The displayName field. - readOnly: false + cronSpec: + description: The cronSpec field. type: string - fileField: - $ref: '#/components/schemas/c1.api.form.v1.FileField' - int64Field: - $ref: '#/components/schemas/c1.api.form.v1.Int64Field' - name: - description: The name field. - readOnly: false + start: + format: date-time + type: + - string + - "null" + timezone: + description: The timezone field. type: string - oauth2Field: - $ref: '#/components/schemas/c1.api.form.v1.Oauth2Field' - required: - description: The required field. - readOnly: false - type: boolean - sharedConfig: - $ref: '#/components/schemas/c1.api.form.v1.SharedProviderConfig' - stringField: - $ref: '#/components/schemas/c1.api.form.v1.StringField' - stringMapField: - $ref: '#/components/schemas/c1.api.form.v1.StringMapField' - stringSliceField: - $ref: '#/components/schemas/c1.api.form.v1.StringSliceField' - userConfig: - $ref: '#/components/schemas/c1.api.form.v1.UserProviderConfig' - title: Field + title: Schedule Trigger App User type: object - x-speakeasy-name-override: FormField - c1.api.form.v1.FieldGroup: - description: The FieldGroup message. + x-speakeasy-name-override: ScheduleTriggerAppUser + c1.api.automations.v1.ScheduleTriggerNoUser: + description: |- + ScheduleTriggerNoUser fires on a cron schedule with no subject user (e.g. reports, syncs, orchestration). + Minimum cron interval is enforced at 1 hour in validation. properties: - default: - description: The default field. - readOnly: false + advanced: + description: The advanced field. type: boolean - displayName: - description: The displayName field. - readOnly: false - type: string - fields: - description: The fields field. - items: - type: string - nullable: true - readOnly: false - type: array - helpText: - description: The helpText field. - readOnly: false + cronSpec: + description: The cronSpec field. type: string - name: - description: The name field. - readOnly: false + start: + format: date-time + type: + - string + - "null" + timezone: + description: The timezone field. type: string - title: Field Group + title: Schedule Trigger No User type: object - x-speakeasy-name-override: FormFieldGroup - c1.api.form.v1.FieldRelationship: - description: | - FieldRelationships can be used during form validation, or they can represent - information that is necessary to when it comes to visually rendering the form - - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - requiredTogether - - atLeastOne - - mutuallyExclusive - - dependentOn + x-speakeasy-name-override: ScheduleTriggerNoUser + c1.api.automations.v1.SearchAllAutomationExecutionsRequest: + description: The SearchAllAutomationExecutionsRequest message. properties: - atLeastOne: - $ref: '#/components/schemas/c1.api.form.v1.AtLeastOne' - dependentOn: - $ref: '#/components/schemas/c1.api.form.v1.DependentOn' - fieldNames: - description: The names of the fields that share this relationship + appIds: + description: Filter to executions associated with one or more apps. items: type: string - nullable: true - readOnly: false - type: array - mutuallyExclusive: - $ref: '#/components/schemas/c1.api.form.v1.MutuallyExclusive' - requiredTogether: - $ref: '#/components/schemas/c1.api.form.v1.RequiredTogether' - title: Field Relationship - type: object - x-speakeasy-name-override: FieldRelationship - c1.api.form.v1.FileField: - description: | - The FileField message. - - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - fileInputField - nullable: true - properties: - acceptedFileTypes: - description: The acceptedFileTypes field. + type: + - array + - "null" + automationTemplateIds: + description: Filter to one or more specific automation templates. items: type: string - nullable: true - readOnly: false - type: array - fileInputField: - $ref: '#/components/schemas/c1.api.form.v1.FileInputField' - maxFileSize: - description: The maxFileSize field. - format: int64 - nullable: true - readOnly: false + type: + - array + - "null" + executionStates: + description: Filter by execution state (e.g. DONE, ERROR). + items: + enum: + - AUTOMATION_EXECUTION_STATE_UNSPECIFIED + - AUTOMATION_EXECUTION_STATE_PENDING + - AUTOMATION_EXECUTION_STATE_CREATING + - AUTOMATION_EXECUTION_STATE_GET_STEP + - AUTOMATION_EXECUTION_STATE_PROCESS_STEP + - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP + - AUTOMATION_EXECUTION_STATE_DONE + - AUTOMATION_EXECUTION_STATE_ERROR + - AUTOMATION_EXECUTION_STATE_TERMINATE + - AUTOMATION_EXECUTION_STATE_WAITING + - AUTOMATION_EXECUTION_STATE_PAUSED_BY_CIRCUIT_BREAKER + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionExpandMask' + - type: "null" + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous SearchAllAutomationExecutionsResponse. type: string - title: File Field - type: object - x-speakeasy-name-override: FileField - c1.api.form.v1.FileInputField: - description: The FileInputField message. - nullable: true - title: File Input Field + subjectUserIds: + description: Filter to executions where one or more C1 users are subjects. + items: + type: string + type: + - array + - "null" + title: Search All Automation Executions Request type: object - x-speakeasy-name-override: FileInputField - c1.api.form.v1.Form: - description: A form is a collection of fields to be filled out by a user + x-speakeasy-name-override: SearchAllAutomationExecutionsRequest + c1.api.automations.v1.SearchAllAutomationExecutionsResponse: + description: The SearchAllAutomationExecutionsResponse message. properties: - description: - description: The description field. - readOnly: false - type: string - displayName: - description: The displayName field. - readOnly: false - type: string - fieldGroups: - description: The fieldGroups field. - items: - $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' - nullable: true - readOnly: false - type: array - fieldRelationships: - description: The fieldRelationships field. + expanded: + description: Related objects requested via the expand mask. items: - $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' - nullable: true - readOnly: false - type: array - fields: - description: The fields field. + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The page of execution views matching the search criteria. items: - $ref: '#/components/schemas/c1.api.form.v1.Field' - nullable: true - readOnly: false - type: array - id: - description: The id field. - readOnly: false + $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. type: string - title: Form + title: Search All Automation Executions Response type: object - x-speakeasy-entity: Request_Schema - x-speakeasy-name-override: RequestSchemaForm - c1.api.form.v1.Int64Field: - description: | - The Int64Field message. - - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - numberField - nullable: true + x-speakeasy-name-override: SearchAllAutomationExecutionsResponse + c1.api.automations.v1.SearchAutomationExecutionsRequest: + description: The SearchAutomationExecutionsRequest message. properties: - defaultValue: - description: The defaultValue field. + automationTemplateId: + description: Filter results to executions of this automation template. + type: string + executionId: + description: Filter results to a specific execution by its numeric identifier. format: int64 - nullable: true - readOnly: false type: string - numberField: - $ref: '#/components/schemas/c1.api.form.v1.NumberField' - placeholder: - description: The placeholder field. - readOnly: false + executionStepStates: + description: Filter results to executions in any of the specified states. + items: + enum: + - AUTOMATION_EXECUTION_STATE_UNSPECIFIED + - AUTOMATION_EXECUTION_STATE_PENDING + - AUTOMATION_EXECUTION_STATE_CREATING + - AUTOMATION_EXECUTION_STATE_GET_STEP + - AUTOMATION_EXECUTION_STATE_PROCESS_STEP + - AUTOMATION_EXECUTION_STATE_COMPLETE_STEP + - AUTOMATION_EXECUTION_STATE_DONE + - AUTOMATION_EXECUTION_STATE_ERROR + - AUTOMATION_EXECUTION_STATE_TERMINATE + - AUTOMATION_EXECUTION_STATE_WAITING + - AUTOMATION_EXECUTION_STATE_PAUSED_BY_CIRCUIT_BREAKER + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionExpandMask' + - type: "null" + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous SearchAutomationExecutionsResponse. type: string - rules: - $ref: '#/components/schemas/validate.Int64Rules' - title: Int 64 Field - type: object - x-speakeasy-name-override: Int64Field - c1.api.form.v1.MutuallyExclusive: - description: The MutuallyExclusive message. - nullable: true - title: Mutually Exclusive + query: + description: Free-text search query to filter executions. + type: string + refs: + description: Restrict results to specific execution references. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionRef' + type: + - array + - "null" + title: Search Automation Executions Request type: object - x-speakeasy-name-override: MutuallyExclusive - c1.api.form.v1.NumberField: - description: The NumberField message. - nullable: true + x-speakeasy-name-override: SearchAutomationExecutionsRequest + c1.api.automations.v1.SearchAutomationExecutionsResponse: + description: The SearchAutomationExecutionsResponse message. properties: - maxValue: - description: The maxValue field. - format: int64 - readOnly: false + expanded: + description: Related objects requested via the expand mask. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The page of execution views matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationExecutionView' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. type: string - minValue: - description: The minValue field. - format: int64 - readOnly: false + title: Search Automation Executions Response + type: object + x-speakeasy-name-override: SearchAutomationExecutionsResponse + c1.api.automations.v1.SearchAutomationTemplateVersionsRequest: + description: The SearchAutomationTemplateVersionsRequest message. + properties: + automationTemplateId: + description: The automation template whose version history to search. type: string - step: - description: The step field. - format: int64 - readOnly: false + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous SearchAutomationTemplateVersionsResponse. type: string - title: Number Field + title: Search Automation Template Versions Request type: object - x-speakeasy-name-override: NumberField - c1.api.form.v1.Oauth2Field: - description: | - The Oauth2Field message. - - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - oauth2FieldView - nullable: true + x-speakeasy-name-override: SearchAutomationTemplateVersionsRequest + c1.api.automations.v1.SearchAutomationTemplateVersionsResponse: + description: The SearchAutomationTemplateVersionsResponse message. properties: - oauth2FieldView: - $ref: '#/components/schemas/c1.api.form.v1.Oauth2FieldView' - title: Oauth 2 Field + list: + description: The page of template versions matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateVersion' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. + type: string + title: Search Automation Template Versions Response type: object - x-speakeasy-name-override: Oauth2Field - c1.api.form.v1.Oauth2FieldView: - description: The Oauth2FieldView message. - nullable: true - title: Oauth 2 Field View - type: object - x-speakeasy-name-override: Oauth2FieldView - c1.api.form.v1.PasswordField: - description: The PasswordField message. - nullable: true - title: Password Field - type: object - x-speakeasy-name-override: PasswordField - c1.api.form.v1.PickerField: - description: | - The PickerField message. - - This message contains a oneof named type. Only a single field of the following list may be set at a time: - - appUserPicker - - resourcePicker - - c1UserPicker - nullable: true - properties: - appUserPicker: - $ref: '#/components/schemas/c1.api.form.v1.AppUserFilter' - c1UserPicker: - $ref: '#/components/schemas/c1.api.form.v1.C1UserFilter' - resourcePicker: - $ref: '#/components/schemas/c1.api.form.v1.AppResourceFilter' - title: Picker Field - type: object - x-speakeasy-name-override: PickerField - c1.api.form.v1.RequiredTogether: - description: The RequiredTogether message. - nullable: true - title: Required Together - type: object - x-speakeasy-name-override: RequiredTogether - c1.api.form.v1.SelectField: - description: The SelectField message. - nullable: true + x-speakeasy-name-override: SearchAutomationTemplateVersionsResponse + c1.api.automations.v1.SearchAutomationsRequest: + description: The SearchAutomationsRequest message. properties: - options: - description: The options field. + appId: + description: Filter results to automations belonging to this application. + type: string + appIds: + description: |- + Filter results to automations belonging to any of the specified apps. + Supersedes the singular `app_id` field when non-empty; when empty, the + server falls back to `app_id` for backward compatibility. items: - $ref: '#/components/schemas/c1.api.form.v1.SelectOption' - nullable: true - readOnly: false - type: array - type: - description: The type field. + type: string + type: + - array + - "null" + direction: + description: |- + Direction to sort in. Unspecified falls back to ASC when sort_field is set; + when sort_field is also unspecified, the server default order (created_at + DESC) applies. enum: - - SELECT_TYPE_UNSPECIFIED - - SELECT_TYPE_DROPDOWN - - SELECT_TYPE_RADIO - - SELECT_TYPE_BUTTONS - readOnly: false + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC type: string x-speakeasy-unknown-values: allow - title: Select Field - type: object - x-speakeasy-name-override: SelectField - c1.api.form.v1.SelectOption: - description: The SelectOption message. - properties: - description: - description: Used for type BUTTONS - readOnly: false + isDraft: + description: |- + Tri-state draft filter. Unset = include both drafts and published; + `true` = drafts only; `false` = published only. + type: + - boolean + - "null" + pageSize: + description: Maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous SearchAutomationsResponse. type: string - displayName: - description: The displayName field. - readOnly: false + query: + description: Free-text search query to filter automations by name or description. type: string - value: - description: The value field. - readOnly: false + refs: + description: Restrict results to automations matching these template references. + items: + $ref: '#/components/schemas/c1.api.automations.v1.AutomationTemplateRef' + type: + - array + - "null" + sortField: + description: Column to sort by. Unspecified (0) means sort by created_at desc (server default). + enum: + - AUTOMATION_SORT_FIELD_UNSPECIFIED + - AUTOMATION_SORT_FIELD_DISPLAY_NAME + - AUTOMATION_SORT_FIELD_CREATED_AT + - AUTOMATION_SORT_FIELD_LAST_EXECUTED_AT + - AUTOMATION_SORT_FIELD_ENABLED + - AUTOMATION_SORT_FIELD_PRIMARY_TRIGGER_TYPE type: string - title: Select Option + x-speakeasy-unknown-values: allow + statuses: + description: |- + Filter results by automation status. Empty or containing both ON and OFF + applies no status filter. + items: + enum: + - AUTOMATION_STATUS_FILTER_UNSPECIFIED + - AUTOMATION_STATUS_FILTER_ON + - AUTOMATION_STATUS_FILTER_OFF + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + triggerTypes: + description: Filter results to automations with any of the specified trigger types. + items: + enum: + - TRIGGER_TYPE_UNSPECIFIED + - TRIGGER_TYPE_USER_PROFILE_CHANGE + - TRIGGER_TYPE_APP_USER_CREATE + - TRIGGER_TYPE_APP_USER_UPDATE + - TRIGGER_TYPE_UNUSED_ACCESS + - TRIGGER_TYPE_USER_CREATED + - TRIGGER_TYPE_GRANT_FOUND + - TRIGGER_TYPE_GRANT_DELETED + - TRIGGER_TYPE_WEBHOOK + - TRIGGER_TYPE_SCHEDULE + - TRIGGER_TYPE_FORM + - TRIGGER_TYPE_SCHEDULE_APP_USER + - TRIGGER_TYPE_ACCESS_CONFLICT + - TRIGGER_TYPE_SCHEDULE_NO_USER + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Search Automations Request type: object - x-speakeasy-name-override: SelectOption - c1.api.form.v1.SharedProviderConfig: - description: The SharedProviderConfig message. - nullable: true + x-speakeasy-name-override: SearchAutomationsRequest + c1.api.automations.v1.SearchAutomationsResponse: + description: The SearchAutomationsResponse message. properties: - defaultValueCel: - description: The defaultValueCel field. - readOnly: false + list: + description: The page of automations matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.automations.v1.Automation' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty when no more results exist. type: string - inputTransformationCel: - description: The inputTransformationCel field. - readOnly: false + title: Search Automations Response + type: object + x-speakeasy-name-override: SearchAutomationsResponse + c1.api.automations.v1.SendEmail: + description: The SendEmail message. + properties: + body: + description: The body field. type: string - lockDefaultValues: - description: The lockDefaultValues field. - readOnly: false + email: + deprecated: true + description: |- + Deprecated: use email_cel instead. Static email field shipped behind FF 541 (SKU_MANUAL) + with zero tenant enablement. CEL subsumes static: '"ops@example.com"' is valid CEL. + type: string + emailCel: + description: |- + CEL expression resolving to one or more email addresses (string or list). + Evaluated against the workflow execution context (trigger + completed steps). + Static emails work too: '"ops@example.com"' is valid CEL. + Supports list for multiple recipients: '["a@x.com", "b@x.com"]'. + Requires the tenant to have a TenantEmailProvider configured. + type: string + subject: + description: The subject field. + type: string + title: + description: The title field. + type: string + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. type: boolean - title: Shared Provider Config + userIdsCel: + description: The userIdsCel field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Send Email type: object - x-speakeasy-name-override: SharedProviderConfig - c1.api.form.v1.StringField: + x-speakeasy-name-override: SendEmail + c1.api.automations.v1.SendSlackMessage: description: | - The StringField message. + SendSlackMessage posts to a channel or DMs one or more users. Delivery mode is + inferred from which fields are populated: DM if any user field is set + (use_subject_user, user_ids_cel, user_refs), otherwise channel. Priority for DM + recipient resolution: use_subject_user > user_ids_cel > user_refs. - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - textField - - passwordField - - selectField - - pickerField - nullable: true + This message contains a oneof named channel. Only a single field of the following list may be set at a time: + - channelName + - channelNameCel properties: - defaultValue: - description: The defaultValue field. - readOnly: false - type: string - passwordField: - $ref: '#/components/schemas/c1.api.form.v1.PasswordField' - pickerField: - $ref: '#/components/schemas/c1.api.form.v1.PickerField' - placeholder: - description: The placeholder field. - readOnly: false + body: + description: The body field. type: string - rules: - $ref: '#/components/schemas/validate.StringRules' - selectField: - $ref: '#/components/schemas/c1.api.form.v1.SelectField' - textField: - $ref: '#/components/schemas/c1.api.form.v1.TextField' - title: String Field - type: object - x-speakeasy-name-override: FormStringField - c1.api.form.v1.StringMapField: - description: The StringMapField message. - nullable: true - properties: - defaultValue: - additionalProperties: - type: string - description: The defaultValue field. - readOnly: false - type: object - rules: - $ref: '#/components/schemas/c1.api.form.v1.StringMapRules' - title: String Map Field - type: object - x-speakeasy-name-override: FormStringMapField - c1.api.form.v1.StringMapRules: - description: The StringMapRules message. - nullable: true - properties: - isRequired: - description: The isRequired field. - readOnly: false + channelIsId: + description: |- + When true, the channel value (channel_name / channel_name_cel) is a Slack + channel ID rather than a name. The backend looks the channel up by ID and + fails permanently if it does not exist or the bot cannot access it — it does + not create or search by name. Only applies to channel delivery. type: boolean - validateEmpty: - description: The validateEmpty field. - readOnly: false + channelName: + description: |- + The channelName field. + This field is part of the `channel` oneof. + See the documentation for `c1.api.automations.v1.SendSlackMessage` for more details. + type: + - string + - "null" + channelNameCel: + description: |- + The channelNameCel field. + This field is part of the `channel` oneof. + See the documentation for `c1.api.automations.v1.SendSlackMessage` for more details. + type: + - string + - "null" + useSubjectUser: + description: The useSubjectUser field. type: boolean - title: String Map Rules + userIdsCel: + description: The userIdsCel field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Send Slack Message type: object - x-speakeasy-name-override: StringMapRules - c1.api.form.v1.StringSliceField: + x-speakeasy-name-override: SendSlackMessage + c1.api.automations.v1.SetCredential: description: | - The StringSliceField message. + SetCredential submits a RotateCredentials baton task to the target connector, + re-encrypting the given password CEL expression with the connector's public JWK. - This message contains a oneof named view. Only a single field of the following list may be set at a time: - - chipsField - - pickerField - nullable: true + This message contains a oneof named connector_identifier. Only a single field of the following list may be set at a time: + - connectorRef properties: - chipsField: - $ref: '#/components/schemas/c1.api.form.v1.ChipsField' - defaultValues: - description: The defaultValues field. - items: - type: string - nullable: true - readOnly: false - type: array - pickerField: - $ref: '#/components/schemas/c1.api.form.v1.PickerField' - placeholder: - description: The placeholder field. - readOnly: false + accountIdCel: + description: The accountIdCel field. type: string - rules: - $ref: '#/components/schemas/validate.RepeatedRules' - title: String Slice Field - type: object - x-speakeasy-name-override: StringSliceField - c1.api.form.v1.TextField: - description: The TextField message. - nullable: true - properties: - multiline: - description: The multiline field. - readOnly: false - type: boolean - suffix: - description: Static text displayed as an end adornment (e.g. ".example.com" for domain fields). - nullable: true - readOnly: false + connectorRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.ConnectorRef' + - type: "null" + passwordCel: + description: The passwordCel field. type: string - title: Text Field - type: object - x-speakeasy-name-override: TextField - c1.api.form.v1.ToggleField: - description: The ToggleField message. - nullable: true - title: Toggle Field + title: Set Credential type: object - x-speakeasy-name-override: ToggleField - c1.api.form.v1.UserProviderConfig: - description: The UserProviderConfig message. - nullable: true + x-speakeasy-name-override: SetCredential + c1.api.automations.v1.StoreCredential: + description: |- + StoreCredential stores a credential from GeneratePassword in a vault. + Supports Paper Vault (SSO/email) and App Vault (entitlement-bound). properties: - inputTransformationCel: - description: The inputTransformationCel field. - readOnly: false + appIdCel: + description: CEL expression that resolves to app ID (App Vault only) type: string - title: User Provider Config - type: object - x-speakeasy-name-override: UserProviderConfig - c1.api.functions.v1.Function: - description: Function represents a customer-provided code extension in the API - properties: - createdAt: - format: date-time - readOnly: true + authType: + description: Authentication type for the paper vault recipient (Paper Vault only) + enum: + - STORE_CREDENTIAL_AUTH_TYPE_UNSPECIFIED + - STORE_CREDENTIAL_AUTH_TYPE_SSO_INTERNAL + - STORE_CREDENTIAL_AUTH_TYPE_VERIFY_EMAIL type: string - deletedAt: - format: date-time - readOnly: true + x-speakeasy-unknown-values: allow + credentialCel: + description: CEL expression that resolves to the encrypted credential from GeneratePassword type: string - description: - description: The description field. - readOnly: false + expiry: + format: duration + type: + - string + - "null" + labelCel: + description: Optional display label for the vault type: string - displayName: - description: The displayName field. - readOnly: false + maxViews: + description: Maximum number of views (0 = unlimited, default 1) (Paper Vault only) + format: uint32 + type: integer + recipientCel: + description: |- + CEL expression resolving to one or more recipient C1 user IDs — a string or list, + e.g. '["u1","u2"]' (SSO_INTERNAL / App Vault). App Vault accepts a single user only. type: string - functionType: - description: The functionType field. + recipientEmailCel: + description: |- + CEL expression resolving to one or more recipient email addresses — a string or list, + e.g. '["a@x.com","b@x.com"]' (Paper Vault + VERIFY_EMAIL only). + type: string + ttl: + format: duration + type: + - string + - "null" + vaultType: + description: 'Vault type selector (default: PAPER_VAULT for backward compatibility)' enum: - - FUNCTION_TYPE_UNSPECIFIED - - FUNCTION_TYPE_ANY - - FUNCTION_TYPE_CODE_MODE - readOnly: false + - STORE_CREDENTIAL_VAULT_TYPE_UNSPECIFIED + - STORE_CREDENTIAL_VAULT_TYPE_PAPER_VAULT + - STORE_CREDENTIAL_VAULT_TYPE_APP_VAULT type: string x-speakeasy-unknown-values: allow - head: - description: The head field. - readOnly: false - type: string - id: - description: The id field. - readOnly: false - type: string - isDraft: - description: The isDraft field. - readOnly: false - type: boolean - outboundNetworkAllowlist: - description: The outboundNetworkAllowlist field. + title: Store Credential + type: object + x-speakeasy-name-override: StoreCredential + c1.api.automations.v1.TaskAction: + description: | + The TaskAction message. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - close + - reassign + properties: + close: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.CloseAction' + - type: "null" + reassign: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.ReassignAction' + - type: "null" + taskTypes: + description: The taskTypes field. items: + enum: + - TASK_TYPE_UNSPECIFIED + - TASK_TYPE_REQUEST + - TASK_TYPE_REVOKE + - TASK_TYPE_REVIEW type: string - nullable: true - readOnly: false - type: array - publishedCommitId: - description: The publishedCommitId field. - readOnly: false + x-speakeasy-unknown-values: allow + type: + - array + - "null" + taskUserRelation: + description: The taskUserRelation field. + enum: + - TASK_USER_RELATION_UNSPECIFIED + - TASK_USER_RELATION_ASSIGNEE + - TASK_USER_RELATION_SUBJECT type: string - scopedRoleIds: - description: |- - Scoped role IDs define the permissions granted to this function when calling - ConductorOne APIs. These are role IDs (not service roles) that get resolved - to their service roles at authentication time. - - Currently only the "Read-Only Administrator" role (system:viewer) is supported. - The role ID can be obtained from the roles API. + x-speakeasy-unknown-values: allow + title: Task Action + type: object + x-speakeasy-name-override: TaskAction + c1.api.automations.v1.TerminateAutomationRequestInput: + description: The TerminateAutomationRequest message. + title: Terminate Automation Request + type: object + x-speakeasy-name-override: TerminateAutomationRequest + c1.api.automations.v1.TerminateAutomationResponse: + description: The TerminateAutomationResponse message. + title: Terminate Automation Response + type: object + x-speakeasy-name-override: TerminateAutomationResponse + c1.api.automations.v1.UnenrollFromAllAccessProfiles: + description: The UnenrollFromAllAccessProfiles message. + properties: + catalogIds: + description: Optional list of catalog IDs to unenroll from. If empty, unenroll from all catalogs. items: type: string - nullable: true - readOnly: false - type: array - secret: - additionalProperties: - type: string - description: The secret field. - readOnly: false - type: object - updatedAt: - format: date-time - readOnly: true + type: + - array + - "null" + catalogIdsCel: + description: CEL expression to dynamically select catalog IDs. If provided, overrides catalog_ids. type: string - useSpn: - description: |- - FN-347 transition flag. When true, the function authenticates to c1-api - as user: via the AssumeIdentity token exchange using its - ServicePrincipalBinding; when false, it authenticates as - function:. Read-only from clients: set by CreateFunction (when the - tenant has completed the FunctionsToSPN migration) and by the migration - itself, never by UpdateFunction. Retired once all functions are on SPN. - readOnly: true + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. type: boolean - title: Function + userIdsCel: + description: The userIdsCel field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Unenroll From All Access Profiles type: object - x-speakeasy-entity: Function - x-speakeasy-name-override: Function - c1.api.functions.v1.FunctionCommit: - description: FunctionCommit represents a single commit in a function's history + x-speakeasy-name-override: UnenrollFromAllAccessProfiles + c1.api.automations.v1.UpdateAutomationRequestInput: + description: The UpdateAutomationRequest message. properties: - author: - description: The author field. - readOnly: false - type: string - createdAt: - format: date-time - readOnly: false - type: string - functionId: - description: The functionId field. - readOnly: false - type: string - id: - description: The id field. - readOnly: false - type: string - message: - description: The message field. - readOnly: false - type: string - title: Function Commit + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.Automation' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Automation Request type: object - x-speakeasy-name-override: FunctionCommit - c1.api.functions.v1.FunctionInvocation: - description: The FunctionInvocation message. + x-speakeasy-name-override: UpdateAutomationRequest + c1.api.automations.v1.UpdateAutomationResponse: + description: The UpdateAutomationResponse message. properties: - commitId: - description: The commitId field. - readOnly: false + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.Automation' + - type: "null" + webhookCapabilityUrl: + description: |- + One-time absolute webhook URL for capability URL authentication, shown once when the trigger is saved. + Contains the full URL including the embedded token (e.g. https://tenant.conductorone.com/api/v1/webhooks/incoming/{id}/t/{token}). + Populated only when the webhook trigger uses capability URL authentication. type: string - createdAt: - format: date-time - readOnly: false + webhookHmacSecret: + description: |- + One-time HMAC shared secret, shown once when the trigger is saved. + Populated only when the webhook trigger uses HMAC authentication. type: string - error: - description: The error field. - readOnly: false + title: Update Automation Response + type: object + x-speakeasy-name-override: UpdateAutomationResponse + c1.api.automations.v1.UpdateUser: + description: | + The UpdateUser message. + + This message contains a oneof named user. Only a single field of the following list may be set at a time: + - userIdCel + - userRef + + + This message contains a oneof named user_status. Only a single field of the following list may be set at a time: + - userStatusEnum + - userStatusCel + properties: + useSubjectUser: + description: If true, the step will use the subject user of the automation as the subject. + type: boolean + userIdCel: + description: |- + The userIdCel field. + This field is part of the `user` oneof. + See the documentation for `c1.api.automations.v1.UpdateUser` for more details. + type: + - string + - "null" + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + userStatusCel: + description: |- + The userStatusCel field. + This field is part of the `user_status` oneof. + See the documentation for `c1.api.automations.v1.UpdateUser` for more details. + type: + - string + - "null" + userStatusEnum: + description: |- + The userStatusEnum field. + This field is part of the `user_status` oneof. + See the documentation for `c1.api.automations.v1.UpdateUser` for more details. + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + type: + - string + - "null" + x-speakeasy-unknown-values: allow + title: Update User + type: object + x-speakeasy-name-override: UpdateUser + c1.api.automations.v1.UsageBasedRevocationTrigger: + description: | + The UsageBasedRevocationTrigger message. + + This message contains a oneof named cold_start_schedule. Only a single field of the following list may be set at a time: + - runImmediately + - runDelayed + properties: + appId: + description: The appId field. type: string - functionId: - description: The functionId field. - readOnly: false + enabledAt: + format: date-time + type: + - string + - "null" + excludedGroupRefs: + description: The excludedGroupRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + excludedUserRefs: + description: The excludedUserRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + includeUsersWithNoActivity: + description: The includeUsersWithNoActivity field. + type: boolean + runDelayed: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.RunDelayed' + - type: "null" + runImmediately: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.RunImmediately' + - type: "null" + targetedAppUserTypes: + description: The targetedAppUserTypes field. + items: + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + targetedEntitlementRefs: + description: The targetedEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + unusedForDays: + description: The unusedForDays field. + format: uint32 + type: integer + title: Usage Based Revocation Trigger + type: object + x-speakeasy-name-override: UsageBasedRevocationTrigger + c1.api.automations.v1.UserCreatedTrigger: + description: The UserCreatedTrigger message. + properties: + condition: + description: The condition field. type: string - id: - description: The id field. - readOnly: false + title: User Created Trigger + type: object + x-speakeasy-name-override: UserCreatedTrigger + c1.api.automations.v1.UserProfileChangeTrigger: + description: The UserProfileChangeTrigger message. + properties: + condition: + description: The condition field. type: string - input: - additionalProperties: true - readOnly: false - type: object - output: + title: User Profile Change Trigger + type: object + x-speakeasy-name-override: UserProfileChangeTrigger + c1.api.automations.v1.UserProperties: + description: The UserProperties message. + properties: + displayNameCel: + description: The displayNameCel field. + type: string + emailCel: + description: The emailCel field. + type: string + profileAttributeCel: + description: The profileAttributeCel field. + type: string + usernameCel: + description: The usernameCel field. + type: string + title: User Properties + type: object + x-speakeasy-name-override: UserProperties + c1.api.automations.v1.WaitForDuration: + description: The WaitForDuration message. + properties: + duration: + format: duration + type: + - string + - "null" + title: Wait For Duration + type: object + x-speakeasy-name-override: WaitForDuration + c1.api.automations.v1.Webhook: + description: | + The Webhook message. + + This message contains a oneof named webhook_identifier. Only a single field of the following list may be set at a time: + - webhookId + - webhookIdCel + properties: + payload: additionalProperties: true - readOnly: false - type: object - status: - description: The status field. - enum: - - FUNCTION_INVOCATION_STATUS_UNSPECIFIED - - FUNCTION_INVOCATION_STATUS_PENDING - - FUNCTION_INVOCATION_STATUS_RUNNING - - FUNCTION_INVOCATION_STATUS_SUCCESS - - FUNCTION_INVOCATION_STATUS_ERROR - readOnly: false + type: + - object + - "null" + webhookId: + description: |- + The webhookId field. + This field is part of the `webhook_identifier` oneof. + See the documentation for `c1.api.automations.v1.Webhook` for more details. + type: + - string + - "null" + webhookIdCel: + description: |- + The webhookIdCel field. + This field is part of the `webhook_identifier` oneof. + See the documentation for `c1.api.automations.v1.Webhook` for more details. + type: + - string + - "null" + title: Webhook + type: object + x-speakeasy-name-override: Webhook + c1.api.automations.v1.WebhookAutomationTrigger: + description: | + The WebhookAutomationTrigger message. + + This message contains a oneof named auth_config. Only a single field of the following list may be set at a time: + - jwt + - hmac + - capabilityUrl + properties: + capabilityUrl: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthCapabilityURL' + - type: "null" + hmac: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthHMAC' + - type: "null" + jwt: + oneOf: + - $ref: '#/components/schemas/c1.api.automations.v1.WebhookListenerAuthJWT' + - type: "null" + listenerId: + description: Optional existing listener ID (hidden field from frontend) type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: false + title: Webhook Automation Trigger + type: object + x-speakeasy-name-override: WebhookAutomationTrigger + c1.api.automations.v1.WebhookListenerAuthCapabilityURL: + description: |- + Capability URL authentication: the URL itself contains an unguessable token that acts + as the credential. This is simpler to integrate but less secure than JWT or HMAC because + the token can leak via server logs, referrer headers, and URL sharing. + See https://www.w3.org/TR/capability-urls/ for background. + title: Webhook Listener Auth Capability Url + type: object + x-speakeasy-name-override: WebhookListenerAuthCapabilityURL + c1.api.automations.v1.WebhookListenerAuthHMAC: + description: The WebhookListenerAuthHMAC message. + title: Webhook Listener Auth Hmac + type: object + x-speakeasy-name-override: WebhookListenerAuthHMAC + c1.api.automations.v1.WebhookListenerAuthJWT: + description: The WebhookListenerAuthJWT message. + properties: + jwksUrl: + description: The jwksUrl field. type: string - title: Function Invocation + title: Webhook Listener Auth Jwt type: object - x-speakeasy-name-override: FunctionInvocation - c1.api.functions.v1.FunctionTestResult: - description: FunctionTestResult contains the result of a single test case execution. + x-speakeasy-name-override: WebhookListenerAuthJWT + c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionRequest: + description: The ConnectorAuthoringServiceActivateRevisionRequest message. properties: - assertions: - description: The assertions evaluated during the test. - items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult.FunctionTestResultAssertion' - nullable: true - readOnly: false - type: array - error: - description: Error message if the test errored (distinct from assertion failure). - readOnly: false + approvalTokenId: + description: The approvalTokenId field. type: string - logs: - description: The log entries captured during the test. - items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult.FunctionTestResultLog' - nullable: true - readOnly: false - type: array - name: - description: The test name. - readOnly: false + catalogId: + description: The catalogId field. type: string - status: - description: The test result status. - enum: - - FUNCTION_TEST_RESULT_STATUS_UNSPECIFIED - - FUNCTION_TEST_RESULT_STATUS_OK - - FUNCTION_TEST_RESULT_STATUS_FAIL - - FUNCTION_TEST_RESULT_STATUS_SKIPPED - readOnly: false + idempotencyKey: + description: |- + Optional, reserved for a future replay-result cache. It is accepted but + currently unused: the single-use approval token is the double-activate + mechanism, so no key is required today. Bounded so a future key stays sane. type: string - x-speakeasy-unknown-values: allow - title: Function Test Result + instanceAppId: + description: The instanceAppId field. + type: string + instanceConnectorId: + description: The instanceConnectorId field. + type: string + revisionId: + description: The revisionId field. + type: string + title: Connector Authoring Service Activate Revision Request type: object - x-speakeasy-name-override: FunctionTestResult - c1.api.functions.v1.FunctionTestResult.FunctionTestResultAssertion: - description: A single assertion within a test. + x-speakeasy-name-override: ConnectorAuthoringServiceActivateRevisionRequest + c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionResponse: + description: The ConnectorAuthoringServiceActivateRevisionResponse message. properties: - actual: - description: The actual value. - readOnly: false + activationEpoch: + description: The activationEpoch field. + format: uint64 type: string - at: - description: Source location of the assertion. - readOnly: false + revisionId: + description: The revisionId field. type: string - description: - description: Description of the assertion. - readOnly: false + title: Connector Authoring Service Activate Revision Response + type: object + x-speakeasy-name-override: ConnectorAuthoringServiceActivateRevisionResponse + c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionRequest: + description: The ConnectorAuthoringServiceRollbackRevisionRequest message. + properties: + approvalTokenId: + description: The approvalTokenId field. type: string - expected: - description: The expected value. - readOnly: false + catalogId: + description: The catalogId field. type: string - operator: - description: The comparison operator (e.g., "==", "!="). - readOnly: false + instanceAppId: + description: The instanceAppId field. type: string - pass: - description: Whether the assertion passed. - readOnly: false - type: boolean - title: Function Test Result Assertion + instanceConnectorId: + description: The instanceConnectorId field. + type: string + reason: + description: Optional operator justification, recorded on the audit event. + type: string + targetRevisionId: + description: |- + The previously activated revision the published + instance pointers roll + back TO. Caller-chosen and explicit so the audit trail records an exact, + human-selected target. + type: string + title: Connector Authoring Service Rollback Revision Request type: object - x-speakeasy-name-override: FunctionTestResultAssertion - c1.api.functions.v1.FunctionTestResult.FunctionTestResultLog: - description: A log entry captured during a test. + x-speakeasy-name-override: ConnectorAuthoringServiceRollbackRevisionRequest + c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionResponse: + description: The ConnectorAuthoringServiceRollbackRevisionResponse message. properties: - level: - description: The log level (e.g., "info", "error"). - readOnly: false - type: string - log: - description: The log message content. - readOnly: false + activationEpoch: + description: The activationEpoch field. + format: uint64 type: string - source: - description: The log source (e.g., "stdout", "stderr"). - readOnly: false + revisionId: + description: The revision now published (the rollback target). type: string - title: Function Test Result Log + title: Connector Authoring Service Rollback Revision Response type: object - x-speakeasy-name-override: FunctionTestResultLog - c1.api.functions.v1.FunctionsInvocationSearchRequestInput: + x-speakeasy-name-override: ConnectorAuthoringServiceRollbackRevisionResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicy: description: |- - FunctionsInvocationSearchRequest is the request for searching function invocations. - Results are returned in descending order by created_at (newest first). + CredentialInventoryPolicy defines which credential types your users may + enroll and the rules for each type. properties: - pageSize: - description: The number of results to return per page. + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + delegated: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.DelegatedConstraints' + - type: "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: A human-readable name for the policy. + type: string + emailOtp: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.EmailOTPConstraints' + - type: "null" + enabledTypes: + description: The credential types users are permitted to enroll under this policy. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + id: + description: Unique identifier for the policy. + readOnly: true + type: string + isBuiltin: + description: |- + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. + readOnly: true + type: boolean + passkey: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.PasskeyConstraints' + - type: "null" + password: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.PasswordConstraints' + - type: "null" + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. format: int32 - readOnly: false type: integer - pageToken: - description: The pagination token for fetching the next page. - readOnly: false - type: string - title: Functions Invocation Search Request + totp: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.TOTPConstraints' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Credential Inventory Policy type: object - x-speakeasy-name-override: FunctionsInvocationSearchRequest - c1.api.functions.v1.FunctionsInvocationSearchResponse: - description: FunctionsInvocationSearchResponse is the response for searching function invocations. + x-speakeasy-entity: CredentialInventoryPolicy + x-speakeasy-name-override: CredentialInventoryPolicy + c1.api.credential_inventory.v1.CredentialInventoryPolicyRef: + description: CredentialInventoryPolicyRef is a lightweight reference to a policy by ID. properties: - list: - description: The list of function invocations, ordered by created_at descending. - items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The pagination token for fetching the next page. - readOnly: false + id: + description: The id field. type: string - title: Functions Invocation Search Response + title: Credential Inventory Policy Ref type: object - x-speakeasy-name-override: FunctionsInvocationSearchResponse - c1.api.functions.v1.FunctionsInvocationServiceGetResponse: - description: The FunctionsInvocationServiceGetResponse message. + x-speakeasy-name-override: CredentialInventoryPolicyRef + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateRequest: + description: The CredentialInventoryPolicyServiceCreateRequest message. properties: - invocation: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' - title: Functions Invocation Service Get Response - type: object - x-speakeasy-name-override: FunctionsInvocationServiceGetResponse - c1.api.functions.v1.FunctionsInvocationServiceListResponse: - description: The FunctionsInvocationServiceListResponse message. + delegated: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.DelegatedConstraints' + - type: "null" + displayName: + description: A human-readable name for the policy. + type: string + emailOtp: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.EmailOTPConstraints' + - type: "null" + enabledTypes: + description: The credential types users are permitted to enroll under this policy. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + passkey: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.PasskeyConstraints' + - type: "null" + password: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.PasswordConstraints' + - type: "null" + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + totp: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.TOTPConstraints' + - type: "null" + required: + - displayName + title: Credential Inventory Policy Service Create Request + type: object + x-speakeasy-entity: CredentialInventoryPolicy + x-speakeasy-name-override: CredentialInventoryPolicyServiceCreateRequest + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateResponse: + description: The CredentialInventoryPolicyServiceCreateResponse message. + properties: + credentialInventoryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + - type: "null" + title: Credential Inventory Policy Service Create Response + type: object + x-speakeasy-name-override: CredentialInventoryPolicyServiceCreateResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteRequestInput: + description: The CredentialInventoryPolicyServiceDeleteRequest message. + title: Credential Inventory Policy Service Delete Request + type: object + x-speakeasy-entity: CredentialInventoryPolicy + x-speakeasy-name-override: CredentialInventoryPolicyServiceDeleteRequest + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteResponse: + description: The CredentialInventoryPolicyServiceDeleteResponse message. + title: Credential Inventory Policy Service Delete Response + type: object + x-speakeasy-name-override: CredentialInventoryPolicyServiceDeleteResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceGetResponse: + description: The CredentialInventoryPolicyServiceGetResponse message. + properties: + credentialInventoryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + - type: "null" + title: Credential Inventory Policy Service Get Response + type: object + x-speakeasy-name-override: CredentialInventoryPolicyServiceGetResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceListResponse: + description: The CredentialInventoryPolicyServiceListResponse message. properties: list: - description: The list field. + description: The page of policies. items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: A token to fetch the next page, or empty if there are no more results. type: string - title: Functions Invocation Service List Response + title: Credential Inventory Policy Service List Response type: object - x-speakeasy-name-override: FunctionsInvocationServiceListResponse - c1.api.functions.v1.FunctionsSearchRequest: - description: The FunctionsSearchRequest message. + x-speakeasy-name-override: CredentialInventoryPolicyServiceListResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceSearchRequest: + description: The CredentialInventoryPolicyServiceSearchRequest message. properties: - functionTypes: - description: The functionTypes field. - items: - enum: - - FUNCTION_TYPE_UNSPECIFIED - - FUNCTION_TYPE_ANY - - FUNCTION_TYPE_CODE_MODE - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array pageSize: - description: The pageSize field. + description: The maximum number of results to return per page. format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: A pagination token from a previous Search response. type: string query: - description: The query field. - readOnly: false + description: Free-text search over the policy name. Empty matches all policies. type: string - title: Functions Search Request + refs: + description: Restrict results to these specific policies. Empty matches all policies. + items: + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyRef' + type: + - array + - "null" + title: Credential Inventory Policy Service Search Request type: object - x-speakeasy-name-override: FunctionsSearchRequest - c1.api.functions.v1.FunctionsSearchResponse: - description: The FunctionsSearchResponse message. + x-speakeasy-name-override: CredentialInventoryPolicyServiceSearchRequest + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceSearchResponse: + description: The CredentialInventoryPolicyServiceSearchResponse message. properties: list: - description: The list field. + description: The page of matching policies. items: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: A token to fetch the next page, or empty if there are no more results. type: string - title: Functions Search Response + title: Credential Inventory Policy Service Search Response type: object - x-speakeasy-name-override: FunctionsSearchResponse - c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput: - description: The FunctionsServiceCreateFinalCommitRequest message. - title: Functions Service Create Final Commit Request + x-speakeasy-name-override: CredentialInventoryPolicyServiceSearchResponse + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateRequestInput: + description: The CredentialInventoryPolicyServiceUpdateRequest message. + properties: + credentialInventoryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Credential Inventory Policy Service Update Request + type: object + x-speakeasy-name-override: CredentialInventoryPolicyServiceUpdateRequest + c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateResponse: + description: The CredentialInventoryPolicyServiceUpdateResponse message. + properties: + credentialInventoryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicy' + - type: "null" + title: Credential Inventory Policy Service Update Response + type: object + x-speakeasy-name-override: CredentialInventoryPolicyServiceUpdateResponse + c1.api.credential_inventory.v1.DelegatedConstraints: + description: |- + DelegatedConstraints controls which third-party sign-in providers are + accepted as proof of email ownership, and how they are scoped. + properties: + googleEnabled: + description: Accept "Sign in with Google". + type: boolean + googleHostedDomains: + description: Restrict Google sign-in to these Google Workspace domains. Empty = any domain. + items: + type: string + type: + - array + - "null" + microsoftEnabled: + description: Accept "Sign in with Microsoft". + type: boolean + microsoftTenantIds: + description: Restrict Microsoft sign-in to these Microsoft tenant IDs. Empty = any tenant. + items: + type: string + type: + - array + - "null" + title: Delegated Constraints type: object - x-speakeasy-name-override: FunctionsServiceCreateFinalCommitRequest - c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse: - description: The FunctionsServiceCreateFinalCommitResponse message. + x-speakeasy-name-override: DelegatedConstraints + c1.api.credential_inventory.v1.EmailOTPConstraints: + description: EmailOTPConstraints configures one-time codes delivered by email. properties: - commit: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' - title: Functions Service Create Final Commit Response + codeLength: + description: Number of digits in each code. + format: int32 + type: integer + maxAttempts: + description: Number of incorrect attempts allowed before the code is invalidated. + format: int32 + type: integer + ttlSeconds: + description: How long a code remains valid, in seconds. + format: int32 + type: integer + title: Email Otp Constraints type: object - x-speakeasy-name-override: FunctionsServiceCreateFinalCommitResponse - c1.api.functions.v1.FunctionsServiceCreateFunctionRequest: - description: The FunctionsServiceCreateFunctionRequest message. + x-speakeasy-name-override: EmailOTPConstraints + c1.api.credential_inventory.v1.PasskeyConstraints: + description: PasskeyConstraints controls how users may enroll passkeys (FIDO2 / WebAuthn). properties: - commitMessage: - description: The commit message describing the initial code submission. - readOnly: false - type: string - description: - description: A description of what the function does. - readOnly: false - type: string - displayName: - description: The human-readable name for the function. - readOnly: false - type: string - functionType: - description: The type of function to create, controlling its execution environment and capabilities. + allowedAaguids: + description: |- + Allowed authenticator models, by AAGUID. Leave empty to permit any + authenticator. + items: + format: base64 + type: string + type: + - array + - "null" + attestation: + description: How strictly the authenticator's origin must be attested. enum: - - FUNCTION_TYPE_UNSPECIFIED - - FUNCTION_TYPE_ANY - - FUNCTION_TYPE_CODE_MODE - readOnly: false + - ATTESTATION_REQUIREMENT_UNSPECIFIED + - ATTESTATION_REQUIREMENT_NONE + - ATTESTATION_REQUIREMENT_INDIRECT + - ATTESTATION_REQUIREMENT_DIRECT + - ATTESTATION_REQUIREMENT_ENTERPRISE type: string x-speakeasy-unknown-values: allow - initialContent: - additionalProperties: - format: base64 - type: string - description: Map of filename to file content for the initial code commit. - readOnly: false - type: object - title: Functions Service Create Function Request + requireUserVerification: + description: Require the authenticator to verify the user (PIN or biometric) at enrollment. + type: boolean + title: Passkey Constraints type: object - x-speakeasy-name-override: FunctionsServiceCreateFunctionRequest - c1.api.functions.v1.FunctionsServiceCreateFunctionResponse: - description: The FunctionsServiceCreateFunctionResponse message. + x-speakeasy-name-override: PasskeyConstraints + c1.api.credential_inventory.v1.PasswordConstraints: + description: PasswordConstraints sets the complexity rules a user's password must satisfy. properties: - commit: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' - function: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - title: Functions Service Create Function Response + checkBreached: + description: Reject passwords found in known-breach corpora. + type: boolean + historyDepth: + description: Number of previous passwords to remember and disallow reuse of. + format: int32 + type: integer + minLength: + description: Minimum length, in characters. + format: int32 + type: integer + requireMixedCase: + description: Require both uppercase and lowercase letters. + type: boolean + requireNumber: + description: Require at least one digit. + type: boolean + requireSymbol: + description: Require at least one symbol. + type: boolean + title: Password Constraints type: object - x-speakeasy-name-override: FunctionsServiceCreateFunctionResponse - c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput: - description: The FunctionsServiceCreateInitialCommitRequest message. + x-speakeasy-name-override: PasswordConstraints + c1.api.credential_inventory.v1.RecoveryPolicy: + description: |- + RecoveryPolicy defines how users recover access when they lose their + credentials. properties: - commitMessage: - description: The commitMessage field. - readOnly: false - type: string - filenames: - description: The filenames field. + allowedRecoveryTypes: + description: The credential types a user may use to recover access under this policy. items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - nullable: true - readOnly: false - type: array - title: Functions Service Create Initial Commit Request + x-speakeasy-unknown-values: allow + type: + - array + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: A human-readable name for the policy. + type: string + id: + description: Unique identifier for the policy. + readOnly: true + type: string + isBuiltin: + description: |- + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. + readOnly: true + type: boolean + minRecoveryAuthLevel: + description: The minimum assurance level a recovery ceremony must reach for this policy. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH + type: string + x-speakeasy-unknown-values: allow + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + revokeOnRecovery: + description: |- + When true, a successful recovery revokes the user's existing credentials + and forces re-enrollment. When false, recovery adds to the existing set. + type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Recovery Policy type: object - x-speakeasy-name-override: FunctionsServiceCreateInitialCommitRequest - c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse: - description: The FunctionsServiceCreateInitialCommitResponse message. + x-speakeasy-entity: RecoveryPolicy + x-speakeasy-name-override: RecoveryPolicy + c1.api.credential_inventory.v1.RecoveryPolicyRef: + description: RecoveryPolicyRef is a lightweight reference to a recovery policy by ID. properties: - commitId: - description: The commitId field. - readOnly: false + id: + description: The id field. type: string - uploadUrls: - additionalProperties: - type: string - description: The uploadUrls field. - readOnly: false - type: object - title: Functions Service Create Initial Commit Response + title: Recovery Policy Ref type: object - x-speakeasy-name-override: FunctionsServiceCreateInitialCommitResponse - c1.api.functions.v1.FunctionsServiceCreateTagRequestInput: - description: The FunctionsServiceCreateTagRequest message. + x-speakeasy-name-override: RecoveryPolicyRef + c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateRequest: + description: The RecoveryPolicyServiceCreateRequest message. properties: - commitId: - description: The commitId field. - readOnly: false + allowedRecoveryTypes: + description: The credential types a user may use to recover access. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + displayName: + description: A human-readable name for the policy. type: string - name: - description: The name field. - readOnly: false + minRecoveryAuthLevel: + description: The minimum assurance level a recovery ceremony must reach. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - title: Functions Service Create Tag Request - type: object - x-speakeasy-name-override: FunctionsServiceCreateTagRequest - c1.api.functions.v1.FunctionsServiceCreateTagResponse: - description: The FunctionsServiceCreateTagResponse message. - title: Functions Service Create Tag Response - type: object - x-speakeasy-name-override: FunctionsServiceCreateTagResponse - c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput: - description: The FunctionsServiceDeleteFunctionRequest message. - title: Functions Service Delete Function Request - type: object - x-speakeasy-name-override: FunctionsServiceDeleteFunctionRequest - c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse: - description: The FunctionsServiceDeleteFunctionResponse message. - title: Functions Service Delete Function Response - type: object - x-speakeasy-name-override: FunctionsServiceDeleteFunctionResponse - c1.api.functions.v1.FunctionsServiceGetCommitContentResponse: - description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. + x-speakeasy-unknown-values: allow + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + revokeOnRecovery: + description: |- + When true, a successful recovery revokes existing credentials and forces + re-enrollment. + type: boolean + required: + - displayName + title: Recovery Policy Service Create Request + type: object + x-speakeasy-entity: RecoveryPolicy + x-speakeasy-name-override: RecoveryPolicyServiceCreateRequest + c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateResponse: + description: The RecoveryPolicyServiceCreateResponse message. + properties: + recoveryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + - type: "null" + title: Recovery Policy Service Create Response + type: object + x-speakeasy-name-override: RecoveryPolicyServiceCreateResponse + c1.api.credential_inventory.v1.RecoveryPolicyServiceDeleteRequestInput: + description: The RecoveryPolicyServiceDeleteRequest message. + title: Recovery Policy Service Delete Request + type: object + x-speakeasy-entity: RecoveryPolicy + x-speakeasy-name-override: RecoveryPolicyServiceDeleteRequest + c1.api.credential_inventory.v1.RecoveryPolicyServiceDeleteResponse: + description: The RecoveryPolicyServiceDeleteResponse message. + title: Recovery Policy Service Delete Response + type: object + x-speakeasy-name-override: RecoveryPolicyServiceDeleteResponse + c1.api.credential_inventory.v1.RecoveryPolicyServiceGetResponse: + description: The RecoveryPolicyServiceGetResponse message. + properties: + recoveryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + - type: "null" + title: Recovery Policy Service Get Response + type: object + x-speakeasy-name-override: RecoveryPolicyServiceGetResponse + c1.api.credential_inventory.v1.RecoveryPolicyServiceListResponse: + description: The RecoveryPolicyServiceListResponse message. properties: - commit: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' - files: - additionalProperties: - format: base64 - type: string - description: Map of filename to file content bytes. - readOnly: false - type: object - title: Functions Service Get Commit Content Response + list: + description: The page of policies. + items: + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + type: + - array + - "null" + nextPageToken: + description: A token to fetch the next page, or empty if there are no more results. + type: string + title: Recovery Policy Service List Response type: object - x-speakeasy-name-override: FunctionsServiceGetCommitContentResponse - c1.api.functions.v1.FunctionsServiceGetFunctionResponse: - description: The FunctionsServiceGetFunctionResponse message. + x-speakeasy-name-override: RecoveryPolicyServiceListResponse + c1.api.credential_inventory.v1.RecoveryPolicyServiceSearchRequest: + description: The RecoveryPolicyServiceSearchRequest message. properties: - function: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - title: Functions Service Get Function Response + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token from a previous Search response. + type: string + query: + description: Free-text search over the policy name. Empty matches all policies. + type: string + refs: + description: Restrict results to these specific policies. Empty matches all policies. + items: + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyRef' + type: + - array + - "null" + title: Recovery Policy Service Search Request type: object - x-speakeasy-name-override: FunctionsServiceGetFunctionResponse - c1.api.functions.v1.FunctionsServiceGetLockFileResponse: - description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. + x-speakeasy-name-override: RecoveryPolicyServiceSearchRequest + c1.api.credential_inventory.v1.RecoveryPolicyServiceSearchResponse: + description: The RecoveryPolicyServiceSearchResponse message. properties: - content: - description: The raw content of the deno lock file (empty if not found). - format: base64 - readOnly: false + list: + description: The page of matching policies. + items: + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + type: + - array + - "null" + nextPageToken: + description: A token to fetch the next page, or empty if there are no more results. type: string - exists: - description: Whether the lock file exists for this commit. - readOnly: false - type: boolean - title: Functions Service Get Lock File Response + title: Recovery Policy Service Search Response type: object - x-speakeasy-name-override: FunctionsServiceGetLockFileResponse - c1.api.functions.v1.FunctionsServiceInvokeRequestInput: - description: | - The FunctionsServiceInvokeRequest message. - - This message contains a oneof named arg. Only a single field of the following list may be set at a time: - - json + x-speakeasy-name-override: RecoveryPolicyServiceSearchResponse + c1.api.credential_inventory.v1.RecoveryPolicyServiceUpdateRequestInput: + description: The RecoveryPolicyServiceUpdateRequest message. properties: - commitId: - description: The commit ID specifying which version of the function code to run. - readOnly: false + recoveryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Recovery Policy Service Update Request + type: object + x-speakeasy-name-override: RecoveryPolicyServiceUpdateRequest + c1.api.credential_inventory.v1.RecoveryPolicyServiceUpdateResponse: + description: The RecoveryPolicyServiceUpdateResponse message. + properties: + recoveryPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy' + - type: "null" + title: Recovery Policy Service Update Response + type: object + x-speakeasy-name-override: RecoveryPolicyServiceUpdateResponse + c1.api.credential_inventory.v1.TOTPConstraints: + description: TOTPConstraints configures authenticator-app one-time codes (RFC 6238). + properties: + codeLength: + description: Number of digits in each code. + format: int32 + type: integer + periodSeconds: + description: How often a new code is generated, in seconds (typically 30 or 60). + format: int32 + type: integer + skewTolerance: + description: How many adjacent time windows to accept, to tolerate clock drift. + format: int32 + type: integer + title: Totp Constraints + type: object + x-speakeasy-name-override: TOTPConstraints + c1.api.cross_app_access.v1.XAAAccessProfile: + description: XAAAccessProfile is a requestable bundle of scopes for one resource server. + properties: + appEntitlementId: + description: The AppEntitlement created for this profile. type: string - json: - description: |- - The JSON-encoded input data passed to the function. - This field is part of the `arg` oneof. - See the documentation for `c1.api.functions.v1.FunctionsServiceInvokeRequest` for more details. - format: base64 - nullable: true - readOnly: false + appId: + description: The application that owns the resource server. type: string - vfsId: - description: Optional VFS volume ID to attach to this invocation. If empty, VFS operations will error. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + description: + description: Description of what access this profile grants. type: string - title: Functions Service Invoke Request - type: object - x-speakeasy-name-override: FunctionsServiceInvokeRequest - c1.api.functions.v1.FunctionsServiceInvokeResponse: - description: | - The FunctionsServiceInvokeResponse message. - - This message contains a oneof named resp. Only a single field of the following list may be set at a time: - - json - properties: - invocationId: - description: The ID of the created invocation, used to track execution status and retrieve results. - readOnly: false + displayName: + description: Display name for the profile. type: string - json: - deprecated: true - description: |- - Deprecated. The JSON-encoded output returned by the function. - This field is part of the `resp` oneof. - See the documentation for `c1.api.functions.v1.FunctionsServiceInvokeResponse` for more details. - format: base64 - nullable: true - readOnly: false + id: + description: Unique identifier for this access profile. type: string - title: Functions Service Invoke Response - type: object - x-speakeasy-name-override: FunctionsServiceInvokeResponse - c1.api.functions.v1.FunctionsServiceListCommitsResponse: - description: The FunctionsServiceListCommitsResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + scopeCount: + description: The number of scopes currently bound to this profile. + format: int32 + type: integer + updatedAt: + format: date-time + type: + - string + - "null" + xaaResourceServerId: + description: The resource server this profile grants access to. type: string - title: Functions Service List Commits Response + title: Xaa Access Profile type: object - x-speakeasy-name-override: FunctionsServiceListCommitsResponse - c1.api.functions.v1.FunctionsServiceListFunctionsResponse: - description: The FunctionsServiceListFunctionsResponse message. + x-speakeasy-name-override: XAAAccessProfile + c1.api.cross_app_access.v1.XAAAccessProfileHistoryEntry: + description: |- + XAAAccessProfileHistoryEntry is one version of an access profile and its + history metadata. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + title: Xaa Access Profile History Entry + type: object + x-speakeasy-name-override: XAAAccessProfileHistoryEntry + c1.api.cross_app_access.v1.XAAAccessProfileRef: + description: |- + XAAAccessProfileRef is a lightweight reference to an access profile, used for + websocket notifications and search filter refs. + properties: + appId: + description: The appId field. type: string - title: Functions Service List Functions Response + id: + description: The id field. + type: string + title: Xaa Access Profile Ref type: object - x-speakeasy-name-override: FunctionsServiceListFunctionsResponse - c1.api.functions.v1.FunctionsServiceListTagsResponse: - description: The FunctionsServiceListTagsResponse message. + x-speakeasy-name-override: XAAAccessProfileRef + c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding: + description: |- + XAAAccessProfileScopeBinding is a binding between an access profile and a + scope. Both ends belong to one resource server. properties: - tags: - additionalProperties: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' - description: The tags field. - readOnly: false - type: object - title: Functions Service List Tags Response + accessProfileId: + description: The access profile end of the binding. + type: string + appId: + description: The application that owns the resource server. + type: string + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + xaaResourceServerId: + description: The resource server both ends belong to. + type: string + xaaScopeId: + description: The scope end of the binding. + type: string + title: Xaa Access Profile Scope Binding type: object - x-speakeasy-name-override: FunctionsServiceListTagsResponse - c1.api.functions.v1.FunctionsServiceTestRequestInput: - description: FunctionsServiceTestRequest runs tests for a function at a specific commit. + x-speakeasy-name-override: XAAAccessProfileScopeBinding + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingRef: + description: |- + XAAAccessProfileScopeBindingRef is a lightweight reference to a binding, used + for websocket notifications and search filter refs. properties: - commitId: - description: The commit ID to test. If empty, the published commit is used. - readOnly: false + accessProfileId: + description: The accessProfileId field. type: string - title: Functions Service Test Request + appId: + description: The appId field. + type: string + xaaScopeId: + description: The xaaScopeId field. + type: string + title: Xaa Access Profile Scope Binding Ref type: object - x-speakeasy-name-override: FunctionsServiceTestRequest - c1.api.functions.v1.FunctionsServiceTestResponse: - description: FunctionsServiceTestResponse contains test execution results. + x-speakeasy-name-override: XAAAccessProfileScopeBindingRef + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput: + description: XAAAccessProfileScopeBindingServiceCreateRequest binds scopes to a profile. properties: - result: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult' - results: - description: All test results. + xaaScopeIds: + description: Scope IDs to bind to the access profile. items: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult' - nullable: true - readOnly: false - type: array - title: Functions Service Test Response + type: string + type: + - array + - "null" + title: Xaa Access Profile Scope Binding Service Create Request type: object - x-speakeasy-name-override: FunctionsServiceTestResponse - c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest: - description: The FunctionsServiceUpdateFunctionRequest message. + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceCreateRequest + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse: + description: XAAAccessProfileScopeBindingServiceCreateResponse returns created bindings. properties: - function: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - updateMask: - nullable: true - readOnly: false - type: string - title: Functions Service Update Function Request + bindings: + description: The created scope bindings. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding' + type: + - array + - "null" + title: Xaa Access Profile Scope Binding Service Create Response type: object - x-speakeasy-name-override: FunctionsServiceUpdateFunctionRequest - c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse: - description: The FunctionsServiceUpdateFunctionResponse message. + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceCreateResponse + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteRequestInput: + description: |- + XAAAccessProfileScopeBindingServiceDeleteRequest unbinds scopes from a + profile. properties: - function: - $ref: '#/components/schemas/c1.api.functions.v1.Function' - title: Functions Service Update Function Response + xaaScopeIds: + description: Scope IDs to unbind from the access profile. + items: + type: string + type: + - array + - "null" + title: Xaa Access Profile Scope Binding Service Delete Request type: object - x-speakeasy-name-override: FunctionsServiceUpdateFunctionResponse - c1.api.hooks.v1.BuiltInPattern: - description: | - BuiltInPattern references a ConductorOne-maintained DLP pattern. - The specific pattern and its configuration are encoded as a oneof. - - This message contains a oneof named config. Only a single field of the following list may be set at a time: - - piiRedaction - - creditCardBlocking - - queryScopeLimit - - writeAuthorization - - sensitiveFileGuard - nullable: true - properties: - creditCardBlocking: - $ref: '#/components/schemas/c1.api.hooks.v1.CreditCardBlockingConfig' - piiRedaction: - $ref: '#/components/schemas/c1.api.hooks.v1.PIIRedactionConfig' - queryScopeLimit: - $ref: '#/components/schemas/c1.api.hooks.v1.QueryScopeLimitConfig' - sensitiveFileGuard: - $ref: '#/components/schemas/c1.api.hooks.v1.SensitiveFileGuardConfig' - writeAuthorization: - $ref: '#/components/schemas/c1.api.hooks.v1.WriteAuthorizationConfig' - title: Built In Pattern + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceDeleteRequest + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteResponse: + description: XAAAccessProfileScopeBindingServiceDeleteResponse confirms deletion. + title: Xaa Access Profile Scope Binding Service Delete Response type: object - x-speakeasy-name-override: BuiltInPattern - c1.api.hooks.v1.BusinessHours: - description: BusinessHours defines a weekly time window in a specific timezone. + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceDeleteResponse + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceListResponse: + description: XAAAccessProfileScopeBindingServiceListResponse returns scope bindings. properties: - days: - description: 0=Sun, 1=Mon, ..., 6=Sat. + bindings: + description: The page of scope bindings. items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - end: - description: '"HH:MM" in 24-hour format.' - readOnly: false + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding' + type: + - array + - "null" + nextPageToken: + description: Token for the next page, or empty if there are no more results. type: string - start: - description: '"HH:MM" in 24-hour format.' - readOnly: false + title: Xaa Access Profile Scope Binding Service List Response + type: object + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceListResponse + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchRequest: + description: XAAAccessProfileScopeBindingServiceSearchRequest searches scope bindings. + properties: + accessProfileIds: + description: Optional filter by access profiles. Empty matches any access profile. + items: + type: string + type: + - array + - "null" + appId: + description: The application that owns the resource server (required). type: string - timezone: - description: The timezone field. - readOnly: false + pageSize: + description: Page size (max 100). + format: int32 + type: integer + pageToken: + description: Page token for pagination. type: string - title: Business Hours - type: object - x-speakeasy-name-override: BusinessHours - c1.api.hooks.v1.CreditCardBlockingConfig: - description: |- - CreditCardBlockingConfig denies any tool call whose output contains a - Luhn-valid credit card number. No configuration fields today; the - presence of the oneof arm is the whole configuration. - nullable: true - title: Credit Card Blocking Config + refs: + description: |- + Optional: fetch a specific set of bindings by ref (used by websocket + notify to re-fetch individual rows). + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingRef' + type: + - array + - "null" + xaaScopeIds: + description: |- + Optional filter by scopes (impact analysis: which profiles contain a + scope). Empty matches any scope. + items: + type: string + type: + - array + - "null" + title: Xaa Access Profile Scope Binding Service Search Request type: object - x-speakeasy-name-override: CreditCardBlockingConfig - c1.api.hooks.v1.Hook: - description: | - Hook represents a customer-configured interception point for tool calls. - - This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - - function - - builtinPattern + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceSearchRequest + c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchResponse: + description: XAAAccessProfileScopeBindingServiceSearchResponse returns matching bindings. properties: - builtinPattern: - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' - createdAt: - format: date-time - readOnly: true + list: + description: Matching scope bindings. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding' + type: + - array + - "null" + nextPageToken: + description: Token for the next page. type: string + title: Xaa Access Profile Scope Binding Service Search Response + type: object + x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceSearchResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateRequestInput: + description: XAAAccessProfileServiceCreateRequest creates a new access profile. + properties: description: - description: The description field. - readOnly: false + description: Description of what access this profile grants. type: string displayName: - description: The displayName field. - readOnly: false - type: string - enabled: - description: The enabled field. - readOnly: false - type: boolean - event: - description: The event field. - enum: - - HOOK_EVENT_TYPE_UNSPECIFIED - - HOOK_EVENT_TYPE_PRE_TOOL_USE - - HOOK_EVENT_TYPE_POST_TOOL_USE - readOnly: false + description: Display name for the profile. type: string - x-speakeasy-unknown-values: allow - filter: - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' - function: - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' - id: - description: The id field. - readOnly: false - type: string - priority: - description: The priority field. - format: int32 - readOnly: false - type: integer - updatedAt: - format: date-time - readOnly: true + xaaResourceServerId: + description: The resource server this profile grants access to. type: string - title: Hook + title: Xaa Access Profile Service Create Request type: object - x-speakeasy-name-override: Hook - c1.api.hooks.v1.HookFilter: - description: HookFilter determines which tool calls a hook applies to. + x-speakeasy-name-override: XAAAccessProfileServiceCreateRequest + c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateResponse: + description: XAAAccessProfileServiceCreateResponse returns the created access profile. properties: - celExpression: - description: |- - CEL expression evaluated against tool call context. - Available variable: ctx.tool_name (string). - Must evaluate to bool. Empty matches all tools. - readOnly: false - type: string - title: Hook Filter + accessProfile: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + title: Xaa Access Profile Service Create Response type: object - x-speakeasy-name-override: HookFilter - c1.api.hooks.v1.HookFunctionRef: - description: HookFunctionRef identifies a customer-authored function to invoke. - nullable: true + x-speakeasy-name-override: XAAAccessProfileServiceCreateResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteRequestInput: + description: XAAAccessProfileServiceDeleteRequest deletes an access profile (soft delete). + title: Xaa Access Profile Service Delete Request + type: object + x-speakeasy-name-override: XAAAccessProfileServiceDeleteRequest + c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteResponse: + description: XAAAccessProfileServiceDeleteResponse confirms deletion. + title: Xaa Access Profile Service Delete Response + type: object + x-speakeasy-name-override: XAAAccessProfileServiceDeleteResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceGetByAppEntitlementIdResponse: + description: |- + XAAAccessProfileServiceGetByAppEntitlementIdResponse returns the matched + profile. + properties: + accessProfile: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + title: Xaa Access Profile Service Get By App Entitlement Id Response + type: object + x-speakeasy-name-override: XAAAccessProfileServiceGetByAppEntitlementIdResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceGetResponse: + description: XAAAccessProfileServiceGetResponse returns a single access profile. + properties: + accessProfile: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + title: Xaa Access Profile Service Get Response + type: object + x-speakeasy-name-override: XAAAccessProfileServiceGetResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceListHistoryResponse: + description: |- + XAAAccessProfileServiceListHistoryResponse returns access profile history + entries. properties: - commitId: - description: If empty, the function's published commit is used at invocation time. - readOnly: false - type: string - functionId: - description: The functionId field. - readOnly: false + list: + description: The page of history entries, newest first. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. type: string - title: Hook Function Ref + title: Xaa Access Profile Service List History Response type: object - x-speakeasy-name-override: HookFunctionRef - c1.api.hooks.v1.HookRef: - description: The HookRef message. + x-speakeasy-name-override: XAAAccessProfileServiceListHistoryResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceListResponse: + description: XAAAccessProfileServiceListResponse returns a page of access profiles. properties: - id: - description: The id field. - readOnly: false + accessProfiles: + description: The page of access profiles. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + type: + - array + - "null" + nextPageToken: + description: Token for the next page, or empty if there are no more results. type: string - title: Hook Ref + title: Xaa Access Profile Service List Response type: object - x-speakeasy-name-override: HookRef - c1.api.hooks.v1.HooksSearchRequest: - description: The HooksSearchRequest message. + x-speakeasy-name-override: XAAAccessProfileServiceListResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchRequest: + description: XAAAccessProfileServiceSearchRequest searches access profiles with filters. properties: + appIds: + description: Optional filter by applications. Empty matches any application. + items: + type: string + type: + - array + - "null" pageSize: - description: The pageSize field. + description: Page size (max 100). format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: Page token for pagination. type: string query: - description: The query field. - readOnly: false + description: Optional text query matched against display_name. type: string refs: - description: The refs field. + description: |- + Optional: fetch a specific set of access profiles by ref (used by + websocket notify to re-fetch individual rows). items: - $ref: '#/components/schemas/c1.api.hooks.v1.HookRef' - nullable: true - readOnly: false - type: array - title: Hooks Search Request + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileRef' + type: + - array + - "null" + xaaResourceServerIds: + description: Optional filter by resource servers. Empty matches any resource server. + items: + type: string + type: + - array + - "null" + title: Xaa Access Profile Service Search Request type: object - x-speakeasy-name-override: HooksSearchRequest - c1.api.hooks.v1.HooksSearchResponse: - description: The HooksSearchResponse message. + x-speakeasy-name-override: XAAAccessProfileServiceSearchRequest + c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchResponse: + description: XAAAccessProfileServiceSearchResponse returns matching access profiles. properties: list: - description: The list field. + description: Matching access profiles. items: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: Token for the next page. type: string - title: Hooks Search Response + title: Xaa Access Profile Service Search Response type: object - x-speakeasy-name-override: HooksSearchResponse - c1.api.hooks.v1.HooksServiceCreateRequest: - description: | - The HooksServiceCreateRequest message. - - This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - - function - - builtinPattern + x-speakeasy-name-override: XAAAccessProfileServiceSearchResponse + c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateRequestInput: + description: XAAAccessProfileServiceUpdateRequest updates an existing access profile. properties: - builtinPattern: - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' - description: - description: The description field. - readOnly: false + accessProfile: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + updateMask: + type: + - string + - "null" + title: Xaa Access Profile Service Update Request + type: object + x-speakeasy-name-override: XAAAccessProfileServiceUpdateRequest + c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateResponse: + description: XAAAccessProfileServiceUpdateResponse returns the updated access profile. + properties: + accessProfile: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile' + - type: "null" + title: Xaa Access Profile Service Update Response + type: object + x-speakeasy-name-override: XAAAccessProfileServiceUpdateResponse + c1.api.cross_app_access.v1.XAAClientAudienceMapping: + description: |- + XAAClientAudienceMapping maps a client to its identifier at one resource + server. Never stores credential material. + properties: + audienceClientId: + description: |- + The client's identifier at the resource authorization server. Stamped + verbatim into the grant's client_id claim. type: string - displayName: - description: The displayName field. - readOnly: false + clientKey: + description: |- + Stable client registration key. One of: a DCR software_id form + (dcr://), a CIMD client_id URL, a native C1 form + (c1://), or a raw client_id. type: string - enabled: - description: The enabled field. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + disabled: + description: |- + When true, exchange requests from this client for this resource server are + rejected without removing the mapping (a kill switch). type: boolean - event: - description: The event field. - enum: - - HOOK_EVENT_TYPE_UNSPECIFIED - - HOOK_EVENT_TYPE_PRE_TOOL_USE - - HOOK_EVENT_TYPE_POST_TOOL_USE - readOnly: false + updatedAt: + format: date-time + type: + - string + - "null" + xaaResourceServerId: + description: The resource server this mapping applies to. type: string - x-speakeasy-unknown-values: allow - filter: - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' - function: - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' - priority: - description: The priority field. - format: int32 - readOnly: false - type: integer - required: - - displayName - title: Hooks Service Create Request + title: Xaa Client Audience Mapping type: object - x-speakeasy-name-override: HooksServiceCreateRequest - c1.api.hooks.v1.HooksServiceCreateResponse: - description: The HooksServiceCreateResponse message. + x-speakeasy-name-override: XAAClientAudienceMapping + c1.api.cross_app_access.v1.XAAClientAudienceMappingHistoryEntry: + description: |- + XAAClientAudienceMappingHistoryEntry is one version of a client audience + mapping and its history metadata. properties: - hook: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - title: Hooks Service Create Response + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + - type: "null" + title: Xaa Client Audience Mapping History Entry + type: object + x-speakeasy-name-override: XAAClientAudienceMappingHistoryEntry + c1.api.cross_app_access.v1.XAAClientAudienceMappingRef: + description: |- + XAAClientAudienceMappingRef is a lightweight reference to a mapping, used for + websocket notifications and search filter refs. + properties: + clientKey: + description: The clientKey field. + type: string + xaaResourceServerId: + description: The xaaResourceServerId field. + type: string + title: Xaa Client Audience Mapping Ref type: object - x-speakeasy-name-override: HooksServiceCreateResponse - c1.api.hooks.v1.HooksServiceDeleteRequestInput: - description: The HooksServiceDeleteRequest message. - title: Hooks Service Delete Request + x-speakeasy-name-override: XAAClientAudienceMappingRef + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceCreateRequestInput: + description: XAAClientAudienceMappingServiceCreateRequest creates a new mapping. + properties: + audienceClientId: + description: The client's identifier at the resource authorization server. + type: string + clientKey: + description: Stable client registration key. + type: string + disabled: + description: When true, the mapping is created but exchange requests are rejected. + type: boolean + title: Xaa Client Audience Mapping Service Create Request type: object - x-speakeasy-name-override: HooksServiceDeleteRequest - c1.api.hooks.v1.HooksServiceDeleteResponse: - description: The HooksServiceDeleteResponse message. - title: Hooks Service Delete Response + x-speakeasy-name-override: XAAClientAudienceMappingServiceCreateRequest + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceCreateResponse: + description: XAAClientAudienceMappingServiceCreateResponse returns the created mapping. + properties: + clientAudienceMapping: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + - type: "null" + title: Xaa Client Audience Mapping Service Create Response type: object - x-speakeasy-name-override: HooksServiceDeleteResponse - c1.api.hooks.v1.HooksServiceGetResponse: - description: The HooksServiceGetResponse message. + x-speakeasy-name-override: XAAClientAudienceMappingServiceCreateResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceDeleteRequestInput: + description: XAAClientAudienceMappingServiceDeleteRequest deletes a mapping (soft delete). properties: - hook: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - title: Hooks Service Get Response + clientKey: + description: The client key identifying the mapping. + type: string + title: Xaa Client Audience Mapping Service Delete Request type: object - x-speakeasy-name-override: HooksServiceGetResponse - c1.api.hooks.v1.HooksServiceListResponse: - description: The HooksServiceListResponse message. + x-speakeasy-name-override: XAAClientAudienceMappingServiceDeleteRequest + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceDeleteResponse: + description: XAAClientAudienceMappingServiceDeleteResponse confirms deletion. + title: Xaa Client Audience Mapping Service Delete Response + type: object + x-speakeasy-name-override: XAAClientAudienceMappingServiceDeleteResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceGetResponse: + description: XAAClientAudienceMappingServiceGetResponse returns a single mapping. + properties: + clientAudienceMapping: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + - type: "null" + title: Xaa Client Audience Mapping Service Get Response + type: object + x-speakeasy-name-override: XAAClientAudienceMappingServiceGetResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceListHistoryResponse: + description: |- + XAAClientAudienceMappingServiceListHistoryResponse returns client audience + mapping history entries. properties: list: - description: The list field. + description: The page of history entries, newest first. items: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingHistoryEntry' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: Pagination token for the next page, or empty if there are no more results. type: string - title: Hooks Service List Response + title: Xaa Client Audience Mapping Service List History Response type: object - x-speakeasy-name-override: HooksServiceListResponse - c1.api.hooks.v1.HooksServiceUpdateRequestInput: - description: The HooksServiceUpdateRequest message. + x-speakeasy-name-override: XAAClientAudienceMappingServiceListHistoryResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceListResponse: + description: XAAClientAudienceMappingServiceListResponse returns a page of mappings. properties: - hook: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - updateMask: - nullable: true - readOnly: false + clientAudienceMappings: + description: The page of mappings. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + type: + - array + - "null" + nextPageToken: + description: Token for the next page, or empty if there are no more results. type: string - title: Hooks Service Update Request + title: Xaa Client Audience Mapping Service List Response type: object - x-speakeasy-name-override: HooksServiceUpdateRequest - c1.api.hooks.v1.HooksServiceUpdateResponse: - description: The HooksServiceUpdateResponse message. + x-speakeasy-name-override: XAAClientAudienceMappingServiceListResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchRequest: + description: XAAClientAudienceMappingServiceSearchRequest searches mappings with filters. properties: - hook: - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' - title: Hooks Service Update Response + disabled: + description: Optional filter by disabled state. + type: + - boolean + - "null" + pageSize: + description: Page size (max 100). + format: int32 + type: integer + pageToken: + description: Page token for pagination. + type: string + query: + description: Optional text query matched against client_key and audience_client_id. + type: string + refs: + description: |- + Optional: fetch a specific set of mappings by ref (used by websocket + notify to re-fetch individual rows). + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingRef' + type: + - array + - "null" + xaaResourceServerIds: + description: Optional filter by resource servers. Empty matches any resource server. + items: + type: string + type: + - array + - "null" + title: Xaa Client Audience Mapping Service Search Request type: object - x-speakeasy-name-override: HooksServiceUpdateResponse - c1.api.hooks.v1.PIIRedactionConfig: - description: PIIRedactionConfig configures post-tool-use redaction of sensitive fields. - nullable: true + x-speakeasy-name-override: XAAClientAudienceMappingServiceSearchRequest + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchResponse: + description: XAAClientAudienceMappingServiceSearchResponse returns matching mappings. properties: - redactFields: - description: The redactFields field. + list: + description: Matching mappings. items: - type: string - nullable: true - readOnly: false - type: array - replacement: - description: The replacement field. - readOnly: false + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + type: + - array + - "null" + nextPageToken: + description: Token for the next page. type: string - title: Pii Redaction Config + title: Xaa Client Audience Mapping Service Search Response type: object - x-speakeasy-name-override: PIIRedactionConfig - c1.api.hooks.v1.QueryScopeLimitConfig: + x-speakeasy-name-override: XAAClientAudienceMappingServiceSearchResponse + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceUpdateRequestInput: + description: XAAClientAudienceMappingServiceUpdateRequest updates an existing mapping. + properties: + clientAudienceMapping: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + - type: "null" + updateMask: + type: + - string + - "null" + title: Xaa Client Audience Mapping Service Update Request + type: object + x-speakeasy-name-override: XAAClientAudienceMappingServiceUpdateRequest + c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceUpdateResponse: + description: XAAClientAudienceMappingServiceUpdateResponse returns the updated mapping. + properties: + clientAudienceMapping: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping' + - type: "null" + title: Xaa Client Audience Mapping Service Update Response + type: object + x-speakeasy-name-override: XAAClientAudienceMappingServiceUpdateResponse + c1.api.cross_app_access.v1.XAAModifyClaimsHook: description: |- - QueryScopeLimitConfig caps numeric fields (e.g. limit, page_size) in tool - input so callers cannot request unbounded data. - nullable: true + XAAModifyClaimsHook registers a tenant Function invoked just before a grant + is signed. The function may deny issuance or narrow the outgoing claims. It + always runs blocking and fails closed: any error, timeout, or invalid result + denies the grant. properties: - fields: - description: The fields field. - items: - type: string - nullable: true - readOnly: false - type: array - maxLimit: - description: The maxLimit field. - format: int32 - readOnly: false - type: integer - title: Query Scope Limit Config - type: object - x-speakeasy-name-override: QueryScopeLimitConfig - c1.api.hooks.v1.SensitiveFileGuardConfig: - description: |- - SensitiveFileGuardConfig blocks tool calls that reference sensitive file - paths or directories. - nullable: true - properties: - blockedDirectories: - description: The blockedDirectories field. - items: - type: string - nullable: true - readOnly: false - type: array - blockedPatterns: - description: The blockedPatterns field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Sensitive File Guard Config + commitId: + description: |- + Pin to a specific commit of the function. Empty uses the function's + published commit, resolved when the resource server is saved. + type: string + disabled: + description: When true, the hook is configured but not invoked. + type: boolean + functionId: + description: The Function to invoke. + type: string + title: Xaa Modify Claims Hook type: object - x-speakeasy-name-override: SensitiveFileGuardConfig - c1.api.hooks.v1.WriteAuthorizationConfig: + x-speakeasy-name-override: XAAModifyClaimsHook + c1.api.cross_app_access.v1.XAAResourceServer: description: |- - WriteAuthorizationConfig blocks tool calls whose ToolClassification is in - blocked_classifications, optionally permitting them within business hours. - nullable: true + XAAResourceServer is a third-party authorization server registered as a + permitted cross-app-access audience for one application. properties: - blockedClassifications: + appId: + description: The application this resource server fronts. + type: string + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + description: + description: Description of the resource server. + type: string + disabled: description: |- - Tool classifications to block. Must have at least one entry; a hook - with no blocked classifications would be a silent misconfiguration. - items: - enum: - - TOOL_CLASSIFICATION_UNSPECIFIED - - TOOL_CLASSIFICATION_READ - - TOOL_CLASSIFICATION_WRITE - - TOOL_CLASSIFICATION_DESTRUCTIVE - - TOOL_CLASSIFICATION_SENSITIVE - - TOOL_CLASSIFICATION_DANGEROUS - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - businessHours: - $ref: '#/components/schemas/c1.api.hooks.v1.BusinessHours' - title: Write Authorization Config - type: object - x-speakeasy-name-override: WriteAuthorizationConfig - c1.api.iam.v1.ActorObjectPermissions: - description: The ActorObjectPermissions message. - properties: - delete: - description: The delete field. - readOnly: false - type: boolean - edit: - description: The edit field. - readOnly: false + When true, exchange requests for this resource server are rejected without + removing the registration (a kill switch). type: boolean - extra: - additionalProperties: - type: boolean - description: The extra field. - readOnly: false - type: object - read: - description: The read field. - readOnly: false + displayName: + description: Display name for the resource server. + type: string + id: + description: Unique identifier for this resource server. + type: string + maxGrantLifetime: + format: duration + type: + - string + - "null" + modifyClaimsHook: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAModifyClaimsHook' + - type: "null" + normalizedAudience: + description: |- + The resource authorization server's issuer identifier (RFC 8414). Becomes + the audience of every grant minted for this server. Stored normalized: + lowercase scheme and host, no trailing slash, https only. Immutable after + creation. Must not equal your own tenant's issuer. + type: string + requireProofOfPossession: + description: |- + When true, mint proof-of-possession-bound grants for clients presenting a + DPoP proof. type: boolean - title: Actor Object Permissions - type: object - x-speakeasy-name-override: ActorObjectPermissions - c1.api.iam.v1.ExternalClientInfo: - description: |- - ExternalClientInfo provides information about an approved external client. - Used by both List (user's own grants) and Search (admin view of all grants). - properties: - clientId: - description: OAuth2 client ID - canonical identifier for this connection (globally unique per DCR) - readOnly: false + resourceUris: + description: |- + The resource identifiers this server governs (RFC 8707). An allowlist for + the token-exchange resource parameter; empty rejects any request that + carries a resource parameter. + items: + type: string + type: + - array + - "null" + sectorId: + description: |- + Optional pairwise sector override. Empty means the resource server's + audience is its own sector. Set to the well-known global sentinel sector to + opt into a correlatable shared `sub`, or to a shared value to share one + pairwise `sub` across a trust group of audiences. Immutable once set. type: string - clientIdType: - description: How the client_id was established. + signingAlgorithm: + description: |- + JWS algorithm for grants minted for this server. UNSPECIFIED uses the + tenant default. Minting fails if no active signing key exists for the + resolved algorithm. enum: - - CLIENT_ID_TYPE_UNSPECIFIED - - CLIENT_ID_TYPE_DCR - - CLIENT_ID_TYPE_METADATA_URL - readOnly: false + - XAA_SIGNING_ALGORITHM_UNSPECIFIED + - XAA_SIGNING_ALGORITHM_EDDSA + - XAA_SIGNING_ALGORITHM_RS256 + - XAA_SIGNING_ALGORITHM_ES256 type: string x-speakeasy-unknown-values: allow - clientIdUrl: - description: |- - Original CIMD metadata URL (e.g., "https://cursor.com/.well-known/oauth-client"). - Empty for DCR clients. - readOnly: false + updatedAt: + format: date-time + type: + - string + - "null" + title: Xaa Resource Server + type: object + x-speakeasy-name-override: XAAResourceServer + c1.api.cross_app_access.v1.XAAResourceServerHistoryEntry: + description: |- + XAAResourceServerHistoryEntry is one version of a resource server and its + history metadata. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + - type: "null" + title: Xaa Resource Server History Entry + type: object + x-speakeasy-name-override: XAAResourceServerHistoryEntry + c1.api.cross_app_access.v1.XAAResourceServerRef: + description: |- + XAAResourceServerRef is a lightweight reference to a resource server, used + for websocket notifications and search filter refs. + properties: + appId: + description: The appId field. type: string - clientName: - description: Original client name from DCR registration - readOnly: false + id: + description: The id field. type: string - createdAt: - format: date-time - readOnly: false + title: Xaa Resource Server Ref + type: object + x-speakeasy-name-override: XAAResourceServerRef + c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput: + description: XAAResourceServerServiceCreateRequest registers a new resource server. + properties: + description: + description: Description of the resource server. type: string + disabled: + description: |- + When true, the resource server is registered but exchange requests are + rejected. + type: boolean displayName: - description: User-provided custom name (defaults to client_name if not set) - readOnly: false - type: string - lastUsedAt: - format: date-time - readOnly: false + description: Display name for the resource server. type: string - mcpClientId: - description: MCP client record ID for AI governance tracking. May be empty for legacy grants. - readOnly: false + maxGrantLifetime: + format: duration + type: + - string + - "null" + modifyClaimsHook: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAModifyClaimsHook' + - type: "null" + normalizedAudience: + description: |- + The resource authorization server's issuer identifier. Must not equal your + own tenant's issuer. Normalized and immutable after creation. type: string - roleIds: - description: Role IDs granted to this client - frontend can fetch display names via SearchRoles + requireProofOfPossession: + description: When true, mint proof-of-possession-bound grants. + type: boolean + resourceUris: + description: Resource identifiers this server governs (RFC 8707). items: type: string - nullable: true - readOnly: false - type: array - userId: - description: The user who approved this external client (always populated) - readOnly: false - type: string - verifiedDomain: + type: + - array + - "null" + signingAlgorithm: description: |- - Verified domain from the client_id URL (e.g., "cursor.com"). - Empty for DCR clients. - readOnly: false - type: string - wellKnownClient: - description: The wellKnownClient field. + JWS algorithm for grants minted for this server. UNSPECIFIED uses the + tenant default. enum: - - WELL_KNOWN_CLIENT_UNSPECIFIED - - WELL_KNOWN_CLIENT_UNKNOWN - - WELL_KNOWN_CLIENT_CLAUDE_AI - - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP - - WELL_KNOWN_CLIENT_CLAUDE_CODE - - WELL_KNOWN_CLIENT_MCP_INSPECTOR - - WELL_KNOWN_CLIENT_CHATGPT - - WELL_KNOWN_CLIENT_VSCODE - - WELL_KNOWN_CLIENT_CURSOR - - WELL_KNOWN_CLIENT_WINDSURF - - WELL_KNOWN_CLIENT_ZED - - WELL_KNOWN_CLIENT_JETBRAINS - - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT - readOnly: false + - XAA_SIGNING_ALGORITHM_UNSPECIFIED + - XAA_SIGNING_ALGORITHM_EDDSA + - XAA_SIGNING_ALGORITHM_RS256 + - XAA_SIGNING_ALGORITHM_ES256 type: string x-speakeasy-unknown-values: allow - title: External Client Info + title: Xaa Resource Server Service Create Request + type: object + x-speakeasy-name-override: XAAResourceServerServiceCreateRequest + c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse: + description: XAAResourceServerServiceCreateResponse returns the registered resource server. + properties: + resourceServer: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + - type: "null" + title: Xaa Resource Server Service Create Response + type: object + x-speakeasy-name-override: XAAResourceServerServiceCreateResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteRequestInput: + description: XAAResourceServerServiceDeleteRequest deletes a resource server (soft delete). + title: Xaa Resource Server Service Delete Request + type: object + x-speakeasy-name-override: XAAResourceServerServiceDeleteRequest + c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteResponse: + description: XAAResourceServerServiceDeleteResponse confirms deletion. + title: Xaa Resource Server Service Delete Response + type: object + x-speakeasy-name-override: XAAResourceServerServiceDeleteResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceGetResponse: + description: XAAResourceServerServiceGetResponse returns a single resource server. + properties: + resourceServer: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + - type: "null" + title: Xaa Resource Server Service Get Response + type: object + x-speakeasy-name-override: XAAResourceServerServiceGetResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceListHistoryResponse: + description: |- + XAAResourceServerServiceListHistoryResponse returns resource server history + entries. + properties: + list: + description: The page of history entries, newest first. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerHistoryEntry' + type: + - array + - "null" + nextPageToken: + description: Pagination token for the next page, or empty if there are no more results. + type: string + title: Xaa Resource Server Service List History Response type: object - x-speakeasy-name-override: ExternalClientInfo - c1.api.iam.v1.ExternalClientSearchServiceSearchRequest: - description: The ExternalClientSearchServiceSearchRequest message. + x-speakeasy-name-override: XAAResourceServerServiceListHistoryResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceListResponse: + description: XAAResourceServerServiceListResponse returns a page of resource servers. properties: - clientIdUrls: - description: |- - Exact-match filter on client_id values (e.g., CIMD URLs). - Returns only grants whose client_id matches one of these values. + nextPageToken: + description: Token for the next page, or empty if there are no more results. + type: string + resourceServers: + description: The page of resource servers. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + type: + - array + - "null" + title: Xaa Resource Server Service List Response + type: object + x-speakeasy-name-override: XAAResourceServerServiceListResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceSearchRequest: + description: XAAResourceServerServiceSearchRequest searches resource servers with filters. + properties: + appIds: + description: Optional filter by applications. Empty matches any application. items: type: string - nullable: true - readOnly: false - type: array + type: + - array + - "null" + disabled: + description: Optional filter by disabled state. + type: + - boolean + - "null" pageSize: - description: The pageSize field. + description: Page size (max 100). format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: Page token for pagination. type: string query: - description: Free-text search on client_name and user display name - readOnly: false + description: Optional text query matched against display_name and normalized_audience. type: string - users: - description: Filter by specific user IDs + refs: + description: |- + Optional: fetch a specific set of resource servers by ref (used by + websocket notify to re-fetch individual rows). items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - wellKnownClients: - description: Filter by well-known client type (e.g., CLAUDE_CODE, CURSOR, etc.) + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerRef' + type: + - array + - "null" + signingAlgorithmFilter: + description: Optional filter by signing algorithm. UNSPECIFIED means no filter. items: enum: - - WELL_KNOWN_CLIENT_UNSPECIFIED - - WELL_KNOWN_CLIENT_UNKNOWN - - WELL_KNOWN_CLIENT_CLAUDE_AI - - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP - - WELL_KNOWN_CLIENT_CLAUDE_CODE - - WELL_KNOWN_CLIENT_MCP_INSPECTOR - - WELL_KNOWN_CLIENT_CHATGPT - - WELL_KNOWN_CLIENT_VSCODE - - WELL_KNOWN_CLIENT_CURSOR - - WELL_KNOWN_CLIENT_WINDSURF - - WELL_KNOWN_CLIENT_ZED - - WELL_KNOWN_CLIENT_JETBRAINS - - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT + - XAA_SIGNING_ALGORITHM_UNSPECIFIED + - XAA_SIGNING_ALGORITHM_EDDSA + - XAA_SIGNING_ALGORITHM_RS256 + - XAA_SIGNING_ALGORITHM_ES256 type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: External Client Search Service Search Request + type: + - array + - "null" + title: Xaa Resource Server Service Search Request type: object - x-speakeasy-name-override: ExternalClientSearchServiceSearchRequest - c1.api.iam.v1.ExternalClientSearchServiceSearchResponse: - description: The ExternalClientSearchServiceSearchResponse message. + x-speakeasy-name-override: XAAResourceServerServiceSearchRequest + c1.api.cross_app_access.v1.XAAResourceServerServiceSearchResponse: + description: XAAResourceServerServiceSearchResponse returns matching resource servers. properties: list: - description: Uses ExternalClientInfo with user_id populated for admin views + description: Matching resource servers. items: - $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientInfo' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: Token for the next page. type: string - title: External Client Search Service Search Response + title: Xaa Resource Server Service Search Response type: object - x-speakeasy-name-override: ExternalClientSearchServiceSearchResponse - c1.api.iam.v1.GetRolesResponse: - description: The GetRolesResponse message contains the retrieved role. + x-speakeasy-name-override: XAAResourceServerServiceSearchResponse + c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateRequestInput: + description: XAAResourceServerServiceUpdateRequest updates an existing resource server. properties: - role: - $ref: '#/components/schemas/c1.api.iam.v1.Role' - title: Get Roles Response - type: object - x-speakeasy-name-override: GetRolesResponse - c1.api.iam.v1.ListRolesResponse: - description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. + resourceServer: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + - type: "null" + updateMask: + type: + - string + - "null" + title: Xaa Resource Server Service Update Request + type: object + x-speakeasy-name-override: XAAResourceServerServiceUpdateRequest + c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateResponse: + description: XAAResourceServerServiceUpdateResponse returns the updated resource server. + properties: + resourceServer: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer' + - type: "null" + title: Xaa Resource Server Service Update Response + type: object + x-speakeasy-name-override: XAAResourceServerServiceUpdateResponse + c1.api.cross_app_access.v1.XAAScope: + description: |- + XAAScope is a single OAuth scope exposed by a resource server, elevated into + a governable object bound to its own entitlement. properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - $ref: '#/components/schemas/c1.api.iam.v1.Role' - nullable: true - readOnly: false - type: array - nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + appEntitlementId: + description: The AppEntitlement created for this scope. type: string - title: List Roles Response - type: object - x-speakeasy-name-override: ListRolesResponse - c1.api.iam.v1.PersonalClient: - description: The PersonalClient message contains information about a presonal client credential. - properties: - allowSourceCidr: - description: |- - If set, only allows the CIDRs in the array to use the credential. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. - items: - type: string - nullable: true - readOnly: false - type: array - clientId: - description: The clientID of the credential. - readOnly: true + appId: + description: The application that owns the resource server. + type: string + classification: + description: Risk classification. + enum: + - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED + - XAA_SCOPE_CLASSIFICATION_READ + - XAA_SCOPE_CLASSIFICATION_WRITE + - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE + - XAA_SCOPE_CLASSIFICATION_SENSITIVE + - XAA_SCOPE_CLASSIFICATION_DANGEROUS type: string + x-speakeasy-unknown-values: allow createdAt: format: date-time - readOnly: true - type: string + type: + - string + - "null" deletedAt: format: date-time - readOnly: true + type: + - string + - "null" + description: + description: Description of what the scope grants. type: string displayName: - description: The display name of the personal client credential. - readOnly: false - type: string - expiresTime: - format: date-time - readOnly: false + description: Display name for the scope. type: string id: - description: The unique ID of the personal client credential. - readOnly: true + description: Unique identifier for this scope. type: string - lastUsedAt: + lastDiscoveredAt: format: date-time - readOnly: true - type: string - scopedRoles: + type: + - string + - "null" + scopeValue: description: |- - scoped_roles provides a list of IAM Roles - that this OAuth2 Client's API permissions - are reduced to. The permissions granted to OAuth2 Client - are AND'ed against the owning User's own permissions. - items: - type: string - nullable: true - readOnly: false - type: array + The literal OAuth scope string minted into the grant. Immutable after + creation (RFC 6749 charset, max 256 bytes). + type: string + source: + description: How C1 learned of the scope. + enum: + - XAA_SCOPE_SOURCE_UNSPECIFIED + - XAA_SCOPE_SOURCE_ADMIN_DECLARED + - XAA_SCOPE_SOURCE_DISCOVERED + type: string + x-speakeasy-unknown-values: allow + state: + description: Approval/lifecycle state. + enum: + - XAA_SCOPE_STATE_UNSPECIFIED + - XAA_SCOPE_STATE_PENDING_REVIEW + - XAA_SCOPE_STATE_ENABLED + - XAA_SCOPE_STATE_DISABLED + - XAA_SCOPE_STATE_REMOVED + type: string + x-speakeasy-unknown-values: allow updatedAt: format: date-time - readOnly: true + type: + - string + - "null" + xaaResourceServerId: + description: The resource server this scope belongs to. type: string - userId: - description: The ID of the user that this credential is created for. - readOnly: true + title: Xaa Scope + type: object + x-speakeasy-name-override: XAAScope + c1.api.cross_app_access.v1.XAAScopeHistoryEntry: + description: XAAScopeHistoryEntry is one version of a scope and its history metadata. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + - type: "null" + title: Xaa Scope History Entry + type: object + x-speakeasy-name-override: XAAScopeHistoryEntry + c1.api.cross_app_access.v1.XAAScopeRef: + description: |- + XAAScopeRef is a lightweight reference to a scope, used for websocket + notifications and search filter refs. + properties: + appId: + description: The appId field. type: string - title: Personal Client + id: + description: The id field. + type: string + title: Xaa Scope Ref type: object - x-speakeasy-name-override: PersonalClient - c1.api.iam.v1.PersonalClientSearchServiceSearchRequest: - description: The PersonalClientSearchServiceSearchRequest message. + x-speakeasy-name-override: XAAScopeRef + c1.api.cross_app_access.v1.XAAScopeServiceCreateRequestInput: + description: XAAScopeServiceCreateRequest declares a new scope. properties: - pageSize: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: A pagination token returned from a previous Search call. - readOnly: false + classification: + description: Risk classification. + enum: + - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED + - XAA_SCOPE_CLASSIFICATION_READ + - XAA_SCOPE_CLASSIFICATION_WRITE + - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE + - XAA_SCOPE_CLASSIFICATION_SENSITIVE + - XAA_SCOPE_CLASSIFICATION_DANGEROUS type: string - query: - description: A text query to filter personal clients by display name. - readOnly: false + x-speakeasy-unknown-values: allow + description: + description: Description of what the scope grants. type: string - users: - description: Filter results to personal clients owned by the specified users. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - title: Personal Client Search Service Search Request + displayName: + description: Display name for the scope. + type: string + scopeValue: + description: The literal OAuth scope string. Immutable after creation. + type: string + state: + description: Initial state. UNSPECIFIED defaults to PENDING_REVIEW. + enum: + - XAA_SCOPE_STATE_UNSPECIFIED + - XAA_SCOPE_STATE_PENDING_REVIEW + - XAA_SCOPE_STATE_ENABLED + - XAA_SCOPE_STATE_DISABLED + - XAA_SCOPE_STATE_REMOVED + type: string + x-speakeasy-unknown-values: allow + xaaResourceServerId: + description: The resource server this scope belongs to. + type: string + title: Xaa Scope Service Create Request type: object - x-speakeasy-name-override: PersonalClientSearchServiceSearchRequest - c1.api.iam.v1.PersonalClientSearchServiceSearchResponse: - description: The PersonalClientSearchServiceSearchResponse message. + x-speakeasy-name-override: XAAScopeServiceCreateRequest + c1.api.cross_app_access.v1.XAAScopeServiceCreateResponse: + description: XAAScopeServiceCreateResponse returns the created scope. + properties: + scope: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + - type: "null" + title: Xaa Scope Service Create Response + type: object + x-speakeasy-name-override: XAAScopeServiceCreateResponse + c1.api.cross_app_access.v1.XAAScopeServiceDeleteRequestInput: + description: XAAScopeServiceDeleteRequest deletes a scope (soft delete). + title: Xaa Scope Service Delete Request + type: object + x-speakeasy-name-override: XAAScopeServiceDeleteRequest + c1.api.cross_app_access.v1.XAAScopeServiceDeleteResponse: + description: XAAScopeServiceDeleteResponse confirms deletion. + title: Xaa Scope Service Delete Response + type: object + x-speakeasy-name-override: XAAScopeServiceDeleteResponse + c1.api.cross_app_access.v1.XAAScopeServiceGetResponse: + description: XAAScopeServiceGetResponse returns a single scope. + properties: + scope: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + - type: "null" + title: Xaa Scope Service Get Response + type: object + x-speakeasy-name-override: XAAScopeServiceGetResponse + c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse: + description: XAAScopeServiceListHistoryResponse returns scope history entries. properties: list: - description: The list of personal client credentials matching the search criteria. + description: The page of history entries, newest first. items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeHistoryEntry' + type: + - array + - "null" nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + description: Pagination token for the next page, or empty if there are no more results. type: string - title: Personal Client Search Service Search Response + title: Xaa Scope Service List History Response type: object - x-speakeasy-name-override: PersonalClientSearchServiceSearchResponse - c1.api.iam.v1.PersonalClientServiceCreateRequest: - description: The PersonalClientServiceCreateRequest message contains the fields for creating a new personal client. + x-speakeasy-name-override: XAAScopeServiceListHistoryResponse + c1.api.cross_app_access.v1.XAAScopeServiceListResponse: + description: XAAScopeServiceListResponse returns a page of scopes. properties: - allowSourceCidr: - description: |- - A list of CIDRs to restrict this credential to. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + nextPageToken: + description: Token for the next page, or empty if there are no more results. + type: string + scopes: + description: The page of scopes. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + type: + - array + - "null" + title: Xaa Scope Service List Response + type: object + x-speakeasy-name-override: XAAScopeServiceListResponse + c1.api.cross_app_access.v1.XAAScopeServiceSearchRequest: + description: XAAScopeServiceSearchRequest searches scopes with filters. + properties: + appIds: + description: Optional filter by applications. Empty matches any application. items: type: string - nullable: true - readOnly: false - type: array - displayName: - description: The display name for the new personal client. - readOnly: false + type: + - array + - "null" + classificationFilter: + description: Optional filter by classification. UNSPECIFIED means no filter. + items: + enum: + - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED + - XAA_SCOPE_CLASSIFICATION_READ + - XAA_SCOPE_CLASSIFICATION_WRITE + - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE + - XAA_SCOPE_CLASSIFICATION_SENSITIVE + - XAA_SCOPE_CLASSIFICATION_DANGEROUS + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: Page size (max 100). + format: int32 + type: integer + pageToken: + description: Page token for pagination. type: string - expires: - format: duration - readOnly: false + query: + description: Optional text query matched against scope_value and display_name. type: string - scopedRoles: - description: The list of roles to restrict the credential to. + refs: + description: |- + Optional: fetch a specific set of scopes by ref (used by websocket notify + to re-fetch individual rows). + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeRef' + type: + - array + - "null" + sourceFilter: + description: Optional filter by source. UNSPECIFIED means no filter. items: + enum: + - XAA_SCOPE_SOURCE_UNSPECIFIED + - XAA_SCOPE_SOURCE_ADMIN_DECLARED + - XAA_SCOPE_SOURCE_DISCOVERED type: string - nullable: true - readOnly: false - type: array - title: Personal Client Service Create Request + x-speakeasy-unknown-values: allow + type: + - array + - "null" + stateFilter: + description: Optional filter by state. UNSPECIFIED means no filter. + items: + enum: + - XAA_SCOPE_STATE_UNSPECIFIED + - XAA_SCOPE_STATE_PENDING_REVIEW + - XAA_SCOPE_STATE_ENABLED + - XAA_SCOPE_STATE_DISABLED + - XAA_SCOPE_STATE_REMOVED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + xaaResourceServerIds: + description: Optional filter by resource servers. Empty matches any resource server. + items: + type: string + type: + - array + - "null" + title: Xaa Scope Service Search Request type: object - x-speakeasy-name-override: PersonalClientServiceCreateRequest - c1.api.iam.v1.PersonalClientServiceCreateResponse: - description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. + x-speakeasy-name-override: XAAScopeServiceSearchRequest + c1.api.cross_app_access.v1.XAAScopeServiceSearchResponse: + description: XAAScopeServiceSearchResponse returns matching scopes. properties: - client: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - clientSecret: - description: The client secret that corresponds to the personal client. Make sure to save this, because it cannot be returned or queried again. - readOnly: false + list: + description: Matching scopes. + items: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + type: + - array + - "null" + nextPageToken: + description: Token for the next page. type: string - title: Personal Client Service Create Response + title: Xaa Scope Service Search Response type: object - x-speakeasy-name-override: PersonalClientServiceCreateResponse - c1.api.iam.v1.PersonalClientServiceDeleteRequestInput: - description: The PersonalClientServiceDeleteRequest message. - title: Personal Client Service Delete Request + x-speakeasy-name-override: XAAScopeServiceSearchResponse + c1.api.cross_app_access.v1.XAAScopeServiceUpdateRequestInput: + description: XAAScopeServiceUpdateRequest updates an existing scope. + properties: + scope: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + - type: "null" + updateMask: + type: + - string + - "null" + title: Xaa Scope Service Update Request type: object - x-speakeasy-name-override: PersonalClientServiceDeleteRequest - c1.api.iam.v1.PersonalClientServiceDeleteResponse: - description: The PersonalClientServiceDeleteResponse message. - title: Personal Client Service Delete Response + x-speakeasy-name-override: XAAScopeServiceUpdateRequest + c1.api.cross_app_access.v1.XAAScopeServiceUpdateResponse: + description: XAAScopeServiceUpdateResponse returns the updated scope. + properties: + scope: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope' + - type: "null" + title: Xaa Scope Service Update Response type: object - x-speakeasy-name-override: PersonalClientServiceDeleteResponse - c1.api.iam.v1.PersonalClientServiceGetResponse: - description: The PersonalClientServiceGetResponse message. + x-speakeasy-name-override: XAAScopeServiceUpdateResponse + c1.api.cross_app_access.v1.XAASettings: + description: XAASettings is the per-tenant cross-app-access issuer configuration. properties: - client: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - title: Personal Client Service Get Response + allowRefreshTokenSubjects: + description: |- + When true, accept refresh tokens as the exchange subject. Must remain false + until that path ships. + type: boolean + createdAt: + format: date-time + type: + - string + - "null" + defaultGrantLifetime: + format: duration + type: + - string + - "null" + defaultSigningAlgorithm: + description: Tenant-default signing algorithm. UNSPECIFIED resolves to ES256. + enum: + - XAA_SIGNING_ALGORITHM_UNSPECIFIED + - XAA_SIGNING_ALGORITHM_EDDSA + - XAA_SIGNING_ALGORITHM_RS256 + - XAA_SIGNING_ALGORITHM_ES256 + type: string + x-speakeasy-unknown-values: allow + enabled: + description: |- + Master switch for the cross-app-access issuer and its published metadata. + C1 also gates the feature behind an operator-controlled rollout flag; this + is the tenant administrator's intent. + type: boolean + enabledSigningAlgorithms: + description: |- + Algorithms this tenant maintains signing-key families for. EdDSA is always + implicitly present. + items: + enum: + - XAA_SIGNING_ALGORITHM_UNSPECIFIED + - XAA_SIGNING_ALGORITHM_EDDSA + - XAA_SIGNING_ALGORITHM_RS256 + - XAA_SIGNING_ALGORITHM_ES256 + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + xaaIdTokenLifetime: + format: duration + type: + - string + - "null" + title: Xaa Settings type: object - x-speakeasy-name-override: PersonalClientServiceGetResponse - c1.api.iam.v1.PersonalClientServiceListResponse: - description: The PersonalClientServiceListResponse message. + x-speakeasy-name-override: XAASettings + c1.api.cross_app_access.v1.XAASettingsHistoryEntry: + description: |- + XAASettingsHistoryEntry is one version of the cross-app-access settings and + its history metadata. + properties: + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata' + - type: "null" + snapshot: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettings' + - type: "null" + title: Xaa Settings History Entry + type: object + x-speakeasy-name-override: XAASettingsHistoryEntry + c1.api.cross_app_access.v1.XAASettingsServiceGetResponse: + description: XAASettingsServiceGetResponse returns the tenant's cross-app-access settings. + properties: + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettings' + - type: "null" + title: Xaa Settings Service Get Response + type: object + x-speakeasy-name-override: XAASettingsServiceGetResponse + c1.api.cross_app_access.v1.XAASettingsServiceListHistoryResponse: + description: |- + XAASettingsServiceListHistoryResponse returns cross-app-access settings + history entries. properties: list: - description: The list of personal client credentials owned by the calling user. + description: The page of history entries, newest first. items: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettingsHistoryEntry' + type: + - array + - "null" nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + description: Pagination token for the next page, or empty if there are no more results. type: string - title: Personal Client Service List Response + title: Xaa Settings Service List History Response type: object - x-speakeasy-name-override: PersonalClientServiceListResponse - c1.api.iam.v1.PersonalClientServiceUpdateRequestInput: - description: The PersonalClientServiceUpdateRequest message. + x-speakeasy-name-override: XAASettingsServiceListHistoryResponse + c1.api.cross_app_access.v1.XAASettingsServiceUpdateRequest: + description: |- + XAASettingsServiceUpdateRequest updates the tenant's cross-app-access + settings. properties: - client: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettings' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string - title: Personal Client Service Update Request - type: object - x-speakeasy-name-override: PersonalClientServiceUpdateRequest - c1.api.iam.v1.PersonalClientServiceUpdateResponse: - description: The PersonalClientServiceUpdateResponse message. - properties: - client: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' - title: Personal Client Service Update Response - type: object - x-speakeasy-name-override: PersonalClientServiceUpdateResponse - c1.api.iam.v1.Role: - description: Role is a role that can be assigned to a user in ConductorOne. + type: + - string + - "null" + title: Xaa Settings Service Update Request + type: object + x-speakeasy-name-override: XAASettingsServiceUpdateRequest + c1.api.cross_app_access.v1.XAASettingsServiceUpdateResponse: + description: XAASettingsServiceUpdateResponse returns the updated settings. + properties: + settings: + oneOf: + - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettings' + - type: "null" + title: Xaa Settings Service Update Response + type: object + x-speakeasy-name-override: XAASettingsServiceUpdateResponse + c1.api.decoy.v1.Decoy: + description: |- + Decoy is the read projection of a planted honey-credential. All + fields except annotations are server-managed. properties: + annotations: + additionalProperties: + type: string + description: |- + Customer-defined grouping/filtering bag. PATCH semantics on Update: + keys in the request overwrite, keys missing stay, keys set to empty + string delete. Copied onto the Finding produced when a decoy fires, + so routing rules can condition on the same keys. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() createdAt: format: date-time readOnly: true + type: + - string + - "null" + description: + description: The description field. type: string - deletedAt: - format: date-time - readOnly: true - type: string + disabled: + description: Admin-disabled. + type: boolean displayName: - description: The display name of the role. - readOnly: false + description: The displayName field. type: string id: - description: The id of the role. + description: The id field. readOnly: true type: string - name: - description: The internal name of the role. + kind: + description: The kind field. + enum: + - DECOY_KIND_UNSPECIFIED + - DECOY_KIND_USER_CLIENT_CREDENTIAL + - DECOY_KIND_CONNECTOR_CLIENT + - DECOY_KIND_WORKLOAD_FEDERATION + - DECOY_KIND_ACCESS_TOKEN readOnly: true type: string - permissions: - description: The list of permissions this role has. - items: - type: string - nullable: true - readOnly: false - type: array - serviceRoles: - description: The list of serviceRoles that this role has. - items: - type: string - nullable: true - readOnly: false - type: array - systemApiOnly: - description: This Role is intended for API keys usage only, and the user interface may not function as expected. + x-speakeasy-unknown-values: allow + lastUsedAt: + format: date-time readOnly: true - type: boolean - systemBuiltin: - description: The system builtin field. If this field is set, the role is not editable. + type: + - string + - "null" + materialFingerprintSha256: + description: |- + Hex-encoded SHA256 of the secret string vended at Create / Rotate. + Stable for the decoy's current material; changes only on Rotate. + Empty for WorkloadFederation decoys (no server-vended secret). readOnly: true - type: boolean + type: string updatedAt: format: date-time readOnly: true - type: string - title: Role + type: + - string + - "null" + title: Decoy type: object - x-speakeasy-name-override: Role - c1.api.iam.v1.UpdateRoleRequestInput: - description: The UpdateRoleRequest message contains the role to update and the update mask. + x-speakeasy-name-override: Decoy + c1.api.decoy.v1.DecoyAccessTokenInput: + description: |- + DecoyAccessTokenInput mints a session access-token decoy under an + existing User. properties: - role: - $ref: '#/components/schemas/c1.api.iam.v1.Role' - updateMask: - nullable: true - readOnly: false + expiresIn: + format: duration + type: + - string + - "null" + subjectUserId: + description: Existing User the access token's subject claim references. type: string - title: Update Role Request + title: Decoy Access Token Input type: object - x-speakeasy-name-override: UpdateRoleRequest - c1.api.iam.v1.UpdateRolesResponse: - description: UpdateRolesResponse is the response message containing the updated role. + x-speakeasy-name-override: DecoyAccessTokenInput + c1.api.decoy.v1.DecoyAccessTokenMaterial: + description: DecoyAccessTokenMaterial is returned for AccessToken decoys. properties: - role: - $ref: '#/components/schemas/c1.api.iam.v1.Role' - title: Update Roles Response + accessToken: + description: The accessToken field. + type: string + title: Decoy Access Token Material type: object - x-speakeasy-name-override: UpdateRolesResponse - c1.api.integration.connector.v1.CheckboxField: - description: The CheckboxField message. - nullable: true + x-speakeasy-name-override: DecoyAccessTokenMaterial + c1.api.decoy.v1.DecoyClientCredentialMaterial: + description: |- + DecoyClientCredentialMaterial is returned for UserClientCredential and + ConnectorClient decoys. properties: - checked: - description: The checked field. - readOnly: false - type: boolean - title: Checkbox Field - type: object - x-speakeasy-name-override: ConnectorCheckboxField - c1.api.integration.connector.v1.ConfigSchema: - description: The ConfigSchema message. - properties: - displayName: - description: The displayName field. - readOnly: false - type: string - fieldGroups: - description: Optional. Metadata for displaying fields in the UI. - items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.FieldGroup' - nullable: true - readOnly: false - type: array - fields: - description: The fields field. - items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.Field' - nullable: true - readOnly: false - type: array - helpUrl: - description: The helpUrl field. - readOnly: false - type: string - iconUrl: - deprecated: true - description: The iconUrl field. - readOnly: false - type: string - isOauth2: - description: The isOauth2 field. - readOnly: false - type: boolean - requiresExternalConnector: - description: The requiresExternalConnector field. - readOnly: false - type: boolean - supportsExternalResources: - description: The supportsExternalResources field. - readOnly: false - type: boolean - title: Config Schema - type: object - x-speakeasy-name-override: ConfigSchema - c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest: - description: ConnectorCatalogServiceConfigurationSchemaRequest is the request for retrieving a connector's configuration schema. - properties: - appId: - description: The ID of the app associated with the connector. Optional. - readOnly: false - type: string - catalogId: - description: The catalog entry ID identifying the connector type. - readOnly: false + clientId: + description: The clientId field. type: string - connectorId: - description: The ID of an existing connector to retrieve its current configuration schema. Optional. - readOnly: false + clientSecret: + description: The clientSecret field. type: string - title: Connector Catalog Service Configuration Schema Request + title: Decoy Client Credential Material type: object - x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaRequest - c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse: - description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. - properties: - formSchema: - $ref: '#/components/schemas/c1.api.form.v1.Form' - schema: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConfigSchema' - title: Connector Catalog Service Configuration Schema Response + x-speakeasy-name-override: DecoyClientCredentialMaterial + c1.api.decoy.v1.DecoyConnectorClientInput: + description: |- + DecoyConnectorClientInput plants a connector-shaped credential decoy. + The server allocates placement under the tenant's ConductorOne app; + the customer makes no app/connector choice. + title: Decoy Connector Client Input type: object - x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaResponse - c1.api.integration.connector.v1.Field: - description: | - The Field message. - - This message contains a oneof named field. Only a single field of the following list may be set at a time: - - str - - select - - random - - import - - oauth2 - - readOnly - - options - - checkbox - - secret - - strList - - text - - keyValue - - stringMap + x-speakeasy-name-override: DecoyConnectorClientInput + c1.api.decoy.v1.DecoySearchRequest: + description: The DecoySearchRequest message. properties: - additionalPlaceholder: + annotationKeys: description: |- - Optional. Additional placeholder text for the field - In cases where a single placeholder is not enough to describe the field - readOnly: false - type: string - checkbox: - $ref: '#/components/schemas/c1.api.integration.connector.v1.CheckboxField' - dependsOnFields: - description: The dependsOnFields field. + Filter to decoys that have at least one of these annotation keys + set. Empty means no annotation filter. Per-key constraints match + the c1api annotation-bag standard (min_len 1, max_len 128, same + regex used by every annotation-bag-typed field across c1api). items: type: string - nullable: true - readOnly: false - type: array - displayName: - description: Human-readable label for this Field - readOnly: false - type: string - helpUrl: - description: empty or https URL - readOnly: false - type: string - import: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ImportField' - keyValue: - $ref: '#/components/schemas/c1.api.integration.connector.v1.KeyValueField' - name: - description: Must not start with `C1_` and match [a-zA-Z0-9_]{2,64}. Must be unique within a connector. - readOnly: false - type: string - oauth2: - $ref: '#/components/schemas/c1.api.integration.connector.v1.OAuth2Field' - options: - $ref: '#/components/schemas/c1.api.integration.connector.v1.OptionsField' - placeholder: - description: The placeholder field. - readOnly: false - type: string - postCreate: - description: The postCreate field. - readOnly: false - type: boolean - random: - $ref: '#/components/schemas/c1.api.integration.connector.v1.RandomStringField' - readOnly: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ReadOnlyField' - secret: - $ref: '#/components/schemas/c1.api.integration.connector.v1.RotatableSecretField' - select: - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField' - str: - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringField' - strList: - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringListField' - stringMap: - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringMapField' - text: - $ref: '#/components/schemas/c1.api.integration.connector.v1.TextField' - title: Field - type: object - x-speakeasy-name-override: Field - c1.api.integration.connector.v1.FieldGroup: - description: The FieldGroup message. - properties: - default: - description: The default field. - readOnly: false + type: + - array + - "null" + hasBeenUsed: + description: |- + Filter to decoys that have been used at least once. False / unset + means no filter (show all). The "never used" case is not covered + in this filter; add an explicit field if needed. type: boolean - displayName: - description: Nice name this group (e.g. renders as a Tab label) - readOnly: false - type: string - fieldNames: - description: Field names are "guaranteed" to be unique, but can be repeated in and between lists. + kinds: + description: Filter by kind (OR within the list). Empty means any kind. items: + enum: + - DECOY_KIND_UNSPECIFIED + - DECOY_KIND_USER_CLIENT_CREDENTIAL + - DECOY_KIND_CONNECTOR_CLIENT + - DECOY_KIND_WORKLOAD_FEDERATION + - DECOY_KIND_ACCESS_TOKEN type: string - nullable: true - readOnly: false - type: array - helpText: - description: Optional. User-facing help text. - readOnly: false + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - name: - description: Unique ID. - readOnly: false + query: + description: |- + Free-text query against display_name and description. Empty means + no text filter. type: string - title: Field Group - type: object - x-speakeasy-name-override: FieldGroup - c1.api.integration.connector.v1.ImportField: - description: The ImportField message. - nullable: true - properties: - allowedExtensions: - description: The allowedExtensions field. + statuses: + description: Filter by status (OR within the list). Empty means any status. items: + enum: + - DECOY_STATUS_FILTER_UNSPECIFIED + - DECOY_STATUS_FILTER_ACTIVE + - DECOY_STATUS_FILTER_DISABLED type: string - nullable: true - readOnly: false - type: array - secret: - description: The secret field. - readOnly: false - type: boolean - valueValidator: - $ref: '#/components/schemas/validate.StringRules' - title: Import Field - type: object - x-speakeasy-name-override: ImportField - c1.api.integration.connector.v1.KeyValueField: - description: The KeyValueField message. - nullable: true - properties: - secret: - description: The secret field. - readOnly: false - type: boolean - supportsFileUpload: - description: When true, UI allows file uploads per key-value entry. - readOnly: false - type: boolean - title: Key Value Field - type: object - x-speakeasy-name-override: KeyValueField - c1.api.integration.connector.v1.OAuth2Field: - description: The OAuth2Field message. - nullable: true - title: O Auth 2 Field - type: object - x-speakeasy-name-override: OAuth2Field - c1.api.integration.connector.v1.OptionsField: - description: The OptionsField message. - nullable: true - title: Options Field - type: object - x-speakeasy-name-override: OptionsField - c1.api.integration.connector.v1.RandomStringField: - description: The RandomStringField message. - nullable: true - properties: - length: - description: The length field. - format: int32 - readOnly: false - type: integer - title: Random String Field - type: object - x-speakeasy-name-override: RandomStringField - c1.api.integration.connector.v1.ReadOnlyField: - description: The ReadOnlyField message. - nullable: true - title: Read Only Field - type: object - x-speakeasy-name-override: ReadOnlyField - c1.api.integration.connector.v1.RotatableSecretField: - description: The RotatableSecretField message. - nullable: true - title: Rotatable Secret Field + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Decoy Search Request type: object - x-speakeasy-name-override: RotatableSecretField - c1.api.integration.connector.v1.SelectField: - description: The SelectField message. - nullable: true + x-speakeasy-name-override: DecoySearchRequest + c1.api.decoy.v1.DecoySearchResponse: + description: The DecoySearchResponse message. properties: - items: - description: list of items that are selected from + list: + description: The list field. items: - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField.Item' - nullable: true - readOnly: false - type: array - title: Select Field + $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Decoy Search Response type: object - x-speakeasy-name-override: ConnectorSelectField - c1.api.integration.connector.v1.SelectField.Item: - description: The Item message. - properties: + x-speakeasy-name-override: DecoySearchResponse + c1.api.decoy.v1.DecoyServiceCreateRequest: + description: | + The DecoyServiceCreateRequest message. + + This message contains a oneof named create_input. Only a single field of the following list may be set at a time: + - userClientCredential + - connectorClient + - workloadFed + - accessToken + properties: + accessToken: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyAccessTokenInput' + - type: "null" + annotations: + additionalProperties: + type: string + description: The annotations field. + type: object + connectorClient: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyConnectorClientInput' + - type: "null" + description: + description: The description field. + type: string displayName: description: The displayName field. - readOnly: false - type: string - value: - description: The value field. - readOnly: false type: string - title: Item - type: object - x-speakeasy-name-override: Item - c1.api.integration.connector.v1.StringField: - description: The StringField message. - nullable: true + userClientCredential: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyUserClientCredentialInput' + - type: "null" + workloadFed: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyWorkloadFederationInput' + - type: "null" + title: Decoy Service Create Request + type: object + x-speakeasy-name-override: DecoyServiceCreateRequest + c1.api.decoy.v1.DecoyServiceCreateResponse: + description: The DecoyServiceCreateResponse message. + properties: + decoy: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + - type: "null" + material: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyVendingMaterial' + - type: "null" + title: Decoy Service Create Response + type: object + x-speakeasy-name-override: DecoyServiceCreateResponse + c1.api.decoy.v1.DecoyServiceDeleteRequestInput: + description: The DecoyServiceDeleteRequest message. + title: Decoy Service Delete Request + type: object + x-speakeasy-name-override: DecoyServiceDeleteRequest + c1.api.decoy.v1.DecoyServiceDeleteResponse: + description: The DecoyServiceDeleteResponse message. + title: Decoy Service Delete Response + type: object + x-speakeasy-name-override: DecoyServiceDeleteResponse + c1.api.decoy.v1.DecoyServiceGetResponse: + description: The DecoyServiceGetResponse message. + properties: + decoy: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + - type: "null" + title: Decoy Service Get Response + type: object + x-speakeasy-name-override: DecoyServiceGetResponse + c1.api.decoy.v1.DecoyServiceListResponse: + description: The DecoyServiceListResponse message. properties: - secret: - description: If secret, value is write-only in UI and a password-type form is used. - readOnly: false - type: boolean - valueValidator: - $ref: '#/components/schemas/validate.StringRules' - title: String Field - type: object - x-speakeasy-name-override: StringField - c1.api.integration.connector.v1.StringListField: - description: The StringListField message. - nullable: true + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Decoy Service List Response + type: object + x-speakeasy-name-override: DecoyServiceListResponse + c1.api.decoy.v1.DecoyServiceRotateRequestInput: + description: The DecoyServiceRotateRequest message. + title: Decoy Service Rotate Request + type: object + x-speakeasy-name-override: DecoyServiceRotateRequest + c1.api.decoy.v1.DecoyServiceRotateResponse: + description: The DecoyServiceRotateResponse message. + properties: + decoy: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + - type: "null" + material: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyVendingMaterial' + - type: "null" + title: Decoy Service Rotate Response + type: object + x-speakeasy-name-override: DecoyServiceRotateResponse + c1.api.decoy.v1.DecoyServiceUpdateRequestInput: + description: The DecoyServiceUpdateRequest message. + properties: + decoy: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Decoy Service Update Request + type: object + x-speakeasy-name-override: DecoyServiceUpdateRequest + c1.api.decoy.v1.DecoyServiceUpdateResponse: + description: The DecoyServiceUpdateResponse message. + properties: + decoy: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.Decoy' + - type: "null" + title: Decoy Service Update Response + type: object + x-speakeasy-name-override: DecoyServiceUpdateResponse + c1.api.decoy.v1.DecoyUserClientCredentialInput: + description: |- + DecoyUserClientCredentialInput plants a client-credential decoy + under an existing User. The User must be typ=HUMAN or typ=SERVICE. properties: - valueValidator: - $ref: '#/components/schemas/validate.StringRules' - title: String List Field + userId: + description: Existing User to plant the decoy credential under. + type: string + title: Decoy User Client Credential Input type: object - x-speakeasy-name-override: StringListField - c1.api.integration.connector.v1.StringMapField: - description: The StringMapField message. - nullable: true + x-speakeasy-name-override: DecoyUserClientCredentialInput + c1.api.decoy.v1.DecoyVendingMaterial: + description: | + DecoyVendingMaterial carries the freshly-vended secret material returned + exactly once at Create or Rotate. + + This message contains a oneof named material. Only a single field of the following list may be set at a time: + - clientCredential + - accessToken + - workloadFederation + properties: + accessToken: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyAccessTokenMaterial' + - type: "null" + clientCredential: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyClientCredentialMaterial' + - type: "null" + workloadFederation: + oneOf: + - $ref: '#/components/schemas/c1.api.decoy.v1.DecoyWorkloadFederationMaterial' + - type: "null" + title: Decoy Vending Material + type: object + x-speakeasy-name-override: DecoyVendingMaterial + c1.api.decoy.v1.DecoyWorkloadFederationInput: + description: |- + DecoyWorkloadFederationInput plants a workload-federation-trust decoy + under an existing Provider. The Provider must already be registered + so its JWKS is reachable for signature verification. properties: - optional: - description: The optional field. - readOnly: false - type: boolean - title: String Map Field + conditionExpression: + description: |- + CEL boolean evaluated against the presented JWT's claims map. Same + shape as the regular WorkloadFederationTrust condition expression. + Example: `claims.sub.startsWith("repo:acme/fake-infra:")`. + type: string + providerId: + description: Existing WorkloadFederationProvider to bind the decoy Trust under. + type: string + servicePrincipalUserId: + description: Existing SERVICE-typed User the Trust would act-as on match. + type: string + title: Decoy Workload Federation Input type: object - x-speakeasy-name-override: StringMapField - c1.api.integration.connector.v1.TextField: - description: The TextField message. - nullable: true + x-speakeasy-name-override: DecoyWorkloadFederationInput + c1.api.decoy.v1.DecoyWorkloadFederationMaterial: + description: |- + DecoyWorkloadFederationMaterial is returned for WorkloadFederation + decoys. No vended secret; the operator binds the trust on the IdP side. properties: - secret: - description: The secret field. - readOnly: false - type: boolean - valueValidator: - $ref: '#/components/schemas/validate.StringRules' - title: Text Field + workloadFederationTrustId: + description: The workloadFederationTrustId field. + type: string + title: Decoy Workload Federation Material type: object - x-speakeasy-name-override: ConnectorTextField - c1.api.local_directory.v1.LocalDirectoryConfig: - description: |- - LocalDirectoryConfig is the public representation of a C1-managed local - directory configuration. The underlying directory infrastructure is provided - by the linked App (identified by app_id). + x-speakeasy-name-override: DecoyWorkloadFederationMaterial + c1.api.directory.v1.Directory: + description: | + This object indicates that an app is also a directory. + + This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: + - all + - celExpression properties: - allowSelfRegistration: - description: Whether unauthenticated users may self-register in this directory. - readOnly: false - type: boolean + all: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' + - type: "null" appId: - description: app_id is the identifier for this config and its linked App. Read-only after creation. + description: The ID of the app associated with the directory. readOnly: true type: string + celExpression: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' + - type: "null" createdAt: format: date-time readOnly: true - type: string - defaultProfileTypeId: - description: Optional FK to a ProfileType applied to new users created via this directory. - readOnly: false - type: string - displayName: - description: The displayName field. - readOnly: false - type: string - invitationTtl: - format: duration - readOnly: false - type: string - isDefault: - description: |- - Whether this is the default local directory for the tenant. - At most one config per tenant may be the default. - readOnly: false - type: boolean - onboardingFlowId: - description: Optional FK to an onboarding flow applied by default when inviting users. - readOnly: false - type: string - organizationId: - description: Optional FK to a ThirdPartyOrganization. Empty means standalone (no vendor linkage). - readOnly: false - type: string - selfRegistrationDomains: - description: |- - Email domain allowlist for self-registration. Empty allows any domain when - allow_self_registration is true. - items: - type: string - nullable: true - readOnly: false - type: array + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + mergeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' + - type: "null" updatedAt: format: date-time readOnly: true - type: string - title: Local Directory Config + type: + - string + - "null" + title: Directory type: object - x-speakeasy-name-override: LocalDirectoryConfig - c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest: - description: The LocalDirectoryConfigServiceCreateRequest message. + x-speakeasy-name-override: Directory + c1.api.directory.v1.DirectoryAccountFilterAll: + description: The DirectoryAccountFilterAll message. + title: Directory Account Filter All + type: object + x-speakeasy-name-override: DirectoryAccountFilterAll + c1.api.directory.v1.DirectoryAccountFilterCel: + description: The DirectoryAccountFilterCel message. properties: - allowSelfRegistration: - description: The allowSelfRegistration field. - readOnly: false - type: boolean - appId: - description: FK to the existing App that will back this local directory. - readOnly: false - type: string - defaultProfileTypeId: - description: The defaultProfileTypeId field. - readOnly: false - type: string - displayName: - description: The displayName field. - readOnly: false + expression: + description: The expression field. type: string - invitationTtl: - format: duration - readOnly: false + title: Directory Account Filter Cel + type: object + x-speakeasy-name-override: DirectoryAccountFilterCel + c1.api.directory.v1.DirectoryExpandMask: + description: The fields to be included in the directory response. + properties: + paths: + description: An array of fields to be included in the directory response. + items: + type: string + type: + - array + - "null" + title: Directory Expand Mask + type: object + x-speakeasy-name-override: DirectoryExpandMask + c1.api.directory.v1.DirectoryMergeConfig: + description: DirectoryMergeConfig configures how AppUsers from this directory are matched to C1 Users. + properties: + matchCases: + description: Ordered list of match cases evaluated in sequence. First match wins. + items: + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeMatchCase' + type: + - array + - "null" + title: Directory Merge Config + type: object + x-speakeasy-name-override: DirectoryMergeConfig + c1.api.directory.v1.DirectoryMergeMatchCase: + description: DirectoryMergeMatchCase defines a pair of CEL key extractors for matching. + properties: + appUserKeyCel: + description: CEL expression evaluated against an AppUser to produce match key(s). type: string - isDefault: - description: Whether this should be the default local directory for the tenant. - readOnly: false - type: boolean - onboardingFlowId: - description: The onboardingFlowId field. - readOnly: false + userKeyCel: + description: CEL expression evaluated against a User to produce match key(s). type: string - organizationId: - description: Optional FK to a ThirdPartyOrganization. - readOnly: false + title: Directory Merge Match Case + type: object + x-speakeasy-name-override: DirectoryMergeMatchCase + c1.api.directory.v1.DirectoryServiceCreateRequest: + description: | + Uplevel an app into a full directory. + + This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: + - all + - celExpression + properties: + all: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' + - type: "null" + appId: + description: The AppID to make into a directory, providing identities and more for the C1 app. type: string - selfRegistrationDomains: - description: The selfRegistrationDomains field. - items: - type: string - nullable: true - readOnly: false - type: array - required: - - appId - - displayName - title: Local Directory Config Service Create Request + celExpression: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryExpandMask' + - type: "null" + mergeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' + - type: "null" + title: Directory Service Create Request type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceCreateRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse: - description: The LocalDirectoryConfigServiceCreateResponse message. + x-speakeasy-name-override: DirectoryServiceCreateRequest + c1.api.directory.v1.DirectoryServiceCreateResponse: + description: The DirectoryServiceCreateResponse message. properties: - localDirectoryConfig: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - title: Local Directory Config Service Create Response + directoryView: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' + - type: "null" + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Directory Service Create Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceCreateResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput: - description: The LocalDirectoryConfigServiceDeleteRequest message. - title: Local Directory Config Service Delete Request + x-speakeasy-name-override: DirectoryServiceCreateResponse + c1.api.directory.v1.DirectoryServiceDeleteRequestInput: + description: DirectoryServiceDeleteRequest is the request message for deleting a directory. It uses URL values for input. + title: Directory Service Delete Request type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse: - description: The LocalDirectoryConfigServiceDeleteResponse message. - title: Local Directory Config Service Delete Response + x-speakeasy-name-override: DirectoryServiceDeleteRequest + c1.api.directory.v1.DirectoryServiceDeleteResponse: + description: Empty response with a status code indicating success. + title: Directory Service Delete Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse: - description: The LocalDirectoryConfigServiceGetResponse message. + x-speakeasy-name-override: DirectoryServiceDeleteResponse + c1.api.directory.v1.DirectoryServiceGetResponse: + description: |- + The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the + location in the expanded array that items are expanded as indicated by the expand mask in the request. properties: - localDirectoryConfig: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - title: Local Directory Config Service Get Response + directoryView: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' + - type: "null" + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Directory Service Get Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceGetResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse: - description: The LocalDirectoryConfigServiceListResponse message. + x-speakeasy-name-override: DirectoryServiceGetResponse + c1.api.directory.v1.DirectoryServiceListResponse: + description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. properties: + expanded: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: List of serialized related objects. type: string - title: Local Directory Config Service List Response + title: Directory Service List Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceListResponse - c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput: - description: The LocalDirectoryConfigServiceUpdateRequest message. + x-speakeasy-name-override: DirectoryServiceListResponse + c1.api.directory.v1.DirectoryServiceUpdateRequestInput: + description: | + Update a directory by app_id. + + This message contains a oneof named account_filter. Only a single field of the following list may be set at a time: + - all + - celExpression properties: - localDirectoryConfig: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - updateMask: - nullable: true - readOnly: false - type: string - title: Local Directory Config Service Update Request + all: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterAll' + - type: "null" + celExpression: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryAccountFilterCel' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryExpandMask' + - type: "null" + mergeConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryMergeConfig' + - type: "null" + title: Directory Service Update Request type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateRequest - c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse: - description: The LocalDirectoryConfigServiceUpdateResponse message. + x-speakeasy-name-override: DirectoryServiceUpdateRequest + c1.api.directory.v1.DirectoryServiceUpdateResponse: + description: The DirectoryServiceUpdateResponse message. properties: - localDirectoryConfig: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' - title: Local Directory Config Service Update Response + directoryView: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryView' + - type: "null" + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + title: Directory Service Update Response type: object - x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateResponse - c1.api.local_directory.v1.LocalUserInvitation: - description: LocalUserInvitation is the public representation of a per-directory user invitation. + x-speakeasy-name-override: DirectoryServiceUpdateResponse + c1.api.directory.v1.DirectoryView: + description: The directory view contains a directory and an app_path which is a JSONPATH set to the location in the expand mask that the expanded app will live if requested by the expander. properties: - acceptedAt: - format: date-time - readOnly: true - type: string - createdAt: - format: date-time - readOnly: true - type: string - createdUserId: - description: Set when status = ACCEPTED. FK to the created User. Read-only. - readOnly: true - type: string - directoryAppId: - description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. Read-only after creation. - readOnly: true - type: string - displayName: - description: Display name to pre-populate on the new user account. - readOnly: false - type: string - email: - description: Email address the invitation was sent to. - readOnly: false - type: string - expiresAt: - format: date-time - readOnly: true - type: string - id: - description: Unique KSUID identifier. Read-only. - readOnly: true - type: string - initialRoleIds: - description: Optional initial role IDs to assign to the user upon acceptance. - items: - type: string - nullable: true - readOnly: false - type: array - invitedByUserId: - description: FK to the User who created the invitation. Read-only. - readOnly: true - type: string - jobId: - description: Optional FK to a ThirdPartyJob. - readOnly: false - type: string - onboardingFlowId: - description: Optional onboarding flow override for this invitation. - readOnly: false - type: string - purpose: - description: Human-readable reason this user was invited. - readOnly: false + appPath: + description: JSONPATH expression indicating the location of the App object in the array. type: string - sponsorUserId: - description: Optional sponsor User override for this invitation. - readOnly: false + directory: + oneOf: + - $ref: '#/components/schemas/c1.api.directory.v1.Directory' + - type: "null" + title: Directory View + type: object + x-speakeasy-name-override: DirectoryView + c1.api.editor.v1.EditorMarker: + description: The EditorMarker message. + properties: + endColumn: + description: The endColumn field. + format: int32 + type: integer + endLineNumber: + description: The endLineNumber field. + format: int32 + type: integer + message: + description: The message field. type: string - status: - description: Current lifecycle status. Read-only. + severity: + description: The severity field. enum: - - LOCAL_INVITATION_STATUS_UNSPECIFIED - - LOCAL_INVITATION_STATUS_PENDING - - LOCAL_INVITATION_STATUS_ACCEPTED - - LOCAL_INVITATION_STATUS_REVOKED - - LOCAL_INVITATION_STATUS_EXPIRED - readOnly: true + - UNKNOWN + - HINT + - INFO + - WARNING + - ERROR type: string x-speakeasy-unknown-values: allow - updatedAt: + startColumn: + description: The startColumn field. + format: int32 + type: integer + startLineNumber: + description: The startLineNumber field. + format: int32 + type: integer + title: Editor Marker + type: object + x-speakeasy-name-override: EditorMarker + c1.api.finding.v1.AcceptRiskAction: + description: AcceptRiskAction parameters for UpdateFindingState. + properties: + expiresAt: format: date-time - readOnly: true + type: + - string + - "null" + justification: + description: The justification field. type: string - title: Local User Invitation + title: Accept Risk Action type: object - x-speakeasy-name-override: LocalUserInvitation - c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput: - description: The LocalUserInvitationServiceCreateRequest message. + x-speakeasy-name-override: AcceptRiskAction + c1.api.finding.v1.AcceptRiskRoutingAction: + description: |- + AcceptRiskRoutingAction accepts the risk for a matched finding for a + relative duration (resolved to risk_acceptance_expires_at = now + duration + at execution time). properties: - displayName: - description: The displayName field. - readOnly: false + duration: + format: duration + type: + - string + - "null" + reason: + description: The reason field. type: string - email: - description: The email field. - readOnly: false + title: Accept Risk Routing Action + type: object + x-speakeasy-name-override: AcceptRiskRoutingAction + c1.api.finding.v1.AppResourceTarget: + description: AppResourceTarget points at the app resource the finding is about. + properties: + appId: + description: The appId field. type: string - initialRoleIds: - description: Optional initial role IDs to assign upon acceptance. - items: - type: string - nullable: true - readOnly: false - type: array - jobId: - description: Optional FK to a ThirdPartyJob. - readOnly: false + appResourceId: + description: The appResourceId field. type: string - onboardingFlowId: - description: Optional onboarding flow override. - readOnly: false + appResourceTypeId: + description: The appResourceTypeId field. type: string - purpose: - description: Human-readable reason for the invitation. - readOnly: false + title: App Resource Target + type: object + x-speakeasy-name-override: AppResourceTarget + c1.api.finding.v1.AppUserTarget: + description: The AppUserTarget message. + properties: + appId: + description: The appId field. type: string - sponsorUserId: - description: Optional sponsor User override. - readOnly: false + appUserId: + description: The appUserId field. type: string - required: - - email - - displayName - title: Local User Invitation Service Create Request + title: App User Target type: object - x-speakeasy-name-override: LocalUserInvitationServiceCreateRequest - c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse: - description: The LocalUserInvitationServiceCreateResponse message. + x-speakeasy-name-override: AppUserTarget + c1.api.finding.v1.BulkAcceptRiskAction: + description: The BulkAcceptRiskAction message. properties: - invitation: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - title: Local User Invitation Service Create Response + expiresAt: + format: date-time + type: + - string + - "null" + justification: + description: The justification field. + type: string + title: Bulk Accept Risk Action type: object - x-speakeasy-name-override: LocalUserInvitationServiceCreateResponse - c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse: - description: The LocalUserInvitationServiceGetResponse message. + x-speakeasy-name-override: BulkAcceptRiskAction + c1.api.finding.v1.BulkAssignOwnerAction: + description: The BulkAssignOwnerAction message. properties: - invitation: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - title: Local User Invitation Service Get Response - type: object - x-speakeasy-name-override: LocalUserInvitationServiceGetResponse - c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput: - description: The LocalUserInvitationServiceRevokeRequest message. - title: Local User Invitation Service Revoke Request + owner: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' + - type: "null" + title: Bulk Assign Owner Action type: object - x-speakeasy-name-override: LocalUserInvitationServiceRevokeRequest - c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse: - description: The LocalUserInvitationServiceRevokeResponse message. + x-speakeasy-name-override: BulkAssignOwnerAction + c1.api.finding.v1.BulkCreateFindingTasksRequest: + description: The BulkCreateFindingTasksRequest message. properties: - invitation: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - title: Local User Invitation Service Revoke Response + policyId: + description: Optional policy ID to use for the created tasks. Defaults to the app's grant policy. + type: string + refs: + description: Individual finding references to create tasks for (by-ID mode). + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingRef' + type: + - array + - "null" + searchRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' + - type: "null" + title: Bulk Create Finding Tasks Request type: object - x-speakeasy-name-override: LocalUserInvitationServiceRevokeResponse - c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest: - description: The LocalUserInvitationServiceSearchRequest message. + x-speakeasy-name-override: BulkCreateFindingTasksRequest + c1.api.finding.v1.BulkCreateFindingTasksResponse: + description: The BulkCreateFindingTasksResponse message. properties: - directoryAppId: - description: The directoryAppId field. - readOnly: false + bulkActionId: + description: The ID of the asynchronous bulk action, which can be used to track progress. type: string - pageSize: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + title: Bulk Create Finding Tasks Response + type: object + x-speakeasy-name-override: BulkCreateFindingTasksResponse + c1.api.finding.v1.BulkReopenAction: + description: The BulkReopenAction message. + title: Bulk Reopen Action + type: object + x-speakeasy-name-override: BulkReopenAction + c1.api.finding.v1.BulkSnoozeAction: + description: The BulkSnoozeAction message. + properties: + reason: + description: The reason field. type: string - statusFilter: - description: Optional filter by invitation status. - enum: - - LOCAL_INVITATION_STATUS_UNSPECIFIED - - LOCAL_INVITATION_STATUS_PENDING - - LOCAL_INVITATION_STATUS_ACCEPTED - - LOCAL_INVITATION_STATUS_REVOKED - - LOCAL_INVITATION_STATUS_EXPIRED - readOnly: false + snoozeUntil: + format: date-time + type: + - string + - "null" + title: Bulk Snooze Action + type: object + x-speakeasy-name-override: BulkSnoozeAction + c1.api.finding.v1.BulkSuppressAction: + description: The BulkSuppressAction message. + properties: + reason: + description: The reason field. type: string - x-speakeasy-unknown-values: allow - title: Local User Invitation Service Search Request + title: Bulk Suppress Action type: object - x-speakeasy-name-override: LocalUserInvitationServiceSearchRequest - c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse: - description: The LocalUserInvitationServiceSearchResponse message. + x-speakeasy-name-override: BulkSuppressAction + c1.api.finding.v1.BulkUnsuppressAction: + deprecated: true + description: The BulkUnsuppressAction message. + title: Bulk Unsuppress Action + type: object + x-speakeasy-name-override: BulkUnsuppressAction + c1.api.finding.v1.BulkUpdateFindingStateRequest: + description: | + The BulkUpdateFindingStateRequest message. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - snooze + - suppress + - acceptRisk + - unsuppress + - assignOwner + - reopen properties: - list: - description: The list field. + acceptRisk: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkAcceptRiskAction' + - type: "null" + assignOwner: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkAssignOwnerAction' + - type: "null" + refs: + description: 'By-ID mode: specify individual finding refs.' items: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Local User Invitation Service Search Response + $ref: '#/components/schemas/c1.api.finding.v1.FindingRef' + type: + - array + - "null" + reopen: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkReopenAction' + - type: "null" + searchRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' + - type: "null" + snooze: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkSnoozeAction' + - type: "null" + suppress: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkSuppressAction' + - type: "null" + unsuppress: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.BulkUnsuppressAction' + - type: "null" + title: Bulk Update Finding State Request type: object - x-speakeasy-name-override: LocalUserInvitationServiceSearchResponse - c1.api.policy.v1.Accept: - description: This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - nullable: true + x-speakeasy-name-override: BulkUpdateFindingStateRequest + c1.api.finding.v1.BulkUpdateFindingStateResponse: + description: The BulkUpdateFindingStateResponse message. properties: - acceptMessage: - description: An optional message to include in the comments when a task is automatically accepted. - readOnly: false + bulkActionId: + description: The ID of the asynchronous bulk action, which can be used to track progress. type: string - title: Accept + title: Bulk Update Finding State Response type: object - x-speakeasy-name-override: Accept - c1.api.policy.v1.AcceptInstance: + x-speakeasy-name-override: BulkUpdateFindingStateResponse + c1.api.finding.v1.ConnectorAnomalyDetectionDisabledType: description: |- - This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - The instance is just a marker for it being copied into an active policy. - nullable: true + ConnectorAnomalyDetectionDisabledType: a connector has sync anomaly + detection turned off, so a sudden drop in synced data will not trip the + circuit breaker. Target: ConnectorTarget. + title: Connector Anomaly Detection Disabled Type + type: object + x-speakeasy-name-override: ConnectorAnomalyDetectionDisabledType + c1.api.finding.v1.ConnectorTarget: + description: ConnectorTarget points at the connector that produced this finding. properties: - acceptMessage: - description: An optional message to include in the comments when a task is automatically accepted. - readOnly: false + appId: + description: The appId field. type: string - title: Accept Instance + connectorId: + description: The connectorId field. + type: string + title: Connector Target type: object - x-speakeasy-name-override: AcceptInstance - c1.api.policy.v1.Action: + x-speakeasy-name-override: ConnectorTarget + c1.api.finding.v1.CreateFindingRequest: description: | - The Action message. + The CreateFindingRequest message. This message contains a oneof named target. Only a single field of the following list may be set at a time: - - automation - - batonResourceAction - - clientIdApproval - nullable: true - properties: - automation: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomation' - batonResourceAction: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceAction' - clientIdApproval: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApproval' - title: Action - type: object - x-speakeasy-name-override: Action - c1.api.policy.v1.ActionInstance: - description: | - The ActionInstance message. - - This message contains a oneof named target_instance. Only a single field of the following list may be set at a time: - - automation - - batonResourceActionInstance - - clientIdApprovalInstance - - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - success - - denied - - error - - cancelled - nullable: true + - identityUserTarget + - appUserTarget + - decoyTarget + - appResourceTarget + - connectorTarget + - tenantTarget properties: - action: - $ref: '#/components/schemas/c1.api.policy.v1.Action' - automation: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomationInstance' - batonResourceActionInstance: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceActionInstance' - cancelled: - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeCancelled' - clientIdApprovalInstance: - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApprovalInstance' - denied: - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeDenied' - error: - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeError' - state: - description: The current state of the action execution. + annotations: + additionalProperties: + type: string + description: Arbitrary metadata attached to the finding; filterable by routing rules. + type: object + appResourceTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AppResourceTarget' + - type: "null" + appUserTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AppUserTarget' + - type: "null" + connectorTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorTarget' + - type: "null" + customSubType: + description: |- + User-supplied sub-classification (e.g. "shadow_it"). Part of the dedup + identity and filterable via FindingSearch. + type: string + decoyTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DecoyTarget' + - type: "null" + dedupKeyParts: + description: |- + Caller-supplied dedup identity. The fingerprint is a domain-separated + SHA-256 over ("custom", custom_sub_type, dedup_key_parts...) — see + pkg/uhash; parts cannot collide regardless of their byte content. Two + creates with the same parts collapse onto one finding. Must be non-empty + and every part must be non-empty. + items: + type: string + type: + - array + - "null" + description: + description: Optional finding body (markdown by convention). + type: string + identityUserTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.IdentityUserTarget' + - type: "null" + remediationDescription: + description: |- + Optional remediation guidance, used as the body of any task created from + this finding. + type: string + severity: + description: Severity of the finding. Must be a defined, non-unspecified value. enum: - - ACTION_INSTANCE_STATE_UNSPECIFIED - - ACTION_INSTANCE_STATE_INIT - - ACTION_INSTANCE_STATE_RUNNING - - ACTION_INSTANCE_STATE_DONE - - ACTION_INSTANCE_STATE_ERROR - readOnly: false + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL type: string x-speakeasy-unknown-values: allow - success: - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeSuccess' - title: Action Instance + tenantTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.TenantTarget' + - type: "null" + title: Create Finding Request type: object - x-speakeasy-name-override: ActionInstance - c1.api.policy.v1.ActionOutcomeCancelled: - description: The ActionOutcomeCancelled message. - nullable: true + x-speakeasy-name-override: CreateFindingRequest + c1.api.finding.v1.CreateFindingResponse: + description: The CreateFindingResponse message. properties: - outcomeTime: - format: date-time - readOnly: false - type: string - title: Action Outcome Cancelled + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.Finding' + - type: "null" + title: Create Finding Response type: object - x-speakeasy-name-override: ActionOutcomeCancelled - c1.api.policy.v1.ActionOutcomeDenied: - description: The ActionOutcomeDenied message. - nullable: true + x-speakeasy-name-override: CreateFindingResponse + c1.api.finding.v1.CreateFindingRoutingRuleRequest: + description: The CreateFindingRoutingRuleRequest message. properties: - outcomeTime: - format: date-time - readOnly: false - type: string - title: Action Outcome Denied + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + - type: "null" + title: Create Finding Routing Rule Request type: object - x-speakeasy-name-override: ActionOutcomeDenied - c1.api.policy.v1.ActionOutcomeError: - description: The ActionOutcomeError message. - nullable: true + x-speakeasy-name-override: CreateFindingRoutingRuleRequest + c1.api.finding.v1.CreateFindingRoutingRuleResponse: + description: The CreateFindingRoutingRuleResponse message. properties: - errorCode: - description: The errorCode field. - readOnly: false - type: string - errorMessage: - description: The errorMessage field. - readOnly: false - type: string - outcomeTime: - format: date-time - readOnly: false - type: string - title: Action Outcome Error + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + - type: "null" + title: Create Finding Routing Rule Response type: object - x-speakeasy-name-override: ActionOutcomeError - c1.api.policy.v1.ActionOutcomeSuccess: - description: The ActionOutcomeSuccess message. - nullable: true + x-speakeasy-name-override: CreateFindingRoutingRuleResponse + c1.api.finding.v1.CreateFindingTaskRequestInput: + description: The CreateFindingTaskRequest message. properties: - outcomeTime: - format: date-time - readOnly: false + policyId: + description: |- + Optional policy ID. Defaults to the app's grant policy or the built-in + "Finding Review" policy. type: string - title: Action Outcome Success + title: Create Finding Task Request type: object - x-speakeasy-name-override: ActionOutcomeSuccess - c1.api.policy.v1.ActionProvision: - description: This provision step indicates that account lifecycle action should be called to provision this entitlement. - nullable: true + x-speakeasy-name-override: CreateFindingTaskRequest + c1.api.finding.v1.CreateFindingTaskResponse: + description: The CreateFindingTaskResponse message. properties: - actionName: - description: The actionName field. - readOnly: false + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.Finding' + - type: "null" + taskId: + description: The ID of the created task. type: string - appId: - description: The appId field. - readOnly: false + title: Create Finding Task Response + type: object + x-speakeasy-name-override: CreateFindingTaskResponse + c1.api.finding.v1.CreateFindingTransformationRuleRequest: + description: The CreateFindingTransformationRuleRequest message. + properties: + transformationRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + - type: "null" + title: Create Finding Transformation Rule Request + type: object + x-speakeasy-name-override: CreateFindingTransformationRuleRequest + c1.api.finding.v1.CreateFindingTransformationRuleResponse: + description: The CreateFindingTransformationRuleResponse message. + properties: + transformationRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + - type: "null" + title: Create Finding Transformation Rule Response + type: object + x-speakeasy-name-override: CreateFindingTransformationRuleResponse + c1.api.finding.v1.CreateTaskAction: + description: The CreateTaskAction message. + properties: + policyId: + description: The policyId field. type: string - connectorId: - description: The connectorId field. - readOnly: false + title: Create Task Action + type: object + x-speakeasy-name-override: CreateTaskAction + c1.api.finding.v1.CustomFindingType: + description: |- + CustomFindingType: a user- or integration-authored finding. The discriminator + carries no payload; the finding's content lives in description / + remediation_description / custom_tags. + title: Custom Finding Type + type: object + x-speakeasy-name-override: CustomFindingType + c1.api.finding.v1.DecoyCredentialUsedType: + description: |- + DecoyCredentialUsedType: a planted decoy credential authenticated + successfully. + properties: + decoyId: + description: The decoyId field. type: string - displayName: - description: The displayName field. - readOnly: false + kind: + description: The kind field. + enum: + - DECOY_CREDENTIAL_KIND_UNSPECIFIED + - DECOY_CREDENTIAL_KIND_USER_CLIENT_CREDENTIAL + - DECOY_CREDENTIAL_KIND_CONNECTOR_CLIENT + - DECOY_CREDENTIAL_KIND_WORKLOAD_FEDERATION + - DECOY_CREDENTIAL_KIND_ACCESS_TOKEN type: string - title: Action Provision + x-speakeasy-unknown-values: allow + title: Decoy Credential Used Type type: object - x-speakeasy-name-override: ActionProvision - c1.api.policy.v1.ActionTargetAutomation: - description: ActionTargetAutomation targets automation templates for policy actions. - nullable: true + x-speakeasy-name-override: DecoyCredentialUsedType + c1.api.finding.v1.DecoyTarget: + description: |- + DecoyTarget points at the planted decoy that produced this finding. + Populated for findings whose subject is the decoy artifact itself + (e.g. decoy_credential_used), giving the UI and routing rules a + uniform handle to the decoy alongside the finding_type payload. properties: - automationTemplateId: - description: The automationTemplateId field. - readOnly: false + decoyId: + description: The decoyId field. type: string - title: Action Target Automation + title: Decoy Target type: object - x-speakeasy-name-override: ActionTargetAutomation - c1.api.policy.v1.ActionTargetAutomationInstance: - description: The ActionTargetAutomationInstance message. - nullable: true - properties: - automationExecutionId: - description: The automationExecutionId field. - readOnly: false - type: string - title: Action Target Automation Instance + x-speakeasy-name-override: DecoyTarget + c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput: + description: The DeleteFindingRoutingRuleRequest message. + title: Delete Finding Routing Rule Request type: object - x-speakeasy-name-override: ActionTargetAutomationInstance - c1.api.policy.v1.ActionTargetBatonResourceAction: - description: ActionTargetResource targets resource actions for policy actions. - nullable: true - properties: - batonResourceActionId: - description: The batonResourceActionId field. - readOnly: false - type: string - title: Action Target Baton Resource Action + x-speakeasy-name-override: DeleteFindingRoutingRuleRequest + c1.api.finding.v1.DeleteFindingRoutingRuleResponse: + description: The DeleteFindingRoutingRuleResponse message. + title: Delete Finding Routing Rule Response type: object - x-speakeasy-name-override: ActionTargetBatonResourceAction - c1.api.policy.v1.ActionTargetBatonResourceActionInstance: - description: The ActionTargetBatonResourceActionInstance message. - nullable: true - properties: - batonActionInvocationId: - description: The batonActionInvocationId field. - readOnly: false - type: string - title: Action Target Baton Resource Action Instance + x-speakeasy-name-override: DeleteFindingRoutingRuleResponse + c1.api.finding.v1.DeleteFindingTransformationRuleRequestInput: + description: The DeleteFindingTransformationRuleRequest message. + title: Delete Finding Transformation Rule Request type: object - x-speakeasy-name-override: ActionTargetBatonResourceActionInstance - c1.api.policy.v1.ActionTargetClientIdApproval: - description: |- - ActionTargetClientIdApproval targets administrator review of an external - OAuth client registration (CIMD or DCR) for policy actions. - nullable: true - title: Action Target Client Id Approval + x-speakeasy-name-override: DeleteFindingTransformationRuleRequest + c1.api.finding.v1.DeleteFindingTransformationRuleResponse: + description: The DeleteFindingTransformationRuleResponse message. + title: Delete Finding Transformation Rule Response type: object - x-speakeasy-name-override: ActionTargetClientIdApproval - c1.api.policy.v1.ActionTargetClientIdApprovalInstance: - description: |- - ActionTargetClientIdApprovalInstance carries the registration key of the - external OAuth client that is being reviewed. - nullable: true + x-speakeasy-name-override: DeleteFindingTransformationRuleResponse + c1.api.finding.v1.Finding: + description: | + The Finding message. + + This message contains a oneof named finding_type. Only a single field of the following list may be set at a time: + - similarUsernameMatch + - serviceAccountMisclassification + - nhiUnowned + - serviceAccountUnowned + - decoyCredentialUsed + - custom + - connectorAnomalyDetectionDisabled + + + This message contains a oneof named target. Only a single field of the following list may be set at a time: + - identityUserTarget + - appUserTarget + - decoyTarget + - appResourceTarget + - tenantTarget + - connectorTarget + + + This message contains a oneof named evidence. Only a single field of the following list may be set at a time: + - similarUsernameMatchEvidence + - serviceAccountMisclassificationEvidence properties: - clientIdUrl: - description: The clientIdUrl field. - readOnly: false + appId: + description: The appId field. type: string - title: Action Target Client Id Approval Instance - type: object - x-speakeasy-name-override: ActionTargetClientIdApprovalInstance - c1.api.policy.v1.AgentApproval: - description: The agent to assign the task to. - nullable: true - properties: - agentFailureAction: - description: The action to take if the agent fails to approve, deny, or reassign the task. + appResourceTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AppResourceTarget' + - type: "null" + appUserTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AppUserTarget' + - type: "null" + assignedOwner: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' + - type: "null" + computedOwner: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingOwnerRef' + - type: "null" + connectorAnomalyDetectionDisabled: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorAnomalyDetectionDisabledType' + - type: "null" + connectorTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ConnectorTarget' + - type: "null" + createdAt: + format: date-time + type: + - string + - "null" + custom: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CustomFindingType' + - type: "null" + customSubType: + description: User-supplied sub-classification for custom findings (e.g. "shadow_it"). + type: string + customTags: + additionalProperties: + type: string + description: The customTags field. + type: object + decoyCredentialUsed: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DecoyCredentialUsedType' + - type: "null" + decoyTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.DecoyTarget' + - type: "null" + dedupKeyParts: + description: |- + Caller-supplied dedup identity for custom findings; echoed back so IaC + clients can roundtrip it. Empty for detector findings. + items: + type: string + type: + - array + - "null" + description: + description: User-authored finding body (markdown by convention). Set for custom findings. + type: string + fingerprint: + description: The fingerprint field. + type: string + firstObservedAt: + format: date-time + type: + - string + - "null" + id: + description: The id field. + type: string + identityUserTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.IdentityUserTarget' + - type: "null" + lastAppearedAt: + format: date-time + type: + - string + - "null" + lastObservedAt: + format: date-time + type: + - string + - "null" + nhiUnowned: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.NhiUnownedType' + - type: "null" + recurrenceCount: + description: The recurrenceCount field. + format: uint32 + type: integer + remediationDescription: + description: The remediationDescription field. + type: string + resolvedAt: + format: date-time + type: + - string + - "null" + riskAcceptanceExpiresAt: + format: date-time + type: + - string + - "null" + riskAcceptanceJustification: + description: The riskAcceptanceJustification field. + type: string + riskScore: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRiskScore' + - type: "null" + serviceAccountMisclassification: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ServiceAccountMisclassificationType' + - type: "null" + serviceAccountMisclassificationEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ServiceAccountMisclassificationEvidence' + - type: "null" + serviceAccountUnowned: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ServiceAccountUnownedType' + - type: "null" + severity: + description: The severity field. enum: - - APPROVAL_AGENT_FAILURE_ACTION_UNSPECIFIED - - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_USERS - - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_SUPER_ADMINS - - APPROVAL_AGENT_FAILURE_ACTION_SKIP_POLICY_STEP - readOnly: false + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL type: string x-speakeasy-unknown-values: allow - agentMode: - description: The mode of the agent, full control, change policy only, or comment only. + similarUsernameMatch: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SimilarUsernameMatchType' + - type: "null" + similarUsernameMatchEvidence: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SimilarUsernameMatchEvidence' + - type: "null" + snoozeReason: + description: The snoozeReason field. + type: string + snoozeUntil: + format: date-time + type: + - string + - "null" + sourceDetectorId: + description: The sourceDetectorId field. + type: string + sourceKind: + description: Who authored the finding (detector, user, external). enum: - - APPROVAL_AGENT_MODE_UNSPECIFIED - - APPROVAL_AGENT_MODE_FULL_CONTROL - - APPROVAL_AGENT_MODE_CHANGE_POLICY_ONLY - - APPROVAL_AGENT_MODE_COMMENT_ONLY - readOnly: false + - FINDING_SOURCE_KIND_UNSPECIFIED + - FINDING_SOURCE_KIND_DETECTOR + - FINDING_SOURCE_KIND_EXTERNAL type: string x-speakeasy-unknown-values: allow - agentUserId: - description: The agent user ID to assign the task to. - readOnly: false + state: + description: The state field. + enum: + - FINDING_STATE_UNSPECIFIED + - FINDING_STATE_OPEN + - FINDING_STATE_IN_PROGRESS + - FINDING_STATE_RESOLVED + - FINDING_STATE_SNOOZED + - FINDING_STATE_RISK_ACCEPTED + - FINDING_STATE_SUPPRESSED type: string - instructions: - description: Instructions for the agent. - readOnly: false + x-speakeasy-unknown-values: allow + stateUpdatedById: + description: The stateUpdatedById field. type: string - policyIds: - description: The allow list of policy IDs to re-route the task to. - items: - type: string - nullable: true - readOnly: false - type: array - reassignToUserIds: - description: The users to reassign the task to if the agent failure action is reassign to users. - items: - type: string - nullable: true - readOnly: false - type: array - title: Agent Approval + suppressReason: + description: The suppressReason field. + type: string + taskId: + description: The taskId field. + type: string + tenantTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.TenantTarget' + - type: "null" + updatedAt: + format: date-time + type: + - string + - "null" + title: Finding type: object - x-speakeasy-name-override: AgentApproval - c1.api.policy.v1.AppEntitlementReference: - description: This object references an app entitlement's ID and AppID. + x-speakeasy-name-override: Finding + c1.api.finding.v1.FindingAuditEvent: + description: |- + FindingAuditEvent is one row in a finding's audit stream. The metadata + columns are denormalized from the side-index so the list view renders + without hydrating the full OCSF payload for every row; ocsf is set to + the parsed OCSF event JSON for callers that want the per-event detail. properties: - appEntitlementId: - description: The ID of the Entitlement. - readOnly: false + actorPrincipalId: + description: |- + Principal id of the actor that performed the action. Empty for + system-driven events (snooze expiry, risk-acceptance expiry). + type: string + actorSubject: + description: |- + Display string for the actor (email for human users, "system" for + cron sweeps). type: string appId: - description: The ID of the App this entitlement belongs to. - readOnly: false + description: The appId field. type: string - title: App Entitlement Reference + bulkOperationId: + description: Stable id grouping events from the same bulk operation. + type: string + createdAt: + format: date-time + type: + - string + - "null" + eventId: + description: The eventId field. + type: string + eventType: + description: The eventType field. + enum: + - FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED + - FINDING_AUDIT_EVENT_TYPE_CREATED + - FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED + - FINDING_AUDIT_EVENT_TYPE_SNOOZED + - FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED + - FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED + - FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED + - FINDING_AUDIT_EVENT_TYPE_SUPPRESSED + - FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED + - FINDING_AUDIT_EVENT_TYPE_RESOLVED + - FINDING_AUDIT_EVENT_TYPE_REOPENED + - FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED + - FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN + - FINDING_AUDIT_EVENT_TYPE_COMMENT + - FINDING_AUDIT_EVENT_TYPE_TASK_CREATED + - FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED + - FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED + - FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED + - FINDING_AUDIT_EVENT_TYPE_TRANSFORMED + type: string + x-speakeasy-unknown-values: allow + findingId: + description: The findingId field. + type: string + ocsf: + additionalProperties: true + type: + - object + - "null" + severityAtEvent: + description: The severityAtEvent field. + enum: + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL + type: string + x-speakeasy-unknown-values: allow + stateAtEvent: + description: The stateAtEvent field. + enum: + - FINDING_STATE_UNSPECIFIED + - FINDING_STATE_OPEN + - FINDING_STATE_IN_PROGRESS + - FINDING_STATE_RESOLVED + - FINDING_STATE_SNOOZED + - FINDING_STATE_RISK_ACCEPTED + - FINDING_STATE_SUPPRESSED + type: string + x-speakeasy-unknown-values: allow + ticketId: + description: Ticket id when the event involved one; empty otherwise. + type: string + title: Finding Audit Event type: object - x-speakeasy-name-override: AppEntitlementReference - c1.api.policy.v1.AppGroupApproval: - description: The AppGroupApproval object provides the configuration for setting a group as the approvers of an approval policy step. - nullable: true + x-speakeasy-name-override: FindingAuditEvent + c1.api.finding.v1.FindingAuditServiceSearchRequest: + description: The FindingAuditServiceSearchRequest message. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is a member of the group during this step. - readOnly: false - type: boolean - appGroupId: - description: The ID of the group specified for approval. - readOnly: false + actorPrincipalId: + description: The actorPrincipalId field. + type: string + actorSubject: + description: |- + Partial match via full-text search over the denormalized actor email + / display name column. type: string appId: - description: The ID of the app that contains the group specified for approval. - readOnly: false + description: Empty skips the filter; non-empty must be a 27-char alphanumeric id. type: string - fallback: - description: Configuration to allow a fallback if the group is empty. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the group is empty. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the group is empty. + eventTypes: + description: Filter by one or more event types. Empty means any. items: + enum: + - FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED + - FINDING_AUDIT_EVENT_TYPE_CREATED + - FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED + - FINDING_AUDIT_EVENT_TYPE_SNOOZED + - FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED + - FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED + - FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED + - FINDING_AUDIT_EVENT_TYPE_SUPPRESSED + - FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED + - FINDING_AUDIT_EVENT_TYPE_RESOLVED + - FINDING_AUDIT_EVENT_TYPE_REOPENED + - FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED + - FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN + - FINDING_AUDIT_EVENT_TYPE_COMMENT + - FINDING_AUDIT_EVENT_TYPE_TASK_CREATED + - FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED + - FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED + - FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED + - FINDING_AUDIT_EVENT_TYPE_TRANSFORMED type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false - type: boolean - title: App Group Approval - type: object - x-speakeasy-name-override: AppGroupApproval - c1.api.policy.v1.AppOwnerApproval: - description: App owner approval provides the configuration for an approval step when the app owner is the target. - nullable: true - properties: - allowSelfApproval: - description: Configuration that allows a user to self approve if they are an app owner during this approval step. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false - type: boolean - title: App Owner Approval + x-speakeasy-unknown-values: allow + type: + - array + - "null" + findingId: + description: |- + Filter to a single finding. The detail-page timeline uses this. + Empty skips the filter; non-empty must be a 27-char alphanumeric id. + type: string + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + since: + format: date-time + type: + - string + - "null" + until: + format: date-time + type: + - string + - "null" + title: Finding Audit Service Search Request type: object - x-speakeasy-name-override: AppOwnerApproval - c1.api.policy.v1.AppOwnerProvisioner: - description: AppOwnerProvisioner resolves to app owners. - nullable: true + x-speakeasy-name-override: FindingAuditServiceSearchRequest + c1.api.finding.v1.FindingAuditServiceSearchResponse: + description: The FindingAuditServiceSearchResponse message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false - type: boolean - fallbackUserIds: - description: Fallback user IDs if no app owners are found. + list: + description: The list field. items: - type: string - nullable: true - readOnly: false - type: array - title: App Owner Provisioner + $ref: '#/components/schemas/c1.api.finding.v1.FindingAuditEvent' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Finding Audit Service Search Response type: object - x-speakeasy-name-override: AppOwnerProvisioner - c1.api.policy.v1.Approval: + x-speakeasy-name-override: FindingAuditServiceSearchResponse + c1.api.finding.v1.FindingOwnerRef: description: | - The Approval message. + The FindingOwnerRef message. - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - users - - manager - - appOwners - - group - - self - - entitlementOwners - - expression - - webhook - - resourceOwners - - agent - nullable: true + This message contains a oneof named owner. Only a single field of the following list may be set at a time: + - identityUserId + - appOwnerAppId + - managerOfUserId + - userSetId properties: - agent: - $ref: '#/components/schemas/c1.api.policy.v1.AgentApproval' - allowDelegation: - description: Whether ticket delegation is allowed for this step. - readOnly: false - type: boolean - allowReassignment: - description: Configuration to allow reassignment by reviewers during this step. - readOnly: false - type: boolean - allowedReassignees: - description: List of users for whom this step can be reassigned. - items: - type: string - nullable: true - readOnly: false - type: array - appOwners: - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerApproval' - assigned: - description: A field indicating whether this step is assigned. - readOnly: true - type: boolean - entitlementOwners: - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerApproval' - escalation: - $ref: '#/components/schemas/c1.api.policy.v1.Escalation' - escalationEnabled: - description: Whether escalation is enabled for this step. - readOnly: false - type: boolean - expression: - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionApproval' - group: - $ref: '#/components/schemas/c1.api.policy.v1.AppGroupApproval' - manager: - $ref: '#/components/schemas/c1.api.policy.v1.ManagerApproval' - requireApprovalReason: - description: Configuration to require a reason when approving this step. - readOnly: false - type: boolean - requireDenialReason: - description: Configuration to require a reason when denying this step. - readOnly: false - type: boolean - requireReassignmentReason: - description: Configuration to require a reason when reassigning this step. - readOnly: false - type: boolean - requiresStepUpProviderId: + appOwnerAppId: description: |- - The ID of a step-up authentication provider that will be required for approvals on this step. - If set, approvers must complete the step-up authentication flow before they can approve. - readOnly: false + The appOwnerAppId field. + This field is part of the `owner` oneof. + See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. + type: + - string + - "null" + identityUserId: + description: |- + The identityUserId field. + This field is part of the `owner` oneof. + See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. + type: + - string + - "null" + managerOfUserId: + description: |- + The managerOfUserId field. + This field is part of the `owner` oneof. + See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. + type: + - string + - "null" + userSetId: + description: |- + The userSetId field. + This field is part of the `owner` oneof. + See the documentation for `c1.api.finding.v1.FindingOwnerRef` for more details. + type: + - string + - "null" + title: Finding Owner Ref + type: object + x-speakeasy-name-override: FindingOwnerRef + c1.api.finding.v1.FindingRef: + description: The FindingRef message. + properties: + id: + description: The ID of the finding. type: string - resourceOwners: - $ref: '#/components/schemas/c1.api.policy.v1.ResourceOwnerApproval' - self: - $ref: '#/components/schemas/c1.api.policy.v1.SelfApproval' - users: - $ref: '#/components/schemas/c1.api.policy.v1.UserApproval' - webhook: - $ref: '#/components/schemas/c1.api.policy.v1.WebhookApproval' - title: Approval + title: Finding Ref type: object - x-speakeasy-name-override: Approval - c1.api.policy.v1.ApprovalInstance: - description: | - The approval instance object describes the way a policy step should be approved as well as its outcomes and state. - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - approved - - denied - - reassigned - - restarted - - reassignedByError - - skipped - nullable: true + x-speakeasy-name-override: FindingRef + c1.api.finding.v1.FindingRiskFactor: + description: The FindingRiskFactor message. properties: - approval: - $ref: '#/components/schemas/c1.api.policy.v1.Approval' - approved: - $ref: '#/components/schemas/c1.api.policy.v1.ApprovedAction' - assignedAt: - format: date-time - readOnly: true + description: + description: The description field. type: string - denied: - $ref: '#/components/schemas/c1.api.policy.v1.DeniedAction' - escalationInstance: - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance' - reassigned: - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' - reassignedByError: - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' - restarted: - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' - skipped: - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' - state: - description: The state of the approval instance + name: + description: The name field. + type: string + severity: + description: The severity field. enum: - - APPROVAL_INSTANCE_STATE_UNSPECIFIED - - APPROVAL_INSTANCE_STATE_INIT - - APPROVAL_INSTANCE_STATE_SENDING_NOTIFICATIONS - - APPROVAL_INSTANCE_STATE_WAITING - - APPROVAL_INSTANCE_STATE_DONE - readOnly: true + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL type: string x-speakeasy-unknown-values: allow - title: Approval Instance + weight: + description: The weight field. + format: uint32 + type: integer + title: Finding Risk Factor type: object - x-speakeasy-name-override: ApprovalInstance - c1.api.policy.v1.ApprovedAction: - description: The approved action indicates that the approvalinstance had an outcome of approved. - nullable: true + x-speakeasy-name-override: FindingRiskFactor + c1.api.finding.v1.FindingRiskScore: + description: The FindingRiskScore message. properties: - approvedAt: - format: date-time - readOnly: true + originalScore: + description: The originalScore field. + format: uint32 + type: integer + overrideByUserId: + description: The overrideByUserId field. type: string - entitlements: - description: The entitlements that were approved. This will only ever be a list of one entitlement. + overrideScore: + description: The overrideScore field. + format: uint32 + type: integer + riskFactors: + description: The riskFactors field. items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: true - type: array - stepUpTransactionId: - description: The ID of the step-up transaction that was used for this approval, if step-up was required. - readOnly: true - type: string - userId: - description: The UserID that approved this step. - readOnly: true - type: string - title: Approved Action + $ref: '#/components/schemas/c1.api.finding.v1.FindingRiskFactor' + type: + - array + - "null" + score: + description: The score field. + format: uint32 + type: integer + systemScore: + description: The systemScore field. + format: uint32 + type: integer + title: Finding Risk Score type: object - x-speakeasy-name-override: ApprovedAction - c1.api.policy.v1.CancelledAction: - description: The outcome of a provision instance that is cancelled. - nullable: true + x-speakeasy-name-override: FindingRiskScore + c1.api.finding.v1.FindingRoutingRule: + description: The FindingRoutingRule message. properties: - cancelledAt: - format: date-time - readOnly: false + action: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRuleAction' + - type: "null" + appId: + description: The appId field. type: string - cancelledByUserId: - description: The userID, usually the system, that cancells a provision instance. - readOnly: false + condition: + description: The condition field. type: string - title: Cancelled Action - type: object - x-speakeasy-name-override: CancelledAction - c1.api.policy.v1.CompletedAction: - description: The outcome of a provision instance that has been completed succesfully. - nullable: true - properties: - completedAt: + createdAt: format: date-time - readOnly: false + type: + - string + - "null" + description: + description: The description field. type: string - entitlements: - description: The list of entitlements that were provisioned. This is leftover from an older design, and is only ever going to be a single entitlement. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - userId: - description: The UserID of who completed provisioning. For connector provisioning this is the system user id, for manual provisioning this is who clicked "provision complete" - readOnly: false + displayName: + description: The displayName field. type: string - title: Completed Action - type: object - x-speakeasy-name-override: CompletedAction - c1.api.policy.v1.ConnectorProvision: - description: | - Indicates that a connector should perform the provisioning. This object has no fields. - - This message contains a oneof named provision_type. Only a single field of the following list may be set at a time: - - defaultBehavior - - account - - deleteAccount - nullable: true - properties: - account: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.AccountProvision' - defaultBehavior: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DefaultBehavior' - deleteAccount: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DeleteAccount' - title: Connector Provision + enabled: + description: The enabled field. + type: boolean + id: + description: The id field. + type: string + priority: + description: The priority field. + format: int32 + type: integer + templateId: + description: The templateId field. + type: string + updatedAt: + format: date-time + type: + - string + - "null" + title: Finding Routing Rule type: object - x-speakeasy-name-override: ConnectorProvision - c1.api.policy.v1.ConnectorProvision.AccountProvision: + x-speakeasy-name-override: FindingRoutingRule + c1.api.finding.v1.FindingRoutingRuleAction: description: | - The AccountProvision message. + The FindingRoutingRuleAction message. - This message contains a oneof named storage_type. Only a single field of the following list may be set at a time: - - saveToVault - - doNotSave - nullable: true + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - createTask + - suppress + - snooze + - acceptRisk properties: - config: - additionalProperties: true - readOnly: false - type: object - connectorId: - description: The connectorId field. - readOnly: false - type: string - doNotSave: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DoNotSave' - saveToVault: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.SaveToVault' - schemaId: - description: The schemaId field. - readOnly: false - type: string - title: Account Provision + acceptRisk: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AcceptRiskRoutingAction' + - type: "null" + createTask: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.CreateTaskAction' + - type: "null" + snooze: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SnoozeRoutingAction' + - type: "null" + suppress: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SuppressRoutingAction' + - type: "null" + title: Finding Routing Rule Action type: object - x-speakeasy-name-override: AccountProvision - c1.api.policy.v1.ConnectorProvision.DefaultBehavior: - description: The DefaultBehavior message. - nullable: true + x-speakeasy-name-override: FindingRoutingRuleAction + c1.api.finding.v1.FindingSearchRequest: + description: The FindingSearchRequest message. properties: - connectorId: + appIds: + description: Filter by app IDs (OR within field). + items: + type: string + type: + - array + - "null" + appResourceIds: description: |- - this checks if the entitlement is enabled by provisioning in a specific connector - this can happen automatically and doesn't need any extra info - readOnly: false - type: string - title: Default Behavior - type: object - x-speakeasy-name-override: DefaultBehavior - c1.api.policy.v1.ConnectorProvision.DeleteAccount: - description: The DeleteAccount message. - nullable: true - properties: - connectorId: - description: The connectorId field. - readOnly: false - type: string - title: Delete Account - type: object - x-speakeasy-name-override: DeleteAccount - c1.api.policy.v1.ConnectorProvision.DoNotSave: - description: The DoNotSave message. - nullable: true - title: Do Not Save - type: object - x-speakeasy-name-override: DoNotSave - c1.api.policy.v1.ConnectorProvision.SaveToVault: - description: The SaveToVault message. - nullable: true - properties: - vaultIds: - description: The vaultIds field. + Filter by app resource IDs (OR within field). Matches findings whose + target.app_resource_target.app_resource_id is in this list. An app resource + is app-scoped, so pair with app_ids (and app_resource_type_ids) to hit the + composite (tenant_id, app_id, app_resource_type_id, app_resource_id) index. items: type: string - nullable: true - readOnly: false - type: array - title: Save To Vault - type: object - x-speakeasy-name-override: SaveToVault - c1.api.policy.v1.CreatePolicyRequest: - description: The CreatePolicyRequest message is used to create a new policy. - properties: - description: - description: The description of the new policy. - readOnly: false + type: + - array + - "null" + appResourceTraitIds: + description: |- + Filter to findings whose target resource's type carries any of these traits + (e.g. the builtin agent / secret trait ids). OR within field; empty = not + applied. + items: + type: string + type: + - array + - "null" + appResourceTypeIds: + description: |- + Filter by app resource type IDs (OR within field). Matches findings whose + target.app_resource_target.app_resource_type_id is in this list. + items: + type: string + type: + - array + - "null" + appUserIds: + description: |- + Filter by app user IDs (OR within field). Matches findings whose + target.app_user_target.app_user_id is in this list. + items: + type: string + type: + - array + - "null" + appUserTypes: + description: |- + Filter to findings whose target is an app user of these types (OR within + field). Empty = not applied. + items: + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + connectorIds: + description: |- + Filter by connector IDs (OR within field). Matches findings whose + target.connector_target.connector_id is in this list. + items: + type: string + type: + - array + - "null" + customSubTypes: + description: |- + Filter by custom sub-type (OR within field). Matches custom findings whose + custom_sub_type equals any listed value. + items: + type: string + type: + - array + - "null" + decoyIds: + description: |- + Filter by decoy IDs (OR within field). Matches findings whose + target.decoy_target.decoy_id is in this list. + items: + type: string + type: + - array + - "null" + findingTypes: + description: Filter by finding type (OR within field). + items: + enum: + - FINDING_TYPE_UNSPECIFIED + - FINDING_TYPE_SIMILAR_USERNAME_MATCH + - FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION + - FINDING_TYPE_NHI_UNOWNED + - FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED + - FINDING_TYPE_DECOY_CREDENTIAL_USED + - FINDING_TYPE_CUSTOM + - FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + includeUnassigned: + description: |- + When true, includes findings with no effective identity-user owner. An + explicit predicate for direct API callers who prefer a bool over the + "unassigned" sentinel in owner_identity_user_ids; both signals are accepted. + type: boolean + nhiTypes: + description: |- + Filter to findings whose target resource's nhi_type is one of these (OR + within field). Empty = not applied; pass all NhiType values to match any + nhi resource. + items: + enum: + - NHI_TYPE_UNSPECIFIED + - NHI_TYPE_APP_REGISTRATION + - NHI_TYPE_ASSUMABLE_ROLE + - NHI_TYPE_MANAGED_IDENTITY + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + ownerIdentityUserIds: + description: |- + Filter by effective owner identity-user IDs (OR within field). Matches + findings whose effective owner (assigned_owner if set, else computed_owner) + resolves to an identity user in this list. The reserved "unassigned" + sentinel token selects findings with no effective identity-user owner; real + identity-user IDs are exactly 27 alphanumerics so the token cannot collide. + items: + type: string + type: + - array + - "null" + pageSize: + description: Maximum number of findings to return per page. + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response. type: string - displayName: - description: The display name of the new policy. - readOnly: false + query: + description: Free text search query. type: string - policySteps: - additionalProperties: - $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' + refs: description: |- - Step sequences for this policy. The map must include a baseline entry keyed - by the lowercased policy type (e.g., "grant"). Additional entries with - opaque keys can be added for conditional routing via the rules array. - readOnly: false - type: object - policyType: - description: The type of policy to create (grant, revoke, or certify). - enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION - readOnly: false - type: string - x-speakeasy-unknown-values: allow - postActions: - description: Ordered actions to execute after the policy completes processing. + Restrict results to these finding refs by ID (OR within field). Backs the + websocket-notify re-query, which refetches just the changed finding(s) to + patch a row in place or detect it dropping out of the filter; empty = not + applied. Hits the (tenant_id, id) primary key. items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' - nullable: true - readOnly: false - type: array - reassignTasksToDelegates: - deprecated: true - description: This field is no longer used. Configure delegate reassignment in the policy step instead. - readOnly: false + $ref: '#/components/schemas/c1.api.finding.v1.FindingRef' + type: + - array + - "null" + scopeToAppOwner: + description: |- + When true, restricts results to findings for apps you own. The caller is + resolved from request credentials (no user id is read from the request), + so results are always limited to your own apps. type: boolean - rules: - description: Conditional routing rules. See the Policy message for details on evaluation order. + severities: + description: Filter by severities (OR within field). items: - $ref: '#/components/schemas/c1.api.policy.v1.Rule' - nullable: true - readOnly: false - type: array - required: - - displayName - title: Create Policy Request + enum: + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + sourceKinds: + description: Filter by source kind (OR within field). + items: + enum: + - FINDING_SOURCE_KIND_UNSPECIFIED + - FINDING_SOURCE_KIND_DETECTOR + - FINDING_SOURCE_KIND_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + states: + description: Filter by states (OR within field). + items: + enum: + - FINDING_STATE_UNSPECIFIED + - FINDING_STATE_OPEN + - FINDING_STATE_IN_PROGRESS + - FINDING_STATE_RESOLVED + - FINDING_STATE_SNOOZED + - FINDING_STATE_RISK_ACCEPTED + - FINDING_STATE_SUPPRESSED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Finding Search Request type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: CreatePolicyRequest - c1.api.policy.v1.CreatePolicyResponse: - description: The CreatePolicyResponse message contains the created policy object. + x-speakeasy-name-override: FindingSearchRequest + c1.api.finding.v1.FindingSearchResponse: + description: The FindingSearchResponse message. properties: - policy: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - title: Create Policy Response + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.finding.v1.Finding' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Finding Search Response type: object - x-speakeasy-name-override: CreatePolicyResponse - c1.api.policy.v1.DelegatedProvision: - description: This provision step indicates that we should delegate provisioning to the configuration of another app entitlement. This app entitlement does not have to be one from the same app, but MUST be configured as a proxy binding leading into this entitlement. - nullable: true + x-speakeasy-name-override: FindingSearchResponse + c1.api.finding.v1.FindingTransform: + description: | + FindingTransform is a single mutation applied to a finding by a matched + transformation rule. Structured ops are the v1 authoring surface; a future + raw-CEL arm continues numbering at 103. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - setSeverity + - setTags + - removeTags + properties: + removeTags: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.RemoveTags' + - type: "null" + setSeverity: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SetSeverity' + - type: "null" + setTags: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SetTags' + - type: "null" + title: Finding Transform + type: object + x-speakeasy-name-override: FindingTransform + c1.api.finding.v1.FindingTransformationRule: + description: |- + FindingTransformationRule transforms a finding at processing time, before + routing runs. Rules fall through: every matching rule applies its transforms + in ascending evaluation_order; the last rule to write a given field wins. properties: appId: - description: The AppID of the entitlement to delegate provisioning to. - readOnly: false + description: The appId field. type: string - entitlementId: - description: The ID of the entitlement we are delegating provisioning to. - readOnly: false + condition: + description: |- + CEL boolean over the Finding object; empty matches all. Evaluated over + base/immutable inputs only (see the transformation env). type: string - implicit: - description: If true, a binding will be automatically created from the entitlement of the parent app. - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + description: + description: The description field. + type: string + displayName: + description: The displayName field. + type: string + enabled: + description: The enabled field. type: boolean - title: Delegated Provision + evaluationOrder: + description: |- + Application order (ascending; last-applied rule wins per field). A sequence, + not a precedence rank. + format: int32 + type: integer + id: + description: The id field. + type: string + templateId: + description: The templateId field. + type: string + transforms: + description: Ordered transforms applied when the rule matches. + items: + $ref: '#/components/schemas/c1.api.finding.v1.FindingTransform' + type: + - array + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + title: Finding Transformation Rule type: object - x-speakeasy-name-override: DelegatedProvision - c1.api.policy.v1.DeletePolicyRequestInput: - description: The DeletePolicyRequest message contains the ID of the policy to delete. It uses URL value for input. - title: Delete Policy Request + x-speakeasy-name-override: FindingTransformationRule + c1.api.finding.v1.GetFindingResponse: + description: The GetFindingResponse message. + properties: + expanded: + description: The expanded field. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.Finding' + - type: "null" + title: Get Finding Response type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: DeletePolicyRequest - c1.api.policy.v1.DeletePolicyResponse: - description: Empty response with a status code indicating success. - title: Delete Policy Response + x-speakeasy-name-override: GetFindingResponse + c1.api.finding.v1.GetFindingRoutingRuleResponse: + description: The GetFindingRoutingRuleResponse message. + properties: + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + - type: "null" + title: Get Finding Routing Rule Response type: object - x-speakeasy-name-override: DeletePolicyResponse - c1.api.policy.v1.DeniedAction: - description: The denied action indicates that the c1.api.policy.v1.ApprovalInstance had an outcome of denied. - nullable: true + x-speakeasy-name-override: GetFindingRoutingRuleResponse + c1.api.finding.v1.GetFindingTransformationRuleResponse: + description: The GetFindingTransformationRuleResponse message. properties: - deniedAt: - format: date-time - readOnly: true - type: string - userId: - description: The UserID that denied this step. - readOnly: true - type: string - title: Denied Action + transformationRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + - type: "null" + title: Get Finding Transformation Rule Response type: object - x-speakeasy-name-override: DeniedAction - c1.api.policy.v1.EditorValidateRequest: - description: The EditorValidateRequest message. + x-speakeasy-name-override: GetFindingTransformationRuleResponse + c1.api.finding.v1.IdentityUserTarget: + description: The IdentityUserTarget message. properties: - text: - description: The text field. - readOnly: false + identityUserId: + description: The identityUserId field. type: string - title: Editor Validate Request + title: Identity User Target type: object - x-speakeasy-name-override: PolicyEditorValidateRequest - c1.api.policy.v1.EditorValidateResponse: - description: The EditorValidateResponse message. + x-speakeasy-name-override: IdentityUserTarget + c1.api.finding.v1.ListFindingRoutingRulesResponse: + description: The ListFindingRoutingRulesResponse message. properties: - markers: - description: The markers field. + list: + description: The list field. items: - $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' - nullable: true - readOnly: false - type: array - title: Editor Validate Response + $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: List Finding Routing Rules Response type: object - x-speakeasy-name-override: PolicyEditorValidateResponse - c1.api.policy.v1.EntitlementOwnerApproval: - description: The entitlement owner approval allows configuration of the approval step when the target approvers are the entitlement owners. - nullable: true + x-speakeasy-name-override: ListFindingRoutingRulesResponse + c1.api.finding.v1.ListFindingTransformationRulesResponse: + description: The ListFindingTransformationRulesResponse message. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is an entitlement owner during this step. - readOnly: false - type: boolean - fallback: - description: Configuration to allow a fallback if the entitlement owner cannot be identified. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the entitlement owner cannot be identified. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the entitlement owner cannot be identified. + list: + description: The list field. items: - type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false - type: boolean - title: Entitlement Owner Approval + $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: List Finding Transformation Rules Response type: object - x-speakeasy-name-override: EntitlementOwnerApproval - c1.api.policy.v1.EntitlementOwnerProvisioner: - description: EntitlementOwnerProvisioner resolves to entitlement owners. - nullable: true + x-speakeasy-name-override: ListFindingTransformationRulesResponse + c1.api.finding.v1.NhiUnownedType: + description: |- + NhiUnownedType: an AppResource with a non-human-identity type has no + primary owner. Target: AppResourceTarget (the unowned NHI resource). + title: Nhi Unowned Type + type: object + x-speakeasy-name-override: NhiUnownedType + c1.api.finding.v1.RemoveTags: + description: The RemoveTags message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false - type: boolean - fallbackUserIds: - description: Fallback user IDs if no entitlement owners are found. + keys: + description: The keys field. items: type: string - nullable: true - readOnly: false - type: array - title: Entitlement Owner Provisioner + type: + - array + - "null" + title: Remove Tags type: object - x-speakeasy-name-override: EntitlementOwnerProvisioner - c1.api.policy.v1.ErroredAction: - description: The outcome of a provision instance that has errored. - nullable: true + x-speakeasy-name-override: RemoveTags + c1.api.finding.v1.ReopenAction: + description: ReopenAction parameters for UpdateFindingState. + title: Reopen Action + type: object + x-speakeasy-name-override: ReopenAction + c1.api.finding.v1.ResolveAction: + description: ResolveAction parameters for UpdateFindingState (manual resolve). properties: - description: - description: The description of a provision instance that has errored. - readOnly: false - type: string - errorCode: - description: The error code of a provision instance that has errored. This is only PEC-1 for now, but more will be added in the future. - readOnly: false + reason: + description: The reason field. type: string - erroredAt: - format: date-time - readOnly: false + title: Resolve Action + type: object + x-speakeasy-name-override: ResolveAction + c1.api.finding.v1.ServiceAccountMisclassificationEvidence: + description: The ServiceAccountMisclassificationEvidence message. + properties: + detectionReason: + description: The detectionReason field. type: string - title: Errored Action + title: Service Account Misclassification Evidence type: object - x-speakeasy-name-override: ErroredAction - c1.api.policy.v1.Escalation: - description: | - The Escalation message. - - This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: - - replacePolicy - - reassignToApprovers - - cancelTicket - - skipStep + x-speakeasy-name-override: ServiceAccountMisclassificationEvidence + c1.api.finding.v1.ServiceAccountMisclassificationType: + description: The ServiceAccountMisclassificationType message. properties: - cancelTicket: - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.CancelTicket' - escalationComment: - description: The escalationComment field. - readOnly: false + currentAccountType: + description: The currentAccountType field. + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT type: string - expiration: - description: The expiration field. - format: int64 - readOnly: false + x-speakeasy-unknown-values: allow + detectedAccountType: + description: The detectedAccountType field. + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT type: string - reassignToApprovers: - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReassignToApprovers' - replacePolicy: - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReplacePolicy' - skipStep: - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.SkipStep' - title: Escalation + x-speakeasy-unknown-values: allow + title: Service Account Misclassification Type type: object - x-speakeasy-name-override: Escalation - c1.api.policy.v1.Escalation.CancelTicket: - description: The CancelTicket message. - nullable: true - title: Cancel Ticket + x-speakeasy-name-override: ServiceAccountMisclassificationType + c1.api.finding.v1.ServiceAccountUnownedType: + description: |- + ServiceAccountUnownedType: a service-account-classified AppUser has no + primary owner. Target: AppUserTarget (the unowned service account). + title: Service Account Unowned Type type: object - x-speakeasy-name-override: CancelTicket - c1.api.policy.v1.Escalation.ReassignToApprovers: - description: The ReassignToApprovers message. - nullable: true + x-speakeasy-name-override: ServiceAccountUnownedType + c1.api.finding.v1.SetSeverity: + description: The SetSeverity message. properties: - approverIds: - description: The approverIds field. - items: + severity: + description: The severity field. + enum: + - FINDING_SEVERITY_UNSPECIFIED + - FINDING_SEVERITY_INFO + - FINDING_SEVERITY_LOW + - FINDING_SEVERITY_MEDIUM + - FINDING_SEVERITY_HIGH + - FINDING_SEVERITY_CRITICAL + type: string + x-speakeasy-unknown-values: allow + title: Set Severity + type: object + x-speakeasy-name-override: SetSeverity + c1.api.finding.v1.SetTags: + description: The SetTags message. + properties: + tags: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - title: Reassign To Approvers + description: The tags field. + type: object + title: Set Tags type: object - x-speakeasy-name-override: ReassignToApprovers - c1.api.policy.v1.Escalation.ReplacePolicy: - description: The ReplacePolicy message. - nullable: true + x-speakeasy-name-override: SetTags + c1.api.finding.v1.SimilarUsernameMatchEvidence: + description: The SimilarUsernameMatchEvidence message. properties: - policyId: - description: The policyId field. - readOnly: false + appUsername: + description: The appUsername field. type: string - title: Replace Policy + identityUsername: + description: The identityUsername field. + type: string + similarityScore: + description: The similarityScore field. + type: number + title: Similar Username Match Evidence type: object - x-speakeasy-name-override: ReplacePolicy - c1.api.policy.v1.Escalation.SkipStep: - description: The SkipStep message. - nullable: true - title: Skip Step + x-speakeasy-name-override: SimilarUsernameMatchEvidence + c1.api.finding.v1.SimilarUsernameMatchType: + description: The SimilarUsernameMatchType message. + properties: + proposedIdentityUserId: + description: The proposedIdentityUserId field. + type: string + title: Similar Username Match Type type: object - x-speakeasy-name-override: SkipStep - c1.api.policy.v1.EscalationInstance: - description: | - The EscalationInstance message. - - This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: - - replacePolicy - - reassignToApprovers - - cancelTicket - - skipStep + x-speakeasy-name-override: SimilarUsernameMatchType + c1.api.finding.v1.SnoozeAction: + description: SnoozeAction parameters for UpdateFindingState. properties: - alreadyEscalated: - description: The alreadyEscalated field. - readOnly: false - type: boolean - cancelTicket: - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.CancelTicket' - escalationComment: - description: The escalationComment field. - readOnly: false + reason: + description: The reason field. type: string - expiresAt: + snoozeUntil: format: date-time - readOnly: false - type: string - reassignToApprovers: - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReassignToApprovers' - replacePolicy: - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReplacePolicy' - skipStep: - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.SkipStep' - title: Escalation Instance + type: + - string + - "null" + title: Snooze Action type: object - x-speakeasy-name-override: EscalationInstance - c1.api.policy.v1.EscalationInstance.CancelTicket: - description: The CancelTicket message. - nullable: true - title: Cancel Ticket + x-speakeasy-name-override: SnoozeAction + c1.api.finding.v1.SnoozeRoutingAction: + description: |- + SnoozeRoutingAction snoozes a matched finding for a relative duration + (resolved to snooze_until = now + duration at execution time). + properties: + duration: + format: duration + type: + - string + - "null" + reason: + description: The reason field. + type: string + title: Snooze Routing Action type: object - x-speakeasy-name-override: EscalationInstanceCancelTicket - c1.api.policy.v1.EscalationInstance.ReassignToApprovers: - description: The ReassignToApprovers message. - nullable: true + x-speakeasy-name-override: SnoozeRoutingAction + c1.api.finding.v1.SuppressRoutingAction: + description: The SuppressRoutingAction message. properties: - approverIds: - description: The approverIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Reassign To Approvers + reason: + description: The reason field. + type: string + title: Suppress Routing Action type: object - x-speakeasy-name-override: EscalationInstanceReassignToApprovers - c1.api.policy.v1.EscalationInstance.ReplacePolicy: - description: The ReplacePolicy message. - nullable: true + x-speakeasy-name-override: SuppressRoutingAction + c1.api.finding.v1.SuppressStateAction: + description: SuppressStateAction parameters for UpdateFindingState. properties: - policyId: - description: The policyId field. - readOnly: false + reason: + description: The reason field. type: string - title: Replace Policy + title: Suppress State Action type: object - x-speakeasy-name-override: EscalationInstanceReplacePolicy - c1.api.policy.v1.EscalationInstance.SkipStep: - description: The SkipStep message. - nullable: true - title: Skip Step + x-speakeasy-name-override: SuppressStateAction + c1.api.finding.v1.TenantTarget: + description: |- + TenantTarget scopes a finding to the whole tenant. It carries no subject id; + the finding's tenant is the scope. + title: Tenant Target type: object - x-speakeasy-name-override: EscalationInstanceSkipStep - c1.api.policy.v1.ExpressionApproval: - description: The ExpressionApproval message. - nullable: true + x-speakeasy-name-override: TenantTarget + c1.api.finding.v1.UnsuppressAction: + deprecated: true + description: UnsuppressAction parameters for UpdateFindingState. + title: Unsuppress Action + type: object + x-speakeasy-name-override: UnsuppressAction + c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput: + description: The UpdateFindingRoutingRuleRequest message. properties: - allowSelfApproval: - description: Configuration to allow self approval of if the user is specified and also the target of the ticket. - readOnly: false - type: boolean - assignedUserIds: - description: The assignedUserIds field. - items: - type: string - nullable: true - readOnly: true - type: array - expressions: - description: Array of dynamic expressions to determine the approvers. The first expression to return a non-empty list of users will be used. - items: - type: string - nullable: true - readOnly: false - type: array - fallback: - description: Configuration to allow a fallback if the expression does not return a valid list of users. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the expression does not return a valid list of users. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if and the expression does not return a valid list of users. - items: - type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false - type: boolean - title: Expression Approval + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + - type: "null" + title: Update Finding Routing Rule Request type: object - x-speakeasy-name-override: ExpressionApproval - c1.api.policy.v1.ExpressionProvisioner: - description: ExpressionProvisioner evaluates CEL expressions to determine provisioners. - nullable: true + x-speakeasy-name-override: UpdateFindingRoutingRuleRequest + c1.api.finding.v1.UpdateFindingRoutingRuleResponse: + description: The UpdateFindingRoutingRuleResponse message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false + routingRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingRoutingRule' + - type: "null" + title: Update Finding Routing Rule Response + type: object + x-speakeasy-name-override: UpdateFindingRoutingRuleResponse + c1.api.finding.v1.UpdateFindingStateRequestInput: + description: | + The UpdateFindingStateRequest message. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - snooze + - suppress + - acceptRisk + - unsuppress + - resolve + - reopen + properties: + acceptRisk: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.AcceptRiskAction' + - type: "null" + reopen: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ReopenAction' + - type: "null" + resolve: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.ResolveAction' + - type: "null" + snooze: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SnoozeAction' + - type: "null" + suppress: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.SuppressStateAction' + - type: "null" + unsuppress: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.UnsuppressAction' + - type: "null" + title: Update Finding State Request + type: object + x-speakeasy-name-override: UpdateFindingStateRequest + c1.api.finding.v1.UpdateFindingStateResponse: + description: The UpdateFindingStateResponse message. + properties: + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.Finding' + - type: "null" + title: Update Finding State Response + type: object + x-speakeasy-name-override: UpdateFindingStateResponse + c1.api.finding.v1.UpdateFindingTransformationRuleRequestInput: + description: The UpdateFindingTransformationRuleRequest message. + properties: + transformationRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + - type: "null" + title: Update Finding Transformation Rule Request + type: object + x-speakeasy-name-override: UpdateFindingTransformationRuleRequest + c1.api.finding.v1.UpdateFindingTransformationRuleResponse: + description: The UpdateFindingTransformationRuleResponse message. + properties: + transformationRule: + oneOf: + - $ref: '#/components/schemas/c1.api.finding.v1.FindingTransformationRule' + - type: "null" + title: Update Finding Transformation Rule Response + type: object + x-speakeasy-name-override: UpdateFindingTransformationRuleResponse + c1.api.form.v1.AdminProviderConfig: + description: The AdminProviderConfig message. + properties: + defaultValueCel: + description: The defaultValueCel field. + type: string + showToUser: + description: The showToUser field. type: boolean - expressions: - description: The CEL expressions to evaluate. - items: - type: string - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Fallback user IDs if expression evaluation yields no users. - items: - type: string - nullable: true - readOnly: false - type: array - title: Expression Provisioner + title: Admin Provider Config type: object - x-speakeasy-name-override: ExpressionProvisioner - c1.api.policy.v1.ExternalTicketProvision: - description: This provision step indicates that we should check an external ticket to provision this entitlement - nullable: true + x-speakeasy-name-override: AdminProviderConfig + c1.api.form.v1.AppResourceFilter: + description: The AppResourceFilter message. properties: appId: description: The appId field. - readOnly: false - type: string - connectorId: - description: The connectorId field. - readOnly: false type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - readOnly: false - type: string - instructions: - description: This field indicates a text body of instructions for the provisioner to indicate. - readOnly: false + resourceTypeId: + description: The resourceTypeId field. type: string - title: External Ticket Provision - type: object - x-speakeasy-name-override: ExternalTicketProvision - c1.api.policy.v1.Form: - description: The Form message. - nullable: true - properties: - form: - $ref: '#/components/schemas/c1.api.form.v1.Form' - title: Form + title: App Resource Filter type: object - x-speakeasy-name-override: Form - c1.api.policy.v1.FormCompletedAction: - description: The FormCompletedAction message. - nullable: true + x-speakeasy-name-override: AppResourceFilter + c1.api.form.v1.AppUserFilter: + description: The AppUserFilter message. properties: - completedAt: - format: date-time - readOnly: false - type: string - userId: - description: The userId field. - readOnly: false + appId: + description: The appId field. type: string - title: Form Completed Action + title: App User Filter type: object - x-speakeasy-name-override: FormCompletedAction - c1.api.policy.v1.FormInstance: + x-speakeasy-name-override: AppUserFilter + c1.api.form.v1.AtLeastOne: + description: The AtLeastOne message. + title: At Least One + type: object + x-speakeasy-name-override: AtLeastOne + c1.api.form.v1.BoolField: description: | - The FormInstance message. + The BoolField message. - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - completed - - restarted - - reassigned - - skipped - nullable: true + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - checkboxField + - toggleField properties: - completed: - $ref: '#/components/schemas/c1.api.policy.v1.FormCompletedAction' - data: - additionalProperties: true - readOnly: false - type: object - form: - $ref: '#/components/schemas/c1.api.form.v1.Form' - reassigned: - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' - restarted: - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' - skipped: - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' - state: - description: The state field. - enum: - - FORM_INSTANCE_STATE_UNSPECIFIED - - FORM_INSTANCE_STATE_WAITING - - FORM_INSTANCE_STATE_DONE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: Form Instance + checkboxField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.CheckboxField' + - type: "null" + defaultValue: + description: The defaultValue field. + type: boolean + rules: + oneOf: + - $ref: '#/components/schemas/validate.BoolRules' + - type: "null" + toggleField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.ToggleField' + - type: "null" + title: Bool Field type: object - x-speakeasy-name-override: FormInstance - c1.api.policy.v1.GetPolicyResponse: - description: The GetPolicyResponse message contains the policy object. - properties: - policy: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - title: Get Policy Response + x-speakeasy-name-override: BoolField + c1.api.form.v1.C1UserFilter: + description: |- + C1UserFilter is used to configure a picker for selecting ConductorOne users. + This is distinct from AppUserFilter which selects accounts within a connected app. + title: C 1 User Filter type: object - x-speakeasy-name-override: GetPolicyResponse - c1.api.policy.v1.GroupProvisioner: - description: GroupProvisioner resolves to members of a specific group. - nullable: true + x-speakeasy-name-override: C1UserFilter + c1.api.form.v1.CheckboxField: + description: The CheckboxField message. + title: Checkbox Field + type: object + x-speakeasy-name-override: CheckboxField + c1.api.form.v1.ChipsField: + description: The ChipsField message. + title: Chips Field + type: object + x-speakeasy-name-override: ChipsField + c1.api.form.v1.DependentOn: + description: |- + DependentOn means the fields in field_names are only valid if all fields + in dependency_field_names are also present properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false - type: boolean - appGroupId: - description: The app group ID (entitlement ID). - readOnly: false - type: string - appId: - description: The app ID containing the group. - readOnly: false - type: string - fallbackUserIds: - description: Fallback user IDs if no group members are found. + dependencyFieldNames: + description: The fields that must be present for the primary field_names to be valid items: type: string - nullable: true - readOnly: false - type: array - title: Group Provisioner + type: + - array + - "null" + title: Dependent On type: object - x-speakeasy-name-override: GroupProvisioner - c1.api.policy.v1.ListPolicyResponse: - description: The ListPolicyResponse message. + x-speakeasy-name-override: DependentOn + c1.api.form.v1.Field: + description: | + A field is a single input meant to collect a piece of data from a user + + This message contains a oneof named type. Only a single field of the following list may be set at a time: + - stringField + - boolField + - stringSliceField + - int64Field + - fileField + - oauth2Field + - stringMapField + + + This message contains a oneof named provider_config. Only a single field of the following list may be set at a time: + - userConfig + - adminConfig + - sharedConfig properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request - items: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + adminConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.AdminProviderConfig' + - type: "null" + boolField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.BoolField' + - type: "null" + description: + description: The description field. type: string - title: List Policy Response - type: object - x-speakeasy-name-override: ListPolicyResponse - c1.api.policy.v1.ManagerApproval: - description: The manager approval object provides configuration options for approval when the target of the approval is the manager of the user in the task. - nullable: true - properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is their own manager. This may occur if a service account has an identity user and manager specified as the same person. - readOnly: false - type: boolean - assignedUserIds: - description: The array of users determined to be the manager during processing time. - items: - type: string - nullable: true - readOnly: true - type: array - fallback: - description: Configuration to allow a fallback if no manager is found. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and no manager is found. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and no manager is found. - items: - type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false + displayName: + description: The displayName field. + type: string + fileField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.FileField' + - type: "null" + int64Field: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Int64Field' + - type: "null" + name: + description: The name field. + type: string + oauth2Field: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Oauth2Field' + - type: "null" + readOnly: + description: When true, this field is displayed to the user but cannot be edited. type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false + required: + description: The required field. type: boolean - title: Manager Approval + sharedConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.SharedProviderConfig' + - type: "null" + stringField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.StringField' + - type: "null" + stringMapField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.StringMapField' + - type: "null" + stringSliceField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.StringSliceField' + - type: "null" + userConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.UserProviderConfig' + - type: "null" + title: Field type: object - x-speakeasy-name-override: ManagerApproval - c1.api.policy.v1.ManagerProvisioner: - description: ManagerProvisioner resolves to the user's manager. - nullable: true + x-speakeasy-name-override: FormField + c1.api.form.v1.FieldGroup: + description: The FieldGroup message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false + default: + description: The default field. type: boolean - fallbackUserIds: - description: Fallback user IDs if no manager is found. + displayName: + description: The displayName field. + type: string + fields: + description: The fields field. items: type: string - nullable: true - readOnly: false - type: array - title: Manager Provisioner + type: + - array + - "null" + helpText: + description: The helpText field. + type: string + name: + description: The name field. + type: string + title: Field Group type: object - x-speakeasy-name-override: ManagerProvisioner - c1.api.policy.v1.ManualProvision: - description: Manual provisioning indicates that a human must intervene for the provisioning of this step. - nullable: true + x-speakeasy-name-override: FormFieldGroup + c1.api.form.v1.FieldRelationship: + description: | + FieldRelationships can be used during form validation, or they can represent + information that is necessary to when it comes to visually rendering the form + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - requiredTogether + - atLeastOne + - mutuallyExclusive + - dependentOn properties: - assignee: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionerAssignment' - instructions: - description: This field indicates a text body of instructions for the provisioner to indicate. - readOnly: false - type: string - userIds: - description: |- - An array of users that are required to provision during this step. - Deprecated: Use assignee field instead for dynamic provisioner assignment. + atLeastOne: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.AtLeastOne' + - type: "null" + dependentOn: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.DependentOn' + - type: "null" + fieldNames: + description: The names of the fields that share this relationship items: type: string - nullable: true - readOnly: false - type: array - title: Manual Provision + type: + - array + - "null" + mutuallyExclusive: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.MutuallyExclusive' + - type: "null" + requiredTogether: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.RequiredTogether' + - type: "null" + title: Field Relationship type: object - x-speakeasy-name-override: ManualProvision - c1.api.policy.v1.MultiStep: - description: MultiStep indicates that this provision step has multiple steps to process. - nullable: true + x-speakeasy-name-override: FieldRelationship + c1.api.form.v1.FileField: + description: | + The FileField message. + + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - fileInputField properties: - provisionSteps: - description: The array of provision steps to process. + acceptedFileTypes: + description: The acceptedFileTypes field. items: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - nullable: true - readOnly: false - type: array - title: Multi Step + type: string + type: + - array + - "null" + fileInputField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.FileInputField' + - type: "null" + maxFileSize: + description: The maxFileSize field. + format: int64 + type: + - string + - "null" + title: File Field type: object - x-speakeasy-name-override: MultiStep - c1.api.policy.v1.Policy: - description: |- - A policy defines a workflow (sequence of steps) that runs when processing - access requests, reviews, or revocations. Policies support conditional - routing: different conditions can trigger different step sequences, with a - baseline fallback. + x-speakeasy-name-override: FileField + c1.api.form.v1.FileInputField: + description: The FileInputField message. + title: File Input Field + type: object + x-speakeasy-name-override: FileInputField + c1.api.form.v1.Form: + description: A form is a collection of fields to be filled out by a user properties: - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time - readOnly: true - type: string description: - description: The description of the Policy. - readOnly: false + description: The description field. type: string displayName: - description: The display name of the Policy. - readOnly: false + description: The displayName field. type: string + fieldGroups: + description: The fieldGroups field. + items: + $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' + type: + - array + - "null" + fieldRelationships: + description: The fieldRelationships field. + items: + $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' + type: + - array + - "null" + fields: + description: The fields field. + items: + $ref: '#/components/schemas/c1.api.form.v1.Field' + type: + - array + - "null" id: - description: The ID of the Policy. - readOnly: true + description: The id field. type: string - policySteps: - additionalProperties: - $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' - description: |- - A map from string keys to step sequences. One entry is always the baseline, - keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify"). - Additional entries have opaque keys (UUIDs) and are referenced by the rules - array for conditional routing. If no conditional rules are configured, only - the baseline entry exists. - readOnly: false - type: object - policyType: - description: |- - The type of this policy (grant, revoke, or certify). The lowercased type - name (e.g., "grant") is also the key for the baseline entry in policy_steps. - enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION - readOnly: false - type: string - x-speakeasy-unknown-values: allow - postActions: - description: Ordered actions to execute after the policy completes processing. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' - nullable: true - readOnly: false - type: array - reassignTasksToDelegates: - deprecated: true - description: This field is no longer used. Configure delegate reassignment in the policy step instead. - readOnly: false - type: boolean - rules: - description: |- - Ordered conditional routing rules. Evaluated top-to-bottom; the first - matching rule selects a step sequence from policy_steps. If no rule matches - (or if this array is empty), the baseline entry in policy_steps is used. - items: - $ref: '#/components/schemas/c1.api.policy.v1.Rule' - nullable: true - readOnly: false - type: array - systemBuiltin: - description: Whether this policy is a builtin system policy. Builtin system policies cannot be edited. - readOnly: true - type: boolean - updatedAt: - format: date-time - readOnly: true - type: string - title: Policy - type: object - x-speakeasy-entity: Policy - x-speakeasy-name-override: Policy - c1.api.policy.v1.PolicyInstance: - description: A policy instance is an object that contains a reference to the policy it was created from, the currently executing step, the next steps, and the history of previously completed steps. - properties: - current: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' - history: - description: An array of steps that were previously processed by the ticket with their outcomes set, in order. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' - nullable: true - readOnly: true - type: array - next: - description: An array of steps that will be processed by the ticket, in order. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' - nullable: true - readOnly: true - type: array - policy: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - title: Policy Instance + title: Form type: object - x-speakeasy-name-override: PolicyInstance - c1.api.policy.v1.PolicyPostActions: + x-speakeasy-entity: Request_Schema + x-speakeasy-name-override: RequestSchemaForm + c1.api.form.v1.Int64Field: description: | - Actions to execute after a policy finishes processing. + The Int64Field message. - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - certifyRemediateImmediately + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - numberField properties: - certifyRemediateImmediately: - description: |- - Only valid on certify policies. When true, any revocations resulting from - the certification are applied immediately when the campaign task closes. - This field is part of the `action` oneof. - See the documentation for `c1.api.policy.v1.PolicyPostActions` for more details. - nullable: true - readOnly: false - type: boolean - title: Policy Post Actions + defaultValue: + description: The defaultValue field. + format: int64 + type: + - string + - "null" + numberField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.NumberField' + - type: "null" + placeholder: + description: The placeholder field. + type: string + rules: + oneOf: + - $ref: '#/components/schemas/validate.Int64Rules' + - type: "null" + title: Int 64 Field type: object - x-speakeasy-name-override: PolicyPostActions - c1.api.policy.v1.PolicyRef: - description: The PolicyRef message. + x-speakeasy-name-override: Int64Field + c1.api.form.v1.MutuallyExclusive: + description: The MutuallyExclusive message. + title: Mutually Exclusive + type: object + x-speakeasy-name-override: MutuallyExclusive + c1.api.form.v1.NumberField: + description: The NumberField message. properties: - id: - description: The id field. - readOnly: false + maxValue: + description: The maxValue field. + format: int64 type: string - title: Policy Ref + minValue: + description: The minValue field. + format: int64 + type: string + step: + description: The step field. + format: int64 + type: string + title: Number Field type: object - x-speakeasy-name-override: PolicyRef - c1.api.policy.v1.PolicyStep: + x-speakeasy-name-override: NumberField + c1.api.form.v1.Oauth2Field: description: | - A single step in a policy workflow. Exactly one step type is set. + The Oauth2Field message. - This message contains a oneof named step. Only a single field of the following list may be set at a time: - - approval - - provision - - accept - - reject - - wait - - form - - action + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - oauth2FieldView properties: - accept: - $ref: '#/components/schemas/c1.api.policy.v1.Accept' - action: - $ref: '#/components/schemas/c1.api.policy.v1.Action' - approval: - $ref: '#/components/schemas/c1.api.policy.v1.Approval' - form: - $ref: '#/components/schemas/c1.api.policy.v1.Form' - provision: - $ref: '#/components/schemas/c1.api.policy.v1.Provision' - reject: - $ref: '#/components/schemas/c1.api.policy.v1.Reject' - wait: - $ref: '#/components/schemas/c1.api.policy.v1.Wait' - title: Policy Step + oauth2FieldView: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Oauth2FieldView' + - type: "null" + title: Oauth 2 Field type: object - x-speakeasy-name-override: PolicyStep - c1.api.policy.v1.PolicyStepInstance: + x-speakeasy-name-override: Oauth2Field + c1.api.form.v1.Oauth2FieldView: + description: The Oauth2FieldView message. + title: Oauth 2 Field View + type: object + x-speakeasy-name-override: Oauth2FieldView + c1.api.form.v1.PasswordField: + description: The PasswordField message. + title: Password Field + type: object + x-speakeasy-name-override: PasswordField + c1.api.form.v1.PickerField: description: | - The policy step instance includes a reference to an instance of a policy step that tracks state and has a unique ID. + The PickerField message. - This message contains a oneof named instance. Only a single field of the following list may be set at a time: - - approval - - provision - - accept - - reject - - wait - - form - - action + This message contains a oneof named type. Only a single field of the following list may be set at a time: + - appUserPicker + - resourcePicker + - c1UserPicker properties: - accept: - $ref: '#/components/schemas/c1.api.policy.v1.AcceptInstance' - action: - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - approval: - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' - form: - $ref: '#/components/schemas/c1.api.policy.v1.FormInstance' - id: - description: The ID of the PolicyStepInstance. This is required by many action submission endpoints to indicate what step you're approving. - readOnly: true - type: string - policyGenerationId: - description: The policy generation id refers to the version of the policy that this step was created from. - readOnly: false - type: string - provision: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionInstance' - reject: - $ref: '#/components/schemas/c1.api.policy.v1.RejectInstance' - state: - description: The state of the step, which is either active or done. + appUserPicker: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.AppUserFilter' + - type: "null" + c1UserPicker: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.C1UserFilter' + - type: "null" + resourcePicker: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.AppResourceFilter' + - type: "null" + title: Picker Field + type: object + x-speakeasy-name-override: PickerField + c1.api.form.v1.RequiredTogether: + description: The RequiredTogether message. + title: Required Together + type: object + x-speakeasy-name-override: RequiredTogether + c1.api.form.v1.SelectField: + description: The SelectField message. + properties: + options: + description: The options field. + items: + $ref: '#/components/schemas/c1.api.form.v1.SelectOption' + type: + - array + - "null" + type: + description: The type field. enum: - - POLICY_STEP_STATE_UNSPECIFIED - - POLICY_STEP_STATE_ACTIVE - - POLICY_STEP_STATE_DONE - readOnly: true + - SELECT_TYPE_UNSPECIFIED + - SELECT_TYPE_DROPDOWN + - SELECT_TYPE_RADIO + - SELECT_TYPE_BUTTONS type: string x-speakeasy-unknown-values: allow - wait: - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance' - title: Policy Step Instance + title: Select Field type: object - x-speakeasy-name-override: PolicyStepInstance - c1.api.policy.v1.PolicySteps: - description: A named sequence of steps that execute in order within a policy. + x-speakeasy-name-override: SelectField + c1.api.form.v1.SelectOption: + description: The SelectOption message. properties: - steps: - description: |- - Ordered array of steps. Each step is a oneof -- exactly one step type is - set per entry. Steps execute sequentially. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' - nullable: true - readOnly: false - type: array - title: Policy Steps + description: + description: Used for type BUTTONS + type: string + displayName: + description: The displayName field. + type: string + value: + description: The value field. + type: string + title: Select Option type: object - x-speakeasy-name-override: PolicySteps - c1.api.policy.v1.Provision: - description: The provision step references a provision policy for this step. - nullable: true + x-speakeasy-name-override: SelectOption + c1.api.form.v1.SharedProviderConfig: + description: The SharedProviderConfig message. properties: - assigned: - description: A field indicating whether this step is assigned. - readOnly: false + defaultValueCel: + description: The defaultValueCel field. + type: string + inputTransformationCel: + description: The inputTransformationCel field. + type: string + lockDefaultValues: + description: The lockDefaultValues field. type: boolean - provisionPolicy: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' - provisionTarget: - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionTarget' - title: Provision + title: Shared Provider Config type: object - x-speakeasy-name-override: Provision - c1.api.policy.v1.ProvisionInstance: + x-speakeasy-name-override: SharedProviderConfig + c1.api.form.v1.StringField: description: | - A provision instance describes the specific configuration of an executing provision policy step including actions taken and notification id. + The StringField message. - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - completed - - cancelled - - errored - - reassignedByError - - skipped - nullable: true + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - textField + - passwordField + - selectField + - pickerField properties: - batonActionInvocationId: - description: This indicates the account lifecycle action id for this step. - readOnly: false - type: string - cancelled: - $ref: '#/components/schemas/c1.api.policy.v1.CancelledAction' - completed: - $ref: '#/components/schemas/c1.api.policy.v1.CompletedAction' - errored: - $ref: '#/components/schemas/c1.api.policy.v1.ErroredAction' - externalTicketId: - description: This indicates the external ticket id for this step. - readOnly: false - type: string - externalTicketProvisionerConfigId: - description: This indicates the external ticket provisioner config id for this step. - readOnly: false - type: string - notificationId: - description: This indicates the notification id for this step. - readOnly: false - type: string - provision: - $ref: '#/components/schemas/c1.api.policy.v1.Provision' - reassignedByError: - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' - skipped: - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' - state: - description: This property indicates the current state of this step. - enum: - - PROVISION_INSTANCE_STATE_UNSPECIFIED - - PROVISION_INSTANCE_STATE_INIT - - PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET - - PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS - - PROVISION_INSTANCE_STATE_WAITING - - PROVISION_INSTANCE_STATE_WEBHOOK - - PROVISION_INSTANCE_STATE_WEBHOOK_WAITING - - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET - - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING - - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS - - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING - - PROVISION_INSTANCE_STATE_DONE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - webhookId: - description: This indicates the webhook id for this step. - readOnly: false + defaultValue: + description: The defaultValue field. type: string - webhookInstanceId: - description: This indicates the webhook instance id for this step. - readOnly: false + passwordField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.PasswordField' + - type: "null" + pickerField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.PickerField' + - type: "null" + placeholder: + description: The placeholder field. type: string - title: Provision Instance + rules: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + selectField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.SelectField' + - type: "null" + textField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.TextField' + - type: "null" + title: String Field type: object - x-speakeasy-name-override: ProvisionInstance - c1.api.policy.v1.ProvisionPolicy: - description: | - ProvisionPolicy is a oneOf that indicates how a provision step should be processed. - - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - connector - - manual - - delegated - - webhook - - multiStep - - externalTicket - - unconfigured - - action + x-speakeasy-name-override: FormStringField + c1.api.form.v1.StringMapField: + description: The StringMapField message. properties: - action: - $ref: '#/components/schemas/c1.api.policy.v1.ActionProvision' - connector: - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision' - delegated: - $ref: '#/components/schemas/c1.api.policy.v1.DelegatedProvision' - externalTicket: - $ref: '#/components/schemas/c1.api.policy.v1.ExternalTicketProvision' - manual: - $ref: '#/components/schemas/c1.api.policy.v1.ManualProvision' - multiStep: - $ref: '#/components/schemas/c1.api.policy.v1.MultiStep' - unconfigured: - $ref: '#/components/schemas/c1.api.policy.v1.UnconfiguredProvision' - webhook: - $ref: '#/components/schemas/c1.api.policy.v1.WebhookProvision' - title: Provision Policy + defaultValue: + additionalProperties: + type: string + description: The defaultValue field. + type: object + rules: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.StringMapRules' + - type: "null" + title: String Map Field type: object - x-speakeasy-name-override: ProvisionPolicy - c1.api.policy.v1.ProvisionTarget: - description: ProvisionTarget indicates the specific app, app entitlement, and if known, the app user and grant duration of this provision step + x-speakeasy-name-override: FormStringMapField + c1.api.form.v1.StringMapRules: + description: The StringMapRules message. properties: - appEntitlementId: - description: The app entitlement that should be provisioned. - readOnly: false - type: string - appId: - description: The app in which the entitlement should be provisioned - readOnly: false - type: string - appUserId: - description: The app user that should be provisioned. May be unset if the app user is unknown - readOnly: false - type: string - grantDuration: - format: duration - readOnly: false - type: string - title: Provision Target + isRequired: + description: The isRequired field. + type: boolean + validateEmpty: + description: The validateEmpty field. + type: boolean + title: String Map Rules type: object - x-speakeasy-name-override: ProvisionTarget - c1.api.policy.v1.ProvisionerAssignment: + x-speakeasy-name-override: StringMapRules + c1.api.form.v1.StringSliceField: description: | - ProvisionerAssignment defines how a provisioner is dynamically assigned. + The StringSliceField message. - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - users - - appOwners - - group - - manager - - expression - - entitlementOwners + This message contains a oneof named view. Only a single field of the following list may be set at a time: + - chipsField + - pickerField properties: - appOwners: - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerProvisioner' - entitlementOwners: - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerProvisioner' - expression: - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionProvisioner' - group: - $ref: '#/components/schemas/c1.api.policy.v1.GroupProvisioner' - manager: - $ref: '#/components/schemas/c1.api.policy.v1.ManagerProvisioner' - users: - $ref: '#/components/schemas/c1.api.policy.v1.UserProvisioner' - title: Provisioner Assignment + chipsField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.ChipsField' + - type: "null" + defaultValues: + description: The defaultValues field. + items: + type: string + type: + - array + - "null" + pickerField: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.PickerField' + - type: "null" + placeholder: + description: The placeholder field. + type: string + rules: + oneOf: + - $ref: '#/components/schemas/validate.RepeatedRules' + - type: "null" + title: String Slice Field type: object - x-speakeasy-name-override: ProvisionerAssignment - c1.api.policy.v1.ReassignedAction: - description: The ReassignedAction object describes the outcome of a policy step that has been reassigned. - nullable: true + x-speakeasy-name-override: StringSliceField + c1.api.form.v1.TextField: + description: The TextField message. properties: - newPolicyStepId: - description: The ID of the policy step that was created as a result of this reassignment. - readOnly: true + multiline: + description: The multiline field. + type: boolean + suffix: + description: Static text displayed as an end adornment (e.g. ".example.com" for domain fields). + type: + - string + - "null" + title: Text Field + type: object + x-speakeasy-name-override: TextField + c1.api.form.v1.ToggleField: + description: The ToggleField message. + title: Toggle Field + type: object + x-speakeasy-name-override: ToggleField + c1.api.form.v1.UserProviderConfig: + description: The UserProviderConfig message. + properties: + inputTransformationCel: + description: The inputTransformationCel field. type: string - reassignedAt: + title: User Provider Config + type: object + x-speakeasy-name-override: UserProviderConfig + c1.api.functions.v1.Function: + description: Function represents a customer-provided code extension in the API + properties: + createdAt: format: date-time readOnly: true - type: string - userId: - description: The UserID of the person who reassigned this step. + type: + - string + - "null" + deletedAt: + format: date-time readOnly: true - type: string - title: Reassigned Action - type: object - x-speakeasy-name-override: ReassignedAction - c1.api.policy.v1.ReassignedByErrorAction: - description: The ReassignedByErrorAction object describes the outcome of a policy step that has been reassigned because it had an error provisioning. - nullable: true - properties: + type: + - string + - "null" description: - description: The description of the error with more details on why this was reassigned. - readOnly: true + description: The description field. type: string - errorCode: - description: Additional information about the error, like http status codes or error messages from SDKs. - readOnly: true + displayName: + description: The displayName field. type: string - errorUserId: - description: The UserID of the user who reassigned this due to an error. This will exclusively be the System's UserID. - readOnly: true + functionType: + description: The functionType field. + enum: + - FUNCTION_TYPE_UNSPECIFIED + - FUNCTION_TYPE_ANY + - FUNCTION_TYPE_CODE_MODE type: string - erroredAt: - format: date-time - readOnly: true + x-speakeasy-unknown-values: allow + head: + description: The head field. type: string - newPolicyStepId: - description: The ID of the policy step that was created by this reassignment. - readOnly: true + id: + description: The id field. type: string - reassignedAt: - format: date-time - readOnly: true + isDraft: + description: The isDraft field. + type: boolean + outboundNetworkAllowlist: + description: The outboundNetworkAllowlist field. + items: + type: string + type: + - array + - "null" + provisionedConcurrency: + description: |- + Number of pre-warmed Lambda instances. 0 (default) leaves the function + cold-started on first invoke. > 0 reserves and provisions that many + execution environments via AWS Lambda provisioned concurrency. + Ignored for FUNCTION_TYPE_CODE_MODE functions — that value is driven + by AIGovernanceSettings.code_mode_concurrency. + format: int32 + type: integer + publishedCommitId: + description: The publishedCommitId field. type: string - title: Reassigned By Error Action + scopedRoleIds: + description: |- + Scoped role IDs define the permissions granted to this function when calling + ConductorOne APIs. These are role IDs (not service roles) that get resolved + to their service roles at authentication time. + + Currently only the "Read-Only Administrator" role (system:viewer) is supported. + The role ID can be obtained from the roles API. + items: + type: string + type: + - array + - "null" + secret: + additionalProperties: + type: string + description: The secret field. + type: object + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + useSpn: + description: |- + FN-347 transition flag. When true, the function authenticates to c1-api + as user: via the AssumeIdentity token exchange using its + ServicePrincipalBinding; when false, it authenticates as + function:. Read-only from clients: set by CreateFunction (when the + tenant has completed the FunctionsToSPN migration) and by the migration + itself, never by UpdateFunction. Retired once all functions are on SPN. + readOnly: true + type: boolean + title: Function type: object - x-speakeasy-name-override: ReassignedByErrorAction - c1.api.policy.v1.Reject: - description: This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - nullable: true + x-speakeasy-entity: Function + x-speakeasy-name-override: Function + c1.api.functions.v1.FunctionCommit: + description: FunctionCommit represents a single commit in a function's history properties: - rejectMessage: - description: An optional message to include in the comments when a task is automatically rejected. - readOnly: false + author: + description: The author field. type: string - title: Reject + createdAt: + format: date-time + type: + - string + - "null" + functionId: + description: The functionId field. + type: string + id: + description: The id field. + type: string + message: + description: The message field. + type: string + title: Function Commit type: object - x-speakeasy-name-override: Reject - c1.api.policy.v1.RejectInstance: - description: |- - This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. - The instance is just a marker for it being copied into an active policy. - nullable: true + x-speakeasy-name-override: FunctionCommit + c1.api.functions.v1.FunctionInvocation: + description: The FunctionInvocation message. properties: - rejectMessage: - description: An optional message to include in the comments when a task is automatically rejected. - readOnly: false + commitId: + description: The commitId field. type: string - title: Reject Instance + createdAt: + format: date-time + type: + - string + - "null" + error: + description: The error field. + type: string + functionId: + description: The functionId field. + type: string + id: + description: The id field. + type: string + input: + additionalProperties: true + type: + - object + - "null" + output: + additionalProperties: true + type: + - object + - "null" + status: + description: The status field. + enum: + - FUNCTION_INVOCATION_STATUS_UNSPECIFIED + - FUNCTION_INVOCATION_STATUS_PENDING + - FUNCTION_INVOCATION_STATUS_RUNNING + - FUNCTION_INVOCATION_STATUS_SUCCESS + - FUNCTION_INVOCATION_STATUS_ERROR + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + title: Function Invocation type: object - x-speakeasy-name-override: RejectInstance - c1.api.policy.v1.ResourceOwnerApproval: - description: The resource owner approval allows configuration of the approval step when the target approvers are the resource owners. - nullable: true + x-speakeasy-name-override: FunctionInvocation + c1.api.functions.v1.FunctionTestResult: + description: FunctionTestResult contains the result of a single test case execution. properties: - allowSelfApproval: - description: Configuration to allow self approval if the target user is an resource owner during this step. - readOnly: false - type: boolean - fallback: - description: Configuration to allow a fallback if the resource owner cannot be identified. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the resource owner cannot be identified. + assertions: + description: The assertions evaluated during the test. items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the resource owner cannot be identified. + $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult.FunctionTestResultAssertion' + type: + - array + - "null" + error: + description: Error message if the test errored (distinct from assertion failure). + type: string + logs: + description: The log entries captured during the test. items: - type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false + $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult.FunctionTestResultLog' + type: + - array + - "null" + name: + description: The test name. + type: string + status: + description: The test result status. + enum: + - FUNCTION_TEST_RESULT_STATUS_UNSPECIFIED + - FUNCTION_TEST_RESULT_STATUS_OK + - FUNCTION_TEST_RESULT_STATUS_FAIL + - FUNCTION_TEST_RESULT_STATUS_SKIPPED + type: string + x-speakeasy-unknown-values: allow + title: Function Test Result + type: object + x-speakeasy-name-override: FunctionTestResult + c1.api.functions.v1.FunctionTestResult.FunctionTestResultAssertion: + description: A single assertion within a test. + properties: + actual: + description: The actual value. + type: string + at: + description: Source location of the assertion. + type: string + description: + description: Description of the assertion. + type: string + expected: + description: The expected value. + type: string + operator: + description: The comparison operator (e.g., "==", "!="). + type: string + pass: + description: Whether the assertion passed. type: boolean - title: Resource Owner Approval + title: Function Test Result Assertion type: object - x-speakeasy-name-override: ResourceOwnerApproval - c1.api.policy.v1.RestartAction: - description: The restart action describes the outcome of policy steps for when the task was restarted. This can be applied to multiple steps since restart skips all pending next steps. - nullable: true + x-speakeasy-name-override: FunctionTestResultAssertion + c1.api.functions.v1.FunctionTestResult.FunctionTestResultLog: + description: A log entry captured during a test. properties: - oldPolicyStepId: - description: The step ID that was restarted. Potentially multiple "history" steps will reference this ID to indicate by what step they were restarted. - readOnly: true + level: + description: The log level (e.g., "info", "error"). type: string - restartedAt: - format: date-time - readOnly: true + log: + description: The log message content. type: string - userId: - description: The user that submitted the restart action. - readOnly: true + source: + description: The log source (e.g., "stdout", "stderr"). type: string - title: Restart Action + title: Function Test Result Log type: object - x-speakeasy-name-override: RestartAction - c1.api.policy.v1.Rule: + x-speakeasy-name-override: FunctionTestResultLog + c1.api.functions.v1.FunctionsInvocationSearchRequestInput: description: |- - A conditional routing rule that maps a CEL expression to a step sequence. - Rules are evaluated top-to-bottom; the first matching rule's policy_key - selects the step sequence from the policy's policy_steps map. If no rule - matches, the baseline entry is used. + FunctionsInvocationSearchRequest is the request for searching function invocations. + Results are returned in descending order by created_at (newest first). properties: - condition: - description: |- - A CEL expression that is evaluated against the request context. If it - returns true, the step sequence identified by policy_key is used. - readOnly: false + pageSize: + description: The number of results to return per page. + format: int32 + type: integer + pageToken: + description: The pagination token for fetching the next page. type: string - policyKey: - description: |- - A key into the policy's policy_steps map identifying which step sequence - to execute when this rule's condition matches. - readOnly: false + title: Functions Invocation Search Request + type: object + x-speakeasy-name-override: FunctionsInvocationSearchRequest + c1.api.functions.v1.FunctionsInvocationSearchResponse: + description: FunctionsInvocationSearchResponse is the response for searching function invocations. + properties: + list: + description: The list of function invocations, ordered by created_at descending. + items: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' + type: + - array + - "null" + nextPageToken: + description: The pagination token for fetching the next page. type: string - title: Rule + title: Functions Invocation Search Response type: object - x-speakeasy-name-override: Rule - c1.api.policy.v1.SearchPoliciesRequest: - description: Search Policies by a few properties. + x-speakeasy-name-override: FunctionsInvocationSearchResponse + c1.api.functions.v1.FunctionsInvocationServiceGetResponse: + description: The FunctionsInvocationServiceGetResponse message. properties: - displayName: - description: Search for policies with a case insensitive match on the display name. - readOnly: false + invocation: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' + - type: "null" + title: Functions Invocation Service Get Response + type: object + x-speakeasy-name-override: FunctionsInvocationServiceGetResponse + c1.api.functions.v1.FunctionsInvocationServiceListResponse: + description: The FunctionsInvocationServiceListResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionInvocation' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - excludePolicyIds: - description: The policy IDs to exclude from the search. + title: Functions Invocation Service List Response + type: object + x-speakeasy-name-override: FunctionsInvocationServiceListResponse + c1.api.functions.v1.FunctionsSearchRequest: + description: The FunctionsSearchRequest message. + properties: + functionTypes: + description: The functionTypes field. items: + enum: + - FUNCTION_TYPE_UNSPECIFIED + - FUNCTION_TYPE_ANY + - FUNCTION_TYPE_CODE_MODE type: string - nullable: true - readOnly: false - type: array - includeDeleted: - description: The includeDeleted field. - readOnly: false - type: boolean + x-speakeasy-unknown-values: allow + type: + - array + - "null" pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: The pageSize field. format: int32 - readOnly: false type: integer pageToken: description: The pageToken field. - readOnly: false type: string - policyTypes: - description: The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. - items: - enum: - - POLICY_TYPE_UNSPECIFIED - - POLICY_TYPE_GRANT - - POLICY_TYPE_REVOKE - - POLICY_TYPE_CERTIFY - - POLICY_TYPE_ACCESS_REQUEST - - POLICY_TYPE_PROVISION - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array query: - description: Query the policies with a fuzzy search on display name and description. - readOnly: false + description: The query field. type: string - refs: - description: The refs field. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' - nullable: true - readOnly: false - type: array - title: Search Policies Request + title: Functions Search Request type: object - x-speakeasy-name-override: SearchPoliciesRequest - c1.api.policy.v1.SearchPoliciesResponse: - description: The SearchPoliciesResponse message. + x-speakeasy-name-override: FunctionsSearchRequest + c1.api.functions.v1.FunctionsSearchResponse: + description: The FunctionsSearchResponse message. properties: list: description: The list field. items: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.functions.v1.Function' + type: + - array + - "null" nextPageToken: description: The nextPageToken field. - readOnly: false type: string - title: Search Policies Response + title: Functions Search Response type: object - x-speakeasy-name-override: SearchPoliciesResponse - c1.api.policy.v1.SelfApproval: - description: The self approval object describes the configuration of a policy step that needs to be approved by the target of the request. - nullable: true - properties: - assignedUserIds: - description: The array of users determined to be themselves during approval. This should only ever be one person, but is saved because it may change if the owner of an app user changes while the ticket is open. - items: - type: string - nullable: true - readOnly: true - type: array - fallback: - description: Configuration to allow a fallback if the identity user of the target app user cannot be determined. - readOnly: false - type: boolean - fallbackGroupIds: - description: Configuration to specify which groups to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. - items: - $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' - nullable: true - readOnly: false - type: array - fallbackUserIds: - description: Configuration to specific which users to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. - items: - type: string - nullable: true - readOnly: false - type: array - isGroupFallbackEnabled: - description: Configuration to enable fallback for group fallback. - readOnly: false - type: boolean - title: Self Approval + x-speakeasy-name-override: FunctionsSearchResponse + c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput: + description: The FunctionsServiceCreateFinalCommitRequest message. + title: Functions Service Create Final Commit Request type: object - x-speakeasy-name-override: SelfApproval - c1.api.policy.v1.SkippedAction: - description: The SkippedAction object describes the outcome of a policy step that has been skipped. - nullable: true + x-speakeasy-name-override: FunctionsServiceCreateFinalCommitRequest + c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse: + description: The FunctionsServiceCreateFinalCommitResponse message. properties: - newPolicyStepId: - description: The ID of the policy step that was created as a result of this skipping. - readOnly: true - type: string - skippedAt: - format: date-time - readOnly: true - type: string - userId: - description: The UserID of the user who skipped this step. - readOnly: true - type: string - title: Skipped Action + commit: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + - type: "null" + title: Functions Service Create Final Commit Response type: object - x-speakeasy-name-override: SkippedAction - c1.api.policy.v1.TestAccountProvisionPolicyRequest: - description: TestAccountProvisionPolicyRequest is the request for testing an account provision policy. + x-speakeasy-name-override: FunctionsServiceCreateFinalCommitResponse + c1.api.functions.v1.FunctionsServiceCreateFunctionRequest: + description: The FunctionsServiceCreateFunctionRequest message. properties: - cel: - description: The CEL expression to evaluate for the account provision policy. - readOnly: false + commitMessage: + description: The commit message describing the initial code submission. type: string - title: Test Account Provision Policy Request - type: object - x-speakeasy-name-override: TestAccountProvisionPolicyRequest - c1.api.policy.v1.TestAccountProvisionPolicyResponse: - description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. - properties: - type: - description: The data type of the computed result value. - readOnly: false + description: + description: A description of what the function does. type: string - value: - description: The computed result value of the CEL expression evaluation. - readOnly: false + displayName: + description: The human-readable name for the function. type: string - title: Test Account Provision Policy Response - type: object - x-speakeasy-name-override: TestAccountProvisionPolicyResponse - c1.api.policy.v1.UnconfiguredProvision: - description: The UnconfiguredProvision message. - nullable: true - title: Unconfigured Provision - type: object - x-speakeasy-name-override: UnconfiguredProvision - c1.api.policy.v1.UpdatePolicyRequestInput: - description: The UpdatePolicyRequest message contains the policy object to update and a field mask to indicate which fields to update. It uses URL value for input. - properties: - policy: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - updateMask: - nullable: true - readOnly: false + functionType: + description: |- + The type of function to create. Use FUNCTION_TYPE_ANY for user functions — + that is the type the Functions UI lists. Do not use any other value. + enum: + - FUNCTION_TYPE_UNSPECIFIED + - FUNCTION_TYPE_ANY + - FUNCTION_TYPE_CODE_MODE type: string - title: Update Policy Request + x-speakeasy-unknown-values: allow + initialContent: + additionalProperties: + format: base64 + type: string + description: |- + File map for the initial code commit. Keys are file paths in the + function root (e.g. "main.ts", "main.test.ts"); values are file + contents as bytes. + + Runtime: TypeScript. The entry file MUST be "main.ts" exporting a + default async handler: + + import { JSONObject } from "@c1/functions-sdk"; + export default async function main(input: JSONObject): Promise { + return { ok: true, echo: input }; + } + + The handler MUST return a JSON object — not a primitive, array, or null. + type: object + title: Functions Service Create Function Request type: object - x-speakeasy-name-override: UpdatePolicyRequest - c1.api.policy.v1.UpdatePolicyResponse: - description: The UpdatePolicyResponse message contains the updated policy object. + x-speakeasy-name-override: FunctionsServiceCreateFunctionRequest + c1.api.functions.v1.FunctionsServiceCreateFunctionResponse: + description: The FunctionsServiceCreateFunctionResponse message. properties: - policy: - $ref: '#/components/schemas/c1.api.policy.v1.Policy' - title: Update Policy Response + commit: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + - type: "null" + function: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.Function' + - type: "null" + title: Functions Service Create Function Response type: object - x-speakeasy-name-override: UpdatePolicyResponse - c1.api.policy.v1.UserApproval: - description: The user approval object describes the approval configuration of a policy step that needs to be approved by a specific list of users. - nullable: true + x-speakeasy-name-override: FunctionsServiceCreateFunctionResponse + c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput: + description: The FunctionsServiceCreateInitialCommitRequest message. properties: - allowSelfApproval: - description: Configuration to allow self approval of if the user is specified and also the target of the ticket. - readOnly: false - type: boolean - requireDistinctApprovers: - description: Configuration to require distinct approvers across approval steps of a rule. - readOnly: false - type: boolean - userIds: - description: Array of users configured for approval. + commitMessage: + description: The commitMessage field. + type: string + filenames: + description: The filenames field. items: type: string - nullable: true - readOnly: false - type: array - title: User Approval + type: + - array + - "null" + title: Functions Service Create Initial Commit Request type: object - x-speakeasy-name-override: UserApproval - c1.api.policy.v1.UserProvisioner: - description: UserProvisioner assigns specific users as provisioners. - nullable: true + x-speakeasy-name-override: FunctionsServiceCreateInitialCommitRequest + c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse: + description: The FunctionsServiceCreateInitialCommitResponse message. properties: - allowReassignment: - description: Whether the provisioner can reassign the task. - readOnly: false - type: boolean - userIds: - description: The user IDs to assign as provisioners. - items: + commitId: + description: The commitId field. + type: string + uploadUrls: + additionalProperties: type: string - nullable: true - readOnly: false - type: array - title: User Provisioner + description: The uploadUrls field. + type: object + title: Functions Service Create Initial Commit Response type: object - x-speakeasy-name-override: UserProvisioner - c1.api.policy.v1.Wait: - description: | - Define a Wait step for a policy to wait on a condition to be met. - - This message contains a oneof named until. Only a single field of the following list may be set at a time: - - condition - - duration - - untilTime - nullable: true + x-speakeasy-name-override: FunctionsServiceCreateInitialCommitResponse + c1.api.functions.v1.FunctionsServiceCreateTagRequestInput: + description: The FunctionsServiceCreateTagRequest message. properties: - commentOnFirstWait: - description: The comment to post on first failed check. - readOnly: false - type: string - commentOnTimeout: - description: The comment to post if we timeout. - readOnly: false + commitId: + description: The commitId field. type: string - condition: - $ref: '#/components/schemas/c1.api.policy.v1.WaitCondition' - duration: - $ref: '#/components/schemas/c1.api.policy.v1.WaitDuration' name: - description: The name of our condition to show on the task details page - readOnly: false - type: string - timeoutDuration: - format: duration - readOnly: false + description: The name field. type: string - untilTime: - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTime' - title: Wait + title: Functions Service Create Tag Request type: object - x-speakeasy-name-override: Wait - c1.api.policy.v1.WaitCondition: - description: The WaitCondition message. - nullable: true - properties: - condition: - description: The condition that has to be true for this wait condition to continue. - readOnly: false - type: string - title: Wait Condition + x-speakeasy-name-override: FunctionsServiceCreateTagRequest + c1.api.functions.v1.FunctionsServiceCreateTagResponse: + description: The FunctionsServiceCreateTagResponse message. + title: Functions Service Create Tag Response type: object - x-speakeasy-name-override: WaitCondition - c1.api.policy.v1.WaitConditionInstance: - description: Used by the policy engine to describe an instantiated condition to wait on. - nullable: true - properties: - condition: - description: The condition that has to be true for this wait condition instance to continue. - readOnly: false - type: string - title: Wait Condition Instance + x-speakeasy-name-override: FunctionsServiceCreateTagResponse + c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput: + description: The FunctionsServiceDeleteFunctionRequest message. + title: Functions Service Delete Function Request type: object - x-speakeasy-name-override: WaitConditionInstance - c1.api.policy.v1.WaitDuration: - description: The WaitDuration message. - nullable: true - properties: - duration: - format: duration - readOnly: false + x-speakeasy-name-override: FunctionsServiceDeleteFunctionRequest + c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse: + description: The FunctionsServiceDeleteFunctionResponse message. + title: Functions Service Delete Function Response + type: object + x-speakeasy-name-override: FunctionsServiceDeleteFunctionResponse + c1.api.functions.v1.FunctionsServiceGetCommitContentResponse: + description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. + properties: + commit: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + - type: "null" + files: + additionalProperties: + format: base64 + type: string + description: Map of filename to file content bytes. + type: object + title: Functions Service Get Commit Content Response + type: object + x-speakeasy-name-override: FunctionsServiceGetCommitContentResponse + c1.api.functions.v1.FunctionsServiceGetFunctionResponse: + description: The FunctionsServiceGetFunctionResponse message. + properties: + function: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.Function' + - type: "null" + title: Functions Service Get Function Response + type: object + x-speakeasy-name-override: FunctionsServiceGetFunctionResponse + c1.api.functions.v1.FunctionsServiceGetLockFileResponse: + description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. + properties: + content: + description: The raw content of the deno lock file (empty if not found). + format: base64 type: string - title: Wait Duration + exists: + description: Whether the lock file exists for this commit. + type: boolean + title: Functions Service Get Lock File Response type: object - x-speakeasy-name-override: WaitDuration - c1.api.policy.v1.WaitInstance: + x-speakeasy-name-override: FunctionsServiceGetLockFileResponse + c1.api.functions.v1.FunctionsServiceInvokeRequestInput: description: | - Used by the policy engine to describe an instantiated wait step. - - This message contains a oneof named until. Only a single field of the following list may be set at a time: - - condition - - untilTime - + The FunctionsServiceInvokeRequest message. - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - succeeded - - timedOut - - skipped - nullable: true + This message contains a oneof named arg. Only a single field of the following list may be set at a time: + - json properties: - commentOnFirstWait: - description: The comment to post on first failed check. - readOnly: false - type: string - commentOnTimeout: - description: The comment to post if we timeout. - readOnly: false - type: string - condition: - $ref: '#/components/schemas/c1.api.policy.v1.WaitConditionInstance' - name: - description: The name field. - readOnly: false - type: string - skipped: - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' - startedWaitingAt: - format: date-time - readOnly: false - type: string - state: - description: The state field. - enum: - - WAIT_INSTANCE_STATE_UNSPECIFIED - - WAIT_INSTANCE_STATE_WAITING - - WAIT_INSTANCE_STATE_COMPLETED - - WAIT_INSTANCE_STATE_TIMED_OUT - readOnly: false - type: string - x-speakeasy-unknown-values: allow - succeeded: - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionSucceeded' - timedOut: - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionTimedOut' - timeout: - format: date-time - readOnly: false + commitId: + description: The commit ID specifying which version of the function code to run. type: string - timeoutDuration: - format: duration - readOnly: false + json: + description: |- + The JSON-encoded input data passed to the function. + This field is part of the `arg` oneof. + See the documentation for `c1.api.functions.v1.FunctionsServiceInvokeRequest` for more details. + format: base64 + type: + - string + - "null" + vfsId: + description: Optional VFS volume ID to attach to this invocation. If empty, VFS operations will error. type: string - untilTime: - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTimeInstance' - title: Wait Instance + title: Functions Service Invoke Request type: object - x-speakeasy-name-override: WaitInstance - c1.api.policy.v1.WaitInstance.ConditionSucceeded: - description: The ConditionSucceeded message. - nullable: true + x-speakeasy-name-override: FunctionsServiceInvokeRequest + c1.api.functions.v1.FunctionsServiceInvokeResponse: + description: | + The FunctionsServiceInvokeResponse message. + + This message contains a oneof named resp. Only a single field of the following list may be set at a time: + - json properties: - succeededAt: - format: date-time - readOnly: false + invocationId: + description: The ID of the created invocation, used to track execution status and retrieve results. type: string - title: Condition Succeeded + json: + deprecated: true + description: |- + Deprecated. The JSON-encoded output returned by the function. + This field is part of the `resp` oneof. + See the documentation for `c1.api.functions.v1.FunctionsServiceInvokeResponse` for more details. + format: base64 + type: + - string + - "null" + title: Functions Service Invoke Response type: object - x-speakeasy-name-override: ConditionSucceeded - c1.api.policy.v1.WaitInstance.ConditionTimedOut: - description: The ConditionTimedOut message. - nullable: true + x-speakeasy-name-override: FunctionsServiceInvokeResponse + c1.api.functions.v1.FunctionsServiceListCommitsResponse: + description: The FunctionsServiceListCommitsResponse message. properties: - timedOutAt: - format: date-time - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Condition Timed Out + title: Functions Service List Commits Response type: object - x-speakeasy-name-override: ConditionTimedOut - c1.api.policy.v1.WaitUntilTime: - description: Waits until a specific time of the day (UTC) - nullable: true + x-speakeasy-name-override: FunctionsServiceListCommitsResponse + c1.api.functions.v1.FunctionsServiceListFunctionsResponse: + description: The FunctionsServiceListFunctionsResponse message. properties: - hours: - description: The hours field. - format: uint32 - readOnly: false - type: integer - minutes: - description: The minutes field. - format: uint32 - readOnly: false - type: integer - timezone: - description: The timezone field. - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.functions.v1.Function' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Wait Until Time + title: Functions Service List Functions Response type: object - x-speakeasy-name-override: WaitUntilTime - c1.api.policy.v1.WaitUntilTimeInstance: - description: The WaitUntilTimeInstance message. - nullable: true + x-speakeasy-name-override: FunctionsServiceListFunctionsResponse + c1.api.functions.v1.FunctionsServiceListTagsResponse: + description: The FunctionsServiceListTagsResponse message. properties: - durationIfExists: - format: duration - readOnly: false - type: string - untilTime: - format: date-time - readOnly: false - type: string - title: Wait Until Time Instance + tags: + additionalProperties: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit' + description: The tags field. + type: object + title: Functions Service List Tags Response type: object - x-speakeasy-name-override: WaitUntilTimeInstance - c1.api.policy.v1.WebhookApproval: - description: The WebhookApproval message. - nullable: true + x-speakeasy-name-override: FunctionsServiceListTagsResponse + c1.api.functions.v1.FunctionsServiceTestRequestInput: + description: FunctionsServiceTestRequest runs tests for a function at a specific commit. properties: - webhookId: - description: The ID of the webhook to call for approval. - readOnly: false + commitId: + description: The commit ID to test. If empty, the published commit is used. type: string - title: Webhook Approval + title: Functions Service Test Request type: object - x-speakeasy-name-override: WebhookApproval - c1.api.policy.v1.WebhookProvision: - description: This provision step indicates that a webhook should be called to provision this entitlement. - nullable: true + x-speakeasy-name-override: FunctionsServiceTestRequest + c1.api.functions.v1.FunctionsServiceTestResponse: + description: FunctionsServiceTestResponse contains test execution results. properties: - webhookId: - description: The ID of the webhook to call for provisioning. - readOnly: false - type: string - title: Webhook Provision + result: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult' + - type: "null" + results: + description: All test results. + items: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionTestResult' + type: + - array + - "null" + title: Functions Service Test Response type: object - x-speakeasy-name-override: WebhookProvision - c1.api.profiletype.v1.ProfileType: - description: ProfileType represents a type of profile in the system + x-speakeasy-name-override: FunctionsServiceTestResponse + c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest: + description: The FunctionsServiceUpdateFunctionRequest message. properties: - description: - description: The description field. - readOnly: false + function: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.Function' + - type: "null" + updateMask: + type: + - string + - "null" + title: Functions Service Update Function Request + type: object + x-speakeasy-name-override: FunctionsServiceUpdateFunctionRequest + c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse: + description: The FunctionsServiceUpdateFunctionResponse message. + properties: + function: + oneOf: + - $ref: '#/components/schemas/c1.api.functions.v1.Function' + - type: "null" + title: Functions Service Update Function Response + type: object + x-speakeasy-name-override: FunctionsServiceUpdateFunctionResponse + c1.api.history.v1.HistoryActor: + description: |- + HistoryActor is a typed reference to whoever performed the change. + kind mirrors the storage-model ActorKind enum; user_id is set when + kind corresponds to a user principal (API / SUPPORT) so the frontend + can resolve the user via its own avatar / lookup hooks. Protos + reference objects by id; the frontend renders / caches itself. + + The raw passport fields (token_id / principal_id) intentionally do not + leave the server. Non-user actors (workflow, connector, internal) are + identified by `kind` alone; correlating IDs (workflow_run_id, etc.) + flow through `HistoryAnnotation` instead of being plucked into the + actor message. + properties: + kind: + description: The kind field. + enum: + - ACTOR_KIND_UNSPECIFIED + - ACTOR_KIND_API + - ACTOR_KIND_SLACK + - ACTOR_KIND_MSTEAMS + - ACTOR_KIND_JIRA_CLOUD + - ACTOR_KIND_INTERNAL + - ACTOR_KIND_SUPPORT + - ACTOR_KIND_WORKFLOW type: string - displayToUser: - description: Whether to display this profile type to users in profile page. Defaults to false if not set - readOnly: false - type: boolean - iconUrl: - description: The iconUrl field. - readOnly: false + x-speakeasy-unknown-values: allow + userId: + description: |- + Bare KSUID. Set when kind = ACTOR_KIND_API or ACTOR_KIND_SUPPORT. + Empty otherwise. The frontend resolves user_id → display name via + the same lookup paths it uses elsewhere (avatars, mentions, ...). type: string - id: - description: The id field. - readOnly: false + title: History Actor + type: object + x-speakeasy-name-override: HistoryActor + c1.api.history.v1.HistoryAnnotation: + description: |- + HistoryAnnotation is a single operator-provided key/value rendered with + per-key display metadata. Annotations are minted from the + Tx.*WithHistoryAnnotations / db.WithHistoryAnnotations call options. + properties: + displayLabel: + description: Server-rendered label, e.g. "Ticket". type: string - name: - description: The name field. - readOnly: false + displayUrl: + description: |- + Resolved from tenant config; "" if none. Frontend applies its own + scheme allowlist. type: string - priority: - description: The priority field. - format: uint32 - readOnly: false - type: integer - sizes: - description: icon sizes - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - slug: - description: Add this field to allow users to reference profile type in cel expressions - readOnly: false + displayValue: + description: UI-friendly rendering (truncated / reshaped from raw_value). type: string - title: Profile Type - type: object - x-speakeasy-name-override: ProfileType - c1.api.request_schema.v1.RequestSchema: - description: A request schema defines a form template that users fill out when requesting access. - properties: - createdAt: - format: date-time - readOnly: false + key: + description: 'Storage-side key. Bounds: ^[a-z][a-z0-9_.-]{0,63}$.' type: string - deletedAt: - format: date-time - readOnly: false + kind: + description: The kind field. + enum: + - ANNOTATION_KIND_UNSPECIFIED + - ANNOTATION_KIND_GENERIC + - ANNOTATION_KIND_TICKET + - ANNOTATION_KIND_REASON + - ANNOTATION_KIND_WORKFLOW + - ANNOTATION_KIND_BATCH + - ANNOTATION_KIND_CORRELATION + - ANNOTATION_KIND_AUTOMATION type: string - form: - $ref: '#/components/schemas/c1.api.form.v1.Form' - id: - description: The unique identifier of this request schema. - readOnly: false + x-speakeasy-unknown-values: allow + rawValue: + description: |- + Raw value as stored in ObjectHistory.annotations; storage-side values + are capped at 512 bytes. type: string - justificationVisibility: - description: Controls whether the justification field is shown or hidden on the request form. + title: History Annotation + type: object + x-speakeasy-name-override: HistoryAnnotation + c1.api.history.v1.HistoryEntryMetadata: + description: |- + HistoryEntryMetadata is the shared metadata envelope embedded on every + per-service HistoryEntry. The strongly-typed snapshot lives on the + per-service entry message alongside this envelope. + properties: + actor: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' + - type: "null" + annotations: + description: |- + Server-rendered annotations: known keys carry display_label and + (for ticket_id, etc.) display_url resolved from tenant config. + Cap mirrors the per-object annotation ceiling (16). + items: + $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' + type: + - array + - "null" + changeKind: + description: |- + Storage-model enum re-exported here for wire compatibility with the + storage row. UNSPECIFIED should never appear on the wire. enum: - - JUSTIFICATION_VISIBILITY_UNSPECIFIED - - JUSTIFICATION_VISIBILITY_SHOW - - JUSTIFICATION_VISIBILITY_HIDE - readOnly: false + - CHANGE_KIND_UNSPECIFIED + - CHANGE_KIND_CREATE + - CHANGE_KIND_PUT + - CHANGE_KIND_HARD_DELETE type: string x-speakeasy-unknown-values: allow - modifiedAt: + createdAt: format: date-time - readOnly: false + type: + - string + - "null" + id: + description: KSUID. Same value as c1.models.history.v1.ObjectHistory.id. type: string - title: Request Schema - type: object - x-speakeasy-name-override: RequestSchema - c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest: - description: The request message for creating a single entitlement binding on a request schema. - properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - requestSchemaId: - description: The unique identifier of the request schema to bind the entitlement to. - readOnly: false + syslogEventId: + description: |- + System Log event id — KSUID of the OCSF event recorded for this + write. Empty for non-RPC writes (workflows, cron). Customer-facing + copy says "System Log event"; the underlying format is OCSF. type: string - title: Request Schema Service Create Entitlement Binding Request - type: object - x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingRequest - c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse: - description: The response message for creating a single entitlement binding. - properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - requestSchemaId: - description: The unique identifier of the request schema the entitlement was bound to. - readOnly: false + traceId: + description: |- + OTel trace correlation. Empty when no valid span at write time. + 32-hex-char otel trace id or empty. type: string - title: Request Schema Service Create Entitlement Binding Response + title: History Entry Metadata type: object - x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingResponse - c1.api.request_schema.v1.RequestSchemaServiceCreateRequest: - description: The request message for creating a new request schema. + x-speakeasy-name-override: HistoryEntryMetadata + c1.api.history.v1.ListHistoryEntryMetadata: + description: ListHistoryEntryMetadata is the per-transaction metadata envelope. properties: - description: - description: An optional description of the request schema's purpose. - readOnly: false - type: string - fieldGroups: - description: Logical groupings of fields for display purposes. - items: - $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' - nullable: true - readOnly: false - type: array - fieldRelationships: - description: Dependencies between fields that control conditional visibility or validation. - items: - $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' - nullable: true - readOnly: false - type: array - fields: - description: The form fields that users must fill out when requesting access. + actor: + oneOf: + - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor' + - type: "null" + annotations: + description: Server-rendered annotations (mirrors object_history). items: - $ref: '#/components/schemas/c1.api.form.v1.Field' - nullable: true - readOnly: false - type: array - justificationVisibility: - description: Controls whether the justification field is shown or hidden on the request form. - enum: - - JUSTIFICATION_VISIBILITY_UNSPECIFIED - - JUSTIFICATION_VISIBILITY_SHOW - - JUSTIFICATION_VISIBILITY_HIDE - readOnly: false + $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation' + type: + - array + - "null" + createdAt: + format: date-time + type: + - string + - "null" + id: + description: KSUID. Same value as c1.models.history.v1.ListHistory.id. type: string - x-speakeasy-unknown-values: allow - name: - description: The human-readable name for the request schema. - readOnly: false + syslogEventId: + description: |- + System Log event id — KSUID of the OCSF event recorded for this + transaction. Empty for non-RPC writes (workflows, cron). type: string - title: Request Schema Service Create Request - type: object - x-speakeasy-name-override: RequestSchemaServiceCreateRequest - c1.api.request_schema.v1.RequestSchemaServiceCreateResponse: - description: The response message for creating a request schema. - properties: - requestSchema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - title: Request Schema Service Create Response - type: object - x-speakeasy-name-override: RequestSchemaServiceCreateResponse - c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput: - description: The request message for deleting a request schema. - title: Request Schema Service Delete Request - type: object - x-speakeasy-name-override: RequestSchemaServiceDeleteRequest - c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse: - description: The response message for deleting a request schema. - title: Request Schema Service Delete Response - type: object - x-speakeasy-name-override: RequestSchemaServiceDeleteResponse - c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest: - description: The request message for finding which request schema is bound to a given app entitlement. - properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - title: Request Schema Service Find Binding For App Entitlement Request - type: object - x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementRequest - c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse: - description: The response message containing the binding for the specified app entitlement. - properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - requestSchemaId: - description: The unique identifier of the request schema bound to this entitlement, if any. - readOnly: false + traceId: + description: 32-hex-char otel trace id or empty. type: string - title: Request Schema Service Find Binding For App Entitlement Response + title: List History Entry Metadata type: object - x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementResponse - c1.api.request_schema.v1.RequestSchemaServiceGetResponse: - description: The response message for retrieving a request schema. + x-speakeasy-name-override: ListHistoryEntryMetadata + c1.api.hooks.v1.BuiltInPattern: + description: | + BuiltInPattern references a ConductorOne-maintained DLP pattern. + The specific pattern and its configuration are encoded as a oneof. + + This message contains a oneof named config. Only a single field of the following list may be set at a time: + - piiRedaction + - creditCardBlocking + - queryScopeLimit + - writeAuthorization + - sensitiveFileGuard + - toolOutputSizeGuard properties: - requestSchema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - title: Request Schema Service Get Response + creditCardBlocking: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.CreditCardBlockingConfig' + - type: "null" + piiRedaction: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.PIIRedactionConfig' + - type: "null" + queryScopeLimit: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.QueryScopeLimitConfig' + - type: "null" + sensitiveFileGuard: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.SensitiveFileGuardConfig' + - type: "null" + toolOutputSizeGuard: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.ToolOutputSizeGuardConfig' + - type: "null" + writeAuthorization: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.WriteAuthorizationConfig' + - type: "null" + title: Built In Pattern type: object - x-speakeasy-name-override: RequestSchemaServiceGetResponse - c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest: - description: The request message for removing a single entitlement binding from a request schema. + x-speakeasy-name-override: BuiltInPattern + c1.api.hooks.v1.BusinessHours: + description: BusinessHours defines a weekly time window in a specific timezone. properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - requestSchemaId: - description: The unique identifier of the request schema to remove the binding from. - readOnly: false + days: + description: 0=Sun, 1=Mon, ..., 6=Sat. + items: + format: int32 + type: integer + type: + - array + - "null" + end: + description: '"HH:MM" in 24-hour format.' type: string - title: Request Schema Service Remove Entitlement Binding Request - type: object - x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingRequest - c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse: - description: The response message for removing a single entitlement binding. - title: Request Schema Service Remove Entitlement Binding Response - type: object - x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingResponse - c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput: - description: The request message for updating an existing request schema. - properties: - requestSchema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - updateMask: - nullable: true - readOnly: false + start: + description: '"HH:MM" in 24-hour format.' type: string - title: Request Schema Service Update Request - type: object - x-speakeasy-name-override: RequestSchemaServiceUpdateRequest - c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse: - description: The response message for updating a request schema. - properties: - requestSchema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' - title: Request Schema Service Update Response + timezone: + description: The timezone field. + type: string + title: Business Hours type: object - x-speakeasy-name-override: RequestSchemaServiceUpdateResponse - c1.api.requestcatalog.v1.AppEntitlementWithUserBindings: - description: The AppEntitlementWithUserBindings message represents an app entitlement and its associated user bindings. - properties: - appEntitlementUserBindings: - description: An array of AppEntitlementUserBinding objects which represent the relationships that give app users access to the specific app entitlement. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' - nullable: true - readOnly: false - type: array - entitlement: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - title: App Entitlement With User Bindings + x-speakeasy-name-override: BusinessHours + c1.api.hooks.v1.CreditCardBlockingConfig: + description: |- + CreditCardBlockingConfig denies any tool call whose output contains a + Luhn-valid credit card number. No configuration fields today; the + presence of the oneof arm is the whole configuration. + title: Credit Card Blocking Config type: object - x-speakeasy-name-override: AppEntitlementWithUserBindings - c1.api.requestcatalog.v1.BundleAutomation: + x-speakeasy-name-override: CreditCardBlockingConfig + c1.api.hooks.v1.Hook: description: | - The BundleAutomation message. + Hook represents a customer-configured interception point for tool calls. - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel + This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: + - function + - builtinPattern properties: - cel: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - circuitBreaker: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker' - createTasks: - description: The createTasks field. - readOnly: false - type: boolean + builtinPattern: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' + - type: "null" createdAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + description: + description: The description field. type: string - deletedAt: - format: date-time - readOnly: false + displayName: + description: The displayName field. type: string - disableCircuitBreaker: - description: The disableCircuitBreaker field. - readOnly: false - type: boolean enabled: description: The enabled field. - readOnly: false type: boolean - entitlements: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - requestCatalogId: - description: The requestCatalogId field. - readOnly: false + event: + description: The event field. + enum: + - HOOK_EVENT_TYPE_UNSPECIFIED + - HOOK_EVENT_TYPE_PRE_TOOL_USE + - HOOK_EVENT_TYPE_POST_TOOL_USE type: string - state: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationLastRunState' - tenantId: - description: The tenantId field. - readOnly: false + x-speakeasy-unknown-values: allow + filter: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' + - type: "null" + function: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - type: "null" + id: + description: The id field. type: string + priority: + description: The priority field. + format: int32 + type: integer updatedAt: format: date-time - readOnly: false - type: string - title: Bundle Automation + readOnly: true + type: + - string + - "null" + title: Hook type: object - x-speakeasy-name-override: BundleAutomation - c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState: - description: The BundleAutomationCelEvaluationState message. - properties: - errorMessage: - description: The errorMessage field. - readOnly: false + x-speakeasy-name-override: Hook + c1.api.hooks.v1.HookFilter: + description: HookFilter determines which tool calls a hook applies to. + properties: + celExpression: + description: |- + CEL expression evaluated against tool call context. + Available variable: ctx.tool_name (string). + Must evaluate to bool. Empty matches all tools. type: string - lastEvaluatedAt: - format: date-time - readOnly: false + title: Hook Filter + type: object + x-speakeasy-name-override: HookFilter + c1.api.hooks.v1.HookFunctionRef: + description: HookFunctionRef identifies a customer-authored function to invoke. + properties: + commitId: + description: If empty, the function's published commit is used at invocation time. type: string - matchedUsers: - description: The matchedUsers field. - format: int64 - readOnly: false + functionId: + description: The functionId field. type: string - status: - description: The status field. - enum: - - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED - - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS - - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE - - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS - - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL - readOnly: false + title: Hook Function Ref + type: object + x-speakeasy-name-override: HookFunctionRef + c1.api.hooks.v1.HookRef: + description: The HookRef message. + properties: + id: + description: The id field. type: string - x-speakeasy-unknown-values: allow - title: Bundle Automation Cel Evaluation State + title: Hook Ref type: object - x-speakeasy-name-override: BundleAutomationCelEvaluationState - c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker: - description: The BundleAutomationCircuitBreaker message. + x-speakeasy-name-override: HookRef + c1.api.hooks.v1.HooksSearchRequest: + description: The HooksSearchRequest message. properties: - removedMembersThresholdPercentage: - description: The removedMembersThresholdPercentage field. - format: int64 - readOnly: false + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - state: - description: The state field. - enum: - - CIRCUIT_BREAKER_STATE_UNSPECIFIED - - CIRCUIT_BREAKER_STATE_TRIGGERED - - CIRCUIT_BREAKER_STATE_BYPASS - - CIRCUIT_BREAKER_STATE_SUPPORT_DISABLED - readOnly: false + query: + description: The query field. type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: false + refs: + description: The refs field. + items: + $ref: '#/components/schemas/c1.api.hooks.v1.HookRef' + type: + - array + - "null" + title: Hooks Search Request + type: object + x-speakeasy-name-override: HooksSearchRequest + c1.api.hooks.v1.HooksSearchResponse: + description: The HooksSearchResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - userRef: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - title: Bundle Automation Circuit Breaker + title: Hooks Search Response type: object - x-speakeasy-name-override: BundleAutomationCircuitBreaker - c1.api.requestcatalog.v1.BundleAutomationLastRunState: - description: The BundleAutomationLastRunState message. + x-speakeasy-name-override: HooksSearchResponse + c1.api.hooks.v1.HooksServiceCreateRequest: + description: | + The HooksServiceCreateRequest message. + + This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: + - function + - builtinPattern properties: - celEvaluation: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState' - errorMessage: - description: The errorMessage field. - readOnly: false + builtinPattern: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.BuiltInPattern' + - type: "null" + description: + description: The description field. type: string - lastRunAt: - format: date-time - readOnly: false + displayName: + description: The displayName field. type: string - status: - description: The status field. + enabled: + description: The enabled field. + type: boolean + event: + description: The event field. enum: - - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED - - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS - - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE - - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS - - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL - readOnly: false + - HOOK_EVENT_TYPE_UNSPECIFIED + - HOOK_EVENT_TYPE_PRE_TOOL_USE + - HOOK_EVENT_TYPE_POST_TOOL_USE type: string x-speakeasy-unknown-values: allow - title: Bundle Automation Last Run State + filter: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFilter' + - type: "null" + function: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.HookFunctionRef' + - type: "null" + priority: + description: The priority field. + format: int32 + type: integer + required: + - displayName + title: Hooks Service Create Request type: object - x-speakeasy-name-override: BundleAutomationLastRunState - c1.api.requestcatalog.v1.BundleAutomationRuleCEL: - description: The BundleAutomationRuleCEL message. - nullable: true + x-speakeasy-name-override: HooksServiceCreateRequest + c1.api.hooks.v1.HooksServiceCreateResponse: + description: The HooksServiceCreateResponse message. properties: - expression: - description: The expression field. - readOnly: false - type: string - title: Bundle Automation Rule Cel + hook: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - type: "null" + title: Hooks Service Create Response type: object - x-speakeasy-name-override: BundleAutomationRuleCEL - c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement: - description: The BundleAutomationRuleEntitlement message. - nullable: true + x-speakeasy-name-override: HooksServiceCreateResponse + c1.api.hooks.v1.HooksServiceDeleteRequestInput: + description: The HooksServiceDeleteRequest message. + title: Hooks Service Delete Request + type: object + x-speakeasy-name-override: HooksServiceDeleteRequest + c1.api.hooks.v1.HooksServiceDeleteResponse: + description: The HooksServiceDeleteResponse message. + title: Hooks Service Delete Response + type: object + x-speakeasy-name-override: HooksServiceDeleteResponse + c1.api.hooks.v1.HooksServiceGetResponse: + description: The HooksServiceGetResponse message. properties: - entitlementRefs: - description: The entitlementRefs field. + hook: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - type: "null" + title: Hooks Service Get Response + type: object + x-speakeasy-name-override: HooksServiceGetResponse + c1.api.hooks.v1.HooksServiceListResponse: + description: The HooksServiceListResponse message. + properties: + list: + description: The list field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Bundle Automation Rule Entitlement + $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Hooks Service List Response type: object - x-speakeasy-name-override: BundleAutomationRuleEntitlement - c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput: - description: | - The request message for creating a new bundle automation rule on a catalog. - - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel + x-speakeasy-name-override: HooksServiceListResponse + c1.api.hooks.v1.HooksServiceUpdateRequestInput: + description: The HooksServiceUpdateRequest message. properties: - cel: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - createTasks: - description: Whether to create access request tasks for matched users instead of granting directly. - readOnly: false - type: boolean - disableCircuitBreaker: - description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. - readOnly: false - type: boolean - enabled: - description: Whether the automation should actively run on its schedule. - readOnly: false - type: boolean - entitlements: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - title: Create Bundle Automation Request + hook: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - type: "null" + updateMask: + type: + - string + - "null" + title: Hooks Service Update Request type: object - x-speakeasy-name-override: CreateBundleAutomationRequest - c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput: - description: The request message for deleting a bundle automation from a catalog. - title: Delete Bundle Automation Request + x-speakeasy-name-override: HooksServiceUpdateRequest + c1.api.hooks.v1.HooksServiceUpdateResponse: + description: The HooksServiceUpdateResponse message. + properties: + hook: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.Hook' + - type: "null" + title: Hooks Service Update Response type: object - x-speakeasy-name-override: DeleteBundleAutomationRequest - c1.api.requestcatalog.v1.DeleteBundleAutomationResponse: - description: The response message for deleting a bundle automation. - title: Delete Bundle Automation Response + x-speakeasy-name-override: HooksServiceUpdateResponse + c1.api.hooks.v1.PIIRedactionConfig: + description: PIIRedactionConfig configures post-tool-use redaction of sensitive fields. + properties: + redactFields: + description: The redactFields field. + items: + type: string + type: + - array + - "null" + replacement: + description: The replacement field. + type: string + title: Pii Redaction Config type: object - x-speakeasy-name-override: DeleteBundleAutomationResponse - c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput: - description: The request message for triggering an immediate bundle automation run. + x-speakeasy-name-override: PIIRedactionConfig + c1.api.hooks.v1.QueryScopeLimitConfig: + description: |- + QueryScopeLimitConfig caps numeric fields (e.g. limit, page_size) in tool + input so callers cannot request unbounded data. properties: - refs: - description: Optional entitlement references to scope the run to specific entitlements. + fields: + description: The fields field. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Force Run Bundle Automation Request + type: string + type: + - array + - "null" + maxLimit: + description: The maxLimit field. + format: int32 + type: integer + title: Query Scope Limit Config type: object - x-speakeasy-name-override: ForceRunBundleAutomationRequest - c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse: - description: The response message for triggering a bundle automation run. - title: Force Run Bundle Automation Response + x-speakeasy-name-override: QueryScopeLimitConfig + c1.api.hooks.v1.SensitiveFileGuardConfig: + description: |- + SensitiveFileGuardConfig blocks tool calls that reference sensitive file + paths or directories. + properties: + blockedDirectories: + description: The blockedDirectories field. + items: + type: string + type: + - array + - "null" + blockedPatterns: + description: The blockedPatterns field. + items: + type: string + type: + - array + - "null" + title: Sensitive File Guard Config type: object - x-speakeasy-name-override: ForceRunBundleAutomationResponse - c1.api.requestcatalog.v1.RequestCatalog: - description: The RequestCatalog is used for managing which entitlements are requestable, and who can request them. + x-speakeasy-name-override: SensitiveFileGuardConfig + c1.api.hooks.v1.ToolOutputSizeGuardConfig: + description: ToolOutputSizeGuardConfig caps post-tool-use output size in bytes. properties: - accessEntitlements: - description: An array of app entitlements that, if the user has, can view the contents of this catalog. + maxBytes: + description: Maximum tool output size in bytes. Outputs exceeding this are denied. + format: int32 + type: integer + title: Tool Output Size Guard Config + type: object + x-speakeasy-name-override: ToolOutputSizeGuardConfig + c1.api.hooks.v1.WriteAuthorizationConfig: + description: |- + WriteAuthorizationConfig blocks tool calls whose ToolClassification is in + blocked_classifications, optionally permitting them within business hours. + properties: + blockedClassifications: + description: |- + Tool classifications to block. Must have at least one entry; a hook + with no blocked classifications would be a silent misconfiguration. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' - nullable: true - readOnly: false - type: array - createdAt: - format: date-time - readOnly: true + enum: + - TOOL_CLASSIFICATION_UNSPECIFIED + - TOOL_CLASSIFICATION_READ + - TOOL_CLASSIFICATION_WRITE + - TOOL_CLASSIFICATION_DESTRUCTIVE + - TOOL_CLASSIFICATION_SENSITIVE + - TOOL_CLASSIFICATION_DANGEROUS + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + businessHours: + oneOf: + - $ref: '#/components/schemas/c1.api.hooks.v1.BusinessHours' + - type: "null" + title: Write Authorization Config + type: object + x-speakeasy-name-override: WriteAuthorizationConfig + c1.api.iam.v1.ActorObjectPermissions: + description: |- + Legacy: do not use for new objects. Retained only for the existing + AppResource / AppEntitlement / access-review consumers, which will migrate to + c1.api.authorization.v1.ActorObjectPermissions in IGA-2331. New object views + should reference c1.api.authorization.v1.ActorObjectPermissions instead. + properties: + delete: + description: The delete field. + type: boolean + edit: + description: The edit field. + type: boolean + extra: + additionalProperties: + type: boolean + description: The extra field. + type: object + read: + description: The read field. + type: boolean + title: Actor Object Permissions + type: object + x-speakeasy-name-override: ActorObjectPermissions + c1.api.iam.v1.AnnouncedTunnelService: + description: |- + AnnouncedTunnelService is one service entry the appliance declared in its + wormhole HELLO frame. Read live from the discovery store; not persisted. + properties: + name: + description: Logical name of the service as declared by the appliance. type: string - createdByUserId: - description: The id of the user this request catalog was created by. - readOnly: false + port: + description: TCP port the service listens on inside the appliance network. + format: uint32 + type: integer + servicePath: + description: Optional URL path prefix for the service. type: string - deletedAt: - format: date-time - readOnly: true + serviceType: + description: Application-level protocol type (e.g. "http", "grpc"). type: string - description: - description: The description of the request catalog. - readOnly: false + transportType: + description: Transport protocol used by the wormhole tunnel (e.g. "tcp"). type: string - displayName: - description: The display name of the request catalog. - readOnly: false + title: Announced Tunnel Service + type: object + x-speakeasy-name-override: AnnouncedTunnelService + c1.api.iam.v1.ExternalClientInfo: + description: |- + ExternalClientInfo provides information about an approved external client. + Used by both List (user's own grants) and Search (admin view of all grants). + properties: + clientId: + description: OAuth2 client ID - canonical identifier for this connection (globally unique per DCR) type: string - enrollmentBehavior: - description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. + clientIdType: + description: How the client_id was established. enum: - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY - readOnly: false + - CLIENT_ID_TYPE_UNSPECIFIED + - CLIENT_ID_TYPE_DCR + - CLIENT_ID_TYPE_METADATA_URL type: string x-speakeasy-unknown-values: allow - grantPolicyId: + clientIdUrl: description: |- - The ID of the policy to use for access requests in this catalog. - This is different from the catalog AppEntitlement's grant_policy_id, which is used for catalog membership grants. - readOnly: false + Original CIMD metadata URL (e.g., "https://cursor.com/.well-known/oauth-client"). + Empty for DCR clients. type: string - id: - description: The id of the request catalog. - readOnly: false + clientName: + description: Original client name from DCR registration type: string - published: - description: Whether or not this catalog is published. - readOnly: false - type: boolean - requestBundle: - description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. - readOnly: false - type: boolean - unenrollmentBehavior: - description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED - readOnly: false + createdAt: + format: date-time + type: + - string + - "null" + displayName: + description: User-provided custom name (defaults to client_name if not set) type: string - x-speakeasy-unknown-values: allow - unenrollmentEntitlementBehavior: - description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. + lastUsedAt: + format: date-time + type: + - string + - "null" + mcpClientId: + description: MCP client record ID for AI governance tracking. May be empty for legacy grants. + type: string + roleIds: + description: Role IDs granted to this client - frontend can fetch display names via SearchRoles + items: + type: string + type: + - array + - "null" + userId: + description: The user who approved this external client (always populated) + type: string + verifiedDomain: + description: |- + Verified domain from the client_id URL (e.g., "cursor.com"). + Empty for DCR clients. + type: string + wellKnownClient: + description: The wellKnownClient field. enum: - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE - readOnly: false + - WELL_KNOWN_CLIENT_UNSPECIFIED + - WELL_KNOWN_CLIENT_UNKNOWN + - WELL_KNOWN_CLIENT_CLAUDE_AI + - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP + - WELL_KNOWN_CLIENT_CLAUDE_CODE + - WELL_KNOWN_CLIENT_MCP_INSPECTOR + - WELL_KNOWN_CLIENT_CHATGPT + - WELL_KNOWN_CLIENT_VSCODE + - WELL_KNOWN_CLIENT_CURSOR + - WELL_KNOWN_CLIENT_WINDSURF + - WELL_KNOWN_CLIENT_ZED + - WELL_KNOWN_CLIENT_JETBRAINS + - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT type: string x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true - type: string - visibleToEveryone: - description: If this is true, the access entitlement requirement is ignored. - readOnly: false - type: boolean - title: Request Catalog + title: External Client Info type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalog - c1.api.requestcatalog.v1.RequestCatalogExpandMask: - description: The RequestCatalogExpandMask includes the paths in the catalog view to expand in the return value of this call. + x-speakeasy-name-override: ExternalClientInfo + c1.api.iam.v1.ExternalClientSearchServiceSearchRequest: + description: The ExternalClientSearchServiceSearchRequest message. properties: - paths: - description: An array of paths to be expanded in the response. May be any combination of "*", "created_by_user_id", "app_ids", and "access_entitlements". + clientIdUrls: + description: |- + Exact-match filter on client_id values (e.g., CIMD URLs). + Returns only grants whose client_id matches one of these values. items: type: string - nullable: true - readOnly: false - type: array - title: Request Catalog Expand Mask - type: object - x-speakeasy-name-override: RequestCatalogExpandMask - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput: - description: |- - The RequestCatalogManagementServiceAddAccessEntitlementsRequest message is used to add access entitlements to a request - catalog to determine which users can view the request catalog. - properties: - accessEntitlements: - description: List of entitlements to add to the request catalog as access entitlements. + type: + - array + - "null" + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + query: + description: Free-text search on client_name and user display name + type: string + users: + description: Filter by specific user IDs items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - required: - - accessEntitlements - title: Request Catalog Management Service Add Access Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Visibility_Bindings - x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Add Access Entitlements Response + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + wellKnownClients: + description: Filter by well-known client type (e.g., CLAUDE_CODE, CURSOR, etc.) + items: + enum: + - WELL_KNOWN_CLIENT_UNSPECIFIED + - WELL_KNOWN_CLIENT_UNKNOWN + - WELL_KNOWN_CLIENT_CLAUDE_AI + - WELL_KNOWN_CLIENT_CLAUDE_DESKTOP + - WELL_KNOWN_CLIENT_CLAUDE_CODE + - WELL_KNOWN_CLIENT_MCP_INSPECTOR + - WELL_KNOWN_CLIENT_CHATGPT + - WELL_KNOWN_CLIENT_VSCODE + - WELL_KNOWN_CLIENT_CURSOR + - WELL_KNOWN_CLIENT_WINDSURF + - WELL_KNOWN_CLIENT_ZED + - WELL_KNOWN_CLIENT_JETBRAINS + - WELL_KNOWN_CLIENT_DOCKER_MCP_TOOLKIT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: External Client Search Service Search Request type: object - x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceAddAppEntitlementsRequest object is used to add app requestable app entitlements to a request catalog. + x-speakeasy-name-override: ExternalClientSearchServiceSearchRequest + c1.api.iam.v1.ExternalClientSearchServiceSearchResponse: + description: The ExternalClientSearchServiceSearchResponse message. properties: - appEntitlements: - description: List of entitlements to add to the request catalog. + list: + description: Uses ExternalClientInfo with user_id populated for admin views items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - createRequests: - description: |- - Whether or not to create requests for newly added entitlements for users in the catalog. - By default, this is false and no requests are created. - readOnly: false - type: boolean - required: - - appEntitlements - title: Request Catalog Management Service Add App Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Add App Entitlements Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest: - description: Create a request catalog. - properties: - description: - description: The description of the new request catalog. - readOnly: false - type: string - displayName: - description: The display name of the new request catalog. - readOnly: false - type: string - enrollmentBehavior: - description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. - enum: - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY - - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY - readOnly: false - type: string - x-speakeasy-unknown-values: allow - expandMask: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' - grantPolicyId: - description: The ID of the grant policy for access requests in this catalog. - readOnly: false - type: string - published: - description: Whether or not the new catalog should be created as published. - readOnly: false - type: boolean - requestBundle: - description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. - readOnly: false - type: boolean - unenrollmentBehavior: - description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL - - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED - readOnly: false - type: string - x-speakeasy-unknown-values: allow - unenrollmentEntitlementBehavior: - description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. - enum: - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS - - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE - readOnly: false + $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientInfo' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - x-speakeasy-unknown-values: allow - visibleToEveryone: - description: Whether or not the new catalog is visible to everyone by default. - readOnly: false - type: boolean - required: - - displayName - title: Request Catalog Management Service Create Request - type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput: - description: Create a single requestable entry - properties: - createRequests: - description: |- - Whether or not to create requests for newly added entitlement for users in the catalog. - By default, this is false and no requests are created. - readOnly: false - type: boolean - title: Request Catalog Management Service Create Requestable Entry Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entry - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse: - description: Response containing the created requestable entry - properties: - requestableEntry: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' - title: Request Catalog Management Service Create Requestable Entry Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput: - description: Delete a request catalog by Id. It uses URL value for input. - title: Request Catalog Management Service Delete Request - type: object - x-speakeasy-entity: Access_Profile - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput: - description: Delete a single requestable entry - title: Request Catalog Management Service Delete Requestable Entry Request - type: object - x-speakeasy-entity: Access_Profile_Requestable_Entry - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse: - description: Empty response for delete operation - title: Request Catalog Management Service Delete Requestable Entry Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Delete Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceDeleteResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse: - description: Response containing the requested entry - properties: - requestableEntry: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' - title: Request Catalog Management Service Get Requestable Entry Response - type: object - x-speakeasy-name-override: RequestCatalogManagementServiceGetRequestableEntryResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse: - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - requestCatalogView: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' - title: Request Catalog Management Service Get Response + title: External Client Search Service Search Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceGetResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse: - description: The response message containing all requestable entitlement references in the catalog. + x-speakeasy-name-override: ExternalClientSearchServiceSearchResponse + c1.api.iam.v1.GetRolesResponse: + description: The GetRolesResponse message contains the retrieved role. properties: - refs: - description: The complete list of app entitlement references in this catalog. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Request Catalog Management Service List All Entitlement Ids Per Catalog Response + role: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - type: "null" + title: Get Roles Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse: - description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: GetRolesResponse + c1.api.iam.v1.ListRolesResponse: + description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.iam.v1.Role' + type: + - array + - "null" nextPageToken: description: |- The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false type: string - title: Request Catalog Management Service List Entitlements For Access Response + title: List Roles Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsForAccessResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse: - description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ListRolesResponse + c1.api.iam.v1.PersonalClient: + description: The PersonalClient message contains information about a presonal client credential. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - list: - description: The list of results containing up to X results, where X is the page size defined in the request. + allowSourceCidr: + description: |- + If set, only allows the CIDRs in the array to use the credential. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' - nullable: true - readOnly: false - type: array - nextPageToken: + type: string + type: + - array + - "null" + clientId: + description: The clientID of the credential. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the personal client credential. + type: string + expiresTime: + format: date-time + type: + - string + - "null" + id: + description: The unique ID of the personal client credential. + readOnly: true + type: string + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + scopedRoles: description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + scoped_roles provides a list of IAM Roles + that this OAuth2 Client's API permissions + are reduced to. The permissions granted to OAuth2 Client + are AND'ed against the owning User's own permissions. + items: + type: string + type: + - array + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The ID of the user that this credential is created for. + readOnly: true type: string - title: Request Catalog Management Service List Entitlements Per Catalog Response + title: Personal Client type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsPerCatalogResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse: - description: The RequestCatalogManagementServiceListResponse message. + x-speakeasy-name-override: PersonalClient + c1.api.iam.v1.PersonalClientSearchServiceSearchRequest: + description: The PersonalClientSearchServiceSearchRequest message. properties: - expanded: - description: List of serialized related objects. + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token returned from a previous Search call. + type: string + query: + description: A text query to filter personal clients by display name. + type: string + users: + description: Filter results to personal clients owned by the specified users. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Personal Client Search Service Search Request + type: object + x-speakeasy-name-override: PersonalClientSearchServiceSearchRequest + c1.api.iam.v1.PersonalClientSearchServiceSearchResponse: + description: The PersonalClientSearchServiceSearchResponse message. + properties: list: - description: The list of request catalogs. + description: The list of personal client credentials matching the search criteria. items: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - title: Request Catalog Management Service List Response + title: Personal Client Search Service Search Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceListResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput: - description: |- - The RequestCatalogManagementServiceRemoveAccessEntitlementsRequest message is used to remove access entitlements from a request catalog. - The access entitlements are used to determine which users can view the request catalog. + x-speakeasy-name-override: PersonalClientSearchServiceSearchResponse + c1.api.iam.v1.PersonalClientServiceCreateRequest: + description: The PersonalClientServiceCreateRequest message contains the fields for creating a new personal client. properties: - accessEntitlements: - description: The list of access entitlements to remove from the catalog. + allowSourceCidr: + description: |- + A list of CIDRs to restrict this credential to. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Request Catalog Management Service Remove Access Entitlements Request - type: object - x-speakeasy-entity: Access_Profile_Visibility_Bindings - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse: - description: Empty response with a status code indicating success. - title: Request Catalog Management Service Remove Access Entitlements Response + type: string + type: + - array + - "null" + displayName: + description: The display name for the new personal client. + type: string + expires: + format: duration + type: + - string + - "null" + scopedRoles: + description: The list of roles to restrict the credential to. + items: + type: string + type: + - array + - "null" + title: Personal Client Service Create Request type: object - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceRemoveAppEntitlementsRequest message is used to remove app entitlements from a request catalog. + x-speakeasy-name-override: PersonalClientServiceCreateRequest + c1.api.iam.v1.PersonalClientServiceCreateResponse: + description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. properties: - appEntitlements: - description: The list of app entitlements to remove from the catalog. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - title: Request Catalog Management Service Remove App Entitlements Request + client: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - type: "null" + clientSecret: + description: The client secret that corresponds to the personal client. Make sure to save this, because it cannot be returned or queried again. + type: string + title: Personal Client Service Create Response type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse: - description: Empty response with a status code indicating success - title: Request Catalog Management Service Remove App Entitlements Response + x-speakeasy-name-override: PersonalClientServiceCreateResponse + c1.api.iam.v1.PersonalClientServiceDeleteRequestInput: + description: The PersonalClientServiceDeleteRequest message. + title: Personal Client Service Delete Request type: object - x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput: - description: The RequestCatalogManagementServiceUpdateAppEntitlementsRequest object is used to update app entitlements to a request catalog id. + x-speakeasy-name-override: PersonalClientServiceDeleteRequest + c1.api.iam.v1.PersonalClientServiceDeleteResponse: + description: The PersonalClientServiceDeleteResponse message. + title: Personal Client Service Delete Response + type: object + x-speakeasy-name-override: PersonalClientServiceDeleteResponse + c1.api.iam.v1.PersonalClientServiceGetResponse: + description: The PersonalClientServiceGetResponse message. properties: - appEntitlements: - description: The entitlement to get from the request catalog. - items: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - nullable: true - readOnly: false - type: array - required: - - appEntitlements - title: Request Catalog Management Service Update App Entitlements Request + client: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - type: "null" + title: Personal Client Service Get Response type: object - x-speakeasy-entity: Access_Profile_Requestable_Entries - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse: - description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. - title: Request Catalog Management Service Update App Entitlements Response + x-speakeasy-name-override: PersonalClientServiceGetResponse + c1.api.iam.v1.PersonalClientServiceListResponse: + description: The PersonalClientServiceListResponse message. + properties: + list: + description: The list of personal client credentials owned by the calling user. + items: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Personal Client Service List Response type: object - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput: - description: Update a request catalog object by ID. + x-speakeasy-name-override: PersonalClientServiceListResponse + c1.api.iam.v1.PersonalClientServiceUpdateRequestInput: + description: The PersonalClientServiceUpdateRequest message. properties: - catalog: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' - expandMask: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' + client: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - type: "null" updateMask: - nullable: true - readOnly: false - type: string - title: Request Catalog Management Service Update Request + type: + - string + - "null" + title: Personal Client Service Update Request type: object - x-speakeasy-name-override: RequestCatalogManagementServiceUpdateRequest - c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest: - description: The RequestCatalogSearchServiceSearchEntitlementsRequest searches entitlements, but only ones that are available to you through the open catalogs. + x-speakeasy-name-override: PersonalClientServiceUpdateRequest + c1.api.iam.v1.PersonalClientServiceUpdateResponse: + description: The PersonalClientServiceUpdateResponse message. properties: - appDisplayName: - description: Search entitlements that belong to this app name (exact match). - readOnly: false + client: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClient' + - type: "null" + title: Personal Client Service Update Response + type: object + x-speakeasy-name-override: PersonalClientServiceUpdateResponse + c1.api.iam.v1.PersonalDevice: + description: |- + PersonalDevice is one physical device with its app clients. The device + identity is a stable thumbprint of the device's root signing key; the root key + never authenticates an app — each client uses its own key. + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deviceId: + description: |- + The stable device identity: a base64url-encoded SHA-256 thumbprint of the + device's root public signing key. + readOnly: true type: string - entitlementAlias: - description: Search for entitlements with this alias (exact match). - readOnly: false + deviceOs: + description: The device operating system, e.g. "macos-14.5". + readOnly: true type: string - expandMask: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' - grantedStatus: - description: Search entitlements with this granted status for your signed in user. + deviceSurface: + description: The device surface, e.g. "macos-desktop". + readOnly: true + type: string + displayName: + description: |- + The human-friendly device label, defaulted from the first app's name at + registration. Devices are listed sorted by this name. Mutable via + UpdateDevice. + type: string + status: + description: |- + The device's lifecycle status. Revoked devices are retained for audit and are + returned by Search only when the status filter requests them. enum: - - UNSPECIFIED - - ALL - - GRANTED - - NOT_GRANTED - readOnly: false + - PERSONAL_DEVICE_STATUS_UNSPECIFIED + - PERSONAL_DEVICE_STATUS_ACTIVE + - PERSONAL_DEVICE_STATUS_REVOKED + readOnly: true type: string x-speakeasy-unknown-values: allow - includeDeleted: - description: Include deleted entitlements - readOnly: false - type: boolean + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The ID of the user this device is bound to (the approving user). + readOnly: true + type: string + title: Personal Device + type: object + x-speakeasy-name-override: PersonalDevice + c1.api.iam.v1.PersonalDeviceClient: + description: |- + PersonalDeviceClient is a single app client on a device. The client + authenticates with its own asymmetric key; there is no client secret. + properties: + clientId: + description: The full client_id of the device credential. + readOnly: true + type: string + clientName: + description: The human-friendly client name from its registration metadata. + readOnly: true + type: string + consumerKeyId: + description: The stable identity of this client's per-app key. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deviceOs: + description: The device operating system captured for this client, e.g. "macos-14.5". + readOnly: true + type: string + deviceSurface: + description: The device surface captured for this client, e.g. "macos-desktop". + readOnly: true + type: string + displayName: + description: The display name of the device credential. + readOnly: true + type: string + id: + description: The unique ID of the device client (the local part of client_id). + readOnly: true + type: string + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + softwareId: + description: An identifier for the client software, from its registration metadata. + readOnly: true + type: string + softwareVersion: + description: The version of the client software, from its registration metadata. + readOnly: true + type: string + title: Personal Device Client + type: object + x-speakeasy-name-override: PersonalDeviceClient + c1.api.iam.v1.PersonalDeviceServiceGetDeviceResponse: + description: The PersonalDeviceServiceGetDeviceResponse message. + properties: + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + title: Personal Device Service Get Device Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceGetDeviceResponse + c1.api.iam.v1.PersonalDeviceServiceListDeviceClientsResponse: + description: The PersonalDeviceServiceListDeviceClientsResponse message. + properties: + clients: + description: The app clients registered on the device. + items: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceClient' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more. + type: string + title: Personal Device Service List Device Clients Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceListDeviceClientsResponse + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientRequestInput: + description: The PersonalDeviceServiceRevokeDeviceClientRequest message. + title: Personal Device Service Revoke Device Client Request + type: object + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientRequest + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientResponse: + description: The PersonalDeviceServiceRevokeDeviceClientResponse message. + title: Personal Device Service Revoke Device Client Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceClientResponse + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceRequestInput: + description: The PersonalDeviceServiceRevokeDeviceRequest message. + title: Personal Device Service Revoke Device Request + type: object + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceRequest + c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceResponse: + description: The PersonalDeviceServiceRevokeDeviceResponse message. + title: Personal Device Service Revoke Device Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceRevokeDeviceResponse + c1.api.iam.v1.PersonalDeviceServiceSearchRequest: + description: The PersonalDeviceServiceSearchRequest message. + properties: pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: The maximum number of results to return per page. format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: A pagination token returned from a previous Search call. type: string query: - description: Fuzzy search the display name of resource types. - readOnly: false + description: An optional case-insensitive filter on the device display name. type: string - title: Request Catalog Search Service Search Entitlements Request + statusFilter: + description: Which device statuses to return. Defaults to active devices only. + enum: + - PERSONAL_DEVICE_STATUS_FILTER_UNSPECIFIED + - PERSONAL_DEVICE_STATUS_FILTER_ACTIVE + - PERSONAL_DEVICE_STATUS_FILTER_REVOKED + - PERSONAL_DEVICE_STATUS_FILTER_ALL + type: string + x-speakeasy-unknown-values: allow + title: Personal Device Service Search Request type: object - x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsRequest - c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse: - description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: PersonalDeviceServiceSearchRequest + c1.api.iam.v1.PersonalDeviceServiceSearchResponse: + description: The PersonalDeviceServiceSearchResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: - description: The list of results containing up to X results, where X is the page size defined in the request. + description: The devices the calling user has registered, matching the search criteria. items: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.AppEntitlementWithUserBindings' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: A token to retrieve the next page of results, or empty if there are no more. type: string - title: Request Catalog Search Service Search Entitlements Response + title: Personal Device Service Search Response type: object - x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsResponse - c1.api.requestcatalog.v1.RequestCatalogView: - description: The request catalog view contains the serialized request catalog and paths to objects referenced by the request catalog. + x-speakeasy-name-override: PersonalDeviceServiceSearchResponse + c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceRequestInput: + description: The PersonalDeviceServiceUpdateDeviceRequest message. properties: - accessEntitlementsPath: - description: JSONPATH expression indicating the location of the access entitlement objects, that the request catalog allows users to request, in the array. - readOnly: false - type: string - createdByUserPath: - description: JSONPATH expression indicating the location of the User object, that created the request catalog, in the array. - readOnly: false - type: string - memberCount: - description: Total number of the members of the catalog - format: int64 - readOnly: false - type: string - requestCatalog: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' - title: Request Catalog View - type: object - x-speakeasy-name-override: RequestCatalogView - c1.api.requestcatalog.v1.RequestableEntry: - description: A requestable entry in a catalog + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + updateMask: + type: + - string + - "null" + title: Personal Device Service Update Device Request + type: object + x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceRequest + c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceResponse: + description: The PersonalDeviceServiceUpdateDeviceResponse message. + properties: + device: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.PersonalDevice' + - type: "null" + title: Personal Device Service Update Device Response + type: object + x-speakeasy-name-override: PersonalDeviceServiceUpdateDeviceResponse + c1.api.iam.v1.Role: + description: Role is a role that can be assigned to a user in ConductorOne. properties: - appId: - description: The ID of the app that contains the entitlement - readOnly: false + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the role. type: string - catalogId: - description: The ID of the access profile (catalog) - readOnly: false + id: + description: The id of the role. + readOnly: true type: string - entitlementId: - description: The ID of the entitlement - readOnly: false + name: + description: The internal name of the role. + readOnly: true type: string - title: Requestable Entry - type: object - x-speakeasy-name-override: RequestableEntry - c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput: - description: The request message for resuming a paused bundle automation. - title: Resume Paused Bundle Automation Request - type: object - x-speakeasy-name-override: ResumePausedBundleAutomationRequest - c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse: - description: The response message for resuming a paused bundle automation. - title: Resume Paused Bundle Automation Response - type: object - x-speakeasy-name-override: ResumePausedBundleAutomationResponse - c1.api.requestcatalog.v1.SetBundleAutomationRequestInput: - description: | - The request message for creating or updating a bundle automation rule on a catalog. - - This message contains a oneof named conditions. Only a single field of the following list may be set at a time: - - entitlements - - cel - properties: - cel: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' - createTasks: - description: Whether to create access request tasks for matched users instead of granting directly. - readOnly: false - type: boolean - disableCircuitBreaker: - description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. - readOnly: false + permissions: + description: The list of permissions this role has. + items: + type: string + type: + - array + - "null" + serviceRoles: + description: The list of serviceRoles that this role has. + items: + type: string + type: + - array + - "null" + systemApiOnly: + description: This Role is intended for API keys usage only, and the user interface may not function as expected. + readOnly: true type: boolean - enabled: - description: Whether the automation should actively run on its schedule. - readOnly: false + systemBuiltin: + description: The system builtin field. If this field is set, the role is not editable. + readOnly: true type: boolean - entitlements: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' - title: Set Bundle Automation Request + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Role type: object - x-speakeasy-name-override: SetBundleAutomationRequest - c1.api.role_mining_management.v1.CohortHintInput: - description: The CohortHintInput message. + x-speakeasy-name-override: Role + c1.api.iam.v1.TunnelAppliance: + description: |- + TunnelAppliance is the live state of the customer-side appliance for one + bridge. properties: - attribute: - description: The user attribute name to use for cohort grouping (e.g., "department", "job_title"). - readOnly: false - type: string - priority: - description: Relative priority of this hint. Higher values cause the analysis to weight this attribute more heavily. - format: int32 - readOnly: false + announcedServiceCount: + description: Number of services the appliance is currently announcing. + format: uint32 type: integer - values: - description: Specific attribute values to focus on. If empty, all values for the attribute are considered. + lastSeenAt: + format: date-time + type: + - string + - "null" + links: + description: |- + Wormhole relays currently holding a Link for this bridge. Typically of + length 1. items: - type: string - nullable: true - readOnly: false - type: array - title: Cohort Hint Input + $ref: '#/components/schemas/c1.api.iam.v1.TunnelApplianceLink' + type: + - array + - "null" + status: + description: The status field. + enum: + - TUNNEL_APPLIANCE_STATUS_UNSPECIFIED + - TUNNEL_APPLIANCE_STATUS_CONNECTED + - TUNNEL_APPLIANCE_STATUS_DISCONNECTED + - TUNNEL_APPLIANCE_STATUS_NEVER_CONNECTED + type: string + x-speakeasy-unknown-values: allow + title: Tunnel Appliance type: object - x-speakeasy-name-override: CohortHintInput - c1.api.role_mining_management.v1.CohortHintView: - description: The CohortHintView message. + x-speakeasy-name-override: TunnelAppliance + c1.api.iam.v1.TunnelApplianceLink: + description: The TunnelApplianceLink message. properties: - attribute: - description: The user attribute name used for cohort grouping. - readOnly: false + avgRtt: + format: duration + type: + - string + - "null" + leaseExpiresAt: + format: date-time + type: + - string + - "null" + relayAddress: + description: |- + Public address (host:port) of the relay server, suitable for use in + client-side connection strings. type: string - priority: - description: Relative priority of this hint. - format: int32 - readOnly: false - type: integer - values: - description: The specific attribute values targeted by this hint. - items: - type: string - nullable: true - readOnly: false - type: array - title: Cohort Hint View + relayId: + description: Identifier of the wormhole relay server holding this Link. + type: string + title: Tunnel Appliance Link type: object - x-speakeasy-name-override: CohortHintView - c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest: - description: The CreateAccessProfileFromCohortRequest message. + x-speakeasy-name-override: TunnelApplianceLink + c1.api.iam.v1.TunnelBridge: + description: |- + TunnelBridge is the API view of a bridge — the customer-facing entity + for managing a wormhole tunnel appliance. properties: - createTasks: - description: |- - If true, the automation will create JIT tasks for access changes. - If false, users are synced to membership without creating tasks. - readOnly: false - type: boolean + appliance: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelAppliance' + - type: "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" description: - description: Description for the access profile. - readOnly: false + description: The description field. type: string displayName: - description: Display name for the access profile. - readOnly: false + description: The displayName field. type: string - enableAutomation: - description: If true, enable the dynamic membership automation immediately. - readOnly: false - type: boolean - entitlements: - description: Entitlements to add to the access profile. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - nullable: true - readOnly: false - type: array - profileFilters: - description: Profile filters defining the cohort for dynamic membership. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - nullable: true - readOnly: false - type: array - suggestionId: - description: Optional suggestion ID to mark as accepted after creating the profile. - readOnly: false + id: + description: The id field. + readOnly: true type: string - title: Create Access Profile From Cohort Request + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Tunnel Bridge type: object - x-speakeasy-name-override: CreateAccessProfileFromCohortRequest - c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse: - description: The CreateAccessProfileFromCohortResponse message. + x-speakeasy-name-override: TunnelBridge + c1.api.iam.v1.TunnelCredential: + description: |- + TunnelCredential is the API view of one OAuth credential within a bridge. + The plaintext client_secret is only populated on the CreateBridgeCredential + response. properties: - accessProfileId: - description: The ID of the created access profile. - readOnly: false + bridgeId: + description: The bridge this credential belongs to. + readOnly: true type: string - celExpression: - description: The CEL expression generated for dynamic membership. - readOnly: false + clientId: + description: The client_id (full ${id}@${tenant_domain}/tcc form). + readOnly: true type: string - title: Create Access Profile From Cohort Response - type: object - x-speakeasy-name-override: CreateAccessProfileFromCohortResponse - c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse: - description: The GetCustomAnalysisResultResponse message. - properties: - appsAnalyzed: - description: The appsAnalyzed field. - format: int32 - readOnly: false - type: integer - clusters: - description: Cluster results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.EntitlementCluster' - nullable: true - readOnly: false - type: array - cohortSize: - description: The cohortSize field. - format: int32 - readOnly: false - type: integer - entitlements: - description: Entitlement coverage results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - nullable: true - readOnly: false - type: array - errorMessage: - description: The errorMessage field. - readOnly: false + clientSecret: + description: |- + The plaintext client_secret. ONLY populated on the + CreateBridgeCredential response; empty on Get / List. + readOnly: true type: string - facetUserCount: - description: The facetUserCount field. - format: int32 - readOnly: false - type: integer - facets: - description: Facet results. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeFacet' - nullable: true - readOnly: false - type: array + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + credentialStatus: + description: Lifecycle status of this credential record. + enum: + - TUNNEL_CREDENTIAL_STATUS_UNSPECIFIED + - TUNNEL_CREDENTIAL_STATUS_ACTIVE + - TUNNEL_CREDENTIAL_STATUS_REVOKED + - TUNNEL_CREDENTIAL_STATUS_EXPIRED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + expiresTime: + format: date-time + readOnly: true + type: + - string + - "null" id: description: The id field. - readOnly: false + readOnly: true type: string - status: - description: The status field. - enum: - - RUN_STATUS_UNSPECIFIED - - RUN_STATUS_RUNNING - - RUN_STATUS_COMPLETED - - RUN_STATUS_FAILED - readOnly: false + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + revokedAt: + format: date-time + readOnly: true + type: + - string + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Tunnel Credential + type: object + x-speakeasy-name-override: TunnelCredential + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialRequestInput: + description: The TunnelCredentialsServiceCreateBridgeCredentialRequest message. + title: Tunnel Credentials Service Create Bridge Credential Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialRequest + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialResponse: + description: The TunnelCredentialsServiceCreateBridgeCredentialResponse message. + properties: + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' + - type: "null" + title: Tunnel Credentials Service Create Bridge Credential Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeCredentialResponse + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeRequest: + description: The TunnelCredentialsServiceCreateBridgeRequest message. + properties: + description: + description: The description field. type: string - x-speakeasy-unknown-values: allow - title: Get Custom Analysis Result Response + displayName: + description: The displayName field. + type: string + title: Tunnel Credentials Service Create Bridge Request type: object - x-speakeasy-name-override: GetCustomAnalysisResultResponse - c1.api.role_mining_management.v1.GetLatestRunResponse: - description: The GetLatestRunResponse message. + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeResponse: + description: The TunnelCredentialsServiceCreateBridgeResponse message. properties: - run: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' - title: Get Latest Run Response + bridge: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - type: "null" + title: Tunnel Credentials Service Create Bridge Response type: object - x-speakeasy-name-override: GetLatestRunResponse - c1.api.role_mining_management.v1.GetRoleMiningConfigResponse: - description: The GetRoleMiningConfigResponse message. + x-speakeasy-name-override: TunnelCredentialsServiceCreateBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeRequestInput: + description: The TunnelCredentialsServiceDeleteBridgeRequest message. + title: Tunnel Credentials Service Delete Bridge Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeResponse: + description: Empty response body. Status code indicates success. + title: Tunnel Credentials Service Delete Bridge Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceDeleteBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceGetBridgeResponse: + description: The TunnelCredentialsServiceGetBridgeResponse message. properties: - config: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' - title: Get Role Mining Config Response + bridge: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - type: "null" + title: Tunnel Credentials Service Get Bridge Response type: object - x-speakeasy-name-override: GetRoleMiningConfigResponse - c1.api.role_mining_management.v1.GetSuggestionResponse: - description: The GetSuggestionResponse message. + x-speakeasy-name-override: TunnelCredentialsServiceGetBridgeResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgeAnnouncedServicesResponse: + description: The TunnelCredentialsServiceListBridgeAnnouncedServicesResponse message. properties: - suggestion: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - title: Get Suggestion Response + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.iam.v1.AnnouncedTunnelService' + type: + - array + - "null" + title: Tunnel Credentials Service List Bridge Announced Services Response type: object - x-speakeasy-name-override: GetSuggestionResponse - c1.api.role_mining_management.v1.ListRunsResponse: - description: The ListRunsResponse message. + x-speakeasy-name-override: TunnelCredentialsServiceListBridgeAnnouncedServicesResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgeCredentialsResponse: + description: The TunnelCredentialsServiceListBridgeCredentialsResponse message. properties: list: - description: The list of role mining analysis runs. + description: The list field. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredential' + type: + - array + - "null" nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. - readOnly: false + description: The nextPageToken field. type: string - title: List Runs Response + title: Tunnel Credentials Service List Bridge Credentials Response type: object - x-speakeasy-name-override: ListRunsResponse - c1.api.role_mining_management.v1.ListSuggestionsResponse: - description: The ListSuggestionsResponse message. + x-speakeasy-name-override: TunnelCredentialsServiceListBridgeCredentialsResponse + c1.api.iam.v1.TunnelCredentialsServiceListBridgesResponse: + description: The TunnelCredentialsServiceListBridgesResponse message. properties: list: - description: The list of role mining suggestions. + description: The list field. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + type: + - array + - "null" nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. - readOnly: false + description: The nextPageToken field. type: string - title: List Suggestions Response + title: Tunnel Credentials Service List Bridges Response type: object - x-speakeasy-name-override: ListSuggestionsResponse - c1.api.role_mining_management.v1.RoleMiningManagementConfig: - description: The RoleMiningManagementConfig message. - properties: - cohortHints: - description: Configured cohort hints that guide which user attributes the analysis prioritizes. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintView' - nullable: true - readOnly: false - type: array - maxSuggestions: - description: Maximum number of suggestions the analysis will produce per run. - format: int32 - readOnly: false - type: integer - minCohortSize: - description: Minimum number of users a cohort must contain to generate a suggestion. - format: int32 - readOnly: false - type: integer - title: Role Mining Management Config + x-speakeasy-name-override: TunnelCredentialsServiceListBridgesResponse + c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialRequestInput: + description: The TunnelCredentialsServiceRevokeBridgeCredentialRequest message. + title: Tunnel Credentials Service Revoke Bridge Credential Request type: object - x-speakeasy-name-override: RoleMiningManagementConfig - c1.api.role_mining_management.v1.RoleMiningManagementRun: - description: The RoleMiningManagementRun message. + x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialRequest + c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialResponse: + description: Empty response body. Status code indicates success. + title: Tunnel Credentials Service Revoke Bridge Credential Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceRevokeBridgeCredentialResponse + c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeRequestInput: + description: The TunnelCredentialsServiceUpdateBridgeRequest message. properties: - cohortsAnalyzed: - description: Number of user cohorts evaluated during the analysis. - format: int32 - readOnly: false - type: integer - completedAt: - format: date-time - readOnly: false + description: + description: |- + New description. Applied only when "description" is in update_mask. + Empty clears the description. type: string + displayName: + description: |- + New display name. Applied only when "display_name" is in update_mask. + Must be non-empty when applied. + type: string + updateMask: + type: + - string + - "null" + title: Tunnel Credentials Service Update Bridge Request + type: object + x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeRequest + c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeResponse: + description: The TunnelCredentialsServiceUpdateBridgeResponse message. + properties: + bridge: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.TunnelBridge' + - type: "null" + title: Tunnel Credentials Service Update Bridge Response + type: object + x-speakeasy-name-override: TunnelCredentialsServiceUpdateBridgeResponse + c1.api.iam.v1.UpdateRoleRequestInput: + description: The UpdateRoleRequest message contains the role to update and the update mask. + properties: + role: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Role Request + type: object + x-speakeasy-name-override: UpdateRoleRequest + c1.api.iam.v1.UpdateRolesResponse: + description: UpdateRolesResponse is the response message containing the updated role. + properties: + role: + oneOf: + - $ref: '#/components/schemas/c1.api.iam.v1.Role' + - type: "null" + title: Update Roles Response + type: object + x-speakeasy-name-override: UpdateRolesResponse + c1.api.identity_platform.v1.IdentityPolicyTenantDefaults: + description: |- + IdentityPolicyTenantDefaults is the tenant-wide set of default identity + policies applied when no more specific policy matches a user. + properties: createdAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + credentialInventoryPolicyId: + description: The default credential inventory policy (which credential types users may enroll). type: string - errorMessage: - description: Error message if the run failed, empty on success. - readOnly: false + enrollmentRequirementId: + description: The default enrollment requirement. type: string - id: - description: Unique identifier for this analysis run. - readOnly: false + recoveryPolicyId: + description: The default recovery policy. type: string - status: - description: Current execution status of this run (e.g., running, completed, failed). - enum: - - RUN_STATUS_UNSPECIFIED - - RUN_STATUS_RUNNING - - RUN_STATUS_COMPLETED - - RUN_STATUS_FAILED - readOnly: false + resourcePolicyId: + description: The default resource policy. type: string - x-speakeasy-unknown-values: allow - suggestionsGenerated: - description: Number of role suggestions produced by this run. - format: int32 - readOnly: false - type: integer - totalUsers: - description: Total number of users evaluated during the analysis. - format: int32 - readOnly: false - type: integer - triggerDetail: - description: Additional detail about the trigger, such as the user or schedule that initiated the run. - readOnly: false + sessionPolicyId: + description: The default session policy. type: string - triggerType: - description: How this run was initiated (e.g., manual, scheduled). - enum: - - TRIGGER_TYPE_UNSPECIFIED - - TRIGGER_TYPE_MANUAL - - TRIGGER_TYPE_UPLIFT_COMPLETION - - TRIGGER_TYPE_SCHEDULED - - TRIGGER_TYPE_DIRECTORY_MERGE - readOnly: false + signInPolicyId: + description: The default sign-in policy. type: string - x-speakeasy-unknown-values: allow + universalPromiseIds: + description: |- + Tenant-wide promises every user must satisfy (e.g. terms-of-service + acceptance). + items: + type: string + type: + - array + - "null" updatedAt: format: date-time - readOnly: false - type: string - title: Role Mining Management Run + readOnly: true + type: + - string + - "null" + title: Identity Policy Tenant Defaults type: object - x-speakeasy-name-override: RoleMiningManagementRun - c1.api.role_mining_management.v1.RoleMiningManagementSuggestion: - description: The RoleMiningManagementSuggestion message. + x-speakeasy-entity: IdentityPolicyTenantDefaults + x-speakeasy-name-override: IdentityPolicyTenantDefaults + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceGetResponse: + description: The IdentityPolicyTenantDefaultsServiceGetResponse message. properties: - avgCoverage: - description: Average fraction of suggested entitlements held by each user in the cohort. - readOnly: false - type: number - cohortFilters: - description: The profile filters that define which users belong to this cohort. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - nullable: true - readOnly: false - type: array - cohortSize: - description: Total number of users in the cohort matching the profile filters. - format: int32 - readOnly: false - type: integer - confidence: - description: Overall confidence score for this suggestion, from 0.0 to 1.0. - readOnly: false - type: number - createdAt: - format: date-time - readOnly: false - type: string - createdCatalogId: - description: The ID of the access profile created when this suggestion was accepted, empty if not yet accepted. - readOnly: false - type: string - description: - description: A human-readable description of the proposed role and the cohort it serves. - readOnly: false + defaults: + oneOf: + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' + - type: "null" + title: Identity Policy Tenant Defaults Service Get Response + type: object + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceGetResponse + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateRequest: + description: The IdentityPolicyTenantDefaultsServiceUpdateRequest message. + properties: + defaults: + oneOf: + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' + - type: "null" + updateMask: + type: + - string + - "null" + title: Identity Policy Tenant Defaults Service Update Request + type: object + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateRequest + c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateResponse: + description: The IdentityPolicyTenantDefaultsServiceUpdateResponse message. + properties: + defaults: + oneOf: + - $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaults' + - type: "null" + title: Identity Policy Tenant Defaults Service Update Response + type: object + x-speakeasy-name-override: IdentityPolicyTenantDefaultsServiceUpdateResponse + c1.api.integration.connector.v1.CheckboxField: + description: The CheckboxField message. + properties: + checked: + description: The checked field. + type: boolean + title: Checkbox Field + type: object + x-speakeasy-name-override: ConnectorCheckboxField + c1.api.integration.connector.v1.ConfigSchema: + description: The ConfigSchema message. + properties: + displayName: + description: The displayName field. type: string - dimensionCount: - description: Number of distinct attribute dimensions used to define the cohort. - format: int32 - readOnly: false - type: integer - entitlements: - description: The entitlements that are commonly held by users in this cohort. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - nullable: true - readOnly: false - type: array - existingProfileMatches: - description: Existing access profiles that overlap with this suggestion. + fieldGroups: + description: Optional. Metadata for displaying fields in the UI. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AccessProfileMatch' - nullable: true - readOnly: false - type: array - id: - description: Unique identifier for this suggestion. - readOnly: false - type: string - insights: - description: Human-readable insights explaining why this role was suggested. + $ref: '#/components/schemas/c1.api.integration.connector.v1.FieldGroup' + type: + - array + - "null" + fields: + description: The fields field. items: - type: string - nullable: true - readOnly: false - type: array - lastGeneratedAt: - format: date-time - readOnly: false + $ref: '#/components/schemas/c1.api.integration.connector.v1.Field' + type: + - array + - "null" + helpUrl: + description: The helpUrl field. type: string - runId: - description: The ID of the analysis run that produced this suggestion. - readOnly: false + iconUrl: + deprecated: true + description: The iconUrl field. type: string - suggestedName: - description: The suggested display name for the proposed role. - readOnly: false + isOauth2: + description: The isOauth2 field. + type: boolean + requiresExternalConnector: + description: The requiresExternalConnector field. + type: boolean + supportsExternalResources: + description: The supportsExternalResources field. + type: boolean + title: Config Schema + type: object + x-speakeasy-name-override: ConfigSchema + c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest: + description: ConnectorCatalogServiceConfigurationSchemaRequest is the request for retrieving a connector's configuration schema. + properties: + appId: + description: The ID of the app associated with the connector. Optional. type: string - suggestionState: - description: Current workflow state of this suggestion (e.g., pending, accepted, dismissed). - enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED - readOnly: false + catalogId: + description: The catalog entry ID identifying the connector type. type: string - x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: false + connectorId: + description: The ID of an existing connector to retrieve its current configuration schema. Optional. type: string - usersWithAll: - description: Number of users in the cohort that hold all of the suggested entitlements. - format: int32 - readOnly: false - type: integer - title: Role Mining Management Suggestion + title: Connector Catalog Service Configuration Schema Request type: object - x-speakeasy-name-override: RoleMiningManagementSuggestion - c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest: - description: The RoleMiningSearchSuggestionsRequest message. + x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaRequest + c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse: + description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. properties: - cohortTypes: - description: Filter by cohort type (e.g. "department", "job_title", "manager"). - items: - type: string - nullable: true - readOnly: false - type: array - matchTypes: - description: Filter by match type against existing access profiles. - items: - enum: - - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED - - ACCESS_PROFILE_MATCH_TYPE_EXACT - - ACCESS_PROFILE_MATCH_TYPE_SUPERSET - - ACCESS_PROFILE_MATCH_TYPE_PARTIAL - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - pageSize: - description: Maximum number of suggestions to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous response. - readOnly: false - type: string - query: - description: Text search — matches against suggested_name, description, and cohort filter values. - readOnly: false + formSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + schema: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConfigSchema' + - type: "null" + title: Connector Catalog Service Configuration Schema Response + type: object + x-speakeasy-name-override: ConnectorCatalogServiceConfigurationSchemaResponse + c1.api.integration.connector.v1.Field: + description: | + The Field message. + + This message contains a oneof named field. Only a single field of the following list may be set at a time: + - str + - select + - random + - import + - oauth2 + - readOnly + - options + - checkbox + - secret + - strList + - text + - keyValue + - stringMap + properties: + additionalPlaceholder: + description: |- + Optional. Additional placeholder text for the field + In cases where a single placeholder is not enough to describe the field type: string - states: - description: Filter by suggestion state. + checkbox: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.CheckboxField' + - type: "null" + dependsOnFields: + description: The dependsOnFields field. items: - enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Role Mining Search Suggestions Request + type: + - array + - "null" + displayName: + description: Human-readable label for this Field + type: string + helpUrl: + description: empty or https URL + type: string + import: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ImportField' + - type: "null" + keyValue: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.KeyValueField' + - type: "null" + name: + description: Must not start with `C1_` and match [a-zA-Z0-9_]{2,64}. Must be unique within a connector. + type: string + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.OAuth2Field' + - type: "null" + options: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.OptionsField' + - type: "null" + placeholder: + description: The placeholder field. + type: string + postCreate: + description: The postCreate field. + type: boolean + random: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.RandomStringField' + - type: "null" + readOnly: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.ReadOnlyField' + - type: "null" + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.RotatableSecretField' + - type: "null" + select: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField' + - type: "null" + str: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringField' + - type: "null" + strList: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringListField' + - type: "null" + stringMap: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.StringMapField' + - type: "null" + text: + oneOf: + - $ref: '#/components/schemas/c1.api.integration.connector.v1.TextField' + - type: "null" + title: Field type: object - x-speakeasy-name-override: RoleMiningSearchSuggestionsRequest - c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse: - description: The RoleMiningSearchSuggestionsResponse message. + x-speakeasy-name-override: Field + c1.api.integration.connector.v1.FieldGroup: + description: The FieldGroup message. properties: - list: - description: The list of matching role mining suggestions. + default: + description: The default field. + type: boolean + displayName: + description: Nice name this group (e.g. renders as a Tab label) + type: string + fieldNames: + description: Field names are "guaranteed" to be unique, but can be repeated in and between lists. items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. - readOnly: false + type: string + type: + - array + - "null" + helpText: + description: Optional. User-facing help text. type: string - title: Role Mining Search Suggestions Response + name: + description: Unique ID. + type: string + title: Field Group type: object - x-speakeasy-name-override: RoleMiningSearchSuggestionsResponse - c1.api.role_mining_management.v1.SearchCohortUsersRequestInput: - description: The SearchCohortUsersRequest message. + x-speakeasy-name-override: FieldGroup + c1.api.integration.connector.v1.ImportField: + description: The ImportField message. properties: - pageSize: - description: Maximum number of users to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous response. - readOnly: false - type: string - profileFilters: - description: Additional profile filters to narrow the cohort user search. + allowedExtensions: + description: The allowedExtensions field. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - nullable: true - readOnly: false - type: array - title: Search Cohort Users Request + type: string + type: + - array + - "null" + secret: + description: The secret field. + type: boolean + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: Import Field type: object - x-speakeasy-name-override: SearchCohortUsersRequest - c1.api.role_mining_management.v1.SearchCohortUsersResponse: - description: The SearchCohortUsersResponse message. + x-speakeasy-name-override: ImportField + c1.api.integration.connector.v1.KeyValueField: + description: The KeyValueField message. properties: - list: - description: The list of users matching the cohort and optional filters. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results, empty if no more results. - readOnly: false - type: string - title: Search Cohort Users Response + secret: + description: The secret field. + type: boolean + supportsFileUpload: + description: When true, UI allows file uploads per key-value entry. + type: boolean + title: Key Value Field type: object - x-speakeasy-name-override: SearchCohortUsersResponse - c1.api.role_mining_management.v1.TriggerAnalysisRequest: - description: The TriggerAnalysisRequest message. - title: Trigger Analysis Request + x-speakeasy-name-override: KeyValueField + c1.api.integration.connector.v1.OAuth2Field: + description: The OAuth2Field message. + title: O Auth 2 Field type: object - x-speakeasy-name-override: TriggerAnalysisRequest - c1.api.role_mining_management.v1.TriggerAnalysisResponse: - description: The TriggerAnalysisResponse message. + x-speakeasy-name-override: OAuth2Field + c1.api.integration.connector.v1.OptionsField: + description: The OptionsField message. + title: Options Field + type: object + x-speakeasy-name-override: OptionsField + c1.api.integration.connector.v1.RandomStringField: + description: The RandomStringField message. properties: - runId: - description: The ID of the newly created analysis run. - readOnly: false - type: string - title: Trigger Analysis Response + length: + description: The length field. + format: int32 + type: integer + title: Random String Field type: object - x-speakeasy-name-override: TriggerAnalysisResponse - c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest: - description: The TriggerCustomAnalysisRequest message. + x-speakeasy-name-override: RandomStringField + c1.api.integration.connector.v1.ReadOnlyField: + description: The ReadOnlyField message. + title: Read Only Field + type: object + x-speakeasy-name-override: ReadOnlyField + c1.api.integration.connector.v1.RotatableSecretField: + description: The RotatableSecretField message. + title: Rotatable Secret Field + type: object + x-speakeasy-name-override: RotatableSecretField + c1.api.integration.connector.v1.SelectField: + description: The SelectField message. properties: - profileFilters: - description: The profileFilters field. + items: + description: list of items that are selected from items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' - nullable: true - readOnly: false - type: array - title: Trigger Custom Analysis Request + $ref: '#/components/schemas/c1.api.integration.connector.v1.SelectField.Item' + type: + - array + - "null" + title: Select Field type: object - x-speakeasy-name-override: TriggerCustomAnalysisRequest - c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse: - description: The TriggerCustomAnalysisResponse message. + x-speakeasy-name-override: ConnectorSelectField + c1.api.integration.connector.v1.SelectField.Item: + description: The Item message. properties: - id: - description: The id field. - readOnly: false + displayName: + description: The displayName field. type: string - title: Trigger Custom Analysis Response + value: + description: The value field. + type: string + title: Item type: object - x-speakeasy-name-override: TriggerCustomAnalysisResponse - c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest: - description: The UpdateRoleMiningConfigRequest message. + x-speakeasy-name-override: Item + c1.api.integration.connector.v1.StringField: + description: The StringField message. properties: - cohortHints: - description: Hints that guide the analysis to prioritize specific user attributes and values when forming cohorts. - items: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintInput' - nullable: true - readOnly: false - type: array - maxSuggestions: - description: Maximum number of suggestions the analysis should produce per run. - format: int32 - readOnly: false - type: integer - minCohortSize: - description: Minimum number of users a cohort must contain to generate a suggestion. - format: int32 - readOnly: false - type: integer - title: Update Role Mining Config Request + secret: + description: If secret, value is write-only in UI and a password-type form is used. + type: boolean + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: String Field type: object - x-speakeasy-name-override: UpdateRoleMiningConfigRequest - c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse: - description: The UpdateRoleMiningConfigResponse message. + x-speakeasy-name-override: StringField + c1.api.integration.connector.v1.StringListField: + description: The StringListField message. properties: - config: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' - title: Update Role Mining Config Response + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: String List Field type: object - x-speakeasy-name-override: UpdateRoleMiningConfigResponse - c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput: - description: The UpdateSuggestionStateRequest message. + x-speakeasy-name-override: StringListField + c1.api.integration.connector.v1.StringMapField: + description: The StringMapField message. properties: - createdCatalogId: - description: The ID of the access profile created from this suggestion, set when accepting. - readOnly: false - type: string - state: - description: The new state to transition the suggestion to. - enum: - - SUGGESTION_STATE_UNSPECIFIED - - SUGGESTION_STATE_NEW - - SUGGESTION_STATE_DISMISSED - - SUGGESTION_STATE_ACCEPTED - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: Update Suggestion State Request + optional: + description: The optional field. + type: boolean + title: String Map Field type: object - x-speakeasy-name-override: UpdateSuggestionStateRequest - c1.api.role_mining_management.v1.UpdateSuggestionStateResponse: - description: The UpdateSuggestionStateResponse message. + x-speakeasy-name-override: StringMapField + c1.api.integration.connector.v1.TextField: + description: The TextField message. properties: - suggestion: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' - title: Update Suggestion State Response + secret: + description: The secret field. + type: boolean + valueValidator: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + title: Text Field type: object - x-speakeasy-name-override: UpdateSuggestionStateResponse - c1.api.search.v1.FacetCategory: - description: | - The FacetCategory indicates a grouping of facets by type. For example, facets "OnePassword" and "Okta" would group under an "Apps" category. - - This message contains a oneof named item. Only a single field of the following list may be set at a time: - - value - - range + x-speakeasy-name-override: ConnectorTextField + c1.api.local_directory.v1.LocalDirectoryConfig: + description: |- + LocalDirectoryConfig is the public representation of a C1-managed local + directory configuration. The underlying directory infrastructure is provided + by the linked App (identified by app_id). properties: + allowSelfRegistration: + description: Whether unauthenticated users may self-register in this directory. + type: boolean + appId: + description: app_id is the identifier for this config and its linked App. Read-only after creation. + readOnly: true + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + defaultProfileTypeId: + description: Optional FK to a ProfileType applied to new users created via this directory. + type: string displayName: - description: The display name of the category. - readOnly: false + description: The displayName field. type: string - iconUrl: - description: An icon for the category. - readOnly: false + invitationTtl: + format: duration + type: + - string + - "null" + isDefault: + description: |- + Whether this is the default local directory for the tenant. + At most one config per tenant may be the default. + type: boolean + onboardingFlowId: + description: Optional FK to an onboarding flow applied by default when inviting users. type: string - param: - description: The param that is being set when checking a facet in this category. - readOnly: false + organizationId: + description: Optional FK to a ThirdPartyOrganization. Empty means standalone (no vendor linkage). type: string - range: - $ref: '#/components/schemas/c1.api.search.v1.FacetRangeItem' - value: - $ref: '#/components/schemas/c1.api.search.v1.FacetValueItem' - title: Facet Category + selfRegistrationDomains: + description: |- + Email domain allowlist for self-registration. Empty allows any domain when + allow_self_registration is true. + items: + type: string + type: + - array + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Local Directory Config type: object - x-speakeasy-name-override: FacetCategory - c1.api.search.v1.FacetRange: - description: The FacetRange message. + x-speakeasy-name-override: LocalDirectoryConfig + c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest: + description: The LocalDirectoryConfigServiceCreateRequest message. properties: - count: - description: The count of items in the range. - format: int64 - readOnly: false + allowSelfRegistration: + description: The allowSelfRegistration field. + type: boolean + appId: + description: FK to the existing App that will back this local directory. type: string - displayName: - description: The display name of the range. - readOnly: false + defaultProfileTypeId: + description: The defaultProfileTypeId field. type: string - from: - description: The starting value of the range. - format: int64 - readOnly: false + displayName: + description: The displayName field. type: string - iconUrl: - description: The icon of the range. - readOnly: false + invitationTtl: + format: duration + type: + - string + - "null" + isDefault: + description: Whether this should be the default local directory for the tenant. + type: boolean + onboardingFlowId: + description: The onboardingFlowId field. type: string - to: - description: The ending value of the range. - format: int64 - readOnly: false + organizationId: + description: Optional FK to a ThirdPartyOrganization. type: string - title: Facet Range + selfRegistrationDomains: + description: The selfRegistrationDomains field. + items: + type: string + type: + - array + - "null" + required: + - appId + - displayName + title: Local Directory Config Service Create Request type: object - x-speakeasy-name-override: FacetRange - c1.api.search.v1.FacetRangeItem: - description: The FacetRangeItem message. - nullable: true + x-speakeasy-name-override: LocalDirectoryConfigServiceCreateRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse: + description: The LocalDirectoryConfigServiceCreateResponse message. properties: - ranges: - description: An array of facet ranges. - items: - $ref: '#/components/schemas/c1.api.search.v1.FacetRange' - nullable: true - readOnly: false - type: array - title: Facet Range Item + localDirectoryConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - type: "null" + title: Local Directory Config Service Create Response type: object - x-speakeasy-name-override: FacetRangeItem - c1.api.search.v1.FacetValue: - description: A FacetValue message contains count and value of the facet entry. + x-speakeasy-name-override: LocalDirectoryConfigServiceCreateResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput: + description: The LocalDirectoryConfigServiceDeleteRequest message. + title: Local Directory Config Service Delete Request + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse: + description: The LocalDirectoryConfigServiceDeleteResponse message. + title: Local Directory Config Service Delete Response + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceDeleteResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse: + description: The LocalDirectoryConfigServiceGetResponse message. properties: - count: - description: The count of the values in this facet. - format: int64 - readOnly: false - type: string - displayName: - description: The name of this facet. - readOnly: false - type: string - iconUrl: - description: The icon for this facet. - readOnly: false - type: string - value: - description: The value of this facet. - readOnly: false - type: string - title: Facet Value + localDirectoryConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - type: "null" + title: Local Directory Config Service Get Response type: object - x-speakeasy-name-override: FacetValue - c1.api.search.v1.FacetValueItem: - description: The FacetValueItem message. - nullable: true + x-speakeasy-name-override: LocalDirectoryConfigServiceGetResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse: + description: The LocalDirectoryConfigServiceListResponse message. properties: - values: - description: An array of facet values. + list: + description: The list field. items: - $ref: '#/components/schemas/c1.api.search.v1.FacetValue' - nullable: true - readOnly: false - type: array - title: Facet Value Item + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Local Directory Config Service List Response type: object - x-speakeasy-name-override: FacetValueItem - c1.api.search.v1.Facets: - description: Indicates one value of a facet. + x-speakeasy-name-override: LocalDirectoryConfigServiceListResponse + c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput: + description: The LocalDirectoryConfigServiceUpdateRequest message. properties: - count: - description: The count of items in this facet. - format: int64 - readOnly: false - type: string - facets: - description: The facet being referenced. - items: - $ref: '#/components/schemas/c1.api.search.v1.FacetCategory' - nullable: true - readOnly: false - type: array - title: Facets + localDirectoryConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - type: "null" + updateMask: + type: + - string + - "null" + title: Local Directory Config Service Update Request type: object - x-speakeasy-name-override: Facets - c1.api.secrets.v1.PaperSecret: - description: |- - PaperSecret is the API view of a secret (combines Vault + PaperVault fields). - The vault_id is the primary identifier (Vault.id). + x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateRequest + c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse: + description: The LocalDirectoryConfigServiceUpdateResponse message. properties: - allowedEmails: - description: The allowedEmails field. - items: - type: string - nullable: true - readOnly: false - type: array - allowedUserIds: - description: Access control - items: - type: string - nullable: true - readOnly: false - type: array - contentDeleted: - description: The contentDeleted field. - readOnly: false - type: boolean - contentExpiresAt: + localDirectoryConfig: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfig' + - type: "null" + title: Local Directory Config Service Update Response + type: object + x-speakeasy-name-override: LocalDirectoryConfigServiceUpdateResponse + c1.api.local_directory.v1.LocalUserInvitation: + description: LocalUserInvitation is the public representation of a per-directory user invitation. + properties: + acceptedAt: format: date-time - readOnly: false - type: string - contentReady: - description: Whether content has been set (text uploaded or file uploaded) - readOnly: false - type: boolean - contentType: - description: The contentType field. - readOnly: false - type: string + readOnly: true + type: + - string + - "null" createdAt: format: date-time readOnly: true + type: + - string + - "null" + createdUserId: + description: Set when status = ACCEPTED. FK to the created User. Read-only. + readOnly: true type: string - creatorUserId: - description: Creator - readOnly: false - type: string - currentViews: - description: The currentViews field. - format: uint32 - readOnly: false - type: integer - deletedAt: - format: date-time + directoryAppId: + description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. Read-only after creation. readOnly: true type: string displayName: - description: From Vault - readOnly: false + description: Display name to pre-populate on the new user account. type: string - fileSize: - description: File metadata - format: int64 - readOnly: false + email: + description: Email address the invitation was sent to. type: string - filename: - description: 'For FILE secrets: original filename (sanitized)' - readOnly: false + expiresAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: Unique KSUID identifier. Read-only. + readOnly: true type: string - inputFormat: - description: The inputFormat field. - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - readOnly: false + initialRoleIds: + description: Optional initial role IDs to assign to the user upon acceptance. + items: + type: string + type: + - array + - "null" + invitedByUserId: + description: FK to the User who created the invitation. Read-only. + readOnly: true type: string - x-speakeasy-unknown-values: allow - maxViews: - description: View tracking - format: uint32 - readOnly: false - type: integer - secretType: - description: The secretType field. - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false + jobId: + description: Optional FK to a ThirdPartyJob. type: string - x-speakeasy-unknown-values: allow - shareCode: - description: Human-friendly share code (XXXX-XXXX-XXXX) for shareable URLs - readOnly: false + onboardingFlowId: + description: Optional onboarding flow override for this invitation. type: string - shareUrl: - description: URL to share with recipients (populated when content_ready is true) - readOnly: false + purpose: + description: Human-readable reason this user was invited. type: string - sharingMode: - description: From PaperVault - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL - readOnly: false + sponsorUserId: + description: Optional sponsor User override for this invitation. type: string - x-speakeasy-unknown-values: allow status: - description: Computed status + description: Current lifecycle status. Read-only. enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED - readOnly: false + - LOCAL_INVITATION_STATUS_UNSPECIFIED + - LOCAL_INVITATION_STATUS_PENDING + - LOCAL_INVITATION_STATUS_ACCEPTED + - LOCAL_INVITATION_STATUS_REVOKED + - LOCAL_INVITATION_STATUS_EXPIRED + readOnly: true type: string x-speakeasy-unknown-values: allow updatedAt: format: date-time readOnly: true + type: + - string + - "null" + title: Local User Invitation + type: object + x-speakeasy-name-override: LocalUserInvitation + c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput: + description: The LocalUserInvitationServiceCreateRequest message. + properties: + displayName: + description: The displayName field. type: string - vaultId: - description: Vault.id - primary identifier for the secret - readOnly: false + email: + description: The email field. type: string - title: Paper Secret + initialRoleIds: + description: Optional initial role IDs to assign upon acceptance. + items: + type: string + type: + - array + - "null" + jobId: + description: Optional FK to a ThirdPartyJob. + type: string + onboardingFlowId: + description: Optional onboarding flow override. + type: string + purpose: + description: Human-readable reason for the invitation. + type: string + sponsorUserId: + description: Optional sponsor User override. + type: string + required: + - email + - displayName + title: Local User Invitation Service Create Request type: object - x-speakeasy-name-override: PaperSecret - c1.api.secrets.v1.PaperSecretAdminServiceGetResponse: - description: The PaperSecretAdminServiceGetResponse message. + x-speakeasy-name-override: LocalUserInvitationServiceCreateRequest + c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse: + description: The LocalUserInvitationServiceCreateResponse message. properties: - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - title: Paper Secret Admin Service Get Response + invitation: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + - type: "null" + title: Local User Invitation Service Create Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceGetResponse - c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput: - description: The PaperSecretAdminServiceRevokeRequest message. - title: Paper Secret Admin Service Revoke Request + x-speakeasy-name-override: LocalUserInvitationServiceCreateResponse + c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse: + description: The LocalUserInvitationServiceGetResponse message. + properties: + invitation: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + - type: "null" + title: Local User Invitation Service Get Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceRevokeRequest - c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse: - description: The PaperSecretAdminServiceRevokeResponse message. + x-speakeasy-name-override: LocalUserInvitationServiceGetResponse + c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput: + description: The LocalUserInvitationServiceRevokeRequest message. + title: Local User Invitation Service Revoke Request + type: object + x-speakeasy-name-override: LocalUserInvitationServiceRevokeRequest + c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse: + description: The LocalUserInvitationServiceRevokeResponse message. properties: - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - title: Paper Secret Admin Service Revoke Response + invitation: + oneOf: + - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + - type: "null" + title: Local User Invitation Service Revoke Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceRevokeResponse - c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest: - description: The PaperSecretAdminServiceSearchAuditEventsRequest message. + x-speakeasy-name-override: LocalUserInvitationServiceRevokeResponse + c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest: + description: The LocalUserInvitationServiceSearchRequest message. properties: - actorEmail: - description: Filter by external email (partial match via full-text search) - readOnly: false - type: string - actorUserId: - description: Filter by C1 user ID (internal users) - readOnly: false - type: string - clientIp: - description: Filter by client IP (exact match) - readOnly: false + directoryAppId: + description: The directoryAppId field. type: string pageSize: description: The pageSize field. format: int32 - readOnly: false type: integer pageToken: description: The pageToken field. - readOnly: false type: string - vaultId: - description: Filter by specific vault - readOnly: false + statusFilter: + description: Optional filter by invitation status. + enum: + - LOCAL_INVITATION_STATUS_UNSPECIFIED + - LOCAL_INVITATION_STATUS_PENDING + - LOCAL_INVITATION_STATUS_ACCEPTED + - LOCAL_INVITATION_STATUS_REVOKED + - LOCAL_INVITATION_STATUS_EXPIRED type: string - title: Paper Secret Admin Service Search Audit Events Request + x-speakeasy-unknown-values: allow + title: Local User Invitation Service Search Request type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsRequest - c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse: - description: The PaperSecretAdminServiceSearchAuditEventsResponse message. + x-speakeasy-name-override: LocalUserInvitationServiceSearchRequest + c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse: + description: The LocalUserInvitationServiceSearchResponse message. properties: list: - description: |- - List contains OCSF events directly as JSON structs. - Follows the same pattern as SystemLogServiceListEventsResponse. + description: The list field. items: - additionalProperties: true - readOnly: false - type: object - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitation' + type: + - array + - "null" nextPageToken: description: The nextPageToken field. - readOnly: false type: string - title: Paper Secret Admin Service Search Audit Events Response + title: Local User Invitation Service Search Response type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsResponse - c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest: - description: Admin search request - can filter by any user's secrets. + x-speakeasy-name-override: LocalUserInvitationServiceSearchResponse + c1.api.policy.v1.Accept: + description: This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. properties: - createdAfter: - format: date-time - readOnly: false - type: string - createdBefore: - format: date-time - readOnly: false - type: string - creatorUserIds: - description: Filter by creator user ID (admin can see all users' secrets) - items: - type: string - nullable: true - readOnly: false - type: array - includeDeleted: - description: Include deleted secrets - readOnly: false - type: boolean - pageSize: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + acceptMessage: + description: An optional message to include in the comments when a task is automatically accepted. type: string - query: - description: Fuzzy search by display name - readOnly: false + title: Accept + type: object + x-speakeasy-name-override: Accept + c1.api.policy.v1.AcceptInstance: + description: |- + This policy step indicates that a ticket should have an approved outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + The instance is just a marker for it being copied into an active policy. + properties: + acceptMessage: + description: An optional message to include in the comments when a task is automatically accepted. type: string - secretType: - description: Filter by secret type (optional) + title: Accept Instance + type: object + x-speakeasy-name-override: AcceptInstance + c1.api.policy.v1.Action: + description: | + The Action message. + + This message contains a oneof named target. Only a single field of the following list may be set at a time: + - automation + - batonResourceAction + - clientIdApproval + properties: + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomation' + - type: "null" + batonResourceAction: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceAction' + - type: "null" + clientIdApproval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApproval' + - type: "null" + title: Action + type: object + x-speakeasy-name-override: Action + c1.api.policy.v1.ActionInstance: + description: | + The ActionInstance message. + + This message contains a oneof named target_instance. Only a single field of the following list may be set at a time: + - automation + - batonResourceActionInstance + - clientIdApprovalInstance + + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - success + - denied + - error + - cancelled + properties: + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Action' + - type: "null" + automation: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetAutomationInstance' + - type: "null" + batonResourceActionInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetBatonResourceActionInstance' + - type: "null" + cancelled: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeCancelled' + - type: "null" + clientIdApprovalInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionTargetClientIdApprovalInstance' + - type: "null" + denied: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeDenied' + - type: "null" + error: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeError' + - type: "null" + state: + description: The current state of the action execution. enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false + - ACTION_INSTANCE_STATE_UNSPECIFIED + - ACTION_INSTANCE_STATE_INIT + - ACTION_INSTANCE_STATE_RUNNING + - ACTION_INSTANCE_STATE_DONE + - ACTION_INSTANCE_STATE_ERROR type: string x-speakeasy-unknown-values: allow - sharingMode: - description: Filter by sharing mode (optional) - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL - readOnly: false + success: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionOutcomeSuccess' + - type: "null" + title: Action Instance + type: object + x-speakeasy-name-override: ActionInstance + c1.api.policy.v1.ActionOutcomeCancelled: + description: The ActionOutcomeCancelled message. + properties: + outcomeTime: + format: date-time + type: + - string + - "null" + title: Action Outcome Cancelled + type: object + x-speakeasy-name-override: ActionOutcomeCancelled + c1.api.policy.v1.ActionOutcomeDenied: + description: The ActionOutcomeDenied message. + properties: + outcomeTime: + format: date-time + type: + - string + - "null" + title: Action Outcome Denied + type: object + x-speakeasy-name-override: ActionOutcomeDenied + c1.api.policy.v1.ActionOutcomeError: + description: The ActionOutcomeError message. + properties: + errorCode: + description: The errorCode field. type: string - x-speakeasy-unknown-values: allow - sortBy: - description: Sort order - enum: - - SEARCH_SORT_BY_UNSPECIFIED - - SEARCH_SORT_BY_CREATED_DESC - - SEARCH_SORT_BY_CREATED_ASC - - SEARCH_SORT_BY_EXPIRES_ASC - - SEARCH_SORT_BY_NAME_ASC - readOnly: false + errorMessage: + description: The errorMessage field. type: string - x-speakeasy-unknown-values: allow - statuses: - description: Filter by status (optional) - items: - enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Paper Secret Admin Service Search Request + outcomeTime: + format: date-time + type: + - string + - "null" + title: Action Outcome Error type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchRequest - c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse: - description: The PaperSecretAdminServiceSearchResponse message. + x-speakeasy-name-override: ActionOutcomeError + c1.api.policy.v1.ActionOutcomeSuccess: + description: The ActionOutcomeSuccess message. properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Paper Secret Admin Service Search Response + outcomeTime: + format: date-time + type: + - string + - "null" + title: Action Outcome Success type: object - x-speakeasy-name-override: PaperSecretAdminServiceSearchResponse - c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest: - description: The PaperSecretServiceCreateExternalRequest message. + x-speakeasy-name-override: ActionOutcomeSuccess + c1.api.policy.v1.ActionProvision: + description: This provision step indicates that account lifecycle action should be called to provision this entitlement. properties: - allowedEmails: - description: |- - External email addresses allowed to view this secret (1 to 64). - Recipients authenticate via email magic link or Google OAuth. - items: - type: string - nullable: true - readOnly: false - type: array - contentType: - description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' - readOnly: false + actionName: + description: The actionName field. + type: string + appId: + description: The appId field. + type: string + connectorId: + description: The connectorId field. type: string displayName: - description: |- - Optional cleartext label visible to the creator in "My Secrets" view. - Not encrypted — do not put sensitive data here. - readOnly: false + description: The displayName field. type: string - expiresIn: - format: duration - readOnly: false + title: Action Provision + type: object + x-speakeasy-name-override: ActionProvision + c1.api.policy.v1.ActionTargetAutomation: + description: ActionTargetAutomation targets automation templates for policy actions. + properties: + automationTemplateId: + description: The automationTemplateId field. type: string - fileSize: - description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' - format: int64 - readOnly: false + title: Action Target Automation + type: object + x-speakeasy-name-override: ActionTargetAutomation + c1.api.policy.v1.ActionTargetAutomationInstance: + description: The ActionTargetAutomationInstance message. + properties: + automationExecutionId: + description: The automationExecutionId field. type: string - filename: - description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' - readOnly: false + title: Action Target Automation Instance + type: object + x-speakeasy-name-override: ActionTargetAutomationInstance + c1.api.policy.v1.ActionTargetBatonResourceAction: + description: ActionTargetResource targets resource actions for policy actions. + properties: + batonResourceActionId: + description: The batonResourceActionId field. type: string - inputFormat: - description: |- - For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). - Used by the viewer UI for syntax highlighting. Does not affect encryption. + title: Action Target Baton Resource Action + type: object + x-speakeasy-name-override: ActionTargetBatonResourceAction + c1.api.policy.v1.ActionTargetBatonResourceActionInstance: + description: The ActionTargetBatonResourceActionInstance message. + properties: + batonActionInvocationId: + description: The batonActionInvocationId field. + type: string + title: Action Target Baton Resource Action Instance + type: object + x-speakeasy-name-override: ActionTargetBatonResourceActionInstance + c1.api.policy.v1.ActionTargetClientIdApproval: + description: |- + ActionTargetClientIdApproval targets administrator review of an external + OAuth client registration (CIMD or DCR) for policy actions. + title: Action Target Client Id Approval + type: object + x-speakeasy-name-override: ActionTargetClientIdApproval + c1.api.policy.v1.ActionTargetClientIdApprovalInstance: + description: |- + ActionTargetClientIdApprovalInstance carries the registration key of the + external OAuth client that is being reviewed. + properties: + clientIdUrl: + description: The clientIdUrl field. + type: string + title: Action Target Client Id Approval Instance + type: object + x-speakeasy-name-override: ActionTargetClientIdApprovalInstance + c1.api.policy.v1.AgentApproval: + description: The agent to assign the task to. + properties: + agentFailureAction: + description: The action to take if the agent fails to approve, deny, or reassign the task. enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - readOnly: false + - APPROVAL_AGENT_FAILURE_ACTION_UNSPECIFIED + - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_USERS + - APPROVAL_AGENT_FAILURE_ACTION_REASSIGN_TO_SUPER_ADMINS + - APPROVAL_AGENT_FAILURE_ACTION_SKIP_POLICY_STEP type: string x-speakeasy-unknown-values: allow - maxViews: - description: Maximum number of views before the secret is burned (0 = unlimited). - format: uint32 - readOnly: false - type: integer - secretType: - description: |- - Secret type: TEXT or FILE. - TEXT secrets use SetTextContent to upload encrypted content (max 64KB). - FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). + agentMode: + description: The mode of the agent, full control, change policy only, or comment only. enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false + - APPROVAL_AGENT_MODE_UNSPECIFIED + - APPROVAL_AGENT_MODE_FULL_CONTROL + - APPROVAL_AGENT_MODE_CHANGE_POLICY_ONLY + - APPROVAL_AGENT_MODE_COMMENT_ONLY type: string x-speakeasy-unknown-values: allow - title: Paper Secret Service Create External Request - type: object - x-speakeasy-name-override: PaperSecretServiceCreateExternalRequest - c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest: - description: The PaperSecretServiceCreateInternalRequest message. - properties: - allowedUserIds: - description: C1 User IDs allowed to view this secret (1 to 128). - items: - type: string - nullable: true - readOnly: false - type: array - contentType: - description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' - readOnly: false - type: string - displayName: + agentUserId: + deprecated: true description: |- - Optional cleartext label visible to the creator in "My Secrets" view. - Not encrypted — do not put sensitive data here. - readOnly: false + Deprecated: agent steps are evaluated by the system; no agent user is + selected. Retained so pre-migration policies still validate. type: string - expiresIn: - format: duration - readOnly: false - type: string - fileSize: - description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' - format: int64 - readOnly: false + instructions: + description: Instructions for the agent. type: string - filename: - description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' - readOnly: false - type: string - inputFormat: - description: |- - For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). - Used by the viewer UI for syntax highlighting. Does not affect encryption. - enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - readOnly: false + policyIds: + description: The allow list of policy IDs to re-route the task to. + items: + type: string + type: + - array + - "null" + reassignToUserIds: + description: The users to reassign the task to if the agent failure action is reassign to users. + items: + type: string + type: + - array + - "null" + title: Agent Approval + type: object + x-speakeasy-name-override: AgentApproval + c1.api.policy.v1.AppEntitlementReference: + description: This object references an app entitlement's ID and AppID. + properties: + appEntitlementId: + description: The ID of the Entitlement. type: string - x-speakeasy-unknown-values: allow - maxViews: - description: Maximum number of views before the secret is burned (0 = unlimited). - format: uint32 - readOnly: false - type: integer - secretType: - description: |- - Secret type: TEXT or FILE. - TEXT secrets use SetTextContent to upload encrypted content (max 64KB). - FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false + appId: + description: The ID of the App this entitlement belongs to. type: string - x-speakeasy-unknown-values: allow - title: Paper Secret Service Create Internal Request + title: App Entitlement Reference type: object - x-speakeasy-name-override: PaperSecretServiceCreateInternalRequest - c1.api.secrets.v1.PaperSecretServiceCreateResponse: - description: The PaperSecretServiceCreateResponse message. + x-speakeasy-name-override: AppEntitlementReference + c1.api.policy.v1.AppGroupApproval: + description: The AppGroupApproval object provides the configuration for setting a group as the approvers of an approval policy step. properties: - ageRecipient: - description: |- - Age X25519 recipient public key (format: "age1...") for client-side encryption. - All content MUST be encrypted to this recipient using the Age encryption format - before calling SetTextContent or uploading to upload_url. - See: https://age-encryption.org - readOnly: false - type: string - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - uploadUrl: - description: |- - For FILE secrets: capability URL for uploading the Age-encrypted file. - Send an HTTP PUT request with the Age-encrypted file bytes as the body - and Content-Type: application/octet-stream. The payload MUST begin with - the Age header "age-encryption.org/v1\n". Maximum file size: 1GB. - Empty for TEXT secrets. - readOnly: false + allowSelfApproval: + description: Configuration to allow self approval if the target user is a member of the group during this step. + type: boolean + appGroupId: + description: The ID of the group specified for approval. type: string - vaultId: - description: Vault ID - primary identifier for this secret. - readOnly: false + appId: + description: The ID of the app that contains the group specified for approval. type: string - title: Paper Secret Service Create Response + fallback: + description: Configuration to allow a fallback if the group is empty. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the group is empty. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the group is empty. + items: + type: string + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: App Group Approval type: object - x-speakeasy-name-override: PaperSecretServiceCreateResponse - c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput: - description: The PaperSecretServiceGetContentRequest message. + x-speakeasy-name-override: AppGroupApproval + c1.api.policy.v1.AppOwnerApproval: + description: App owner approval provides the configuration for an approval step when the app owner is the target. properties: - readerRecipient: + allowSelfApproval: + description: Configuration that allows a user to self approve if they are an app owner during this approval step. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: App Owner Approval + type: object + x-speakeasy-name-override: AppOwnerApproval + c1.api.policy.v1.AppOwnerProvisioner: + description: AppOwnerProvisioner resolves to app owners. + properties: + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + fallbackUserIds: + description: Fallback user IDs if no app owners are found. + items: + type: string + type: + - array + - "null" + title: App Owner Provisioner + type: object + x-speakeasy-name-override: AppOwnerProvisioner + c1.api.policy.v1.Approval: + description: | + The Approval message. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + - manager + - appOwners + - group + - self + - entitlementOwners + - expression + - webhook + - resourceOwners + - agent + properties: + agent: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AgentApproval' + - type: "null" + allowDelegation: + description: Whether ticket delegation is allowed for this step. + type: boolean + allowReassignment: + description: Configuration to allow reassignment by reviewers during this step. + type: boolean + allowedReassignees: + description: List of users for whom this step can be reassigned. + items: + type: string + type: + - array + - "null" + appOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerApproval' + - type: "null" + assigned: + description: A field indicating whether this step is assigned. + readOnly: true + type: boolean + entitlementOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerApproval' + - type: "null" + escalation: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation' + - type: "null" + escalationEnabled: + description: Whether escalation is enabled for this step. + type: boolean + expression: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionApproval' + - type: "null" + group: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AppGroupApproval' + - type: "null" + manager: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManagerApproval' + - type: "null" + requireApprovalReason: + description: Configuration to require a reason when approving this step. + type: boolean + requireDenialReason: + description: Configuration to require a reason when denying this step. + type: boolean + requireReassignmentReason: + description: Configuration to require a reason when reassigning this step. + type: boolean + requiresStepUpProviderId: description: |- - Client's ephemeral Age recipient (age1...) for re-encryption - Server re-encrypts the content to this recipient - readOnly: false + The ID of a step-up authentication provider that will be required for approvals on this step. + If set, approvers must complete the step-up authentication flow before they can approve. type: string - title: Paper Secret Service Get Content Request + resourceOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ResourceOwnerApproval' + - type: "null" + self: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SelfApproval' + - type: "null" + users: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UserApproval' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WebhookApproval' + - type: "null" + title: Approval type: object - x-speakeasy-name-override: PaperSecretServiceGetContentRequest - c1.api.secrets.v1.PaperSecretServiceGetContentResponse: + x-speakeasy-name-override: Approval + c1.api.policy.v1.ApprovalInstance: description: | - The PaperSecretServiceGetContentResponse message. + The approval instance object describes the way a policy step should be approved as well as its outcomes and state. - This message contains a oneof named content. Only a single field of the following list may be set at a time: - - encryptedContent - - downloadUrl + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - approved + - denied + - reassigned + - restarted + - reassignedByError + - skipped properties: - createdAt: + approval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Approval' + - type: "null" + approved: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovedAction' + - type: "null" + assignedAt: format: date-time - readOnly: false - type: string - creatorUserId: - description: The creatorUserId field. - readOnly: false - type: string - downloadUrl: - description: |- - For file secrets: presigned S3 download URL (5 minute expiry) - File is still E2E encrypted - client must decrypt after download - This field is part of the `content` oneof. - See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. - nullable: true - readOnly: false - type: string - encryptedContent: - description: |- - For text secrets: Age-encrypted content (encrypted to reader's recipient) - This field is part of the `content` oneof. - See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. - format: base64 - nullable: true - readOnly: false - type: string - filename: - description: Original filename (file secrets only) - readOnly: false - type: string - inputFormat: - description: Input format hint for rendering (text secrets only) + readOnly: true + type: + - string + - "null" + denied: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.DeniedAction' + - type: "null" + escalationInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance' + - type: "null" + reassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' + - type: "null" + reassignedByError: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' + - type: "null" + restarted: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: The state of the approval instance enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - readOnly: false + - APPROVAL_INSTANCE_STATE_UNSPECIFIED + - APPROVAL_INSTANCE_STATE_INIT + - APPROVAL_INSTANCE_STATE_SENDING_NOTIFICATIONS + - APPROVAL_INSTANCE_STATE_WAITING + - APPROVAL_INSTANCE_STATE_DONE + readOnly: true type: string x-speakeasy-unknown-values: allow - secretType: - description: Secret metadata - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false + title: Approval Instance + type: object + x-speakeasy-name-override: ApprovalInstance + c1.api.policy.v1.ApprovedAction: + description: The approved action indicates that the approvalinstance had an outcome of approved. + properties: + approvedAt: + format: date-time + readOnly: true + type: + - string + - "null" + entitlements: + description: The entitlements that were approved. This will only ever be a list of one entitlement. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + readOnly: true + type: + - array + - "null" + stepUpTransactionId: + description: The ID of the step-up transaction that was used for this approval, if step-up was required. + readOnly: true type: string - x-speakeasy-unknown-values: allow - viewsRemaining: - description: Views remaining after this view (-1 = unlimited) - format: int32 - readOnly: false - type: integer - title: Paper Secret Service Get Content Response + userId: + description: The UserID that approved this step. + readOnly: true + type: string + title: Approved Action type: object - x-speakeasy-name-override: PaperSecretServiceGetContentResponse - c1.api.secrets.v1.PaperSecretServiceGetResponse: - description: The PaperSecretServiceGetResponse message. + x-speakeasy-name-override: ApprovedAction + c1.api.policy.v1.CancelledAction: + description: The outcome of a provision instance that is cancelled. properties: - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - title: Paper Secret Service Get Response + cancelledAt: + format: date-time + type: + - string + - "null" + cancelledByUserId: + description: The userID, usually the system, that cancells a provision instance. + type: string + title: Cancelled Action type: object - x-speakeasy-name-override: PaperSecretServiceGetResponse - c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput: - description: The PaperSecretServiceRevokeRequest message. - title: Paper Secret Service Revoke Request + x-speakeasy-name-override: CancelledAction + c1.api.policy.v1.CompletedAction: + description: The outcome of a provision instance that has been completed succesfully. + properties: + completedAt: + format: date-time + type: + - string + - "null" + entitlements: + description: The list of entitlements that were provisioned. This is leftover from an older design, and is only ever going to be a single entitlement. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + userId: + description: The UserID of who completed provisioning. For connector provisioning this is the system user id, for manual provisioning this is who clicked "provision complete" + type: string + title: Completed Action type: object - x-speakeasy-name-override: PaperSecretServiceRevokeRequest - c1.api.secrets.v1.PaperSecretServiceRevokeResponse: - description: The PaperSecretServiceRevokeResponse message. + x-speakeasy-name-override: CompletedAction + c1.api.policy.v1.ConnectorProvision: + description: | + Indicates that a connector should perform the provisioning. This object has no fields. + + This message contains a oneof named provision_type. Only a single field of the following list may be set at a time: + - defaultBehavior + - account + - deleteAccount properties: - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - title: Paper Secret Service Revoke Response + account: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.AccountProvision' + - type: "null" + defaultBehavior: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DefaultBehavior' + - type: "null" + deleteAccount: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DeleteAccount' + - type: "null" + title: Connector Provision type: object - x-speakeasy-name-override: PaperSecretServiceRevokeResponse - c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest: - description: |- - PaperSecretServiceSearchAuditEventsRequest searches audit events for a secret - owned by the calling user. Only the secret creator may query events. Results - are sanitized to include only time, event type, and actor information. + x-speakeasy-name-override: ConnectorProvision + c1.api.policy.v1.ConnectorProvision.AccountProvision: + description: | + The AccountProvision message. + + This message contains a oneof named storage_type. Only a single field of the following list may be set at a time: + - saveToVault + - doNotSave properties: - pageSize: - description: Maximum number of results per page (0 uses server default, max 100). - format: int32 - readOnly: false - type: integer - pageToken: - description: Pagination token from a previous response's next_page_token. - readOnly: false + config: + additionalProperties: true + type: + - object + - "null" + connectorId: + description: The connectorId field. type: string - vaultId: - description: Required. The vault ID of the secret whose audit events to retrieve. - readOnly: false + doNotSave: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.DoNotSave' + - type: "null" + saveToVault: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision.SaveToVault' + - type: "null" + schemaId: + description: The schemaId field. type: string - title: Paper Secret Service Search Audit Events Request + title: Account Provision type: object - x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsRequest - c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse: - description: |- - PaperSecretServiceSearchAuditEventsResponse contains a page of audit events - for the requested secret. + x-speakeasy-name-override: AccountProvision + c1.api.policy.v1.ConnectorProvision.DefaultBehavior: + description: The DefaultBehavior message. properties: - list: + connectorId: description: |- - Sanitized OCSF events containing only time, event type, and actor fields. - Sensitive fields such as IP addresses, messages, and raw payloads are removed. - items: - additionalProperties: true - readOnly: false - type: object - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page of results. Empty when no more pages exist. - readOnly: false + this checks if the entitlement is enabled by provisioning in a specific connector + this can happen automatically and doesn't need any extra info type: string - title: Paper Secret Service Search Audit Events Response + title: Default Behavior type: object - x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsResponse - c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest: - description: |- - SearchMySecrets request - for end users viewing their own secrets. - Automatically scoped to current user. + x-speakeasy-name-override: DefaultBehavior + c1.api.policy.v1.ConnectorProvision.DeleteAccount: + description: The DeleteAccount message. properties: - pageSize: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false - type: string - query: - description: Fuzzy search by display name - readOnly: false - type: string - secretType: - description: Filter by secret type (optional) - enum: - - SECRET_TYPE_UNSPECIFIED - - SECRET_TYPE_TEXT - - SECRET_TYPE_FILE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - sharingMode: - description: Filter by sharing mode (optional) - enum: - - PAPER_VAULT_SHARING_MODE_UNSPECIFIED - - PAPER_VAULT_SHARING_MODE_INTERNAL - - PAPER_VAULT_SHARING_MODE_EXTERNAL - readOnly: false - type: string - x-speakeasy-unknown-values: allow - sortBy: - description: Sort order - enum: - - SEARCH_SORT_BY_UNSPECIFIED - - SEARCH_SORT_BY_CREATED_DESC - - SEARCH_SORT_BY_CREATED_ASC - - SEARCH_SORT_BY_EXPIRES_ASC - - SEARCH_SORT_BY_NAME_ASC - readOnly: false + connectorId: + description: The connectorId field. type: string - x-speakeasy-unknown-values: allow - statuses: - description: Filter by status (optional) - items: - enum: - - SECRET_STATUS_UNSPECIFIED - - SECRET_STATUS_ACTIVE - - SECRET_STATUS_EXPIRED - - SECRET_STATUS_BURNED - - SECRET_STATUS_REVOKED - - SECRET_STATUS_DATA_DELETED - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Paper Secret Service Search My Secrets Request + title: Delete Account type: object - x-speakeasy-name-override: PaperSecretServiceSearchMySecretsRequest - c1.api.secrets.v1.PaperSecretServiceSearchResponse: - description: Search response for user's own secrets + x-speakeasy-name-override: DeleteAccount + c1.api.policy.v1.ConnectorProvision.DoNotSave: + description: The DoNotSave message. + title: Do Not Save + type: object + x-speakeasy-name-override: DoNotSave + c1.api.policy.v1.ConnectorProvision.SaveToVault: + description: The SaveToVault message. properties: - list: - description: The list field. + vaultIds: + description: The vaultIds field. items: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Paper Secret Service Search Response + type: string + type: + - array + - "null" + title: Save To Vault type: object - x-speakeasy-name-override: PaperSecretServiceSearchResponse - c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput: - description: The PaperSecretServiceSetTextContentRequest message. + x-speakeasy-name-override: SaveToVault + c1.api.policy.v1.CreatePolicyRequest: + description: The CreatePolicyRequest message is used to create a new policy. properties: - encryptedContent: + annotations: + additionalProperties: + type: string description: |- - Age-encrypted content bytes. The plaintext MUST be encrypted using the Age - encryption format to the age_recipient returned by CreateInternal/CreateExternal. - The resulting bytes begin with "age-encryption.org/v1\n" followed by the - encrypted payload. Maximum 64KB after encryption — for larger content, create - a FILE secret and use the upload_url instead. - format: base64 - readOnly: false + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + description: + description: The description of the new policy. type: string - inputFormat: + displayName: + description: The display name of the new policy. + type: string + policySteps: + additionalProperties: + $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' description: |- - Input format hint for the viewer UI when the secret is decrypted. - Does not affect encryption — this is metadata only. + Step sequences for this policy. The map must include a baseline entry keyed + by the lowercased policy type (e.g., "grant"). Additional entries with + opaque keys can be added for conditional routing via the rules array. + type: object + policyType: + description: The type of policy to create (grant, revoke, or certify). enum: - - SECRET_INPUT_FORMAT_UNSPECIFIED - - SECRET_INPUT_FORMAT_PLAINTEXT - - SECRET_INPUT_FORMAT_JSON - - SECRET_INPUT_FORMAT_YAML - - SECRET_INPUT_FORMAT_KEY_VALUE - readOnly: false + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION type: string x-speakeasy-unknown-values: allow - title: Paper Secret Service Set Text Content Request + postActions: + description: Ordered actions to execute after the policy completes processing. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' + type: + - array + - "null" + reassignTasksToDelegates: + deprecated: true + description: This field is no longer used. Configure delegate reassignment in the policy step instead. + type: boolean + rules: + description: Conditional routing rules. See the Policy message for details on evaluation order. + items: + $ref: '#/components/schemas/c1.api.policy.v1.Rule' + type: + - array + - "null" + required: + - displayName + title: Create Policy Request type: object - x-speakeasy-name-override: PaperSecretServiceSetTextContentRequest - c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse: - description: The PaperSecretServiceSetTextContentResponse message. + x-speakeasy-entity: Policy + x-speakeasy-name-override: CreatePolicyRequest + c1.api.policy.v1.CreatePolicyResponse: + description: The CreatePolicyResponse message contains the created policy object. properties: - secret: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' - title: Paper Secret Service Set Text Content Response + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + title: Create Policy Response type: object - x-speakeasy-name-override: PaperSecretServiceSetTextContentResponse - c1.api.service_principal.v1.ServicePrincipal: - description: ServicePrincipal represents a tenant-managed non-human identity. + x-speakeasy-name-override: CreatePolicyResponse + c1.api.policy.v1.DelegatedProvision: + description: This provision step indicates that we should delegate provisioning to the configuration of another app entitlement. This app entitlement does not have to be one from the same app, but MUST be configured as a proxy binding leading into this entitlement. properties: - createdAt: - format: date-time - readOnly: true - type: string - displayName: - description: The display name of the service principal. - readOnly: false + appId: + description: The AppID of the entitlement to delegate provisioning to. type: string - id: - description: The unique user ID of the service principal. - readOnly: true + entitlementId: + description: The ID of the entitlement we are delegating provisioning to. type: string - updatedAt: + implicit: + description: If true, a binding will be automatically created from the entitlement of the parent app. + type: boolean + title: Delegated Provision + type: object + x-speakeasy-name-override: DelegatedProvision + c1.api.policy.v1.DeletePolicyRequestInput: + description: The DeletePolicyRequest message contains the ID of the policy to delete. It uses URL value for input. + title: Delete Policy Request + type: object + x-speakeasy-entity: Policy + x-speakeasy-name-override: DeletePolicyRequest + c1.api.policy.v1.DeletePolicyResponse: + description: Empty response with a status code indicating success. + title: Delete Policy Response + type: object + x-speakeasy-name-override: DeletePolicyResponse + c1.api.policy.v1.DeniedAction: + description: The denied action indicates that the c1.api.policy.v1.ApprovalInstance had an outcome of denied. + properties: + deniedAt: format: date-time readOnly: true + type: + - string + - "null" + userId: + description: The UserID that denied this step. + readOnly: true type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: Service Principal + title: Denied Action type: object - x-speakeasy-name-override: ServicePrincipal - c1.api.service_principal.v1.ServicePrincipalBinding: - description: |- - ServicePrincipalBinding is one row in the binding store, naming a - subject's link to a single service principal. + x-speakeasy-name-override: DeniedAction + c1.api.policy.v1.EditorValidateRequest: + description: The EditorValidateRequest message. properties: - createdAt: - format: date-time - readOnly: false + text: + description: The text field. type: string - servicePrincipalId: - description: The servicePrincipalId field. - readOnly: false + title: Editor Validate Request + type: object + x-speakeasy-name-override: PolicyEditorValidateRequest + c1.api.policy.v1.EditorValidateResponse: + description: The EditorValidateResponse message. + properties: + markers: + description: The markers field. + items: + $ref: '#/components/schemas/c1.api.editor.v1.EditorMarker' + type: + - array + - "null" + title: Editor Validate Response + type: object + x-speakeasy-name-override: PolicyEditorValidateResponse + c1.api.policy.v1.EntitlementOwnerApproval: + description: The entitlement owner approval allows configuration of the approval step when the target approvers are the entitlement owners. + properties: + allowSelfApproval: + description: Configuration to allow self approval if the target user is an entitlement owner during this step. + type: boolean + fallback: + description: Configuration to allow a fallback if the entitlement owner cannot be identified. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the entitlement owner cannot be identified. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the entitlement owner cannot be identified. + items: + type: string + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: Entitlement Owner Approval + type: object + x-speakeasy-name-override: EntitlementOwnerApproval + c1.api.policy.v1.EntitlementOwnerProvisioner: + description: EntitlementOwnerProvisioner resolves to entitlement owners. + properties: + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + fallbackUserIds: + description: Fallback user IDs if no entitlement owners are found. + items: + type: string + type: + - array + - "null" + title: Entitlement Owner Provisioner + type: object + x-speakeasy-name-override: EntitlementOwnerProvisioner + c1.api.policy.v1.ErroredAction: + description: The outcome of a provision instance that has errored. + properties: + description: + description: The description of a provision instance that has errored. type: string - updatedAt: - format: date-time - readOnly: false + errorCode: + description: The error code of a provision instance that has errored. This is only PEC-1 for now, but more will be added in the future. type: string - title: Service Principal Binding + erroredAt: + format: date-time + type: + - string + - "null" + title: Errored Action type: object - x-speakeasy-name-override: ServicePrincipalBinding - c1.api.service_principal.v1.ServicePrincipalBindingSubject: + x-speakeasy-name-override: ErroredAction + c1.api.policy.v1.Escalation: description: | - ServicePrincipalBindingSubject identifies the entity that is bound to a - service principal. Open-ended oneof so future subject kinds (workflows, - connectors, etc.) can be added without changing the RPC shape. + The Escalation message. - This message contains a oneof named kind. Only a single field of the following list may be set at a time: - - functionId + This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: + - replacePolicy + - reassignToApprovers + - cancelTicket + - skipStep properties: - functionId: - description: |- - Function ID. The function authenticates outbound c1-api calls as - user: instead of function:. - This field is part of the `kind` oneof. - See the documentation for `c1.api.service_principal.v1.ServicePrincipalBindingSubject` for more details. - nullable: true - readOnly: false + cancelTicket: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.CancelTicket' + - type: "null" + escalationComment: + description: The escalationComment field. type: string - title: Service Principal Binding Subject + expiration: + description: The expiration field. + format: int64 + type: string + reassignToApprovers: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReassignToApprovers' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.ReplacePolicy' + - type: "null" + skipStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Escalation.SkipStep' + - type: "null" + title: Escalation type: object - x-speakeasy-name-override: ServicePrincipalBindingSubject - c1.api.service_principal.v1.ServicePrincipalCredential: - description: ServicePrincipalCredential represents a client credential for a service principal. + x-speakeasy-name-override: Escalation + c1.api.policy.v1.Escalation.CancelTicket: + description: The CancelTicket message. + title: Cancel Ticket + type: object + x-speakeasy-name-override: CancelTicket + c1.api.policy.v1.Escalation.ReassignToApprovers: + description: The ReassignToApprovers message. properties: - allowSourceCidrs: - description: CIDR restrictions for this credential. + approverIds: + description: The approverIds field. items: type: string - nullable: true - readOnly: true - type: array - clientId: - description: 'The full client ID in format: ${cutename}@${tenant}.${installation}/spc' - readOnly: true - type: string - createdAt: - format: date-time - readOnly: true + type: + - array + - "null" + title: Reassign To Approvers + type: object + x-speakeasy-name-override: ReassignToApprovers + c1.api.policy.v1.Escalation.ReplacePolicy: + description: The ReplacePolicy message. + properties: + policyId: + description: The policyId field. type: string - displayName: - description: The display name of the credential. - readOnly: false + title: Replace Policy + type: object + x-speakeasy-name-override: ReplacePolicy + c1.api.policy.v1.Escalation.SkipStep: + description: The SkipStep message. + title: Skip Step + type: object + x-speakeasy-name-override: SkipStep + c1.api.policy.v1.EscalationInstance: + description: | + The EscalationInstance message. + + This message contains a oneof named escalation_policy. Only a single field of the following list may be set at a time: + - replacePolicy + - reassignToApprovers + - cancelTicket + - skipStep + properties: + alreadyEscalated: + description: The alreadyEscalated field. + type: boolean + cancelTicket: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.CancelTicket' + - type: "null" + escalationComment: + description: The escalationComment field. type: string expiresAt: format: date-time - readOnly: true - type: string - id: - description: The unique ID of the credential (cutename format). - readOnly: true - type: string - lastUsedAt: - format: date-time - readOnly: true - type: string - requireDpop: - description: Whether DPoP proof-of-possession is required for this credential. - readOnly: true - type: boolean - scopedRoleIds: - description: Scoped role IDs for this credential (intersection with SP roles at token issuance). + type: + - string + - "null" + reassignToApprovers: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReassignToApprovers' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.ReplacePolicy' + - type: "null" + skipStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EscalationInstance.SkipStep' + - type: "null" + title: Escalation Instance + type: object + x-speakeasy-name-override: EscalationInstance + c1.api.policy.v1.EscalationInstance.CancelTicket: + description: The CancelTicket message. + title: Cancel Ticket + type: object + x-speakeasy-name-override: EscalationInstanceCancelTicket + c1.api.policy.v1.EscalationInstance.ReassignToApprovers: + description: The ReassignToApprovers message. + properties: + approverIds: + description: The approverIds field. items: type: string - nullable: true - readOnly: true - type: array - servicePrincipalId: - description: The service principal user ID this credential belongs to. - readOnly: true - type: string - title: Service Principal Credential + type: + - array + - "null" + title: Reassign To Approvers type: object - x-speakeasy-name-override: ServicePrincipalCredential - c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest: - description: The ServicePrincipalServiceAddBindingRequest message. + x-speakeasy-name-override: EscalationInstanceReassignToApprovers + c1.api.policy.v1.EscalationInstance.ReplacePolicy: + description: The ReplacePolicy message. properties: - servicePrincipalId: - description: The servicePrincipalId field. - readOnly: false + policyId: + description: The policyId field. type: string - subject: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - title: Service Principal Service Add Binding Request + title: Replace Policy type: object - x-speakeasy-name-override: ServicePrincipalServiceAddBindingRequest - c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse: - description: The ServicePrincipalServiceAddBindingResponse message. - title: Service Principal Service Add Binding Response + x-speakeasy-name-override: EscalationInstanceReplacePolicy + c1.api.policy.v1.EscalationInstance.SkipStep: + description: The SkipStep message. + title: Skip Step type: object - x-speakeasy-name-override: ServicePrincipalServiceAddBindingResponse - c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput: - description: The ServicePrincipalServiceCreateCredentialRequest message. + x-speakeasy-name-override: EscalationInstanceSkipStep + c1.api.policy.v1.ExpressionApproval: + description: The ExpressionApproval message. properties: - allowSourceCidrs: - description: |- - A list of CIDRs to restrict this credential to. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + allowSelfApproval: + description: Configuration to allow self approval of if the user is specified and also the target of the ticket. + type: boolean + assignedUserIds: + description: The assignedUserIds field. items: type: string - nullable: true - readOnly: false - type: array - displayName: - description: The display name for the new credential. - readOnly: false - type: string - expires: - format: duration - readOnly: false - type: string - requireDpop: - description: If true, requires DPoP proof-of-possession for token exchange using this credential. - readOnly: false + readOnly: true + type: + - array + - "null" + expressions: + description: Array of dynamic expressions to determine the approvers. The first expression to return a non-empty list of users will be used. + items: + type: string + type: + - array + - "null" + fallback: + description: Configuration to allow a fallback if the expression does not return a valid list of users. type: boolean - scopedRoles: - description: The list of roles to restrict the credential to. + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the expression does not return a valid list of users. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if and the expression does not return a valid list of users. items: type: string - nullable: true - readOnly: false - type: array - title: Service Principal Service Create Credential Request + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + title: Expression Approval type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse: - description: The ServicePrincipalServiceCreateCredentialResponse message. + x-speakeasy-name-override: ExpressionApproval + c1.api.policy.v1.ExpressionProvisioner: + description: ExpressionProvisioner evaluates CEL expressions to determine provisioners. properties: - clientSecret: - description: The client secret. Shown exactly once at creation -- cannot be retrieved again. - readOnly: false - type: string - credential: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - title: Service Principal Service Create Credential Response + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + expressions: + description: The CEL expressions to evaluate. + items: + type: string + type: + - array + - "null" + fallbackUserIds: + description: Fallback user IDs if expression evaluation yields no users. + items: + type: string + type: + - array + - "null" + title: Expression Provisioner type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest: - description: The ServicePrincipalServiceCreateRequest message. + x-speakeasy-name-override: ExpressionProvisioner + c1.api.policy.v1.ExternalTicketProvision: + description: This provision step indicates that we should check an external ticket to provision this entitlement properties: - displayName: - description: The display name for the new service principal. - readOnly: false + appId: + description: The appId field. type: string - title: Service Principal Service Create Request + connectorId: + description: The connectorId field. + type: string + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. + type: string + instructions: + description: This field indicates a text body of instructions for the provisioner to indicate. + type: string + title: External Ticket Provision type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateRequest - c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse: - description: The ServicePrincipalServiceCreateResponse message. + x-speakeasy-name-override: ExternalTicketProvision + c1.api.policy.v1.Form: + description: The Form message. properties: - servicePrincipal: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - title: Service Principal Service Create Response + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + title: Form type: object - x-speakeasy-name-override: ServicePrincipalServiceCreateResponse - c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest: - description: The ServicePrincipalServiceDeleteBindingRequest message. + x-speakeasy-name-override: Form + c1.api.policy.v1.FormCompletedAction: + description: The FormCompletedAction message. properties: - servicePrincipalId: - description: The servicePrincipalId field. - readOnly: false + completedAt: + format: date-time + type: + - string + - "null" + userId: + description: The userId field. type: string - subject: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - title: Service Principal Service Delete Binding Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingRequest - c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse: - description: The ServicePrincipalServiceDeleteBindingResponse message. - title: Service Principal Service Delete Binding Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingResponse - c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput: - description: The ServicePrincipalServiceDeleteRequest message. - title: Service Principal Service Delete Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteRequest - c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse: - description: The ServicePrincipalServiceDeleteResponse message. - title: Service Principal Service Delete Response + title: Form Completed Action type: object - x-speakeasy-name-override: ServicePrincipalServiceDeleteResponse - c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse: - description: The ServicePrincipalServiceGetCredentialResponse message. + x-speakeasy-name-override: FormCompletedAction + c1.api.policy.v1.FormInstance: + description: | + The FormInstance message. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - completed + - restarted + - reassigned + - skipped properties: - credential: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - title: Service Principal Service Get Credential Response + completed: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.FormCompletedAction' + - type: "null" + data: + additionalProperties: true + type: + - object + - "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + reassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedAction' + - type: "null" + restarted: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RestartAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: The state field. + enum: + - FORM_INSTANCE_STATE_UNSPECIFIED + - FORM_INSTANCE_STATE_WAITING + - FORM_INSTANCE_STATE_DONE + type: string + x-speakeasy-unknown-values: allow + title: Form Instance type: object - x-speakeasy-name-override: ServicePrincipalServiceGetCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceGetResponse: - description: The ServicePrincipalServiceGetResponse message. + x-speakeasy-name-override: FormInstance + c1.api.policy.v1.GetPolicyResponse: + description: The GetPolicyResponse message contains the policy object. properties: - servicePrincipal: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - title: Service Principal Service Get Response + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + title: Get Policy Response type: object - x-speakeasy-name-override: ServicePrincipalServiceGetResponse - c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest: - description: The ServicePrincipalServiceListBindingsRequest message. + x-speakeasy-name-override: GetPolicyResponse + c1.api.policy.v1.GroupProvisioner: + description: GroupProvisioner resolves to members of a specific group. properties: - pageSize: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + allowReassignment: + description: Whether the provisioner can reassign the task. + type: boolean + appGroupId: + description: The app group ID (entitlement ID). type: string - subject: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' - title: Service Principal Service List Bindings Request + appId: + description: The app ID containing the group. + type: string + fallbackUserIds: + description: Fallback user IDs if no group members are found. + items: + type: string + type: + - array + - "null" + title: Group Provisioner type: object - x-speakeasy-name-override: ServicePrincipalServiceListBindingsRequest - c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse: - description: The ServicePrincipalServiceListBindingsResponse message. - properties: - bindings: - description: |- - Active bindings held by the subject in this page. Empty when the - subject is unbound. Order is unspecified. - items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBinding' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Service Principal Service List Bindings Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceListBindingsResponse - c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse: - description: The ServicePrincipalServiceListCredentialsResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Service Principal Service List Credentials Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceListCredentialsResponse - c1.api.service_principal.v1.ServicePrincipalServiceListResponse: - description: The ServicePrincipalServiceListResponse message. + x-speakeasy-name-override: GroupProvisioner + c1.api.policy.v1.ListPolicyResponse: + description: The ListPolicyResponse message. properties: list: - description: The list field. + description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.policy.v1.Policy' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false - type: string - title: Service Principal Service List Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceListResponse - c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput: - description: The ServicePrincipalServiceRevokeCredentialRequest message. - title: Service Principal Service Revoke Credential Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse: - description: The ServicePrincipalServiceRevokeCredentialResponse message. - title: Service Principal Service Revoke Credential Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput: - description: The ServicePrincipalServiceUpdateCredentialRequest message. - properties: - credential: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - updateMask: - nullable: true - readOnly: false - type: string - title: Service Principal Service Update Credential Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialRequest - c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse: - description: The ServicePrincipalServiceUpdateCredentialResponse message. - properties: - credential: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' - title: Service Principal Service Update Credential Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialResponse - c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput: - description: The ServicePrincipalServiceUpdateRequest message. - properties: - servicePrincipal: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - updateMask: - nullable: true - readOnly: false - type: string - title: Service Principal Service Update Request - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateRequest - c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse: - description: The ServicePrincipalServiceUpdateResponse message. - properties: - servicePrincipal: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' - title: Service Principal Service Update Response - type: object - x-speakeasy-name-override: ServicePrincipalServiceUpdateResponse - c1.api.settings.v1.AWSExternalID: - description: AWSExternalID contains the tenant's external ID for AWS IAM role trust policies. - properties: - externalId: - description: The external ID value to include in the AWS IAM role trust policy condition. - readOnly: false - type: string - title: Aws External Id - type: object - x-speakeasy-entity: AWS_EXTERNAL_ID - x-speakeasy-name-override: AWSExternalID - c1.api.settings.v1.AWSSESProviderConfig: - description: AWSSESProviderConfig configures sending via a customer's AWS SES account. - nullable: true - properties: - configurationSetName: - description: Optional SES configuration set name for tracking/metrics. - readOnly: false - type: string - region: - description: AWS region where SES identities are verified (e.g., "us-east-1"). - readOnly: false - type: string - roleArn: - description: |- - IAM role ARN for sts:AssumeRole. The trust policy should require the - tenant's AWS External ID (GET /api/v1/settings/aws-external-id). - readOnly: false + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Awsses Provider Config + title: List Policy Response type: object - x-speakeasy-name-override: AWSSESProviderConfig - c1.api.settings.v1.AccessProvisionedPreference: - description: The AccessProvisionedPreference message. + x-speakeasy-name-override: ListPolicyResponse + c1.api.policy.v1.ManagerApproval: + description: The manager approval object provides configuration options for approval when the target of the approval is the manager of the user in the task. properties: - enabled: - description: The enabled field. - readOnly: false + allowSelfApproval: + description: Configuration to allow self approval if the target user is their own manager. This may occur if a service account has an identity user and manager specified as the same person. type: boolean - locked: - description: The locked field. - readOnly: false + assignedUserIds: + description: The array of users determined to be the manager during processing time. + items: + type: string + readOnly: true + type: + - array + - "null" + fallback: + description: Configuration to allow a fallback if no manager is found. type: boolean - title: Access Provisioned Preference - type: object - x-speakeasy-name-override: AccessProvisionedPreference - c1.api.settings.v1.ApprovalNeededPreference: - description: The ApprovalNeededPreference message. - properties: - enabled: - description: The enabled field. - readOnly: false + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and no manager is found. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and no manager is found. + items: + type: string + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. type: boolean - locked: - description: The locked field. - readOnly: false + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. type: boolean - title: Approval Needed Preference - type: object - x-speakeasy-name-override: ApprovalNeededPreference - c1.api.settings.v1.C1BuiltInProviderConfig: - description: |- - C1BuiltInProviderConfig selects the ConductorOne built-in email provider. - Emails are sent from no-reply@conductorone.com via the platform SendGrid account. - Only supports sending to C1 users — external email addresses are not supported. - No configuration fields required. - nullable: true - title: C 1 Built In Provider Config + title: Manager Approval type: object - x-speakeasy-name-override: C1BuiltInProviderConfig - c1.api.settings.v1.CIDRRestriction: - description: CIDRRestriction defines an IP-based access restriction with an enable toggle and a list of allowed CIDRs. + x-speakeasy-name-override: ManagerApproval + c1.api.policy.v1.ManagerProvisioner: + description: ManagerProvisioner resolves to the user's manager. properties: - enabled: - description: Whether this CIDR restriction is enforced. - readOnly: false + allowReassignment: + description: Whether the provisioner can reassign the task. type: boolean - sourceCidr: - description: |- - The list of CIDR ranges that are allowed when the restriction is enabled. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + fallbackUserIds: + description: Fallback user IDs if no manager is found. items: type: string - nullable: true - readOnly: false - type: array - title: Cidr Restriction - type: object - x-speakeasy-name-override: CIDRRestriction - c1.api.settings.v1.ChannelSettings: - description: ChannelSettings groups notification preferences for all supported channels. - properties: - email: - $ref: '#/components/schemas/c1.api.settings.v1.EmailChannelSettings' - slack: - $ref: '#/components/schemas/c1.api.settings.v1.SlackChannelSettings' - teams: - $ref: '#/components/schemas/c1.api.settings.v1.MSTeamsChannelSettings' - title: Channel Settings - type: object - x-speakeasy-name-override: ChannelSettings - c1.api.settings.v1.CommentOnRequestPreference: - description: The CommentOnRequestPreference message. - properties: - enabled: - description: The enabled field. - readOnly: false - type: boolean - locked: - description: The locked field. - readOnly: false - type: boolean - title: Comment On Request Preference + type: + - array + - "null" + title: Manager Provisioner type: object - x-speakeasy-name-override: CommentOnRequestPreference - c1.api.settings.v1.CompletionPreference: - description: The CompletionPreference message. + x-speakeasy-name-override: ManagerProvisioner + c1.api.policy.v1.ManualProvision: + description: Manual provisioning indicates that a human must intervene for the provisioning of this step. properties: - enabled: - description: The enabled field. - readOnly: false - type: boolean - locked: - description: The locked field. - readOnly: false - type: boolean - title: Completion Preference + assignee: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionerAssignment' + - type: "null" + instructions: + description: This field indicates a text body of instructions for the provisioner to indicate. + type: string + userIds: + description: |- + An array of users that are required to provision during this step. + Deprecated: Use assignee field instead for dynamic provisioner assignment. + items: + type: string + type: + - array + - "null" + title: Manual Provision type: object - x-speakeasy-name-override: CompletionPreference - c1.api.settings.v1.ConnectorIssuesPreference: - description: The ConnectorIssuesPreference message. + x-speakeasy-name-override: ManualProvision + c1.api.policy.v1.MultiStep: + description: MultiStep indicates that this provision step has multiple steps to process. properties: - enabled: - description: The enabled field. - readOnly: false - type: boolean - locked: - description: The locked field. - readOnly: false - type: boolean - title: Connector Issues Preference + provisionSteps: + description: The array of provision steps to process. + items: + $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + type: + - array + - "null" + title: Multi Step type: object - x-speakeasy-name-override: ConnectorIssuesPreference - c1.api.settings.v1.Contacts: - description: Contacts represents the contact configuration for an organization. + x-speakeasy-name-override: MultiStep + c1.api.policy.v1.Policy: + description: |- + A policy defines a workflow (sequence of steps) that runs when processing + access requests, reviews, or revocations. Policies support conditional + routing: different conditions can trigger different step sequences, with a + baseline fallback. properties: - billingEmails: - description: Email addresses of billing contacts for this organization. - items: + annotations: + additionalProperties: type: string - nullable: true - readOnly: false - type: array + description: |- + Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256 + chars; URL-safe ASCII. Keys starting with `c1/` are reserved. + + Updates have PATCH semantics: keys absent from the request are + preserved; an empty value deletes the key. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() createdAt: format: date-time readOnly: true - type: string - operationsEmails: - description: Email addresses of operations contacts for this organization. - items: - type: string - nullable: true - readOnly: false - type: array - securityEmails: - description: Email addresses of security contacts for this organization. - items: - type: string - nullable: true - readOnly: false - type: array - updatedAt: + type: + - string + - "null" + deletedAt: format: date-time readOnly: true + type: + - string + - "null" + description: + description: The description of the Policy. type: string - title: Contacts - type: object - x-speakeasy-name-override: Contacts - c1.api.settings.v1.DigestPreference: - description: DigestPreference controls whether summary digest notifications are sent and how often. - properties: - dayOfWeek: - description: The day of the week to send weekly digests. - enum: - - WEEKDAY_UNSPECIFIED - - WEEKDAY_MONDAY - - WEEKDAY_TUESDAY - - WEEKDAY_WEDNESDAY - - WEEKDAY_THURSDAY - - WEEKDAY_FRIDAY - - WEEKDAY_SATURDAY - - WEEKDAY_SUNDAY - readOnly: false + displayName: + description: The display name of the Policy. type: string - x-speakeasy-unknown-values: allow - enabled: - description: Whether digest notifications are enabled. - readOnly: false - type: boolean - frequency: - description: How often digest notifications are sent. + id: + description: The ID of the Policy. + readOnly: true + type: string + policySteps: + additionalProperties: + $ref: '#/components/schemas/c1.api.policy.v1.PolicySteps' + description: |- + A map from string keys to step sequences. One entry is always the baseline, + keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify"). + Additional entries have opaque keys (UUIDs) and are referenced by the rules + array for conditional routing. If no conditional rules are configured, only + the baseline entry exists. + type: object + policyType: + description: |- + The type of this policy (grant, revoke, or certify). The lowercased type + name (e.g., "grant") is also the key for the baseline entry in policy_steps. enum: - - DIGEST_FREQUENCY_UNSPECIFIED - - DIGEST_FREQUENCY_DAILY - - DIGEST_FREQUENCY_WEEKLY - readOnly: false + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION type: string x-speakeasy-unknown-values: allow - locked: - description: Whether this preference is locked by org-level settings, preventing users from overriding it. - readOnly: false + postActions: + description: Ordered actions to execute after the policy completes processing. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyPostActions' + type: + - array + - "null" + reassignTasksToDelegates: + deprecated: true + description: This field is no longer used. Configure delegate reassignment in the policy step instead. type: boolean - title: Digest Preference - type: object - x-speakeasy-name-override: DigestPreference - c1.api.settings.v1.EmailChannelSettings: - description: The EmailChannelSettings message. - properties: - accessProvisioned: - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - approvalNeeded: - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - commentOnRequest: - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - completion: - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - connectorIssues: - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - digest: - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - enabled: - description: The enabled field. - readOnly: false + rules: + description: |- + Ordered conditional routing rules. Evaluated top-to-bottom; the first + matching rule selects a step sequence from policy_steps. If no rule matches + (or if this array is empty), the baseline entry in policy_steps is used. + items: + $ref: '#/components/schemas/c1.api.policy.v1.Rule' + type: + - array + - "null" + systemBuiltin: + description: Whether this policy is a builtin system policy. Builtin system policies cannot be edited. + readOnly: true type: boolean - expiringAccess: - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - provisioningRequest: - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - reviews: - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - taskReminders: - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' - title: Email Channel Settings + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Policy type: object - x-speakeasy-name-override: EmailChannelSettings - c1.api.settings.v1.ExpiringAccessPreference: - description: The ExpiringAccessPreference message. + x-speakeasy-entity: Policy + x-speakeasy-name-override: Policy + c1.api.policy.v1.PolicyInstance: + description: A policy instance is an object that contains a reference to the policy it was created from, the currently executing step, the next steps, and the history of previously completed steps. properties: - enabled: - description: The enabled field. - readOnly: false - type: boolean - locked: - description: The locked field. - readOnly: false - type: boolean - title: Expiring Access Preference + current: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' + - type: "null" + history: + description: An array of steps that were previously processed by the ticket with their outcomes set, in order. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStepInstance' + readOnly: true + type: + - array + - "null" + next: + description: An array of steps that will be processed by the ticket, in order. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + readOnly: true + type: + - array + - "null" + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + title: Policy Instance type: object - x-speakeasy-name-override: ExpiringAccessPreference - c1.api.settings.v1.GetAWSExternalIDResponse: - description: The GetAWSExternalIDResponse message. + x-speakeasy-name-override: PolicyInstance + c1.api.policy.v1.PolicyPostActions: + description: | + Actions to execute after a policy finishes processing. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - certifyRemediateImmediately properties: - awsExternalId: - $ref: '#/components/schemas/c1.api.settings.v1.AWSExternalID' - title: Get Aws External Id Response + certifyRemediateImmediately: + description: |- + Only valid on certify policies. When true, any revocations resulting from + the certification are applied immediately when the campaign task closes. + This field is part of the `action` oneof. + See the documentation for `c1.api.policy.v1.PolicyPostActions` for more details. + type: + - boolean + - "null" + title: Policy Post Actions type: object - x-speakeasy-name-override: GetAWSExternalIDResponse - c1.api.settings.v1.GetContactsResponse: - description: The GetContactsResponse message. + x-speakeasy-name-override: PolicyPostActions + c1.api.policy.v1.PolicyRef: + description: The PolicyRef message. properties: - contacts: - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' - title: Get Contacts Response + id: + description: The id field. + type: string + title: Policy Ref type: object - x-speakeasy-name-override: GetContactsResponse - c1.api.settings.v1.GetEmailCapabilitiesResponse: - description: The GetEmailCapabilitiesResponse message. + x-speakeasy-name-override: PolicyRef + c1.api.policy.v1.PolicyStep: + description: | + A single step in a policy workflow. Exactly one step type is set. + + This message contains a oneof named step. Only a single field of the following list may be set at a time: + - approval + - provision + - accept + - reject + - wait + - form + - action properties: - externalEmailSupported: - description: |- - True when external email addresses (outside C1 users) can be used as - recipients in automation email steps. False when only the C1 built-in - provider is configured (C1 users only). - readOnly: false - type: boolean - title: Get Email Capabilities Response + accept: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Accept' + - type: "null" + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Action' + - type: "null" + approval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Approval' + - type: "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Form' + - type: "null" + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Provision' + - type: "null" + reject: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Reject' + - type: "null" + wait: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Wait' + - type: "null" + title: Policy Step type: object - x-speakeasy-name-override: GetEmailCapabilitiesResponse - c1.api.settings.v1.GetOnboardingSettingsResponse: - description: The GetOnboardingSettingsResponse message. + x-speakeasy-name-override: PolicyStep + c1.api.policy.v1.PolicyStepInstance: + description: | + The policy step instance includes a reference to an instance of a policy step that tracks state and has a unique ID. + + This message contains a oneof named instance. Only a single field of the following list may be set at a time: + - approval + - provision + - accept + - reject + - wait + - form + - action properties: - conversationId: - description: The identifier of the onboarding conversation thread, if one is in progress. - readOnly: false + accept: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AcceptInstance' + - type: "null" + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + approval: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' + - type: "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.FormInstance' + - type: "null" + id: + description: The ID of the PolicyStepInstance. This is required by many action submission endpoints to indicate what step you're approving. + readOnly: true type: string - intents: - description: The intents field. - items: - type: string - nullable: true - readOnly: false - type: array - orgContext: - $ref: '#/components/schemas/c1.api.settings.v1.OnboardingOrgContext' - status: - description: The current status of the tenant onboarding process. + policyGenerationId: + description: The policy generation id refers to the version of the policy that this step was created from. + type: string + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionInstance' + - type: "null" + reject: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.RejectInstance' + - type: "null" + state: + description: The state of the step, which is either active or done. enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED - readOnly: false + - POLICY_STEP_STATE_UNSPECIFIED + - POLICY_STEP_STATE_ACTIVE + - POLICY_STEP_STATE_DONE + readOnly: true type: string x-speakeasy-unknown-values: allow - title: Get Onboarding Settings Response - type: object - x-speakeasy-name-override: GetOnboardingSettingsResponse - c1.api.settings.v1.GetOrgNotificationSettingsResponse: - description: The GetOrgNotificationSettingsResponse message. - properties: - orgNotificationSettings: - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' - title: Get Org Notification Settings Response + wait: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance' + - type: "null" + title: Policy Step Instance type: object - x-speakeasy-name-override: GetOrgNotificationSettingsResponse - c1.api.settings.v1.GetSessionSettingsResponse: - description: The GetSessionSettingsResponse message. + x-speakeasy-name-override: PolicyStepInstance + c1.api.policy.v1.PolicySteps: + description: A named sequence of steps that execute in order within a policy. properties: - sessionSettings: - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - title: Get Session Settings Response - type: object - x-speakeasy-name-override: GetSessionSettingsResponse - c1.api.settings.v1.GetTenantEmailProviderResponse: - description: The GetTenantEmailProviderResponse message. - properties: - emailProvider: - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - title: Get Tenant Email Provider Response + steps: + description: |- + Ordered array of steps. Each step is a oneof -- exactly one step type is + set per entry. Steps execute sequentially. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + type: + - array + - "null" + title: Policy Steps type: object - x-speakeasy-name-override: GetTenantEmailProviderResponse - c1.api.settings.v1.GetUserNotificationSettingsResponse: - description: The GetUserNotificationSettingsResponse message. + x-speakeasy-name-override: PolicySteps + c1.api.policy.v1.Provision: + description: The provision step references a provision policy for this step. properties: - userNotificationSettings: - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' - title: Get User Notification Settings Response + assigned: + description: A field indicating whether this step is assigned. + type: boolean + provisionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionPolicy' + - type: "null" + provisionTarget: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ProvisionTarget' + - type: "null" + title: Provision type: object - x-speakeasy-name-override: GetUserNotificationSettingsResponse - c1.api.settings.v1.GoogleWorkspaceProviderConfig: - description: |- - GoogleWorkspaceProviderConfig configures sending via Google Workspace Gmail API - using domain-wide delegation with a service account. - Requires: customer Workspace super admin grants DWD to the service account's - OAuth client ID for the gmail.send scope. - nullable: true + x-speakeasy-name-override: Provision + c1.api.policy.v1.ProvisionInstance: + description: | + A provision instance describes the specific configuration of an executing provision policy step including actions taken and notification id. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - completed + - cancelled + - errored + - reassignedByError + - skipped properties: - delegatedUser: - description: |- - The Workspace user email to impersonate via domain-wide delegation. - Typically a dedicated sender like noreply@customer.com. - readOnly: false + batonActionInvocationId: + description: This indicates the account lifecycle action id for this step. type: string - serviceAccountJson: - description: |- - Service account JSON credentials. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing credentials". - readOnly: false + cancelled: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.CancelledAction' + - type: "null" + completed: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.CompletedAction' + - type: "null" + errored: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ErroredAction' + - type: "null" + externalTicketId: + description: This indicates the external ticket id for this step. type: string - title: Google Workspace Provider Config - type: object - x-speakeasy-name-override: GoogleWorkspaceProviderConfig - c1.api.settings.v1.ListOrgDomainsResponse: - description: The ListOrgDomainsResponse message. - properties: - list: - description: The list of verified domains. - items: - $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' - nullable: true - readOnly: false - type: array - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + externalTicketProvisionerConfigId: + description: This indicates the external ticket provisioner config id for this step. type: string - title: List Org Domains Response + notificationId: + description: This indicates the notification id for this step. + type: string + provision: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Provision' + - type: "null" + reassignedByError: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ReassignedByErrorAction' + - type: "null" + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + state: + description: This property indicates the current state of this step. + enum: + - PROVISION_INSTANCE_STATE_UNSPECIFIED + - PROVISION_INSTANCE_STATE_INIT + - PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET + - PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS + - PROVISION_INSTANCE_STATE_WAITING + - PROVISION_INSTANCE_STATE_WEBHOOK + - PROVISION_INSTANCE_STATE_WEBHOOK_WAITING + - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET + - PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING + - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS + - PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING + - PROVISION_INSTANCE_STATE_DONE + type: string + x-speakeasy-unknown-values: allow + webhookId: + description: This indicates the webhook id for this step. + type: string + webhookInstanceId: + description: This indicates the webhook instance id for this step. + type: string + title: Provision Instance type: object - x-speakeasy-name-override: ListOrgDomainsResponse - c1.api.settings.v1.MSTeamsChannelSettings: - description: The MSTeamsChannelSettings message. + x-speakeasy-name-override: ProvisionInstance + c1.api.policy.v1.ProvisionPolicy: + description: | + ProvisionPolicy is a oneOf that indicates how a provision step should be processed. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - connector + - manual + - delegated + - webhook + - multiStep + - externalTicket + - unconfigured + - action properties: - accessProvisioned: - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - approvalNeeded: - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - commentOnRequest: - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - completion: - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - connectorIssues: - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - digest: - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - enabled: - description: The enabled field. - readOnly: false - type: boolean - expiringAccess: - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - isConfigured: - description: The isConfigured field. - readOnly: false - type: boolean - provisioningRequest: - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - reviews: - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - taskReminders: - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' - title: Ms Teams Channel Settings + action: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionProvision' + - type: "null" + connector: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ConnectorProvision' + - type: "null" + delegated: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.DelegatedProvision' + - type: "null" + externalTicket: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExternalTicketProvision' + - type: "null" + manual: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManualProvision' + - type: "null" + multiStep: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.MultiStep' + - type: "null" + unconfigured: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UnconfiguredProvision' + - type: "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WebhookProvision' + - type: "null" + title: Provision Policy type: object - x-speakeasy-name-override: MSTeamsChannelSettings - c1.api.settings.v1.MicrosoftGraphProviderConfig: - description: |- - MicrosoftGraphProviderConfig configures sending via Microsoft Graph sendMail API. - Requires an Azure AD app registration with Mail.Send application permission (admin-consented). - nullable: true + x-speakeasy-name-override: ProvisionPolicy + c1.api.policy.v1.ProvisionTarget: + description: ProvisionTarget indicates the specific app, app entitlement, and if known, the app user and grant duration of this provision step properties: - azureTenantId: - description: Customer's Azure AD tenant ID (directory ID). - readOnly: false + appEntitlementId: + description: The app entitlement that should be provisioned. type: string - clientId: - description: App registration client ID with Mail.Send application permission. - readOnly: false + appId: + description: The app in which the entitlement should be provisioned type: string - clientSecret: - description: |- - Client secret. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing secret". - readOnly: false + appUserId: + description: The app user that should be provisioned. May be unset if the app user is unknown type: string - title: Microsoft Graph Provider Config + grantDuration: + format: duration + type: + - string + - "null" + title: Provision Target type: object - x-speakeasy-name-override: MicrosoftGraphProviderConfig - c1.api.settings.v1.OnboardingOrgContext: - description: The OnboardingOrgContext message. + x-speakeasy-name-override: ProvisionTarget + c1.api.policy.v1.ProvisionerAssignment: + description: | + ProvisionerAssignment defines how a provisioner is dynamically assigned. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + - appOwners + - group + - manager + - expression + - entitlementOwners properties: - industry: - description: The industry field. - readOnly: false + appOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.AppOwnerProvisioner' + - type: "null" + entitlementOwners: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.EntitlementOwnerProvisioner' + - type: "null" + expression: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ExpressionProvisioner' + - type: "null" + group: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.GroupProvisioner' + - type: "null" + manager: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ManagerProvisioner' + - type: "null" + users: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.UserProvisioner' + - type: "null" + title: Provisioner Assignment + type: object + x-speakeasy-name-override: ProvisionerAssignment + c1.api.policy.v1.ReassignedAction: + description: The ReassignedAction object describes the outcome of a policy step that has been reassigned. + properties: + newPolicyStepId: + description: The ID of the policy step that was created as a result of this reassignment. + readOnly: true type: string - organizationSize: - description: The organizationSize field. - readOnly: false + reassignedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The UserID of the person who reassigned this step. + readOnly: true type: string - title: Onboarding Org Context + title: Reassigned Action type: object - x-speakeasy-name-override: OnboardingOrgContext - c1.api.settings.v1.OrgDomain: - description: OrgDomain represents a verified email domain associated with the tenant. + x-speakeasy-name-override: ReassignedAction + c1.api.policy.v1.ReassignedByErrorAction: + description: The ReassignedByErrorAction object describes the outcome of a policy step that has been reassigned because it had an error provisioning. properties: - createdAt: - format: date-time + description: + description: The description of the error with more details on why this was reassigned. readOnly: true type: string - deletedAt: - format: date-time + errorCode: + description: Additional information about the error, like http status codes or error messages from SDKs. readOnly: true type: string - domain: - description: The verified domain name (e.g., "example.com"). - readOnly: false + errorUserId: + description: The UserID of the user who reassigned this due to an error. This will exclusively be the System's UserID. + readOnly: true type: string - id: - description: The unique identifier of the domain record. - readOnly: false + erroredAt: + format: date-time + readOnly: true + type: + - string + - "null" + newPolicyStepId: + description: The ID of the policy step that was created by this reassignment. + readOnly: true type: string - updatedAt: + reassignedAt: format: date-time readOnly: true + type: + - string + - "null" + title: Reassigned By Error Action + type: object + x-speakeasy-name-override: ReassignedByErrorAction + c1.api.policy.v1.Reject: + description: This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + properties: + rejectMessage: + description: An optional message to include in the comments when a task is automatically rejected. type: string - title: Org Domain + title: Reject type: object - x-speakeasy-name-override: OrgDomain - c1.api.settings.v1.OrgNotificationSettings: - description: OrgNotificationSettings contains organization-wide notification channel configurations and default preferences. + x-speakeasy-name-override: Reject + c1.api.policy.v1.RejectInstance: + description: |- + This policy step indicates that a ticket should have a denied outcome. This is a terminal approval state and is used to explicitly define the end of approval steps. + The instance is just a marker for it being copied into an active policy. properties: - channelSettings: - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - title: Org Notification Settings + rejectMessage: + description: An optional message to include in the comments when a task is automatically rejected. + type: string + title: Reject Instance type: object - x-speakeasy-name-override: OrgNotificationSettings - c1.api.settings.v1.ProvisioningRequestPreference: - description: The ProvisioningRequestPreference message. + x-speakeasy-name-override: RejectInstance + c1.api.policy.v1.ResourceOwnerApproval: + description: The resource owner approval allows configuration of the approval step when the target approvers are the resource owners. properties: - enabled: - description: The enabled field. - readOnly: false + allowSelfApproval: + description: Configuration to allow self approval if the target user is an resource owner during this step. type: boolean - locked: - description: The locked field. - readOnly: false + fallback: + description: Configuration to allow a fallback if the resource owner cannot be identified. type: boolean - title: Provisioning Request Preference - type: object - x-speakeasy-name-override: ProvisioningRequestPreference - c1.api.settings.v1.ReviewsPreference: - description: The ReviewsPreference message. - properties: - enabled: - description: The enabled field. - readOnly: false + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the resource owner cannot be identified. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the resource owner cannot be identified. + items: + type: string + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. type: boolean - locked: - description: The locked field. - readOnly: false + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. type: boolean - title: Reviews Preference + title: Resource Owner Approval type: object - x-speakeasy-name-override: ReviewsPreference - c1.api.settings.v1.SearchEmailAuditEventsRequest: - description: The SearchEmailAuditEventsRequest message. + x-speakeasy-name-override: ResourceOwnerApproval + c1.api.policy.v1.RestartAction: + description: The restart action describes the outcome of policy steps for when the task was restarted. This can be applied to multiple steps since restart skips all pending next steps. + properties: + oldPolicyStepId: + description: The step ID that was restarted. Potentially multiple "history" steps will reference this ID to indicate by what step they were restarted. + readOnly: true + type: string + restartedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The user that submitted the restart action. + readOnly: true + type: string + title: Restart Action + type: object + x-speakeasy-name-override: RestartAction + c1.api.policy.v1.Rule: + description: |- + A conditional routing rule that maps a CEL expression to a step sequence. + Rules are evaluated top-to-bottom; the first matching rule's policy_key + selects the step sequence from the policy's policy_steps map. If no rule + matches, the baseline entry is used. + properties: + condition: + description: |- + A CEL expression that is evaluated against the request context. If it + returns true, the step sequence identified by policy_key is used. + type: string + policyKey: + description: |- + A key into the policy's policy_steps map identifying which step sequence + to execute when this rule's condition matches. + type: string + title: Rule + type: object + x-speakeasy-name-override: Rule + c1.api.policy.v1.SearchPoliciesRequest: + description: Search Policies by a few properties. properties: + displayName: + description: Search for policies with a case insensitive match on the display name. + type: string + excludePolicyIds: + description: The policy IDs to exclude from the search. + items: + type: string + type: + - array + - "null" + includeDeleted: + description: The includeDeleted field. + type: boolean pageSize: - description: Maximum results per page (0 = server default, max 100). + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) format: int32 - readOnly: false type: integer pageToken: - description: Pagination token from previous response. - readOnly: false + description: The pageToken field. type: string - title: Search Email Audit Events Request + policyTypes: + description: The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. + items: + enum: + - POLICY_TYPE_UNSPECIFIED + - POLICY_TYPE_GRANT + - POLICY_TYPE_REVOKE + - POLICY_TYPE_CERTIFY + - POLICY_TYPE_ACCESS_REQUEST + - POLICY_TYPE_PROVISION + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + query: + description: Query the policies with a fuzzy search on display name and description. + type: string + refs: + description: The refs field. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyRef' + type: + - array + - "null" + title: Search Policies Request type: object - x-speakeasy-name-override: SearchEmailAuditEventsRequest - c1.api.settings.v1.SearchEmailAuditEventsResponse: - description: The SearchEmailAuditEventsResponse message. + x-speakeasy-name-override: SearchPoliciesRequest + c1.api.policy.v1.SearchPoliciesResponse: + description: The SearchPoliciesResponse message. properties: list: - description: OCSF EmailActivity events as Struct for frontend rendering. + description: The list field. items: - additionalProperties: true - readOnly: false - type: object - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.policy.v1.Policy' + type: + - array + - "null" nextPageToken: - description: Token for next page. Empty when no more pages. - readOnly: false + description: The nextPageToken field. type: string - title: Search Email Audit Events Response + title: Search Policies Response type: object - x-speakeasy-name-override: SearchEmailAuditEventsResponse - c1.api.settings.v1.SendGridProviderConfig: - description: SendGridProviderConfig configures sending via a customer's SendGrid account. - nullable: true + x-speakeasy-name-override: SearchPoliciesResponse + c1.api.policy.v1.SelfApproval: + description: The self approval object describes the configuration of a policy step that needs to be approved by the target of the request. properties: - apiKey: - description: |- - Customer's SendGrid API key. Write-only: accepted on create/update, never returned in Get. - Empty on update means "keep existing key". - readOnly: false - type: string - title: Send Grid Provider Config + assignedUserIds: + description: The array of users determined to be themselves during approval. This should only ever be one person, but is saved because it may change if the owner of an app user changes while the ticket is open. + items: + type: string + readOnly: true + type: + - array + - "null" + fallback: + description: Configuration to allow a fallback if the identity user of the target app user cannot be determined. + type: boolean + fallbackGroupIds: + description: Configuration to specify which groups to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. + items: + $ref: '#/components/schemas/c1.api.policy.v1.AppEntitlementReference' + type: + - array + - "null" + fallbackUserIds: + description: Configuration to specific which users to fallback to if fallback is enabled and the identity user of the target app user cannot be determined. + items: + type: string + type: + - array + - "null" + isGroupFallbackEnabled: + description: Configuration to enable fallback for group fallback. + type: boolean + title: Self Approval type: object - x-speakeasy-name-override: SendGridProviderConfig - c1.api.settings.v1.SessionSettings: - description: SessionSettings configures session security for the tenant, including timeouts and per-role IP restrictions. + x-speakeasy-name-override: SelfApproval + c1.api.policy.v1.SkippedAction: + description: The SkippedAction object describes the outcome of a policy step that has been skipped. properties: - clientIdApprovalRequestPolicyId: - description: Policy ID for REQUESTABLE mode approval routing. - readOnly: false - type: string - clientIdMetadataDocumentPolicy: - description: Policy for metadata document client_id URLs. - enum: - - CLIENT_ID_METADATA_DOCUMENT_POLICY_UNSPECIFIED - - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOW_ALL - - CLIENT_ID_METADATA_DOCUMENT_POLICY_REQUESTABLE - - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOWLIST_ONLY - readOnly: false + newPolicyStepId: + description: The ID of the policy step that was created as a result of this skipping. + readOnly: true type: string - x-speakeasy-unknown-values: allow - connectorSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - externalClientSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - externalClientsEnabled: - description: |- - Enable external client registration (OAuth 2.0 DCR) for MCP clients - like Claude Desktop, Cursor, and other AI assistants. - readOnly: false - type: boolean - maxSessionLength: - format: duration - readOnly: false + skippedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The UserID of the user who skipped this step. + readOnly: true type: string - pccAdminSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - pccUserSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - ssoAdminSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - ssoUserSource: - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' - title: Session Settings + title: Skipped Action type: object - x-speakeasy-name-override: SessionSettings - c1.api.settings.v1.SlackChannelSettings: - description: The SlackChannelSettings message. + x-speakeasy-name-override: SkippedAction + c1.api.policy.v1.TestAccountProvisionPolicyRequest: + description: TestAccountProvisionPolicyRequest is the request for testing an account provision policy. properties: - accessProvisioned: - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' - approvalNeeded: - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' - commentOnRequest: - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' - completion: - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' - connectorIssues: - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' - digest: - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' - enabled: - description: The enabled field. - readOnly: false - type: boolean - expiringAccess: - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' - isConfigured: - description: The isConfigured field. - readOnly: false - type: boolean - provisioningRequest: - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' - reviews: - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' - taskReminders: - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' - title: Slack Channel Settings + cel: + description: The CEL expression to evaluate for the account provision policy. + type: string + title: Test Account Provision Policy Request type: object - x-speakeasy-name-override: SlackChannelSettings - c1.api.settings.v1.TaskRemindersPreference: - description: The TaskRemindersPreference message. + x-speakeasy-name-override: TestAccountProvisionPolicyRequest + c1.api.policy.v1.TestAccountProvisionPolicyResponse: + description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. properties: - enabled: - description: The enabled field. - readOnly: false - type: boolean - locked: - description: The locked field. - readOnly: false - type: boolean - title: Task Reminders Preference - type: object - x-speakeasy-name-override: TaskRemindersPreference - c1.api.settings.v1.TenantEmailProvider: - description: | - TenantEmailProvider is the API representation of the tenant's email provider. - - This message contains a oneof named provider. Only a single field of the following list may be set at a time: - - c1Builtin - - awsSes - - sendgrid - - microsoftGraph - - googleWorkspace - properties: - awsSes: - $ref: '#/components/schemas/c1.api.settings.v1.AWSSESProviderConfig' - c1Builtin: - $ref: '#/components/schemas/c1.api.settings.v1.C1BuiltInProviderConfig' - createdAt: - format: date-time - readOnly: true - type: string - fromAddress: - description: |- - Sender email address. Must be verified with the provider. - Ignored when using the C1 built-in provider (uses no-reply@conductorone.com). - readOnly: false - type: string - fromName: - description: |- - Sender display name shown in the recipient's inbox (e.g., "Acme Corp IT"). - Used as the RFC 5322 display-name: "Acme Corp IT" . - Ignored when using the C1 built-in provider. - readOnly: false - type: string - googleWorkspace: - $ref: '#/components/schemas/c1.api.settings.v1.GoogleWorkspaceProviderConfig' - microsoftGraph: - $ref: '#/components/schemas/c1.api.settings.v1.MicrosoftGraphProviderConfig' - replyToAddress: - description: Optional reply-to address. - readOnly: false + type: + description: The data type of the computed result value. type: string - sendgrid: - $ref: '#/components/schemas/c1.api.settings.v1.SendGridProviderConfig' - updatedAt: - format: date-time - readOnly: true + value: + description: The computed result value of the CEL expression evaluation. type: string - title: Tenant Email Provider + title: Test Account Provision Policy Response type: object - x-speakeasy-name-override: TenantEmailProvider - c1.api.settings.v1.TestSourceIPRequest: - description: The TestSourceIPRequest message. + x-speakeasy-name-override: TestAccountProvisionPolicyResponse + c1.api.policy.v1.UnconfiguredProvision: + description: The UnconfiguredProvision message. + title: Unconfigured Provision + type: object + x-speakeasy-name-override: UnconfiguredProvision + c1.api.policy.v1.UpdatePolicyRequestInput: + description: The UpdatePolicyRequest message contains the policy object to update and a field mask to indicate which fields to update. It uses URL value for input. properties: - allowCidr: - description: |- - The CIDR allowlist rules to test against. If empty, uses the tenant's current allowlist. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Policy Request + type: object + x-speakeasy-name-override: UpdatePolicyRequest + c1.api.policy.v1.UpdatePolicyResponse: + description: The UpdatePolicyResponse message contains the updated policy object. + properties: + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.Policy' + - type: "null" + title: Update Policy Response + type: object + x-speakeasy-name-override: UpdatePolicyResponse + c1.api.policy.v1.UserApproval: + description: The user approval object describes the approval configuration of a policy step that needs to be approved by a specific list of users. + properties: + allowSelfApproval: + description: Configuration to allow self approval of if the user is specified and also the target of the ticket. + type: boolean + requireDistinctApprovers: + description: Configuration to require distinct approvers across approval steps of a rule. + type: boolean + userIds: + description: Array of users configured for approval. items: type: string - nullable: true - readOnly: false - type: array - sourceIp: - description: |- - if unset, uses the source IP of the request. - Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. - readOnly: false - type: string - title: Test Source Ip Request + type: + - array + - "null" + title: User Approval type: object - x-speakeasy-name-override: TestSourceIPRequest - c1.api.settings.v1.TestSourceIPResponse: - description: The TestSourceIPResponse message. + x-speakeasy-name-override: UserApproval + c1.api.policy.v1.UserProvisioner: + description: UserProvisioner assigns specific users as provisioners. properties: - allowed: - description: Whether the tested IP address is allowed by the CIDR rules. - readOnly: false + allowReassignment: + description: Whether the provisioner can reassign the task. type: boolean - checkedIp: - description: The IP address that was checked, either from the request or inferred from the caller. - readOnly: false - type: string - details: - $ref: '#/components/schemas/google.rpc.Status' - title: Test Source Ip Response + userIds: + description: The user IDs to assign as provisioners. + items: + type: string + type: + - array + - "null" + title: User Provisioner type: object - x-speakeasy-name-override: TestSourceIPResponse - c1.api.settings.v1.TestTenantEmailProviderRequest: - description: The TestTenantEmailProviderRequest message. + x-speakeasy-name-override: UserProvisioner + c1.api.policy.v1.Wait: + description: | + Define a Wait step for a policy to wait on a condition to be met. + + This message contains a oneof named until. Only a single field of the following list may be set at a time: + - condition + - duration + - untilTime properties: - testRecipientEmail: - description: The email address to send the test email to. - readOnly: false + commentOnFirstWait: + description: The comment to post on first failed check. type: string - title: Test Tenant Email Provider Request + commentOnTimeout: + description: The comment to post if we timeout. + type: string + condition: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitCondition' + - type: "null" + duration: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitDuration' + - type: "null" + name: + description: The name of our condition to show on the task details page + type: string + timeoutDuration: + format: duration + type: + - string + - "null" + untilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTime' + - type: "null" + title: Wait type: object - x-speakeasy-name-override: TestTenantEmailProviderRequest - c1.api.settings.v1.TestTenantEmailProviderResponse: - description: The TestTenantEmailProviderResponse message. + x-speakeasy-name-override: Wait + c1.api.policy.v1.WaitCondition: + description: The WaitCondition message. properties: - message: - description: Human-readable detail about the result. - readOnly: false + condition: + description: The condition that has to be true for this wait condition to continue. type: string - success: - description: Whether the test email was sent successfully. - readOnly: false - type: boolean - title: Test Tenant Email Provider Response + title: Wait Condition type: object - x-speakeasy-name-override: TestTenantEmailProviderResponse - c1.api.settings.v1.UpdateContactsRequest: - description: The UpdateContactsRequest message. + x-speakeasy-name-override: WaitCondition + c1.api.policy.v1.WaitConditionInstance: + description: Used by the policy engine to describe an instantiated condition to wait on. properties: - contacts: - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' - updateMask: - nullable: true - readOnly: false + condition: + description: The condition that has to be true for this wait condition instance to continue. type: string - title: Update Contacts Request + title: Wait Condition Instance type: object - x-speakeasy-name-override: UpdateContactsRequest - c1.api.settings.v1.UpdateContactsResponse: - description: The UpdateContactsResponse message. + x-speakeasy-name-override: WaitConditionInstance + c1.api.policy.v1.WaitDuration: + description: The WaitDuration message. properties: - contacts: - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' - title: Update Contacts Response + duration: + format: duration + type: + - string + - "null" + title: Wait Duration type: object - x-speakeasy-name-override: UpdateContactsResponse - c1.api.settings.v1.UpdateOnboardingSettingsRequest: - description: The UpdateOnboardingSettingsRequest message. + x-speakeasy-name-override: WaitDuration + c1.api.policy.v1.WaitInstance: + description: | + Used by the policy engine to describe an instantiated wait step. + + This message contains a oneof named until. Only a single field of the following list may be set at a time: + - condition + - untilTime + + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - succeeded + - timedOut + - skipped properties: - conversationId: - description: The identifier of the onboarding conversation thread to associate. - readOnly: false + commentOnFirstWait: + description: The comment to post on first failed check. type: string - status: - description: The new onboarding status to set. - enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED - readOnly: false + commentOnTimeout: + description: The comment to post if we timeout. type: string - x-speakeasy-unknown-values: allow - title: Update Onboarding Settings Request - type: object - x-speakeasy-name-override: UpdateOnboardingSettingsRequest - c1.api.settings.v1.UpdateOnboardingSettingsResponse: - description: The UpdateOnboardingSettingsResponse message. - properties: - status: - description: The updated onboarding status. + condition: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitConditionInstance' + - type: "null" + name: + description: The name field. + type: string + skipped: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.SkippedAction' + - type: "null" + startedWaitingAt: + format: date-time + type: + - string + - "null" + state: + description: The state field. enum: - - ONBOARDING_STATUS_UNSPECIFIED - - ONBOARDING_STATUS_NOT_STARTED - - ONBOARDING_STATUS_IN_PROGRESS - - ONBOARDING_STATUS_COMPLETE - - ONBOARDING_STATUS_DISMISSED - readOnly: false + - WAIT_INSTANCE_STATE_UNSPECIFIED + - WAIT_INSTANCE_STATE_WAITING + - WAIT_INSTANCE_STATE_COMPLETED + - WAIT_INSTANCE_STATE_TIMED_OUT type: string x-speakeasy-unknown-values: allow - title: Update Onboarding Settings Response - type: object - x-speakeasy-name-override: UpdateOnboardingSettingsResponse - c1.api.settings.v1.UpdateOrgDomainRequest: - description: The UpdateOrgDomainRequest message. - properties: - newDomains: - description: The complete list of domain names that should be set as the tenant's verified domains. - items: - type: string - nullable: true - readOnly: false - type: array - title: Update Org Domain Request - type: object - x-speakeasy-name-override: UpdateOrgDomainRequest - c1.api.settings.v1.UpdateOrgDomainResponse: - description: The UpdateOrgDomainResponse message. - properties: - list: - description: The resulting list of verified domains after the update. - items: - $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' - nullable: true - readOnly: false - type: array - title: Update Org Domain Response + succeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionSucceeded' + - type: "null" + timedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitInstance.ConditionTimedOut' + - type: "null" + timeout: + format: date-time + type: + - string + - "null" + timeoutDuration: + format: duration + type: + - string + - "null" + untilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.WaitUntilTimeInstance' + - type: "null" + title: Wait Instance type: object - x-speakeasy-name-override: UpdateOrgDomainResponse - c1.api.settings.v1.UpdateOrgNotificationSettingsRequest: - description: The UpdateOrgNotificationSettingsRequest message. + x-speakeasy-name-override: WaitInstance + c1.api.policy.v1.WaitInstance.ConditionSucceeded: + description: The ConditionSucceeded message. properties: - channelSettings: - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - title: Update Org Notification Settings Request + succeededAt: + format: date-time + type: + - string + - "null" + title: Condition Succeeded type: object - x-speakeasy-name-override: UpdateOrgNotificationSettingsRequest - c1.api.settings.v1.UpdateOrgNotificationSettingsResponse: - description: The UpdateOrgNotificationSettingsResponse message. + x-speakeasy-name-override: ConditionSucceeded + c1.api.policy.v1.WaitInstance.ConditionTimedOut: + description: The ConditionTimedOut message. properties: - orgNotificationSettings: - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' - title: Update Org Notification Settings Response + timedOutAt: + format: date-time + type: + - string + - "null" + title: Condition Timed Out type: object - x-speakeasy-name-override: UpdateOrgNotificationSettingsResponse - c1.api.settings.v1.UpdateSessionSettingsRequest: - description: The UpdateSessionSettingsRequest message. + x-speakeasy-name-override: ConditionTimedOut + c1.api.policy.v1.WaitUntilTime: + description: Waits until a specific time of the day (UTC) properties: - sessionSettings: - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - updateMask: - nullable: true - readOnly: false + hours: + description: The hours field. + format: uint32 + type: integer + minutes: + description: The minutes field. + format: uint32 + type: integer + timezone: + description: The timezone field. type: string - title: Update Session Settings Request + title: Wait Until Time type: object - x-speakeasy-name-override: UpdateSessionSettingsRequest - c1.api.settings.v1.UpdateSessionSettingsResponse: - description: The UpdateSessionSettingsResponse message. + x-speakeasy-name-override: WaitUntilTime + c1.api.policy.v1.WaitUntilTimeInstance: + description: The WaitUntilTimeInstance message. properties: - sessionSettings: - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' - title: Update Session Settings Response + durationIfExists: + format: duration + type: + - string + - "null" + untilTime: + format: date-time + type: + - string + - "null" + title: Wait Until Time Instance type: object - x-speakeasy-name-override: UpdateSessionSettingsResponse - c1.api.settings.v1.UpdateTenantEmailProviderRequest: - description: The UpdateTenantEmailProviderRequest message. + x-speakeasy-name-override: WaitUntilTimeInstance + c1.api.policy.v1.WebhookApproval: + description: The WebhookApproval message. properties: - emailProvider: - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - updateMask: - nullable: true - readOnly: false + webhookId: + description: The ID of the webhook to call for approval. type: string - title: Update Tenant Email Provider Request - type: object - x-speakeasy-name-override: UpdateTenantEmailProviderRequest - c1.api.settings.v1.UpdateTenantEmailProviderResponse: - description: The UpdateTenantEmailProviderResponse message. - properties: - emailProvider: - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' - title: Update Tenant Email Provider Response - type: object - x-speakeasy-name-override: UpdateTenantEmailProviderResponse - c1.api.settings.v1.UpdateUserNotificationSettingsRequest: - description: The UpdateUserNotificationSettingsRequest message. - properties: - channelSettings: - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - title: Update User Notification Settings Request - type: object - x-speakeasy-name-override: UpdateUserNotificationSettingsRequest - c1.api.settings.v1.UpdateUserNotificationSettingsResponse: - description: The UpdateUserNotificationSettingsResponse message. - properties: - userNotificationSettings: - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' - title: Update User Notification Settings Response - type: object - x-speakeasy-name-override: UpdateUserNotificationSettingsResponse - c1.api.settings.v1.UserNotificationSettings: - description: UserNotificationSettings contains the calling user's personal notification preferences. - properties: - channelSettings: - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' - title: User Notification Settings + title: Webhook Approval type: object - x-speakeasy-name-override: UserNotificationSettings - c1.api.ssf_receiver.v1.SSFOutboundAuthBearer: - description: |- - SSFOutboundAuthBearer is a static bearer token for outbound auth. - Token is write-only: accepted on create/update, never returned. - nullable: true + x-speakeasy-name-override: WebhookApproval + c1.api.policy.v1.WebhookProvision: + description: This provision step indicates that a webhook should be called to provision this entitlement. properties: - token: - description: The token field. - readOnly: false + webhookId: + description: The ID of the webhook to call for provisioning. type: string - title: Ssf Outbound Auth Bearer + title: Webhook Provision type: object - x-speakeasy-name-override: SSFOutboundAuthBearer - c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2: - description: |- - SSFOutboundAuthOAuth2 uses OAuth2 client credentials for outbound auth. - client_secret is write-only: accepted on create/update, never returned. - nullable: true + x-speakeasy-name-override: WebhookProvision + c1.api.profiletype.v1.ProfileType: + description: ProfileType represents a type of profile in the system properties: - clientId: - description: The clientId field. - readOnly: false + description: + description: The description field. type: string - clientSecret: - description: The clientSecret field. - readOnly: false + displayToUser: + description: Whether to display this profile type to users in profile page. Defaults to false if not set + type: boolean + iconUrl: + description: The iconUrl field. type: string - scopes: - description: The scopes field. + id: + description: The id field. + type: string + name: + description: The name field. + type: string + priority: + description: The priority field. + format: uint32 + type: integer + sizes: + description: icon sizes items: - type: string - nullable: true - readOnly: false - type: array - tokenUrl: - description: The tokenUrl field. - readOnly: false + format: int32 + type: integer + type: + - array + - "null" + slug: + description: Add this field to allow users to reference profile type in cel expressions type: string - title: Ssf Outbound Auth O Auth 2 + title: Profile Type type: object - x-speakeasy-name-override: SSFOutboundAuthOAuth2 - c1.api.ssf_receiver.v1.SSFReceiverEvent: - description: SSFReceiverEvent shows both wire-level data and C1 canonical outcome. + x-speakeasy-name-override: ProfileType + c1.api.request_schema.v1.RequestSchema: + description: A request schema defines a form template that users fill out when requesting access. properties: - canonicalType: - description: |- - C1 canonical outcome (what C1 understood and did). - The normalized event type after mapping from the wire event type. - enum: - - SSF_CANONICAL_EVENT_TYPE_UNSPECIFIED - - SSF_CANONICAL_EVENT_TYPE_UNRECOGNIZED - - SSF_CANONICAL_EVENT_TYPE_SESSION_REVOKED - - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_TOKEN_CLAIMS_CHANGED - - SSF_CANONICAL_EVENT_TYPE_ASSURANCE_LEVEL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_DEVICE_COMPLIANCE_CHANGED - - SSF_CANONICAL_EVENT_TYPE_RISK_LEVEL_CHANGED - - SSF_CANONICAL_EVENT_TYPE_SESSION_ESTABLISHED - - SSF_CANONICAL_EVENT_TYPE_SESSION_PRESENTED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_DISABLED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_ENABLED - - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_PURGED - - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_COMPROMISE - - SSF_CANONICAL_EVENT_TYPE_RECOVERY_ACTIVATED - - SSF_CANONICAL_EVENT_TYPE_IDENTIFIER_CHANGED - - SSF_CANONICAL_EVENT_TYPE_VERIFICATION - - SSF_CANONICAL_EVENT_TYPE_STREAM_UPDATED - readOnly: false - type: string - x-speakeasy-unknown-values: allow + createdAt: + format: date-time + type: + - string + - "null" + deletedAt: + format: date-time + type: + - string + - "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" id: - description: The unique identifier of this event. - readOnly: false + description: The unique identifier of this request schema. type: string - matchMethod: - description: How the upstream subject was resolved to a ConductorOne user. + justificationVisibility: + description: Controls whether the justification field is shown or hidden on the request form. enum: - - SSF_SUBJECT_MATCH_METHOD_UNSPECIFIED - - SSF_SUBJECT_MATCH_METHOD_IDP_USER - - SSF_SUBJECT_MATCH_METHOD_EMAIL - - SSF_SUBJECT_MATCH_METHOD_NOT_FOUND - - SSF_SUBJECT_MATCH_METHOD_NOT_APPLICABLE - readOnly: false + - JUSTIFICATION_VISIBILITY_UNSPECIFIED + - JUSTIFICATION_VISIBILITY_SHOW + - JUSTIFICATION_VISIBILITY_HIDE type: string x-speakeasy-unknown-values: allow - matchedUserId: - description: The ConductorOne user ID that the event subject was resolved to, if any. - readOnly: false + modifiedAt: + format: date-time + type: + - string + - "null" + title: Request Schema + type: object + x-speakeasy-name-override: RequestSchema + c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest: + description: The request message for creating a single entitlement binding on a request schema. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema to bind the entitlement to. type: string - outcome: - description: The action ConductorOne took in response to this event. - enum: - - SSF_EVENT_OUTCOME_UNSPECIFIED - - SSF_EVENT_OUTCOME_SESSIONS_REVOKED - - SSF_EVENT_OUTCOME_LOGGED - - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND - - SSF_EVENT_OUTCOME_VERIFIED - - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED - - SSF_EVENT_OUTCOME_UNRECOGNIZED - - SSF_EVENT_OUTCOME_ERROR - readOnly: false + title: Request Schema Service Create Entitlement Binding Request + type: object + x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingRequest + c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse: + description: The response message for creating a single entitlement binding. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema the entitlement was bound to. type: string - x-speakeasy-unknown-values: allow - outcomeDetail: - description: Human-readable details about the outcome (e.g., error message or revocation summary). - readOnly: false + title: Request Schema Service Create Entitlement Binding Response + type: object + x-speakeasy-name-override: RequestSchemaServiceCreateEntitlementBindingResponse + c1.api.request_schema.v1.RequestSchemaServiceCreateRequest: + description: The request message for creating a new request schema. + properties: + description: + description: An optional description of the request schema's purpose. type: string - receivedAt: - format: date-time - readOnly: false - type: string - sessionsRevoked: - description: Number of sessions that were revoked as a result of this event. - format: int32 - readOnly: false - type: integer - setJti: - description: |- - Wire-level data (what the transmitter sent). - The SET (Security Event Token) JWT ID claim, uniquely identifying the token. - readOnly: false - type: string - streamId: - description: The SSF receiver stream that received this event. - readOnly: false - type: string - wireEventProfile: - description: The event profile URI from the SET, if present. - readOnly: false - type: string - wireEventType: - description: The raw event type URI from the SET (e.g., "https://schemas.openid.net/secevent/caep/event-type/session-revoked"). - readOnly: false - type: string - wireInitiatingEntity: - description: The entity that initiated the event, as reported by the transmitter. - readOnly: false - type: string - wireReasonAdmin: - description: The admin-facing reason string from the SET, if provided by the transmitter. - readOnly: false - type: string - wireSubjectFormat: - description: The subject identifier format from the SET (e.g., "email", "iss_sub"). - readOnly: false - type: string - wireSubjectIdentifier: - description: The raw subject identifier value from the SET. - readOnly: false - type: string - title: Ssf Receiver Event - type: object - x-speakeasy-name-override: SSFReceiverEvent - c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest: - description: SSFReceiverEventSearchServiceSearchRequest carries the search query and optional filters for narrowing results. - properties: - eventType: - description: Restricts results to events matching this wire event type URI. Optional. - readOnly: false - type: string - matchedUserId: - description: Restricts results to events matched to this ConductorOne user ID. Optional. - readOnly: false - type: string - outcome: - description: Restricts results to events with this processing outcome. Optional. + fieldGroups: + description: Logical groupings of fields for display purposes. + items: + $ref: '#/components/schemas/c1.api.form.v1.FieldGroup' + type: + - array + - "null" + fieldRelationships: + description: Dependencies between fields that control conditional visibility or validation. + items: + $ref: '#/components/schemas/c1.api.form.v1.FieldRelationship' + type: + - array + - "null" + fields: + description: The form fields that users must fill out when requesting access. + items: + $ref: '#/components/schemas/c1.api.form.v1.Field' + type: + - array + - "null" + justificationVisibility: + description: Controls whether the justification field is shown or hidden on the request form. enum: - - SSF_EVENT_OUTCOME_UNSPECIFIED - - SSF_EVENT_OUTCOME_SESSIONS_REVOKED - - SSF_EVENT_OUTCOME_LOGGED - - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND - - SSF_EVENT_OUTCOME_VERIFIED - - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED - - SSF_EVENT_OUTCOME_UNRECOGNIZED - - SSF_EVENT_OUTCOME_ERROR - readOnly: false + - JUSTIFICATION_VISIBILITY_UNSPECIFIED + - JUSTIFICATION_VISIBILITY_SHOW + - JUSTIFICATION_VISIBILITY_HIDE type: string x-speakeasy-unknown-values: allow - pageSize: - description: Maximum number of events to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: Token from a previous SearchResponse to fetch the next page of results. - readOnly: false - type: string - query: - description: Full-text search query matched against event fields. - readOnly: false + name: + description: The human-readable name for the request schema. type: string - streamId: - description: Restricts results to events from this SSF receiver stream. Optional. - readOnly: false + title: Request Schema Service Create Request + type: object + x-speakeasy-name-override: RequestSchemaServiceCreateRequest + c1.api.request_schema.v1.RequestSchemaServiceCreateResponse: + description: The response message for creating a request schema. + properties: + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + title: Request Schema Service Create Response + type: object + x-speakeasy-name-override: RequestSchemaServiceCreateResponse + c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput: + description: The request message for deleting a request schema. + title: Request Schema Service Delete Request + type: object + x-speakeasy-name-override: RequestSchemaServiceDeleteRequest + c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse: + description: The response message for deleting a request schema. + title: Request Schema Service Delete Response + type: object + x-speakeasy-name-override: RequestSchemaServiceDeleteResponse + c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest: + description: The request message for finding which request schema is bound to a given app entitlement. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Request Schema Service Find Binding For App Entitlement Request + type: object + x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementRequest + c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse: + description: The response message containing the binding for the specified app entitlement. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema bound to this entitlement, if any. type: string - title: Ssf Receiver Event Search Service Search Request + title: Request Schema Service Find Binding For App Entitlement Response type: object - x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchRequest - c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse: - description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. + x-speakeasy-name-override: RequestSchemaServiceFindBindingForAppEntitlementResponse + c1.api.request_schema.v1.RequestSchemaServiceGetResponse: + description: The response message for retrieving a request schema. properties: - list: - description: The SSF events matching the search criteria. - items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. - readOnly: false + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + title: Request Schema Service Get Response + type: object + x-speakeasy-name-override: RequestSchemaServiceGetResponse + c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest: + description: The request message for removing a single entitlement binding from a request schema. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + requestSchemaId: + description: The unique identifier of the request schema to remove the binding from. type: string - title: Ssf Receiver Event Search Service Search Response + title: Request Schema Service Remove Entitlement Binding Request type: object - x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchResponse - c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse: - description: SSFReceiverEventServiceListResponse contains a page of received SSF events. + x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingRequest + c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse: + description: The response message for removing a single entitlement binding. + title: Request Schema Service Remove Entitlement Binding Response + type: object + x-speakeasy-name-override: RequestSchemaServiceRemoveEntitlementBindingResponse + c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput: + description: The request message for updating an existing request schema. properties: - list: - description: The SSF events in the current page. + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + updateMask: + type: + - string + - "null" + title: Request Schema Service Update Request + type: object + x-speakeasy-name-override: RequestSchemaServiceUpdateRequest + c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse: + description: The response message for updating a request schema. + properties: + requestSchema: + oneOf: + - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchema' + - type: "null" + title: Request Schema Service Update Response + type: object + x-speakeasy-name-override: RequestSchemaServiceUpdateResponse + c1.api.requestcatalog.v1.AppEntitlementWithUserBindings: + description: The AppEntitlementWithUserBindings message represents an app entitlement and its associated user bindings. + properties: + appEntitlementUserBindings: + description: An array of AppEntitlementUserBinding objects which represent the relationships that give app users access to the specific app entitlement. items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. - readOnly: false - type: string - title: Ssf Receiver Event Service List Response + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementUserBinding' + type: + - array + - "null" + entitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + - type: "null" + title: App Entitlement With User Bindings type: object - x-speakeasy-name-override: SSFReceiverEventServiceListResponse - c1.api.ssf_receiver.v1.SSFReceiverStream: + x-speakeasy-name-override: AppEntitlementWithUserBindings + c1.api.requestcatalog.v1.BundleAutomation: description: | - SSFReceiverStream is the public API representation. - Secrets (push_auth_token, outbound credentials) are write-only. + The BundleAutomation message. - This message contains a oneof named outbound_auth. Only a single field of the following list may be set at a time: - - outboundAuthBearer - - outboundAuthOauth2 + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - accountDisabledAction: - description: Action to take when an account-disabled event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false - type: string - x-speakeasy-unknown-values: allow + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' + - type: "null" + circuitBreaker: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker' + - type: "null" + createTasks: + description: The createTasks field. + type: boolean createdAt: format: date-time - readOnly: true - type: string - credentialChangeAction: - description: Action to take when a credential-change event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false - type: string - x-speakeasy-unknown-values: allow - credentialCompromiseAction: - description: Action to take when a credential-compromise event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false - type: string - x-speakeasy-unknown-values: allow + type: + - string + - "null" deletedAt: format: date-time - readOnly: true - type: string - deliveryMethod: - description: Controls whether events are received via push (transmitter POSTs to C1) or poll (C1 fetches from transmitter). - enum: - - SSF_DELIVERY_METHOD_UNSPECIFIED - - SSF_DELIVERY_METHOD_PUSH - - SSF_DELIVERY_METHOD_POLL - readOnly: false - type: string - x-speakeasy-unknown-values: allow - description: - description: Optional description of the stream's purpose or source. - readOnly: false - type: string - displayName: - description: Human-readable name for the stream shown in the UI. - readOnly: false - type: string + type: + - string + - "null" + disableCircuitBreaker: + description: The disableCircuitBreaker field. + type: boolean enabled: - description: Controls whether this stream actively processes incoming events. When false, events are ignored. - readOnly: false + description: The enabled field. type: boolean - eventTypesEnabled: - description: SSF/CAEP/RISC event type URIs that this stream is configured to accept. - items: - type: string - nullable: true - readOnly: false - type: array - expectedAudience: - description: Expected audience (aud) claim in incoming SETs. Optional. - readOnly: false - type: string - id: - description: The unique identifier of this SSF receiver stream. - readOnly: false + enforceOnSmallProfiles: + description: |- + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. + type: boolean + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - type: "null" + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means the tenant default applies. + format: int64 type: string - issuerUrl: - description: Upstream IdP identification. - readOnly: false + requestCatalogId: + description: The requestCatalogId field. type: string - jwksUrl: - description: The jwksUrl field. - readOnly: false + state: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationLastRunState' + - type: "null" + tenantId: + description: The tenantId field. type: string - lastErrorAt: + updatedAt: format: date-time - readOnly: false - type: string - lastErrorMessage: - description: The lastErrorMessage field. - readOnly: false + type: + - string + - "null" + title: Bundle Automation + type: object + x-speakeasy-name-override: BundleAutomation + c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState: + description: The BundleAutomationCelEvaluationState message. + properties: + errorMessage: + description: The errorMessage field. type: string - lastVerifiedAt: + lastEvaluatedAt: format: date-time - readOnly: false - type: string - outboundAuthBearer: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthBearer' - outboundAuthOauth2: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2' - pollEndpointUrl: - description: URL of the transmitter's poll endpoint where C1 fetches events from. - readOnly: false - type: string - pollInterval: - format: duration - readOnly: false - type: string - pushAuthToken: - description: 'Push auth token: write-only. Accepted on create, never returned in get/list.' - readOnly: false - type: string - pushEndpointUrl: - description: 'Push delivery: C1 generates a unique endpoint URL.' - readOnly: true + type: + - string + - "null" + matchedUsers: + description: The matchedUsers field. + format: int64 type: string - sessionRevokedAction: - description: |- - Per-canonical-type action configuration. - Event types without a config here default to LOG_ONLY. - Action to take when a session-revoked event is received. + status: + description: The status field. enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false + - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED + - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS + - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE + - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS + - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL type: string x-speakeasy-unknown-values: allow - updatedAt: - format: date-time - readOnly: true - type: string - title: Ssf Receiver Stream + title: Bundle Automation Cel Evaluation State type: object - x-speakeasy-name-override: SSFReceiverStream - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest: - description: SSFReceiverStreamServiceCreateRequest contains the configuration for a new SSF receiver stream. + x-speakeasy-name-override: BundleAutomationCelEvaluationState + c1.api.requestcatalog.v1.BundleAutomationCircuitBreaker: + description: The BundleAutomationCircuitBreaker message. properties: - accountDisabledAction: - description: Action to take when an account-disabled event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false - type: string - x-speakeasy-unknown-values: allow - credentialChangeAction: - description: Action to take when a credential-change event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false - type: string - x-speakeasy-unknown-values: allow - credentialCompromiseAction: - description: Action to take when a credential-compromise event is received. - enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false + removedMembersThresholdPercentage: + description: The removedMembersThresholdPercentage field. + format: int64 type: string - x-speakeasy-unknown-values: allow - deliveryMethod: - description: Controls whether events are received via push or poll delivery. + state: + description: The state field. enum: - - SSF_DELIVERY_METHOD_UNSPECIFIED - - SSF_DELIVERY_METHOD_PUSH - - SSF_DELIVERY_METHOD_POLL - readOnly: false + - CIRCUIT_BREAKER_STATE_UNSPECIFIED + - CIRCUIT_BREAKER_STATE_TRIGGERED + - CIRCUIT_BREAKER_STATE_BYPASS + - CIRCUIT_BREAKER_STATE_SUPPORT_DISABLED type: string x-speakeasy-unknown-values: allow - description: - description: Optional description of the stream's purpose or source. - readOnly: false - type: string - displayName: - description: Human-readable name for the stream. - readOnly: false - type: string - enabled: - description: Controls whether the stream starts processing events immediately after creation. - readOnly: false - type: boolean - expectedAudience: - description: Expected audience claim in incoming SETs. If set, SETs with a different audience are rejected. - readOnly: false - type: string - issuerUrl: - description: The issuer URL of the upstream SSF transmitter, used for token validation. - readOnly: false - type: string - jwksUrl: - description: URL to fetch the transmitter's JSON Web Key Set for SET signature verification. - readOnly: false - type: string - pollEndpointUrl: - description: URL of the transmitter's poll endpoint. Required when delivery_method is POLL. - readOnly: false - type: string - pollInterval: - format: duration - readOnly: false + updatedAt: + format: date-time + type: + - string + - "null" + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Bundle Automation Circuit Breaker + type: object + x-speakeasy-name-override: BundleAutomationCircuitBreaker + c1.api.requestcatalog.v1.BundleAutomationLastRunState: + description: The BundleAutomationLastRunState message. + properties: + celEvaluation: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationCelEvaluationState' + - type: "null" + errorMessage: + description: The errorMessage field. type: string - sessionRevokedAction: - description: |- - Per-event-type action configuration. - Action to take when a session-revoked event is received. + lastRunAt: + format: date-time + type: + - string + - "null" + status: + description: The status field. enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false + - BUNDLE_AUTOMATION_RUN_STATUS_UNSPECIFIED + - BUNDLE_AUTOMATION_RUN_STATUS_SUCCESS + - BUNDLE_AUTOMATION_RUN_STATUS_FAILURE + - BUNDLE_AUTOMATION_RUN_STATUS_IN_PROGRESS + - BUNDLE_AUTOMATION_RUN_STATUS_WAITING_FOR_APPROVAL type: string x-speakeasy-unknown-values: allow - required: - - displayName - - issuerUrl - title: Ssf Receiver Stream Service Create Request + title: Bundle Automation Last Run State type: object - x-speakeasy-name-override: SSFReceiverStreamServiceCreateRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse: - description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + x-speakeasy-name-override: BundleAutomationLastRunState + c1.api.requestcatalog.v1.BundleAutomationRuleCEL: + description: The BundleAutomationRuleCEL message. properties: - pushAuthTokenPlaintext: - description: Push auth token returned in plaintext ONLY on create. - readOnly: false + expression: + description: The expression field. type: string - ssfReceiverStream: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - title: Ssf Receiver Stream Service Create Response - type: object - x-speakeasy-name-override: SSFReceiverStreamServiceCreateResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput: - description: SSFReceiverStreamServiceDeleteRequest identifies the SSF receiver stream to delete. - title: Ssf Receiver Stream Service Delete Request - type: object - x-speakeasy-name-override: SSFReceiverStreamServiceDeleteRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse: - description: SSFReceiverStreamServiceDeleteResponse is empty on success. - title: Ssf Receiver Stream Service Delete Response - type: object - x-speakeasy-name-override: SSFReceiverStreamServiceDeleteResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse: - description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. - properties: - ssfReceiverStream: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - title: Ssf Receiver Stream Service Get Response - type: object - x-speakeasy-name-override: SSFReceiverStreamServiceGetResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse: - description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. - properties: - stats: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamStats' - title: Ssf Receiver Stream Service Get Stats Response + title: Bundle Automation Rule Cel type: object - x-speakeasy-name-override: SSFReceiverStreamServiceGetStatsResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse: - description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. + x-speakeasy-name-override: BundleAutomationRuleCEL + c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement: + description: The BundleAutomationRuleEntitlement message. properties: - list: - description: The SSF receiver streams in the current page. + entitlementRefs: + description: The entitlementRefs field. items: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - nullable: true - readOnly: false - type: array - nextPageToken: - description: Token to retrieve the next page. Empty when there are no more results. - readOnly: false - type: string - title: Ssf Receiver Stream Service List Response + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Bundle Automation Rule Entitlement type: object - x-speakeasy-name-override: SSFReceiverStreamServiceListResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput: - description: SSFReceiverStreamServiceTestRequest identifies the stream to test and an optional subject for identity resolution validation. + x-speakeasy-name-override: BundleAutomationRuleEntitlement + c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput: + description: | + The request message for creating a new bundle automation rule on a catalog. + + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - testSubject: + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' + - type: "null" + createTasks: + description: Whether to create access request tasks for matched users instead of granting directly. + type: boolean + disableCircuitBreaker: + description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. + type: boolean + enabled: + description: Whether the automation should actively run on its schedule. + type: boolean + enforceOnSmallProfiles: description: |- - The upstream identifier to test resolution with. Typically an email address - (e.g., "alice@company.com") — the same value the IdP would send in a SET subject. - The Test RPC runs resolveSubject on this to verify the identity mapping works. - Optional: upstream identifier (email) to test identity resolution. - If empty, only JWKS reachability is tested. - readOnly: false + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. Defaults to false. + type: boolean + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - type: "null" + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means inherit the tenant default. + format: int64 type: string - title: Ssf Receiver Stream Service Test Request + title: Create Bundle Automation Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceTestRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse: - description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. + x-speakeasy-name-override: CreateBundleAutomationRequest + c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput: + description: The request message for deleting a bundle automation from a catalog. + title: Delete Bundle Automation Request + type: object + x-speakeasy-name-override: DeleteBundleAutomationRequest + c1.api.requestcatalog.v1.DeleteBundleAutomationResponse: + description: The response message for deleting a bundle automation. + title: Delete Bundle Automation Response + type: object + x-speakeasy-name-override: DeleteBundleAutomationResponse + c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput: + description: The request message for triggering an immediate bundle automation run. properties: - activeRefreshTokenCount: - description: Number of active refresh tokens for the matched user that would be affected. - format: int32 - readOnly: false - type: integer - activeSessionCount: - description: Number of active sessions for the matched user that would be affected. - format: int32 - readOnly: false - type: integer - configuredSessionRevokedAction: + refs: + description: Optional entitlement references to scope the run to specific entitlements. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Force Run Bundle Automation Request + type: object + x-speakeasy-name-override: ForceRunBundleAutomationRequest + c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse: + description: The response message for triggering a bundle automation run. + title: Force Run Bundle Automation Response + type: object + x-speakeasy-name-override: ForceRunBundleAutomationResponse + c1.api.requestcatalog.v1.RequestCatalog: + description: The RequestCatalog is used for managing which entitlements are requestable, and who can request them. + properties: + accessEntitlements: + description: An array of app entitlements that, if the user has, can view the contents of this catalog. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + type: + - array + - "null" + annotations: + additionalProperties: + type: string description: |- - Step 3: Action preview. - The action configured for session-revoked events on this stream. + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/ + are reserved. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdByUserId: + description: The id of the user this request catalog was created by. + type: string + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: The description of the request catalog. + type: string + displayName: + description: The display name of the request catalog. + type: string + enrollmentBehavior: + description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. enum: - - SSF_REVOCATION_ACTION_UNSPECIFIED - - SSF_REVOCATION_ACTION_REVOKE_ALL - - SSF_REVOCATION_ACTION_LOG_ONLY - readOnly: false + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY type: string x-speakeasy-unknown-values: allow - identityLinkFound: - description: |- - Step 2: Identity mapping. - Whether the test subject was resolved to a ConductorOne user. - readOnly: false - type: boolean - jwksError: - description: Error message if the JWKS endpoint could not be reached or returned invalid data. - readOnly: false + id: + description: The id of the request catalog. type: string - jwksKeyCount: - description: Number of signing keys found at the JWKS endpoint. - format: int32 - readOnly: false - type: integer - jwksReachable: - description: |- - Step 1: JWKS reachability. - Whether the JWKS endpoint was reachable and returned valid keys. - readOnly: false + published: + description: Whether or not this catalog is published. type: boolean - matchedUserId: - description: The ConductorOne user ID the test subject maps to, if an identity link was found. - readOnly: false - type: string - ready: - description: |- - Overall readiness. - Whether the stream passed all test checks and is ready to process events. - readOnly: false + requestBundle: + description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. type: boolean - upstreamSubject: - description: The upstream IdP subject identifier (e.g., Okta user ID "00u1234") resolved from the test subject. - readOnly: false + unenrollmentBehavior: + description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED type: string - title: Ssf Receiver Stream Service Test Response + x-speakeasy-unknown-values: allow + unenrollmentEntitlementBehavior: + description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + visibleToEveryone: + description: If this is true, the access entitlement requirement is ignored. + type: boolean + title: Request Catalog type: object - x-speakeasy-name-override: SSFReceiverStreamServiceTestResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput: - description: SSFReceiverStreamServiceUpdateRequest carries the stream to update and the mask of fields to modify. + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalog + c1.api.requestcatalog.v1.RequestCatalogExpandMask: + description: The RequestCatalogExpandMask includes the paths in the catalog view to expand in the return value of this call. properties: - ssfReceiverStream: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - updateMask: - nullable: true - readOnly: false - type: string - title: Ssf Receiver Stream Service Update Request + paths: + description: An array of paths to be expanded in the response. May be any combination of "*", "created_by_user_id", "app_ids", and "access_entitlements". + items: + type: string + type: + - array + - "null" + title: Request Catalog Expand Mask type: object - x-speakeasy-name-override: SSFReceiverStreamServiceUpdateRequest - c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse: - description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. + x-speakeasy-name-override: RequestCatalogExpandMask + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput: + description: |- + The RequestCatalogManagementServiceAddAccessEntitlementsRequest message is used to add access entitlements to a request + catalog to determine which users can view the request catalog. properties: - ssfReceiverStream: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' - title: Ssf Receiver Stream Service Update Response + accessEntitlements: + description: List of entitlements to add to the request catalog as access entitlements. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + required: + - accessEntitlements + title: Request Catalog Management Service Add Access Entitlements Request type: object - x-speakeasy-name-override: SSFReceiverStreamServiceUpdateResponse - c1.api.ssf_receiver.v1.SSFReceiverStreamStats: - description: SSFReceiverStreamStats is a lightweight read-only stats object. + x-speakeasy-entity: Access_Profile_Visibility_Bindings + x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Add Access Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceAddAccessEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceAddAppEntitlementsRequest object is used to add app requestable app entitlements to a request catalog. properties: - eventsActedOnCount: - description: Number of events that triggered an action (e.g., session revocation). - format: int64 - readOnly: false - type: string - eventsFailedCount: - description: Number of events that failed processing. - format: int64 - readOnly: false - type: string - eventsReceivedCount: - description: Total number of events received on this stream. - format: int64 - readOnly: false - type: string - lastErrorAt: - format: date-time - readOnly: false - type: string - lastErrorMessage: - description: Human-readable description of the most recent processing error. - readOnly: false - type: string - lastEventReceivedAt: - format: date-time - readOnly: false + appEntitlements: + description: List of entitlements to add to the request catalog. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + createRequests: + description: |- + Whether or not to create requests for newly added entitlements for users in the catalog. + By default, this is false and no requests are created. + type: boolean + required: + - appEntitlements + title: Request Catalog Management Service Add App Entitlements Request + type: object + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Add App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceAddAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest: + description: Create a request catalog. + properties: + annotations: + additionalProperties: + type: string + description: |- + Bounded key/value metadata bag for IaC marking and customer tags. + See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128 + chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars + matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting + with `c1/` are reserved for server-managed use and rejected on write. + + Well-known keys: `managed_by`, `iac_workspace`, + `iac_resource_address`, `iac_tool_version`. + type: object + x-speakeasy-terraform-plan-modifier: + imports: + - github.com/conductorone/terraform-provider-conductorone/internal/annotations + schemaDefinition: annotations.PlanModifier() + description: + description: The description of the new request catalog. type: string - lastVerifiedAt: - format: date-time - readOnly: false + displayName: + description: The display name of the new request catalog. type: string - streamId: - description: The SSF receiver stream these stats belong to. - readOnly: false + enrollmentBehavior: + description: Defines how to handle the request policies of the entitlements in the catalog during enrollment. + enum: + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY + - REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY type: string - transmitterStatus: - description: Current status reported by the transmitter (e.g., "enabled", "paused"). - readOnly: false + x-speakeasy-unknown-values: allow + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' + - type: "null" + published: + description: Whether or not the new catalog should be created as published. + type: boolean + requestBundle: + description: Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. + type: boolean + unenrollmentBehavior: + description: Defines how to handle the revocation of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL + - REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_UNJUSTIFIED type: string - transmitterStatusReason: - description: Reason provided by the transmitter for its current status. - readOnly: false + x-speakeasy-unknown-values: allow + unenrollmentEntitlementBehavior: + description: Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. + enum: + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS + - REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE type: string - title: Ssf Receiver Stream Stats + x-speakeasy-unknown-values: allow + visibleToEveryone: + description: Whether or not the new catalog is visible to everyone by default. + type: boolean + required: + - displayName + title: Request Catalog Management Service Create Request type: object - x-speakeasy-name-override: SSFReceiverStreamStats - c1.api.stepup.v1.CreateStepUpProviderRequest: - description: | - The CreateStepUpProviderRequest message. - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oauth2 - - microsoft + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput: + description: Create a single requestable entry properties: - clientId: - description: The OAuth2 client ID used to authenticate with the step-up provider. - readOnly: false - type: string - clientSecret: - description: The OAuth2 client secret. Write-only; never returned in responses. - readOnly: false - type: string - displayName: - description: The human-readable name for the new step-up provider. - readOnly: false - type: string - issuerUrl: - description: The OIDC issuer URL for the step-up provider. - readOnly: false - type: string - microsoft: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' - oauth2: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' - title: Create Step Up Provider Request + createRequests: + description: |- + Whether or not to create requests for newly added entitlement for users in the catalog. + By default, this is false and no requests are created. + type: boolean + title: Request Catalog Management Service Create Requestable Entry Request type: object - x-speakeasy-name-override: CreateStepUpProviderRequest - c1.api.stepup.v1.CreateStepUpProviderResponse: - description: The CreateStepUpProviderResponse message. + x-speakeasy-entity: Access_Profile_Requestable_Entry + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse: + description: Response containing the created requestable entry properties: - stepUpProvider: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - title: Create Step Up Provider Response + requestableEntry: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' + - type: "null" + title: Request Catalog Management Service Create Requestable Entry Response type: object - x-speakeasy-name-override: CreateStepUpProviderResponse - c1.api.stepup.v1.DeleteStepUpProviderRequestInput: - description: The DeleteStepUpProviderRequest message. - title: Delete Step Up Provider Request + x-speakeasy-name-override: RequestCatalogManagementServiceCreateRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput: + description: Delete a request catalog by Id. It uses URL value for input. + title: Request Catalog Management Service Delete Request type: object - x-speakeasy-name-override: DeleteStepUpProviderRequest - c1.api.stepup.v1.DeleteStepUpProviderResponse: - description: The DeleteStepUpProviderResponse message. - title: Delete Step Up Provider Response + x-speakeasy-entity: Access_Profile + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput: + description: Delete a single requestable entry + title: Request Catalog Management Service Delete Requestable Entry Request type: object - x-speakeasy-name-override: DeleteStepUpProviderResponse - c1.api.stepup.v1.GetStepUpProviderResponse: - description: The GetStepUpProviderResponse message. - properties: - stepUpProvider: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - title: Get Step Up Provider Response + x-speakeasy-entity: Access_Profile_Requestable_Entry + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse: + description: Empty response for delete operation + title: Request Catalog Management Service Delete Requestable Entry Response type: object - x-speakeasy-name-override: GetStepUpProviderResponse - c1.api.stepup.v1.GetStepUpTransactionResponse: - description: Response message containing the requested step-up transaction + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Delete Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceDeleteResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse: + description: Response containing the requested entry properties: - transaction: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' - title: Get Step Up Transaction Response + requestableEntry: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestableEntry' + - type: "null" + title: Request Catalog Management Service Get Requestable Entry Response type: object - x-speakeasy-name-override: GetStepUpTransactionResponse - c1.api.stepup.v1.ListStepUpProvidersResponse: - description: The ListStepUpProvidersResponse message. + x-speakeasy-name-override: RequestCatalogManagementServiceGetRequestableEntryResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse: + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. properties: - list: - description: The list of step-up authentication providers. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - nullable: true - readOnly: false - type: array - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false - type: string - title: List Step Up Providers Response + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + requestCatalogView: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' + - type: "null" + title: Request Catalog Management Service Get Response type: object - x-speakeasy-name-override: ListStepUpProvidersResponse - c1.api.stepup.v1.SearchStepUpProvidersRequest: - description: Request message for searching step-up providers + x-speakeasy-name-override: RequestCatalogManagementServiceGetResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse: + description: The response message containing all requestable entitlement references in the catalog. properties: - pageSize: - description: Maximum number of results to return - format: int32 - readOnly: false - type: integer - pageToken: - description: Token for pagination - readOnly: false - type: string - providerType: - description: The providerType field. - enum: - - PROVIDER_TYPE_UNSPECIFIED - - PROVIDER_TYPE_OAUTH2 - - PROVIDER_TYPE_MICROSOFT - readOnly: false - type: string - x-speakeasy-unknown-values: allow - query: - description: Filter by name (partial match) - readOnly: false - type: string refs: - description: Filter to specific providers by their references. + description: The complete list of app entitlement references in this catalog. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProviderRef' - nullable: true - readOnly: false - type: array - title: Search Step Up Providers Request + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Request Catalog Management Service List All Entitlement Ids Per Catalog Response type: object - x-speakeasy-name-override: SearchStepUpProvidersRequest - c1.api.stepup.v1.SearchStepUpProvidersResponse: - description: Response message for searching step-up providers + x-speakeasy-name-override: RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse: + description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" list: - description: List of providers matching the search criteria + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + type: + - array + - "null" nextPageToken: - description: Token for retrieving the next page of results - readOnly: false - type: string - title: Search Step Up Providers Response - type: object - x-speakeasy-name-override: SearchStepUpProvidersResponse - c1.api.stepup.v1.SearchStepUpTransactionsRequest: - description: Request message for searching step-up transactions - properties: - createdAfter: - format: date-time - readOnly: false - type: string - createdBefore: - format: date-time - readOnly: false - type: string - pageSize: - description: Maximum number of results to return - format: int32 - readOnly: false - type: integer - pageToken: - description: Token for pagination - readOnly: false - type: string - providerId: - description: Filter by provider ID - readOnly: false - type: string - state: - description: Filter by transaction state - enum: - - STEP_UP_TRANSACTION_STATE_UNSPECIFIED - - STEP_UP_TRANSACTION_STATE_PENDING - - STEP_UP_TRANSACTION_STATE_VERIFIED - - STEP_UP_TRANSACTION_STATE_ERROR - readOnly: false - type: string - x-speakeasy-unknown-values: allow - targetType: - description: The targetType field. - enum: - - TARGET_TYPE_UNSPECIFIED - - TARGET_TYPE_TICKET - - TARGET_TYPE_TEST - readOnly: false - type: string - x-speakeasy-unknown-values: allow - taskId: - description: Filter by task ID (only applicable if target_type is TICKET) - readOnly: false - type: string - userId: - description: Filter by user ID - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search Step Up Transactions Request + title: Request Catalog Management Service List Entitlements For Access Response type: object - x-speakeasy-name-override: SearchStepUpTransactionsRequest - c1.api.stepup.v1.SearchStepUpTransactionsResponse: - description: Response message for searching step-up transactions + x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsForAccessResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse: + description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" list: - description: List of transactions matching the search criteria + description: The list of results containing up to X results, where X is the page size defined in the request. items: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementView' + type: + - array + - "null" nextPageToken: - description: Token for retrieving the next page of results - readOnly: false + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Search Step Up Transactions Response + title: Request Catalog Management Service List Entitlements Per Catalog Response type: object - x-speakeasy-name-override: SearchStepUpTransactionsResponse - c1.api.stepup.v1.StepUpMicrosoftSettings: - description: StepUpMicrosoftSettings configures a Microsoft Entra step-up provider using Conditional Access. - nullable: true - properties: - conditionalAccessIds: - description: Authentication context IDs (C1-C99). Required for ACRS mode; ignored for OIDC mode. + x-speakeasy-name-override: RequestCatalogManagementServiceListEntitlementsPerCatalogResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse: + description: The RequestCatalogManagementServiceListResponse message. + properties: + expanded: + description: List of serialized related objects. items: - type: string - nullable: true - readOnly: false - type: array - tenant: - description: Microsoft Entra tenant ID (GUID or domain). Used for response validation. - readOnly: false - type: string - validationMode: - description: Validation approach. See MicrosoftValidationMode for details on each mode. - enum: - - MICROSOFT_VALIDATION_MODE_UNSPECIFIED - - MICROSOFT_VALIDATION_MODE_ACRS - - MICROSOFT_VALIDATION_MODE_OIDC - readOnly: false + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of request catalogs. + items: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - x-speakeasy-unknown-values: allow - title: Step Up Microsoft Settings + title: Request Catalog Management Service List Response type: object - x-speakeasy-name-override: StepUpMicrosoftSettings - c1.api.stepup.v1.StepUpOAuth2Settings: + x-speakeasy-name-override: RequestCatalogManagementServiceListResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput: description: |- - StepUpOAuth2Settings repersents an OAuth2 provider that supports RFC 9470 - - Common ACR values for OAuth2 providers include: - - "urn:okta:loa:1fa:any" (okta) - - "urn:okta:loa:1fa:pwd" (okta) - - "urn:okta:loa:2fa:any" (okta) - - "urn:okta:loa:2fa:any:ifpossible" (okta) - - "phr" (okta) - - "phrh" (okta) - nullable: true + The RequestCatalogManagementServiceRemoveAccessEntitlementsRequest message is used to remove access entitlements from a request catalog. + The access entitlements are used to determine which users can view the request catalog. properties: - acrValues: - description: The acrValues field. + accessEntitlements: + description: The list of access entitlements to remove from the catalog. items: - type: string - nullable: true - readOnly: false - type: array - title: Step Up O Auth 2 Settings + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Request Catalog Management Service Remove Access Entitlements Request type: object - x-speakeasy-name-override: StepUpOAuth2Settings - c1.api.stepup.v1.StepUpProvider: - description: | - StepUpProvider represents a configured step-up authentication integration (e.g., Duo, custom OIDC). - - This message contains a oneof named settings. Only a single field of the following list may be set at a time: - - oauth2 - - microsoft + x-speakeasy-entity: Access_Profile_Visibility_Bindings + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse: + description: Empty response with a status code indicating success. + title: Request Catalog Management Service Remove Access Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAccessEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceRemoveAppEntitlementsRequest message is used to remove app entitlements from a request catalog. properties: - clientId: - description: The OAuth2 client ID used to authenticate with the step-up provider. - readOnly: false + appEntitlements: + description: The list of app entitlements to remove from the catalog. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + title: Request Catalog Management Service Remove App Entitlements Request + type: object + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse: + description: Empty response with a status code indicating success + title: Request Catalog Management Service Remove App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceRemoveAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput: + description: The RequestCatalogManagementServiceUpdateAppEntitlementsRequest object is used to update app entitlements to a request catalog id. + properties: + appEntitlements: + description: The entitlement to get from the request catalog. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + required: + - appEntitlements + title: Request Catalog Management Service Update App Entitlements Request + type: object + x-speakeasy-entity: Access_Profile_Requestable_Entries + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse: + description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. + title: Request Catalog Management Service Update App Entitlements Response + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateAppEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput: + description: Update a request catalog object by ID. + properties: + catalog: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' + - type: "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogExpandMask' + - type: "null" + updateMask: + type: + - string + - "null" + title: Request Catalog Management Service Update Request + type: object + x-speakeasy-name-override: RequestCatalogManagementServiceUpdateRequest + c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest: + description: The RequestCatalogSearchServiceSearchEntitlementsRequest searches entitlements, but only ones that are available to you through the open catalogs. + properties: + appDisplayName: + description: Search entitlements that belong to this app name (exact match). type: string - createdAt: - format: date-time - readOnly: true + entitlementAlias: + description: Search for entitlements with this alias (exact match). type: string - displayName: - description: The human-readable name of the step-up provider. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementExpandMask' + - type: "null" + grantedStatus: + description: Search entitlements with this granted status for your signed in user. + enum: + - UNSPECIFIED + - ALL + - GRANTED + - NOT_GRANTED type: string - enabled: - description: Whether the step-up provider is active and available for use. - readOnly: false + x-speakeasy-unknown-values: allow + includeDeleted: + description: Include deleted entitlements type: boolean - id: - description: The unique identifier of the step-up provider. - readOnly: true - type: string - issuerUrl: - description: The OIDC issuer URL for the step-up provider. - readOnly: false - type: string - lastTestedAt: - format: date-time - readOnly: true + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - microsoft: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' - oauth2: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' - updatedAt: - format: date-time - readOnly: true + query: + description: Fuzzy search the display name of resource types. type: string - title: Step Up Provider + title: Request Catalog Search Service Search Entitlements Request type: object - x-speakeasy-name-override: StepUpProvider - c1.api.stepup.v1.StepUpProviderRef: - description: StepUpProviderRef is a lightweight reference to a step-up authentication provider. + x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsRequest + c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse: + description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. properties: - id: - description: The unique identifier of the step-up provider. - readOnly: false + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.AppEntitlementWithUserBindings' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: Step Up Provider Ref + title: Request Catalog Search Service Search Entitlements Response type: object - x-speakeasy-name-override: StepUpProviderRef - c1.api.stepup.v1.StepUpTransaction: - description: | - StepUpTransaction represents a record of a step-up authentication attempt - - This message contains a oneof named target. Only a single field of the following list may be set at a time: - - approveTask - - test + x-speakeasy-name-override: RequestCatalogSearchServiceSearchEntitlementsResponse + c1.api.requestcatalog.v1.RequestCatalogView: + description: The request catalog view contains the serialized request catalog and paths to objects referenced by the request catalog. properties: - approveTask: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTask' - claims: - additionalProperties: true - readOnly: false - type: object - createdAt: - format: date-time - readOnly: true - type: string - errorMessage: - description: Error message if the transaction failed - readOnly: true - type: string - expiresAt: - format: date-time - readOnly: true - type: string - id: - description: Unique identifier for the transaction - readOnly: false - type: string - providerId: - description: ID of the provider used for this step-up authentication - readOnly: false - type: string - state: - description: Current state of the transaction - enum: - - STEP_UP_TRANSACTION_STATE_UNSPECIFIED - - STEP_UP_TRANSACTION_STATE_PENDING - - STEP_UP_TRANSACTION_STATE_VERIFIED - - STEP_UP_TRANSACTION_STATE_ERROR - readOnly: true + accessEntitlementsPath: + description: JSONPATH expression indicating the location of the access entitlement objects, that the request catalog allows users to request, in the array. type: string - x-speakeasy-unknown-values: allow - test: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTest' - updatedAt: - format: date-time - readOnly: true + createdByUserPath: + description: JSONPATH expression indicating the location of the User object, that created the request catalog, in the array. type: string - userId: - description: ID of the user who performed the step-up authentication - readOnly: false + memberCount: + description: Total number of the members of the catalog + format: int64 type: string - title: Step Up Transaction + requestCatalog: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalog' + - type: "null" + title: Request Catalog View type: object - x-speakeasy-name-override: StepUpTransaction - c1.api.stepup.v1.StepUpTransaction.TargetTask: - description: Target for approving a task - nullable: true + x-speakeasy-name-override: RequestCatalogView + c1.api.requestcatalog.v1.RequestableEntry: + description: A requestable entry in a catalog properties: - policyStepId: - description: ID of the policy step requiring step-up authentication - readOnly: false + appId: + description: The ID of the app that contains the entitlement type: string - taskId: - description: ID of the task being approved - readOnly: false + catalogId: + description: The ID of the access profile (catalog) type: string - title: Target Task + entitlementId: + description: The ID of the entitlement + type: string + title: Requestable Entry type: object - x-speakeasy-name-override: TargetTask - c1.api.stepup.v1.StepUpTransaction.TargetTest: - description: Target for testing a provider - nullable: true - title: Target Test + x-speakeasy-name-override: RequestableEntry + c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput: + description: The request message for resuming a paused bundle automation. + title: Resume Paused Bundle Automation Request type: object - x-speakeasy-name-override: TargetTest - c1.api.stepup.v1.TestStepUpProviderRequestInput: - description: The TestStepUpProviderRequest message. - title: Test Step Up Provider Request + x-speakeasy-name-override: ResumePausedBundleAutomationRequest + c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse: + description: The response message for resuming a paused bundle automation. + title: Resume Paused Bundle Automation Response type: object - x-speakeasy-name-override: TestStepUpProviderRequest - c1.api.stepup.v1.TestStepUpProviderResponse: - description: The TestStepUpProviderResponse message. + x-speakeasy-name-override: ResumePausedBundleAutomationResponse + c1.api.requestcatalog.v1.SetBundleAutomationRequestInput: + description: | + The request message for creating or updating a bundle automation rule on a catalog. + + This message contains a oneof named conditions. Only a single field of the following list may be set at a time: + - entitlements + - cel properties: - redirectUrl: - description: The URL to redirect the user to for testing the Step Up flow - readOnly: false + cel: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleCEL' + - type: "null" + createTasks: + description: Whether to create access request tasks for matched users instead of granting directly. + type: boolean + disableCircuitBreaker: + description: Whether to disable the circuit breaker that pauses the automation when excessive membership changes are detected. + type: boolean + enabled: + description: Whether the automation should actively run on its schedule. + type: boolean + enforceOnSmallProfiles: + description: |- + When true, the circuit breaker is evaluated even on profiles below the + tenant min-members floor. Defaults to false. + type: boolean + entitlements: + oneOf: + - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomationRuleEntitlement' + - type: "null" + removedMembersThresholdPercent: + description: |- + Per-automation override for the removed-members percent that trips the + circuit breaker (1-100). 0 / unset means inherit the tenant default. + format: int64 type: string - title: Test Step Up Provider Response + title: Set Bundle Automation Request type: object - x-speakeasy-name-override: TestStepUpProviderResponse - c1.api.stepup.v1.UpdateStepUpProviderRequestInput: - description: The UpdateStepUpProviderRequest message. + x-speakeasy-name-override: SetBundleAutomationRequest + c1.api.role_mining_management.v1.CohortHintInput: + description: The CohortHintInput message. properties: - stepUpProvider: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - updateMask: - nullable: true - readOnly: false + attribute: + description: The user attribute name to use for cohort grouping (e.g., "department", "job_title"). type: string - title: Update Step Up Provider Request - type: object - x-speakeasy-name-override: UpdateStepUpProviderRequest - c1.api.stepup.v1.UpdateStepUpProviderResponse: - description: The UpdateStepUpProviderResponse message. - properties: - stepUpProvider: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - title: Update Step Up Provider Response + priority: + description: Relative priority of this hint. Higher values cause the analysis to weight this attribute more heavily. + format: int32 + type: integer + values: + description: Specific attribute values to focus on. If empty, all values for the attribute are considered. + items: + type: string + type: + - array + - "null" + title: Cohort Hint Input type: object - x-speakeasy-name-override: UpdateStepUpProviderResponse - c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput: - description: The UpdateStepUpProviderSecretRequest message. + x-speakeasy-name-override: CohortHintInput + c1.api.role_mining_management.v1.CohortHintView: + description: The CohortHintView message. properties: - clientSecret: - description: The new OAuth2 client secret. Write-only; never returned in responses. - readOnly: false + attribute: + description: The user attribute name used for cohort grouping. type: string - title: Update Step Up Provider Secret Request + priority: + description: Relative priority of this hint. + format: int32 + type: integer + values: + description: The specific attribute values targeted by this hint. + items: + type: string + type: + - array + - "null" + title: Cohort Hint View type: object - x-speakeasy-name-override: UpdateStepUpProviderSecretRequest - c1.api.stepup.v1.UpdateStepUpProviderSecretResponse: - description: The UpdateStepUpProviderSecretResponse message. + x-speakeasy-name-override: CohortHintView + c1.api.role_mining_management.v1.CohortUserWithCoverage: + description: CohortUserWithCoverage pairs a user with the count of selected entitlements they hold. properties: - stepUpProvider: - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' - title: Update Step Up Provider Secret Response + coveredCount: + description: Number of selected_entitlements that this user currently holds. + format: int32 + type: integer + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Cohort User With Coverage type: object - x-speakeasy-name-override: UpdateStepUpProviderSecretResponse - c1.api.systemlog.v1.ExportServiceCreateRequest: - description: | - The ExportServiceCreateRequest message is used to create a new system log exporter. - - This message contains a oneof named export_to. Only a single field of the following list may be set at a time: - - datasource + x-speakeasy-name-override: CohortUserWithCoverage + c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest: + description: The CreateAccessProfileFromCohortRequest message. properties: - datasource: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' + celExpression: + description: |- + Optional CEL expression for dynamic membership. When non-empty, used + instead of auto-generating from profile_filters. + type: string + createTasks: + description: |- + If true, the automation will create JIT tasks for access changes. + If false, users are synced to membership without creating tasks. + type: boolean + description: + description: Description for the access profile. + type: string displayName: - description: The display name of the new system log exporter. - readOnly: false + description: Display name for the access profile. type: string - title: Export Service Create Request - type: object - x-speakeasy-name-override: ExportServiceCreateRequest - c1.api.systemlog.v1.ExportServiceCreateResponse: - description: The ExportServiceCreateResponse message. - properties: - exporter: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - title: Export Service Create Response - type: object - x-speakeasy-name-override: ExportServiceCreateResponse - c1.api.systemlog.v1.ExportServiceDeleteRequestInput: - description: The ExportServiceDeleteRequest message. - title: Export Service Delete Request - type: object - x-speakeasy-name-override: ExportServiceDeleteRequest - c1.api.systemlog.v1.ExportServiceDeleteResponse: - description: The ExportServiceDeleteResponse message. - title: Export Service Delete Response + enableAutomation: + description: If true, enable the dynamic membership automation immediately. + type: boolean + entitlements: + description: Entitlements to add to the access profile. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + profileFilters: + description: Profile filters defining the cohort for dynamic membership. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + suggestionId: + description: Optional suggestion ID to mark as accepted after creating the profile. + type: string + title: Create Access Profile From Cohort Request type: object - x-speakeasy-name-override: ExportServiceDeleteResponse - c1.api.systemlog.v1.ExportServiceGetResponse: - description: The ExportServiceGetResponse message contains the system log exporter object. + x-speakeasy-name-override: CreateAccessProfileFromCohortRequest + c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse: + description: The CreateAccessProfileFromCohortResponse message. properties: - exporter: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - title: Export Service Get Response + accessProfileId: + description: The ID of the created access profile. + type: string + celExpression: + description: The CEL expression generated for dynamic membership. + type: string + title: Create Access Profile From Cohort Response type: object - x-speakeasy-name-override: ExportServiceGetResponse - c1.api.systemlog.v1.ExportServiceListEventsRequestInput: - description: ExportServiceListEventsRequest is the request for listing audit events within a specific export. + x-speakeasy-name-override: CreateAccessProfileFromCohortResponse + c1.api.role_mining_management.v1.CustomAnalysisResultView: + description: CustomAnalysisResultView is a lightweight summary of a past custom analysis run. properties: - pageSize: - description: The pageSize field. + cohortSize: + description: Number of users in the cohort. format: int32 - readOnly: false type: integer - pageToken: - description: The pageToken field. - readOnly: false + completedAt: + format: date-time + type: + - string + - "null" + createdAt: + format: date-time + type: + - string + - "null" + errorMessage: + description: Error message if the analysis failed, empty on success. type: string - title: Export Service List Events Request - type: object - x-speakeasy-name-override: ExportServiceListEventsRequest - c1.api.systemlog.v1.ExportServiceListEventsResponse: - description: ExportServiceListEventsResponse is the response containing audit events for an export. - properties: - list: - description: List contains an array of JSON OCSF events. - items: - additionalProperties: true - readOnly: false - type: object - nullable: true - readOnly: false - type: array - nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + id: + description: Unique identifier for this custom analysis result. type: string - title: Export Service List Events Response - type: object - x-speakeasy-name-override: ExportServiceListEventsResponse - c1.api.systemlog.v1.ExportServiceListResponse: - description: The ExportServiceListResponse message. - properties: - list: - description: The list of results containing up to X results, where X is the page size defined in the request + profileFilters: + description: Profile filters that defined the cohort for this analysis. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + status: + description: Execution status of this analysis (e.g., running, completed, failed). + enum: + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED type: string - title: Export Service List Response + x-speakeasy-unknown-values: allow + suggestionsGenerated: + description: Number of role suggestions generated. + format: int32 + type: integer + title: Custom Analysis Result View type: object - x-speakeasy-name-override: ExportServiceListResponse - c1.api.systemlog.v1.ExportServiceUpdateRequestInput: - description: The ExportServiceUpdateRequest message. + x-speakeasy-name-override: CustomAnalysisResultView + c1.api.role_mining_management.v1.EntitlementRef: + description: EntitlementRef identifies an entitlement by app and entitlement ID. properties: - exporter: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - updateMask: - nullable: true - readOnly: false + appId: + description: The appId field. type: string - title: Export Service Update Request + entitlementId: + description: The entitlementId field. + type: string + title: Entitlement Ref type: object - x-speakeasy-name-override: ExportServiceUpdateRequest - c1.api.systemlog.v1.ExportServiceUpdateResponse: - description: The ExportServiceUpdateResponse message. - properties: - exporter: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - title: Export Service Update Response - type: object - x-speakeasy-name-override: ExportServiceUpdateResponse - c1.api.systemlog.v1.ExportToDatasource: - description: The ExportToDatasource message. - nullable: true + x-speakeasy-name-override: EntitlementRef + c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse: + description: The GetCustomAnalysisResultResponse message. properties: - datasourceId: - description: The datasourceId field. - readOnly: false + appsAnalyzed: + description: The appsAnalyzed field. + format: int32 + type: integer + clusters: + description: Cluster results. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.EntitlementCluster' + type: + - array + - "null" + cohortSize: + description: The cohortSize field. + format: int32 + type: integer + entitlements: + description: Entitlement coverage results. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + errorMessage: + description: The errorMessage field. type: string - format: - description: The format field. + facetUserCount: + description: The facetUserCount field. + format: int32 + type: integer + facets: + description: Facet results. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeFacet' + type: + - array + - "null" + id: + description: The id field. + type: string + status: + description: The status field. enum: - - EXPORT_FORMAT_UNSPECIFIED - - EXPORT_FORMAT_OCSF_JSON_ZSTD - - EXPORT_FORMAT_OCSF_JSON_GZIP - readOnly: false + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED type: string x-speakeasy-unknown-values: allow - prefix: - description: The prefix field. - readOnly: false + title: Get Custom Analysis Result Response + type: object + x-speakeasy-name-override: GetCustomAnalysisResultResponse + c1.api.role_mining_management.v1.GetLatestRunResponse: + description: The GetLatestRunResponse message. + properties: + run: + oneOf: + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' + - type: "null" + title: Get Latest Run Response + type: object + x-speakeasy-name-override: GetLatestRunResponse + c1.api.role_mining_management.v1.GetRoleMiningConfigResponse: + description: The GetRoleMiningConfigResponse message. + properties: + config: + oneOf: + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' + - type: "null" + title: Get Role Mining Config Response + type: object + x-speakeasy-name-override: GetRoleMiningConfigResponse + c1.api.role_mining_management.v1.GetSuggestionResponse: + description: The GetSuggestionResponse message. + properties: + suggestion: + oneOf: + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + - type: "null" + title: Get Suggestion Response + type: object + x-speakeasy-name-override: GetSuggestionResponse + c1.api.role_mining_management.v1.ListCustomAnalysisResultsResponse: + description: The ListCustomAnalysisResultsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CustomAnalysisResultView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Export To Datasource + title: List Custom Analysis Results Response type: object - x-speakeasy-name-override: ExportToDatasource - c1.api.systemlog.v1.Exporter: - description: | - The Exporter message. - - This message contains a oneof named export_to. Only a single field of the following list may be set at a time: - - datasource + x-speakeasy-name-override: ListCustomAnalysisResultsResponse + c1.api.role_mining_management.v1.ListRunsResponse: + description: The ListRunsResponse message. + properties: + list: + description: The list of role mining analysis runs. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementRun' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty if no more results. + type: string + title: List Runs Response + type: object + x-speakeasy-name-override: ListRunsResponse + c1.api.role_mining_management.v1.ListSuggestionsResponse: + description: The ListSuggestionsResponse message. + properties: + list: + description: The list of role mining suggestions. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results, empty if no more results. + type: string + title: List Suggestions Response + type: object + x-speakeasy-name-override: ListSuggestionsResponse + c1.api.role_mining_management.v1.RoleMiningManagementConfig: + description: The RoleMiningManagementConfig message. + properties: + cohortHints: + description: Configured cohort hints that guide which user attributes the analysis prioritizes. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintView' + type: + - array + - "null" + maxSuggestions: + description: Maximum number of suggestions the analysis will produce per run. + format: int32 + type: integer + minCohortSize: + description: Minimum number of users a cohort must contain to generate a suggestion. + format: int32 + type: integer + title: Role Mining Management Config + type: object + x-speakeasy-name-override: RoleMiningManagementConfig + c1.api.role_mining_management.v1.RoleMiningManagementRun: + description: The RoleMiningManagementRun message. properties: + cohortsAnalyzed: + description: Number of user cohorts evaluated during the analysis. + format: int32 + type: integer + completedAt: + format: date-time + type: + - string + - "null" createdAt: format: date-time - readOnly: true + type: + - string + - "null" + errorMessage: + description: Error message if the run failed, empty on success. type: string - datasource: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' - deletedAt: - format: date-time - readOnly: true + id: + description: Unique identifier for this analysis run. type: string - displayName: - description: The displayName field. - readOnly: false + status: + description: Current execution status of this run (e.g., running, completed, failed). + enum: + - RUN_STATUS_UNSPECIFIED + - RUN_STATUS_RUNNING + - RUN_STATUS_COMPLETED + - RUN_STATUS_FAILED type: string - exportId: - description: The exportId field. - readOnly: true + x-speakeasy-unknown-values: allow + suggestionsGenerated: + description: Number of role suggestions produced by this run. + format: int32 + type: integer + totalUsers: + description: Total number of users evaluated during the analysis. + format: int32 + type: integer + triggerDetail: + description: Additional detail about the trigger, such as the user or schedule that initiated the run. type: string - state: - description: The state field. + triggerType: + description: How this run was initiated (e.g., manual, scheduled). enum: - - EXPORT_STATE_UNSPECIFIED - - EXPORT_STATE_EXPORTING - - EXPORT_STATE_WAITING - - EXPORT_STATE_ERROR - readOnly: true + - TRIGGER_TYPE_UNSPECIFIED + - TRIGGER_TYPE_MANUAL + - TRIGGER_TYPE_UPLIFT_COMPLETION + - TRIGGER_TYPE_SCHEDULED + - TRIGGER_TYPE_DIRECTORY_MERGE type: string x-speakeasy-unknown-values: allow updatedAt: format: date-time - readOnly: true - type: string - watermarkEventId: - description: we've synchorized this far - readOnly: true - type: string - title: Exporter + type: + - string + - "null" + title: Role Mining Management Run type: object - x-speakeasy-name-override: Exporter - c1.api.systemlog.v1.ExporterRef: - description: The ExporterRef message. + x-speakeasy-name-override: RoleMiningManagementRun + c1.api.role_mining_management.v1.RoleMiningManagementSuggestion: + description: The RoleMiningManagementSuggestion message. properties: - exportId: - description: The exportId field. - readOnly: false + avgCoverage: + description: Average fraction of suggested entitlements held by each user in the cohort. + type: number + cohortFilters: + description: The profile filters that define which users belong to this cohort. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + cohortSize: + description: Total number of users in the cohort matching the profile filters. + format: int32 + type: integer + confidence: + description: Overall confidence score for this suggestion, from 0.0 to 1.0. + type: number + createdAt: + format: date-time + type: + - string + - "null" + createdCatalogId: + description: The ID of the access profile created when this suggestion was accepted, empty if not yet accepted. type: string - title: Exporter Ref + description: + description: A human-readable description of the proposed role and the cohort it serves. + type: string + dimensionCount: + description: Number of distinct attribute dimensions used to define the cohort. + format: int32 + type: integer + entitlements: + description: The entitlements that are commonly held by users in this cohort. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + existingProfileMatches: + description: Existing access profiles that overlap with this suggestion. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AccessProfileMatch' + type: + - array + - "null" + id: + description: Unique identifier for this suggestion. + type: string + insights: + description: Human-readable insights explaining why this role was suggested. + items: + type: string + type: + - array + - "null" + lastGeneratedAt: + format: date-time + type: + - string + - "null" + runId: + description: The ID of the analysis run that produced this suggestion. + type: string + suggestedName: + description: The suggested display name for the proposed role. + type: string + suggestionState: + description: Current workflow state of this suggestion (e.g., pending, accepted, dismissed). + enum: + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + type: + - string + - "null" + usersWithAll: + description: Number of users in the cohort that hold all of the suggested entitlements. + format: int32 + type: integer + title: Role Mining Management Suggestion type: object - x-speakeasy-name-override: ExporterRef - c1.api.systemlog.v1.ExportsSearchServiceSearchRequest: - description: ExportsSearchServiceSearchRequest is the request for searching system log exports. + x-speakeasy-name-override: RoleMiningManagementSuggestion + c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest: + description: The RoleMiningSearchSuggestionsRequest message. properties: - displayName: - description: Search for system log exporters with a case insensitive match on the display name. - readOnly: false - type: string + cohortTypes: + description: Filter by cohort type (e.g. "department", "job_title", "manager"). + items: + type: string + type: + - array + - "null" + matchTypes: + description: Filter by match type against existing access profiles. + items: + enum: + - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED + - ACCESS_PROFILE_MATCH_TYPE_EXACT + - ACCESS_PROFILE_MATCH_TYPE_SUPERSET + - ACCESS_PROFILE_MATCH_TYPE_PARTIAL + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" pageSize: - description: The pageSize field. + description: Maximum number of suggestions to return per page. format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: Pagination token from a previous response. type: string query: - description: The query field. - readOnly: false + description: Text search — matches against suggested_name, description, and cohort filter values. type: string - refs: - description: The refs field. + states: + description: Filter by suggestion state. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExporterRef' - nullable: true - readOnly: false - type: array - title: Exports Search Service Search Request + enum: + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Role Mining Search Suggestions Request type: object - x-speakeasy-name-override: ExportsSearchServiceSearchRequest - c1.api.systemlog.v1.ExportsSearchServiceSearchResponse: - description: ExportsSearchServiceSearchResponse is the response for searching system log exports. + x-speakeasy-name-override: RoleMiningSearchSuggestionsRequest + c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse: + description: The RoleMiningSearchSuggestionsResponse message. properties: list: - description: The list of system log exports matching the search criteria. + description: The list of matching role mining suggestions. items: - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + type: + - array + - "null" nextPageToken: - description: The token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + description: Token to retrieve the next page of results, empty if no more results. type: string - title: Exports Search Service Search Response + title: Role Mining Search Suggestions Response type: object - x-speakeasy-name-override: ExportsSearchServiceSearchResponse - c1.api.systemlog.v1.SystemLogServiceListEventsRequest: - description: The SystemLogServiceListEventsRequest message. + x-speakeasy-name-override: RoleMiningSearchSuggestionsResponse + c1.api.role_mining_management.v1.SearchCohortUsersRequestInput: + description: The SearchCohortUsersRequest message. properties: pageSize: - description: The pageSize field. + description: Maximum number of users to return per page. format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false - type: string - since: - format: date-time - readOnly: false - type: string - sinceEventUid: - description: The sinceEventUid field. - readOnly: false - type: string - sortDirection: - description: The sortDirection field. - enum: - - SORT_DIRECTION_UNSPECIFIED - - SORT_DIRECTION_ASC - - SORT_DIRECTION_DESC - readOnly: false - type: string - x-speakeasy-unknown-values: allow - until: - format: date-time - readOnly: false - type: string - untilEventUid: - description: The untilEventUid field. - readOnly: false + description: Pagination token from a previous response. type: string - title: System Log Service List Events Request + profileFilters: + description: Additional profile filters to narrow the cohort user search. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + selectedEntitlements: + description: Optional list of entitlements to compute per-user coverage for. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.EntitlementRef' + type: + - array + - "null" + title: Search Cohort Users Request type: object - x-speakeasy-name-override: SystemLogServiceListEventsRequest - c1.api.systemlog.v1.SystemLogServiceListEventsResponse: - description: The SystemLogServiceListEventsResponse message. + x-speakeasy-name-override: SearchCohortUsersRequest + c1.api.role_mining_management.v1.SearchCohortUsersResponse: + description: The SearchCohortUsersResponse message. properties: list: - description: List contains an array of JSON OCSF events. + description: The list of users matching the cohort and optional filters. items: - additionalProperties: true - readOnly: false - type: object - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" nextPageToken: - description: The nextPageToken field. - readOnly: false + description: Token to retrieve the next page of results, empty if no more results. type: string - title: System Log Service List Events Response + usersWithCoverage: + description: Per-user coverage counts, populated when selected_entitlements is non-empty. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortUserWithCoverage' + type: + - array + - "null" + title: Search Cohort Users Response type: object - x-speakeasy-name-override: SystemLogServiceListEventsResponse - c1.api.task.v1.ActionInstance: - description: | - ActionInstance is the API mirror of the internal immutable snapshot of an - Action captured on a TaskTypeAction at ticket-creation time. - - This message contains a oneof named target_ref. Only a single field of the following list may be set at a time: - - connectorActionRef + x-speakeasy-name-override: SearchCohortUsersResponse + c1.api.role_mining_management.v1.TriggerAnalysisRequest: + description: The TriggerAnalysisRequest message. + title: Trigger Analysis Request + type: object + x-speakeasy-name-override: TriggerAnalysisRequest + c1.api.role_mining_management.v1.TriggerAnalysisResponse: + description: The TriggerAnalysisResponse message. properties: - connectorActionRef: - $ref: '#/components/schemas/c1.api.task.v1.ConnectorActionRef' - displayName: - description: |- - Display label at ticket-creation time. Same value as - TaskTypeAction.display_name; repeated here so clients that walk the - instance see a self-contained view. - readOnly: true + runId: + description: The ID of the newly created analysis run. type: string - title: Action Instance + title: Trigger Analysis Response type: object - x-speakeasy-name-override: TaskActionInstance - c1.api.task.v1.ConnectorActionRef: - description: |- - ConnectorActionRef describes dispatch through a connector's built-in - GrantManagerService Grant / Revoke RPC — i.e. the default connector - operation, used for synthesized tickets like scope-role requests. - nullable: true + x-speakeasy-name-override: TriggerAnalysisResponse + c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest: + description: The TriggerCustomAnalysisRequest message. properties: - appId: - description: The app whose connector handles the operation. - readOnly: true + profileFilters: + description: The profileFilters field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.ProfileFilter' + type: + - array + - "null" + title: Trigger Custom Analysis Request + type: object + x-speakeasy-name-override: TriggerCustomAnalysisRequest + c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse: + description: The TriggerCustomAnalysisResponse message. + properties: + id: + description: The id field. type: string - connectorId: - description: The connector that will execute the Grant / Revoke. - readOnly: true + title: Trigger Custom Analysis Response + type: object + x-speakeasy-name-override: TriggerCustomAnalysisResponse + c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest: + description: The UpdateRoleMiningConfigRequest message. + properties: + cohortHints: + description: Hints that guide the analysis to prioritize specific user attributes and values when forming cohorts. + items: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CohortHintInput' + type: + - array + - "null" + maxSuggestions: + description: Maximum number of suggestions the analysis should produce per run. + format: int32 + type: integer + minCohortSize: + description: Minimum number of users a cohort must contain to generate a suggestion. + format: int32 + type: integer + title: Update Role Mining Config Request + type: object + x-speakeasy-name-override: UpdateRoleMiningConfigRequest + c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse: + description: The UpdateRoleMiningConfigResponse message. + properties: + config: + oneOf: + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementConfig' + - type: "null" + title: Update Role Mining Config Response + type: object + x-speakeasy-name-override: UpdateRoleMiningConfigResponse + c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput: + description: The UpdateSuggestionStateRequest message. + properties: + createdCatalogId: + description: The ID of the access profile created from this suggestion, set when accepting. type: string - operation: - description: Which connector RPC this dispatches to. + state: + description: The new state to transition the suggestion to. enum: - - OPERATION_UNSPECIFIED - - OPERATION_GRANT - readOnly: true + - SUGGESTION_STATE_UNSPECIFIED + - SUGGESTION_STATE_NEW + - SUGGESTION_STATE_DISMISSED + - SUGGESTION_STATE_ACCEPTED type: string x-speakeasy-unknown-values: allow - title: Connector Action Ref + title: Update Suggestion State Request type: object - x-speakeasy-name-override: ConnectorActionRef - c1.api.task.v1.ExternalRef: - description: A reference to an external source. This value is unused currently, but may be brought back. + x-speakeasy-name-override: UpdateSuggestionStateRequest + c1.api.role_mining_management.v1.UpdateSuggestionStateResponse: + description: The UpdateSuggestionStateResponse message. properties: - externalRefSource: - description: The source of the external reference. - enum: - - UNSPECIFIED - - JIRA - readOnly: true + suggestion: + oneOf: + - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningManagementSuggestion' + - type: "null" + title: Update Suggestion State Response + type: object + x-speakeasy-name-override: UpdateSuggestionStateResponse + c1.api.search.v1.FacetCategory: + description: | + The FacetCategory indicates a grouping of facets by type. For example, facets "OnePassword" and "Okta" would group under an "Apps" category. + + This message contains a oneof named item. Only a single field of the following list may be set at a time: + - value + - range + properties: + displayName: + description: The display name of the category. type: string - x-speakeasy-unknown-values: allow - name: - description: The name of the external reference. - readOnly: true + iconUrl: + description: An icon for the category. type: string - url: - description: The URL to the external reference. - readOnly: true + param: + description: The param that is being set when checking a facet in this category. type: string - title: External Ref + range: + oneOf: + - $ref: '#/components/schemas/c1.api.search.v1.FacetRangeItem' + - type: "null" + value: + oneOf: + - $ref: '#/components/schemas/c1.api.search.v1.FacetValueItem' + - type: "null" + title: Facet Category type: object - x-speakeasy-name-override: ExternalRef - c1.api.task.v1.ScopeRole: - description: |- - Scope-role variant of TaskTypeAction.target_object. The UI uses the - embedded identifiers to build links and title strings without a separate - Action fetch. - nullable: true + x-speakeasy-name-override: FacetCategory + c1.api.search.v1.FacetRange: + description: The FacetRange message. properties: - appId: - description: The IaaS/sparse-ACL app the (scope, role) pair lives on. - readOnly: true + count: + description: The count of items in the range. + format: int64 type: string - grantDuration: - format: duration - readOnly: true + displayName: + description: The display name of the range. type: string - roleResourceId: - description: The roleResourceId field. - readOnly: true + from: + description: The starting value of the range. + format: int64 type: string - roleResourceTypeId: - description: The roleResourceTypeId field. - readOnly: true + iconUrl: + description: The icon of the range. type: string - scopeResourceId: - description: The scopeResourceId field. - readOnly: true + to: + description: The ending value of the range. + format: int64 type: string - scopeResourceTypeId: - description: The scopeResourceTypeId field. - readOnly: true + title: Facet Range + type: object + x-speakeasy-name-override: FacetRange + c1.api.search.v1.FacetRangeItem: + description: The FacetRangeItem message. + properties: + ranges: + description: An array of facet ranges. + items: + $ref: '#/components/schemas/c1.api.search.v1.FacetRange' + type: + - array + - "null" + title: Facet Range Item + type: object + x-speakeasy-name-override: FacetRangeItem + c1.api.search.v1.FacetValue: + description: A FacetValue message contains count and value of the facet entry. + properties: + count: + description: The count of the values in this facet. + format: int64 type: string - title: Scope Role + displayName: + description: The name of this facet. + type: string + iconUrl: + description: The icon for this facet. + type: string + value: + description: The value of this facet. + type: string + title: Facet Value type: object - x-speakeasy-name-override: ScopeRole - c1.api.task.v1.Task: - description: A fully-fleged task object. Includes its policy, references to external apps, its type, its processing history, and more. + x-speakeasy-name-override: FacetValue + c1.api.search.v1.FacetValueItem: + description: The FacetValueItem message. properties: - actions: - description: The actions that can be performed on the task by the current user. + values: + description: An array of facet values. items: - enum: - - TASK_ACTION_TYPE_UNSPECIFIED - - TASK_ACTION_TYPE_CLOSE - - TASK_ACTION_TYPE_APPROVE - - TASK_ACTION_TYPE_DENY - - TASK_ACTION_TYPE_COMMENT - - TASK_ACTION_TYPE_DELETE - - TASK_ACTION_TYPE_REASSIGN - - TASK_ACTION_TYPE_RESTART - - TASK_ACTION_TYPE_SEND_REMINDER - - TASK_ACTION_TYPE_PROVISION_COMPLETE - - TASK_ACTION_TYPE_PROVISION_CANCELLED - - TASK_ACTION_TYPE_PROVISION_ERRORED - - TASK_ACTION_TYPE_ROLLBACK_SKIPPED - - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED - - TASK_ACTION_TYPE_HARD_RESET - - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS - - TASK_ACTION_TYPE_CHANGE_POLICY - - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS - - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION - - TASK_ACTION_TYPE_SET_ANALYSIS_ID - - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST - - TASK_ACTION_TYPE_PROCESS_NOW - - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP - - TASK_ACTION_TYPE_SKIP_STEP - - TASK_ACTION_TYPE_ROLLBACK_CANCELLED - - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA - - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: true - type: array - analysisId: - description: The ID of the analysis object associated with this task created by an analysis workflow if the analysis feature is enabled for your tenant. - readOnly: true + $ref: '#/components/schemas/c1.api.search.v1.FacetValue' + type: + - array + - "null" + title: Facet Value Item + type: object + x-speakeasy-name-override: FacetValueItem + c1.api.search.v1.Facets: + description: Indicates one value of a facet. + properties: + count: + description: The count of items in this facet. + format: int64 type: string - annotations: - description: An array of `google.protobuf.Any` annotations with various base64-encoded data. + facets: + description: The facet being referenced. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - approverIds: - description: An array of IDs belonging to Identity Users that have approved or denied any step in this task. + $ref: '#/components/schemas/c1.api.search.v1.FacetCategory' + type: + - array + - "null" + title: Facets + type: object + x-speakeasy-name-override: Facets + c1.api.secrets.v1.PaperSecret: + description: |- + PaperSecret is the API view of a secret (combines Vault + PaperVault fields). + The vault_id is the primary identifier (Vault.id). + properties: + ageSuite: + description: Exact Age suite used by the stored ciphertext. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + allowedEmails: + description: The allowedEmails field. items: type: string - nullable: true - readOnly: true - type: array - commentCount: - description: The count of comments. - format: int32 - readOnly: true - type: integer - createdAt: + type: + - array + - "null" + allowedUserIds: + description: Access control + items: + type: string + type: + - array + - "null" + contentDeleted: + description: The contentDeleted field. + type: boolean + contentExpiresAt: format: date-time - readOnly: true + type: + - string + - "null" + contentReady: + description: Whether content has been set (text uploaded or file uploaded) + type: boolean + contentType: + description: The contentType field. type: string - createdByUserId: - description: The ID of the user that is the creator of this task. This may not always match the userId field. + createdAt: + format: date-time readOnly: true + type: + - string + - "null" + creatorUserId: + description: Creator type: string - data: - additionalProperties: true - readOnly: true - type: object + currentViews: + description: The currentViews field. + format: uint32 + type: integer deletedAt: format: date-time readOnly: true - type: string - description: - description: The description of the task. This is also known as justification. - readOnly: true - type: string + type: + - string + - "null" displayName: - description: The display name of the task. - readOnly: true - type: string - emergencyAccess: - description: A field indicating whether this task was created using an emergency access flow, or escalated to emergency access. On task creation, it will also use the app entitlement's emergency policy when possible. - readOnly: true - type: boolean - externalRefs: - description: An array of external references to the task. Historically that has been items like Jira task IDs. This is currently unused, but may come back in the future for integrations. - items: - $ref: '#/components/schemas/c1.api.task.v1.ExternalRef' - nullable: true - readOnly: true - type: array - form: - $ref: '#/components/schemas/c1.api.form.v1.Form' - id: - description: The ID of the task. - readOnly: true + description: From Vault type: string - insightIds: - description: The insightIds field. - items: - type: string - nullable: true - readOnly: false - type: array - numericId: - description: A human-usable numeric ID of a task which can be included in place of the fully qualified task id in path parmeters (but not search queries). + fileSize: + description: File metadata format: int64 - readOnly: true - type: string - origin: - description: The origin field. - enum: - - TASK_ORIGIN_UNSPECIFIED - - TASK_ORIGIN_PROFILE_MEMBERSHIP_AUTOMATION - - TASK_ORIGIN_SLACK - - TASK_ORIGIN_API - - TASK_ORIGIN_JIRA - - TASK_ORIGIN_COPILOT - - TASK_ORIGIN_WEBAPP - - TASK_ORIGIN_TIME_REVOKE - - TASK_ORIGIN_NON_USAGE_REVOKE - - TASK_ORIGIN_PROFILE_MEMBERSHIP_MANUAL - - TASK_ORIGIN_PROFILE_MEMBERSHIP - - TASK_ORIGIN_AUTOMATION - - TASK_ORIGIN_ACCESS_REVIEW - - TASK_ORIGIN_CASCADE_DELETE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - policy: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyInstance' - policyGenerationId: - description: The policy generation id refers to the current policy's generation ID. This is changed when the policy is changed on a task. - readOnly: true type: string - processing: - description: The processing state of a task as defined by the `processing_enum` - enum: - - TASK_PROCESSING_TYPE_UNSPECIFIED - - TASK_PROCESSING_TYPE_PROCESSING - - TASK_PROCESSING_TYPE_WAITING - - TASK_PROCESSING_TYPE_DONE - readOnly: true + filename: + description: 'For FILE secrets: original filename (sanitized)' type: string - x-speakeasy-unknown-values: allow - recommendation: - description: The recommendation field. + inputFormat: + description: The inputFormat field. enum: - - INSIGHT_RECOMMENDATION_UNSPECIFIED - - INSIGHT_RECOMMENDATION_APPROVE - - INSIGHT_RECOMMENDATION_DENY - - INSIGHT_RECOMMENDATION_REVIEW - readOnly: false + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE type: string x-speakeasy-unknown-values: allow - revocationTargets: - description: |- - Ancestor entitlements that will also be revoked when this revoke task is approved. - Populated at ticket creation time for inherited grant revocations. - items: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevocationTarget' - nullable: true - readOnly: true - type: array - state: - description: The current state of the task as defined by the `state_enum` + maxViews: + description: View tracking + format: uint32 + type: integer + secretType: + description: The secretType field. enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED - readOnly: true + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE type: string x-speakeasy-unknown-values: allow - stepApproverIds: - description: An array of IDs belonging to Identity Users that are allowed to review this step in a task. - items: - type: string - nullable: true - readOnly: true - type: array - type: - $ref: '#/components/schemas/c1.api.task.v1.TaskType' - updatedAt: - format: date-time - readOnly: true + shareCode: + description: Human-friendly share code (XXXX-XXXX-XXXX) for shareable URLs type: string - userId: - description: The ID of the user that is the target of this task. This may be empty if we're targeting a specific app user that has no known identity user. - readOnly: true + shareUrl: + description: URL to share with recipients (populated when content_ready is true) type: string - title: Task - type: object - x-speakeasy-name-override: Task - c1.api.task.v1.TaskAction: - description: Represents a single action that was performed on a task. - properties: - actionType: - description: The type of action that was performed. + sharingMode: + description: From PaperVault enum: - - TASK_ACTION_TYPE_UNSPECIFIED - - TASK_ACTION_TYPE_CLOSE - - TASK_ACTION_TYPE_APPROVE - - TASK_ACTION_TYPE_DENY - - TASK_ACTION_TYPE_COMMENT - - TASK_ACTION_TYPE_DELETE - - TASK_ACTION_TYPE_REASSIGN - - TASK_ACTION_TYPE_RESTART - - TASK_ACTION_TYPE_SEND_REMINDER - - TASK_ACTION_TYPE_PROVISION_COMPLETE - - TASK_ACTION_TYPE_PROVISION_CANCELLED - - TASK_ACTION_TYPE_PROVISION_ERRORED - - TASK_ACTION_TYPE_ROLLBACK_SKIPPED - - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED - - TASK_ACTION_TYPE_HARD_RESET - - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS - - TASK_ACTION_TYPE_CHANGE_POLICY - - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS - - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION - - TASK_ACTION_TYPE_SET_ANALYSIS_ID - - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST - - TASK_ACTION_TYPE_PROCESS_NOW - - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP - - TASK_ACTION_TYPE_SKIP_STEP - - TASK_ACTION_TYPE_ROLLBACK_CANCELLED - - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA - - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION - readOnly: false + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL type: string x-speakeasy-unknown-values: allow - bulkActionId: - description: The ID of the bulk action this action belongs to, if it was part of a bulk operation. - readOnly: false - type: string - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time - readOnly: true - type: string - id: - description: The unique ID of this action. - readOnly: false - type: string - policyStepId: - description: The ID of the policy step this action was performed on. - readOnly: false + status: + description: Computed status + enum: + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED type: string + x-speakeasy-unknown-values: allow updatedAt: format: date-time readOnly: true + type: + - string + - "null" + vaultId: + description: Vault.id - primary identifier for the secret type: string - userId: - description: The ID of the user who performed the action. - readOnly: false - type: string - title: Task Action + title: Paper Secret type: object - x-speakeasy-name-override: SubmittedTaskAction - c1.api.task.v1.TaskActionsServiceApproveRequestInput: - description: The TaskActionsServiceApproveRequest object lets you approve a task. + x-speakeasy-name-override: PaperSecret + c1.api.secrets.v1.PaperSecretAdminServiceGetResponse: + description: The PaperSecretAdminServiceGetResponse message. properties: - comment: - description: The comment attached to the request. - readOnly: false - type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: The ID of the policy step on the given task to approve. - readOnly: false - type: string - required: - - policyStepId - title: Task Actions Service Approve Request + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + title: Paper Secret Admin Service Get Response type: object - x-speakeasy-name-override: TaskActionsServiceApproveRequest - c1.api.task.v1.TaskActionsServiceApproveResponse: - description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: PaperSecretAdminServiceGetResponse + c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput: + description: The PaperSecretAdminServiceRevokeRequest message. + title: Paper Secret Admin Service Revoke Request + type: object + x-speakeasy-name-override: PaperSecretAdminServiceRevokeRequest + c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse: + description: The PaperSecretAdminServiceRevokeResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task approve action created by this request. - readOnly: true - type: string - title: Task Actions Service Approve Response + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + title: Paper Secret Admin Service Revoke Response type: object - x-speakeasy-name-override: TaskActionsServiceApproveResponse - c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput: - description: TaskActionsServiceApproveWithStepUpRequest is used to approve a task with step-up authentication + x-speakeasy-name-override: PaperSecretAdminServiceRevokeResponse + c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest: + description: The PaperSecretAdminServiceSearchAuditEventsRequest message. properties: - comment: - description: The comment attached to the request. - readOnly: false + actorEmail: + description: Filter by external email (partial match via full-text search) type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: The ID of the policy step on the given task to approve. - readOnly: false + actorUserId: + description: Filter by C1 user ID (internal users) type: string - stepUpTransactionId: - description: |- - The step-up transaction ID that was verified. - If unset, the response will include a redirect URL to - complete the step-up authentication. - readOnly: false + clientIp: + description: Filter by client IP (exact match) type: string - required: - - policyStepId - - stepUpTransactionId - title: Task Actions Service Approve With Step Up Request + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + vaultId: + description: Filter by specific vault + type: string + title: Paper Secret Admin Service Search Audit Events Request type: object - x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpRequest - c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse: - description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication + x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsRequest + c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse: + description: The PaperSecretAdminServiceSearchAuditEventsResponse message. properties: - expanded: - description: List of serialized related objects. + list: + description: |- + List contains OCSF events directly as JSON structs. + Follows the same pattern as SystemLogServiceListEventsResponse. items: additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true type: object - nullable: true - readOnly: true - type: array - redirectUrl: - description: The redirect URL the client must visit to complete the step-up authentication. - readOnly: false - type: string - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task approve action created by this request. - readOnly: true + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Task Actions Service Approve With Step Up Response + title: Paper Secret Admin Service Search Audit Events Response type: object - x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpResponse - c1.api.task.v1.TaskActionsServiceCloseRequestInput: - description: The TaskActionsServiceCloseRequest object lets you close or cancel a task. + x-speakeasy-name-override: PaperSecretAdminServiceSearchAuditEventsResponse + c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest: + description: Admin search request - can filter by any user's secrets. properties: - comment: - description: An optional comment attached to the close action. - readOnly: false - type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - title: Task Actions Service Close Request - type: object - x-speakeasy-name-override: TaskActionsServiceCloseRequest - c1.api.task.v1.TaskActionsServiceCloseResponse: - description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. - properties: - expanded: - description: List of serialized related objects. + createdAfter: + format: date-time + type: + - string + - "null" + createdBefore: + format: date-time + type: + - string + - "null" + creatorUserIds: + description: Filter by creator user ID (admin can see all users' secrets) items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskActionId: - description: The ID of the task close action created by this request. - readOnly: true + type: string + type: + - array + - "null" + includeDeleted: + description: Include deleted secrets + type: boolean + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Actions Service Close Response - type: object - x-speakeasy-name-override: TaskActionsServiceCloseResponse - c1.api.task.v1.TaskActionsServiceCommentRequestInput: - description: The TaskActionsServiceCommentRequest object lets you create a new comment on a task. - properties: - comment: - description: The comment to be posted to the task. - readOnly: false + query: + description: Fuzzy search by display name type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - title: Task Actions Service Comment Request + secretType: + description: Filter by secret type (optional) + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + sharingMode: + description: Filter by sharing mode (optional) + enum: + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + sortBy: + description: Sort order + enum: + - SEARCH_SORT_BY_UNSPECIFIED + - SEARCH_SORT_BY_CREATED_DESC + - SEARCH_SORT_BY_CREATED_ASC + - SEARCH_SORT_BY_EXPIRES_ASC + - SEARCH_SORT_BY_NAME_ASC + type: string + x-speakeasy-unknown-values: allow + statuses: + description: Filter by status (optional) + items: + enum: + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Paper Secret Admin Service Search Request type: object - x-speakeasy-name-override: TaskActionsServiceCommentRequest - c1.api.task.v1.TaskActionsServiceCommentResponse: - description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. + x-speakeasy-name-override: PaperSecretAdminServiceSearchRequest + c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse: + description: The PaperSecretAdminServiceSearchResponse message. properties: - expanded: - description: List of serialized related objects. + list: + description: The list field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Actions Service Comment Response + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Paper Secret Admin Service Search Response type: object - x-speakeasy-name-override: TaskActionsServiceCommentResponse - c1.api.task.v1.TaskActionsServiceDenyRequestInput: - description: The TaskActionsServiceDenyRequest object lets you deny a task. + x-speakeasy-name-override: PaperSecretAdminServiceSearchResponse + c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest: + description: The PaperSecretServiceCreateExternalRequest message. properties: - comment: - description: The comment attached to the request. - readOnly: false + allowedEmails: + description: |- + External email addresses allowed to view this secret (1 to 64). + Recipients authenticate via email magic link or Google OAuth. + items: + type: string + type: + - array + - "null" + contentType: + description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: The ID of the current policy step. This is the step you want to deny. - readOnly: false + displayName: + description: |- + Optional cleartext label visible to the creator in "My Secrets" view. + Not encrypted — do not put sensitive data here. type: string - title: Task Actions Service Deny Request + expiresIn: + format: duration + type: + - string + - "null" + fileSize: + description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' + format: int64 + type: string + filename: + description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' + type: string + inputFormat: + description: |- + For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). + Used by the viewer UI for syntax highlighting. Does not affect encryption. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + maxViews: + description: Maximum number of views before the secret is burned (0 = unlimited). + format: uint32 + type: integer + requiredAgeSuite: + description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secretType: + description: |- + Secret type: TEXT or FILE. + TEXT secrets use SetTextContent to upload encrypted content (max 64KB). + FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + title: Paper Secret Service Create External Request type: object - x-speakeasy-name-override: TaskActionsServiceDenyRequest - c1.api.task.v1.TaskActionsServiceDenyResponse: - description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: PaperSecretServiceCreateExternalRequest + c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest: + description: The PaperSecretServiceCreateInternalRequest message. properties: - expanded: - description: List of serialized related objects. + allowedUserIds: + description: C1 User IDs allowed to view this secret (1 to 128). items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task deny action created by this request. - readOnly: true + type: string + type: + - array + - "null" + contentType: + description: 'For FILE secrets: MIME content type of the original file. Ignored for TEXT secrets.' type: string - title: Task Actions Service Deny Response - type: object - x-speakeasy-name-override: TaskActionsServiceDenyResponse - c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput: - description: The TaskActionsServiceEscalateToEmergencyAccessRequest object lets you escalate a task to the emergency access workflow. - properties: - comment: - description: An optional comment attached to the escalation. - readOnly: false + displayName: + description: |- + Optional cleartext label visible to the creator in "My Secrets" view. + Not encrypted — do not put sensitive data here. type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: The ID of the current policy step being escalated from. - readOnly: false + expiresIn: + format: duration + type: + - string + - "null" + fileSize: + description: 'For FILE secrets: expected file size in bytes (max 1GB). Ignored for TEXT secrets.' + format: int64 type: string - title: Task Actions Service Escalate To Emergency Access Request + filename: + description: 'For FILE secrets: original filename (sanitized server-side). Ignored for TEXT secrets.' + type: string + inputFormat: + description: |- + For TEXT secrets: hint about the plaintext format (e.g., JSON, YAML, key-value). + Used by the viewer UI for syntax highlighting. Does not affect encryption. + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + maxViews: + description: Maximum number of views before the secret is burned (0 = unlimited). + format: uint32 + type: integer + requiredAgeSuite: + description: Exact Age suite required for this submission. UNSPECIFIED preserves legacy X25519 behavior. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secretType: + description: |- + Secret type: TEXT or FILE. + TEXT secrets use SetTextContent to upload encrypted content (max 64KB). + FILE secrets use the upload_url from CreateResponse to upload encrypted content (max 1GB). + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + title: Paper Secret Service Create Internal Request type: object - x-speakeasy-name-override: TaskActionsServiceEscalateToEmergencyAccessRequest - c1.api.task.v1.TaskActionsServiceHardResetRequestInput: - description: The TaskActionsServiceHardResetRequest object lets you reset a task and recalculate its policy. + x-speakeasy-name-override: PaperSecretServiceCreateInternalRequest + c1.api.secrets.v1.PaperSecretServiceCreateResponse: + description: The PaperSecretServiceCreateResponse message. properties: - comment: - description: The comment attached to the request. - readOnly: false + ageRecipient: + description: |- + Canonical recipient public key for the exact age_suite returned below. + All content MUST be encrypted to this recipient using the Age encryption format + before calling SetTextContent or uploading to upload_url. + See: https://age-encryption.org type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - title: Task Actions Service Hard Reset Request + ageSuite: + description: Exact Age suite required for this submission. + enum: + - AGE_SUITE_UNSPECIFIED + - AGE_SUITE_X25519 + - AGE_SUITE_MLKEM768X25519 + type: string + x-speakeasy-unknown-values: allow + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + uploadUrl: + description: |- + For FILE secrets: capability URL for uploading the Age-encrypted file. + Send an HTTP PUT request with the Age-encrypted file bytes as the body + and Content-Type: application/octet-stream. The payload MUST begin with + the Age header "age-encryption.org/v1\n". Maximum file size: 1GB. + Empty for TEXT secrets. + type: string + vaultId: + description: Vault ID - primary identifier for this secret. + type: string + title: Paper Secret Service Create Response type: object - x-speakeasy-name-override: TaskActionsServiceHardResetRequest - c1.api.task.v1.TaskActionsServiceHardResetResponse: - description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. + x-speakeasy-name-override: PaperSecretServiceCreateResponse + c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput: + description: The PaperSecretServiceGetContentRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task reset action created by this request. - readOnly: false + readerRecipient: + description: |- + Client's ephemeral Age recipient (age1...) for re-encryption + Server re-encrypts the content to this recipient type: string - title: Task Actions Service Hard Reset Response + title: Paper Secret Service Get Content Request type: object - x-speakeasy-name-override: TaskActionsServiceHardResetResponse - c1.api.task.v1.TaskActionsServiceProcessNowRequestInput: - description: The TaskActionsServiceProcessNowRequest object lets you trigger processing of a task immediately. + x-speakeasy-name-override: PaperSecretServiceGetContentRequest + c1.api.secrets.v1.PaperSecretServiceGetContentResponse: + description: | + The PaperSecretServiceGetContentResponse message. + + This message contains a oneof named content. Only a single field of the following list may be set at a time: + - encryptedContent + - downloadUrl properties: - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - title: Task Actions Service Process Now Request + createdAt: + format: date-time + type: + - string + - "null" + creatorUserId: + description: The creatorUserId field. + type: string + downloadUrl: + description: |- + For file secrets: presigned S3 download URL (5 minute expiry) + File is still E2E encrypted - client must decrypt after download + This field is part of the `content` oneof. + See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. + type: + - string + - "null" + encryptedContent: + description: |- + For text secrets: Age-encrypted content (encrypted to reader's recipient) + This field is part of the `content` oneof. + See the documentation for `c1.api.secrets.v1.PaperSecretServiceGetContentResponse` for more details. + format: base64 + type: + - string + - "null" + filename: + description: Original filename (file secrets only) + type: string + inputFormat: + description: Input format hint for rendering (text secrets only) + enum: + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE + type: string + x-speakeasy-unknown-values: allow + secretType: + description: Secret metadata + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE + type: string + x-speakeasy-unknown-values: allow + viewsRemaining: + description: Views remaining after this view (-1 = unlimited) + format: int32 + type: integer + title: Paper Secret Service Get Content Response type: object - x-speakeasy-name-override: TaskActionsServiceProcessNowRequest - c1.api.task.v1.TaskActionsServiceProcessNowResponse: - description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. + x-speakeasy-name-override: PaperSecretServiceGetContentResponse + c1.api.secrets.v1.PaperSecretServiceGetResponse: + description: The PaperSecretServiceGetResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Actions Service Process Now Response + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + title: Paper Secret Service Get Response type: object - x-speakeasy-name-override: TaskActionsServiceProcessNowResponse - c1.api.task.v1.TaskActionsServiceReassignRequestInput: - description: The TaskActionsServiceReassignRequest object lets you reassign a task's current policy step to different users. - properties: - comment: - description: An optional comment attached to the reassignment. - readOnly: false - type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - newStepUserIds: - description: The IDs of the users to reassign the current policy step to. Must be from the allowed reassignees list. - items: - type: string - nullable: true - readOnly: false - type: array - policyStepId: - description: The ID of the current policy step to reassign. Must match the task's active step. - readOnly: false - type: string - title: Task Actions Service Reassign Request + x-speakeasy-name-override: PaperSecretServiceGetResponse + c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput: + description: The PaperSecretServiceRevokeRequest message. + title: Paper Secret Service Revoke Request type: object - x-speakeasy-name-override: TaskActionsServiceReassignRequest - c1.api.task.v1.TaskActionsServiceReassignResponse: - description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. + x-speakeasy-name-override: PaperSecretServiceRevokeRequest + c1.api.secrets.v1.PaperSecretServiceRevokeResponse: + description: The PaperSecretServiceRevokeResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task reassign action created by this request. - readOnly: true - type: string - title: Task Actions Service Reassign Response + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + title: Paper Secret Service Revoke Response type: object - x-speakeasy-name-override: TaskActionsServiceReassignResponse - c1.api.task.v1.TaskActionsServiceRestartRequestInput: - description: The TaskActionsServiceRestartRequest object lets you restart a task. + x-speakeasy-name-override: PaperSecretServiceRevokeResponse + c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest: + description: |- + PaperSecretServiceSearchAuditEventsRequest searches audit events for a secret + owned by the calling user. Only the secret creator may query events. Results + are sanitized to include only time, event type, and actor information. properties: - comment: - description: The comment attached to the request. - readOnly: false + pageSize: + description: Maximum number of results per page (0 uses server default, max 100). + format: int32 + type: integer + pageToken: + description: Pagination token from a previous response's next_page_token. type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: Deprecated. This field is accepted but does not affect behavior. - readOnly: false + vaultId: + description: Required. The vault ID of the secret whose audit events to retrieve. type: string - title: Task Actions Service Restart Request + title: Paper Secret Service Search Audit Events Request type: object - x-speakeasy-name-override: TaskActionsServiceRestartRequest - c1.api.task.v1.TaskActionsServiceRestartResponse: - description: The TaskActionsServiceRestartResponse returns the updated task after restarting. + x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsRequest + c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse: + description: |- + PaperSecretServiceSearchAuditEventsResponse contains a page of audit events + for the requested secret. properties: - expanded: - description: List of serialized related objects. + list: + description: |- + Sanitized OCSF events containing only time, event type, and actor fields. + Sensitive fields such as IP addresses, messages, and raw payloads are removed. items: additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task restart action created by this request. - readOnly: false + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page of results. Empty when no more pages exist. type: string - title: Task Actions Service Restart Response + title: Paper Secret Service Search Audit Events Response type: object - x-speakeasy-name-override: TaskActionsServiceRestartResponse - c1.api.task.v1.TaskActionsServiceSkipStepRequestInput: - description: The TaskActionsServiceSkipStepRequest object lets you skip a policy step in a task. + x-speakeasy-name-override: PaperSecretServiceSearchAuditEventsResponse + c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest: + description: |- + SearchMySecrets request - for end users viewing their own secrets. + Automatically scoped to current user. properties: - comment: - description: The comment attached to the request. - readOnly: false + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - policyStepId: - description: The ID of the policy step to skip. - readOnly: false + query: + description: Fuzzy search by display name type: string - required: - - policyStepId - title: Task Actions Service Skip Step Request - type: object - x-speakeasy-name-override: TaskActionsServiceSkipStepRequest - c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput: - description: The TaskActionsServiceUpdateGrantDurationRequest object lets you change the grant duration on a grant task. - properties: - duration: - format: duration - readOnly: false + secretType: + description: Filter by secret type (optional) + enum: + - SECRET_TYPE_UNSPECIFIED + - SECRET_TYPE_TEXT + - SECRET_TYPE_FILE type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - required: - - duration - title: Task Actions Service Update Grant Duration Request + x-speakeasy-unknown-values: allow + sharingMode: + description: Filter by sharing mode (optional) + enum: + - PAPER_VAULT_SHARING_MODE_UNSPECIFIED + - PAPER_VAULT_SHARING_MODE_INTERNAL + - PAPER_VAULT_SHARING_MODE_EXTERNAL + type: string + x-speakeasy-unknown-values: allow + sortBy: + description: Sort order + enum: + - SEARCH_SORT_BY_UNSPECIFIED + - SEARCH_SORT_BY_CREATED_DESC + - SEARCH_SORT_BY_CREATED_ASC + - SEARCH_SORT_BY_EXPIRES_ASC + - SEARCH_SORT_BY_NAME_ASC + type: string + x-speakeasy-unknown-values: allow + statuses: + description: Filter by status (optional) + items: + enum: + - SECRET_STATUS_UNSPECIFIED + - SECRET_STATUS_ACTIVE + - SECRET_STATUS_EXPIRED + - SECRET_STATUS_BURNED + - SECRET_STATUS_REVOKED + - SECRET_STATUS_DATA_DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Paper Secret Service Search My Secrets Request type: object - x-speakeasy-name-override: TaskActionsServiceUpdateGrantDurationRequest - c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput: - description: The TaskActionsServiceUpdateRequestDataRequest object lets you submit form data for a task that is in a form policy step. + x-speakeasy-name-override: PaperSecretServiceSearchMySecretsRequest + c1.api.secrets.v1.PaperSecretServiceSearchResponse: + description: Search response for user's own secrets properties: - data: - additionalProperties: true - readOnly: false - type: object - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - title: Task Actions Service Update Request Data Request + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Paper Secret Service Search Response type: object - x-speakeasy-name-override: TaskActionsServiceUpdateRequestDataRequest - c1.api.task.v1.TaskAuditAccessRequestOutcome: - description: The TaskAuditAccessRequestOutcome message. - nullable: true + x-speakeasy-name-override: PaperSecretServiceSearchResponse + c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput: + description: The PaperSecretServiceSetTextContentRequest message. properties: - outcome: - description: The outcome field. + encryptedContent: + description: |- + Age-encrypted content bytes. The plaintext MUST be encrypted using the Age + encryption format to the age_recipient returned by CreateInternal/CreateExternal. + The resulting bytes begin with "age-encryption.org/v1\n" followed by the + encrypted payload. Maximum 64KB after encryption — for larger content, create + a FILE secret and use the upload_url instead. + format: base64 + type: string + inputFormat: + description: |- + Input format hint for the viewer UI when the secret is decrypted. + Does not affect encryption — this is metadata only. enum: - - ACCESS_REQUEST_OUTCOME_UNSPECIFIED - - ACCESS_REQUEST_OUTCOME_APPROVED - - ACCESS_REQUEST_OUTCOME_DENIED - - ACCESS_REQUEST_OUTCOME_ERROR - - ACCESS_REQUEST_OUTCOME_CANCELLED - readOnly: false + - SECRET_INPUT_FORMAT_UNSPECIFIED + - SECRET_INPUT_FORMAT_PLAINTEXT + - SECRET_INPUT_FORMAT_JSON + - SECRET_INPUT_FORMAT_YAML + - SECRET_INPUT_FORMAT_KEY_VALUE type: string x-speakeasy-unknown-values: allow - title: Task Audit Access Request Outcome + title: Paper Secret Service Set Text Content Request type: object - x-speakeasy-name-override: TaskAuditAccessRequestOutcome - c1.api.task.v1.TaskAuditAccountLifecycleActionCreated: - description: The TaskAuditAccountLifecycleActionCreated message. - nullable: true + x-speakeasy-name-override: PaperSecretServiceSetTextContentRequest + c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse: + description: The PaperSecretServiceSetTextContentResponse message. properties: - batonActionDisplayName: - description: The batonActionDisplayName field. - readOnly: false - type: string - batonActionInvocationId: - description: The batonActionInvocationId field. - readOnly: false - type: string - batonActionName: - description: The batonActionName field. - readOnly: false + secret: + oneOf: + - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret' + - type: "null" + title: Paper Secret Service Set Text Content Response + type: object + x-speakeasy-name-override: PaperSecretServiceSetTextContentResponse + c1.api.service_principal.v1.ServicePrincipal: + description: ServicePrincipal represents a tenant-managed non-human identity. + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the service principal. type: string - batonAppId: - description: The batonAppId field. - readOnly: false + id: + description: The unique user ID of the service principal. + readOnly: true type: string - batonConnectorId: - description: The batonConnectorId field. - readOnly: false + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Service Principal + type: object + x-speakeasy-name-override: ServicePrincipal + c1.api.service_principal.v1.ServicePrincipalBinding: + description: |- + ServicePrincipalBinding is one row in the binding store, naming a + subject's link to a single service principal. + properties: + createdAt: + format: date-time + type: + - string + - "null" + servicePrincipalId: + description: The servicePrincipalId field. type: string - title: Task Audit Account Lifecycle Action Created + updatedAt: + format: date-time + type: + - string + - "null" + title: Service Principal Binding type: object - x-speakeasy-name-override: TaskAuditAccountLifecycleActionCreated - c1.api.task.v1.TaskAuditAccountLifecycleActionFailed: - description: The TaskAuditAccountLifecycleActionFailed message. - nullable: true + x-speakeasy-name-override: ServicePrincipalBinding + c1.api.service_principal.v1.ServicePrincipalBindingSubject: + description: | + ServicePrincipalBindingSubject identifies the entity that is bound to a + service principal. Open-ended oneof so future subject kinds (workflows, + connectors, etc.) can be added without changing the RPC shape. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - functionId properties: - batonActionDisplayName: - description: The batonActionDisplayName field. - readOnly: false + functionId: + description: |- + Function ID. The function authenticates outbound c1-api calls as + user: instead of function:. + This field is part of the `kind` oneof. + See the documentation for `c1.api.service_principal.v1.ServicePrincipalBindingSubject` for more details. + type: + - string + - "null" + title: Service Principal Binding Subject + type: object + x-speakeasy-name-override: ServicePrincipalBindingSubject + c1.api.service_principal.v1.ServicePrincipalCredential: + description: ServicePrincipalCredential represents a client credential for a service principal. + properties: + allowSourceCidrs: + description: CIDR restrictions for this credential. + items: + type: string + readOnly: true + type: + - array + - "null" + clientId: + description: 'The full client ID in format: ${cutename}@${tenant}.${installation}/spc' + readOnly: true type: string - batonActionInvocationId: - description: The batonActionInvocationId field. - readOnly: false + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: The display name of the credential. type: string - batonActionName: - description: The batonActionName field. - readOnly: false + expiresAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The unique ID of the credential (cutename format). + readOnly: true type: string - batonAppId: - description: The batonAppId field. - readOnly: false + lastUsedAt: + format: date-time + readOnly: true + type: + - string + - "null" + requireDpop: + description: Whether DPoP proof-of-possession is required for this credential. + readOnly: true + type: boolean + scopedRoleIds: + description: Scoped role IDs for this credential (intersection with SP roles at token issuance). + items: + type: string + readOnly: true + type: + - array + - "null" + servicePrincipalId: + description: The service principal user ID this credential belongs to. + readOnly: true type: string - batonConnectorId: - description: The batonConnectorId field. - readOnly: false + title: Service Principal Credential + type: object + x-speakeasy-name-override: ServicePrincipalCredential + c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest: + description: The ServicePrincipalServiceAddBindingRequest message. + properties: + servicePrincipalId: + description: The servicePrincipalId field. type: string - error: - description: The error field. - readOnly: false + subject: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - type: "null" + title: Service Principal Service Add Binding Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceAddBindingRequest + c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse: + description: The ServicePrincipalServiceAddBindingResponse message. + title: Service Principal Service Add Binding Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceAddBindingResponse + c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput: + description: The ServicePrincipalServiceCreateCredentialRequest message. + properties: + allowSourceCidrs: + description: |- + A list of CIDRs to restrict this credential to. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + displayName: + description: The display name for the new credential. type: string - title: Task Audit Account Lifecycle Action Failed + expires: + format: duration + type: + - string + - "null" + requireDpop: + description: If true, requires DPoP proof-of-possession for token exchange using this credential. + type: boolean + scopedRoles: + description: The list of roles to restrict the credential to. + items: + type: string + type: + - array + - "null" + title: Service Principal Service Create Credential Request type: object - x-speakeasy-name-override: TaskAuditAccountLifecycleActionFailed - c1.api.task.v1.TaskAuditActionInstanceCreated: - description: The TaskAuditActionInstanceCreated message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse: + description: The ServicePrincipalServiceCreateCredentialResponse message. properties: - instance: - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - title: Task Audit Action Instance Created + clientSecret: + description: The client secret. Shown exactly once at creation -- cannot be retrieved again. + type: string + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - type: "null" + title: Service Principal Service Create Credential Response type: object - x-speakeasy-name-override: TaskAuditActionInstanceCreated - c1.api.task.v1.TaskAuditActionInstanceFailed: - description: The TaskAuditActionInstanceFailed message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceCreateCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest: + description: The ServicePrincipalServiceCreateRequest message. properties: - instance: - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - title: Task Audit Action Instance Failed + displayName: + description: The display name for the new service principal. + type: string + title: Service Principal Service Create Request type: object - x-speakeasy-name-override: TaskAuditActionInstanceFailed - c1.api.task.v1.TaskAuditActionInstanceSucceeded: - description: The TaskAuditActionInstanceSucceeded message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceCreateRequest + c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse: + description: The ServicePrincipalServiceCreateResponse message. properties: - instance: - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' - title: Task Audit Action Instance Succeeded + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + title: Service Principal Service Create Response type: object - x-speakeasy-name-override: TaskAuditActionInstanceSucceeded - c1.api.task.v1.TaskAuditActionSubmitted: - description: The TaskAuditActionSubmitted message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceCreateResponse + c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest: + description: The ServicePrincipalServiceDeleteBindingRequest message. properties: - action: - $ref: '#/components/schemas/c1.api.task.v1.TaskAction' - title: Task Audit Action Submitted + servicePrincipalId: + description: The servicePrincipalId field. + type: string + subject: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - type: "null" + title: Service Principal Service Delete Binding Request type: object - x-speakeasy-name-override: TaskAuditActionSubmitted - c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy: - description: The TaskAuditApprovalAutoAcceptedByPolicy message. - nullable: true - title: Task Audit Approval Auto Accepted By Policy + x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingRequest + c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse: + description: The ServicePrincipalServiceDeleteBindingResponse message. + title: Service Principal Service Delete Binding Response type: object - x-speakeasy-name-override: TaskAuditApprovalAutoAcceptedByPolicy - c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy: - description: The TaskAuditApprovalAutoRejectedByPolicy message. - nullable: true - title: Task Audit Approval Auto Rejected By Policy + x-speakeasy-name-override: ServicePrincipalServiceDeleteBindingResponse + c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput: + description: The ServicePrincipalServiceDeleteRequest message. + title: Service Principal Service Delete Request type: object - x-speakeasy-name-override: TaskAuditApprovalAutoRejectedByPolicy - c1.api.task.v1.TaskAuditApprovalHappenedAutomatically: - description: The TaskAuditApprovalHappenedAutomatically message. - nullable: true - title: Task Audit Approval Happened Automatically + x-speakeasy-name-override: ServicePrincipalServiceDeleteRequest + c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse: + description: The ServicePrincipalServiceDeleteResponse message. + title: Service Principal Service Delete Response type: object - x-speakeasy-name-override: TaskAuditApprovalHappenedAutomatically - c1.api.task.v1.TaskAuditApprovalInstanceChange: - description: The TaskAuditApprovalInstanceChange message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceDeleteResponse + c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse: + description: The ServicePrincipalServiceGetCredentialResponse message. properties: - instance: - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' - title: Task Audit Approval Instance Change + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - type: "null" + title: Service Principal Service Get Credential Response type: object - x-speakeasy-name-override: TaskAuditApprovalInstanceChange - c1.api.task.v1.TaskAuditBulkActionError: - description: The TaskAuditBulkActionError message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceGetCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceGetResponse: + description: The ServicePrincipalServiceGetResponse message. properties: - error: - description: The error field. - readOnly: false - type: string - title: Task Audit Bulk Action Error + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + title: Service Principal Service Get Response type: object - x-speakeasy-name-override: TaskAuditBulkActionError - c1.api.task.v1.TaskAuditCertifyOutcome: - description: The TaskAuditCertifyOutcome message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceGetResponse + c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest: + description: The ServicePrincipalServiceListBindingsRequest message. properties: - outcome: - description: The outcome field. - enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT - readOnly: false + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - x-speakeasy-unknown-values: allow - title: Task Audit Certify Outcome + subject: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject' + - type: "null" + title: Service Principal Service List Bindings Request type: object - x-speakeasy-name-override: TaskAuditCertifyOutcome - c1.api.task.v1.TaskAuditComment: - description: The TaskAuditComment message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceListBindingsRequest + c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse: + description: The ServicePrincipalServiceListBindingsResponse message. properties: - comment: - description: The comment field. - readOnly: false + bindings: + description: |- + Active bindings held by the subject in this page. Empty when the + subject is unbound. Order is unspecified. + items: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalBinding' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - updatedAt: - format: date-time - readOnly: false + title: Service Principal Service List Bindings Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceListBindingsResponse + c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse: + description: The ServicePrincipalServiceListCredentialsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - updatedBy: - description: The updatedBy field. - readOnly: false + title: Service Principal Service List Credentials Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceListCredentialsResponse + c1.api.service_principal.v1.ServicePrincipalServiceListResponse: + description: The ServicePrincipalServiceListResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Task Audit Comment + title: Service Principal Service List Response type: object - x-speakeasy-name-override: TaskAuditComment - c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult: - description: The TaskAuditConditionalPolicyExecutionResult message. - nullable: true + x-speakeasy-name-override: ServicePrincipalServiceListResponse + c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput: + description: The ServicePrincipalServiceRevokeCredentialRequest message. + title: Service Principal Service Revoke Credential Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse: + description: The ServicePrincipalServiceRevokeCredentialResponse message. + title: Service Principal Service Revoke Credential Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceRevokeCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput: + description: The ServicePrincipalServiceUpdateCredentialRequest message. properties: - condition: - description: The condition field. - readOnly: false + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - type: "null" + updateMask: + type: + - string + - "null" + title: Service Principal Service Update Credential Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialRequest + c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse: + description: The ServicePrincipalServiceUpdateCredentialResponse message. + properties: + credential: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential' + - type: "null" + title: Service Principal Service Update Credential Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceUpdateCredentialResponse + c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput: + description: The ServicePrincipalServiceUpdateRequest message. + properties: + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + updateMask: + type: + - string + - "null" + title: Service Principal Service Update Request + type: object + x-speakeasy-name-override: ServicePrincipalServiceUpdateRequest + c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse: + description: The ServicePrincipalServiceUpdateResponse message. + properties: + servicePrincipal: + oneOf: + - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipal' + - type: "null" + title: Service Principal Service Update Response + type: object + x-speakeasy-name-override: ServicePrincipalServiceUpdateResponse + c1.api.session_policy.v1.Allow: + description: Allow continues the session. + properties: + floorLevel: + description: The minimum assurance level that satisfies this rule. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - conditionMatched: - description: The conditionMatched field. - readOnly: false - type: boolean - defaultCondition: - description: The defaultCondition field. - readOnly: false - type: boolean - error: - description: The error field. - readOnly: false + x-speakeasy-unknown-values: allow + title: Allow + type: object + x-speakeasy-name-override: SessionPolicyAllow + c1.api.session_policy.v1.Assignment: + description: Assignment is one principal (user) assigned to a session policy. + properties: + source: + description: Whether the assignment is direct or conferred through a group. + enum: + - ASSIGNMENT_SOURCE_UNSPECIFIED + - ASSIGNMENT_SOURCE_DIRECT + - ASSIGNMENT_SOURCE_GROUP type: string - policyKey: - description: The policyKey field. - readOnly: false + x-speakeasy-unknown-values: allow + userId: + description: The assigned user's ID. type: string - title: Task Audit Conditional Policy Execution Result + title: Assignment type: object - x-speakeasy-name-override: TaskAuditConditionalPolicyExecutionResult - c1.api.task.v1.TaskAuditConnectorActionResult: - description: | - The TaskAuditConnectorActionResult message. - - This message contains a oneof named result. Only a single field of the following list may be set at a time: - - success - - error - - cancelled - - pending - nullable: true + x-speakeasy-name-override: Assignment + c1.api.session_policy.v1.ChallengeRequired: + description: ChallengeRequired asks for an additional factor. properties: - appEntitlementId: - description: The appEntitlementId field. - readOnly: false + types: + description: The types field. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Challenge Required + type: object + x-speakeasy-name-override: SessionPolicyChallengeRequired + c1.api.session_policy.v1.Deny: + description: Deny terminates the session. + properties: + reasonAdmin: + description: Reason shown in admin-only audit. type: string - appId: - description: The appId field. - readOnly: false + reasonUser: + description: Reason safe to show the end user. type: string - cancelled: - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditCancelledResult' - connectorActionId: - description: The connectorActionId field. - readOnly: false - type: string - connectorId: - description: The connectorId field. - readOnly: false - type: string - error: - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditErrorResult' - pending: - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditPendingResult' - success: - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditSuccessResult' - title: Task Audit Connector Action Result - type: object - x-speakeasy-name-override: TaskAuditConnectorActionResult - c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask: - description: |- - TaskAuditCreatedReplacementExtensionGrantTask is used when a replacement extension grant task is created - (e.g. when an extension grant task is cancelled due to app user deletion). - nullable: true - properties: - newTaskId: - description: The ID of the newly created replacement task - readOnly: false - type: string - newTaskNumericId: - description: The numeric ID of the newly created replacement task (for display) - format: int64 - readOnly: false - type: string - title: Task Audit Created Replacement Extension Grant Task + title: Deny type: object - x-speakeasy-name-override: TaskAuditCreatedReplacementExtensionGrantTask - c1.api.task.v1.TaskAuditEscalateToEmergencyAccess: - description: The TaskAuditEscalateToEmergencyAccess message. - nullable: true + x-speakeasy-name-override: SessionPolicyDeny + c1.api.session_policy.v1.EnrollmentRequired: + description: EnrollmentRequired tells the user to enroll a credential before continuing. properties: - oldPolicyId: - description: The oldPolicyId field. - readOnly: false - type: string - oldPolicyStepId: - description: The oldPolicyStepId field. - readOnly: false - type: string - title: Task Audit Escalate To Emergency Access + credentialTypes: + description: The credentialTypes field. + items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Enrollment Required type: object - x-speakeasy-name-override: TaskAuditEscalateToEmergencyAccess - c1.api.task.v1.TaskAuditExpressionPolicyStepError: - description: The TaskAuditExpressionPolicyStepError message. - nullable: true + x-speakeasy-name-override: SessionPolicyEnrollmentRequired + c1.api.session_policy.v1.PerCredentialDuration: + description: |- + PerCredentialDuration overrides session lifetimes for sessions established + with a particular credential type — stronger credentials can earn longer + sessions. properties: - error: - description: The error field. - readOnly: false + accessTokenTtlSeconds: + description: Access-token lifetime for this credential type, in seconds. + format: int32 + type: integer + credentialType: + description: The credentialType field. + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - title: Task Audit Expression Policy Step Error + x-speakeasy-unknown-values: allow + maxSessionDurationSeconds: + description: Maximum total session duration for this credential type, in seconds. + format: int32 + type: integer + title: Per Credential Duration type: object - x-speakeasy-name-override: TaskAuditExpressionPolicyStepError - c1.api.task.v1.TaskAuditExternalTicketCreated: - description: The TaskAuditExternalTicketCreated message. - nullable: true + x-speakeasy-name-override: PerCredentialDuration + c1.api.session_policy.v1.PolicyOutcome: + description: | + PolicyOutcome is the effect of a matched rule. Exactly one kind is set. For + session continuous-evaluation, the meaningful kinds are Allow (continue), + Deny (terminate), and StepUpRequired. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - allow + - deny + - stepUpRequired + - challengeRequired + - enrollmentRequired + properties: + allow: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.Allow' + - type: "null" + challengeRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.ChallengeRequired' + - type: "null" + deny: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.Deny' + - type: "null" + enrollmentRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.EnrollmentRequired' + - type: "null" + stepUpRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.StepUpRequired' + - type: "null" + title: Policy Outcome + type: object + x-speakeasy-name-override: SessionPolicyPolicyOutcome + c1.api.session_policy.v1.PolicyRule: + description: |- + PolicyRule is one rung of the ordered continuous-evaluation cascade. Rules + are evaluated top to bottom on every request; the first enforced rule whose + condition matches supplies the outcome. properties: - appId: - description: The appId field. - readOnly: false - type: string - connectorId: - description: The connectorId field. - readOnly: false - type: string - externalTicketId: - description: The externalTicketId field. - readOnly: false + description: + description: The description field. type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - readOnly: false + id: + description: The id field. type: string - externalTicketProvisionerConfigName: - description: The externalTicketProvisionerConfigName field. - readOnly: false + matchCel: + description: The matchCel field. type: string - externalTicketUrl: - description: The externalTicketUrl field. - readOnly: false + mode: + description: The mode field. + enum: + - POLICY_RULE_MODE_UNSPECIFIED + - POLICY_RULE_MODE_ENFORCE + - POLICY_RULE_MODE_OBSERVE + - POLICY_RULE_MODE_DISABLED type: string - title: Task Audit External Ticket Created + x-speakeasy-unknown-values: allow + outcome: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' + - type: "null" + title: Policy Rule type: object - x-speakeasy-name-override: TaskAuditExternalTicketCreated - c1.api.task.v1.TaskAuditExternalTicketError: - description: The TaskAuditExternalTicketError message. - nullable: true + x-speakeasy-name-override: SessionPolicyPolicyRule + c1.api.session_policy.v1.SSFReceiverConfig: + description: |- + SSFReceiverConfig selects which inbound shared-signals streams this session + trusts. Each stream's issuer, keys, expected audience, and per-event actions + are configured on the stream itself; this policy just lists the stream IDs. properties: - errorMessage: - description: The errorMessage field. - readOnly: false - type: string - title: Task Audit External Ticket Error + enabled: + description: Whether inbound shared-signals consumption is enabled for this policy. + type: boolean + ssfReceiverStreamIds: + description: The inbound stream IDs this policy trusts. + items: + type: string + type: + - array + - "null" + title: Ssf Receiver Config type: object - x-speakeasy-name-override: TaskAuditExternalTicketError - c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved: - description: The TaskAuditExternalTicketProvisionStepResolved message. - nullable: true + x-speakeasy-name-override: SSFReceiverConfig + c1.api.session_policy.v1.SSFTransmitterConfig: + description: |- + SSFTransmitterConfig selects which outbound shared-signals streams this + session emits security events to. Each stream's delivery endpoint, + authentication, and per-event allowlist are configured on the stream itself; + this policy just lists the stream IDs and the event types to emit. properties: - appId: - description: The appId field. - readOnly: false - type: string - connectorId: - description: The connectorId field. - readOnly: false - type: string - externalTicketId: - description: The externalTicketId field. - readOnly: false - type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - readOnly: false - type: string - externalTicketUrl: - description: The externalTicketUrl field. - readOnly: false - type: string - title: Task Audit External Ticket Provision Step Resolved + enabled: + description: Whether outbound shared-signals emission is enabled for this policy. + type: boolean + eventTypes: + description: The shared-signals event types to emit at the policy level. + items: + type: string + type: + - array + - "null" + ssfTransmitterStreamIds: + description: The outbound stream IDs this policy emits to. + items: + type: string + type: + - array + - "null" + title: Ssf Transmitter Config type: object - x-speakeasy-name-override: TaskAuditExternalTicketProvisionStepResolved - c1.api.task.v1.TaskAuditExternalTicketTriggered: - description: The TaskAuditExternalTicketTriggered message. - nullable: true + x-speakeasy-name-override: SSFTransmitterConfig + c1.api.session_policy.v1.SessionPolicy: + description: SessionPolicy defines session lifetime and continuous-evaluation behavior. properties: - appId: - description: The appId field. - readOnly: false - type: string - connectorId: - description: The connectorId field. - readOnly: false - type: string - externalTicketId: - description: The externalTicketId field. - readOnly: false + accessTokenTtlSeconds: + description: How long an access token is valid, in seconds. + format: int32 + type: integer + continuousDefaultOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' + - type: "null" + continuousRules: + description: |- + The continuous-evaluation rule cascade, re-checked on every request and on + inbound shared-signals events. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' + type: + - array + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + credentialDurations: + description: Per-credential-type lifetime overrides. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + type: + - array + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + displayName: + description: A human-readable name for the policy. type: string - externalTicketProvisionerConfigId: - description: The externalTicketProvisionerConfigId field. - readOnly: false + id: + description: Unique identifier for the policy. + readOnly: true type: string - externalTicketProvisionerConfigName: - description: The externalTicketProvisionerConfigName field. - readOnly: false + idleTimeoutSeconds: + description: How long a session may be idle before it ends, in seconds. + format: int32 + type: integer + isBuiltin: + description: |- + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. + readOnly: true + type: boolean + maxSessionDurationSeconds: + description: The maximum total lifetime of a session, in seconds. + format: int32 + type: integer + persistence: + description: Whether sessions may persist across browser restarts. + enum: + - PERSISTENCE_MODE_UNSPECIFIED + - PERSISTENCE_MODE_ALLOW_USER_CHOICE + - PERSISTENCE_MODE_ALWAYS_PERSIST + - PERSISTENCE_MODE_SESSION_ONLY type: string - title: Task Audit External Ticket Triggered + x-speakeasy-unknown-values: allow + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + refreshRotationWindowSeconds: + description: |- + Grace window after rotation during which the previous refresh token is + still accepted, in seconds (covers in-flight client retries). + format: int32 + type: integer + refreshTokenTtlSeconds: + description: How long a refresh token is valid, in seconds. + format: int32 + type: integer + rotateRefreshOnUse: + description: Whether to issue a new refresh token each time one is used. + type: boolean + ssfReceive: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' + - type: "null" + ssfTransmit: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Session Policy type: object - x-speakeasy-name-override: TaskAuditExternalTicketTriggered - c1.api.task.v1.TaskAuditFinishedConnectorActions: - description: The TaskAuditFinishedConnectorActions message. - nullable: true + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicy + c1.api.session_policy.v1.SessionPolicyRef: + description: SessionPolicyRef is a lightweight reference to a session policy by ID. properties: - policyStepId: - description: The policyStepId field. - readOnly: false + id: + description: The id field. type: string - title: Task Audit Finished Connector Actions + title: Session Policy Ref type: object - x-speakeasy-name-override: TaskAuditFinishedConnectorActions - c1.api.task.v1.TaskAuditFormInstanceChange: - description: The TaskAuditFormInstanceChange message. - nullable: true + x-speakeasy-name-override: SessionPolicyRef + c1.api.session_policy.v1.SessionPolicyServiceAssignGroupRequestInput: + description: The SessionPolicyServiceAssignGroupRequest message. properties: - isValid: - description: The isValid field. - readOnly: false - type: boolean - title: Task Audit Form Instance Change + groupAppEntitlementId: + description: The group's app-entitlement ID. Every member of the group becomes assigned. + type: string + required: + - groupAppEntitlementId + title: Session Policy Service Assign Group Request type: object - x-speakeasy-name-override: TaskAuditFormInstanceChange - c1.api.task.v1.TaskAuditGrantDurationUpdated: - description: The TaskAuditGrantDurationUpdated message. - nullable: true + x-speakeasy-name-override: SessionPolicyServiceAssignGroupRequest + c1.api.session_policy.v1.SessionPolicyServiceAssignGroupResponse: + description: The SessionPolicyServiceAssignGroupResponse message. + title: Session Policy Service Assign Group Response + type: object + x-speakeasy-name-override: SessionPolicyServiceAssignGroupResponse + c1.api.session_policy.v1.SessionPolicyServiceAssignUserRequestInput: + description: The SessionPolicyServiceAssignUserRequest message. properties: - duration: - format: duration - readOnly: false + userId: + description: The user to assign. type: string - title: Task Audit Grant Duration Updated + required: + - userId + title: Session Policy Service Assign User Request type: object - x-speakeasy-name-override: TaskAuditGrantDurationUpdated - c1.api.task.v1.TaskAuditGrantOutcome: - description: The TaskAuditGrantOutcome message. - nullable: true + x-speakeasy-name-override: SessionPolicyServiceAssignUserRequest + c1.api.session_policy.v1.SessionPolicyServiceAssignUserResponse: + description: The SessionPolicyServiceAssignUserResponse message. + title: Session Policy Service Assign User Response + type: object + x-speakeasy-name-override: SessionPolicyServiceAssignUserResponse + c1.api.session_policy.v1.SessionPolicyServiceCreateRequest: + description: The SessionPolicyServiceCreateRequest message. properties: - outcome: - description: The outcome field. + accessTokenTtlSeconds: + description: The accessTokenTtlSeconds field. + format: int32 + type: integer + continuousDefaultOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyOutcome' + - type: "null" + continuousRules: + description: The continuousRules field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PolicyRule' + type: + - array + - "null" + credentialDurations: + description: The credentialDurations field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.PerCredentialDuration' + type: + - array + - "null" + displayName: + description: The displayName field. + type: string + idleTimeoutSeconds: + description: The idleTimeoutSeconds field. + format: int32 + type: integer + maxSessionDurationSeconds: + description: The maxSessionDurationSeconds field. + format: int32 + type: integer + persistence: + description: The persistence field. enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT - readOnly: false + - PERSISTENCE_MODE_UNSPECIFIED + - PERSISTENCE_MODE_ALLOW_USER_CHOICE + - PERSISTENCE_MODE_ALWAYS_PERSIST + - PERSISTENCE_MODE_SESSION_ONLY type: string x-speakeasy-unknown-values: allow - title: Task Audit Grant Outcome + priority: + description: The priority field. + format: int32 + type: integer + refreshRotationWindowSeconds: + description: The refreshRotationWindowSeconds field. + format: int32 + type: integer + refreshTokenTtlSeconds: + description: The refreshTokenTtlSeconds field. + format: int32 + type: integer + rotateRefreshOnUse: + description: The rotateRefreshOnUse field. + type: boolean + ssfReceive: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFReceiverConfig' + - type: "null" + ssfTransmit: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SSFTransmitterConfig' + - type: "null" + required: + - displayName + title: Session Policy Service Create Request + type: object + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicyServiceCreateRequest + c1.api.session_policy.v1.SessionPolicyServiceCreateResponse: + description: The SessionPolicyServiceCreateResponse message. + properties: + sessionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - type: "null" + title: Session Policy Service Create Response + type: object + x-speakeasy-name-override: SessionPolicyServiceCreateResponse + c1.api.session_policy.v1.SessionPolicyServiceDeleteRequestInput: + description: The SessionPolicyServiceDeleteRequest message. + title: Session Policy Service Delete Request + type: object + x-speakeasy-entity: SessionPolicy + x-speakeasy-name-override: SessionPolicyServiceDeleteRequest + c1.api.session_policy.v1.SessionPolicyServiceDeleteResponse: + description: The SessionPolicyServiceDeleteResponse message. + title: Session Policy Service Delete Response + type: object + x-speakeasy-name-override: SessionPolicyServiceDeleteResponse + c1.api.session_policy.v1.SessionPolicyServiceGetResponse: + description: The SessionPolicyServiceGetResponse message. + properties: + sessionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - type: "null" + title: Session Policy Service Get Response + type: object + x-speakeasy-name-override: SessionPolicyServiceGetResponse + c1.api.session_policy.v1.SessionPolicyServiceListAssignmentsResponse: + description: The SessionPolicyServiceListAssignmentsResponse message. + properties: + assignments: + description: The assignments field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.Assignment' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Session Policy Service List Assignments Response type: object - x-speakeasy-name-override: TaskAuditGrantOutcome - c1.api.task.v1.TaskAuditHardReset: - description: The TaskAuditHardReset message. - nullable: true + x-speakeasy-name-override: SessionPolicyServiceListAssignmentsResponse + c1.api.session_policy.v1.SessionPolicyServiceListResponse: + description: The SessionPolicyServiceListResponse message. properties: - oldPolicyStepId: - description: The oldPolicyStepId field. - readOnly: false + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Task Audit Hard Reset + title: Session Policy Service List Response type: object - x-speakeasy-name-override: TaskAuditHardReset - c1.api.task.v1.TaskAuditListRequest: - description: The TaskAuditListRequest message. + x-speakeasy-name-override: SessionPolicyServiceListResponse + c1.api.session_policy.v1.SessionPolicyServiceSearchRequest: + description: The SessionPolicyServiceSearchRequest message. properties: pageSize: - description: The maximum number of audit events to return per page. + description: The pageSize field. format: int32 - readOnly: false type: integer pageToken: - description: A pagination token from a previous response to retrieve the next page. - readOnly: false + description: The pageToken field. + type: string + query: + description: Free-text search over the policy name. Empty matches all policies. type: string refs: - description: References to specific audit events to retrieve. If provided, only these events are returned. + description: Restrict results to these specific policies. Empty matches all policies. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditViewRef' - nullable: true - readOnly: false - type: array - taskId: - description: The ID of the task to list audit events for. - readOnly: false - type: string - title: Task Audit List Request + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyRef' + type: + - array + - "null" + title: Session Policy Service Search Request type: object - x-speakeasy-name-override: TaskAuditListRequest - c1.api.task.v1.TaskAuditListResponse: - description: The TaskAuditListResponse message. + x-speakeasy-name-override: SessionPolicyServiceSearchRequest + c1.api.session_policy.v1.SessionPolicyServiceSearchResponse: + description: The SessionPolicyServiceSearchResponse message. properties: list: - description: The list of audit events for the task. + description: The list field. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + type: + - array + - "null" nextPageToken: - description: A pagination token to retrieve the next page of results. - readOnly: false + description: The nextPageToken field. type: string - title: Task Audit List Response + title: Session Policy Service Search Response type: object - x-speakeasy-name-override: TaskAuditListResponse - c1.api.task.v1.TaskAuditMetaData: - description: The TaskAuditMetaData message. - properties: - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: Task Audit Meta Data + x-speakeasy-name-override: SessionPolicyServiceSearchResponse + c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupRequestInput: + description: The SessionPolicyServiceUnassignGroupRequest message. + title: Session Policy Service Unassign Group Request type: object - x-speakeasy-name-override: TaskAuditMetaData - c1.api.task.v1.TaskAuditNewTask: - description: The TaskAuditNewTask message. - nullable: true - title: Task Audit New Task + x-speakeasy-name-override: SessionPolicyServiceUnassignGroupRequest + c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupResponse: + description: The SessionPolicyServiceUnassignGroupResponse message. + title: Session Policy Service Unassign Group Response type: object - x-speakeasy-name-override: TaskAuditNewTask - c1.api.task.v1.TaskAuditNewTaskCreatedFrom: - description: |- - TaskAuditNewTaskCreatedFrom is used when a task is created from another task - (e.g. when a replacement extension grant task is created after the original is cancelled). - This is set on the NEW task to indicate its origin. - nullable: true - properties: - originalTaskId: - description: The originalTaskId field. - readOnly: false - type: string - originalTaskNumericId: - description: The originalTaskNumericId field. - format: int64 - readOnly: false - type: string - originalTaskType: - description: The task type of the original task (e.g. "grant", "revoke", "certify"). - readOnly: false - type: string - title: Task Audit New Task Created From + x-speakeasy-name-override: SessionPolicyServiceUnassignGroupResponse + c1.api.session_policy.v1.SessionPolicyServiceUnassignUserRequestInput: + description: The SessionPolicyServiceUnassignUserRequest message. + title: Session Policy Service Unassign User Request type: object - x-speakeasy-name-override: TaskAuditNewTaskCreatedFrom - c1.api.task.v1.TaskAuditPolicyApprovalReassigned: - description: The TaskAuditPolicyApprovalReassigned message. - nullable: true + x-speakeasy-name-override: SessionPolicyServiceUnassignUserRequest + c1.api.session_policy.v1.SessionPolicyServiceUnassignUserResponse: + description: The SessionPolicyServiceUnassignUserResponse message. + title: Session Policy Service Unassign User Response + type: object + x-speakeasy-name-override: SessionPolicyServiceUnassignUserResponse + c1.api.session_policy.v1.SessionPolicyServiceUpdateRequestInput: + description: The SessionPolicyServiceUpdateRequest message. properties: - newPolicyStepId: - description: The newPolicyStepId field. - readOnly: false + sessionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Session Policy Service Update Request + type: object + x-speakeasy-name-override: SessionPolicyServiceUpdateRequest + c1.api.session_policy.v1.SessionPolicyServiceUpdateResponse: + description: The SessionPolicyServiceUpdateResponse message. + properties: + sessionPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicy' + - type: "null" + title: Session Policy Service Update Response + type: object + x-speakeasy-name-override: SessionPolicyServiceUpdateResponse + c1.api.session_policy.v1.StepUpRequired: + description: |- + StepUpRequired demands a stronger re-authentication before the session may + continue. + properties: + level: + description: The level field. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - newUsers: - description: The newUsers field. + x-speakeasy-unknown-values: allow + maxAgeSeconds: + description: How fresh the step-up must be, in seconds. + format: int32 + type: integer + types: + description: The types field. items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - nullable: true - readOnly: false - type: array - oldPolicyStepId: - description: The oldPolicyStepId field. - readOnly: false - type: string - users: - description: The users field. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - title: Task Audit Policy Approval Reassigned + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Step Up Required type: object - x-speakeasy-name-override: TaskAuditPolicyApprovalReassigned - c1.api.task.v1.TaskAuditPolicyChanged: - description: The TaskAuditPolicyChanged message. - nullable: true + x-speakeasy-name-override: SessionPolicyStepUpRequired + c1.api.settings.v1.AWSExternalID: + description: AWSExternalID contains the tenant's external ID for AWS IAM role trust policies. properties: - newPolicyId: - description: The newPolicyId field. - readOnly: false - type: string - oldPolicyId: - description: The oldPolicyId field. - readOnly: false + externalId: + description: The external ID value to include in the AWS IAM role trust policy condition. type: string - title: Task Audit Policy Changed + title: Aws External Id type: object - x-speakeasy-name-override: TaskAuditPolicyChanged - c1.api.task.v1.TaskAuditPolicyEvaluationStep: - description: The TaskAuditPolicyEvaluationStep message. - nullable: true + x-speakeasy-entity: AWS_EXTERNAL_ID + x-speakeasy-name-override: AWSExternalID + c1.api.settings.v1.AWSSESProviderConfig: + description: AWSSESProviderConfig configures sending via a customer's AWS SES account. properties: - stepComment: - description: The stepComment field. - readOnly: false + configurationSetName: + description: Optional SES configuration set name for tracking/metrics. type: string - title: Task Audit Policy Evaluation Step - type: object - x-speakeasy-name-override: TaskAuditPolicyEvaluationStep - c1.api.task.v1.TaskAuditPolicyProvisionCancelled: - description: The TaskAuditPolicyProvisionCancelled message. - nullable: true - properties: - cancelReason: - description: The cancelReason field. - readOnly: false + region: + description: AWS region where SES identities are verified (e.g., "us-east-1"). type: string - title: Task Audit Policy Provision Cancelled - type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionCancelled - c1.api.task.v1.TaskAuditPolicyProvisionError: - description: The TaskAuditPolicyProvisionError message. - nullable: true - properties: - error: - description: The error field. - readOnly: false + roleArn: + description: |- + IAM role ARN for sts:AssumeRole. The trust policy should require the + tenant's AWS External ID (GET /api/v1/settings/aws-external-id). type: string - title: Task Audit Policy Provision Error + title: Awsses Provider Config type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionError - c1.api.task.v1.TaskAuditPolicyProvisionReassigned: - description: The TaskAuditPolicyProvisionReassigned message. - nullable: true + x-speakeasy-name-override: AWSSESProviderConfig + c1.api.settings.v1.AccessProvisionedPreference: + description: The AccessProvisionedPreference message. properties: - newPolicyStepId: - description: The newPolicyStepId field. - readOnly: false - type: string - newUsers: - description: The newUsers field. - items: - type: string - nullable: true - readOnly: false - type: array - oldPolicyStepId: - description: The oldPolicyStepId field. - readOnly: false - type: string - users: - description: The users field. - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - title: Task Audit Policy Provision Reassigned + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Access Provisioned Preference type: object - x-speakeasy-name-override: TaskAuditPolicyProvisionReassigned - c1.api.task.v1.TaskAuditReassignedToDelegate: - description: The TaskAuditReassignedToDelegate message. - nullable: true + x-speakeasy-name-override: AccessProvisionedPreference + c1.api.settings.v1.ApprovalNeededPreference: + description: The ApprovalNeededPreference message. properties: - delegatedAssigneeUser: - $ref: '#/components/schemas/c1.api.user.v1.User' - delegatedAssigneeUserId: - description: The delegatedAssigneeUserId field. - readOnly: false - type: string - originalAssigneeUser: - $ref: '#/components/schemas/c1.api.user.v1.User' - originalAssigneeUserId: - description: The originalAssigneeUserId field. - readOnly: false - type: string - title: Task Audit Reassigned To Delegate + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Approval Needed Preference type: object - x-speakeasy-name-override: TaskAuditReassignedToDelegate - c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin: + x-speakeasy-name-override: ApprovalNeededPreference + c1.api.settings.v1.C1BuiltInProviderConfig: description: |- - TaskAuditReassignmentFallbackToAdmin is used when no eligible reviewers are found - from the policy configuration and the task falls back to system administrators - without creating a new policy step. This prevents reassignment loops. - nullable: true + C1BuiltInProviderConfig selects the ConductorOne built-in email provider. + Emails are sent from no-reply@conductorone.com via the platform SendGrid account. + Only supports sending to C1 users — external email addresses are not supported. + No configuration fields required. + title: C 1 Built In Provider Config + type: object + x-speakeasy-name-override: C1BuiltInProviderConfig + c1.api.settings.v1.CIDRRestriction: + description: CIDRRestriction defines an IP-based access restriction with an enable toggle and a list of allowed CIDRs. properties: - adminUserIds: - description: The IDs of the system administrator users that the task is being assigned to + enabled: + description: Whether this CIDR restriction is enforced. + type: boolean + sourceCidr: + description: |- + The list of CIDR ranges that are allowed when the restriction is enabled. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. items: type: string - nullable: true - readOnly: false - type: array - adminUsers: - description: The system administrator users (populated for display) - items: - $ref: '#/components/schemas/c1.api.user.v1.User' - nullable: true - readOnly: false - type: array - title: Task Audit Reassignment Fallback To Admin + type: + - array + - "null" + title: Cidr Restriction type: object - x-speakeasy-name-override: TaskAuditReassignmentFallbackToAdmin - c1.api.task.v1.TaskAuditReassignmentListError: - description: The TaskAuditReassignmentListError message. - nullable: true + x-speakeasy-name-override: CIDRRestriction + c1.api.settings.v1.ChannelSettings: + description: ChannelSettings groups notification preferences for all supported channels. properties: - errorMessage: - description: The errorMessage field. - readOnly: false - type: string - title: Task Audit Reassignment List Error + email: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.EmailChannelSettings' + - type: "null" + slack: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SlackChannelSettings' + - type: "null" + teams: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.MSTeamsChannelSettings' + - type: "null" + title: Channel Settings type: object - x-speakeasy-name-override: TaskAuditReassignmentListError - c1.api.task.v1.TaskAuditRestart: - description: The TaskAuditRestart message. - nullable: true + x-speakeasy-name-override: ChannelSettings + c1.api.settings.v1.CommentOnRequestPreference: + description: The CommentOnRequestPreference message. properties: - oldPolicyStepId: - description: The oldPolicyStepId field. - readOnly: false - type: string - title: Task Audit Restart + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Comment On Request Preference type: object - x-speakeasy-name-override: TaskAuditRestart - c1.api.task.v1.TaskAuditRevokeOutcome: - description: The TaskAuditRevokeOutcome message. - nullable: true + x-speakeasy-name-override: CommentOnRequestPreference + c1.api.settings.v1.CompletionPreference: + description: The CompletionPreference message. properties: - outcome: - description: The outcome field. - enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT - readOnly: false - type: string - x-speakeasy-unknown-values: allow - title: Task Audit Revoke Outcome + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Completion Preference type: object - x-speakeasy-name-override: TaskAuditRevokeOutcome - c1.api.task.v1.TaskAuditSLAEscalation: - description: The TaskAuditSLAEscalation message. - nullable: true - properties: - message: - description: The message field. - readOnly: false - type: string - title: Task Audit Sla Escalation + x-speakeasy-name-override: CompletionPreference + c1.api.settings.v1.ConnectorIssuesPreference: + description: The ConnectorIssuesPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Connector Issues Preference type: object - x-speakeasy-name-override: TaskAuditSLAEscalation - c1.api.task.v1.TaskAuditStartedConnectorActions: - description: The TaskAuditStartedConnectorActions message. - nullable: true + x-speakeasy-name-override: ConnectorIssuesPreference + c1.api.settings.v1.Contacts: + description: Contacts represents the contact configuration for an organization. properties: - policyStepId: - description: The policyStepId field. - readOnly: false - type: string - title: Task Audit Started Connector Actions + billingEmails: + description: Email addresses of billing contacts for this organization. + items: + type: string + type: + - array + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + operationsEmails: + description: Email addresses of operations contacts for this organization. + items: + type: string + type: + - array + - "null" + securityEmails: + description: Email addresses of security contacts for this organization. + items: + type: string + type: + - array + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Contacts type: object - x-speakeasy-name-override: TaskAuditStartedConnectorActions - c1.api.task.v1.TaskAuditStateChange: - description: The TaskAuditStateChange message. - nullable: true + x-speakeasy-name-override: Contacts + c1.api.settings.v1.DigestPreference: + description: DigestPreference controls whether summary digest notifications are sent and how often. properties: - previousState: - description: The previousState field. + dayOfWeek: + description: The day of the week to send weekly digests. enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED - readOnly: false + - WEEKDAY_UNSPECIFIED + - WEEKDAY_MONDAY + - WEEKDAY_TUESDAY + - WEEKDAY_WEDNESDAY + - WEEKDAY_THURSDAY + - WEEKDAY_FRIDAY + - WEEKDAY_SATURDAY + - WEEKDAY_SUNDAY type: string x-speakeasy-unknown-values: allow - title: Task Audit State Change + enabled: + description: Whether digest notifications are enabled. + type: boolean + frequency: + description: How often digest notifications are sent. + enum: + - DIGEST_FREQUENCY_UNSPECIFIED + - DIGEST_FREQUENCY_DAILY + - DIGEST_FREQUENCY_WEEKLY + type: string + x-speakeasy-unknown-values: allow + locked: + description: Whether this preference is locked by org-level settings, preventing users from overriding it. + type: boolean + title: Digest Preference type: object - x-speakeasy-name-override: TaskAuditStateChange - c1.api.task.v1.TaskAuditStepSkipped: - description: The TaskAuditStepSkipped message. - nullable: true + x-speakeasy-name-override: DigestPreference + c1.api.settings.v1.EmailChannelSettings: + description: The EmailChannelSettings message. properties: - skippedBy: - description: The skippedBy field. - readOnly: false - type: string - title: Task Audit Step Skipped + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Email Channel Settings type: object - x-speakeasy-name-override: TaskAuditStepSkipped - c1.api.task.v1.TaskAuditStepUpApproval: - description: The TaskAuditStepUpApproval message. - nullable: true + x-speakeasy-name-override: EmailChannelSettings + c1.api.settings.v1.ExpiringAccessPreference: + description: The ExpiringAccessPreference message. properties: - stepUpTransactionId: - description: The stepUpTransactionId field. - readOnly: false - type: string - title: Task Audit Step Up Approval + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Expiring Access Preference type: object - x-speakeasy-name-override: TaskAuditStepUpApproval - c1.api.task.v1.TaskAuditView: - description: | - The TaskAuditView message. - - This message contains a oneof named typ. Only a single field of the following list may be set at a time: - - comment - - stateChange - - approvalInstanceChange - - connectorActionsStart - - connectorActionsEnd - - actionResult - - taskCreated - - certifyOutcome - - actionSubmitted - - grantOutcome - - revokeOutcome - - approvalReassigned - - taskRestarted - - accessRequestOutcome - - provisionReassigned - - provisionError - - approvedAutomatically - - reassignedToDelegate - - hardReset - - taskEscalated - - conditionalPolicyExecutionResult - - expressionPolicyStepError - - approvalAutoAcceptedByPolicy - - approvalAutoRejectedByPolicy - - bulkActionError - - webhookTriggered - - webhookAttempt - - webhookSuccess - - policyEvaluationStep - - waitStepSuccess - - waitStepWaiting - - waitStepTimedOut - - webhookApprovalTriggered - - webhookApprovalAttempt - - webhookApprovalSuccess - - webhookApprovalBadResponse - - externalTicketTriggered - - externalTicketCreated - - externalTicketError - - waitStepAnalysisSuccess - - waitStepAnalysisWaiting - - waitStepAnalysisTimedOut - - stepUpApproval - - externalTicketProvisionStepResolved - - stepSkipped - - reassignmentListError - - slaEscalation - - policyChanged - - formInstanceChange - - grantDurationUpdated - - waitStepUntilTime - - webhookApprovalFatalError - - accountLifecycleActionCreated - - accountLifecycleActionFailed - - provisionCancelled - - actionInstanceCreated - - actionInstanceSucceeded - - actionInstanceFailed - - createdReplacementExtensionGrantTask - - taskCreatedFrom - - reassignmentFallbackToAdmin + x-speakeasy-name-override: ExpiringAccessPreference + c1.api.settings.v1.GetAWSExternalIDResponse: + description: The GetAWSExternalIDResponse message. properties: - accessRequestOutcome: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccessRequestOutcome' - accountLifecycleActionCreated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionCreated' - accountLifecycleActionFailed: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionFailed' - actionInstanceCreated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceCreated' - actionInstanceFailed: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceFailed' - actionInstanceSucceeded: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceSucceeded' - actionResult: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConnectorActionResult' - actionSubmitted: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionSubmitted' - approvalAutoAcceptedByPolicy: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy' - approvalAutoRejectedByPolicy: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy' - approvalInstanceChange: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalInstanceChange' - approvalReassigned: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyApprovalReassigned' - approvedAutomatically: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalHappenedAutomatically' - bulkActionError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditBulkActionError' - certifyOutcome: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCertifyOutcome' - comment: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditComment' - conditionalPolicyExecutionResult: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult' - connectorActionsEnd: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFinishedConnectorActions' - connectorActionsStart: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStartedConnectorActions' - created: - format: date-time - readOnly: false + awsExternalId: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AWSExternalID' + - type: "null" + title: Get Aws External Id Response + type: object + x-speakeasy-name-override: GetAWSExternalIDResponse + c1.api.settings.v1.GetContactsResponse: + description: The GetContactsResponse message. + properties: + contacts: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - type: "null" + title: Get Contacts Response + type: object + x-speakeasy-name-override: GetContactsResponse + c1.api.settings.v1.GetEmailCapabilitiesResponse: + description: The GetEmailCapabilitiesResponse message. + properties: + externalEmailSupported: + description: |- + True when external email addresses (outside C1 users) can be used as + recipients in automation email steps. False when only the C1 built-in + provider is configured (C1 users only). + type: boolean + title: Get Email Capabilities Response + type: object + x-speakeasy-name-override: GetEmailCapabilitiesResponse + c1.api.settings.v1.GetOnboardingSettingsResponse: + description: The GetOnboardingSettingsResponse message. + properties: + conversationId: + description: The identifier of the onboarding conversation thread, if one is in progress. type: string - createdReplacementExtensionGrantTask: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask' - currentState: - description: The currentState field. - enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED - readOnly: false + intents: + description: The intents field. + items: + type: string + type: + - array + - "null" + mcpOnboardingGoal: + description: The admin's free-form AIAM onboarding goal, captured at the Goals step. type: string - x-speakeasy-unknown-values: allow - eventType: - description: The eventType field. + mcpOnboardingStatus: + description: |- + The current status of the AIAM MCP onboarding briefing, tracked + independently of `status`. enum: - - TASK_AUDIT_EVENT_TYPE_UNSPECIFIED - - TASK_AUDIT_EVENT_TYPE_NEUTRAL - - TASK_AUDIT_EVENT_TYPE_ERROR - readOnly: false + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED type: string x-speakeasy-unknown-values: allow - expressionPolicyStepError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExpressionPolicyStepError' - externalTicketCreated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketCreated' - externalTicketError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketError' - externalTicketProvisionStepResolved: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved' - externalTicketTriggered: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketTriggered' - formInstanceChange: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFormInstanceChange' - grantDurationUpdated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantDurationUpdated' - grantOutcome: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantOutcome' - hardReset: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditHardReset' - id: - description: The id field. - readOnly: false - type: string - metadata: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditMetaData' - policyChanged: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyChanged' - policyEvaluationStep: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyEvaluationStep' - provisionCancelled: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionCancelled' - provisionError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionError' - provisionReassigned: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionReassigned' - reassignedToDelegate: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignedToDelegate' - reassignmentFallbackToAdmin: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin' - reassignmentListError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentListError' - revokeOutcome: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRevokeOutcome' - slaEscalation: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditSLAEscalation' - source: - description: The source field. + mcpOnboardingTargets: + description: |- + Per-target progress of the AIAM briefing: the servers/apps the admin chose + to govern and how far each got. + items: + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + type: + - array + - "null" + orgContext: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.OnboardingOrgContext' + - type: "null" + status: + description: The current status of the tenant onboarding process. enum: - - SOURCE_UNSPECIFIED - - SOURCE_C1 - - SOURCE_JIRA - - SOURCE_SLACK - - SOURCE_COPILOT_AGENTS - readOnly: false + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED type: string x-speakeasy-unknown-values: allow - stateChange: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStateChange' - stepSkipped: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepSkipped' - stepUpApproval: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepUpApproval' - taskCreated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTask' - taskCreatedFrom: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTaskCreatedFrom' - taskEscalated: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditEscalateToEmergencyAccess' - taskRestarted: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRestart' - ticketId: - description: The ticketId field. - readOnly: false - type: string - userId: - description: The userId field. - readOnly: false - type: string - waitStepAnalysisSuccess: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess' - waitStepAnalysisTimedOut: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut' - waitStepAnalysisWaiting: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting' - waitStepSuccess: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepSuccess' - waitStepTimedOut: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepTimedOut' - waitStepUntilTime: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepUntilTime' - waitStepWaiting: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepWaiting' - webhookApprovalAttempt: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalAttempt' - webhookApprovalBadResponse: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalBadResponse' - webhookApprovalFatalError: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalFatalError' - webhookApprovalSuccess: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalSuccess' - webhookApprovalTriggered: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalTriggered' - webhookAttempt: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookAttempt' - webhookSuccess: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookSuccess' - webhookTriggered: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookTriggered' - workflowStep: - description: The workflowStep field. - format: int32 - readOnly: false - type: integer - title: Task Audit View + title: Get Onboarding Settings Response type: object - x-speakeasy-name-override: TaskAuditView - c1.api.task.v1.TaskAuditViewRef: - description: The TaskAuditViewRef message. + x-speakeasy-name-override: GetOnboardingSettingsResponse + c1.api.settings.v1.GetOrgNotificationSettingsResponse: + description: The GetOrgNotificationSettingsResponse message. properties: - id: - description: The ID of the audit event. - readOnly: false - type: string - title: Task Audit View Ref + orgNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' + - type: "null" + title: Get Org Notification Settings Response type: object - x-speakeasy-name-override: TaskAuditViewRef - c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess: - description: The TaskAuditWaitForAnalysisStepSuccess message. - nullable: true + x-speakeasy-name-override: GetOrgNotificationSettingsResponse + c1.api.settings.v1.GetRequestSettingsResponse: + description: The GetRequestSettingsResponse message. properties: - stepId: - description: The stepId field. - readOnly: false - type: string - succeededAt: - format: date-time - readOnly: false - type: string - title: Task Audit Wait For Analysis Step Success + requestSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' + - type: "null" + title: Get Request Settings Response type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepSuccess - c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut: - description: The TaskAuditWaitForAnalysisStepTimedOut message. - nullable: true + x-speakeasy-name-override: GetRequestSettingsResponse + c1.api.settings.v1.GetSessionSettingsResponse: + description: The GetSessionSettingsResponse message. properties: - stepId: - description: The stepId field. - readOnly: false - type: string - timedOutAt: - format: date-time - readOnly: false - type: string - title: Task Audit Wait For Analysis Step Timed Out + sessionSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' + - type: "null" + title: Get Session Settings Response type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepTimedOut - c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting: - description: The TaskAuditWaitForAnalysisStepWaiting message. - nullable: true + x-speakeasy-name-override: GetSessionSettingsResponse + c1.api.settings.v1.GetTenantEmailProviderResponse: + description: The GetTenantEmailProviderResponse message. properties: - stepId: - description: The stepId field. - readOnly: false - type: string - title: Task Audit Wait For Analysis Step Waiting + emailProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' + - type: "null" + title: Get Tenant Email Provider Response type: object - x-speakeasy-name-override: TaskAuditWaitForAnalysisStepWaiting - c1.api.task.v1.TaskAuditWaitStepSuccess: - description: The TaskAuditWaitStepSuccess message. - nullable: true + x-speakeasy-name-override: GetTenantEmailProviderResponse + c1.api.settings.v1.GetUserDeveloperPreferencesResponse: + description: The GetUserDeveloperPreferencesResponse message. properties: - condition: - description: The condition field. - readOnly: false - type: string - stepId: - description: The stepId field. - readOnly: false - type: string - succeededAt: - format: date-time - readOnly: false - type: string - title: Task Audit Wait Step Success + userDeveloperPreferences: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' + - type: "null" + title: Get User Developer Preferences Response type: object - x-speakeasy-name-override: TaskAuditWaitStepSuccess - c1.api.task.v1.TaskAuditWaitStepTimedOut: - description: The TaskAuditWaitStepTimedOut message. - nullable: true + x-speakeasy-name-override: GetUserDeveloperPreferencesResponse + c1.api.settings.v1.GetUserNotificationSettingsResponse: + description: The GetUserNotificationSettingsResponse message. properties: - condition: - description: The condition field. - readOnly: false - type: string - stepId: - description: The stepId field. - readOnly: false - type: string - timedOutAt: - format: date-time - readOnly: false - type: string - title: Task Audit Wait Step Timed Out + userNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' + - type: "null" + title: Get User Notification Settings Response type: object - x-speakeasy-name-override: TaskAuditWaitStepTimedOut - c1.api.task.v1.TaskAuditWaitStepUntilTime: - description: The TaskAuditWaitStepUntilTime message. - nullable: true + x-speakeasy-name-override: GetUserNotificationSettingsResponse + c1.api.settings.v1.GoogleWorkspaceProviderConfig: + description: |- + GoogleWorkspaceProviderConfig configures sending via Google Workspace Gmail API + using domain-wide delegation with a service account. + Requires: customer Workspace super admin grants DWD to the service account's + OAuth client ID for the gmail.send scope. properties: - stepId: - description: The stepId field. - readOnly: false + delegatedUser: + description: |- + The Workspace user email to impersonate via domain-wide delegation. + Typically a dedicated sender like noreply@customer.com. type: string - untilTime: - format: date-time - readOnly: false + serviceAccountJson: + description: |- + Service account JSON credentials. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing credentials". type: string - title: Task Audit Wait Step Until Time + title: Google Workspace Provider Config type: object - x-speakeasy-name-override: TaskAuditWaitStepUntilTime - c1.api.task.v1.TaskAuditWaitStepWaiting: - description: The TaskAuditWaitStepWaiting message. - nullable: true + x-speakeasy-name-override: GoogleWorkspaceProviderConfig + c1.api.settings.v1.ListOrgDomainsResponse: + description: The ListOrgDomainsResponse message. properties: - condition: - description: The condition field. - readOnly: false - type: string - stepId: - description: The stepId field. - readOnly: false + list: + description: The list of verified domains. + items: + $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - title: Task Audit Wait Step Waiting + title: List Org Domains Response type: object - x-speakeasy-name-override: TaskAuditWaitStepWaiting - c1.api.task.v1.TaskAuditWebhookApprovalAttempt: - description: The TaskAuditWebhookApprovalAttempt message. - nullable: true + x-speakeasy-name-override: ListOrgDomainsResponse + c1.api.settings.v1.MSTeamsChannelSettings: + description: The MSTeamsChannelSettings message. properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false - type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false - type: string - title: Task Audit Webhook Approval Attempt + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + isConfigured: + description: The isConfigured field. + type: boolean + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Ms Teams Channel Settings type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalAttempt - c1.api.task.v1.TaskAuditWebhookApprovalBadResponse: - description: The TaskAuditWebhookApprovalBadResponse message. - nullable: true + x-speakeasy-name-override: MSTeamsChannelSettings + c1.api.settings.v1.McpOnboardingTarget: + description: |- + McpOnboardingTarget is one server/app the admin chose to govern during the + AIAM briefing, plus its progress. properties: - error: - description: The error field. - readOnly: false - type: string - webhookId: - description: The webhookId field. - readOnly: false + displayName: + description: Snapshot of the human label at selection time. type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false + id: + description: Identifies the target within the id space named by kind. type: string - webhookName: - description: The webhookName field. - readOnly: false + kind: + description: The kind field. + enum: + - MCP_ONBOARDING_TARGET_KIND_UNSPECIFIED + - MCP_ONBOARDING_TARGET_KIND_APP + - MCP_ONBOARDING_TARGET_KIND_CATALOG_ENTRY + - MCP_ONBOARDING_TARGET_KIND_MCP_SERVER type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false + x-speakeasy-unknown-values: allow + mcpServerId: + description: The registered MCP server a CATALOG_ENTRY target became, once registered. type: string - title: Task Audit Webhook Approval Bad Response + status: + description: The status field. + enum: + - MCP_ONBOARDING_TARGET_STATUS_UNSPECIFIED + - MCP_ONBOARDING_TARGET_STATUS_PENDING + - MCP_ONBOARDING_TARGET_STATUS_DONE + - MCP_ONBOARDING_TARGET_STATUS_SKIPPED + type: string + x-speakeasy-unknown-values: allow + title: Mcp Onboarding Target type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalBadResponse - c1.api.task.v1.TaskAuditWebhookApprovalFatalError: - description: The TaskAuditWebhookApprovalFatalError message. - nullable: true + x-speakeasy-name-override: McpOnboardingTarget + c1.api.settings.v1.McpOnboardingTargetList: + description: |- + McpOnboardingTargetList wraps the target list so an update can distinguish + replace (present, even if empty) from leave-unchanged (omitted). properties: - error: - description: The error field. - readOnly: false - type: string - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false - type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false - type: string - title: Task Audit Webhook Approval Fatal Error + targets: + description: The targets field. + items: + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + type: + - array + - "null" + title: Mcp Onboarding Target List type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalFatalError - c1.api.task.v1.TaskAuditWebhookApprovalSuccess: - description: The TaskAuditWebhookApprovalSuccess message. - nullable: true + x-speakeasy-name-override: McpOnboardingTargetList + c1.api.settings.v1.MicrosoftGraphProviderConfig: + description: |- + MicrosoftGraphProviderConfig configures sending via Microsoft Graph sendMail API. + Requires an Azure AD app registration with Mail.Send application permission (admin-consented). properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false + azureTenantId: + description: Customer's Azure AD tenant ID (directory ID). type: string - webhookName: - description: The webhookName field. - readOnly: false + clientId: + description: App registration client ID with Mail.Send application permission. type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false + clientSecret: + description: |- + Client secret. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing secret". type: string - title: Task Audit Webhook Approval Success + title: Microsoft Graph Provider Config type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalSuccess - c1.api.task.v1.TaskAuditWebhookApprovalTriggered: - description: The TaskAuditWebhookApprovalTriggered message. - nullable: true + x-speakeasy-name-override: MicrosoftGraphProviderConfig + c1.api.settings.v1.OnboardingOrgContext: + description: The OnboardingOrgContext message. properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false + industry: + description: The industry field. type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false + organizationSize: + description: The organizationSize field. type: string - title: Task Audit Webhook Approval Triggered + title: Onboarding Org Context type: object - x-speakeasy-name-override: TaskAuditWebhookApprovalTriggered - c1.api.task.v1.TaskAuditWebhookAttempt: - description: The TaskAuditWebhookAttempt message. - nullable: true + x-speakeasy-name-override: OnboardingOrgContext + c1.api.settings.v1.OrgDomain: + description: OrgDomain represents a verified email domain associated with the tenant. properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + domain: + description: The verified domain name (e.g., "example.com"). type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false + id: + description: The unique identifier of the domain record. type: string - title: Task Audit Webhook Attempt + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Org Domain type: object - x-speakeasy-name-override: TaskAuditWebhookAttempt - c1.api.task.v1.TaskAuditWebhookSuccess: - description: The TaskAuditWebhookSuccess message. - nullable: true + x-speakeasy-name-override: OrgDomain + c1.api.settings.v1.OrgNotificationSettings: + description: OrgNotificationSettings contains organization-wide notification channel configurations and default preferences. properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false - type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false - type: string - title: Task Audit Webhook Success + channelSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - type: "null" + title: Org Notification Settings type: object - x-speakeasy-name-override: TaskAuditWebhookSuccess - c1.api.task.v1.TaskAuditWebhookTriggered: - description: The TaskAuditWebhookTriggered message. - nullable: true + x-speakeasy-name-override: OrgNotificationSettings + c1.api.settings.v1.ProvisioningRequestPreference: + description: The ProvisioningRequestPreference message. properties: - webhookId: - description: The webhookId field. - readOnly: false - type: string - webhookInstanceId: - description: The webhookInstanceId field. - readOnly: false - type: string - webhookName: - description: The webhookName field. - readOnly: false - type: string - webhookUrl: - description: The webhookUrl field. - readOnly: false + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Provisioning Request Preference + type: object + x-speakeasy-name-override: ProvisioningRequestPreference + c1.api.settings.v1.RequestSettings: + description: RequestSettings holds tenant-wide configuration for the access-request flow. + properties: + skipJustification: + description: |- + When true, request surfaces (webapp, Slack, MS Teams) skip prompting the + requester for a justification. + type: boolean + title: Request Settings + type: object + x-speakeasy-name-override: RequestSettings + c1.api.settings.v1.ReviewsPreference: + description: The ReviewsPreference message. + properties: + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Reviews Preference + type: object + x-speakeasy-name-override: ReviewsPreference + c1.api.settings.v1.SearchEmailAuditEventsRequest: + description: The SearchEmailAuditEventsRequest message. + properties: + pageSize: + description: Maximum results per page (0 = server default, max 100). + format: int32 + type: integer + pageToken: + description: Pagination token from previous response. type: string - title: Task Audit Webhook Triggered + title: Search Email Audit Events Request type: object - x-speakeasy-name-override: TaskAuditWebhookTriggered - c1.api.task.v1.TaskExpandMask: - description: The task expand mask is an array of strings that specifes the related objects the requester wishes to have returned when making a request where the expand mask is part of the input. Use '*' to view all possible responses. + x-speakeasy-name-override: SearchEmailAuditEventsRequest + c1.api.settings.v1.SearchEmailAuditEventsResponse: + description: The SearchEmailAuditEventsResponse message. properties: - paths: - description: A list of paths to expand in the response. May be any combination of "*", "access_review_id", "user_id", "created_by_user_id", "app_id", "app_user_id", "app_entitlement_ids", "step_approver_ids", "approver_ids", "identity_user_id", "insight_ids", "app_user_last_usage", "entitlement_scope_bindings", and "scope_role_resources". + list: + description: OCSF EmailActivity events as Struct for frontend rendering. items: - type: string - nullable: true - readOnly: false - type: array - title: Task Expand Mask + additionalProperties: true + type: object + type: + - array + - "null" + nextPageToken: + description: Token for next page. Empty when no more pages. + type: string + title: Search Email Audit Events Response type: object - x-speakeasy-name-override: TaskExpandMask - c1.api.task.v1.TaskGrantSource: - description: The TaskGrantSource message tracks which external URL was the source of the specificed grant ticket. + x-speakeasy-name-override: SearchEmailAuditEventsResponse + c1.api.settings.v1.SendGridProviderConfig: + description: SendGridProviderConfig configures sending via a customer's SendGrid account. properties: - conversationId: - description: The ID of the conversation that created this ticket - readOnly: false + apiKey: + description: |- + Customer's SendGrid API key. Write-only: accepted on create/update, never returned in Get. + Empty on update means "keep existing key". type: string - externalUrl: - description: The external url source of the grant ticket. - readOnly: false + title: Send Grid Provider Config + type: object + x-speakeasy-name-override: SendGridProviderConfig + c1.api.settings.v1.SessionSettings: + description: SessionSettings configures session security for the tenant, including timeouts and per-role IP restrictions. + properties: + clientIdApprovalRequestPolicyId: + description: Policy ID for REQUESTABLE mode approval routing. type: string - integrationId: - description: The integration id for the source of tickets. - readOnly: false + clientIdMetadataDocumentPolicy: + description: Policy for metadata document client_id URLs. + enum: + - CLIENT_ID_METADATA_DOCUMENT_POLICY_UNSPECIFIED + - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOW_ALL + - CLIENT_ID_METADATA_DOCUMENT_POLICY_REQUESTABLE + - CLIENT_ID_METADATA_DOCUMENT_POLICY_ALLOWLIST_ONLY type: string - isExtension: - description: Whether the grant task is an extension task. - readOnly: false + x-speakeasy-unknown-values: allow + connectorSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + externalClientSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + externalClientsEnabled: + description: |- + Enable external client registration (OAuth 2.0 DCR) for MCP clients + like Claude Desktop, Cursor, and other AI assistants. type: boolean - requestId: - description: the request id for the grant ticket if the source is external - readOnly: false - type: string - title: Task Grant Source + maxSessionLength: + format: duration + type: + - string + - "null" + pccAdminSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + pccUserSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + ssoAdminSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + ssoUserSource: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CIDRRestriction' + - type: "null" + title: Session Settings type: object - x-speakeasy-name-override: TaskGrantSource - c1.api.task.v1.TaskRef: - description: This object references a task by ID. + x-speakeasy-name-override: SessionSettings + c1.api.settings.v1.SlackChannelSettings: + description: The SlackChannelSettings message. properties: - id: - description: The ID of the referenced Task - readOnly: false - type: string - title: Task Ref + accessProvisioned: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AccessProvisionedPreference' + - type: "null" + approvalNeeded: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ApprovalNeededPreference' + - type: "null" + commentOnRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CommentOnRequestPreference' + - type: "null" + completion: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.CompletionPreference' + - type: "null" + connectorIssues: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ConnectorIssuesPreference' + - type: "null" + digest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.DigestPreference' + - type: "null" + enabled: + description: The enabled field. + type: boolean + expiringAccess: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ExpiringAccessPreference' + - type: "null" + isConfigured: + description: The isConfigured field. + type: boolean + provisioningRequest: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ProvisioningRequestPreference' + - type: "null" + reviews: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ReviewsPreference' + - type: "null" + taskReminders: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TaskRemindersPreference' + - type: "null" + title: Slack Channel Settings type: object - x-speakeasy-name-override: TaskRef - c1.api.task.v1.TaskRevocationTarget: - description: An ancestor entitlement that will be revoked as part of an inheritance revocation. + x-speakeasy-name-override: SlackChannelSettings + c1.api.settings.v1.TaskRemindersPreference: + description: The TaskRemindersPreference message. properties: - entitlementRef: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' - title: Task Revocation Target + enabled: + description: The enabled field. + type: boolean + locked: + description: The locked field. + type: boolean + title: Task Reminders Preference type: object - x-speakeasy-name-override: TaskRevocationTarget - c1.api.task.v1.TaskRevokeSource: + x-speakeasy-name-override: TaskRemindersPreference + c1.api.settings.v1.TenantEmailProvider: description: | - The TaskRevokeSource message indicates the source of the revoke task is one of expired, nonUsage, request, or review. + TenantEmailProvider is the API representation of the tenant's email provider. - This message contains a oneof named origin. Only a single field of the following list may be set at a time: - - review - - request - - expired - - nonUsage + This message contains a oneof named provider. Only a single field of the following list may be set at a time: + - c1Builtin + - awsSes + - sendgrid + - microsoftGraph + - googleWorkspace properties: - expired: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceExpired' - nonUsage: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceNonUsage' - request: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceRequest' - review: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceReview' - title: Task Revoke Source + awsSes: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.AWSSESProviderConfig' + - type: "null" + c1Builtin: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.C1BuiltInProviderConfig' + - type: "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + fromAddress: + description: |- + Sender email address. Must be verified with the provider. + Ignored when using the C1 built-in provider (uses no-reply@conductorone.com). + type: string + fromName: + description: |- + Sender display name shown in the recipient's inbox (e.g., "Acme Corp IT"). + Used as the RFC 5322 display-name: "Acme Corp IT" . + Ignored when using the C1 built-in provider. + type: string + googleWorkspace: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.GoogleWorkspaceProviderConfig' + - type: "null" + microsoftGraph: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.MicrosoftGraphProviderConfig' + - type: "null" + replyToAddress: + description: Optional reply-to address. + type: string + sendgrid: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SendGridProviderConfig' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Tenant Email Provider type: object - x-speakeasy-name-override: TaskRevokeSource - c1.api.task.v1.TaskRevokeSourceExpired: - description: The TaskRevokeSourceExpired message indicates that the source of the revoke task is due to a grant expiring. - nullable: true + x-speakeasy-name-override: TenantEmailProvider + c1.api.settings.v1.TerraformPreferences: + description: |- + TerraformPreferences groups the user's preferences for the "Show + Terraform code" feature. properties: - expiredAt: - format: date-time - readOnly: false + showCode: + description: |- + When true, the user sees the "Show Terraform code" trigger on + supported detail pages and list rows. Defaults to false. + + Visibility is also role-gated: the trigger is shown only to users + with one of the SystemOwner, SystemOwnerReadOnly, IntegrationAdmin, + ApplicationAdmin, CampaignAdmin, or AccessRequestAdmin roles. Users + without one of these roles will not see the trigger even when this + flag is true. + type: boolean + title: Terraform Preferences + type: object + x-speakeasy-name-override: TerraformPreferences + c1.api.settings.v1.TestSourceIPRequest: + description: The TestSourceIPRequest message. + properties: + allowCidr: + description: |- + The CIDR allowlist rules to test against. If empty, uses the tenant's current allowlist. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + sourceIp: + description: |- + if unset, uses the source IP of the request. + Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. type: string - title: Task Revoke Source Expired + title: Test Source Ip Request type: object - x-speakeasy-name-override: TaskRevokeSourceExpired - c1.api.task.v1.TaskRevokeSourceNonUsage: - description: The TaskRevokeSourceNonUsage message indicates that the source of the revoke task is due to the grant not being used. - nullable: true + x-speakeasy-name-override: TestSourceIPRequest + c1.api.settings.v1.TestSourceIPResponse: + description: The TestSourceIPResponse message. properties: - expiresAt: - format: date-time - readOnly: false + allowed: + description: Whether the tested IP address is allowed by the CIDR rules. + type: boolean + checkedIp: + description: The IP address that was checked, either from the request or inferred from the caller. type: string - lastLogin: - format: date-time - readOnly: false + details: + oneOf: + - $ref: '#/components/schemas/google.rpc.Status' + - type: "null" + title: Test Source Ip Response + type: object + x-speakeasy-name-override: TestSourceIPResponse + c1.api.settings.v1.TestTenantEmailProviderRequest: + description: The TestTenantEmailProviderRequest message. + properties: + testRecipientEmail: + description: The email address to send the test email to. type: string - title: Task Revoke Source Non Usage + title: Test Tenant Email Provider Request type: object - x-speakeasy-name-override: TaskRevokeSourceNonUsage - c1.api.task.v1.TaskRevokeSourceRequest: - description: The TaskRevokeSourceRequest message indicates that the source of the revoke task was a request. - nullable: true + x-speakeasy-name-override: TestTenantEmailProviderRequest + c1.api.settings.v1.TestTenantEmailProviderResponse: + description: The TestTenantEmailProviderResponse message. properties: - requestUserId: - description: The ID of the user who initiated the revoke request. - readOnly: false + message: + description: Human-readable detail about the result. type: string - title: Task Revoke Source Request + success: + description: Whether the test email was sent successfully. + type: boolean + title: Test Tenant Email Provider Response type: object - x-speakeasy-name-override: TaskRevokeSourceRequest - c1.api.task.v1.TaskRevokeSourceReview: - description: The TaskRevokeSourceReview message tracks which access review was the source of the specificed revoke ticket. - nullable: true + x-speakeasy-name-override: TestTenantEmailProviderResponse + c1.api.settings.v1.UpdateContactsRequest: + description: The UpdateContactsRequest message. properties: - accessReviewId: - description: The ID of the access review associated with the revoke task. - readOnly: false + contacts: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Contacts Request + type: object + x-speakeasy-name-override: UpdateContactsRequest + c1.api.settings.v1.UpdateContactsResponse: + description: The UpdateContactsResponse message. + properties: + contacts: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.Contacts' + - type: "null" + title: Update Contacts Response + type: object + x-speakeasy-name-override: UpdateContactsResponse + c1.api.settings.v1.UpdateOnboardingSettingsRequest: + description: The UpdateOnboardingSettingsRequest message. + properties: + conversationId: + description: The identifier of the onboarding conversation thread to associate. type: string - certTicketId: - description: The ID of the certify ticket that was denied and created this revoke task. - readOnly: false + mcpOnboardingGoal: + description: The admin's AIAM onboarding goal. Omit to leave unchanged; set to "" to clear. + type: + - string + - "null" + mcpOnboardingStatus: + description: |- + The new MCP onboarding status to set. Omit (or UNSPECIFIED) to leave it + unchanged. Setting NOT_STARTED restarts the briefing and clears the stored + mcp_onboarding_goal and mcp_onboarding_targets, unless this same request also + sets them (those win). + enum: + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED + type: + - string + - "null" + x-speakeasy-unknown-values: allow + mcpOnboardingTargets: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTargetList' + - type: "null" + status: + description: |- + The new onboarding status to set. UNSPECIFIED leaves the core onboarding + status unchanged (set mcp_onboarding_status alone to retire the AIAM + briefing without touching the core wizard). + enum: + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED type: string - title: Task Revoke Source Review + x-speakeasy-unknown-values: allow + title: Update Onboarding Settings Request type: object - x-speakeasy-name-override: TaskRevokeSourceReview - c1.api.task.v1.TaskSearchRequest: - description: Search for tasks based on a plethora filters. + x-speakeasy-name-override: UpdateOnboardingSettingsRequest + c1.api.settings.v1.UpdateOnboardingSettingsResponse: + description: The UpdateOnboardingSettingsResponse message. properties: - accessReviewIds: - description: Search tasks that belong to any of the access reviews included in this list. - items: - type: string - nullable: true - readOnly: false - type: array - accountOwnerIds: - description: Search tasks that have any of these account owners. - items: - type: string - nullable: true - readOnly: false - type: array - accountTypes: - description: The accountTypes field. - items: - enum: - - APP_USER_TYPE_UNSPECIFIED - - APP_USER_TYPE_USER - - APP_USER_TYPE_SERVICE_ACCOUNT - - APP_USER_TYPE_SYSTEM_ACCOUNT - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - actorId: - description: Search tasks that have this actor ID. - readOnly: false + mcpOnboardingGoal: + description: The updated AIAM onboarding goal. type: string - appEntitlementIds: - description: Search tasks that have any of these app entitlement IDs. - items: - type: string - nullable: true - readOnly: false - type: array - appResourceIds: - description: Search tasks that have any of these app resource IDs. + mcpOnboardingStatus: + description: The updated AIAM MCP onboarding status. + enum: + - MCP_ONBOARDING_STATUS_UNSPECIFIED + - MCP_ONBOARDING_STATUS_NOT_STARTED + - MCP_ONBOARDING_STATUS_IN_PROGRESS + - MCP_ONBOARDING_STATUS_COMPLETE + - MCP_ONBOARDING_STATUS_DISMISSED + type: string + x-speakeasy-unknown-values: allow + mcpOnboardingTargets: + description: The updated AIAM onboarding targets. items: - type: string - nullable: true - readOnly: false - type: array - appResourceTypeIds: - description: Search tasks that have any of these app resource type IDs. + $ref: '#/components/schemas/c1.api.settings.v1.McpOnboardingTarget' + type: + - array + - "null" + status: + description: The updated onboarding status. + enum: + - ONBOARDING_STATUS_UNSPECIFIED + - ONBOARDING_STATUS_NOT_STARTED + - ONBOARDING_STATUS_IN_PROGRESS + - ONBOARDING_STATUS_COMPLETE + - ONBOARDING_STATUS_DISMISSED + type: string + x-speakeasy-unknown-values: allow + title: Update Onboarding Settings Response + type: object + x-speakeasy-name-override: UpdateOnboardingSettingsResponse + c1.api.settings.v1.UpdateOrgDomainRequest: + description: The UpdateOrgDomainRequest message. + properties: + newDomains: + description: The complete list of domain names that should be set as the tenant's verified domains. items: type: string - nullable: true - readOnly: false - type: array - appUserSubjectIds: - description: Search tasks that have any of these app users as subjects. + type: + - array + - "null" + title: Update Org Domain Request + type: object + x-speakeasy-name-override: UpdateOrgDomainRequest + c1.api.settings.v1.UpdateOrgDomainResponse: + description: The UpdateOrgDomainResponse message. + properties: + list: + description: The resulting list of verified domains after the update. items: - type: string - nullable: true - readOnly: false - type: array - applicationIds: - description: Search tasks that have any of these apps as targets. - items: - type: string - nullable: true - readOnly: false - type: array - assignedOrStepApproverUserId: - description: Search tasks that are currently assigned to this user, or that are closed and were previously approved by this user. - readOnly: false + $ref: '#/components/schemas/c1.api.settings.v1.OrgDomain' + type: + - array + - "null" + title: Update Org Domain Response + type: object + x-speakeasy-name-override: UpdateOrgDomainResponse + c1.api.settings.v1.UpdateOrgNotificationSettingsRequest: + description: The UpdateOrgNotificationSettingsRequest message. + properties: + channelSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - type: "null" + title: Update Org Notification Settings Request + type: object + x-speakeasy-name-override: UpdateOrgNotificationSettingsRequest + c1.api.settings.v1.UpdateOrgNotificationSettingsResponse: + description: The UpdateOrgNotificationSettingsResponse message. + properties: + orgNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.OrgNotificationSettings' + - type: "null" + title: Update Org Notification Settings Response + type: object + x-speakeasy-name-override: UpdateOrgNotificationSettingsResponse + c1.api.settings.v1.UpdateRequestSettingsRequest: + description: The UpdateRequestSettingsRequest message. + properties: + requestSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Request Settings Request + type: object + x-speakeasy-name-override: UpdateRequestSettingsRequest + c1.api.settings.v1.UpdateRequestSettingsResponse: + description: The UpdateRequestSettingsResponse message. + properties: + requestSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.RequestSettings' + - type: "null" + title: Update Request Settings Response + type: object + x-speakeasy-name-override: UpdateRequestSettingsResponse + c1.api.settings.v1.UpdateSessionSettingsRequest: + description: The UpdateSessionSettingsRequest message. + properties: + sessionSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Session Settings Request + type: object + x-speakeasy-name-override: UpdateSessionSettingsRequest + c1.api.settings.v1.UpdateSessionSettingsResponse: + description: The UpdateSessionSettingsResponse message. + properties: + sessionSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.SessionSettings' + - type: "null" + title: Update Session Settings Response + type: object + x-speakeasy-name-override: UpdateSessionSettingsResponse + c1.api.settings.v1.UpdateTenantEmailProviderRequest: + description: The UpdateTenantEmailProviderRequest message. + properties: + emailProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Tenant Email Provider Request + type: object + x-speakeasy-name-override: UpdateTenantEmailProviderRequest + c1.api.settings.v1.UpdateTenantEmailProviderResponse: + description: The UpdateTenantEmailProviderResponse message. + properties: + emailProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TenantEmailProvider' + - type: "null" + title: Update Tenant Email Provider Response + type: object + x-speakeasy-name-override: UpdateTenantEmailProviderResponse + c1.api.settings.v1.UpdateUserDeveloperPreferencesRequest: + description: The UpdateUserDeveloperPreferencesRequest message. + properties: + terraform: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' + - type: "null" + title: Update User Developer Preferences Request + type: object + x-speakeasy-name-override: UpdateUserDeveloperPreferencesRequest + c1.api.settings.v1.UpdateUserDeveloperPreferencesResponse: + description: The UpdateUserDeveloperPreferencesResponse message. + properties: + userDeveloperPreferences: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserDeveloperPreferences' + - type: "null" + title: Update User Developer Preferences Response + type: object + x-speakeasy-name-override: UpdateUserDeveloperPreferencesResponse + c1.api.settings.v1.UpdateUserNotificationSettingsRequest: + description: The UpdateUserNotificationSettingsRequest message. + properties: + channelSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - type: "null" + title: Update User Notification Settings Request + type: object + x-speakeasy-name-override: UpdateUserNotificationSettingsRequest + c1.api.settings.v1.UpdateUserNotificationSettingsResponse: + description: The UpdateUserNotificationSettingsResponse message. + properties: + userNotificationSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.UserNotificationSettings' + - type: "null" + title: Update User Notification Settings Response + type: object + x-speakeasy-name-override: UpdateUserNotificationSettingsResponse + c1.api.settings.v1.UserDeveloperPreferences: + description: |- + UserDeveloperPreferences holds a user's developer-tooling preferences, + organized into per-feature clusters. + properties: + terraform: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.TerraformPreferences' + - type: "null" + title: User Developer Preferences + type: object + x-speakeasy-name-override: UserDeveloperPreferences + c1.api.settings.v1.UserNotificationSettings: + description: UserNotificationSettings contains the calling user's personal notification preferences. + properties: + channelSettings: + oneOf: + - $ref: '#/components/schemas/c1.api.settings.v1.ChannelSettings' + - type: "null" + title: User Notification Settings + type: object + x-speakeasy-name-override: UserNotificationSettings + c1.api.sign_in_policy.v1.Allow: + description: Allow permits the sign-in. + properties: + floorLevel: + description: |- + The minimum assurance level that satisfies this rule. Required on enforced + Allow rules. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH type: string - assigneesInIds: - description: Search tasks by List of UserIDs which are currently assigned these Tasks + x-speakeasy-unknown-values: allow + title: Allow + type: object + x-speakeasy-name-override: Allow + c1.api.sign_in_policy.v1.ChallengeRequired: + description: ChallengeRequired asks for an additional factor before the sign-in completes. + properties: + types: + description: The credential types that may satisfy the challenge. items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - nullable: true - readOnly: false - type: array - certifyOutcomes: - description: Search tasks by certify outcome + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Challenge Required + type: object + x-speakeasy-name-override: ChallengeRequired + c1.api.sign_in_policy.v1.Deny: + description: Deny rejects the sign-in. + properties: + reasonAdmin: + description: Reason shown in admin-only audit. + type: string + reasonUser: + description: Reason safe to show the end user. + type: string + title: Deny + type: object + x-speakeasy-name-override: Deny + c1.api.sign_in_policy.v1.EnrollmentRequired: + description: EnrollmentRequired tells the user to enroll a credential before continuing. + properties: + credentialTypes: + description: |- + The credential types the user may enroll. Empty means "complete identity + verification first". items: enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - createdAfter: - format: date-time - readOnly: false + type: + - array + - "null" + title: Enrollment Required + type: object + x-speakeasy-name-override: EnrollmentRequired + c1.api.sign_in_policy.v1.PolicyOutcome: + description: | + PolicyOutcome is the effect of a matched rule. Exactly one kind is set. + + This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - allow + - deny + - stepUpRequired + - challengeRequired + - enrollmentRequired + properties: + allow: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Allow' + - type: "null" + challengeRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.ChallengeRequired' + - type: "null" + deny: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Deny' + - type: "null" + enrollmentRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.EnrollmentRequired' + - type: "null" + stepUpRequired: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.StepUpRequired' + - type: "null" + title: Policy Outcome + type: object + x-speakeasy-name-override: PolicyOutcome + c1.api.sign_in_policy.v1.PolicyRule: + description: |- + PolicyRule is one rung of the ordered sign-in cascade. Rules are evaluated + top to bottom; the first enforced rule whose condition matches supplies the + outcome. + properties: + description: + description: A human-readable description shown in the admin UI. type: string - createdBefore: - format: date-time - readOnly: false + id: + description: A stable identifier for the rule, surfaced in audit. type: string - currentStep: - description: Search tasks that have this type of step as the current step. - enum: - - TASK_SEARCH_CURRENT_STEP_UNSPECIFIED - - TASK_SEARCH_CURRENT_STEP_APPROVAL - - TASK_SEARCH_CURRENT_STEP_PROVISION - readOnly: false + matchCel: + description: A boolean condition expression evaluated against the sign-in context. type: string - x-speakeasy-unknown-values: allow - emergencyStatus: - description: Search tasks that are or are not emergency access. + mode: + description: Whether the rule is live, evaluated-only, or skipped. enum: - - UNSPECIFIED - - ALL - - NON_EMERGENCY - - EMERGENCY - readOnly: false + - POLICY_RULE_MODE_UNSPECIFIED + - POLICY_RULE_MODE_ENFORCE + - POLICY_RULE_MODE_OBSERVE + - POLICY_RULE_MODE_DISABLED type: string x-speakeasy-unknown-values: allow - excludeAppEntitlementIds: - description: Search tasks that do not have any of these app entitlement IDs. - items: - type: string - nullable: true - readOnly: false - type: array - excludeAppResourceTypeIds: - description: Search tasks that do not have any of these app resource type IDs. - items: - type: string - nullable: true - readOnly: false - type: array - excludeApplicationIds: - description: Search tasks that do NOT have any of these apps as targets. - items: - type: string - nullable: true - readOnly: false - type: array - excludeIds: - description: Exclude Specific TaskIDs from this serach result. - items: - type: string - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - grantOutcomes: - description: Search tasks by grant outcome + outcome: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' + - type: "null" + title: Policy Rule + type: object + x-speakeasy-name-override: PolicyRule + c1.api.sign_in_policy.v1.SignInPolicy: + description: SignInPolicy defines how users sign in. + properties: + allowedMfaTypes: + description: |- + The credential types accepted as a second factor. Must be a subset of the + credential types their inventory policy permits. items: enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - includeActedAfter: - format: date-time - readOnly: false - type: string - includeDeleted: - description: Whether or not to include deleted tasks. - readOnly: false - type: boolean - myWorkUserIds: - description: Search tasks where the user would see this task in the My Work section - items: - type: string - nullable: true - readOnly: false - type: array - olderThanDuration: - format: duration - readOnly: false - type: string - openerIds: - description: Search tasks that were created by any of the users in this array. + type: + - array + - "null" + allowedPrimaryTypes: + description: |- + The primary credential types users may sign in with. Must be a subset of + the credential types their inventory policy permits. items: + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string - nullable: true - readOnly: false - type: array - openerOrSubjectUserId: - description: Search tasks that were opened by this user, or that the user is the subject of. - readOnly: false - type: string - outcomeAfter: + x-speakeasy-unknown-values: allow + type: + - array + - "null" + createdAt: format: date-time - readOnly: false - type: string - outcomeBefore: + readOnly: true + type: + - string + - "null" + defaultOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' + - type: "null" + deletedAt: format: date-time - readOnly: false + readOnly: true + type: + - string + - "null" + displayName: + description: A human-readable name for the policy. type: string - pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + id: + description: Unique identifier for the policy. + readOnly: true type: string - pendingActionFilter: + isBuiltin: description: |- - Filter tasks by pending action status. Only applies when exactly one access_review_id is specified. - Requires the REVIEWS_PENDING_ACTIONS feature flag to be enabled. - enum: - - PENDING_ACTION_FILTER_UNSPECIFIED - - PENDING_ACTION_FILTER_WITH_PENDING - - PENDING_ACTION_FILTER_WITHOUT_PENDING - readOnly: false - type: string - x-speakeasy-unknown-values: allow - previouslyActedOnIds: - description: Search tasks that were acted on by any of these users. - items: - type: string - nullable: true - readOnly: false - type: array - query: - description: Fuzzy search tasks by display name, description, or ID. - readOnly: false - type: string - refs: - description: Query tasks by display name, description, or numeric ID. - items: - $ref: '#/components/schemas/c1.api.task.v1.TaskRef' - nullable: true - readOnly: false - type: array - requireApprovalReason: - description: Filter tasks where the current approval step requires an approval reason. - readOnly: false - type: boolean - requireDenialReason: - description: Filter tasks where the current approval step requires a denial reason. - readOnly: false + True for built-in policies provided by ConductorOne. Built-in policies + cannot be edited or deleted. + readOnly: true type: boolean - revokeOutcomes: - description: Search tasks by revoke outcome + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + rules: + description: The ordered rule cascade, evaluated top to bottom. items: - enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - sortBy: - description: Sort tasks in a specific order. - enum: - - TASK_SEARCH_SORT_BY_UNSPECIFIED - - TASK_SEARCH_SORT_BY_ACCOUNT - - TASK_SEARCH_SORT_BY_RESOURCE - - TASK_SEARCH_SORT_BY_ACCOUNT_OWNER - - TASK_SEARCH_SORT_BY_REVERSE_TICKET_ID - - TASK_SEARCH_SORT_BY_TICKET_ID - - TASK_SEARCH_SORT_BY_CREATED_AT - - TASK_SEARCH_SORT_BY_REVERSE_CREATED_AT - - TASK_SEARCH_SORT_BY_APP_RESOURCE_ID_AND_APP_ENTITLEMENT - readOnly: false + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + type: + - array + - "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Sign In Policy + type: object + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicy + c1.api.sign_in_policy.v1.SignInPolicyRef: + description: SignInPolicyRef is a lightweight reference to a sign-in policy by ID. + properties: + id: + description: The id field. type: string - x-speakeasy-unknown-values: allow - stepApprovalTypes: - description: Search tasks that have a current policy step of this type + title: Sign In Policy Ref + type: object + x-speakeasy-name-override: SignInPolicyRef + c1.api.sign_in_policy.v1.SignInPolicyServiceCreateRequest: + description: The SignInPolicyServiceCreateRequest message. + properties: + allowedMfaTypes: + description: The credential types accepted as a second factor. items: enum: - - STEP_APPROVAL_TYPE_UNSPECIFIED - - STEP_APPROVAL_TYPE_USERS - - STEP_APPROVAL_TYPE_MANAGER - - STEP_APPROVAL_TYPE_APP_OWNERS - - STEP_APPROVAL_TYPE_GROUP - - STEP_APPROVAL_TYPE_SELF - - STEP_APPROVAL_TYPE_ENTITLEMENT_OWNERS - - STEP_APPROVAL_TYPE_EXPRESSION - - STEP_APPROVAL_TYPE_WEBHOOK - - STEP_APPROVAL_TYPE_RESOURCE_OWNERS - - STEP_APPROVAL_TYPE_AGENT + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - subjectIds: - description: Search tasks where these users are the subject. - items: - type: string - nullable: true - readOnly: false - type: array - taskStates: - description: Search tasks with this task state. + type: + - array + - "null" + allowedPrimaryTypes: + description: The primary credential types users may sign in with. items: enum: - - TASK_STATE_UNSPECIFIED - - TASK_STATE_OPEN - - TASK_STATE_CLOSED + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP type: string x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - taskTypes: - description: Search tasks with this task type. This is a oneOf, and needs an object, which can be empty, to sort. - items: - $ref: '#/components/schemas/c1.api.task.v1.TaskType' - nullable: true - readOnly: false - type: array - userEmploymentStatuses: - description: The userEmploymentStatuses field. + type: + - array + - "null" + defaultOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome' + - type: "null" + displayName: + description: A human-readable name for the policy. + type: string + priority: + description: |- + When a user matches more than one policy, the policy with the highest + priority applies. + format: int32 + type: integer + rules: + description: The ordered rule cascade. items: - type: string - nullable: true - readOnly: false - type: array - title: Task Search Request - type: object - x-speakeasy-name-override: TaskSearchRequest - c1.api.task.v1.TaskSearchResponse: - description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule' + type: + - array + - "null" + required: + - displayName + title: Sign In Policy Service Create Request + type: object + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicyServiceCreateRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceCreateResponse: + description: The SignInPolicyServiceCreateResponse message. + properties: + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Create Response + type: object + x-speakeasy-name-override: SignInPolicyServiceCreateResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteRequestInput: + description: The SignInPolicyServiceDeleteRequest message. + title: Sign In Policy Service Delete Request + type: object + x-speakeasy-entity: SignInPolicy + x-speakeasy-name-override: SignInPolicyServiceDeleteRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteResponse: + description: The SignInPolicyServiceDeleteResponse message. + title: Sign In Policy Service Delete Response + type: object + x-speakeasy-name-override: SignInPolicyServiceDeleteResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceGetResponse: + description: The SignInPolicyServiceGetResponse message. + properties: + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Get Response + type: object + x-speakeasy-name-override: SignInPolicyServiceGetResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceListResponse: + description: The SignInPolicyServiceListResponse message. properties: - expanded: - description: The list of results containing up to X results, where X is the page size defined in the request. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: - description: List of serialized related objects. + description: The page of policies. items: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: A token to fetch the next page, or empty if there are no more results. type: string - title: Task Search Response + title: Sign In Policy Service List Response type: object - x-speakeasy-name-override: TaskSearchResponse - c1.api.task.v1.TaskServiceActionResponse: - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + x-speakeasy-name-override: SignInPolicyServiceListResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest: + description: The SignInPolicyServiceSearchRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - ticketActionId: - description: The ID of the task action created by this request. - readOnly: false + pageSize: + description: The maximum number of results to return per page. + format: int32 + type: integer + pageToken: + description: A pagination token from a previous Search response. type: string - title: Task Service Action Response + query: + description: Free-text search over the policy name. Empty matches all policies. + type: string + refs: + description: Restrict results to these specific policies. Empty matches all policies. + items: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyRef' + type: + - array + - "null" + title: Sign In Policy Service Search Request type: object - x-speakeasy-name-override: TaskServiceActionResponse - c1.api.task.v1.TaskServiceCreateGrantRequest: - description: Create a grant task. + x-speakeasy-name-override: SignInPolicyServiceSearchRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse: + description: The SignInPolicyServiceSearchResponse message. properties: - appEntitlementId: - description: The ID of the app entitlement to grant access to. - readOnly: false - type: string - appId: - description: The ID of the app that is associated with the entitlement. - readOnly: false - type: string - appUserId: - description: The ID of the app user to grant access for. This field and identityUserId cannot both be set for a given request. - readOnly: false - type: string - description: - description: The description of the request. - readOnly: false - type: string - emergencyAccess: - description: Boolean stating whether or not the task is marked as emergency access. - readOnly: false - type: boolean - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - grantDuration: - format: duration - readOnly: false - type: string - identityUserId: - description: The ID of the user associated with the app user we are granting access for. This field cannot be set if appUserID is also set. - readOnly: false + list: + description: The page of matching policies. + items: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + type: + - array + - "null" + nextPageToken: + description: A token to fetch the next page, or empty if there are no more results. type: string - requestData: - additionalProperties: true - readOnly: false - type: object - source: - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' - required: - - appId - - appEntitlementId - title: Task Service Create Grant Request + title: Sign In Policy Service Search Response type: object - x-speakeasy-name-override: TaskServiceCreateGrantRequest - c1.api.task.v1.TaskServiceCreateGrantResponse: - description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SignInPolicyServiceSearchResponse + c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput: + description: The SignInPolicyServiceUpdateRequest message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Service Create Grant Response + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + updateMask: + type: + - string + - "null" + title: Sign In Policy Service Update Request type: object - x-speakeasy-name-override: TaskServiceCreateGrantResponse - c1.api.task.v1.TaskServiceCreateOffboardingRequest: - description: Create an offboarding task. + x-speakeasy-name-override: SignInPolicyServiceUpdateRequest + c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse: + description: The SignInPolicyServiceUpdateResponse message. properties: - description: - description: The description of the offboarding request. - readOnly: false - type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - subjectUserId: - description: The ID of the user to offboard. - readOnly: false - type: string - title: Task Service Create Offboarding Request + signInPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy' + - type: "null" + title: Sign In Policy Service Update Response type: object - x-speakeasy-name-override: TaskServiceCreateOffboardingRequest - c1.api.task.v1.TaskServiceCreateOffboardingResponse: - description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. + x-speakeasy-name-override: SignInPolicyServiceUpdateResponse + c1.api.sign_in_policy.v1.StepUpRequired: + description: StepUpRequired demands a stronger re-authentication before access is granted. properties: - expanded: - description: List of serialized related objects. + level: + description: The assurance level the step-up must reach. + enum: + - AUTH_LEVEL_UNSPECIFIED + - AUTH_LEVEL_NONE + - AUTH_LEVEL_SINGLE_FACTOR + - AUTH_LEVEL_MULTI_FACTOR + - AUTH_LEVEL_PHR + - AUTH_LEVEL_PHRH + type: string + x-speakeasy-unknown-values: allow + maxAgeSeconds: + description: How fresh the step-up must be, in seconds. + format: int32 + type: integer + types: + description: The credential types that may satisfy the step-up. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Service Create Offboarding Response + enum: + - CREDENTIAL_TYPE_UNSPECIFIED + - CREDENTIAL_TYPE_PASSKEY + - CREDENTIAL_TYPE_PASSWORD + - CREDENTIAL_TYPE_TOTP + - CREDENTIAL_TYPE_EMAIL_OTP + - CREDENTIAL_TYPE_RECOVERY_CODE + - CREDENTIAL_TYPE_DELEGATED_GOOGLE + - CREDENTIAL_TYPE_DELEGATED_MICROSOFT + - CREDENTIAL_TYPE_UPSTREAM_IDP + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Step Up Required type: object - x-speakeasy-name-override: TaskServiceCreateOffboardingResponse - c1.api.task.v1.TaskServiceCreateRevokeRequest: - description: Create a revoke task. + x-speakeasy-name-override: StepUpRequired + c1.api.ssf_receiver.v1.SSFOutboundAuthBearer: + description: |- + SSFOutboundAuthBearer is a static bearer token for outbound auth. + Token is write-only: accepted on create/update, never returned. properties: - appEntitlementId: - description: The ID of the app entitlement to revoke access to. - readOnly: false - type: string - appId: - description: The ID of the app associated with the entitlement. - readOnly: false - type: string - appUserId: - description: The ID of the app user to revoke access from. This field and identityUserId cannot both be set for a given request. - readOnly: false - type: string - description: - description: The description of the request. - readOnly: false - type: string - expandMask: - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' - identityUserId: - description: The ID of the user associated with the app user we are revoking access from. This field cannot be set if appUserID is also set. - readOnly: false + token: + description: The token field. type: string - required: - - appId - - appEntitlementId - title: Task Service Create Revoke Request + title: Ssf Outbound Auth Bearer type: object - x-speakeasy-name-override: TaskServiceCreateRevokeRequest - c1.api.task.v1.TaskServiceCreateRevokeResponse: - description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SSFOutboundAuthBearer + c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2: + description: |- + SSFOutboundAuthOAuth2 uses OAuth2 client credentials for outbound auth. + client_secret is write-only: accepted on create/update, never returned. properties: - expanded: - description: List of serialized related objects. + clientId: + description: The clientId field. + type: string + clientSecret: + description: The clientSecret field. + type: string + scopes: + description: The scopes field. items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Service Create Revoke Response + type: string + type: + - array + - "null" + tokenUrl: + description: The tokenUrl field. + type: string + title: Ssf Outbound Auth O Auth 2 type: object - x-speakeasy-name-override: TaskServiceCreateRevokeResponse - c1.api.task.v1.TaskServiceGetResponse: - description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: SSFOutboundAuthOAuth2 + c1.api.ssf_receiver.v1.SSFReceiverEvent: + description: SSFReceiverEvent shows both wire-level data and C1 canonical outcome. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: true - type: object - nullable: true - readOnly: true - type: array - taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Task Service Get Response - type: object - x-speakeasy-name-override: TaskServiceGetResponse - c1.api.task.v1.TaskType: - description: | - Task Type provides configuration for the type of task: certify, grant, or revoke - - This message contains a oneof named task_type. Only a single field of the following list may be set at a time: - - grant - - revoke - - certify - - offboarding - - action - - finding - properties: - action: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeAction' - certify: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeCertify' - finding: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeFinding' - grant: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeGrant' - offboarding: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeOffboarding' - revoke: - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeRevoke' - title: Task Type - type: object - x-speakeasy-name-override: TaskType - c1.api.task.v1.TaskTypeAction: - description: | - The TaskTypeAction message. - - This message contains a oneof named target_object. Only a single field of the following list may be set at a time: - - scopeRole - nullable: true - properties: - actionId: + canonicalType: description: |- - The ID of the admin-authored action to execute. Empty for synthesized - action tickets (e.g. scope-role grants) — those carry dispatch - configuration on action_instance and target_object instead. - readOnly: true + C1 canonical outcome (what C1 understood and did). + The normalized event type after mapping from the wire event type. + enum: + - SSF_CANONICAL_EVENT_TYPE_UNSPECIFIED + - SSF_CANONICAL_EVENT_TYPE_UNRECOGNIZED + - SSF_CANONICAL_EVENT_TYPE_SESSION_REVOKED + - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_TOKEN_CLAIMS_CHANGED + - SSF_CANONICAL_EVENT_TYPE_ASSURANCE_LEVEL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_DEVICE_COMPLIANCE_CHANGED + - SSF_CANONICAL_EVENT_TYPE_RISK_LEVEL_CHANGED + - SSF_CANONICAL_EVENT_TYPE_SESSION_ESTABLISHED + - SSF_CANONICAL_EVENT_TYPE_SESSION_PRESENTED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_DISABLED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_ENABLED + - SSF_CANONICAL_EVENT_TYPE_ACCOUNT_PURGED + - SSF_CANONICAL_EVENT_TYPE_CREDENTIAL_COMPROMISE + - SSF_CANONICAL_EVENT_TYPE_RECOVERY_ACTIVATED + - SSF_CANONICAL_EVENT_TYPE_IDENTIFIER_CHANGED + - SSF_CANONICAL_EVENT_TYPE_VERIFICATION + - SSF_CANONICAL_EVENT_TYPE_STREAM_UPDATED type: string - actionInstance: - $ref: '#/components/schemas/c1.api.task.v1.ActionInstance' - displayName: - description: |- - Display label captured on the action snapshot at ticket-creation time. - Stable under admin renames to a referenced Action row and populated for - synthesized tickets that have no Action row at all. UI reads this to - render the task title without an Action fetch. - readOnly: true + x-speakeasy-unknown-values: allow + id: + description: The unique identifier of this event. type: string - formValues: - additionalProperties: true - readOnly: true - type: object - outcome: - description: The outcome field. + matchMethod: + description: How the upstream subject was resolved to a ConductorOne user. enum: - - ACTION_OUTCOME_UNSPECIFIED - - ACTION_OUTCOME_SUCCESS - - ACTION_OUTCOME_DENIED - - ACTION_OUTCOME_ERROR - - ACTION_OUTCOME_CANCELLED - readOnly: true + - SSF_SUBJECT_MATCH_METHOD_UNSPECIFIED + - SSF_SUBJECT_MATCH_METHOD_IDP_USER + - SSF_SUBJECT_MATCH_METHOD_EMAIL + - SSF_SUBJECT_MATCH_METHOD_NOT_FOUND + - SSF_SUBJECT_MATCH_METHOD_NOT_APPLICABLE type: string x-speakeasy-unknown-values: allow - outcomeTime: - format: date-time - readOnly: true + matchedUserId: + description: The ConductorOne user ID that the event subject was resolved to, if any. type: string - scopeRole: - $ref: '#/components/schemas/c1.api.task.v1.ScopeRole' - type: - description: |- - Flavor of action the ticket represents — mirrors the snapshot's - target_ref variant. + outcome: + description: The action ConductorOne took in response to this event. enum: - - TYPE_UNSPECIFIED - - TYPE_GRANT - - TYPE_WORKFLOW - - TYPE_RESOURCE_ACTION - readOnly: true + - SSF_EVENT_OUTCOME_UNSPECIFIED + - SSF_EVENT_OUTCOME_SESSIONS_REVOKED + - SSF_EVENT_OUTCOME_LOGGED + - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND + - SSF_EVENT_OUTCOME_VERIFIED + - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED + - SSF_EVENT_OUTCOME_UNRECOGNIZED + - SSF_EVENT_OUTCOME_ERROR type: string x-speakeasy-unknown-values: allow - title: Task Type Action - type: object - x-speakeasy-name-override: TaskTypeAction - c1.api.task.v1.TaskTypeCertify: - description: The TaskTypeCertify message indicates that a task is a certify task and all related details. - nullable: true - properties: - accessReviewId: - description: The ID of the access review. - readOnly: true + outcomeDetail: + description: Human-readable details about the outcome (e.g., error message or revocation summary). type: string - accessReviewSelection: - description: The ID of the specific access review object that owns this certify task. This is also set on a revoke task if the revoke task is created from the denied outcome of a certify task. - readOnly: true + receivedAt: + format: date-time + type: + - string + - "null" + sessionsRevoked: + description: Number of sessions that were revoked as a result of this event. + format: int32 + type: integer + setJti: + description: |- + Wire-level data (what the transmitter sent). + The SET (Security Event Token) JWT ID claim, uniquely identifying the token. type: string - appEntitlementId: - description: The ID of the app entitlement. - readOnly: true + streamId: + description: The SSF receiver stream that received this event. type: string - appId: - description: The ID of the app. - readOnly: true + wireEventProfile: + description: The event profile URI from the SET, if present. type: string - appUserId: - description: The ID of the app user. - readOnly: true + wireEventType: + description: The raw event type URI from the SET (e.g., "https://schemas.openid.net/secevent/caep/event-type/session-revoked"). type: string - identityUserId: - description: The ID of the user. - readOnly: true + wireInitiatingEntity: + description: The entity that initiated the event, as reported by the transmitter. type: string - outcome: - description: The outcome of the certification. - enum: - - CERTIFY_OUTCOME_UNSPECIFIED - - CERTIFY_OUTCOME_CERTIFIED - - CERTIFY_OUTCOME_DECERTIFIED - - CERTIFY_OUTCOME_ERROR - - CERTIFY_OUTCOME_CANCELLED - - CERTIFY_OUTCOME_WAIT_TIMED_OUT - readOnly: true + wireReasonAdmin: + description: The admin-facing reason string from the SET, if provided by the transmitter. type: string - x-speakeasy-unknown-values: allow - outcomeTime: - format: date-time - readOnly: true + wireSubjectFormat: + description: The subject identifier format from the SET (e.g., "email", "iss_sub"). type: string - title: Task Type Certify + wireSubjectIdentifier: + description: The raw subject identifier value from the SET. + type: string + title: Ssf Receiver Event type: object - x-speakeasy-name-override: TaskTypeCertify - c1.api.task.v1.TaskTypeFinding: - description: The TaskTypeFinding message. - nullable: true + x-speakeasy-name-override: SSFReceiverEvent + c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest: + description: SSFReceiverEventSearchServiceSearchRequest carries the search query and optional filters for narrowing results. properties: - findingId: - description: Reference to the source finding. - readOnly: true + eventType: + description: Restricts results to events matching this wire event type URI. Optional. type: string - findingType: - description: The finding type discriminator. - readOnly: true + matchedUserId: + description: Restricts results to events matched to this ConductorOne user ID. Optional. type: string outcome: - description: The outcome field. + description: Restricts results to events with this processing outcome. Optional. enum: - - FINDING_TASK_OUTCOME_UNSPECIFIED - - FINDING_TASK_OUTCOME_REMEDIATED - - FINDING_TASK_OUTCOME_RISK_ACCEPTED - - FINDING_TASK_OUTCOME_CANCELLED - readOnly: true + - SSF_EVENT_OUTCOME_UNSPECIFIED + - SSF_EVENT_OUTCOME_SESSIONS_REVOKED + - SSF_EVENT_OUTCOME_LOGGED + - SSF_EVENT_OUTCOME_PRINCIPAL_NOT_FOUND + - SSF_EVENT_OUTCOME_VERIFIED + - SSF_EVENT_OUTCOME_STREAM_STATUS_UPDATED + - SSF_EVENT_OUTCOME_UNRECOGNIZED + - SSF_EVENT_OUTCOME_ERROR type: string x-speakeasy-unknown-values: allow - outcomeTime: - format: date-time - readOnly: true - type: string - title: Task Type Finding - type: object - x-speakeasy-name-override: TaskTypeFinding - c1.api.task.v1.TaskTypeGrant: - description: The TaskTypeGrant message indicates that a task is a grant task and all related details. - nullable: true - properties: - appEntitlementId: - description: The ID of the app entitlement. - readOnly: true + pageSize: + description: Maximum number of events to return per page. + format: int32 + type: integer + pageToken: + description: Token from a previous SearchResponse to fetch the next page of results. type: string - appId: - description: The ID of the app. - readOnly: true + query: + description: Full-text search query matched against event fields. type: string - appUserId: - description: The ID of the app user. - readOnly: true + streamId: + description: Restricts results to events from this SSF receiver stream. Optional. type: string - grantDuration: - format: duration - readOnly: true + title: Ssf Receiver Event Search Service Search Request + type: object + x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchRequest + c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse: + description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. + properties: + list: + description: The SSF events matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - identityUserId: - description: The ID of the user. - readOnly: true + title: Ssf Receiver Event Search Service Search Response + type: object + x-speakeasy-name-override: SSFReceiverEventSearchServiceSearchResponse + c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse: + description: SSFReceiverEventServiceListResponse contains a page of received SSF events. + properties: + list: + description: The SSF events in the current page. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEvent' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - outcome: - description: The outcome of the grant. + title: Ssf Receiver Event Service List Response + type: object + x-speakeasy-name-override: SSFReceiverEventServiceListResponse + c1.api.ssf_receiver.v1.SSFReceiverStream: + description: | + SSFReceiverStream is the public API representation. + Secrets (push_auth_token, outbound credentials) are write-only. + + This message contains a oneof named outbound_auth. Only a single field of the following list may be set at a time: + - outboundAuthBearer + - outboundAuthOauth2 + properties: + accountDisabledAction: + description: Action to take when an account-disabled event is received. enum: - - GRANT_OUTCOME_UNSPECIFIED - - GRANT_OUTCOME_GRANTED - - GRANT_OUTCOME_DENIED - - GRANT_OUTCOME_ERROR - - GRANT_OUTCOME_CANCELLED - - GRANT_OUTCOME_WAIT_TIMED_OUT - readOnly: true + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - outcomeTime: + createdAt: format: date-time readOnly: true + type: + - string + - "null" + credentialChangeAction: + description: Action to take when a credential-change event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - source: - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' - title: Task Type Grant - type: object - x-speakeasy-name-override: TaskTypeGrant - c1.api.task.v1.TaskTypeOffboarding: - description: The TaskTypeOffboarding message. - nullable: true - properties: - outcome: - description: The outcome field. + x-speakeasy-unknown-values: allow + credentialCompromiseAction: + description: Action to take when a credential-compromise event is received. enum: - - OFFBOARDING_OUTCOME_UNSPECIFIED - - OFFBOARDING_OUTCOME_IN_PROGRESS - - OFFBOARDING_OUTCOME_DONE - - OFFBOARDING_OUTCOME_ERROR - - OFFBOARDING_OUTCOME_CANCELLED - readOnly: true + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - outcomeTime: + deletedAt: format: date-time readOnly: true + type: + - string + - "null" + deliveryMethod: + description: Controls whether events are received via push (transmitter POSTs to C1) or poll (C1 fetches from transmitter). + enum: + - SSF_DELIVERY_METHOD_UNSPECIFIED + - SSF_DELIVERY_METHOD_PUSH + - SSF_DELIVERY_METHOD_POLL type: string - subjectUserId: - description: The subjectUserId field. - readOnly: true + x-speakeasy-unknown-values: allow + description: + description: Optional description of the stream's purpose or source. type: string - title: Task Type Offboarding - type: object - x-speakeasy-name-override: TaskTypeOffboarding - c1.api.task.v1.TaskTypeRevoke: - description: The TaskTypeRevoke message indicates that a task is a revoke task and all related details. - nullable: true - properties: - appEntitlementId: - description: The ID of the app entitlement. - readOnly: true + displayName: + description: Human-readable name for the stream shown in the UI. type: string - appId: - description: The ID of the app. - readOnly: true + enabled: + description: Controls whether this stream actively processes incoming events. When false, events are ignored. + type: boolean + eventTypesEnabled: + description: SSF/CAEP/RISC event type URIs that this stream is configured to accept. + items: + type: string + type: + - array + - "null" + expectedAudience: + description: Expected audience (aud) claim in incoming SETs. Optional. type: string - appUserId: - description: The ID of the app user. - readOnly: true + id: + description: The unique identifier of this SSF receiver stream. type: string - identityUserId: - description: The ID of the user. + issuerUrl: + description: Upstream IdP identification. + type: string + jwksUrl: + description: The jwksUrl field. + type: string + lastErrorAt: + format: date-time + type: + - string + - "null" + lastErrorMessage: + description: The lastErrorMessage field. + type: string + lastVerifiedAt: + format: date-time + type: + - string + - "null" + outboundAuthBearer: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthBearer' + - type: "null" + outboundAuthOauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFOutboundAuthOAuth2' + - type: "null" + pollEndpointUrl: + description: URL of the transmitter's poll endpoint where C1 fetches events from. + type: string + pollInterval: + format: duration + type: + - string + - "null" + pushAuthToken: + description: 'Push auth token: write-only. Accepted on create, never returned in get/list.' + type: string + pushEndpointUrl: + description: 'Push delivery: C1 generates a unique endpoint URL.' readOnly: true type: string - outcome: - description: The outcome of the revoke. + sessionRevokedAction: + description: |- + Per-canonical-type action configuration. + Event types without a config here default to LOG_ONLY. + Action to take when a session-revoked event is received. enum: - - REVOKE_OUTCOME_UNSPECIFIED - - REVOKE_OUTCOME_REVOKED - - REVOKE_OUTCOME_DENIED - - REVOKE_OUTCOME_ERROR - - REVOKE_OUTCOME_CANCELLED - - REVOKE_OUTCOME_WAIT_TIMED_OUT - readOnly: true + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string x-speakeasy-unknown-values: allow - outcomeTime: + updatedAt: format: date-time readOnly: true - type: string - source: - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSource' - title: Task Type Revoke + type: + - string + - "null" + title: Ssf Receiver Stream type: object - x-speakeasy-name-override: TaskTypeRevoke - c1.api.task.v1.TaskView: - description: Contains a task and JSONPATH expressions that describe where in the expanded array related objects are located. This view can be used to display a fully-detailed dashboard of task information. + x-speakeasy-name-override: SSFReceiverStream + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest: + description: SSFReceiverStreamServiceCreateRequest contains the configuration for a new SSF receiver stream. properties: - accessReviewPath: - description: JSONPATH expression indicating the location of the AccessReview object in the expanded array - readOnly: true + accountDisabledAction: + description: Action to take when an account-disabled event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - appPath: - description: JSONPATH expression indicating the location of the App object in the expanded array - readOnly: true + x-speakeasy-unknown-values: allow + credentialChangeAction: + description: Action to take when a credential-change event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - appUserLastUsagePath: - description: JSONPATH expression indicating the location of the AppUser last usage timestamp in the expanded array - readOnly: true + x-speakeasy-unknown-values: allow + credentialCompromiseAction: + description: Action to take when a credential-compromise event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - appUserPath: - description: JSONPATH expression indicating the location of the AppUser object in the expanded array - readOnly: true + x-speakeasy-unknown-values: allow + deliveryMethod: + description: Controls whether events are received via push or poll delivery. + enum: + - SSF_DELIVERY_METHOD_UNSPECIFIED + - SSF_DELIVERY_METHOD_PUSH + - SSF_DELIVERY_METHOD_POLL type: string - approversPath: - description: JSONPATH expression indicating the location of the ApproverUsers objects in the expanded array. These are the users who have approved or denied this task. - readOnly: true + x-speakeasy-unknown-values: allow + description: + description: Optional description of the stream's purpose or source. type: string - createdByUserPath: - description: JSONPATH expression indicating the location of the object of the User that created the ticket in the expanded array - readOnly: true + displayName: + description: Human-readable name for the stream. type: string - entitlementsPath: - description: JSONPATH expression indicating the location of the Entitlements objects in the expanded array - readOnly: true + enabled: + description: Controls whether the stream starts processing events immediately after creation. + type: boolean + expectedAudience: + description: Expected audience claim in incoming SETs. If set, SETs with a different audience are rejected. type: string - identityUserPath: - description: JSONPATH expression indicating the location of the User object of the User that this task is targeting in the expanded array. This is the user that is the identity when the target of a task is an app user. - readOnly: true + issuerUrl: + description: The issuer URL of the upstream SSF transmitter, used for token validation. type: string - insightsPath: - description: JSONPATH expression indicating the location of the Insights objects in the expanded array - readOnly: true + jwksUrl: + description: URL to fetch the transmitter's JSON Web Key Set for SET signature verification. type: string - resourceBindingsPath: - description: JSONPATH expression indicating the location of the EntitlementScopeBindingList object in the expanded array. - readOnly: true + pollEndpointUrl: + description: URL of the transmitter's poll endpoint. Required when delivery_method is POLL. type: string - roleResourcePath: - description: JSONPATH expression indicating the location of the role AppResource for a scope-role action task in the expanded array. - readOnly: true + pollInterval: + format: duration + type: + - string + - "null" + sessionRevokedAction: + description: |- + Per-event-type action configuration. + Action to take when a session-revoked event is received. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - scopeResourcePath: - description: JSONPATH expression indicating the location of the scope AppResource for a scope-role action task in the expanded array. - readOnly: true + x-speakeasy-unknown-values: allow + required: + - displayName + - issuerUrl + title: Ssf Receiver Stream Service Create Request + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceCreateRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse: + description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + properties: + pushAuthTokenPlaintext: + description: Push auth token returned in plaintext ONLY on create. type: string - stepApproversPath: - description: JSONPATH expression indicating the location of the StepApproverUsers objects in the expanded array - readOnly: true + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + title: Ssf Receiver Stream Service Create Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceCreateResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput: + description: SSFReceiverStreamServiceDeleteRequest identifies the SSF receiver stream to delete. + title: Ssf Receiver Stream Service Delete Request + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceDeleteRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse: + description: SSFReceiverStreamServiceDeleteResponse is empty on success. + title: Ssf Receiver Stream Service Delete Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceDeleteResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse: + description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. + properties: + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + title: Ssf Receiver Stream Service Get Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceGetResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse: + description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. + properties: + stats: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamStats' + - type: "null" + title: Ssf Receiver Stream Service Get Stats Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceGetStatsResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse: + description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. + properties: + list: + description: The SSF receiver streams in the current page. + items: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + type: + - array + - "null" + nextPageToken: + description: Token to retrieve the next page. Empty when there are no more results. type: string - task: - $ref: '#/components/schemas/c1.api.task.v1.Task' - userPath: - description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. - readOnly: true + title: Ssf Receiver Stream Service List Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceListResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput: + description: SSFReceiverStreamServiceTestRequest identifies the stream to test and an optional subject for identity resolution validation. + properties: + testSubject: + description: |- + The upstream identifier to test resolution with. Typically an email address + (e.g., "alice@company.com") — the same value the IdP would send in a SET subject. + The Test RPC runs resolveSubject on this to verify the identity mapping works. + Optional: upstream identifier (email) to test identity resolution. + If empty, only JWKS reachability is tested. type: string - title: Task View + title: Ssf Receiver Stream Service Test Request type: object - x-speakeasy-name-override: TaskView - c1.api.user.v1.ExpiringUserDelegationBinding: - description: The ExpiringUserDelegationBinding message. + x-speakeasy-name-override: SSFReceiverStreamServiceTestRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse: + description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. properties: - createdAt: - format: date-time - readOnly: false + activeRefreshTokenCount: + description: Number of active refresh tokens for the matched user that would be affected. + format: int32 + type: integer + activeSessionCount: + description: Number of active sessions for the matched user that would be affected. + format: int32 + type: integer + configuredSessionRevokedAction: + description: |- + Step 3: Action preview. + The action configured for session-revoked events on this stream. + enum: + - SSF_REVOCATION_ACTION_UNSPECIFIED + - SSF_REVOCATION_ACTION_REVOKE_ALL + - SSF_REVOCATION_ACTION_LOG_ONLY type: string - delegatedUserId: - description: The delegatedUserId field. - readOnly: false + x-speakeasy-unknown-values: allow + identityLinkFound: + description: |- + Step 2: Identity mapping. + Whether the test subject was resolved to a ConductorOne user. + type: boolean + jwksError: + description: Error message if the JWKS endpoint could not be reached or returned invalid data. type: string - deletedAt: - format: date-time - readOnly: false + jwksKeyCount: + description: Number of signing keys found at the JWKS endpoint. + format: int32 + type: integer + jwksReachable: + description: |- + Step 1: JWKS reachability. + Whether the JWKS endpoint was reachable and returned valid keys. + type: boolean + matchedUserId: + description: The ConductorOne user ID the test subject maps to, if an identity link was found. type: string - expirationAt: - format: date-time - readOnly: false + ready: + description: |- + Overall readiness. + Whether the stream passed all test checks and is ready to process events. + type: boolean + upstreamSubject: + description: The upstream IdP subject identifier (e.g., Okta user ID "00u1234") resolved from the test subject. type: string - startAt: + title: Ssf Receiver Stream Service Test Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceTestResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput: + description: SSFReceiverStreamServiceUpdateRequest carries the stream to update and the mask of fields to modify. + properties: + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + updateMask: + type: + - string + - "null" + title: Ssf Receiver Stream Service Update Request + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceUpdateRequest + c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse: + description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. + properties: + ssfReceiverStream: + oneOf: + - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStream' + - type: "null" + title: Ssf Receiver Stream Service Update Response + type: object + x-speakeasy-name-override: SSFReceiverStreamServiceUpdateResponse + c1.api.ssf_receiver.v1.SSFReceiverStreamStats: + description: SSFReceiverStreamStats is a lightweight read-only stats object. + properties: + eventsActedOnCount: + description: Number of events that triggered an action (e.g., session revocation). + format: int64 + type: string + eventsFailedCount: + description: Number of events that failed processing. + format: int64 + type: string + eventsReceivedCount: + description: Total number of events received on this stream. + format: int64 + type: string + lastErrorAt: format: date-time - readOnly: false + type: + - string + - "null" + lastErrorMessage: + description: Human-readable description of the most recent processing error. type: string - updatedAt: + lastEventReceivedAt: + format: date-time + type: + - string + - "null" + lastVerifiedAt: format: date-time - readOnly: false + type: + - string + - "null" + streamId: + description: The SSF receiver stream these stats belong to. type: string - userId: - description: The userId field. - readOnly: false + transmitterStatus: + description: Current status reported by the transmitter (e.g., "enabled", "paused"). type: string - title: Expiring User Delegation Binding + transmitterStatusReason: + description: Reason provided by the transmitter for its current status. + type: string + title: Ssf Receiver Stream Stats type: object - x-speakeasy-name-override: ExpiringUserDelegationBinding - c1.api.user.v1.GetUserProfileTypesResponse: - description: GetUserProfileTypesResponse is the response containing the profile types for a user. + x-speakeasy-name-override: SSFReceiverStreamStats + c1.api.stepup.v1.CreateStepUpProviderRequest: + description: | + The CreateStepUpProviderRequest message. + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oauth2 + - microsoft properties: - profileTypes: - description: The list of profile types associated with the user across their connected apps. - items: - $ref: '#/components/schemas/c1.api.profiletype.v1.ProfileType' - nullable: true - readOnly: false - type: array - title: Get User Profile Types Response + clientId: + description: The OAuth2 client ID used to authenticate with the step-up provider. + type: string + clientSecret: + description: The OAuth2 client secret. Write-only; never returned in responses. + type: string + displayName: + description: The human-readable name for the new step-up provider. + type: string + issuerUrl: + description: The OIDC issuer URL for the step-up provider. + type: string + microsoft: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' + - type: "null" + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' + - type: "null" + title: Create Step Up Provider Request type: object - x-speakeasy-name-override: GetUserProfileTypesResponse - c1.api.user.v1.SearchUsersRequest: - description: Search for users based on some filters. + x-speakeasy-name-override: CreateStepUpProviderRequest + c1.api.stepup.v1.CreateStepUpProviderResponse: + description: The CreateStepUpProviderResponse message. properties: - delegateStatus: - description: Filter for users based on their delegate status. - enum: - - DELEGATE_STATUS_UNSPECIFIED - - DELEGATE_STATUS_HAS_DELEGATE - - DELEGATE_STATUS_NO_DELEGATE - readOnly: false - type: string - x-speakeasy-unknown-values: allow - delegatedUserIds: - description: Filter for users that have any of the delegated user IDs on this list. - items: - type: string - nullable: true - readOnly: false - type: array - departments: - description: Search for users that have any of the departments on this list. + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + title: Create Step Up Provider Response + type: object + x-speakeasy-name-override: CreateStepUpProviderResponse + c1.api.stepup.v1.DeleteStepUpProviderRequestInput: + description: The DeleteStepUpProviderRequest message. + title: Delete Step Up Provider Request + type: object + x-speakeasy-name-override: DeleteStepUpProviderRequest + c1.api.stepup.v1.DeleteStepUpProviderResponse: + description: The DeleteStepUpProviderResponse message. + title: Delete Step Up Provider Response + type: object + x-speakeasy-name-override: DeleteStepUpProviderResponse + c1.api.stepup.v1.GetStepUpProviderResponse: + description: The GetStepUpProviderResponse message. + properties: + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + title: Get Step Up Provider Response + type: object + x-speakeasy-name-override: GetStepUpProviderResponse + c1.api.stepup.v1.GetStepUpTransactionResponse: + description: Response message containing the requested step-up transaction + properties: + transaction: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' + - type: "null" + title: Get Step Up Transaction Response + type: object + x-speakeasy-name-override: GetStepUpTransactionResponse + c1.api.stepup.v1.ListStepUpProvidersResponse: + description: The ListStepUpProvidersResponse message. + properties: + list: + description: The list of step-up authentication providers. items: - type: string - nullable: true - readOnly: false - type: array - email: - description: Search for users based on their email (exact match). - readOnly: false + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. type: string - excludeIds: - description: An array of users IDs to exclude from the results. - items: - type: string - nullable: true - readOnly: false - type: array - excludeOrigins: - description: Filter to exclude users with these origins. - items: - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - excludeTypes: - description: An array of types to exclude from the results. - items: - enum: - - USER_TYPE_UNSPECIFIED - - USER_TYPE_SYSTEM - - USER_TYPE_HUMAN - - USER_TYPE_SERVICE - - USER_TYPE_AGENT - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - expandMask: - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' - ids: - description: Deprecated. Use refs array instead. - items: - type: string - nullable: true - readOnly: false - type: array - isDelegate: - description: Filter for users who are delegates of at least one other user. - readOnly: false - type: boolean - jobTitles: - description: Search for users that have any of the job titles on this list. - items: - type: string - nullable: true - readOnly: false - type: array - managerIds: - description: Search for users that have any of the manager IDs on this list. - items: - type: string - nullable: true - readOnly: false - type: array - origins: - description: Filter to include only users with these origins. - items: - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array + title: List Step Up Providers Response + type: object + x-speakeasy-name-override: ListStepUpProvidersResponse + c1.api.stepup.v1.SearchStepUpProvidersRequest: + description: Request message for searching step-up providers + properties: pageSize: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + description: Maximum number of results to return format: int32 - readOnly: false type: integer pageToken: - description: The pageToken field. - readOnly: false + description: Token for pagination + type: string + providerType: + description: The providerType field. + enum: + - PROVIDER_TYPE_UNSPECIFIED + - PROVIDER_TYPE_OAUTH2 + - PROVIDER_TYPE_MICROSOFT type: string + x-speakeasy-unknown-values: allow query: - description: Query the apps with a fuzzy search on display name and emails. - readOnly: false + description: Filter by name (partial match) type: string refs: - description: An array of user refs to restrict the return values to by ID. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserRef' - nullable: true - readOnly: false - type: array - roleIds: - description: Search for users that have any of the role IDs on this list. - items: - type: string - nullable: true - readOnly: false - type: array - userStatuses: - description: Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED + description: Filter to specific providers by their references. items: - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED - type: string - x-speakeasy-unknown-values: allow - nullable: true - readOnly: false - type: array - title: Search Users Request + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProviderRef' + type: + - array + - "null" + title: Search Step Up Providers Request type: object - x-speakeasy-name-override: SearchUsersRequest - c1.api.user.v1.SearchUsersResponse: - description: The SearchUsersResponse message. + x-speakeasy-name-override: SearchStepUpProvidersRequest + c1.api.stepup.v1.SearchStepUpProvidersResponse: + description: Response message for searching step-up providers properties: - expanded: - description: List of related objects - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: - description: The list of results containing up to X results, where X is the page size defined in the request + description: List of providers matching the search criteria items: - $ref: '#/components/schemas/c1.api.user.v1.UserView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + type: + - array + - "null" nextPageToken: - description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: Token for retrieving the next page of results type: string - title: Search Users Response + title: Search Step Up Providers Response type: object - x-speakeasy-name-override: SearchUsersResponse - c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput: - description: SetExpiringUserDelegationBindingByAdminRequest is the request for an admin to set a temporary delegation binding for a user. + x-speakeasy-name-override: SearchStepUpProvidersResponse + c1.api.stepup.v1.SearchStepUpTransactionsRequest: + description: Request message for searching step-up transactions properties: - delegatedUserId: - description: The ID of the user who will act as delegate. Empty string removes the delegation. - readOnly: false - type: string - delegationExpireAt: - format: date-time - readOnly: false - type: string - delegationStartAt: + createdAfter: format: date-time - readOnly: false - type: string - title: Set Expiring User Delegation Binding By Admin Request - type: object - x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminRequest - c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse: - description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. - properties: - item: - $ref: '#/components/schemas/c1.api.user.v1.ExpiringUserDelegationBinding' - title: Set Expiring User Delegation Binding By Admin Response - type: object - x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminResponse - c1.api.user.v1.User: - description: The User object provides all of the details for an user, as well as some configuration. - properties: - createdAt: + type: + - string + - "null" + createdBefore: format: date-time - readOnly: true - type: string - delegatedUserId: - description: The id of the user to whom tasks will be automatically reassigned to. - readOnly: false + type: + - string + - "null" + pageSize: + description: Maximum number of results to return + format: int32 + type: integer + pageToken: + description: Token for pagination type: string - deletedAt: - format: date-time - readOnly: true + providerId: + description: Filter by provider ID type: string - department: - description: The department which the user belongs to in the organization. - readOnly: true + state: + description: Filter by transaction state + enum: + - STEP_UP_TRANSACTION_STATE_UNSPECIFIED + - STEP_UP_TRANSACTION_STATE_PENDING + - STEP_UP_TRANSACTION_STATE_VERIFIED + - STEP_UP_TRANSACTION_STATE_ERROR type: string - departmentSources: - description: A list of objects mapped based on department attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - directoryIds: - description: A list of unique ids that represent different directories. - items: - type: string - nullable: true - readOnly: true - type: array - directoryStatus: - description: The status of the user in the directory. + x-speakeasy-unknown-values: allow + targetType: + description: The targetType field. enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED - readOnly: true + - TARGET_TYPE_UNSPECIFIED + - TARGET_TYPE_TICKET + - TARGET_TYPE_TEST type: string x-speakeasy-unknown-values: allow - directoryStatusSources: - description: A list of objects mapped based on directoryStatus attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - displayName: - description: The display name of the user. - readOnly: true + taskId: + description: Filter by task ID (only applicable if target_type is TICKET) type: string - email: - description: This is the user's email. - readOnly: true + userId: + description: Filter by user ID type: string - emailSources: - description: A list of source data for the email attribute. + title: Search Step Up Transactions Request + type: object + x-speakeasy-name-override: SearchStepUpTransactionsRequest + c1.api.stepup.v1.SearchStepUpTransactionsResponse: + description: Response message for searching step-up transactions + properties: + list: + description: List of transactions matching the search criteria items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - emails: - description: This is a list of all of the user's emails from app users. + $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction' + type: + - array + - "null" + nextPageToken: + description: Token for retrieving the next page of results + type: string + title: Search Step Up Transactions Response + type: object + x-speakeasy-name-override: SearchStepUpTransactionsResponse + c1.api.stepup.v1.StepUpMicrosoftSettings: + description: StepUpMicrosoftSettings configures a Microsoft Entra step-up provider using Conditional Access. + properties: + conditionalAccessIds: + description: Authentication context IDs (C1-C99). Required for ACRS mode; ignored for OIDC mode. items: type: string - nullable: true - readOnly: true - type: array - employeeIdSources: - description: A list of source data for the employee IDs attribute. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - employeeIds: - description: This is a list of all of the user's employee IDs from app users. + type: + - array + - "null" + tenant: + description: Microsoft Entra tenant ID (GUID or domain). Used for response validation. + type: string + validationMode: + description: Validation approach. See MicrosoftValidationMode for details on each mode. + enum: + - MICROSOFT_VALIDATION_MODE_UNSPECIFIED + - MICROSOFT_VALIDATION_MODE_ACRS + - MICROSOFT_VALIDATION_MODE_OIDC + type: string + x-speakeasy-unknown-values: allow + title: Step Up Microsoft Settings + type: object + x-speakeasy-name-override: StepUpMicrosoftSettings + c1.api.stepup.v1.StepUpOAuth2Settings: + description: |- + StepUpOAuth2Settings repersents an OAuth2 provider that supports RFC 9470 + + Common ACR values for OAuth2 providers include: + - "urn:okta:loa:1fa:any" (okta) + - "urn:okta:loa:1fa:pwd" (okta) + - "urn:okta:loa:2fa:any" (okta) + - "urn:okta:loa:2fa:any:ifpossible" (okta) + - "phr" (okta) + - "phrh" (okta) + properties: + acrValues: + description: The acrValues field. items: type: string - nullable: true - readOnly: true - type: array - employmentStatus: - description: The users employment status. - readOnly: true + type: + - array + - "null" + title: Step Up O Auth 2 Settings + type: object + x-speakeasy-name-override: StepUpOAuth2Settings + c1.api.stepup.v1.StepUpProvider: + description: | + StepUpProvider represents a configured step-up authentication integration (e.g., Duo, custom OIDC). + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oauth2 + - microsoft + properties: + clientId: + description: The OAuth2 client ID used to authenticate with the step-up provider. type: string - employmentStatusSources: - description: A list of objects mapped based on employmentStatus attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - employmentType: - description: The employment type of the user. + createdAt: + format: date-time readOnly: true + type: + - string + - "null" + displayName: + description: The human-readable name of the step-up provider. type: string - employmentTypeSources: - description: A list of objects mapped based on employmentType attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array + enabled: + description: Whether the step-up provider is active and available for use. + type: boolean id: - description: A unique identifier of the user. + description: The unique identifier of the step-up provider. readOnly: true type: string - jobTitle: - description: The job title of the user. - readOnly: true + issuerUrl: + description: The OIDC issuer URL for the step-up provider. type: string - jobTitleSources: - description: A list of objects mapped based on jobTitle attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true + lastTestedAt: + format: date-time readOnly: true - type: array - managerIds: - description: A list of ids of the user's managers. - items: - type: string - nullable: true + type: + - string + - "null" + microsoft: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpMicrosoftSettings' + - type: "null" + oauth2: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpOAuth2Settings' + - type: "null" + updatedAt: + format: date-time readOnly: true - type: array - managerSources: - description: A list of objects mapped based on managerId attribute mappings configured in the system. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true + type: + - string + - "null" + title: Step Up Provider + type: object + x-speakeasy-name-override: StepUpProvider + c1.api.stepup.v1.StepUpProviderRef: + description: StepUpProviderRef is a lightweight reference to a step-up authentication provider. + properties: + id: + description: The unique identifier of the step-up provider. + type: string + title: Step Up Provider Ref + type: object + x-speakeasy-name-override: StepUpProviderRef + c1.api.stepup.v1.StepUpTransaction: + description: | + StepUpTransaction represents a record of a step-up authentication attempt + + This message contains a oneof named target. Only a single field of the following list may be set at a time: + - approveTask + - test + properties: + approveTask: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTask' + - type: "null" + claims: + additionalProperties: true + type: + - object + - "null" + createdAt: + format: date-time readOnly: true - type: array - origin: - description: The origin of the user, describing who owns the user's lifecycle. - enum: - - USER_ORIGIN_UNSPECIFIED - - USER_ORIGIN_DIRECTORY - - USER_ORIGIN_LOCAL - - USER_ORIGIN_SYSTEM + type: + - string + - "null" + errorMessage: + description: Error message if the transaction failed readOnly: true type: string - x-speakeasy-unknown-values: allow - profile: - additionalProperties: true + expiresAt: + format: date-time readOnly: true - type: object - roleIds: - description: A list of unique identifiers that maps to ConductorOne's user roles let you assign users permissions tailored to the work they do in the software. - items: - type: string - nullable: true - readOnly: false - type: array - status: - description: The status of the user in the system. - enum: - - UNKNOWN - - ENABLED - - DISABLED - - DELETED - readOnly: false + type: + - string + - "null" + id: + description: Unique identifier for the transaction type: string - x-speakeasy-unknown-values: allow - type: - description: The type of the user. + providerId: + description: ID of the provider used for this step-up authentication + type: string + state: + description: Current state of the transaction enum: - - USER_TYPE_UNSPECIFIED - - USER_TYPE_SYSTEM - - USER_TYPE_HUMAN - - USER_TYPE_SERVICE - - USER_TYPE_AGENT + - STEP_UP_TRANSACTION_STATE_UNSPECIFIED + - STEP_UP_TRANSACTION_STATE_PENDING + - STEP_UP_TRANSACTION_STATE_VERIFIED + - STEP_UP_TRANSACTION_STATE_ERROR readOnly: true type: string x-speakeasy-unknown-values: allow + test: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpTransaction.TargetTest' + - type: "null" updatedAt: format: date-time readOnly: true + type: + - string + - "null" + userId: + description: ID of the user who performed the step-up authentication type: string - username: - description: This is the user's primary username. Typically sourced from the primary directory. - readOnly: true - type: string - usernameSources: - description: A list of source data for the usernames attribute. - items: - $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' - nullable: true - readOnly: true - type: array - usernames: - description: This is a list of all of the user's usernames from app users. - items: - type: string - nullable: true - readOnly: true - type: array - title: User + title: Step Up Transaction type: object - x-speakeasy-name-override: User - c1.api.user.v1.UserAttributeMappingSource: - description: The UserAttributeMappingSource message. + x-speakeasy-name-override: StepUpTransaction + c1.api.stepup.v1.StepUpTransaction.TargetTask: + description: Target for approving a task properties: - appId: - description: The appId field. - readOnly: false + policyStepId: + description: ID of the policy step requiring step-up authentication type: string - appUserId: - description: The appUserId field. - readOnly: false + taskId: + description: ID of the task being approved type: string - appUserProfileAttributeKey: - description: The appUserProfileAttributeKey field. - readOnly: false + title: Target Task + type: object + x-speakeasy-name-override: TargetTask + c1.api.stepup.v1.StepUpTransaction.TargetTest: + description: Target for testing a provider + title: Target Test + type: object + x-speakeasy-name-override: TargetTest + c1.api.stepup.v1.TestStepUpProviderRequestInput: + description: The TestStepUpProviderRequest message. + title: Test Step Up Provider Request + type: object + x-speakeasy-name-override: TestStepUpProviderRequest + c1.api.stepup.v1.TestStepUpProviderResponse: + description: The TestStepUpProviderResponse message. + properties: + redirectUrl: + description: The URL to redirect the user to for testing the Step Up flow type: string - userAttributeMappingId: - description: The userAttributeMappingId field. - readOnly: false + title: Test Step Up Provider Response + type: object + x-speakeasy-name-override: TestStepUpProviderResponse + c1.api.stepup.v1.UpdateStepUpProviderRequestInput: + description: The UpdateStepUpProviderRequest message. + properties: + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + updateMask: + type: + - string + - "null" + title: Update Step Up Provider Request + type: object + x-speakeasy-name-override: UpdateStepUpProviderRequest + c1.api.stepup.v1.UpdateStepUpProviderResponse: + description: The UpdateStepUpProviderResponse message. + properties: + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + title: Update Step Up Provider Response + type: object + x-speakeasy-name-override: UpdateStepUpProviderResponse + c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput: + description: The UpdateStepUpProviderSecretRequest message. + properties: + clientSecret: + description: The new OAuth2 client secret. Write-only; never returned in responses. type: string - value: - description: The value field. - readOnly: false + title: Update Step Up Provider Secret Request + type: object + x-speakeasy-name-override: UpdateStepUpProviderSecretRequest + c1.api.stepup.v1.UpdateStepUpProviderSecretResponse: + description: The UpdateStepUpProviderSecretResponse message. + properties: + stepUpProvider: + oneOf: + - $ref: '#/components/schemas/c1.api.stepup.v1.StepUpProvider' + - type: "null" + title: Update Step Up Provider Secret Response + type: object + x-speakeasy-name-override: UpdateStepUpProviderSecretResponse + c1.api.systemlog.v1.ExportServiceCreateRequest: + description: | + The ExportServiceCreateRequest message is used to create a new system log exporter. + + This message contains a oneof named export_to. Only a single field of the following list may be set at a time: + - datasource + properties: + datasource: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' + - type: "null" + displayName: + description: The display name of the new system log exporter. type: string - title: User Attribute Mapping Source + title: Export Service Create Request type: object - x-speakeasy-name-override: UserAttributeMappingSource - c1.api.user.v1.UserExpandMask: - description: |- - The user expand mask is used to indicate which related objects should be expanded in the response. - The supported paths are 'role_ids', 'manager_ids', 'delegated_user_id', 'directory_ids', and '*'. + x-speakeasy-name-override: ExportServiceCreateRequest + c1.api.systemlog.v1.ExportServiceCreateResponse: + description: The ExportServiceCreateResponse message. properties: - paths: - description: An array of paths to be expanded in the response. - items: - type: string - nullable: true - readOnly: false - type: array - title: User Expand Mask + exporter: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - type: "null" + title: Export Service Create Response type: object - x-speakeasy-name-override: UserExpandMask - c1.api.user.v1.UserRef: - description: A reference to a user. + x-speakeasy-name-override: ExportServiceCreateResponse + c1.api.systemlog.v1.ExportServiceDeleteRequestInput: + description: The ExportServiceDeleteRequest message. + title: Export Service Delete Request + type: object + x-speakeasy-name-override: ExportServiceDeleteRequest + c1.api.systemlog.v1.ExportServiceDeleteResponse: + description: The ExportServiceDeleteResponse message. + title: Export Service Delete Response + type: object + x-speakeasy-name-override: ExportServiceDeleteResponse + c1.api.systemlog.v1.ExportServiceGetResponse: + description: The ExportServiceGetResponse message contains the system log exporter object. properties: - id: - description: The id of the user. - readOnly: false + exporter: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - type: "null" + title: Export Service Get Response + type: object + x-speakeasy-name-override: ExportServiceGetResponse + c1.api.systemlog.v1.ExportServiceListEventsRequestInput: + description: ExportServiceListEventsRequest is the request for listing audit events within a specific export. + properties: + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. type: string - title: User Ref + title: Export Service List Events Request type: object - x-speakeasy-name-override: UserRef - c1.api.user.v1.UserServiceGetResponse: - description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. + x-speakeasy-name-override: ExportServiceListEventsRequest + c1.api.systemlog.v1.ExportServiceListEventsResponse: + description: ExportServiceListEventsResponse is the response containing audit events for an export. properties: - expanded: - description: List of serialized related objects. + list: + description: List contains an array of JSON OCSF events. items: additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array - userView: - $ref: '#/components/schemas/c1.api.user.v1.UserView' - title: User Service Get Response + type: + - array + - "null" + nextPageToken: + description: The token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Export Service List Events Response type: object - x-speakeasy-name-override: UserServiceGetResponse - c1.api.user.v1.UserServiceListResponse: - description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. + x-speakeasy-name-override: ExportServiceListEventsResponse + c1.api.systemlog.v1.ExportServiceListResponse: + description: The ExportServiceListResponse message. properties: - expanded: - description: List of serialized related objects. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array list: description: The list of results containing up to X results, where X is the page size defined in the request items: - $ref: '#/components/schemas/c1.api.user.v1.UserView' - nullable: true - readOnly: false - type: array + $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + type: + - array + - "null" nextPageToken: - description: |- - The nextPageToken is shown for the next page if the number of results is larger than the max page size. - The server returns one page of results and the nextPageToken until all results are retreived. - To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. - readOnly: false + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. type: string - title: User Service List Response + title: Export Service List Response type: object - x-speakeasy-name-override: UserServiceListResponse - c1.api.user.v1.UserView: - description: The UserView object provides a user response object, as well as JSONPATHs to related objects provided by expanders. + x-speakeasy-name-override: ExportServiceListResponse + c1.api.systemlog.v1.ExportServiceUpdateRequestInput: + description: The ExportServiceUpdateRequest message. properties: - delegatedUserPath: - description: JSONPATH expression indicating the location of the user objects of delegates of the current user in the expanded array. - readOnly: true - type: string - directoriesPath: - description: JSONPATH expression indicating the location of directory objects in the expanded array. - readOnly: true - type: string - managersPath: - description: JSONPATH expression indicating the location of the user objects that managed the current user in the expanded array. - readOnly: true - type: string - rolesPath: - description: JSONPATH expression indicating the location of the roles of the current user in the expanded array. - readOnly: true - type: string - user: - $ref: '#/components/schemas/c1.api.user.v1.User' - title: User View + exporter: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - type: "null" + updateMask: + type: + - string + - "null" + title: Export Service Update Request type: object - x-speakeasy-name-override: UserView - c1.api.vault.v1.GroupAuthzVault: - description: GroupAuthzVault configures a vault that uses group-based authorization to control access to stored credentials. - nullable: true - title: Group Authz Vault + x-speakeasy-name-override: ExportServiceUpdateRequest + c1.api.systemlog.v1.ExportServiceUpdateResponse: + description: The ExportServiceUpdateResponse message. + properties: + exporter: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + - type: "null" + title: Export Service Update Response type: object - x-speakeasy-name-override: GroupAuthzVault - c1.api.vault.v1.MagicVault: - description: MagicVault configures a vault that grants time-limited credential access via magic links. - nullable: true + x-speakeasy-name-override: ExportServiceUpdateResponse + c1.api.systemlog.v1.ExportToDatasource: + description: The ExportToDatasource message. properties: - allowUnauthedViews: - description: Controls whether unauthenticated users can view credentials via a magic link. - readOnly: false - type: boolean - allowedViews: - description: The maximum number of times a credential in this vault may be viewed. - format: uint32 - readOnly: false - type: integer - title: Magic Vault + datasourceId: + description: The datasourceId field. + type: string + format: + description: The format field. + enum: + - EXPORT_FORMAT_UNSPECIFIED + - EXPORT_FORMAT_OCSF_JSON_ZSTD + - EXPORT_FORMAT_OCSF_JSON_GZIP + type: string + x-speakeasy-unknown-values: allow + prefix: + description: The prefix field. + type: string + title: Export To Datasource type: object - x-speakeasy-name-override: MagicVault - c1.api.vault.v1.Vault: + x-speakeasy-name-override: ExportToDatasource + c1.api.systemlog.v1.Exporter: description: | - Vault represents an external secret storage integration used to store connector credentials securely. + The Exporter message. - This message contains a oneof named vault. Only a single field of the following list may be set at a time: - - groupAuthzVault - - magicVault + This message contains a oneof named export_to. Only a single field of the following list may be set at a time: + - datasource properties: createdAt: format: date-time readOnly: true - type: string - credentialExpirationDuration: - format: duration - readOnly: false - type: string + type: + - string + - "null" + datasource: + oneOf: + - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportToDatasource' + - type: "null" deletedAt: format: date-time readOnly: true - type: string - description: - description: A free-text description of the vault's purpose or configuration. - readOnly: false - type: string + type: + - string + - "null" displayName: - description: The human-readable name of the vault. - readOnly: false + description: The displayName field. type: string - groupAuthzVault: - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' - id: - description: The unique identifier of the vault. - readOnly: false + exportId: + description: The exportId field. + readOnly: true type: string - magicVault: - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + state: + description: The state field. + enum: + - EXPORT_STATE_UNSPECIFIED + - EXPORT_STATE_EXPORTING + - EXPORT_STATE_WAITING + - EXPORT_STATE_ERROR + readOnly: true + type: string + x-speakeasy-unknown-values: allow updatedAt: format: date-time readOnly: true + type: + - string + - "null" + watermarkEventId: + description: we've synchorized this far + readOnly: true type: string - title: Vault + title: Exporter type: object - x-speakeasy-entity: Vault - x-speakeasy-name-override: Vault - c1.api.vault.v1.VaultServiceCreateRequest: - description: | - VaultServiceCreateRequest is the request message for creating a new vault. - - This message contains a oneof named vault. Only a single field of the following list may be set at a time: - - groupAuthzVault - - magicVault + x-speakeasy-name-override: Exporter + c1.api.systemlog.v1.ExporterRef: + description: The ExporterRef message. properties: - description: - description: A free-text description of the vault's purpose or configuration. - readOnly: false + exportId: + description: The exportId field. type: string + title: Exporter Ref + type: object + x-speakeasy-name-override: ExporterRef + c1.api.systemlog.v1.ExportsSearchServiceSearchRequest: + description: ExportsSearchServiceSearchRequest is the request for searching system log exports. + properties: displayName: - description: The human-readable name for the new vault. - readOnly: false + description: Search for system log exporters with a case insensitive match on the display name. type: string - groupAuthzVault: - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' - magicVault: - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' - ownerIds: - description: The IDs of users to assign as owners of this vault. + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + query: + description: The query field. + type: string + refs: + description: The refs field. items: - type: string - nullable: true - readOnly: false - type: array - required: - - displayName - title: Vault Service Create Request - type: object - x-speakeasy-name-override: VaultServiceCreateRequest - c1.api.vault.v1.VaultServiceCreateResponse: - description: VaultServiceCreateResponse is the response message for creating a new vault. - properties: - vault: - $ref: '#/components/schemas/c1.api.vault.v1.Vault' - title: Vault Service Create Response - type: object - x-speakeasy-name-override: VaultServiceCreateResponse - c1.api.vault.v1.VaultServiceDeleteRequestInput: - description: VaultServiceDeleteRequest is the request message for deleting a vault. - title: Vault Service Delete Request - type: object - x-speakeasy-name-override: VaultServiceDeleteRequest - c1.api.vault.v1.VaultServiceDeleteResponse: - description: Empty response body. Status code indicates success. - title: Vault Service Delete Response - type: object - x-speakeasy-name-override: VaultServiceDeleteResponse - c1.api.vault.v1.VaultServiceGetResponse: - description: VaultServiceGetResponse is the response message containing the requested vault. - properties: - vault: - $ref: '#/components/schemas/c1.api.vault.v1.Vault' - title: Vault Service Get Response - type: object - x-speakeasy-name-override: VaultServiceGetResponse - c1.api.vault.v1.VaultServiceUpdateRequestInput: - description: The VaultServiceUpdateRequest message contains the vault object to update and a field mask to indicate which fields to update. - properties: - updateMask: - nullable: true - readOnly: false - type: string - vault: - $ref: '#/components/schemas/c1.api.vault.v1.Vault' - title: Vault Service Update Request - type: object - x-speakeasy-name-override: VaultServiceUpdateRequest - c1.api.vault.v1.VaultServiceUpdateResponse: - description: VaultServiceUpdateResponse is the response message containing the updated vault. - properties: - vault: - $ref: '#/components/schemas/c1.api.vault.v1.Vault' - title: Vault Service Update Response + $ref: '#/components/schemas/c1.api.systemlog.v1.ExporterRef' + type: + - array + - "null" + title: Exports Search Service Search Request type: object - x-speakeasy-name-override: VaultServiceUpdateResponse - c1.api.webhooks.v1.Webhook: - description: The Webhook message. + x-speakeasy-name-override: ExportsSearchServiceSearchRequest + c1.api.systemlog.v1.ExportsSearchServiceSearchResponse: + description: ExportsSearchServiceSearchResponse is the response for searching system log exports. properties: - callbackTimeout: - format: duration - readOnly: false - type: string - createdAt: - format: date-time - readOnly: true - type: string - deletedAt: - format: date-time - readOnly: true - type: string - description: - description: An optional description of the webhook's purpose. - readOnly: false - type: string - displayName: - description: The human-readable name of the webhook. - readOnly: false - type: string - id: - description: The unique identifier of the webhook. - readOnly: false - type: string - updatedAt: - format: date-time - readOnly: true - type: string - url: - description: The destination URL that receives event notification HTTP callbacks. - readOnly: false + list: + description: The list of system log exports matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.systemlog.v1.Exporter' + type: + - array + - "null" + nextPageToken: + description: The token to retrieve the next page of results, or empty if there are no more results. type: string - title: Webhook + title: Exports Search Service Search Response type: object - x-speakeasy-entity: Webhook - x-speakeasy-name-override: WebhookEndpoint - c1.api.webhooks.v1.WebhookInstance: - description: The WebhookInstance message. + x-speakeasy-name-override: ExportsSearchServiceSearchResponse + c1.api.systemlog.v1.SystemLogServiceListEventsRequest: + description: The SystemLogServiceListEventsRequest message. properties: - attempts: - description: The attempts field. + pageSize: + description: The pageSize field. format: int32 - readOnly: false type: integer - completedAt: - format: date-time - readOnly: true - type: string - createdAt: - format: date-time - readOnly: true - type: string - expiresAt: - format: date-time - readOnly: true - type: string - id: - description: The id field. - readOnly: false + pageToken: + description: The pageToken field. type: string - lastAttemptedAt: + since: format: date-time - readOnly: true + type: + - string + - "null" + sinceEventUid: + description: The sinceEventUid field. type: string - source: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource' - spec: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSpec' - state: - description: The state field. + sortDirection: + description: The sortDirection field. enum: - - WEBHOOK_STATE_UNSPECIFIED - - WEBHOOK_STATE_PENDING - - WEBHOOK_STATE_RUNNING - - WEBHOOK_STATE_ERROR - - WEBHOOK_STATE_WAITING_CALLBACK - - WEBHOOK_STATE_PROCESS_RESPONSE - - WEBHOOK_STATE_SUCCESS - - WEBHOOK_STATE_FATAL_ERROR - readOnly: false + - SORT_DIRECTION_UNSPECIFIED + - SORT_DIRECTION_ASC + - SORT_DIRECTION_DESC type: string x-speakeasy-unknown-values: allow - updatedAt: + until: format: date-time - readOnly: true - type: string - webhookId: - description: The webhookId field. - readOnly: false + type: + - string + - "null" + untilEventUid: + description: The untilEventUid field. type: string - title: Webhook Instance + title: System Log Service List Events Request type: object - x-speakeasy-name-override: WebhookInstance - c1.api.webhooks.v1.WebhookRef: - description: The WebhookRef message. + x-speakeasy-name-override: SystemLogServiceListEventsRequest + c1.api.systemlog.v1.SystemLogServiceListEventsResponse: + description: The SystemLogServiceListEventsResponse message. properties: - id: - description: The ID of the referenced webhook. - readOnly: false + list: + description: List contains an array of JSON OCSF events. + items: + additionalProperties: true + type: object + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. type: string - title: Webhook Ref + title: System Log Service List Events Response type: object - x-speakeasy-name-override: WebhookRef - c1.api.webhooks.v1.WebhookSource: + x-speakeasy-name-override: SystemLogServiceListEventsResponse + c1.api.task.v1.ActionInstance: description: | - The WebhookSource message. + ActionInstance is the API mirror of the internal immutable snapshot of an + Action captured on a TaskTypeAction at ticket-creation time. - This message contains a oneof named source. Only a single field of the following list may be set at a time: - - test - - policyPostAction - - approvalStep - - provisionStep - - workflowStep - properties: - approvalStep: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep' - policyPostAction: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction' - provisionStep: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep' - test: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceTest' - workflowStep: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep' - title: Webhook Source - type: object - x-speakeasy-name-override: WebhookSource - c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep: - description: The WebhookSourceApprovalStep message. - nullable: true + This message contains a oneof named target_ref. Only a single field of the following list may be set at a time: + - batonResourceActionRef + - connectorActionRef properties: - ticketId: - description: The ticketId field. - readOnly: false + batonResourceActionRef: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.BatonResourceActionRef' + - type: "null" + connectorActionRef: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ConnectorActionRef' + - type: "null" + displayName: + description: |- + Display label at ticket-creation time. Same value as + TaskTypeAction.display_name; repeated here so clients that walk the + instance see a self-contained view. + readOnly: true type: string - title: Webhook Source Approval Step + title: Action Instance type: object - x-speakeasy-name-override: WebhookSourceApprovalStep - c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction: - description: The WebhookSourcePolicyPostAction message. - nullable: true + x-speakeasy-name-override: TaskActionInstance + c1.api.task.v1.BatonResourceActionRef: + description: |- + BatonResourceActionRef describes dispatch to a connector resource-create + action (for example, a group template that creates a group in the connected + application). properties: - ticketId: - description: The ticketId field. - readOnly: false + appId: + description: The app the resource is created in. + readOnly: true type: string - title: Webhook Source Policy Post Action - type: object - x-speakeasy-name-override: WebhookSourcePolicyPostAction - c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep: - description: The WebhookSourceProvisionStep message. - nullable: true - properties: - ticketId: - description: The ticketId field. - readOnly: false + batonActionDisplayName: + description: The connector-defined display name of the resource-create action. + readOnly: true type: string - title: Webhook Source Provision Step - type: object - x-speakeasy-name-override: WebhookSourceProvisionStep - c1.api.webhooks.v1.WebhookSource.WebhookSourceTest: - description: The WebhookSourceTest message. - nullable: true - title: Webhook Source Test - type: object - x-speakeasy-name-override: WebhookSourceTest - c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep: - description: The WebhookSourceWorkflowStep message. - nullable: true - properties: - workflowExecutionId: - description: The workflowExecutionId field. - format: int64 - readOnly: false + batonActionName: + description: The connector-defined name of the resource-create action. + readOnly: true type: string - workflowStepId: - description: The workflowStepId field. - readOnly: false + connectorId: + description: The connector that executes the resource-create action. + readOnly: true type: string - title: Webhook Source Workflow Step - type: object - x-speakeasy-name-override: WebhookSourceWorkflowStep - c1.api.webhooks.v1.WebhookSpec: - description: The WebhookSpec message. - properties: - destination: - description: The destination field. - readOnly: false + resourceTypeId: + description: The type of resource the action creates (for example, "group"). + readOnly: true type: string - title: Webhook Spec + title: Baton Resource Action Ref type: object - x-speakeasy-name-override: WebhookSpec - c1.api.webhooks.v1.WebhooksSearchRequest: - description: The WebhooksSearchRequest message. + x-speakeasy-name-override: BatonResourceActionRef + c1.api.task.v1.ConnectorActionRef: + description: |- + ConnectorActionRef describes dispatch through a connector's built-in + GrantManagerService Grant / Revoke RPC — i.e. the default connector + operation, used for synthesized tickets like scope-role requests. properties: - pageSize: - description: The maximum number of webhooks to return per page. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pagination token from a previous search response to fetch the next page. - readOnly: false + appId: + description: The app whose connector handles the operation. + readOnly: true type: string - query: - description: A text query to match against webhook names and descriptions. - readOnly: false + connectorId: + description: The connector that will execute the Grant / Revoke. + readOnly: true type: string - refs: - description: Optional set of webhook references to restrict the search to specific webhooks. - items: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookRef' - nullable: true - readOnly: false - type: array - title: Webhooks Search Request - type: object - x-speakeasy-name-override: WebhooksSearchRequest - c1.api.webhooks.v1.WebhooksSearchResponse: - description: The WebhooksSearchResponse message. - properties: - list: - description: The list of webhooks matching the search criteria. - items: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - nullable: true - readOnly: false - type: array - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + operation: + description: Which connector RPC this dispatches to. + enum: + - OPERATION_UNSPECIFIED + - OPERATION_GRANT + readOnly: true type: string - title: Webhooks Search Response + x-speakeasy-unknown-values: allow + title: Connector Action Ref type: object - x-speakeasy-name-override: WebhooksSearchResponse - c1.api.webhooks.v1.WebhooksServiceCreateRequest: - description: The WebhooksServiceCreateRequest message. + x-speakeasy-name-override: ConnectorActionRef + c1.api.task.v1.ExternalRef: + description: A reference to an external source. This value is unused currently, but may be brought back. properties: - callbackTimeout: - format: duration - readOnly: false - type: string - description: - description: An optional description of the webhook's purpose. - readOnly: false + externalRefSource: + description: The source of the external reference. + enum: + - UNSPECIFIED + - JIRA + readOnly: true type: string - displayName: - description: The human-readable name for the new webhook. - readOnly: false + x-speakeasy-unknown-values: allow + name: + description: The name of the external reference. + readOnly: true type: string url: - description: The destination URL that will receive event notification HTTP callbacks. - readOnly: false + description: The URL to the external reference. + readOnly: true type: string - required: - - displayName - - url - title: Webhooks Service Create Request - type: object - x-speakeasy-name-override: WebhooksServiceCreateRequest - c1.api.webhooks.v1.WebhooksServiceCreateResponse: - description: The WebhooksServiceCreateResponse message. - properties: - webhook: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - title: Webhooks Service Create Response - type: object - x-speakeasy-name-override: WebhooksServiceCreateResponse - c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput: - description: The WebhooksServiceDeleteRequest message. - title: Webhooks Service Delete Request - type: object - x-speakeasy-name-override: WebhooksServiceDeleteRequest - c1.api.webhooks.v1.WebhooksServiceDeleteResponse: - description: Empty response body. Status code indicates success. - title: Webhooks Service Delete Response - type: object - x-speakeasy-name-override: WebhooksServiceDeleteResponse - c1.api.webhooks.v1.WebhooksServiceGetResponse: - description: The WebhooksServiceGetResponse message. - properties: - webhook: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - title: Webhooks Service Get Response + title: External Ref type: object - x-speakeasy-name-override: WebhooksServiceGetResponse - c1.api.webhooks.v1.WebhooksServiceListResponse: - description: The WebhooksServiceListResponse message. + x-speakeasy-name-override: ExternalRef + c1.api.task.v1.FindingTarget: + description: The finding an inert TYPE_MANUAL action ticket remediates. properties: - list: - description: The list of webhooks for the current page. - items: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - nullable: true - readOnly: false - type: array - nextPageToken: - description: A token to retrieve the next page of results, or empty if there are no more results. - readOnly: false + findingId: + description: Reference to the source finding. + readOnly: true type: string - title: Webhooks Service List Response - type: object - x-speakeasy-name-override: WebhooksServiceListResponse - c1.api.webhooks.v1.WebhooksServiceTestRequestInput: - description: The WebhooksServiceTestRequest message. - title: Webhooks Service Test Request - type: object - x-speakeasy-name-override: WebhooksServiceTestRequest - c1.api.webhooks.v1.WebhooksServiceTestResponse: - description: The WebhooksServiceTestResponse message. - properties: - webhook: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookInstance' - title: Webhooks Service Test Response - type: object - x-speakeasy-name-override: WebhooksServiceTestResponse - c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput: - description: The WebhooksServiceUpdateRequest message contains the webhook object to update and a field mask to indicate which fields to update. It uses URL value for input. - properties: - updateMask: - nullable: true - readOnly: false + findingType: + description: The finding type discriminator. + readOnly: true type: string - webhook: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - title: Webhooks Service Update Request - type: object - x-speakeasy-name-override: WebhooksServiceUpdateRequest - c1.api.webhooks.v1.WebhooksServiceUpdateResponse: - description: The WebhooksServiceUpdateResponse message. - properties: - webhook: - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' - title: Webhooks Service Update Response + title: Finding Target type: object - x-speakeasy-name-override: WebhooksServiceUpdateResponse - c1.api.workload_federation.v1.TestTokenStepResult: - description: TestTokenStepResult represents the result of a single validation step. + x-speakeasy-name-override: FindingTarget + c1.api.task.v1.GatedToolCallTarget: + description: The GatedToolCallTarget message. properties: - actual: - description: Actual value from the token. - readOnly: false - type: string - detail: - description: Human-readable detail message. - readOnly: false - type: string - expected: - description: Expected value (for comparison steps). - readOnly: false + appEntitlementId: + description: The appEntitlementId field. + readOnly: true type: string - passed: - description: Whether this step passed. - readOnly: false - type: boolean - skipped: - description: Whether this step was skipped (e.g., CIDR check when no allowlist configured). - readOnly: false - type: boolean - stepName: - description: Step name for display (e.g., "JWT decode", "Issuer match"). - readOnly: false + appId: + description: The appId field. + readOnly: true type: string - title: Test Token Step Result - type: object - x-speakeasy-name-override: TestTokenStepResult - c1.api.workload_federation.v1.WorkloadFederationProvider: - description: WorkloadFederationProvider represents a tenant-level OIDC issuer registration. - properties: - createdAt: - format: date-time + callerKind: + description: The callerKind field. readOnly: true type: string - description: - description: A description of what this provider is for. - readOnly: false + connectorId: + description: The connectorId field. + readOnly: true type: string - disabled: - description: Whether the provider is disabled. Disabled providers reject all token exchanges. - readOnly: false - type: boolean - displayName: - description: The display name of the provider. - readOnly: false + gateId: + description: The gateId field. + readOnly: true type: string - id: - description: The unique ID of the provider. + inputSizeBytes: + description: The inputSizeBytes field. + format: int32 + readOnly: true + type: integer + toolError: + description: The toolError field. readOnly: true type: string - issuerUrl: - description: The OIDC issuer URL. Immutable after creation. + toolId: + description: The toolId field. readOnly: true type: string - updatedAt: - format: date-time + toolInput: + additionalProperties: true + readOnly: true + type: + - object + - "null" + toolKind: + description: The toolKind field. readOnly: true type: string - wellKnownProvider: - description: |- - Well-known provider type. Drives UX (wizard presets, docs, icons). - Set at creation time, immutable. - enum: - - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED - - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM - - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS - - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI - - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM - - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND + toolName: + description: The toolName field. readOnly: true type: string - x-speakeasy-unknown-values: allow - title: Workload Federation Provider + toolOutput: + readOnly: true + type: + - string + - number + - object + - array + - boolean + - "null" + title: Gated Tool Call Target type: object - x-speakeasy-name-override: WorkloadFederationProvider - c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest: - description: The WorkloadFederationServiceCreateProviderRequest message. + x-speakeasy-name-override: GatedToolCallTarget + c1.api.task.v1.ScopeRole: + description: |- + Scope-role variant of TaskTypeAction.target_object. The UI uses the + embedded identifiers to build links and title strings without a separate + Action fetch. properties: - description: - description: A description of what this provider is for. - readOnly: false + appId: + description: The IaaS/sparse-ACL app the (scope, role) pair lives on. + readOnly: true type: string - displayName: - description: The display name for the new provider. - readOnly: false + grantDuration: + format: duration + readOnly: true + type: + - string + - "null" + roleResourceId: + description: The roleResourceId field. + readOnly: true type: string - issuerUrl: - description: |- - The OIDC issuer URL. Will be validated via OIDC discovery. - Normalized on write: lowercase host, no trailing slash, HTTPS only. - readOnly: false + roleResourceTypeId: + description: The roleResourceTypeId field. + readOnly: true type: string - wellKnownProvider: - description: |- - Well-known provider type. Required -- UNSPECIFIED is rejected. - When set to a named source, the backend validates issuer_url consistency. - enum: - - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED - - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM - - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS - - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI - - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM - - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND - readOnly: false + scopeResourceId: + description: The scopeResourceId field. + readOnly: true type: string - x-speakeasy-unknown-values: allow - title: Workload Federation Service Create Provider Request + scopeResourceTypeId: + description: The scopeResourceTypeId field. + readOnly: true + type: string + title: Scope Role type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse: - description: The WorkloadFederationServiceCreateProviderResponse message. + x-speakeasy-name-override: ScopeRole + c1.api.task.v1.Task: + description: A fully-fleged task object. Includes its policy, references to external apps, its type, its processing history, and more. properties: - provider: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - title: Workload Federation Service Create Provider Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput: - description: The WorkloadFederationServiceCreateTrustRequest message. - properties: - allowSourceCidrs: - description: |- - IP allowlist for token exchange requests matching this trust. - Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + actions: + description: The actions that can be performed on the task by the current user. items: + enum: + - TASK_ACTION_TYPE_UNSPECIFIED + - TASK_ACTION_TYPE_CLOSE + - TASK_ACTION_TYPE_APPROVE + - TASK_ACTION_TYPE_DENY + - TASK_ACTION_TYPE_COMMENT + - TASK_ACTION_TYPE_DELETE + - TASK_ACTION_TYPE_REASSIGN + - TASK_ACTION_TYPE_RESTART + - TASK_ACTION_TYPE_SEND_REMINDER + - TASK_ACTION_TYPE_PROVISION_COMPLETE + - TASK_ACTION_TYPE_PROVISION_CANCELLED + - TASK_ACTION_TYPE_PROVISION_ERRORED + - TASK_ACTION_TYPE_ROLLBACK_SKIPPED + - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED + - TASK_ACTION_TYPE_HARD_RESET + - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS + - TASK_ACTION_TYPE_CHANGE_POLICY + - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS + - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION + - TASK_ACTION_TYPE_SET_ANALYSIS_ID + - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST + - TASK_ACTION_TYPE_PROCESS_NOW + - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP + - TASK_ACTION_TYPE_SKIP_STEP + - TASK_ACTION_TYPE_ROLLBACK_CANCELLED + - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA + - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION type: string - nullable: true - readOnly: false - type: array - conditionExpression: - description: |- - CEL expression evaluated against JWT claims. Must return bool. - Compiled and validated before storage. - readOnly: false + x-speakeasy-unknown-values: allow + readOnly: true + type: + - array + - "null" + analysisId: + description: The ID of the analysis object associated with this task created by an analysis workflow if the analysis feature is enabled for your tenant. + readOnly: true + type: string + annotations: + description: An array of `google.protobuf.Any` annotations with various base64-encoded data. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + approverIds: + description: An array of IDs belonging to Identity Users that have approved or denied any step in this task. + items: + type: string + readOnly: true + type: + - array + - "null" + commentCount: + description: The count of comments. + format: int32 + readOnly: true + type: integer + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdByUserId: + description: The ID of the user that is the creator of this task. This may not always match the userId field. + readOnly: true type: string + data: + additionalProperties: true + readOnly: true + type: + - object + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" description: - description: A description of what this trust policy matches. - readOnly: false + description: The description of the task. This is also known as justification. + readOnly: true type: string displayName: - description: The display name for the trust. - readOnly: false + description: The display name of the task. + readOnly: true type: string - passthroughClaims: - description: JWT claim names from the subject token to copy into the issued C1 token. + emergencyAccess: + description: A field indicating whether this task was created using an emergency access flow, or escalated to emergency access. On task creation, it will also use the app entitlement's emergency policy when possible. + readOnly: true + type: boolean + externalRefs: + description: An array of external references to the task. Historically that has been items like Jira task IDs. This is currently unused, but may come back in the future for integrations. items: - type: string - nullable: true - readOnly: false - type: array - providerId: - description: The provider this trust references. - readOnly: false + $ref: '#/components/schemas/c1.api.task.v1.ExternalRef' + readOnly: true + type: + - array + - "null" + form: + oneOf: + - $ref: '#/components/schemas/c1.api.form.v1.Form' + - type: "null" + id: + description: The ID of the task. + readOnly: true type: string - scopedRoleIds: - description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + insightIds: + description: The insightIds field. items: type: string - nullable: true - readOnly: false - type: array - title: Workload Federation Service Create Trust Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse: - description: The WorkloadFederationServiceCreateTrustResponse message. - properties: - trust: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - title: Workload Federation Service Create Trust Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceCreateTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput: - description: The WorkloadFederationServiceDeleteProviderRequest message. - title: Workload Federation Service Delete Provider Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse: - description: The WorkloadFederationServiceDeleteProviderResponse message. - title: Workload Federation Service Delete Provider Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput: - description: The WorkloadFederationServiceDeleteTrustRequest message. - title: Workload Federation Service Delete Trust Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse: - description: The WorkloadFederationServiceDeleteTrustResponse message. - title: Workload Federation Service Delete Trust Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse: - description: The WorkloadFederationServiceGetProviderResponse message. - properties: - provider: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - title: Workload Federation Service Get Provider Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceGetProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse: - description: The WorkloadFederationServiceGetTrustResponse message. - properties: - trust: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - title: Workload Federation Service Get Trust Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceGetTrustResponse - c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse: - description: The WorkloadFederationServiceListProvidersResponse message. - properties: - list: - description: The list field. + type: + - array + - "null" + numericId: + description: A human-usable numeric ID of a task which can be included in place of the fully qualified task id in path parmeters (but not search queries). + format: int64 + readOnly: true + type: string + origin: + description: The origin field. + enum: + - TASK_ORIGIN_UNSPECIFIED + - TASK_ORIGIN_PROFILE_MEMBERSHIP_AUTOMATION + - TASK_ORIGIN_SLACK + - TASK_ORIGIN_API + - TASK_ORIGIN_JIRA + - TASK_ORIGIN_COPILOT + - TASK_ORIGIN_WEBAPP + - TASK_ORIGIN_TIME_REVOKE + - TASK_ORIGIN_NON_USAGE_REVOKE + - TASK_ORIGIN_PROFILE_MEMBERSHIP_MANUAL + - TASK_ORIGIN_PROFILE_MEMBERSHIP + - TASK_ORIGIN_AUTOMATION + - TASK_ORIGIN_ACCESS_REVIEW + - TASK_ORIGIN_CASCADE_DELETE + type: string + x-speakeasy-unknown-values: allow + policy: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.PolicyInstance' + - type: "null" + policyGenerationId: + description: The policy generation id refers to the current policy's generation ID. This is changed when the policy is changed on a task. + readOnly: true + type: string + processing: + description: The processing state of a task as defined by the `processing_enum` + enum: + - TASK_PROCESSING_TYPE_UNSPECIFIED + - TASK_PROCESSING_TYPE_PROCESSING + - TASK_PROCESSING_TYPE_WAITING + - TASK_PROCESSING_TYPE_DONE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + recommendation: + description: The recommendation field. + enum: + - INSIGHT_RECOMMENDATION_UNSPECIFIED + - INSIGHT_RECOMMENDATION_APPROVE + - INSIGHT_RECOMMENDATION_DENY + - INSIGHT_RECOMMENDATION_REVIEW + type: string + x-speakeasy-unknown-values: allow + revocationTargets: + description: |- + Ancestor entitlements that will also be revoked when this revoke task is approved. + Populated at ticket creation time for inherited grant revocations. items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + $ref: '#/components/schemas/c1.api.task.v1.TaskRevocationTarget' + readOnly: true + type: + - array + - "null" + state: + description: The current state of the task as defined by the `state_enum` + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED + readOnly: true type: string - title: Workload Federation Service List Providers Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceListProvidersResponse - c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse: - description: The WorkloadFederationServiceListTrustsResponse message. - properties: - list: - description: The list field. + x-speakeasy-unknown-values: allow + stepApproverIds: + description: An array of IDs belonging to Identity Users that are allowed to review this step in a task. items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + type: string + readOnly: true + type: + - array + - "null" + type: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskType' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The ID of the user that is the target of this task. This may be empty if we're targeting a specific app user that has no known identity user. + readOnly: true type: string - title: Workload Federation Service List Trusts Response + title: Task type: object - x-speakeasy-name-override: WorkloadFederationServiceListTrustsResponse - c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest: - description: The WorkloadFederationServiceSearchTrustsRequest message. + x-speakeasy-name-override: Task + c1.api.task.v1.TaskAction: + description: Represents a single action that was performed on a task. properties: - pageSize: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - pageToken: - description: The pageToken field. - readOnly: false + actionType: + description: The type of action that was performed. + enum: + - TASK_ACTION_TYPE_UNSPECIFIED + - TASK_ACTION_TYPE_CLOSE + - TASK_ACTION_TYPE_APPROVE + - TASK_ACTION_TYPE_DENY + - TASK_ACTION_TYPE_COMMENT + - TASK_ACTION_TYPE_DELETE + - TASK_ACTION_TYPE_REASSIGN + - TASK_ACTION_TYPE_RESTART + - TASK_ACTION_TYPE_SEND_REMINDER + - TASK_ACTION_TYPE_PROVISION_COMPLETE + - TASK_ACTION_TYPE_PROVISION_CANCELLED + - TASK_ACTION_TYPE_PROVISION_ERRORED + - TASK_ACTION_TYPE_ROLLBACK_SKIPPED + - TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED + - TASK_ACTION_TYPE_HARD_RESET + - TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS + - TASK_ACTION_TYPE_CHANGE_POLICY + - TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS + - TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION + - TASK_ACTION_TYPE_SET_ANALYSIS_ID + - TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST + - TASK_ACTION_TYPE_PROCESS_NOW + - TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP + - TASK_ACTION_TYPE_SKIP_STEP + - TASK_ACTION_TYPE_ROLLBACK_CANCELLED + - TASK_ACTION_TYPE_UPDATE_REQUEST_DATA + - TASK_ACTION_TYPE_UPDATE_GRANT_DURATION type: string - providerId: - description: 'Optional: filter trusts by provider ID.' - readOnly: false + x-speakeasy-unknown-values: allow + bulkActionId: + description: The ID of the bulk action this action belongs to, if it was part of a bulk operation. type: string - query: - description: 'Optional: full-text search on trust display name and description.' - readOnly: false + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The unique ID of this action. type: string - servicePrincipalId: - description: 'Optional: filter trusts by service principal ID.' - readOnly: false + policyStepId: + description: The ID of the policy step this action was performed on. type: string - title: Workload Federation Service Search Trusts Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsRequest - c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse: - description: The WorkloadFederationServiceSearchTrustsResponse message. - properties: - list: - description: The list field. - items: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - nullable: true - readOnly: false - type: array - nextPageToken: - description: The nextPageToken field. - readOnly: false + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + userId: + description: The ID of the user who performed the action. type: string - title: Workload Federation Service Search Trusts Response + title: Task Action type: object - x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsResponse - c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest: - description: The WorkloadFederationServiceTestCELRequest message. + x-speakeasy-name-override: SubmittedTaskAction + c1.api.task.v1.TaskActionsServiceApproveRequestInput: + description: The TaskActionsServiceApproveRequest object lets you approve a task. properties: - claimsJson: - description: |- - The claims to evaluate against, as a JSON string. - Parsed into map[string]any for CEL evaluation. - readOnly: false + comment: + description: The comment attached to the request. type: string - expression: - description: The CEL expression to evaluate. Must return bool. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the policy step on the given task to approve. type: string - title: Workload Federation Service Test Cel Request + required: + - policyStepId + title: Task Actions Service Approve Request type: object - x-speakeasy-name-override: WorkloadFederationServiceTestCELRequest - c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse: - description: The WorkloadFederationServiceTestCELResponse message. + x-speakeasy-name-override: TaskActionsServiceApproveRequest + c1.api.task.v1.TaskActionsServiceApproveResponse: + description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. properties: - error: - description: Error message if compilation or evaluation failed. - readOnly: false - type: string - expression: - description: The expression that was evaluated (echo back). - readOnly: false + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task approve action created by this request. + readOnly: true type: string - matched: - description: Whether the expression matched (returned true). - readOnly: false - type: boolean - title: Workload Federation Service Test Cel Response + title: Task Actions Service Approve Response type: object - x-speakeasy-name-override: WorkloadFederationServiceTestCELResponse - c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput: - description: The WorkloadFederationServiceTestTokenRequest message. + x-speakeasy-name-override: TaskActionsServiceApproveResponse + c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput: + description: TaskActionsServiceApproveWithStepUpRequest is used to approve a task with step-up authentication properties: - sourceIp: - description: |- - Optional: override source IP for CIDR testing. - If empty, uses the request's source IP. - Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. - readOnly: false + comment: + description: The comment attached to the request. type: string - subjectToken: - description: The raw JWT to validate (the subject_token from a CI job). - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the policy step on the given task to approve. type: string - title: Workload Federation Service Test Token Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceTestTokenRequest - c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse: - description: The WorkloadFederationServiceTestTokenResponse message. - properties: - audienceValidation: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - celEvaluation: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - cidrCheck: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - decodedClaimsJson: + stepUpTransactionId: description: |- - The decoded JWT claims (best-effort, even if signature fails). - Returned as JSON string for display. - readOnly: false + The step-up transaction ID that was verified. + If unset, the response will include a redirect URL to + complete the step-up authentication. type: string - issuerMatch: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - jwtDecode: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - overallResult: - description: 'Overall result: true only if ALL steps passed.' - readOnly: false - type: boolean - signatureValidation: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - tokenFreshness: - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' - title: Workload Federation Service Test Token Response + required: + - policyStepId + - stepUpTransactionId + title: Task Actions Service Approve With Step Up Request type: object - x-speakeasy-name-override: WorkloadFederationServiceTestTokenResponse - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput: - description: The WorkloadFederationServiceUpdateProviderRequest message. + x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpRequest + c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse: + description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication properties: - provider: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - updateMask: - nullable: true - readOnly: false + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + redirectUrl: + description: The redirect URL the client must visit to complete the step-up authentication. type: string - title: Workload Federation Service Update Provider Request - type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderRequest - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse: - description: The WorkloadFederationServiceUpdateProviderResponse message. - properties: - provider: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' - title: Workload Federation Service Update Provider Response - type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderResponse - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput: - description: The WorkloadFederationServiceUpdateTrustRequest message. - properties: - trust: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - updateMask: - nullable: true - readOnly: false + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task approve action created by this request. + readOnly: true type: string - title: Workload Federation Service Update Trust Request + title: Task Actions Service Approve With Step Up Response type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustRequest - c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse: - description: The WorkloadFederationServiceUpdateTrustResponse message. + x-speakeasy-name-override: TaskActionsServiceApproveWithStepUpResponse + c1.api.task.v1.TaskActionsServiceCloseRequestInput: + description: The TaskActionsServiceCloseRequest object lets you close or cancel a task. properties: - trust: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' - title: Workload Federation Service Update Trust Response + comment: + description: An optional comment attached to the close action. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Close Request type: object - x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustResponse - c1.api.workload_federation.v1.WorkloadFederationTrust: - description: |- - WorkloadFederationTrust represents a per-SP trust policy that references - a tenant-level provider and defines a CEL condition for claim matching. + x-speakeasy-name-override: TaskActionsServiceCloseRequest + c1.api.task.v1.TaskActionsServiceCloseResponse: + description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. properties: - allowSourceCidrs: - description: IP allowlist for token exchange requests matching this trust. + expanded: + description: List of serialized related objects. items: - type: string - nullable: true - readOnly: false - type: array - clientId: - description: |- - The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). - Used as the client_id parameter in RFC 8693 token exchange requests. + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskActionId: + description: The ID of the task close action created by this request. readOnly: true type: string - conditionExpression: - description: |- - CEL expression evaluated against JWT claims. Must return bool. - Example: claims.sub.startsWith("repo:acme/infra:") && claims.environment == "production" - readOnly: false - type: string - createdAt: - format: date-time - readOnly: true - type: string - description: - description: A description of what this trust policy matches. - readOnly: false - type: string - disabled: - description: Whether the trust is disabled. - readOnly: false - type: boolean - displayName: - description: The display name of the trust. - readOnly: false - type: string - passthroughClaims: - description: |- - JWT claim names from the subject token to copy into the issued C1 token. - Values are placed in the "c1wfc" claim as a map[string]string. - Only string-valued claims are copied; non-string claims are silently skipped. - Example: ["repository", "repository_owner", "job_workflow_ref"] - items: - type: string - nullable: true - readOnly: false - type: array - providerId: - description: The provider ID this trust references. Immutable after creation. - readOnly: true - type: string - scopedRoleIds: - description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). - items: - type: string - nullable: true - readOnly: false - type: array - servicePrincipalId: - description: The service principal user ID this trust belongs to. - readOnly: true - type: string - updatedAt: - format: date-time - readOnly: true - type: string - title: Workload Federation Trust + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Actions Service Close Response type: object - x-speakeasy-name-override: WorkloadFederationTrust - c1.mcp.role_mining.v1.AccessProfileMatch: - description: The AccessProfileMatch message. + x-speakeasy-name-override: TaskActionsServiceCloseResponse + c1.api.task.v1.TaskActionsServiceCommentRequestInput: + description: The TaskActionsServiceCommentRequest object lets you create a new comment on a task. properties: - catalogDisplayName: - description: The catalogDisplayName field. - readOnly: false - type: string - catalogId: - description: The catalogId field. - readOnly: false - type: string - matchType: - description: The matchType field. - enum: - - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED - - ACCESS_PROFILE_MATCH_TYPE_EXACT - - ACCESS_PROFILE_MATCH_TYPE_SUPERSET - - ACCESS_PROFILE_MATCH_TYPE_PARTIAL - readOnly: false + comment: + description: The comment to be posted to the task. type: string - x-speakeasy-unknown-values: allow - missingEntitlements: - description: The missingEntitlements field. - items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - nullable: true - readOnly: false - type: array - overlapRatio: - description: The overlapRatio field. - readOnly: false - type: number - title: Access Profile Match + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Comment Request type: object - x-speakeasy-name-override: AccessProfileMatch - c1.mcp.role_mining.v1.AttributeFacet: - description: AttributeFacet represents a filterable user profile attribute with its available values. + x-speakeasy-name-override: TaskActionsServiceCommentRequest + c1.api.task.v1.TaskActionsServiceCommentResponse: + description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. properties: - attribute: - description: The attribute field. - readOnly: false - type: string - displayName: - description: The displayName field. - readOnly: false - type: string - values: - description: The values field. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeValue' - nullable: true - readOnly: false - type: array - title: Attribute Facet - type: object - x-speakeasy-name-override: AttributeFacet - c1.mcp.role_mining.v1.AttributeValue: - description: AttributeValue represents a single value within a facet. - properties: - displayName: - description: The displayName field. - readOnly: false - type: string - userCount: - description: The userCount field. - format: int32 - readOnly: false - type: integer - value: - description: The value field. - readOnly: false - type: string - title: Attribute Value + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Actions Service Comment Response type: object - x-speakeasy-name-override: RoleMiningAttributeValue - c1.mcp.role_mining.v1.CohortEntitlement: - description: The CohortEntitlement message. + x-speakeasy-name-override: TaskActionsServiceCommentResponse + c1.api.task.v1.TaskActionsServiceDenyRequestInput: + description: The TaskActionsServiceDenyRequest object lets you deny a task. properties: - appDisplayName: - description: The appDisplayName field. - readOnly: false - type: string - appId: - description: The appId field. - readOnly: false - type: string - appResourceDisplayName: - description: The appResourceDisplayName field. - readOnly: false - type: string - appResourceTypeDisplayName: - description: The appResourceTypeDisplayName field. - readOnly: false - type: string - coverage: - description: The coverage field. - readOnly: false - type: number - entitlementDisplayName: - description: The entitlementDisplayName field. - readOnly: false + comment: + description: The comment attached to the request. type: string - entitlementId: - description: The entitlementId field. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the current policy step. This is the step you want to deny. type: string - grantedCount: - description: The grantedCount field. - format: int32 - readOnly: false - type: integer - title: Cohort Entitlement + title: Task Actions Service Deny Request type: object - x-speakeasy-name-override: CohortEntitlement - c1.mcp.role_mining.v1.EntitlementCluster: - description: The EntitlementCluster message. + x-speakeasy-name-override: TaskActionsServiceDenyRequest + c1.api.task.v1.TaskActionsServiceDenyResponse: + description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. properties: - avgCoverage: - description: The avgCoverage field. - readOnly: false - type: number - avgSimilarity: - description: The avgSimilarity field. - readOnly: false - type: number - entitlements: - description: The entitlements field. + expanded: + description: List of serialized related objects. items: - $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' - nullable: true - readOnly: false - type: array - userCount: - description: The userCount field. - format: int32 - readOnly: false - type: integer - title: Entitlement Cluster - type: object - x-speakeasy-name-override: EntitlementCluster - c1.mcp.role_mining.v1.ProfileFilter: - description: |- - ProfileFilter defines a filter on a user profile attribute. - Use GetOrgOverview to discover available attribute keys and their values. - properties: - attribute: - description: The attribute field. - readOnly: false + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task deny action created by this request. + readOnly: true type: string - values: - description: The values field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Profile Filter + title: Task Actions Service Deny Response type: object - x-speakeasy-name-override: ProfileFilter - c1.webhooks.v1.Body: - description: The Body message. + x-speakeasy-name-override: TaskActionsServiceDenyResponse + c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput: + description: The TaskActionsServiceEscalateToEmergencyAccessRequest object lets you escalate a task to the emergency access workflow. properties: - callbackUrl: - description: |- - If your receiver returns HTTP Status Code 202 Accepted, it MUST send its resposne to this URL as a POST - message body. - - If your receiver returns any other status code, it is expected to not use the callback url. - - This value will match the "Webhook-Callback-Url" header. - readOnly: false - type: string - event: - description: |- - The type of event that triggered this Webhook. - - This value will match the "Webhook-Event" header. - - The value will be one of: - - "c1.webhooks.v1.PayloadTest" - - "c1.webhooks.v1.PayloadPolicyApprovalStep" - - "c1.webhooks.v1.PayloadPolicyPostAction" - - "c1.webhooks.v1.PayloadProvisionStep" - readOnly: false + comment: + description: An optional comment attached to the escalation. type: string - payload: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook body will use a different string. - - This value will match the "Webhook-Version" header. - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the current policy step being escalated from. type: string - webhookId: - description: |- - Unique ID for this Webhook. Your receiver should only process this ID once. - - This value will match the "Webhook-Id" header. - readOnly: false + title: Task Actions Service Escalate To Emergency Access Request + type: object + x-speakeasy-name-override: TaskActionsServiceEscalateToEmergencyAccessRequest + c1.api.task.v1.TaskActionsServiceHardResetRequestInput: + description: The TaskActionsServiceHardResetRequest object lets you reset a task and recalculate its policy. + properties: + comment: + description: The comment attached to the request. type: string - title: Body + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Hard Reset Request type: object - x-speakeasy-include: true - x-speakeasy-name-override: Body - c1.webhooks.v1.PayloadPolicyApprovalStep: - description: The PayloadPolicyApprovalStep message. + x-speakeasy-name-override: TaskActionsServiceHardResetRequest + c1.api.task.v1.TaskActionsServiceHardResetResponse: + description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. properties: expanded: description: List of serialized related objects. @@ -28017,19 +34188,32 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Payload Policy Approval Step + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task reset action created by this request. + type: string + title: Task Actions Service Hard Reset Response type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadPolicyApprovalStep - c1.webhooks.v1.PayloadPolicyPostAction: - description: The PayloadPolicyPostAction message. + x-speakeasy-name-override: TaskActionsServiceHardResetResponse + c1.api.task.v1.TaskActionsServiceProcessNowRequestInput: + description: The TaskActionsServiceProcessNowRequest object lets you trigger processing of a task immediately. + properties: + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Process Now Request + type: object + x-speakeasy-name-override: TaskActionsServiceProcessNowRequest + c1.api.task.v1.TaskActionsServiceProcessNowResponse: + description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. properties: expanded: description: List of serialized related objects. @@ -28040,19 +34224,42 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false type: object - nullable: true - readOnly: false - type: array + type: + - array + - "null" taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Payload Policy Post Action + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Actions Service Process Now Response type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadPolicyPostAction - c1.webhooks.v1.PayloadProvisionStep: - description: The PayloadProvisionStep message. + x-speakeasy-name-override: TaskActionsServiceProcessNowResponse + c1.api.task.v1.TaskActionsServiceReassignRequestInput: + description: The TaskActionsServiceReassignRequest object lets you reassign a task's current policy step to different users. + properties: + comment: + description: An optional comment attached to the reassignment. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + newStepUserIds: + description: The IDs of the users to reassign the current policy step to. Must be from the allowed reassignees list. + items: + type: string + type: + - array + - "null" + policyStepId: + description: The ID of the current policy step to reassign. Must match the task's active step. + type: string + title: Task Actions Service Reassign Request + type: object + x-speakeasy-name-override: TaskActionsServiceReassignRequest + c1.api.task.v1.TaskActionsServiceReassignResponse: + description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. properties: expanded: description: List of serialized related objects. @@ -28063,13888 +34270,25018 @@ components: '@type': description: The type of the serialized message. type: string - readOnly: false + readOnly: true type: object - nullable: true - readOnly: false - type: array + readOnly: true + type: + - array + - "null" taskView: - $ref: '#/components/schemas/c1.api.task.v1.TaskView' - title: Payload Provision Step - type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadProvisionStep - c1.webhooks.v1.PayloadTest: - description: The PayloadTest message. - title: Payload Test + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task reassign action created by this request. + readOnly: true + type: string + title: Task Actions Service Reassign Response type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadTest - c1.webhooks.v1.PayloadWorkflowStep: - description: The PayloadWorkflowStep message. + x-speakeasy-name-override: TaskActionsServiceReassignResponse + c1.api.task.v1.TaskActionsServiceRestartRequestInput: + description: The TaskActionsServiceRestartRequest object lets you restart a task. properties: - context: - additionalProperties: true - readOnly: false - type: object - workflowExecutionId: - description: The workflow execution ID - format: int64 - readOnly: false - type: string - workflowExecutionStepId: - description: The workflow execution step ID - readOnly: false + comment: + description: The comment attached to the request. type: string - workflowId: - description: The workflow template ID - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: Deprecated. This field is accepted but does not affect behavior. type: string - title: Payload Workflow Step + title: Task Actions Service Restart Request type: object - x-speakeasy-include: true - x-speakeasy-name-override: PayloadWorkflowStep - c1.webhooks.v1.ResponsePolicyApprovalStep: - description: | - The ResponsePolicyApprovalStep message. - - This message contains a oneof named action. Only a single field of the following list may be set at a time: - - approve - - deny - - reassign - - replacePolicy + x-speakeasy-name-override: TaskActionsServiceRestartRequest + c1.api.task.v1.TaskActionsServiceRestartResponse: + description: The TaskActionsServiceRestartResponse returns the updated task after restarting. properties: - approve: - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove' - deny: - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny' - reassign: - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign' - replacePolicy: - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy' - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. - readOnly: false + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task restart action created by this request. type: string - title: Response Policy Approval Step + title: Task Actions Service Restart Response type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponsePolicyApprovalStep - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy: - description: The ResponsePolicyApprovalReplacePolicy message. - nullable: true + x-speakeasy-name-override: TaskActionsServiceRestartResponse + c1.api.task.v1.TaskActionsServiceSkipStepRequestInput: + description: The TaskActionsServiceSkipStepRequest object lets you skip a policy step in a task. properties: comment: - description: The comment field. - readOnly: false + description: The comment attached to the request. type: string - policySteps: - description: The policySteps field. - items: - $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' - nullable: true - readOnly: false - type: array - title: Response Policy Approval Replace Policy - type: object - x-speakeasy-name-override: ResponsePolicyApprovalReplacePolicy - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove: - description: The ResponsePolicyApprovalStepApprove message. - nullable: true - properties: - comment: - description: optional comment - readOnly: false + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + policyStepId: + description: The ID of the policy step to skip. type: string - title: Response Policy Approval Step Approve + required: + - policyStepId + title: Task Actions Service Skip Step Request type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepApprove - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny: - description: The ResponsePolicyApprovalStepDeny message. - nullable: true + x-speakeasy-name-override: TaskActionsServiceSkipStepRequest + c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput: + description: The TaskActionsServiceUpdateGrantDurationRequest object lets you change the grant duration on a grant task. properties: - comment: - description: optional comment - readOnly: false - type: string - title: Response Policy Approval Step Deny + duration: + format: duration + type: + - string + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + required: + - duration + title: Task Actions Service Update Grant Duration Request type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepDeny - c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign: - description: The ResponsePolicyApprovalStepReassign message. - nullable: true + x-speakeasy-name-override: TaskActionsServiceUpdateGrantDurationRequest + c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput: + description: The TaskActionsServiceUpdateRequestDataRequest object lets you submit form data for a task that is in a form policy step. properties: - comment: - description: optional comment - readOnly: false - type: string - newStepUserIds: - description: The newStepUserIds field. - items: - type: string - nullable: true - readOnly: false - type: array - title: Response Policy Approval Step Reassign + data: + additionalProperties: true + type: + - object + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + title: Task Actions Service Update Request Data Request type: object - x-speakeasy-name-override: ResponsePolicyApprovalStepReassign - c1.webhooks.v1.ResponsePolicyPostAction: - description: The ResponsePolicyPostAction message. + x-speakeasy-name-override: TaskActionsServiceUpdateRequestDataRequest + c1.api.task.v1.TaskAuditAccessRequestOutcome: + description: The TaskAuditAccessRequestOutcome message. properties: - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. - readOnly: false + outcome: + description: The outcome field. + enum: + - ACCESS_REQUEST_OUTCOME_UNSPECIFIED + - ACCESS_REQUEST_OUTCOME_APPROVED + - ACCESS_REQUEST_OUTCOME_DENIED + - ACCESS_REQUEST_OUTCOME_ERROR + - ACCESS_REQUEST_OUTCOME_CANCELLED type: string - title: Response Policy Post Action + x-speakeasy-unknown-values: allow + title: Task Audit Access Request Outcome type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponsePolicyPostAction - c1.webhooks.v1.ResponseProvisionStep: - description: | - The ResponseProvisionStep message. - - This message contains a oneof named outcome. Only a single field of the following list may be set at a time: - - complete - - errored + x-speakeasy-name-override: TaskAuditAccessRequestOutcome + c1.api.task.v1.TaskAuditAccountLifecycleActionCreated: + description: The TaskAuditAccountLifecycleActionCreated message. properties: - complete: - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete' - errored: - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored' - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. - readOnly: false + batonActionDisplayName: + description: The batonActionDisplayName field. type: string - title: Response Provision Step - type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseProvisionStep - c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete: - description: The ResponseProvisionStepComplete message. - nullable: true - properties: - comment: - description: optional comment - readOnly: false + batonActionInvocationId: + description: The batonActionInvocationId field. type: string - title: Response Provision Step Complete - type: object - x-speakeasy-name-override: ResponseProvisionStepComplete - c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored: - description: The ResponseProvisionStepErrored message. - nullable: true - properties: - comment: - description: optional comment - readOnly: false + batonActionName: + description: The batonActionName field. type: string - title: Response Provision Step Errored + batonAppId: + description: The batonAppId field. + type: string + batonConnectorId: + description: The batonConnectorId field. + type: string + title: Task Audit Account Lifecycle Action Created type: object - x-speakeasy-name-override: ResponseProvisionStepErrored - c1.webhooks.v1.ResponseTest: - description: The ResponseTest message. + x-speakeasy-name-override: TaskAuditAccountLifecycleActionCreated + c1.api.task.v1.TaskAuditAccountLifecycleActionFailed: + description: The TaskAuditAccountLifecycleActionFailed message. properties: - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. - readOnly: false + batonActionDisplayName: + description: The batonActionDisplayName field. type: string - title: Response Test + batonActionInvocationId: + description: The batonActionInvocationId field. + type: string + batonActionName: + description: The batonActionName field. + type: string + batonAppId: + description: The batonAppId field. + type: string + batonConnectorId: + description: The batonConnectorId field. + type: string + error: + description: The error field. + type: string + title: Task Audit Account Lifecycle Action Failed type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseTest - c1.webhooks.v1.ResponseWorkflowStep: - description: The ResponseWorkflowStep message. + x-speakeasy-name-override: TaskAuditAccountLifecycleActionFailed + c1.api.task.v1.TaskAuditActionInstanceCreated: + description: The TaskAuditActionInstanceCreated message. properties: - context: - additionalProperties: true - readOnly: false - type: object - version: - description: |- - version contains the constant value "v1". Future versions of the Webhook Response - will use a different string. - readOnly: false + instance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + title: Task Audit Action Instance Created + type: object + x-speakeasy-name-override: TaskAuditActionInstanceCreated + c1.api.task.v1.TaskAuditActionInstanceFailed: + description: The TaskAuditActionInstanceFailed message. + properties: + instance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + title: Task Audit Action Instance Failed + type: object + x-speakeasy-name-override: TaskAuditActionInstanceFailed + c1.api.task.v1.TaskAuditActionInstanceSucceeded: + description: The TaskAuditActionInstanceSucceeded message. + properties: + instance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ActionInstance' + - type: "null" + title: Task Audit Action Instance Succeeded + type: object + x-speakeasy-name-override: TaskAuditActionInstanceSucceeded + c1.api.task.v1.TaskAuditActionSubmitted: + description: The TaskAuditActionSubmitted message. + properties: + action: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAction' + - type: "null" + title: Task Audit Action Submitted + type: object + x-speakeasy-name-override: TaskAuditActionSubmitted + c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy: + description: The TaskAuditApprovalAutoAcceptedByPolicy message. + title: Task Audit Approval Auto Accepted By Policy + type: object + x-speakeasy-name-override: TaskAuditApprovalAutoAcceptedByPolicy + c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy: + description: The TaskAuditApprovalAutoRejectedByPolicy message. + title: Task Audit Approval Auto Rejected By Policy + type: object + x-speakeasy-name-override: TaskAuditApprovalAutoRejectedByPolicy + c1.api.task.v1.TaskAuditApprovalHappenedAutomatically: + description: The TaskAuditApprovalHappenedAutomatically message. + title: Task Audit Approval Happened Automatically + type: object + x-speakeasy-name-override: TaskAuditApprovalHappenedAutomatically + c1.api.task.v1.TaskAuditApprovalInstanceChange: + description: The TaskAuditApprovalInstanceChange message. + properties: + instance: + oneOf: + - $ref: '#/components/schemas/c1.api.policy.v1.ApprovalInstance' + - type: "null" + title: Task Audit Approval Instance Change + type: object + x-speakeasy-name-override: TaskAuditApprovalInstanceChange + c1.api.task.v1.TaskAuditBulkActionError: + description: The TaskAuditBulkActionError message. + properties: + error: + description: The error field. type: string - title: Response Workflow Step + title: Task Audit Bulk Action Error type: object - x-speakeasy-include: true - x-speakeasy-name-override: ResponseWorkflowStep - google.rpc.Status: - description: |- - The `Status` type defines a logical error model that is suitable for - different programming environments, including REST APIs and RPC APIs. It is - used by [gRPC](https://github.com/grpc). Each `Status` message contains - three pieces of data: error code, error message, and error details. - - You can find out more about this error model and how to work with it in the - [API Design Guide](https://cloud.google.com/apis/design/errors). + x-speakeasy-name-override: TaskAuditBulkActionError + c1.api.task.v1.TaskAuditCertifyOutcome: + description: The TaskAuditCertifyOutcome message. properties: - code: - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - format: int32 - readOnly: false - type: integer - details: - description: |- - A list of messages that carry the error details. There is a common set of - message types for APIs to use. - items: - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - properties: - '@type': - description: The type of the serialized message. - type: string - readOnly: false - type: object - nullable: true - readOnly: false - type: array - message: - description: |- - A developer-facing error message, which should be in English. Any - user-facing error message should be localized and sent in the - [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - readOnly: false + outcome: + description: The outcome field. + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT type: string - title: Status + x-speakeasy-unknown-values: allow + title: Task Audit Certify Outcome type: object - x-speakeasy-name-override: Status - validate.AnyRules: - description: |- - AnyRules describe constraints applied exclusively to the - `google.protobuf.Any` well-known type - nullable: true + x-speakeasy-name-override: TaskAuditCertifyOutcome + c1.api.task.v1.TaskAuditComment: + description: The TaskAuditComment message. properties: - in: - description: |- - In specifies that this field's `type_url` must be equal to one of the - specified values. - items: - type: string - nullable: true - readOnly: false - type: array - notIn: - description: |- - NotIn specifies that this field's `type_url` must not be equal to any of - the specified values. - items: - type: string - nullable: true - readOnly: false - type: array - required: - description: Required specifies that this field must be set - readOnly: false - type: boolean - title: Any Rules + comment: + description: The comment field. + type: string + updatedAt: + format: date-time + type: + - string + - "null" + updatedBy: + description: The updatedBy field. + type: string + title: Task Audit Comment type: object - x-speakeasy-name-override: AnyRules - validate.BoolRules: - description: BoolRules describes the constraints applied to `bool` values - nullable: true + x-speakeasy-name-override: TaskAuditComment + c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult: + description: The TaskAuditConditionalPolicyExecutionResult message. properties: - const: - description: Const specifies that this field must be exactly the specified value - readOnly: false + condition: + description: The condition field. + type: string + conditionMatched: + description: The conditionMatched field. type: boolean - title: Bool Rules + defaultCondition: + description: The defaultCondition field. + type: boolean + error: + description: The error field. + type: string + policyKey: + description: The policyKey field. + type: string + title: Task Audit Conditional Policy Execution Result type: object - x-speakeasy-name-override: BoolRules - validate.BytesRules: + x-speakeasy-name-override: TaskAuditConditionalPolicyExecutionResult + c1.api.task.v1.TaskAuditConnectorActionResult: description: | - BytesRules describe the constraints applied to `bytes` values + The TaskAuditConnectorActionResult message. - This message contains a oneof named well_known. Only a single field of the following list may be set at a time: - - ip - - ipv4 - - ipv6 - nullable: true + This message contains a oneof named result. Only a single field of the following list may be set at a time: + - success + - error + - cancelled + - pending properties: - const: - description: Const specifies that this field must be exactly the specified value - format: base64 - readOnly: false + appEntitlementId: + description: The appEntitlementId field. type: string - contains: - description: |- - Contains specifies that this field must have the specified bytes - anywhere in the string. - format: base64 - readOnly: false + appId: + description: The appId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: base64 - type: string - nullable: true - readOnly: false - type: array - ip: - description: |- - Ip specifies that the field must be a valid IP (v4 or v6) address in - byte format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - nullable: true - readOnly: false - type: boolean - ipv4: - description: |- - Ipv4 specifies that the field must be a valid IPv4 address in byte - format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - nullable: true - readOnly: false - type: boolean - ipv6: - description: |- - Ipv6 specifies that the field must be a valid IPv6 address in byte - format - This field is part of the `well_known` oneof. - See the documentation for `validate.BytesRules` for more details. - nullable: true - readOnly: false - type: boolean - len: - description: Len specifies that this field must be the specified number of bytes - format: uint64 - readOnly: false + cancelled: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditCancelledResult' + - type: "null" + connectorActionId: + description: The connectorActionId field. type: string - maxLen: - description: |- - MaxLen specifies that this field must be the specified number of bytes - at a maximum - format: uint64 - readOnly: false + connectorId: + description: The connectorId field. type: string - minLen: - description: |- - MinLen specifies that this field must be the specified number of bytes - at a minimum - format: uint64 - readOnly: false + error: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditErrorResult' + - type: "null" + pending: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditPendingResult' + - type: "null" + success: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.TaskAuditSuccessResult' + - type: "null" + title: Task Audit Connector Action Result + type: object + x-speakeasy-name-override: TaskAuditConnectorActionResult + c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask: + description: |- + TaskAuditCreatedReplacementExtensionGrantTask is used when a replacement extension grant task is created + (e.g. when an extension grant task is cancelled due to app user deletion). + properties: + newTaskId: + description: The ID of the newly created replacement task type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: base64 - type: string - nullable: true - readOnly: false - type: array - pattern: - description: |- - Pattern specifes that this field must match against the specified - regular expression (RE2 syntax). The included expression should elide - any delimiters. - readOnly: false + newTaskNumericId: + description: The numeric ID of the newly created replacement task (for display) + format: int64 type: string - prefix: - description: |- - Prefix specifies that this field must have the specified bytes at the - beginning of the string. - format: base64 - readOnly: false + title: Task Audit Created Replacement Extension Grant Task + type: object + x-speakeasy-name-override: TaskAuditCreatedReplacementExtensionGrantTask + c1.api.task.v1.TaskAuditEscalateToEmergencyAccess: + description: The TaskAuditEscalateToEmergencyAccess message. + properties: + oldPolicyId: + description: The oldPolicyId field. type: string - suffix: - description: |- - Suffix specifies that this field must have the specified bytes at the - end of the string. - format: base64 - readOnly: false + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - title: Bytes Rules + title: Task Audit Escalate To Emergency Access type: object - x-speakeasy-name-override: BytesRules - validate.DoubleRules: - description: DoubleRules describes the constraints applied to `double` values - nullable: true + x-speakeasy-name-override: TaskAuditEscalateToEmergencyAccess + c1.api.task.v1.TaskAuditExpressionPolicyStepError: + description: The TaskAuditExpressionPolicyStepError message. properties: - const: - description: Const specifies that this field must be exactly the specified value - readOnly: false - type: number - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - readOnly: false - type: number - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - readOnly: false - type: number - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - type: number - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - readOnly: false - type: number - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - readOnly: false - type: number - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - type: number - nullable: true - readOnly: false - type: array - title: Double Rules + error: + description: The error field. + type: string + title: Task Audit Expression Policy Step Error type: object - x-speakeasy-name-override: DoubleRules - validate.DurationRules: - description: |- - DurationRules describe the constraints applied exclusively to the - `google.protobuf.Duration` well-known type - nullable: true + x-speakeasy-name-override: TaskAuditExpressionPolicyStepError + c1.api.task.v1.TaskAuditExternalTicketCreated: + description: The TaskAuditExternalTicketCreated message. properties: - const: - format: duration - readOnly: false + appId: + description: The appId field. type: string - gt: - format: duration - readOnly: false + connectorId: + description: The connectorId field. type: string - gte: - format: duration - readOnly: false + externalTicketId: + description: The externalTicketId field. type: string - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: duration - readOnly: false - type: string - nullable: true - readOnly: false - type: array - lt: - format: duration - readOnly: false + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. type: string - lte: - format: duration - readOnly: false + externalTicketProvisionerConfigName: + description: The externalTicketProvisionerConfigName field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: duration - readOnly: false - type: string - nullable: true - readOnly: false - type: array - required: - description: Required specifies that this field must be set - readOnly: false - type: boolean - title: Duration Rules + externalTicketUrl: + description: The externalTicketUrl field. + type: string + title: Task Audit External Ticket Created type: object - x-speakeasy-name-override: DurationRules - validate.EnumRules: - description: EnumRules describe the constraints applied to enum values - nullable: true + x-speakeasy-name-override: TaskAuditExternalTicketCreated + c1.api.task.v1.TaskAuditExternalTicketError: + description: The TaskAuditExternalTicketError message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - readOnly: false - type: integer - definedOnly: - description: |- - DefinedOnly specifies that this field must be only one of the defined - values for this enum, failing on any undefined value. - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - title: Enum Rules + errorMessage: + description: The errorMessage field. + type: string + title: Task Audit External Ticket Error type: object - x-speakeasy-name-override: EnumRules - validate.FieldRules: - description: | - FieldRules encapsulates the rules for each type of field. Depending on the - field, the correct set should be used to ensure proper validations. - - This message contains a oneof named type. Only a single field of the following list may be set at a time: - - float - - double - - int32 - - int64 - - uint32 - - uint64 - - sint32 - - sint64 - - fixed32 - - fixed64 - - sfixed32 - - sfixed64 - - bool - - string - - bytes - - enum - - repeated - - map - - any - - duration - - timestamp + x-speakeasy-name-override: TaskAuditExternalTicketError + c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved: + description: The TaskAuditExternalTicketProvisionStepResolved message. properties: - any: - $ref: '#/components/schemas/validate.AnyRules' - bool: - $ref: '#/components/schemas/validate.BoolRules' - bytes: - $ref: '#/components/schemas/validate.BytesRules' - double: - $ref: '#/components/schemas/validate.DoubleRules' - duration: - $ref: '#/components/schemas/validate.DurationRules' - enum: - $ref: '#/components/schemas/validate.EnumRules' - fixed32: - $ref: '#/components/schemas/validate.Fixed32Rules' - fixed64: - $ref: '#/components/schemas/validate.Fixed64Rules' - float: - $ref: '#/components/schemas/validate.FloatRules' - int32: - $ref: '#/components/schemas/validate.Int32Rules' - int64: - $ref: '#/components/schemas/validate.Int64Rules' - map: - $ref: '#/components/schemas/validate.MapRules' - message: - $ref: '#/components/schemas/validate.MessageRules' - repeated: - $ref: '#/components/schemas/validate.RepeatedRules' - sfixed32: - $ref: '#/components/schemas/validate.SFixed32Rules' - sfixed64: - $ref: '#/components/schemas/validate.SFixed64Rules' - sint32: - $ref: '#/components/schemas/validate.SInt32Rules' - sint64: - $ref: '#/components/schemas/validate.SInt64Rules' - string: - $ref: '#/components/schemas/validate.StringRules' - timestamp: - $ref: '#/components/schemas/validate.TimestampRules' - uint32: - $ref: '#/components/schemas/validate.UInt32Rules' - uint64: - $ref: '#/components/schemas/validate.UInt64Rules' - title: Field Rules - type: object - x-speakeasy-name-override: FieldRules - validate.Fixed32Rules: - description: Fixed32Rules describes the constraints applied to `fixed32` values - nullable: true - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint32 - readOnly: false - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint32 - readOnly: false - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint32 - readOnly: false - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint32 - type: integer - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint32 - readOnly: false - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint32 - readOnly: false - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint32 - type: integer - nullable: true - readOnly: false - type: array - title: Fixed 32 Rules + appId: + description: The appId field. + type: string + connectorId: + description: The connectorId field. + type: string + externalTicketId: + description: The externalTicketId field. + type: string + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. + type: string + externalTicketUrl: + description: The externalTicketUrl field. + type: string + title: Task Audit External Ticket Provision Step Resolved type: object - x-speakeasy-name-override: Fixed32Rules - validate.Fixed64Rules: - description: Fixed64Rules describes the constraints applied to `fixed64` values - nullable: true + x-speakeasy-name-override: TaskAuditExternalTicketProvisionStepResolved + c1.api.task.v1.TaskAuditExternalTicketTriggered: + description: The TaskAuditExternalTicketTriggered message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint64 - readOnly: false + appId: + description: The appId field. type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint64 - readOnly: false + connectorId: + description: The connectorId field. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint64 - readOnly: false + externalTicketId: + description: The externalTicketId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint64 - type: string - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint64 - readOnly: false + externalTicketProvisionerConfigId: + description: The externalTicketProvisionerConfigId field. type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint64 - readOnly: false + externalTicketProvisionerConfigName: + description: The externalTicketProvisionerConfigName field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint64 - type: string - nullable: true - readOnly: false - type: array - title: Fixed 64 Rules + title: Task Audit External Ticket Triggered type: object - x-speakeasy-name-override: Fixed64Rules - validate.FloatRules: - description: FloatRules describes the constraints applied to `float` values - nullable: true + x-speakeasy-name-override: TaskAuditExternalTicketTriggered + c1.api.task.v1.TaskAuditFinishedConnectorActions: + description: The TaskAuditFinishedConnectorActions message. properties: - const: - description: Const specifies that this field must be exactly the specified value - readOnly: false - type: number - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - readOnly: false - type: number - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - readOnly: false - type: number - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false + policyStepId: + description: The policyStepId field. + type: string + title: Task Audit Finished Connector Actions + type: object + x-speakeasy-name-override: TaskAuditFinishedConnectorActions + c1.api.task.v1.TaskAuditFormInstanceChange: + description: The TaskAuditFormInstanceChange message. + properties: + isValid: + description: The isValid field. type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - type: number - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - readOnly: false - type: number - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - readOnly: false - type: number - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - type: number - nullable: true - readOnly: false - type: array - title: Float Rules + title: Task Audit Form Instance Change type: object - x-speakeasy-name-override: FloatRules - validate.Int32Rules: - description: Int32Rules describes the constraints applied to `int32` values - nullable: true + x-speakeasy-name-override: TaskAuditFormInstanceChange + c1.api.task.v1.TaskAuditGrantDurationUpdated: + description: The TaskAuditGrantDurationUpdated message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - readOnly: false - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - readOnly: false - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - readOnly: false - type: integer - ignoreEmpty: + duration: + format: duration + type: + - string + - "null" + title: Task Audit Grant Duration Updated + type: object + x-speakeasy-name-override: TaskAuditGrantDurationUpdated + c1.api.task.v1.TaskAuditGrantOutcome: + description: The TaskAuditGrantOutcome message. + properties: + outcome: + description: The outcome field. + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + title: Task Audit Grant Outcome + type: object + x-speakeasy-name-override: TaskAuditGrantOutcome + c1.api.task.v1.TaskAuditHardReset: + description: The TaskAuditHardReset message. + properties: + oldPolicyStepId: + description: The oldPolicyStepId field. + type: string + title: Task Audit Hard Reset + type: object + x-speakeasy-name-override: TaskAuditHardReset + c1.api.task.v1.TaskAuditListRequest: + description: The TaskAuditListRequest message. + properties: + commentsOnly: description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false + When true, only comment events are returned, so a page of page_size holds + page_size comments rather than a mix of comments and state-change events. type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - readOnly: false - type: integer - lte: + newestFirst: description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive + When true, events are returned newest-first (descending created_at) instead + of the default chronological (ascending) order. + type: boolean + pageSize: + description: The maximum number of audit events to return per page. format: int32 - readOnly: false type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + pageToken: + description: A pagination token from a previous response to retrieve the next page. + type: string + refs: + description: References to specific audit events to retrieve. If provided, only these events are returned. items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - title: Int 32 Rules + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditViewRef' + type: + - array + - "null" + taskId: + description: The ID of the task to list audit events for. + type: string + title: Task Audit List Request type: object - x-speakeasy-name-override: Int32Rules - validate.Int64Rules: - description: Int64Rules describes the constraints applied to `int64` values - nullable: true + x-speakeasy-name-override: TaskAuditListRequest + c1.api.task.v1.TaskAuditListResponse: + description: The TaskAuditListResponse message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 - readOnly: false + list: + description: The list of audit events for the task. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditView' + type: + - array + - "null" + nextPageToken: + description: A pagination token to retrieve the next page of results. type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 - readOnly: false + title: Task Audit List Response + type: object + x-speakeasy-name-override: TaskAuditListResponse + c1.api.task.v1.TaskAuditMetaData: + description: The TaskAuditMetaData message. + properties: + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + title: Task Audit Meta Data + type: object + x-speakeasy-name-override: TaskAuditMetaData + c1.api.task.v1.TaskAuditNewTask: + description: The TaskAuditNewTask message. + title: Task Audit New Task + type: object + x-speakeasy-name-override: TaskAuditNewTask + c1.api.task.v1.TaskAuditNewTaskCreatedFrom: + description: |- + TaskAuditNewTaskCreatedFrom is used when a task is created from another task + (e.g. when a replacement extension grant task is created after the original is cancelled). + This is set on the NEW task to indicate its origin. + properties: + originalTaskId: + description: The originalTaskId field. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. + originalTaskNumericId: + description: The originalTaskNumericId field. format: int64 - readOnly: false type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int64 - type: string - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - readOnly: false + originalTaskType: + description: The task type of the original task (e.g. "grant", "revoke", "certify"). type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 - readOnly: false + title: Task Audit New Task Created From + type: object + x-speakeasy-name-override: TaskAuditNewTaskCreatedFrom + c1.api.task.v1.TaskAuditPolicyApprovalReassigned: + description: The TaskAuditPolicyApprovalReassigned message. + properties: + newPolicyStepId: + description: The newPolicyStepId field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + newUsers: + description: The newUsers field. items: - format: int64 type: string - nullable: true - readOnly: false - type: array - title: Int 64 Rules + type: + - array + - "null" + oldPolicyStepId: + description: The oldPolicyStepId field. + type: string + users: + description: The users field. + items: + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" + title: Task Audit Policy Approval Reassigned type: object - x-speakeasy-name-override: Int64Rules - validate.MapRules: - description: MapRules describe the constraints applied to `map` values - nullable: true + x-speakeasy-name-override: TaskAuditPolicyApprovalReassigned + c1.api.task.v1.TaskAuditPolicyChanged: + description: The TaskAuditPolicyChanged message. properties: - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - keys: - $ref: '#/components/schemas/validate.FieldRules' - maxPairs: - description: |- - MaxPairs specifies that this field must have the specified number of - KVs at a maximum - format: uint64 - readOnly: false + newPolicyId: + description: The newPolicyId field. type: string - minPairs: - description: |- - MinPairs specifies that this field must have the specified number of - KVs at a minimum - format: uint64 - readOnly: false + oldPolicyId: + description: The oldPolicyId field. type: string - noSparse: - description: |- - NoSparse specifies values in this field cannot be unset. This only - applies to map's with message value types. - readOnly: false - type: boolean - values: - $ref: '#/components/schemas/validate.FieldRules' - title: Map Rules + title: Task Audit Policy Changed type: object - x-speakeasy-name-override: MapRules - validate.MessageRules: - description: |- - MessageRules describe the constraints applied to embedded message values. - For message-type fields, validation is performed recursively. + x-speakeasy-name-override: TaskAuditPolicyChanged + c1.api.task.v1.TaskAuditPolicyEvaluationStep: + description: The TaskAuditPolicyEvaluationStep message. properties: - required: - description: Required specifies that this field must be set - readOnly: false - type: boolean - skip: - description: |- - Skip specifies that the validation rules of this field should not be - evaluated - readOnly: false - type: boolean - title: Message Rules + stepComment: + description: The stepComment field. + type: string + title: Task Audit Policy Evaluation Step type: object - x-speakeasy-name-override: MessageRules - validate.RepeatedRules: - description: RepeatedRules describe the constraints applied to `repeated` values - nullable: true + x-speakeasy-name-override: TaskAuditPolicyEvaluationStep + c1.api.task.v1.TaskAuditPolicyProvisionCancelled: + description: The TaskAuditPolicyProvisionCancelled message. properties: - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - items: - $ref: '#/components/schemas/validate.FieldRules' - maxItems: - description: |- - MaxItems specifies that this field must have the specified number of - items at a maximum - format: uint64 - readOnly: false + cancelReason: + description: The cancelReason field. type: string - minItems: - description: |- - MinItems specifies that this field must have the specified number of - items at a minimum - format: uint64 - readOnly: false + title: Task Audit Policy Provision Cancelled + type: object + x-speakeasy-name-override: TaskAuditPolicyProvisionCancelled + c1.api.task.v1.TaskAuditPolicyProvisionError: + description: The TaskAuditPolicyProvisionError message. + properties: + error: + description: The error field. type: string - unique: - description: |- - Unique specifies that all elements in this field must be unique. This - contraint is only applicable to scalar and enum types (messages are not - supported). - readOnly: false - type: boolean - title: Repeated Rules + title: Task Audit Policy Provision Error type: object - x-speakeasy-name-override: RepeatedRules - validate.SFixed32Rules: - description: SFixed32Rules describes the constraints applied to `sfixed32` values - nullable: true + x-speakeasy-name-override: TaskAuditPolicyProvisionError + c1.api.task.v1.TaskAuditPolicyProvisionReassigned: + description: The TaskAuditPolicyProvisionReassigned message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - readOnly: false - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - readOnly: false - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - readOnly: false - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - readOnly: false - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int32 - readOnly: false - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - title: S Fixed 32 Rules - type: object - x-speakeasy-name-override: SFixed32Rules - validate.SFixed64Rules: - description: SFixed64Rules describes the constraints applied to `sfixed64` values - nullable: true - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 - readOnly: false - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 - readOnly: false - type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int64 - readOnly: false + newPolicyStepId: + description: The newPolicyStepId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + newUsers: + description: The newUsers field. items: - format: int64 type: string - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - readOnly: false - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 - readOnly: false + type: + - array + - "null" + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: int64 - type: string - nullable: true - readOnly: false - type: array - title: S Fixed 64 Rules - type: object - x-speakeasy-name-override: SFixed64Rules - validate.SInt32Rules: - description: SInt32Rules describes the constraints applied to `sint32` values - nullable: true - properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int32 - readOnly: false - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int32 - readOnly: false - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int32 - readOnly: false - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int32 - readOnly: false - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int32 - readOnly: false - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + users: + description: The users field. items: - format: int32 - type: integer - nullable: true - readOnly: false - type: array - title: S Int 32 Rules + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" + title: Task Audit Policy Provision Reassigned type: object - x-speakeasy-name-override: SInt32Rules - validate.SInt64Rules: - description: SInt64Rules describes the constraints applied to `sint64` values - nullable: true + x-speakeasy-name-override: TaskAuditPolicyProvisionReassigned + c1.api.task.v1.TaskAuditReassignedToDelegate: + description: The TaskAuditReassignedToDelegate message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: int64 - readOnly: false - type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: int64 - readOnly: false + delegatedAssigneeUser: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + delegatedAssigneeUserId: + description: The delegatedAssigneeUserId field. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: int64 - readOnly: false + originalAssigneeUser: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + originalAssigneeUserId: + description: The originalAssigneeUserId field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values + title: Task Audit Reassigned To Delegate + type: object + x-speakeasy-name-override: TaskAuditReassignedToDelegate + c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin: + description: |- + TaskAuditReassignmentFallbackToAdmin is used when no eligible reviewers are found + from the policy configuration and the task falls back to system administrators + without creating a new policy step. This prevents reassignment loops. + properties: + adminUserIds: + description: The IDs of the system administrator users that the task is being assigned to items: - format: int64 type: string - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: int64 - readOnly: false - type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: int64 - readOnly: false - type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + type: + - array + - "null" + adminUsers: + description: The system administrator users (populated for display) items: - format: int64 - type: string - nullable: true - readOnly: false - type: array - title: S Int 64 Rules + $ref: '#/components/schemas/c1.api.user.v1.User' + type: + - array + - "null" + title: Task Audit Reassignment Fallback To Admin type: object - x-speakeasy-name-override: SInt64Rules - validate.StringRules: - description: | - StringRules describe the constraints applied to `string` values - - This message contains a oneof named well_known. Only a single field of the following list may be set at a time: - - email - - hostname - - ip - - ipv4 - - ipv6 - - uri - - uriRef - - address - - uuid - - wellKnownRegex - nullable: true + x-speakeasy-name-override: TaskAuditReassignmentFallbackToAdmin + c1.api.task.v1.TaskAuditReassignmentListError: + description: The TaskAuditReassignmentListError message. properties: - address: - description: |- - Address specifies that the field must be either a valid hostname as - defined by RFC 1034 (which does not support internationalized domain - names or IDNs), or it can be a valid IP (v4 or v6). - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - const: - description: Const specifies that this field must be exactly the specified value - readOnly: false - type: string - contains: - description: |- - Contains specifies that this field must have the specified substring - anywhere in the string. - readOnly: false - type: string - email: - description: |- - Email specifies that the field must be a valid email address as - defined by RFC 5322 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - hostname: - description: |- - Hostname specifies that the field must be a valid hostname as - defined by RFC 1034. This constraint does not support - internationalized domain names (IDNs). - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - type: string - nullable: true - readOnly: false - type: array - ip: - description: |- - Ip specifies that the field must be a valid IP (v4 or v6) address. - Valid IPv6 addresses should not include surrounding square brackets. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - ipv4: - description: |- - Ipv4 specifies that the field must be a valid IPv4 address. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - ipv6: - description: |- - Ipv6 specifies that the field must be a valid IPv6 address. Valid - IPv6 addresses should not include surrounding square brackets. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - len: - description: |- - Len specifies that this field must be the specified number of - characters (Unicode code points). Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 - readOnly: false - type: string - lenBytes: - description: |- - LenBytes specifies that this field must be the specified number of bytes - at a minimum - format: uint64 - readOnly: false - type: string - maxBytes: - description: |- - MaxBytes specifies that this field must be the specified number of bytes - at a maximum - format: uint64 - readOnly: false + errorMessage: + description: The errorMessage field. type: string - maxLen: - description: |- - MaxLen specifies that this field must be the specified number of - characters (Unicode code points) at a maximum. Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 - readOnly: false + title: Task Audit Reassignment List Error + type: object + x-speakeasy-name-override: TaskAuditReassignmentListError + c1.api.task.v1.TaskAuditRequestDefaultsApplied: + description: |- + TaskAuditRequestDefaultsApplied records which tier of the request-settings + precedence chain supplied the defaults for a grant request. The rule ID, not + its name, is stored; consumers resolve the current display name via + (app_id, routing_rule_id). + properties: + appId: + description: The appId field. type: string - minBytes: - description: |- - MinBytes specifies that this field must be the specified number of bytes - at a minimum - format: uint64 - readOnly: false + routingRuleId: + description: The routingRuleId field. type: string - minLen: - description: |- - MinLen specifies that this field must be the specified number of - characters (Unicode code points) at a minimum. Note that the number of - characters may differ from the number of bytes in the string. - format: uint64 - readOnly: false + source: + description: The source field. + enum: + - APPLIED_SETTINGS_SOURCE_UNSPECIFIED + - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_OVERRIDE + - APPLIED_SETTINGS_SOURCE_ROUTING_RULE + - APPLIED_SETTINGS_SOURCE_ENTITLEMENT_DEFAULT + - APPLIED_SETTINGS_SOURCE_APP_DEFAULT + - APPLIED_SETTINGS_SOURCE_ACCESS_PROFILE_DEFAULT type: string - notContains: - description: |- - NotContains specifies that this field cannot have the specified substring - anywhere in the string. - readOnly: false + x-speakeasy-unknown-values: allow + title: Task Audit Request Defaults Applied + type: object + x-speakeasy-name-override: TaskAuditRequestDefaultsApplied + c1.api.task.v1.TaskAuditRestart: + description: The TaskAuditRestart message. + properties: + oldPolicyStepId: + description: The oldPolicyStepId field. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - type: string - nullable: true - readOnly: false - type: array - pattern: - description: |- - Pattern specifes that this field must match against the specified - regular expression (RE2 syntax). The included expression should elide - any delimiters. - readOnly: false + title: Task Audit Restart + type: object + x-speakeasy-name-override: TaskAuditRestart + c1.api.task.v1.TaskAuditRevokeOutcome: + description: The TaskAuditRevokeOutcome message. + properties: + outcome: + description: The outcome field. + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT type: string - prefix: - description: |- - Prefix specifies that this field must have the specified substring at - the beginning of the string. - readOnly: false + x-speakeasy-unknown-values: allow + title: Task Audit Revoke Outcome + type: object + x-speakeasy-name-override: TaskAuditRevokeOutcome + c1.api.task.v1.TaskAuditSLAEscalation: + description: The TaskAuditSLAEscalation message. + properties: + message: + description: The message field. type: string - strict: - description: |- - This applies to regexes HTTP_HEADER_NAME and HTTP_HEADER_VALUE to enable - strict header validation. - By default, this is true, and HTTP header validations are RFC-compliant. - Setting to false will enable a looser validations that only disallows - \r\n\0 characters, which can be used to bypass header matching rules. - readOnly: false - type: boolean - suffix: - description: |- - Suffix specifies that this field must have the specified substring at - the end of the string. - readOnly: false + title: Task Audit Sla Escalation + type: object + x-speakeasy-name-override: TaskAuditSLAEscalation + c1.api.task.v1.TaskAuditStartedConnectorActions: + description: The TaskAuditStartedConnectorActions message. + properties: + policyStepId: + description: The policyStepId field. type: string - uri: - description: |- - Uri specifies that the field must be a valid, absolute URI as defined - by RFC 3986 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - uriRef: - description: |- - UriRef specifies that the field must be a valid URI as defined by RFC - 3986 and may be relative or absolute. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - uuid: - description: |- - Uuid specifies that the field must be a valid UUID as defined by - RFC 4122 - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. - nullable: true - readOnly: false - type: boolean - wellKnownRegex: - description: |- - WellKnownRegex specifies a common well known pattern defined as a regex. - This field is part of the `well_known` oneof. - See the documentation for `validate.StringRules` for more details. + title: Task Audit Started Connector Actions + type: object + x-speakeasy-name-override: TaskAuditStartedConnectorActions + c1.api.task.v1.TaskAuditStateChange: + description: The TaskAuditStateChange message. + properties: + previousState: + description: The previousState field. enum: - - UNKNOWN - - HTTP_HEADER_NAME - - HTTP_HEADER_VALUE - nullable: true - readOnly: false + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED type: string x-speakeasy-unknown-values: allow - title: String Rules + title: Task Audit State Change type: object - x-speakeasy-name-override: StringRules - validate.TimestampRules: - description: |- - TimestampRules describe the constraints applied exclusively to the - `google.protobuf.Timestamp` well-known type - nullable: true + x-speakeasy-name-override: TaskAuditStateChange + c1.api.task.v1.TaskAuditStepSkipped: + description: The TaskAuditStepSkipped message. properties: - const: - format: date-time - readOnly: false - type: string - gt: - format: date-time - readOnly: false - type: string - gtNow: - description: |- - GtNow specifies that this must be greater than the current time. GtNow - can only be used with the Within rule. - readOnly: false - type: boolean - gte: - format: date-time - readOnly: false + skippedBy: + description: The skippedBy field. type: string - lt: - format: date-time - readOnly: false + title: Task Audit Step Skipped + type: object + x-speakeasy-name-override: TaskAuditStepSkipped + c1.api.task.v1.TaskAuditStepUpApproval: + description: The TaskAuditStepUpApproval message. + properties: + stepUpTransactionId: + description: The stepUpTransactionId field. type: string - ltNow: - description: |- - LtNow specifies that this must be less than the current time. LtNow - can only be used with the Within rule. - readOnly: false - type: boolean - lte: + title: Task Audit Step Up Approval + type: object + x-speakeasy-name-override: TaskAuditStepUpApproval + c1.api.task.v1.TaskAuditView: + description: | + The TaskAuditView message. + + This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - comment + - stateChange + - approvalInstanceChange + - connectorActionsStart + - connectorActionsEnd + - actionResult + - taskCreated + - certifyOutcome + - actionSubmitted + - grantOutcome + - revokeOutcome + - approvalReassigned + - taskRestarted + - accessRequestOutcome + - provisionReassigned + - provisionError + - approvedAutomatically + - reassignedToDelegate + - hardReset + - taskEscalated + - conditionalPolicyExecutionResult + - expressionPolicyStepError + - approvalAutoAcceptedByPolicy + - approvalAutoRejectedByPolicy + - bulkActionError + - webhookTriggered + - webhookAttempt + - webhookSuccess + - policyEvaluationStep + - waitStepSuccess + - waitStepWaiting + - waitStepTimedOut + - webhookApprovalTriggered + - webhookApprovalAttempt + - webhookApprovalSuccess + - webhookApprovalBadResponse + - externalTicketTriggered + - externalTicketCreated + - externalTicketError + - waitStepAnalysisSuccess + - waitStepAnalysisWaiting + - waitStepAnalysisTimedOut + - stepUpApproval + - externalTicketProvisionStepResolved + - stepSkipped + - reassignmentListError + - slaEscalation + - policyChanged + - formInstanceChange + - grantDurationUpdated + - waitStepUntilTime + - webhookApprovalFatalError + - accountLifecycleActionCreated + - accountLifecycleActionFailed + - provisionCancelled + - actionInstanceCreated + - actionInstanceSucceeded + - actionInstanceFailed + - createdReplacementExtensionGrantTask + - taskCreatedFrom + - reassignmentFallbackToAdmin + - requestDefaultsApplied + properties: + accessRequestOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccessRequestOutcome' + - type: "null" + accountLifecycleActionCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionCreated' + - type: "null" + accountLifecycleActionFailed: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditAccountLifecycleActionFailed' + - type: "null" + actionInstanceCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceCreated' + - type: "null" + actionInstanceFailed: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceFailed' + - type: "null" + actionInstanceSucceeded: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionInstanceSucceeded' + - type: "null" + actionResult: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConnectorActionResult' + - type: "null" + actionSubmitted: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditActionSubmitted' + - type: "null" + approvalAutoAcceptedByPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoAcceptedByPolicy' + - type: "null" + approvalAutoRejectedByPolicy: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalAutoRejectedByPolicy' + - type: "null" + approvalInstanceChange: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalInstanceChange' + - type: "null" + approvalReassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyApprovalReassigned' + - type: "null" + approvedAutomatically: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditApprovalHappenedAutomatically' + - type: "null" + bulkActionError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditBulkActionError' + - type: "null" + certifyOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCertifyOutcome' + - type: "null" + comment: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditComment' + - type: "null" + conditionalPolicyExecutionResult: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditConditionalPolicyExecutionResult' + - type: "null" + connectorActionsEnd: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFinishedConnectorActions' + - type: "null" + connectorActionsStart: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStartedConnectorActions' + - type: "null" + created: format: date-time - readOnly: false + type: + - string + - "null" + createdReplacementExtensionGrantTask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditCreatedReplacementExtensionGrantTask' + - type: "null" + currentState: + description: The currentState field. + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED type: string - required: - description: Required specifies that this field must be set - readOnly: false - type: boolean - within: - format: duration - readOnly: false + x-speakeasy-unknown-values: allow + eventType: + description: The eventType field. + enum: + - TASK_AUDIT_EVENT_TYPE_UNSPECIFIED + - TASK_AUDIT_EVENT_TYPE_NEUTRAL + - TASK_AUDIT_EVENT_TYPE_ERROR type: string - title: Timestamp Rules + x-speakeasy-unknown-values: allow + expressionPolicyStepError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExpressionPolicyStepError' + - type: "null" + externalTicketCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketCreated' + - type: "null" + externalTicketError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketError' + - type: "null" + externalTicketProvisionStepResolved: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketProvisionStepResolved' + - type: "null" + externalTicketTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditExternalTicketTriggered' + - type: "null" + formInstanceChange: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditFormInstanceChange' + - type: "null" + grantDurationUpdated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantDurationUpdated' + - type: "null" + grantOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditGrantOutcome' + - type: "null" + hardReset: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditHardReset' + - type: "null" + id: + description: The id field. + type: string + metadata: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditMetaData' + - type: "null" + policyChanged: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyChanged' + - type: "null" + policyEvaluationStep: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyEvaluationStep' + - type: "null" + provisionCancelled: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionCancelled' + - type: "null" + provisionError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionError' + - type: "null" + provisionReassigned: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditPolicyProvisionReassigned' + - type: "null" + reassignedToDelegate: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignedToDelegate' + - type: "null" + reassignmentFallbackToAdmin: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentFallbackToAdmin' + - type: "null" + reassignmentListError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditReassignmentListError' + - type: "null" + requestDefaultsApplied: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRequestDefaultsApplied' + - type: "null" + revokeOutcome: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRevokeOutcome' + - type: "null" + slaEscalation: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditSLAEscalation' + - type: "null" + source: + description: The source field. + enum: + - SOURCE_UNSPECIFIED + - SOURCE_C1 + - SOURCE_JIRA + - SOURCE_SLACK + - SOURCE_COPILOT_AGENTS + type: string + x-speakeasy-unknown-values: allow + stateChange: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStateChange' + - type: "null" + stepSkipped: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepSkipped' + - type: "null" + stepUpApproval: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditStepUpApproval' + - type: "null" + taskCreated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTask' + - type: "null" + taskCreatedFrom: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditNewTaskCreatedFrom' + - type: "null" + taskEscalated: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditEscalateToEmergencyAccess' + - type: "null" + taskRestarted: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditRestart' + - type: "null" + ticketId: + description: The ticketId field. + type: string + userId: + description: The userId field. + type: string + waitStepAnalysisSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess' + - type: "null" + waitStepAnalysisTimedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut' + - type: "null" + waitStepAnalysisWaiting: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting' + - type: "null" + waitStepSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepSuccess' + - type: "null" + waitStepTimedOut: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepTimedOut' + - type: "null" + waitStepUntilTime: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepUntilTime' + - type: "null" + waitStepWaiting: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWaitStepWaiting' + - type: "null" + webhookApprovalAttempt: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalAttempt' + - type: "null" + webhookApprovalBadResponse: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalBadResponse' + - type: "null" + webhookApprovalFatalError: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalFatalError' + - type: "null" + webhookApprovalSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalSuccess' + - type: "null" + webhookApprovalTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookApprovalTriggered' + - type: "null" + webhookAttempt: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookAttempt' + - type: "null" + webhookSuccess: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookSuccess' + - type: "null" + webhookTriggered: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditWebhookTriggered' + - type: "null" + workflowStep: + description: The workflowStep field. + format: int32 + type: integer + title: Task Audit View type: object - x-speakeasy-name-override: TimestampRules - validate.UInt32Rules: - description: UInt32Rules describes the constraints applied to `uint32` values - nullable: true + x-speakeasy-name-override: TaskAuditView + c1.api.task.v1.TaskAuditViewRef: + description: The TaskAuditViewRef message. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint32 - readOnly: false - type: integer - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint32 - readOnly: false - type: integer - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint32 - readOnly: false - type: integer - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint32 - type: integer - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint32 - readOnly: false - type: integer - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint32 - readOnly: false - type: integer - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values + id: + description: The ID of the audit event. + type: string + title: Task Audit View Ref + type: object + x-speakeasy-name-override: TaskAuditViewRef + c1.api.task.v1.TaskAuditWaitForAnalysisStepSuccess: + description: The TaskAuditWaitForAnalysisStepSuccess message. + properties: + stepId: + description: The stepId field. + type: string + succeededAt: + format: date-time + type: + - string + - "null" + title: Task Audit Wait For Analysis Step Success + type: object + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepSuccess + c1.api.task.v1.TaskAuditWaitForAnalysisStepTimedOut: + description: The TaskAuditWaitForAnalysisStepTimedOut message. + properties: + stepId: + description: The stepId field. + type: string + timedOutAt: + format: date-time + type: + - string + - "null" + title: Task Audit Wait For Analysis Step Timed Out + type: object + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepTimedOut + c1.api.task.v1.TaskAuditWaitForAnalysisStepWaiting: + description: The TaskAuditWaitForAnalysisStepWaiting message. + properties: + stepId: + description: The stepId field. + type: string + title: Task Audit Wait For Analysis Step Waiting + type: object + x-speakeasy-name-override: TaskAuditWaitForAnalysisStepWaiting + c1.api.task.v1.TaskAuditWaitStepSuccess: + description: The TaskAuditWaitStepSuccess message. + properties: + condition: + description: The condition field. + type: string + stepId: + description: The stepId field. + type: string + succeededAt: + format: date-time + type: + - string + - "null" + title: Task Audit Wait Step Success + type: object + x-speakeasy-name-override: TaskAuditWaitStepSuccess + c1.api.task.v1.TaskAuditWaitStepTimedOut: + description: The TaskAuditWaitStepTimedOut message. + properties: + condition: + description: The condition field. + type: string + stepId: + description: The stepId field. + type: string + timedOutAt: + format: date-time + type: + - string + - "null" + title: Task Audit Wait Step Timed Out + type: object + x-speakeasy-name-override: TaskAuditWaitStepTimedOut + c1.api.task.v1.TaskAuditWaitStepUntilTime: + description: The TaskAuditWaitStepUntilTime message. + properties: + stepId: + description: The stepId field. + type: string + untilTime: + format: date-time + type: + - string + - "null" + title: Task Audit Wait Step Until Time + type: object + x-speakeasy-name-override: TaskAuditWaitStepUntilTime + c1.api.task.v1.TaskAuditWaitStepWaiting: + description: The TaskAuditWaitStepWaiting message. + properties: + condition: + description: The condition field. + type: string + stepId: + description: The stepId field. + type: string + title: Task Audit Wait Step Waiting + type: object + x-speakeasy-name-override: TaskAuditWaitStepWaiting + c1.api.task.v1.TaskAuditWebhookApprovalAttempt: + description: The TaskAuditWebhookApprovalAttempt message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Attempt + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalAttempt + c1.api.task.v1.TaskAuditWebhookApprovalBadResponse: + description: The TaskAuditWebhookApprovalBadResponse message. + properties: + error: + description: The error field. + type: string + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Bad Response + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalBadResponse + c1.api.task.v1.TaskAuditWebhookApprovalFatalError: + description: The TaskAuditWebhookApprovalFatalError message. + properties: + error: + description: The error field. + type: string + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Fatal Error + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalFatalError + c1.api.task.v1.TaskAuditWebhookApprovalSuccess: + description: The TaskAuditWebhookApprovalSuccess message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Success + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalSuccess + c1.api.task.v1.TaskAuditWebhookApprovalTriggered: + description: The TaskAuditWebhookApprovalTriggered message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Approval Triggered + type: object + x-speakeasy-name-override: TaskAuditWebhookApprovalTriggered + c1.api.task.v1.TaskAuditWebhookAttempt: + description: The TaskAuditWebhookAttempt message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Attempt + type: object + x-speakeasy-name-override: TaskAuditWebhookAttempt + c1.api.task.v1.TaskAuditWebhookSuccess: + description: The TaskAuditWebhookSuccess message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Success + type: object + x-speakeasy-name-override: TaskAuditWebhookSuccess + c1.api.task.v1.TaskAuditWebhookTriggered: + description: The TaskAuditWebhookTriggered message. + properties: + webhookId: + description: The webhookId field. + type: string + webhookInstanceId: + description: The webhookInstanceId field. + type: string + webhookName: + description: The webhookName field. + type: string + webhookUrl: + description: The webhookUrl field. + type: string + title: Task Audit Webhook Triggered + type: object + x-speakeasy-name-override: TaskAuditWebhookTriggered + c1.api.task.v1.TaskExpandMask: + description: The task expand mask is an array of strings that specifes the related objects the requester wishes to have returned when making a request where the expand mask is part of the input. Use '*' to view all possible responses. + properties: + paths: + description: A list of paths to expand in the response. May be any combination of "*", "access_review_id", "user_id", "created_by_user_id", "app_id", "app_user_id", "app_entitlement_ids", "step_approver_ids", "approver_ids", "identity_user_id", "insight_ids", "app_user_last_usage", "entitlement_scope_bindings", "scope_role_resources", and "resource". items: - format: uint32 - type: integer - nullable: true - readOnly: false - type: array - title: U Int 32 Rules + type: string + type: + - array + - "null" + title: Task Expand Mask type: object - x-speakeasy-name-override: UInt32Rules - validate.UInt64Rules: - description: UInt64Rules describes the constraints applied to `uint64` values - nullable: true + x-speakeasy-name-override: TaskExpandMask + c1.api.task.v1.TaskGrantSource: + description: The TaskGrantSource message tracks which external URL was the source of the specificed grant ticket. properties: - const: - description: Const specifies that this field must be exactly the specified value - format: uint64 - readOnly: false + conversationId: + description: The ID of the conversation that created this ticket type: string - gt: - description: |- - Gt specifies that this field must be greater than the specified value, - exclusive. If the value of Gt is larger than a specified Lt or Lte, the - range is reversed. - format: uint64 - readOnly: false + externalUrl: + description: The external url source of the grant ticket. type: string - gte: - description: |- - Gte specifies that this field must be greater than or equal to the - specified value, inclusive. If the value of Gte is larger than a - specified Lt or Lte, the range is reversed. - format: uint64 - readOnly: false + integrationId: + description: The integration id for the source of tickets. + type: string + isExtension: + description: Whether the grant task is an extension task. + type: boolean + requestId: + description: the request id for the grant ticket if the source is external + type: string + title: Task Grant Source + type: object + x-speakeasy-name-override: TaskGrantSource + c1.api.task.v1.TaskRef: + description: This object references a task by ID. + properties: + id: + description: The ID of the referenced Task + type: string + title: Task Ref + type: object + x-speakeasy-name-override: TaskRef + c1.api.task.v1.TaskRevocationTarget: + description: An ancestor entitlement that will be revoked as part of an inheritance revocation. + properties: + entitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Task Revocation Target + type: object + x-speakeasy-name-override: TaskRevocationTarget + c1.api.task.v1.TaskRevokeSource: + description: | + The TaskRevokeSource message indicates the source of the revoke task is one of expired, nonUsage, request, or review. + + This message contains a oneof named origin. Only a single field of the following list may be set at a time: + - review + - request + - expired + - nonUsage + properties: + expired: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceExpired' + - type: "null" + nonUsage: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceNonUsage' + - type: "null" + request: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceRequest' + - type: "null" + review: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSourceReview' + - type: "null" + title: Task Revoke Source + type: object + x-speakeasy-name-override: TaskRevokeSource + c1.api.task.v1.TaskRevokeSourceExpired: + description: The TaskRevokeSourceExpired message indicates that the source of the revoke task is due to a grant expiring. + properties: + expiredAt: + format: date-time + type: + - string + - "null" + title: Task Revoke Source Expired + type: object + x-speakeasy-name-override: TaskRevokeSourceExpired + c1.api.task.v1.TaskRevokeSourceNonUsage: + description: The TaskRevokeSourceNonUsage message indicates that the source of the revoke task is due to the grant not being used. + properties: + expiresAt: + format: date-time + type: + - string + - "null" + lastLogin: + format: date-time + type: + - string + - "null" + title: Task Revoke Source Non Usage + type: object + x-speakeasy-name-override: TaskRevokeSourceNonUsage + c1.api.task.v1.TaskRevokeSourceRequest: + description: The TaskRevokeSourceRequest message indicates that the source of the revoke task was a request. + properties: + requestUserId: + description: The ID of the user who initiated the revoke request. + type: string + title: Task Revoke Source Request + type: object + x-speakeasy-name-override: TaskRevokeSourceRequest + c1.api.task.v1.TaskRevokeSourceReview: + description: The TaskRevokeSourceReview message tracks which access review was the source of the specificed revoke ticket. + properties: + accessReviewId: + description: The ID of the access review associated with the revoke task. + type: string + certTicketId: + description: The ID of the certify ticket that was denied and created this revoke task. + type: string + title: Task Revoke Source Review + type: object + x-speakeasy-name-override: TaskRevokeSourceReview + c1.api.task.v1.TaskSearchRequest: + description: Search for tasks based on a plethora filters. + properties: + accessReviewIds: + description: Search tasks that belong to any of the access reviews included in this list. + items: + type: string + type: + - array + - "null" + accountOwnerIds: + description: Search tasks that have any of these account owners. + items: + type: string + type: + - array + - "null" + accountTypes: + description: The accountTypes field. + items: + enum: + - APP_USER_TYPE_UNSPECIFIED + - APP_USER_TYPE_USER + - APP_USER_TYPE_SERVICE_ACCOUNT + - APP_USER_TYPE_SYSTEM_ACCOUNT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + actorId: + description: Search tasks that have this actor ID. + type: string + appEntitlementIds: + description: Search tasks that have any of these app entitlement IDs. + items: + type: string + type: + - array + - "null" + appResourceIds: + description: Search tasks that have any of these app resource IDs. + items: + type: string + type: + - array + - "null" + appResourceTypeIds: + description: Search tasks that have any of these app resource type IDs. + items: + type: string + type: + - array + - "null" + appUserSubjectIds: + description: Search tasks that have any of these app users as subjects. + items: + type: string + type: + - array + - "null" + applicationIds: + description: Search tasks that have any of these apps as targets. + items: + type: string + type: + - array + - "null" + assignedOrStepApproverUserId: + description: Search tasks that are currently assigned to this user, or that are closed and were previously approved by this user. + type: string + assigneesInIds: + description: Search tasks by List of UserIDs which are currently assigned these Tasks + items: + type: string + type: + - array + - "null" + certifyOutcomes: + description: Search tasks by certify outcome + items: + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + createdAfter: + format: date-time + type: + - string + - "null" + createdBefore: + format: date-time + type: + - string + - "null" + currentStep: + description: Search tasks that have this type of step as the current step. + enum: + - TASK_SEARCH_CURRENT_STEP_UNSPECIFIED + - TASK_SEARCH_CURRENT_STEP_APPROVAL + - TASK_SEARCH_CURRENT_STEP_PROVISION + type: string + x-speakeasy-unknown-values: allow + emergencyStatus: + description: Search tasks that are or are not emergency access. + enum: + - UNSPECIFIED + - ALL + - NON_EMERGENCY + - EMERGENCY + type: string + x-speakeasy-unknown-values: allow + excludeAppEntitlementIds: + description: Search tasks that do not have any of these app entitlement IDs. + items: + type: string + type: + - array + - "null" + excludeAppResourceTypeIds: + description: Search tasks that do not have any of these app resource type IDs. + items: + type: string + type: + - array + - "null" + excludeApplicationIds: + description: Search tasks that do NOT have any of these apps as targets. + items: + type: string + type: + - array + - "null" + excludeIds: + description: Exclude Specific TaskIDs from this serach result. + items: + type: string + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + grantOutcomes: + description: Search tasks by grant outcome + items: + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + includeActedAfter: + format: date-time + type: + - string + - "null" + includeDeleted: + description: Whether or not to include deleted tasks. + type: boolean + myWorkUserIds: + description: Search tasks where the user would see this task in the My Work section + items: + type: string + type: + - array + - "null" + olderThanDuration: + format: duration + type: + - string + - "null" + openerIds: + description: Search tasks that were created by any of the users in this array. + items: + type: string + type: + - array + - "null" + openerOrSubjectUserId: + description: Search tasks that were opened by this user, or that the user is the subject of. + type: string + outcomeAfter: + format: date-time + type: + - string + - "null" + outcomeBefore: + format: date-time + type: + - string + - "null" + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + pendingActionFilter: + description: |- + Filter tasks by pending action status. Only applies when exactly one access_review_id is specified. + Requires the REVIEWS_PENDING_ACTIONS feature flag to be enabled. + enum: + - PENDING_ACTION_FILTER_UNSPECIFIED + - PENDING_ACTION_FILTER_WITH_PENDING + - PENDING_ACTION_FILTER_WITHOUT_PENDING + type: string + x-speakeasy-unknown-values: allow + previouslyActedOnIds: + description: Search tasks that were acted on by any of these users. + items: + type: string + type: + - array + - "null" + query: + description: Fuzzy search tasks by display name, description, or ID. + type: string + refs: + description: Query tasks by display name, description, or numeric ID. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskRef' + type: + - array + - "null" + requireApprovalReason: + description: Filter tasks where the current approval step requires an approval reason. + type: boolean + requireDenialReason: + description: Filter tasks where the current approval step requires a denial reason. + type: boolean + revokeOutcomes: + description: Search tasks by revoke outcome + items: + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + sortBy: + description: Sort tasks in a specific order. + enum: + - TASK_SEARCH_SORT_BY_UNSPECIFIED + - TASK_SEARCH_SORT_BY_ACCOUNT + - TASK_SEARCH_SORT_BY_RESOURCE + - TASK_SEARCH_SORT_BY_ACCOUNT_OWNER + - TASK_SEARCH_SORT_BY_REVERSE_TICKET_ID + - TASK_SEARCH_SORT_BY_TICKET_ID + - TASK_SEARCH_SORT_BY_CREATED_AT + - TASK_SEARCH_SORT_BY_REVERSE_CREATED_AT + - TASK_SEARCH_SORT_BY_APP_RESOURCE_ID_AND_APP_ENTITLEMENT + type: string + x-speakeasy-unknown-values: allow + stepApprovalTypes: + description: Search tasks that have a current policy step of this type + items: + enum: + - STEP_APPROVAL_TYPE_UNSPECIFIED + - STEP_APPROVAL_TYPE_USERS + - STEP_APPROVAL_TYPE_MANAGER + - STEP_APPROVAL_TYPE_APP_OWNERS + - STEP_APPROVAL_TYPE_GROUP + - STEP_APPROVAL_TYPE_SELF + - STEP_APPROVAL_TYPE_ENTITLEMENT_OWNERS + - STEP_APPROVAL_TYPE_EXPRESSION + - STEP_APPROVAL_TYPE_WEBHOOK + - STEP_APPROVAL_TYPE_RESOURCE_OWNERS + - STEP_APPROVAL_TYPE_AGENT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + subjectIds: + description: Search tasks where these users are the subject. + items: + type: string + type: + - array + - "null" + taskStates: + description: Search tasks with this task state. + items: + enum: + - TASK_STATE_UNSPECIFIED + - TASK_STATE_OPEN + - TASK_STATE_CLOSED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + taskTypes: + description: Search tasks with this task type. This is a oneOf, and needs an object, which can be empty, to sort. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskType' + type: + - array + - "null" + userEmploymentStatuses: + description: The userEmploymentStatuses field. + items: + type: string + type: + - array + - "null" + title: Task Search Request + type: object + x-speakeasy-name-override: TaskSearchRequest + c1.api.task.v1.TaskSearchResponse: + description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. + properties: + expanded: + description: The list of results containing up to X results, where X is the page size defined in the request. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: List of serialized related objects. + items: + $ref: '#/components/schemas/c1.api.task.v1.TaskView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: Task Search Response + type: object + x-speakeasy-name-override: TaskSearchResponse + c1.api.task.v1.TaskServiceActionResponse: + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + ticketActionId: + description: The ID of the task action created by this request. + type: string + title: Task Service Action Response + type: object + x-speakeasy-name-override: TaskServiceActionResponse + c1.api.task.v1.TaskServiceCreateActionRequest: + description: The TaskServiceCreateActionRequest message submits a request action (requestable automation). + properties: + actionId: + description: The ID of the action to request. + type: string + description: + description: An optional description of the request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + formValues: + additionalProperties: true + type: + - object + - "null" + title: Task Service Create Action Request + type: object + x-speakeasy-name-override: TaskServiceCreateActionRequest + c1.api.task.v1.TaskServiceCreateActionResponse: + description: The TaskServiceCreateActionResponse returns the created action task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Action Response + type: object + x-speakeasy-name-override: TaskServiceCreateActionResponse + c1.api.task.v1.TaskServiceCreateGrantRequest: + description: Create a grant task. + properties: + appEntitlementId: + description: The ID of the app entitlement to grant access to. + type: string + appId: + description: The ID of the app that is associated with the entitlement. + type: string + appUserId: + description: The ID of the app user to grant access for. This field and identityUserId cannot both be set for a given request. + type: string + description: + description: The description of the request. + type: string + emergencyAccess: + description: Boolean stating whether or not the task is marked as emergency access. + type: boolean + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + grantDuration: + format: duration + type: + - string + - "null" + identityUserId: + description: The ID of the user associated with the app user we are granting access for. This field cannot be set if appUserID is also set. + type: string + requestData: + additionalProperties: true + type: + - object + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' + - type: "null" + required: + - appId + - appEntitlementId + title: Task Service Create Grant Request + type: object + x-speakeasy-name-override: TaskServiceCreateGrantRequest + c1.api.task.v1.TaskServiceCreateGrantResponse: + description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Grant Response + type: object + x-speakeasy-name-override: TaskServiceCreateGrantResponse + c1.api.task.v1.TaskServiceCreateOffboardingRequest: + description: Create an offboarding task. + properties: + description: + description: The description of the offboarding request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + subjectUserId: + description: The ID of the user to offboard. + type: string + title: Task Service Create Offboarding Request + type: object + x-speakeasy-name-override: TaskServiceCreateOffboardingRequest + c1.api.task.v1.TaskServiceCreateOffboardingResponse: + description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Offboarding Response + type: object + x-speakeasy-name-override: TaskServiceCreateOffboardingResponse + c1.api.task.v1.TaskServiceCreateResourceActionRequest: + description: The TaskServiceCreateResourceActionRequest submits a request to execute a connector resource-create action, for example creating a group from a group template. + properties: + actionId: + description: The ID of the resource-create action to execute. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + formValues: + additionalProperties: true + type: + - object + - "null" + required: + - actionId + title: Task Service Create Resource Action Request + type: object + x-speakeasy-name-override: TaskServiceCreateResourceActionRequest + c1.api.task.v1.TaskServiceCreateResourceActionResponse: + description: The TaskServiceCreateResourceActionResponse returns the created action task with optional expanded related objects. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Resource Action Response + type: object + x-speakeasy-name-override: TaskServiceCreateResourceActionResponse + c1.api.task.v1.TaskServiceCreateRevokeRequest: + description: Create a revoke task. + properties: + appEntitlementId: + description: The ID of the app entitlement to revoke access to. + type: string + appId: + description: The ID of the app associated with the entitlement. + type: string + appUserId: + description: The ID of the app user to revoke access from. This field and identityUserId cannot both be set for a given request. + type: string + description: + description: The description of the request. + type: string + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskExpandMask' + - type: "null" + identityUserId: + description: The ID of the user associated with the app user we are revoking access from. This field cannot be set if appUserID is also set. + type: string + required: + - appId + - appEntitlementId + title: Task Service Create Revoke Request + type: object + x-speakeasy-name-override: TaskServiceCreateRevokeRequest + c1.api.task.v1.TaskServiceCreateRevokeResponse: + description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Create Revoke Response + type: object + x-speakeasy-name-override: TaskServiceCreateRevokeResponse + c1.api.task.v1.TaskServiceGetResponse: + description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + readOnly: true + type: object + readOnly: true + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Task Service Get Response + type: object + x-speakeasy-name-override: TaskServiceGetResponse + c1.api.task.v1.TaskType: + description: | + Task Type provides configuration for the type of task: certify, grant, or revoke + + This message contains a oneof named task_type. Only a single field of the following list may be set at a time: + - grant + - revoke + - certify + - offboarding + - action + - finding + properties: + action: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeAction' + - type: "null" + certify: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeCertify' + - type: "null" + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeFinding' + - type: "null" + grant: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeGrant' + - type: "null" + offboarding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeOffboarding' + - type: "null" + revoke: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskTypeRevoke' + - type: "null" + title: Task Type + type: object + x-speakeasy-name-override: TaskType + c1.api.task.v1.TaskTypeAction: + description: | + The TaskTypeAction message. + + This message contains a oneof named target_object. Only a single field of the following list may be set at a time: + - scopeRole + - toolCall + - finding + properties: + actionId: + description: |- + The ID of the admin-authored action to execute. Empty for synthesized + action tickets (e.g. scope-role grants) — those carry dispatch + configuration on action_instance and target_object instead. + readOnly: true + type: string + actionInstance: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ActionInstance' + - type: "null" + createdAppEntitlementIds: + description: |- + The C1 IDs of the AppEntitlements materialized from the connector response + (for a group, typically its members and owners entitlements). Use these to + request access, attach a virtual entitlement, or otherwise manage the new + resource. Empty until outcome is SUCCESS; may be empty on SUCCESS if + materialization was skipped or failed, in which case the entitlements + appear after the next connector sync. + items: + type: string + readOnly: true + type: + - array + - "null" + createdAppResourceId: + description: |- + Populated when a resource-create action completes: the C1 ID of the + AppResource materialized from the connector response. + readOnly: true + type: string + createdAppResourceTypeId: + description: The resource type ID of the materialized AppResource. + readOnly: true + type: string + displayName: + description: |- + Display label captured on the action snapshot at ticket-creation time. + Stable under admin renames to a referenced Action row and populated for + synthesized tickets that have no Action row at all. UI reads this to + render the task title without an Action fetch. + readOnly: true + type: string + finding: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.FindingTarget' + - type: "null" + formValues: + additionalProperties: true + readOnly: true + type: + - object + - "null" + outcome: + description: The outcome field. + enum: + - ACTION_OUTCOME_UNSPECIFIED + - ACTION_OUTCOME_SUCCESS + - ACTION_OUTCOME_DENIED + - ACTION_OUTCOME_ERROR + - ACTION_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + scopeRole: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.ScopeRole' + - type: "null" + toolCall: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.GatedToolCallTarget' + - type: "null" + type: + description: |- + Flavor of action the ticket represents — mirrors the snapshot's + target_ref variant. + enum: + - TYPE_UNSPECIFIED + - TYPE_GRANT + - TYPE_WORKFLOW + - TYPE_RESOURCE_ACTION + - TYPE_TOOL_CALL + - TYPE_MANUAL + readOnly: true + type: string + x-speakeasy-unknown-values: allow + title: Task Type Action + type: object + x-speakeasy-name-override: TaskTypeAction + c1.api.task.v1.TaskTypeCertify: + description: | + The TaskTypeCertify message indicates that a task is a certify task and all related details. + + This message contains a oneof named principal. Only a single field of the following list may be set at a time: + - resource + properties: + accessReviewId: + description: The ID of the access review. + readOnly: true + type: string + accessReviewSelection: + description: The ID of the specific access review object that owns this certify task. This is also set on a revoke task if the revoke task is created from the denied outcome of a certify task. + readOnly: true + type: string + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the certification. + enum: + - CERTIFY_OUTCOME_UNSPECIFIED + - CERTIFY_OUTCOME_CERTIFIED + - CERTIFY_OUTCOME_DECERTIFIED + - CERTIFY_OUTCOME_ERROR + - CERTIFY_OUTCOME_CANCELLED + - CERTIFY_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' + - type: "null" + title: Task Type Certify + type: object + x-speakeasy-name-override: TaskTypeCertify + c1.api.task.v1.TaskTypeFinding: + description: The TaskTypeFinding message. + properties: + findingId: + description: Reference to the source finding. + readOnly: true + type: string + findingType: + description: The finding type discriminator. + readOnly: true + type: string + outcome: + description: The outcome field. + enum: + - FINDING_TASK_OUTCOME_UNSPECIFIED + - FINDING_TASK_OUTCOME_REMEDIATED + - FINDING_TASK_OUTCOME_RISK_ACCEPTED + - FINDING_TASK_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + title: Task Type Finding + type: object + x-speakeasy-name-override: TaskTypeFinding + c1.api.task.v1.TaskTypeGrant: + description: The TaskTypeGrant message indicates that a task is a grant task and all related details. + properties: + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + grantDuration: + format: duration + readOnly: true + type: + - string + - "null" + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the grant. + enum: + - GRANT_OUTCOME_UNSPECIFIED + - GRANT_OUTCOME_GRANTED + - GRANT_OUTCOME_DENIED + - GRANT_OUTCOME_ERROR + - GRANT_OUTCOME_CANCELLED + - GRANT_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskGrantSource' + - type: "null" + title: Task Type Grant + type: object + x-speakeasy-name-override: TaskTypeGrant + c1.api.task.v1.TaskTypeOffboarding: + description: The TaskTypeOffboarding message. + properties: + outcome: + description: The outcome field. + enum: + - OFFBOARDING_OUTCOME_UNSPECIFIED + - OFFBOARDING_OUTCOME_IN_PROGRESS + - OFFBOARDING_OUTCOME_DONE + - OFFBOARDING_OUTCOME_ERROR + - OFFBOARDING_OUTCOME_CANCELLED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + subjectUserId: + description: The subjectUserId field. + readOnly: true + type: string + title: Task Type Offboarding + type: object + x-speakeasy-name-override: TaskTypeOffboarding + c1.api.task.v1.TaskTypeRevoke: + description: | + The TaskTypeRevoke message indicates that a task is a revoke task and all related details. + + This message contains a oneof named principal. Only a single field of the following list may be set at a time: + - resource + properties: + appEntitlementId: + description: The ID of the app entitlement. + readOnly: true + type: string + appId: + description: The ID of the app. + readOnly: true + type: string + appUserId: + description: The ID of the app user. + readOnly: true + type: string + identityUserId: + description: The ID of the user. + readOnly: true + type: string + outcome: + description: The outcome of the revoke. + enum: + - REVOKE_OUTCOME_UNSPECIFIED + - REVOKE_OUTCOME_REVOKED + - REVOKE_OUTCOME_DENIED + - REVOKE_OUTCOME_ERROR + - REVOKE_OUTCOME_CANCELLED + - REVOKE_OUTCOME_WAIT_TIMED_OUT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + outcomeTime: + format: date-time + readOnly: true + type: + - string + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef' + - type: "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskRevokeSource' + - type: "null" + title: Task Type Revoke + type: object + x-speakeasy-name-override: TaskTypeRevoke + c1.api.task.v1.TaskView: + description: Contains a task and JSONPATH expressions that describe where in the expanded array related objects are located. This view can be used to display a fully-detailed dashboard of task information. + properties: + accessReviewPath: + description: JSONPATH expression indicating the location of the AccessReview object in the expanded array + readOnly: true + type: string + appPath: + description: JSONPATH expression indicating the location of the App object in the expanded array + readOnly: true + type: string + appUserLastUsagePath: + description: JSONPATH expression indicating the location of the AppUser last usage timestamp in the expanded array + readOnly: true + type: string + appUserPath: + description: JSONPATH expression indicating the location of the AppUser object in the expanded array + readOnly: true + type: string + approversPath: + description: JSONPATH expression indicating the location of the ApproverUsers objects in the expanded array. These are the users who have approved or denied this task. + readOnly: true + type: string + createdByUserPath: + description: JSONPATH expression indicating the location of the object of the User that created the ticket in the expanded array + readOnly: true + type: string + entitlementsPath: + description: JSONPATH expression indicating the location of the Entitlements objects in the expanded array + readOnly: true + type: string + identityUserPath: + description: JSONPATH expression indicating the location of the User object of the User that this task is targeting in the expanded array. This is the user that is the identity when the target of a task is an app user. + readOnly: true + type: string + insightsPath: + description: JSONPATH expression indicating the location of the Insights objects in the expanded array + readOnly: true + type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + principalResourcePath: + description: JSONPATH expression indicating the location of the AppResource under review for a resource-principal certify task in the expanded array. + readOnly: true + type: string + resourceBindingsPath: + description: JSONPATH expression indicating the location of the EntitlementScopeBindingList object in the expanded array. + readOnly: true + type: string + roleResourcePath: + description: JSONPATH expression indicating the location of the role AppResource for a scope-role action task in the expanded array. + readOnly: true + type: string + scopeResourcePath: + description: JSONPATH expression indicating the location of the scope AppResource for a scope-role action task in the expanded array. + readOnly: true + type: string + stepApproversPath: + description: JSONPATH expression indicating the location of the StepApproverUsers objects in the expanded array + readOnly: true + type: string + task: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.Task' + - type: "null" + userPath: + description: JSONPATH expression indicating the location of the User object in the expanded array. This is the user that is a direct target of the ticket without a specific relationship to a potentially non-existent app user. + readOnly: true + type: string + title: Task View + type: object + x-speakeasy-name-override: TaskView + c1.api.terraform_export.v1.CompositeKeyField: + description: |- + CompositeKeyField names one sibling component of a composite-key + reference lookup. + properties: + c1Field: + description: |- + C1 API field name on the parent message (snake_case proto + field). The collector reads the runtime value at this path. + type: string + tfField: + description: |- + Attribute name in the Terraform data source's `refs[]` struct. + Usually identical to c1_field (the conductorone provider + matches them 1:1 today). Distinct fields anyway so a future + provider rename is wire-safe — no migration needed. + type: string + title: Composite Key Field + type: object + x-speakeasy-name-override: CompositeKeyField + c1.api.terraform_export.v1.CompositeKeyFieldSet: + description: |- + CompositeKeyFieldSet groups a non-empty set of composite-key + fields as declared by one or more consumer reference sites that + target the same Terraform type. Used in `TFSchemaMapping + .referer_shapes` (the "inverted index" of composite-key shapes + targeting this kind) so a multi-root producer can register + canonical lookup keys for every shape its consumers might + compute. + + Invariant: `fields` MUST be non-empty. The bare-id (single-id) + form is implicit — every producer registers under + `canonicalRefKey(id, {})` unconditionally, and consumer sites + with empty composite_key_fields are not represented here. The + backend's inverted-index computation skips them; including an + empty `fields` would just round-trip to the bare-id form and + produce a duplicate registration. + properties: + fields: + description: The fields field. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' + type: + - array + - "null" + title: Composite Key Field Set + type: object + x-speakeasy-name-override: CompositeKeyFieldSet + c1.api.terraform_export.v1.EnumValue: + description: EnumValue is one declared variant of a proto enum. + properties: + name: + description: |- + Full proto enum value name (e.g. "POLICY_TYPE_GRANT"). The + conductorone provider accepts this verbatim as a quoted-string HCL + literal. + type: string + number: + description: |- + Proto enum number — the value on the wire (e.g. 1 for + POLICY_TYPE_GRANT). + format: int32 + type: integer + title: Enum Value + type: object + x-speakeasy-name-override: EnumValue + c1.api.terraform_export.v1.GetSchemaResponse: + description: The GetSchemaResponse message. + properties: + schema: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping' + - type: "null" + title: Get Schema Response + type: object + x-speakeasy-name-override: GetSchemaResponse + c1.api.terraform_export.v1.ImportIDShape: + description: | + ImportIDShape describes the structure of the `id` value in a + Terraform `import { to = ..., id = "..." }` block. Most resources use + a single string; binding-style resources (App_Owner, + App_Entitlement_Owner, …) use a composite of multiple field values. + + This message contains a oneof named shape. Only a single field of the following list may be set at a time: + - singleString + - composite + properties: + composite: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.Composite' + - type: "null" + singleString: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.SingleString' + - type: "null" + title: Import Id Shape + type: object + x-speakeasy-name-override: ImportIDShape + c1.api.terraform_export.v1.ImportIDShape.Composite: + description: |- + Composite import IDs combine values from multiple component fields + per the declared `format`. + properties: + fields: + description: |- + Component fields, in the order they participate in the import + ID. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape.CompositeField' + type: + - array + - "null" + format: + description: |- + Wire format the provider expects. Defaults to + FORMAT_JSON_OBJECT. + enum: + - FORMAT_JSON_OBJECT + - FORMAT_COLON_SEPARATED + - FORMAT_UNDERSCORE_SEPARATED + type: string + x-speakeasy-unknown-values: allow + title: Composite + type: object + x-speakeasy-name-override: Composite + c1.api.terraform_export.v1.ImportIDShape.CompositeField: + description: CompositeField names one component of a composite import ID. + properties: + c1Field: + description: The C1 API field whose value supplies this component. + type: string + tfType: + description: The TF attribute type of the component value. + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + title: Composite Field + type: object + x-speakeasy-name-override: CompositeField + c1.api.terraform_export.v1.ImportIDShape.SingleString: + description: Single-string import IDs use the resource's id value verbatim. + title: Single String + type: object + x-speakeasy-name-override: SingleString + c1.api.terraform_export.v1.TFFieldMapping: + description: |- + TFFieldMapping describes how one field of a C1 API object maps to one + attribute of a Terraform block. + properties: + c1Field: + description: The C1 API field name (proto field name, snake_case). + type: string + computed: + description: |- + Whether the server populates this field. A field that is + `computed` and neither `optional` nor `required` is server-only — + do not emit it in user-authored HCL. + type: boolean + elementTfType: + description: |- + For collection fields (list/set/tuple/map) whose elements are + primitives (string/number/bool), the TF type of those elements. + TF_TYPE_UNSPECIFIED for non-collection fields and for collections + of objects (where `nested_fields` describes the element shape). + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + enumValues: + description: |- + Declared variants for fields whose C1-side proto type is an enum. + Empty for non-enum fields. The conductorone provider accepts the + full proto enum name as a quoted string (e.g. + `policy_type = "POLICY_TYPE_GRANT"`); emit `EnumValue.name` as the + literal value. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.EnumValue' + type: + - array + - "null" + nestedFields: + description: |- + For object-typed fields and list/set/tuple fields whose elements + are objects, the shape of the nested attributes. Empty for + primitive scalars and primitive-element collections. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' + type: + - array + - "null" + oneofField: + description: |- + When this Terraform attribute corresponds to one variant of a + proto `oneof`, `oneof_field` names the proto oneof and + `oneof_variant` names the active case. Both unset for regular + (non-oneof) fields, which is the common case. + + Example: a oneof `target` with variant `automation` on message + `Action` exposed as the TF attribute `action_target_automation`: + + oneof_field = "target" + oneof_variant = "automation" + type: string + oneofVariant: + description: The oneofVariant field. + type: string + optional: + description: |- + Whether the user may supply this field. May co-occur with + `computed` (i.e. either the user or the server can set the value). + type: boolean + references: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFReference' + - type: "null" + required: + description: Whether the user must supply this field in HCL. + type: boolean + sensitive: + description: |- + Whether the value is a secret. Sensitive values must not be + rendered verbatim; emit a placeholder so callers wire the value + through a Terraform variable or vault data source. + type: boolean + tfField: + description: |- + The Terraform attribute name. Usually matches c1_field but may + differ in casing or pluralization. + type: string + tfType: + description: |- + The Terraform attribute type. For collections of structured + objects, the element shape is in `nested_fields`. For collections + of primitives, the element type is in `element_tf_type`. + enum: + - TF_TYPE_UNSPECIFIED + - TF_TYPE_STRING + - TF_TYPE_NUMBER + - TF_TYPE_BOOL + - TF_TYPE_LIST + - TF_TYPE_SET + - TF_TYPE_MAP + - TF_TYPE_OBJECT + - TF_TYPE_TUPLE + type: string + x-speakeasy-unknown-values: allow + title: Tf Field Mapping + type: object + x-speakeasy-name-override: TFFieldMapping + c1.api.terraform_export.v1.TFReference: + description: |- + TFReference describes the Terraform type(s) an ID-shaped field may + reference, plus any sibling fields needed to disambiguate a + composite-key lookup. + + `tf_type_names` covers the polymorphic / preferred-default + dimension. `composite_key_fields` covers the multi-key dimension — + some referents can't be resolved with a single id (every + `conductorone_app_entitlement` lookup needs `(app_id, id)`, + every `conductorone_app_entitlement_user_binding` needs three + keys, etc.). + properties: + compositeKeyFields: + description: |- + Sibling fields on the SAME parent message whose runtime values + must be paired with this reference's id to look the referent up + via its Terraform data source. + + Examples (each entry's c1_field is the C1 proto field name on + the parent message; tf_field is the attribute name in the data + source's `refs[]` struct): + + `AppEntitlementAutomation.app_entitlement_id` → + `[{c1_field: "app_id", tf_field: "app_id"}]` (2 keys total) + + `AppEntitlementUserBinding.app_user_id` → + `[{c1_field: "app_id", tf_field: "app_id"}, + {c1_field: "app_entitlement_id", tf_field: "app_entitlement_id"}]` + (3 keys total) + + `AppResourceOwner.user_id` → + `[{c1_field: "app_id", tf_field: "app_id"}, + {c1_field: "app_resource_type_id", tf_field: "app_resource_type_id"}, + {c1_field: "app_resource_id", tf_field: "app_resource_id"}]` + (4 keys total) + + The reference id field itself is always emitted as `id` in the + data source's ref struct (provider convention) — it is NOT + re-listed here. + + Empty/unset means single-id lookup is sufficient (User, Policy, + App today). Mirrors `ImportIDShape.Composite.fields`'s + structured shape. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyField' + type: + - array + - "null" + tfTypeNames: + description: |- + Candidate Terraform types this field may reference. The first + entry is the preferred default when no other signal disambiguates. + Empty means the field is not a reference. + items: + type: string + type: + - array + - "null" + title: Tf Reference + type: object + x-speakeasy-name-override: TFReference + c1.api.terraform_export.v1.TFSchemaMapping: + description: | + TFSchemaMapping describes how to translate one C1 API object into a + single Terraform block. Variant-specific metadata (e.g. `import_id` for + resources) lives on the `block` oneof. + + This message contains a oneof named block. Only a single field of the following list may be set at a time: + - resource + - dataSource + properties: + dataSource: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.DataSource' + - type: "null" + fields: + description: |- + Per-attribute mapping. Order matches the provider schema; preserve + it when emitting for stable output. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.TFFieldMapping' + type: + - array + - "null" + providerVersion: + description: |- + The conductorone provider version this schema was derived from + (e.g. "1.0.40"). + type: string + refererShapes: + description: |- + The set of distinct composite-key-field shapes that consumers + declare when referencing this target via a TFReference. Used by + the FE multi-root producer to enumerate canonical lookup keys for + its `addressByImportId` registration so cross-root references + collapse correctly to direct expressions regardless of which + consumer site does the lookup. + + Each entry is one distinct shape (one `CompositeKeyFieldSet` + with non-empty `fields`). The single-id (bare-id) form is + implicit and is NOT represented here — every producer registers + under `canonicalRefKey(id, {})` unconditionally as a baseline. + + Computed at schema-load time from `references_table.go` by + grouping consumer-site `composite_key_fields` declarations + by target tf_type and de-duplicating distinct shapes. Targets + with no composite-key consumers (User, Policy, App today) + ship an empty list. + items: + $ref: '#/components/schemas/c1.api.terraform_export.v1.CompositeKeyFieldSet' + type: + - array + - "null" + resource: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.TFSchemaMapping.Resource' + - type: "null" + tfTypeName: + description: |- + The Terraform type identifier — the string immediately after the + `resource` or `data` keyword in HCL (e.g. "conductorone_app"). + type: string + title: Tf Schema Mapping + type: object + x-speakeasy-name-override: TFSchemaMapping + c1.api.terraform_export.v1.TFSchemaMapping.DataSource: + description: |- + Data-source-specific schema metadata. Reserved for future use; empty + in v1. + title: Data Source + type: object + x-speakeasy-name-override: DataSource + c1.api.terraform_export.v1.TFSchemaMapping.Resource: + description: Resource-specific schema metadata. + properties: + importId: + oneOf: + - $ref: '#/components/schemas/c1.api.terraform_export.v1.ImportIDShape' + - type: "null" + title: Resource + type: object + x-speakeasy-name-override: Resource + c1.api.user.v1.ExpiringUserDelegationBinding: + description: The ExpiringUserDelegationBinding message. + properties: + createdAt: + format: date-time + type: + - string + - "null" + delegatedUserId: + description: The delegatedUserId field. + type: string + deletedAt: + format: date-time + type: + - string + - "null" + expirationAt: + format: date-time + type: + - string + - "null" + startAt: + format: date-time + type: + - string + - "null" + updatedAt: + format: date-time + type: + - string + - "null" + userId: + description: The userId field. + type: string + title: Expiring User Delegation Binding + type: object + x-speakeasy-name-override: ExpiringUserDelegationBinding + c1.api.user.v1.GetUserProfileTypesResponse: + description: GetUserProfileTypesResponse is the response containing the profile types for a user. + properties: + profileTypes: + description: The list of profile types associated with the user across their connected apps. + items: + $ref: '#/components/schemas/c1.api.profiletype.v1.ProfileType' + type: + - array + - "null" + title: Get User Profile Types Response + type: object + x-speakeasy-name-override: GetUserProfileTypesResponse + c1.api.user.v1.IntrospectRequest: + description: The IntrospectRequest message. + properties: + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' + - type: "null" + title: Introspect Request + type: object + x-speakeasy-name-override: UserIntrospectRequest + c1.api.user.v1.IntrospectResponse: + description: The IntrospectResponse message. + properties: + expanded: + description: The expanded field. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + userView: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserView' + - type: "null" + title: Introspect Response + type: object + x-speakeasy-name-override: UserIntrospectResponse + c1.api.user.v1.SearchUsersRequest: + description: Search for users based on some filters. + properties: + delegateStatus: + description: Filter for users based on their delegate status. + enum: + - DELEGATE_STATUS_UNSPECIFIED + - DELEGATE_STATUS_HAS_DELEGATE + - DELEGATE_STATUS_NO_DELEGATE + type: string + x-speakeasy-unknown-values: allow + delegatedUserIds: + description: Filter for users that have any of the delegated user IDs on this list. + items: + type: string + type: + - array + - "null" + departments: + description: Search for users that have any of the departments on this list. + items: + type: string + type: + - array + - "null" + email: + description: Search for users based on their email (exact match). + type: string + excludeIds: + description: An array of users IDs to exclude from the results. + items: + type: string + type: + - array + - "null" + excludeOrigins: + description: Filter to exclude users with these origins. + items: + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + excludeTypes: + description: An array of types to exclude from the results. + items: + enum: + - USER_TYPE_UNSPECIFIED + - USER_TYPE_SYSTEM + - USER_TYPE_HUMAN + - USER_TYPE_SERVICE + - USER_TYPE_AGENT + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + expandMask: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserExpandMask' + - type: "null" + ids: + description: Deprecated. Use refs array instead. + items: + type: string + type: + - array + - "null" + isDelegate: + description: Filter for users who are delegates of at least one other user. + type: boolean + jobTitles: + description: Search for users that have any of the job titles on this list. + items: + type: string + type: + - array + - "null" + managerIds: + description: Search for users that have any of the manager IDs on this list. + items: + type: string + type: + - array + - "null" + origins: + description: Filter to include only users with these origins. + items: + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + pageSize: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + query: + description: Query the apps with a fuzzy search on display name and emails. + type: string + refs: + description: An array of user refs to restrict the return values to by ID. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + roleIds: + description: Search for users that have any of the role IDs on this list. + items: + type: string + type: + - array + - "null" + userStatuses: + description: Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED + items: + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + type: string + x-speakeasy-unknown-values: allow + type: + - array + - "null" + title: Search Users Request + type: object + x-speakeasy-name-override: SearchUsersRequest + c1.api.user.v1.SearchUsersResponse: + description: The SearchUsersResponse message. + properties: + expanded: + description: List of related objects + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request + items: + $ref: '#/components/schemas/c1.api.user.v1.UserView' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken is shown for the next page if the number of results is larger than the max page size. The server returns one page of results and the nextPageToken until all results are retreived. To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: Search Users Response + type: object + x-speakeasy-name-override: SearchUsersResponse + c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput: + description: SetExpiringUserDelegationBindingByAdminRequest is the request for an admin to set a temporary delegation binding for a user. + properties: + delegatedUserId: + description: The ID of the user who will act as delegate. Empty string removes the delegation. + type: string + delegationExpireAt: + format: date-time + type: + - string + - "null" + delegationStartAt: + format: date-time + type: + - string + - "null" + title: Set Expiring User Delegation Binding By Admin Request + type: object + x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminRequest + c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse: + description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. + properties: + item: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.ExpiringUserDelegationBinding' + - type: "null" + title: Set Expiring User Delegation Binding By Admin Response + type: object + x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdminResponse + c1.api.user.v1.User: + description: The User object provides all of the details for an user, as well as some configuration. + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + delegatedUserId: + description: The id of the user to whom tasks will be automatically reassigned to. + type: string + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + department: + description: The department which the user belongs to in the organization. + readOnly: true + type: string + departmentSources: + description: A list of objects mapped based on department attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + directoryIds: + description: A list of unique ids that represent different directories. + items: + type: string + readOnly: true + type: + - array + - "null" + directoryStatus: + description: The status of the user in the directory. + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + readOnly: true + type: string + x-speakeasy-unknown-values: allow + directoryStatusSources: + description: A list of objects mapped based on directoryStatus attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + displayName: + description: The display name of the user. + readOnly: true + type: string + email: + description: This is the user's email. + readOnly: true + type: string + emailSources: + description: A list of source data for the email attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + emails: + description: This is a list of all of the user's emails from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + employeeIdSources: + description: A list of source data for the employee IDs attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + employeeIds: + description: This is a list of all of the user's employee IDs from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + employmentStatus: + description: The users employment status. + readOnly: true + type: string + employmentStatusSources: + description: A list of objects mapped based on employmentStatus attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + employmentType: + description: The employment type of the user. + readOnly: true + type: string + employmentTypeSources: + description: A list of objects mapped based on employmentType attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + id: + description: A unique identifier of the user. + readOnly: true + type: string + jobTitle: + description: The job title of the user. + readOnly: true + type: string + jobTitleSources: + description: A list of objects mapped based on jobTitle attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + managerIds: + description: A list of ids of the user's managers. + items: + type: string + readOnly: true + type: + - array + - "null" + managerSources: + description: A list of objects mapped based on managerId attribute mappings configured in the system. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + origin: + description: The origin of the user, describing who owns the user's lifecycle. + enum: + - USER_ORIGIN_UNSPECIFIED + - USER_ORIGIN_DIRECTORY + - USER_ORIGIN_LOCAL + - USER_ORIGIN_SYSTEM + readOnly: true + type: string + x-speakeasy-unknown-values: allow + profile: + additionalProperties: true + readOnly: true + type: + - object + - "null" + roleIds: + description: A list of unique identifiers that maps to ConductorOne's user roles let you assign users permissions tailored to the work they do in the software. + items: + type: string + type: + - array + - "null" + status: + description: The status of the user in the system. + enum: + - UNKNOWN + - ENABLED + - DISABLED + - DELETED + type: string + x-speakeasy-unknown-values: allow + type: + description: The type of the user. + enum: + - USER_TYPE_UNSPECIFIED + - USER_TYPE_SYSTEM + - USER_TYPE_HUMAN + - USER_TYPE_SERVICE + - USER_TYPE_AGENT + readOnly: true + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + username: + description: This is the user's primary username. Typically sourced from the primary directory. + readOnly: true + type: string + usernameSources: + description: A list of source data for the usernames attribute. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserAttributeMappingSource' + readOnly: true + type: + - array + - "null" + usernames: + description: This is a list of all of the user's usernames from app users. + items: + type: string + readOnly: true + type: + - array + - "null" + title: User + type: object + x-speakeasy-name-override: User + c1.api.user.v1.UserAttributeMappingSource: + description: The UserAttributeMappingSource message. + properties: + appId: + description: The appId field. + type: string + appUserId: + description: The appUserId field. + type: string + appUserProfileAttributeKey: + description: The appUserProfileAttributeKey field. + type: string + priority: + description: Lower number = higher precedence; sources[0] is the winning source. + format: uint32 + readOnly: true + type: integer + userAttributeMappingId: + description: The userAttributeMappingId field. + type: string + value: + description: The value field. + type: string + title: User Attribute Mapping Source + type: object + x-speakeasy-name-override: UserAttributeMappingSource + c1.api.user.v1.UserExpandMask: + description: |- + The user expand mask is used to indicate which related objects should be expanded in the response. + The supported paths are 'role_ids', 'manager_ids', 'delegated_user_id', 'directory_ids', and '*'. + properties: + paths: + description: An array of paths to be expanded in the response. + items: + type: string + type: + - array + - "null" + title: User Expand Mask + type: object + x-speakeasy-name-override: UserExpandMask + c1.api.user.v1.UserRef: + description: A reference to a user. + properties: + id: + description: The id of the user. + type: string + title: User Ref + type: object + x-speakeasy-name-override: UserRef + c1.api.user.v1.UserServiceGetResponse: + description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + userView: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserView' + - type: "null" + title: User Service Get Response + type: object + x-speakeasy-name-override: UserServiceGetResponse + c1.api.user.v1.UserServiceListResponse: + description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + list: + description: The list of results containing up to X results, where X is the page size defined in the request + items: + $ref: '#/components/schemas/c1.api.user.v1.UserView' + type: + - array + - "null" + nextPageToken: + description: |- + The nextPageToken is shown for the next page if the number of results is larger than the max page size. + The server returns one page of results and the nextPageToken until all results are retreived. + To retrieve the next page, use the same request and append a pageToken field with the value of nextPageToken shown on the previous page. + type: string + title: User Service List Response + type: object + x-speakeasy-name-override: UserServiceListResponse + c1.api.user.v1.UserView: + description: The UserView object provides a user response object, as well as JSONPATHs to related objects provided by expanders. + properties: + delegatedUserPath: + description: JSONPATH expression indicating the location of the user objects of delegates of the current user in the expanded array. + readOnly: true + type: string + directoriesPath: + description: JSONPATH expression indicating the location of directory objects in the expanded array. + readOnly: true + type: string + managersPath: + description: JSONPATH expression indicating the location of the user objects that managed the current user in the expanded array. + readOnly: true + type: string + objectPermissions: + oneOf: + - $ref: '#/components/schemas/c1.api.authorization.v1.ActorObjectPermissions' + - type: "null" + rolesPath: + description: JSONPATH expression indicating the location of the roles of the current user in the expanded array. + readOnly: true + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + userId: + description: The id of the user. + readOnly: true + type: string + title: User View + type: object + x-speakeasy-name-override: UserView + c1.api.user.v2.CreateUserEntitlementOwnerRequestInput: + description: CreateUserEntitlementOwnerRequest is the request for creating an entitlement ownership source on a user (service account). + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Create User Entitlement Owner Request + type: object + x-speakeasy-name-override: CreateUserEntitlementOwnerRequest + c1.api.user.v2.CreateUserEntitlementOwnerResponse: + description: CreateUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on a user (service account). + properties: + userOwnerEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' + - type: "null" + title: Create User Entitlement Owner Response + type: object + x-speakeasy-name-override: CreateUserEntitlementOwnerResponse + c1.api.user.v2.CreateUserUserOwnerRequestInput: + description: CreateUserUserOwnerRequest is the request for creating a user ownership source on a user (service account). + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Create User User Owner Request + type: object + x-speakeasy-name-override: CreateUserUserOwnerRequest + c1.api.user.v2.CreateUserUserOwnerResponse: + description: CreateUserUserOwnerResponse is the response for creating a user ownership source on a user (service account). + properties: + userOwnerUser: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' + - type: "null" + title: Create User User Owner Response + type: object + x-speakeasy-name-override: CreateUserUserOwnerResponse + c1.api.user.v2.DeleteUserEntitlementOwnerRequestInput: + description: DeleteUserEntitlementOwnerRequest is the request for deleting an entitlement ownership source on a user (service account). + properties: + appEntitlementRef: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + - type: "null" + title: Delete User Entitlement Owner Request + type: object + x-speakeasy-name-override: DeleteUserEntitlementOwnerRequest + c1.api.user.v2.DeleteUserEntitlementOwnerResponse: + description: DeleteUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a user (service account). + title: Delete User Entitlement Owner Response + type: object + x-speakeasy-name-override: DeleteUserEntitlementOwnerResponse + c1.api.user.v2.DeleteUserUserOwnerRequestInput: + description: DeleteUserUserOwnerRequest is the request for deleting a user ownership source on a user (service account). + properties: + userRef: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.UserRef' + - type: "null" + title: Delete User User Owner Request + type: object + x-speakeasy-name-override: DeleteUserUserOwnerRequest + c1.api.user.v2.DeleteUserUserOwnerResponse: + description: DeleteUserUserOwnerResponse is the empty response for deleting a user ownership source on a user (service account). + title: Delete User User Owner Response + type: object + x-speakeasy-name-override: DeleteUserUserOwnerResponse + c1.api.user.v2.SearchUserEntitlementOwnersResponse: + description: SearchUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on a user (service account). + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.user.v2.UserOwnerEntitlement' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search User Entitlement Owners Response + type: object + x-speakeasy-name-override: SearchUserEntitlementOwnersResponse + c1.api.user.v2.SearchUserOwnersResponse: + description: SearchUserOwnersResponse is the response for searching user ownership sources on a user (service account). + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.user.v2.UserOwnerUser' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Search User Owners Response + type: object + x-speakeasy-name-override: SearchUserOwnersResponse + c1.api.user.v2.SetUserOwnersV2RequestInput: + description: SetUserOwnersV2Request is the request for setting the owners of a user (service account) for a given role. + properties: + appEntitlementRefs: + description: The appEntitlementRefs field. + items: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementRef' + type: + - array + - "null" + roleSlug: + description: The roleSlug field. + type: string + userRefs: + description: The userRefs field. + items: + $ref: '#/components/schemas/c1.api.user.v1.UserRef' + type: + - array + - "null" + title: Set User Owners V 2 Request + type: object + x-speakeasy-name-override: SetUserOwnersV2Request + c1.api.user.v2.SetUserOwnersV2Response: + description: SetUserOwnersV2Response is the empty response for setting user owners. + title: Set User Owners V 2 Response + type: object + x-speakeasy-name-override: SetUserOwnersV2Response + c1.api.user.v2.UserOwnerEntitlement: + description: UserOwnerEntitlement represents an entitlement ownership source for a canonical User (a service account). + properties: + appEntitlement: + oneOf: + - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlement' + - type: "null" + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + userId: + description: The userId field. + type: string + title: User Owner Entitlement + type: object + x-speakeasy-name-override: UserOwnerEntitlement + c1.api.user.v2.UserOwnerUser: + description: UserOwnerUser represents a user ownership source for a canonical User (a service account). + properties: + createdAt: + format: date-time + type: + - string + - "null" + roleSlug: + description: The roleSlug field. + type: string + user: + oneOf: + - $ref: '#/components/schemas/c1.api.user.v1.User' + - type: "null" + userId: + description: The userId field. + type: string + title: User Owner User + type: object + x-speakeasy-name-override: UserOwnerUser + c1.api.vault.v1.GroupAuthzVault: + description: GroupAuthzVault configures a vault that uses group-based authorization to control access to stored credentials. + title: Group Authz Vault + type: object + x-speakeasy-name-override: GroupAuthzVault + c1.api.vault.v1.MagicVault: + description: MagicVault configures a vault that grants time-limited credential access via magic links. + properties: + allowUnauthedViews: + description: Controls whether unauthenticated users can view credentials via a magic link. + type: boolean + allowedViews: + description: The maximum number of times a credential in this vault may be viewed. + format: uint32 + type: integer + title: Magic Vault + type: object + x-speakeasy-name-override: MagicVault + c1.api.vault.v1.Vault: + description: | + Vault represents an external secret storage integration used to store connector credentials securely. + + This message contains a oneof named vault. Only a single field of the following list may be set at a time: + - groupAuthzVault + - magicVault + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + credentialExpirationDuration: + format: duration + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A free-text description of the vault's purpose or configuration. + type: string + displayName: + description: The human-readable name of the vault. + type: string + groupAuthzVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' + - type: "null" + id: + description: The unique identifier of the vault. + type: string + magicVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Vault + type: object + x-speakeasy-entity: Vault + x-speakeasy-name-override: Vault + c1.api.vault.v1.VaultServiceCreateRequest: + description: | + VaultServiceCreateRequest is the request message for creating a new vault. + + This message contains a oneof named vault. Only a single field of the following list may be set at a time: + - groupAuthzVault + - magicVault + properties: + description: + description: A free-text description of the vault's purpose or configuration. + type: string + displayName: + description: The human-readable name for the new vault. + type: string + groupAuthzVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.GroupAuthzVault' + - type: "null" + magicVault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.MagicVault' + - type: "null" + ownerIds: + description: The IDs of users to assign as owners of this vault. + items: + type: string + type: + - array + - "null" + required: + - displayName + title: Vault Service Create Request + type: object + x-speakeasy-name-override: VaultServiceCreateRequest + c1.api.vault.v1.VaultServiceCreateResponse: + description: VaultServiceCreateResponse is the response message for creating a new vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Create Response + type: object + x-speakeasy-name-override: VaultServiceCreateResponse + c1.api.vault.v1.VaultServiceDeleteRequestInput: + description: VaultServiceDeleteRequest is the request message for deleting a vault. + title: Vault Service Delete Request + type: object + x-speakeasy-name-override: VaultServiceDeleteRequest + c1.api.vault.v1.VaultServiceDeleteResponse: + description: Empty response body. Status code indicates success. + title: Vault Service Delete Response + type: object + x-speakeasy-name-override: VaultServiceDeleteResponse + c1.api.vault.v1.VaultServiceGetResponse: + description: VaultServiceGetResponse is the response message containing the requested vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Get Response + type: object + x-speakeasy-name-override: VaultServiceGetResponse + c1.api.vault.v1.VaultServiceUpdateRequestInput: + description: The VaultServiceUpdateRequest message contains the vault object to update and a field mask to indicate which fields to update. + properties: + updateMask: + type: + - string + - "null" + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Update Request + type: object + x-speakeasy-name-override: VaultServiceUpdateRequest + c1.api.vault.v1.VaultServiceUpdateResponse: + description: VaultServiceUpdateResponse is the response message containing the updated vault. + properties: + vault: + oneOf: + - $ref: '#/components/schemas/c1.api.vault.v1.Vault' + - type: "null" + title: Vault Service Update Response + type: object + x-speakeasy-name-override: VaultServiceUpdateResponse + c1.api.webhooks.v1.Webhook: + description: The Webhook message. + properties: + callbackTimeout: + format: duration + type: + - string + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + deletedAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: An optional description of the webhook's purpose. + type: string + displayName: + description: The human-readable name of the webhook. + type: string + id: + description: The unique identifier of the webhook. + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + url: + description: The destination URL that receives event notification HTTP callbacks. + type: string + title: Webhook + type: object + x-speakeasy-entity: Webhook + x-speakeasy-name-override: WebhookEndpoint + c1.api.webhooks.v1.WebhookInstance: + description: The WebhookInstance message. + properties: + attempts: + description: The attempts field. + format: int32 + type: integer + completedAt: + format: date-time + readOnly: true + type: + - string + - "null" + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + expiresAt: + format: date-time + readOnly: true + type: + - string + - "null" + id: + description: The id field. + type: string + lastAttemptedAt: + format: date-time + readOnly: true + type: + - string + - "null" + source: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource' + - type: "null" + spec: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSpec' + - type: "null" + state: + description: The state field. + enum: + - WEBHOOK_STATE_UNSPECIFIED + - WEBHOOK_STATE_PENDING + - WEBHOOK_STATE_RUNNING + - WEBHOOK_STATE_ERROR + - WEBHOOK_STATE_WAITING_CALLBACK + - WEBHOOK_STATE_PROCESS_RESPONSE + - WEBHOOK_STATE_SUCCESS + - WEBHOOK_STATE_FATAL_ERROR + type: string + x-speakeasy-unknown-values: allow + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + webhookId: + description: The webhookId field. + type: string + title: Webhook Instance + type: object + x-speakeasy-name-override: WebhookInstance + c1.api.webhooks.v1.WebhookRef: + description: The WebhookRef message. + properties: + id: + description: The ID of the referenced webhook. + type: string + title: Webhook Ref + type: object + x-speakeasy-name-override: WebhookRef + c1.api.webhooks.v1.WebhookSource: + description: | + The WebhookSource message. + + This message contains a oneof named source. Only a single field of the following list may be set at a time: + - test + - policyPostAction + - approvalStep + - provisionStep + - workflowStep + properties: + approvalStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep' + - type: "null" + policyPostAction: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction' + - type: "null" + provisionStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep' + - type: "null" + test: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceTest' + - type: "null" + workflowStep: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep' + - type: "null" + title: Webhook Source + type: object + x-speakeasy-name-override: WebhookSource + c1.api.webhooks.v1.WebhookSource.WebhookSourceApprovalStep: + description: The WebhookSourceApprovalStep message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Approval Step + type: object + x-speakeasy-name-override: WebhookSourceApprovalStep + c1.api.webhooks.v1.WebhookSource.WebhookSourcePolicyPostAction: + description: The WebhookSourcePolicyPostAction message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Policy Post Action + type: object + x-speakeasy-name-override: WebhookSourcePolicyPostAction + c1.api.webhooks.v1.WebhookSource.WebhookSourceProvisionStep: + description: The WebhookSourceProvisionStep message. + properties: + ticketId: + description: The ticketId field. + type: string + title: Webhook Source Provision Step + type: object + x-speakeasy-name-override: WebhookSourceProvisionStep + c1.api.webhooks.v1.WebhookSource.WebhookSourceTest: + description: The WebhookSourceTest message. + title: Webhook Source Test + type: object + x-speakeasy-name-override: WebhookSourceTest + c1.api.webhooks.v1.WebhookSource.WebhookSourceWorkflowStep: + description: The WebhookSourceWorkflowStep message. + properties: + workflowExecutionId: + description: The workflowExecutionId field. + format: int64 + type: string + workflowStepId: + description: The workflowStepId field. + type: string + title: Webhook Source Workflow Step + type: object + x-speakeasy-name-override: WebhookSourceWorkflowStep + c1.api.webhooks.v1.WebhookSpec: + description: The WebhookSpec message. + properties: + destination: + description: The destination field. + type: string + title: Webhook Spec + type: object + x-speakeasy-name-override: WebhookSpec + c1.api.webhooks.v1.WebhooksSearchRequest: + description: The WebhooksSearchRequest message. + properties: + pageSize: + description: The maximum number of webhooks to return per page. + format: int32 + type: integer + pageToken: + description: The pagination token from a previous search response to fetch the next page. + type: string + query: + description: A text query to match against webhook names and descriptions. + type: string + refs: + description: Optional set of webhook references to restrict the search to specific webhooks. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookRef' + type: + - array + - "null" + title: Webhooks Search Request + type: object + x-speakeasy-name-override: WebhooksSearchRequest + c1.api.webhooks.v1.WebhooksSearchResponse: + description: The WebhooksSearchResponse message. + properties: + list: + description: The list of webhooks matching the search criteria. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Webhooks Search Response + type: object + x-speakeasy-name-override: WebhooksSearchResponse + c1.api.webhooks.v1.WebhooksServiceCreateRequest: + description: The WebhooksServiceCreateRequest message. + properties: + callbackTimeout: + format: duration + type: + - string + - "null" + description: + description: An optional description of the webhook's purpose. + type: string + displayName: + description: The human-readable name for the new webhook. + type: string + url: + description: The destination URL that will receive event notification HTTP callbacks. + type: string + required: + - displayName + - url + title: Webhooks Service Create Request + type: object + x-speakeasy-name-override: WebhooksServiceCreateRequest + c1.api.webhooks.v1.WebhooksServiceCreateResponse: + description: The WebhooksServiceCreateResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Create Response + type: object + x-speakeasy-name-override: WebhooksServiceCreateResponse + c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput: + description: The WebhooksServiceDeleteRequest message. + title: Webhooks Service Delete Request + type: object + x-speakeasy-name-override: WebhooksServiceDeleteRequest + c1.api.webhooks.v1.WebhooksServiceDeleteResponse: + description: Empty response body. Status code indicates success. + title: Webhooks Service Delete Response + type: object + x-speakeasy-name-override: WebhooksServiceDeleteResponse + c1.api.webhooks.v1.WebhooksServiceGetResponse: + description: The WebhooksServiceGetResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Get Response + type: object + x-speakeasy-name-override: WebhooksServiceGetResponse + c1.api.webhooks.v1.WebhooksServiceListResponse: + description: The WebhooksServiceListResponse message. + properties: + list: + description: The list of webhooks for the current page. + items: + $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + type: + - array + - "null" + nextPageToken: + description: A token to retrieve the next page of results, or empty if there are no more results. + type: string + title: Webhooks Service List Response + type: object + x-speakeasy-name-override: WebhooksServiceListResponse + c1.api.webhooks.v1.WebhooksServiceTestRequestInput: + description: The WebhooksServiceTestRequest message. + title: Webhooks Service Test Request + type: object + x-speakeasy-name-override: WebhooksServiceTestRequest + c1.api.webhooks.v1.WebhooksServiceTestResponse: + description: The WebhooksServiceTestResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhookInstance' + - type: "null" + title: Webhooks Service Test Response + type: object + x-speakeasy-name-override: WebhooksServiceTestResponse + c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput: + description: The WebhooksServiceUpdateRequest message contains the webhook object to update and a field mask to indicate which fields to update. It uses URL value for input. + properties: + updateMask: + type: + - string + - "null" + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Update Request + type: object + x-speakeasy-name-override: WebhooksServiceUpdateRequest + c1.api.webhooks.v1.WebhooksServiceUpdateResponse: + description: The WebhooksServiceUpdateResponse message. + properties: + webhook: + oneOf: + - $ref: '#/components/schemas/c1.api.webhooks.v1.Webhook' + - type: "null" + title: Webhooks Service Update Response + type: object + x-speakeasy-name-override: WebhooksServiceUpdateResponse + c1.api.workload_federation.v1.OIDCSettings: + description: |- + OIDCSettings is the kind-specific configuration block for classic OIDC + providers (GitHub Actions, GitLab CI, HCP Terraform, AWS IAM Outbound, + any CUSTOM provider). Empty for now; future fields like custom_jwks_url, + audience overrides, and required_claims land here. + title: Oidc Settings + type: object + x-speakeasy-name-override: OIDCSettings + c1.api.workload_federation.v1.SPIFFESettings: + description: |- + SPIFFESettings is the kind-specific configuration block for SPIFFE + trust-domain providers (issuer_url = spiffe://). + properties: + bundleEndpointUrl: + description: |- + HTTPS URL of the JWKS endpoint serving the trust domain's signing keys. + Required: the spiffe:// scheme has no discovery mechanism. + Typically the SPIRE OIDC Discovery Provider's /keys endpoint. + + Mutable: updates re-validate the new URL by fetching its JWKS before + persisting; the issuer (trust domain) itself remains immutable. + type: string + title: Spiffe Settings + type: object + x-speakeasy-name-override: SPIFFESettings + c1.api.workload_federation.v1.TestTokenStepResult: + description: TestTokenStepResult represents the result of a single validation step. + properties: + actual: + description: Actual value from the token. + type: string + detail: + description: Human-readable detail message. + type: string + expected: + description: Expected value (for comparison steps). + type: string + passed: + description: Whether this step passed. + type: boolean + skipped: + description: Whether this step was skipped (e.g., CIDR check when no allowlist configured). + type: boolean + stepName: + description: Step name for display (e.g., "JWT decode", "Issuer match"). + type: string + title: Test Token Step Result + type: object + x-speakeasy-name-override: TestTokenStepResult + c1.api.workload_federation.v1.WorkloadFederationProvider: + description: | + WorkloadFederationProvider represents a tenant-level workload identity + issuer registration. Two issuer schemes are supported: + + - https://... classic OIDC issuer; `settings.oidc` MUST be set. + - spiffe://... SPIFFE trust-domain URI; `settings.spiffe` MUST be set. + + The (well_known_provider, issuer_url scheme, settings oneof) tuple is a + tri-invariant: SPIFFE wkp ⟺ spiffe:// issuer ⟺ settings.spiffe set; any + other wkp ⟺ https:// issuer ⟺ settings.oidc set. Issuer URLs are unique + within tenant. + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oidc + - spiffe + properties: + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A description of what this provider is for. + type: string + disabled: + description: Whether the provider is disabled. Disabled providers reject all token exchanges. + type: boolean + displayName: + description: The display name of the provider. + type: string + id: + description: The unique ID of the provider. + readOnly: true + type: string + issuerUrl: + description: |- + Canonical issuer URL. https:// for OIDC providers, spiffe:// for SPIFFE + trust domains. Unique within tenant. Immutable after creation. + readOnly: true + type: string + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' + - type: "null" + spiffe: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' + - type: "null" + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + wellKnownProvider: + description: |- + Well-known provider type. Drives UX (wizard presets, docs, icons). + Set at creation time, immutable. + enum: + - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED + - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM + - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS + - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI + - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM + - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND + - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE + readOnly: true + type: string + x-speakeasy-unknown-values: allow + title: Workload Federation Provider + type: object + x-speakeasy-name-override: WorkloadFederationProvider + c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest: + description: | + The WorkloadFederationServiceCreateProviderRequest message. + + This message contains a oneof named settings. Only a single field of the following list may be set at a time: + - oidc + - spiffe + properties: + description: + description: A description of what this provider is for. + type: string + displayName: + description: The display name for the new provider. + type: string + issuerUrl: + description: |- + The issuer URL. For OIDC providers, this is an HTTPS URL validated via + OIDC discovery. For SPIFFE providers, this is the SPIFFE trust-domain URI + (e.g., spiffe://prod.example.com). Normalized on write: lowercase + scheme/host, no trailing slash. Unique within tenant. + type: string + oidc: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.OIDCSettings' + - type: "null" + spiffe: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.SPIFFESettings' + - type: "null" + wellKnownProvider: + description: |- + Well-known provider type. Required -- UNSPECIFIED is rejected. + When set to a named source, the backend validates issuer_url consistency. + SPIFFE wkp requires `settings.spiffe`; all other wkp values require + `settings.oidc`. + enum: + - WELL_KNOWN_WORKLOAD_PROVIDER_UNSPECIFIED + - WELL_KNOWN_WORKLOAD_PROVIDER_CUSTOM + - WELL_KNOWN_WORKLOAD_PROVIDER_GITHUB_ACTIONS + - WELL_KNOWN_WORKLOAD_PROVIDER_GITLAB_CI + - WELL_KNOWN_WORKLOAD_PROVIDER_HCP_TERRAFORM + - WELL_KNOWN_WORKLOAD_PROVIDER_AWS_IAM_OUTBOUND + - WELL_KNOWN_WORKLOAD_PROVIDER_SPIFFE + type: string + x-speakeasy-unknown-values: allow + title: Workload Federation Service Create Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse: + description: The WorkloadFederationServiceCreateProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Create Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput: + description: The WorkloadFederationServiceCreateTrustRequest message. + properties: + allowSourceCidrs: + description: |- + IP allowlist for token exchange requests matching this trust. + Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs. + items: + type: string + type: + - array + - "null" + conditionExpression: + description: |- + CEL expression evaluated against JWT claims. Must return bool. + Compiled and validated before storage. + type: string + description: + description: A description of what this trust policy matches. + type: string + displayName: + description: The display name for the trust. + type: string + passthroughClaims: + description: JWT claim names from the subject token to copy into the issued C1 token. + items: + type: string + type: + - array + - "null" + providerId: + description: The provider this trust references. + type: string + scopedRoleIds: + description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + items: + type: string + type: + - array + - "null" + title: Workload Federation Service Create Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse: + description: The WorkloadFederationServiceCreateTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Create Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceCreateTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput: + description: The WorkloadFederationServiceDeleteProviderRequest message. + title: Workload Federation Service Delete Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse: + description: The WorkloadFederationServiceDeleteProviderResponse message. + title: Workload Federation Service Delete Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput: + description: The WorkloadFederationServiceDeleteTrustRequest message. + title: Workload Federation Service Delete Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse: + description: The WorkloadFederationServiceDeleteTrustResponse message. + title: Workload Federation Service Delete Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceDeleteTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse: + description: The WorkloadFederationServiceGetProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Get Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceGetProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse: + description: The WorkloadFederationServiceGetTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Get Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceGetTrustResponse + c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse: + description: The WorkloadFederationServiceListProvidersResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service List Providers Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceListProvidersResponse + c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse: + description: The WorkloadFederationServiceListTrustsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service List Trusts Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceListTrustsResponse + c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest: + description: The WorkloadFederationServiceSearchTrustsRequest message. + properties: + pageSize: + description: The pageSize field. + format: int32 + type: integer + pageToken: + description: The pageToken field. + type: string + providerId: + description: 'Optional: filter trusts by provider ID.' + type: string + query: + description: 'Optional: full-text search on trust display name and description.' + type: string + servicePrincipalId: + description: 'Optional: filter trusts by service principal ID.' + type: string + title: Workload Federation Service Search Trusts Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsRequest + c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse: + description: The WorkloadFederationServiceSearchTrustsResponse message. + properties: + list: + description: The list field. + items: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + type: + - array + - "null" + nextPageToken: + description: The nextPageToken field. + type: string + title: Workload Federation Service Search Trusts Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceSearchTrustsResponse + c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest: + description: The WorkloadFederationServiceTestCELRequest message. + properties: + claimsJson: + description: |- + The claims to evaluate against, as a JSON string. + Parsed into map[string]any for CEL evaluation. + type: string + expression: + description: The CEL expression to evaluate. Must return bool. + type: string + title: Workload Federation Service Test Cel Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestCELRequest + c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse: + description: The WorkloadFederationServiceTestCELResponse message. + properties: + error: + description: Error message if compilation or evaluation failed. + type: string + expression: + description: The expression that was evaluated (echo back). + type: string + matched: + description: Whether the expression matched (returned true). + type: boolean + title: Workload Federation Service Test Cel Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestCELResponse + c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput: + description: The WorkloadFederationServiceTestTokenRequest message. + properties: + sourceIp: + description: |- + Optional: override source IP for CIDR testing. + If empty, uses the request's source IP. + Accepts IPv4 (e.g. 10.0.0.5) or IPv6 (e.g. 2001:db8::1) addresses, optionally with a CIDR prefix. + type: string + subjectToken: + description: The raw JWT to validate (the subject_token from a CI job). + type: string + title: Workload Federation Service Test Token Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestTokenRequest + c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse: + description: The WorkloadFederationServiceTestTokenResponse message. + properties: + audienceValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + celEvaluation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + cidrCheck: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + decodedClaimsJson: + description: |- + The decoded JWT claims (best-effort, even if signature fails). + Returned as JSON string for display. + type: string + issuerMatch: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + jwtDecode: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + overallResult: + description: 'Overall result: true only if ALL steps passed.' + type: boolean + signatureValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + subjectValidation: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + tokenFreshness: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.TestTokenStepResult' + - type: "null" + title: Workload Federation Service Test Token Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceTestTokenResponse + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput: + description: The WorkloadFederationServiceUpdateProviderRequest message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + updateMask: + type: + - string + - "null" + title: Workload Federation Service Update Provider Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderRequest + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse: + description: The WorkloadFederationServiceUpdateProviderResponse message. + properties: + provider: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationProvider' + - type: "null" + title: Workload Federation Service Update Provider Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateProviderResponse + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput: + description: The WorkloadFederationServiceUpdateTrustRequest message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + updateMask: + type: + - string + - "null" + title: Workload Federation Service Update Trust Request + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustRequest + c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse: + description: The WorkloadFederationServiceUpdateTrustResponse message. + properties: + trust: + oneOf: + - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationTrust' + - type: "null" + title: Workload Federation Service Update Trust Response + type: object + x-speakeasy-name-override: WorkloadFederationServiceUpdateTrustResponse + c1.api.workload_federation.v1.WorkloadFederationTrust: + description: |- + WorkloadFederationTrust represents a per-SP trust policy that references + a tenant-level provider and defines a CEL condition for claim matching. + properties: + allowSourceCidrs: + description: IP allowlist for token exchange requests matching this trust. + items: + type: string + type: + - array + - "null" + clientId: + description: |- + The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). + Used as the client_id parameter in RFC 8693 token exchange requests. + readOnly: true + type: string + conditionExpression: + description: |- + CEL expression evaluated against JWT claims. Must return bool. + Example: claims.sub.startsWith("repo:acme/infra:") && claims.environment == "production" + type: string + createdAt: + format: date-time + readOnly: true + type: + - string + - "null" + description: + description: A description of what this trust policy matches. + type: string + disabled: + description: Whether the trust is disabled. + type: boolean + displayName: + description: The display name of the trust. + type: string + passthroughClaims: + description: |- + JWT claim names from the subject token to copy into the issued C1 token. + Values are placed in the "c1wfc" claim as a map[string]string. + Only string-valued claims are copied; non-string claims are silently skipped. + Example: ["repository", "repository_owner", "job_workflow_ref"] + items: + type: string + type: + - array + - "null" + providerId: + description: The provider ID this trust references. Immutable after creation. + readOnly: true + type: string + scopedRoleIds: + description: Scoped role IDs. Effective permissions = min(SP roles, trust.scoped_role_ids). + items: + type: string + type: + - array + - "null" + servicePrincipalId: + description: The service principal user ID this trust belongs to. + readOnly: true + type: string + updatedAt: + format: date-time + readOnly: true + type: + - string + - "null" + title: Workload Federation Trust + type: object + x-speakeasy-name-override: WorkloadFederationTrust + c1.mcp.role_mining.v1.AccessProfileMatch: + description: The AccessProfileMatch message. + properties: + catalogDisplayName: + description: The catalogDisplayName field. + type: string + catalogId: + description: The catalogId field. + type: string + matchType: + description: The matchType field. + enum: + - ACCESS_PROFILE_MATCH_TYPE_UNSPECIFIED + - ACCESS_PROFILE_MATCH_TYPE_EXACT + - ACCESS_PROFILE_MATCH_TYPE_SUPERSET + - ACCESS_PROFILE_MATCH_TYPE_PARTIAL + type: string + x-speakeasy-unknown-values: allow + missingEntitlements: + description: The missingEntitlements field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + overlapRatio: + description: The overlapRatio field. + type: number + title: Access Profile Match + type: object + x-speakeasy-name-override: AccessProfileMatch + c1.mcp.role_mining.v1.AttributeFacet: + description: AttributeFacet represents a filterable user profile attribute with its available values. + properties: + attribute: + description: The attribute field. + type: string + displayName: + description: The displayName field. + type: string + values: + description: The values field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.AttributeValue' + type: + - array + - "null" + title: Attribute Facet + type: object + x-speakeasy-name-override: AttributeFacet + c1.mcp.role_mining.v1.AttributeValue: + description: AttributeValue represents a single value within a facet. + properties: + displayName: + description: The displayName field. + type: string + userCount: + description: The userCount field. + format: int32 + type: integer + value: + description: The value field. + type: string + title: Attribute Value + type: object + x-speakeasy-name-override: RoleMiningAttributeValue + c1.mcp.role_mining.v1.CohortEntitlement: + description: The CohortEntitlement message. + properties: + appDisplayName: + description: The appDisplayName field. + type: string + appId: + description: The appId field. + type: string + appResourceDisplayName: + description: The appResourceDisplayName field. + type: string + appResourceTypeDisplayName: + description: The appResourceTypeDisplayName field. + type: string + coverage: + description: The coverage field. + type: number + entitlementDisplayName: + description: The entitlementDisplayName field. + type: string + entitlementId: + description: The entitlementId field. + type: string + grantedCount: + description: The grantedCount field. + format: int32 + type: integer + riskLevelValueId: + description: The riskLevelValueId field. + type: string + title: Cohort Entitlement + type: object + x-speakeasy-name-override: CohortEntitlement + c1.mcp.role_mining.v1.EntitlementCluster: + description: The EntitlementCluster message. + properties: + avgCoverage: + description: The avgCoverage field. + type: number + avgSimilarity: + description: The avgSimilarity field. + type: number + entitlements: + description: The entitlements field. + items: + $ref: '#/components/schemas/c1.mcp.role_mining.v1.CohortEntitlement' + type: + - array + - "null" + userCount: + description: The userCount field. + format: int32 + type: integer + title: Entitlement Cluster + type: object + x-speakeasy-name-override: EntitlementCluster + c1.mcp.role_mining.v1.ProfileFilter: + description: |- + ProfileFilter defines a filter on a user profile attribute. + Use GetOrgOverview to discover available attribute keys and their values. + properties: + attribute: + description: The attribute field. + type: string + values: + description: The values field. + items: + type: string + type: + - array + - "null" + title: Profile Filter + type: object + x-speakeasy-name-override: ProfileFilter + c1.webhooks.v1.Body: + description: The Body message. + properties: + callbackUrl: + description: |- + If your receiver returns HTTP Status Code 202 Accepted, it MUST send its resposne to this URL as a POST + message body. + + If your receiver returns any other status code, it is expected to not use the callback url. + + This value will match the "Webhook-Callback-Url" header. + type: string + event: + description: |- + The type of event that triggered this Webhook. + + This value will match the "Webhook-Event" header. + + The value will be one of: + - "c1.webhooks.v1.PayloadTest" + - "c1.webhooks.v1.PayloadPolicyApprovalStep" + - "c1.webhooks.v1.PayloadPolicyPostAction" + - "c1.webhooks.v1.PayloadProvisionStep" + type: string + payload: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: + - object + - "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook body will use a different string. + + This value will match the "Webhook-Version" header. + type: string + webhookId: + description: |- + Unique ID for this Webhook. Your receiver should only process this ID once. + + This value will match the "Webhook-Id" header. + type: string + title: Body + type: object + x-speakeasy-include: true + x-speakeasy-name-override: Body + c1.webhooks.v1.PayloadPolicyApprovalStep: + description: The PayloadPolicyApprovalStep message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Policy Approval Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadPolicyApprovalStep + c1.webhooks.v1.PayloadPolicyPostAction: + description: The PayloadPolicyPostAction message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Policy Post Action + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadPolicyPostAction + c1.webhooks.v1.PayloadProvisionStep: + description: The PayloadProvisionStep message. + properties: + expanded: + description: List of serialized related objects. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + taskView: + oneOf: + - $ref: '#/components/schemas/c1.api.task.v1.TaskView' + - type: "null" + title: Payload Provision Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadProvisionStep + c1.webhooks.v1.PayloadTest: + description: The PayloadTest message. + title: Payload Test + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadTest + c1.webhooks.v1.PayloadWorkflowStep: + description: The PayloadWorkflowStep message. + properties: + context: + additionalProperties: true + type: + - object + - "null" + workflowExecutionId: + description: The workflow execution ID + format: int64 + type: string + workflowExecutionStepId: + description: The workflow execution step ID + type: string + workflowId: + description: The workflow template ID + type: string + title: Payload Workflow Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: PayloadWorkflowStep + c1.webhooks.v1.ResponsePolicyApprovalStep: + description: | + The ResponsePolicyApprovalStep message. + + This message contains a oneof named action. Only a single field of the following list may be set at a time: + - approve + - deny + - reassign + - replacePolicy + properties: + approve: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove' + - type: "null" + deny: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny' + - type: "null" + reassign: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign' + - type: "null" + replacePolicy: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy' + - type: "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Policy Approval Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponsePolicyApprovalStep + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalReplacePolicy: + description: The ResponsePolicyApprovalReplacePolicy message. + properties: + comment: + description: The comment field. + type: string + policySteps: + description: The policySteps field. + items: + $ref: '#/components/schemas/c1.api.policy.v1.PolicyStep' + type: + - array + - "null" + title: Response Policy Approval Replace Policy + type: object + x-speakeasy-name-override: ResponsePolicyApprovalReplacePolicy + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepApprove: + description: The ResponsePolicyApprovalStepApprove message. + properties: + comment: + description: optional comment + type: string + title: Response Policy Approval Step Approve + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepApprove + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepDeny: + description: The ResponsePolicyApprovalStepDeny message. + properties: + comment: + description: optional comment + type: string + title: Response Policy Approval Step Deny + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepDeny + c1.webhooks.v1.ResponsePolicyApprovalStep.ResponsePolicyApprovalStepReassign: + description: The ResponsePolicyApprovalStepReassign message. + properties: + comment: + description: optional comment + type: string + newStepUserIds: + description: The newStepUserIds field. + items: + type: string + type: + - array + - "null" + title: Response Policy Approval Step Reassign + type: object + x-speakeasy-name-override: ResponsePolicyApprovalStepReassign + c1.webhooks.v1.ResponsePolicyPostAction: + description: The ResponsePolicyPostAction message. + properties: + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Policy Post Action + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponsePolicyPostAction + c1.webhooks.v1.ResponseProvisionStep: + description: | + The ResponseProvisionStep message. + + This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - complete + - errored + properties: + complete: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete' + - type: "null" + errored: + oneOf: + - $ref: '#/components/schemas/c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored' + - type: "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Provision Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseProvisionStep + c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepComplete: + description: The ResponseProvisionStepComplete message. + properties: + comment: + description: optional comment + type: string + title: Response Provision Step Complete + type: object + x-speakeasy-name-override: ResponseProvisionStepComplete + c1.webhooks.v1.ResponseProvisionStep.ResponseProvisionStepErrored: + description: The ResponseProvisionStepErrored message. + properties: + comment: + description: optional comment + type: string + title: Response Provision Step Errored + type: object + x-speakeasy-name-override: ResponseProvisionStepErrored + c1.webhooks.v1.ResponseTest: + description: The ResponseTest message. + properties: + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Test + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseTest + c1.webhooks.v1.ResponseWorkflowStep: + description: The ResponseWorkflowStep message. + properties: + context: + additionalProperties: true + type: + - object + - "null" + version: + description: |- + version contains the constant value "v1". Future versions of the Webhook Response + will use a different string. + type: string + title: Response Workflow Step + type: object + x-speakeasy-include: true + x-speakeasy-name-override: ResponseWorkflowStep + google.rpc.Status: + description: |- + The `Status` type defines a logical error model that is suitable for + different programming environments, including REST APIs and RPC APIs. It is + used by [gRPC](https://github.com/grpc). Each `Status` message contains + three pieces of data: error code, error message, and error details. + + You can find out more about this error model and how to work with it in the + [API Design Guide](https://cloud.google.com/apis/design/errors). + properties: + code: + description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. + format: int32 + type: integer + details: + description: |- + A list of messages that carry the error details. There is a common set of + message types for APIs to use. + items: + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + properties: + '@type': + description: The type of the serialized message. + type: string + type: object + type: + - array + - "null" + message: + description: |- + A developer-facing error message, which should be in English. Any + user-facing error message should be localized and sent in the + [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. + type: string + title: Status + type: object + x-speakeasy-name-override: Status + validate.AnyRules: + description: |- + AnyRules describe constraints applied exclusively to the + `google.protobuf.Any` well-known type + properties: + in: + description: |- + In specifies that this field's `type_url` must be equal to one of the + specified values. + items: + type: string + type: + - array + - "null" + notIn: + description: |- + NotIn specifies that this field's `type_url` must not be equal to any of + the specified values. + items: + type: string + type: + - array + - "null" + required: + description: Required specifies that this field must be set + type: boolean + title: Any Rules + type: object + x-speakeasy-name-override: AnyRules + validate.BoolRules: + description: BoolRules describes the constraints applied to `bool` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: boolean + title: Bool Rules + type: object + x-speakeasy-name-override: BoolRules + validate.BytesRules: + description: | + BytesRules describe the constraints applied to `bytes` values + + This message contains a oneof named well_known. Only a single field of the following list may be set at a time: + - ip + - ipv4 + - ipv6 + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: base64 + type: string + contains: + description: |- + Contains specifies that this field must have the specified bytes + anywhere in the string. + format: base64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: base64 + type: string + type: + - array + - "null" + ip: + description: |- + Ip specifies that the field must be a valid IP (v4 or v6) address in + byte format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + ipv4: + description: |- + Ipv4 specifies that the field must be a valid IPv4 address in byte + format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + ipv6: + description: |- + Ipv6 specifies that the field must be a valid IPv6 address in byte + format + This field is part of the `well_known` oneof. + See the documentation for `validate.BytesRules` for more details. + type: + - boolean + - "null" + len: + description: Len specifies that this field must be the specified number of bytes + format: uint64 + type: string + maxLen: + description: |- + MaxLen specifies that this field must be the specified number of bytes + at a maximum + format: uint64 + type: string + minLen: + description: |- + MinLen specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: base64 + type: string + type: + - array + - "null" + pattern: + description: |- + Pattern specifes that this field must match against the specified + regular expression (RE2 syntax). The included expression should elide + any delimiters. + type: string + prefix: + description: |- + Prefix specifies that this field must have the specified bytes at the + beginning of the string. + format: base64 + type: string + suffix: + description: |- + Suffix specifies that this field must have the specified bytes at the + end of the string. + format: base64 + type: string + title: Bytes Rules + type: object + x-speakeasy-name-override: BytesRules + validate.DoubleRules: + description: DoubleRules describes the constraints applied to `double` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: number + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + type: number + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + type: number + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + type: number + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + type: number + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + title: Double Rules + type: object + x-speakeasy-name-override: DoubleRules + validate.DurationRules: + description: |- + DurationRules describe the constraints applied exclusively to the + `google.protobuf.Duration` well-known type + properties: + const: + format: duration + type: + - string + - "null" + gt: + format: duration + type: + - string + - "null" + gte: + format: duration + type: + - string + - "null" + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: duration + type: string + type: + - array + - "null" + lt: + format: duration + type: + - string + - "null" + lte: + format: duration + type: + - string + - "null" + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: duration + type: string + type: + - array + - "null" + required: + description: Required specifies that this field must be set + type: boolean + title: Duration Rules + type: object + x-speakeasy-name-override: DurationRules + validate.EnumRules: + description: EnumRules describe the constraints applied to enum values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + definedOnly: + description: |- + DefinedOnly specifies that this field must be only one of the defined + values for this enum, failing on any undefined value. + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: Enum Rules + type: object + x-speakeasy-name-override: EnumRules + validate.FieldRules: + description: | + FieldRules encapsulates the rules for each type of field. Depending on the + field, the correct set should be used to ensure proper validations. + + This message contains a oneof named type. Only a single field of the following list may be set at a time: + - float + - double + - int32 + - int64 + - uint32 + - uint64 + - sint32 + - sint64 + - fixed32 + - fixed64 + - sfixed32 + - sfixed64 + - bool + - string + - bytes + - enum + - repeated + - map + - any + - duration + - timestamp + properties: + any: + oneOf: + - $ref: '#/components/schemas/validate.AnyRules' + - type: "null" + bool: + oneOf: + - $ref: '#/components/schemas/validate.BoolRules' + - type: "null" + bytes: + oneOf: + - $ref: '#/components/schemas/validate.BytesRules' + - type: "null" + double: + oneOf: + - $ref: '#/components/schemas/validate.DoubleRules' + - type: "null" + duration: + oneOf: + - $ref: '#/components/schemas/validate.DurationRules' + - type: "null" + enum: + oneOf: + - $ref: '#/components/schemas/validate.EnumRules' + - type: "null" + fixed32: + oneOf: + - $ref: '#/components/schemas/validate.Fixed32Rules' + - type: "null" + fixed64: + oneOf: + - $ref: '#/components/schemas/validate.Fixed64Rules' + - type: "null" + float: + oneOf: + - $ref: '#/components/schemas/validate.FloatRules' + - type: "null" + int32: + oneOf: + - $ref: '#/components/schemas/validate.Int32Rules' + - type: "null" + int64: + oneOf: + - $ref: '#/components/schemas/validate.Int64Rules' + - type: "null" + map: + oneOf: + - $ref: '#/components/schemas/validate.MapRules' + - type: "null" + message: + oneOf: + - $ref: '#/components/schemas/validate.MessageRules' + - type: "null" + repeated: + oneOf: + - $ref: '#/components/schemas/validate.RepeatedRules' + - type: "null" + sfixed32: + oneOf: + - $ref: '#/components/schemas/validate.SFixed32Rules' + - type: "null" + sfixed64: + oneOf: + - $ref: '#/components/schemas/validate.SFixed64Rules' + - type: "null" + sint32: + oneOf: + - $ref: '#/components/schemas/validate.SInt32Rules' + - type: "null" + sint64: + oneOf: + - $ref: '#/components/schemas/validate.SInt64Rules' + - type: "null" + string: + oneOf: + - $ref: '#/components/schemas/validate.StringRules' + - type: "null" + timestamp: + oneOf: + - $ref: '#/components/schemas/validate.TimestampRules' + - type: "null" + uint32: + oneOf: + - $ref: '#/components/schemas/validate.UInt32Rules' + - type: "null" + uint64: + oneOf: + - $ref: '#/components/schemas/validate.UInt64Rules' + - type: "null" + title: Field Rules + type: object + x-speakeasy-name-override: FieldRules + validate.Fixed32Rules: + description: Fixed32Rules describes the constraints applied to `fixed32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + title: Fixed 32 Rules + type: object + x-speakeasy-name-override: Fixed32Rules + validate.Fixed64Rules: + description: Fixed64Rules describes the constraints applied to `fixed64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + title: Fixed 64 Rules + type: object + x-speakeasy-name-override: Fixed64Rules + validate.FloatRules: + description: FloatRules describes the constraints applied to `float` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + type: number + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + type: number + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + type: number + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + type: number + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + type: number + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: number + type: + - array + - "null" + title: Float Rules + type: object + x-speakeasy-name-override: FloatRules + validate.Int32Rules: + description: Int32Rules describes the constraints applied to `int32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: Int 32 Rules + type: object + x-speakeasy-name-override: Int32Rules + validate.Int64Rules: + description: Int64Rules describes the constraints applied to `int64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: Int 64 Rules + type: object + x-speakeasy-name-override: Int64Rules + validate.MapRules: + description: MapRules describe the constraints applied to `map` values + properties: + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + keys: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + maxPairs: + description: |- + MaxPairs specifies that this field must have the specified number of + KVs at a maximum + format: uint64 + type: string + minPairs: + description: |- + MinPairs specifies that this field must have the specified number of + KVs at a minimum + format: uint64 + type: string + noSparse: + description: |- + NoSparse specifies values in this field cannot be unset. This only + applies to map's with message value types. + type: boolean + values: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + title: Map Rules + type: object + x-speakeasy-name-override: MapRules + validate.MessageRules: + description: |- + MessageRules describe the constraints applied to embedded message values. + For message-type fields, validation is performed recursively. + properties: + required: + description: Required specifies that this field must be set + type: boolean + skip: + description: |- + Skip specifies that the validation rules of this field should not be + evaluated + type: boolean + title: Message Rules + type: object + x-speakeasy-name-override: MessageRules + validate.RepeatedRules: + description: RepeatedRules describe the constraints applied to `repeated` values + properties: + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + items: + oneOf: + - $ref: '#/components/schemas/validate.FieldRules' + - type: "null" + maxItems: + description: |- + MaxItems specifies that this field must have the specified number of + items at a maximum + format: uint64 + type: string + minItems: + description: |- + MinItems specifies that this field must have the specified number of + items at a minimum + format: uint64 + type: string + unique: + description: |- + Unique specifies that all elements in this field must be unique. This + contraint is only applicable to scalar and enum types (messages are not + supported). + type: boolean + title: Repeated Rules + type: object + x-speakeasy-name-override: RepeatedRules + validate.SFixed32Rules: + description: SFixed32Rules describes the constraints applied to `sfixed32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: S Fixed 32 Rules + type: object + x-speakeasy-name-override: SFixed32Rules + validate.SFixed64Rules: + description: SFixed64Rules describes the constraints applied to `sfixed64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: S Fixed 64 Rules + type: object + x-speakeasy-name-override: SFixed64Rules + validate.SInt32Rules: + description: SInt32Rules describes the constraints applied to `sint32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int32 + type: integer + type: + - array + - "null" + title: S Int 32 Rules + type: object + x-speakeasy-name-override: SInt32Rules + validate.SInt64Rules: + description: SInt64Rules describes the constraints applied to `sint64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: int64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: int64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: int64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: int64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: int64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: int64 + type: string + type: + - array + - "null" + title: S Int 64 Rules + type: object + x-speakeasy-name-override: SInt64Rules + validate.StringRules: + description: | + StringRules describe the constraints applied to `string` values + + This message contains a oneof named well_known. Only a single field of the following list may be set at a time: + - email + - hostname + - ip + - ipv4 + - ipv6 + - uri + - uriRef + - address + - uuid + - wellKnownRegex + properties: + address: + description: |- + Address specifies that the field must be either a valid hostname as + defined by RFC 1034 (which does not support internationalized domain + names or IDNs), or it can be a valid IP (v4 or v6). + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + const: + description: Const specifies that this field must be exactly the specified value + type: string + contains: + description: |- + Contains specifies that this field must have the specified substring + anywhere in the string. + type: string + email: + description: |- + Email specifies that the field must be a valid email address as + defined by RFC 5322 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + hostname: + description: |- + Hostname specifies that the field must be a valid hostname as + defined by RFC 1034. This constraint does not support + internationalized domain names (IDNs). + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + type: string + type: + - array + - "null" + ip: + description: |- + Ip specifies that the field must be a valid IP (v4 or v6) address. + Valid IPv6 addresses should not include surrounding square brackets. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ipv4: + description: |- + Ipv4 specifies that the field must be a valid IPv4 address. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + ipv6: + description: |- + Ipv6 specifies that the field must be a valid IPv6 address. Valid + IPv6 addresses should not include surrounding square brackets. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + len: + description: |- + Len specifies that this field must be the specified number of + characters (Unicode code points). Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + lenBytes: + description: |- + LenBytes specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + maxBytes: + description: |- + MaxBytes specifies that this field must be the specified number of bytes + at a maximum + format: uint64 + type: string + maxLen: + description: |- + MaxLen specifies that this field must be the specified number of + characters (Unicode code points) at a maximum. Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + minBytes: + description: |- + MinBytes specifies that this field must be the specified number of bytes + at a minimum + format: uint64 + type: string + minLen: + description: |- + MinLen specifies that this field must be the specified number of + characters (Unicode code points) at a minimum. Note that the number of + characters may differ from the number of bytes in the string. + format: uint64 + type: string + notContains: + description: |- + NotContains specifies that this field cannot have the specified substring + anywhere in the string. + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + type: string + type: + - array + - "null" + pattern: + description: |- + Pattern specifes that this field must match against the specified + regular expression (RE2 syntax). The included expression should elide + any delimiters. + type: string + prefix: + description: |- + Prefix specifies that this field must have the specified substring at + the beginning of the string. + type: string + strict: + description: |- + This applies to regexes HTTP_HEADER_NAME and HTTP_HEADER_VALUE to enable + strict header validation. + By default, this is true, and HTTP header validations are RFC-compliant. + Setting to false will enable a looser validations that only disallows + \r\n\0 characters, which can be used to bypass header matching rules. + type: boolean + suffix: + description: |- + Suffix specifies that this field must have the specified substring at + the end of the string. + type: string + uri: + description: |- + Uri specifies that the field must be a valid, absolute URI as defined + by RFC 3986 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + uriRef: + description: |- + UriRef specifies that the field must be a valid URI as defined by RFC + 3986 and may be relative or absolute. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + uuid: + description: |- + Uuid specifies that the field must be a valid UUID as defined by + RFC 4122 + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + type: + - boolean + - "null" + wellKnownRegex: + description: |- + WellKnownRegex specifies a common well known pattern defined as a regex. + This field is part of the `well_known` oneof. + See the documentation for `validate.StringRules` for more details. + enum: + - UNKNOWN + - HTTP_HEADER_NAME + - HTTP_HEADER_VALUE + type: + - string + - "null" + x-speakeasy-unknown-values: allow + title: String Rules + type: object + x-speakeasy-name-override: StringRules + validate.TimestampRules: + description: |- + TimestampRules describe the constraints applied exclusively to the + `google.protobuf.Timestamp` well-known type + properties: + const: + format: date-time + type: + - string + - "null" + gt: + format: date-time + type: + - string + - "null" + gtNow: + description: |- + GtNow specifies that this must be greater than the current time. GtNow + can only be used with the Within rule. + type: boolean + gte: + format: date-time + type: + - string + - "null" + lt: + format: date-time + type: + - string + - "null" + ltNow: + description: |- + LtNow specifies that this must be less than the current time. LtNow + can only be used with the Within rule. + type: boolean + lte: + format: date-time + type: + - string + - "null" + required: + description: Required specifies that this field must be set + type: boolean + within: + format: duration + type: + - string + - "null" + title: Timestamp Rules + type: object + x-speakeasy-name-override: TimestampRules + validate.UInt32Rules: + description: UInt32Rules describes the constraints applied to `uint32` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint32 + type: integer + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint32 + type: integer + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint32 + type: integer + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint32 + type: integer + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint32 + type: integer + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint32 + type: integer + type: + - array + - "null" + title: U Int 32 Rules + type: object + x-speakeasy-name-override: UInt32Rules + validate.UInt64Rules: + description: UInt64Rules describes the constraints applied to `uint64` values + properties: + const: + description: Const specifies that this field must be exactly the specified value + format: uint64 + type: string + gt: + description: |- + Gt specifies that this field must be greater than the specified value, + exclusive. If the value of Gt is larger than a specified Lt or Lte, the + range is reversed. + format: uint64 + type: string + gte: + description: |- + Gte specifies that this field must be greater than or equal to the + specified value, inclusive. If the value of Gte is larger than a + specified Lt or Lte, the range is reversed. + format: uint64 + type: string + ignoreEmpty: + description: |- + IgnoreEmpty specifies that the validation rules of this field should be + evaluated only if the field is not empty + type: boolean + in: + description: |- + In specifies that this field must be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + lt: + description: |- + Lt specifies that this field must be less than the specified value, + exclusive + format: uint64 + type: string + lte: + description: |- + Lte specifies that this field must be less than or equal to the + specified value, inclusive + format: uint64 + type: string + notIn: + description: |- + NotIn specifies that this field cannot be equal to one of the specified + values + items: + format: uint64 + type: string + type: + - array + - "null" + title: U Int 64 Rules + type: object + x-speakeasy-name-override: UInt64Rules + securitySchemes: + bearerAuth: + scheme: bearer + type: http + oauth: + description: |- + This API uses OAuth2 with the Client Credential flow. + Client Credentials must be sent in the BODY, not the headers. + For an example of how to implement this, refer to the [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187) function. + flows: + clientCredentials: + scopes: {} + tokenUrl: /auth/v1/token + type: oauth2 +info: + description: The C1 API is a HTTP API for managing C1 resources. + title: C1 API + version: 0.1.0-alpha +openapi: 3.1.0 +paths: + /api/v1/a2ui/conversations/{conversation_id}/surfaces: + get: + description: ListSurfaces returns active surfaces for a conversation. + operationId: c1.api.a2ui.v1.A2UIService.ListSurfaces + parameters: + - in: path + name: conversation_id + required: true + schema: + description: The conversationId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfacesResponse' + description: A2UIServiceListSurfacesResponse returns active surfaces. + summary: List Surfaces + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: ListSurfaces + /api/v1/a2ui/surfaces/{surface_id}/actions: + post: + description: SubmitAction handles user actions on A2UI surfaces. + operationId: c1.api.a2ui.v1.A2UIService.SubmitAction + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionResponse' + description: A2UIServiceSubmitActionResponse returns the result of an action. + summary: Submit Action + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: SubmitAction + /api/v1/a2ui/surfaces/{surface_id}/feedback: + get: + description: ListSurfaceFeedback lists feedback for a surface. + operationId: c1.api.a2ui.v1.A2UIService.ListSurfaceFeedback + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfaceFeedbackResponse' + description: A2UIServiceListSurfaceFeedbackResponse returns feedback for a surface. + summary: List Surface Feedback + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: ListSurfaceFeedback + post: + description: CreateSurfaceFeedback submits feedback for a surface with a snapshot. + operationId: c1.api.a2ui.v1.A2UIService.CreateSurfaceFeedback + parameters: + - in: path + name: surface_id + required: true + schema: + description: The surfaceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackResponse' + description: A2UIServiceCreateSurfaceFeedbackResponse returns the created feedback. + summary: Create Surface Feedback + tags: + - A 2 UI + x-speakeasy-group: A2UI + x-speakeasy-name-override: CreateSurfaceFeedback + /api/v1/access_review: + post: + description: Create creates a new access review campaign with the specified name, policy, and owners. + operationId: c1.api.accessreview.v1.AccessReviewService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#create + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Create + x-stability-level: draft + /api/v1/access_review/{access_review_id}/scope_and_entitlements: + get: + description: GetCampaignScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review campaign. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.GetCampaignScopeAndEntitlements + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to retrieve scope and entitlements for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + description: Successful response + summary: Get Campaign Scope And Entitlements + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Setup#read + terraform-resource: Access Review Setup#read + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: GetCampaignScopeAndEntitlements + x-stability-level: stable + post: + description: SetCampaignScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review campaign. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeAndEntitlements + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + description: Successful response + summary: Set Campaign Scope And Entitlements + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: + - Access Review Setup#create + - Access Review Setup#update + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: SetCampaignScopeAndEntitlements + x-stability-level: stable + /api/v1/access_review/{access_review_id}/scope_by_resource_type: + post: + description: SetCampaignScopeByResourceType sets the campaign scope by selecting specific resource types to include in the review. + operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeByResourceType + parameters: + - in: path + name: access_review_id + required: true + schema: + description: The ID of the access review campaign to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeResponse' + description: Successful response + summary: Set Campaign Scope By Resource Type + tags: + - Access Review + x-speakeasy-group: AccessReviewSetupEntitlement + x-speakeasy-name-override: SetCampaignScopeByResourceType + x-stability-level: draft + /api/v1/access_review/{id}: + delete: + description: Delete transitions an access review campaign to the deleted state, along with its dependent objects. + operationId: c1.api.accessreview.v1.AccessReviewService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review campaign to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#delete + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Delete + x-stability-level: draft + get: + description: Get retrieves a single access review campaign by ID. + operationId: c1.api.accessreview.v1.AccessReviewService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review campaign to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceGetResponse' + description: Successful response + summary: Get + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review#read + terraform-resource: Access Review#read + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Get + x-stability-level: draft + post: + description: Update modifies an existing access review campaign. Use the update_mask to specify which fields to change. + operationId: c1.api.accessreview.v1.AccessReviewService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of this access review campaign. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review#update + x-speakeasy-group: AccessReview + x-speakeasy-name-override: Update + x-stability-level: draft + /api/v1/access_review_template: + post: + description: Create creates a new access review template that defines a reusable configuration for launching campaigns. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#create + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Create + x-stability-level: draft + /api/v1/access_review_template/{access_review_template_id}/scope_and_entitlements: + get: + description: GetScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.GetScopeAndEntitlements + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to retrieve scope and entitlements for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + description: Successful response + summary: Get Scope And Entitlements + tags: + - Access Review Templates + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Template Setup#read + terraform-resource: Access Review Template Setup#read + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: GetScopeAndEntitlements + x-stability-level: stable + post: + description: SetScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeAndEntitlements + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' + description: Successful response + summary: Set Scope And Entitlements + tags: + - Access Review Templates + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: + - Access Review Template Setup#create + - Access Review Template Setup#update + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: SetScopeAndEntitlements + x-stability-level: stable + /api/v1/access_review_template/{access_review_template_id}/scope_by_resource_type: + post: + description: SetScopeByResourceType sets the template scope by selecting specific resource types to include in campaigns created from this template. + operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeByResourceType + parameters: + - in: path + name: access_review_template_id + required: true + schema: + description: The ID of the access review template to configure. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeResponse' + description: Successful response + summary: Set Scope By Resource Type + tags: + - Access Review Templates + x-speakeasy-group: AccessReviewTemplateSetupEntitlement + x-speakeasy-name-override: SetScopeByResourceType + x-stability-level: draft + /api/v1/access_review_template/{id}: + delete: + description: Delete an access review template. The template can no longer be used to create campaigns. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review template to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#delete + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Delete + x-stability-level: draft + get: + description: Get retrieves a single access review template by ID. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the access review template to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceGetResponse' + description: Successful response + summary: Get + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Review Template#read + terraform-resource: Access Review Template#read + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Get + x-stability-level: draft + post: + description: Update modifies an existing access review template. Use the update_mask to specify which fields to change. + operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of this template. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Access Review Template + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access Review Template#update + x-speakeasy-group: AccessReviewTemplate + x-speakeasy-name-override: Update + x-stability-level: draft + /api/v1/access_reviews: + get: + description: List returns a paginated list of access review campaigns. + operationId: c1.api.accessreview.v1.AccessReviewService.List + parameters: + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. Maximum 100. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Pagination token from a previous List response to fetch the next page. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceListResponse' + description: Successful response + summary: List + tags: + - Access Review + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Access Reviews#read + terraform-resource: Access Reviews#read + x-speakeasy-group: AccessReview + x-speakeasy-name-override: List + x-stability-level: draft + /api/v1/accessconflict: + post: + description: Create a new conflict monitor for defining a Separation of Duty rule. Entitlement sets are bound separately via AppEntitlementMonitorBindingService. + operationId: c1.api.accessconflict.v1.AccessConflictService.CreateMonitor + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Create Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#create + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: CreateMonitor + /api/v1/accessconflict/{id}: + delete: + description: Delete a conflict monitor and its associated entitlement set bindings. + operationId: c1.api.accessconflict.v1.AccessConflictService.DeleteMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteResponse' + description: The response message for deleting a conflict monitor. + summary: Delete Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#delete + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: DeleteMonitor + get: + description: Retrieve a single conflict monitor by ID. + operationId: c1.api.accessconflict.v1.AccessConflictService.GetMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Get Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Access_Conflict#read + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: GetMonitor + post: + description: Update the display name, description, or notification settings of a conflict monitor. + operationId: c1.api.accessconflict.v1.AccessConflictService.UpdateMonitor + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the conflict monitor to update. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' + description: |- + A conflict monitor defines a Separation of Duty rule between two entitlement sets. + It detects when any user holds entitlements from both set A and set B simultaneously. + summary: Update Monitor + tags: + - Access Conflict + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Conflict#update + x-speakeasy-group: AccessConflict + x-speakeasy-name-override: UpdateMonitor + /api/v1/app_users/owned_service_accounts: + post: + description: |- + ListOwnedServiceAccounts returns the service accounts owned by the calling + user. The owner is the authenticated caller; it is not accepted as an input. + operationId: c1.api.app.v1.AppUserService.ListOwnedServiceAccounts + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListOwnedServiceAccountsResponse' + description: Successful response + summary: List Owned Service Accounts + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListOwnedServiceAccounts + x-stability-level: draft + /api/v1/appentitlementmonitorbinding: + delete: + description: Remove an app entitlement from a conflict monitor's entitlement set. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.DeleteAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingResponse' + description: The response message for deleting an app entitlement monitor binding. + summary: Delete App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Monitor_Binding#delete + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: DeleteAppEntitlementMonitorBinding + post: + description: Bind an app entitlement to one side (A or B) of a conflict monitor. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.CreateAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.CreateAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' + description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. + summary: Create App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Monitor_Binding#create + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: CreateAppEntitlementMonitorBinding + /api/v1/appentitlementmonitorbinding/get: + post: + description: Retrieve a single binding that associates an app entitlement with one side of a conflict monitor. + operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.GetAppEntitlementMonitorBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.GetAppEntitlementMonitorBindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' + description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. + summary: Get App Entitlement Monitor Binding + tags: + - App Entitlement Monitor Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Entitlement_Monitor_Binding#read + terraform-resource: App_Entitlement_Monitor_Binding#read + x-speakeasy-group: AppEntitlementMonitorBinding + x-speakeasy-name-override: GetAppEntitlementMonitorBinding + /api/v1/apps: + get: + description: List all apps. + operationId: c1.api.app.v1.Apps.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppsResponse' + description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App + x-speakeasy-group: Apps + x-speakeasy-name-override: List + post: + description: Create a new manual app without a connector. + operationId: c1.api.app.v1.Apps.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppResponse' + description: Returns the new app's values. + summary: Create + tags: + - App + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App#create + x-speakeasy-group: Apps + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/access_request_defaults: + get: + description: Retrieve the current access request default settings for an app. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.GetAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to retrieve access request defaults for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Get App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: GetAppAccessRequestsDefaults + post: + description: Create or replace the access request default settings for an app. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CreateAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The app id for the app access request rule + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaultsInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Create App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: CreateAppAccessRequestsDefaults + /api/v1/apps/{app_id}/access_request_defaults/cancel: + post: + description: Cancel an in-progress apply operation for the app's access request defaults. + operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CancelAppAccessRequestsDefaults + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app whose access request defaults apply operation should be cancelled. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CancelAccessRequestDefaultsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + description: Successful response + summary: Cancel App Access Requests Defaults + tags: + - AppAccessRequestDefaults + x-speakeasy-group: AppAccessRequestsDefaults + x-speakeasy-name-override: CancelAppAccessRequestsDefaults + /api/v1/apps/{app_id}/app_users: + get: + description: List app user accounts within a specific app, with pagination support. + operationId: c1.api.app.v1.AppUserService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to list users for. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListResponse' + description: The response message for listing app users. + summary: List + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/app_users/{app_user_id}/credentials: + get: + description: List credentials associated with a specific app user account. + operationId: c1.api.app.v1.AppUserService.ListAppUserCredentials + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that the user belongs to. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The ID of the app user whose credentials to list. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListCredentialsResponse' + description: The response message for listing credentials of an app user. + summary: List App User Credentials + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListAppUserCredentials + /api/v1/apps/{app_id}/connectors: + get: + description: List connectors for an app. + operationId: c1.api.app.v1.ConnectorService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceListResponse' + description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable + summary: List + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: List + post: + description: Create a connector that is pending a connector config. + operationId: c1.api.app.v1.ConnectorService.CreateDelegated + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' + description: The ConnectorServiceCreateResponse is the response returned from creating a connector. + summary: Create Delegated + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: CreateDelegated + /api/v1/apps/{app_id}/connectors/{connector_id}/confirm_sync_valid/{sync_lifecycle_id}: + post: + description: Confirm that a sync which errored due to a data drop is valid, overriding the error and triggering a new sync. Only applicable when the sync status is ERRORED_NO_DATA. + operationId: c1.api.app.v1.ConnectorService.ConfirmSyncValid + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are confirming the sync for. + type: string + - in: path + name: sync_lifecycle_id + required: true + schema: + description: The completed lifecycle id of the most recent sync we want to validate + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidResponse' + description: Empty response body. Status code indicates success. + summary: Confirm Sync Valid + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ConfirmSyncValid + /api/v1/apps/{app_id}/connectors/{connector_id}/credentials/{id}: + get: + description: Get credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.GetCredentials + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector that we are getting the credentials for. + type: string + - in: path + name: id + required: true + schema: + description: The id of the ConnectorCredential. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetCredentialsResponse' + description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. + summary: Get Credentials + tags: + - Connector + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: ConnectorCredential#read + terraform-resource: ConnectorCredential#read + x-speakeasy-group: Connector + x-speakeasy-name-override: GetCredentials + post: + description: Revoke credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.RevokeCredential + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector that we are revoking the credentials for. + type: string + - in: path + name: id + required: true + schema: + description: The id of the ConnectorCredential. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialResponse' + description: Empty response body. Status code indicates success. + summary: Revoke Credential + tags: + - Connector + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: ConnectorCredential#delete + x-speakeasy-group: Connector + x-speakeasy-name-override: RevokeCredential + /api/v1/apps/{app_id}/connectors/{connector_id}/force_sync: + post: + description: Trigger an immediate sync for a connector. The sync is queued and may not start instantly. + operationId: c1.api.app.v1.ConnectorService.ForceSync + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are forcing to sync. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ForceSyncRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ForceSyncResponse' + description: Empty response body. Status code indicates success. + summary: Force Sync + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ForceSync + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools: + get: + description: |- + List returns the MCP tools discovered for a single (app_id, connector_id), + paginated. To filter by state, classification, or visibility, use Search. + operationId: c1.api.ai_governance.v1.MCPToolService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListResponse' + description: MCPToolServiceListResponse returns a list of MCP tools. + summary: List + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: List + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}: + delete: + description: |- + Delete soft-deletes an MCP tool. It reappears as PENDING_REVIEW if the + connector rediscovers it on the next sync. + operationId: c1.api.ai_governance.v1.MCPToolService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceDeleteResponse' + description: MCPToolServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Delete + get: + description: |- + Get retrieves a single discovered MCP tool by app_id + connector_id + id, + including its approval state, classification, visibility, input schema, and + bound app_entitlement_id. + operationId: c1.api.ai_governance.v1.MCPToolService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceGetResponse' + description: MCPToolServiceGetResponse returns a single MCP tool. + summary: Get + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Get + post: + description: |- + Update modifies an MCP tool's admin-editable fields via update_mask. This + is how a tool is approved: set tool.state = MCP_TOOL_STATE_APPROVED with + update_mask "state" to move it out of PENDING_REVIEW (or DISABLED to block + it). Editable paths: display_name, description, classification, state, + allowed_client_types, visibility. tool must include id, app_id, connector_id. + operationId: c1.api.ai_governance.v1.MCPToolService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (app that owns the connector). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this MCP tool record. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceUpdateResponse' + description: MCPToolServiceUpdateResponse returns the updated MCP tool. + summary: Update + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single MCP + tool — each entry is a snapshot plus who/when metadata. + operationId: c1.api.ai_governance.v1.MCPToolService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP tool. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceListHistoryResponse' + description: MCPToolServiceListHistoryResponse returns MCP tool history entries. + summary: List History + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_tools/search: + post: + description: |- + Search returns a connector's MCP tools filtered by state, classification, + visibility, access-profile binding, or text query. Filter on + MCP_TOOL_STATE_PENDING_REVIEW to find tools awaiting approval, then approve + them with Update. + operationId: c1.api.ai_governance.v1.MCPToolService.Search + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPToolServiceSearchResponse' + description: MCPToolServiceSearchResponse returns matching MCP tools. + summary: Search + tags: + - MCP Tools + x-speakeasy-group: MCPTool + x-speakeasy-name-override: Search + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets: + get: + description: |- + List returns the MCP toolsets (access profiles) defined for a single + (app_id, connector_id), paginated. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector ID (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceListResponse' + description: MCPAccessProfileServiceListResponse returns a list of MCP access profiles. + summary: List + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: List + post: + description: |- + Create creates a new MCP toolset (access profile) under a connector. The + backend also provisions a backing AppEntitlement that users request in + order to be granted the toolset's tools. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceCreateResponse' + description: MCPAccessProfileServiceCreateResponse returns the created MCP access profile. + summary: Create + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings: + get: + description: |- + List returns the tool bindings for a single toolset (access profile) — + i.e. which MCP tools belong to the toolset — paginated. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListResponse' + description: MCPAccessProfileToolBindingServiceListResponse returns tool bindings. + summary: List + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: List + post: + description: CreateBindings adds one or more MCP tools (mcp_tool_ids) to a toolset. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.CreateBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceCreateResponse' + description: MCPAccessProfileToolBindingServiceCreateResponse returns created bindings. + summary: Create Bindings + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: CreateBindings + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/delete: + post: + description: |- + DeleteBindings removes one or more MCP tools (mcp_tool_ids) from a toolset. + Uses a POST .../delete action route because the tool IDs travel in the + request body, which HTTP DELETE does not reliably support. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.DeleteBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Access profile identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceDeleteResponse' + description: MCPAccessProfileToolBindingServiceDeleteResponse confirms deletion. + summary: Delete Bindings + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: DeleteBindings + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{access_profile_id}/tool_bindings/history: + get: + description: |- + ListToolsByProfileHistory returns the transactional history of + tools bound to (app, connector, access_profile). Newest first. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListToolsByProfileHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: Toolset (access profile) identifier. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListToolsByProfileHistoryResponse' + description: |- + Contains a page of change-history entries for the tools bound to one toolset + sorted newest first. + summary: List Tools By Profile History + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: ListToolsByProfileHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/mcp_toolsets/{id}: + delete: + description: |- + Delete soft-deletes a toolset (access profile) and cascades to its tool + bindings and backing entitlement. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP access profile. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceDeleteResponse' + description: MCPAccessProfileServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Delete + get: + description: |- + Get retrieves a single MCP toolset (access profile) by app_id + + connector_id + id, including its display name, description, linked + app_entitlement_id, and bound tool count. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the MCP access profile. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetResponse' + description: MCPAccessProfileServiceGetResponse returns a single MCP access profile. + summary: Get + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Get + post: + description: |- + Update modifies a toolset's admin-editable fields via update_mask. + Editable paths: display_name, description. profile must include id, + app_id, and connector_id. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (app that owns the connector). + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this access profile. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceUpdateResponse' + description: MCPAccessProfileServiceUpdateResponse returns the updated MCP access profile. + summary: Update + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/{connector_id}/pause: + post: + description: Pause syncing and provisioning for a connector. No new syncs or grant/revoke operations will run until the connector is resumed. + operationId: c1.api.app.v1.ConnectorService.PauseSync + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are pausing the sync for. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.PauseSyncRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.PauseSyncResponse' + description: Empty response body. Status code indicates success. + summary: Pause Sync + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: PauseSync + /api/v1/apps/{app_id}/connectors/{connector_id}/resume: + post: + description: Resume syncing and provisioning for a connector that was previously paused. Clears the paused state and triggers a new sync. + operationId: c1.api.app.v1.ConnectorService.ResumeSync + parameters: + - in: path + name: app_id + required: true + schema: + description: The AppID of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The ConnectorID of the connector that we are resuming the sync for. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncResponse' + description: Empty response body. Status code indicates success. + summary: Resume Sync + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ResumeSync + /api/v1/apps/{app_id}/connectors/{connector_id}/schedule: + post: + description: Update the sync schedule for a connector. + operationId: c1.api.app.v1.ConnectorService.UpdateConnectorSchedule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId of the connector whose schedule is being updated. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleResponse' + description: Empty response body. Status code indicates success. + summary: Update Connector Schedule + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: UpdateConnectorSchedule + x-stability-level: alpha + /api/v1/apps/{app_id}/connectors/{connector_id}/syncs/{sync_id}/download_url: + get: + description: GetConnectorSyncDownloadURL generates a short-lived download URL for a completed connector sync artifact. + operationId: c1.api.app.v1.ConnectorService.GetConnectorSyncDownloadURL + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: sync_id + required: true + schema: + description: The syncId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetConnectorSyncDownloadURLResponse' + description: Successful response + summary: Get Connector Sync Download Url + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: GetConnectorSyncDownloadURL + /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tool/{mcp_tool_id}/history: + get: + description: |- + ListProfilesByToolHistory returns the transactional history of + profiles bound to (app, connector, mcp_tool). Newest first. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.ListProfilesByToolHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + - in: path + name: mcp_tool_id + required: true + schema: + description: MCP tool identifier. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceListProfilesByToolHistoryResponse' + description: |- + Contains a page of change-history entries for the toolsets one tool has belonged to, + sorted newest first. + summary: List Profiles By Tool History + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: ListProfilesByToolHistory + /api/v1/apps/{app_id}/connectors/{connector_id}/tool_bindings/by_tools: + post: + description: |- + GetAccessProfilesForTools returns the access profiles bound to each + of the given MCP tools, hydrated with display_name. Used by the tools + list to render the "toolset" column for visible rows. + operationId: c1.api.ai_governance.v1.MCPAccessProfileToolBindingService.GetAccessProfilesForTools + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: Connector identifier. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse' + description: |- + MCPAccessProfileToolBindingServiceGetAccessProfilesForToolsResponse returns + access profiles grouped by MCP tool. + summary: Get Access Profiles For Tools + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfileToolBinding + x-speakeasy-name-override: GetAccessProfilesForTools + /api/v1/apps/{app_id}/connectors/{id}: + delete: + description: Delete a connector. + operationId: c1.api.app.v1.ConnectorService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: id + required: true + schema: + description: The id of the connector. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteResponse' + description: Empty response body. Status code indicates success. + summary: Delete + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: Delete + get: + description: Get a connector. + operationId: c1.api.app.v1.ConnectorService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId of the app the connector is attached to. + type: string + - in: path + name: id + required: true + schema: + description: The id of the connector. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetResponse' + description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. + summary: Get + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: Get + post: + description: Update a connector. + operationId: c1.api.app.v1.ConnectorService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The id of the app the connector is associated with. + type: string + - in: path + name: id + required: true + schema: + description: The id of the connector. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' + description: ConnectorServiceUpdateResponse is the response returned by the update method. + summary: Update + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/connectors/create: + post: + description: Create a configured connector. + operationId: c1.api.app.v1.ConnectorService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' + description: The ConnectorServiceCreateResponse is the response returned from creating a connector. + summary: Create + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/entitlement_configuration_rules: + get: + description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules method. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementRoutingRulesResponse' + description: Successful response + summary: List App Entitlement Routing Rules + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: ListAppEntitlementRoutingRules + post: + description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule method. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRoutingRuleResponse' + description: Successful response + summary: Create App Entitlement Routing Rule + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: CreateAppEntitlementRoutingRule + /api/v1/apps/{app_id}/entitlement_configuration_rules/{id}: + delete: + description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule method. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRoutingRuleResponse' + description: Successful response + summary: Delete App Entitlement Routing Rule + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: DeleteAppEntitlementRoutingRule + get: + description: Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule method. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementRoutingRuleResponse' + description: Successful response + summary: Get App Entitlement Routing Rule + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: GetAppEntitlementRoutingRule + post: + description: |- + Update an existing app entitlement configuration rule. The app_id field is + immutable; moving a rule between apps is modeled as delete + create. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.UpdateAppEntitlementRoutingRule + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRoutingRuleResponse' + description: Successful response + summary: Update App Entitlement Routing Rule + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: UpdateAppEntitlementRoutingRule + /api/v1/apps/{app_id}/entitlement_configuration_rules/reorder: + post: + description: |- + Reorder all configuration rules for an app in a single call. The caller + supplies the full ordered list of rule IDs; the server assigns dense + priorities (1..N) in that order. The request must be a permutation of every + active rule in the app — missing or extra IDs are rejected. + operationId: c1.api.app.v1.AppEntitlementRoutingRuleService.ReorderAppEntitlementRoutingRules + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app whose rules should be reordered. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ReorderAppEntitlementRoutingRulesResponse' + description: Successful response + summary: Reorder App Entitlement Routing Rules + tags: + - App Entitlement Configuration Rule + x-speakeasy-group: AppEntitlementRoutingRule + x-speakeasy-name-override: ReorderAppEntitlementRoutingRules + /api/v1/apps/{app_id}/entitlements: + get: + description: List app entitlements associated with an app. + operationId: c1.api.app.v1.AppEntitlements.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: List + post: + description: Create a new app entitlement for an app. This is used to define a custom permission, group, or role within the app. + operationId: c1.api.app.v1.AppEntitlements.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to create the entitlement in. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementResponse' + description: Successful response + summary: Create + tags: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Custom App Entitlement#create + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/add-manual-user: + post: + description: Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. + operationId: c1.api.app.v1.AppEntitlements.AddManuallyManagedMembers + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to add manually managed members to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddManuallyManagedUsersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ManuallyManagedUsersResponse' + description: Successful response + summary: Add Manually Managed Members + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: AddManuallyManagedMembers + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation: + delete: + description: Delete the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.DeleteAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement whose automation to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationResponse' + description: Successful response + summary: Delete Automation + tags: + - App Entitlement Automation + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Automation#delete + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: DeleteAutomation + get: + description: Get the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.GetAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that is associated with the app entitlement. + readOnly: true + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The unique ID for the App Entitlement. + readOnly: true + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceGetAutomationResponse' + description: Successful response + summary: Get Automation + tags: + - App Entitlement Automation + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App Entitlement Automation#read + terraform-resource: App Entitlement Automation#read + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: GetAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/create: + post: + description: Create an automation rule for an app entitlement. Automations automatically provision or revoke access based on defined conditions. + operationId: c1.api.app.v1.AppEntitlements.CreateAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to create an automation for. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationResponse' + description: Successful response + summary: Create Automation + tags: + - App Entitlement Automation + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Automation#create + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: CreateAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/exclusions: + delete: + description: Remove users from the automation exclusion list for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.RemoveAutomationExclusion + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement whose automation exclusion list to update. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionResponse' + description: Empty response with a status code indicating success. + summary: Remove Automation Exclusion + tags: + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: RemoveAutomationExclusion + get: + description: List users who are excluded from the automation rule for an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.ListAutomationExclusions + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to list exclusions for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAutomationExclusionsResponse' + description: Successful response + summary: List Automation Exclusions + tags: + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListAutomationExclusions + post: + description: Add users to the automation exclusion list for an app entitlement. Excluded users are not affected by the automation rule. + operationId: c1.api.app.v1.AppEntitlements.AddAutomationExclusion + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement whose automation exclusion list to update. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionResponse' + description: Empty response with a status code indicating success. + summary: Add Automation Exclusion + tags: + - App Entitlement Automation Exclusion + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: AddAutomationExclusion + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/update: + post: + description: Update the automation rule for an app entitlement, including its display name, description, and conditions. + operationId: c1.api.app.v1.AppEntitlements.UpdateAutomation + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that is associated with the app entitlement. + readOnly: true + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The unique ID for the App Entitlement. + readOnly: true + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse' + description: Successful response + summary: Update Automation + tags: + - App Entitlement Automation + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Automation#update + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: UpdateAutomation + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/grants: + get: + description: |- + Search app entitlements, include app users, users, expires, discovered. + Response rows are large — request a small page_size (≤10) to keep responses small. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsWithExpired + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The appEntitlementId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse' + description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. + summary: Search App Entitlements With Expired + tags: + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchAppEntitlementsWithExpired + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/remove-membership: + delete: + description: Remove a user from a ConductorOne-managed entitlement (catalog, group, or profile type). For access profiles, this creates a revoke task to deprovision access. + operationId: c1.api.app.v1.AppEntitlements.RemoveEntitlementMembership + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the app entitlement to remove the membership from. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipResponse' + description: Successful response + summary: Remove Entitlement Membership + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: RemoveEntitlementMembership + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users: + get: + deprecated: true + description: List the users, as AppEntitlementUsers objects, of an app entitlement. + operationId: c1.api.app.v1.AppEntitlements.ListUsers + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The appEntitlementId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementUsersResponse' + description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. + summary: List Users + tags: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppEntitlementUsers#read + terraform-resource: null + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListUsers + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/remove-grant-duration: + post: + description: Remove the expiration time from a grant, converting it to an indefinite (standing) grant. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.RemoveGrantDuration + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the entitlement whose grant duration is being removed. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The ID of the app user whose grant expiration is being removed. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationResponse' + description: The response message for removing the expiration time from a grant. + summary: Remove Grant Duration + tags: + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: RemoveGrantDuration + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/update-grant-duration: + post: + description: Update the expiration time of an existing grant, changing when automatic revocation will occur. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.UpdateGrantDuration + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the entitlement. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The ID of the entitlement whose grant duration is being updated. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The ID of the app user whose grant is being updated. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationResponse' + description: The response message for updating the duration of a grant. + summary: Update Grant Duration + tags: + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: UpdateGrantDuration + /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{identity_user_id}/grants: + get: + description: Returns a list of app users for the identity in the app. If that app user also has a grant to the entitlement from the request, data about the grant is also returned. It will always return ALL app users for this identity, but only SOME may have grant data. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.ListAppUsersForIdentityWithGrant + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: The appEntitlementId field. + type: string + - in: path + name: identity_user_id + required: true + schema: + description: The identityUserId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse' + description: Successful response + summary: List App Users For Identity With Grant + tags: + - App Entitlement User Binding + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: ListAppUsersForIdentityWithGrant + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/ownerids: + get: + description: ListUserIDs lists owner IDs for a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.ListOwnerIDs + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to list owners of. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to list owners of. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnerIDsResponse' + description: The response message for listing app entitlement owners IDs. + summary: List Owner I Ds + tags: + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Entitlement_Owner#read + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners: + delete: + description: Delete deletes the owners from a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to remove the owner of. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to remove the owner of. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersResponse' + description: the empty response message for deleting app entitlement owners. + summary: Delete + tags: + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner#delete + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Delete + get: + description: List owners for a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to list owners of. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to list owners of. + type: string + - in: query + name: page_size + schema: + description: The page_size field for pagination. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The page_token field for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnersResponse' + description: The response message for listing app entitlement owners. + summary: List + tags: + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppEntitlementOwners#read + terraform-resource: null + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: List + post: + description: Add an owner to a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Add + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to add the owner to. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to add the owner to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerResponse' + description: The empty response message for adding an app entitlement owner. + summary: Add + tags: + - App Entitlement Owner + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Add + put: + description: Sets the owners for a given app entitlement to the specified list of users. + operationId: c1.api.app.v1.AppEntitlementOwners.Set + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to set the owners of. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to set the owners of. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersResponse' + description: The empty response message for setting the app entitlement owners. + summary: Set + tags: + - App Entitlement Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner#create + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners/{user_id}: + delete: + description: Remove an owner from a given app entitlement. + operationId: c1.api.app.v1.AppEntitlementOwners.Remove + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app entitlement to remove the owner of. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlement_id field for the app entitlement to remove the owner of. + type: string + - in: path + name: user_id + required: true + schema: + description: The user_id field for the user to remove as an owner of the app entitlement. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerResponse' + description: The empty response message for removing an app entitlement owner. + summary: Remove + tags: + - App Entitlement Owner + x-speakeasy-group: AppEntitlementOwners + x-speakeasy-name-override: Remove + /api/v1/apps/{app_id}/entitlements/{id}: + delete: + description: Delete an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement. + type: string + - in: path + name: id + required: true + schema: + description: The ID of the app entitlement to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementResponse' + description: Successful response + summary: Delete + tags: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Custom App Entitlement#delete + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Delete + get: + description: Get an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementResponse' + description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. + summary: Get + tags: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Custom App Entitlement#read + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Get + post: + description: Update an app entitlement by ID. + operationId: c1.api.app.v1.AppEntitlements.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that is associated with the app entitlement. + type: string + - in: path + name: id + required: true + schema: + description: The unique ID for the App Entitlement. + readOnly: true + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementResponse' + description: Successful response + summary: Update + tags: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Custom App Entitlement#update + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/entitlements/resource_types/{app_resource_type_id}/resources/{app_resource_id}: + get: + description: List app entitlements associated with an app resource. + operationId: c1.api.app.v1.AppEntitlements.ListForAppResource + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The appResourceTypeId field. + type: string + - in: path + name: app_resource_id + required: true + schema: + description: The appResourceId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List For App Resource + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListForAppResource + /api/v1/apps/{app_id}/entitlements/users/{app_user_id}: + get: + description: List app entitlements associated with an app user. + operationId: c1.api.app.v1.AppEntitlements.ListForAppUser + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_user_id + required: true + schema: + description: The appUserId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: List For App User + tags: + - App Entitlement + x-speakeasy-group: AppEntitlements + x-speakeasy-name-override: ListForAppUser + /api/v1/apps/{app_id}/mcp_servers: + get: + description: List retrieves MCP servers for an app. + operationId: c1.api.ai_governance.v1.MCPServerService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceListResponse' + description: MCPServerServiceListResponse returns a paginated list of MCP servers. + summary: List + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: List + post: + description: |- + Register a new MCP server under an application. Set server_type to HOSTED + (C1 runs a catalog integration) or EXTERNAL (a third-party MCP server you + point C1 at by URL). Auth credentials are validated and stored securely. + operationId: c1.api.ai_governance.v1.MCPServerService.Register + parameters: + - in: path + name: app_id + required: true + schema: + description: |- + App to register the MCP server under. When empty and app_managed_state_binding_ref + is not set, a new managed app is created automatically. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceRegisterResponse' + description: MCPServerServiceRegisterResponse returns the newly created MCP server. + summary: Register + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: Register + /api/v1/apps/{app_id}/mcp_servers/{connector_id}: + delete: + description: |- + Delete an MCP server. Its connector stops and it is soft-deleted from this + tenant's MCP catalog, and any per-user credentials issued against it are + revoked. + operationId: c1.api.ai_governance.v1.MCPServerService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: MCP server identifier (connector ID). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDeleteResponse' + description: MCPServerServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: Delete + get: + description: Get retrieves a single MCP server. + operationId: c1.api.ai_governance.v1.MCPServerService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: MCP server identifier (connector ID). + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceGetResponse' + description: MCPServerServiceGetResponse returns a single MCP server. + summary: Get + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: Get + post: + description: Update modifies an existing MCP server's editable fields. + operationId: c1.api.ai_governance.v1.MCPServerService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: MCP server identifier (connector ID). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateResponse' + description: MCPServerServiceUpdateResponse returns the updated MCP server. + summary: Update + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/mcp_servers/{connector_id}/credentials: + post: + description: UpdateCredentials replaces the auth config and/or config fields for an MCP server. + operationId: c1.api.ai_governance.v1.MCPServerService.UpdateCredentials + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: MCP server identifier (connector ID). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceUpdateCredentialsResponse' + description: MCPServerServiceUpdateCredentialsResponse returns the updated MCP server. + summary: Update Credentials + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: UpdateCredentials + /api/v1/apps/{app_id}/mcp_servers/{connector_id}/resync_tools: + post: + description: |- + ResyncTools re-runs per-identity tool discovery for the calling user's + own credential on a per-user MCP server, so a session opened before the + user connected (or after their visible tools changed) doesn't have to + wait for the next unrelated MCPTool/AppEntitlementUserBinding change to + pick it up. + operationId: c1.api.ai_governance.v1.MCPServerService.ResyncTools + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: connector_id + required: true + schema: + description: MCP server identifier (connector ID). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceResyncToolsResponse' + description: MCPServerServiceResyncToolsResponse is empty on success. + summary: Resync Tools + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: ResyncTools + /api/v1/apps/{app_id}/mcp_servers/search: + post: + description: SearchWithToolCount searches MCP servers with filtering and returns per-server tool state counts. + operationId: c1.api.ai_governance.v1.MCPServerService.SearchWithToolCount + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier (required). + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceSearchWithToolCountResponse' + description: MCPServerServiceSearchWithToolCountResponse returns matching MCP servers with tool counts. + summary: Search With Tool Count + tags: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: SearchWithToolCount + /api/v1/apps/{app_id}/mcp_toolsets/by_app_entitlement_id/{app_entitlement_id}: + get: + description: |- + GetByAppEntitlementId looks up the toolset (access profile) linked to a + synced role entitlement, by app_id + app_entitlement_id. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.GetByAppEntitlementId + parameters: + - in: path + name: app_id + required: true + schema: + description: App identifier. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: AppEntitlement ID to look up. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceGetByAppEntitlementIdResponse' + description: MCPAccessProfileServiceGetByAppEntitlementIdResponse returns the matched profile. + summary: Get By App Entitlement Id + tags: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: GetByAppEntitlementId + /api/v1/apps/{app_id}/ownerids: + get: + description: ListOwnerIDs lists owner IDs for a given app. + operationId: c1.api.app.v1.AppOwners.ListOwnerIDs + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app to list owners of. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnerIDsResponse' + description: The response message for listing app owners IDs. + summary: List Owner I Ds + tags: + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Owner#read + x-speakeasy-group: AppOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/owners: + delete: + description: Delete deletes the owners from a given app. + operationId: c1.api.app.v1.AppOwners.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app to remove the owner of. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersResponse' + description: the empty response message for deleting app owners. + summary: Delete + tags: + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner#delete + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Delete + get: + description: List owners of an app. + operationId: c1.api.app.v1.AppOwners.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnersResponse' + description: Successful response + summary: List + tags: + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppOwners#read + terraform-resource: null + x-speakeasy-group: AppOwners + x-speakeasy-name-override: List + put: + description: Sets the owners for a given app to the specified list of users. + operationId: c1.api.app.v1.AppOwners.Set + parameters: + - in: path + name: app_id + required: true + schema: + description: The app_id field for the app to set the owners of. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersResponse' + description: The empty response message for setting the app owners. + summary: Set + tags: + - App Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner#create + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/owners/{user_id}: + delete: + description: Removes an owner from an app. + operationId: c1.api.app.v1.AppOwners.Remove + parameters: + - in: path + name: app_id + required: true + schema: + description: App ID of the app to remove the owner from. + type: string + - in: path + name: user_id + required: true + schema: + description: User ID of the user to remove as an owner. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerResponse' + description: Empty response with a status code indicating success. + summary: Remove + tags: + - App Owner + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Remove + post: + description: Adds an owner to an app. + operationId: c1.api.app.v1.AppOwners.Add + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerResponse' + description: Empty response with a status code indicating success + summary: Add + tags: + - App Owner + x-speakeasy-group: AppOwners + x-speakeasy-name-override: Add + /api/v1/apps/{app_id}/report: + get: + description: Get a list of reports for the given app. + operationId: c1.api.app.v1.AppReportService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppReportServiceListResponse' + description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App Reports + x-speakeasy-group: AppReport + x-speakeasy-name-override: List + post: + description: Generate a report for the given app. + operationId: c1.api.app.v1.AppReportActionService.GenerateReport + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportResponse' + description: Empty response body. Status code indicates success. + summary: Generate Report + tags: + - App Reports + x-speakeasy-group: AppReportAction + x-speakeasy-name-override: GenerateReport + /api/v1/apps/{app_id}/resource_types: + get: + description: List app resource types. + operationId: c1.api.app.v1.AppResourceTypeService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceListResponse' + description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App Resource Type + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: List + post: + description: Create a manually managed resource type that classifies resources within an app. + operationId: c1.api.app.v1.AppResourceTypeService.CreateManuallyManagedResourceType + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to create the resource type under. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeResponse' + description: The response message for creating a manually managed resource type. + summary: Create Manually Managed Resource Type + tags: + - App Resource Type + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource Type#create + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: CreateManuallyManagedResourceType + /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources: + get: + description: List app resources for a given app and optionally filter by resource type. + operationId: c1.api.app.v1.AppResourceService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to list resources for. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: Optional resource type ID to filter results by. If empty, resources of all types are returned. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceListResponse' + description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. + summary: List + tags: + - App Resource + x-speakeasy-group: AppResource + x-speakeasy-name-override: List + post: + description: Create a manually managed app resource tracked directly by ConductorOne under an existing resource type. + operationId: c1.api.app.v1.AppResourceService.CreateManuallyManagedAppResource + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to create the resource under. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The resource type ID that classifies this resource. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceResponse' + description: The response message for creating a manually managed app resource. + summary: Create Manually Managed App Resource + tags: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#create + x-speakeasy-group: AppResource + x-speakeasy-name-override: CreateManuallyManagedAppResource + /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources/{id}: + delete: + description: Delete a manually managed app resource and its associated entitlements from an app. + operationId: c1.api.app.v1.AppResourceService.DeleteManuallyManagedAppResource + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the resource. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The ID of the resource type that classifies the resource. + type: string + - in: path + name: id + required: true + schema: + description: The ID of the app resource to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceResponse' + description: The empty response message for deleting a manually managed app resource. + summary: Delete Manually Managed App Resource + tags: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#delete + x-speakeasy-group: AppResource + x-speakeasy-name-override: DeleteManuallyManagedAppResource + get: + description: Retrieve a single app resource by its app, resource type, and resource ID. + operationId: c1.api.app.v1.AppResourceService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the resource. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The ID of the resource type that classifies this resource. + type: string + - in: path + name: id + required: true + schema: + description: The unique ID of the app resource to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceGetResponse' + description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. + summary: Get + tags: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App Resource#read + terraform-resource: App Resource#read + x-speakeasy-group: AppResource + x-speakeasy-name-override: Get + post: + description: Update an app resource's fields. Only the fields specified in the update mask are modified. + operationId: c1.api.app.v1.AppResourceService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The app that this resource belongs to. + type: string + - in: path + name: app_resource_type_id + required: true + schema: + description: The resource type that this resource is. + type: string + - in: path + name: id + required: true + schema: + description: The id of the resource. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateResponse' + description: The response message for updating an app resource. + summary: Update + tags: + - App Resource + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource#update + x-speakeasy-group: AppResource + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/resource_types/{id}: + delete: + description: Delete a manually managed resource type and all its associated resources from an app. + operationId: c1.api.app.v1.AppResourceTypeService.DeleteManuallyManagedResourceType + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the resource type. + type: string + - in: path + name: id + required: true + schema: + description: The ID of the resource type to delete. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse' + description: The empty response message for deleting a manually managed resource type. + summary: Delete Manually Managed Resource Type + tags: + - App Resource Type + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource Type#delete + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: DeleteManuallyManagedResourceType + get: + description: Get an app resource type. + operationId: c1.api.app.v1.AppResourceTypeService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceGetResponse' + description: |- + The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask + in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. + summary: Get + tags: + - App Resource Type + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App Resource Type#read + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: Get + post: + description: Update a manually managed resource type's fields. Only the fields specified in the update mask are modified. + operationId: c1.api.app.v1.AppResourceTypeService.UpdateManuallyManagedResourceType + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that is associated with the app resource type + readOnly: true + type: string + - in: path + name: id + required: true + schema: + description: The unique ID for the app resource type. + readOnly: true + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse' + description: The response message for updating a manually managed resource type. + summary: Update Manually Managed Resource Type + tags: + - App Resource Type + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Resource Type#update + x-speakeasy-group: AppResourceType + x-speakeasy-name-override: UpdateManuallyManagedResourceType + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/ownerids: + delete: + description: Delete deletes the owners from a given app resource. + operationId: c1.api.app.v1.AppResourceOwners.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersResponse' + description: the empty response message for deleting app resource owners. + summary: Delete + tags: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner#delete + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Delete + get: + description: ListOwnerIDs lists owner IDs for a given app resource. + operationId: c1.api.app.v1.AppResourceOwners.ListOwnerIDs + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnerIDsResponse' + description: The response message for listing app resource owners IDs. + summary: List Owner I Ds + tags: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Resource_Owner#read + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: ListOwnerIDs + /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/owners: + delete: + description: Remove a user from the owners of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.Remove + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the resource. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The ID of the resource type that classifies the resource. + type: string + - in: path + name: resource_id + required: true + schema: + description: The ID of the app resource to remove an owner from. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerResponse' + description: The empty response message for removing an owner from an app resource. + summary: Remove + tags: + - App Resource Owner + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Remove + get: + description: List all owners of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnersResponse' + description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable + summary: List + tags: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AppResourceOwners#read + terraform-resource: null + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: List + post: + description: Add a user as an owner of an app resource. + operationId: c1.api.app.v1.AppResourceOwners.Add + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app that owns the resource. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The ID of the resource type that classifies the resource. + type: string + - in: path + name: resource_id + required: true + schema: + description: The ID of the app resource to add an owner to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerResponse' + description: The empty response message for adding an owner to an app resource. + summary: Add + tags: + - App Resource Owner + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Add + put: + description: Sets the owners for a given app resource to the specified list of users. + operationId: c1.api.app.v1.AppResourceOwners.Set + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersResponse' + description: The empty response message for setting the app resource owners. + summary: Set + tags: + - App Resource Owner + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner#create + x-speakeasy-group: AppResourceOwners + x-speakeasy-name-override: Set + /api/v1/apps/{app_id}/usage_controls: + get: + description: Get usage controls, as an AppUsageControls object which describes some peripheral configuration, for an app. + operationId: c1.api.app.v1.AppUsageControlsService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppUsageControlsResponse' + description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. + summary: Get + tags: + - App Usage Controls + x-speakeasy-group: AppUsageControls + x-speakeasy-name-override: Get + post: + description: Update usage controls for an app. + operationId: c1.api.app.v1.AppUsageControlsService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The app that this object belongs to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsResponse' + description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. + summary: Update + tags: + - App Usage Controls + x-speakeasy-group: AppUsageControls + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/users/{user_id}/app_users: + get: + description: List app user accounts within a specific app that are correlated to a given C1 user. + operationId: c1.api.app.v1.AppUserService.ListAppUsersForUser + parameters: + - in: path + name: app_id + required: true + schema: + description: The ID of the app to list users for. + type: string + - in: path + name: user_id + required: true + schema: + description: The C1 user ID to filter app users by identity correlation. + type: string + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The token for fetching the next page of results. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUsersForUserServiceListResponse' + description: The response message for listing app users correlated to a specific C1 user. + summary: List App Users For User + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: ListAppUsersForUser + /api/v1/apps/{app_id}/xaa/access_profiles: + get: + description: List the access profiles defined for an application, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The application to list access profiles for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListResponse' + description: XAAAccessProfileServiceListResponse returns a page of access profiles. + summary: List + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: List + post: + description: |- + Create an access profile under a resource server. The backend also + provisions a backing AppEntitlement that users request to be granted the + profile's scopes. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceCreateResponse' + description: XAAAccessProfileServiceCreateResponse returns the created access profile. + summary: Create + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings: + get: + description: List the scopes bound to an access profile, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: The access profile to list bindings for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceListResponse' + description: XAAAccessProfileScopeBindingServiceListResponse returns scope bindings. + summary: List + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: List + post: + description: |- + CreateBindings binds one or more scopes (xaa_scope_ids) to an access + profile. Every scope must belong to the profile's resource server. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.CreateBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: The access profile to bind scopes to. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse' + description: XAAAccessProfileScopeBindingServiceCreateResponse returns created bindings. + summary: Create Bindings + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: CreateBindings + /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings/delete: + post: + description: |- + DeleteBindings unbinds one or more scopes (xaa_scope_ids) from an access + profile. Uses a POST .../delete action route because the scope IDs travel + in the request body, which HTTP DELETE does not reliably support. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.DeleteBindings + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: access_profile_id + required: true + schema: + description: The access profile to unbind scopes from. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceDeleteResponse' + description: XAAAccessProfileScopeBindingServiceDeleteResponse confirms deletion. + summary: Delete Bindings + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: DeleteBindings + /api/v1/apps/{app_id}/xaa/access_profiles/{id}: + delete: + description: |- + Delete an access profile (soft delete). Cascades to its scope bindings and + backing entitlement; outstanding grants end with the entitlement. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the access profile. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceDeleteResponse' + description: XAAAccessProfileServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Delete + get: + description: Get an access profile by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the access profile. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetResponse' + description: XAAAccessProfileServiceGetResponse returns a single access profile. + summary: Get + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Get + post: + description: |- + Update an access profile's editable fields via update_mask. Editable + paths: display_name, description. The profile must include id and app_id. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this access profile. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceUpdateResponse' + description: XAAAccessProfileServiceUpdateResponse returns the updated access profile. + summary: Update + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/access_profiles/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single access + profile — each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the access profile. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceListHistoryResponse' + description: |- + XAAAccessProfileServiceListHistoryResponse returns access profile history + entries. + summary: List History + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/xaa/access_profiles/by_app_entitlement_id/{app_entitlement_id}: + get: + description: |- + GetByAppEntitlementId looks up the access profile linked to an + entitlement, by app_id + app_entitlement_id. Used by the request catalog. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.GetByAppEntitlementId + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: app_entitlement_id + required: true + schema: + description: AppEntitlement ID to look up. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceGetByAppEntitlementIdResponse' + description: |- + XAAAccessProfileServiceGetByAppEntitlementIdResponse returns the matched + profile. + summary: Get By App Entitlement Id + tags: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: GetByAppEntitlementId + /api/v1/apps/{app_id}/xaa/resource_servers: + get: + description: List the resource servers registered for an application, one page at a time. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The application to list resource servers for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListResponse' + description: XAAResourceServerServiceListResponse returns a page of resource servers. + summary: List + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: List + post: + description: |- + Register a resource server (a third-party authorization server) as a + permitted cross-app-access audience for an application. The audience must + be unique within the application and must not equal your own tenant's + issuer — C1 cannot be both the granting IdP and the resource server in the + same flow. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this resource server fronts. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse' + description: XAAResourceServerServiceCreateResponse returns the registered resource server. + summary: Create + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/resource_servers/{id}: + delete: + description: |- + Delete a resource server (soft delete). Cascades to its scopes, access + profiles, and client audience mappings. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this resource server fronts. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the resource server. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceDeleteResponse' + description: XAAResourceServerServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Delete + get: + description: Get a registered resource server by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this resource server fronts. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the resource server. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceGetResponse' + description: XAAResourceServerServiceGetResponse returns a single resource server. + summary: Get + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Get + post: + description: |- + Update a resource server's editable fields via update_mask. The audience + is immutable (delete and recreate to change it); supplying a different + audience is rejected. Editable paths: display_name, description, + resource_uris, max_grant_lifetime, signing_algorithm, + require_proof_of_possession, modify_claims_hook, disabled. sector_id is + immutable once set (delete and recreate to change it). + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this resource server fronts. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this resource server. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceUpdateResponse' + description: XAAResourceServerServiceUpdateResponse returns the updated resource server. + summary: Update + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/resource_servers/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single + resource server — each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this resource server fronts. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the resource server. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceListHistoryResponse' + description: |- + XAAResourceServerServiceListHistoryResponse returns resource server history + entries. + summary: List History + tags: + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_id}/xaa/scopes: + get: + description: |- + List the scopes defined for an application, one page at a time. To filter + by resource server, state, or classification, use Search. + operationId: c1.api.cross_app_access.v1.XAAScopeService.List + parameters: + - in: path + name: app_id + required: true + schema: + description: The application to list scopes for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListResponse' + description: XAAScopeServiceListResponse returns a page of scopes. + summary: List + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: List + post: + description: |- + Declare a scope under a resource server. The scope value is the literal + OAuth scope string and is immutable after creation. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Create + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceCreateResponse' + description: XAAScopeServiceCreateResponse returns the created scope. + summary: Create + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Create + /api/v1/apps/{app_id}/xaa/scopes/{id}: + delete: + description: |- + Delete a scope (soft delete). Cascades to its backing entitlement and to + any access-profile bindings that reference it. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Delete + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the scope. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceDeleteResponse' + description: XAAScopeServiceDeleteResponse confirms deletion. + summary: Delete + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Delete + get: + description: Get a scope by app_id + id. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Get + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the scope. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceGetResponse' + description: XAAScopeServiceGetResponse returns a single scope. + summary: Get + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Get + post: + description: |- + Update a scope's editable fields via update_mask. This is how a scope is + approved: set state to ENABLED to make it mintable, or DISABLED to block + it. The scope value is immutable. Editable paths: display_name, + description, state, classification. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Update + parameters: + - in: path + name: app_id + required: true + schema: + description: The application that owns the resource server. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for this scope. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceUpdateResponse' + description: XAAScopeServiceUpdateResponse returns the updated scope. + summary: Update + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Update + /api/v1/apps/{app_id}/xaa/scopes/{id}/history: + get: + description: |- + ListHistory returns the change history (newest first) for a single scope — + each entry is a snapshot plus who/when metadata. + operationId: c1.api.cross_app_access.v1.XAAScopeService.ListHistory + parameters: + - in: path + name: app_id + required: true + schema: + description: The application this scope belongs to. + type: string + - in: path + name: id + required: true + schema: + description: Unique identifier for the scope. + type: string + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse' + description: XAAScopeServiceListHistoryResponse returns scope history entries. + summary: List History + tags: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: ListHistory + /api/v1/apps/{app_user_app_id}/app_users/{app_user_id}: + post: + description: |- + Update an app user by ID. Only the fields specified in the update mask are updated. + Currently, only the appUserType, and identityUserId fields can be updated. + operationId: c1.api.app.v1.AppUserService.Update + parameters: + - in: path + name: app_user_app_id + required: true + schema: + description: The ID of the application. + readOnly: true + type: string + - in: path + name: app_user_id + required: true + schema: + description: A unique idenditfier of the application user. + readOnly: true + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: Update + /api/v1/apps/{connector_app_id}/connectors/{connector_id}/delegated: + post: + description: Update a delegated connector. + operationId: c1.api.app.v1.ConnectorService.UpdateDelegated + parameters: + - in: path + name: connector_app_id + required: true + schema: + description: The id of the app the connector is associated with. + type: string + - in: path + name: connector_id + required: true + schema: + description: The id of the connector. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' + description: ConnectorServiceUpdateResponse is the response returned by the update method. + summary: Update Delegated + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: UpdateDelegated + /api/v1/apps/{id}: + delete: + description: Delete an app. + operationId: c1.api.app.v1.Apps.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResponse' + description: Empty response body. Status code indicates success. + summary: Delete + tags: + - App + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App#delete + x-speakeasy-group: Apps + x-speakeasy-name-override: Delete + get: + description: Get an app by ID. + operationId: c1.api.app.v1.Apps.Get + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppResponse' + description: The GetAppResponse message contains the details of the requested app in the app field. + summary: Get + tags: + - App + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App#read + x-speakeasy-group: Apps + x-speakeasy-name-override: Get + post: + description: Update an existing app. + operationId: c1.api.app.v1.Apps.Update + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the app. + readOnly: true + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.UpdateAppResponse' + description: Returns the updated app's new values. + summary: Update + tags: + - App + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App#update + x-speakeasy-group: Apps + x-speakeasy-name-override: Update + /api/v1/apps/{src_app_id}/{src_app_entitlement_id}/bindings/{dst_app_id}/{dst_app_entitlement_id}: + delete: + description: Delete a proxy binding between a source and destination entitlement. + operationId: c1.api.app.v1.AppEntitlementsProxy.Delete + parameters: + - in: path + name: src_app_id + required: true + schema: + description: The ID of the app that owns the source entitlement. + type: string + - in: path + name: src_app_entitlement_id + required: true + schema: + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyResponse' + description: The empty response message for deleting an entitlement proxy binding. + summary: Delete + tags: + - App Entitlement Proxy Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Proxy Binding#delete + x-speakeasy-group: AppEntitlementsProxy + x-speakeasy-name-override: Delete + get: + description: Retrieve a specific proxy binding between a source and destination entitlement. + operationId: c1.api.app.v1.AppEntitlementsProxy.Get + parameters: + - in: path + name: src_app_id + required: true + schema: + description: The ID of the app that owns the source entitlement. + type: string + - in: path + name: src_app_entitlement_id + required: true + schema: + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementProxyResponse' + description: The response message for getting a specific entitlement proxy binding. + summary: Get + tags: + - App Entitlement Proxy Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App Entitlement Proxy Binding#read + terraform-resource: App Entitlement Proxy Binding#read + x-speakeasy-group: AppEntitlementsProxy + x-speakeasy-name-override: Get + post: + description: Create a proxy binding between a source and destination entitlement, establishing a hierarchical relationship. + operationId: c1.api.app.v1.AppEntitlementsProxy.Create + parameters: + - in: path + name: src_app_id + required: true + schema: + description: The ID of the app that owns the source entitlement. + type: string + - in: path + name: src_app_entitlement_id + required: true + schema: + description: The ID of the source (parent) entitlement. + type: string + - in: path + name: dst_app_id + required: true + schema: + description: The ID of the app that owns the destination entitlement. + type: string + - in: path + name: dst_app_entitlement_id + required: true + schema: + description: The ID of the destination (child) entitlement. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyResponse' + description: The response message for creating an entitlement proxy binding. + summary: Create + tags: + - App Entitlement Proxy Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App Entitlement Proxy Binding#create + x-speakeasy-group: AppEntitlementsProxy + x-speakeasy-name-override: Create + /api/v1/apps/connectors/credentials: + post: + description: Rotate credentials for a connector. + operationId: c1.api.app.v1.ConnectorService.RotateCredential + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialResponse' + description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. + summary: Rotate Credential + tags: + - Connector + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: ConnectorCredential#create + x-speakeasy-group: Connector + x-speakeasy-name-override: RotateCredential + /api/v1/apps/connectors/validate_config/http: + post: + description: Validate an HTTP connector configuration and return any diagnostics or errors found. + operationId: c1.api.app.v1.ConnectorService.ValidateHTTPConnectorConfig + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.EditorValidateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.EditorValidateResponse' + description: The EditorValidateResponse message contains validation results. + summary: Validate Http Connector Config + tags: + - Connector + x-speakeasy-group: Connector + x-speakeasy-name-override: ValidateHTTPConnectorConfig + /api/v1/attribute/{id}: + delete: + description: Delete an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueResponse' + description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. + summary: Delete Attribute Value + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteAttributeValue + /api/v1/attributes: + post: + description: Create a new attribute value. + operationId: c1.api.attribute.v1.Attributes.CreateAttributeValue + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueResponse' + description: CreateAttributeValueResponse is the response for creating an attribute value. + summary: Create Attribute Value + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateAttributeValue + /api/v1/attributes/{id}: + get: + description: Get an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.GetAttributeValueResponse' + description: GetAttributeValueResponse is the response for getting an attribute value by id. + summary: Get Attribute Value + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetAttributeValue + /api/v1/attributes/compliance_frameworks: + get: + description: List all compliance framework attribute values (e.g., SOC 2, HIPAA) with pagination. + operationId: c1.api.attribute.v1.Attributes.ListComplianceFrameworks + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.ListComplianceFrameworksResponse' + description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. + summary: List Compliance Frameworks + tags: + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Compliance Frameworks#read + terraform-resource: null + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListComplianceFrameworks + post: + description: Create a compliance framework value. + operationId: c1.api.attribute.v1.Attributes.CreateComplianceFrameworkAttributeValue + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Create Compliance Framework Attribute Value + tags: + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Compliance Framework#create + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateComplianceFrameworkAttributeValue + /api/v1/attributes/compliance_frameworks/{id}: + delete: + description: Delete an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteComplianceFrameworkAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Delete Compliance Framework Attribute Value + tags: + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Compliance Framework#delete + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValue + get: + description: Get an attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetComplianceFrameworkAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse' + description: Successful response + summary: Get Compliance Framework Attribute Value + tags: + - Compliance Framework + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Compliance Framework#read + terraform-resource: Compliance Framework#read + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetComplianceFrameworkAttributeValue + /api/v1/attributes/risk_levels: + get: + description: List all risk level attribute values with pagination. + operationId: c1.api.attribute.v1.Attributes.ListRiskLevels + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.ListRiskLevelsResponse' + description: ListRiskLevelsResponse is the response for listing risk level attribute values. + summary: List Risk Levels + tags: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Risk Levels#read + terraform-resource: null + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListRiskLevels + post: + description: Create a risk level attribute. + operationId: c1.api.attribute.v1.Attributes.CreateRiskLevelAttributeValue + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse' + description: Successful response + summary: Create Risk Level Attribute Value + tags: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Risk Level#create + x-speakeasy-group: Attributes + x-speakeasy-name-override: CreateRiskLevelAttributeValue + /api/v1/attributes/risk_levels/{id}: + delete: + description: Delete a risk level attribute value by id. + operationId: c1.api.attribute.v1.Attributes.DeleteRiskLevelAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse' + description: Successful response + summary: Delete Risk Level Attribute Value + tags: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Risk Level#delete + x-speakeasy-group: Attributes + x-speakeasy-name-override: DeleteRiskLevelAttributeValue + get: + description: Get a risk level attribute value by id. + operationId: c1.api.attribute.v1.Attributes.GetRiskLevelAttributeValue + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.GetRiskLevelAttributeValueResponse' + description: Successful response + summary: Get Risk Level Attribute Value + tags: + - Risk Level + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Risk Level#read + terraform-resource: Risk Level#read + x-speakeasy-group: Attributes + x-speakeasy-name-override: GetRiskLevelAttributeValue + /api/v1/attributes/types: + get: + description: List all attribute types. + operationId: c1.api.attribute.v1.Attributes.ListAttributeTypes + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeTypesResponse' + description: ListAttributeTypesResponse is the response for listing attribute types. + summary: List Attribute Types + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListAttributeTypes + /api/v1/attributes/types/{attribute_type_id}/values: + get: + description: List all attribute values for a given attribute type. + operationId: c1.api.attribute.v1.Attributes.ListAttributeValues + parameters: + - in: path + name: attribute_type_id + required: true + schema: + description: The attributeTypeId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - ignoreEmpty: - description: |- - IgnoreEmpty specifies that the validation rules of this field should be - evaluated only if the field is not empty - readOnly: false - type: boolean - in: - description: |- - In specifies that this field must be equal to one of the specified - values - items: - format: uint64 - type: string - nullable: true - readOnly: false - type: array - lt: - description: |- - Lt specifies that this field must be less than the specified value, - exclusive - format: uint64 - readOnly: false + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeValuesResponse' + description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. + summary: List Attribute Values + tags: + - Attribute + x-speakeasy-group: Attributes + x-speakeasy-name-override: ListAttributeValues + /api/v1/auth-configs: + get: + description: List returns all authentication provider configurations for the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.List + parameters: + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: A pagination token returned from a previous List call. type: string - lte: - description: |- - Lte specifies that this field must be less than or equal to the - specified value, inclusive - format: uint64 - readOnly: false + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceListResponse' + description: Successful response + summary: List + tags: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: List + post: + description: Create registers a new authentication provider configuration for the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse' + description: Successful response + summary: Create + tags: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: Create + /api/v1/auth-configs/{id}: + delete: + description: Delete removes an authentication provider configuration from the tenant. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the authentication provider configuration to delete. type: string - notIn: - description: |- - NotIn specifies that this field cannot be equal to one of the specified - values - items: - format: uint64 - type: string - nullable: true - readOnly: false - type: array - title: U Int 64 Rules - type: object - x-speakeasy-name-override: UInt64Rules - securitySchemes: - bearerAuth: - scheme: bearer - type: http - oauth: - description: |- - This API uses OAuth2 with the Client Credential flow. - Client Credentials must be sent in the BODY, not the headers. - For an example of how to implement this, refer to the [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187) function. - flows: - clientCredentials: - scopes: {} - tokenUrl: /auth/v1/token - type: oauth2 -info: - description: The C1 API is a HTTP API for managing C1 resources. - title: C1 API - version: 0.1.0-alpha -openapi: 3.1.0 -paths: - /api/v1/a2ui/conversations/{conversation_id}/surfaces: + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse' + description: Successful response + summary: Delete + tags: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: Delete get: - description: ListSurfaces returns active surfaces for a conversation. - operationId: c1.api.a2ui.v1.A2UIService.ListSurfaces + description: Get retrieves a single authentication provider configuration by its ID. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Get parameters: - in: path - name: conversation_id + name: id required: true schema: - description: The conversationId field. - readOnly: false + description: The unique identifier of the authentication provider configuration to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfacesResponse' - description: A2UIServiceListSurfacesResponse returns active surfaces. - summary: List Surfaces + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse' + description: Successful response + summary: Get tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: ListSurfaces - /api/v1/a2ui/surfaces/{surface_id}/actions: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: Get post: - description: SubmitAction handles user actions on A2UI surfaces. - operationId: c1.api.a2ui.v1.A2UIService.SubmitAction + description: Update modifies an existing authentication provider configuration. Use the update mask to specify which fields to change. + operationId: c1.api.auth_config.v1.TenantAuthConfigService.Update parameters: - in: path - name: surface_id + name: id required: true schema: - description: The surfaceId field. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionRequestInput' + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceSubmitActionResponse' - description: A2UIServiceSubmitActionResponse returns the result of an action. - summary: Submit Action + $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse' + description: Successful response + summary: Update tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: SubmitAction - /api/v1/a2ui/surfaces/{surface_id}/feedback: + - Auth Config + x-speakeasy-group: TenantAuthConfig + x-speakeasy-name-override: Update + /api/v1/auth/introspect: get: - description: ListSurfaceFeedback lists feedback for a surface. - operationId: c1.api.a2ui.v1.A2UIService.ListSurfaceFeedback + description: Introspect returns the current user's principle_id, user_id and a list of roles, permissions, and enabled features. + operationId: c1.api.auth.v1.Auth.Introspect + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.auth.v1.IntrospectResponse' + description: IntrospectResponse contains information about the current user who is authenticated. + summary: Introspect + tags: + - Auth + x-speakeasy-group: Auth + x-speakeasy-name-override: Introspect + /api/v1/automation_executions: + get: + description: List all automation executions in the tenant with pagination support. + operationId: c1.api.automations.v1.AutomationExecutionService.ListAutomationExecutions + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationExecutionsResponse' + description: Successful response + summary: List Automation Executions + tags: + - Automations + x-speakeasy-group: AutomationExecution + x-speakeasy-name-override: ListAutomationExecutions + /api/v1/automation_executions/{id}: + get: + description: Retrieve a single automation execution by its unique identifier, with optional expanded related objects. + operationId: c1.api.automations.v1.AutomationExecutionService.GetAutomationExecution parameters: - in: path - name: surface_id + name: id required: true schema: - description: The surfaceId field. - readOnly: false + description: The unique identifier of the automation execution to retrieve. + format: int64 type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceListSurfaceFeedbackResponse' - description: A2UIServiceListSurfaceFeedbackResponse returns feedback for a surface. - summary: List Surface Feedback + $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationExecutionResponse' + description: Successful response + summary: Get Automation Execution tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: ListSurfaceFeedback + - Automations + x-speakeasy-group: AutomationExecution + x-speakeasy-name-override: GetAutomationExecution + /api/v1/automation_executions/{id}/actions/terminate: post: - description: CreateSurfaceFeedback submits feedback for a surface with a snapshot. - operationId: c1.api.a2ui.v1.A2UIService.CreateSurfaceFeedback + description: Terminate a running automation execution asynchronously, stopping it and marking it as terminated. + operationId: c1.api.automations.v1.AutomationExecutionActionsService.TerminateAutomation parameters: - in: path - name: surface_id + name: id required: true schema: - description: The surfaceId field. - readOnly: false + description: The unique identifier of the automation execution to terminate. + format: int64 type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.a2ui.v1.A2UIServiceCreateSurfaceFeedbackResponse' - description: A2UIServiceCreateSurfaceFeedbackResponse returns the created feedback. - summary: Create Surface Feedback + $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationResponse' + description: Successful response + summary: Terminate Automation tags: - - A 2 UI - x-speakeasy-group: A2UI - x-speakeasy-name-override: CreateSurfaceFeedback - /api/v1/access_review: + - Automations + x-speakeasy-group: AutomationExecutionActions + x-speakeasy-name-override: TerminateAutomation + /api/v1/automations: + get: + description: List all automations in the tenant with pagination support. + operationId: c1.api.automations.v1.AutomationService.ListAutomations + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationsResponse' + description: Successful response + summary: List Automations + tags: + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ListAutomations post: - description: Create creates a new access review campaign with the specified name, policy, and owners. - operationId: c1.api.accessreview.v1.AccessReviewService.Create + description: |- + Create a new automation with the specified steps, triggers, and + configuration. See get_authoring_guide for the AutomationStep contract + (step kinds, evaluate_expressions shape, CEL identifier scope). + + At create time, draft_automation_steps and draft_triggers default to + their published counterparts when omitted — callers writing a single + working version don't need to populate both. The draft/publish + distinction matters only on subsequent edits. + operationId: c1.api.automations.v1.AutomationService.CreateAutomation requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateRequest' + $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceCreateResponse' + $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationResponse' description: Successful response - summary: Create + summary: Create Automation tags: - - Access Review + - Automations x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access Review#create - x-speakeasy-group: AccessReview - x-speakeasy-name-override: Create - x-stability-level: draft - /api/v1/access_review/{access_review_id}/scope_and_entitlements: - get: - description: GetCampaignScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review campaign. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.GetCampaignScopeAndEntitlements + terraform-resource: Automation#create + x-speakeasy-group: Automation + x-speakeasy-name-override: CreateAutomation + /api/v1/automations/{id}: + delete: + description: Delete an automation by its unique identifier, removing it and its associated triggers. + operationId: c1.api.automations.v1.AutomationService.DeleteAutomation parameters: - in: path - name: access_review_id + name: id required: true schema: - description: The ID of the access review campaign to retrieve scope and entitlements for. - readOnly: false + description: The unique identifier of the automation to delete. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationResponse' description: Successful response - summary: Get Campaign Scope And Entitlements + summary: Delete Automation tags: - - Access Review + - Automations x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Access Review Setup#read - terraform-resource: Access Review Setup#read - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: GetCampaignScopeAndEntitlements - x-stability-level: stable - post: - description: SetCampaignScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review campaign. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeAndEntitlements + terraform-resource: Automation#delete + x-speakeasy-group: Automation + x-speakeasy-name-override: DeleteAutomation + get: + description: Retrieve a single automation by its unique identifier. + operationId: c1.api.automations.v1.AutomationService.GetAutomation parameters: - in: path - name: access_review_id + name: id required: true schema: - description: The ID of the access review campaign to configure. - readOnly: false + description: The unique identifier of the automation to retrieve. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetupEntitlementAndScopeServiceSetResponse' + $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationResponse' description: Successful response - summary: Set Campaign Scope And Entitlements + summary: Get Automation tags: - - Access Review + - Automations x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: - - Access Review Setup#create - - Access Review Setup#update - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: SetCampaignScopeAndEntitlements - x-stability-level: stable - /api/v1/access_review/{access_review_id}/scope_by_resource_type: + terraform-datasource: null + terraform-resource: Automation#read + x-speakeasy-group: Automation + x-speakeasy-name-override: GetAutomation post: - description: SetCampaignScopeByResourceType sets the campaign scope by selecting specific resource types to include in the review. - operationId: c1.api.accessreview.v1.AccessReviewSetupEntitlementService.SetCampaignScopeByResourceType + description: Update an existing automation's properties, steps, or triggers using a field mask. + operationId: c1.api.automations.v1.AutomationService.UpdateAutomation parameters: - in: path - name: access_review_id + name: id required: true schema: - description: The ID of the access review campaign to configure. - readOnly: false + description: The id field. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewSetScopeByResourceTypeResponse' + $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationResponse' description: Successful response - summary: Set Campaign Scope By Resource Type + summary: Update Automation tags: - - Access Review - x-speakeasy-group: AccessReviewSetupEntitlement - x-speakeasy-name-override: SetCampaignScopeByResourceType - x-stability-level: draft - /api/v1/access_review/{id}: - delete: - description: Delete transitions an access review campaign to the deleted state, along with its dependent objects. - operationId: c1.api.accessreview.v1.AccessReviewService.Delete + - Automations + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Automation#update + x-speakeasy-group: Automation + x-speakeasy-name-override: UpdateAutomation + /api/v1/automations/{id}/circuit_breaker/clear: + post: + description: |- + Clear the circuit breaker on an automation that was auto-disabled by the + rate cap. Future events flow normally; existing paused executions are not + affected (use ResolvePausedAutomationExecutions to run or cancel them). + operationId: c1.api.automations.v1.AutomationService.ClearAutomationCircuitBreaker parameters: - in: path name: id required: true schema: - description: The ID of the access review campaign to delete. - readOnly: false + description: |- + The unique identifier of the automation whose circuit breaker should + be cleared. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerResponse' description: Successful response - summary: Delete + summary: Clear Automation Circuit Breaker tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access Review#delete - x-speakeasy-group: AccessReview - x-speakeasy-name-override: Delete - x-stability-level: draft - get: - description: Get retrieves a single access review campaign by ID. - operationId: c1.api.accessreview.v1.AccessReviewService.Get + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ClearAutomationCircuitBreaker + /api/v1/automations/{id}/circuit_breaker/resolve_paused: + post: + description: |- + Decide what to do with the executions that were paused while the + automation's circuit breaker was tripped. Idempotent. + operationId: c1.api.automations.v1.AutomationService.ResolvePausedAutomationExecutions parameters: - in: path name: id required: true schema: - description: The ID of the access review campaign to retrieve. - readOnly: false + description: |- + The unique identifier of the automation whose paused executions should + be resolved. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceGetResponse' + $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse' description: Successful response - summary: Get + summary: Resolve Paused Automation Executions tags: - - Access Review - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access Review#read - terraform-resource: Access Review#read - x-speakeasy-group: AccessReview - x-speakeasy-name-override: Get - x-stability-level: draft + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ResolvePausedAutomationExecutions + /api/v1/automations/{id}/execute: post: - description: Update modifies an existing access review campaign. Use the update_mask to specify which fields to change. - operationId: c1.api.accessreview.v1.AccessReviewService.Update + description: Trigger an on-demand execution of an automation, returning the new execution's identifier. + operationId: c1.api.automations.v1.AutomationService.ExecuteAutomation parameters: - in: path name: id required: true schema: - description: The unique identifier of this access review campaign. - readOnly: false + description: The unique identifier of the automation to execute. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationResponse' description: Successful response - summary: Update + summary: Execute Automation tags: - - Access Review + - Automations + x-speakeasy-group: Automation + x-speakeasy-name-override: ExecuteAutomation + /api/v1/catalogs: + get: + description: Get a list of request catalogs. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The page_token field for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse' + description: Successful response + summary: List + tags: + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access Review#update - x-speakeasy-group: AccessReview - x-speakeasy-name-override: Update - x-stability-level: draft - /api/v1/access_review_template: + terraform-datasource: Request Catalogs#read + terraform-resource: null + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: List post: - description: Create creates a new access review template that defines a reusable configuration for launching campaigns. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Create + description: Creates a new request catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceCreateResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. summary: Create tags: - - Access Review Template + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access Review Template#create - x-speakeasy-group: AccessReviewTemplate + terraform-resource: Access_Profile#create + x-speakeasy-group: RequestCatalogManagement x-speakeasy-name-override: Create - x-stability-level: draft - /api/v1/access_review_template/{access_review_template_id}/scope_and_entitlements: + /api/v1/catalogs/{catalog_id}/requestable_entitlementIDs: get: - description: GetScopeAndEntitlements retrieves the current scope configuration and selected entitlements for an access review template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.GetScopeAndEntitlements + description: List all requestable entitlement IDs in a catalog without pagination. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListAllEntitlementIdsPerApp parameters: - in: path - name: access_review_template_id + name: catalog_id required: true schema: - description: The ID of the access review template to retrieve scope and entitlements for. - readOnly: false + description: The unique identifier of the access profile. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' - description: Successful response - summary: Get Scope And Entitlements + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse' + description: The response message containing all requestable entitlement references in the catalog. + summary: List All Entitlement Ids Per App tags: - - Access Review Templates + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Access Review Template Setup#read - terraform-resource: Access Review Template Setup#read - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: GetScopeAndEntitlements - x-stability-level: stable - post: - description: SetScopeAndEntitlements replaces the scope configuration and selected entitlements for an access review template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeAndEntitlements + terraform-datasource: null + terraform-resource: Access_Profile_Requestable_Entries#read + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListAllEntitlementIdsPerApp + /api/v1/catalogs/{catalog_id}/requestable_entitlements: + get: + description: List entitlements in a catalog that are requestable. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsPerCatalog parameters: - in: path - name: access_review_template_id + name: catalog_id required: true schema: - description: The ID of the access review template to configure. - readOnly: false + description: The catalogId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementServiceSetResponse' - description: Successful response - summary: Set Scope And Entitlements + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse' + description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. + summary: List Entitlements Per Catalog tags: - - Access Review Templates - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: - - Access Review Template Setup#create - - Access Review Template Setup#update - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: SetScopeAndEntitlements - x-stability-level: stable - /api/v1/access_review_template/{access_review_template_id}/scope_by_resource_type: + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListEntitlementsPerCatalog + /api/v1/catalogs/{catalog_id}/requestable_entitlements/update: post: - description: SetScopeByResourceType sets the template scope by selecting specific resource types to include in campaigns created from this template. - operationId: c1.api.accessreview.v1.AccessReviewTemplateSetupEntitlementService.SetScopeByResourceType + description: Replace the full set of requestable entitlements in a catalog with the provided list. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.UpdateAppEntitlements parameters: - in: path - name: access_review_template_id + name: catalog_id required: true schema: - description: The ID of the access review template to configure. - readOnly: false + description: The Id of the request catalog to get app entitlement to. This is a URL value. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateSetScopeByResourceTypeResponse' - description: Successful response - summary: Set Scope By Resource Type + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse' + description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. + summary: Update App Entitlements tags: - - Access Review Templates - x-speakeasy-group: AccessReviewTemplateSetupEntitlement - x-speakeasy-name-override: SetScopeByResourceType - x-stability-level: draft - /api/v1/access_review_template/{id}: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Access_Profile_Requestable_Entries#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: UpdateAppEntitlements + /api/v1/catalogs/{catalog_id}/requestable_entries: delete: - description: Delete an access review template. The template can no longer be used to create campaigns. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Delete + description: Remove requestable entitlements from a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAppEntitlements parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The ID of the access review template to delete. - readOnly: false + description: The catalogId for the catalog to remove entitlements from. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceDeleteResponse' - description: Successful response - summary: Delete + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse' + description: Empty response with a status code indicating success + summary: Remove App Entitlements tags: - - Access Review Template + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access Review Template#delete - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Delete - x-stability-level: draft - get: - description: Get retrieves a single access review template by ID. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Get + terraform-resource: Access_Profile_Requestable_Entries#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: RemoveAppEntitlements + post: + description: Add requestable entitlements to a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAppEntitlements parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The ID of the access review template to retrieve. - readOnly: false + description: The Id of the request catalog to add app entitlements to. This is a URL value. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceGetResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Add App Entitlements tags: - - Access Review Template + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Access Review Template#read - terraform-resource: Access Review Template#read - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Get - x-stability-level: draft - post: - description: Update modifies an existing access review template. Use the update_mask to specify which fields to change. - operationId: c1.api.accessreview.v1.AccessReviewTemplateService.Update + terraform-resource: Access_Profile_Requestable_Entries#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: AddAppEntitlements + /api/v1/catalogs/{catalog_id}/requestable_entries/{app_id}/{entitlement_id}: + delete: + description: Delete a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteRequestableEntry parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The unique identifier of this template. - readOnly: false + description: The ID of the access profile (catalog) + type: string + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The ID of the entitlement type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewTemplateServiceUpdateResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse' + description: Empty response for delete operation + summary: Delete Requestable Entry tags: - - Access Review Template + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access Review Template#update - x-speakeasy-group: AccessReviewTemplate - x-speakeasy-name-override: Update - x-stability-level: draft - /api/v1/access_reviews: + terraform-resource: Access_Profile_Requestable_Entry#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: DeleteRequestableEntry get: - description: List returns a paginated list of access review campaigns. - operationId: c1.api.accessreview.v1.AccessReviewService.List + description: Get a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetRequestableEntry parameters: - - in: query - name: page_size + - in: path + name: catalog_id + required: true schema: - description: The maximum number of results to return per page. Maximum 100. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + description: The ID of the access profile (catalog) + type: string + - in: path + name: app_id + required: true schema: - description: Pagination token from a previous List response to fetch the next page. - readOnly: false + description: The ID of the app that contains the entitlement + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The ID of the entitlement type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessreview.v1.AccessReviewServiceListResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse' + description: Response containing the requested entry + summary: Get Requestable Entry tags: - - Access Review + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Access Reviews#read - terraform-resource: Access Reviews#read - x-speakeasy-group: AccessReview - x-speakeasy-name-override: List - x-stability-level: draft - /api/v1/accessconflict: - post: - description: Create a new conflict monitor for defining a Separation of Duty rule. Entitlement sets are bound separately via AppEntitlementMonitorBindingService. - operationId: c1.api.accessconflict.v1.AccessConflictService.CreateMonitor + terraform-datasource: Access_Profile_Requestable_Entry#read + terraform-resource: null + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: GetRequestableEntry + put: + description: Create a single requestable entry + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateRequestableEntry + parameters: + - in: path + name: catalog_id + required: true + schema: + description: The ID of the access profile (catalog) to add the entitlement to + type: string + - in: path + name: app_id + required: true + schema: + description: The ID of the app that contains the entitlement + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The ID of the entitlement to add to the request catalog + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorCreateRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Create Monitor + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse' + description: Response containing the created requestable entry + summary: Create Requestable Entry tags: - - Access Conflict + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#create - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: CreateMonitor - /api/v1/accessconflict/{id}: + terraform-resource: Access_Profile_Requestable_Entry#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: CreateRequestableEntry + /api/v1/catalogs/{catalog_id}/visibility_bindings: delete: - description: Delete a conflict monitor and its associated entitlement set bindings. - operationId: c1.api.accessconflict.v1.AccessConflictService.DeleteMonitor + description: Remove visibility bindings (access entitlements) from a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAccessEntitlements parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The unique identifier of the conflict monitor to delete. - readOnly: false + description: The catalogId for the catalog to remove access entitlements from. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorDeleteResponse' - description: The response message for deleting a conflict monitor. - summary: Delete Monitor + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Remove Access Entitlements tags: - - Access Conflict + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#delete - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: DeleteMonitor - get: - description: Retrieve a single conflict monitor by ID. - operationId: c1.api.accessconflict.v1.AccessConflictService.GetMonitor + terraform-resource: Access_Profile_Visibility_Bindings#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: RemoveAccessEntitlements + post: + description: Add visibility bindings (access entitlements) to a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAccessEntitlements parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The unique identifier of the conflict monitor to retrieve. - readOnly: false + description: The Id of the request catalog to add access entitlements to. This is a URL value. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Get Monitor + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse' + description: Empty response with a status code indicating success. + summary: Add Access Entitlements tags: - - Access Conflict + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Access_Conflict#read - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: GetMonitor - post: - description: Update the display name, description, or notification settings of a conflict monitor. - operationId: c1.api.accessconflict.v1.AccessConflictService.UpdateMonitor + terraform-resource: Access_Profile_Visibility_Bindings#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: AddAccessEntitlements + /api/v1/catalogs/{catalog_id}/visibility_entitlements: + get: + description: List visibility bindings (access entitlements) for a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsForAccess parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The unique identifier of the conflict monitor to update. - readOnly: false + description: The catalogId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitorUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.ConflictMonitor' - description: |- - A conflict monitor defines a Separation of Duty rule between two entitlement sets. - It detects when any user holds entitlements from both set A and set B simultaneously. - summary: Update Monitor + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse' + description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. + summary: List Entitlements For Access tags: - - Access Conflict - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Conflict#update - x-speakeasy-group: AccessConflict - x-speakeasy-name-override: UpdateMonitor - /api/v1/appentitlementmonitorbinding: + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ListEntitlementsForAccess + /api/v1/catalogs/{id}: delete: - description: Remove an app entitlement from a conflict monitor's entitlement set. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.DeleteAppEntitlementMonitorBinding + description: Delete a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The Id of the RequestCatalog to delete. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.DeleteAppEntitlementMonitorBindingResponse' - description: The response message for deleting an app entitlement monitor binding. - summary: Delete App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse' + description: Empty response with a status code indicating success. + summary: Delete tags: - - App Entitlement Monitor Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Monitor_Binding#delete - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: DeleteAppEntitlementMonitorBinding - post: - description: Bind an app entitlement to one side (A or B) of a conflict monitor. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.CreateAppEntitlementMonitorBinding - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.CreateAppEntitlementMonitorBindingRequest' + terraform-resource: Access_Profile#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: Delete + get: + description: Get a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' - description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. - summary: Create App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. + summary: Get tags: - - App Entitlement Monitor Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Monitor_Binding#create - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: CreateAppEntitlementMonitorBinding - /api/v1/appentitlementmonitorbinding/get: + terraform-datasource: Access_Profile#read + terraform-resource: Access_Profile#read + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: Get post: - description: Retrieve a single binding that associates an app entitlement with one side of a conflict monitor. - operationId: c1.api.accessconflict.v1.AppEntitlementMonitorBindingService.GetAppEntitlementMonitorBinding + description: Update a catalog. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The id of the request catalog. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.GetAppEntitlementMonitorBindingRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.accessconflict.v1.AppEntitlementMonitorBinding' - description: Represents the association of an app entitlement with one side (A or B) of a conflict monitor. - summary: Get App Entitlement Monitor Binding + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' + description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. + summary: Update tags: - - App Entitlement Monitor Binding + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App_Entitlement_Monitor_Binding#read - terraform-resource: App_Entitlement_Monitor_Binding#read - x-speakeasy-group: AppEntitlementMonitorBinding - x-speakeasy-name-override: GetAppEntitlementMonitorBinding - /api/v1/apps: - get: - description: List all apps. - operationId: c1.api.app.v1.Apps.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + terraform-resource: Access_Profile#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: Update + /api/v1/catalogs/{request_catalog_id}/bundle_automation: + delete: + description: Delete the bundle automation rule for a catalog, stopping automatic membership syncing. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteBundleAutomation + parameters: + - in: path + name: request_catalog_id + required: true schema: - description: The pageToken field. - readOnly: false + description: The unique identifier of the access profile whose automation should be deleted. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppsResponse' - description: The ListAppsResponse message contains a list of results and a nextPageToken if applicable. - summary: List - tags: - - App - x-speakeasy-group: Apps - x-speakeasy-name-override: List - post: - description: Create a new manual app without a connector. - operationId: c1.api.app.v1.Apps.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppRequest' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppResponse' - description: Returns the new app's values. - summary: Create + $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationResponse' + description: The response message for deleting a bundle automation. + summary: Delete Bundle Automation tags: - - App + - Request Catalog x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App#create - x-speakeasy-group: Apps - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/access_request_defaults: + terraform-resource: BundleAutomation#delete + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: DeleteBundleAutomation get: - description: Retrieve the current access request default settings for an app. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.GetAppAccessRequestsDefaults + description: Get bundle automation + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetBundleAutomation parameters: - in: path - name: app_id + name: request_catalog_id required: true schema: - description: The ID of the app to retrieve access request defaults for. - readOnly: false + description: The requestCatalogId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' description: Successful response - summary: Get App Access Requests Defaults + summary: Get Bundle Automation tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: GetAppAccessRequestsDefaults + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: BundleAutomation#read + terraform-resource: BundleAutomation#read + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: GetBundleAutomation post: - description: Create or replace the access request default settings for an app. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CreateAppAccessRequestsDefaults + description: Create or update the bundle automation rule for a catalog that automatically syncs catalog membership. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.SetBundleAutomation parameters: - in: path - name: app_id + name: request_catalog_id required: true schema: - description: The app id for the app access request rule - readOnly: false + description: The unique identifier of the access profile to set the automation on. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaultsInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.SetBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' description: Successful response - summary: Create App Access Requests Defaults + summary: Set Bundle Automation tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: CreateAppAccessRequestsDefaults - /api/v1/apps/{app_id}/access_request_defaults/cancel: + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: BundleAutomation#update + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: SetBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/create: post: - description: Cancel an in-progress apply operation for the app's access request defaults. - operationId: c1.api.app.v1.AppAccessRequestsDefaultsService.CancelAppAccessRequestsDefaults + description: Create a new bundle automation rule for a catalog that automatically syncs catalog membership from a query. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateBundleAutomation parameters: - in: path - name: app_id + name: request_catalog_id required: true schema: - description: The ID of the app whose access request defaults apply operation should be cancelled. - readOnly: false + description: The unique identifier of the access profile to create the automation for. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CancelAccessRequestDefaultsRequestInput' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppAccessRequestDefaults' + $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' description: Successful response - summary: Cancel App Access Requests Defaults + summary: Create Bundle Automation tags: - - AppAccessRequestDefaults - x-speakeasy-group: AppAccessRequestsDefaults - x-speakeasy-name-override: CancelAppAccessRequestsDefaults - /api/v1/apps/{app_id}/app_users: - get: - description: List app user accounts within a specific app, with pagination support. - operationId: c1.api.app.v1.AppUserService.List + - Request Catalog + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: BundleAutomation#create + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: CreateBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/resume: + post: + description: Resume a bundle automation that was paused by the circuit breaker after detecting excessive membership changes. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ResumePausedBundleAutomation parameters: - in: path - name: app_id + name: request_catalog_id required: true schema: - description: The ID of the app to list users for. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The token for fetching the next page of results. - readOnly: false + description: The unique identifier of the access profile whose automation should be resumed. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListResponse' - description: The response message for listing app users. - summary: List + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse' + description: The response message for resuming a paused bundle automation. + summary: Resume Paused Bundle Automation tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: List - /api/v1/apps/{app_id}/app_users/{app_user_id}/credentials: - get: - description: List credentials associated with a specific app user account. - operationId: c1.api.app.v1.AppUserService.ListAppUserCredentials + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ResumePausedBundleAutomation + /api/v1/catalogs/{request_catalog_id}/bundle_automation/run: + post: + description: Trigger an immediate execution of a catalog's bundle automation, bypassing the normal schedule. + operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ForceRunBundleAutomation parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that the user belongs to. - readOnly: false - type: string - - in: path - name: app_user_id + name: request_catalog_id required: true schema: - description: The ID of the app user whose credentials to list. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The token for fetching the next page of results. - readOnly: false + description: The unique identifier of the access profile whose automation should be run. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceListCredentialsResponse' - description: The response message for listing credentials of an app user. - summary: List App User Credentials + $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse' + description: The response message for triggering a bundle automation run. + summary: Force Run Bundle Automation tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: ListAppUserCredentials - /api/v1/apps/{app_id}/connectors: - get: - description: List connectors for an app. - operationId: c1.api.app.v1.ConnectorService.List - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + - Request Catalog + x-speakeasy-group: RequestCatalogManagement + x-speakeasy-name-override: ForceRunBundleAutomation + /api/v1/connector-authoring/activations: + post: + description: |- + ActivateRevision redeems a one-time approval token to activate a built + connector revision onto its instance connector. It is OWNER-only. + Double-activate protection is the single-use approval token itself: redeeming + it is a compare-and-swap that rejects a second redemption of the same token. + idempotency_key is optional and reserved for a future replay-result cache. + operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.ActivateRevision + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceListResponse' - description: The ConnectorServiceListResponse message contains a list of results and a nextPageToken if applicable - summary: List + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceActivateRevisionResponse' + description: Successful response + summary: Activate Revision tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: List + - Connector Authoring Activation + x-speakeasy-group: ConnectorAuthoringActivation + x-speakeasy-name-override: ActivateRevision + /api/v1/connector-authoring/rollbacks: post: - description: Create a connector that is pending a connector config. - operationId: c1.api.app.v1.ConnectorService.CreateDelegated - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string + description: |- + RollbackRevision redeems a one-time approval token (bound to the rollback + target's integrity root) to re-point the published + instance pointers at a + previously activated, still-servable revision under a strictly greater + activation epoch. It is OWNER-only. The rolled-back-FROM revision's serve + state is untouched — the pointer move alone stops it serving; permanently + ending a revision's serve eligibility is a platform kill-switch operation, + not a tenant API verb. + operationId: c1.api.connector_authoring.v1.ConnectorAuthoringActivationService.RollbackRevision requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateDelegatedRequestInput' + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' - description: The ConnectorServiceCreateResponse is the response returned from creating a connector. - summary: Create Delegated + $ref: '#/components/schemas/c1.api.connector_authoring.v1.ConnectorAuthoringServiceRollbackRevisionResponse' + description: Successful response + summary: Rollback Revision tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: CreateDelegated - /api/v1/apps/{app_id}/connectors/{connector_id}/confirm_sync_valid/{sync_lifecycle_id}: + - Connector Authoring Activation + x-speakeasy-group: ConnectorAuthoringActivation + x-speakeasy-name-override: RollbackRevision + /api/v1/connectorcatalog: post: - description: Confirm that a sync which errored due to a data drop is valid, overriding the error and triggering a new sync. Only applicable when the sync status is ERRORED_NO_DATA. - operationId: c1.api.app.v1.ConnectorService.ConfirmSyncValid - parameters: - - in: path - name: app_id - required: true - schema: - description: The AppID of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id - required: true - schema: - description: The ConnectorID of the connector that we are confirming the sync for. - readOnly: false - type: string - - in: path - name: sync_lifecycle_id - required: true - schema: - description: The completed lifecycle id of the most recent sync we want to validate - readOnly: false - type: string + description: Return the configuration schema describing the fields required to set up a connector of the specified type. + operationId: c1.api.integration.connector.v1.ConnectorCatalogService.ConfigurationSchema requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidRequestInput' + $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConfirmSyncValidResponse' - description: Empty response body. Status code indicates success. - summary: Confirm Sync Valid + $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse' + description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. + summary: Configuration Schema tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ConfirmSyncValid - /api/v1/apps/{app_id}/connectors/{connector_id}/credentials/{id}: + - Connector Catalog + x-speakeasy-group: ConnectorCatalog + x-speakeasy-name-override: ConfigurationSchema + /api/v1/credential-inventory-policies: get: - description: Get credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.GetCredentials + description: List all credential inventory policies in your tenant, one page at a time. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.List parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id - required: true + - in: query + name: page_size schema: - description: The connectorId of the connector that we are getting the credentials for. - readOnly: false - type: string - - in: path - name: id - required: true + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token schema: - description: The id of the ConnectorCredential. - readOnly: false + description: A pagination token from a previous List response. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetCredentialsResponse' - description: ConnectorServiceGetCredentialsResponse is the response returned by the get method. - summary: Get Credentials + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceListResponse' + description: Successful response + summary: List tags: - - Connector - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: ConnectorCredential#read - terraform-resource: ConnectorCredential#read - x-speakeasy-group: Connector - x-speakeasy-name-override: GetCredentials + - Credential Inventory + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: List post: - description: Revoke credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.RevokeCredential - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId of the connector that we are revoking the credentials for. - readOnly: false - type: string - - in: path - name: id - required: true - schema: - description: The id of the ConnectorCredential. - readOnly: false - type: string + description: Create a credential inventory policy. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRevokeCredentialResponse' - description: Empty response body. Status code indicates success. - summary: Revoke Credential + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceCreateResponse' + description: Successful response + summary: Create tags: - - Connector + - Credential Inventory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: ConnectorCredential#delete - x-speakeasy-group: Connector - x-speakeasy-name-override: RevokeCredential - /api/v1/apps/{app_id}/connectors/{connector_id}/force_sync: - post: - description: Trigger an immediate sync for a connector. The sync is queued and may not start instantly. - operationId: c1.api.app.v1.ConnectorService.ForceSync + terraform-resource: CredentialInventoryPolicy#create + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Create + /api/v1/credential-inventory-policies/{id}: + delete: + description: Delete a credential inventory policy by ID. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Delete parameters: - in: path - name: app_id - required: true - schema: - description: The AppID of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id + name: id required: true schema: - description: The ConnectorID of the connector that we are forcing to sync. - readOnly: false + description: The ID of the policy to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ForceSyncRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ForceSyncResponse' - description: Empty response body. Status code indicates success. - summary: Force Sync + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceDeleteResponse' + description: Successful response + summary: Delete tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ForceSync - /api/v1/apps/{app_id}/connectors/{connector_id}/pause: - post: - description: Pause syncing and provisioning for a connector. No new syncs or grant/revoke operations will run until the connector is resumed. - operationId: c1.api.app.v1.ConnectorService.PauseSync + - Credential Inventory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: CredentialInventoryPolicy#delete + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Delete + get: + description: Get a credential inventory policy by ID. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Get parameters: - in: path - name: app_id - required: true - schema: - description: The AppID of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id + name: id required: true schema: - description: The ConnectorID of the connector that we are pausing the sync for. - readOnly: false + description: The ID of the policy to retrieve. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.PauseSyncRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.PauseSyncResponse' - description: Empty response body. Status code indicates success. - summary: Pause Sync + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceGetResponse' + description: Successful response + summary: Get tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: PauseSync - /api/v1/apps/{app_id}/connectors/{connector_id}/resume: + - Credential Inventory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: CredentialInventoryPolicy#read + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Get post: - description: Resume syncing and provisioning for a connector that was previously paused. Clears the paused state and triggers a new sync. - operationId: c1.api.app.v1.ConnectorService.ResumeSync + description: |- + Update a credential inventory policy. Supply the policy object and an + update mask listing the fields to change; omitted fields are left as-is. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Update parameters: - in: path - name: app_id - required: true - schema: - description: The AppID of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id + name: id required: true schema: - description: The ConnectorID of the connector that we are resuming the sync for. - readOnly: false + description: Unique identifier for the policy. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ResumeSyncResponse' - description: Empty response body. Status code indicates success. - summary: Resume Sync + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceUpdateResponse' + description: Successful response + summary: Update tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ResumeSync - /api/v1/apps/{app_id}/connectors/{connector_id}/schedule: - post: - description: Update the sync schedule for a connector. - operationId: c1.api.app.v1.ConnectorService.UpdateConnectorSchedule - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId of the connector whose schedule is being updated. - readOnly: false - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleRequestInput' + - Credential Inventory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: CredentialInventoryPolicy#update + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Update + /api/v1/decoys: + get: + description: List returns decoys for the tenant, paginated. + operationId: c1.api.decoy.v1.DecoyService.List responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateConnectorScheduleResponse' - description: Empty response body. Status code indicates success. - summary: Update Connector Schedule + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceListResponse' + description: Successful response + summary: List tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: UpdateConnectorSchedule - x-stability-level: alpha - /api/v1/apps/{app_id}/connectors/{connector_id}/syncs/{sync_id}/download_url: - get: - description: GetConnectorSyncDownloadURL generates a short-lived download URL for a completed connector sync artifact. - operationId: c1.api.app.v1.ConnectorService.GetConnectorSyncDownloadURL - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: connector_id - required: true - schema: - description: The connectorId field. - readOnly: false - type: string - - in: path - name: sync_id - required: true - schema: - description: The syncId field. - readOnly: false - type: string + - Decoy + x-speakeasy-group: Decoy + x-speakeasy-name-override: List + post: + description: |- + Create mints a decoy credential and returns the one-time vending + material exactly once. The Decoy id is server-set; the credential's + secret cannot be retrieved again after this response. + operationId: c1.api.decoy.v1.DecoyService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetConnectorSyncDownloadURLResponse' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceCreateResponse' description: Successful response - summary: Get Connector Sync Download Url + summary: Create tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: GetConnectorSyncDownloadURL - /api/v1/apps/{app_id}/connectors/{id}: + - Decoy + x-speakeasy-group: Decoy + x-speakeasy-name-override: Create + /api/v1/decoys/{id}: delete: - description: Delete a connector. - operationId: c1.api.app.v1.ConnectorService.Delete + description: Delete soft-deletes a decoy and disables the paired credential row. + operationId: c1.api.decoy.v1.DecoyService.Delete parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string - in: path name: id required: true schema: - description: The id of the connector. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceDeleteResponse' - description: Empty response body. Status code indicates success. + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceDeleteResponse' + description: Successful response summary: Delete tags: - - Connector - x-speakeasy-group: Connector + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Delete get: - description: Get a connector. - operationId: c1.api.app.v1.ConnectorService.Get + description: Get returns a decoy by id. + operationId: c1.api.decoy.v1.DecoyService.Get parameters: - - in: path - name: app_id - required: true - schema: - description: The appId of the app the connector is attached to. - readOnly: false - type: string - in: path name: id required: true schema: - description: The id of the connector. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceGetResponse' - description: The ConnectorServiceGetResponse message contains the connectorView, and an expand mask. + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceGetResponse' + description: Successful response summary: Get tags: - - Connector - x-speakeasy-group: Connector + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Get - post: - description: Update a connector. - operationId: c1.api.app.v1.ConnectorService.Update + patch: + description: |- + Update modifies mutable metadata on a decoy. The decoy variant is + fixed at Create -- rotate the secret with Rotate instead. + operationId: c1.api.decoy.v1.DecoyService.Update parameters: - - in: path - name: app_id - required: true - schema: - description: The id of the app the connector is associated with. - readOnly: false - type: string - in: path name: id required: true schema: - description: The id of the connector. - readOnly: false + description: The id field. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' - description: ConnectorServiceUpdateResponse is the response returned by the update method. + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceUpdateResponse' + description: Successful response summary: Update tags: - - Connector - x-speakeasy-group: Connector + - Decoy + x-speakeasy-group: Decoy x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/connectors/create: + /api/v1/decoys/{id}/rotate: post: - description: Create a configured connector. - operationId: c1.api.app.v1.ConnectorService.Create + description: |- + Rotate re-mints the paired credential's secret material, preserves + the decoy_id binding, and returns the new one-time vending material. + operationId: c1.api.decoy.v1.DecoyService.Rotate parameters: - in: path - name: app_id + name: id required: true schema: - description: The appId field. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceCreateResponse' - description: The ConnectorServiceCreateResponse is the response returned from creating a connector. - summary: Create + $ref: '#/components/schemas/c1.api.decoy.v1.DecoyServiceRotateResponse' + description: Successful response + summary: Rotate tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/entitlements: + - Decoy + x-speakeasy-group: Decoy + x-speakeasy-name-override: Rotate + /api/v1/decoys/search: + post: + description: |- + Search decoys with free-text query and filters for kind, status, + and annotation key. + operationId: c1.api.decoy.v1.DecoySearchService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.decoy.v1.DecoySearchResponse' + description: Successful response + summary: Search + tags: + - Decoy + x-speakeasy-group: DecoySearch + x-speakeasy-name-override: Search + /api/v1/directories: get: - description: List app entitlements associated with an app. - operationId: c1.api.app.v1.AppEntitlements.List + description: List directories. + operationId: c1.api.directory.v1.DirectoryService.List parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceListResponse' + description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. summary: List tags: - - App Entitlement - x-speakeasy-group: AppEntitlements + - Directory + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: + - Directory#read + - Directories#read + terraform-resource: null + x-speakeasy-group: Directory x-speakeasy-name-override: List post: - description: Create a new app entitlement for an app. This is used to define a custom permission, group, or role within the app. - operationId: c1.api.app.v1.AppEntitlements.Create - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app to create the entitlement in. - readOnly: false - type: string + description: Create a directory. + operationId: c1.api.directory.v1.DirectoryService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementRequestInput' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateResponse' + description: The DirectoryServiceCreateResponse message. summary: Create tags: - - App Entitlement + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#create - x-speakeasy-group: AppEntitlements + terraform-resource: Directory#create + x-speakeasy-group: Directory x-speakeasy-name-override: Create - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/add-manual-user: - post: - description: Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. - operationId: c1.api.app.v1.AppEntitlements.AddManuallyManagedMembers + /api/v1/directories/{app_id}: + delete: + description: Delete a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Delete parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The ID of the app entitlement to add manually managed members to. - readOnly: false + description: The app_id of the directory to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddManuallyManagedUsersRequestInput' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ManuallyManagedUsersResponse' - description: Successful response - summary: Add Manually Managed Members + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteResponse' + description: Empty response with a status code indicating success. + summary: Delete tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: AddManuallyManagedMembers - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation: - delete: - description: Delete the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.DeleteAutomation + - Directory + x-speakeasy-group: Directory + x-speakeasy-name-override: Delete + get: + description: Get a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Get parameters: - in: path name: app_id required: true schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The ID of the app entitlement whose automation to delete. - readOnly: false + description: The appId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAutomationResponse' - description: Successful response - summary: Delete Automation + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceGetResponse' + description: |- + The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the + location in the expanded array that items are expanded as indicated by the expand mask in the request. + summary: Get tags: - - App Entitlement Automation + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#delete - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: DeleteAutomation - get: - description: Get the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.GetAutomation + terraform-datasource: null + terraform-resource: Directory#read + x-speakeasy-group: Directory + x-speakeasy-name-override: Get + put: + description: Update a directory by app_id. + operationId: c1.api.directory.v1.DirectoryService.Update parameters: - in: path name: app_id required: true schema: - description: The ID of the app that is associated with the app entitlement. - readOnly: true - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The unique ID for the App Entitlement. - readOnly: true + description: The appId field. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceGetAutomationResponse' + $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateResponse' description: Successful response - summary: Get Automation + summary: Update tags: - - App Entitlement Automation + - Directory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: App Entitlement Automation#read - terraform-resource: App Entitlement Automation#read - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: GetAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/create: + terraform-resource: Directory#update + x-speakeasy-group: Directory + x-speakeasy-name-override: Update + /api/v1/findings: post: - description: Create an automation rule for an app entitlement. Automations automatically provision or revoke access based on defined conditions. - operationId: c1.api.app.v1.AppEntitlements.CreateAutomation + description: Create a user-authored custom finding. + operationId: c1.api.finding.v1.FindingService.CreateFinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingResponse' + description: Successful response + summary: Create Finding + tags: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: CreateFinding + /api/v1/findings/{finding_id}/state: + post: + description: Update finding workflow state (snooze, accept risk, suppress, reopen, resolve). + operationId: c1.api.finding.v1.FindingService.UpdateFindingState parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id + name: finding_id required: true schema: - description: The ID of the app entitlement to create an automation for. - readOnly: false + description: The ID of the finding whose state to update. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAutomationResponse' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateResponse' description: Successful response - summary: Create Automation + summary: Update Finding State tags: - - App Entitlement Automation - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#create - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: CreateAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/exclusions: - delete: - description: Remove users from the automation exclusion list for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.RemoveAutomationExclusion + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: UpdateFindingState + /api/v1/findings/{finding_id}/task: + post: + description: Create a task for a finding. + operationId: c1.api.finding.v1.FindingService.CreateFindingTask parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id + name: finding_id required: true schema: - description: The ID of the app entitlement whose automation exclusion list to update. - readOnly: false + description: The ID of the finding to create a remediation task for. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAutomationExclusionResponse' - description: Empty response with a status code indicating success. - summary: Remove Automation Exclusion + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskResponse' + description: Successful response + summary: Create Finding Task tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: RemoveAutomationExclusion + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: CreateFindingTask + /api/v1/findings/{id}: get: - description: List users who are excluded from the automation rule for an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.ListAutomationExclusions + description: Get a single finding by ID. + operationId: c1.api.finding.v1.FindingService.GetFinding parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id + name: id required: true schema: - description: The ID of the app entitlement to list exclusions for. - readOnly: false + description: The ID of the finding to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAutomationExclusionsResponse' + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingResponse' description: Successful response - summary: List Automation Exclusions + summary: Get Finding tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListAutomationExclusions + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: GetFinding + /api/v1/findings/bulk/state: post: - description: Add users to the automation exclusion list for an app entitlement. Excluded users are not affected by the automation rule. - operationId: c1.api.app.v1.AppEntitlements.AddAutomationExclusion - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The ID of the app entitlement whose automation exclusion list to update. - readOnly: false - type: string + description: Bulk update finding states. + operationId: c1.api.finding.v1.FindingService.BulkUpdateFindingState requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAutomationExclusionResponse' - description: Empty response with a status code indicating success. - summary: Add Automation Exclusion + $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateResponse' + description: Successful response + summary: Bulk Update Finding State tags: - - App Entitlement Automation Exclusion - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: AddAutomationExclusion - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/automation/update: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: BulkUpdateFindingState + /api/v1/findings/bulk/tasks: post: - description: Update the automation rule for an app entitlement, including its display name, description, and conditions. - operationId: c1.api.app.v1.AppEntitlements.UpdateAutomation - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that is associated with the app entitlement. - readOnly: true - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The unique ID for the App Entitlement. - readOnly: true - type: string + description: Bulk create tasks for findings. + operationId: c1.api.finding.v1.FindingService.BulkCreateFindingTasks requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementServiceUpdateAutomationResponse' + $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksResponse' description: Successful response - summary: Update Automation + summary: Bulk Create Finding Tasks tags: - - App Entitlement Automation - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Entitlement Automation#update - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: UpdateAutomation - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/grants: + - Findings + x-speakeasy-group: Finding + x-speakeasy-name-override: BulkCreateFindingTasks + /api/v1/findings/routing-rules: get: - description: Search app entitlements, include app users, users, expires, discovered. - operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsWithExpired - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The appEntitlementId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + description: List finding routing rules, optionally filtered to a specific app. + operationId: c1.api.finding.v1.FindingRoutingRuleService.ListFindingRoutingRules responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppEntitlementsWithExpiredResponse' - description: The SearchAppEntitlementsWithExpiredResponse message contains a list of results and a nextPageToken if applicable. - summary: Search App Entitlements With Expired + $ref: '#/components/schemas/c1.api.finding.v1.ListFindingRoutingRulesResponse' + description: Successful response + summary: List Finding Routing Rules tags: - - App Entitlement - x-speakeasy-group: AppEntitlementSearch - x-speakeasy-name-override: SearchAppEntitlementsWithExpired - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/remove-membership: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: ListFindingRoutingRules + post: + description: Create a new finding routing rule that defines which policy to use for auto-routing matching findings. + operationId: c1.api.finding.v1.FindingRoutingRuleService.CreateFindingRoutingRule + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleResponse' + description: Successful response + summary: Create Finding Routing Rule + tags: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: CreateFindingRoutingRule + /api/v1/findings/routing-rules/{id}: delete: - description: Remove a user from a ConductorOne-managed entitlement (catalog, group, or profile type). For access profiles, this creates a revoke task to deprovision access. - operationId: c1.api.app.v1.AppEntitlements.RemoveEntitlementMembership + description: Delete a finding routing rule. Findings already routed by this rule are not affected. + operationId: c1.api.finding.v1.FindingRoutingRuleService.DeleteFindingRoutingRule parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id + name: id required: true schema: - description: The ID of the app entitlement to remove the membership from. - readOnly: false + description: The ID of the finding routing rule to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveEntitlementMembershipResponse' + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleResponse' description: Successful response - summary: Remove Entitlement Membership + summary: Delete Finding Routing Rule tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: RemoveEntitlementMembership - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users: - get: - deprecated: true - description: List the users, as AppEntitlementUsers objects, of an app entitlement. - operationId: c1.api.app.v1.AppEntitlements.ListUsers - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: DeleteFindingRoutingRule + get: + description: Retrieve a single finding routing rule by ID. + operationId: c1.api.finding.v1.FindingRoutingRuleService.GetFindingRoutingRule + parameters: - in: path - name: app_entitlement_id + name: id required: true schema: - description: The appEntitlementId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false + description: The ID of the finding routing rule to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementUsersResponse' - description: The ListAppEntitlementUsersResponse message contains a list of results and a nextPageToken if applicable. - summary: List Users + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingRoutingRuleResponse' + description: Successful response + summary: Get Finding Routing Rule tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: AppEntitlementUsers#read - terraform-resource: null - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListUsers - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/remove-grant-duration: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: GetFindingRoutingRule + /api/v1/findings/routing-rules/{routing_rule_id}/update: post: - description: Remove the expiration time from a grant, converting it to an indefinite (standing) grant. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.RemoveGrantDuration + description: Update an existing finding routing rule's match criteria or target policy. + operationId: c1.api.finding.v1.FindingRoutingRuleService.UpdateFindingRoutingRule parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The ID of the entitlement whose grant duration is being removed. - readOnly: false - type: string - - in: path - name: app_user_id + name: routing_rule_id required: true schema: - description: The ID of the app user whose grant expiration is being removed. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveGrantDurationResponse' - description: The response message for removing the expiration time from a grant. - summary: Remove Grant Duration + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleResponse' + description: Successful response + summary: Update Finding Routing Rule tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: RemoveGrantDuration - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{app_user_id}/update-grant-duration: + - Finding Routing Rules + x-speakeasy-group: FindingRoutingRule + x-speakeasy-name-override: UpdateFindingRoutingRule + /api/v1/findings/search: post: - description: Update the expiration time of an existing grant, changing when automatic revocation will occur. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.UpdateGrantDuration - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the entitlement. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The ID of the entitlement whose grant duration is being updated. - readOnly: false - type: string - - in: path - name: app_user_id - required: true - schema: - description: The ID of the app user whose grant is being updated. - readOnly: false - type: string + description: |- + Search findings using full-text query and filters for severity, state, type, and app. + Each Finding row is large (risk factors, evidence, target, tags) — request a small page_size (≤10) to keep responses small. + operationId: c1.api.finding.v1.FindingSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateGrantDurationResponse' - description: The response message for updating the duration of a grant. - summary: Update Grant Duration + $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchResponse' + description: Successful response + summary: Search tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: UpdateGrantDuration - /api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/users/{identity_user_id}/grants: + - Findings + x-speakeasy-group: FindingSearch + x-speakeasy-name-override: Search + /api/v1/findings/transformation-rules: get: - description: Returns a list of app users for the identity in the app. If that app user also has a grant to the entitlement from the request, data about the grant is also returned. It will always return ALL app users for this identity, but only SOME may have grant data. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.ListAppUsersForIdentityWithGrant - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: app_entitlement_id - required: true - schema: - description: The appEntitlementId field. - readOnly: false - type: string - - in: path - name: identity_user_id - required: true - schema: - description: The identityUserId field. - readOnly: false - type: string + description: List finding transformation rules, optionally filtered to a specific app. + operationId: c1.api.finding.v1.FindingTransformationRuleService.ListFindingTransformationRules responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppUsersForIdentityWithGrantResponse' + $ref: '#/components/schemas/c1.api.finding.v1.ListFindingTransformationRulesResponse' description: Successful response - summary: List App Users For Identity With Grant + summary: List Finding Transformation Rules tags: - - App Entitlement User Binding - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: ListAppUsersForIdentityWithGrant - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/ownerids: - get: - description: ListUserIDs lists owner IDs for a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.ListOwnerIDs - parameters: - - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to list owners of. - readOnly: false - type: string - - in: path - name: entitlement_id - required: true - schema: - description: The entitlement_id field for the app entitlement to list owners of. - readOnly: false - type: string + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: ListFindingTransformationRules + post: + description: Create a new finding transformation rule. + operationId: c1.api.finding.v1.FindingTransformationRuleService.CreateFindingTransformationRule + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnerIDsResponse' - description: The response message for listing app entitlement owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTransformationRuleResponse' + description: Successful response + summary: Create Finding Transformation Rule tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Entitlement_Owner#read - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners: + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: CreateFindingTransformationRule + /api/v1/findings/transformation-rules/{id}: delete: - description: Delete deletes the owners from a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Delete + description: Delete a finding transformation rule. Findings already transformed by this rule are not affected. + operationId: c1.api.finding.v1.FindingTransformationRuleService.DeleteFindingTransformationRule parameters: - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to remove the owner of. - readOnly: false - type: string - - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to remove the owner of. - readOnly: false + description: The ID of the finding transformation rule to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementOwnersResponse' - description: the empty response message for deleting app entitlement owners. - summary: Delete + $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingTransformationRuleResponse' + description: Successful response + summary: Delete Finding Transformation Rule tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Owner#delete - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Delete + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: DeleteFindingTransformationRule get: - description: List owners for a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.List + description: Retrieve a single finding transformation rule by ID. + operationId: c1.api.finding.v1.FindingTransformationRuleService.GetFindingTransformationRule parameters: - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to list owners of. - readOnly: false - type: string - - in: path - name: entitlement_id + name: id required: true schema: - description: The entitlement_id field for the app entitlement to list owners of. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The page_size field for pagination. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The page_token field for pagination. - readOnly: false + description: The ID of the finding transformation rule to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementOwnersResponse' - description: The response message for listing app entitlement owners. - summary: List + $ref: '#/components/schemas/c1.api.finding.v1.GetFindingTransformationRuleResponse' + description: Successful response + summary: Get Finding Transformation Rule tags: - - App Entitlement Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: AppEntitlementOwners#read - terraform-resource: null - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: List + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: GetFindingTransformationRule + /api/v1/findings/transformation-rules/{transformation_rule_id}/update: post: - description: Add an owner to a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Add + description: Update an existing finding transformation rule's match criteria or transforms. + operationId: c1.api.finding.v1.FindingTransformationRuleService.UpdateFindingTransformationRule parameters: - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to add the owner to. - readOnly: false - type: string - - in: path - name: entitlement_id + name: transformation_rule_id required: true schema: - description: The entitlement_id field for the app entitlement to add the owner to. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppEntitlementOwnerResponse' - description: The empty response message for adding an app entitlement owner. - summary: Add + $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingTransformationRuleResponse' + description: Successful response + summary: Update Finding Transformation Rule tags: - - App Entitlement Owner - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Add - put: - description: Sets the owners for a given app entitlement to the specified list of users. - operationId: c1.api.app.v1.AppEntitlementOwners.Set - parameters: - - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to set the owners of. - readOnly: false - type: string - - in: path - name: entitlement_id - required: true - schema: - description: The entitlement_id field for the app entitlement to set the owners of. - readOnly: false - type: string + - Finding Transformation Rules + x-speakeasy-group: FindingTransformationRule + x-speakeasy-name-override: UpdateFindingTransformationRule + /api/v1/functions: + get: + description: List retrieves all functions with pagination + operationId: c1.api.functions.v1.FunctionsService.ListFunctions + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListFunctionsResponse' + description: Successful response + summary: List Functions + tags: + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: ListFunctions + x-stability-level: draft + post: + description: |- + CreateFunction registers a new serverless function and creates its + initial code commit. Functions run as TypeScript modules in a sandboxed + runtime; see initial_content for the entry-file signature and SDK import. + + The new function is unpublished. To make the commit the default + runnable version (and have the function appear as runnable in the + Functions UI), call UpdateFunction with function.published_commit_id + set and update_mask=["published_commit_id"]. + operationId: c1.api.functions.v1.FunctionsService.CreateFunction requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppEntitlementOwnersResponse' - description: The empty response message for setting the app entitlement owners. - summary: Set + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionResponse' + description: Successful response + summary: Create Function tags: - - App Entitlement Owner + - Function x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Entitlement_Owner#create - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/entitlements/{entitlement_id}/owners/{user_id}: - delete: - description: Remove an owner from a given app entitlement. - operationId: c1.api.app.v1.AppEntitlementOwners.Remove + terraform-resource: Function#create + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateFunction + /api/v1/functions/{function_id}/commits: + get: + description: ListCommits retrieves the commit history + operationId: c1.api.functions.v1.FunctionsService.ListCommits parameters: - in: path - name: app_id - required: true - schema: - description: The app_id field for the app entitlement to remove the owner of. - readOnly: false - type: string - - in: path - name: entitlement_id + name: function_id required: true schema: - description: The entitlement_id field for the app entitlement to remove the owner of. - readOnly: false + description: The functionId field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListCommitsResponse' + description: Successful response + summary: List Commits + tags: + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: ListCommits + x-stability-level: draft + post: + description: CreateInitialCommit starts a new commit and returns upload URLs for files + operationId: c1.api.functions.v1.FunctionsService.CreateInitialCommit + parameters: - in: path - name: user_id + name: function_id required: true schema: - description: The user_id field for the user to remove as an owner of the app entitlement. - readOnly: false + description: The functionId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppEntitlementOwnerResponse' - description: The empty response message for removing an app entitlement owner. - summary: Remove + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse' + description: Successful response + summary: Create Initial Commit tags: - - App Entitlement Owner - x-speakeasy-group: AppEntitlementOwners - x-speakeasy-name-override: Remove - /api/v1/apps/{app_id}/entitlements/{id}: - delete: - description: Delete an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Delete + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateInitialCommit + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{commit_id}/finalize: + post: + description: CreateFinalCommit completes a commit after files are uploaded + operationId: c1.api.functions.v1.FunctionsService.CreateFinalCommit parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The ID of the app that contains the entitlement. - readOnly: false + description: The functionId field. type: string - in: path - name: id + name: commit_id required: true schema: - description: The ID of the app entitlement to delete. - readOnly: false + description: The commitId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse' description: Successful response - summary: Delete + summary: Create Final Commit tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#delete - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Delete + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateFinalCommit + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{commit_id}/lockfile: get: - description: Get an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Get + description: GetLockFile retrieves the deno lock file for a specific commit, if it exists. + operationId: c1.api.functions.v1.FunctionsService.GetLockFile parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The appId field. - readOnly: false + description: The functionId field. type: string - in: path - name: id + name: commit_id required: true schema: - description: The id field. - readOnly: false + description: The commitId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementResponse' - description: The get app entitlement response returns an entitlement view containing paths in the expanded array for the objects expanded as indicated by the expand mask in the request. - summary: Get + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetLockFileResponse' + description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. + summary: Get Lock File tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Custom App Entitlement#read - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Get - post: - description: Update an app entitlement by ID. - operationId: c1.api.app.v1.AppEntitlements.Update + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: GetLockFile + x-stability-level: draft + /api/v1/functions/{function_id}/commits/{id}: + get: + description: |- + GetCommitContent retrieves a commit and all its file contents in a single unary response. + This is a non-streaming alternative to GetCommit for REST API consumers. + operationId: c1.api.functions.v1.FunctionsService.GetCommitContent parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The ID of the app that is associated with the app entitlement. - readOnly: false + description: The function ID (KSUID). type: string - in: path name: id required: true schema: - description: The unique ID for the App Entitlement. - readOnly: true + description: The commit reference to retrieve. Accepts a KSUID, "HEAD", or a tag reference like "refs/tags/v1.0". type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppEntitlementResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetCommitContentResponse' + description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. + summary: Get Commit Content tags: - - App Entitlement - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Custom App Entitlement#update - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/entitlements/resource_types/{app_resource_type_id}/resources/{app_resource_id}: + - Function Commit + x-speakeasy-group: Functions + x-speakeasy-name-override: GetCommitContent + x-stability-level: draft + /api/v1/functions/{function_id}/invocations: get: - description: List app entitlements associated with an app resource. - operationId: c1.api.app.v1.AppEntitlements.ListForAppResource + description: List retrieves the invocation history for a function + operationId: c1.api.functions.v1.FunctionsInvocationService.List parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The appResourceTypeId field. - readOnly: false - type: string - - in: path - name: app_resource_id + name: function_id required: true schema: - description: The appResourceId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false + description: The functionId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: List For App Resource + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceListResponse' + description: Successful response + summary: List tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListForAppResource - /api/v1/apps/{app_id}/entitlements/users/{app_user_id}: + - Function Invocation + x-speakeasy-group: FunctionsInvocation + x-speakeasy-name-override: List + x-stability-level: draft + /api/v1/functions/{function_id}/invocations/{id}: get: - description: List app entitlements associated with an app user. - operationId: c1.api.app.v1.AppEntitlements.ListForAppUser + description: Get retrieves a specific invocation by ID + operationId: c1.api.functions.v1.FunctionsInvocationService.Get parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The appId field. - readOnly: false + description: The functionId field. type: string - in: path - name: app_user_id + name: id required: true schema: - description: The appUserId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: List For App User + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceGetResponse' + description: Successful response + summary: Get tags: - - App Entitlement - x-speakeasy-group: AppEntitlements - x-speakeasy-name-override: ListForAppUser - /api/v1/apps/{app_id}/ownerids: - get: - description: ListOwnerIDs lists owner IDs for a given app. - operationId: c1.api.app.v1.AppOwners.ListOwnerIDs + - Function Invocation + x-speakeasy-group: FunctionsInvocation + x-speakeasy-name-override: Get + x-stability-level: draft + /api/v1/functions/{function_id}/invocations/search: + post: + description: |- + Search searches for function invocations with filtering and ordering support + Each invocation carries its input/output payloads, which can be large — request a small page_size (≤10) to keep responses small. + operationId: c1.api.functions.v1.FunctionsInvocationSearchService.Search parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The app_id field for the app to list owners of. - readOnly: false + description: The function ID to search invocations for. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnerIDsResponse' - description: The response message for listing app owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchResponse' + description: FunctionsInvocationSearchResponse is the response for searching function invocations. + summary: Search tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Owner#read - x-speakeasy-group: AppOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/owners: - delete: - description: Delete deletes the owners from a given app. - operationId: c1.api.app.v1.AppOwners.Delete + - Function Invocation + x-speakeasy-group: FunctionsInvocationSearch + x-speakeasy-name-override: Search + x-stability-level: draft + /api/v1/functions/{function_id}/invoke: + post: + description: Invoke executes a function at a specific commit with the provided input data. + operationId: c1.api.functions.v1.FunctionsService.Invoke parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The app_id field for the app to remove the owner of. - readOnly: false + description: The ID of the function to invoke. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppOwnersResponse' - description: the empty response message for deleting app owners. - summary: Delete + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeResponse' + description: Successful response + summary: Invoke tags: - - App Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner#delete - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Delete + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: Invoke + x-stability-level: draft + /api/v1/functions/{function_id}/tags: get: - description: List owners of an app. - operationId: c1.api.app.v1.AppOwners.List + description: ListTags lists all tags for a function + operationId: c1.api.functions.v1.FunctionsService.ListTags parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The appId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false + description: The functionId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppOwnersResponse' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListTagsResponse' description: Successful response - summary: List + summary: List Tags tags: - - App Owner + - Function Tag x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: AppOwners#read - terraform-resource: null - x-speakeasy-group: AppOwners - x-speakeasy-name-override: List - put: - description: Sets the owners for a given app to the specified list of users. - operationId: c1.api.app.v1.AppOwners.Set + terraform-datasource: Function_Tag#read + terraform-resource: Function_Tag#read + x-speakeasy-group: Functions + x-speakeasy-name-override: ListTags + x-stability-level: draft + post: + description: CreateTag creates a named reference to a specific commit + operationId: c1.api.functions.v1.FunctionsService.CreateTag parameters: - in: path - name: app_id + name: function_id required: true schema: - description: The app_id field for the app to set the owners of. - readOnly: false + description: The functionId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppOwnersResponse' - description: The empty response message for setting the app owners. - summary: Set + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagResponse' + description: Successful response + summary: Create Tag tags: - - App Owner + - Function Tag x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Owner#create - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/owners/{user_id}: - delete: - description: Removes an owner from an app. - operationId: c1.api.app.v1.AppOwners.Remove + terraform-resource: Function_Tag#create + x-speakeasy-group: Functions + x-speakeasy-name-override: CreateTag + x-stability-level: draft + /api/v1/functions/{function_id}/test: + post: + description: Test runs a function's test suite in a sandboxed environment and returns the results. + operationId: c1.api.functions.v1.FunctionsService.Test parameters: - in: path - name: app_id - required: true - schema: - description: App ID of the app to remove the owner from. - readOnly: false - type: string - - in: path - name: user_id + name: function_id required: true schema: - description: User ID of the user to remove as an owner. - readOnly: false + description: The function ID to test. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppOwnerResponse' - description: Empty response with a status code indicating success. - summary: Remove + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestResponse' + description: FunctionsServiceTestResponse contains test execution results. + summary: Test tags: - - App Owner - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Remove - post: - description: Adds an owner to an app. - operationId: c1.api.app.v1.AppOwners.Add + - Function + x-speakeasy-group: Functions + x-speakeasy-name-override: Test + x-stability-level: draft + /api/v1/functions/{id}: + delete: + description: Delete removes a function + operationId: c1.api.functions.v1.FunctionsService.DeleteFunction parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: user_id + name: id required: true schema: - description: The userId field. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerRequestInput' + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppOwnerResponse' - description: Empty response with a status code indicating success - summary: Add + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse' + description: Successful response + summary: Delete Function tags: - - App Owner - x-speakeasy-group: AppOwners - x-speakeasy-name-override: Add - /api/v1/apps/{app_id}/report: + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Function#delete + x-speakeasy-group: Functions + x-speakeasy-name-override: DeleteFunction + x-stability-level: draft get: - description: Get a list of reports for the given app. - operationId: c1.api.app.v1.AppReportService.List + description: Get retrieves a specific function by ID + operationId: c1.api.functions.v1.FunctionsService.GetFunction parameters: - in: path - name: app_id + name: id required: true schema: - description: The appId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppReportServiceListResponse' - description: The AppReportServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetFunctionResponse' + description: Successful response + summary: Get Function tags: - - App Reports - x-speakeasy-group: AppReport - x-speakeasy-name-override: List + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Function#read + x-speakeasy-group: Functions + x-speakeasy-name-override: GetFunction + x-stability-level: draft + /api/v1/functions/update: post: - description: Generate a report for the given app. - operationId: c1.api.app.v1.AppReportActionService.GenerateReport - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string + description: |- + Update an existing function's metadata. Also the publish path: set + function.published_commit_id and include "published_commit_id" in + update_mask to make a commit the default runnable version. + operationId: c1.api.functions.v1.FunctionsService.UpdateFunction requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AppActionsServiceGenerateReportResponse' - description: Empty response body. Status code indicates success. - summary: Generate Report - tags: - - App Reports - x-speakeasy-group: AppReportAction - x-speakeasy-name-override: GenerateReport - /api/v1/apps/{app_id}/resource_types: - get: - description: List app resource types. - operationId: c1.api.app.v1.AppResourceTypeService.List - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceListResponse' - description: The AppResourceTypeServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse' + description: Successful response + summary: Update Function tags: - - App Resource Type - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: List + - Function + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Function#update + x-speakeasy-group: Functions + x-speakeasy-name-override: UpdateFunction + x-stability-level: draft + /api/v1/grants/feed: post: - description: Create a manually managed resource type that classifies resources within an app. - operationId: c1.api.app.v1.AppResourceTypeService.CreateManuallyManagedResourceType - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app to create the resource type under. - readOnly: false - type: string + description: Search a chronological feed of grant and revoke events, filtered by app user, entitlement, or time range. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.SearchGrantFeed requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SearchGrantFeedRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedResourceTypeResponse' - description: The response message for creating a manually managed resource type. - summary: Create Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.app.v1.SearchGrantFeedResponse' + description: The SearchGrantFeedResponse message contains a list of grant event results and a nextPageToken if applicable. + summary: Search Grant Feed tags: - - App Resource Type - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource Type#create - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: CreateManuallyManagedResourceType - /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources: + - App Entitlement User Binding Feed + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: SearchGrantFeed + /api/v1/hooks: get: - description: List app resources for a given app and optionally filter by resource type. - operationId: c1.api.app.v1.AppResourceService.List + description: Invokes the c1.api.hooks.v1.HooksService.List method. + operationId: c1.api.hooks.v1.HooksService.List parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app to list resources for. - readOnly: false - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: Optional resource type ID to filter results by. If empty, resources of all types are returned. - readOnly: false - type: string - in: query name: page_size schema: - description: The maximum number of results to return per page. + description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: The token for fetching the next page of results. - readOnly: false + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceListResponse' - description: The AppResourceServiceListResponse message contains a list of results and a nextPageToken if applicable. + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceListResponse' + description: Successful response summary: List tags: - - App Resource - x-speakeasy-group: AppResource + - Hook + x-speakeasy-group: Hooks x-speakeasy-name-override: List post: - description: Create a manually managed app resource tracked directly by ConductorOne under an existing resource type. - operationId: c1.api.app.v1.AppResourceService.CreateManuallyManagedAppResource - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app to create the resource under. - readOnly: false - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The resource type ID that classifies this resource. - readOnly: false - type: string + description: Invokes the c1.api.hooks.v1.HooksService.Create method. + operationId: c1.api.hooks.v1.HooksService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceRequestInput' + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateManuallyManagedAppResourceResponse' - description: The response message for creating a manually managed app resource. - summary: Create Manually Managed App Resource + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceCreateResponse' + description: Successful response + summary: Create tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource#create - x-speakeasy-group: AppResource - x-speakeasy-name-override: CreateManuallyManagedAppResource - /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources/{id}: + - Hook + x-speakeasy-group: Hooks + x-speakeasy-name-override: Create + /api/v1/hooks/{id}: delete: - description: Delete a manually managed app resource and its associated entitlements from an app. - operationId: c1.api.app.v1.AppResourceService.DeleteManuallyManagedAppResource + description: Invokes the c1.api.hooks.v1.HooksService.Delete method. + operationId: c1.api.hooks.v1.HooksService.Delete parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - readOnly: false - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The ID of the resource type that classifies the resource. - readOnly: false - type: string - in: path name: id required: true schema: - description: The ID of the app resource to delete. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceRequestInput' + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedAppResourceResponse' - description: The empty response message for deleting a manually managed app resource. - summary: Delete Manually Managed App Resource + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceDeleteResponse' + description: Successful response + summary: Delete tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource#delete - x-speakeasy-group: AppResource - x-speakeasy-name-override: DeleteManuallyManagedAppResource + - Hook + x-speakeasy-group: Hooks + x-speakeasy-name-override: Delete get: - description: Retrieve a single app resource by its app, resource type, and resource ID. - operationId: c1.api.app.v1.AppResourceService.Get - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - readOnly: false - type: string - - in: path - name: app_resource_type_id - required: true - schema: - description: The ID of the resource type that classifies this resource. - readOnly: false - type: string - - in: path - name: id - required: true - schema: - description: The unique ID of the app resource to retrieve. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceGetResponse' - description: The app resource service get response contains the app resource view and array of expanded items indicated by the request's expand mask. - summary: Get - tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: App Resource#read - terraform-resource: App Resource#read - x-speakeasy-group: AppResource - x-speakeasy-name-override: Get - post: - description: Update an app resource's fields. Only the fields specified in the update mask are modified. - operationId: c1.api.app.v1.AppResourceService.Update - parameters: - - in: path - name: app_id - required: true - schema: - description: The app that this resource belongs to. - readOnly: false - type: string + description: Invokes the c1.api.hooks.v1.HooksService.Get method. + operationId: c1.api.hooks.v1.HooksService.Get + parameters: - in: path - name: app_resource_type_id + name: id required: true schema: - description: The resource type that this resource is. - readOnly: false + description: The id field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceGetResponse' + description: Successful response + summary: Get + tags: + - Hook + x-speakeasy-group: Hooks + x-speakeasy-name-override: Get + post: + description: Invokes the c1.api.hooks.v1.HooksService.Update method. + operationId: c1.api.hooks.v1.HooksService.Update + parameters: - in: path name: id required: true schema: - description: The id of the resource. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceServiceUpdateResponse' - description: The response message for updating an app resource. + $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceUpdateResponse' + description: Successful response summary: Update tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource#update - x-speakeasy-group: AppResource + - Hook + x-speakeasy-group: Hooks x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/resource_types/{id}: + /api/v1/iam/personal_clients: + get: + description: List returns all personal client credentials owned by the calling user. + operationId: c1.api.iam.v1.PersonalClientService.List + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceListResponse' + description: Successful response + summary: 'NOTE: Only shows personal clients for the current user.' + tags: + - Personal Client + x-speakeasy-group: PersonalClient + x-speakeasy-name-override: List + post: + description: Create creates a new PersonalClient object for the current User. + operationId: c1.api.iam.v1.PersonalClientService.Create + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceCreateRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceCreateResponse' + description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. + summary: Create + tags: + - Personal Client + x-speakeasy-group: PersonalClient + x-speakeasy-name-override: Create + /api/v1/iam/personal_clients/{id}: delete: - description: Delete a manually managed resource type and all its associated resources from an app. - operationId: c1.api.app.v1.AppResourceTypeService.DeleteManuallyManagedResourceType + description: Delete a personal client credential, revoking it and preventing further API access. + operationId: c1.api.iam.v1.PersonalClientService.Delete parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource type. - readOnly: false - type: string - in: path name: id required: true schema: - description: The ID of the resource type to delete. - readOnly: false + description: The human-readable name of the personal client credential to delete (e.g., blue-whale-12345). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteManuallyManagedResourceTypeResponse' - description: The empty response message for deleting a manually managed resource type. - summary: Delete Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceDeleteResponse' + description: Successful response + summary: Delete tags: - - App Resource Type - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource Type#delete - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: DeleteManuallyManagedResourceType + - Personal Client + x-speakeasy-group: PersonalClient + x-speakeasy-name-override: Delete get: - description: Get an app resource type. - operationId: c1.api.app.v1.AppResourceTypeService.Get + description: Get retrieves a single personal client credential by its ID. + operationId: c1.api.iam.v1.PersonalClientService.Get parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The human-readable name of the personal client credential to retrieve (e.g., blue-whale-12345). type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppResourceTypeServiceGetResponse' - description: |- - The AppResourceTypeServiceGetResponse contains an expanded array containing the expanded values indicated by the expand mask - in the request and an app resource type view containing the resource type and JSONPATHs indicating which objects are where in the expand mask. + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceGetResponse' + description: Successful response summary: Get tags: - - App Resource Type - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App Resource Type#read - x-speakeasy-group: AppResourceType + - Personal Client + x-speakeasy-group: PersonalClient x-speakeasy-name-override: Get post: - description: Update a manually managed resource type's fields. Only the fields specified in the update mask are modified. - operationId: c1.api.app.v1.AppResourceTypeService.UpdateManuallyManagedResourceType + description: Update modifies an existing personal client credential. Use the update mask to specify which fields to change. + operationId: c1.api.iam.v1.PersonalClientService.Update parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app that is associated with the app resource type - readOnly: true - type: string - in: path name: id required: true schema: - description: The unique ID for the app resource type. + description: The unique ID of the personal client credential. readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateManuallyManagedResourceTypeResponse' - description: The response message for updating a manually managed resource type. - summary: Update Manually Managed Resource Type + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceUpdateResponse' + description: Successful response + summary: Update tags: - - App Resource Type - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Resource Type#update - x-speakeasy-group: AppResourceType - x-speakeasy-name-override: UpdateManuallyManagedResourceType - /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/ownerids: + - Personal Client + x-speakeasy-group: PersonalClient + x-speakeasy-name-override: Update + /api/v1/iam/personal_devices/{device_id}: delete: - description: Delete deletes the owners from a given app resource. - operationId: c1.api.app.v1.AppResourceOwners.Delete + description: |- + RevokeDevice revokes a whole device: it revokes the device and removes every + app client on it, so no app on that machine can mint further tokens. + operationId: c1.api.iam.v1.PersonalDeviceService.RevokeDevice parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - readOnly: false - type: string - - in: path - name: resource_id + name: device_id required: true schema: - description: The resourceId field. - readOnly: false + description: The device identity of the device to revoke (whole-device). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResourceOwnersResponse' - description: the empty response message for deleting app resource owners. - summary: Delete + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceResponse' + description: Successful response + summary: Revoke Device tags: - - App Resource Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Resource_Owner#delete - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Delete + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: RevokeDevice get: - description: ListOwnerIDs lists owner IDs for a given app resource. - operationId: c1.api.app.v1.AppResourceOwners.ListOwnerIDs + description: GetDevice retrieves a single device (by device_id) with its child clients. + operationId: c1.api.iam.v1.PersonalDeviceService.GetDevice parameters: - in: path - name: app_id + name: device_id required: true schema: - description: The appId field. - readOnly: false + description: |- + The device identity (a base64url-encoded SHA-256 thumbprint of the device + root key). type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceGetDeviceResponse' + description: Successful response + summary: Get Device + tags: + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: GetDevice + put: + description: |- + UpdateDevice renames one of the calling user's devices. Use the update mask + to specify which fields to change; only the display name is mutable, so + device identity and keys never change. + operationId: c1.api.iam.v1.PersonalDeviceService.UpdateDevice + parameters: - in: path - name: resource_type_id + name: device_id required: true schema: - description: The resourceTypeId field. - readOnly: false + description: |- + The stable device identity: a base64url-encoded SHA-256 thumbprint of the + device's root public signing key. + readOnly: true type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceUpdateDeviceResponse' + description: Successful response + summary: 'NOTE: Only updates devices owned by the current user.' + tags: + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: UpdateDevice + /api/v1/iam/personal_devices/{device_id}/clients: + get: + description: |- + ListDeviceClients returns the app clients registered on a device, one page at + a time. A device can accrue many app clients over time, so the clients are + served from this dedicated paginated endpoint rather than inlined on the + device. + operationId: c1.api.iam.v1.PersonalDeviceService.ListDeviceClients + parameters: - in: path - name: resource_id + name: device_id required: true schema: - description: The resourceId field. - readOnly: false + description: |- + The device identity (a base64url-encoded SHA-256 thumbprint of the device + root key) whose clients to list. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnerIDsResponse' - description: The response message for listing app resource owners IDs. - summary: List Owner I Ds + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceListDeviceClientsResponse' + description: Successful response + summary: List Device Clients tags: - - App Resource Owner - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Resource_Owner#read - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: ListOwnerIDs - /api/v1/apps/{app_id}/resource_types/{resource_type_id}/resource/{resource_id}/owners: + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: ListDeviceClients + /api/v1/iam/personal_devices/{device_id}/clients/{id}: delete: - description: Remove a user from the owners of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.Remove + description: |- + RevokeDeviceClient revokes a single app client on a device: it removes that + client, leaving the device and its other clients intact. + operationId: c1.api.iam.v1.PersonalDeviceService.RevokeDeviceClient parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - readOnly: false - type: string - - in: path - name: resource_type_id + name: device_id required: true schema: - description: The ID of the resource type that classifies the resource. - readOnly: false + description: The device identity the client belongs to. type: string - in: path - name: resource_id + name: id required: true schema: - description: The ID of the app resource to remove an owner from. - readOnly: false + description: The human-readable ID of the client to revoke (e.g., blue-whale-12345). type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.RemoveAppResourceOwnerResponse' - description: The empty response message for removing an owner from an app resource. - summary: Remove + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceRevokeDeviceClientResponse' + description: Successful response + summary: Revoke Device Client tags: - - App Resource Owner - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Remove + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: RevokeDeviceClient + /api/v1/iam/roles: get: - description: List all owners of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.List + description: List all roles for the current user. + operationId: c1.api.iam.v1.Roles.List parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - readOnly: false - type: string - - in: path - name: resource_id - required: true - schema: - description: The resourceId field. - readOnly: false - type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppResourceOwnersResponse' - description: The ListAppResourceOwnersResponse message contains a list of results and a nextPageToken if applicable + $ref: '#/components/schemas/c1.api.iam.v1.ListRolesResponse' + description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. summary: List tags: - - App Resource Owner + - Role x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: AppResourceOwners#read + terraform-datasource: + - Role#read + - Roles#read terraform-resource: null - x-speakeasy-group: AppResourceOwners + x-speakeasy-group: Roles x-speakeasy-name-override: List - post: - description: Add a user as an owner of an app resource. - operationId: c1.api.app.v1.AppResourceOwners.Add + /api/v1/iam/roles/{role_id}: + get: + description: Get a role by id. + operationId: c1.api.iam.v1.Roles.Get parameters: - in: path - name: app_id - required: true - schema: - description: The ID of the app that owns the resource. - readOnly: false - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The ID of the resource type that classifies the resource. - readOnly: false - type: string - - in: path - name: resource_id + name: role_id required: true schema: - description: The ID of the app resource to add an owner to. - readOnly: false + description: The roleId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AddAppResourceOwnerResponse' - description: The empty response message for adding an owner to an app resource. - summary: Add + $ref: '#/components/schemas/c1.api.iam.v1.GetRolesResponse' + description: The GetRolesResponse message contains the retrieved role. + summary: Get tags: - - App Resource Owner - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Add - put: - description: Sets the owners for a given app resource to the specified list of users. - operationId: c1.api.app.v1.AppResourceOwners.Set + - Role + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Role#read + x-speakeasy-group: Roles + x-speakeasy-name-override: Get + post: + description: Update a role by passing a Role object. + operationId: c1.api.iam.v1.Roles.Update parameters: - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: resource_type_id - required: true - schema: - description: The resourceTypeId field. - readOnly: false - type: string - - in: path - name: resource_id + name: role_id required: true schema: - description: The resourceId field. - readOnly: false + description: The id of the role. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.UpdateRoleRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SetAppResourceOwnersResponse' - description: The empty response message for setting the app resource owners. - summary: Set + $ref: '#/components/schemas/c1.api.iam.v1.UpdateRolesResponse' + description: UpdateRolesResponse is the response message containing the updated role. + summary: Update tags: - - App Resource Owner + - Role x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: App_Resource_Owner#create - x-speakeasy-group: AppResourceOwners - x-speakeasy-name-override: Set - /api/v1/apps/{app_id}/usage_controls: + terraform-resource: Role#update + x-speakeasy-group: Roles + x-speakeasy-name-override: Update + /api/v1/iam/tunnel/bridges: get: - description: Get usage controls, as an AppUsageControls object which describes some peripheral configuration, for an app. - operationId: c1.api.app.v1.AppUsageControlsService.Get - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string + description: |- + ListBridges returns the tenant's bridges, paginated, each with live + appliance status. + operationId: c1.api.iam.v1.TunnelCredentialsService.ListBridges responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppUsageControlsResponse' - description: The GetAppUsageControlsResponse message contains the retrieved AppUsageControls object. - summary: Get + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceListBridgesResponse' + description: Successful response + summary: List Bridges tags: - - App Usage Controls - x-speakeasy-group: AppUsageControls - x-speakeasy-name-override: Get + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: ListBridges post: - description: Update usage controls for an app. - operationId: c1.api.app.v1.AppUsageControlsService.Update - parameters: - - in: path - name: app_id - required: true - schema: - description: The app that this object belongs to. - readOnly: false - type: string + description: |- + CreateBridge creates a bridge with no credentials. Use + CreateBridgeCredential to mint the first credential. + operationId: c1.api.iam.v1.TunnelCredentialsService.CreateBridge requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppUsageControlsResponse' - description: The UpdateAppUsageControlsResponse message contains the updated AppUsageControls object. - summary: Update + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeResponse' + description: Successful response + summary: Create Bridge tags: - - App Usage Controls - x-speakeasy-group: AppUsageControls - x-speakeasy-name-override: Update - /api/v1/apps/{app_id}/users/{user_id}/app_users: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: CreateBridge + /api/v1/iam/tunnel/bridges/{bridge_id}/announced_services: get: - description: List app user accounts within a specific app that are correlated to a given C1 user. - operationId: c1.api.app.v1.AppUserService.ListAppUsersForUser + description: |- + ListBridgeAnnouncedServices returns the services the appliance is + currently announcing for this bridge. Read live from the tunnel store; + empty when no appliance is connected. + operationId: c1.api.iam.v1.TunnelCredentialsService.ListBridgeAnnouncedServices parameters: - in: path - name: app_id + name: bridge_id required: true schema: - description: The ID of the app to list users for. - readOnly: false + description: The bridgeId field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceListBridgeAnnouncedServicesResponse' + description: Successful response + summary: List Bridge Announced Services + tags: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: ListBridgeAnnouncedServices + /api/v1/iam/tunnel/bridges/{bridge_id}/credentials: + get: + description: |- + ListBridgeCredentials returns every credential (active + revoked) for + one bridge. + operationId: c1.api.iam.v1.TunnelCredentialsService.ListBridgeCredentials + parameters: - in: path - name: user_id + name: bridge_id required: true schema: - description: The C1 user ID to filter app users by identity correlation. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The maximum number of results to return per page. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The token for fetching the next page of results. - readOnly: false + description: The bridge whose credentials to list. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUsersForUserServiceListResponse' - description: The response message for listing app users correlated to a specific C1 user. - summary: List App Users For User + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceListBridgeCredentialsResponse' + description: Successful response + summary: List Bridge Credentials tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: ListAppUsersForUser - /api/v1/apps/{app_user_app_id}/app_users/{app_user_id}: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: ListBridgeCredentials post: description: |- - Update an app user by ID. Only the fields specified in the update mask are updated. - Currently, only the appUserType, and identityUserId fields can be updated. - operationId: c1.api.app.v1.AppUserService.Update + CreateBridgeCredential mints a credential for a bridge. If the bridge + already has an active credential, it is revoked. The plaintext + client_secret is returned exactly once on the response. + operationId: c1.api.iam.v1.TunnelCredentialsService.CreateBridgeCredential parameters: - in: path - name: app_user_app_id + name: bridge_id required: true schema: - description: The ID of the application. - readOnly: true + description: The bridge to mint a credential for. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceCreateBridgeCredentialResponse' + description: Successful response + summary: Create Bridge Credential + tags: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: CreateBridgeCredential + /api/v1/iam/tunnel/bridges/{id}: + delete: + description: DeleteBridge hard-deletes a bridge and every credential it owns. + operationId: c1.api.iam.v1.TunnelCredentialsService.DeleteBridge + parameters: - in: path - name: app_user_id + name: id required: true schema: - description: A unique idenditfier of the application user. - readOnly: true + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceUpdateResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceDeleteBridgeResponse' + description: Empty response body. Status code indicates success. + summary: Delete Bridge tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: Update - /api/v1/apps/{connector_app_id}/connectors/{connector_id}/delegated: - post: - description: Update a delegated connector. - operationId: c1.api.app.v1.ConnectorService.UpdateDelegated + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: DeleteBridge + get: + description: GetBridge returns a bridge by id with live appliance status. + operationId: c1.api.iam.v1.TunnelCredentialsService.GetBridge parameters: - in: path - name: connector_app_id + name: id required: true schema: - description: The id of the app the connector is associated with. - readOnly: false + description: The id field. type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceGetBridgeResponse' + description: Successful response + summary: Get Bridge + tags: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: GetBridge + patch: + description: |- + UpdateBridge patches a bridge's editable metadata (display_name, + description). Credentials are not affected. + operationId: c1.api.iam.v1.TunnelCredentialsService.UpdateBridge + parameters: - in: path - name: connector_id + name: id required: true schema: - description: The id of the connector. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateDelegatedRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceUpdateResponse' - description: ConnectorServiceUpdateResponse is the response returned by the update method. - summary: Update Delegated + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceUpdateBridgeResponse' + description: Successful response + summary: Update Bridge tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: UpdateDelegated - /api/v1/apps/{id}: + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: UpdateBridge + /api/v1/iam/tunnel/credentials/{id}: delete: - description: Delete an app. - operationId: c1.api.app.v1.Apps.Delete + description: |- + RevokeBridgeCredential soft-revokes one credential by id. The row is + retained for audit; token mints with this credential are rejected. + operationId: c1.api.iam.v1.TunnelCredentialsService.RevokeBridgeCredential parameters: - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The id of the credential to revoke. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppResponse' + $ref: '#/components/schemas/c1.api.iam.v1.TunnelCredentialsServiceRevokeBridgeCredentialResponse' description: Empty response body. Status code indicates success. - summary: Delete + summary: Revoke Bridge Credential tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App#delete - x-speakeasy-group: Apps - x-speakeasy-name-override: Delete + - Tunnel + x-speakeasy-group: TunnelCredentials + x-speakeasy-name-override: RevokeBridgeCredential + /api/v1/local-directory-configs: get: - description: Get an app by ID. - operationId: c1.api.app.v1.Apps.Get + description: List local directory configs for the tenant. + operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.List parameters: - - in: path - name: id - required: true + - in: query + name: page_size schema: - description: The id field. - readOnly: false + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppResponse' - description: The GetAppResponse message contains the details of the requested app in the app field. - summary: Get + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse' + description: Successful response + summary: List tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App#read - x-speakeasy-group: Apps - x-speakeasy-name-override: Get + - Local Directory + x-speakeasy-group: LocalDirectoryConfig + x-speakeasy-name-override: List post: - description: Update an existing app. - operationId: c1.api.app.v1.Apps.Update - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the app. - readOnly: true - type: string + description: Create a new local directory config backed by an existing App. + operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppRequestInput' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.UpdateAppResponse' - description: Returns the updated app's new values. - summary: Update + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse' + description: Successful response + summary: Create tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App#update - x-speakeasy-group: Apps - x-speakeasy-name-override: Update - /api/v1/apps/{src_app_id}/{src_app_entitlement_id}/bindings/{dst_app_id}/{dst_app_entitlement_id}: + - Local Directory + x-speakeasy-group: LocalDirectoryConfig + x-speakeasy-name-override: Create + /api/v1/local-directory-configs/{app_id}: delete: - description: Delete a proxy binding between a source and destination entitlement. - operationId: c1.api.app.v1.AppEntitlementsProxy.Delete + description: Delete a local directory config. Does not delete the underlying App. + operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Delete parameters: - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - readOnly: false - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - readOnly: false - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - readOnly: false - type: string - - in: path - name: dst_app_entitlement_id + name: app_id required: true schema: - description: The ID of the destination (child) entitlement. - readOnly: false + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyRequestInput' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.DeleteAppEntitlementProxyResponse' - description: The empty response message for deleting an entitlement proxy binding. + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse' + description: Successful response summary: Delete tags: - - App Entitlement Proxy Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Entitlement Proxy Binding#delete - x-speakeasy-group: AppEntitlementsProxy + - Local Directory + x-speakeasy-group: LocalDirectoryConfig x-speakeasy-name-override: Delete get: - description: Retrieve a specific proxy binding between a source and destination entitlement. - operationId: c1.api.app.v1.AppEntitlementsProxy.Get + description: Get a local directory config by app_id. + operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Get parameters: - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - readOnly: false - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - readOnly: false - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - readOnly: false - type: string - - in: path - name: dst_app_entitlement_id + name: app_id required: true schema: - description: The ID of the destination (child) entitlement. - readOnly: false + description: The appId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.GetAppEntitlementProxyResponse' - description: The response message for getting a specific entitlement proxy binding. + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse' + description: Successful response summary: Get tags: - - App Entitlement Proxy Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: App Entitlement Proxy Binding#read - terraform-resource: App Entitlement Proxy Binding#read - x-speakeasy-group: AppEntitlementsProxy + - Local Directory + x-speakeasy-group: LocalDirectoryConfig x-speakeasy-name-override: Get post: - description: Create a proxy binding between a source and destination entitlement, establishing a hierarchical relationship. - operationId: c1.api.app.v1.AppEntitlementsProxy.Create + description: Update a local directory config. + operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Update parameters: - in: path - name: src_app_id - required: true - schema: - description: The ID of the app that owns the source entitlement. - readOnly: false - type: string - - in: path - name: src_app_entitlement_id - required: true - schema: - description: The ID of the source (parent) entitlement. - readOnly: false - type: string - - in: path - name: dst_app_id - required: true - schema: - description: The ID of the app that owns the destination entitlement. - readOnly: false - type: string - - in: path - name: dst_app_entitlement_id + name: app_id required: true schema: - description: The ID of the destination (child) entitlement. - readOnly: false + description: app_id is the identifier for this config and its linked App. Read-only after creation. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyRequestInput' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.CreateAppEntitlementProxyResponse' - description: The response message for creating an entitlement proxy binding. - summary: Create + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse' + description: Successful response + summary: Update tags: - - App Entitlement Proxy Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App Entitlement Proxy Binding#create - x-speakeasy-group: AppEntitlementsProxy - x-speakeasy-name-override: Create - /api/v1/apps/connectors/credentials: + - Local Directory + x-speakeasy-group: LocalDirectoryConfig + x-speakeasy-name-override: Update + /api/v1/local-directory-configs/{directory_app_id}/invitations: post: - description: Rotate credentials for a connector. - operationId: c1.api.app.v1.ConnectorService.RotateCredential + description: Create (send) a new invitation to a user. + operationId: c1.api.local_directory.v1.LocalUserInvitationService.Create + parameters: + - in: path + name: directory_app_id + required: true + schema: + description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialRequest' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ConnectorServiceRotateCredentialResponse' - description: ConnectorServiceRotateCredentialResponse is the response returned by the rotate method. - summary: Rotate Credential + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse' + description: Successful response + summary: Create tags: - - Connector - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: ConnectorCredential#create - x-speakeasy-group: Connector - x-speakeasy-name-override: RotateCredential - /api/v1/apps/connectors/validate_config/http: - post: - description: Validate an HTTP connector configuration and return any diagnostics or errors found. - operationId: c1.api.app.v1.ConnectorService.ValidateHTTPConnectorConfig - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.EditorValidateRequest' + - Local Directory + x-speakeasy-group: LocalUserInvitation + x-speakeasy-name-override: Create + /api/v1/local-directory-configs/{directory_app_id}/invitations/{id}: + get: + description: Get a specific invitation by id. + operationId: c1.api.local_directory.v1.LocalUserInvitationService.Get + parameters: + - in: path + name: directory_app_id + required: true + schema: + description: The directoryAppId field. + type: string + - in: path + name: id + required: true + schema: + description: The id field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.EditorValidateResponse' - description: The EditorValidateResponse message contains validation results. - summary: Validate Http Connector Config + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse' + description: Successful response + summary: Get tags: - - Connector - x-speakeasy-group: Connector - x-speakeasy-name-override: ValidateHTTPConnectorConfig - /api/v1/attribute/{id}: - delete: - description: Delete an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteAttributeValue + - Local Directory + x-speakeasy-group: LocalUserInvitation + x-speakeasy-name-override: Get + /api/v1/local-directory-configs/{directory_app_id}/invitations/{id}/revoke: + post: + description: Revoke a pending invitation. + operationId: c1.api.local_directory.v1.LocalUserInvitationService.Revoke parameters: + - in: path + name: directory_app_id + required: true + schema: + description: The directoryAppId field. + type: string - in: path name: id required: true schema: description: The id field. - readOnly: false type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueRequestInput' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteAttributeValueResponse' - description: DeleteAttributeValueResponse is the empty response for deleting an attribute value. - summary: Delete Attribute Value + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse' + description: Successful response + summary: Revoke tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteAttributeValue - /api/v1/attributes: - post: - description: Create a new attribute value. - operationId: c1.api.attribute.v1.Attributes.CreateAttributeValue - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueRequest' + - Local Directory + x-speakeasy-group: LocalUserInvitation + x-speakeasy-name-override: Revoke + /api/v1/mcp_server_catalog: + get: + description: ListCatalog returns all available MCP server catalog entries. + operationId: c1.api.ai_governance.v1.MCPServerService.ListCatalog + parameters: + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + - in: query + name: query + schema: + description: Optional text query to filter catalog entries by display name. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateAttributeValueResponse' - description: CreateAttributeValueResponse is the response for creating an attribute value. - summary: Create Attribute Value + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceListCatalogResponse' + description: MCPServerServiceListCatalogResponse returns a paginated list of catalog entries. + summary: List Catalog tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateAttributeValue - /api/v1/attributes/{id}: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: ListCatalog + /api/v1/mcp_server_catalog/{catalog_id}: get: - description: Get an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetAttributeValue + description: GetCatalog retrieves a single MCP server catalog entry by ID. + operationId: c1.api.ai_governance.v1.MCPServerService.GetCatalog parameters: - in: path - name: id + name: catalog_id required: true schema: - description: The id field. - readOnly: false + description: The catalogId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetAttributeValueResponse' - description: GetAttributeValueResponse is the response for getting an attribute value by id. - summary: Get Attribute Value + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceGetCatalogResponse' + description: MCPServerServiceGetCatalogResponse returns a single catalog entry. + summary: Get Catalog tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetAttributeValue - /api/v1/attributes/compliance_frameworks: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: GetCatalog + /api/v1/mcp_server_connections: get: - description: List all compliance framework attribute values (e.g., SOC 2, HIPAA) with pagination. - operationId: c1.api.attribute.v1.Attributes.ListComplianceFrameworks + description: |- + ListConnections returns per-user MCP servers the calling user can + connect to, filtered to apps where the user has an account. Covers + OAuth2 authorization-code passthrough as well as bearer-token / + custom-header per-user methods. Includes per-user connection status. + operationId: c1.api.ai_governance.v1.MCPServerService.ListConnections parameters: - in: query name: page_size schema: - description: The pageSize field. + description: Page size (max 100). format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: The pageToken field. - readOnly: false + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListComplianceFrameworksResponse' - description: ListComplianceFrameworksResponse is the response for listing compliance framework attribute values. - summary: List Compliance Frameworks + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceListConnectionsResponse' + description: |- + MCPServerServiceListConnectionsResponse returns a list of passthrough-mode + MCP servers with per-user connection status. + summary: List Connections tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Compliance Frameworks#read - terraform-resource: null - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListComplianceFrameworks + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: ListConnections + /api/v1/mcp_servers/discover_oidc: post: - description: Create a compliance framework value. - operationId: c1.api.attribute.v1.Attributes.CreateComplianceFrameworkAttributeValue + description: |- + DiscoverOIDCEndpoints fetches the OpenID Connect discovery document for an issuer + and returns the authorization, token, and supported scopes. + operationId: c1.api.ai_governance.v1.MCPServerService.DiscoverOIDCEndpoints requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueRequest' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDiscoverOIDCEndpointsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateComplianceFrameworkAttributeValueResponse' - description: Successful response - summary: Create Compliance Framework Attribute Value + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceDiscoverOIDCEndpointsResponse' + description: MCPServerServiceDiscoverOIDCEndpointsResponse returns the discovered OAuth2 endpoints. + summary: Discover Oidc Endpoints tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Compliance Framework#create - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateComplianceFrameworkAttributeValue - /api/v1/attributes/compliance_frameworks/{id}: - delete: - description: Delete an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteComplianceFrameworkAttributeValue - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - readOnly: false - type: string + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: DiscoverOIDCEndpoints + /api/v1/mcp_servers/test_connection: + post: + description: |- + TestConnection probes an MCP server with the + supplied URL + transport + plaintext credentials and reports + whether a real MCP initialize + tools/list succeeded. + operationId: c1.api.ai_governance.v1.MCPServerService.TestConnection requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteComplianceFrameworkAttributeValueResponse' - description: Successful response - summary: Delete Compliance Framework Attribute Value - tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Compliance Framework#delete - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteComplianceFrameworkAttributeValue - get: - description: Get an attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetComplianceFrameworkAttributeValue - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceTestConnectionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetComplianceFrameworkAttributeValueResponse' + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPServerServiceTestConnectionResponse' description: Successful response - summary: Get Compliance Framework Attribute Value + summary: Test Connection tags: - - Compliance Framework - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Compliance Framework#read - terraform-resource: Compliance Framework#read - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetComplianceFrameworkAttributeValue - /api/v1/attributes/risk_levels: + - MCP Servers + x-speakeasy-group: MCPServer + x-speakeasy-name-override: TestConnection + /api/v1/policies: get: - description: List all risk level attribute values with pagination. - operationId: c1.api.attribute.v1.Attributes.ListRiskLevels + description: List policies. + operationId: c1.api.policy.v1.Policies.List parameters: - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListRiskLevelsResponse' - description: ListRiskLevelsResponse is the response for listing risk level attribute values. - summary: List Risk Levels + $ref: '#/components/schemas/c1.api.policy.v1.ListPolicyResponse' + description: Successful response + summary: List tags: - - Risk Level - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Risk Levels#read - terraform-resource: null - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListRiskLevels + - Policy + x-speakeasy-group: Policies + x-speakeasy-name-override: List post: - description: Create a risk level attribute. - operationId: c1.api.attribute.v1.Attributes.CreateRiskLevelAttributeValue + description: Create a policy. + operationId: c1.api.policy.v1.Policies.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueRequest' + $ref: '#/components/schemas/c1.api.policy.v1.CreatePolicyRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.CreateRiskLevelAttributeValueResponse' - description: Successful response - summary: Create Risk Level Attribute Value + $ref: '#/components/schemas/c1.api.policy.v1.CreatePolicyResponse' + description: The CreatePolicyResponse message contains the created policy object. + summary: Create tags: - - Risk Level + - Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Risk Level#create - x-speakeasy-group: Attributes - x-speakeasy-name-override: CreateRiskLevelAttributeValue - /api/v1/attributes/risk_levels/{id}: + terraform-resource: Policy#create + x-speakeasy-group: Policies + x-speakeasy-name-override: Create + /api/v1/policies/{id}: delete: - description: Delete a risk level attribute value by id. - operationId: c1.api.attribute.v1.Attributes.DeleteRiskLevelAttributeValue + description: Delete a policy by ID. + operationId: c1.api.policy.v1.Policies.Delete parameters: - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The Id of the policy to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueRequestInput' + $ref: '#/components/schemas/c1.api.policy.v1.DeletePolicyRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.policy.v1.DeletePolicyResponse' + description: Empty response with a status code indicating success. + summary: Delete + tags: + - Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Policy#delete + x-speakeasy-group: Policies + x-speakeasy-name-override: Delete + get: + description: Get a policy by ID. + operationId: c1.api.policy.v1.Policies.Get + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.DeleteRiskLevelAttributeValueResponse' - description: Successful response - summary: Delete Risk Level Attribute Value + $ref: '#/components/schemas/c1.api.policy.v1.GetPolicyResponse' + description: The GetPolicyResponse message contains the policy object. + summary: Get tags: - - Risk Level + - Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Risk Level#delete - x-speakeasy-group: Attributes - x-speakeasy-name-override: DeleteRiskLevelAttributeValue - get: - description: Get a risk level attribute value by id. - operationId: c1.api.attribute.v1.Attributes.GetRiskLevelAttributeValue + terraform-datasource: null + terraform-resource: Policy#read + x-speakeasy-group: Policies + x-speakeasy-name-override: Get + post: + description: Update a policy by providing a policy object and an update mask. + operationId: c1.api.policy.v1.Policies.Update parameters: - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The ID of the Policy. + readOnly: true type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.policy.v1.UpdatePolicyRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.GetRiskLevelAttributeValueResponse' - description: Successful response - summary: Get Risk Level Attribute Value + $ref: '#/components/schemas/c1.api.policy.v1.UpdatePolicyResponse' + description: The UpdatePolicyResponse message contains the updated policy object. + summary: Update tags: - - Risk Level + - Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Risk Level#read - terraform-resource: Risk Level#read - x-speakeasy-group: Attributes - x-speakeasy-name-override: GetRiskLevelAttributeValue - /api/v1/attributes/types: - get: - description: List all attribute types. - operationId: c1.api.attribute.v1.Attributes.ListAttributeTypes - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + terraform-resource: Policy#update + x-speakeasy-group: Policies + x-speakeasy-name-override: Update + /api/v1/policies/test-account-provision-policy: + post: + description: Test an account provision policy by evaluating a CEL expression and returning the computed result. + operationId: c1.api.policy.v1.AccountProvisionPolicyTest.Test + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.policy.v1.TestAccountProvisionPolicyRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeTypesResponse' - description: ListAttributeTypesResponse is the response for listing attribute types. - summary: List Attribute Types + $ref: '#/components/schemas/c1.api.policy.v1.TestAccountProvisionPolicyResponse' + description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. + summary: Test tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListAttributeTypes - /api/v1/attributes/types/{attribute_type_id}/values: - get: - description: List all attribute values for a given attribute type. - operationId: c1.api.attribute.v1.Attributes.ListAttributeValues - parameters: - - in: path - name: attribute_type_id - required: true - schema: - description: The attributeTypeId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + - Policy + x-speakeasy-group: AccountProvisionPolicyTest + x-speakeasy-name-override: Test + /api/v1/policies/validate/cel: + post: + description: Validate policies + operationId: c1.api.policy.v1.PolicyValidate.ValidateCEL + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.policy.v1.EditorValidateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.ListAttributeValuesResponse' - description: ListAttributeValuesResponse is the response for listing attribute values for a given AttributeType. - summary: List Attribute Values + $ref: '#/components/schemas/c1.api.policy.v1.EditorValidateResponse' + description: Successful response + summary: Validate Cel tags: - - Attribute - x-speakeasy-group: Attributes - x-speakeasy-name-override: ListAttributeValues - /api/v1/auth-configs: + - Policy + x-speakeasy-group: PolicyValidate + x-speakeasy-name-override: ValidateCEL + /api/v1/recovery-policies: get: - description: List returns all authentication provider configurations for the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.List + description: List all recovery policies in your tenant, one page at a time. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.List parameters: - in: query name: page_size schema: description: The maximum number of results to return per page. format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: A pagination token returned from a previous List call. - readOnly: false + description: A pagination token from a previous List response. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceListResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceListResponse' description: Successful response summary: List tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Recovery Policy + x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: List post: - description: Create registers a new authentication provider configuration for the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Create + description: Create a recovery policy. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateRequest' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceCreateResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateResponse' description: Successful response summary: Create tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Recovery Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: RecoveryPolicy#create + x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: Create - /api/v1/auth-configs/{id}: + /api/v1/recovery-policies/{id}: delete: - description: Delete removes an authentication provider configuration from the tenant. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Delete + description: Delete a recovery policy by ID. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Delete parameters: - in: path name: id required: true schema: - description: The unique identifier of the authentication provider configuration to delete. - readOnly: false + description: The ID of the policy to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceDeleteResponse' description: Successful response summary: Delete tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Recovery Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: RecoveryPolicy#delete + x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: Delete get: - description: Get retrieves a single authentication provider configuration by its ID. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Get + description: Get a recovery policy by ID. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Get parameters: - in: path name: id required: true schema: - description: The unique identifier of the authentication provider configuration to retrieve. - readOnly: false + description: The ID of the policy to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceGetResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceGetResponse' description: Successful response summary: Get tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Recovery Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: RecoveryPolicy#read + x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: Get post: - description: Update modifies an existing authentication provider configuration. Use the update mask to specify which fields to change. - operationId: c1.api.auth_config.v1.TenantAuthConfigService.Update + description: |- + Update a recovery policy. Supply the policy object and an update mask + listing the fields to change; omitted fields are left as-is. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Update parameters: - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: Unique identifier for the policy. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.auth_config.v1.TenantAuthConfigServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceUpdateResponse' description: Successful response summary: Update tags: - - Auth Config - x-speakeasy-group: TenantAuthConfig + - Recovery Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: RecoveryPolicy#update + x-speakeasy-group: RecoveryPolicy x-speakeasy-name-override: Update - /api/v1/auth/introspect: - get: - description: Introspect returns the current user's principle_id, user_id and a list of roles, permissions, and enabled features. - operationId: c1.api.auth.v1.Auth.Introspect - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.auth.v1.IntrospectResponse' - description: IntrospectResponse contains information about the current user who is authenticated. - summary: Introspect - tags: - - Auth - x-speakeasy-group: Auth - x-speakeasy-name-override: Introspect - /api/v1/automation_executions: - get: - description: List all automation executions in the tenant with pagination support. - operationId: c1.api.automations.v1.AutomationExecutionService.ListAutomationExecutions - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationExecutionsResponse' - description: Successful response - summary: List Automation Executions - tags: - - Automations - x-speakeasy-group: AutomationExecution - x-speakeasy-name-override: ListAutomationExecutions - /api/v1/automation_executions/{id}: - get: - description: Retrieve a single automation execution by its unique identifier, with optional expanded related objects. - operationId: c1.api.automations.v1.AutomationExecutionService.GetAutomationExecution - parameters: - - in: path - name: id - required: true - schema: - description: The unique identifier of the automation execution to retrieve. - format: int64 - readOnly: false - type: string + /api/v1/request_schema_entitlement_binding: + delete: + description: Remove the link between a request schema and a single app entitlement. + operationId: c1.api.request_schema.v1.RequestSchemaService.RemoveEntitlementBinding + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationExecutionResponse' - description: Successful response - summary: Get Automation Execution + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse' + description: The response message for removing a single entitlement binding. + summary: Remove Entitlement Binding tags: - - Automations - x-speakeasy-group: AutomationExecution - x-speakeasy-name-override: GetAutomationExecution - /api/v1/automation_executions/{id}/actions/terminate: + - Request Schema Entitlement Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Request Schema Entitlement Binding#delete + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: RemoveEntitlementBinding post: - description: Terminate a running automation execution asynchronously, stopping it and marking it as terminated. - operationId: c1.api.automations.v1.AutomationExecutionActionsService.TerminateAutomation - parameters: - - in: path - name: id - required: true - schema: - description: The unique identifier of the automation execution to terminate. - format: int64 - readOnly: false - type: string + description: Link a request schema to a single app entitlement so the form is shown when requesting that entitlement. + operationId: c1.api.request_schema.v1.RequestSchemaService.CreateEntitlementBinding requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.TerminateAutomationResponse' - description: Successful response - summary: Terminate Automation + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse' + description: The response message for creating a single entitlement binding. + summary: Create Entitlement Binding tags: - - Automations - x-speakeasy-group: AutomationExecutionActions - x-speakeasy-name-override: TerminateAutomation - /api/v1/automations: - get: - description: List all automations in the tenant with pagination support. - operationId: c1.api.automations.v1.AutomationService.ListAutomations + - Request Schema Entitlement Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Request Schema Entitlement Binding#create + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: CreateEntitlementBinding + put: + description: Look up which request schema is bound to a given app entitlement. + operationId: c1.api.request_schema.v1.RequestSchemaService.FindBindingForAppEntitlement + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ListAutomationsResponse' - description: Successful response - summary: List Automations + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse' + description: The response message containing the binding for the specified app entitlement. + summary: Find Binding For App Entitlement tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ListAutomations + - Request Schema Entitlement Binding + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Request Schema Entitlement Binding#read + terraform-resource: Request Schema Entitlement Binding#read + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: FindBindingForAppEntitlement + /api/v1/request_schemas: post: - description: Create a new automation with the specified steps, triggers, and configuration. - operationId: c1.api.automations.v1.AutomationService.CreateAutomation + description: Create a new request schema that defines a form template for access requests. + operationId: c1.api.request_schema.v1.RequestSchemaService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationRequest' + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.CreateAutomationResponse' - description: Successful response - summary: Create Automation + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateResponse' + description: The response message for creating a request schema. + summary: Create tags: - - Automations + - Request Schema x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Automation#create - x-speakeasy-group: Automation - x-speakeasy-name-override: CreateAutomation - /api/v1/automations/{id}: + terraform-resource: Request_Schema#create + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: Create + /api/v1/request_schemas/{request_schema_id}: delete: - description: Delete an automation by its unique identifier, removing it and its associated triggers. - operationId: c1.api.automations.v1.AutomationService.DeleteAutomation + description: Delete a request schema by ID. Associated entitlement bindings are also deleted. + operationId: c1.api.request_schema.v1.RequestSchemaService.Delete parameters: - in: path - name: id + name: request_schema_id required: true schema: - description: The unique identifier of the automation to delete. - readOnly: false + description: The unique identifier of the request schema to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationRequestInput' + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.DeleteAutomationResponse' - description: Successful response - summary: Delete Automation + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse' + description: The response message for deleting a request schema. + summary: Delete tags: - - Automations + - Request Schema x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Automation#delete - x-speakeasy-group: Automation - x-speakeasy-name-override: DeleteAutomation + terraform-resource: Request_Schema#delete + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: Delete get: - description: Retrieve a single automation by its unique identifier. - operationId: c1.api.automations.v1.AutomationService.GetAutomation + description: Retrieve a single request schema by ID. + operationId: c1.api.request_schema.v1.RequestSchemaService.Get parameters: - in: path - name: id + name: request_schema_id required: true schema: - description: The unique identifier of the automation to retrieve. - readOnly: false + description: The unique identifier of the request schema to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.GetAutomationResponse' - description: Successful response - summary: Get Automation + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceGetResponse' + description: The response message for retrieving a request schema. + summary: Get tags: - - Automations + - Request Schema x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Automation#read - x-speakeasy-group: Automation - x-speakeasy-name-override: GetAutomation + terraform-datasource: Request_Schema#read + terraform-resource: Request_Schema#read + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: Get post: - description: Update an existing automation's properties, steps, or triggers using a field mask. - operationId: c1.api.automations.v1.AutomationService.UpdateAutomation + description: Update an existing request schema's form definition or settings. + operationId: c1.api.request_schema.v1.RequestSchemaService.Update parameters: - in: path - name: id + name: request_schema_id required: true schema: - description: The id field. - readOnly: true + description: The unique identifier of this request schema. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationRequestInput' + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.UpdateAutomationResponse' - description: Successful response - summary: Update Automation + $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse' + description: The response message for updating a request schema. + summary: Update tags: - - Automations + - Request Schema x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Automation#update - x-speakeasy-group: Automation - x-speakeasy-name-override: UpdateAutomation - /api/v1/automations/{id}/circuit_breaker/clear: + terraform-resource: Request_Schema#update + x-speakeasy-group: RequestSchema + x-speakeasy-name-override: Update + /api/v1/role-mining/access-profiles: post: description: |- - Clear the circuit breaker on an automation that was auto-disabled by the - rate cap. Future events flow normally; existing paused executions are not - affected (use ResolvePausedAutomationExecutions to run or cancel them). - operationId: c1.api.automations.v1.AutomationService.ClearAutomationCircuitBreaker - parameters: - - in: path - name: id - required: true - schema: - description: |- - The unique identifier of the automation whose circuit breaker should - be cleared. - readOnly: false - type: string + CreateAccessProfileFromCohort creates an access profile from a cohort definition, + adds the specified entitlements, and sets up dynamic membership automation using + a CEL expression derived from the profile filters. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.CreateAccessProfileFromCohort requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerRequestInput' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ClearAutomationCircuitBreakerResponse' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse' description: Successful response - summary: Clear Automation Circuit Breaker + summary: Create Access Profile From Cohort tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ClearAutomationCircuitBreaker - /api/v1/automations/{id}/circuit_breaker/resolve_paused: - post: - description: |- - Decide what to do with the executions that were paused while the - automation's circuit breaker was tripped. Idempotent. - operationId: c1.api.automations.v1.AutomationService.ResolvePausedAutomationExecutions - parameters: - - in: path - name: id - required: true - schema: - description: |- - The unique identifier of the automation whose paused executions should - be resolved. - readOnly: false - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsRequestInput' + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: CreateAccessProfileFromCohort + /api/v1/role-mining/config: + get: + description: Retrieve the current role mining configuration, including cohort hints and threshold settings. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetRoleMiningConfig responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ResolvePausedAutomationExecutionsResponse' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetRoleMiningConfigResponse' description: Successful response - summary: Resolve Paused Automation Executions + summary: Get Role Mining Config tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ResolvePausedAutomationExecutions - /api/v1/automations/{id}/execute: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: GetRoleMiningConfig post: - description: Trigger an on-demand execution of an automation, returning the new execution's identifier. - operationId: c1.api.automations.v1.AutomationService.ExecuteAutomation - parameters: - - in: path - name: id - required: true - schema: - description: The unique identifier of the automation to execute. - readOnly: false - type: string + description: Update the role mining configuration, such as cohort hints, max suggestions, and minimum cohort size. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.UpdateRoleMiningConfig requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationRequestInput' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.ExecuteAutomationResponse' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse' description: Successful response - summary: Execute Automation + summary: Update Role Mining Config tags: - - Automations - x-speakeasy-group: Automation - x-speakeasy-name-override: ExecuteAutomation - /api/v1/catalogs: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: UpdateRoleMiningConfig + /api/v1/role-mining/custom-analysis: get: - description: Get a list of request catalogs. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + description: List recent custom analysis results in reverse chronological order. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.ListCustomAnalysisResults + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.ListCustomAnalysisResultsResponse' + description: Successful response + summary: List Custom Analysis Results + tags: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: ListCustomAnalysisResults + /api/v1/role-mining/custom-analysis/{id}: + get: + description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult method. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult + parameters: + - in: path + name: id + required: true schema: - description: The page_token field for pagination. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListResponse' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse' description: Successful response - summary: List + summary: Get Custom Analysis Result tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Request Catalogs#read - terraform-resource: null - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: List + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: GetCustomAnalysisResult + /api/v1/role-mining/custom-analysis/trigger: post: - description: Creates a new request catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Create + description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis method. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequest' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Create + $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse' + description: Successful response + summary: Trigger Custom Analysis tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Create - /api/v1/catalogs/{catalog_id}/requestable_entitlementIDs: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: TriggerCustomAnalysis + /api/v1/role-mining/runs: get: - description: List all requestable entitlement IDs in a catalog without pagination. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListAllEntitlementIdsPerApp - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The unique identifier of the access profile. - readOnly: false - type: string + description: List role mining analysis runs in reverse chronological order. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.ListRuns responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListAllEntitlementIdsPerCatalogResponse' - description: The response message containing all requestable entitlement references in the catalog. - summary: List All Entitlement Ids Per App + $ref: '#/components/schemas/c1.api.role_mining_management.v1.ListRunsResponse' + description: Successful response + summary: List Runs tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Access_Profile_Requestable_Entries#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListAllEntitlementIdsPerApp - /api/v1/catalogs/{catalog_id}/requestable_entitlements: + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: ListRuns + /api/v1/role-mining/runs/latest: get: - description: List entitlements in a catalog that are requestable. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsPerCatalog - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + description: Retrieve the most recent role mining analysis run, including its status and results summary. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetLatestRun responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsPerCatalogResponse' - description: The RequestCatalogManagementServiceListEntitlementsPerCatalogResponse message contains a list of results and a nextPageToken if applicable. - summary: List Entitlements Per Catalog + $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetLatestRunResponse' + description: Successful response + summary: Get Latest Run tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListEntitlementsPerCatalog - /api/v1/catalogs/{catalog_id}/requestable_entitlements/update: - post: - description: Replace the full set of requestable entitlements in a catalog with the provided list. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.UpdateAppEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The Id of the request catalog to get app entitlement to. This is a URL value. - readOnly: false - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsRequestInput' + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: GetLatestRun + /api/v1/role-mining/suggestions: + get: + description: List role suggestions generated by analysis runs, optionally filtered by state. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.ListSuggestions responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateAppEntitlementsResponse' - description: The RequestCatalogManagementServiceUpdateAppEntitlementsResponse object is is the response from UpdateAppEntitlements endpoint. - summary: Update App Entitlements + $ref: '#/components/schemas/c1.api.role_mining_management.v1.ListSuggestionsResponse' + description: Successful response + summary: List Suggestions tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: UpdateAppEntitlements - /api/v1/catalogs/{catalog_id}/requestable_entries: - delete: - description: Remove requestable entitlements from a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAppEntitlements + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: ListSuggestions + /api/v1/role-mining/suggestions/{id}: + get: + description: Retrieve a single role suggestion by ID, including its cohort filters, entitlements, and confidence score. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetSuggestion parameters: - in: path - name: catalog_id + name: id required: true schema: - description: The catalogId for the catalog to remove entitlements from. - readOnly: false + description: The ID of the role mining suggestion to retrieve. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAppEntitlementsResponse' - description: Empty response with a status code indicating success - summary: Remove App Entitlements + $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetSuggestionResponse' + description: Successful response + summary: Get Suggestion tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: RemoveAppEntitlements + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: GetSuggestion + /api/v1/role-mining/suggestions/{id}/state: post: - description: Add requestable entitlements to a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAppEntitlements + description: Transition a role suggestion to a new state, such as accepted, rejected, or dismissed. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.UpdateSuggestionState parameters: - in: path - name: catalog_id + name: id required: true schema: - description: The Id of the request catalog to add app entitlements to. This is a URL value. - readOnly: false + description: The ID of the role mining suggestion to update. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAppEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Add App Entitlements + $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateSuggestionStateResponse' + description: Successful response + summary: Update Suggestion State tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entries#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: AddAppEntitlements - /api/v1/catalogs/{catalog_id}/requestable_entries/{app_id}/{entitlement_id}: - delete: - description: Delete a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteRequestableEntry + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: UpdateSuggestionState + /api/v1/role-mining/suggestions/{suggestion_id}/users: + post: + description: Search for users that belong to a suggestion's cohort, with optional additional profile filters. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.SearchCohortUsers parameters: - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) - readOnly: false - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - readOnly: false - type: string - - in: path - name: entitlement_id + name: suggestion_id required: true schema: - description: The ID of the entitlement - readOnly: false + description: The ID of the suggestion whose cohort to search within. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryRequestInput' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.SearchCohortUsersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestableEntryResponse' - description: Empty response for delete operation - summary: Delete Requestable Entry + $ref: '#/components/schemas/c1.api.role_mining_management.v1.SearchCohortUsersResponse' + description: Successful response + summary: Search Cohort Users tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entry#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: DeleteRequestableEntry - get: - description: Get a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetRequestableEntry - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) - readOnly: false - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - readOnly: false - type: string - - in: path - name: entitlement_id - required: true - schema: - description: The ID of the entitlement - readOnly: false - type: string + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: SearchCohortUsers + /api/v1/role-mining/trigger: + post: + description: Start a new role mining analysis job that scans existing access patterns to generate role suggestions. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerAnalysis + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerAnalysisRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetRequestableEntryResponse' - description: Response containing the requested entry - summary: Get Requestable Entry + $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerAnalysisResponse' + description: Successful response + summary: Trigger Analysis tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access_Profile_Requestable_Entry#read - terraform-resource: null - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: GetRequestableEntry - put: - description: Create a single requestable entry - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateRequestableEntry - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The ID of the access profile (catalog) to add the entitlement to - readOnly: false - type: string - - in: path - name: app_id - required: true - schema: - description: The ID of the app that contains the entitlement - readOnly: false - type: string - - in: path - name: entitlement_id - required: true - schema: - description: The ID of the entitlement to add to the request catalog - readOnly: false - type: string + - Role Mining + x-speakeasy-group: RoleMiningManagement + x-speakeasy-name-override: TriggerAnalysis + /api/v1/search/all_automation_executions: + post: + description: |- + Search across all automation executions in the tenant, with filters for state, template, app, and subject user. + Each AutomationExecutionView row is large — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.automations.v1.AutomationExecutionSearchService.SearchAllAutomationExecutions requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.SearchAllAutomationExecutionsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceCreateRequestableEntryResponse' - description: Response containing the created requestable entry - summary: Create Requestable Entry + $ref: '#/components/schemas/c1.api.automations.v1.SearchAllAutomationExecutionsResponse' + description: Successful response + summary: Search All Automation Executions tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Requestable_Entry#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: CreateRequestableEntry - /api/v1/catalogs/{catalog_id}/visibility_bindings: - delete: - description: Remove visibility bindings (access entitlements) from a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.RemoveAccessEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId for the catalog to remove access entitlements from. - readOnly: false - type: string + - Automations + x-speakeasy-group: AutomationExecutionSearch + x-speakeasy-name-override: SearchAllAutomationExecutions + /api/v1/search/app_resource_types: + post: + description: Search app resources based on filters specified in the request body. + operationId: c1.api.app.v1.AppResourceSearch.SearchAppResourceTypes requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourceTypesRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceRemoveAccessEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Remove Access Entitlements + $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourceTypesResponse' + description: The SearchAppResourceTypesResponse message contains a list of results and a nextPageToken if applicable. + summary: Search App Resource Types tags: - - Request Catalog + - App Resource x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Visibility_Bindings#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: RemoveAccessEntitlements + terraform-datasource: + - App Resource Type#read + - App Resource Types#read + terraform-resource: null + x-speakeasy-group: AppResourceSearch + x-speakeasy-name-override: SearchAppResourceTypes + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/app_resources: post: - description: Add visibility bindings (access entitlements) to a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.AddAccessEntitlements - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The Id of the request catalog to add access entitlements to. This is a URL value. - readOnly: false - type: string + description: Search app resources based on filters specified in the request body. + operationId: c1.api.app.v1.AppResourceSearch.SearchAppResources requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceAddAccessEntitlementsResponse' - description: Empty response with a status code indicating success. - summary: Add Access Entitlements + $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesResponse' + description: The SearchAppResourcesResponse message contains a list of results and a nextPageToken if applicable. + summary: Search App Resources tags: - - Request Catalog + - App Resource x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Profile_Visibility_Bindings#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: AddAccessEntitlements - /api/v1/catalogs/{catalog_id}/visibility_entitlements: - get: - description: List visibility bindings (access entitlements) for a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ListEntitlementsForAccess - parameters: - - in: path - name: catalog_id - required: true - schema: - description: The catalogId field. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + terraform-datasource: App Resources#read + terraform-resource: null + x-speakeasy-group: AppResourceSearch + x-speakeasy-name-override: SearchAppResources + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/app_users: + post: + description: Search app users based on filters specified in the request body. + operationId: c1.api.app.v1.AppUserService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceListEntitlementsForAccessResponse' - description: The RequestCatalogManagementServiceListEntitlementsForAccessResponse message contains a list of results and a nextPageToken if applicable. - summary: List Entitlements For Access + $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceSearchResponse' + description: Successful response + summary: Search tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ListEntitlementsForAccess - /api/v1/catalogs/{id}: - delete: - description: Delete a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Delete - parameters: - - in: path - name: id - required: true - schema: - description: The Id of the RequestCatalog to delete. - readOnly: false - type: string + - AppUsers + x-speakeasy-group: AppUser + x-speakeasy-name-override: Search + /api/v1/search/apps: + post: + description: Search apps based on filters specified in the request body. + operationId: c1.api.app.v1.AppSearch.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SearchAppsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceDeleteResponse' - description: Empty response with a status code indicating success. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v1.SearchAppsResponse' + description: The SearchAppsResponse message contains a list of results and a nextPageToken if applicable. + summary: Search tags: - - Request Catalog + - App x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Access_Profile#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Delete + terraform-datasource: + - App#read + - Apps#read + terraform-resource: null + x-speakeasy-group: AppSearch + x-speakeasy-name-override: Search + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/apps/{app_id}/entitlements/users/{app_user_id}: get: - description: Get a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Get + description: |- + Search for app entitlements associated with a specific app user, with optional resource type trait filtering. + Each AppEntitlementView row is large — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsForAppUser parameters: - in: path - name: id + name: app_id + required: true + schema: + description: The ID of the app to search entitlements within. + type: string + - in: path + name: app_user_id required: true schema: - description: The id field. - readOnly: false + description: The ID of the app user to search entitlements for. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Get + $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' + description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: Search App Entitlements For App User tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Access_Profile#read - terraform-resource: Access_Profile#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Get + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchAppEntitlementsForAppUser + /api/v1/search/attributes: post: - description: Update a catalog. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.Update - parameters: - - in: path - name: id - required: true - schema: - description: The id of the request catalog. - readOnly: false - type: string + description: Search attributes based on filters specified in the request body. + operationId: c1.api.attribute.v1.AttributeSearch.SearchAttributeValues requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.attribute.v1.SearchAttributeValuesRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogManagementServiceGetResponse' - description: The request catalog management service get response returns a request catalog view with the expanded items in the expanded array indicated by the expand mask in the request. - summary: Update + $ref: '#/components/schemas/c1.api.attribute.v1.SearchAttributeValuesResponse' + description: SearchAttributeValuesResponse is the response for searching AttributeValues. + summary: Search Attribute Values tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Access_Profile#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: Update - /api/v1/catalogs/{request_catalog_id}/bundle_automation: - delete: - description: Delete the bundle automation rule for a catalog, stopping automatic membership syncing. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.DeleteBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile whose automation should be deleted. - readOnly: false - type: string + - Attribute + x-speakeasy-group: AttributeSearch + x-speakeasy-name-override: SearchAttributeValues + /api/v1/search/automation_executions: + post: + description: |- + Search for automation executions with optional filters for automation_template_id, state, and query. + Each AutomationExecutionView row is large — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.automations.v1.AutomationExecutionSearchService.SearchAutomationExecutions requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationExecutionsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.DeleteBundleAutomationResponse' - description: The response message for deleting a bundle automation. - summary: Delete Bundle Automation + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationExecutionsResponse' + description: Successful response + summary: Search Automation Executions tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#delete - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: DeleteBundleAutomation - get: - description: Get bundle automation - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.GetBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The requestCatalogId field. - readOnly: false - type: string + - Automations + x-speakeasy-group: AutomationExecutionSearch + x-speakeasy-name-override: SearchAutomationExecutions + /api/v1/search/automation_versions: + post: + description: |- + Search for versioned snapshots of an automation template's steps and triggers. + Each version carries a full steps-and-triggers snapshot — request a small page_size (≤10) to keep responses small. + operationId: c1.api.automations.v1.AutomationSearchService.SearchAutomationTemplateVersions + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationTemplateVersionsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationTemplateVersionsResponse' description: Successful response - summary: Get Bundle Automation + summary: Search Automation Template Versions tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: BundleAutomation#read - terraform-resource: BundleAutomation#read - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: GetBundleAutomation + - Automations + x-speakeasy-group: AutomationSearch + x-speakeasy-name-override: SearchAutomationTemplateVersions + /api/v1/search/automations: post: - description: Create or update the bundle automation rule for a catalog that automatically syncs catalog membership. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.SetBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile to set the automation on. - readOnly: false - type: string + description: |- + Search for automations matching the provided filters, including query text, template refs, app, and trigger types. + Each Automation row is heavy (carries its full triggers and steps) — request a small page_size (≤10) to keep responses small. + operationId: c1.api.automations.v1.AutomationSearchService.SearchAutomations requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.SetBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationsResponse' description: Successful response - summary: Set Bundle Automation + summary: Search Automations tags: - - Request Catalog - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#update - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: SetBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/create: + - Automations + x-speakeasy-group: AutomationSearch + x-speakeasy-name-override: SearchAutomations + /api/v1/search/credential-inventory-policies: post: - description: Create a new bundle automation rule for a catalog that automatically syncs catalog membership from a query. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.CreateBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile to create the automation for. - readOnly: false - type: string + description: |- + Search credential inventory policies by name, or fetch a specific set by + ID. Returns one page of matching policies at a time. + operationId: c1.api.credential_inventory.v1.CredentialInventoryPolicyService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.CreateBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.BundleAutomation' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.CredentialInventoryPolicyServiceSearchResponse' description: Successful response - summary: Create Bundle Automation + summary: Search tags: - - Request Catalog + - Credential Inventory x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: BundleAutomation#create - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: CreateBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/resume: + terraform-datasource: CredentialInventoryPolicy#read + terraform-resource: null + x-speakeasy-group: CredentialInventoryPolicy + x-speakeasy-name-override: Search + /api/v1/search/entitlements: post: - description: Resume a bundle automation that was paused by the circuit breaker after detecting excessive membership changes. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ResumePausedBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile whose automation should be resumed. - readOnly: false - type: string + description: |- + Search app entitlements based on filters specified in the request body. + Each AppEntitlementView row is large — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.app.v1.AppEntitlementSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ResumePausedBundleAutomationResponse' - description: The response message for resuming a paused bundle automation. - summary: Resume Paused Bundle Automation + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchResponse' + description: Successful response + summary: Search tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ResumePausedBundleAutomation - /api/v1/catalogs/{request_catalog_id}/bundle_automation/run: + - App Entitlement + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: + - App Entitlement#read + - App Entitlements#read + terraform-resource: null + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: Search + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/finding_audits: post: - description: Trigger an immediate execution of a catalog's bundle automation, bypassing the normal schedule. - operationId: c1.api.requestcatalog.v1.RequestCatalogManagementService.ForceRunBundleAutomation - parameters: - - in: path - name: request_catalog_id - required: true - schema: - description: The unique identifier of the access profile whose automation should be run. - readOnly: false - type: string + description: |- + Search returns audit events filtered by finding, actor, type, or + app. Authorized as VIEWER -- the same role required to read the + finding itself. + operationId: c1.api.finding.v1.FindingAuditService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationRequestInput' + $ref: '#/components/schemas/c1.api.finding.v1.FindingAuditServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.ForceRunBundleAutomationResponse' - description: The response message for triggering a bundle automation run. - summary: Force Run Bundle Automation + $ref: '#/components/schemas/c1.api.finding.v1.FindingAuditServiceSearchResponse' + description: Successful response + summary: Search tags: - - Request Catalog - x-speakeasy-group: RequestCatalogManagement - x-speakeasy-name-override: ForceRunBundleAutomation - /api/v1/connectorcatalog: + - Findings + x-speakeasy-group: FindingAudit + x-speakeasy-name-override: Search + x-stability-level: beta + /api/v1/search/functions: post: - description: Return the configuration schema describing the fields required to set up a connector of the specified type. - operationId: c1.api.integration.connector.v1.ConnectorCatalogService.ConfigurationSchema + description: Search searches for functions based on criteria + operationId: c1.api.functions.v1.FunctionsSearch.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.integration.connector.v1.ConnectorCatalogServiceConfigurationSchemaResponse' - description: ConnectorCatalogServiceConfigurationSchemaResponse is the response containing the connector's configuration schema. - summary: Configuration Schema - tags: - - Connector Catalog - x-speakeasy-group: ConnectorCatalog - x-speakeasy-name-override: ConfigurationSchema - /api/v1/directories: - get: - description: List directories. - operationId: c1.api.directory.v1.DirectoryService.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceListResponse' - description: The DirectoryServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.functions.v1.FunctionsSearchResponse' + description: Successful response + summary: Search tags: - - Directory + - Function x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: - - Directory#read - - Directories#read + terraform-datasource: Function#read terraform-resource: null - x-speakeasy-group: Directory - x-speakeasy-name-override: List + x-speakeasy-group: FunctionsSearch + x-speakeasy-name-override: Search + x-stability-level: draft + /api/v1/search/grants: post: - description: Create a directory. - operationId: c1.api.directory.v1.DirectoryService.Create + description: |- + Search grants (user-to-entitlement bindings) across apps, with filters for app, user, resource type, and entitlement. + Rows are heavy (each binding carries a full entitlement + user view) — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchGrants requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateRequest' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceCreateResponse' - description: The DirectoryServiceCreateResponse message. - summary: Create + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsResponse' + description: Successful response + summary: Search Grants tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Directory#create - x-speakeasy-group: Directory - x-speakeasy-name-override: Create - /api/v1/directories/{app_id}: - delete: - description: Delete a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Delete - parameters: - - in: path - name: app_id - required: true - schema: - description: The app_id of the directory to delete. - readOnly: false - type: string + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchGrants + /api/v1/search/graph: + post: + description: |- + SearchGraph performs a server-side BFS traversal and returns a bounded, filtered subgraph. + Exactly one of user_id, app_id, or resource_id must be set. + operationId: c1.api.app.v1.AppEntitlementSearchService.SearchGraph requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGraphRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceDeleteResponse' - description: Empty response with a status code indicating success. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGraphResponse' + description: SearchGraph response. Contains a subgraph of nodes and edges. + summary: Search Graph tags: - - Directory - x-speakeasy-group: Directory - x-speakeasy-name-override: Delete - get: - description: Get a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Get - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: SearchGraph + /api/v1/search/graph/counts: + post: + description: |- + CountGrantsForUserByApp returns, for a user, the number of grants held per + application. Use it to size or filter an access graph before calling + SearchGraph: counts are computed directly from grant bindings and are an + upper bound on what SearchGraph will render for the same user and app + filter (SearchGraph applies additional filters that this count does not). + operationId: c1.api.app.v1.AppEntitlementSearchService.CountGrantsForUserByApp + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceCountGrantsForUserByAppRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceGetResponse' + $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceCountGrantsForUserByAppResponse' description: |- - The Directory Service Get Response returns a directory view with a directory and JSONPATHs indicating the - location in the expanded array that items are expanded as indicated by the expand mask in the request. - summary: Get + CountGrantsForUserByApp response. Grant counts are computed directly from + grant bindings and are an upper bound on what SearchGraph renders for the + same user and app filter — SearchGraph applies additional filters that + these counts do not. + summary: Count Grants For User By App tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Directory#read - x-speakeasy-group: Directory - x-speakeasy-name-override: Get - put: - description: Update a directory by app_id. - operationId: c1.api.directory.v1.DirectoryService.Update - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string + - App Entitlement + x-speakeasy-group: AppEntitlementSearch + x-speakeasy-name-override: CountGrantsForUserByApp + /api/v1/search/hooks: + post: + description: Invokes the c1.api.hooks.v1.HooksSearch.Search method. + operationId: c1.api.hooks.v1.HooksSearch.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.hooks.v1.HooksSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.directory.v1.DirectoryServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.hooks.v1.HooksSearchResponse' description: Successful response - summary: Update + summary: Search tags: - - Directory - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Directory#update - x-speakeasy-group: Directory - x-speakeasy-name-override: Update - /api/v1/findings/{finding_id}/state: + - Hook + x-speakeasy-group: HooksSearch + x-speakeasy-name-override: Search + /api/v1/search/iam/external_clients: post: - description: Update finding workflow state (snooze, accept risk, suppress, reopen, resolve). - operationId: c1.api.finding.v1.FindingService.UpdateFindingState - parameters: - - in: path - name: finding_id - required: true - schema: - description: The ID of the finding whose state to update. - readOnly: false - type: string + description: |- + Search returns external client grants for all users in the tenant. + Request a modest page_size (≤25) to keep responses small. + operationId: c1.api.iam.v1.ExternalClientSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateRequestInput' + $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientSearchServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingStateResponse' + $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientSearchServiceSearchResponse' description: Successful response - summary: Update Finding State + summary: 'NOTE: Searches external client grants for all users' tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: UpdateFindingState - /api/v1/findings/{finding_id}/task: + - External Client + x-speakeasy-group: ExternalClientSearch + x-speakeasy-name-override: Search + /api/v1/search/iam/personal_clients: post: - description: Create a task for a finding. - operationId: c1.api.finding.v1.FindingService.CreateFindingTask - parameters: - - in: path - name: finding_id - required: true - schema: - description: The ID of the finding to create a remediation task for. - readOnly: false - type: string + description: |- + Search finds personal client credentials across all users, with optional filtering by query text or user. + Request a modest page_size (≤25) to keep responses small. + operationId: c1.api.iam.v1.PersonalClientSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingTaskResponse' - description: Successful response - summary: Create Finding Task - tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: CreateFindingTask - /api/v1/findings/{id}: - get: - description: Get a single finding by ID. - operationId: c1.api.finding.v1.FindingService.GetFinding - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the finding to retrieve. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientSearchServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.GetFindingResponse' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientSearchServiceSearchResponse' description: Successful response - summary: Get Finding + summary: 'NOTE: Searches personal clients for all users' tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: GetFinding - /api/v1/findings/bulk/state: + - Personal Client + x-speakeasy-group: PersonalClientSearch + x-speakeasy-name-override: Search + /api/v1/search/iam/personal_devices: post: - description: Bulk update finding states. - operationId: c1.api.finding.v1.FindingService.BulkUpdateFindingState + description: |- + Search returns the calling user's registered devices, ordered by display name. + By default only active devices are returned; use the status filter to include + revoked devices. Optionally filter by a display-name query. + operationId: c1.api.iam.v1.PersonalDeviceService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateRequest' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkUpdateFindingStateResponse' + $ref: '#/components/schemas/c1.api.iam.v1.PersonalDeviceServiceSearchResponse' description: Successful response - summary: Bulk Update Finding State + summary: 'NOTE: Only shows devices for the current user.' tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: BulkUpdateFindingState - /api/v1/findings/bulk/tasks: + - Personal Device + x-speakeasy-group: PersonalDevice + x-speakeasy-name-override: Search + /api/v1/search/local-directory-invitations: post: - description: Bulk create tasks for findings. - operationId: c1.api.finding.v1.FindingService.BulkCreateFindingTasks + description: |- + List invitations for a directory, with optional status filter. + Search invitations with filters (directory, status). + operationId: c1.api.local_directory.v1.LocalUserInvitationService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksRequest' + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest' responses: "200": content: application/json: - schema: - $ref: '#/components/schemas/c1.api.finding.v1.BulkCreateFindingTasksResponse' - description: Successful response - summary: Bulk Create Finding Tasks - tags: - - Findings - x-speakeasy-group: Finding - x-speakeasy-name-override: BulkCreateFindingTasks - /api/v1/findings/routing-rules: - get: - description: List finding routing rules, optionally filtered to a specific app. - operationId: c1.api.finding.v1.FindingRoutingRuleService.ListFindingRoutingRules + schema: + $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse' + description: Successful response + summary: Search + tags: + - Local Directory + x-speakeasy-group: LocalUserInvitation + x-speakeasy-name-override: Search + /api/v1/search/past-grants: + post: + description: Search historical grants that have been revoked, filtered by app user or entitlement. + operationId: c1.api.app.v1.AppEntitlementUserBindingService.SearchPastGrants + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v1.SearchPastGrantsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.ListFindingRoutingRulesResponse' - description: Successful response - summary: List Finding Routing Rules + $ref: '#/components/schemas/c1.api.app.v1.SearchPastGrantsResponse' + description: The SearchPastGrantsResponse message contains a list of past grants and a nextPageToken if applicable. + summary: Search Past Grants tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: ListFindingRoutingRules + - App Entitlement User Binding History + x-speakeasy-group: AppEntitlementUserBinding + x-speakeasy-name-override: SearchPastGrants + /api/v1/search/policies: post: - description: Create a new finding routing rule that defines which policy to use for auto-routing matching findings. - operationId: c1.api.finding.v1.FindingRoutingRuleService.CreateFindingRoutingRule + description: Search policies based on filters specified in the request body. + operationId: c1.api.policy.v1.PolicySearch.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleRequest' + $ref: '#/components/schemas/c1.api.policy.v1.SearchPoliciesRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.CreateFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.policy.v1.SearchPoliciesResponse' description: Successful response - summary: Create Finding Routing Rule + summary: Search tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: CreateFindingRoutingRule - /api/v1/findings/routing-rules/{id}: - delete: - description: Delete a finding routing rule. Findings already routed by this rule are not affected. - operationId: c1.api.finding.v1.FindingRoutingRuleService.DeleteFindingRoutingRule - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the finding routing rule to delete. - readOnly: false - type: string + - Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: + - Policy#read + - Policies#read + terraform-resource: null + x-speakeasy-group: PolicySearch + x-speakeasy-name-override: Search + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/recovery-policies: + post: + description: |- + Search recovery policies by name, or fetch a specific set by ID. Returns + one page of matching policies at a time. + operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.DeleteFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceSearchResponse' description: Successful response - summary: Delete Finding Routing Rule + summary: Search tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: DeleteFindingRoutingRule - get: - description: Retrieve a single finding routing rule by ID. - operationId: c1.api.finding.v1.FindingRoutingRuleService.GetFindingRoutingRule - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the finding routing rule to retrieve. - readOnly: false - type: string + - Recovery Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: RecoveryPolicy#read + terraform-resource: null + x-speakeasy-group: RecoveryPolicy + x-speakeasy-name-override: Search + /api/v1/search/request_catalog/entitlements: + post: + description: |- + Search request catalogs based on filters specified in the request body. + Rows are heavy (each entitlement carries its user bindings) — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects and bloats the response. + operationId: c1.api.requestcatalog.v1.RequestCatalogSearchService.SearchEntitlements + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.GetFindingRoutingRuleResponse' - description: Successful response - summary: Get Finding Routing Rule + $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse' + description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. + summary: Search Entitlements tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: GetFindingRoutingRule - /api/v1/findings/routing-rules/{routing_rule_id}/update: + - Request Catalog + x-speakeasy-group: RequestCatalogSearch + x-speakeasy-name-override: SearchEntitlements + /api/v1/search/role-mining/suggestions: post: - description: Update an existing finding routing rule's match criteria or target policy. - operationId: c1.api.finding.v1.FindingRoutingRuleService.UpdateFindingRoutingRule - parameters: - - in: path - name: routing_rule_id - required: true - schema: - description: The id field. - readOnly: false - type: string + description: |- + Search role mining suggestions by name, description, or cohort filter values with optional state and type filters. + Each suggestion row is large (cohort filters, entitlements, insights, profile matches) — request a small page_size (≤10) to keep responses small. + operationId: c1.api.role_mining_management.v1.RoleMiningManagementSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleRequestInput' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.UpdateFindingRoutingRuleResponse' + $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse' description: Successful response - summary: Update Finding Routing Rule + summary: Search tags: - - Finding Routing Rules - x-speakeasy-group: FindingRoutingRule - x-speakeasy-name-override: UpdateFindingRoutingRule - /api/v1/findings/search: + - Role Mining + x-speakeasy-group: RoleMiningManagementSearch + x-speakeasy-name-override: Search + /api/v1/search/secrets-admin: post: - description: Search findings using full-text query and filters for severity, state, type, and app. - operationId: c1.api.finding.v1.FindingSearchService.Search + description: |- + Search returns secrets across the tenant. + Can filter by creator, sharing mode, status, time range, etc. + operationId: c1.api.secrets.v1.PaperSecretAdminService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchRequest' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.finding.v1.FindingSearchResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse' description: Successful response summary: Search tags: - - Findings - x-speakeasy-group: FindingSearch + - Secrets Admin + x-speakeasy-group: PaperSecretAdmin x-speakeasy-name-override: Search - /api/v1/functions: - get: - description: List retrieves all functions with pagination - operationId: c1.api.functions.v1.FunctionsService.ListFunctions + x-stability-level: beta + /api/v1/search/secrets-admin/audit_events: + post: + description: |- + SearchAuditEvents returns audit events for paper secrets. + Can filter by vault_id, actor (user ID or email), client IP. + operationId: c1.api.secrets.v1.PaperSecretAdminService.SearchAuditEvents + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListFunctionsResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse' description: Successful response - summary: List Functions + summary: Search Audit Events tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: ListFunctions - x-stability-level: draft + - Secrets Admin + x-speakeasy-group: PaperSecretAdmin + x-speakeasy-name-override: SearchAuditEvents + x-stability-level: beta + /api/v1/search/secrets/audit_events: post: - description: CreateFunction registers a new serverless function and creates its initial code commit. - operationId: c1.api.functions.v1.FunctionsService.CreateFunction + description: |- + SearchAuditEvents returns audit events for a secret owned by the calling user. + Returns sanitized OCSF events (IP addresses stripped for non-admin consumption). + operationId: c1.api.secrets.v1.PaperSecretService.SearchAuditEvents requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionRequest' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFunctionResponse' - description: Successful response - summary: Create Function + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse' + description: |- + PaperSecretServiceSearchAuditEventsResponse contains a page of audit events + for the requested secret. + summary: Search Audit Events tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#create - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateFunction - /api/v1/functions/{function_id}/commits: - get: - description: ListCommits retrieves the commit history - operationId: c1.api.functions.v1.FunctionsService.ListCommits - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: SearchAuditEvents + x-stability-level: beta + /api/v1/search/secrets/mine: + post: + description: |- + SearchMySecrets returns secrets created by the current user. + Automatically scoped to current user - no user_id filter parameter. + operationId: c1.api.secrets.v1.PaperSecretService.SearchMySecrets + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListCommitsResponse' - description: Successful response - summary: List Commits + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchResponse' + description: Search response for user's own secrets + summary: Search My Secrets tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: ListCommits - x-stability-level: draft + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: SearchMySecrets + x-stability-level: beta + /api/v1/search/session-policies: post: - description: CreateInitialCommit starts a new commit and returns upload URLs for files - operationId: c1.api.functions.v1.FunctionsService.CreateInitialCommit - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string + description: |- + Search session policies by name, or fetch a specific set by ID. Returns + one page of matching policies at a time. + operationId: c1.api.session_policy.v1.SessionPolicyService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitRequestInput' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateInitialCommitResponse' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceSearchResponse' description: Successful response - summary: Create Initial Commit + summary: Search tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateInitialCommit - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{commit_id}/finalize: + - Session Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: SessionPolicy#read + terraform-resource: null + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: Search + /api/v1/search/sign-in-policies: post: - description: CreateFinalCommit completes a commit after files are uploaded - operationId: c1.api.functions.v1.FunctionsService.CreateFinalCommit - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string - - in: path - name: commit_id - required: true - schema: - description: The commitId field. - readOnly: false - type: string + description: |- + Search sign-in policies by name, or fetch a specific set by ID. Returns + one page of matching policies at a time. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitRequestInput' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateFinalCommitResponse' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse' description: Successful response - summary: Create Final Commit + summary: Search tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateFinalCommit - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{commit_id}/lockfile: - get: - description: GetLockFile retrieves the deno lock file for a specific commit, if it exists. - operationId: c1.api.functions.v1.FunctionsService.GetLockFile - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string - - in: path - name: commit_id - required: true - schema: - description: The commitId field. - readOnly: false - type: string + - Sign-In Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: SignInPolicy#read + terraform-resource: null + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: Search + /api/v1/search/ssf-receiver-events: + post: + description: |- + Search performs a full-text search across received SSF events with optional filters for stream, event type, outcome, and matched user. + Request a modest page_size (≤25) to keep responses small. + operationId: c1.api.ssf_receiver.v1.SSFReceiverEventSearchService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetLockFileResponse' - description: FunctionsServiceGetLockFileResponse returns the deno lock file content for a commit. - summary: Get Lock File + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse' + description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. + summary: Search tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: GetLockFile - x-stability-level: draft - /api/v1/functions/{function_id}/commits/{id}: - get: - description: |- - GetCommitContent retrieves a commit and all its file contents in a single unary response. - This is a non-streaming alternative to GetCommit for REST API consumers. - operationId: c1.api.functions.v1.FunctionsService.GetCommitContent - parameters: - - in: path - name: function_id - required: true - schema: - description: The function ID (KSUID). - readOnly: false - type: string - - in: path - name: id - required: true - schema: - description: The commit reference to retrieve. Accepts a KSUID, "HEAD", or a tag reference like "refs/tags/v1.0". - readOnly: false - type: string + - SSF Receiver + x-speakeasy-group: SSFReceiverEventSearch + x-speakeasy-name-override: Search + /api/v1/search/step-up/providers: + post: + description: Search allows searching for step-up providers with various filters + operationId: c1.api.stepup.v1.StepUpProviderService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpProvidersRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetCommitContentResponse' - description: FunctionsServiceGetCommitContentResponse contains a commit and all its file contents. - summary: Get Commit Content + $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpProvidersResponse' + description: Response message for searching step-up providers + summary: Search tags: - - Function Commit - x-speakeasy-group: Functions - x-speakeasy-name-override: GetCommitContent - x-stability-level: draft - /api/v1/functions/{function_id}/invocations: - get: - description: List retrieves the invocation history for a function - operationId: c1.api.functions.v1.FunctionsInvocationService.List - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: Search + /api/v1/search/step-up/transactions: + post: + description: Search allows searching for step-up transactions with various filters + operationId: c1.api.stepup.v1.StepUpTransactionService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpTransactionsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceListResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpTransactionsResponse' + description: Response message for searching step-up transactions + summary: Search tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocation - x-speakeasy-name-override: List - x-stability-level: draft - /api/v1/functions/{function_id}/invocations/{id}: - get: - description: Get retrieves a specific invocation by ID - operationId: c1.api.functions.v1.FunctionsInvocationService.Get - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string - - in: path - name: id - required: true - schema: - description: The id field. - readOnly: false - type: string + - Step Up Authentication Transactions + x-speakeasy-group: StepUpTransaction + x-speakeasy-name-override: Search + /api/v1/search/systemlog/exports: + post: + description: Search for system log exports matching the specified filters. + operationId: c1.api.systemlog.v1.ExportsSearchService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportsSearchServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationServiceGetResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportsSearchServiceSearchResponse' + description: ExportsSearchServiceSearchResponse is the response for searching system log exports. + summary: Search tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocation - x-speakeasy-name-override: Get - x-stability-level: draft - /api/v1/functions/{function_id}/invocations/search: + - System Log Exporter + x-speakeasy-group: ExportsSearch + x-speakeasy-name-override: Search + /api/v1/search/tasks: post: - description: Search searches for function invocations with filtering and ordering support - operationId: c1.api.functions.v1.FunctionsInvocationSearchService.Search - parameters: - - in: path - name: function_id - required: true - schema: - description: The function ID to search invocations for. - readOnly: false - type: string + description: |- + Search tasks based on filters specified in the request body. + Each TaskView row is large — request a small page_size (≤10) and set expand_mask to only the paths you need; broad expansion inlines whole related objects (app, entitlement, user, policy) and bloats the response. + operationId: c1.api.task.v1.TaskSearchService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsInvocationSearchResponse' - description: FunctionsInvocationSearchResponse is the response for searching function invocations. + $ref: '#/components/schemas/c1.api.task.v1.TaskSearchResponse' + description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. summary: Search tags: - - Function Invocation - x-speakeasy-group: FunctionsInvocationSearch + - Task + x-speakeasy-group: TaskSearch x-speakeasy-name-override: Search - x-stability-level: draft - /api/v1/functions/{function_id}/invoke: + /api/v1/search/user-ownership: post: - description: Invoke executes a function at a specific commit with the provided input data. - operationId: c1.api.functions.v1.FunctionsService.Invoke - parameters: - - in: path - name: function_id - required: true - schema: - description: The ID of the function to invoke. - readOnly: false - type: string + description: Search all ownership assignments for a given user across apps, resources, and entitlements. + operationId: c1.api.app.v1.AppSearch.SearchUserOwnership requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeRequestInput' + $ref: '#/components/schemas/c1.api.app.v1.SearchUserOwnershipRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceInvokeResponse' - description: Successful response - summary: Invoke + $ref: '#/components/schemas/c1.api.app.v1.SearchUserOwnershipResponse' + description: The SearchUserOwnershipResponse message contains a paginated list of ownership entries. + summary: Search User Ownership tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: Invoke - x-stability-level: draft - /api/v1/functions/{function_id}/tags: - get: - description: ListTags lists all tags for a function - operationId: c1.api.functions.v1.FunctionsService.ListTags - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string + - App + x-speakeasy-group: AppSearch + x-speakeasy-name-override: SearchUserOwnership + /api/v1/search/users: + post: + description: Search users based on filters specified in the request body. + operationId: c1.api.user.v1.UserSearch.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.user.v1.SearchUsersRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceListTagsResponse' + $ref: '#/components/schemas/c1.api.user.v1.SearchUsersResponse' description: Successful response - summary: List Tags + summary: Search tags: - - Function Tag + - User x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Function_Tag#read - terraform-resource: Function_Tag#read - x-speakeasy-group: Functions - x-speakeasy-name-override: ListTags - x-stability-level: draft + terraform-datasource: + - User#read + - Users#read + terraform-resource: null + x-speakeasy-group: UserSearch + x-speakeasy-name-override: Search + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/webhooks: post: - description: CreateTag creates a named reference to a specific commit - operationId: c1.api.functions.v1.FunctionsService.CreateTag - parameters: - - in: path - name: function_id - required: true - schema: - description: The functionId field. - readOnly: false - type: string + description: Search for webhook subscriptions by query string or specific webhook references. + operationId: c1.api.webhooks.v1.WebhooksSearch.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagRequestInput' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceCreateTagResponse' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksSearchResponse' description: Successful response - summary: Create Tag + summary: Search tags: - - Function Tag + - Webhook x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Function_Tag#create - x-speakeasy-group: Functions - x-speakeasy-name-override: CreateTag - x-stability-level: draft - /api/v1/functions/{function_id}/test: + terraform-datasource: + - Webhook#read + - Webhooks#read + terraform-resource: null + x-speakeasy-group: WebhooksSearch + x-speakeasy-name-override: Search + x-speakeasy-pagination: + inputs: + - in: requestBody + name: pageToken + type: cursor + outputs: + nextCursor: $.nextPageToken + type: cursor + /api/v1/search/workload_federation_trusts: post: - description: Test runs a function's test suite in a sandboxed environment and returns the results. - operationId: c1.api.functions.v1.FunctionsService.Test - parameters: - - in: path - name: function_id - required: true - schema: - description: The function ID to test. - readOnly: false - type: string + description: |- + SearchTrusts searches trusts across all service principals with optional filters. + Used by the admin providers page to list trusts referencing a provider. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.SearchTrusts requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestRequestInput' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceTestResponse' - description: FunctionsServiceTestResponse contains test execution results. - summary: Test + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse' + description: Successful response + summary: Search Trusts tags: - - Function - x-speakeasy-group: Functions - x-speakeasy-name-override: Test - x-stability-level: draft - /api/v1/functions/{id}: - delete: - description: Delete removes a function - operationId: c1.api.functions.v1.FunctionsService.DeleteFunction - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - readOnly: false - type: string + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: SearchTrusts + /api/v1/search/xaa/access_profile_scope_bindings: + post: + description: |- + Search scope bindings, filtered by access profile or by scope, or fetch a + specific set by ref. The by-scope direction answers "which profiles + contain this scope" for impact analysis. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceDeleteFunctionResponse' - description: Successful response - summary: Delete Function - tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#delete - x-speakeasy-group: Functions - x-speakeasy-name-override: DeleteFunction - x-stability-level: draft - get: - description: Get retrieves a specific function by ID - operationId: c1.api.functions.v1.FunctionsService.GetFunction - parameters: - - in: path - name: id - required: true - schema: - description: The id field. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceGetFunctionResponse' - description: Successful response - summary: Get Function + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchResponse' + description: XAAAccessProfileScopeBindingServiceSearchResponse returns matching bindings. + summary: Search tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Function#read - x-speakeasy-group: Functions - x-speakeasy-name-override: GetFunction - x-stability-level: draft - /api/v1/functions/update: + - Cross-App Access + x-speakeasy-group: XAAAccessProfileScopeBinding + x-speakeasy-name-override: Search + /api/v1/search/xaa/access_profiles: post: - description: Update updates an existing function's metadata - operationId: c1.api.functions.v1.FunctionsService.UpdateFunction + description: |- + Search access profiles across the tenant, filtered by application, + resource server, or text query, or fetch a specific set by ref. + operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse' - description: Successful response - summary: Update Function + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchResponse' + description: XAAAccessProfileServiceSearchResponse returns matching access profiles. + summary: Search tags: - - Function - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Function#update - x-speakeasy-group: Functions - x-speakeasy-name-override: UpdateFunction - x-stability-level: draft - /api/v1/grants/feed: + - Cross-App Access + x-speakeasy-group: XAAAccessProfile + x-speakeasy-name-override: Search + /api/v1/search/xaa/client_audience_mappings: post: - description: Search a chronological feed of grant and revoke events, filtered by app user, entitlement, or time range. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.SearchGrantFeed + description: |- + Search client audience mappings across the tenant, filtered by resource + server, disabled state, or text query, or fetch a specific set by ref. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchGrantFeedRequest' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchGrantFeedResponse' - description: The SearchGrantFeedResponse message contains a list of grant event results and a nextPageToken if applicable. - summary: Search Grant Feed + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchResponse' + description: XAAClientAudienceMappingServiceSearchResponse returns matching mappings. + summary: Search tags: - - App Entitlement User Binding Feed - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: SearchGrantFeed - /api/v1/hooks: - get: - description: Invokes the c1.api.hooks.v1.HooksService.List method. - operationId: c1.api.hooks.v1.HooksService.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: Search + /api/v1/search/xaa/resource_servers: + post: + description: |- + Search resource servers across the tenant, filtered by application, + audience substring, signing algorithm, or disabled state, or fetch a + specific set by ref. Returns one page at a time. + operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Search + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceListResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceSearchResponse' + description: XAAResourceServerServiceSearchResponse returns matching resource servers. + summary: Search tags: - - Hook - x-speakeasy-group: Hooks - x-speakeasy-name-override: List + - Cross-App Access + x-speakeasy-group: XAAResourceServer + x-speakeasy-name-override: Search + /api/v1/search/xaa/scopes: post: - description: Invokes the c1.api.hooks.v1.HooksService.Create method. - operationId: c1.api.hooks.v1.HooksService.Create + description: |- + Search scopes across the tenant, filtered by resource server, state, + classification, source, or text query, or fetch a specific set by ref. + Filter on PENDING_REVIEW to find scopes awaiting approval. + operationId: c1.api.cross_app_access.v1.XAAScopeService.Search requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceCreateRequest' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceSearchRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceCreateResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceSearchResponse' + description: XAAScopeServiceSearchResponse returns matching scopes. + summary: Search tags: - - Hook - x-speakeasy-group: Hooks - x-speakeasy-name-override: Create - /api/v1/hooks/{id}: + - Cross-App Access + x-speakeasy-group: XAAScope + x-speakeasy-name-override: Search + /api/v1/secrets-admin/{vault_id}: delete: - description: Invokes the c1.api.hooks.v1.HooksService.Delete method. - operationId: c1.api.hooks.v1.HooksService.Delete + description: Revoke allows admin to revoke any secret (not just their own). + operationId: c1.api.secrets.v1.PaperSecretAdminService.Revoke parameters: - in: path - name: id + name: vault_id required: true schema: - description: The id field. - readOnly: false + description: The vaultId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse' description: Successful response - summary: Delete + summary: Revoke tags: - - Hook - x-speakeasy-group: Hooks - x-speakeasy-name-override: Delete + - Secrets Admin + x-speakeasy-group: PaperSecretAdmin + x-speakeasy-name-override: Revoke + x-stability-level: beta get: - description: Invokes the c1.api.hooks.v1.HooksService.Get method. - operationId: c1.api.hooks.v1.HooksService.Get + description: Get retrieves any secret's metadata by vault ID (admin override). + operationId: c1.api.secrets.v1.PaperSecretAdminService.Get parameters: - in: path - name: id + name: vault_id required: true schema: - description: The id field. - readOnly: false + description: The vaultId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceGetResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceGetResponse' description: Successful response summary: Get tags: - - Hook - x-speakeasy-group: Hooks + - Secrets Admin + x-speakeasy-group: PaperSecretAdmin x-speakeasy-name-override: Get - post: - description: Invokes the c1.api.hooks.v1.HooksService.Update method. - operationId: c1.api.hooks.v1.HooksService.Update + x-stability-level: beta + /api/v1/secrets/{vault_id}: + delete: + description: Revoke soft-deletes a secret (sets Vault.deleted_at, deletes content). + operationId: c1.api.secrets.v1.PaperSecretService.Revoke parameters: - in: path - name: id + name: vault_id required: true schema: - description: The id field. - readOnly: false + description: The vaultId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceRevokeResponse' description: Successful response - summary: Update + summary: Revoke tags: - - Hook - x-speakeasy-group: Hooks - x-speakeasy-name-override: Update - /api/v1/iam/personal_clients: + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: Revoke + x-stability-level: beta get: - description: List returns all personal client credentials owned by the calling user. - operationId: c1.api.iam.v1.PersonalClientService.List + description: |- + Get retrieves a secret's metadata by vault ID. + Creator can always get their own secrets. Admins can get any secret. + operationId: c1.api.secrets.v1.PaperSecretService.Get + parameters: + - in: path + name: vault_id + required: true + schema: + description: The vaultId field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceListResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetResponse' description: Successful response - summary: 'NOTE: Only shows personal clients for the current user.' + summary: Get tags: - - Personal Client - x-speakeasy-group: PersonalClient - x-speakeasy-name-override: List + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: Get + x-stability-level: beta + /api/v1/secrets/{vault_id}/content: post: - description: Create creates a new PersonalClient object for the current User. - operationId: c1.api.iam.v1.PersonalClientService.Create + description: |- + SetTextContent sets the encrypted content for a text secret. + Client encrypts content using age_recipient from CreateResponse. + operationId: c1.api.secrets.v1.PaperSecretService.SetTextContent + parameters: + - in: path + name: vault_id + required: true + schema: + description: The vaultId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceCreateRequest' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceCreateResponse' - description: The PersonalClientServiceCreateResponse message contains the created personal client and client secret. - summary: Create + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse' + description: Successful response + summary: Set Text Content tags: - - Personal Client - x-speakeasy-group: PersonalClient - x-speakeasy-name-override: Create - /api/v1/iam/personal_clients/{id}: - delete: - description: Delete a personal client credential, revoking it and preventing further API access. - operationId: c1.api.iam.v1.PersonalClientService.Delete + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: SetTextContent + x-stability-level: beta + /api/v1/secrets/{vault_id}/view: + post: + description: |- + GetContent retrieves the encrypted secret content for an authorized recipient. + Caller must be in the secret's allowed_user_ids list (for INTERNAL secrets). + Returns content re-encrypted to caller's ephemeral public key. + operationId: c1.api.secrets.v1.PaperSecretService.GetContent parameters: - in: path - name: id + name: vault_id required: true schema: - description: The human-readable name of the personal client credential to delete (e.g., blue-whale-12345). - readOnly: false + description: The vaultId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetContentResponse' description: Successful response - summary: Delete + summary: Get Content tags: - - Personal Client - x-speakeasy-group: PersonalClient - x-speakeasy-name-override: Delete + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: GetContent + x-stability-level: draft + /api/v1/secrets/code/{share_code}: get: - description: Get retrieves a single personal client credential by its ID. - operationId: c1.api.iam.v1.PersonalClientService.Get + description: |- + GetByShareCode retrieves a secret by its human-friendly share code. + Share codes are in XXXX-XXXX-XXXX format and are used in share URLs. + operationId: c1.api.secrets.v1.PaperSecretService.GetByShareCode parameters: - in: path - name: id + name: share_code required: true schema: - description: The human-readable name of the personal client credential to retrieve (e.g., blue-whale-12345). - readOnly: false + description: 'Human-friendly share code (format: XXXX-XXXX-XXXX, case-insensitive)' type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceGetResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetResponse' description: Successful response - summary: Get + summary: Get By Share Code tags: - - Personal Client - x-speakeasy-group: PersonalClient - x-speakeasy-name-override: Get + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: GetByShareCode + x-stability-level: beta + /api/v1/secrets/external: post: - description: Update modifies an existing personal client credential. Use the update mask to specify which fields to change. - operationId: c1.api.iam.v1.PersonalClientService.Update - parameters: - - in: path - name: id - required: true - schema: - description: The unique ID of the personal client credential. - readOnly: true - type: string + description: CreateExternal creates a secret using the requested Age suite. + operationId: c1.api.secrets.v1.PaperSecretService.CreateExternal requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateResponse' description: Successful response - summary: Update - tags: - - Personal Client - x-speakeasy-group: PersonalClient - x-speakeasy-name-override: Update - /api/v1/iam/roles: - get: - description: List all roles for the current user. - operationId: c1.api.iam.v1.Roles.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.iam.v1.ListRolesResponse' - description: The ListRolesResponse message contains a list of results and a nextPageToken if applicable. - summary: List - tags: - - Role - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - Role#read - - Roles#read - terraform-resource: null - x-speakeasy-group: Roles - x-speakeasy-name-override: List - /api/v1/iam/roles/{role_id}: - get: - description: Get a role by id. - operationId: c1.api.iam.v1.Roles.Get - parameters: - - in: path - name: role_id - required: true - schema: - description: The roleId field. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.iam.v1.GetRolesResponse' - description: The GetRolesResponse message contains the retrieved role. - summary: Get + summary: Create External tags: - - Role - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Role#read - x-speakeasy-group: Roles - x-speakeasy-name-override: Get + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: CreateExternal + x-stability-level: beta + /api/v1/secrets/internal: post: - description: Update a role by passing a Role object. - operationId: c1.api.iam.v1.Roles.Update - parameters: - - in: path - name: role_id - required: true - schema: - description: The id of the role. - readOnly: true - type: string + description: CreateInternal creates a secret using the requested Age suite. + operationId: c1.api.secrets.v1.PaperSecretService.CreateInternal requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.UpdateRoleRequestInput' + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.UpdateRolesResponse' - description: UpdateRolesResponse is the response message containing the updated role. - summary: Update - tags: - - Role - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Role#update - x-speakeasy-group: Roles - x-speakeasy-name-override: Update - /api/v1/local-directory-configs: + $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateResponse' + description: Successful response + summary: Create Internal + tags: + - Secrets + x-speakeasy-group: PaperSecret + x-speakeasy-name-override: CreateInternal + x-stability-level: beta + /api/v1/service_principals: get: - description: List local directory configs for the tenant. - operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.List - parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + description: List lists service principals for the tenant. + operationId: c1.api.service_principal.v1.ServicePrincipalService.List responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceListResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListResponse' description: Successful response summary: List tags: - - Local Directory - x-speakeasy-group: LocalDirectoryConfig + - Service Principal + x-speakeasy-group: Principal x-speakeasy-name-override: List post: - description: Create a new local directory config backed by an existing App. - operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Create + description: Create creates a new service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateRequest' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceCreateResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse' description: Successful response summary: Create tags: - - Local Directory - x-speakeasy-group: LocalDirectoryConfig + - Service Principal + x-speakeasy-group: Principal x-speakeasy-name-override: Create - /api/v1/local-directory-configs/{app_id}: + /api/v1/service_principals/{id}: delete: - description: Delete a local directory config. Does not delete the underlying App. - operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Delete + description: Delete deletes a service principal and all its credentials. + operationId: c1.api.service_principal.v1.ServicePrincipalService.Delete parameters: - in: path - name: app_id + name: id required: true schema: - description: The appId field. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse' description: Successful response summary: Delete tags: - - Local Directory - x-speakeasy-group: LocalDirectoryConfig + - Service Principal + x-speakeasy-group: Principal x-speakeasy-name-override: Delete get: - description: Get a local directory config by app_id. - operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Get + description: Get returns a service principal by ID. + operationId: c1.api.service_principal.v1.ServicePrincipalService.Get parameters: - in: path - name: app_id + name: id required: true schema: - description: The appId field. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceGetResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceGetResponse' description: Successful response summary: Get tags: - - Local Directory - x-speakeasy-group: LocalDirectoryConfig + - Service Principal + x-speakeasy-group: Principal x-speakeasy-name-override: Get - post: - description: Update a local directory config. - operationId: c1.api.local_directory.v1.LocalDirectoryConfigService.Update + patch: + description: Update updates a service principal's display name. + operationId: c1.api.service_principal.v1.ServicePrincipalService.Update parameters: - in: path - name: app_id + name: id required: true schema: - description: app_id is the identifier for this config and its linked App. Read-only after creation. + description: The unique user ID of the service principal. readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalDirectoryConfigServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse' description: Successful response summary: Update tags: - - Local Directory - x-speakeasy-group: LocalDirectoryConfig + - Service Principal + x-speakeasy-group: Principal x-speakeasy-name-override: Update - /api/v1/local-directory-configs/{directory_app_id}/invitations: + /api/v1/service_principals/{service_principal_id}/credentials: + get: + description: ListCredentials lists client credentials for a service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.ListCredentials + parameters: + - in: path + name: service_principal_id + required: true + schema: + description: The service principal ID to list credentials for. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse' + description: Successful response + summary: List Credentials + tags: + - Service Principal + x-speakeasy-group: Principal + x-speakeasy-name-override: ListCredentials post: - description: Create (send) a new invitation to a user. - operationId: c1.api.local_directory.v1.LocalUserInvitationService.Create + description: CreateCredential creates a new client credential for a service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.CreateCredential parameters: - in: path - name: directory_app_id + name: service_principal_id required: true schema: - description: FK to the LocalDirectoryConfig (app_id) this invitation belongs to. - readOnly: false + description: The service principal ID to create the credential for. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceCreateRequestInput' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceCreateResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse' description: Successful response - summary: Create + summary: Create Credential tags: - - Local Directory - x-speakeasy-group: LocalUserInvitation - x-speakeasy-name-override: Create - /api/v1/local-directory-configs/{directory_app_id}/invitations/{id}: + - Service Principal + x-speakeasy-group: Principal + x-speakeasy-name-override: CreateCredential + /api/v1/service_principals/{service_principal_id}/credentials/{id}: + delete: + description: RevokeCredential revokes (deletes) a client credential for a service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.RevokeCredential + parameters: + - in: path + name: service_principal_id + required: true + schema: + description: The service principal ID. + type: string + - in: path + name: id + required: true + schema: + description: The credential ID to revoke. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse' + description: Successful response + summary: Revoke Credential + tags: + - Service Principal + x-speakeasy-group: Principal + x-speakeasy-name-override: RevokeCredential get: - description: Get a specific invitation by id. - operationId: c1.api.local_directory.v1.LocalUserInvitationService.Get + description: GetCredential returns a single client credential for a service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.GetCredential parameters: - in: path - name: directory_app_id + name: service_principal_id required: true schema: - description: The directoryAppId field. - readOnly: false + description: The service principal ID. type: string - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The credential ID to get. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceGetResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse' description: Successful response - summary: Get + summary: Get Credential tags: - - Local Directory - x-speakeasy-group: LocalUserInvitation - x-speakeasy-name-override: Get - /api/v1/local-directory-configs/{directory_app_id}/invitations/{id}/revoke: - post: - description: Revoke a pending invitation. - operationId: c1.api.local_directory.v1.LocalUserInvitationService.Revoke + - Service Principal + x-speakeasy-group: Principal + x-speakeasy-name-override: GetCredential + patch: + description: UpdateCredential updates a client credential for a service principal. + operationId: c1.api.service_principal.v1.ServicePrincipalService.UpdateCredential parameters: - in: path - name: directory_app_id + name: service_principal_id required: true schema: - description: The directoryAppId field. - readOnly: false + description: The service principal ID. type: string - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The unique ID of the credential (cutename format). + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceRevokeRequestInput' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceRevokeResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse' description: Successful response - summary: Revoke + summary: Update Credential tags: - - Local Directory - x-speakeasy-group: LocalUserInvitation - x-speakeasy-name-override: Revoke - /api/v1/policies: + - Service Principal + x-speakeasy-group: Principal + x-speakeasy-name-override: UpdateCredential + /api/v1/service_principals/{service_principal_id}/trusts: get: - description: List policies. - operationId: c1.api.policy.v1.Policies.List + description: ListTrusts lists trusts for a service principal. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.ListTrusts parameters: - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + - in: path + name: service_principal_id + required: true schema: - description: The pageToken field. - readOnly: false + description: The service principal ID to list trusts for (from URL path). type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.ListPolicyResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse' description: Successful response - summary: List + summary: List Trusts tags: - - Policy - x-speakeasy-group: Policies - x-speakeasy-name-override: List + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: ListTrusts post: - description: Create a policy. - operationId: c1.api.policy.v1.Policies.Create + description: |- + CreateTrust creates a trust policy for a service principal. + Validates the CEL condition_expression at creation time. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.CreateTrust + parameters: + - in: path + name: service_principal_id + required: true + schema: + description: The service principal ID to create the trust for (from URL path). + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.CreatePolicyRequest' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.CreatePolicyResponse' - description: The CreatePolicyResponse message contains the created policy object. - summary: Create + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse' + description: Successful response + summary: Create Trust tags: - - Policy - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Policy#create - x-speakeasy-group: Policies - x-speakeasy-name-override: Create - /api/v1/policies/{id}: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: CreateTrust + /api/v1/service_principals/{service_principal_id}/trusts/{client_id}: delete: - description: Delete a policy by ID. - operationId: c1.api.policy.v1.Policies.Delete + description: DeleteTrust deletes a trust for a service principal. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.DeleteTrust parameters: - in: path - name: id + name: service_principal_id required: true schema: - description: The Id of the policy to delete. - readOnly: false + description: The service principal ID (from URL path). + type: string + - in: path + name: client_id + required: true + schema: + description: |- + The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the + full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). + The server normalizes to the cutename portion before lookup. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.DeletePolicyRequestInput' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.DeletePolicyResponse' - description: Empty response with a status code indicating success. - summary: Delete + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse' + description: Successful response + summary: Delete Trust tags: - - Policy - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Policy#delete - x-speakeasy-group: Policies - x-speakeasy-name-override: Delete + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: DeleteTrust get: - description: Get a policy by ID. - operationId: c1.api.policy.v1.Policies.Get + description: GetTrust returns a trust by ID for a service principal. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.GetTrust parameters: - in: path - name: id + name: service_principal_id required: true schema: - description: The id field. - readOnly: false + description: The service principal ID (from URL path). + type: string + - in: path + name: client_id + required: true + schema: + description: |- + The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the + full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). + The server normalizes to the cutename portion before lookup. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.GetPolicyResponse' - description: The GetPolicyResponse message contains the policy object. - summary: Get + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse' + description: Successful response + summary: Get Trust tags: - - Policy - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: Policy#read - x-speakeasy-group: Policies - x-speakeasy-name-override: Get - post: - description: Update a policy by providing a policy object and an update mask. - operationId: c1.api.policy.v1.Policies.Update + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: GetTrust + patch: + description: UpdateTrust updates a trust's mutable fields. The provider_id is immutable. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.UpdateTrust parameters: - in: path - name: id + name: service_principal_id required: true schema: - description: The ID of the Policy. + description: The service principal ID (from URL path). + type: string + - in: path + name: client_id + required: true + schema: + description: |- + The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). + Used as the client_id parameter in RFC 8693 token exchange requests. readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.UpdatePolicyRequestInput' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.UpdatePolicyResponse' - description: The UpdatePolicyResponse message contains the updated policy object. - summary: Update + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse' + description: Successful response + summary: Update Trust tags: - - Policy - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Policy#update - x-speakeasy-group: Policies - x-speakeasy-name-override: Update - /api/v1/policies/test-account-provision-policy: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: UpdateTrust + /api/v1/service_principals/{service_principal_id}/trusts/{client_id}/test: post: - description: Test an account provision policy by evaluating a CEL expression and returning the computed result. - operationId: c1.api.policy.v1.AccountProvisionPolicyTest.Test + description: |- + TestToken validates a JWT against a specific trust's configuration without + issuing an access token. Returns per-step validation results for debugging. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.TestToken + parameters: + - in: path + name: service_principal_id + required: true + schema: + description: The service principal ID (from URL path). + type: string + - in: path + name: client_id + required: true + schema: + description: |- + The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the + full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). + The server normalizes to the cutename portion before lookup. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.TestAccountProvisionPolicyRequest' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.TestAccountProvisionPolicyResponse' - description: TestAccountProvisionPolicyResponse is the response for testing an account provision policy. - summary: Test + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse' + description: Successful response + summary: Test Token tags: - - Policy - x-speakeasy-group: AccountProvisionPolicyTest - x-speakeasy-name-override: Test - /api/v1/policies/validate/cel: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: TestToken + /api/v1/service_principals/bindings: post: - description: Validate policies - operationId: c1.api.policy.v1.PolicyValidate.ValidateCEL + description: |- + AddBinding links a tenant-scoped subject (a function today; future kinds + tomorrow) to a service principal. Outbound c1-api calls made on the + subject's behalf can then be minted as user: via + an RFC 8693 token-exchange (act-as) flow. Many-aware: a subject may + hold multiple bindings at the storage layer. Idempotent on + (subject, service_principal_id) — adds the row if missing, + resurrects it if soft-deleted, no-op if already active. Consumers + that need 0-or-1 cardinality (Functions today) enforce it + client-side via ListBindings + DeleteBinding. Requires the + SERVICE_PRINCIPALS feature flag. + operationId: c1.api.service_principal.v1.ServicePrincipalService.AddBinding requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.EditorValidateRequest' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.EditorValidateResponse' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse' description: Successful response - summary: Validate Cel - tags: - - Policy - x-speakeasy-group: PolicyValidate - x-speakeasy-name-override: ValidateCEL - /api/v1/request_schema_entitlement_binding: - delete: - description: Remove the link between a request schema and a single app entitlement. - operationId: c1.api.request_schema.v1.RequestSchemaService.RemoveEntitlementBinding - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceRemoveEntitlementBindingResponse' - description: The response message for removing a single entitlement binding. - summary: Remove Entitlement Binding + summary: Add Binding tags: - - Request Schema Entitlement Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Request Schema Entitlement Binding#delete - x-speakeasy-group: RequestSchema - x-speakeasy-name-override: RemoveEntitlementBinding + - Service Principal Binding + x-speakeasy-group: Principal + x-speakeasy-name-override: AddBinding + x-stability-level: draft + /api/v1/service_principals/bindings/delete: post: - description: Link a request schema to a single app entitlement so the form is shown when requesting that entitlement. - operationId: c1.api.request_schema.v1.RequestSchemaService.CreateEntitlementBinding + description: |- + DeleteBinding removes a single (subject, service_principal_id) binding + row. At-most-one delete — does not touch other bindings the subject + may hold against different service principals. Idempotent — succeeds + even if no matching row exists. + operationId: c1.api.service_principal.v1.ServicePrincipalService.DeleteBinding requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingRequest' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateEntitlementBindingResponse' - description: The response message for creating a single entitlement binding. - summary: Create Entitlement Binding + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse' + description: Successful response + summary: Delete Binding tags: - - Request Schema Entitlement Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: Request Schema Entitlement Binding#create - x-speakeasy-group: RequestSchema - x-speakeasy-name-override: CreateEntitlementBinding - put: - description: Look up which request schema is bound to a given app entitlement. - operationId: c1.api.request_schema.v1.RequestSchemaService.FindBindingForAppEntitlement + - Service Principal Binding + x-speakeasy-group: Principal + x-speakeasy-name-override: DeleteBinding + x-stability-level: draft + /api/v1/service_principals/bindings/list: + post: + description: |- + ListBindings returns every active binding held by a subject. Empty + list when the subject is unbound. The response is unordered. + operationId: c1.api.service_principal.v1.ServicePrincipalService.ListBindings requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementRequest' + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceFindBindingForAppEntitlementResponse' - description: The response message containing the binding for the specified app entitlement. - summary: Find Binding For App Entitlement + $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse' + description: Successful response + summary: List Bindings tags: - - Request Schema Entitlement Binding - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: Request Schema Entitlement Binding#read - terraform-resource: Request Schema Entitlement Binding#read - x-speakeasy-group: RequestSchema - x-speakeasy-name-override: FindBindingForAppEntitlement - /api/v1/request_schemas: + - Service Principal Binding + x-speakeasy-group: Principal + x-speakeasy-name-override: ListBindings + x-stability-level: draft + /api/v1/session-policies: + get: + description: List all session policies in your tenant, one page at a time. + operationId: c1.api.session_policy.v1.SessionPolicyService.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceListResponse' + description: Successful response + summary: List + tags: + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: List post: - description: Create a new request schema that defines a form template for access requests. - operationId: c1.api.request_schema.v1.RequestSchemaService.Create + description: Create a session policy. + operationId: c1.api.session_policy.v1.SessionPolicyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateRequest' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceCreateResponse' - description: The response message for creating a request schema. + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceCreateResponse' + description: Successful response summary: Create tags: - - Request Schema + - Session Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Request_Schema#create - x-speakeasy-group: RequestSchema + terraform-resource: SessionPolicy#create + x-speakeasy-group: SessionPolicy x-speakeasy-name-override: Create - /api/v1/request_schemas/{request_schema_id}: + /api/v1/session-policies/{id}: delete: - description: Delete a request schema by ID. Associated entitlement bindings are also deleted. - operationId: c1.api.request_schema.v1.RequestSchemaService.Delete + description: Delete a session policy by ID. + operationId: c1.api.session_policy.v1.SessionPolicyService.Delete parameters: - in: path - name: request_schema_id + name: id required: true schema: - description: The unique identifier of the request schema to delete. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceDeleteResponse' - description: The response message for deleting a request schema. + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceDeleteResponse' + description: Successful response summary: Delete tags: - - Request Schema + - Session Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Request_Schema#delete - x-speakeasy-group: RequestSchema + terraform-resource: SessionPolicy#delete + x-speakeasy-group: SessionPolicy x-speakeasy-name-override: Delete get: - description: Retrieve a single request schema by ID. - operationId: c1.api.request_schema.v1.RequestSchemaService.Get + description: Get a session policy by ID. + operationId: c1.api.session_policy.v1.SessionPolicyService.Get parameters: - in: path - name: request_schema_id + name: id required: true schema: - description: The unique identifier of the request schema to retrieve. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceGetResponse' - description: The response message for retrieving a request schema. + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceGetResponse' + description: Successful response summary: Get tags: - - Request Schema + - Session Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Request_Schema#read - terraform-resource: Request_Schema#read - x-speakeasy-group: RequestSchema + terraform-datasource: null + terraform-resource: SessionPolicy#read + x-speakeasy-group: SessionPolicy x-speakeasy-name-override: Get post: - description: Update an existing request schema's form definition or settings. - operationId: c1.api.request_schema.v1.RequestSchemaService.Update + description: |- + Update a session policy. Supply the policy object and an update mask + listing the fields to change; omitted fields are left as-is. + operationId: c1.api.session_policy.v1.SessionPolicyService.Update parameters: - in: path - name: request_schema_id + name: id required: true schema: - description: The unique identifier of this request schema. - readOnly: false + description: Unique identifier for the policy. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.request_schema.v1.RequestSchemaServiceUpdateResponse' - description: The response message for updating a request schema. + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUpdateResponse' + description: Successful response summary: Update tags: - - Request Schema + - Session Policy x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Request_Schema#update - x-speakeasy-group: RequestSchema + terraform-resource: SessionPolicy#update + x-speakeasy-group: SessionPolicy x-speakeasy-name-override: Update - /api/v1/role-mining/access-profiles: + /api/v1/session-policies/{id}/assignments: + get: + description: |- + List the principals assigned to a session policy, including both direct + assignments and those conferred through a group. + operationId: c1.api.session_policy.v1.SessionPolicyService.ListAssignments + parameters: + - in: path + name: id + required: true + schema: + description: The session policy whose assignments to list. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceListAssignmentsResponse' + description: Successful response + summary: List Assignments + tags: + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: ListAssignments + /api/v1/session-policies/{id}/assignments/groups: post: description: |- - CreateAccessProfileFromCohort creates an access profile from a cohort definition, - adds the specified entitlements, and sets up dynamic membership automation using - a CEL expression derived from the profile filters. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.CreateAccessProfileFromCohort + Assign a group to a session policy. Every member of the group becomes + assigned to the policy; because group membership is expanded + asynchronously, the per-user effect is eventually consistent (typically + within a few minutes). + operationId: c1.api.session_policy.v1.SessionPolicyService.AssignGroup + parameters: + - in: path + name: id + required: true + schema: + description: The session policy to assign to. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CreateAccessProfileFromCohortRequest' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceAssignGroupRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.CreateAccessProfileFromCohortResponse' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceAssignGroupResponse' description: Successful response - summary: Create Access Profile From Cohort + summary: Assign Group tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: CreateAccessProfileFromCohort - /api/v1/role-mining/config: - get: - description: Retrieve the current role mining configuration, including cohort hints and threshold settings. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetRoleMiningConfig + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: AssignGroup + /api/v1/session-policies/{id}/assignments/groups/{group_app_entitlement_id}: + delete: + description: |- + Unassign a group from a session policy. The per-user effect is eventually + consistent, mirroring AssignGroup. + operationId: c1.api.session_policy.v1.SessionPolicyService.UnassignGroup + parameters: + - in: path + name: id + required: true + schema: + description: The session policy to unassign from. + type: string + - in: path + name: group_app_entitlement_id + required: true + schema: + description: The group's app-entitlement ID. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetRoleMiningConfigResponse' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUnassignGroupResponse' description: Successful response - summary: Get Role Mining Config + summary: Unassign Group tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: GetRoleMiningConfig + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: UnassignGroup + /api/v1/session-policies/{id}/assignments/users: post: - description: Update the role mining configuration, such as cohort hints, max suggestions, and minimum cohort size. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.UpdateRoleMiningConfig + description: Assign a user to a session policy. The assignment takes effect immediately. + operationId: c1.api.session_policy.v1.SessionPolicyService.AssignUser + parameters: + - in: path + name: id + required: true + schema: + description: The session policy to assign to. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateRoleMiningConfigRequest' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceAssignUserRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateRoleMiningConfigResponse' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceAssignUserResponse' description: Successful response - summary: Update Role Mining Config + summary: Assign User tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: UpdateRoleMiningConfig - /api/v1/role-mining/custom-analysis/{id}: - get: - description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult method. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: AssignUser + /api/v1/session-policies/{id}/assignments/users/{user_id}: + delete: + description: Unassign a user from a session policy. + operationId: c1.api.session_policy.v1.SessionPolicyService.UnassignUser parameters: - in: path name: id required: true schema: - description: The id field. - readOnly: false + description: The session policy to unassign from. type: string + - in: path + name: user_id + required: true + schema: + description: The user to unassign. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUnassignUserRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetCustomAnalysisResultResponse' + $ref: '#/components/schemas/c1.api.session_policy.v1.SessionPolicyServiceUnassignUserResponse' description: Successful response - summary: Get Custom Analysis Result + summary: Unassign User tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: GetCustomAnalysisResult - /api/v1/role-mining/custom-analysis/trigger: + - Session Policy + x-speakeasy-group: SessionPolicy + x-speakeasy-name-override: UnassignUser + /api/v1/settings/ai-governance: + get: + description: |- + Get the tenant's AI governance settings — the controls behind the admin + /admin/settings/ai-governance page. Returns the full AIGovernanceSettings: + allowed MCP client types, default client lifecycle, require_tool_approval, + default tool classification, audit verbosity, auto-discovery toggle + + interval, prefer_code_mode_over_direct_tools, and surface_requestable_tools. + operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.Get + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.ai_governance.v1.GetAIGovernanceSettingsResponse' + description: GetAIGovernanceSettingsResponse contains the tenant's AI governance settings. + summary: Get + tags: + - AI Governance Settings + x-speakeasy-group: AIGovernanceSettings + x-speakeasy-name-override: Get post: - description: Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis method. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis + description: |- + Update the tenant's AI governance settings. Requires update_mask listing + which fields to apply (e.g. require_tool_approval, + default_tool_classification, audit_verbosity, auto_discovery_enabled, + discovery_interval, prefer_code_mode_over_direct_tools, + surface_requestable_tools, allowed_client_types, default_client_lifecycle). + Only masked fields change. Returns the updated settings. + operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerCustomAnalysisRequest' + $ref: '#/components/schemas/c1.api.ai_governance.v1.UpdateAIGovernanceSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerCustomAnalysisResponse' - description: Successful response - summary: Trigger Custom Analysis + $ref: '#/components/schemas/c1.api.ai_governance.v1.UpdateAIGovernanceSettingsResponse' + description: UpdateAIGovernanceSettingsResponse contains the updated AI governance settings. + summary: Update tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: TriggerCustomAnalysis - /api/v1/role-mining/runs: + - AI Governance Settings + x-speakeasy-group: AIGovernanceSettings + x-speakeasy-name-override: Update + /api/v1/settings/ai-governance/history: get: - description: List role mining analysis runs in reverse chronological order. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.ListRuns + description: |- + List the change history for AI governance settings (newest first). + Singleton: scoped to the caller's tenant. Admin-tier per object-history convention. + operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.ListHistory responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.ListRunsResponse' - description: Successful response - summary: List Runs + $ref: '#/components/schemas/c1.api.ai_governance.v1.ListAIGovernanceSettingsHistoryResponse' + description: |- + ListAIGovernanceSettingsHistoryResponse contains a page of AI governance + settings change-history entries, newest first. + summary: List History tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: ListRuns - /api/v1/role-mining/runs/latest: + - AI Governance Settings + x-speakeasy-group: AIGovernanceSettings + x-speakeasy-name-override: ListHistory + /api/v1/settings/ai-governance/tenant-defaults: get: - description: Retrieve the most recent role mining analysis run, including its status and results summary. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetLatestRun + description: |- + Get the tenant-default subset of AI governance settings. Currently returns + only require_tool_approval — the default applied to newly registered MCP + servers/tools. Use Get for the full settings object. + operationId: c1.api.ai_governance.v1.AIGovernanceSettingsService.GetTenantDefaults responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetLatestRunResponse' - description: Successful response - summary: Get Latest Run + $ref: '#/components/schemas/c1.api.ai_governance.v1.GetTenantDefaultsResponse' + description: |- + GetTenantDefaultsResponse contains the tenant-default subset of AI governance + settings applied to newly registered MCP servers and tools. + summary: Get Tenant Defaults tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: GetLatestRun - /api/v1/role-mining/suggestions: + - AI Governance Settings + x-speakeasy-group: AIGovernanceSettings + x-speakeasy-name-override: GetTenantDefaults + /api/v1/settings/aws-external-id: get: - description: List role suggestions generated by analysis runs, optionally filtered by state. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.ListSuggestions + description: Get retrieves the AWS external ID for the tenant, used in IAM role trust policies for AWS connectors. + operationId: c1.api.settings.v1.AWSExternalIDSettings.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.ListSuggestionsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.GetAWSExternalIDResponse' description: Successful response - summary: List Suggestions + summary: Get tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: ListSuggestions - /api/v1/role-mining/suggestions/{id}: + - AWS External ID Settings + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: AWS_EXTERNAL_ID#read + terraform-resource: AWS_EXTERNAL_ID#read + x-speakeasy-group: AWSExternalIDSettings + x-speakeasy-name-override: Get + /api/v1/settings/contacts: get: - description: Retrieve a single role suggestion by ID, including its cohort filters, entitlements, and confidence score. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.GetSuggestion - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the role mining suggestion to retrieve. - readOnly: false - type: string + description: Invokes the c1.api.settings.v1.ContactsService.GetContacts method. + operationId: c1.api.settings.v1.ContactsService.GetContacts responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.GetSuggestionResponse' + $ref: '#/components/schemas/c1.api.settings.v1.GetContactsResponse' description: Successful response - summary: Get Suggestion + summary: Get Contacts tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: GetSuggestion - /api/v1/role-mining/suggestions/{id}/state: + - Contacts + x-speakeasy-group: Contacts + x-speakeasy-name-override: GetContacts post: - description: Transition a role suggestion to a new state, such as accepted, rejected, or dismissed. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.UpdateSuggestionState - parameters: - - in: path - name: id - required: true - schema: - description: The ID of the role mining suggestion to update. - readOnly: false - type: string + description: Invokes the c1.api.settings.v1.ContactsService.UpdateContacts method. + operationId: c1.api.settings.v1.ContactsService.UpdateContacts requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateSuggestionStateRequestInput' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateContactsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.UpdateSuggestionStateResponse' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateContactsResponse' description: Successful response - summary: Update Suggestion State + summary: Update Contacts tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: UpdateSuggestionState - /api/v1/role-mining/suggestions/{suggestion_id}/users: - post: - description: Search for users that belong to a suggestion's cohort, with optional additional profile filters. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.SearchCohortUsers - parameters: - - in: path - name: suggestion_id - required: true - schema: - description: The ID of the suggestion whose cohort to search within. - readOnly: false - type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.SearchCohortUsersRequestInput' + - Contacts + x-speakeasy-group: Contacts + x-speakeasy-name-override: UpdateContacts + /api/v1/settings/cross-app-access: + get: + description: Get the tenant's cross-app-access settings. + operationId: c1.api.cross_app_access.v1.XAASettingsService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.SearchCohortUsersResponse' - description: Successful response - summary: Search Cohort Users + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettingsServiceGetResponse' + description: XAASettingsServiceGetResponse returns the tenant's cross-app-access settings. + summary: Get tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: SearchCohortUsers - /api/v1/role-mining/trigger: + - Cross-App Access + x-speakeasy-group: XAASettings + x-speakeasy-name-override: Get post: - description: Start a new role mining analysis job that scans existing access patterns to generate role suggestions. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerAnalysis + description: |- + Update the tenant's cross-app-access settings. Supply the settings object + and an update mask listing the fields to change; only masked fields are + applied. Editable paths: enabled, default_grant_lifetime, + allow_refresh_token_subjects, default_signing_algorithm, + enabled_signing_algorithms, xaa_id_token_lifetime. + operationId: c1.api.cross_app_access.v1.XAASettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerAnalysisRequest' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettingsServiceUpdateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.TriggerAnalysisResponse' - description: Successful response - summary: Trigger Analysis + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettingsServiceUpdateResponse' + description: XAASettingsServiceUpdateResponse returns the updated settings. + summary: Update tags: - - Role Mining - x-speakeasy-group: RoleMiningManagement - x-speakeasy-name-override: TriggerAnalysis - /api/v1/search/all_automation_executions: - post: - description: Search across all automation executions in the tenant, with filters for state, template, app, and subject user. - operationId: c1.api.automations.v1.AutomationExecutionSearchService.SearchAllAutomationExecutions - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAllAutomationExecutionsRequest' + - Cross-App Access + x-speakeasy-group: XAASettings + x-speakeasy-name-override: Update + /api/v1/settings/cross-app-access/history: + get: + description: |- + List the change history for the tenant's cross-app-access settings (newest + first). Singleton: scoped to the caller's tenant. + operationId: c1.api.cross_app_access.v1.XAASettingsService.ListHistory + parameters: + - in: query + name: page_size + schema: + description: Page size (max 200). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAllAutomationExecutionsResponse' - description: Successful response - summary: Search All Automation Executions + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAASettingsServiceListHistoryResponse' + description: |- + XAASettingsServiceListHistoryResponse returns cross-app-access settings + history entries. + summary: List History tags: - - Automations - x-speakeasy-group: AutomationExecutionSearch - x-speakeasy-name-override: SearchAllAutomationExecutions - /api/v1/search/app_resource_types: - post: - description: Search app resources based on filters specified in the request body. - operationId: c1.api.app.v1.AppResourceSearch.SearchAppResourceTypes - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourceTypesRequest' + - Cross-App Access + x-speakeasy-group: XAASettings + x-speakeasy-name-override: ListHistory + /api/v1/settings/developer-preferences/user: + get: + description: |- + Get returns the calling user's developer preferences. Returns the + zero value (all preferences off) for users who have never updated + them. + operationId: c1.api.settings.v1.UserDeveloperPreferencesService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourceTypesResponse' - description: The SearchAppResourceTypesResponse message contains a list of results and a nextPageToken if applicable. - summary: Search App Resource Types + $ref: '#/components/schemas/c1.api.settings.v1.GetUserDeveloperPreferencesResponse' + description: Successful response + summary: Get tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - App Resource Type#read - - App Resource Types#read - terraform-resource: null - x-speakeasy-group: AppResourceSearch - x-speakeasy-name-override: SearchAppResourceTypes - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/app_resources: + - User Developer Preferences + x-speakeasy-group: UserDeveloperPreferences + x-speakeasy-name-override: Get post: - description: Search app resources based on filters specified in the request body. - operationId: c1.api.app.v1.AppResourceSearch.SearchAppResources + description: |- + Update modifies the calling user's developer preferences. See the + service-level comment for cluster-merge semantics. + operationId: c1.api.settings.v1.UserDeveloperPreferencesService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserDeveloperPreferencesRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesResponse' - description: The SearchAppResourcesResponse message contains a list of results and a nextPageToken if applicable. - summary: Search App Resources + $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserDeveloperPreferencesResponse' + description: Successful response + summary: Update tags: - - App Resource - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: App Resources#read - terraform-resource: null - x-speakeasy-group: AppResourceSearch - x-speakeasy-name-override: SearchAppResources - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/app_users: - post: - description: Search app users based on filters specified in the request body. - operationId: c1.api.app.v1.AppUserService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceSearchRequest' + - User Developer Preferences + x-speakeasy-group: UserDeveloperPreferences + x-speakeasy-name-override: Update + /api/v1/settings/domains: + get: + description: List returns all verified domains configured for the tenant. + operationId: c1.api.settings.v1.OrgDomainService.List + parameters: + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: A pagination token returned from a previous List call. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppUserServiceSearchResponse' + $ref: '#/components/schemas/c1.api.settings.v1.ListOrgDomainsResponse' description: Successful response - summary: Search + summary: List tags: - - AppUsers - x-speakeasy-group: AppUser - x-speakeasy-name-override: Search - /api/v1/search/apps: - post: - description: Search apps based on filters specified in the request body. - operationId: c1.api.app.v1.AppSearch.Search + - Org Domain + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: OrgDomains#read + terraform-resource: null + x-speakeasy-group: OrgDomain + x-speakeasy-name-override: List + put: + description: Update replaces the tenant's set of verified domains with the provided list. + operationId: c1.api.settings.v1.OrgDomainService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgDomainRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchAppsResponse' - description: The SearchAppsResponse message contains a list of results and a nextPageToken if applicable. - summary: Search + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgDomainResponse' + description: Successful response + summary: Update tags: - - App - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - App#read - - Apps#read - terraform-resource: null - x-speakeasy-group: AppSearch - x-speakeasy-name-override: Search - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/apps/{app_id}/entitlements/users/{app_user_id}: + - Org Domain + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: OrgDomains#update + x-speakeasy-group: OrgDomain + x-speakeasy-name-override: Update + /api/v1/settings/email-capabilities: get: - description: Search for app entitlements associated with a specific app user, with optional resource type trait filtering. - operationId: c1.api.app.v1.AppEntitlementSearchService.SearchAppEntitlementsForAppUser - parameters: - - in: path - name: app_id - required: true - schema: - description: The ID of the app to search entitlements within. - readOnly: false - type: string - - in: path - name: app_user_id - required: true - schema: - description: The ID of the app user to search entitlements for. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: The pageToken field. - readOnly: false - type: string + description: |- + GetEmailCapabilities returns a lightweight summary of email capabilities + for the current tenant. Intended for non-admin users (automation builders, + secret sharers) to check if external email is available without exposing + provider configuration details. + operationId: c1.api.settings.v1.TenantEmailProviderService.GetEmailCapabilities responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.ListAppEntitlementsResponse' - description: The ListAppEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: Search App Entitlements For App User + $ref: '#/components/schemas/c1.api.settings.v1.GetEmailCapabilitiesResponse' + description: Successful response + summary: Get Email Capabilities tags: - - App Entitlement - x-speakeasy-group: AppEntitlementSearch - x-speakeasy-name-override: SearchAppEntitlementsForAppUser - /api/v1/search/attributes: - post: - description: Search attributes based on filters specified in the request body. - operationId: c1.api.attribute.v1.AttributeSearch.SearchAttributeValues - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.attribute.v1.SearchAttributeValuesRequest' + - Tenant Email Provider + x-speakeasy-group: TenantEmailProvider + x-speakeasy-name-override: GetEmailCapabilities + /api/v1/settings/email-provider: + get: + description: Get retrieves the current tenant email provider configuration. + operationId: c1.api.settings.v1.TenantEmailProviderService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.attribute.v1.SearchAttributeValuesResponse' - description: SearchAttributeValuesResponse is the response for searching AttributeValues. - summary: Search Attribute Values + $ref: '#/components/schemas/c1.api.settings.v1.GetTenantEmailProviderResponse' + description: Successful response + summary: Get tags: - - Attribute - x-speakeasy-group: AttributeSearch - x-speakeasy-name-override: SearchAttributeValues - /api/v1/search/automation_executions: + - Tenant Email Provider + x-speakeasy-group: TenantEmailProvider + x-speakeasy-name-override: Get post: - description: Search for automation executions with optional filters for automation_template_id, state, and query. - operationId: c1.api.automations.v1.AutomationExecutionSearchService.SearchAutomationExecutions + description: Update creates or updates the tenant email provider configuration. + operationId: c1.api.settings.v1.TenantEmailProviderService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationExecutionsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateTenantEmailProviderRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationExecutionsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateTenantEmailProviderResponse' description: Successful response - summary: Search Automation Executions + summary: Update tags: - - Automations - x-speakeasy-group: AutomationExecutionSearch - x-speakeasy-name-override: SearchAutomationExecutions - /api/v1/search/automation_versions: + - Tenant Email Provider + x-speakeasy-group: TenantEmailProvider + x-speakeasy-name-override: Update + /api/v1/settings/email-provider/audit-events: post: - description: Search for versioned snapshots of an automation template's steps and triggers. - operationId: c1.api.automations.v1.AutomationSearchService.SearchAutomationTemplateVersions + description: SearchAuditEvents returns email audit events for the tenant. + operationId: c1.api.settings.v1.TenantEmailProviderService.SearchAuditEvents requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationTemplateVersionsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.SearchEmailAuditEventsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationTemplateVersionsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.SearchEmailAuditEventsResponse' description: Successful response - summary: Search Automation Template Versions + summary: Search Audit Events tags: - - Automations - x-speakeasy-group: AutomationSearch - x-speakeasy-name-override: SearchAutomationTemplateVersions - /api/v1/search/automations: + - Tenant Email Provider + x-speakeasy-group: TenantEmailProvider + x-speakeasy-name-override: SearchAuditEvents + /api/v1/settings/email-provider/test: post: - description: Search for automations matching the provided filters, including query text, template refs, app, and trigger types. - operationId: c1.api.automations.v1.AutomationSearchService.SearchAutomations + description: Test sends a test email to verify the provider configuration works end-to-end. + operationId: c1.api.settings.v1.TenantEmailProviderService.Test requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.TestTenantEmailProviderRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.automations.v1.SearchAutomationsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.TestTenantEmailProviderResponse' description: Successful response - summary: Search Automations + summary: Test tags: - - Automations - x-speakeasy-group: AutomationSearch - x-speakeasy-name-override: SearchAutomations - /api/v1/search/entitlements: - post: - description: Search app entitlements based on filters specified in the request body. - operationId: c1.api.app.v1.AppEntitlementSearchService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchRequest' + - Tenant Email Provider + x-speakeasy-group: TenantEmailProvider + x-speakeasy-name-override: Test + /api/v1/settings/identity-policy-defaults: + get: + description: Get returns the tenant's default identity policies. + operationId: c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchResponse' + $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceGetResponse' description: Successful response - summary: Search + summary: Get tags: - - App Entitlement + - Identity Policy Defaults x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: - - App Entitlement#read - - App Entitlements#read - terraform-resource: null - x-speakeasy-group: AppEntitlementSearch - x-speakeasy-name-override: Search - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/functions: + terraform-datasource: null + terraform-resource: IdentityPolicyTenantDefaults#read + x-speakeasy-group: IdentityPolicyTenantDefaults + x-speakeasy-name-override: Get post: - description: Search searches for functions based on criteria - operationId: c1.api.functions.v1.FunctionsSearch.Search + description: |- + Update changes the tenant's default identity policies. Supply the defaults + object and an update mask listing the fields to change; omitted fields are + left as-is. + operationId: c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsSearchRequest' + $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.functions.v1.FunctionsSearchResponse' + $ref: '#/components/schemas/c1.api.identity_platform.v1.IdentityPolicyTenantDefaultsServiceUpdateResponse' description: Successful response - summary: Search + summary: Update tags: - - Function + - Identity Policy Defaults x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: Function#read - terraform-resource: null - x-speakeasy-group: FunctionsSearch - x-speakeasy-name-override: Search - x-stability-level: draft - /api/v1/search/grants: - post: - description: Search grants (user-to-entitlement bindings) across apps, with filters for app, user, resource type, and entitlement. - operationId: c1.api.app.v1.AppEntitlementSearchService.SearchGrants - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsRequest' + terraform-resource: IdentityPolicyTenantDefaults#update + x-speakeasy-group: IdentityPolicyTenantDefaults + x-speakeasy-name-override: Update + /api/v1/settings/notifications/org: + get: + description: Get retrieves the organization-level notification settings, including per-channel preferences and admin-locked defaults. + operationId: c1.api.settings.v1.OrgNotificationSettingsService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.AppEntitlementSearchServiceSearchGrantsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.GetOrgNotificationSettingsResponse' description: Successful response - summary: Search Grants + summary: Get tags: - - App Entitlement - x-speakeasy-group: AppEntitlementSearch - x-speakeasy-name-override: SearchGrants - /api/v1/search/hooks: + - Org Notification Settings + x-speakeasy-group: OrgNotificationSettings + x-speakeasy-name-override: Get post: - description: Invokes the c1.api.hooks.v1.HooksSearch.Search method. - operationId: c1.api.hooks.v1.HooksSearch.Search + description: Update modifies the organization-level notification settings, such as enabling channels and locking preferences for users. + operationId: c1.api.settings.v1.OrgNotificationSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksSearchRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgNotificationSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.hooks.v1.HooksSearchResponse' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgNotificationSettingsResponse' description: Successful response - summary: Search + summary: Update tags: - - Hook - x-speakeasy-group: HooksSearch - x-speakeasy-name-override: Search - /api/v1/search/iam/external_clients: - post: - description: Search returns external client grants for all users in the tenant. - operationId: c1.api.iam.v1.ExternalClientSearchService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientSearchServiceSearchRequest' + - Org Notification Settings + x-speakeasy-group: OrgNotificationSettings + x-speakeasy-name-override: Update + /api/v1/settings/notifications/user: + get: + description: Get retrieves the calling user's notification preferences, merged with organization-level defaults. + operationId: c1.api.settings.v1.UserNotificationSettingsService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.ExternalClientSearchServiceSearchResponse' + $ref: '#/components/schemas/c1.api.settings.v1.GetUserNotificationSettingsResponse' description: Successful response - summary: 'NOTE: Searches external client grants for all users' + summary: Get tags: - - External Client - x-speakeasy-group: ExternalClientSearch - x-speakeasy-name-override: Search - /api/v1/search/iam/personal_clients: + - User Notification Settings + x-speakeasy-group: UserNotificationSettings + x-speakeasy-name-override: Get post: - description: Search finds personal client credentials across all users, with optional filtering by query text or user. - operationId: c1.api.iam.v1.PersonalClientSearchService.Search + description: Update modifies the calling user's personal notification preferences for each channel. + operationId: c1.api.settings.v1.UserNotificationSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientSearchServiceSearchRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserNotificationSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.iam.v1.PersonalClientSearchServiceSearchResponse' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserNotificationSettingsResponse' description: Successful response - summary: 'NOTE: Searches personal clients for all users' + summary: Update tags: - - Personal Client - x-speakeasy-group: PersonalClientSearch - x-speakeasy-name-override: Search - /api/v1/search/local-directory-invitations: - post: - description: |- - List invitations for a directory, with optional status filter. - Search invitations with filters (directory, status). - operationId: c1.api.local_directory.v1.LocalUserInvitationService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceSearchRequest' + - User Notification Settings + x-speakeasy-group: UserNotificationSettings + x-speakeasy-name-override: Update + /api/v1/settings/onboarding: + get: + description: Get retrieves the current onboarding progress for the tenant. + operationId: c1.api.settings.v1.OnboardingSettingsService.Get responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.local_directory.v1.LocalUserInvitationServiceSearchResponse' + $ref: '#/components/schemas/c1.api.settings.v1.GetOnboardingSettingsResponse' description: Successful response - summary: Search + summary: Get tags: - - Local Directory - x-speakeasy-group: LocalUserInvitation - x-speakeasy-name-override: Search - /api/v1/search/past-grants: + - Onboarding Settings + x-speakeasy-group: OnboardingSettings + x-speakeasy-name-override: Get post: - description: Search historical grants that have been revoked, filtered by app user or entitlement. - operationId: c1.api.app.v1.AppEntitlementUserBindingService.SearchPastGrants + description: Update modifies the onboarding progress, such as marking steps complete or dismissing the wizard. + operationId: c1.api.settings.v1.OnboardingSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchPastGrantsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOnboardingSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchPastGrantsResponse' - description: The SearchPastGrantsResponse message contains a list of past grants and a nextPageToken if applicable. - summary: Search Past Grants + $ref: '#/components/schemas/c1.api.settings.v1.UpdateOnboardingSettingsResponse' + description: Successful response + summary: Update tags: - - App Entitlement User Binding History - x-speakeasy-group: AppEntitlementUserBinding - x-speakeasy-name-override: SearchPastGrants - /api/v1/search/policies: + - Onboarding Settings + x-speakeasy-group: OnboardingSettings + x-speakeasy-name-override: Update + /api/v1/settings/request: + get: + description: Get returns the tenant's access-request settings. + operationId: c1.api.settings.v1.RequestSettingsService.Get + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.settings.v1.GetRequestSettingsResponse' + description: Successful response + summary: Get + tags: + - Request Settings + x-speakeasy-group: RequestSettings + x-speakeasy-name-override: Get post: - description: Search policies based on filters specified in the request body. - operationId: c1.api.policy.v1.PolicySearch.Search + description: Update modifies the tenant's access-request settings. + operationId: c1.api.settings.v1.RequestSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.SearchPoliciesRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateRequestSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.policy.v1.SearchPoliciesResponse' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateRequestSettingsResponse' description: Successful response - summary: Search + summary: Update tags: - - Policy + - Request Settings + x-speakeasy-group: RequestSettings + x-speakeasy-name-override: Update + /api/v1/settings/session: + get: + description: Get retrieves the current session security settings for the tenant. + operationId: c1.api.settings.v1.SessionSettingsService.Get + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.settings.v1.GetSessionSettingsResponse' + description: Successful response + summary: Get + tags: + - Session Settings x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-datasource: - - Policy#read - - Policies#read - terraform-resource: null - x-speakeasy-group: PolicySearch - x-speakeasy-name-override: Search - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/request_catalog/entitlements: + terraform-datasource: null + terraform-resource: SessionSettings#read + x-speakeasy-group: SessionSettings + x-speakeasy-name-override: Get post: - description: Search request catalogs based on filters specified in the request body. - operationId: c1.api.requestcatalog.v1.RequestCatalogSearchService.SearchEntitlements + description: Update modifies the session security settings for the tenant, such as session length and IP allowlists. + operationId: c1.api.settings.v1.SessionSettingsService.Update requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.UpdateSessionSettingsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.requestcatalog.v1.RequestCatalogSearchServiceSearchEntitlementsResponse' - description: The RequestCatalogSearchServiceSearchEntitlementsResponse message contains a list of results and a nextPageToken if applicable. - summary: Search Entitlements + $ref: '#/components/schemas/c1.api.settings.v1.UpdateSessionSettingsResponse' + description: Successful response + summary: Update tags: - - Request Catalog - x-speakeasy-group: RequestCatalogSearch - x-speakeasy-name-override: SearchEntitlements - /api/v1/search/role-mining/suggestions: + - Session Settings + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: SessionSettings#update + x-speakeasy-group: SessionSettings + x-speakeasy-name-override: Update + /api/v1/settings/session/test-source-ip: post: - description: Search role mining suggestions by name, description, or cohort filter values with optional state and type filters. - operationId: c1.api.role_mining_management.v1.RoleMiningManagementSearchService.Search + description: TestSourceIP checks whether a given IP address would be allowed by the specified CIDR allowlist rules. + operationId: c1.api.settings.v1.SessionSettingsService.TestSourceIP requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsRequest' + $ref: '#/components/schemas/c1.api.settings.v1.TestSourceIPRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.role_mining_management.v1.RoleMiningSearchSuggestionsResponse' + $ref: '#/components/schemas/c1.api.settings.v1.TestSourceIPResponse' description: Successful response - summary: Search + summary: Test Source Ip tags: - - Role Mining - x-speakeasy-group: RoleMiningManagementSearch - x-speakeasy-name-override: Search - /api/v1/search/secrets-admin: - post: - description: |- - Search returns secrets across the tenant. - Can filter by creator, sharing mode, status, time range, etc. - operationId: c1.api.secrets.v1.PaperSecretAdminService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchRequest' + - Session Settings + x-speakeasy-group: SessionSettings + x-speakeasy-name-override: TestSourceIP + /api/v1/sign-in-policies: + get: + description: List all sign-in policies in your tenant, one page at a time. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.List + parameters: + - in: query + name: page_size + schema: + description: The maximum number of results to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: A pagination token from a previous List response. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchResponse' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceListResponse' description: Successful response - summary: Search + summary: List tags: - - Secrets Admin - x-speakeasy-group: PaperSecretAdmin - x-speakeasy-name-override: Search - x-stability-level: beta - /api/v1/search/secrets-admin/audit_events: + - Sign-In Policy + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: List post: - description: |- - SearchAuditEvents returns audit events for paper secrets. - Can filter by vault_id, actor (user ID or email), client IP. - operationId: c1.api.secrets.v1.PaperSecretAdminService.SearchAuditEvents + description: Create a sign-in policy. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsRequest' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceSearchAuditEventsResponse' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceCreateResponse' description: Successful response - summary: Search Audit Events + summary: Create tags: - - Secrets Admin - x-speakeasy-group: PaperSecretAdmin - x-speakeasy-name-override: SearchAuditEvents - x-stability-level: beta - /api/v1/search/secrets/audit_events: - post: - description: |- - SearchAuditEvents returns audit events for a secret owned by the calling user. - Returns sanitized OCSF events (IP addresses stripped for non-admin consumption). - operationId: c1.api.secrets.v1.PaperSecretService.SearchAuditEvents + - Sign-In Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: SignInPolicy#create + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: Create + /api/v1/sign-in-policies/{id}: + delete: + description: Delete a sign-in policy by ID. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the policy to delete. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsRequest' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchAuditEventsResponse' - description: |- - PaperSecretServiceSearchAuditEventsResponse contains a page of audit events - for the requested secret. - summary: Search Audit Events + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceDeleteResponse' + description: Successful response + summary: Delete tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: SearchAuditEvents - x-stability-level: beta - /api/v1/search/secrets/mine: + - Sign-In Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: SignInPolicy#delete + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: Delete + get: + description: Get a sign-in policy by ID. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the policy to retrieve. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceGetResponse' + description: Successful response + summary: Get + tags: + - Sign-In Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: SignInPolicy#read + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: Get post: description: |- - SearchMySecrets returns secrets created by the current user. - Automatically scoped to current user - no user_id filter parameter. - operationId: c1.api.secrets.v1.PaperSecretService.SearchMySecrets + Update a sign-in policy. Supply the policy object and an update mask + listing the fields to change; omitted fields are left as-is. + operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Update + parameters: + - in: path + name: id + required: true + schema: + description: Unique identifier for the policy. + readOnly: true + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchMySecretsRequest' + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse' + description: Successful response + summary: Update + tags: + - Sign-In Policy + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: SignInPolicy#update + x-speakeasy-group: SignInPolicy + x-speakeasy-name-override: Update + /api/v1/ssf-receiver-streams: + get: + description: List returns a paginated list of all SSF receiver streams configured for the tenant. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.List + parameters: + - in: query + name: page_size + schema: + description: Maximum number of streams to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Token from a previous ListResponse to fetch the next page of results. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSearchResponse' - description: Search response for user's own secrets - summary: Search My Secrets + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse' + description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. + summary: List tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: SearchMySecrets - x-stability-level: beta - /api/v1/search/ssf-receiver-events: + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: List post: - description: Search performs a full-text search across received SSF events with optional filters for stream, event type, outcome, and matched user. - operationId: c1.api.ssf_receiver.v1.SSFReceiverEventSearchService.Search + description: Create registers a new SSF receiver stream with the specified configuration and returns the created stream along with the push auth token (if push delivery). + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchRequest' + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventSearchServiceSearchResponse' - description: SSFReceiverEventSearchServiceSearchResponse contains the matching events and a pagination token. - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse' + description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + summary: Create tags: - SSF Receiver - x-speakeasy-group: SSFReceiverEventSearch - x-speakeasy-name-override: Search - /api/v1/search/step-up/providers: - post: - description: Search allows searching for step-up providers with various filters - operationId: c1.api.stepup.v1.StepUpProviderService.Search + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: Create + /api/v1/ssf-receiver-streams/{id}: + delete: + description: Delete removes an SSF receiver stream and stops receiving events from the associated transmitter. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the SSF receiver stream to delete. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpProvidersRequest' + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpProvidersResponse' - description: Response message for searching step-up providers - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse' + description: SSFReceiverStreamServiceDeleteResponse is empty on success. + summary: Delete tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Search - /api/v1/search/step-up/transactions: - post: - description: Search allows searching for step-up transactions with various filters - operationId: c1.api.stepup.v1.StepUpTransactionService.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpTransactionsRequest' + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: Delete + get: + description: Get retrieves a single SSF receiver stream by its ID. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the SSF receiver stream to retrieve. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.SearchStepUpTransactionsResponse' - description: Response message for searching step-up transactions - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse' + description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. + summary: Get tags: - - Step Up Authentication Transactions - x-speakeasy-group: StepUpTransaction - x-speakeasy-name-override: Search - /api/v1/search/systemlog/exports: + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: Get post: - description: Search for system log exports matching the specified filters. - operationId: c1.api.systemlog.v1.ExportsSearchService.Search + description: Update modifies an existing SSF receiver stream's configuration. Only fields specified in the update mask are changed. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of this SSF receiver stream. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportsSearchServiceSearchRequest' + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportsSearchServiceSearchResponse' - description: ExportsSearchServiceSearchResponse is the response for searching system log exports. - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse' + description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. + summary: Update tags: - - System Log Exporter - x-speakeasy-group: ExportsSearch - x-speakeasy-name-override: Search - /api/v1/search/tasks: + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: Update + /api/v1/ssf-receiver-streams/{id}/test: post: - description: Search tasks based on filters specified in the request body. - operationId: c1.api.task.v1.TaskSearchService.Search + description: Test validates an SSF receiver stream's configuration by checking JWKS reachability, identity resolution, and action preview without processing real events. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Test + parameters: + - in: path + name: id + required: true + schema: + description: The ID of the SSF receiver stream to test. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskSearchRequest' + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskSearchResponse' - description: The TaskSearchResponse message contains a list of results and a nextPageToken if applicable. - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse' + description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. + summary: Test tags: - - Task - x-speakeasy-group: TaskSearch - x-speakeasy-name-override: Search - /api/v1/search/user-ownership: - post: - description: Search all ownership assignments for a given user across apps, resources, and entitlements. - operationId: c1.api.app.v1.AppSearch.SearchUserOwnership - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchUserOwnershipRequest' + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: Test + /api/v1/ssf-receiver-streams/{stream_id}/events: + get: + description: List returns a paginated list of events received on a specific SSF receiver stream, ordered by receipt time. + operationId: c1.api.ssf_receiver.v1.SSFReceiverEventService.List + parameters: + - in: path + name: stream_id + required: true + schema: + description: The ID of the SSF receiver stream to list events for. + type: string + - in: query + name: page_size + schema: + description: Maximum number of events to return per page. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Token from a previous ListResponse to fetch the next page of results. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v1.SearchUserOwnershipResponse' - description: The SearchUserOwnershipResponse message contains a paginated list of ownership entries. - summary: Search User Ownership + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse' + description: SSFReceiverEventServiceListResponse contains a page of received SSF events. + summary: List tags: - - App - x-speakeasy-group: AppSearch - x-speakeasy-name-override: SearchUserOwnership - /api/v1/search/users: - post: - description: Search users based on filters specified in the request body. - operationId: c1.api.user.v1.UserSearch.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.user.v1.SearchUsersRequest' + - SSF Receiver + x-speakeasy-group: SSFReceiverEvent + x-speakeasy-name-override: List + /api/v1/ssf-receiver-streams/{stream_id}/stats: + get: + description: GetStats retrieves event processing statistics for a specific SSF receiver stream, including counts of received, acted-on, and failed events. + operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.GetStats + parameters: + - in: path + name: stream_id + required: true + schema: + description: The ID of the SSF receiver stream to get stats for. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.SearchUsersResponse' - description: Successful response - summary: Search + $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse' + description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. + summary: Get Stats tags: - - User - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - User#read - - Users#read - terraform-resource: null - x-speakeasy-group: UserSearch - x-speakeasy-name-override: Search - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/webhooks: - post: - description: Search for webhook subscriptions by query string or specific webhook references. - operationId: c1.api.webhooks.v1.WebhooksSearch.Search - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksSearchRequest' + - SSF Receiver + x-speakeasy-group: SSFReceiverStream + x-speakeasy-name-override: GetStats + /api/v1/step-up/providers: + get: + description: List returns all step-up authentication providers configured for the tenant. + operationId: c1.api.stepup.v1.StepUpProviderService.List responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksSearchResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.ListStepUpProvidersResponse' description: Successful response - summary: Search + summary: List tags: - - Webhook - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: - - Webhook#read - - Webhooks#read - terraform-resource: null - x-speakeasy-group: WebhooksSearch - x-speakeasy-name-override: Search - x-speakeasy-pagination: - inputs: - - in: requestBody - name: pageToken - type: cursor - outputs: - nextCursor: $.nextPageToken - type: cursor - /api/v1/search/workload_federation_trusts: + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: List post: - description: |- - SearchTrusts searches trusts across all service principals with optional filters. - Used by the admin providers page to list trusts referencing a provider. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.SearchTrusts + description: Create registers a new step-up authentication provider for the tenant. + operationId: c1.api.stepup.v1.StepUpProviderService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsRequest' + $ref: '#/components/schemas/c1.api.stepup.v1.CreateStepUpProviderRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceSearchTrustsResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.CreateStepUpProviderResponse' description: Successful response - summary: Search Trusts + summary: Create tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: SearchTrusts - /api/v1/secrets-admin/{vault_id}: + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: Create + /api/v1/step-up/providers/{id}: delete: - description: Revoke allows admin to revoke any secret (not just their own). - operationId: c1.api.secrets.v1.PaperSecretAdminService.Revoke + description: Delete removes a step-up authentication provider from the tenant. + operationId: c1.api.stepup.v1.StepUpProviderService.Delete parameters: - in: path - name: vault_id + name: id required: true schema: - description: The vaultId field. - readOnly: false + description: The unique identifier of the step-up provider to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput' + $ref: '#/components/schemas/c1.api.stepup.v1.DeleteStepUpProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.DeleteStepUpProviderResponse' description: Successful response - summary: Revoke + summary: Delete tags: - - Secrets Admin - x-speakeasy-group: PaperSecretAdmin - x-speakeasy-name-override: Revoke - x-stability-level: beta + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: Delete get: - description: Get retrieves any secret's metadata by vault ID (admin override). - operationId: c1.api.secrets.v1.PaperSecretAdminService.Get + description: Get retrieves a single step-up authentication provider by its ID. + operationId: c1.api.stepup.v1.StepUpProviderService.Get parameters: - in: path - name: vault_id + name: id required: true schema: - description: The vaultId field. - readOnly: false + description: The unique identifier of the step-up provider to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceGetResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.GetStepUpProviderResponse' description: Successful response summary: Get tags: - - Secrets Admin - x-speakeasy-group: PaperSecretAdmin + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider x-speakeasy-name-override: Get - x-stability-level: beta - /api/v1/secrets/{vault_id}: - delete: - description: Revoke soft-deletes a secret (sets Vault.deleted_at, deletes content). - operationId: c1.api.secrets.v1.PaperSecretService.Revoke + post: + description: Update modifies an existing step-up authentication provider's configuration. Use the update mask to specify which fields to change. + operationId: c1.api.stepup.v1.StepUpProviderService.Update parameters: - in: path - name: vault_id + name: id required: true schema: - description: The vaultId field. - readOnly: false + description: The unique identifier of the step-up provider. + readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceRevokeRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceRevokeResponse' - description: Successful response - summary: Revoke - tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: Revoke - x-stability-level: beta - get: - description: |- - Get retrieves a secret's metadata by vault ID. - Creator can always get their own secrets. Admins can get any secret. - operationId: c1.api.secrets.v1.PaperSecretService.Get - parameters: - - in: path - name: vault_id - required: true - schema: - description: The vaultId field. - readOnly: false - type: string + $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderResponse' description: Successful response - summary: Get + summary: Update tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: Get - x-stability-level: beta - /api/v1/secrets/{vault_id}/content: + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: Update + /api/v1/step-up/providers/{id}/secret: post: - description: |- - SetTextContent sets the encrypted content for a text secret. - Client encrypts content using age_recipient from CreateResponse. - operationId: c1.api.secrets.v1.PaperSecretService.SetTextContent + description: UpdateSecret rotates the client secret for a step-up authentication provider without modifying other settings. + operationId: c1.api.stepup.v1.StepUpProviderService.UpdateSecret parameters: - in: path - name: vault_id + name: id required: true schema: - description: The vaultId field. - readOnly: false + description: The unique identifier of the step-up provider whose secret is being rotated. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSetTextContentRequestInput' + $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceSetTextContentResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderSecretResponse' description: Successful response - summary: Set Text Content + summary: Update Secret tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: SetTextContent - x-stability-level: beta - /api/v1/secrets/{vault_id}/view: + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: UpdateSecret + /api/v1/step-up/providers/{id}/test: post: - description: |- - GetContent retrieves the encrypted secret content for an authorized recipient. - Caller must be in the secret's allowed_user_ids list (for INTERNAL secrets). - Returns content re-encrypted to caller's ephemeral public key. - operationId: c1.api.secrets.v1.PaperSecretService.GetContent + description: Test initiates a test authentication flow against a step-up provider and returns a redirect URL for the caller to complete verification. + operationId: c1.api.stepup.v1.StepUpProviderService.Test parameters: - in: path - name: vault_id + name: id required: true schema: - description: The vaultId field. - readOnly: false + description: The unique identifier of the step-up provider to test. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetContentRequestInput' + $ref: '#/components/schemas/c1.api.stepup.v1.TestStepUpProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetContentResponse' + $ref: '#/components/schemas/c1.api.stepup.v1.TestStepUpProviderResponse' description: Successful response - summary: Get Content + summary: Test tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: GetContent - x-stability-level: draft - /api/v1/secrets/code/{share_code}: + - Step Up Authentication Providers + x-speakeasy-group: StepUpProvider + x-speakeasy-name-override: Test + /api/v1/step-up/transactions/{id}: get: - description: |- - GetByShareCode retrieves a secret by its human-friendly share code. - Share codes are in XXXX-XXXX-XXXX format and are used in share URLs. - operationId: c1.api.secrets.v1.PaperSecretService.GetByShareCode + description: Get retrieves a specific step-up transaction by ID + operationId: c1.api.stepup.v1.StepUpTransactionService.Get parameters: - in: path - name: share_code + name: id required: true schema: - description: 'Human-friendly share code (format: XXXX-XXXX-XXXX, case-insensitive)' - readOnly: false + description: ID of the transaction to retrieve type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceGetResponse' - description: Successful response - summary: Get By Share Code - tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: GetByShareCode - x-stability-level: beta - /api/v1/secrets/external: - post: - description: CreateExternal creates a secret vault for external email recipients. - operationId: c1.api.secrets.v1.PaperSecretService.CreateExternal - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateExternalRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateResponse' - description: Successful response - summary: Create External + $ref: '#/components/schemas/c1.api.stepup.v1.GetStepUpTransactionResponse' + description: Response message containing the requested step-up transaction + summary: Get tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: CreateExternal - x-stability-level: beta - /api/v1/secrets/internal: + - Step Up Authentication Transactions + x-speakeasy-group: StepUpTransaction + x-speakeasy-name-override: Get + /api/v1/systemlog/events: post: - description: CreateInternal creates a secret vault for internal C1 users. - operationId: c1.api.secrets.v1.PaperSecretService.CreateInternal + description: |- + ListEvents pulls Events from the ConductorOne system. + + This endpoint should be used to synchronize the + system log events to external systems. + operationId: c1.api.systemlog.v1.SystemLogService.ListEvents requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateInternalRequest' + $ref: '#/components/schemas/c1.api.systemlog.v1.SystemLogServiceListEventsRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecretServiceCreateResponse' + $ref: '#/components/schemas/c1.api.systemlog.v1.SystemLogServiceListEventsResponse' description: Successful response - summary: Create Internal + summary: List Events tags: - - Secrets - x-speakeasy-group: PaperSecret - x-speakeasy-name-override: CreateInternal - x-stability-level: beta - /api/v1/service_principals: + - System Log + x-speakeasy-group: SystemLog + x-speakeasy-name-override: ListEvents + /api/v1/systemlog/exports: get: - description: List lists service principals for the tenant. - operationId: c1.api.service_principal.v1.ServicePrincipalService.List + description: List Exports. + operationId: c1.api.systemlog.v1.ExportService.List + parameters: + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListResponse' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListResponse' description: Successful response summary: List tags: - - Service Principal - x-speakeasy-group: Principal + - System Log Exporter + x-speakeasy-group: Export x-speakeasy-name-override: List post: - description: Create creates a new service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.Create + description: Create a system log export. + operationId: c1.api.systemlog.v1.ExportService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateRequest' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateResponse' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceCreateResponse' description: Successful response summary: Create tags: - - Service Principal - x-speakeasy-group: Principal + - System Log Exporter + x-speakeasy-group: Export x-speakeasy-name-override: Create - /api/v1/service_principals/{id}: + /api/v1/systemlog/exports/{export_id}: delete: - description: Delete deletes a service principal and all its credentials. - operationId: c1.api.service_principal.v1.ServicePrincipalService.Delete + description: Delete a system log export by ID. + operationId: c1.api.systemlog.v1.ExportService.Delete parameters: - in: path - name: id + name: export_id required: true schema: - description: The id field. - readOnly: false + description: The exportId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteResponse' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceDeleteResponse' description: Successful response summary: Delete tags: - - Service Principal - x-speakeasy-group: Principal + - System Log Exporter + x-speakeasy-group: Export x-speakeasy-name-override: Delete get: - description: Get returns a service principal by ID. - operationId: c1.api.service_principal.v1.ServicePrincipalService.Get + description: Get a system log export by ID + operationId: c1.api.systemlog.v1.ExportService.Get parameters: - in: path - name: id + name: export_id required: true schema: - description: The id field. - readOnly: false + description: The exportId field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceGetResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceGetResponse' + description: The ExportServiceGetResponse message contains the system log exporter object. summary: Get tags: - - Service Principal - x-speakeasy-group: Principal + - System Log Exporter + x-speakeasy-group: Export x-speakeasy-name-override: Get - patch: - description: Update updates a service principal's display name. - operationId: c1.api.service_principal.v1.ServicePrincipalService.Update + post: + description: Update a system log export by providing an export object and an update mask. + operationId: c1.api.systemlog.v1.ExportService.Update parameters: - in: path - name: id + name: export_id required: true schema: - description: The unique user ID of the service principal. + description: The exportId field. readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateResponse' + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceUpdateResponse' description: Successful response summary: Update tags: - - Service Principal - x-speakeasy-group: Principal + - System Log Exporter + x-speakeasy-group: Export x-speakeasy-name-override: Update - /api/v1/service_principals/{service_principal_id}/credentials: - get: - description: ListCredentials lists client credentials for a service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.ListCredentials + /api/v1/systemlog/exports/{export_id}/events: + post: + description: List audit events belonging to a specific system log export. + operationId: c1.api.systemlog.v1.ExportService.ListEvents parameters: - in: path - name: service_principal_id + name: export_id required: true schema: - description: The service principal ID to list credentials for. - readOnly: false + description: The ID of the system log export whose events are being listed. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListEventsRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListCredentialsResponse' - description: Successful response - summary: List Credentials + $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListEventsResponse' + description: ExportServiceListEventsResponse is the response containing audit events for an export. + summary: List Events tags: - - Service Principal - x-speakeasy-group: Principal - x-speakeasy-name-override: ListCredentials + - System Log Exporter + x-speakeasy-group: Export + x-speakeasy-name-override: ListEvents + /api/v1/task/action: post: - description: CreateCredential creates a new client credential for a service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.CreateCredential - parameters: - - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID to create the credential for. - readOnly: false - type: string + description: 'Create an action task: request a "request action" (requestable automation).' + operationId: c1.api.task.v1.TaskService.CreateActionTask requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateActionRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceCreateCredentialResponse' - description: Successful response - summary: Create Credential + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateActionResponse' + description: The TaskServiceCreateActionResponse returns the created action task with optional expanded related objects. + summary: Create Action Task tags: - - Service Principal - x-speakeasy-group: Principal - x-speakeasy-name-override: CreateCredential - /api/v1/service_principals/{service_principal_id}/credentials/{id}: - delete: - description: RevokeCredential revokes (deletes) a client credential for a service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.RevokeCredential - parameters: - - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID. - readOnly: false - type: string - - in: path - name: id - required: true - schema: - description: The credential ID to revoke. - readOnly: false - type: string + - Task + x-speakeasy-group: Task + x-speakeasy-name-override: CreateActionTask + /api/v1/task/audits: + post: + description: List audit trail events for a task. + operationId: c1.api.task.v1.TaskAudit.List requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditListRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceRevokeCredentialResponse' + $ref: '#/components/schemas/c1.api.task.v1.TaskAuditListResponse' description: Successful response - summary: Revoke Credential + summary: List tags: - - Service Principal - x-speakeasy-group: Principal - x-speakeasy-name-override: RevokeCredential + - Task + x-speakeasy-group: TaskAudit + x-speakeasy-name-override: List + /api/v1/task/grant: + post: + description: Create a grant task + operationId: c1.api.task.v1.TaskService.CreateGrantTask + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateGrantRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateGrantResponse' + description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + summary: Create Grant Task + tags: + - Task + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: TaskGrant#create + x-speakeasy-group: Task + x-speakeasy-name-override: CreateGrantTask + /api/v1/task/offboarding: + post: + description: Create an offboarding task to remove a user's access across applications. + operationId: c1.api.task.v1.TaskService.CreateOffboardingTask + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateOffboardingRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateOffboardingResponse' + description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. + summary: Create Offboarding Task + tags: + - Task + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: TaskOffboarding#create + x-speakeasy-group: Task + x-speakeasy-name-override: CreateOffboardingTask + /api/v1/task/resource-action: + post: + description: |- + Create a task that executes a connector resource-create action, for example + creating a group in a connected application from a group template. The action + must be enabled, visible to the caller, and target a connector action of type + resource-create. Form values are validated against the connector's schema at + request time. + operationId: c1.api.task.v1.TaskService.CreateResourceActionTask + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateResourceActionRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateResourceActionResponse' + description: The TaskServiceCreateResourceActionResponse returns the created action task with optional expanded related objects. + summary: Create Resource Action Task + tags: + - Task + x-speakeasy-group: Task + x-speakeasy-name-override: CreateResourceActionTask + /api/v1/task/revoke: + post: + description: Create a revoke task + operationId: c1.api.task.v1.TaskService.CreateRevokeTask + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateRevokeRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateRevokeResponse' + description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + summary: Create Revoke Task + tags: + - Task + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: TaskRevoke#create + x-speakeasy-group: Task + x-speakeasy-name-override: CreateRevokeTask + /api/v1/tasks/{id}: get: - description: GetCredential returns a single client credential for a service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.GetCredential + description: Get a task by ID + operationId: c1.api.task.v1.TaskService.Get parameters: - - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID. - readOnly: false - type: string - in: path name: id required: true schema: - description: The credential ID to get. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceGetCredentialResponse' - description: Successful response - summary: Get Credential + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceGetResponse' + description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. + summary: Get tags: - - Service Principal - x-speakeasy-group: Principal - x-speakeasy-name-override: GetCredential - patch: - description: UpdateCredential updates a client credential for a service principal. - operationId: c1.api.service_principal.v1.ServicePrincipalService.UpdateCredential + - Task + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Task#read + x-speakeasy-group: Task + x-speakeasy-name-override: Get + /api/v1/tasks/{task_id}/action/approve: + post: + description: Approve the specified policy step on a task. + operationId: c1.api.task.v1.TaskActionsService.Approve parameters: - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID. - readOnly: false - type: string - - in: path - name: id + name: task_id required: true schema: - description: The unique ID of the credential (cutename format). - readOnly: true + description: The ID of the task to approve. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceUpdateCredentialResponse' - description: Successful response - summary: Update Credential + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveResponse' + description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. + summary: Approve tags: - - Service Principal - x-speakeasy-group: Principal - x-speakeasy-name-override: UpdateCredential - /api/v1/service_principals/{service_principal_id}/trusts: - get: - description: ListTrusts lists trusts for a service principal. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.ListTrusts + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Approve + /api/v1/tasks/{task_id}/action/approve-with-step-up: + post: + description: Approve a task that requires step-up authentication. If a verified step-up transaction ID is provided, the approval is processed immediately. Otherwise, a redirect URL is returned for the caller to complete authentication first. + operationId: c1.api.task.v1.TaskActionsService.ApproveWithStepUp parameters: - in: path - name: service_principal_id + name: task_id required: true schema: - description: The service principal ID to list trusts for (from URL path). - readOnly: false + description: The ID of the task to approve with step-up. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceListTrustsResponse' - description: Successful response - summary: List Trusts + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse' + description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication + summary: Approve With Step Up tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: ListTrusts + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: ApproveWithStepUp + /api/v1/tasks/{task_id}/action/close: post: description: |- - CreateTrust creates a trust policy for a service principal. - Validates the CEL condition_expression at creation time. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.CreateTrust + Close a task, ending its workflow. Async — returns a ticketActionId on + accept and queues the close; the task's state field is not updated + synchronously. Poll task_service_get to observe the transition to + TASK_STATE_CLOSED. When the task has an active provision step, close + may no-op — finish or cancel the provision step first + (mark_provision_complete / _errored / _cancelled) before closing. + operationId: c1.api.task.v1.TaskActionsService.Close parameters: - in: path - name: service_principal_id + name: task_id required: true schema: - description: The service principal ID to create the trust for (from URL path). - readOnly: false + description: The ID of the task to close. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCloseRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateTrustResponse' - description: Successful response - summary: Create Trust + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCloseResponse' + description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. + summary: Close tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: CreateTrust - /api/v1/service_principals/{service_principal_id}/trusts/{client_id}: - delete: - description: DeleteTrust deletes a trust for a service principal. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.DeleteTrust + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Close + /api/v1/tasks/{task_id}/action/comment: + post: + description: Post a comment on a task without changing its state. + operationId: c1.api.task.v1.TaskActionsService.Comment parameters: - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID (from URL path). - readOnly: false - type: string - - in: path - name: client_id + name: task_id required: true schema: - description: |- - The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the - full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). - The server normalizes to the cutename portion before lookup. - readOnly: false + description: The ID of the task to be commented on type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCommentRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteTrustResponse' - description: Successful response - summary: Delete Trust + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCommentResponse' + description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. + summary: Comment tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: DeleteTrust - get: - description: GetTrust returns a trust by ID for a service principal. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.GetTrust + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Comment + /api/v1/tasks/{task_id}/action/deny: + post: + description: Deny the specified policy step on a task. In multi-step policies, this may route to fallback steps rather than finalizing the task outcome. + operationId: c1.api.task.v1.TaskActionsService.Deny parameters: - in: path - name: service_principal_id + name: task_id required: true schema: - description: The service principal ID (from URL path). - readOnly: false + description: The ID of the task to be denied. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceDenyRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceDenyResponse' + description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. + summary: Deny + tags: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Deny + /api/v1/tasks/{task_id}/action/escalate: + post: + description: Escalate a grant task to use the emergency access policy, bypassing the normal approval flow. Only valid for grant tasks. + operationId: c1.api.task.v1.TaskActionsService.EscalateToEmergencyAccess + parameters: - in: path - name: client_id + name: task_id required: true schema: - description: |- - The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the - full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). - The server normalizes to the cutename portion before lookup. - readOnly: false + description: The ID of the task to escalate. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceGetTrustResponse' - description: Successful response - summary: Get Trust + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + summary: Escalate To Emergency Access tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: GetTrust - patch: - description: UpdateTrust updates a trust's mutable fields. The provider_id is immutable. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.UpdateTrust + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: EscalateToEmergencyAccess + /api/v1/tasks/{task_id}/action/process: + post: + description: Trigger immediate processing of a task, bypassing any scheduled wait. For tasks linked to an external system, this also attempts to sync the external state. + operationId: c1.api.task.v1.TaskActionsService.ProcessNow parameters: - in: path - name: service_principal_id + name: task_id required: true schema: - description: The service principal ID (from URL path). - readOnly: false + description: The ID of the task to process now. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceProcessNowRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceProcessNowResponse' + description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. + summary: Process Now + tags: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: ProcessNow + /api/v1/tasks/{task_id}/action/reassign: + post: + description: Reassign a task's current policy step to a different set of users. The target step must be an approval, provision, or form step. + operationId: c1.api.task.v1.TaskActionsService.Reassign + parameters: - in: path - name: client_id + name: task_id required: true schema: - description: |- - The full client ID of the trust (e.g., "clever-fox-42195@acme.conductorone.com/wfe"). - Used as the client_id parameter in RFC 8693 token exchange requests. - readOnly: true + description: The ID of the task to reassign. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceReassignRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateTrustResponse' - description: Successful response - summary: Update Trust + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceReassignResponse' + description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. + summary: Reassign tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: UpdateTrust - /api/v1/service_principals/{service_principal_id}/trusts/{client_id}/test: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Reassign + /api/v1/tasks/{task_id}/action/reset: post: - description: |- - TestToken validates a JWT against a specific trust's configuration without - issuing an access token. Returns per-step validation results for debugging. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.TestToken + description: Reset a task and recalculate its policy from scratch. Unlike Restart, this re-evaluates which policy applies to the task. + operationId: c1.api.task.v1.TaskActionsService.HardReset parameters: - in: path - name: service_principal_id - required: true - schema: - description: The service principal ID (from URL path). - readOnly: false - type: string - - in: path - name: client_id + name: task_id required: true schema: - description: |- - The trust client ID. Accepts the cutename (e.g. "clever-fox-42195") or the - full client ID (e.g. "clever-fox-42195@acme.conductorone.com/wfe"). - The server normalizes to the cutename portion before lookup. - readOnly: false + description: The ID of the task to reset. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenRequestInput' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceHardResetRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestTokenResponse' - description: Successful response - summary: Test Token + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceHardResetResponse' + description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. + summary: Hard Reset tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: TestToken - /api/v1/service_principals/bindings: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: HardReset + /api/v1/tasks/{task_id}/action/restart: post: - description: |- - AddBinding links a tenant-scoped subject (a function today; future kinds - tomorrow) to a service principal. Outbound c1-api calls made on the - subject's behalf can then be minted as user: via - an RFC 8693 token-exchange (act-as) flow. Many-aware: a subject may - hold multiple bindings at the storage layer. Idempotent on - (subject, service_principal_id) — adds the row if missing, - resurrects it if soft-deleted, no-op if already active. Consumers - that need 0-or-1 cardinality (Functions today) enforce it - client-side via ListBindings + DeleteBinding. Requires the - SERVICE_PRINCIPALS feature flag. - operationId: c1.api.service_principal.v1.ServicePrincipalService.AddBinding + description: Restart a task, returning it to the beginning of its current policy workflow. + operationId: c1.api.task.v1.TaskActionsService.Restart + parameters: + - in: path + name: task_id + required: true + schema: + description: The ID of the task to restart. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceRestartRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse' - description: Successful response - summary: Add Binding + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceRestartResponse' + description: The TaskActionsServiceRestartResponse returns the updated task after restarting. + summary: Restart tags: - - Service Principal Binding - x-speakeasy-group: Principal - x-speakeasy-name-override: AddBinding - x-stability-level: draft - /api/v1/service_principals/bindings/delete: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: Restart + /api/v1/tasks/{task_id}/action/skip-step: post: - description: |- - DeleteBinding removes a single (subject, service_principal_id) binding - row. At-most-one delete — does not touch other bindings the subject - may hold against different service principals. Idempotent — succeeds - even if no matching row exists. - operationId: c1.api.service_principal.v1.ServicePrincipalService.DeleteBinding + description: Skip a specific policy step in a task, advancing the task to the next step in the workflow. + operationId: c1.api.task.v1.TaskActionsService.SkipStep + parameters: + - in: path + name: task_id + required: true + schema: + description: The ID of the task containing the step to skip. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingRequest' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceSkipStepRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceDeleteBindingResponse' - description: Successful response - summary: Delete Binding + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + summary: Skip Step tags: - - Service Principal Binding - x-speakeasy-group: Principal - x-speakeasy-name-override: DeleteBinding - x-stability-level: draft - /api/v1/service_principals/bindings/list: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: SkipStep + /api/v1/tasks/{task_id}/action/update-grant-duration: post: - description: |- - ListBindings returns every active binding held by a subject. Empty - list when the subject is unbound. The response is unordered. - operationId: c1.api.service_principal.v1.ServicePrincipalService.ListBindings + description: Update the grant duration for a task. Only applies to grant tasks with a single entitlement that are not in a provision step. The new duration must not exceed the entitlement's maximum allowed provision time. + operationId: c1.api.task.v1.TaskActionsService.UpdateGrantDuration + parameters: + - in: path + name: task_id + required: true + schema: + description: The ID of the task to update the grant duration for. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListBindingsRequest' + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceListBindingsResponse' - description: Successful response - summary: List Bindings + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + summary: Update Grant Duration tags: - - Service Principal Binding - x-speakeasy-group: Principal - x-speakeasy-name-override: ListBindings - x-stability-level: draft - /api/v1/settings/aws-external-id: - get: - description: Get retrieves the AWS external ID for the tenant, used in IAM role trust policies for AWS connectors. - operationId: c1.api.settings.v1.AWSExternalIDSettings.Get + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: UpdateGrantDuration + /api/v1/tasks/{task_id}/action/update-request-data: + post: + description: Update the request data on a task that is currently in a form step. The submitted data is validated against the form schema before being applied. + operationId: c1.api.task.v1.TaskActionsService.UpdateRequestData + parameters: + - in: path + name: task_id + required: true + schema: + description: The ID of the task containing the request data to update. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetAWSExternalIDResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' + description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + summary: Update Request Data tags: - - AWS External ID Settings - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: AWS_EXTERNAL_ID#read - terraform-resource: AWS_EXTERNAL_ID#read - x-speakeasy-group: AWSExternalIDSettings - x-speakeasy-name-override: Get - /api/v1/settings/contacts: + - Task + x-speakeasy-group: TaskActions + x-speakeasy-name-override: UpdateRequestData + /api/v1/terraform-export/schema: get: - description: Invokes the c1.api.settings.v1.ContactsService.GetContacts method. - operationId: c1.api.settings.v1.ContactsService.GetContacts - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetContactsResponse' - description: Successful response - summary: Get Contacts - tags: - - Contacts - x-speakeasy-group: Contacts - x-speakeasy-name-override: GetContacts - post: - description: Invokes the c1.api.settings.v1.ContactsService.UpdateContacts method. - operationId: c1.api.settings.v1.ContactsService.UpdateContacts - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateContactsRequest' + description: |- + GetSchema returns the field-by-field Terraform mapping for one C1 + API object type. Cacheable by (object_fqn, block_kind, + provider_version). + operationId: c1.api.terraform_export.v1.TerraformExportService.GetSchema responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateContactsResponse' + $ref: '#/components/schemas/c1.api.terraform_export.v1.GetSchemaResponse' description: Successful response - summary: Update Contacts + summary: Get Schema tags: - - Contacts - x-speakeasy-group: Contacts - x-speakeasy-name-override: UpdateContacts - /api/v1/settings/domains: + - Terraform Export + x-speakeasy-group: TerraformExport + x-speakeasy-name-override: GetSchema + /api/v1/users: get: - description: List returns all verified domains configured for the tenant. - operationId: c1.api.settings.v1.OrgDomainService.List + description: List users. + operationId: c1.api.user.v1.UserService.List parameters: - in: query name: page_size schema: - description: The maximum number of results to return per page. + description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: A pagination token returned from a previous List call. - readOnly: false + description: The pageToken field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.ListOrgDomainsResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.user.v1.UserServiceListResponse' + description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. summary: List tags: - - Org Domain - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: OrgDomains#read - terraform-resource: null - x-speakeasy-group: OrgDomain + - User + x-speakeasy-group: User x-speakeasy-name-override: List - put: - description: Update replaces the tenant's set of verified domains with the provided list. - operationId: c1.api.settings.v1.OrgDomainService.Update - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgDomainRequest' + /api/v1/users/{id}: + get: + description: Get a user by ID. + operationId: c1.api.user.v1.UserService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The id field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgDomainResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.user.v1.UserServiceGetResponse' + description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. + summary: Get tags: - - Org Domain - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: OrgDomains#update - x-speakeasy-group: OrgDomain - x-speakeasy-name-override: Update - /api/v1/settings/email-capabilities: + - User + x-speakeasy-group: User + x-speakeasy-name-override: Get + /api/v1/users/{user_id}/mcp_toolsets/requestable_connectors: get: description: |- - GetEmailCapabilities returns a lightweight summary of email capabilities - for the current tenant. Intended for non-admin users (automation builders, - secret sharers) to check if external email is available without exposing - provider configuration details. - operationId: c1.api.settings.v1.TenantEmailProviderService.GetEmailCapabilities + ListRequestableConnectors returns the (app_id, connector_id) pairs that + have at least one requestable toolset (access profile) for the given user. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.ListRequestableConnectors + parameters: + - in: path + name: user_id + required: true + schema: + description: The user ID to check requestable profiles for. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetEmailCapabilitiesResponse' - description: Successful response - summary: Get Email Capabilities + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceListRequestableConnectorsResponse' + description: |- + MCPAccessProfileServiceListRequestableConnectorsResponse returns connector references + that have requestable MCP access profiles. + summary: List Requestable Connectors tags: - - Tenant Email Provider - x-speakeasy-group: TenantEmailProvider - x-speakeasy-name-override: GetEmailCapabilities - /api/v1/settings/email-provider: + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: ListRequestableConnectors + /api/v1/users/{user_id}/mcp_toolsets/requestable_connectors/search: get: - description: Get retrieves the current tenant email provider configuration. - operationId: c1.api.settings.v1.TenantEmailProviderService.Get - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetTenantEmailProviderResponse' - description: Successful response - summary: Get - tags: - - Tenant Email Provider - x-speakeasy-group: TenantEmailProvider - x-speakeasy-name-override: Get - post: - description: Update creates or updates the tenant email provider configuration. - operationId: c1.api.settings.v1.TenantEmailProviderService.Update - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateTenantEmailProviderRequest' + description: |- + SearchRequestableConnectors returns card-ready entries — one per MCP + connector the user can browse and request tools for — with server-side + visibility + policy filtering, grant-enrollment-status filtering, text + search over the connector display name, and pagination. Backs the + Requests -> AI tools connector cards. Held connectors are surfaced even + when no longer requestable so "My tools" reflects what the user actually + holds. + operationId: c1.api.ai_governance.v1.MCPAccessProfileService.SearchRequestableConnectors + parameters: + - in: path + name: user_id + required: true + schema: + description: The user the requestable set is scoped to. + type: string + - in: query + name: grant_enrollment_status + schema: + description: |- + Filters by whether the user already holds the connector's tools. + UNSPECIFIED = all, FULLY_GRANTED = held, NOT_GRANTED = available. + enum: + - GRANT_ENROLLMENT_STATUS_UNSPECIFIED + - GRANT_ENROLLMENT_STATUS_FULLY_GRANTED + - GRANT_ENROLLMENT_STATUS_NOT_GRANTED + - GRANT_ENROLLMENT_STATUS_PARTIALLY_GRANTED + type: string + x-speakeasy-unknown-values: allow + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + - in: query + name: query + schema: + description: Case-insensitive search over the connector display name. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateTenantEmailProviderResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.ai_governance.v1.MCPAccessProfileServiceSearchRequestableConnectorsResponse' + description: |- + MCPAccessProfileServiceSearchRequestableConnectorsResponse returns one page + of card-ready requestable-connector entries. + summary: Search Requestable Connectors tags: - - Tenant Email Provider - x-speakeasy-group: TenantEmailProvider - x-speakeasy-name-override: Update - /api/v1/settings/email-provider/audit-events: - post: - description: SearchAuditEvents returns email audit events for the tenant. - operationId: c1.api.settings.v1.TenantEmailProviderService.SearchAuditEvents - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.SearchEmailAuditEventsRequest' + - MCP Toolsets + x-speakeasy-group: MCPAccessProfile + x-speakeasy-name-override: SearchRequestableConnectors + /api/v1/users/{user_id}/profile-types: + get: + description: Retrieve the profile types associated with a user across their connected apps. + operationId: c1.api.user.v1.UserService.GetUserProfileTypes + parameters: + - in: path + name: user_id + required: true + schema: + description: The ID of the user whose profile types are being retrieved. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.SearchEmailAuditEventsResponse' - description: Successful response - summary: Search Audit Events + $ref: '#/components/schemas/c1.api.user.v1.GetUserProfileTypesResponse' + description: GetUserProfileTypesResponse is the response containing the profile types for a user. + summary: Get User Profile Types tags: - - Tenant Email Provider - x-speakeasy-group: TenantEmailProvider - x-speakeasy-name-override: SearchAuditEvents - /api/v1/settings/email-provider/test: + - User + x-speakeasy-group: User + x-speakeasy-name-override: GetUserProfileTypes + /api/v1/users/{user_id}/set-delegation-by-admin: post: - description: Test sends a test email to verify the provider configuration works end-to-end. - operationId: c1.api.settings.v1.TenantEmailProviderService.Test + description: Set or update an expiring delegation binding for a user, allowing an admin to designate a temporary delegate. + operationId: c1.api.user.v1.UserService.SetExpiringUserDelegationBindingByAdmin + parameters: + - in: path + name: user_id + required: true + schema: + description: The ID of the user whose tasks will be delegated. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.TestTenantEmailProviderRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.TestTenantEmailProviderResponse' - description: Successful response - summary: Test - tags: - - Tenant Email Provider - x-speakeasy-group: TenantEmailProvider - x-speakeasy-name-override: Test - /api/v1/settings/notifications/org: - get: - description: Get retrieves the organization-level notification settings, including per-channel preferences and admin-locked defaults. - operationId: c1.api.settings.v1.OrgNotificationSettingsService.Get + $ref: '#/components/schemas/c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetOrgNotificationSettingsResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse' + description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. + summary: Set Expiring User Delegation Binding By Admin tags: - - Org Notification Settings - x-speakeasy-group: OrgNotificationSettings - x-speakeasy-name-override: Get + - User + x-speakeasy-group: User + x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdmin + /api/v1/users/introspect: post: - description: Update modifies the organization-level notification settings, such as enabling channels and locking preferences for users. - operationId: c1.api.settings.v1.OrgNotificationSettingsService.Update + description: |- + Introspect returns the calling user's full UserView (profile, manager, attributes) + resolved from the passport on the request. + operationId: c1.api.user.v1.UserService.Introspect requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgNotificationSettingsRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOrgNotificationSettingsResponse' - description: Successful response - summary: Update - tags: - - Org Notification Settings - x-speakeasy-group: OrgNotificationSettings - x-speakeasy-name-override: Update - /api/v1/settings/notifications/user: - get: - description: Get retrieves the calling user's notification preferences, merged with organization-level defaults. - operationId: c1.api.settings.v1.UserNotificationSettingsService.Get + $ref: '#/components/schemas/c1.api.user.v1.IntrospectRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetUserNotificationSettingsResponse' + $ref: '#/components/schemas/c1.api.user.v1.IntrospectResponse' description: Successful response - summary: Get + summary: Introspect tags: - - User Notification Settings - x-speakeasy-group: UserNotificationSettings - x-speakeasy-name-override: Get + - User + x-speakeasy-group: User + x-speakeasy-name-override: Introspect + /api/v1/vaults: post: - description: Update modifies the calling user's personal notification preferences for each channel. - operationId: c1.api.settings.v1.UserNotificationSettingsService.Update + description: Create provisions a new external secret storage vault and returns it. + operationId: c1.api.vault.v1.VaultService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserNotificationSettingsRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateUserNotificationSettingsResponse' - description: Successful response - summary: Update - tags: - - User Notification Settings - x-speakeasy-group: UserNotificationSettings - x-speakeasy-name-override: Update - /api/v1/settings/onboarding: - get: - description: Get retrieves the current onboarding progress for the tenant. - operationId: c1.api.settings.v1.OnboardingSettingsService.Get + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetOnboardingSettingsResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceCreateResponse' + description: VaultServiceCreateResponse is the response message for creating a new vault. + summary: Create tags: - - Onboarding Settings - x-speakeasy-group: OnboardingSettings - x-speakeasy-name-override: Get - post: - description: Update modifies the onboarding progress, such as marking steps complete or dismissing the wizard. - operationId: c1.api.settings.v1.OnboardingSettingsService.Update + - Vault + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Vault#create + x-speakeasy-group: Vault + x-speakeasy-name-override: Create + x-stability-level: draft + /api/v1/vaults/{id}: + delete: + description: Delete a vault by its ID. Active connectors using this vault will no longer be able to access their stored credentials. + operationId: c1.api.vault.v1.VaultService.Delete + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the vault to delete. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOnboardingSettingsRequest' + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateOnboardingSettingsResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceDeleteResponse' + description: Empty response body. Status code indicates success. + summary: Delete tags: - - Onboarding Settings - x-speakeasy-group: OnboardingSettings - x-speakeasy-name-override: Update - /api/v1/settings/session: + - Vault + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Vault#delete + x-speakeasy-group: Vault + x-speakeasy-name-override: Delete + x-stability-level: draft get: - description: Get retrieves the current session security settings for the tenant. - operationId: c1.api.settings.v1.SessionSettingsService.Get + description: Get returns a single vault by its ID. + operationId: c1.api.vault.v1.VaultService.Get + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the vault to retrieve. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.GetSessionSettingsResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceGetResponse' + description: VaultServiceGetResponse is the response message containing the requested vault. summary: Get tags: - - Session Settings + - Vault x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: terraform-datasource: null - terraform-resource: SessionSettings#read - x-speakeasy-group: SessionSettings + terraform-resource: Vault#read + x-speakeasy-group: Vault x-speakeasy-name-override: Get + x-stability-level: draft post: - description: Update modifies the session security settings for the tenant, such as session length and IP allowlists. - operationId: c1.api.settings.v1.SessionSettingsService.Update + description: Update modifies an existing vault's properties using a field mask. + operationId: c1.api.vault.v1.VaultService.Update + parameters: + - in: path + name: id + required: true + schema: + description: The unique identifier of the vault. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateSessionSettingsRequest' + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.settings.v1.UpdateSessionSettingsResponse' - description: Successful response + $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceUpdateResponse' + description: VaultServiceUpdateResponse is the response message containing the updated vault. summary: Update tags: - - Session Settings + - Vault x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: SessionSettings#update - x-speakeasy-group: SessionSettings + terraform-resource: Vault#update + x-speakeasy-group: Vault x-speakeasy-name-override: Update - /api/v1/settings/session/test-source-ip: - post: - description: TestSourceIP checks whether a given IP address would be allowed by the specified CIDR allowlist rules. - operationId: c1.api.settings.v1.SessionSettingsService.TestSourceIP - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.TestSourceIPRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.settings.v1.TestSourceIPResponse' - description: Successful response - summary: Test Source Ip - tags: - - Session Settings - x-speakeasy-group: SessionSettings - x-speakeasy-name-override: TestSourceIP - /api/v1/ssf-receiver-streams: + x-stability-level: draft + /api/v1/webhooks: get: - description: List returns a paginated list of all SSF receiver streams configured for the tenant. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.List + description: List all webhook subscriptions in the tenant, with pagination. + operationId: c1.api.webhooks.v1.WebhooksService.List parameters: - in: query name: page_size schema: - description: Maximum number of streams to return per page. + description: The maximum number of webhooks to return per page. format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: Token from a previous ListResponse to fetch the next page of results. - readOnly: false + description: The pagination token from a previous list response to fetch the next page. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceListResponse' - description: SSFReceiverStreamServiceListResponse contains a page of SSF receiver streams. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceListResponse' + description: Successful response summary: List tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-group: Webhooks x-speakeasy-name-override: List post: - description: Create registers a new SSF receiver stream with the specified configuration and returns the created stream along with the push auth token (if push delivery). - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Create + description: Create a new webhook subscription to receive event notifications at the specified URL. + operationId: c1.api.webhooks.v1.WebhooksService.Create requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateRequest' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceCreateRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceCreateResponse' - description: SSFReceiverStreamServiceCreateResponse returns the created stream and the push auth token in plaintext. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceCreateResponse' + description: Successful response summary: Create tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Webhook#create + x-speakeasy-group: Webhooks x-speakeasy-name-override: Create - /api/v1/ssf-receiver-streams/{id}: + /api/v1/webhooks/{id}: delete: - description: Delete removes an SSF receiver stream and stops receiving events from the associated transmitter. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Delete + description: Delete a webhook subscription, stopping all future event deliveries to its URL. + operationId: c1.api.webhooks.v1.WebhooksService.Delete parameters: - in: path name: id required: true schema: - description: The ID of the SSF receiver stream to delete. - readOnly: false + description: The ID of the webhook to delete. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceDeleteResponse' - description: SSFReceiverStreamServiceDeleteResponse is empty on success. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceDeleteResponse' + description: Empty response body. Status code indicates success. summary: Delete tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Webhook#delete + x-speakeasy-group: Webhooks x-speakeasy-name-override: Delete get: - description: Get retrieves a single SSF receiver stream by its ID. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Get + description: Retrieve a single webhook by its ID. + operationId: c1.api.webhooks.v1.WebhooksService.Get parameters: - in: path name: id required: true schema: - description: The ID of the SSF receiver stream to retrieve. - readOnly: false + description: The ID of the webhook to retrieve. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetResponse' - description: SSFReceiverStreamServiceGetResponse contains the requested SSF receiver stream. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceGetResponse' + description: Successful response summary: Get tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Webhook#read + x-speakeasy-group: Webhooks x-speakeasy-name-override: Get post: - description: Update modifies an existing SSF receiver stream's configuration. Only fields specified in the update mask are changed. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Update + description: Update an existing webhook subscription's properties, such as its URL or display name. + operationId: c1.api.webhooks.v1.WebhooksService.Update parameters: - in: path name: id required: true schema: - description: The unique identifier of this SSF receiver stream. - readOnly: false + description: The unique identifier of the webhook. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceUpdateResponse' - description: SSFReceiverStreamServiceUpdateResponse contains the updated SSF receiver stream. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceUpdateResponse' + description: Successful response summary: Update tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Webhook#update + x-speakeasy-group: Webhooks x-speakeasy-name-override: Update - /api/v1/ssf-receiver-streams/{id}/test: + /api/v1/webhooks/{id}/test: post: - description: Test validates an SSF receiver stream's configuration by checking JWKS reachability, identity resolution, and action preview without processing real events. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.Test + description: Send a sample event to the webhook URL to verify that the endpoint is reachable and responding correctly. + operationId: c1.api.webhooks.v1.WebhooksService.Test parameters: - in: path name: id required: true schema: - description: The ID of the SSF receiver stream to test. - readOnly: false + description: The ID of the webhook to send a test event to. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestRequestInput' + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceTestRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceTestResponse' - description: SSFReceiverStreamServiceTestResponse reports the results of the stream configuration test across JWKS, identity, and action readiness checks. + $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceTestResponse' + description: Successful response summary: Test tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream + - Webhook + x-speakeasy-group: Webhooks x-speakeasy-name-override: Test - /api/v1/ssf-receiver-streams/{stream_id}/events: - get: - description: List returns a paginated list of events received on a specific SSF receiver stream, ordered by receipt time. - operationId: c1.api.ssf_receiver.v1.SSFReceiverEventService.List - parameters: - - in: path - name: stream_id - required: true - schema: - description: The ID of the SSF receiver stream to list events for. - readOnly: false - type: string - - in: query - name: page_size - schema: - description: Maximum number of events to return per page. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token - schema: - description: Token from a previous ListResponse to fetch the next page of results. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverEventServiceListResponse' - description: SSFReceiverEventServiceListResponse contains a page of received SSF events. - summary: List - tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverEvent - x-speakeasy-name-override: List - /api/v1/ssf-receiver-streams/{stream_id}/stats: - get: - description: GetStats retrieves event processing statistics for a specific SSF receiver stream, including counts of received, acted-on, and failed events. - operationId: c1.api.ssf_receiver.v1.SSFReceiverStreamService.GetStats - parameters: - - in: path - name: stream_id - required: true - schema: - description: The ID of the SSF receiver stream to get stats for. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.ssf_receiver.v1.SSFReceiverStreamServiceGetStatsResponse' - description: SSFReceiverStreamServiceGetStatsResponse contains the event processing statistics for the stream. - summary: Get Stats - tags: - - SSF Receiver - x-speakeasy-group: SSFReceiverStream - x-speakeasy-name-override: GetStats - /api/v1/step-up/providers: + /api/v1/workload_federation/providers: get: - description: List returns all step-up authentication providers configured for the tenant. - operationId: c1.api.stepup.v1.StepUpProviderService.List + description: ListProviders lists all providers for the tenant. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.ListProviders responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.ListStepUpProvidersResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse' description: Successful response - summary: List + summary: List Providers tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: List + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: ListProviders post: - description: Create registers a new step-up authentication provider for the tenant. - operationId: c1.api.stepup.v1.StepUpProviderService.Create + description: |- + CreateProvider registers a new external OIDC issuer for the tenant. + Validates the issuer URL via OIDC discovery synchronously. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.CreateProvider requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.CreateStepUpProviderRequest' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.CreateStepUpProviderResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse' description: Successful response - summary: Create + summary: Create Provider tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Create - /api/v1/step-up/providers/{id}: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: CreateProvider + /api/v1/workload_federation/providers/{id}: delete: - description: Delete removes a step-up authentication provider from the tenant. - operationId: c1.api.stepup.v1.StepUpProviderService.Delete + description: DeleteProvider deletes a provider. Fails if active trusts reference it. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.DeleteProvider parameters: - in: path name: id required: true schema: - description: The unique identifier of the step-up provider to delete. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.DeleteStepUpProviderRequestInput' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.DeleteStepUpProviderResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse' description: Successful response - summary: Delete + summary: Delete Provider tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Delete + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: DeleteProvider get: - description: Get retrieves a single step-up authentication provider by its ID. - operationId: c1.api.stepup.v1.StepUpProviderService.Get + description: GetProvider returns a provider by ID. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.GetProvider parameters: - in: path name: id required: true schema: - description: The unique identifier of the step-up provider to retrieve. - readOnly: false + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.GetStepUpProviderResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse' description: Successful response - summary: Get + summary: Get Provider tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Get - post: - description: Update modifies an existing step-up authentication provider's configuration. Use the update mask to specify which fields to change. - operationId: c1.api.stepup.v1.StepUpProviderService.Update + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: GetProvider + patch: + description: |- + UpdateProvider updates a provider's mutable fields (display_name, description, disabled). + The issuer_url is immutable after creation. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.UpdateProvider parameters: - in: path name: id required: true schema: - description: The unique identifier of the step-up provider. + description: The unique ID of the provider. readOnly: true type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderRequestInput' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderResponse' + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse' description: Successful response - summary: Update + summary: Update Provider tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Update - /api/v1/step-up/providers/{id}/secret: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: UpdateProvider + /api/v1/workload_federation/test-cel: post: - description: UpdateSecret rotates the client secret for a step-up authentication provider without modifying other settings. - operationId: c1.api.stepup.v1.StepUpProviderService.UpdateSecret + description: |- + TestCEL evaluates a CEL expression against provided claims without + requiring a JWT, provider, or trust. Used for expression authoring. + operationId: c1.api.workload_federation.v1.WorkloadFederationService.TestCEL + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse' + description: Successful response + summary: Test Cel + tags: + - Workload Federation + x-speakeasy-group: WorkloadFederation + x-speakeasy-name-override: TestCEL + /api/v1/xaa/resource_servers/{client_audience_mapping_xaa_resource_server_id}/client_audience_mappings/update: + post: + description: |- + Update a mapping's editable fields via update_mask. The resource server + and client key identify the mapping and are immutable. Editable paths: + audience_client_id, disabled. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Update parameters: - in: path - name: id + name: client_audience_mapping_xaa_resource_server_id required: true schema: - description: The unique identifier of the step-up provider whose secret is being rotated. - readOnly: false + description: The resource server this mapping applies to. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderSecretRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceUpdateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.UpdateStepUpProviderSecretResponse' - description: Successful response - summary: Update Secret + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceUpdateResponse' + description: XAAClientAudienceMappingServiceUpdateResponse returns the updated mapping. + summary: Update tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: UpdateSecret - /api/v1/step-up/providers/{id}/test: + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: Update + /api/v1/xaa/resource_servers/{xaa_resource_server_id}/client_audience_mappings: + get: + description: |- + List the client audience mappings for a resource server, one page at a + time. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.List + parameters: + - in: path + name: xaa_resource_server_id + required: true + schema: + description: The resource server to list mappings for. + type: string + - in: query + name: page_size + schema: + description: Page size (max 100). + format: int32 + type: integer + - in: query + name: page_token + schema: + description: Page token for pagination. + type: string + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceListResponse' + description: XAAClientAudienceMappingServiceListResponse returns a page of mappings. + summary: List + tags: + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: List post: - description: Test initiates a test authentication flow against a step-up provider and returns a redirect URL for the caller to complete verification. - operationId: c1.api.stepup.v1.StepUpProviderService.Test + description: Create a client audience mapping under a resource server. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Create parameters: - in: path - name: id + name: xaa_resource_server_id required: true schema: - description: The unique identifier of the step-up provider to test. - readOnly: false + description: The resource server this mapping applies to. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.TestStepUpProviderRequestInput' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceCreateRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.TestStepUpProviderResponse' - description: Successful response - summary: Test + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceCreateResponse' + description: XAAClientAudienceMappingServiceCreateResponse returns the created mapping. + summary: Create tags: - - Step Up Authentication Providers - x-speakeasy-group: StepUpProvider - x-speakeasy-name-override: Test - /api/v1/step-up/transactions/{id}: + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: Create + /api/v1/xaa/resource_servers/{xaa_resource_server_id}/client_audience_mappings/by_client_key: get: - description: Get retrieves a specific step-up transaction by ID - operationId: c1.api.stepup.v1.StepUpTransactionService.Get + description: |- + Get a client audience mapping by resource server + client key. The client + key is passed as a query parameter because it may be a URL. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Get parameters: - in: path - name: id + name: xaa_resource_server_id required: true schema: - description: ID of the transaction to retrieve - readOnly: false + description: The resource server this mapping applies to. + type: string + - in: query + name: client_key + schema: + description: The client key identifying the mapping. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.stepup.v1.GetStepUpTransactionResponse' - description: Response message containing the requested step-up transaction + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceGetResponse' + description: XAAClientAudienceMappingServiceGetResponse returns a single mapping. summary: Get tags: - - Step Up Authentication Transactions - x-speakeasy-group: StepUpTransaction + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping x-speakeasy-name-override: Get - /api/v1/systemlog/events: + /api/v1/xaa/resource_servers/{xaa_resource_server_id}/client_audience_mappings/delete: post: description: |- - ListEvents pulls Events from the ConductorOne system. - - This endpoint should be used to synchronize the - system log events to external systems. - operationId: c1.api.systemlog.v1.SystemLogService.ListEvents + Delete a mapping (soft delete). Uses a POST .../delete action route + because the client key travels in the request body, which HTTP DELETE does + not reliably support. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Delete + parameters: + - in: path + name: xaa_resource_server_id + required: true + schema: + description: The resource server this mapping applies to. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.SystemLogServiceListEventsRequest' + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.SystemLogServiceListEventsResponse' - description: Successful response - summary: List Events + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceDeleteResponse' + description: XAAClientAudienceMappingServiceDeleteResponse confirms deletion. + summary: Delete tags: - - System Log - x-speakeasy-group: SystemLog - x-speakeasy-name-override: ListEvents - /api/v1/systemlog/exports: + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: Delete + /api/v1/xaa/resource_servers/{xaa_resource_server_id}/client_audience_mappings/history: get: - description: List Exports. - operationId: c1.api.systemlog.v1.ExportService.List + description: |- + ListHistory returns the change history (newest first) for a single client + audience mapping — each entry is a snapshot plus who/when metadata. The + client key is passed as a query parameter because it may be a URL. + operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.ListHistory parameters: + - in: path + name: xaa_resource_server_id + required: true + schema: + description: The resource server this mapping applies to. + type: string + - in: query + name: client_key + schema: + description: Stable client registration key identifying the mapping. + type: string - in: query name: page_size schema: - description: The pageSize field. + description: Page size (max 200). format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: The pageToken field. - readOnly: false + description: Page token for pagination. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceListHistoryResponse' + description: |- + XAAClientAudienceMappingServiceListHistoryResponse returns client audience + mapping history entries. + summary: List History tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: List - post: - description: Create a system log export. - operationId: c1.api.systemlog.v1.ExportService.Create + - Cross-App Access + x-speakeasy-group: XAAClientAudienceMapping + x-speakeasy-name-override: ListHistory + /api/v2/apps/{app_id}/connectors/{connector_id}/owners: + put: + description: Set replaces all owners for a given connector and role. + operationId: c1.api.app.v2.ConnectorOwners.Set + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceCreateRequest' + $ref: '#/components/schemas/c1.api.app.v2.SetConnectorOwnersV2RequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceCreateResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.app.v2.SetConnectorOwnersV2Response' + description: SetConnectorOwnersV2Response is the empty response for setting connector owners. + summary: Set tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: Create - /api/v1/systemlog/exports/{export_id}: - delete: - description: Delete a system log export by ID. - operationId: c1.api.systemlog.v1.ExportService.Delete + - Connector Owner V2 + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: Set + x-stability-level: draft + /api/v2/apps/{app_id}/connectors/{connector_id}/owners/entitlements: + get: + description: SearchEntitlementOwners searches for entitlement ownership sources for a connector. + operationId: c1.api.app.v2.ConnectorOwners.SearchEntitlementOwners parameters: - in: path - name: export_id + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id required: true schema: - description: The exportId field. - readOnly: false + description: The connectorId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceDeleteRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceDeleteResponse' - description: Successful response - summary: Delete + $ref: '#/components/schemas/c1.api.app.v2.SearchConnectorEntitlementOwnersResponse' + description: SearchConnectorEntitlementOwnersResponse is the response for searching entitlement ownership sources on a connector. + summary: Search Entitlement Owners tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: Delete - get: - description: Get a system log export by ID - operationId: c1.api.systemlog.v1.ExportService.Get + - Connector Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: Connector_Owner_Entitlement#read + terraform-resource: null + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: SearchEntitlementOwners + x-stability-level: draft + ? /api/v2/apps/{app_id}/connectors/{connector_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id} + : delete: + description: DeleteEntitlementOwner deletes an entitlement ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.DeleteEntitlementOwner parameters: - in: path - name: export_id + name: app_id required: true schema: - description: The exportId field. - readOnly: false + description: The appId field. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceGetResponse' - description: The ExportServiceGetResponse message contains the system log exporter object. - summary: Get - tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: Get - post: - description: Update a system log export by providing an export object and an update mask. - operationId: c1.api.systemlog.v1.ExportService.Update - parameters: - in: path - name: export_id + name: connector_id required: true schema: - description: The exportId field. - readOnly: true + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteConnectorEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceUpdateResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.app.v2.DeleteConnectorEntitlementOwnerResponse' + description: DeleteConnectorEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a connector. + summary: Delete Entitlement Owner tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: Update - /api/v1/systemlog/exports/{export_id}/events: - post: - description: List audit events belonging to a specific system log export. - operationId: c1.api.systemlog.v1.ExportService.ListEvents + - Connector Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Connector_Owner_Entitlement#delete + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: DeleteEntitlementOwner + x-stability-level: draft + get: + description: GetEntitlementOwner gets an entitlement ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.GetEntitlementOwner parameters: - in: path - name: export_id + name: app_id required: true schema: - description: The ID of the system log export whose events are being listed. - readOnly: false + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListEventsRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.systemlog.v1.ExportServiceListEventsResponse' - description: ExportServiceListEventsResponse is the response containing audit events for an export. - summary: List Events - tags: - - System Log Exporter - x-speakeasy-group: Export - x-speakeasy-name-override: ListEvents - /api/v1/task/audits: - post: - description: List audit trail events for a task. - operationId: c1.api.task.v1.TaskAudit.List - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditListRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskAuditListResponse' - description: Successful response - summary: List + $ref: '#/components/schemas/c1.api.app.v2.GetConnectorEntitlementOwnerResponse' + description: GetConnectorEntitlementOwnerResponse is the response for getting an entitlement ownership source on a connector. + summary: Get Entitlement Owner tags: - - Task - x-speakeasy-group: TaskAudit - x-speakeasy-name-override: List - /api/v1/task/grant: + - Connector Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: Connector_Owner_Entitlement#read + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: GetEntitlementOwner + x-stability-level: draft post: - description: Create a grant task - operationId: c1.api.task.v1.TaskService.CreateGrantTask + description: CreateEntitlementOwner creates an entitlement ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.CreateEntitlementOwner + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateGrantRequest' + $ref: '#/components/schemas/c1.api.app.v2.CreateConnectorEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateGrantResponse' - description: The TaskServiceCreateGrantResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. - summary: Create Grant Task + $ref: '#/components/schemas/c1.api.app.v2.CreateConnectorEntitlementOwnerResponse' + description: CreateConnectorEntitlementOwnerResponse is the response for creating an entitlement ownership source on a connector. + summary: Create Entitlement Owner tags: - - Task + - Connector Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: TaskGrant#create - x-speakeasy-group: Task - x-speakeasy-name-override: CreateGrantTask - /api/v1/task/offboarding: - post: - description: Create an offboarding task to remove a user's access across applications. - operationId: c1.api.task.v1.TaskService.CreateOffboardingTask - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateOffboardingRequest' + terraform-resource: Connector_Owner_Entitlement#create + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: CreateEntitlementOwner + x-stability-level: draft + /api/v2/apps/{app_id}/connectors/{connector_id}/owners/users: + get: + description: SearchUserOwners searches for user ownership sources for a connector. + operationId: c1.api.app.v2.ConnectorOwners.SearchUserOwners + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateOffboardingResponse' - description: The TaskServiceCreateOffboardingResponse returns the created offboarding task with optional expanded related objects. - summary: Create Offboarding Task + $ref: '#/components/schemas/c1.api.app.v2.SearchConnectorUserOwnersResponse' + description: SearchConnectorUserOwnersResponse is the response for searching user ownership sources on a connector. + summary: Search User Owners tags: - - Task + - Connector Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: TaskOffboarding#create - x-speakeasy-group: Task - x-speakeasy-name-override: CreateOffboardingTask - /api/v1/task/revoke: - post: - description: Create a revoke task - operationId: c1.api.task.v1.TaskService.CreateRevokeTask + terraform-datasource: Connector_Owner_User#read + terraform-resource: null + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: SearchUserOwners + x-stability-level: draft + /api/v2/apps/{app_id}/connectors/{connector_id}/owners/users/{role_slug}/{user_ref_id}: + delete: + description: DeleteUserOwner deletes a user ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.DeleteUserOwner + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateRevokeRequest' + $ref: '#/components/schemas/c1.api.app.v2.DeleteConnectorUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceCreateRevokeResponse' - description: The TaskServiceCreateRevokeResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. - summary: Create Revoke Task + $ref: '#/components/schemas/c1.api.app.v2.DeleteConnectorUserOwnerResponse' + description: DeleteConnectorUserOwnerResponse is the empty response for deleting a user ownership source on a connector. + summary: Delete User Owner tags: - - Task + - Connector Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: TaskRevoke#create - x-speakeasy-group: Task - x-speakeasy-name-override: CreateRevokeTask - /api/v1/tasks/{id}: + terraform-resource: Connector_Owner_User#delete + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: DeleteUserOwner + x-stability-level: draft get: - description: Get a task by ID - operationId: c1.api.task.v1.TaskService.Get + description: GetUserOwner gets a user ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.GetUserOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The id field. - readOnly: false + description: The appId field. + type: string + - in: path + name: connector_id + required: true + schema: + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceGetResponse' - description: The TaskServiceGetResponse returns a task view which has a task including JSONPATHs to the expanded items in the expanded array. - summary: Get + $ref: '#/components/schemas/c1.api.app.v2.GetConnectorUserOwnerResponse' + description: GetConnectorUserOwnerResponse is the response for getting a user ownership source on a connector. + summary: Get User Owner tags: - - Task + - Connector Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: terraform-datasource: null - terraform-resource: Task#read - x-speakeasy-group: Task - x-speakeasy-name-override: Get - /api/v1/tasks/{task_id}/action/approve: + terraform-resource: Connector_Owner_User#read + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: GetUserOwner + x-stability-level: draft post: - description: Approve the specified policy step on a task. - operationId: c1.api.task.v1.TaskActionsService.Approve + description: CreateUserOwner creates a user ownership source for a connector. + operationId: c1.api.app.v2.ConnectorOwners.CreateUserOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to approve. - readOnly: false + description: The appId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveResponse' - description: The TaskActionsServiceApproveResponse returns a task view with paths indicating the location of expanded items in the array. - summary: Approve - tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Approve - /api/v1/tasks/{task_id}/action/approve-with-step-up: - post: - description: Approve a task that requires step-up authentication. If a verified step-up transaction ID is provided, the approval is processed immediately. Otherwise, a redirect URL is returned for the caller to complete authentication first. - operationId: c1.api.task.v1.TaskActionsService.ApproveWithStepUp - parameters: - in: path - name: task_id + name: connector_id required: true schema: - description: The ID of the task to approve with step-up. - readOnly: false + description: The connectorId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveWithStepUpRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateConnectorUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceApproveWithStepUpResponse' - description: TaskActionsServiceApproveWithStepUpResponse is the response for approving a task with step-up authentication - summary: Approve With Step Up + $ref: '#/components/schemas/c1.api.app.v2.CreateConnectorUserOwnerResponse' + description: CreateConnectorUserOwnerResponse is the response for creating a user ownership source on a connector. + summary: Create User Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: ApproveWithStepUp - /api/v1/tasks/{task_id}/action/close: - post: - description: Close a task, ending its workflow. - operationId: c1.api.task.v1.TaskActionsService.Close + - Connector Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: Connector_Owner_User#create + x-speakeasy-group: ConnectorOwnersV2 + x-speakeasy-name-override: CreateUserOwner + x-stability-level: draft + /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners: + put: + description: Set replaces all owners for a given app entitlement and role. + operationId: c1.api.app.v2.AppEntitlementOwners.Set parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to close. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCloseRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.SetAppEntitlementOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCloseResponse' - description: The TaskActionsServiceCloseResponse returns a task view with paths indicating the location of expanded items in the array. - summary: Close + $ref: '#/components/schemas/c1.api.app.v2.SetAppEntitlementOwnersResponse' + description: SetAppEntitlementOwnersResponse is the empty response for setting app entitlement owners. + summary: Set tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Close - /api/v1/tasks/{task_id}/action/comment: - post: - description: Post a comment on a task without changing its state. - operationId: c1.api.task.v1.TaskActionsService.Comment + - App Entitlement Owner V2 + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: Set + x-stability-level: draft + /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/entitlements: + get: + description: SearchEntitlementOwners searches for entitlement ownership sources for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.SearchEntitlementOwners parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to be commented on - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCommentRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceCommentResponse' - description: Task actions service comment response returns the task view inluding the expanded array of items that are indicated by the expand mask on the request. - summary: Comment + $ref: '#/components/schemas/c1.api.app.v2.SearchAppEntitlementEntitlementOwnersResponse' + description: SearchAppEntitlementEntitlementOwnersResponse is the response for searching entitlement ownership sources on an entitlement. + summary: Search Entitlement Owners tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Comment - /api/v1/tasks/{task_id}/action/deny: - post: - description: Deny the specified policy step on a task. In multi-step policies, this may route to fallback steps rather than finalizing the task outcome. - operationId: c1.api.task.v1.TaskActionsService.Deny + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Entitlement_Owner_Entitlement#read + terraform-resource: null + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: SearchEntitlementOwners + x-stability-level: draft + ? /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id} + : delete: + description: DeleteEntitlementOwner deletes an entitlement ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.DeleteEntitlementOwner parameters: - in: path - name: task_id + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id required: true schema: - description: The ID of the task to be denied. - readOnly: false + description: The appId field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceDenyRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceDenyResponse' - description: The TaskActionsServiceDenyResponse returns a task view with paths indicating the location of expanded items in the array. - summary: Deny - tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Deny - /api/v1/tasks/{task_id}/action/escalate: - post: - description: Escalate a grant task to use the emergency access policy, bypassing the normal approval flow. Only valid for grant tasks. - operationId: c1.api.task.v1.TaskActionsService.EscalateToEmergencyAccess - parameters: - in: path - name: task_id + name: app_entitlement_ref_id required: true schema: - description: The ID of the task to escalate. - readOnly: false + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceEscalateToEmergencyAccessRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. - summary: Escalate To Emergency Access + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementEntitlementOwnerResponse' + description: DeleteAppEntitlementEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on an entitlement. + summary: Delete Entitlement Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: EscalateToEmergencyAccess - /api/v1/tasks/{task_id}/action/process: - post: - description: Trigger immediate processing of a task, bypassing any scheduled wait. For tasks linked to an external system, this also attempts to sync the external state. - operationId: c1.api.task.v1.TaskActionsService.ProcessNow + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner_Entitlement#delete + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: DeleteEntitlementOwner + x-stability-level: draft + get: + description: GetEntitlementOwner gets an entitlement ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.GetEntitlementOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to process now. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceProcessNowRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceProcessNowResponse' - description: The TaskActionsServiceProcessNowResponse returns the task view after triggering immediate processing. - summary: Process Now + $ref: '#/components/schemas/c1.api.app.v2.GetAppEntitlementEntitlementOwnerResponse' + description: GetAppEntitlementEntitlementOwnerResponse is the response for getting an entitlement ownership source on an entitlement. + summary: Get Entitlement Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: ProcessNow - /api/v1/tasks/{task_id}/action/reassign: + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Entitlement_Owner_Entitlement#read + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: GetEntitlementOwner + x-stability-level: draft post: - description: Reassign a task's current policy step to a different set of users. The target step must be an approval, provision, or form step. - operationId: c1.api.task.v1.TaskActionsService.Reassign + description: CreateEntitlementOwner creates an entitlement ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.CreateEntitlementOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to reassign. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceReassignRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceReassignResponse' - description: The TaskActionsServiceReassignResponse returns a task view with paths indicating the location of expanded items in the array. - summary: Reassign + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementEntitlementOwnerResponse' + description: CreateAppEntitlementEntitlementOwnerResponse is the response for creating an entitlement ownership source on an entitlement. + summary: Create Entitlement Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Reassign - /api/v1/tasks/{task_id}/action/reset: - post: - description: Reset a task and recalculate its policy from scratch. Unlike Restart, this re-evaluates which policy applies to the task. - operationId: c1.api.task.v1.TaskActionsService.HardReset + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner_Entitlement#create + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: CreateEntitlementOwner + x-stability-level: draft + /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/users: + get: + description: SearchUserOwners searches for user ownership sources of this app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.SearchUserOwners parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to reset. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceHardResetRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceHardResetResponse' - description: The TaskActionsServiceHardResetResponse returns the updated task after a hard reset. - summary: Hard Reset + $ref: '#/components/schemas/c1.api.app.v2.SearchAppEntitlementUserOwnersResponse' + description: SearchAppEntitlementUserOwnersResponse is the response for searching user ownership sources on an entitlement. + summary: Search User Owners tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: HardReset - /api/v1/tasks/{task_id}/action/restart: - post: - description: Restart a task, returning it to the beginning of its current policy workflow. - operationId: c1.api.task.v1.TaskActionsService.Restart + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Entitlement_Owner_User#read + terraform-resource: null + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: SearchUserOwners + x-stability-level: draft + /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/users/{role_slug}/{user_ref_id}: + delete: + description: DeleteUserOwner deletes a user ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.DeleteUserOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to restart. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceRestartRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceRestartResponse' - description: The TaskActionsServiceRestartResponse returns the updated task after restarting. - summary: Restart + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementUserOwnerResponse' + description: DeleteAppEntitlementUserOwnerResponse is the empty response for deleting a user ownership source on an entitlement. + summary: Delete User Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: Restart - /api/v1/tasks/{task_id}/action/skip-step: - post: - description: Skip a specific policy step in a task, advancing the task to the next step in the workflow. - operationId: c1.api.task.v1.TaskActionsService.SkipStep + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner_User#delete + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: DeleteUserOwner + x-stability-level: draft + get: + description: GetUserOwner gets a user ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.GetUserOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task containing the step to skip. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceSkipStepRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. - summary: Skip Step + $ref: '#/components/schemas/c1.api.app.v2.GetAppEntitlementUserOwnerResponse' + description: GetAppEntitlementUserOwnerResponse is the response for getting a user ownership source on an entitlement. + summary: Get User Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: SkipStep - /api/v1/tasks/{task_id}/action/update-grant-duration: + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Entitlement_Owner_User#read + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: GetUserOwner + x-stability-level: draft post: - description: Update the grant duration for a task. Only applies to grant tasks with a single entitlement that are not in a provision step. The new duration must not exceed the entitlement's maximum allowed provision time. - operationId: c1.api.task.v1.TaskActionsService.UpdateGrantDuration + description: CreateUserOwner creates a user ownership source for an app entitlement. + operationId: c1.api.app.v2.AppEntitlementOwners.CreateUserOwner parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task to update the grant duration for. - readOnly: false + description: The appId field. + type: string + - in: path + name: entitlement_id + required: true + schema: + description: The entitlementId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceUpdateGrantDurationRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. - summary: Update Grant Duration + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementUserOwnerResponse' + description: CreateAppEntitlementUserOwnerResponse is the response for creating a user ownership source on an entitlement. + summary: Create User Owner tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: UpdateGrantDuration - /api/v1/tasks/{task_id}/action/update-request-data: - post: - description: Update the request data on a task that is currently in a form step. The submitted data is validated against the form schema before being applied. - operationId: c1.api.task.v1.TaskActionsService.UpdateRequestData + - App Entitlement Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Entitlement_Owner_User#create + x-speakeasy-group: AppEntitlementOwnersV2 + x-speakeasy-name-override: CreateUserOwner + x-stability-level: draft + /api/v2/apps/{app_id}/owners: + put: + description: Set replaces all user owners for a given app and role. + operationId: c1.api.app.v2.AppOwners.Set parameters: - in: path - name: task_id + name: app_id required: true schema: - description: The ID of the task containing the request data to update. - readOnly: false + description: The appId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskActionsServiceUpdateRequestDataRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.SetAppOwnersRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.task.v1.TaskServiceActionResponse' - description: A generic response for task action endpoints, containing the updated task and the ID of the action that was created. - summary: Update Request Data + $ref: '#/components/schemas/c1.api.app.v2.SetAppOwnersResponse' + description: SetAppOwnersResponse is the empty response for setting app owners. + summary: Set tags: - - Task - x-speakeasy-group: TaskActions - x-speakeasy-name-override: UpdateRequestData - /api/v1/users: + - App Owner V2 + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: Set + x-stability-level: draft + /api/v2/apps/{app_id}/owners/entitlements: get: - description: List users. - operationId: c1.api.user.v1.UserService.List + description: SearchEntitlementOwners searches for entitlement ownership sources for an app. + operationId: c1.api.app.v2.AppOwners.SearchEntitlementOwners parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.UserServiceListResponse' - description: The UserServiceListResponse message contains a list of results and a nextPageToken if applicable. - summary: List + $ref: '#/components/schemas/c1.api.app.v2.SearchAppEntitlementOwnersResponse' + description: SearchEntitlementOwnersResponse is the response for searching entitlement ownership sources. + summary: Search Entitlement Owners tags: - - User - x-speakeasy-group: User - x-speakeasy-name-override: List - /api/v1/users/{id}: - get: - description: Get a user by ID. - operationId: c1.api.user.v1.UserService.Get + - App Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Owner_Entitlement#read + terraform-resource: null + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: SearchEntitlementOwners + x-stability-level: draft + /api/v2/apps/{app_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id}: + delete: + description: DeleteEntitlementOwner deletes an entitlement ownership source for an app. + operationId: c1.api.app.v2.AppOwners.DeleteEntitlementOwner parameters: - in: path - name: id + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id required: true schema: description: The id field. - readOnly: false type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.UserServiceGetResponse' - description: The UserServiceGetResponse returns a user view which has a user including JSONPATHs to the expanded items in the expanded array. - summary: Get + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppEntitlementOwnerResponse' + description: DeleteEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source. + summary: Delete Entitlement Owner tags: - - User - x-speakeasy-group: User - x-speakeasy-name-override: Get - /api/v1/users/{user_id}/profile-types: + - App Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner_Entitlement#delete + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: DeleteEntitlementOwner + x-stability-level: draft get: - description: Retrieve the profile types associated with a user across their connected apps. - operationId: c1.api.user.v1.UserService.GetUserProfileTypes + description: GetEntitlementOwner gets an entitlement ownership source for an app. + operationId: c1.api.app.v2.AppOwners.GetEntitlementOwner parameters: - in: path - name: user_id + name: app_id required: true schema: - description: The ID of the user whose profile types are being retrieved. - readOnly: false + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.GetUserProfileTypesResponse' - description: GetUserProfileTypesResponse is the response containing the profile types for a user. - summary: Get User Profile Types + $ref: '#/components/schemas/c1.api.app.v2.GetAppEntitlementOwnerResponse' + description: GetEntitlementOwnerResponse is the response for getting an entitlement ownership source. + summary: Get Entitlement Owner tags: - - User - x-speakeasy-group: User - x-speakeasy-name-override: GetUserProfileTypes - /api/v1/users/{user_id}/set-delegation-by-admin: + - App Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Owner_Entitlement#read + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: GetEntitlementOwner + x-stability-level: draft post: - description: Set or update an expiring delegation binding for a user, allowing an admin to designate a temporary delegate. - operationId: c1.api.user.v1.UserService.SetExpiringUserDelegationBindingByAdmin + description: CreateEntitlementOwner creates an entitlement ownership source for an app. + operationId: c1.api.app.v2.AppOwners.CreateEntitlementOwner parameters: - in: path - name: user_id + name: app_id required: true schema: - description: The ID of the user whose tasks will be delegated. - readOnly: false + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.SetExpiringUserDelegationBindingByAdminRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.user.v1.SetExpiringUserDelegationBindingByAdminResponse' - description: SetExpiringUserDelegationBindingByAdminResponse is the response containing the created or updated delegation binding. - summary: Set Expiring User Delegation Binding By Admin + $ref: '#/components/schemas/c1.api.app.v2.CreateAppEntitlementOwnerResponse' + description: CreateEntitlementOwnerResponse is the response for creating an entitlement ownership source. + summary: Create Entitlement Owner tags: - - User - x-speakeasy-group: User - x-speakeasy-name-override: SetExpiringUserDelegationBindingByAdmin - /api/v1/vaults: - post: - description: Create provisions a new external secret storage vault and returns it. - operationId: c1.api.vault.v1.VaultService.Create - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceCreateRequest' + - App Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Owner_Entitlement#create + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: CreateEntitlementOwner + x-stability-level: draft + /api/v2/apps/{app_id}/owners/users: + get: + description: SearchUserOwners searches for user ownership sources for an app. + operationId: c1.api.app.v2.AppOwners.SearchUserOwners + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. + type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceCreateResponse' - description: VaultServiceCreateResponse is the response message for creating a new vault. - summary: Create + $ref: '#/components/schemas/c1.api.app.v2.SearchAppUserOwnersResponse' + description: SearchUserOwnersResponse is the response for searching user ownership sources. + summary: Search User Owners tags: - - Vault + - App Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Vault#create - x-speakeasy-group: Vault - x-speakeasy-name-override: Create + terraform-datasource: App_Owner_User#read + terraform-resource: null + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: SearchUserOwners x-stability-level: draft - /api/v1/vaults/{id}: + /api/v2/apps/{app_id}/owners/users/{role_slug}/{user_ref_id}: delete: - description: Delete a vault by its ID. Active connectors using this vault will no longer be able to access their stored credentials. - operationId: c1.api.vault.v1.VaultService.Delete + description: DeleteUserOwner deletes a user ownership source for an app. + operationId: c1.api.app.v2.AppOwners.DeleteUserOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the vault to delete. - readOnly: false + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceDeleteResponse' - description: Empty response body. Status code indicates success. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserOwnerResponse' + description: DeleteUserOwnerResponse is the empty response for deleting a user ownership source. + summary: Delete User Owner tags: - - Vault + - App Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Vault#delete - x-speakeasy-group: Vault - x-speakeasy-name-override: Delete + terraform-resource: App_Owner_User#delete + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: DeleteUserOwner x-stability-level: draft get: - description: Get returns a single vault by its ID. - operationId: c1.api.vault.v1.VaultService.Get + description: GetUserOwner gets a user ownership source for an app. + operationId: c1.api.app.v2.AppOwners.GetUserOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the vault to retrieve. - readOnly: false + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceGetResponse' - description: VaultServiceGetResponse is the response message containing the requested vault. - summary: Get + $ref: '#/components/schemas/c1.api.app.v2.GetAppUserOwnerResponse' + description: GetUserOwnerResponse is the response for getting a user ownership source. + summary: Get User Owner tags: - - Vault + - App Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: terraform-datasource: null - terraform-resource: Vault#read - x-speakeasy-group: Vault - x-speakeasy-name-override: Get + terraform-resource: App_Owner_User#read + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: GetUserOwner x-stability-level: draft post: - description: Update modifies an existing vault's properties using a field mask. - operationId: c1.api.vault.v1.VaultService.Update + description: CreateUserOwner creates a user ownership source for an app. + operationId: c1.api.app.v2.AppOwners.CreateUserOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the vault. - readOnly: false + description: The appId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.vault.v1.VaultServiceUpdateResponse' - description: VaultServiceUpdateResponse is the response message containing the updated vault. - summary: Update + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserOwnerResponse' + description: CreateUserOwnerResponse is the response for creating a user ownership source. + summary: Create User Owner tags: - - Vault + - App Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Vault#update - x-speakeasy-group: Vault - x-speakeasy-name-override: Update + terraform-resource: App_Owner_User#create + x-speakeasy-group: AppOwnersV2 + x-speakeasy-name-override: CreateUserOwner x-stability-level: draft - /api/v1/webhooks: + /api/v2/apps/{app_id}/resource_types/{resource_type_id}/resources/{resource_id}/owners: + put: + description: Set replaces all owners for a given app resource and role. + operationId: c1.api.app.v2.AppResourceOwnersV2.Set + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.SetAppResourceOwnersV2RequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.SetAppResourceOwnersV2Response' + description: SetAppResourceOwnersV2Response is the empty response for setting app resource owners. + summary: Set + tags: + - App Resource Owner V2 + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: Set + x-stability-level: draft + /api/v2/apps/{app_id}/resource_types/{resource_type_id}/resources/{resource_id}/owners/entitlements: get: - description: List all webhook subscriptions in the tenant, with pagination. - operationId: c1.api.webhooks.v1.WebhooksService.List + description: SearchEntitlementOwners searches for entitlement ownership sources of this app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.SearchEntitlementOwners parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string - in: query name: page_size schema: - description: The maximum number of webhooks to return per page. + description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: - description: The pagination token from a previous list response to fetch the next page. - readOnly: false + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceListResponse' - description: Successful response - summary: List - tags: - - Webhook - x-speakeasy-group: Webhooks - x-speakeasy-name-override: List - post: - description: Create a new webhook subscription to receive event notifications at the specified URL. - operationId: c1.api.webhooks.v1.WebhooksService.Create - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceCreateRequest' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceCreateResponse' - description: Successful response - summary: Create + $ref: '#/components/schemas/c1.api.app.v2.SearchAppResourceEntitlementOwnersResponse' + description: SearchAppResourceEntitlementOwnersResponse is the response for searching entitlement ownership sources on a resource. + summary: Search Entitlement Owners tags: - - Webhook + - App Resource Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Webhook#create - x-speakeasy-group: Webhooks - x-speakeasy-name-override: Create - /api/v1/webhooks/{id}: - delete: - description: Delete a webhook subscription, stopping all future event deliveries to its URL. - operationId: c1.api.webhooks.v1.WebhooksService.Delete + terraform-datasource: App_Resource_Owner_Entitlement#read + terraform-resource: null + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: SearchEntitlementOwners + x-stability-level: draft + ? /api/v2/apps/{app_id}/resource_types/{resource_type_id}/resources/{resource_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id} + : delete: + description: DeleteEntitlementOwner deletes an entitlement ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.DeleteEntitlementOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The ID of the webhook to delete. - readOnly: false + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceDeleteRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppResourceEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceDeleteResponse' - description: Empty response body. Status code indicates success. - summary: Delete + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppResourceEntitlementOwnerResponse' + description: DeleteAppResourceEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a resource. + summary: Delete Entitlement Owner tags: - - Webhook + - App Resource Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Webhook#delete - x-speakeasy-group: Webhooks - x-speakeasy-name-override: Delete + terraform-resource: App_Resource_Owner_Entitlement#delete + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: DeleteEntitlementOwner + x-stability-level: draft get: - description: Retrieve a single webhook by its ID. - operationId: c1.api.webhooks.v1.WebhooksService.Get + description: GetEntitlementOwner gets an entitlement ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.GetEntitlementOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The ID of the webhook to retrieve. - readOnly: false + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceGetResponse' - description: Successful response - summary: Get + $ref: '#/components/schemas/c1.api.app.v2.GetAppResourceEntitlementOwnerResponse' + description: GetAppResourceEntitlementOwnerResponse is the response for getting an entitlement ownership source on a resource. + summary: Get Entitlement Owner tags: - - Webhook + - App Resource Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: terraform-datasource: null - terraform-resource: Webhook#read - x-speakeasy-group: Webhooks - x-speakeasy-name-override: Get + terraform-resource: App_Resource_Owner_Entitlement#read + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: GetEntitlementOwner + x-stability-level: draft post: - description: Update an existing webhook subscription's properties, such as its URL or display name. - operationId: c1.api.webhooks.v1.WebhooksService.Update + description: CreateEntitlementOwner creates an entitlement ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.CreateEntitlementOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The unique identifier of the webhook. - readOnly: false + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceUpdateRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppResourceEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceUpdateResponse' - description: Successful response - summary: Update + $ref: '#/components/schemas/c1.api.app.v2.CreateAppResourceEntitlementOwnerResponse' + description: CreateAppResourceEntitlementOwnerResponse is the response for creating an entitlement ownership source on a resource. + summary: Create Entitlement Owner tags: - - Webhook + - App Resource Owner V2 x-speakeasy-entity-missing-codes: - 404 x-speakeasy-entity-operation: - terraform-resource: Webhook#update - x-speakeasy-group: Webhooks - x-speakeasy-name-override: Update - /api/v1/webhooks/{id}/test: - post: - description: Send a sample event to the webhook URL to verify that the endpoint is reachable and responding correctly. - operationId: c1.api.webhooks.v1.WebhooksService.Test + terraform-resource: App_Resource_Owner_Entitlement#create + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: CreateEntitlementOwner + x-stability-level: draft + /api/v2/apps/{app_id}/resource_types/{resource_type_id}/resources/{resource_id}/owners/users: + get: + description: SearchUserOwners searches for user ownership sources of this app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.SearchUserOwners parameters: - in: path - name: id + name: app_id required: true schema: - description: The ID of the webhook to send a test event to. - readOnly: false + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: query + name: page_size + schema: + description: The pageSize field. + format: int32 + type: integer + - in: query + name: page_token + schema: + description: The pageToken field. + type: string + - in: query + name: role_slug + schema: + description: The roleSlug field. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceTestRequestInput' - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.webhooks.v1.WebhooksServiceTestResponse' - description: Successful response - summary: Test - tags: - - Webhook - x-speakeasy-group: Webhooks - x-speakeasy-name-override: Test - /api/v1/workload_federation/providers: - get: - description: ListProviders lists all providers for the tenant. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.ListProviders - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceListProvidersResponse' - description: Successful response - summary: List Providers - tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: ListProviders - post: - description: |- - CreateProvider registers a new external OIDC issuer for the tenant. - Validates the issuer URL via OIDC discovery synchronously. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.CreateProvider - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderRequest' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceCreateProviderResponse' - description: Successful response - summary: Create Provider + $ref: '#/components/schemas/c1.api.app.v2.SearchAppResourceUserOwnersResponse' + description: SearchAppResourceUserOwnersResponse is the response for searching user ownership sources on a resource. + summary: Search User Owners tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: CreateProvider - /api/v1/workload_federation/providers/{id}: + - App Resource Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: App_Resource_Owner_User#read + terraform-resource: null + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: SearchUserOwners + x-stability-level: draft + /api/v2/apps/{app_id}/resource_types/{resource_type_id}/resources/{resource_id}/owners/users/{role_slug}/{user_ref_id}: delete: - description: DeleteProvider deletes a provider. Fails if active trusts reference it. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.DeleteProvider + description: DeleteUserOwner deletes a user ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.DeleteUserOwner parameters: - in: path - name: id + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id required: true schema: - description: The id field. - readOnly: false + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderRequestInput' + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppResourceUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceDeleteProviderResponse' - description: Successful response - summary: Delete Provider + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppResourceUserOwnerResponse' + description: DeleteAppResourceUserOwnerResponse is the empty response for deleting a user ownership source on a resource. + summary: Delete User Owner tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: DeleteProvider + - App Resource Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner_User#delete + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: DeleteUserOwner + x-stability-level: draft get: - description: GetProvider returns a provider by ID. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.GetProvider + description: GetUserOwner gets a user ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.GetUserOwner parameters: - in: path - name: id + name: app_id required: true schema: - description: The id field. - readOnly: false + description: The appId field. type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceGetProviderResponse' - description: Successful response - summary: Get Provider - tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: GetProvider - patch: - description: |- - UpdateProvider updates a provider's mutable fields (display_name, description, disabled). - The issuer_url is immutable after creation. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.UpdateProvider - parameters: - in: path - name: id + name: resource_type_id required: true schema: - description: The unique ID of the provider. - readOnly: true + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. type: string - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceUpdateProviderResponse' - description: Successful response - summary: Update Provider + $ref: '#/components/schemas/c1.api.app.v2.GetAppResourceUserOwnerResponse' + description: GetAppResourceUserOwnerResponse is the response for getting a user ownership source on a resource. + summary: Get User Owner tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: UpdateProvider - /api/v1/workload_federation/test-cel: + - App Resource Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-datasource: null + terraform-resource: App_Resource_Owner_User#read + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: GetUserOwner + x-stability-level: draft post: - description: |- - TestCEL evaluates a CEL expression against provided claims without - requiring a JWT, provider, or trust. Used for expression authoring. - operationId: c1.api.workload_federation.v1.WorkloadFederationService.TestCEL + description: CreateUserOwner creates a user ownership source for an app resource. + operationId: c1.api.app.v2.AppResourceOwnersV2.CreateUserOwner + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: resource_type_id + required: true + schema: + description: The resourceTypeId field. + type: string + - in: path + name: resource_id + required: true + schema: + description: The resourceId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true + schema: + description: The id of the user. + type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestCELRequest' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppResourceUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.workload_federation.v1.WorkloadFederationServiceTestCELResponse' - description: Successful response - summary: Test Cel + $ref: '#/components/schemas/c1.api.app.v2.CreateAppResourceUserOwnerResponse' + description: CreateAppResourceUserOwnerResponse is the response for creating a user ownership source on a resource. + summary: Create User Owner tags: - - Workload Federation - x-speakeasy-group: WorkloadFederation - x-speakeasy-name-override: TestCEL - /api/v2/apps/{app_id}/connectors/{connector_id}/owners: + - App Resource Owner V2 + x-speakeasy-entity-missing-codes: + - 404 + x-speakeasy-entity-operation: + terraform-resource: App_Resource_Owner_User#create + x-speakeasy-group: AppResourceOwnersV2 + x-speakeasy-name-override: CreateUserOwner + x-stability-level: draft + /api/v2/apps/{app_id}/users/{user_id}/owners: put: - description: Set replaces all owners for a given connector and role. - operationId: c1.api.app.v2.ConnectorOwners.Set + description: Set replaces all owners for a given app user and role. + operationId: c1.api.app.v2.AppUserOwnersV2.Set parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: connector_id + name: user_id required: true schema: - description: The connectorId field. - readOnly: false + description: The userId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetConnectorOwnersV2RequestInput' + $ref: '#/components/schemas/c1.api.app.v2.SetAppUserOwnersV2RequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetConnectorOwnersV2Response' - description: SetConnectorOwnersV2Response is the empty response for setting connector owners. + $ref: '#/components/schemas/c1.api.app.v2.SetAppUserOwnersV2Response' + description: SetAppUserOwnersV2Response is the empty response for setting app user owners. summary: Set tags: - - Connector Owner V2 - x-speakeasy-group: ConnectorOwnersV2 + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 x-speakeasy-name-override: Set x-stability-level: draft - /api/v2/apps/{app_id}/connectors/{connector_id}/owners/entitlements: + /api/v2/apps/{app_id}/users/{user_id}/owners/entitlements: get: - description: SearchEntitlementOwners searches for the entitlement ownership for a connector. - operationId: c1.api.app.v2.ConnectorOwners.SearchEntitlementOwners + description: SearchEntitlementOwners searches for entitlement ownership sources of this app user. + operationId: c1.api.app.v2.AppUserOwnersV2.SearchEntitlementOwners parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: connector_id + name: user_id required: true schema: - description: The connectorId field. - readOnly: false + description: The userId field. type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string - in: query name: role_slug schema: description: The roleSlug field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchConnectorEntitlementOwnersResponse' - description: SearchConnectorEntitlementOwnersResponse is the response for searching entitlement ownership sources on a connector. + $ref: '#/components/schemas/c1.api.app.v2.SearchAppUserEntitlementOwnersResponse' + description: SearchAppUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on an app user. summary: Search Entitlement Owners tags: - - Connector Owner V2 - x-speakeasy-group: ConnectorOwnersV2 + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 x-speakeasy-name-override: SearchEntitlementOwners x-stability-level: draft - /api/v2/apps/{app_id}/connectors/{connector_id}/owners/users: - get: - description: SearchUserOwners searches for users who are owners of this connector. - operationId: c1.api.app.v2.ConnectorOwners.SearchUserOwners + /api/v2/apps/{app_id}/users/{user_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id}: + delete: + description: DeleteEntitlementOwner deletes an entitlement ownership source for an app user. + operationId: c1.api.app.v2.AppUserOwnersV2.DeleteEntitlementOwner parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: connector_id + name: user_id required: true schema: - description: The connectorId field. - readOnly: false + description: The userId field. type: string - - in: query - name: page_size + - in: path + name: role_slug + required: true schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true schema: - description: The pageToken field. - readOnly: false + description: The appId field. type: string - - in: query - name: role_slug + - in: path + name: app_entitlement_ref_id + required: true schema: - description: The roleSlug field. - readOnly: false + description: The id field. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchConnectorUserOwnersResponse' - description: SearchConnectorUserOwnersResponse is the response for searching user ownership sources on a connector. - summary: Search User Owners + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserEntitlementOwnerResponse' + description: DeleteAppUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on an app user. + summary: Delete Entitlement Owner tags: - - Connector Owner V2 - x-speakeasy-group: ConnectorOwnersV2 - x-speakeasy-name-override: SearchUserOwners + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 + x-speakeasy-name-override: DeleteEntitlementOwner x-stability-level: draft - /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners: - put: - description: Set replaces all owners for a given app entitlement and role. - operationId: c1.api.app.v2.AppEntitlementOwners.Set + post: + description: CreateEntitlementOwner creates an entitlement ownership source for an app user. + operationId: c1.api.app.v2.AppUserOwnersV2.CreateEntitlementOwner parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: entitlement_id + name: user_id required: true schema: - description: The entitlementId field. - readOnly: false + description: The userId field. + type: string + - in: path + name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: app_entitlement_ref_app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: app_entitlement_ref_id + required: true + schema: + description: The id field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetAppEntitlementOwnersV2RequestInput' + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetAppEntitlementOwnersV2Response' - description: SetAppEntitlementOwnersV2Response is the empty response for setting app entitlement owners. - summary: Set + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserEntitlementOwnerResponse' + description: CreateAppUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on an app user. + summary: Create Entitlement Owner tags: - - App Entitlement Owner V2 - x-speakeasy-group: AppEntitlementOwnersV2 - x-speakeasy-name-override: Set + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 + x-speakeasy-name-override: CreateEntitlementOwner x-stability-level: draft - /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/entitlements: + /api/v2/apps/{app_id}/users/{user_id}/owners/users: get: - description: SearchEntitlementOwners searches for the entitlement ownership for an app entitlement. - operationId: c1.api.app.v2.AppEntitlementOwners.SearchEntitlementOwners + description: SearchUserOwners searches for user ownership sources of this app user. + operationId: c1.api.app.v2.AppUserOwnersV2.SearchUserOwners parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: entitlement_id + name: user_id required: true schema: - description: The entitlementId field. - readOnly: false + description: The userId field. type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string - in: query name: role_slug schema: - description: Empty means "any role" (no filter). - readOnly: false + description: The roleSlug field. type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchAppEntitlementEntitlementOwnersResponse' - description: SearchAppEntitlementEntitlementOwnersResponse is the response for searching entitlement ownership sources on an entitlement. - summary: Search Entitlement Owners + $ref: '#/components/schemas/c1.api.app.v2.SearchAppUserUserOwnersResponse' + description: SearchAppUserUserOwnersResponse is the response for searching user ownership sources on an app user. + summary: Search User Owners tags: - - App Entitlement Owner V2 - x-speakeasy-group: AppEntitlementOwnersV2 - x-speakeasy-name-override: SearchEntitlementOwners + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 + x-speakeasy-name-override: SearchUserOwners x-stability-level: draft - /api/v2/apps/{app_id}/entitlements/{entitlement_id}/owners/users: - get: - description: SearchUserOwners searches for users who are owners of this app entitlement. - operationId: c1.api.app.v2.AppEntitlementOwners.SearchUserOwners + /api/v2/apps/{app_id}/users/{user_id}/owners/users/{role_slug}/{user_ref_id}: + delete: + description: DeleteUserOwner deletes a user ownership source for an app user. + operationId: c1.api.app.v2.AppUserOwnersV2.DeleteUserOwner parameters: - in: path name: app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path - name: entitlement_id + name: user_id required: true schema: - description: The entitlementId field. - readOnly: false + description: The userId field. type: string - - in: query - name: page_size + - in: path + name: role_slug + required: true schema: - description: The pageSize field. - format: int32 - readOnly: false - type: integer - - in: query - name: page_token + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true schema: - description: The pageToken field. - readOnly: false + description: The id of the user. type: string - - in: query + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserUserOwnerRequestInput' + responses: + "200": + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.DeleteAppUserUserOwnerResponse' + description: DeleteAppUserUserOwnerResponse is the empty response for deleting a user ownership source on an app user. + summary: Delete User Owner + tags: + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 + x-speakeasy-name-override: DeleteUserOwner + x-stability-level: draft + post: + description: CreateUserOwner creates a user ownership source for an app user. + operationId: c1.api.app.v2.AppUserOwnersV2.CreateUserOwner + parameters: + - in: path + name: app_id + required: true + schema: + description: The appId field. + type: string + - in: path + name: user_id + required: true + schema: + description: The userId field. + type: string + - in: path name: role_slug + required: true + schema: + description: The roleSlug field. + type: string + - in: path + name: user_ref_id + required: true schema: - description: Empty means "any role" (no filter). - readOnly: false + description: The id of the user. type: string + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchAppEntitlementUserOwnersResponse' - description: SearchAppEntitlementUserOwnersResponse is the response for searching user ownership sources on an entitlement. - summary: Search User Owners + $ref: '#/components/schemas/c1.api.app.v2.CreateAppUserUserOwnerResponse' + description: CreateAppUserUserOwnerResponse is the response for creating a user ownership source on an app user. + summary: Create User Owner tags: - - App Entitlement Owner V2 - x-speakeasy-group: AppEntitlementOwnersV2 - x-speakeasy-name-override: SearchUserOwners + - App User Owner V2 + x-speakeasy-group: AppUserOwnersV2 + x-speakeasy-name-override: CreateUserOwner x-stability-level: draft - /api/v2/apps/{app_id}/owners: + /api/v2/users/{user_id}/owners: put: - description: Set replaces all user owners for a given app and role. - operationId: c1.api.app.v2.AppOwners.Set + description: Set replaces all owners for a given user (service account) and role. + operationId: c1.api.user.v2.UserOwnersV2.Set parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetAppOwnersRequestInput' + $ref: '#/components/schemas/c1.api.user.v2.SetUserOwnersV2RequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SetAppOwnersResponse' - description: SetAppOwnersResponse is the empty response for setting app owners. + $ref: '#/components/schemas/c1.api.user.v2.SetUserOwnersV2Response' + description: SetUserOwnersV2Response is the empty response for setting user owners. summary: Set tags: - - App Owner V2 - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: Set x-stability-level: draft - /api/v2/apps/{app_id}/owners/entitlements: + /api/v2/users/{user_id}/owners/entitlements: get: - description: SearchEntitlementOwners searches for entitlement ownership sources for an app. - operationId: c1.api.app.v2.AppOwners.SearchEntitlementOwners + description: SearchEntitlementOwners searches for entitlement ownership sources of this user (service account). + operationId: c1.api.user.v2.UserOwnersV2.SearchEntitlementOwners parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string - in: query name: role_slug schema: description: The roleSlug field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchEntitlementOwnersResponse' - description: SearchEntitlementOwnersResponse is the response for searching entitlement ownership sources. + $ref: '#/components/schemas/c1.api.user.v2.SearchUserEntitlementOwnersResponse' + description: SearchUserEntitlementOwnersResponse is the response for searching entitlement ownership sources on a user (service account). summary: Search Entitlement Owners tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: App_Owner_Entitlement#read - terraform-resource: null - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: SearchEntitlementOwners x-stability-level: draft - /api/v2/apps/{app_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id}: + /api/v2/users/{user_id}/owners/entitlements/{role_slug}/{app_entitlement_ref_app_id}/{app_entitlement_ref_id}: delete: - description: DeleteEntitlementOwner deletes an entitlement ownership source for an app. - operationId: c1.api.app.v2.AppOwners.DeleteEntitlementOwner + description: DeleteEntitlementOwner deletes an entitlement ownership source for a user (service account). + operationId: c1.api.user.v2.UserOwnersV2.DeleteEntitlementOwner parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: path name: role_slug required: true schema: description: The roleSlug field. - readOnly: false type: string - in: path name: app_entitlement_ref_app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path name: app_entitlement_ref_id required: true schema: description: The id field. - readOnly: false type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.DeleteEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.user.v2.DeleteUserEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.DeleteEntitlementOwnerResponse' - description: DeleteEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source. + $ref: '#/components/schemas/c1.api.user.v2.DeleteUserEntitlementOwnerResponse' + description: DeleteUserEntitlementOwnerResponse is the empty response for deleting an entitlement ownership source on a user (service account). summary: Delete Entitlement Owner tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner_Entitlement#delete - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: DeleteEntitlementOwner x-stability-level: draft - get: - description: GetEntitlementOwner gets an entitlement ownership source for an app. - operationId: c1.api.app.v2.AppOwners.GetEntitlementOwner - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: role_slug - required: true - schema: - description: The roleSlug field. - readOnly: false - type: string - - in: path - name: app_entitlement_ref_app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: app_entitlement_ref_id - required: true - schema: - description: The id field. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v2.GetEntitlementOwnerResponse' - description: GetEntitlementOwnerResponse is the response for getting an entitlement ownership source. - summary: Get Entitlement Owner - tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Owner_Entitlement#read - x-speakeasy-group: AppOwnersV2 - x-speakeasy-name-override: GetEntitlementOwner - x-stability-level: draft post: - description: CreateEntitlementOwner creates an entitlement ownership source for an app. - operationId: c1.api.app.v2.AppOwners.CreateEntitlementOwner + description: CreateEntitlementOwner creates an entitlement ownership source for a user (service account). + operationId: c1.api.user.v2.UserOwnersV2.CreateEntitlementOwner parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: path name: role_slug required: true schema: description: The roleSlug field. - readOnly: false type: string - in: path name: app_entitlement_ref_app_id required: true schema: description: The appId field. - readOnly: false type: string - in: path name: app_entitlement_ref_id required: true schema: description: The id field. - readOnly: false type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.CreateEntitlementOwnerRequestInput' + $ref: '#/components/schemas/c1.api.user.v2.CreateUserEntitlementOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.CreateEntitlementOwnerResponse' - description: CreateEntitlementOwnerResponse is the response for creating an entitlement ownership source. + $ref: '#/components/schemas/c1.api.user.v2.CreateUserEntitlementOwnerResponse' + description: CreateUserEntitlementOwnerResponse is the response for creating an entitlement ownership source on a user (service account). summary: Create Entitlement Owner tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner_Entitlement#create - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: CreateEntitlementOwner x-stability-level: draft - /api/v2/apps/{app_id}/owners/users: + /api/v2/users/{user_id}/owners/users: get: - description: SearchUserOwners searches for user ownership sources for an app. - operationId: c1.api.app.v2.AppOwners.SearchUserOwners + description: SearchUserOwners searches for user ownership sources of this user (service account). + operationId: c1.api.user.v2.UserOwnersV2.SearchUserOwners parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: query name: page_size schema: description: The pageSize field. format: int32 - readOnly: false type: integer - in: query name: page_token schema: description: The pageToken field. - readOnly: false type: string - in: query name: role_slug schema: description: The roleSlug field. - readOnly: false type: string responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.SearchUserOwnersResponse' - description: SearchUserOwnersResponse is the response for searching user ownership sources. + $ref: '#/components/schemas/c1.api.user.v2.SearchUserOwnersResponse' + description: SearchUserOwnersResponse is the response for searching user ownership sources on a user (service account). summary: Search User Owners tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: App_Owner_User#read - terraform-resource: null - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: SearchUserOwners x-stability-level: draft - /api/v2/apps/{app_id}/owners/users/{role_slug}/{user_ref_id}: + /api/v2/users/{user_id}/owners/users/{role_slug}/{user_ref_id}: delete: - description: DeleteUserOwner deletes a user ownership source for an app. - operationId: c1.api.app.v2.AppOwners.DeleteUserOwner + description: DeleteUserOwner deletes a user ownership source for a user (service account). + operationId: c1.api.user.v2.UserOwnersV2.DeleteUserOwner parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: path name: role_slug required: true schema: description: The roleSlug field. - readOnly: false type: string - in: path name: user_ref_id required: true schema: description: The id of the user. - readOnly: false type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.DeleteUserOwnerRequestInput' + $ref: '#/components/schemas/c1.api.user.v2.DeleteUserUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.DeleteUserOwnerResponse' - description: DeleteUserOwnerResponse is the empty response for deleting a user ownership source. + $ref: '#/components/schemas/c1.api.user.v2.DeleteUserUserOwnerResponse' + description: DeleteUserUserOwnerResponse is the empty response for deleting a user ownership source on a user (service account). summary: Delete User Owner tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner_User#delete - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: DeleteUserOwner x-stability-level: draft - get: - description: GetUserOwner gets a user ownership source for an app. - operationId: c1.api.app.v2.AppOwners.GetUserOwner - parameters: - - in: path - name: app_id - required: true - schema: - description: The appId field. - readOnly: false - type: string - - in: path - name: role_slug - required: true - schema: - description: The roleSlug field. - readOnly: false - type: string - - in: path - name: user_ref_id - required: true - schema: - description: The id of the user. - readOnly: false - type: string - responses: - "200": - content: - application/json: - schema: - $ref: '#/components/schemas/c1.api.app.v2.GetUserOwnerResponse' - description: GetUserOwnerResponse is the response for getting a user ownership source. - summary: Get User Owner - tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-datasource: null - terraform-resource: App_Owner_User#read - x-speakeasy-group: AppOwnersV2 - x-speakeasy-name-override: GetUserOwner - x-stability-level: draft post: - description: CreateUserOwner creates a user ownership source for an app. - operationId: c1.api.app.v2.AppOwners.CreateUserOwner + description: CreateUserOwner creates a user ownership source for a user (service account). + operationId: c1.api.user.v2.UserOwnersV2.CreateUserOwner parameters: - in: path - name: app_id + name: user_id required: true schema: - description: The appId field. - readOnly: false + description: The userId field. type: string - in: path name: role_slug required: true schema: description: The roleSlug field. - readOnly: false type: string - in: path name: user_ref_id required: true schema: description: The id of the user. - readOnly: false type: string requestBody: content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.CreateUserOwnerRequestInput' + $ref: '#/components/schemas/c1.api.user.v2.CreateUserUserOwnerRequestInput' responses: "200": content: application/json: schema: - $ref: '#/components/schemas/c1.api.app.v2.CreateUserOwnerResponse' - description: CreateUserOwnerResponse is the response for creating a user ownership source. + $ref: '#/components/schemas/c1.api.user.v2.CreateUserUserOwnerResponse' + description: CreateUserUserOwnerResponse is the response for creating a user ownership source on a user (service account). summary: Create User Owner tags: - - App Owner V2 - x-speakeasy-entity-missing-codes: - - 404 - x-speakeasy-entity-operation: - terraform-resource: App_Owner_User#create - x-speakeasy-group: AppOwnersV2 + - User Owner V2 + x-speakeasy-group: UserOwnersV2 x-speakeasy-name-override: CreateUserOwner x-stability-level: draft security: diff --git a/.speakeasy/logs/naming.log b/.speakeasy/logs/naming.log index 9d440eb17..aadb0c8d0 100644 --- a/.speakeasy/logs/naming.log +++ b/.speakeasy/logs/naming.log @@ -10,6 +10,16 @@ C1ApiA2uiV1A2UiServiceCreateSurfaceFeedbackResponse (A2UIServiceCreateSurfaceFee A2UiSurfaceFeedback (actionName: string, componentsSnapshot: string, conversationId: string ...) A2UiSurfaceFeedbackSentiment (enum: A2UI_SURFACE_FEEDBACK_SENTIMENT_UNSPECIFIED, A2UI_SURFACE_FEEDBACK_SENTIMENT_POSITIVE, A2UI_SURFACE_FEEDBACK_SENTIMENT_NEGATIVE) Security (bearerAuth: string, oauth: string) +C1ApiA2uiV1A2UiServiceGetSurfaceProvenanceRequest (conversation_id: string, surface_id: string) +C1ApiA2uiV1A2UiServiceGetSurfaceProvenanceResponse (A2UIServiceGetSurfaceProvenanceResponse: A2UIServiceGetSurfaceProvenanceResponse, ContentType: string, StatusCode: int32 ...) + A2UiServiceGetSurfaceProvenanceResponse (programCommitId: string, programFunctionId: string, programInput: string ...) + A2UiProvenanceSource (componentId: string, count: integer, kind: string ...) + A2UiProvenanceStep (objects: array, operation: enum, recordType: enum) + A2UiProvenanceObject (displayName: string, id: string, recordType: enum) + RecordType (enum: A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED, A2UI_PROVENANCE_RECORD_TYPE_APP, A2UI_PROVENANCE_RECORD_TYPE_USER ...) + Operation (enum: A2UI_PROVENANCE_OPERATION_UNSPECIFIED, A2UI_PROVENANCE_OPERATION_LOOKED_UP, A2UI_PROVENANCE_OPERATION_COUNTED ...) + A2UiProvenanceStepRecordType (enum: A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED, A2UI_PROVENANCE_RECORD_TYPE_APP, A2UI_PROVENANCE_RECORD_TYPE_USER ...) + A2UiProvenanceToolCall (calledAt: date-time, inputDigest: string, toolName: string) C1ApiA2uiV1A2UiServiceListSurfaceFeedbackRequest (surface_id: string) C1ApiA2uiV1A2UiServiceListSurfaceFeedbackResponse (A2UIServiceListSurfaceFeedbackResponse: A2UIServiceListSurfaceFeedbackResponse, ContentType: string, StatusCode: int32 ...) A2UiServiceListSurfaceFeedbackResponse (feedback: array) @@ -44,6 +54,9 @@ C1ApiA2uiV1A2UiServiceListSurfacesResponse (A2UIServiceListSurfacesResponse: A2U C1ConnectorSyncProgressComponent (appId: string, connectorId: string, title: string) C1DurationPickerComponent (label: DynamicString, maxDurationSeconds: DynamicNumber, value: DynamicNumber) DynamicNumber (call: FunctionCall, literal: number, path: string) + C1MetricCardsComponent (cards: array, sources: array, title: DynamicString) + C1MetricCard (delta: string, deltaSentiment: enum, label: string ...) + DeltaSentiment (enum: C1_METRIC_DELTA_SENTIMENT_UNSPECIFIED, C1_METRIC_DELTA_SENTIMENT_POSITIVE, C1_METRIC_DELTA_SENTIMENT_NEGATIVE ...) C1MsTeamsNotificationsComponent (empty) C1OnboardingPlanComponent (categories: array) C1OnboardingPlanCategory (id: string, steps: array, title: string) @@ -52,6 +65,8 @@ C1ApiA2uiV1A2UiServiceListSurfacesResponse (A2UIServiceListSurfacesResponse: A2U C1ResourcePickerComponent (appId: string, connectorId: string, label: DynamicString ...) C1SlackNotificationsComponent (empty) C1StatusIndicatorComponent (message: DynamicString, showSpinner: DynamicBool, status: DynamicString ...) + C1TableComponent (artifactUrl: DynamicString, columns: array, pageSize: int32 ...) + C1TableRow (cells: array) C1TodoListComponent (items: array, title: DynamicString) C1TodoItem (description: DynamicString, id: string, label: DynamicString ...) CardComponent (children: ChildList) @@ -119,8 +134,10 @@ C1ApiAccessreviewV1AccessReviewServiceCreateResponse (AccessReviewServiceCreateR BindingObjectSetup (empty) CampaignHealthSnapshot (checkedAt: date-time, phantomLockedCount: int32) CampaignInsights (markdown: string) - AccessReviewColumnConfig (columns: array) + AccessReviewColumnConfig (columns: array, orderedColumns: array) Columns (enum: ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED, ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK, ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE ...) + AccessReviewTaskColumnRef (appUserAttributeKey: string, builtin: enum) + Builtin (enum: ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED, ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK, ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE ...) DefaultView (enum: ACCESS_REVIEW_VIEW_TYPE_UNSPECIFIED, ACCESS_REVIEW_VIEW_TYPE_BY_APP, ACCESS_REVIEW_VIEW_TYPE_BY_USER ...) ErrorState (enum: ACCESS_REVIEW_ERROR_STATE_UNSPECIFIED, ACCESS_REVIEW_ERROR_STATE_SELECTION_QUOTA_EXCEED_ERROR) AccessReviewExclusionScope (appUserStatuses: array, appUserTypes: array) @@ -163,6 +180,21 @@ C1ApiAccessreviewV1AccessReviewServiceUpdateRequest (AccessReviewServiceUpdateRe C1ApiAccessreviewV1AccessReviewServiceUpdateResponse (AccessReviewServiceUpdateResponse: AccessReviewServiceUpdateResponse, ContentType: string, StatusCode: int32 ...) AccessReviewServiceUpdateResponse (accessReview: AccessReviewView, expanded: array) AccessReviewServiceUpdateResponseExpanded (@type: string, AdditionalProperties: map) +AccessReviewReport (SDK empty) +C1ApiAccessreviewV1AccessReviewReportServiceListRequest (access_review_id: string, page_size: int32, page_token: string) +C1ApiAccessreviewV1AccessReviewReportServiceListResponse (AccessReviewReportServiceListResponse: AccessReviewReportServiceListResponse, ContentType: string, StatusCode: int32 ...) + AccessReviewReportServiceListResponse (list: array, nextPageToken: string) + AccessReviewReport (accessReviewId: string, createdAt: date-time, downloadUrl: string ...) + AccessReviewReportFormat (enum: ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED, ACCESS_REVIEW_REPORT_FORMAT_XLSX, ACCESS_REVIEW_REPORT_FORMAT_JSON ...) + AccessReviewReportState (enum: REPORT_STATE_UNSPECIFIED, REPORT_STATE_PENDING, REPORT_STATE_OK ...) +AccessReviewActions (SDK empty) +C1ApiAccessreviewV1AccessReviewActionsServiceGenerateReportRequest (AccessReviewActionsServiceGenerateReportRequest: AccessReviewActionsServiceGenerateReportRequest, access_review_id: string) + AccessReviewActionsServiceGenerateReportRequest (format: enum, reportColumnConfig: AccessReviewReportColumnConfig) + Format (enum: ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED, ACCESS_REVIEW_REPORT_FORMAT_XLSX, ACCESS_REVIEW_REPORT_FORMAT_JSON ...) + AccessReviewReportColumnConfig (columns: array) + AccessReviewReportColumnConfigColumns (enum: ACCESS_REVIEW_REPORT_COLUMN_UNSPECIFIED, ACCESS_REVIEW_REPORT_COLUMN_EMPLOYEE_ID, ACCESS_REVIEW_REPORT_COLUMN_JOB_TITLE ...) +C1ApiAccessreviewV1AccessReviewActionsServiceGenerateReportResponse (AccessReviewActionsServiceGenerateReportResponse: AccessReviewActionsServiceGenerateReportResponse, ContentType: string, StatusCode: int32 ...) + AccessReviewActionsServiceGenerateReportResponse (empty) AccessReviewSetupEntitlement (SDK empty) C1ApiAccessreviewV1AccessReviewSetupEntitlementServiceGetCampaignScopeAndEntitlementsRequest (access_review_id: string) C1ApiAccessreviewV1AccessReviewSetupEntitlementServiceGetCampaignScopeAndEntitlementsResponse (AccessReviewSetupEntitlementAndScopeServiceSetResponse: AccessReviewSetupEntitlementAndScopeServiceSetResponse, ContentType: string, StatusCode: int32 ...) @@ -194,6 +226,7 @@ C1ApiAccessreviewV1AccessReviewTemplateServiceCreateResponse (AccessReviewTempla AccessReviewTemplateAccuracyIssueAction (enum: ACCURACY_ISSUE_ACTION_UNSPECIFIED, ACCURACY_ISSUE_ACTION_CONTINUE, ACCURACY_ISSUE_ACTION_WAIT) AccessReviewTemplateAutoCloseDecision (enum: CLOSE_DECISION_UNSPECIFIED, CLOSE_DECISION_REVOKED, CLOSE_DECISION_SKIP ...) AccessReviewTemplateDefaultView (enum: ACCESS_REVIEW_VIEW_TYPE_UNSPECIFIED, ACCESS_REVIEW_VIEW_TYPE_BY_APP, ACCESS_REVIEW_VIEW_TYPE_BY_USER ...) + MsTeamsChannel (channelName: string, externalDirectoryId: string) AccessReviewTemplateScopeType (enum: ACCESS_REVIEW_SCOPE_TYPE_UNSPECIFIED, ACCESS_REVIEW_SCOPE_TYPE_BY_ENTITLEMENTS, ACCESS_REVIEW_SCOPE_TYPE_BY_ACCESS_CONFLICTS ...) SlackChannel (channelId: string, description: string, isChannelId: boolean ...) C1ApiAccessreviewV1AccessReviewTemplateServiceDeleteRequest (AccessReviewTemplateServiceDeleteRequest: AccessReviewTemplateServiceDeleteRequest, id: string) @@ -246,8 +279,10 @@ C1ApiAppV1AppUserServiceListResponse (AppUserServiceListResponse: AppUserService AppUserServiceListResponse (expanded: array, list: array, nextPageToken: string) AppUserServiceListResponseExpanded (@type: string, AdditionalProperties: map) AppUserView (appPath: string, appUser: AppUser, identityUserPath: string ...) - AppUser (appId: string, appUserType: enum, createdAt: date-time ...) + AppUser (agentStatus: enum, appId: string, appUserType: enum ...) + AgentStatus (enum: APP_USER_AGENT_STATUS_UNSPECIFIED, APP_USER_AGENT_STATUS_READY, APP_USER_AGENT_STATUS_DISABLED ...) AppUserType (enum: APP_USER_TYPE_UNSPECIFIED, APP_USER_TYPE_USER, APP_USER_TYPE_SERVICE_ACCOUNT ...) + AppUserNhiType (enum: APP_USER_NHI_TYPE_UNSPECIFIED, APP_USER_NHI_TYPE_APP_REGISTRATION, APP_USER_NHI_TYPE_ASSUMABLE_ROLE ...) AppUserStatus (details: string, status: enum) AppUserStatusStatus (enum: STATUS_UNSPECIFIED, STATUS_ENABLED, STATUS_DISABLED ...) C1ApiAppV1AppUserServiceListAppUserCredentialsRequest (app_id: string, app_user_id: string, page_size: int32 ...) @@ -264,10 +299,12 @@ ListOwnedServiceAccountsRequest (expandMask: AppUserExpandMask, pageSize: int32, C1ApiAppV1AppUserServiceListOwnedServiceAccountsResponse (ContentType: string, ListOwnedServiceAccountsResponse: ListOwnedServiceAccountsResponse, StatusCode: int32 ...) ListOwnedServiceAccountsResponse (expanded: array, list: array, nextPageToken: string) ListOwnedServiceAccountsResponseExpanded (@type: string, AdditionalProperties: map) -AppUserServiceSearchRequest (appId: string, appIds: array, appUserDomains: array ...) +AppUserServiceSearchRequest (agentStatuses: array, appId: string, appIds: array ...) + AgentStatuses (enum: APP_USER_AGENT_STATUS_UNSPECIFIED, APP_USER_AGENT_STATUS_READY, APP_USER_AGENT_STATUS_DISABLED ...) AppUserDomains (enum: APP_USER_DOMAIN_UNSPECIFIED, APP_USER_DOMAIN_EXTERNAL, APP_USER_DOMAIN_TRUSTED) AppUserServiceSearchRequestAppUserStatuses (enum: STATUS_UNSPECIFIED, STATUS_ENABLED, STATUS_DISABLED ...) AppUserServiceSearchRequestAppUserTypes (enum: APP_USER_TYPE_UNSPECIFIED, APP_USER_TYPE_USER, APP_USER_TYPE_SERVICE_ACCOUNT ...) + NhiTypes (enum: APP_USER_NHI_TYPE_UNSPECIFIED, APP_USER_NHI_TYPE_APP_REGISTRATION, APP_USER_NHI_TYPE_ASSUMABLE_ROLE ...) AppUserRef (appId: string, id: string) SortBy (enum: APP_USER_SEARCH_SORT_BY_UNSPECIFIED, APP_USER_SEARCH_SORT_BY_APP) C1ApiAppV1AppUserServiceSearchResponse (AppUserServiceSearchResponse: AppUserServiceSearchResponse, ContentType: string, StatusCode: int32 ...) @@ -296,6 +333,7 @@ C1ApiAccessconflictV1AppEntitlementMonitorBindingServiceGetAppEntitlementMonitor Apps (SDK empty) CreateAppRequest (annotations: map, appEntitlementOwnerRefs: array, certifyPolicyId: string ...) CreateAppRequestIdentityMatching (enum: APP_USER_IDENTITY_MATCHING_UNSPECIFIED, APP_USER_IDENTITY_MATCHING_STRICT, APP_USER_IDENTITY_MATCHING_DISPLAY_NAME ...) + AppMatchBatonRef (appId: string, connectorId: string, externalId: string) C1ApiAppV1AppsCreateResponse (ContentType: string, CreateAppResponse: CreateAppResponse, StatusCode: int32 ...) CreateAppResponse (app: App) App (accessModel: enum, annotations: map, appAccountId: string ...) @@ -420,6 +458,39 @@ C1ApiAppV1AppAccessRequestsDefaultsServiceCreateAppAccessRequestsDefaultsRequest C1ApiAppV1AppAccessRequestsDefaultsServiceCreateAppAccessRequestsDefaultsResponse (AppAccessRequestDefaults: AppAccessRequestDefaults, ContentType: string, StatusCode: int32 ...) C1ApiAppV1AppAccessRequestsDefaultsServiceGetAppAccessRequestsDefaultsRequest (app_id: string) C1ApiAppV1AppAccessRequestsDefaultsServiceGetAppAccessRequestsDefaultsResponse (AppAccessRequestDefaults: AppAccessRequestDefaults, ContentType: string, StatusCode: int32 ...) +McpResource (SDK empty) +C1ApiAiGovernanceV1McpResourceServiceGetRequest (app_id: string, connector_id: string, id: string) +C1ApiAiGovernanceV1McpResourceServiceGetResponse (ContentType: string, MCPResourceServiceGetResponse: MCPResourceServiceGetResponse, StatusCode: int32 ...) + McpResourceServiceGetResponse (resource: MCPResource) + McpResource (appEntitlementId: string, appId: string, connectorId: string ...) + McpResourceKind (enum: MCP_RESOURCE_KIND_UNSPECIFIED, MCP_RESOURCE_KIND_STATIC, MCP_RESOURCE_KIND_TEMPLATE) + McpResourceState (enum: MCP_RESOURCE_STATE_UNSPECIFIED, MCP_RESOURCE_STATE_PENDING_REVIEW, MCP_RESOURCE_STATE_APPROVED ...) +C1ApiAiGovernanceV1McpResourceServiceListRequest (app_id: string, connector_id: string, page_size: int32 ...) +C1ApiAiGovernanceV1McpResourceServiceListResponse (ContentType: string, MCPResourceServiceListResponse: MCPResourceServiceListResponse, StatusCode: int32 ...) + McpResourceServiceListResponse (nextPageToken: string, resources: array) +C1ApiAiGovernanceV1McpResourceServiceListHistoryRequest (app_id: string, connector_id: string, id: string ...) +C1ApiAiGovernanceV1McpResourceServiceListHistoryResponse (ContentType: string, MCPResourceServiceListHistoryResponse: MCPResourceServiceListHistoryResponse, StatusCode: int32 ...) + McpResourceServiceListHistoryResponse (list: array, nextPageToken: string) + McpResourceHistoryEntry (metadata: HistoryEntryMetadata, snapshot: MCPResource) + HistoryEntryMetadata (actor: HistoryActor, annotations: array, changeKind: enum ...) + HistoryActor (kind: enum, userId: string) + HistoryActorKind (enum: ACTOR_KIND_UNSPECIFIED, ACTOR_KIND_API, ACTOR_KIND_SLACK ...) + HistoryAnnotation (displayLabel: string, displayUrl: string, displayValue: string ...) + HistoryAnnotationKind (enum: ANNOTATION_KIND_UNSPECIFIED, ANNOTATION_KIND_GENERIC, ANNOTATION_KIND_TICKET ...) + ChangeKind (enum: CHANGE_KIND_UNSPECIFIED, CHANGE_KIND_CREATE, CHANGE_KIND_PUT ...) +C1ApiAiGovernanceV1McpResourceServiceSearchRequest (MCPResourceServiceSearchRequest: MCPResourceServiceSearchRequest, app_id: string, connector_id: string) + McpResourceServiceSearchRequest (includeGrantStatus: boolean, kindFilter: array, pageSize: int32 ...) + KindFilter (enum: MCP_RESOURCE_KIND_UNSPECIFIED, MCP_RESOURCE_KIND_STATIC, MCP_RESOURCE_KIND_TEMPLATE) + McpResourceServiceSearchRequestSortBy (enum: MCP_RESOURCE_SORT_BY_UNSPECIFIED, MCP_RESOURCE_SORT_BY_NAME, MCP_RESOURCE_SORT_BY_URI ...) + SortDirection (enum: SORT_DIRECTION_UNSPECIFIED, SORT_DIRECTION_ASC, SORT_DIRECTION_DESC) + StateFilter (enum: MCP_RESOURCE_STATE_UNSPECIFIED, MCP_RESOURCE_STATE_PENDING_REVIEW, MCP_RESOURCE_STATE_APPROVED ...) +C1ApiAiGovernanceV1McpResourceServiceSearchResponse (ContentType: string, MCPResourceServiceSearchResponse: MCPResourceServiceSearchResponse, StatusCode: int32 ...) + McpResourceServiceSearchResponse (list: array, nextPageToken: string) +C1ApiAiGovernanceV1McpResourceServiceUpdateRequest (MCPResourceServiceUpdateRequest: MCPResourceServiceUpdateRequest, app_id: string, connector_id: string ...) + McpResourceServiceUpdateRequest (resource: MCPResource_input, updateMask: string) + McpResourceInput (appEntitlementId: string, appId: string, connectorId: string ...) +C1ApiAiGovernanceV1McpResourceServiceUpdateResponse (ContentType: string, MCPResourceServiceUpdateResponse: MCPResourceServiceUpdateResponse, StatusCode: int32 ...) + McpResourceServiceUpdateResponse (resource: MCPResource) McpTool (SDK empty) C1ApiAiGovernanceV1McpToolServiceDeleteRequest (MCPToolServiceDeleteRequest: MCPToolServiceDeleteRequest, app_id: string, connector_id: string ...) McpToolServiceDeleteRequest (empty) @@ -442,19 +513,13 @@ C1ApiAiGovernanceV1McpToolServiceListHistoryRequest (app_id: string, connector_i C1ApiAiGovernanceV1McpToolServiceListHistoryResponse (ContentType: string, MCPToolServiceListHistoryResponse: MCPToolServiceListHistoryResponse, StatusCode: int32 ...) McpToolServiceListHistoryResponse (list: array, nextPageToken: string) McpToolHistoryEntry (metadata: HistoryEntryMetadata, snapshot: MCPTool) - HistoryEntryMetadata (actor: HistoryActor, annotations: array, changeKind: enum ...) - HistoryActor (kind: enum, userId: string) - HistoryActorKind (enum: ACTOR_KIND_UNSPECIFIED, ACTOR_KIND_API, ACTOR_KIND_SLACK ...) - HistoryAnnotation (displayLabel: string, displayUrl: string, displayValue: string ...) - HistoryAnnotationKind (enum: ANNOTATION_KIND_UNSPECIFIED, ANNOTATION_KIND_GENERIC, ANNOTATION_KIND_TICKET ...) - ChangeKind (enum: CHANGE_KIND_UNSPECIFIED, CHANGE_KIND_CREATE, CHANGE_KIND_PUT ...) C1ApiAiGovernanceV1McpToolServiceSearchRequest (MCPToolServiceSearchRequest: MCPToolServiceSearchRequest, app_id: string, connector_id: string) McpToolServiceSearchRequest (accessProfileId: string, accessProfileIds: array, classificationFilter: array ...) ClassificationFilter (enum: TOOL_CLASSIFICATION_UNSPECIFIED, TOOL_CLASSIFICATION_READ, TOOL_CLASSIFICATION_WRITE ...) McpToolRef (appId: string, connectorId: string, id: string) McpToolServiceSearchRequestSortBy (enum: MCP_TOOL_SORT_BY_UNSPECIFIED, MCP_TOOL_SORT_BY_TOOL_NAME, MCP_TOOL_SORT_BY_VISIBILITY ...) - SortDirection (enum: SORT_DIRECTION_UNSPECIFIED, SORT_DIRECTION_ASC, SORT_DIRECTION_DESC) - StateFilter (enum: MCP_TOOL_STATE_UNSPECIFIED, MCP_TOOL_STATE_PENDING_REVIEW, MCP_TOOL_STATE_APPROVED ...) + McpToolServiceSearchRequestSortDirection (enum: SORT_DIRECTION_UNSPECIFIED, SORT_DIRECTION_ASC, SORT_DIRECTION_DESC) + McpToolServiceSearchRequestStateFilter (enum: MCP_TOOL_STATE_UNSPECIFIED, MCP_TOOL_STATE_PENDING_REVIEW, MCP_TOOL_STATE_APPROVED ...) VisibilityFilter (enum: TOOL_VISIBILITY_UNSPECIFIED, TOOL_VISIBILITY_FEATURED, TOOL_VISIBILITY_AVAILABLE ...) C1ApiAiGovernanceV1McpToolServiceSearchResponse (ContentType: string, MCPToolServiceSearchResponse: MCPToolServiceSearchResponse, StatusCode: int32 ...) McpToolServiceSearchResponse (list: array, nextPageToken: string) @@ -468,7 +533,7 @@ C1ApiAiGovernanceV1McpAccessProfileServiceCreateRequest (MCPAccessProfileService McpAccessProfileServiceCreateRequest (description: string, displayName: string) C1ApiAiGovernanceV1McpAccessProfileServiceCreateResponse (ContentType: string, MCPAccessProfileServiceCreateResponse: MCPAccessProfileServiceCreateResponse, StatusCode: int32 ...) McpAccessProfileServiceCreateResponse (profile: MCPAccessProfile) - McpAccessProfile (appEntitlementId: string, appId: string, connectorId: string ...) + McpAccessProfile (appEntitlementId: string, appId: string, connectorDisplayName: string ...) C1ApiAiGovernanceV1McpAccessProfileServiceDeleteRequest (MCPAccessProfileServiceDeleteRequest: MCPAccessProfileServiceDeleteRequest, app_id: string, connector_id: string ...) McpAccessProfileServiceDeleteRequest (empty) C1ApiAiGovernanceV1McpAccessProfileServiceDeleteResponse (ContentType: string, MCPAccessProfileServiceDeleteResponse: MCPAccessProfileServiceDeleteResponse, StatusCode: int32 ...) @@ -486,13 +551,17 @@ C1ApiAiGovernanceV1McpAccessProfileServiceListRequestableConnectorsRequest (user C1ApiAiGovernanceV1McpAccessProfileServiceListRequestableConnectorsResponse (ContentType: string, MCPAccessProfileServiceListRequestableConnectorsResponse: MCPAccessProfileServiceListRequestableConnectorsResponse, StatusCode: int32 ...) McpAccessProfileServiceListRequestableConnectorsResponse (connectors: array) RequestableConnector (appId: string, connectorId: string) +C1ApiAiGovernanceV1McpAccessProfileServiceSearchAccessProfilesRequest (page_size: int32, page_token: string, query: string) +C1ApiAiGovernanceV1McpAccessProfileServiceSearchAccessProfilesResponse (ContentType: string, MCPAccessProfileServiceSearchAccessProfilesResponse: MCPAccessProfileServiceSearchAccessProfilesResponse, StatusCode: int32 ...) + McpAccessProfileServiceSearchAccessProfilesResponse (nextPageToken: string, profiles: array) C1ApiAiGovernanceV1McpAccessProfileServiceSearchRequestableConnectorsRequest (grant_enrollment_status: enum, page_size: int32, page_token: string ...) GrantEnrollmentStatus (enum: GRANT_ENROLLMENT_STATUS_UNSPECIFIED, GRANT_ENROLLMENT_STATUS_FULLY_GRANTED, GRANT_ENROLLMENT_STATUS_NOT_GRANTED ...) C1ApiAiGovernanceV1McpAccessProfileServiceSearchRequestableConnectorsResponse (ContentType: string, MCPAccessProfileServiceSearchRequestableConnectorsResponse: MCPAccessProfileServiceSearchRequestableConnectorsResponse, StatusCode: int32 ...) McpAccessProfileServiceSearchRequestableConnectorsResponse (list: array, nextPageToken: string) RequestableConnectorView (appId: string, connectorId: string, description: string ...) C1ApiAiGovernanceV1McpAccessProfileServiceUpdateRequest (MCPAccessProfileServiceUpdateRequest: MCPAccessProfileServiceUpdateRequest, app_id: string, connector_id: string ...) - McpAccessProfileServiceUpdateRequest (profile: MCPAccessProfile, updateMask: string) + McpAccessProfileServiceUpdateRequest (profile: MCPAccessProfile_input, updateMask: string) + McpAccessProfileInput (appEntitlementId: string, appId: string, connectorId: string ...) C1ApiAiGovernanceV1McpAccessProfileServiceUpdateResponse (ContentType: string, MCPAccessProfileServiceUpdateResponse: MCPAccessProfileServiceUpdateResponse, StatusCode: int32 ...) McpAccessProfileServiceUpdateResponse (profile: MCPAccessProfile) McpAccessProfileToolBinding (SDK empty) @@ -570,6 +639,7 @@ C1ApiAppV1AppEntitlementsCreateRequest (CreateAppEntitlementRequest: CreateAppEn DefaultBehavior (connectorId: string) DeleteAccount (connectorId: string) DelegatedProvision (appId: string, entitlementId: string, implicit: boolean) + DevicePlacementProvision (vaultBoundaryId: string) ExternalTicketProvision (appId: string, connectorId: string, externalTicketProvisionerConfigId: string ...) ManualProvision (assignee: ProvisionerAssignment, instructions: string, userIds: array) ProvisionerAssignment (appOwners: AppOwnerProvisioner, entitlementOwners: EntitlementOwnerProvisioner, expression: ExpressionProvisioner ...) @@ -619,7 +689,7 @@ C1ApiAppV1AppEntitlementsGetResponse (ContentType: string, GetAppEntitlementResp C1ApiAppV1AppEntitlementsGetAutomationRequest (app_entitlement_id: string, app_id: string) C1ApiAppV1AppEntitlementsGetAutomationResponse (AppEntitlementServiceGetAutomationResponse: AppEntitlementServiceGetAutomationResponse, ContentType: string, StatusCode: int32 ...) AppEntitlementServiceGetAutomationResponse (AppEntitlementAutomation: AppEntitlementAutomation) -C1ApiAppV1AppEntitlementsListRequest (app_id: string, page_size: int32, page_token: string) +C1ApiAppV1AppEntitlementsListRequest (app_id: string, app_user_id: string, page_size: int32 ...) C1ApiAppV1AppEntitlementsListResponse (ContentType: string, ListAppEntitlementsResponse: ListAppEntitlementsResponse, StatusCode: int32 ...) ListAppEntitlementsResponse (expanded: array, list: array, nextPageToken: string) ListAppEntitlementsResponseExpanded (@type: string, AdditionalProperties: map) @@ -693,6 +763,9 @@ C1ApiAppV1AppEntitlementSearchServiceSearchGraphResponse (AppEntitlementSearchSe Type (enum: GRAPH_EDGE_TYPE_UNSPECIFIED, GRAPH_EDGE_TYPE_IDENTITY_LINK, GRAPH_EDGE_TYPE_DIRECT_GRANT ...) GraphNode (appId: string, displayName: string, id: string ...) GraphNodeType (enum: GRAPH_NODE_TYPE_UNSPECIFIED, GRAPH_NODE_TYPE_USER, GRAPH_NODE_TYPE_APP_USER ...) +AppEntitlementSearchServiceSearchReachableResourcesForUserRequest (appIds: array, pageSize: int32, pageToken: string ...) +C1ApiAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse (AppEntitlementSearchServiceSearchReachableResourcesForUserResponse: AppEntitlementSearchServiceSearchReachableResourcesForUserResponse, ContentType: string, StatusCode: int32 ...) + AppEntitlementSearchServiceSearchReachableResourcesForUserResponse (list: array, nextPageToken: string) AppEntitlementUserBinding (SDK empty) C1ApiAppV1AppEntitlementUserBindingServiceListAppUsersForIdentityWithGrantRequest (app_entitlement_id: string, app_id: string, identity_user_id: string) C1ApiAppV1AppEntitlementUserBindingServiceListAppUsersForIdentityWithGrantResponse (ContentType: string, ListAppUsersForIdentityWithGrantResponse: ListAppUsersForIdentityWithGrantResponse, StatusCode: int32 ...) @@ -771,6 +844,7 @@ C1ApiAiGovernanceV1McpServerServiceGetCatalogResponse (ContentType: string, MCPS McpServerCatalogEntry (authModes: array, baseUrl: string, channel: enum ...) McpServerCatalogAuthMode (authMethod: enum, authStyle: string, authorizeUrl: string ...) McpServerCatalogAuthModeAuthMethod (enum: MCP_SERVER_AUTH_METHOD_UNSPECIFIED, MCP_SERVER_AUTH_METHOD_NONE, MCP_SERVER_AUTH_METHOD_BEARER_TOKEN ...) + McpServerCatalogAuthModeClientIdMode (enum: MCP_SERVER_CATALOG_CLIENT_ID_MODE_UNSPECIFIED, MCP_SERVER_CATALOG_CLIENT_ID_MODE_MANUAL, MCP_SERVER_CATALOG_CLIENT_ID_MODE_DCR ...) Channel (enum: MCP_SERVER_CATALOG_CHANNEL_UNSPECIFIED, MCP_SERVER_CATALOG_CHANNEL_STABLE, MCP_SERVER_CATALOG_CHANNEL_BETA ...) McpServerCatalogConfigSchema (fields: array) McpServerCatalogConfigField (default: string, description: string, displayName: string ...) @@ -791,7 +865,7 @@ C1ApiAiGovernanceV1McpServerServiceListConnectionsResponse (ContentType: string, AuthMethod (enum: MCP_SERVER_AUTH_METHOD_UNSPECIFIED, MCP_SERVER_AUTH_METHOD_NONE, MCP_SERVER_AUTH_METHOD_BEARER_TOKEN ...) ServerType (enum: MCP_SERVER_TYPE_UNSPECIFIED, MCP_SERVER_TYPE_HOSTED, MCP_SERVER_TYPE_EXTERNAL) C1ApiAiGovernanceV1McpServerServiceRegisterRequest (MCPServerServiceRegisterRequest: MCPServerServiceRegisterRequest, app_id: string) - McpServerServiceRegisterRequest (acknowledgedFindingIds: array, appManagedStateBindingRef: AppManagedStateBindingRef, dataSensitivity: enum ...) + McpServerServiceRegisterRequest (accessProfileIds: array, acknowledgedFindingIds: array, appManagedStateBindingRef: AppManagedStateBindingRef ...) DataSensitivity (enum: MCP_SERVER_DATA_SENSITIVITY_UNSPECIFIED, MCP_SERVER_DATA_SENSITIVITY_PUBLIC, MCP_SERVER_DATA_SENSITIVITY_INTERNAL ...) McpServerExternalConfig (basicAuth: MCPServerAuthBasicAuth, bearerToken: MCPServerAuthBearerToken, customHeader: MCPServerAuthCustomHeader ...) McpServerAuthBasicAuth (password: string, username: string) @@ -811,7 +885,7 @@ C1ApiAiGovernanceV1McpServerServiceRegisterRequest (MCPServerServiceRegisterRequ McpServerHostedConfigTokenSharing (enum: MCP_SERVER_TOKEN_SHARING_UNSPECIFIED, MCP_SERVER_TOKEN_SHARING_SHARED, MCP_SERVER_TOKEN_SHARING_PER_USER) McpServerServiceRegisterRequestServerType (enum: MCP_SERVER_TYPE_UNSPECIFIED, MCP_SERVER_TYPE_HOSTED, MCP_SERVER_TYPE_EXTERNAL) C1ApiAiGovernanceV1McpServerServiceRegisterResponse (ContentType: string, MCPServerServiceRegisterResponse: MCPServerServiceRegisterResponse, StatusCode: int32 ...) - McpServerServiceRegisterResponse (mcpServer: MCPServerView) + McpServerServiceRegisterResponse (accessProfilesAttached: boolean, mcpServer: MCPServerView) C1ApiAiGovernanceV1McpServerServiceResyncToolsRequest (MCPServerServiceResyncToolsRequest: MCPServerServiceResyncToolsRequest, app_id: string, connector_id: string) McpServerServiceResyncToolsRequest (empty) C1ApiAiGovernanceV1McpServerServiceResyncToolsResponse (ContentType: string, MCPServerServiceResyncToolsResponse: MCPServerServiceResyncToolsResponse, StatusCode: int32 ...) @@ -925,6 +999,24 @@ C1ApiAppV1AppResourceServiceUpdateRequest (AppResourceServiceUpdateRequest: AppR C1ApiAppV1AppResourceServiceUpdateResponse (AppResourceServiceUpdateResponse: AppResourceServiceUpdateResponse, ContentType: string, StatusCode: int32 ...) AppResourceServiceUpdateResponse (appResourceView: AppResourceView, expanded: array) AppResourceServiceUpdateResponseExpanded (@type: string, AdditionalProperties: map) +AppManagedState (SDK empty) +C1ApiAppV1AppManagedStateServiceGetRequest (app_id: string, resource_id: string, resource_type_id: string) +C1ApiAppV1AppManagedStateServiceGetResponse (ContentType: string, GetAppManagedStateBindingResponse: GetAppManagedStateBindingResponse, StatusCode: int32 ...) + GetAppManagedStateBindingResponse (appManagementState: AppManagedStateBindingView, expanded: array) + AppManagedStateBindingView (appManagementStateBinding: AppManagedStateBinding, appPath: string, resourcePath: string) + AppManagedStateBinding (appId: string, createdAt: date-time, deletedAt: date-time ...) + AppManagedState (managed: AppManagedStateManaged, unmanaged: AppManagedStateUnmanaged) + AppManagedStateManaged (appId: string) + AppManagedStateUnmanaged (empty) + GetAppManagedStateBindingResponseExpanded (@type: string, AdditionalProperties: map) +C1ApiAppV1AppManagedStateServiceListRequest (app_id: string, page_size: int32, page_token: string ...) +C1ApiAppV1AppManagedStateServiceListResponse (ContentType: string, ListAppManagedStateBindingsResponse: ListAppManagedStateBindingsResponse, StatusCode: int32 ...) + ListAppManagedStateBindingsResponse (expanded: array, list: array, nextPageToken: string) + ListAppManagedStateBindingsResponseExpanded (@type: string, AdditionalProperties: map) +C1ApiAppV1AppManagedStateServicePromoteRequest (PromoteAppManagedStateBindingRequest: PromoteAppManagedStateBindingRequest, app_id: string, resource_id: string ...) + PromoteAppManagedStateBindingRequest (appEntitlementOwnerRefs: array, expandMask: AppManagedStateBindingExpandMask, userIds: array) + AppManagedStateBindingExpandMask (paths: array) +C1ApiAppV1AppManagedStateServicePromoteResponse (ContentType: string, GetAppManagedStateBindingResponse: GetAppManagedStateBindingResponse, StatusCode: int32 ...) AppResourceOwners (SDK empty) C1ApiAppV1AppResourceOwnersAddRequest (AddAppResourceOwnerRequest: AddAppResourceOwnerRequest, app_id: string, resource_id: string ...) AddAppResourceOwnerRequest (userId: string) @@ -948,6 +1040,90 @@ C1ApiAppV1AppResourceOwnersSetRequest (SetAppResourceOwnersRequest: SetAppResour SetAppResourceOwnersRequest (userIds: array) C1ApiAppV1AppResourceOwnersSetResponse (ContentType: string, SetAppResourceOwnersResponse: SetAppResourceOwnersResponse, StatusCode: int32 ...) SetAppResourceOwnersResponse (empty) +SsoApplication (SDK empty) +C1ApiSsoV1SsoApplicationServiceBatchDeleteSubjectCompatibilityRequest (SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest: SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest, app_id: string, id: string) + SsoApplicationServiceBatchDeleteSubjectCompatibilityRequest (userIds: array) +C1ApiSsoV1SsoApplicationServiceBatchDeleteSubjectCompatibilityResponse (ContentType: string, SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse: SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse, StatusCode: int32 ...) + SsoApplicationServiceBatchDeleteSubjectCompatibilityResponse (deletedRows: int32, issues: array) + SsoSubjectCompatibilityDeleteIssue (reason: string, userId: string) +C1ApiSsoV1SsoApplicationServiceBatchImportSubjectCompatibilityRequest (SSOApplicationServiceBatchImportSubjectCompatibilityRequest: SSOApplicationServiceBatchImportSubjectCompatibilityRequest, app_id: string, id: string) + SsoApplicationServiceBatchImportSubjectCompatibilityRequest (apply: boolean, entries: array, importId: string) + SsoSubjectCompatibilityImportEntry (row: int32, subject: string, userId: string) +C1ApiSsoV1SsoApplicationServiceBatchImportSubjectCompatibilityResponse (ContentType: string, SSOApplicationServiceBatchImportSubjectCompatibilityResponse: SSOApplicationServiceBatchImportSubjectCompatibilityResponse, StatusCode: int32 ...) + SsoApplicationServiceBatchImportSubjectCompatibilityResponse (blockingUserIds: array, importedRows: int32, importedUserIds: array ...) + SsoSubjectCompatibilityImportIssue (reason: string, row: int32, subject: string ...) +C1ApiSsoV1SsoApplicationServiceCreateRequest (SSOApplicationServiceCreateRequest: SSOApplicationServiceCreateRequest, app_id: string) + SsoApplicationServiceCreateRequest (assertionLifetime: string, description: string, displayName: string ...) + SsoApplicationOidcClientConfig (authentication: SSOApplicationOIDCClientAuthentication, displayName: string, pkcePolicy: enum ...) + SsoApplicationOidcClientAuthentication (clientSecretBasic: SSOApplicationOIDCClientAuthClientSecretBasic, clientSecretPost: SSOApplicationOIDCClientAuthClientSecretPost, none: SSOApplicationOIDCClientAuthNone ...) + SsoApplicationOidcClientAuthClientSecretBasic (empty) + SsoApplicationOidcClientAuthClientSecretPost (empty) + SsoApplicationOidcClientAuthNone (empty) + SsoApplicationOidcClientAuthPrivateKeyJwt (publicJwks: string) + SsoApplicationOidcClientConfigPkcePolicy (enum: SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED, SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256, SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY) + SsoApplicationOidcConfig (claimMappings: array, idTokenSignedResponseAlg: enum) + OidcClaimMapping (claimName: string, destination: enum, userAttributeMappingId: string) + Destination (enum: OIDC_CLAIM_DESTINATION_UNSPECIFIED, OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY, OIDC_CLAIM_DESTINATION_USERINFO_ONLY) + IdTokenSignedResponseAlg (enum: OIDC_SIGNING_ALGORITHM_UNSPECIFIED, OIDC_SIGNING_ALGORITHM_EDDSA, OIDC_SIGNING_ALGORITHM_ES256 ...) + SsoApplicationSamlConfig (acsUrls: array, attributeMappings: array, encryptAssertions: boolean ...) + SamlAttributeMapping (friendlyName: string, name: string, nameFormat: enum ...) + NameFormat (enum: SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED, SAML_ATTRIBUTE_NAME_FORMAT_URI, SAML_ATTRIBUTE_NAME_FORMAT_BASIC ...) + EncryptionAlgorithm (enum: SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED, SAML_ENCRYPTION_ALGORITHM_AES256_GCM, SAML_ENCRYPTION_ALGORITHM_AES128_GCM ...) + NameIdFormat (enum: SAML_NAME_ID_FORMAT_UNSPECIFIED, SAML_NAME_ID_FORMAT_PERSISTENT, SAML_NAME_ID_FORMAT_EMAIL_ADDRESS ...) + SsoSubjectCompatibility (userAttributeMappingId: string) + SsoApplicationServiceCreateRequestSubjectType (enum: SSO_SUBJECT_TYPE_UNSPECIFIED, SSO_SUBJECT_TYPE_PAIRWISE, SSO_SUBJECT_TYPE_PUBLIC ...) +C1ApiSsoV1SsoApplicationServiceCreateResponse (ContentType: string, SSOApplicationServiceCreateResponse: SSOApplicationServiceCreateResponse, StatusCode: int32 ...) + SsoApplicationServiceCreateResponse (application: SSOApplication, client: SSOApplicationOIDCClient, clientSecret: string) + SsoApplication (appEntitlementId: string, appId: string, assertionLifetime: string ...) + SubjectType (enum: SSO_SUBJECT_TYPE_UNSPECIFIED, SSO_SUBJECT_TYPE_PAIRWISE, SSO_SUBJECT_TYPE_PUBLIC ...) + SsoApplicationOidcClient (appId: string, authentication: SSOApplicationOIDCClientAuthentication, clientId: string ...) + PkcePolicy (enum: SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED, SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256, SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY) +C1ApiSsoV1SsoApplicationServiceCreateClientRequest (SSOApplicationServiceCreateClientRequest: SSOApplicationServiceCreateClientRequest, app_id: string, id: string) + SsoApplicationServiceCreateClientRequest (client: SSOApplicationOIDCClientConfig) +C1ApiSsoV1SsoApplicationServiceCreateClientResponse (ContentType: string, SSOApplicationServiceCreateClientResponse: SSOApplicationServiceCreateClientResponse, StatusCode: int32 ...) + SsoApplicationServiceCreateClientResponse (client: SSOApplicationOIDCClient, clientSecret: string) +C1ApiSsoV1SsoApplicationServiceDeleteRequest (SSOApplicationServiceDeleteRequest: SSOApplicationServiceDeleteRequest, app_id: string, id: string) + SsoApplicationServiceDeleteRequest (empty) +C1ApiSsoV1SsoApplicationServiceDeleteResponse (ContentType: string, SSOApplicationServiceDeleteResponse: SSOApplicationServiceDeleteResponse, StatusCode: int32 ...) + SsoApplicationServiceDeleteResponse (empty) +C1ApiSsoV1SsoApplicationServiceDeleteClientRequest (SSOApplicationServiceDeleteClientRequest: SSOApplicationServiceDeleteClientRequest, app_id: string, id: string) + SsoApplicationServiceDeleteClientRequest (clientId: string) +C1ApiSsoV1SsoApplicationServiceDeleteClientResponse (ContentType: string, SSOApplicationServiceDeleteClientResponse: SSOApplicationServiceDeleteClientResponse, StatusCode: int32 ...) + SsoApplicationServiceDeleteClientResponse (empty) +C1ApiSsoV1SsoApplicationServiceGetRequest (app_id: string, id: string) +C1ApiSsoV1SsoApplicationServiceGetResponse (ContentType: string, SSOApplicationServiceGetResponse: SSOApplicationServiceGetResponse, StatusCode: int32 ...) + SsoApplicationServiceGetResponse (application: SSOApplication) +C1ApiSsoV1SsoApplicationServiceListRequest (app_id: string, page_size: int32, page_token: string) +C1ApiSsoV1SsoApplicationServiceListResponse (ContentType: string, SSOApplicationServiceListResponse: SSOApplicationServiceListResponse, StatusCode: int32 ...) + SsoApplicationServiceListResponse (list: array, nextPageToken: string) +C1ApiSsoV1SsoApplicationServiceListClientsRequest (app_id: string, id: string, page_size: int32 ...) +C1ApiSsoV1SsoApplicationServiceListClientsResponse (ContentType: string, SSOApplicationServiceListClientsResponse: SSOApplicationServiceListClientsResponse, StatusCode: int32 ...) + SsoApplicationServiceListClientsResponse (list: array, nextPageToken: string) +C1ApiSsoV1SsoApplicationServiceListHistoryRequest (app_id: string, id: string, page_size: int32 ...) +C1ApiSsoV1SsoApplicationServiceListHistoryResponse (ContentType: string, SSOApplicationServiceListHistoryResponse: SSOApplicationServiceListHistoryResponse, StatusCode: int32 ...) + SsoApplicationServiceListHistoryResponse (list: array, nextPageToken: string) + SsoApplicationHistoryEntry (metadata: HistoryEntryMetadata, snapshot: SSOApplication) +SsoApplicationServiceParseSamlServiceProviderMetadataRequest (metadataXml: string) +C1ApiSsoV1SsoApplicationServiceParseSamlServiceProviderMetadataResponse (ContentType: string, SSOApplicationServiceParseSAMLServiceProviderMetadataResponse: SSOApplicationServiceParseSAMLServiceProviderMetadataResponse, StatusCode: int32 ...) + SsoApplicationServiceParseSamlServiceProviderMetadataResponse (config: SSOApplicationSAMLConfig, findings: array) + SamlMetadataFinding (component: enum, level: enum, reason: string) + Component (enum: COMPONENT_UNSPECIFIED, COMPONENT_DOCUMENT, COMPONENT_ENTITY_ID ...) + Level (enum: LEVEL_UNSPECIFIED, LEVEL_BLOCKING, LEVEL_WARNING) +C1ApiSsoV1SsoApplicationServiceRotateClientSecretRequest (SSOApplicationServiceRotateClientSecretRequest: SSOApplicationServiceRotateClientSecretRequest, app_id: string, id: string) + SsoApplicationServiceRotateClientSecretRequest (clientId: string) +C1ApiSsoV1SsoApplicationServiceRotateClientSecretResponse (ContentType: string, SSOApplicationServiceRotateClientSecretResponse: SSOApplicationServiceRotateClientSecretResponse, StatusCode: int32 ...) + SsoApplicationServiceRotateClientSecretResponse (clientSecret: string) +SsoApplicationServiceSearchRequest (appIds: array, pageSize: int32, pageToken: string ...) +C1ApiSsoV1SsoApplicationServiceSearchResponse (ContentType: string, SSOApplicationServiceSearchResponse: SSOApplicationServiceSearchResponse, StatusCode: int32 ...) + SsoApplicationServiceSearchResponse (list: array, nextPageToken: string) +C1ApiSsoV1SsoApplicationServiceUpdateRequest (SSOApplicationServiceUpdateRequest: SSOApplicationServiceUpdateRequest, app_id: string, id: string) + SsoApplicationServiceUpdateRequest (application: SSOApplication, updateMask: string) +C1ApiSsoV1SsoApplicationServiceUpdateResponse (ContentType: string, SSOApplicationServiceUpdateResponse: SSOApplicationServiceUpdateResponse, StatusCode: int32 ...) + SsoApplicationServiceUpdateResponse (application: SSOApplication) +C1ApiSsoV1SsoApplicationServiceUpdateClientRequest (SSOApplicationServiceUpdateClientRequest: SSOApplicationServiceUpdateClientRequest, app_id: string, id: string) + SsoApplicationServiceUpdateClientRequest (client: SSOApplicationOIDCClientConfig, clientId: string) +C1ApiSsoV1SsoApplicationServiceUpdateClientResponse (ContentType: string, SSOApplicationServiceUpdateClientResponse: SSOApplicationServiceUpdateClientResponse, StatusCode: int32 ...) + SsoApplicationServiceUpdateClientResponse (client: SSOApplicationOIDCClient) AppUsageControls (SDK empty) C1ApiAppV1AppUsageControlsServiceGetRequest (app_id: string) C1ApiAppV1AppUsageControlsServiceGetResponse (ContentType: string, GetAppUsageControlsResponse: GetAppUsageControlsResponse, StatusCode: int32 ...) @@ -1170,7 +1346,8 @@ C1ApiAuthConfigV1TenantAuthConfigServiceUpdateResponse (ContentType: string, Sta TenantAuthConfigServiceUpdateResponse (authConfig: TenantAuthConfig) Auth (SDK empty) C1ApiAuthV1AuthIntrospectResponse (ContentType: string, IntrospectResponse: IntrospectResponse, StatusCode: int32 ...) - IntrospectResponse (deviceClientId: string, features: array, permissions: array ...) + IntrospectResponse (deviceClientId: string, disabledModules: array, features: array ...) + DisabledModules (enum: MODULE_ID_UNSPECIFIED, MODULE_ID_SECRET_SHARING) AutomationExecution (SDK empty) C1ApiAutomationsV1AutomationExecutionServiceGetAutomationExecutionRequest (id: integer) C1ApiAutomationsV1AutomationExecutionServiceGetAutomationExecutionResponse (ContentType: string, GetAutomationExecutionResponse: GetAutomationExecutionResponse, StatusCode: int32 ...) @@ -1210,6 +1387,7 @@ AutomationsCreateAutomationRequest (annotations: map, appId: string, automationS EntitlementExclusionList (excludedAppEntitlementRefs: array) EntitlementExclusionListCel (excludedAppEntitlementRefsCel: string) EntitlementExclusionNone (empty) + GrantSourceFilter (enum: GRANT_SOURCE_FILTER_UNSPECIFIED, GRANT_SOURCE_FILTER_DIRECT) EntitlementInclusionAccessOnly (empty) EntitlementInclusionAll (empty) EntitlementInclusionCriteria (appIds: array, complianceFrameworkIds: array, resourceTypeIds: array ...) @@ -1260,7 +1438,7 @@ AutomationsCreateAutomationRequest (annotations: map, appId: string, automationS GrantFilter (grantFilterType: enum, grantJustificationType: enum, grantSourceFilter: enum) GrantFilterType (enum: GRANT_FILTER_TYPE_UNSPECIFIED, GRANT_FILTER_TYPE_PERMANENT, GRANT_FILTER_TYPE_TEMPORARY) GrantJustificationType (enum: GRANT_JUSTIFICATION_TYPE_UNSPECIFIED, GRANT_JUSTIFICATION_TYPE_ALL, GRANT_JUSTIFICATION_TYPE_CONDUCTOR_ONE ...) - GrantSourceFilter (enum: GRANT_SOURCE_FILTER_UNSPECIFIED, GRANT_SOURCE_FILTER_DIRECT, GRANT_SOURCE_FILTER_INHERITED) + GrantFilterGrantSourceFilter (enum: GRANT_SOURCE_FILTER_UNSPECIFIED, GRANT_SOURCE_FILTER_DIRECT, GRANT_SOURCE_FILTER_INHERITED) GrantFoundTrigger (grantTriggerFilter: GrantTriggerFilter) ScheduleTrigger (advanced: boolean, condition: string, cronSpec: string ...) ScheduleTriggerAppUser (appId: string, condition: string, cronSpec: string ...) @@ -1279,7 +1457,7 @@ C1ApiAutomationsV1AutomationServiceCreateAutomationResponse (AutomationsCreateAu AutomationsCreateAutomationResponse (automation: Automation, webhookCapabilityUrl: string, webhookHmacSecret: string) Automation (annotations: map, appId: string, automationSteps: array ...) DisabledReasonCircuitBreaker (observedCount: integer, period: enum, threshold: integer ...) - Period (enum: CIRCUIT_BREAKER_PERIOD_UNSPECIFIED, CIRCUIT_BREAKER_PERIOD_HOUR, CIRCUIT_BREAKER_PERIOD_DAY ...) + DisabledReasonCircuitBreakerPeriod (enum: CIRCUIT_BREAKER_PERIOD_UNSPECIFIED, CIRCUIT_BREAKER_PERIOD_HOUR, CIRCUIT_BREAKER_PERIOD_DAY ...) CircuitBreakerPeriod (enum: CIRCUIT_BREAKER_PERIOD_UNSPECIFIED, CIRCUIT_BREAKER_PERIOD_HOUR, CIRCUIT_BREAKER_PERIOD_DAY ...) PrimaryTriggerType (enum: TRIGGER_TYPE_UNSPECIFIED, TRIGGER_TYPE_USER_PROFILE_CHANGE, TRIGGER_TYPE_APP_USER_CREATE ...) C1ApiAutomationsV1AutomationServiceDeleteAutomationRequest (AutomationsDeleteAutomationRequest: AutomationsDeleteAutomationRequest, id: string) @@ -1317,6 +1495,7 @@ C1ApiRequestcatalogV1RequestCatalogManagementServiceAddAppEntitlementsResponse ( RequestCatalogManagementServiceCreateRequest (annotations: map, description: string, displayName: string ...) RequestCatalogManagementServiceCreateRequestEnrollmentBehavior (enum: REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY, REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY) RequestCatalogExpandMask (paths: array) + RequestCatalogManagementServiceCreateRequestType (enum: REQUEST_CATALOG_TYPE_UNSPECIFIED, REQUEST_CATALOG_TYPE_CATALOG, REQUEST_CATALOG_TYPE_PROFILE ...) RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior (enum: REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS, REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL ...) RequestCatalogManagementServiceCreateRequestUnenrollmentEntitlementBehavior (enum: REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS, REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE) C1ApiRequestcatalogV1RequestCatalogManagementServiceCreateResponse (ContentType: string, RequestCatalogManagementServiceGetResponse: RequestCatalogManagementServiceGetResponse, StatusCode: int32 ...) @@ -1325,6 +1504,7 @@ C1ApiRequestcatalogV1RequestCatalogManagementServiceCreateResponse (ContentType: RequestCatalogView (accessEntitlementsPath: string, createdByUserPath: string, memberCount: integer ...) RequestCatalog (accessEntitlements: array, annotations: map, createdAt: date-time ...) EnrollmentBehavior (enum: REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_BYPASS_ENTITLEMENT_REQUEST_POLICY, REQUEST_CATALOG_ENROLLMENT_BEHAVIOR_ENFORCE_ENTITLEMENT_REQUEST_POLICY) + RequestCatalogType (enum: REQUEST_CATALOG_TYPE_UNSPECIFIED, REQUEST_CATALOG_TYPE_CATALOG, REQUEST_CATALOG_TYPE_PROFILE ...) UnenrollmentBehavior (enum: REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_LEAVE_ACCESS_AS_IS, REQUEST_CATALOG_UNENROLLMENT_BEHAVIOR_REVOKE_ALL ...) UnenrollmentEntitlementBehavior (enum: REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_UNSPECIFIED, REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_BYPASS, REQUEST_CATALOG_UNENROLLMENT_ENTITLEMENT_BEHAVIOR_ENFORCE) C1ApiRequestcatalogV1RequestCatalogManagementServiceCreateBundleAutomationRequest (CreateBundleAutomationRequest: CreateBundleAutomationRequest, request_catalog_id: string) @@ -1437,11 +1617,12 @@ C1ApiIntegrationConnectorV1ConnectorCatalogServiceConfigurationSchemaResponse (C Oauth2Field1 (oauth2FieldView: Oauth2FieldView) Oauth2FieldView (empty) SharedProviderConfig (defaultValueCel: string, inputTransformationCel: string, lockDefaultValues: boolean) - FormStringField (defaultValue: string, passwordField: PasswordField, pickerField: PickerField ...) + FormStringField (dateField: DateField, defaultValue: string, passwordField: PasswordField ...) + DateField (defaultToToday: boolean, maxDate: string, maxDaysFromToday: int32 ...) PasswordField (empty) PickerField (appUserPicker: AppUserFilter, c1UserPicker: C1UserFilter, resourcePicker: AppResourceFilter) AppUserFilter (appId: string) - C1UserFilter (empty) + C1UserFilter (excludeUserIds: array, includeDeactivated: boolean, userIds: array) AppResourceFilter (appId: string, resourceTypeId: string) StringRules (address: boolean, const: string, contains: string ...) WellKnownRegex (enum: UNKNOWN, HTTP_HEADER_NAME, HTTP_HEADER_VALUE) @@ -1491,6 +1672,10 @@ C1ApiIntegrationConnectorV1ConnectorCatalogServiceConfigurationSchemaResponse (C StringListField (valueValidator: StringRules) StringMapField (optional: boolean) ConnectorTextField (secret: boolean, valueValidator: StringRules) +UiConversations (SDK empty) +EnsureOnboardingSessionRequest (empty) +C1ApiConversationsV1UiConversationsServiceEnsureOnboardingSessionResponse (ContentType: string, EnsureOnboardingSessionResponse: EnsureOnboardingSessionResponse, StatusCode: int32 ...) + EnsureOnboardingSessionResponse (conversationId: string, created: boolean) CredentialInventoryPolicy (SDK empty) CredentialInventoryPolicyServiceCreateRequest (delegated: DelegatedConstraints, displayName: string, emailOtp: EmailOTPConstraints ...) DelegatedConstraints (googleEnabled: boolean, googleHostedDomains: array, microsoftEnabled: boolean ...) @@ -1596,7 +1781,7 @@ BulkCreateFindingTasksRequest (policyId: string, refs: array, searchRequest: Fin FindingSearchRequest (appIds: array, appResourceIds: array, appResourceTraitIds: array ...) FindingSearchRequestAppUserTypes (enum: APP_USER_TYPE_UNSPECIFIED, APP_USER_TYPE_USER, APP_USER_TYPE_SERVICE_ACCOUNT ...) FindingTypes (enum: FINDING_TYPE_UNSPECIFIED, FINDING_TYPE_SIMILAR_USERNAME_MATCH, FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION ...) - NhiTypes (enum: NHI_TYPE_UNSPECIFIED, NHI_TYPE_APP_REGISTRATION, NHI_TYPE_ASSUMABLE_ROLE ...) + FindingSearchRequestNhiTypes (enum: NHI_TYPE_UNSPECIFIED, NHI_TYPE_APP_REGISTRATION, NHI_TYPE_ASSUMABLE_ROLE ...) Severities (enum: FINDING_SEVERITY_UNSPECIFIED, FINDING_SEVERITY_INFO, FINDING_SEVERITY_LOW ...) SourceKinds (enum: FINDING_SOURCE_KIND_UNSPECIFIED, FINDING_SOURCE_KIND_DETECTOR, FINDING_SOURCE_KIND_EXTERNAL) States (enum: FINDING_STATE_UNSPECIFIED, FINDING_STATE_OPEN, FINDING_STATE_IN_PROGRESS ...) @@ -1607,6 +1792,7 @@ BulkUpdateFindingStateRequest (acceptRisk: BulkAcceptRiskAction, assignOwner: Bu BulkAssignOwnerAction (owner: FindingOwnerRef) FindingOwnerRef (appOwnerAppId: string, identityUserId: string, managerOfUserId: string ...) BulkReopenAction (empty) + BulkReprocessAction (overrideHumanEdits: boolean, runDispatchers: boolean) BulkSnoozeAction (reason: string, snoozeUntil: date-time) BulkSuppressAction (reason: string) BulkUnsuppressAction (empty) @@ -1622,11 +1808,24 @@ CreateFindingRequest (annotations: map, appResourceTarget: AppResourceTarget, ap TenantTarget (empty) C1ApiFindingV1FindingServiceCreateFindingResponse (ContentType: string, CreateFindingResponse: CreateFindingResponse, StatusCode: int32 ...) CreateFindingResponse (finding: Finding) - Finding (appId: string, appResourceTarget: AppResourceTarget, appUserTarget: AppUserTarget ...) + Finding (annotations: map, appId: string, appResourceTarget: AppResourceTarget ...) ConnectorAnomalyDetectionDisabledType (empty) + ConnectorSyncFailingType (empty) + ConnectorSyncFailingEvidence (consecutiveFailureCount: integer, lastFailedAt: date-time, lastSyncLifecycleId: string ...) + CredentialExpiringType (credentialDisplayName: string, userClientId: string) + CredentialExpiringEvidence (expired: boolean, expiresAt: date-time) + CredentialPubliclyExposedType (connectorClientId: string, connectorManagedCredentialId: string, credentialDisplayName: string ...) + CredentialPubliclyExposedEvidence (credentialRevoked: boolean, fingerprintPrefix: string, firstObservedAt: date-time ...) CustomFindingType (empty) + DeactivatedOwnerType (source: enum) + DeactivatedOwnerTypeSource (enum: DEACTIVATED_OWNER_SOURCE_UNSPECIFIED, DEACTIVATED_OWNER_SOURCE_IDENTITY_CORRELATION, DEACTIVATED_OWNER_SOURCE_OWNERSHIP_ASSIGNED ...) + DeactivatedOwnerEvidence (deactivatedOwners: array) + DeactivatedOwnerDetail (reason: enum, userId: string) + Reason (enum: DEACTIVATED_OWNER_REASON_UNSPECIFIED, DEACTIVATED_OWNER_REASON_USER_DELETED, DEACTIVATED_OWNER_REASON_USER_DISABLED ...) DecoyCredentialUsedType (decoyId: string, kind: enum) DecoyCredentialUsedTypeKind (enum: DECOY_CREDENTIAL_KIND_UNSPECIFIED, DECOY_CREDENTIAL_KIND_USER_CLIENT_CREDENTIAL, DECOY_CREDENTIAL_KIND_CONNECTOR_CLIENT ...) + DecoyPubliclyExposedType (decoyDisplayName: string, decoyId: string) + DecoyPubliclyExposedEvidence (credentialRevoked: boolean, fingerprintPrefix: string, firstObservedAt: date-time ...) NhiUnownedType (empty) FindingRiskScore (originalScore: integer, overrideByUserId: string, overrideScore: integer ...) FindingRiskFactor (description: string, name: string, severity: enum ...) @@ -1641,6 +1840,8 @@ C1ApiFindingV1FindingServiceCreateFindingResponse (ContentType: string, CreateFi SimilarUsernameMatchEvidence (appUsername: string, identityUsername: string, similarityScore: number) SourceKind (enum: FINDING_SOURCE_KIND_UNSPECIFIED, FINDING_SOURCE_KIND_DETECTOR, FINDING_SOURCE_KIND_EXTERNAL) FindingState (enum: FINDING_STATE_UNSPECIFIED, FINDING_STATE_OPEN, FINDING_STATE_IN_PROGRESS ...) + UnusedSecretType (empty) + UnusedSecretEvidence (lastUsedAt: date-time) C1ApiFindingV1FindingServiceCreateFindingTaskRequest (CreateFindingTaskRequest: CreateFindingTaskRequest, finding_id: string) CreateFindingTaskRequest (policyId: string) C1ApiFindingV1FindingServiceCreateFindingTaskResponse (ContentType: string, CreateFindingTaskResponse: CreateFindingTaskResponse, StatusCode: int32 ...) @@ -1667,6 +1868,18 @@ CreateFindingRoutingRuleRequest (routingRule: FindingRoutingRule) CreateTaskAction (policyId: string) SnoozeRoutingAction (duration: string, reason: string) SuppressRoutingAction (reason: string) + FindingDispatcher (displayName: string, enabled: boolean, invokeFunction: InvokeFunctionDispatcher ...) + InvokeFunctionDispatcher (args: map, functionCommitId: string, functionId: string) + NotifyDispatcher (audience: FindingAudience, batchWindowSeconds: integer, detailLevel: enum ...) + FindingAudience (users: FindingAudienceUsers) + FindingAudienceUsers (userIds: array) + DetailLevel (enum: FINDING_NOTIFY_DETAIL_LEVEL_UNSPECIFIED, FINDING_NOTIFY_DETAIL_LEVEL_SUMMARY, FINDING_NOTIFY_DETAIL_LEVEL_FULL_DETAIL) + SlackChannelTarget (channelId: string, channelName: string) + FindingDispatchOutcomeNotify (onDone: boolean, onError: boolean, recipients: array) + TierOverride (enum: FINDING_DISPATCH_TIER_UNSPECIFIED, FINDING_DISPATCH_TIER_AUTO, FINDING_DISPATCH_TIER_REQUIRES_APPROVAL) + TriggerAutomationDispatcher (automationId: string, inputMapping: map) + WebhookDispatcher (payloadTemplate: string, webhookId: string) + FindingType (enum: FINDING_TYPE_UNSPECIFIED, FINDING_TYPE_SIMILAR_USERNAME_MATCH, FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION ...) C1ApiFindingV1FindingRoutingRuleServiceCreateFindingRoutingRuleResponse (ContentType: string, CreateFindingRoutingRuleResponse: CreateFindingRoutingRuleResponse, StatusCode: int32 ...) CreateFindingRoutingRuleResponse (routingRule: FindingRoutingRule) C1ApiFindingV1FindingRoutingRuleServiceDeleteFindingRoutingRuleRequest (DeleteFindingRoutingRuleRequest: DeleteFindingRoutingRuleRequest, id: string) @@ -1685,9 +1898,20 @@ C1ApiFindingV1FindingRoutingRuleServiceUpdateFindingRoutingRuleResponse (Content FindingSearch (SDK empty) C1ApiFindingV1FindingSearchServiceSearchResponse (ContentType: string, FindingSearchResponse: FindingSearchResponse, StatusCode: int32 ...) FindingSearchResponse (list: array, nextPageToken: string) +FindingSettings (SDK empty) +C1ApiFindingV1FindingSettingsServiceListFindingSettingsResponse (ContentType: string, ListFindingSettingsResponse: ListFindingSettingsResponse, StatusCode: int32 ...) + ListFindingSettingsResponse (configured: boolean, list: array) + FindingTypeSetting (enabled: boolean, findingType: enum) + FindingTypeSettingFindingType (enum: FINDING_TYPE_UNSPECIFIED, FINDING_TYPE_SIMILAR_USERNAME_MATCH, FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION ...) +UpdateFindingSettingsRequest (settings: array) + FindingSettingsEntry (enabled: boolean, findingType: enum) + FindingSettingsEntryFindingType (enum: FINDING_TYPE_UNSPECIFIED, FINDING_TYPE_SIMILAR_USERNAME_MATCH, FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION ...) +C1ApiFindingV1FindingSettingsServiceUpdateFindingSettingsResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) + UpdateFindingSettingsResponse (list: array) FindingTransformationRule (SDK empty) CreateFindingTransformationRuleRequest (transformationRule: FindingTransformationRule) FindingTransformationRule (appId: string, condition: string, createdAt: date-time ...) + FindingTransformationRuleFindingType (enum: FINDING_TYPE_UNSPECIFIED, FINDING_TYPE_SIMILAR_USERNAME_MATCH, FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION ...) FindingTransform (removeTags: RemoveTags, setSeverity: SetSeverity, setTags: SetTags) RemoveTags (keys: array) SetSeverity (severity: enum) @@ -1761,10 +1985,10 @@ C1ApiFunctionsV1FunctionsServiceTestResponse (ContentType: string, FunctionsServ FunctionTestResultAssertion (actual: string, at: string, description: string ...) FunctionTestResultLog (level: string, log: string, source: string) FunctionTestResultStatus (enum: FUNCTION_TEST_RESULT_STATUS_UNSPECIFIED, FUNCTION_TEST_RESULT_STATUS_OK, FUNCTION_TEST_RESULT_STATUS_FAIL ...) -FunctionsServiceUpdateFunctionRequest (function: Function_input, updateMask: string) +FunctionsServiceUpdateFunctionRequest (commitMessage: string, content: map, function: Function_input ...) FunctionInput (description: string, displayName: string, functionType: enum ...) C1ApiFunctionsV1FunctionsServiceUpdateFunctionResponse (ContentType: string, FunctionsServiceUpdateFunctionResponse: FunctionsServiceUpdateFunctionResponse, StatusCode: int32 ...) - FunctionsServiceUpdateFunctionResponse (function: Function) + FunctionsServiceUpdateFunctionResponse (commit: FunctionCommit, function: Function) FunctionsInvocation (SDK empty) C1ApiFunctionsV1FunctionsInvocationServiceGetRequest (function_id: string, id: string) C1ApiFunctionsV1FunctionsInvocationServiceGetResponse (ContentType: string, FunctionsInvocationServiceGetResponse: FunctionsInvocationServiceGetResponse, StatusCode: int32 ...) @@ -1779,24 +2003,191 @@ C1ApiFunctionsV1FunctionsInvocationSearchServiceSearchRequest (FunctionsInvocati FunctionsInvocationSearchRequest (pageSize: int32, pageToken: string) C1ApiFunctionsV1FunctionsInvocationSearchServiceSearchResponse (ContentType: string, FunctionsInvocationSearchResponse: FunctionsInvocationSearchResponse, StatusCode: int32 ...) FunctionsInvocationSearchResponse (list: array, nextPageToken: string) +AppCap (SDK empty) +C1ApiFundsV1AppCapServiceDeleteRequest (AppCapServiceDeleteRequest: AppCapServiceDeleteRequest, app_id: string) + AppCapServiceDeleteRequest (empty) +C1ApiFundsV1AppCapServiceDeleteResponse (AppCapServiceDeleteResponse: AppCapServiceDeleteResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceDeleteResponse (empty) +C1ApiFundsV1AppCapServiceGetRequest (app_id: string) +C1ApiFundsV1AppCapServiceGetResponse (AppCapServiceGetResponse: AppCapServiceGetResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceGetResponse (cap: AppCap) + AppCap (appId: string, controls: SpendControls, createdAt: date-time ...) + SpendControls (extension: SpendExtension, limit: SpendLimit, period: enum ...) + SpendExtension (expiresAt: date-time, limit: SpendLimit, reason: string) + SpendLimit (amount: SpendLimitAmount, blocked: SpendLimitBlocked, unlimited: SpendLimitUnlimited) + SpendLimitAmount (money: Money) + Money (currencyCode: string, nanos: int32, units: integer) + SpendLimitBlocked (empty) + SpendLimitUnlimited (empty) + SpendControlsPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) + SpendSuspension (reason: string, suspendedAt: date-time) +C1ApiFundsV1AppCapServiceListRequest (page_size: int32, page_token: string) +C1ApiFundsV1AppCapServiceListResponse (AppCapServiceListResponse: AppCapServiceListResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceListResponse (list: array, nextPageToken: string) +C1ApiFundsV1AppCapServiceListHistoryRequest (app_id: string, page_size: int32, page_token: string) +C1ApiFundsV1AppCapServiceListHistoryResponse (AppCapServiceListHistoryResponse: AppCapServiceListHistoryResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceListHistoryResponse (list: array, nextPageToken: string) + AppCapHistoryEntry (metadata: HistoryEntryMetadata, snapshot: AppCap) +C1ApiFundsV1AppCapServiceSetLimitRequest (AppCapServiceSetLimitRequest: AppCapServiceSetLimitRequest, app_id: string) + AppCapServiceSetLimitRequest (limit: SpendLimit, period: enum) + Period (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +C1ApiFundsV1AppCapServiceSetLimitResponse (AppCapServiceSetLimitResponse: AppCapServiceSetLimitResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceSetLimitResponse (cap: AppCap) +C1ApiFundsV1AppCapServiceSuspendRequest (AppCapServiceSuspendRequest: AppCapServiceSuspendRequest, app_id: string) + AppCapServiceSuspendRequest (reason: string) +C1ApiFundsV1AppCapServiceSuspendResponse (AppCapServiceSuspendResponse: AppCapServiceSuspendResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceSuspendResponse (cap: AppCap) +C1ApiFundsV1AppCapServiceUnsuspendRequest (AppCapServiceUnsuspendRequest: AppCapServiceUnsuspendRequest, app_id: string) + AppCapServiceUnsuspendRequest (empty) +C1ApiFundsV1AppCapServiceUnsuspendResponse (AppCapServiceUnsuspendResponse: AppCapServiceUnsuspendResponse, ContentType: string, StatusCode: int32 ...) + AppCapServiceUnsuspendResponse (cap: AppCap) +FundAssignment (SDK empty) +C1ApiFundsV1FundAssignmentServiceClearExtensionRequest (FundAssignmentServiceClearExtensionRequest: FundAssignmentServiceClearExtensionRequest, user_id: string) + FundAssignmentServiceClearExtensionRequest (empty) +C1ApiFundsV1FundAssignmentServiceClearExtensionResponse (ContentType: string, FundAssignmentServiceClearExtensionResponse: FundAssignmentServiceClearExtensionResponse, StatusCode: int32 ...) + FundAssignmentServiceClearExtensionResponse (assignment: FundAssignment) + FundAssignment (controls: SpendControls, createdAt: date-time, tenantId: string ...) +C1ApiFundsV1FundAssignmentServiceDeleteRequest (FundAssignmentServiceDeleteRequest: FundAssignmentServiceDeleteRequest, user_id: string) + FundAssignmentServiceDeleteRequest (empty) +C1ApiFundsV1FundAssignmentServiceDeleteResponse (ContentType: string, FundAssignmentServiceDeleteResponse: FundAssignmentServiceDeleteResponse, StatusCode: int32 ...) + FundAssignmentServiceDeleteResponse (empty) +C1ApiFundsV1FundAssignmentServiceGetRequest (user_id: string) +C1ApiFundsV1FundAssignmentServiceGetResponse (ContentType: string, FundAssignmentServiceGetResponse: FundAssignmentServiceGetResponse, StatusCode: int32 ...) + FundAssignmentServiceGetResponse (assignment: FundAssignment) +C1ApiFundsV1FundAssignmentServiceGrantExtensionRequest (FundAssignmentServiceGrantExtensionRequest: FundAssignmentServiceGrantExtensionRequest, user_id: string) + FundAssignmentServiceGrantExtensionRequest (expiresAt: date-time, limit: SpendLimit, reason: string) +C1ApiFundsV1FundAssignmentServiceGrantExtensionResponse (ContentType: string, FundAssignmentServiceGrantExtensionResponse: FundAssignmentServiceGrantExtensionResponse, StatusCode: int32 ...) + FundAssignmentServiceGrantExtensionResponse (assignment: FundAssignment) +C1ApiFundsV1FundAssignmentServiceListHistoryRequest (page_size: int32, page_token: string, user_id: string) +C1ApiFundsV1FundAssignmentServiceListHistoryResponse (ContentType: string, FundAssignmentServiceListHistoryResponse: FundAssignmentServiceListHistoryResponse, StatusCode: int32 ...) + FundAssignmentServiceListHistoryResponse (list: array, nextPageToken: string) + FundAssignmentHistoryEntry (metadata: HistoryEntryMetadata, snapshot: FundAssignment) +FundAssignmentServiceSearchRequest (pageSize: int32, pageToken: string, userIds: array) +C1ApiFundsV1FundAssignmentServiceSearchResponse (ContentType: string, FundAssignmentServiceSearchResponse: FundAssignmentServiceSearchResponse, StatusCode: int32 ...) + FundAssignmentServiceSearchResponse (list: array, nextPageToken: string) +C1ApiFundsV1FundAssignmentServiceSetLimitRequest (FundAssignmentServiceSetLimitRequest: FundAssignmentServiceSetLimitRequest, user_id: string) + FundAssignmentServiceSetLimitRequest (limit: SpendLimit, period: enum) + FundAssignmentServiceSetLimitRequestPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +C1ApiFundsV1FundAssignmentServiceSetLimitResponse (ContentType: string, FundAssignmentServiceSetLimitResponse: FundAssignmentServiceSetLimitResponse, StatusCode: int32 ...) + FundAssignmentServiceSetLimitResponse (assignment: FundAssignment) +C1ApiFundsV1FundAssignmentServiceSuspendRequest (FundAssignmentServiceSuspendRequest: FundAssignmentServiceSuspendRequest, user_id: string) + FundAssignmentServiceSuspendRequest (reason: string) +C1ApiFundsV1FundAssignmentServiceSuspendResponse (ContentType: string, FundAssignmentServiceSuspendResponse: FundAssignmentServiceSuspendResponse, StatusCode: int32 ...) + FundAssignmentServiceSuspendResponse (assignment: FundAssignment) +C1ApiFundsV1FundAssignmentServiceUnsuspendRequest (FundAssignmentServiceUnsuspendRequest: FundAssignmentServiceUnsuspendRequest, user_id: string) + FundAssignmentServiceUnsuspendRequest (empty) +C1ApiFundsV1FundAssignmentServiceUnsuspendResponse (ContentType: string, FundAssignmentServiceUnsuspendResponse: FundAssignmentServiceUnsuspendResponse, StatusCode: int32 ...) + FundAssignmentServiceUnsuspendResponse (assignment: FundAssignment) +MyFundLimits (SDK empty) +C1ApiFundsV1MyFundLimitsServiceDeleteRequest (MyFundLimitsServiceDeleteRequest: MyFundLimitsServiceDeleteRequest, app_id: string) + MyFundLimitsServiceDeleteRequest (empty) +C1ApiFundsV1MyFundLimitsServiceDeleteResponse (ContentType: string, MyFundLimitsServiceDeleteResponse: MyFundLimitsServiceDeleteResponse, StatusCode: int32 ...) + MyFundLimitsServiceDeleteResponse (empty) +C1ApiFundsV1MyFundLimitsServiceListRequest (page_size: int32, page_token: string) +C1ApiFundsV1MyFundLimitsServiceListResponse (ContentType: string, MyFundLimitsServiceListResponse: MyFundLimitsServiceListResponse, StatusCode: int32 ...) + MyFundLimitsServiceListResponse (list: array, nextPageToken: string) + MyFundLimit (appId: string, controls: SpendControls, createdAt: date-time ...) +C1ApiFundsV1MyFundLimitsServiceListHistoryRequest (app_id: string, page_size: int32, page_token: string) +C1ApiFundsV1MyFundLimitsServiceListHistoryResponse (ContentType: string, MyFundLimitsServiceListHistoryResponse: MyFundLimitsServiceListHistoryResponse, StatusCode: int32 ...) + MyFundLimitsServiceListHistoryResponse (list: array, nextPageToken: string) + MyFundLimitHistoryEntry (metadata: HistoryEntryMetadata, snapshot: MyFundLimit) +C1ApiFundsV1MyFundLimitsServicePauseRequest (MyFundLimitsServicePauseRequest: MyFundLimitsServicePauseRequest, app_id: string) + MyFundLimitsServicePauseRequest (reason: string) +C1ApiFundsV1MyFundLimitsServicePauseResponse (ContentType: string, MyFundLimitsServicePauseResponse: MyFundLimitsServicePauseResponse, StatusCode: int32 ...) + MyFundLimitsServicePauseResponse (limit: MyFundLimit) +C1ApiFundsV1MyFundLimitsServiceResumeRequest (MyFundLimitsServiceResumeRequest: MyFundLimitsServiceResumeRequest, app_id: string) + MyFundLimitsServiceResumeRequest (empty) +C1ApiFundsV1MyFundLimitsServiceResumeResponse (ContentType: string, MyFundLimitsServiceResumeResponse: MyFundLimitsServiceResumeResponse, StatusCode: int32 ...) + MyFundLimitsServiceResumeResponse (limit: MyFundLimit) +C1ApiFundsV1MyFundLimitsServiceSetLimitRequest (MyFundLimitsServiceSetLimitRequest: MyFundLimitsServiceSetLimitRequest, app_id: string) + MyFundLimitsServiceSetLimitRequest (limit: SpendLimit, period: enum) + MyFundLimitsServiceSetLimitRequestPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +C1ApiFundsV1MyFundLimitsServiceSetLimitResponse (ContentType: string, MyFundLimitsServiceSetLimitResponse: MyFundLimitsServiceSetLimitResponse, StatusCode: int32 ...) + MyFundLimitsServiceSetLimitResponse (limit: MyFundLimit) +FundPolicy (SDK empty) +FundPolicyServiceCreateRequest (currencyCode: string, defaultLimit: SpendLimit, period: enum) + FundPolicyServiceCreateRequestPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +C1ApiFundsV1FundPolicyServiceCreateResponse (ContentType: string, FundPolicyServiceCreateResponse: FundPolicyServiceCreateResponse, StatusCode: int32 ...) + FundPolicyServiceCreateResponse (policy: FundPolicy) + FundPolicy (createdAt: date-time, currencyCode: string, defaultLimit: SpendLimit ...) + FundPolicyPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +FundPolicyServiceDeleteRequest (empty) +C1ApiFundsV1FundPolicyServiceDeleteResponse (ContentType: string, FundPolicyServiceDeleteResponse: FundPolicyServiceDeleteResponse, StatusCode: int32 ...) + FundPolicyServiceDeleteResponse (empty) +FundPolicyServiceFreezeTenantRequest (reason: string) +C1ApiFundsV1FundPolicyServiceFreezeTenantResponse (ContentType: string, FundPolicyServiceFreezeTenantResponse: FundPolicyServiceFreezeTenantResponse, StatusCode: int32 ...) + FundPolicyServiceFreezeTenantResponse (policy: FundPolicy) +C1ApiFundsV1FundPolicyServiceGetResponse (ContentType: string, FundPolicyServiceGetResponse: FundPolicyServiceGetResponse, StatusCode: int32 ...) + FundPolicyServiceGetResponse (policy: FundPolicy) +C1ApiFundsV1FundPolicyServiceListHistoryRequest (page_size: int32, page_token: string) +C1ApiFundsV1FundPolicyServiceListHistoryResponse (ContentType: string, FundPolicyServiceListHistoryResponse: FundPolicyServiceListHistoryResponse, StatusCode: int32 ...) + FundPolicyServiceListHistoryResponse (list: array, nextPageToken: string) + FundPolicyHistoryEntry (metadata: HistoryEntryMetadata, snapshot: FundPolicy) +FundPolicyServiceSetOrgCeilingRequest (limit: SpendLimit, period: enum) + FundPolicyServiceSetOrgCeilingRequestPeriod (enum: PERIOD_KIND_UNSPECIFIED, PERIOD_KIND_DAILY, PERIOD_KIND_WEEKLY ...) +C1ApiFundsV1FundPolicyServiceSetOrgCeilingResponse (ContentType: string, FundPolicyServiceSetOrgCeilingResponse: FundPolicyServiceSetOrgCeilingResponse, StatusCode: int32 ...) + FundPolicyServiceSetOrgCeilingResponse (policy: FundPolicy) +FundPolicyServiceUnfreezeTenantRequest (empty) +C1ApiFundsV1FundPolicyServiceUnfreezeTenantResponse (ContentType: string, FundPolicyServiceUnfreezeTenantResponse: FundPolicyServiceUnfreezeTenantResponse, StatusCode: int32 ...) + FundPolicyServiceUnfreezeTenantResponse (policy: FundPolicy) +FundPolicyServiceUpdateRequest (policy: FundPolicy, updateMask: string) +C1ApiFundsV1FundPolicyServiceUpdateResponse (ContentType: string, FundPolicyServiceUpdateResponse: FundPolicyServiceUpdateResponse, StatusCode: int32 ...) + FundPolicyServiceUpdateResponse (policy: FundPolicy) +FundRule (SDK empty) +FundRuleServiceCreateRequest (displayName: string, grant: SpendLimit, groupRef: AppEntitlementRef ...) +C1ApiFundsV1FundRuleServiceCreateResponse (ContentType: string, FundRuleServiceCreateResponse: FundRuleServiceCreateResponse, StatusCode: int32 ...) + FundRuleServiceCreateResponse (rule: FundRule) + FundRule (createdAt: date-time, displayName: string, grant: SpendLimit ...) +C1ApiFundsV1FundRuleServiceDeleteRequest (FundRuleServiceDeleteRequest: FundRuleServiceDeleteRequest, rule_id: string) + FundRuleServiceDeleteRequest (empty) +C1ApiFundsV1FundRuleServiceDeleteResponse (ContentType: string, FundRuleServiceDeleteResponse: FundRuleServiceDeleteResponse, StatusCode: int32 ...) + FundRuleServiceDeleteResponse (empty) +C1ApiFundsV1FundRuleServiceGetRequest (rule_id: string) +C1ApiFundsV1FundRuleServiceGetResponse (ContentType: string, FundRuleServiceGetResponse: FundRuleServiceGetResponse, StatusCode: int32 ...) + FundRuleServiceGetResponse (rule: FundRule) +C1ApiFundsV1FundRuleServiceListRequest (page_size: int32, page_token: string) +C1ApiFundsV1FundRuleServiceListResponse (ContentType: string, FundRuleServiceListResponse: FundRuleServiceListResponse, StatusCode: int32 ...) + FundRuleServiceListResponse (list: array, nextPageToken: string) +C1ApiFundsV1FundRuleServiceListHistoryRequest (page_size: int32, page_token: string, rule_id: string) +C1ApiFundsV1FundRuleServiceListHistoryResponse (ContentType: string, FundRuleServiceListHistoryResponse: FundRuleServiceListHistoryResponse, StatusCode: int32 ...) + FundRuleServiceListHistoryResponse (list: array, nextPageToken: string) + FundRuleHistoryEntry (metadata: HistoryEntryMetadata, snapshot: FundRule) +FundRuleServiceSearchRequest (pageSize: int32, pageToken: string, query: string) +C1ApiFundsV1FundRuleServiceSearchResponse (ContentType: string, FundRuleServiceSearchResponse: FundRuleServiceSearchResponse, StatusCode: int32 ...) + FundRuleServiceSearchResponse (list: array, nextPageToken: string) +C1ApiFundsV1FundRuleServiceUpdateRequest (FundRuleServiceUpdateRequest: FundRuleServiceUpdateRequest, rule_id: string) + FundRuleServiceUpdateRequest (rule: FundRule, updateMask: string) +C1ApiFundsV1FundRuleServiceUpdateResponse (ContentType: string, FundRuleServiceUpdateResponse: FundRuleServiceUpdateResponse, StatusCode: int32 ...) + FundRuleServiceUpdateResponse (rule: FundRule) Hooks (SDK empty) HooksServiceCreateRequest (builtinPattern: BuiltInPattern, description: string, displayName: string ...) - BuiltInPattern (creditCardBlocking: CreditCardBlockingConfig, piiRedaction: PIIRedactionConfig, queryScopeLimit: QueryScopeLimitConfig ...) + BuiltInPattern (blockOutput: BlockOutputConfig, blockToolCall: BlockToolCallConfig, creditCardBlocking: CreditCardBlockingConfig ...) + BlockOutputConfig (message: string, surfaces: array) + Surfaces (enum: HOOK_OUTPUT_SURFACE_UNSPECIFIED, HOOK_OUTPUT_SURFACE_SLACK, HOOK_OUTPUT_SURFACE_WEB) + BlockToolCallConfig (message: string) CreditCardBlockingConfig (empty) + EncodedContentGuardConfig (flagOnly: boolean, minBase64Run: int32, minHexRun: int32) + LinkFilterConfig (action: enum, allowedHosts: array, blockImages: boolean) + LinkFilterConfigAction (enum: LINK_FILTER_ACTION_UNSPECIFIED, LINK_FILTER_ACTION_REDACT, LINK_FILTER_ACTION_ANNOTATE) PiiRedactionConfig (redactFields: array, replacement: string) + PreToolBlockConfig (message: string) + PromptInjectionScanConfig (flagOnly: boolean, threshold: enum) + Threshold (enum: PROMPT_INJECTION_THRESHOLD_UNSPECIFIED, PROMPT_INJECTION_THRESHOLD_LOW, PROMPT_INJECTION_THRESHOLD_MEDIUM ...) QueryScopeLimitConfig (fields: array, maxLimit: int32) + SecretsMaskingConfig (additionalPatterns: array, placeholder: string) SensitiveFileGuardConfig (blockedDirectories: array, blockedPatterns: array) ToolOutputSizeGuardConfig (maxBytes: int32) WriteAuthorizationConfig (blockedClassifications: array, businessHours: BusinessHours) BlockedClassifications (enum: TOOL_CLASSIFICATION_UNSPECIFIED, TOOL_CLASSIFICATION_READ, TOOL_CLASSIFICATION_WRITE ...) BusinessHours (days: array, end: string, start: string ...) - HooksServiceCreateRequestEvent (enum: HOOK_EVENT_TYPE_UNSPECIFIED, HOOK_EVENT_TYPE_PRE_TOOL_USE, HOOK_EVENT_TYPE_POST_TOOL_USE) + HooksServiceCreateRequestEvent (enum: HOOK_EVENT_TYPE_UNSPECIFIED, HOOK_EVENT_TYPE_PRE_TOOL_USE, HOOK_EVENT_TYPE_POST_TOOL_USE ...) HookFilter (celExpression: string) HookFunctionRef (commitId: string, functionId: string) + JsonPatchConfig (celExpression: string, staticOverlay: map) C1ApiHooksV1HooksServiceCreateResponse (ContentType: string, HooksServiceCreateResponse: HooksServiceCreateResponse, StatusCode: int32 ...) HooksServiceCreateResponse (hook: Hook) Hook (builtinPattern: BuiltInPattern, createdAt: date-time, description: string ...) - Event (enum: HOOK_EVENT_TYPE_UNSPECIFIED, HOOK_EVENT_TYPE_PRE_TOOL_USE, HOOK_EVENT_TYPE_POST_TOOL_USE) + Event (enum: HOOK_EVENT_TYPE_UNSPECIFIED, HOOK_EVENT_TYPE_PRE_TOOL_USE, HOOK_EVENT_TYPE_POST_TOOL_USE ...) C1ApiHooksV1HooksServiceDeleteRequest (HooksServiceDeleteRequest: HooksServiceDeleteRequest, id: string) HooksServiceDeleteRequest (empty) C1ApiHooksV1HooksServiceDeleteResponse (ContentType: string, HooksServiceDeleteResponse: HooksServiceDeleteResponse, StatusCode: int32 ...) @@ -1909,6 +2300,32 @@ C1ApiIamV1TunnelCredentialsServiceUpdateBridgeRequest (TunnelCredentialsServiceU TunnelCredentialsServiceUpdateBridgeRequest (description: string, displayName: string, updateMask: string) C1ApiIamV1TunnelCredentialsServiceUpdateBridgeResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) TunnelCredentialsServiceUpdateBridgeResponse (bridge: TunnelBridge) +GatewayKey (SDK empty) +C1ApiLlmGatewayV1GatewayKeyServiceListResponse (ContentType: string, ListGatewayKeysResponse: ListGatewayKeysResponse, StatusCode: int32 ...) + ListGatewayKeysResponse (list: array, nextPageToken: string) + GatewayKey (createdAt: date-time, displayName: string, id: string ...) +MintGatewayKeyRequest (displayName: string) +C1ApiLlmGatewayV1GatewayKeyServiceMintResponse (ContentType: string, MintGatewayKeyResponse: MintGatewayKeyResponse, StatusCode: int32 ...) + MintGatewayKeyResponse (gatewayKey: GatewayKey, plaintextKey: string) +C1ApiLlmGatewayV1GatewayKeyServiceRevokeRequest (RevokeGatewayKeyRequest: RevokeGatewayKeyRequest, id: string) + RevokeGatewayKeyRequest (empty) +C1ApiLlmGatewayV1GatewayKeyServiceRevokeResponse (ContentType: string, RevokeGatewayKeyResponse: RevokeGatewayKeyResponse, StatusCode: int32 ...) + RevokeGatewayKeyResponse (gatewayKey: GatewayKey) +ProviderCredential (SDK empty) +C1ApiLlmGatewayV1ProviderCredentialServiceClearRequest (ClearProviderCredentialRequest: ClearProviderCredentialRequest, slot_id: string) + ClearProviderCredentialRequest (empty) +C1ApiLlmGatewayV1ProviderCredentialServiceClearResponse (ClearProviderCredentialResponse: ClearProviderCredentialResponse, ContentType: string, StatusCode: int32 ...) + ClearProviderCredentialResponse (credential: ProviderCredential) + ProviderCredential (createdAt: date-time, displayName: string, headerStyle: enum ...) + HeaderStyle (enum: PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED, PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY, PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER) +C1ApiLlmGatewayV1ProviderCredentialServiceGetRequest (slot_id: string) +C1ApiLlmGatewayV1ProviderCredentialServiceGetResponse (ContentType: string, GetProviderCredentialResponse: GetProviderCredentialResponse, StatusCode: int32 ...) + GetProviderCredentialResponse (credential: ProviderCredential) +C1ApiLlmGatewayV1ProviderCredentialServiceSetRequest (SetProviderCredentialRequest: SetProviderCredentialRequest, slot_id: string) + SetProviderCredentialRequest (apiKey: string, displayName: string, headerStyle: enum) + SetProviderCredentialRequestHeaderStyle (enum: PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED, PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY, PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER) +C1ApiLlmGatewayV1ProviderCredentialServiceSetResponse (ContentType: string, SetProviderCredentialResponse: SetProviderCredentialResponse, StatusCode: int32 ...) + SetProviderCredentialResponse (credential: ProviderCredential) LocalDirectoryConfig (SDK empty) LocalDirectoryConfigServiceCreateRequest (allowSelfRegistration: boolean, appId: string, defaultProfileTypeId: string ...) C1ApiLocalDirectoryV1LocalDirectoryConfigServiceCreateResponse (ContentType: string, LocalDirectoryConfigServiceCreateResponse: LocalDirectoryConfigServiceCreateResponse, StatusCode: int32 ...) @@ -1948,7 +2365,7 @@ LocalUserInvitationServiceSearchRequest (directoryAppId: string, pageSize: int32 C1ApiLocalDirectoryV1LocalUserInvitationServiceSearchResponse (ContentType: string, LocalUserInvitationServiceSearchResponse: LocalUserInvitationServiceSearchResponse, StatusCode: int32 ...) LocalUserInvitationServiceSearchResponse (list: array, nextPageToken: string) Policies (SDK empty) -CreatePolicyRequest (annotations: map, description: string, displayName: string ...) +CreatePolicyRequest (annotations: map, baselinePolicyId: string, description: string ...) PolicyStepsInput (steps: array) PolicyStepInput (accept: Accept, action: Action, approval: Approval_input ...) Accept (acceptMessage: string) @@ -1985,10 +2402,12 @@ CreatePolicyRequest (annotations: map, description: string, displayName: string WaitUntilTime (hours: integer, minutes: integer, timezone: string) PolicyType (enum: POLICY_TYPE_UNSPECIFIED, POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE ...) PolicyPostActions (certifyRemediateImmediately: boolean) - Rule (condition: string, policyKey: string) + Rule (condition: string, policyId: string, policyKey: string ...) + PolicyScope (appEntitlementId: string, appId: string, slot: enum) + Slot (enum: POLICY_SCOPE_SLOT_UNSPECIFIED, POLICY_SCOPE_SLOT_EMERGENCY) C1ApiPolicyV1PoliciesCreateResponse (ContentType: string, CreatePolicyResponse: CreatePolicyResponse, StatusCode: int32 ...) CreatePolicyResponse (policy: Policy) - Policy (annotations: map, createdAt: date-time, deletedAt: date-time ...) + Policy (annotations: map, baselinePolicyId: string, createdAt: date-time ...) PolicySteps (steps: array) PolicyStep (accept: Accept, action: Action, approval: Approval ...) Approval (agent: AgentApproval, allowDelegation: boolean, allowReassignment: boolean ...) @@ -2009,7 +2428,7 @@ C1ApiPolicyV1PoliciesListResponse (ContentType: string, ListPolicyResponse: List ListPolicyResponse (list: array, nextPageToken: string) C1ApiPolicyV1PoliciesUpdateRequest (UpdatePolicyRequest: UpdatePolicyRequest, id: string) UpdatePolicyRequest (policy: Policy_input, updateMask: string) - PolicyInput (annotations: map, description: string, displayName: string ...) + PolicyInput (annotations: map, baselinePolicyId: string, description: string ...) C1ApiPolicyV1PoliciesUpdateResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) UpdatePolicyResponse (policy: Policy) AccountProvisionPolicyTest (SDK empty) @@ -2048,6 +2467,36 @@ C1ApiCredentialInventoryV1RecoveryPolicyServiceUpdateRequest (RecoveryPolicyServ RecoveryPolicyInput (allowedRecoveryTypes: array, displayName: string, minRecoveryAuthLevel: enum ...) C1ApiCredentialInventoryV1RecoveryPolicyServiceUpdateResponse (ContentType: string, RecoveryPolicyServiceUpdateResponse: RecoveryPolicyServiceUpdateResponse, StatusCode: int32 ...) RecoveryPolicyServiceUpdateResponse (recoveryPolicy: RecoveryPolicy) +Reporting (SDK empty) +C1ApiReportingV1ReportingServiceDeleteRequest (ReportingServiceDeleteRequest: ReportingServiceDeleteRequest, id: string) + ReportingServiceDeleteRequest (empty) +C1ApiReportingV1ReportingServiceDeleteResponse (ContentType: string, ReportingServiceDeleteResponse: ReportingServiceDeleteResponse, StatusCode: int32 ...) + ReportingServiceDeleteResponse (empty) +C1ApiReportingV1ReportingServiceGetRequest (id: string) +C1ApiReportingV1ReportingServiceGetResponse (ContentType: string, ReportingServiceGetResponse: ReportingServiceGetResponse, StatusCode: int32 ...) + ReportingServiceGetResponse (latestRun: ReportRun, latestSuccessfulRun: ReportRun, promptDrifted: boolean ...) + ReportRun (artifactUrl: string, conversationId: string, createdAt: date-time ...) + ProgramRef (commitId: string, functionId: string, plannedFromPrompt: string) + ReportSource (count: integer, kind: string, label: string ...) + ReportRunStatus (enum: REPORT_RUN_STATUS_UNSPECIFIED, REPORT_RUN_STATUS_PENDING, REPORT_RUN_STATUS_SUCCEEDED ...) + Report (createdAt: date-time, createdByUserId: string, deletedAt: date-time ...) +C1ApiReportingV1ReportingServiceGetRunProvenanceRequest (id: string, run_id: string) +C1ApiReportingV1ReportingServiceGetRunProvenanceResponse (ContentType: string, ReportingServiceGetRunProvenanceResponse: ReportingServiceGetRunProvenanceResponse, StatusCode: int32 ...) + ReportingServiceGetRunProvenanceResponse (programCommitId: string, programFunctionId: string, programInput: string ...) +C1ApiReportingV1ReportingServiceListRequest (page_size: int32, page_token: string) +C1ApiReportingV1ReportingServiceListResponse (ContentType: string, ReportingServiceListResponse: ReportingServiceListResponse, StatusCode: int32 ...) + ReportingServiceListResponse (list: array, nextPageToken: string) +C1ApiReportingV1ReportingServiceRunRequest (ReportingServiceRunRequest: ReportingServiceRunRequest, id: string) + ReportingServiceRunRequest (empty) +C1ApiReportingV1ReportingServiceRunResponse (ContentType: string, ReportingServiceRunResponse: ReportingServiceRunResponse, StatusCode: int32 ...) + ReportingServiceRunResponse (run: ReportRun) +ReportingServiceSaveRequest (conversationId: string, displayName: string, prompt: string ...) +C1ApiReportingV1ReportingServiceSaveResponse (ContentType: string, ReportingServiceSaveResponse: ReportingServiceSaveResponse, StatusCode: int32 ...) + ReportingServiceSaveResponse (report: Report) +C1ApiReportingV1ReportingServiceUpdateRequest (ReportingServiceUpdateRequest: ReportingServiceUpdateRequest, id: string) + ReportingServiceUpdateRequest (displayName: string, parameterValues: map, prompt: string) +C1ApiReportingV1ReportingServiceUpdateResponse (ContentType: string, ReportingServiceUpdateResponse: ReportingServiceUpdateResponse, StatusCode: int32 ...) + ReportingServiceUpdateResponse (report: Report) RequestSchema (SDK empty) RequestSchemaServiceCreateRequest (description: string, fieldGroups: array, fieldRelationships: array ...) RequestSchemaServiceCreateRequestJustificationVisibility (enum: JUSTIFICATION_VISIBILITY_UNSPECIFIED, JUSTIFICATION_VISIBILITY_SHOW, JUSTIFICATION_VISIBILITY_HIDE) @@ -2081,12 +2530,18 @@ CreateAccessProfileFromCohortRequest (celExpression: string, createTasks: boolea ProfileFilter (attribute: string, values: array) C1ApiRoleMiningManagementV1RoleMiningManagementServiceCreateAccessProfileFromCohortResponse (ContentType: string, CreateAccessProfileFromCohortResponse: CreateAccessProfileFromCohortResponse, StatusCode: int32 ...) CreateAccessProfileFromCohortResponse (accessProfileId: string, celExpression: string) +C1ApiRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest (EvaluateEntitlementSelectionRequest: EvaluateEntitlementSelectionRequest, analysis_id: string) + EvaluateEntitlementSelectionRequest (explicitlyExcluded: array, explicitlyIncluded: array, includeFacets: boolean ...) + EntitlementRef (appId: string, entitlementId: string) +C1ApiRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse (ContentType: string, EvaluateEntitlementSelectionResponse: EvaluateEntitlementSelectionResponse, StatusCode: int32 ...) + EvaluateEntitlementSelectionResponse (coreHolderFacets: array, selectedEntitlementCount: int32, usersWithAllEntitlements: int32) + AttributeFacet (attribute: string, displayName: string, values: array) + RoleMiningAttributeValue (displayName: string, userCount: int32, value: string) C1ApiRoleMiningManagementV1RoleMiningManagementServiceGetCustomAnalysisResultRequest (id: string) C1ApiRoleMiningManagementV1RoleMiningManagementServiceGetCustomAnalysisResultResponse (ContentType: string, GetCustomAnalysisResultResponse: GetCustomAnalysisResultResponse, StatusCode: int32 ...) GetCustomAnalysisResultResponse (appsAnalyzed: int32, clusters: array, cohortSize: int32 ...) EntitlementCluster (avgCoverage: number, avgSimilarity: number, entitlements: array ...) - AttributeFacet (attribute: string, displayName: string, values: array) - RoleMiningAttributeValue (displayName: string, userCount: int32, value: string) + EntitlementCutoffImpactPoint (entitlementCount: int32, minimumCoverageBasisPoints: int32, usersWithAllEntitlements: int32) GetCustomAnalysisResultResponseStatus (enum: RUN_STATUS_UNSPECIFIED, RUN_STATUS_RUNNING, RUN_STATUS_COMPLETED ...) C1ApiRoleMiningManagementV1RoleMiningManagementServiceGetLatestRunResponse (ContentType: string, GetLatestRunResponse: GetLatestRunResponse, StatusCode: int32 ...) GetLatestRunResponse (run: RoleMiningManagementRun) @@ -2114,7 +2569,6 @@ C1ApiRoleMiningManagementV1RoleMiningManagementServiceListSuggestionsResponse (C ListSuggestionsResponse (list: array, nextPageToken: string) C1ApiRoleMiningManagementV1RoleMiningManagementServiceSearchCohortUsersRequest (SearchCohortUsersRequest: SearchCohortUsersRequest, suggestion_id: string) SearchCohortUsersRequest (pageSize: int32, pageToken: string, profileFilters: array ...) - EntitlementRef (appId: string, entitlementId: string) C1ApiRoleMiningManagementV1RoleMiningManagementServiceSearchCohortUsersResponse (ContentType: string, SearchCohortUsersResponse: SearchCohortUsersResponse, StatusCode: int32 ...) SearchCohortUsersResponse (list: array, nextPageToken: string, usersWithCoverage: array) CohortUserWithCoverage (coveredCount: int32, user: User) @@ -2151,7 +2605,7 @@ SearchAppResourceTypesRequest (appIds: array, appUserIds: array, displayName: st C1ApiAppV1AppResourceSearchSearchAppResourceTypesResponse (ContentType: string, SearchAppResourceTypesResponse: SearchAppResourceTypesResponse, StatusCode: int32 ...) SearchAppResourceTypesResponse (list: array, nextPageToken: string) SearchAppResourcesRequest (agentStatuses: array, appId: string, appIds: array ...) - AgentStatuses (enum: AGENT_STATUS_UNSPECIFIED, AGENT_STATUS_READY, AGENT_STATUS_DISABLED ...) + SearchAppResourcesRequestAgentStatuses (enum: AGENT_STATUS_UNSPECIFIED, AGENT_STATUS_READY, AGENT_STATUS_DISABLED ...) SearchAppResourcesRequestCredentialTypes (enum: CREDENTIAL_TYPE_UNSPECIFIED, CREDENTIAL_TYPE_STATIC_SECRET, CREDENTIAL_TYPE_ASYMMETRIC_KEY ...) Direction (enum: SORT_DIRECTION_UNSPECIFIED, SORT_DIRECTION_ASC, SORT_DIRECTION_DESC) SearchAppResourcesRequestNhiTypes (enum: NHI_TYPE_UNSPECIFIED, NHI_TYPE_APP_REGISTRATION, NHI_TYPE_ASSUMABLE_ROLE ...) @@ -2212,7 +2666,7 @@ ExternalClientSearchServiceSearchRequest (clientIdUrls: array, pageSize: int32, C1ApiIamV1ExternalClientSearchServiceSearchResponse (ContentType: string, ExternalClientSearchServiceSearchResponse: ExternalClientSearchServiceSearchResponse, StatusCode: int32 ...) ExternalClientSearchServiceSearchResponse (list: array, nextPageToken: string) ExternalClientInfo (clientId: string, clientIdType: enum, clientIdUrl: string ...) - ClientIdType (enum: CLIENT_ID_TYPE_UNSPECIFIED, CLIENT_ID_TYPE_DCR, CLIENT_ID_TYPE_METADATA_URL) + ClientIdType (enum: CLIENT_ID_TYPE_UNSPECIFIED, CLIENT_ID_TYPE_DCR, CLIENT_ID_TYPE_METADATA_URL ...) WellKnownClient (enum: WELL_KNOWN_CLIENT_UNSPECIFIED, WELL_KNOWN_CLIENT_UNKNOWN, WELL_KNOWN_CLIENT_CLAUDE_AI ...) PersonalClientSearch (SDK empty) PersonalClientSearchServiceSearchRequest (pageSize: int32, pageToken: string, query: string ...) @@ -2221,6 +2675,9 @@ C1ApiIamV1PersonalClientSearchServiceSearchResponse (ContentType: string, Person PolicySearch (SDK empty) SearchPoliciesRequest (displayName: string, excludePolicyIds: array, includeDeleted: boolean ...) PolicyTypes (enum: POLICY_TYPE_UNSPECIFIED, POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE ...) + ScopeObjectType (enum: POLICY_SCOPE_OBJECT_TYPE_UNSPECIFIED, POLICY_SCOPE_OBJECT_TYPE_APP, POLICY_SCOPE_OBJECT_TYPE_ENTITLEMENT) + ScopeSlot (enum: POLICY_SCOPE_SLOT_UNSPECIFIED, POLICY_SCOPE_SLOT_EMERGENCY) + ScopeView (enum: POLICY_SCOPE_VIEW_UNSPECIFIED, POLICY_SCOPE_VIEW_GLOBAL, POLICY_SCOPE_VIEW_SCOPED ...) C1ApiPolicyV1PolicySearchSearchResponse (ContentType: string, SearchPoliciesResponse: SearchPoliciesResponse, StatusCode: int32 ...) SearchPoliciesResponse (list: array, nextPageToken: string) RequestCatalogSearch (SDK empty) @@ -2322,7 +2779,7 @@ SessionPolicyServiceCreateRequest (accessTokenTtlSeconds: int32, continuousDefau SessionPolicyEnrollmentRequired (credentialTypes: array) SessionPolicyEnrollmentRequiredCredentialTypes (enum: CREDENTIAL_TYPE_UNSPECIFIED, CREDENTIAL_TYPE_PASSKEY, CREDENTIAL_TYPE_PASSWORD ...) SessionPolicyStepUpRequired (level: enum, maxAgeSeconds: int32, types: array) - Level (enum: AUTH_LEVEL_UNSPECIFIED, AUTH_LEVEL_NONE, AUTH_LEVEL_SINGLE_FACTOR ...) + SessionPolicyStepUpRequiredLevel (enum: AUTH_LEVEL_UNSPECIFIED, AUTH_LEVEL_NONE, AUTH_LEVEL_SINGLE_FACTOR ...) SessionPolicyStepUpRequiredTypes (enum: CREDENTIAL_TYPE_UNSPECIFIED, CREDENTIAL_TYPE_PASSKEY, CREDENTIAL_TYPE_PASSWORD ...) SessionPolicyPolicyRule (description: string, id: string, matchCel: string ...) SessionPolicyPolicyRuleMode (enum: POLICY_RULE_MODE_UNSPECIFIED, POLICY_RULE_MODE_ENFORCE, POLICY_RULE_MODE_OBSERVE ...) @@ -2475,7 +2932,8 @@ C1ApiSystemlogV1ExportsSearchServiceSearchResponse (ContentType: string, Exports ExportToDatasourceFormat (enum: EXPORT_FORMAT_UNSPECIFIED, EXPORT_FORMAT_OCSF_JSON_ZSTD, EXPORT_FORMAT_OCSF_JSON_GZIP) ExporterState (enum: EXPORT_STATE_UNSPECIFIED, EXPORT_STATE_EXPORTING, EXPORT_STATE_WAITING ...) TaskSearch (SDK empty) -TaskSearchRequest (accessReviewIds: array, accountOwnerIds: array, accountTypes: array ...) +TaskSearchRequest (accessReviewIds: array, accountOwnerIds: array, accountStatuses: array ...) + AccountStatuses (enum: STATUS_UNSPECIFIED, STATUS_ENABLED, STATUS_DISABLED ...) TaskSearchRequestAccountTypes (enum: APP_USER_TYPE_UNSPECIFIED, APP_USER_TYPE_USER, APP_USER_TYPE_SERVICE_ACCOUNT ...) CertifyOutcomes (enum: CERTIFY_OUTCOME_UNSPECIFIED, CERTIFY_OUTCOME_CERTIFIED, CERTIFY_OUTCOME_DECERTIFIED ...) CurrentStep (enum: TASK_SEARCH_CURRENT_STEP_UNSPECIFIED, TASK_SEARCH_CURRENT_STEP_APPROVAL, TASK_SEARCH_CURRENT_STEP_PROVISION) @@ -2551,6 +3009,9 @@ C1ApiTaskV1TaskSearchServiceSearchResponse (ContentType: string, StatusCode: int CompletedAction (completedAt: date-time, entitlements: array, userId: string) ErroredAction (description: string, errorCode: string, erroredAt: date-time) ProvisionInstanceState (enum: PROVISION_INSTANCE_STATE_UNSPECIFIED, PROVISION_INSTANCE_STATE_INIT, PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET ...) + ProvisionWaitingOn (devicePlacement: WaitingForDevicePlacement, entitlementMerge: WaitingForEntitlementMerge, fallbackAt: date-time ...) + WaitingForDevicePlacement (recipientUserId: string, vaultBoundaryId: string) + WaitingForEntitlementMerge (appEntitlementId: string, appId: string) RejectInstance (rejectMessage: string) PolicyStepInstanceState (enum: POLICY_STEP_STATE_UNSPECIFIED, POLICY_STEP_STATE_ACTIVE, POLICY_STEP_STATE_DONE) WaitInstance (commentOnFirstWait: string, commentOnTimeout: string, condition: WaitConditionInstance ...) @@ -2568,7 +3029,7 @@ C1ApiTaskV1TaskSearchServiceSearchResponse (ContentType: string, StatusCode: int TaskActionInstance (batonResourceActionRef: BatonResourceActionRef, connectorActionRef: ConnectorActionRef, displayName: string) BatonResourceActionRef (appId: string, batonActionDisplayName: string, batonActionName: string ...) ConnectorActionRef (appId: string, connectorId: string, operation: enum) - Operation (enum: OPERATION_UNSPECIFIED, OPERATION_GRANT) + ConnectorActionRefOperation (enum: OPERATION_UNSPECIFIED, OPERATION_GRANT) FindingTarget (findingId: string, findingType: string) TaskTypeActionOutcome (enum: ACTION_OUTCOME_UNSPECIFIED, ACTION_OUTCOME_SUCCESS, ACTION_OUTCOME_DENIED ...) ScopeRole (appId: string, grantDuration: string, roleResourceId: string ...) @@ -2839,7 +3300,9 @@ C1ApiSettingsV1OrgNotificationSettingsServiceGetResponse (ContentType: string, G Frequency (enum: DIGEST_FREQUENCY_UNSPECIFIED, DIGEST_FREQUENCY_DAILY, DIGEST_FREQUENCY_WEEKLY) ExpiringAccessPreference (enabled: boolean, locked: boolean) ProvisioningRequestPreference (enabled: boolean, locked: boolean) + RequestCreatedPreference (enabled: boolean, locked: boolean) ReviewsPreference (enabled: boolean, locked: boolean) + SystemPreference (enabled: boolean, locked: boolean) TaskRemindersPreference (enabled: boolean, locked: boolean) SlackChannelSettings (accessProvisioned: AccessProvisionedPreference, approvalNeeded: ApprovalNeededPreference, commentOnRequest: CommentOnRequestPreference ...) MsTeamsChannelSettings (accessProvisioned: AccessProvisionedPreference, approvalNeeded: ApprovalNeededPreference, commentOnRequest: CommentOnRequestPreference ...) @@ -2873,7 +3336,7 @@ C1ApiSettingsV1OnboardingSettingsServiceUpdateResponse (ContentType: string, Sta RequestSettings (SDK empty) C1ApiSettingsV1RequestSettingsServiceGetResponse (ContentType: string, GetRequestSettingsResponse: GetRequestSettingsResponse, StatusCode: int32 ...) GetRequestSettingsResponse (requestSettings: RequestSettings) - RequestSettings (skipJustification: boolean) + RequestSettings (maxBulkEntitlementSelection: int32, skipJustification: boolean) UpdateRequestSettingsRequest (requestSettings: RequestSettings, updateMask: string) C1ApiSettingsV1RequestSettingsServiceUpdateResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) UpdateRequestSettingsResponse (requestSettings: RequestSettings) @@ -2891,6 +3354,19 @@ C1ApiSettingsV1SessionSettingsServiceTestSourceIpResponse (ContentType: string, UpdateSessionSettingsRequest (sessionSettings: SessionSettings, updateMask: string) C1ApiSettingsV1SessionSettingsServiceUpdateResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) UpdateSessionSettingsResponse (sessionSettings: SessionSettings) +SsoSettings (SDK empty) +C1ApiSsoV1SsoSettingsServiceGetResponse (ContentType: string, SSOSettingsServiceGetResponse: SSOSettingsServiceGetResponse, StatusCode: int32 ...) + SsoSettingsServiceGetResponse (settings: SSOSettings) + SsoSettings (createdAt: date-time, defaultAssertionLifetime: string, defaultIdTokenSignedResponseAlg: enum ...) + DefaultIdTokenSignedResponseAlg (enum: OIDC_SIGNING_ALGORITHM_UNSPECIFIED, OIDC_SIGNING_ALGORITHM_EDDSA, OIDC_SIGNING_ALGORITHM_ES256 ...) + DefaultSubjectType (enum: SSO_SUBJECT_TYPE_UNSPECIFIED, SSO_SUBJECT_TYPE_PAIRWISE, SSO_SUBJECT_TYPE_PUBLIC ...) +C1ApiSsoV1SsoSettingsServiceListHistoryRequest (page_size: int32, page_token: string) +C1ApiSsoV1SsoSettingsServiceListHistoryResponse (ContentType: string, SSOSettingsServiceListHistoryResponse: SSOSettingsServiceListHistoryResponse, StatusCode: int32 ...) + SsoSettingsServiceListHistoryResponse (list: array, nextPageToken: string) + SsoSettingsHistoryEntry (metadata: HistoryEntryMetadata, snapshot: SSOSettings) +SsoSettingsServiceUpdateRequest (settings: SSOSettings, updateMask: string) +C1ApiSsoV1SsoSettingsServiceUpdateResponse (ContentType: string, SSOSettingsServiceUpdateResponse: SSOSettingsServiceUpdateResponse, StatusCode: int32 ...) + SsoSettingsServiceUpdateResponse (settings: SSOSettings) SsfReceiverStream (SDK empty) SsfReceiverStreamServiceCreateRequest (accountDisabledAction: enum, credentialChangeAction: enum, credentialCompromiseAction: enum ...) SsfReceiverStreamServiceCreateRequestAccountDisabledAction (enum: SSF_REVOCATION_ACTION_UNSPECIFIED, SSF_REVOCATION_ACTION_REVOKE_ALL, SSF_REVOCATION_ACTION_LOG_ONLY) @@ -2990,13 +3466,14 @@ C1ApiTaskV1TaskServiceGetResponse (ContentType: string, StatusCode: int32, RawRe TaskServiceGetResponse (expanded: array, taskView: TaskView) TaskServiceGetResponseExpanded (@type: string, AdditionalProperties: map) TaskAudit (SDK empty) -TaskAuditListRequest (commentsOnly: boolean, newestFirst: boolean, pageSize: int32 ...) +TaskAuditListRequest (commentsOnly: boolean, excludeComments: boolean, newestFirst: boolean ...) TaskAuditViewRef (id: string) C1ApiTaskV1TaskAuditListResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) - TaskAuditListResponse (list: array, nextPageToken: string) - TaskAuditView (accessRequestOutcome: TaskAuditAccessRequestOutcome, accountLifecycleActionCreated: TaskAuditAccountLifecycleActionCreated, accountLifecycleActionFailed: TaskAuditAccountLifecycleActionFailed ...) + TaskAuditListResponse (list: array, nextPageToken: string, totalCount: integer) + TaskAuditView (accessRequestOutcome: TaskAuditAccessRequestOutcome, accountDeleted: TaskAuditAccountDeleted, accountLifecycleActionCreated: TaskAuditAccountLifecycleActionCreated ...) TaskAuditAccessRequestOutcome (outcome: enum) TaskAuditAccessRequestOutcomeOutcome (enum: ACCESS_REQUEST_OUTCOME_UNSPECIFIED, ACCESS_REQUEST_OUTCOME_APPROVED, ACCESS_REQUEST_OUTCOME_DENIED ...) + TaskAuditAccountDeleted (appId: string, appUserId: string, connectorResourceId: string ...) TaskAuditAccountLifecycleActionCreated (batonActionDisplayName: string, batonActionInvocationId: string, batonActionName: string ...) TaskAuditAccountLifecycleActionFailed (batonActionDisplayName: string, batonActionInvocationId: string, batonActionName: string ...) TaskAuditActionInstanceCreated (instance: ActionInstance) @@ -3019,11 +3496,12 @@ C1ApiTaskV1TaskAuditListResponse (ContentType: string, StatusCode: int32, RawRes TaskAuditApprovalInstanceChange (instance: ApprovalInstance) TaskAuditPolicyApprovalReassigned (newPolicyStepId: string, newUsers: array, oldPolicyStepId: string ...) TaskAuditApprovalHappenedAutomatically (empty) + TaskAuditAutomationTriggered (automationExecutionId: integer, automationId: string, automationName: string) TaskAuditBulkActionError (error: string) TaskAuditCertifyOutcome (outcome: enum) TaskAuditCertifyOutcomeOutcome (enum: CERTIFY_OUTCOME_UNSPECIFIED, CERTIFY_OUTCOME_CERTIFIED, CERTIFY_OUTCOME_DECERTIFIED ...) TaskAuditComment (comment: string, updatedAt: date-time, updatedBy: string) - TaskAuditConditionalPolicyExecutionResult (condition: string, conditionMatched: boolean, defaultCondition: boolean ...) + TaskAuditConditionalPolicyExecutionResult (chainDepth: int32, condition: string, conditionMatched: boolean ...) TaskAuditFinishedConnectorActions (policyStepId: string) TaskAuditStartedConnectorActions (policyStepId: string) TaskAuditCreatedReplacementExtensionGrantTask (newTaskId: string, newTaskNumericId: integer) @@ -3043,8 +3521,11 @@ C1ApiTaskV1TaskAuditListResponse (ContentType: string, StatusCode: int32, RawRes TaskAuditPolicyChanged (newPolicyId: string, oldPolicyId: string) TaskAuditPolicyEvaluationStep (stepComment: string) TaskAuditPolicyProvisionCancelled (cancelReason: string) + TaskAuditProvisionEntitlementMergeCompleted (appEntitlementId: string, appId: string) + TaskAuditProvisionEntitlementMergeTimedOut (appEntitlementId: string, appId: string) TaskAuditPolicyProvisionError (error: string) TaskAuditPolicyProvisionReassigned (newPolicyStepId: string, newUsers: array, oldPolicyStepId: string ...) + TaskAuditProvisionWaitingForEntitlementMerge (appEntitlementId: string, appId: string, fallbackAt: date-time) TaskAuditReassignedToDelegate (delegatedAssigneeUser: User, delegatedAssigneeUserId: string, originalAssigneeUser: User ...) TaskAuditReassignmentFallbackToAdmin (adminUserIds: array, adminUsers: array) TaskAuditReassignmentListError (errorMessage: string) @@ -3075,7 +3556,7 @@ C1ApiTaskV1TaskAuditListResponse (ContentType: string, StatusCode: int32, RawRes TaskAuditWebhookApprovalSuccess (webhookId: string, webhookInstanceId: string, webhookName: string ...) TaskAuditWebhookApprovalTriggered (webhookId: string, webhookInstanceId: string, webhookName: string ...) TaskAuditWebhookAttempt (webhookId: string, webhookInstanceId: string, webhookName: string ...) - TaskAuditWebhookSuccess (webhookId: string, webhookInstanceId: string, webhookName: string ...) + TaskAuditWebhookSuccess (comment: string, webhookId: string, webhookInstanceId: string ...) TaskAuditWebhookTriggered (webhookId: string, webhookInstanceId: string, webhookName: string ...) TaskActions (SDK empty) C1ApiTaskV1TaskActionsServiceApproveRequest (TaskActionsServiceApproveRequest: TaskActionsServiceApproveRequest, task_id: string) @@ -3128,6 +3609,9 @@ C1ApiTaskV1TaskActionsServiceRestartRequest (TaskActionsServiceRestartRequest: T C1ApiTaskV1TaskActionsServiceRestartResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) TaskActionsServiceRestartResponse (expanded: array, taskView: TaskView, ticketActionId: string) TaskActionsServiceRestartResponseExpanded (@type: string, AdditionalProperties: map) +C1ApiTaskV1TaskActionsServiceRetryProvisioningRequest (TaskActionsServiceRetryProvisioningRequest: TaskActionsServiceRetryProvisioningRequest, task_id: string) + TaskActionsServiceRetryProvisioningRequest (comment: string, expandMask: TaskExpandMask, policyStepId: string) +C1ApiTaskV1TaskActionsServiceRetryProvisioningResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) C1ApiTaskV1TaskActionsServiceSkipStepRequest (TaskActionsServiceSkipStepRequest: TaskActionsServiceSkipStepRequest, task_id: string) TaskActionsServiceSkipStepRequest (comment: string, expandMask: TaskExpandMask, policyStepId: string) C1ApiTaskV1TaskActionsServiceSkipStepResponse (ContentType: string, StatusCode: int32, RawResponse: response ...) @@ -3154,7 +3638,7 @@ C1ApiTerraformExportV1TerraformExportServiceGetSchemaResponse (ContentType: stri Composite (fields: array, format: enum) CompositeField (c1Field: string, tfType: enum) TfType (enum: TF_TYPE_UNSPECIFIED, TF_TYPE_STRING, TF_TYPE_NUMBER ...) - Format (enum: FORMAT_JSON_OBJECT, FORMAT_COLON_SEPARATED, FORMAT_UNDERSCORE_SEPARATED) + CompositeFormat (enum: FORMAT_JSON_OBJECT, FORMAT_COLON_SEPARATED, FORMAT_UNDERSCORE_SEPARATED) SingleString (empty) User (SDK empty) C1ApiUserV1UserServiceGetRequest (id: string) @@ -3429,6 +3913,7 @@ C1ApiUserV2UserOwnersV2SetResponse (ContentType: string, SetUserOwnersV2Response SetUserOwnersV2Response (empty) Body (callbackUrl: string, event: string, payload: class ...) Payload (@type: string, AdditionalProperties: map) +PayloadFindingDispatch (dispatchId: string, finding: Finding, findingId: string ...) PayloadPolicyApprovalStep (expanded: array, taskView: TaskView) PayloadPolicyApprovalStepExpanded (@type: string, AdditionalProperties: map) PayloadPolicyPostAction (expanded: array, taskView: TaskView) diff --git a/.speakeasy/workflow.lock b/.speakeasy/workflow.lock index 30ed6a3e2..7fd4ea509 100644 --- a/.speakeasy/workflow.lock +++ b/.speakeasy/workflow.lock @@ -2,8 +2,8 @@ speakeasyVersion: 1.790.2 sources: my-source: sourceNamespace: my-source - sourceRevisionDigest: sha256:f48892ff7a5f6de97b645b0f6b857a0aa5dff6f63f776e5cf1a295eede9ec3c1 - sourceBlobDigest: sha256:28ec0d6785c9e6da0057ba9d72c162d92735720da61e12318359aa8d3e6c23d0 + sourceRevisionDigest: sha256:10aec36180d7971d99ed8e234a339ee4fd797ee7e08c4e8a11b813ae59fe26d5 + sourceBlobDigest: sha256:5d46ac54de771b8710d966b5d33e5e87f4e215569b451df9d50a703d9f080c71 tags: - latest - 0.1.0-alpha @@ -11,10 +11,10 @@ targets: conductorone-go: source: my-source sourceNamespace: my-source - sourceRevisionDigest: sha256:f48892ff7a5f6de97b645b0f6b857a0aa5dff6f63f776e5cf1a295eede9ec3c1 - sourceBlobDigest: sha256:28ec0d6785c9e6da0057ba9d72c162d92735720da61e12318359aa8d3e6c23d0 + sourceRevisionDigest: sha256:10aec36180d7971d99ed8e234a339ee4fd797ee7e08c4e8a11b813ae59fe26d5 + sourceBlobDigest: sha256:5d46ac54de771b8710d966b5d33e5e87f4e215569b451df9d50a703d9f080c71 codeSamplesNamespace: my-source-go-code-samples - codeSamplesRevisionDigest: sha256:08ff7721e11ebc2b48740456d0438e3ea38c127fc013402cf10a34534952a3b8 + codeSamplesRevisionDigest: sha256:8e317f0065b1a6568ed69d6350abdae1e992a0b4e97c37665f7c87ddc3729f32 workflow: workflowVersion: 1.0.0 speakeasyVersion: latest diff --git a/README.md b/README.md index 433ed4061..861ffbf0b 100644 --- a/README.md +++ b/README.md @@ -77,6 +77,7 @@ func main() { ### [A2Ui](docs/sdks/a2ui/README.md) * [CreateSurfaceFeedback](docs/sdks/a2ui/README.md#createsurfacefeedback) - Create Surface Feedback +* [GetSurfaceProvenance](docs/sdks/a2ui/README.md#getsurfaceprovenance) - Get Surface Provenance * [ListSurfaceFeedback](docs/sdks/a2ui/README.md#listsurfacefeedback) - List Surface Feedback * [ListSurfaces](docs/sdks/a2ui/README.md#listsurfaces) - List Surfaces * [SubmitAction](docs/sdks/a2ui/README.md#submitaction) - Submit Action @@ -96,6 +97,14 @@ func main() { * [List](docs/sdks/accessreview/README.md#list) - List * [Update](docs/sdks/accessreview/README.md#update) - Update +### [AccessReviewActions](docs/sdks/accessreviewactions/README.md) + +* [GenerateReport](docs/sdks/accessreviewactions/README.md#generatereport) - Generate Report + +### [AccessReviewReport](docs/sdks/accessreviewreport/README.md) + +* [List](docs/sdks/accessreviewreport/README.md#list) - List + ### [AccessReviewSetupEntitlement](docs/sdks/accessreviewsetupentitlement/README.md) * [GetCampaignScopeAndEntitlements](docs/sdks/accessreviewsetupentitlement/README.md#getcampaignscopeandentitlements) - Get Campaign Scope And Entitlements @@ -132,6 +141,16 @@ func main() { * [CreateAppAccessRequestsDefaults](docs/sdks/appaccessrequestsdefaults/README.md#createappaccessrequestsdefaults) - Create App Access Requests Defaults * [GetAppAccessRequestsDefaults](docs/sdks/appaccessrequestsdefaults/README.md#getappaccessrequestsdefaults) - Get App Access Requests Defaults +### [AppCap](docs/sdks/appcap/README.md) + +* [Delete](docs/sdks/appcap/README.md#delete) - Delete +* [Get](docs/sdks/appcap/README.md#get) - Get +* [List](docs/sdks/appcap/README.md#list) - List +* [ListHistory](docs/sdks/appcap/README.md#listhistory) - List History +* [SetLimit](docs/sdks/appcap/README.md#setlimit) - Set Limit +* [Suspend](docs/sdks/appcap/README.md#suspend) - Suspend +* [Unsuspend](docs/sdks/appcap/README.md#unsuspend) - Unsuspend + ### [AppEntitlementMonitorBinding](docs/sdks/appentitlementmonitorbinding/README.md) * [CreateAppEntitlementMonitorBinding](docs/sdks/appentitlementmonitorbinding/README.md#createappentitlementmonitorbinding) - Create App Entitlement Monitor Binding @@ -196,6 +215,7 @@ func main() { * [SearchAppEntitlementsWithExpired](docs/sdks/appentitlementsearch/README.md#searchappentitlementswithexpired) - Search App Entitlements With Expired * [SearchGrants](docs/sdks/appentitlementsearch/README.md#searchgrants) - Search Grants * [SearchGraph](docs/sdks/appentitlementsearch/README.md#searchgraph) - Search Graph +* [SearchReachableResourcesForUser](docs/sdks/appentitlementsearch/README.md#searchreachableresourcesforuser) - Search Reachable Resources For User ### [AppEntitlementsProxy](docs/sdks/appentitlementsproxy/README.md) @@ -211,6 +231,12 @@ func main() { * [SearchPastGrants](docs/sdks/appentitlementuserbinding/README.md#searchpastgrants) - Search Past Grants * [UpdateGrantDuration](docs/sdks/appentitlementuserbinding/README.md#updategrantduration) - Update Grant Duration +### [AppManagedState](docs/sdks/appmanagedstate/README.md) + +* [Get](docs/sdks/appmanagedstate/README.md#get) - Get +* [List](docs/sdks/appmanagedstate/README.md#list) - List +* [Promote](docs/sdks/appmanagedstate/README.md#promote) - Promote + ### [AppOwners](docs/sdks/appowners/README.md) * [Add](docs/sdks/appowners/README.md#add) - Add @@ -495,6 +521,11 @@ func main() { * [Search](docs/sdks/findingsearch/README.md#search) - Search +### [FindingSettings](docs/sdks/findingsettings/README.md) + +* [ListFindingSettings](docs/sdks/findingsettings/README.md#listfindingsettings) - List Finding Settings +* [UpdateFindingSettings](docs/sdks/findingsettings/README.md#updatefindingsettings) - Update Finding Settings + ### [FindingTransformationRule](docs/sdks/findingtransformationrule/README.md) * [CreateFindingTransformationRule](docs/sdks/findingtransformationrule/README.md#createfindingtransformationrule) - Create Finding Transformation Rule @@ -533,6 +564,45 @@ func main() { * [Search](docs/sdks/functionssearch/README.md#search) - Search +### [FundAssignment](docs/sdks/fundassignment/README.md) + +* [ClearExtension](docs/sdks/fundassignment/README.md#clearextension) - Clear Extension +* [Delete](docs/sdks/fundassignment/README.md#delete) - Delete +* [Get](docs/sdks/fundassignment/README.md#get) - Get +* [GrantExtension](docs/sdks/fundassignment/README.md#grantextension) - Grant Extension +* [ListHistory](docs/sdks/fundassignment/README.md#listhistory) - List History +* [Search](docs/sdks/fundassignment/README.md#search) - Search +* [SetLimit](docs/sdks/fundassignment/README.md#setlimit) - Set Limit +* [Suspend](docs/sdks/fundassignment/README.md#suspend) - Suspend +* [Unsuspend](docs/sdks/fundassignment/README.md#unsuspend) - Unsuspend + +### [FundPolicy](docs/sdks/fundpolicy/README.md) + +* [Create](docs/sdks/fundpolicy/README.md#create) - Create +* [Delete](docs/sdks/fundpolicy/README.md#delete) - Delete +* [FreezeTenant](docs/sdks/fundpolicy/README.md#freezetenant) - Freeze Tenant +* [Get](docs/sdks/fundpolicy/README.md#get) - Get +* [ListHistory](docs/sdks/fundpolicy/README.md#listhistory) - List History +* [SetOrgCeiling](docs/sdks/fundpolicy/README.md#setorgceiling) - Set Org Ceiling +* [UnfreezeTenant](docs/sdks/fundpolicy/README.md#unfreezetenant) - Unfreeze Tenant +* [Update](docs/sdks/fundpolicy/README.md#update) - Update + +### [FundRule](docs/sdks/fundrule/README.md) + +* [Create](docs/sdks/fundrule/README.md#create) - Create +* [Delete](docs/sdks/fundrule/README.md#delete) - Delete +* [Get](docs/sdks/fundrule/README.md#get) - Get +* [List](docs/sdks/fundrule/README.md#list) - List +* [ListHistory](docs/sdks/fundrule/README.md#listhistory) - List History +* [Search](docs/sdks/fundrule/README.md#search) - Search +* [Update](docs/sdks/fundrule/README.md#update) - Update + +### [GatewayKey](docs/sdks/gatewaykey/README.md) + +* [List](docs/sdks/gatewaykey/README.md#list) - List +* [Mint](docs/sdks/gatewaykey/README.md#mint) - Mint +* [Revoke](docs/sdks/gatewaykey/README.md#revoke) - Revoke + ### [Hooks](docs/sdks/hooks/README.md) * [Create](docs/sdks/hooks/README.md#create) - Create @@ -573,6 +643,7 @@ func main() { * [GetByAppEntitlementID](docs/sdks/mcpaccessprofile/README.md#getbyappentitlementid) - Get By App Entitlement Id * [List](docs/sdks/mcpaccessprofile/README.md#list) - List * [ListRequestableConnectors](docs/sdks/mcpaccessprofile/README.md#listrequestableconnectors) - List Requestable Connectors +* [SearchAccessProfiles](docs/sdks/mcpaccessprofile/README.md#searchaccessprofiles) - Search Access Profiles * [SearchRequestableConnectors](docs/sdks/mcpaccessprofile/README.md#searchrequestableconnectors) - Search Requestable Connectors * [Update](docs/sdks/mcpaccessprofile/README.md#update) - Update @@ -585,6 +656,14 @@ func main() { * [ListProfilesByToolHistory](docs/sdks/mcpaccessprofiletoolbinding/README.md#listprofilesbytoolhistory) - List Profiles By Tool History * [ListToolsByProfileHistory](docs/sdks/mcpaccessprofiletoolbinding/README.md#listtoolsbyprofilehistory) - List Tools By Profile History +### [MCPResource](docs/sdks/mcpresource/README.md) + +* [Get](docs/sdks/mcpresource/README.md#get) - Get +* [List](docs/sdks/mcpresource/README.md#list) - List +* [ListHistory](docs/sdks/mcpresource/README.md#listhistory) - List History +* [Search](docs/sdks/mcpresource/README.md#search) - Search +* [Update](docs/sdks/mcpresource/README.md#update) - Update + ### [MCPServer](docs/sdks/mcpserver/README.md) * [Delete](docs/sdks/mcpserver/README.md#delete) - Delete @@ -610,6 +689,15 @@ func main() { * [Search](docs/sdks/mcptool/README.md#search) - Search * [Update](docs/sdks/mcptool/README.md#update) - Update +### [MyFundLimits](docs/sdks/myfundlimits/README.md) + +* [Delete](docs/sdks/myfundlimits/README.md#delete) - Delete +* [List](docs/sdks/myfundlimits/README.md#list) - List +* [ListHistory](docs/sdks/myfundlimits/README.md#listhistory) - List History +* [Pause](docs/sdks/myfundlimits/README.md#pause) - Pause +* [Resume](docs/sdks/myfundlimits/README.md#resume) - Resume +* [SetLimit](docs/sdks/myfundlimits/README.md#setlimit) - Set Limit + ### [OnboardingSettings](docs/sdks/onboardingsettings/README.md) * [Get](docs/sdks/onboardingsettings/README.md#get) - Get @@ -697,6 +785,12 @@ func main() { * [Update](docs/sdks/principal/README.md#update) - Update * [UpdateCredential](docs/sdks/principal/README.md#updatecredential) - Update Credential +### [ProviderCredential](docs/sdks/providercredential/README.md) + +* [Clear](docs/sdks/providercredential/README.md#clear) - Clear +* [Get](docs/sdks/providercredential/README.md#get) - Get +* [Set](docs/sdks/providercredential/README.md#set) - Set + ### [RecoveryPolicy](docs/sdks/recoverypolicy/README.md) * [Create](docs/sdks/recoverypolicy/README.md#create) - Create @@ -706,6 +800,16 @@ func main() { * [Search](docs/sdks/recoverypolicy/README.md#search) - Search * [Update](docs/sdks/recoverypolicy/README.md#update) - Update +### [Reporting](docs/sdks/reporting/README.md) + +* [Delete](docs/sdks/reporting/README.md#delete) - Delete +* [Get](docs/sdks/reporting/README.md#get) - Get +* [GetRunProvenance](docs/sdks/reporting/README.md#getrunprovenance) - Get Run Provenance +* [List](docs/sdks/reporting/README.md#list) - List +* [Run](docs/sdks/reporting/README.md#run) - Run +* [Save](docs/sdks/reporting/README.md#save) - Save +* [Update](docs/sdks/reporting/README.md#update) - Update + ### [RequestCatalogManagement](docs/sdks/requestcatalogmanagement/README.md) * [AddAccessEntitlements](docs/sdks/requestcatalogmanagement/README.md#addaccessentitlements) - Add Access Entitlements @@ -753,6 +857,7 @@ func main() { ### [RoleMiningManagement](docs/sdks/roleminingmanagement/README.md) * [CreateAccessProfileFromCohort](docs/sdks/roleminingmanagement/README.md#createaccessprofilefromcohort) - Create Access Profile From Cohort +* [EvaluateEntitlementSelection](docs/sdks/roleminingmanagement/README.md#evaluateentitlementselection) - Evaluate Entitlement Selection * [GetCustomAnalysisResult](docs/sdks/roleminingmanagement/README.md#getcustomanalysisresult) - Get Custom Analysis Result * [GetLatestRun](docs/sdks/roleminingmanagement/README.md#getlatestrun) - Get Latest Run * [GetRoleMiningConfig](docs/sdks/roleminingmanagement/README.md#getroleminingconfig) - Get Role Mining Config @@ -823,6 +928,30 @@ func main() { * [Test](docs/sdks/ssfreceiverstream/README.md#test) - Test * [Update](docs/sdks/ssfreceiverstream/README.md#update) - Update +### [SSOApplication](docs/sdks/ssoapplication/README.md) + +* [BatchDeleteSubjectCompatibility](docs/sdks/ssoapplication/README.md#batchdeletesubjectcompatibility) - Batch Delete Subject Compatibility +* [BatchImportSubjectCompatibility](docs/sdks/ssoapplication/README.md#batchimportsubjectcompatibility) - Batch Import Subject Compatibility +* [Create](docs/sdks/ssoapplication/README.md#create) - Create +* [CreateClient](docs/sdks/ssoapplication/README.md#createclient) - Create Client +* [Delete](docs/sdks/ssoapplication/README.md#delete) - Delete +* [DeleteClient](docs/sdks/ssoapplication/README.md#deleteclient) - Delete Client +* [Get](docs/sdks/ssoapplication/README.md#get) - Get +* [List](docs/sdks/ssoapplication/README.md#list) - List +* [ListClients](docs/sdks/ssoapplication/README.md#listclients) - List Clients +* [ListHistory](docs/sdks/ssoapplication/README.md#listhistory) - List History +* [ParseSAMLServiceProviderMetadata](docs/sdks/ssoapplication/README.md#parsesamlserviceprovidermetadata) - Parse Saml Service Provider Metadata +* [RotateClientSecret](docs/sdks/ssoapplication/README.md#rotateclientsecret) - Rotate Client Secret +* [Search](docs/sdks/ssoapplication/README.md#search) - Search +* [Update](docs/sdks/ssoapplication/README.md#update) - Update +* [UpdateClient](docs/sdks/ssoapplication/README.md#updateclient) - Update Client + +### [SSOSettings](docs/sdks/ssosettings/README.md) + +* [Get](docs/sdks/ssosettings/README.md#get) - Get +* [ListHistory](docs/sdks/ssosettings/README.md#listhistory) - List History +* [Update](docs/sdks/ssosettings/README.md#update) - Update + ### [StepUpProvider](docs/sdks/stepupprovider/README.md) * [Create](docs/sdks/stepupprovider/README.md#create) - Create @@ -864,6 +993,7 @@ func main() { * [ProcessNow](docs/sdks/taskactions/README.md#processnow) - Process Now * [Reassign](docs/sdks/taskactions/README.md#reassign) - Reassign * [Restart](docs/sdks/taskactions/README.md#restart) - Restart +* [RetryProvisioning](docs/sdks/taskactions/README.md#retryprovisioning) - Retry Provisioning * [SkipStep](docs/sdks/taskactions/README.md#skipstep) - Skip Step * [UpdateGrantDuration](docs/sdks/taskactions/README.md#updategrantduration) - Update Grant Duration * [UpdateRequestData](docs/sdks/taskactions/README.md#updaterequestdata) - Update Request Data @@ -908,6 +1038,10 @@ func main() { * [RevokeBridgeCredential](docs/sdks/tunnelcredentials/README.md#revokebridgecredential) - Revoke Bridge Credential * [UpdateBridge](docs/sdks/tunnelcredentials/README.md#updatebridge) - Update Bridge +### [UIConversations](docs/sdks/uiconversations/README.md) + +* [EnsureOnboardingSession](docs/sdks/uiconversations/README.md#ensureonboardingsession) - Ensure Onboarding Session + ### [User](docs/sdks/user/README.md) * [Get](docs/sdks/user/README.md#get) - Get diff --git a/RELEASES.md b/RELEASES.md index bf394b676..69176f69f 100644 --- a/RELEASES.md +++ b/RELEASES.md @@ -128,4 +128,14 @@ Based on: ### Generated - [go v1.29.0] . ### Releases -- [Go v1.29.0] https://github.com/ConductorOne/conductorone-sdk-go/releases/tag/v1.29.0 - . \ No newline at end of file +- [Go v1.29.0] https://github.com/ConductorOne/conductorone-sdk-go/releases/tag/v1.29.0 - . + +## 2026-09-01 00:50:05 +### Changes +Based on: +- OpenAPI Doc +- Speakeasy CLI 1.790.2 (2.918.3) https://github.com/speakeasy-api/speakeasy +### Generated +- [go v1.29.1] . +### Releases +- [Go v1.29.1] https://github.com/ConductorOne/conductorone-sdk-go/releases/tag/v1.29.1 - . \ No newline at end of file diff --git a/a2ui.go b/a2ui.go index f7962a742..4a3a2c53d 100644 --- a/a2ui.go +++ b/a2ui.go @@ -242,6 +242,214 @@ func (s *A2UI) CreateSurfaceFeedback(ctx context.Context, request operations.C1A } +// GetSurfaceProvenance - Get Surface Provenance +// GetSurfaceProvenance returns, in plain terms, what the surface's report +// +// was built from: every record its program touched, in the order it touched +// them. +func (s *A2UI) GetSurfaceProvenance(ctx context.Context, request operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest, opts ...operations.Option) (*operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/a2ui/conversations/{conversation_id}/surfaces/{surface_id}/provenance", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.a2ui.v1.A2UIService.GetSurfaceProvenance", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.A2UIServiceGetSurfaceProvenanceResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.A2UIServiceGetSurfaceProvenanceResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + // ListSurfaceFeedback - List Surface Feedback // ListSurfaceFeedback lists feedback for a surface. func (s *A2UI) ListSurfaceFeedback(ctx context.Context, request operations.C1APIA2uiV1A2UIServiceListSurfaceFeedbackRequest, opts ...operations.Option) (*operations.C1APIA2uiV1A2UIServiceListSurfaceFeedbackResponse, error) { diff --git a/accessreviewactions.go b/accessreviewactions.go new file mode 100644 index 000000000..c12c5db36 --- /dev/null +++ b/accessreviewactions.go @@ -0,0 +1,247 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" +) + +type AccessReviewActions struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newAccessReviewActions(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *AccessReviewActions { + return &AccessReviewActions{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// GenerateReport - Generate Report +// Generate a report of the campaign's reviews and decisions. The format +// +// defaults to JSON (also available: CSV, XLSX). Works on in-flight (OPEN) +// and closed campaigns. Asynchronous — the report record is created +// immediately; the file is materialized in the background. +func (s *AccessReviewActions) GenerateReport(ctx context.Context, request operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest, opts ...operations.Option) (*operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/access_review/{access_review_id}/report", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.accessreview.v1.AccessReviewActionsService.GenerateReport", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "AccessReviewActionsServiceGenerateReportRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AccessReviewActionsServiceGenerateReportResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AccessReviewActionsServiceGenerateReportResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/accessreviewreport.go b/accessreviewreport.go new file mode 100644 index 000000000..112c0552d --- /dev/null +++ b/accessreviewreport.go @@ -0,0 +1,242 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" +) + +type AccessReviewReport struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newAccessReviewReport(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *AccessReviewReport { + return &AccessReviewReport{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// List +// List the generated reports for an access review campaign, each with a +// +// time-limited download_url and its output format. +func (s *AccessReviewReport) List(ctx context.Context, request operations.C1APIAccessreviewV1AccessReviewReportServiceListRequest, opts ...operations.Option) (*operations.C1APIAccessreviewV1AccessReviewReportServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/access_review/{access_review_id}/report", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.accessreview.v1.AccessReviewReportService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAccessreviewV1AccessReviewReportServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AccessReviewReportServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AccessReviewReportServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/aigovernancesettings.go b/aigovernancesettings.go index c3c13dd5f..09b1875a1 100644 --- a/aigovernancesettings.go +++ b/aigovernancesettings.go @@ -37,7 +37,8 @@ func newAIGovernanceSettings(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfi // /admin/settings/ai-governance page. Returns the full AIGovernanceSettings: // allowed MCP client types, default client lifecycle, require_tool_approval, // default tool classification, audit verbosity, auto-discovery toggle + -// interval, prefer_code_mode_over_direct_tools, and surface_requestable_tools. +// interval, prefer_code_mode_over_direct_tools, surface_requestable_tools, +// and untrusted_judge_disable. func (s *AIGovernanceSettings) Get(ctx context.Context, opts ...operations.Option) (*operations.C1APIAIGovernanceV1AIGovernanceSettingsServiceGetResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -662,7 +663,8 @@ func (s *AIGovernanceSettings) ListHistory(ctx context.Context, opts ...operatio // which fields to apply (e.g. require_tool_approval, // default_tool_classification, audit_verbosity, auto_discovery_enabled, // discovery_interval, prefer_code_mode_over_direct_tools, -// surface_requestable_tools, allowed_client_types, default_client_lifecycle). +// surface_requestable_tools, untrusted_judge_disable, allowed_client_types, +// default_client_lifecycle). // Only masked fields change. Returns the updated settings. func (s *AIGovernanceSettings) Update(ctx context.Context, request *shared.UpdateAIGovernanceSettingsRequest, opts ...operations.Option) (*operations.C1APIAIGovernanceV1AIGovernanceSettingsServiceUpdateResponse, error) { o := operations.Options{} diff --git a/appcap.go b/appcap.go new file mode 100644 index 000000000..ecdbff74c --- /dev/null +++ b/appcap.go @@ -0,0 +1,1515 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type AppCap struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newAppCap(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *AppCap { + return &AppCap{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Delete +// Delete the cap entirely. The app is no longer bounded tenant-wide. +func (s *AppCap) Delete(ctx context.Context, request operations.C1APIFundsV1AppCapServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "AppCapServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns the tenant's ceiling for one app, together with any suspension +// +// acting as that app's kill switch. An app with no cap is not found, meaning +// nothing bounds it beyond the fund the spender already has. +func (s *AppCap) Get(ctx context.Context, request operations.C1APIFundsV1AppCapServiceGetRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List every capped app in the tenant. Cardinality is the tenant's installed +// +// App count, so this is one runtime-plane query. +func (s *AppCap) List(ctx context.Context, request operations.C1APIFundsV1AppCapServiceListRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/app-caps") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// List the change history for one app's cap, newest first. Admin-tier per the +// +// object-history convention. A cap cleared down to nothing is deleted, and its +// history is where the kill switch that preceded the delete is still readable. +func (s *AppCap) ListHistory(ctx context.Context, request operations.C1APIFundsV1AppCapServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// SetLimit - Set Limit +// Set the app's tenant-wide ceiling, creating the cap if absent. Leaves any +// +// suspension in place. +func (s *AppCap) SetLimit(ctx context.Context, request operations.C1APIFundsV1AppCapServiceSetLimitRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceSetLimitResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}/limit", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.SetLimit", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "AppCapServiceSetLimitRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceSetLimitResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceSetLimitResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceSetLimitResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Suspend +// Kill the app tenant-wide. The cap amount underneath is preserved and +// +// restored by Unsuspend. +func (s *AppCap) Suspend(ctx context.Context, request operations.C1APIFundsV1AppCapServiceSuspendRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceSuspendResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.Suspend", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "AppCapServiceSuspendRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceSuspendResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceSuspendResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceSuspendResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Unsuspend +// Bring the app back, restoring the cap it froze. +func (s *AppCap) Unsuspend(ctx context.Context, request operations.C1APIFundsV1AppCapServiceUnsuspendRequest, opts ...operations.Option) (*operations.C1APIFundsV1AppCapServiceUnsuspendResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/app-caps/{app_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.AppCapService.Unsuspend", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "AppCapServiceUnsuspendRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1AppCapServiceUnsuspendResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppCapServiceUnsuspendResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppCapServiceUnsuspendResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/appentitlementroutingrule.go b/appentitlementroutingrule.go index 6c4e09648..05d22ad20 100644 --- a/appentitlementroutingrule.go +++ b/appentitlementroutingrule.go @@ -31,7 +31,11 @@ func newAppEntitlementRoutingRule(rootSDK *ConductoroneAPI, sdkConfig config.SDK } // CreateAppEntitlementRoutingRule - Create App Entitlement Routing Rule -// Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule method. +// CreateAppEntitlementRoutingRule creates an entitlement configuration rule +// +// for an application. Rules are evaluated in priority order and the first +// rule whose condition matches supplies the entitlement's request settings. +// An app can have at most 5 rules. func (s *AppEntitlementRoutingRule) CreateAppEntitlementRoutingRule(ctx context.Context, request operations.C1APIAppV1AppEntitlementRoutingRuleServiceCreateAppEntitlementRoutingRuleRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementRoutingRuleServiceCreateAppEntitlementRoutingRuleResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -243,7 +247,9 @@ func (s *AppEntitlementRoutingRule) CreateAppEntitlementRoutingRule(ctx context. } // DeleteAppEntitlementRoutingRule - Delete App Entitlement Routing Rule -// Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule method. +// DeleteAppEntitlementRoutingRule deletes an entitlement configuration rule +// +// by ID. func (s *AppEntitlementRoutingRule) DeleteAppEntitlementRoutingRule(ctx context.Context, request operations.C1APIAppV1AppEntitlementRoutingRuleServiceDeleteAppEntitlementRoutingRuleRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementRoutingRuleServiceDeleteAppEntitlementRoutingRuleResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -455,7 +461,9 @@ func (s *AppEntitlementRoutingRule) DeleteAppEntitlementRoutingRule(ctx context. } // GetAppEntitlementRoutingRule - Get App Entitlement Routing Rule -// Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule method. +// GetAppEntitlementRoutingRule returns a single entitlement configuration +// +// rule by ID. func (s *AppEntitlementRoutingRule) GetAppEntitlementRoutingRule(ctx context.Context, request operations.C1APIAppV1AppEntitlementRoutingRuleServiceGetAppEntitlementRoutingRuleRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementRoutingRuleServiceGetAppEntitlementRoutingRuleResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -660,7 +668,9 @@ func (s *AppEntitlementRoutingRule) GetAppEntitlementRoutingRule(ctx context.Con } // ListAppEntitlementRoutingRules - List App Entitlement Routing Rules -// Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules method. +// ListAppEntitlementRoutingRules returns an application's entitlement +// +// configuration rules in evaluation order, by priority then by ID. func (s *AppEntitlementRoutingRule) ListAppEntitlementRoutingRules(ctx context.Context, request operations.C1APIAppV1AppEntitlementRoutingRuleServiceListAppEntitlementRoutingRulesRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementRoutingRuleServiceListAppEntitlementRoutingRulesResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/appentitlements.go b/appentitlements.go index 8bc4cad05..fda526e15 100644 --- a/appentitlements.go +++ b/appentitlements.go @@ -244,6 +244,8 @@ func (s *AppEntitlements) AddAutomationExclusion(ctx context.Context, request op // AddManuallyManagedMembers - Add Manually Managed Members // Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. +// +// Adding members to an access profile's enrollment entitlement requires the JML feature; without it the request fails with a failed-precondition error. func (s *AppEntitlements) AddManuallyManagedMembers(ctx context.Context, request operations.C1APIAppV1AppEntitlementsAddManuallyManagedMembersRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementsAddManuallyManagedMembersResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -1713,7 +1715,11 @@ func (s *AppEntitlements) GetAutomation(ctx context.Context, request operations. } // List -// List app entitlements associated with an app. +// List app entitlements associated with an app. Query parameters are +// +// accepted in snake_case (page_size, page_token, app_user_id) and, as a +// compatibility shim, their camelCase equivalents (pageSize, pageToken, +// appUserId). func (s *AppEntitlements) List(ctx context.Context, request operations.C1APIAppV1AppEntitlementsListRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementsListResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -2968,7 +2974,14 @@ func (s *AppEntitlements) RemoveAutomationExclusion(ctx context.Context, request } // RemoveEntitlementMembership - Remove Entitlement Membership -// Remove a user from a ConductorOne-managed entitlement (catalog, group, or profile type). For access profiles, this creates a revoke task to deprovision access. +// Remove a user from a manually managed entitlement. For ConductorOne +// +// catalogs, groups, and profile types, the existing resource-specific +// removal behavior applies. When the SSO provider feature is enabled, an SSO +// application's sign-in entitlement removes only direct manual access and +// preserves independent requested, connector, and group-derived access. +// Removing a member from an access profile requires the JML feature; without +// it the request fails with a failed-precondition error. func (s *AppEntitlements) RemoveEntitlementMembership(ctx context.Context, request operations.C1APIAppV1AppEntitlementsRemoveEntitlementMembershipRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementsRemoveEntitlementMembershipResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/appentitlementsearch.go b/appentitlementsearch.go index de67e77ca..69433c60c 100644 --- a/appentitlementsearch.go +++ b/appentitlementsearch.go @@ -1358,3 +1358,220 @@ func (s *AppEntitlementSearch) SearchGraph(ctx context.Context, request *shared. return res, nil } + +// SearchReachableResourcesForUser - Search Reachable Resources For User +// SearchReachableResourcesForUser returns the distinct app resources a user +// +// can reach through any of their grants, deduplicated across entitlements +// (a resource reachable via more than one grant appears once). Powers the +// Resources lane of the access graph's list view: supports free-text search +// over resource display name and narrowing to specific applications. +func (s *AppEntitlementSearch) SearchReachableResourcesForUser(ctx context.Context, request *shared.AppEntitlementSearchServiceSearchReachableResourcesForUserRequest, opts ...operations.Option) (*operations.C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/search/graph/resources") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.app.v1.AppEntitlementSearchService.SearchReachableResourcesForUser", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/appmanagedstate.go b/appmanagedstate.go new file mode 100644 index 000000000..44167ddfd --- /dev/null +++ b/appmanagedstate.go @@ -0,0 +1,660 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" +) + +type AppManagedState struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newAppManagedState(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *AppManagedState { + return &AppManagedState{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Get +// Get the managed state of a discovered application. +func (s *AppManagedState) Get(ctx context.Context, request operations.C1APIAppV1AppManagedStateServiceGetRequest, opts ...operations.Option) (*operations.C1APIAppV1AppManagedStateServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings/{resource_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.app.v1.AppManagedStateService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAppV1AppManagedStateServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.GetAppManagedStateBindingResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.GetAppManagedStateBindingResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List the managed states of applications discovered by a connector. +func (s *AppManagedState) List(ctx context.Context, request operations.C1APIAppV1AppManagedStateServiceListRequest, opts ...operations.Option) (*operations.C1APIAppV1AppManagedStateServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.app.v1.AppManagedStateService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAppV1AppManagedStateServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ListAppManagedStateBindingsResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ListAppManagedStateBindingsResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Promote +// Promote an unmanaged application into a managed application. +// +// Returns AlreadyExists when the application is already managed. The new application inherits source owners when user_ids is omitted. +// Concurrent promotion requests are not supported. +func (s *AppManagedState) Promote(ctx context.Context, request operations.C1APIAppV1AppManagedStateServicePromoteRequest, opts ...operations.Option) (*operations.C1APIAppV1AppManagedStateServicePromoteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/resource_types/{resource_type_id}/managed_state_bindings/{resource_id}/promote", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.app.v1.AppManagedStateService.Promote", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "PromoteAppManagedStateBindingRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAppV1AppManagedStateServicePromoteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.GetAppManagedStateBindingResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.GetAppManagedStateBindingResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/automation.go b/automation.go index 055d6b158..b24210777 100644 --- a/automation.go +++ b/automation.go @@ -250,7 +250,7 @@ func (s *Automation) ClearAutomationCircuitBreaker(ctx context.Context, request // Create a new automation with the specified steps, triggers, and // // configuration. See get_authoring_guide for the AutomationStep contract -// (step kinds, evaluate_expressions shape, CEL identifier scope). +// (step kinds and their required fields, CEL identifier scope). // // At create time, draft_automation_steps and draft_triggers default to // their published counterparts when omitted — callers writing a single diff --git a/conductoroneapi.go b/conductoroneapi.go index 04948488a..70a7b5182 100644 --- a/conductoroneapi.go +++ b/conductoroneapi.go @@ -53,6 +53,8 @@ type ConductoroneAPI struct { SDKVersion string A2UI *A2UI AccessReview *AccessReview + AccessReviewReport *AccessReviewReport + AccessReviewActions *AccessReviewActions AccessReviewSetupEntitlement *AccessReviewSetupEntitlement AccessReviewTemplate *AccessReviewTemplate AccessReviewTemplateSetupEntitlement *AccessReviewTemplateSetupEntitlement @@ -62,6 +64,7 @@ type ConductoroneAPI struct { Apps *Apps Connector *Connector AppAccessRequestsDefaults *AppAccessRequestsDefaults + MCPResource *MCPResource MCPTool *MCPTool MCPAccessProfile *MCPAccessProfile MCPAccessProfileToolBinding *MCPAccessProfileToolBinding @@ -76,7 +79,9 @@ type ConductoroneAPI struct { AppReportAction *AppReportAction AppResourceType *AppResourceType AppResource *AppResource + AppManagedState *AppManagedState AppResourceOwners *AppResourceOwners + SSOApplication *SSOApplication AppUsageControls *AppUsageControls XAAAccessProfile *XAAAccessProfile XAAAccessProfileScopeBinding *XAAAccessProfileScopeBinding @@ -92,6 +97,7 @@ type ConductoroneAPI struct { RequestCatalogManagement *RequestCatalogManagement ConnectorAuthoringActivation *ConnectorAuthoringActivation ConnectorCatalog *ConnectorCatalog + UIConversations *UIConversations CredentialInventoryPolicy *CredentialInventoryPolicy Decoy *Decoy DecoySearch *DecoySearch @@ -99,21 +105,30 @@ type ConductoroneAPI struct { Finding *Finding FindingRoutingRule *FindingRoutingRule FindingSearch *FindingSearch + FindingSettings *FindingSettings FindingTransformationRule *FindingTransformationRule Functions *Functions FunctionsInvocation *FunctionsInvocation FunctionsInvocationSearch *FunctionsInvocationSearch + AppCap *AppCap + FundAssignment *FundAssignment + MyFundLimits *MyFundLimits + FundPolicy *FundPolicy + FundRule *FundRule Hooks *Hooks PersonalClient *PersonalClient PersonalDevice *PersonalDevice Roles *Roles TunnelCredentials *TunnelCredentials + GatewayKey *GatewayKey + ProviderCredential *ProviderCredential LocalDirectoryConfig *LocalDirectoryConfig LocalUserInvitation *LocalUserInvitation Policies *Policies AccountProvisionPolicyTest *AccountProvisionPolicyTest PolicyValidate *PolicyValidate RecoveryPolicy *RecoveryPolicy + Reporting *Reporting RequestSchema *RequestSchema RoleMiningManagement *RoleMiningManagement AutomationExecutionSearch *AutomationExecutionSearch @@ -156,6 +171,7 @@ type ConductoroneAPI struct { OnboardingSettings *OnboardingSettings RequestSettings *RequestSettings SessionSettings *SessionSettings + SSOSettings *SSOSettings SSFReceiverStream *SSFReceiverStream SSFReceiverEvent *SSFReceiverEvent SystemLog *SystemLog @@ -261,9 +277,9 @@ func WithTimeout(timeout time.Duration) SDKOption { // New creates a new instance of the SDK with the provided options func New(opts ...SDKOption) *ConductoroneAPI { sdk := &ConductoroneAPI{ - SDKVersion: "1.29.0", + SDKVersion: "1.29.1", sdkConfiguration: config.SDKConfiguration{ - UserAgent: "speakeasy-sdk/go 1.29.0 2.918.3 0.1.0-alpha github.com/conductorone/conductorone-sdk-go", + UserAgent: "speakeasy-sdk/go 1.29.1 2.918.3 0.1.0-alpha github.com/conductorone/conductorone-sdk-go", ServerList: ServerList, ServerVariables: []map[string]string{ { @@ -291,6 +307,8 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.A2UI = newA2UI(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AccessReview = newAccessReview(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.AccessReviewReport = newAccessReviewReport(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.AccessReviewActions = newAccessReviewActions(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AccessReviewSetupEntitlement = newAccessReviewSetupEntitlement(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AccessReviewTemplate = newAccessReviewTemplate(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AccessReviewTemplateSetupEntitlement = newAccessReviewTemplateSetupEntitlement(sdk, sdk.sdkConfiguration, sdk.hooks) @@ -300,6 +318,7 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.Apps = newApps(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Connector = newConnector(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AppAccessRequestsDefaults = newAppAccessRequestsDefaults(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.MCPResource = newMCPResource(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.MCPTool = newMCPTool(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.MCPAccessProfile = newMCPAccessProfile(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.MCPAccessProfileToolBinding = newMCPAccessProfileToolBinding(sdk, sdk.sdkConfiguration, sdk.hooks) @@ -314,7 +333,9 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.AppReportAction = newAppReportAction(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AppResourceType = newAppResourceType(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AppResource = newAppResource(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.AppManagedState = newAppManagedState(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AppResourceOwners = newAppResourceOwners(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.SSOApplication = newSSOApplication(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AppUsageControls = newAppUsageControls(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.XAAAccessProfile = newXAAAccessProfile(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.XAAAccessProfileScopeBinding = newXAAAccessProfileScopeBinding(sdk, sdk.sdkConfiguration, sdk.hooks) @@ -330,6 +351,7 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.RequestCatalogManagement = newRequestCatalogManagement(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.ConnectorAuthoringActivation = newConnectorAuthoringActivation(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.ConnectorCatalog = newConnectorCatalog(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.UIConversations = newUIConversations(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.CredentialInventoryPolicy = newCredentialInventoryPolicy(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Decoy = newDecoy(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.DecoySearch = newDecoySearch(sdk, sdk.sdkConfiguration, sdk.hooks) @@ -337,21 +359,30 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.Finding = newFinding(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.FindingRoutingRule = newFindingRoutingRule(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.FindingSearch = newFindingSearch(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.FindingSettings = newFindingSettings(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.FindingTransformationRule = newFindingTransformationRule(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Functions = newFunctions(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.FunctionsInvocation = newFunctionsInvocation(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.FunctionsInvocationSearch = newFunctionsInvocationSearch(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.AppCap = newAppCap(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.FundAssignment = newFundAssignment(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.MyFundLimits = newMyFundLimits(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.FundPolicy = newFundPolicy(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.FundRule = newFundRule(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Hooks = newHooks(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.PersonalClient = newPersonalClient(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.PersonalDevice = newPersonalDevice(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Roles = newRoles(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.TunnelCredentials = newTunnelCredentials(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.GatewayKey = newGatewayKey(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.ProviderCredential = newProviderCredential(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.LocalDirectoryConfig = newLocalDirectoryConfig(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.LocalUserInvitation = newLocalUserInvitation(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.Policies = newPolicies(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AccountProvisionPolicyTest = newAccountProvisionPolicyTest(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.PolicyValidate = newPolicyValidate(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.RecoveryPolicy = newRecoveryPolicy(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.Reporting = newReporting(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.RequestSchema = newRequestSchema(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.RoleMiningManagement = newRoleMiningManagement(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.AutomationExecutionSearch = newAutomationExecutionSearch(sdk, sdk.sdkConfiguration, sdk.hooks) @@ -394,6 +425,7 @@ func New(opts ...SDKOption) *ConductoroneAPI { sdk.OnboardingSettings = newOnboardingSettings(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.RequestSettings = newRequestSettings(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.SessionSettings = newSessionSettings(sdk, sdk.sdkConfiguration, sdk.hooks) + sdk.SSOSettings = newSSOSettings(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.SSFReceiverStream = newSSFReceiverStream(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.SSFReceiverEvent = newSSFReceiverEvent(sdk, sdk.sdkConfiguration, sdk.hooks) sdk.SystemLog = newSystemLog(sdk, sdk.sdkConfiguration, sdk.hooks) diff --git a/connector.go b/connector.go index 2db198947..1939bac5c 100644 --- a/connector.go +++ b/connector.go @@ -880,7 +880,10 @@ func (s *Connector) Delete(ctx context.Context, request operations.C1APIAppV1Con } // ForceSync - Force Sync -// Trigger an immediate sync for a connector. The sync is queued and may not start instantly. +// Trigger an immediate sync for a connector. The sync is queued and may not start +// +// instantly. Poll the connector's sync_status (or GetConnector) for progress; an empty +// success response means the sync was accepted onto the queue, not that it has finished. func (s *Connector) ForceSync(ctx context.Context, request operations.C1APIAppV1ConnectorServiceForceSyncRequest, opts ...operations.Option) (*operations.C1APIAppV1ConnectorServiceForceSyncResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/contacts.go b/contacts.go index 144e4ca22..c40962e25 100644 --- a/contacts.go +++ b/contacts.go @@ -32,7 +32,9 @@ func newContacts(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, ho } // GetContacts - Get Contacts -// Invokes the c1.api.settings.v1.ContactsService.GetContacts method. +// GetContacts returns the organization's security, billing, and operations +// +// contact email addresses. func (s *Contacts) GetContacts(ctx context.Context, opts ...operations.Option) (*operations.C1APISettingsV1ContactsServiceGetContactsResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -237,7 +239,11 @@ func (s *Contacts) GetContacts(ctx context.Context, opts ...operations.Option) ( } // UpdateContacts - Update Contacts -// Invokes the c1.api.settings.v1.ContactsService.UpdateContacts method. +// UpdateContacts updates the organization's security, billing, and +// +// operations contact email addresses. If update_mask is set, only the +// selected fields are changed; otherwise all contact fields are replaced +// with the values in the request. func (s *Contacts) UpdateContacts(ctx context.Context, request *shared.UpdateContactsRequest, opts ...operations.Option) (*operations.C1APISettingsV1ContactsServiceUpdateContactsResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md b/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md new file mode 100644 index 000000000..902c9433c --- /dev/null +++ b/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md @@ -0,0 +1,9 @@ +# C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `ConversationID` | `string` | :heavy_check_mark: | N/A | +| `SurfaceID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md b/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md new file mode 100644 index 000000000..9732c7df1 --- /dev/null +++ b/docs/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md @@ -0,0 +1,11 @@ +# C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | +| `A2UIServiceGetSurfaceProvenanceResponse` | [*shared.A2UIServiceGetSurfaceProvenanceResponse](../../../pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md) | :heavy_minus_sign: | A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built
    from: the steps its program ran, and the sources its components report. | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md new file mode 100644 index 000000000..e85a9555e --- /dev/null +++ b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md @@ -0,0 +1,9 @@ +# C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | +| `AccessReviewActionsServiceGenerateReportRequest` | [*shared.AccessReviewActionsServiceGenerateReportRequest](../../../pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md) | :heavy_minus_sign: | N/A | +| `AccessReviewID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md new file mode 100644 index 000000000..d5c8d0362 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md @@ -0,0 +1,11 @@ +# C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `AccessReviewActionsServiceGenerateReportResponse` | [*shared.AccessReviewActionsServiceGenerateReportResponse](../../../pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md new file mode 100644 index 000000000..5c5e03b8c --- /dev/null +++ b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md @@ -0,0 +1,10 @@ +# C1APIAccessreviewV1AccessReviewReportServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AccessReviewID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md new file mode 100644 index 000000000..eb8bb2d41 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIAccessreviewV1AccessReviewReportServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `AccessReviewReportServiceListResponse` | [*shared.AccessReviewReportServiceListResponse](../../../pkg/models/shared/accessreviewreportservicelistresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md new file mode 100644 index 000000000..6a0a739a4 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md @@ -0,0 +1,10 @@ +# C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | +| `Query` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md new file mode 100644 index 000000000..c7b645c49 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPAccessProfileServiceSearchAccessProfilesResponse` | [*shared.MCPAccessProfileServiceSearchAccessProfilesResponse](../../../pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md) | :heavy_minus_sign: | MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of
    tenant-wide MCP access profiles. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md new file mode 100644 index 000000000..b04feb4f2 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md @@ -0,0 +1,10 @@ +# C1APIAiGovernanceV1MCPResourceServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ConnectorID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md new file mode 100644 index 000000000..e37ac81e5 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPResourceServiceGetResponse` | [*shared.MCPResourceServiceGetResponse](../../../pkg/models/shared/mcpresourceservicegetresponse.md) | :heavy_minus_sign: | MCPResourceServiceGetResponse returns a single MCP resource. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md new file mode 100644 index 000000000..07b96921f --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md @@ -0,0 +1,12 @@ +# C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ConnectorID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md new file mode 100644 index 000000000..7bfba7ef1 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPResourceServiceListHistoryResponse` | [*shared.MCPResourceServiceListHistoryResponse](../../../pkg/models/shared/mcpresourceservicelisthistoryresponse.md) | :heavy_minus_sign: | MCPResourceServiceListHistoryResponse returns MCP resource history entries. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md new file mode 100644 index 000000000..cb44710bd --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ConnectorID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md new file mode 100644 index 000000000..e08f7d692 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPResourceServiceListResponse` | [*shared.MCPResourceServiceListResponse](../../../pkg/models/shared/mcpresourceservicelistresponse.md) | :heavy_minus_sign: | MCPResourceServiceListResponse returns a list of MCP resources. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md new file mode 100644 index 000000000..23e8b048c --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md @@ -0,0 +1,10 @@ +# C1APIAiGovernanceV1MCPResourceServiceSearchRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `MCPResourceServiceSearchRequest` | [*shared.MCPResourceServiceSearchRequest](../../../pkg/models/shared/mcpresourceservicesearchrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ConnectorID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md new file mode 100644 index 000000000..788c965be --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceSearchResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPResourceServiceSearchResponse` | [*shared.MCPResourceServiceSearchResponse](../../../pkg/models/shared/mcpresourceservicesearchresponse.md) | :heavy_minus_sign: | MCPResourceServiceSearchResponse returns matching MCP resources. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md new file mode 100644 index 000000000..1dff8cd69 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceUpdateRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `MCPResourceServiceUpdateRequest` | [*shared.MCPResourceServiceUpdateRequest](../../../pkg/models/shared/mcpresourceserviceupdaterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ConnectorID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md new file mode 100644 index 000000000..22d317921 --- /dev/null +++ b/docs/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APIAiGovernanceV1MCPResourceServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MCPResourceServiceUpdateResponse` | [*shared.MCPResourceServiceUpdateResponse](../../../pkg/models/shared/mcpresourceserviceupdateresponse.md) | :heavy_minus_sign: | MCPResourceServiceUpdateResponse returns the updated MCP resource. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md b/docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md new file mode 100644 index 000000000..39af5af91 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `AppEntitlementSearchServiceSearchReachableResourcesForUserResponse` | [*shared.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse](../../../pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md) | :heavy_minus_sign: | SearchReachableResourcesForUser response. Resources are deduplicated: a
    resource reachable through more than one grant or entitlement appears once. | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appentitlementslistrequest.md b/docs/pkg/models/operations/c1apiappv1appentitlementslistrequest.md index 5cee87424..b5dd401e3 100644 --- a/docs/pkg/models/operations/c1apiappv1appentitlementslistrequest.md +++ b/docs/pkg/models/operations/c1apiappv1appentitlementslistrequest.md @@ -6,5 +6,7 @@ | Field | Type | Required | Description | | ------------------ | ------------------ | ------------------ | ------------------ | | `AppID` | `string` | :heavy_check_mark: | N/A | +| `AppUserID` | `*string` | :heavy_minus_sign: | N/A | | `PageSize` | `*int` | :heavy_minus_sign: | N/A | -| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | +| `Q` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md new file mode 100644 index 000000000..1b377a296 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md @@ -0,0 +1,10 @@ +# C1APIAppV1AppManagedStateServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ResourceID` | `string` | :heavy_check_mark: | N/A | +| `ResourceTypeID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md new file mode 100644 index 000000000..fe56adb59 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppManagedStateServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `GetAppManagedStateBindingResponse` | [*shared.GetAppManagedStateBindingResponse](../../../pkg/models/shared/getappmanagedstatebindingresponse.md) | :heavy_minus_sign: | GetAppManagedStateBindingResponse contains the managed state of a discovered application. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md new file mode 100644 index 000000000..b30cc2b3a --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppManagedStateServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | +| `ResourceTypeID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md new file mode 100644 index 000000000..38a488f65 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppManagedStateServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ListAppManagedStateBindingsResponse` | [*shared.ListAppManagedStateBindingsResponse](../../../pkg/models/shared/listappmanagedstatebindingsresponse.md) | :heavy_minus_sign: | ListAppManagedStateBindingsResponse contains one page of discovered application managed states. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md new file mode 100644 index 000000000..5652bcfa7 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppManagedStateServicePromoteRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `PromoteAppManagedStateBindingRequest` | [*shared.PromoteAppManagedStateBindingRequest](../../../pkg/models/shared/promoteappmanagedstatebindingrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ResourceID` | `string` | :heavy_check_mark: | N/A | +| `ResourceTypeID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md new file mode 100644 index 000000000..0e72b10c8 --- /dev/null +++ b/docs/pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md @@ -0,0 +1,11 @@ +# C1APIAppV1AppManagedStateServicePromoteResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `GetAppManagedStateBindingResponse` | [*shared.GetAppManagedStateBindingResponse](../../../pkg/models/shared/getappmanagedstatebindingresponse.md) | :heavy_minus_sign: | GetAppManagedStateBindingResponse contains the managed state of a discovered application. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1appscreateresponse.md b/docs/pkg/models/operations/c1apiappv1appscreateresponse.md index 5007a79ec..07467d1b1 100644 --- a/docs/pkg/models/operations/c1apiappv1appscreateresponse.md +++ b/docs/pkg/models/operations/c1apiappv1appscreateresponse.md @@ -6,6 +6,6 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | | `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | -| `CreateAppResponse` | [*shared.CreateAppResponse](../../../pkg/models/shared/createappresponse.md) | :heavy_minus_sign: | Returns the new app's values. | +| `CreateAppResponse` | [*shared.CreateAppResponse](../../../pkg/models/shared/createappresponse.md) | :heavy_minus_sign: | CreateAppResponse contains the newly created application. | | `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | | `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiappv1connectorserviceforcesyncresponse.md b/docs/pkg/models/operations/c1apiappv1connectorserviceforcesyncresponse.md index 7952f8f04..a5ec7b9ad 100644 --- a/docs/pkg/models/operations/c1apiappv1connectorserviceforcesyncresponse.md +++ b/docs/pkg/models/operations/c1apiappv1connectorserviceforcesyncresponse.md @@ -3,9 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | -| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | -| `ForceSyncResponse` | [*shared.ForceSyncResponse](../../../pkg/models/shared/forcesyncresponse.md) | :heavy_minus_sign: | Empty response body. Status code indicates success. | -| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | -| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ForceSyncResponse` | [*shared.ForceSyncResponse](../../../pkg/models/shared/forcesyncresponse.md) | :heavy_minus_sign: | Empty response body. Status code indicates success. Poll the connector sync status
    for progress after ForceSync accepts the request. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md b/docs/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md new file mode 100644 index 000000000..1ec532222 --- /dev/null +++ b/docs/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md @@ -0,0 +1,11 @@ +# C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `EnsureOnboardingSessionResponse` | [*shared.EnsureOnboardingSessionResponse](../../../pkg/models/shared/ensureonboardingsessionresponse.md) | :heavy_minus_sign: | Returns the active onboarding conversation and whether this call created it. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md b/docs/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md new file mode 100644 index 000000000..e62f12ba4 --- /dev/null +++ b/docs/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md @@ -0,0 +1,11 @@ +# C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ListFindingSettingsResponse` | [*shared.ListFindingSettingsResponse](../../../pkg/models/shared/listfindingsettingsresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md b/docs/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md new file mode 100644 index 000000000..90f08cbe7 --- /dev/null +++ b/docs/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md @@ -0,0 +1,11 @@ +# C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | +| `UpdateFindingSettingsResponse` | [*shared.UpdateFindingSettingsResponse](../../../pkg/models/shared/updatefindingsettingsresponse.md) | :heavy_minus_sign: | Successful response | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md new file mode 100644 index 000000000..7a287adc7 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1AppCapServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `AppCapServiceDeleteRequest` | [*shared.AppCapServiceDeleteRequest](../../../pkg/models/shared/appcapservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md new file mode 100644 index 000000000..ffd519b06 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `AppCapServiceDeleteResponse` | [*shared.AppCapServiceDeleteResponse](../../../pkg/models/shared/appcapservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicegetrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicegetrequest.md new file mode 100644 index 000000000..5681d300c --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicegetrequest.md @@ -0,0 +1,8 @@ +# C1APIFundsV1AppCapServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicegetresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicegetresponse.md new file mode 100644 index 000000000..2a7bf9121 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `AppCapServiceGetResponse` | [*shared.AppCapServiceGetResponse](../../../pkg/models/shared/appcapservicegetresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md new file mode 100644 index 000000000..03cd85047 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md @@ -0,0 +1,10 @@ +# C1APIFundsV1AppCapServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md new file mode 100644 index 000000000..75e1459fe --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `AppCapServiceListHistoryResponse` | [*shared.AppCapServiceListHistoryResponse](../../../pkg/models/shared/appcapservicelisthistoryresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicelistrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicelistrequest.md new file mode 100644 index 000000000..1a0002d1e --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicelistrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1AppCapServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicelistresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicelistresponse.md new file mode 100644 index 000000000..7f7eac842 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | +| `AppCapServiceListResponse` | [*shared.AppCapServiceListResponse](../../../pkg/models/shared/appcapservicelistresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md new file mode 100644 index 000000000..bc51ac3f8 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1AppCapServiceSetLimitRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `AppCapServiceSetLimitRequest` | [*shared.AppCapServiceSetLimitRequest](../../../pkg/models/shared/appcapservicesetlimitrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md new file mode 100644 index 000000000..c60739bdb --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceSetLimitResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `AppCapServiceSetLimitResponse` | [*shared.AppCapServiceSetLimitResponse](../../../pkg/models/shared/appcapservicesetlimitresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md new file mode 100644 index 000000000..199240967 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1AppCapServiceSuspendRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `AppCapServiceSuspendRequest` | [*shared.AppCapServiceSuspendRequest](../../../pkg/models/shared/appcapservicesuspendrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md new file mode 100644 index 000000000..6c1a39617 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceSuspendResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `AppCapServiceSuspendResponse` | [*shared.AppCapServiceSuspendResponse](../../../pkg/models/shared/appcapservicesuspendresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md b/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md new file mode 100644 index 000000000..727a1e77c --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1AppCapServiceUnsuspendRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `AppCapServiceUnsuspendRequest` | [*shared.AppCapServiceUnsuspendRequest](../../../pkg/models/shared/appcapserviceunsuspendrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md b/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md new file mode 100644 index 000000000..72fcb8779 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1AppCapServiceUnsuspendResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `AppCapServiceUnsuspendResponse` | [*shared.AppCapServiceUnsuspendResponse](../../../pkg/models/shared/appcapserviceunsuspendresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md new file mode 100644 index 000000000..a17520c72 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceClearExtensionRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `FundAssignmentServiceClearExtensionRequest` | [*shared.FundAssignmentServiceClearExtensionRequest](../../../pkg/models/shared/fundassignmentserviceclearextensionrequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md new file mode 100644 index 000000000..644b899c5 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceClearExtensionResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceClearExtensionResponse` | [*shared.FundAssignmentServiceClearExtensionResponse](../../../pkg/models/shared/fundassignmentserviceclearextensionresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md new file mode 100644 index 000000000..70eba7801 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `FundAssignmentServiceDeleteRequest` | [*shared.FundAssignmentServiceDeleteRequest](../../../pkg/models/shared/fundassignmentservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md new file mode 100644 index 000000000..dd77ddafa --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceDeleteResponse` | [*shared.FundAssignmentServiceDeleteResponse](../../../pkg/models/shared/fundassignmentservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md new file mode 100644 index 000000000..fc04b75b7 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md @@ -0,0 +1,8 @@ +# C1APIFundsV1FundAssignmentServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md new file mode 100644 index 000000000..26253300b --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceGetResponse` | [*shared.FundAssignmentServiceGetResponse](../../../pkg/models/shared/fundassignmentservicegetresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md new file mode 100644 index 000000000..2c65418ee --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceGrantExtensionRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `FundAssignmentServiceGrantExtensionRequest` | [*shared.FundAssignmentServiceGrantExtensionRequest](../../../pkg/models/shared/fundassignmentservicegrantextensionrequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md new file mode 100644 index 000000000..51948906d --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceGrantExtensionResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceGrantExtensionResponse` | [*shared.FundAssignmentServiceGrantExtensionResponse](../../../pkg/models/shared/fundassignmentservicegrantextensionresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md new file mode 100644 index 000000000..b2830adb8 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md @@ -0,0 +1,10 @@ +# C1APIFundsV1FundAssignmentServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md new file mode 100644 index 000000000..513c45aea --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceListHistoryResponse` | [*shared.FundAssignmentServiceListHistoryResponse](../../../pkg/models/shared/fundassignmentservicelisthistoryresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md new file mode 100644 index 000000000..d98d9e9d2 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceSearchResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceSearchResponse` | [*shared.FundAssignmentServiceSearchResponse](../../../pkg/models/shared/fundassignmentservicesearchresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md new file mode 100644 index 000000000..3efa41be3 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceSetLimitRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `FundAssignmentServiceSetLimitRequest` | [*shared.FundAssignmentServiceSetLimitRequest](../../../pkg/models/shared/fundassignmentservicesetlimitrequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md new file mode 100644 index 000000000..18e8d4c2a --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceSetLimitResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceSetLimitResponse` | [*shared.FundAssignmentServiceSetLimitResponse](../../../pkg/models/shared/fundassignmentservicesetlimitresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md new file mode 100644 index 000000000..e8e3137b5 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceSuspendRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `FundAssignmentServiceSuspendRequest` | [*shared.FundAssignmentServiceSuspendRequest](../../../pkg/models/shared/fundassignmentservicesuspendrequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md new file mode 100644 index 000000000..e3c9c8907 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceSuspendResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceSuspendResponse` | [*shared.FundAssignmentServiceSuspendResponse](../../../pkg/models/shared/fundassignmentservicesuspendresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md new file mode 100644 index 000000000..5d805c8d7 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundAssignmentServiceUnsuspendRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `FundAssignmentServiceUnsuspendRequest` | [*shared.FundAssignmentServiceUnsuspendRequest](../../../pkg/models/shared/fundassignmentserviceunsuspendrequest.md) | :heavy_minus_sign: | N/A | +| `UserID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md new file mode 100644 index 000000000..e6ee91337 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundAssignmentServiceUnsuspendResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundAssignmentServiceUnsuspendResponse` | [*shared.FundAssignmentServiceUnsuspendResponse](../../../pkg/models/shared/fundassignmentserviceunsuspendresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md new file mode 100644 index 000000000..8b2997f1b --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceCreateResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceCreateResponse` | [*shared.FundPolicyServiceCreateResponse](../../../pkg/models/shared/fundpolicyservicecreateresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md new file mode 100644 index 000000000..bd0bafeee --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceDeleteResponse` | [*shared.FundPolicyServiceDeleteResponse](../../../pkg/models/shared/fundpolicyservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md new file mode 100644 index 000000000..d73cda289 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceFreezeTenantResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceFreezeTenantResponse` | [*shared.FundPolicyServiceFreezeTenantResponse](../../../pkg/models/shared/fundpolicyservicefreezetenantresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md new file mode 100644 index 000000000..dc428ab86 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceGetResponse` | [*shared.FundPolicyServiceGetResponse](../../../pkg/models/shared/fundpolicyservicegetresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md new file mode 100644 index 000000000..0e65892bc --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundPolicyServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md new file mode 100644 index 000000000..89dd38fa8 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceListHistoryResponse` | [*shared.FundPolicyServiceListHistoryResponse](../../../pkg/models/shared/fundpolicyservicelisthistoryresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md new file mode 100644 index 000000000..0b339d164 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceSetOrgCeilingResponse` | [*shared.FundPolicyServiceSetOrgCeilingResponse](../../../pkg/models/shared/fundpolicyservicesetorgceilingresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md new file mode 100644 index 000000000..01425116d --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceUnfreezeTenantResponse` | [*shared.FundPolicyServiceUnfreezeTenantResponse](../../../pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md b/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md new file mode 100644 index 000000000..f1d78de42 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundPolicyServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundPolicyServiceUpdateResponse` | [*shared.FundPolicyServiceUpdateResponse](../../../pkg/models/shared/fundpolicyserviceupdateresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md new file mode 100644 index 000000000..4e77007da --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceCreateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceCreateResponse` | [*shared.FundRuleServiceCreateResponse](../../../pkg/models/shared/fundruleservicecreateresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md new file mode 100644 index 000000000..068303722 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundRuleServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `FundRuleServiceDeleteRequest` | [*shared.FundRuleServiceDeleteRequest](../../../pkg/models/shared/fundruleservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `RuleID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md new file mode 100644 index 000000000..ecc7c8f9e --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceDeleteResponse` | [*shared.FundRuleServiceDeleteResponse](../../../pkg/models/shared/fundruleservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md new file mode 100644 index 000000000..6582bb93c --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md @@ -0,0 +1,8 @@ +# C1APIFundsV1FundRuleServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `RuleID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md new file mode 100644 index 000000000..1366bd5a3 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceGetResponse` | [*shared.FundRuleServiceGetResponse](../../../pkg/models/shared/fundruleservicegetresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md new file mode 100644 index 000000000..59d053aed --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md @@ -0,0 +1,10 @@ +# C1APIFundsV1FundRuleServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | +| `RuleID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md new file mode 100644 index 000000000..4702b5322 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceListHistoryResponse` | [*shared.FundRuleServiceListHistoryResponse](../../../pkg/models/shared/fundruleservicelisthistoryresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md new file mode 100644 index 000000000..3bf07586a --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundRuleServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md new file mode 100644 index 000000000..80957aaff --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceListResponse` | [*shared.FundRuleServiceListResponse](../../../pkg/models/shared/fundruleservicelistresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md new file mode 100644 index 000000000..10de09258 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceSearchResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceSearchResponse` | [*shared.FundRuleServiceSearchResponse](../../../pkg/models/shared/fundruleservicesearchresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md b/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md new file mode 100644 index 000000000..48bfb972c --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1FundRuleServiceUpdateRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `FundRuleServiceUpdateRequest` | [*shared.FundRuleServiceUpdateRequest](../../../pkg/models/shared/fundruleserviceupdaterequest.md) | :heavy_minus_sign: | N/A | +| `RuleID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md b/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md new file mode 100644 index 000000000..238c85063 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1FundRuleServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `FundRuleServiceUpdateResponse` | [*shared.FundRuleServiceUpdateResponse](../../../pkg/models/shared/fundruleserviceupdateresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md new file mode 100644 index 000000000..065d87c67 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1MyFundLimitsServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `MyFundLimitsServiceDeleteRequest` | [*shared.MyFundLimitsServiceDeleteRequest](../../../pkg/models/shared/myfundlimitsservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md new file mode 100644 index 000000000..76ba52948 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServiceDeleteResponse` | [*shared.MyFundLimitsServiceDeleteResponse](../../../pkg/models/shared/myfundlimitsservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md new file mode 100644 index 000000000..56d7cd954 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md @@ -0,0 +1,10 @@ +# C1APIFundsV1MyFundLimitsServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md new file mode 100644 index 000000000..07c335f10 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServiceListHistoryResponse` | [*shared.MyFundLimitsServiceListHistoryResponse](../../../pkg/models/shared/myfundlimitsservicelisthistoryresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md new file mode 100644 index 000000000..5789ec19c --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1MyFundLimitsServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md new file mode 100644 index 000000000..4a95a0589 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServiceListResponse` | [*shared.MyFundLimitsServiceListResponse](../../../pkg/models/shared/myfundlimitsservicelistresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md new file mode 100644 index 000000000..a0d4b0b55 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1MyFundLimitsServicePauseRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `MyFundLimitsServicePauseRequest` | [*shared.MyFundLimitsServicePauseRequest](../../../pkg/models/shared/myfundlimitsservicepauserequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md new file mode 100644 index 000000000..dce54c73b --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServicePauseResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServicePauseResponse` | [*shared.MyFundLimitsServicePauseResponse](../../../pkg/models/shared/myfundlimitsservicepauseresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md new file mode 100644 index 000000000..b717a01ff --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1MyFundLimitsServiceResumeRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `MyFundLimitsServiceResumeRequest` | [*shared.MyFundLimitsServiceResumeRequest](../../../pkg/models/shared/myfundlimitsserviceresumerequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md new file mode 100644 index 000000000..f23b9619a --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServiceResumeResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServiceResumeResponse` | [*shared.MyFundLimitsServiceResumeResponse](../../../pkg/models/shared/myfundlimitsserviceresumeresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md new file mode 100644 index 000000000..7a2e15216 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md @@ -0,0 +1,9 @@ +# C1APIFundsV1MyFundLimitsServiceSetLimitRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `MyFundLimitsServiceSetLimitRequest` | [*shared.MyFundLimitsServiceSetLimitRequest](../../../pkg/models/shared/myfundlimitsservicesetlimitrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md new file mode 100644 index 000000000..8476e5ed6 --- /dev/null +++ b/docs/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md @@ -0,0 +1,11 @@ +# C1APIFundsV1MyFundLimitsServiceSetLimitResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MyFundLimitsServiceSetLimitResponse` | [*shared.MyFundLimitsServiceSetLimitResponse](../../../pkg/models/shared/myfundlimitsservicesetlimitresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md new file mode 100644 index 000000000..3397e4f33 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1GatewayKeyServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ListGatewayKeysResponse` | [*shared.ListGatewayKeysResponse](../../../pkg/models/shared/listgatewaykeysresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md new file mode 100644 index 000000000..c1029073d --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1GatewayKeyServiceMintResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `MintGatewayKeyResponse` | [*shared.MintGatewayKeyResponse](../../../pkg/models/shared/mintgatewaykeyresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md new file mode 100644 index 000000000..cfd24aad2 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md @@ -0,0 +1,9 @@ +# C1APILlmGatewayV1GatewayKeyServiceRevokeRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | +| `RevokeGatewayKeyRequest` | [*shared.RevokeGatewayKeyRequest](../../../pkg/models/shared/revokegatewaykeyrequest.md) | :heavy_minus_sign: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md new file mode 100644 index 000000000..b2831195a --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1GatewayKeyServiceRevokeResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `RevokeGatewayKeyResponse` | [*shared.RevokeGatewayKeyResponse](../../../pkg/models/shared/revokegatewaykeyresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md new file mode 100644 index 000000000..8e69138f9 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md @@ -0,0 +1,9 @@ +# C1APILlmGatewayV1ProviderCredentialServiceClearRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `ClearProviderCredentialRequest` | [*shared.ClearProviderCredentialRequest](../../../pkg/models/shared/clearprovidercredentialrequest.md) | :heavy_minus_sign: | N/A | +| `SlotID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md new file mode 100644 index 000000000..995e1bc54 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1ProviderCredentialServiceClearResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `ClearProviderCredentialResponse` | [*shared.ClearProviderCredentialResponse](../../../pkg/models/shared/clearprovidercredentialresponse.md) | :heavy_minus_sign: | Successful response | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md new file mode 100644 index 000000000..eb8262005 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md @@ -0,0 +1,8 @@ +# C1APILlmGatewayV1ProviderCredentialServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `SlotID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md new file mode 100644 index 000000000..e109b0ad1 --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1ProviderCredentialServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `GetProviderCredentialResponse` | [*shared.GetProviderCredentialResponse](../../../pkg/models/shared/getprovidercredentialresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md new file mode 100644 index 000000000..3b7cf87ea --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md @@ -0,0 +1,9 @@ +# C1APILlmGatewayV1ProviderCredentialServiceSetRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `SetProviderCredentialRequest` | [*shared.SetProviderCredentialRequest](../../../pkg/models/shared/setprovidercredentialrequest.md) | :heavy_minus_sign: | N/A | +| `SlotID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md new file mode 100644 index 000000000..f3c03e44b --- /dev/null +++ b/docs/pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md @@ -0,0 +1,11 @@ +# C1APILlmGatewayV1ProviderCredentialServiceSetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SetProviderCredentialResponse` | [*shared.SetProviderCredentialResponse](../../../pkg/models/shared/setprovidercredentialresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md b/docs/pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md new file mode 100644 index 000000000..46db929a3 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md @@ -0,0 +1,9 @@ +# C1APIReportingV1ReportingServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ReportingServiceDeleteRequest` | [*shared.ReportingServiceDeleteRequest](../../../pkg/models/shared/reportingservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md new file mode 100644 index 000000000..263b7b896 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceDeleteResponse` | [*shared.ReportingServiceDeleteResponse](../../../pkg/models/shared/reportingservicedeleteresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicegetrequest.md b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrequest.md new file mode 100644 index 000000000..57ee9ff6e --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrequest.md @@ -0,0 +1,8 @@ +# C1APIReportingV1ReportingServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicegetresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicegetresponse.md new file mode 100644 index 000000000..cdd7d9c34 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceGetResponse` | [*shared.ReportingServiceGetResponse](../../../pkg/models/shared/reportingservicegetresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md new file mode 100644 index 000000000..687a104f8 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md @@ -0,0 +1,9 @@ +# C1APIReportingV1ReportingServiceGetRunProvenanceRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `ID` | `string` | :heavy_check_mark: | N/A | +| `RunID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md new file mode 100644 index 000000000..76fcbec71 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceGetRunProvenanceResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceGetRunProvenanceResponse` | [*shared.ReportingServiceGetRunProvenanceResponse](../../../pkg/models/shared/reportingservicegetrunprovenanceresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicelistrequest.md b/docs/pkg/models/operations/c1apireportingv1reportingservicelistrequest.md new file mode 100644 index 000000000..b0ff02a2b --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicelistrequest.md @@ -0,0 +1,9 @@ +# C1APIReportingV1ReportingServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicelistresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicelistresponse.md new file mode 100644 index 000000000..a05333ac7 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceListResponse` | [*shared.ReportingServiceListResponse](../../../pkg/models/shared/reportingservicelistresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicerunrequest.md b/docs/pkg/models/operations/c1apireportingv1reportingservicerunrequest.md new file mode 100644 index 000000000..fd22f04bf --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicerunrequest.md @@ -0,0 +1,9 @@ +# C1APIReportingV1ReportingServiceRunRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `ReportingServiceRunRequest` | [*shared.ReportingServiceRunRequest](../../../pkg/models/shared/reportingservicerunrequest.md) | :heavy_minus_sign: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicerunresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicerunresponse.md new file mode 100644 index 000000000..a002c12fc --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicerunresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceRunResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceRunResponse` | [*shared.ReportingServiceRunResponse](../../../pkg/models/shared/reportingservicerunresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md new file mode 100644 index 000000000..d38924ae4 --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceSaveResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceSaveResponse` | [*shared.ReportingServiceSaveResponse](../../../pkg/models/shared/reportingservicesaveresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md b/docs/pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md new file mode 100644 index 000000000..f666524bb --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md @@ -0,0 +1,9 @@ +# C1APIReportingV1ReportingServiceUpdateRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ReportingServiceUpdateRequest` | [*shared.ReportingServiceUpdateRequest](../../../pkg/models/shared/reportingserviceupdaterequest.md) | :heavy_minus_sign: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md b/docs/pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md new file mode 100644 index 000000000..f69f129cb --- /dev/null +++ b/docs/pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APIReportingV1ReportingServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `ReportingServiceUpdateResponse` | [*shared.ReportingServiceUpdateResponse](../../../pkg/models/shared/reportingserviceupdateresponse.md) | :heavy_minus_sign: | Successful response | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md b/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md new file mode 100644 index 000000000..358bfdeb6 --- /dev/null +++ b/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md @@ -0,0 +1,9 @@ +# C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `EvaluateEntitlementSelectionRequest` | [*shared.EvaluateEntitlementSelectionRequest](../../../pkg/models/shared/evaluateentitlementselectionrequest.md) | :heavy_minus_sign: | N/A | +| `AnalysisID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md b/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md new file mode 100644 index 000000000..4cf4117c9 --- /dev/null +++ b/docs/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md @@ -0,0 +1,11 @@ +# C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `EvaluateEntitlementSelectionResponse` | [*shared.EvaluateEntitlementSelectionResponse](../../../pkg/models/shared/evaluateentitlementselectionresponse.md) | :heavy_minus_sign: | EvaluateEntitlementSelectionResponse contains the exact impact of the
    resolved entitlement selection. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md new file mode 100644 index 000000000..e07f77490 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest` | [*shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest](../../../pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md new file mode 100644 index 000000000..4e69b7fb8 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse` | [*shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse](../../../pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md) | :heavy_minus_sign: | SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded
    recovery progress. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md new file mode 100644 index 000000000..aefacc1b7 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceBatchImportSubjectCompatibilityRequest` | [*shared.SSOApplicationServiceBatchImportSubjectCompatibilityRequest](../../../pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md new file mode 100644 index 000000000..4dd2235c6 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceBatchImportSubjectCompatibilityResponse` | [*shared.SSOApplicationServiceBatchImportSubjectCompatibilityResponse](../../../pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md) | :heavy_minus_sign: | SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one
    bounded validation or apply batch. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md new file mode 100644 index 000000000..7dc49ab7c --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceCreateClientRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceCreateClientRequest` | [*shared.SSOApplicationServiceCreateClientRequest](../../../pkg/models/shared/ssoapplicationservicecreateclientrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md new file mode 100644 index 000000000..274295696 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceCreateClientResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceCreateClientResponse` | [*shared.SSOApplicationServiceCreateClientResponse](../../../pkg/models/shared/ssoapplicationservicecreateclientresponse.md) | :heavy_minus_sign: | SSOApplicationServiceCreateClientResponse contains the generated client and
    its one-time secret, when applicable. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md new file mode 100644 index 000000000..f3c12edd8 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md @@ -0,0 +1,9 @@ +# C1APISSOV1SSOApplicationServiceCreateRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceCreateRequest` | [*shared.SSOApplicationServiceCreateRequest](../../../pkg/models/shared/ssoapplicationservicecreaterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md new file mode 100644 index 000000000..4c4bd7341 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceCreateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceCreateResponse` | [*shared.SSOApplicationServiceCreateResponse](../../../pkg/models/shared/ssoapplicationservicecreateresponse.md) | :heavy_minus_sign: | SSOApplicationServiceCreateResponse returns the created SSO application. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md new file mode 100644 index 000000000..108bb5a1c --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceDeleteClientRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceDeleteClientRequest` | [*shared.SSOApplicationServiceDeleteClientRequest](../../../pkg/models/shared/ssoapplicationservicedeleteclientrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md new file mode 100644 index 000000000..1a214cd96 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceDeleteClientResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceDeleteClientResponse` | [*shared.SSOApplicationServiceDeleteClientResponse](../../../pkg/models/shared/ssoapplicationservicedeleteclientresponse.md) | :heavy_minus_sign: | SSOApplicationServiceDeleteClientResponse confirms deletion. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md new file mode 100644 index 000000000..b1cdc8bdc --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceDeleteRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceDeleteRequest` | [*shared.SSOApplicationServiceDeleteRequest](../../../pkg/models/shared/ssoapplicationservicedeleterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md new file mode 100644 index 000000000..dda289691 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceDeleteResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceDeleteResponse` | [*shared.SSOApplicationServiceDeleteResponse](../../../pkg/models/shared/ssoapplicationservicedeleteresponse.md) | :heavy_minus_sign: | SSOApplicationServiceDeleteResponse confirms deletion. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md new file mode 100644 index 000000000..0492f763c --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md @@ -0,0 +1,9 @@ +# C1APISSOV1SSOApplicationServiceGetRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md new file mode 100644 index 000000000..1e0f700e6 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceGetResponse` | [*shared.SSOApplicationServiceGetResponse](../../../pkg/models/shared/ssoapplicationservicegetresponse.md) | :heavy_minus_sign: | SSOApplicationServiceGetResponse returns a single SSO application. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md new file mode 100644 index 000000000..733661a54 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceListClientsRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md new file mode 100644 index 000000000..df485c06c --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceListClientsResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceListClientsResponse` | [*shared.SSOApplicationServiceListClientsResponse](../../../pkg/models/shared/ssoapplicationservicelistclientsresponse.md) | :heavy_minus_sign: | SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth
    clients. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md new file mode 100644 index 000000000..42af669a9 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md new file mode 100644 index 000000000..01902d162 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceListHistoryResponse` | [*shared.SSOApplicationServiceListHistoryResponse](../../../pkg/models/shared/ssoapplicationservicelisthistoryresponse.md) | :heavy_minus_sign: | SSOApplicationServiceListHistoryResponse returns SSO application history
    entries. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md new file mode 100644 index 000000000..874d45c32 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceListRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md new file mode 100644 index 000000000..a3d2bbcd2 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceListResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceListResponse` | [*shared.SSOApplicationServiceListResponse](../../../pkg/models/shared/ssoapplicationservicelistresponse.md) | :heavy_minus_sign: | SSOApplicationServiceListResponse returns a page of SSO applications. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md new file mode 100644 index 000000000..b7397e9a5 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceParseSAMLServiceProviderMetadataResponse` | [*shared.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse](../../../pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md) | :heavy_minus_sign: | SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the
    SAML configuration derived from one metadata document and every finding the
    parser raised about it. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md new file mode 100644 index 000000000..454df2eb5 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceRotateClientSecretRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceRotateClientSecretRequest` | [*shared.SSOApplicationServiceRotateClientSecretRequest](../../../pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md new file mode 100644 index 000000000..597699cae --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceRotateClientSecretResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceRotateClientSecretResponse` | [*shared.SSOApplicationServiceRotateClientSecretResponse](../../../pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md) | :heavy_minus_sign: | SSOApplicationServiceRotateClientSecretResponse contains the replacement
    secret. The value cannot be retrieved again. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md new file mode 100644 index 000000000..5b9edb578 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceSearchResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceSearchResponse` | [*shared.SSOApplicationServiceSearchResponse](../../../pkg/models/shared/ssoapplicationservicesearchresponse.md) | :heavy_minus_sign: | SSOApplicationServiceSearchResponse returns matching SSO applications. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md new file mode 100644 index 000000000..eedd4c7a3 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceUpdateClientRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceUpdateClientRequest` | [*shared.SSOApplicationServiceUpdateClientRequest](../../../pkg/models/shared/ssoapplicationserviceupdateclientrequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md new file mode 100644 index 000000000..7db2ce735 --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceUpdateClientResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceUpdateClientResponse` | [*shared.SSOApplicationServiceUpdateClientResponse](../../../pkg/models/shared/ssoapplicationserviceupdateclientresponse.md) | :heavy_minus_sign: | SSOApplicationServiceUpdateClientResponse contains the updated client. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md new file mode 100644 index 000000000..c7a386fce --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md @@ -0,0 +1,10 @@ +# C1APISSOV1SSOApplicationServiceUpdateRequest + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `SSOApplicationServiceUpdateRequest` | [*shared.SSOApplicationServiceUpdateRequest](../../../pkg/models/shared/ssoapplicationserviceupdaterequest.md) | :heavy_minus_sign: | N/A | +| `AppID` | `string` | :heavy_check_mark: | N/A | +| `ID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md new file mode 100644 index 000000000..b9342a6af --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOApplicationServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOApplicationServiceUpdateResponse` | [*shared.SSOApplicationServiceUpdateResponse](../../../pkg/models/shared/ssoapplicationserviceupdateresponse.md) | :heavy_minus_sign: | SSOApplicationServiceUpdateResponse returns the updated SSO application. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md b/docs/pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md new file mode 100644 index 000000000..30ef6e0ed --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOSettingsServiceGetResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOSettingsServiceGetResponse` | [*shared.SSOSettingsServiceGetResponse](../../../pkg/models/shared/ssosettingsservicegetresponse.md) | :heavy_minus_sign: | SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md b/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md new file mode 100644 index 000000000..4ea75545d --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md @@ -0,0 +1,9 @@ +# C1APISSOV1SSOSettingsServiceListHistoryRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `PageSize` | `*int` | :heavy_minus_sign: | N/A | +| `PageToken` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md b/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md new file mode 100644 index 000000000..754db71fc --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOSettingsServiceListHistoryResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOSettingsServiceListHistoryResponse` | [*shared.SSOSettingsServiceListHistoryResponse](../../../pkg/models/shared/ssosettingsservicelisthistoryresponse.md) | :heavy_minus_sign: | SSOSettingsServiceListHistoryResponse returns SSO settings history entries. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md b/docs/pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md new file mode 100644 index 000000000..fefc643bb --- /dev/null +++ b/docs/pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md @@ -0,0 +1,11 @@ +# C1APISSOV1SSOSettingsServiceUpdateResponse + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `SSOSettingsServiceUpdateResponse` | [*shared.SSOSettingsServiceUpdateResponse](../../../pkg/models/shared/ssosettingsserviceupdateresponse.md) | :heavy_minus_sign: | SSOSettingsServiceUpdateResponse returns the updated settings. | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md b/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md new file mode 100644 index 000000000..97ff808b5 --- /dev/null +++ b/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md @@ -0,0 +1,9 @@ +# C1APITaskV1TaskActionsServiceRetryProvisioningRequest + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `TaskActionsServiceRetryProvisioningRequest` | [*shared.TaskActionsServiceRetryProvisioningRequest](../../../pkg/models/shared/taskactionsserviceretryprovisioningrequest.md) | :heavy_minus_sign: | N/A | +| `TaskID` | `string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md b/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md new file mode 100644 index 000000000..08dea2fc6 --- /dev/null +++ b/docs/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md @@ -0,0 +1,11 @@ +# C1APITaskV1TaskActionsServiceRetryProvisioningResponse + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ContentType` | `string` | :heavy_check_mark: | HTTP response content type for this operation | +| `StatusCode` | `int` | :heavy_check_mark: | HTTP response status code for this operation | +| `RawResponse` | [*http.Response](https://pkg.go.dev/net/http#Response) | :heavy_check_mark: | Raw HTTP response; suitable for custom response parsing | +| `TaskServiceActionResponse` | [*shared.TaskServiceActionResponse](../../../pkg/models/shared/taskserviceactionresponse.md) | :heavy_minus_sign: | A generic response for task action endpoints, containing the updated task and the ID of the action that was created. | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uicomponent.md b/docs/pkg/models/shared/a2uicomponent.md index 31aa2eed2..06c885e43 100644 --- a/docs/pkg/models/shared/a2uicomponent.md +++ b/docs/pkg/models/shared/a2uicomponent.md @@ -29,6 +29,8 @@ This message contains a oneof named component. Only a single field of the follow - c1OnboardingPlan - c1ConnectorSyncDetail - c1Chart + - c1MetricCards + - c1Table @@ -43,12 +45,14 @@ This message contains a oneof named component. Only a single field of the follow | `C1ConnectorSyncDetail` | [*shared.C1ConnectorSyncDetailComponent](../../../pkg/models/shared/c1connectorsyncdetailcomponent.md) | :heavy_minus_sign: | N/A | | `C1ConnectorSyncProgress` | [*shared.C1ConnectorSyncProgressComponent](../../../pkg/models/shared/c1connectorsyncprogresscomponent.md) | :heavy_minus_sign: | N/A | | `C1DurationPicker` | [*shared.C1DurationPickerComponent](../../../pkg/models/shared/c1durationpickercomponent.md) | :heavy_minus_sign: | N/A | +| `C1MetricCards` | [*shared.C1MetricCardsComponent](../../../pkg/models/shared/c1metriccardscomponent.md) | :heavy_minus_sign: | N/A | | `C1MsTeamsNotifications` | [*shared.C1MSTeamsNotificationsComponent](../../../pkg/models/shared/c1msteamsnotificationscomponent.md) | :heavy_minus_sign: | N/A | | `C1OnboardingPlan` | [*shared.C1OnboardingPlanComponent](../../../pkg/models/shared/c1onboardingplancomponent.md) | :heavy_minus_sign: | N/A | | `C1OnboardingWelcome` | [*shared.C1OnboardingWelcomeComponent](../../../pkg/models/shared/c1onboardingwelcomecomponent.md) | :heavy_minus_sign: | N/A | | `C1ResourcePicker` | [*shared.C1ResourcePickerComponent](../../../pkg/models/shared/c1resourcepickercomponent.md) | :heavy_minus_sign: | N/A | | `C1SlackNotifications` | [*shared.C1SlackNotificationsComponent](../../../pkg/models/shared/c1slacknotificationscomponent.md) | :heavy_minus_sign: | N/A | | `C1StatusIndicator` | [*shared.C1StatusIndicatorComponent](../../../pkg/models/shared/c1statusindicatorcomponent.md) | :heavy_minus_sign: | N/A | +| `C1Table` | [*shared.C1TableComponent](../../../pkg/models/shared/c1tablecomponent.md) | :heavy_minus_sign: | N/A | | `C1TodoList` | [*shared.C1TodoListComponent](../../../pkg/models/shared/c1todolistcomponent.md) | :heavy_minus_sign: | N/A | | `Card` | [*shared.CardComponent](../../../pkg/models/shared/cardcomponent.md) | :heavy_minus_sign: | N/A | | `CheckBox` | [*shared.CheckBoxComponent](../../../pkg/models/shared/checkboxcomponent.md) | :heavy_minus_sign: | N/A | diff --git a/docs/pkg/models/shared/a2uiprovenanceobject.md b/docs/pkg/models/shared/a2uiprovenanceobject.md new file mode 100644 index 000000000..6b28257cd --- /dev/null +++ b/docs/pkg/models/shared/a2uiprovenanceobject.md @@ -0,0 +1,12 @@ +# A2UIProvenanceObject + +A2UIProvenanceObject names one record a step referred to by id. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | Empty when the record's type has no name to resolve, or the record is
    gone. The id then stands alone rather than the whole row being dropped. | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `RecordType` | [*shared.RecordType](../../../pkg/models/shared/recordtype.md) | :heavy_minus_sign: | Not always the step's own type: a step over grants can be narrowed to one
    app, and the app is the record worth naming. | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uiprovenancesource.md b/docs/pkg/models/shared/a2uiprovenancesource.md new file mode 100644 index 000000000..37ca45bdd --- /dev/null +++ b/docs/pkg/models/shared/a2uiprovenancesource.md @@ -0,0 +1,17 @@ +# A2UIProvenanceSource + +A2UIProvenanceSource is one self-reported source from a reporting component: + what a chart or table says it was drawn from, and how many rows fed it. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ComponentID` | `*string` | :heavy_minus_sign: | The componentId field. | +| `Count` | `*int64` | :heavy_minus_sign: | The count field. | +| `Kind` | `*string` | :heavy_minus_sign: | The kind field. | +| `Label` | `*string` | :heavy_minus_sign: | The label field. | +| ~~`MatchedToolCall`~~ | `*string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: always empty. See verified. | +| `Ref` | `*string` | :heavy_minus_sign: | The ref field. | +| ~~`Verified`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: always false. Superseded by
    A2UIServiceGetSurfaceProvenanceResponse.steps, which reports what the
    program did rather than judging it. | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uiprovenancestep.md b/docs/pkg/models/shared/a2uiprovenancestep.md new file mode 100644 index 000000000..534c53b0c --- /dev/null +++ b/docs/pkg/models/shared/a2uiprovenancestep.md @@ -0,0 +1,13 @@ +# A2UIProvenanceStep + +A2UIProvenanceStep is one thing the report's program did. Steps are returned + in the order the program performs them. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | +| `Objects` | [][shared.A2UIProvenanceObject](../../../pkg/models/shared/a2uiprovenanceobject.md) | :heavy_minus_sign: | The specific records this step named. Empty when the step names none, and
    withheld wholesale when step_objects_visible is false. | +| `Operation` | [*shared.Operation](../../../pkg/models/shared/operation.md) | :heavy_minus_sign: | The operation field. | +| `RecordType` | [*shared.A2UIProvenanceStepRecordType](../../../pkg/models/shared/a2uiprovenancesteprecordtype.md) | :heavy_minus_sign: | The recordType field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uiprovenancesteprecordtype.md b/docs/pkg/models/shared/a2uiprovenancesteprecordtype.md new file mode 100644 index 000000000..322c2112f --- /dev/null +++ b/docs/pkg/models/shared/a2uiprovenancesteprecordtype.md @@ -0,0 +1,51 @@ +# A2UIProvenanceStepRecordType + +The recordType field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.A2UIProvenanceStepRecordType("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeUnspecified` | A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeApp` | A2UI_PROVENANCE_RECORD_TYPE_APP | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeUser` | A2UI_PROVENANCE_RECORD_TYPE_USER | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrant` | A2UI_PROVENANCE_RECORD_TYPE_GRANT | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppEntitlement` | A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppUser` | A2UI_PROVENANCE_RECORD_TYPE_APP_USER | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppResource` | A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppResourceType` | A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeTask` | A2UI_PROVENANCE_RECORD_TYPE_TASK | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypePolicy` | A2UI_PROVENANCE_RECORD_TYPE_POLICY | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeConnector` | A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReview` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReviewTemplate` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReviewSelection` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeConflictMonitor` | A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessViolation` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeRequestCatalog` | A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeWebhook` | A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeDirectory` | A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeProfileType` | A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeRoleBinding` | A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomationExecution` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomationExecutionStep` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeFinding` | A2UI_PROVENANCE_RECORD_TYPE_FINDING | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeMetric` | A2UI_PROVENANCE_RECORD_TYPE_METRIC | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomation` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrantHistory` | A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrantReason` | A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON | +| `A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppOwner` | A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uiprovenancetoolcall.md b/docs/pkg/models/shared/a2uiprovenancetoolcall.md new file mode 100644 index 000000000..3c18e5762 --- /dev/null +++ b/docs/pkg/models/shared/a2uiprovenancetoolcall.md @@ -0,0 +1,12 @@ +# A2UIProvenanceToolCall + +A2UIProvenanceToolCall is one tool call extracted from the transcript. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | +| `CalledAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `InputDigest` | `*string` | :heavy_minus_sign: | Leading characters of the tool input, whitespace-collapsed. | +| `ToolName` | `*string` | :heavy_minus_sign: | The toolName field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md b/docs/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md new file mode 100644 index 000000000..6ef3fe5b2 --- /dev/null +++ b/docs/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.md @@ -0,0 +1,21 @@ +# A2UIServiceGetSurfaceProvenanceResponse + +A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built + from: the steps its program ran, and the sources its components report. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ProgramCommitID` | `*string` | :heavy_minus_sign: | The program's identity: code mode invokes by explicit commit, so the commit
    — not the function — is what a refresh re-executes. | +| `ProgramFunctionID` | `*string` | :heavy_minus_sign: | The program that produced a reporting surface. Flat rather than a nested
    ref: these five fields are read together by one drawer and nothing else,
    and a saved report's ProgramRef is the type worth converging on later.
    All empty for a surface carrying no report components, and for reports
    emitted before the report-program requirement was enabled for the tenant. | +| `ProgramInput` | `*string` | :heavy_minus_sign: | The JSON parameters the program ran with. Empty when the invocation has aged
    out of retention. | +| `ProgramInvocationID` | `*string` | :heavy_minus_sign: | The run that produced this surface. | +| `ProgramSource` | `*string` | :heavy_minus_sign: | The program's source, read from the pinned commit. Empty when the commit has
    aged out of code-mode retention — the report still renders, but what
    produced it is no longer recoverable. | +| `Sources` | [][shared.A2UIProvenanceSource](../../../pkg/models/shared/a2uiprovenancesource.md) | :heavy_minus_sign: | The sources field. | +| `StepObjectsVisible` | `*bool` | :heavy_minus_sign: | Whether the caller may see the ids each step named. False withholds every
    A2UIProvenanceStep.objects on the same boundary that withholds
    program_source: those ids are the program's parameters by another name. | +| `Steps` | [][shared.A2UIProvenanceStep](../../../pkg/models/shared/a2uiprovenancestep.md) | :heavy_minus_sign: | Everything the surface's program did, in the order it does it. | +| `StepsAvailable` | `*bool` | :heavy_minus_sign: | False when neither the pinned program nor the conversation transcript could
    be read, so no record of what was looked at survives. Distinguishes that
    from a record that was read and genuinely contains no steps. | +| ~~`ToolCalls`~~ | [][shared.A2UIProvenanceToolCall](../../../pkg/models/shared/a2uiprovenancetoolcall.md) | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: raw tool names, superseded by steps. Still populated for
    clients on the previous shape. | +| `TranscriptAvailable` | `*bool` | :heavy_minus_sign: | False when the backing session or its transcript steps are gone. | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md b/docs/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md new file mode 100644 index 000000000..7cc0b5de5 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.md @@ -0,0 +1,11 @@ +# AccessReviewActionsServiceGenerateReportRequest + +The AccessReviewActionsServiceGenerateReportRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Format` | [*shared.Format](../../../pkg/models/shared/format.md) | :heavy_minus_sign: | Output format for the report. When unspecified, programmatic public-API
    callers (REST gateway and MCP) get JSON and the in-app UI gets XLSX. JSON
    and CSV return the per-decision certification rows; XLSX returns the full
    multi-sheet Excel workbook. | +| `ReportColumnConfig` | [*shared.AccessReviewReportColumnConfig](../../../pkg/models/shared/accessreviewreportcolumnconfig.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md b/docs/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md new file mode 100644 index 000000000..5bfd3978f --- /dev/null +++ b/docs/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.md @@ -0,0 +1,9 @@ +# AccessReviewActionsServiceGenerateReportResponse + +The AccessReviewActionsServiceGenerateReportResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewcolumnconfig.md b/docs/pkg/models/shared/accessreviewcolumnconfig.md index 94b0aab5a..fef93cd98 100644 --- a/docs/pkg/models/shared/accessreviewcolumnconfig.md +++ b/docs/pkg/models/shared/accessreviewcolumnconfig.md @@ -5,6 +5,7 @@ Configuration for which columns are visible in the reviewer task list. ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | -| `Columns` | [][shared.Columns](../../../pkg/models/shared/columns.md) | :heavy_minus_sign: | Ordered list of columns visible to reviewers.
    If empty, the default column set for the campaign's default_view is used. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| ~~`Columns`~~ | [][shared.Columns](../../../pkg/models/shared/columns.md) | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: use `ordered_columns`, which can also include app user
    attribute columns. | +| `OrderedColumns` | [][shared.AccessReviewTaskColumnRef](../../../pkg/models/shared/accessreviewtaskcolumnref.md) | :heavy_minus_sign: | Ordered columns visible to reviewers, built-ins and attributes
    interleaved. Falls back to `columns`, then to the default set for the
    campaign's default_view. | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreport.md b/docs/pkg/models/shared/accessreviewreport.md new file mode 100644 index 000000000..7d793b103 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreport.md @@ -0,0 +1,16 @@ +# AccessReviewReport + +The AccessReviewReport message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `AccessReviewID` | `*string` | :heavy_minus_sign: | The accessReviewId field. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DownloadURL` | `*string` | :heavy_minus_sign: | The downloadUrl field. | +| `Format` | [*shared.AccessReviewReportFormat](../../../pkg/models/shared/accessreviewreportformat.md) | :heavy_minus_sign: | Output format of the generated file (XLSX / JSON / CSV). | +| `Hashes` | map[string]`string` | :heavy_minus_sign: | The hashes field. | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `State` | [*shared.AccessReviewReportState](../../../pkg/models/shared/accessreviewreportstate.md) | :heavy_minus_sign: | The state field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreportcolumnconfig.md b/docs/pkg/models/shared/accessreviewreportcolumnconfig.md new file mode 100644 index 000000000..47bda06b4 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreportcolumnconfig.md @@ -0,0 +1,10 @@ +# AccessReviewReportColumnConfig + +Configuration for columns in the generated access review Excel report. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Columns` | [][shared.AccessReviewReportColumnConfigColumns](../../../pkg/models/shared/accessreviewreportcolumnconfigcolumns.md) | :heavy_minus_sign: | Ordered list of columns to include in the report's "Access Reviews" sheet.
    When non-empty, the report renders exactly these columns in the order given.
    When empty, the default column set is used (the original 19 columns without
    Employee ID or other user-attribute extras). | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreportcolumnconfigcolumns.md b/docs/pkg/models/shared/accessreviewreportcolumnconfigcolumns.md new file mode 100644 index 000000000..99b708903 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreportcolumnconfigcolumns.md @@ -0,0 +1,50 @@ +# AccessReviewReportColumnConfigColumns + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AccessReviewReportColumnConfigColumnsAccessReviewReportColumnUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AccessReviewReportColumnConfigColumns("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnUnspecified` | ACCESS_REVIEW_REPORT_COLUMN_UNSPECIFIED | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmployeeID` | ACCESS_REVIEW_REPORT_COLUMN_EMPLOYEE_ID | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnJobTitle` | ACCESS_REVIEW_REPORT_COLUMN_JOB_TITLE | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDepartment` | ACCESS_REVIEW_REPORT_COLUMN_DEPARTMENT | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmploymentStatus` | ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_STATUS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmploymentType` | ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_TYPE | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnManager` | ACCESS_REVIEW_REPORT_COLUMN_MANAGER | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnTask` | ACCESS_REVIEW_REPORT_COLUMN_TASK | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccount` | ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnUserName` | ACCESS_REVIEW_REPORT_COLUMN_USER_NAME | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnIdentityType` | ACCESS_REVIEW_REPORT_COLUMN_IDENTITY_TYPE | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccountOwner` | ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccountOwnerEmail` | ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER_EMAIL | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnApplication` | ACCESS_REVIEW_REPORT_COLUMN_APPLICATION | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResource` | ACCESS_REVIEW_REPORT_COLUMN_RESOURCE | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResourceType` | ACCESS_REVIEW_REPORT_COLUMN_RESOURCE_TYPE | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEntitlement` | ACCESS_REVIEW_REPORT_COLUMN_ENTITLEMENT | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDescription` | ACCESS_REVIEW_REPORT_COLUMN_DESCRIPTION | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnCertificationPolicy` | ACCESS_REVIEW_REPORT_COLUMN_CERTIFICATION_POLICY | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAssignedTo` | ACCESS_REVIEW_REPORT_COLUMN_ASSIGNED_TO | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnReassignments` | ACCESS_REVIEW_REPORT_COLUMN_REASSIGNMENTS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnCertifiers` | ACCESS_REVIEW_REPORT_COLUMN_CERTIFIERS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDecisions` | ACCESS_REVIEW_REPORT_COLUMN_DECISIONS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResolvedOn` | ACCESS_REVIEW_REPORT_COLUMN_RESOLVED_ON | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnComments` | ACCESS_REVIEW_REPORT_COLUMN_COMMENTS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnLastLogin` | ACCESS_REVIEW_REPORT_COLUMN_LAST_LOGIN | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnSubmissions` | ACCESS_REVIEW_REPORT_COLUMN_SUBMISSIONS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnExternalTicket` | ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnExternalTicketStatus` | ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET_STATUS | +| `AccessReviewReportColumnConfigColumnsAccessReviewReportColumnSubjectUsername` | ACCESS_REVIEW_REPORT_COLUMN_SUBJECT_USERNAME | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreportformat.md b/docs/pkg/models/shared/accessreviewreportformat.md new file mode 100644 index 000000000..9fc6a61ce --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreportformat.md @@ -0,0 +1,26 @@ +# AccessReviewReportFormat + +Output format of the generated file (XLSX / JSON / CSV). + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AccessReviewReportFormatAccessReviewReportFormatUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AccessReviewReportFormat("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------- | ------------------------------------------------------------- | +| `AccessReviewReportFormatAccessReviewReportFormatUnspecified` | ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED | +| `AccessReviewReportFormatAccessReviewReportFormatXlsx` | ACCESS_REVIEW_REPORT_FORMAT_XLSX | +| `AccessReviewReportFormatAccessReviewReportFormatJSON` | ACCESS_REVIEW_REPORT_FORMAT_JSON | +| `AccessReviewReportFormatAccessReviewReportFormatCsv` | ACCESS_REVIEW_REPORT_FORMAT_CSV | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreportservicelistresponse.md b/docs/pkg/models/shared/accessreviewreportservicelistresponse.md new file mode 100644 index 000000000..bd2a60af2 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreportservicelistresponse.md @@ -0,0 +1,11 @@ +# AccessReviewReportServiceListResponse + +The AccessReviewReportServiceListResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | +| `List` | [][shared.AccessReviewReport](../../../pkg/models/shared/accessreviewreport.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewreportstate.md b/docs/pkg/models/shared/accessreviewreportstate.md new file mode 100644 index 000000000..562230f8d --- /dev/null +++ b/docs/pkg/models/shared/accessreviewreportstate.md @@ -0,0 +1,26 @@ +# AccessReviewReportState + +The state field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AccessReviewReportStateReportStateUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AccessReviewReportState("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------- | ----------------------------------------------- | +| `AccessReviewReportStateReportStateUnspecified` | REPORT_STATE_UNSPECIFIED | +| `AccessReviewReportStateReportStatePending` | REPORT_STATE_PENDING | +| `AccessReviewReportStateReportStateOk` | REPORT_STATE_OK | +| `AccessReviewReportStateReportStateError` | REPORT_STATE_ERROR | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewtaskcolumnref.md b/docs/pkg/models/shared/accessreviewtaskcolumnref.md new file mode 100644 index 000000000..f81a006b1 --- /dev/null +++ b/docs/pkg/models/shared/accessreviewtaskcolumnref.md @@ -0,0 +1,19 @@ +# AccessReviewTaskColumnRef + +One column in the reviewer task list: a built-in column, or an app user + profile attribute. An attribute only renders for apps whose + reviewer_attribute_config permits it — that config is the authorization, + this is the view preference. + +This message contains a oneof named column. Only a single field of the following list may be set at a time: + - builtin + - appUserAttributeKey + + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AppUserAttributeKey` | `*string` | :heavy_minus_sign: | The appUserAttributeKey field.
    This field is part of the `column` oneof.
    See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. | +| `Builtin` | [*shared.Builtin](../../../pkg/models/shared/builtin.md) | :heavy_minus_sign: | The builtin field.
    This field is part of the `column` oneof.
    See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. | \ No newline at end of file diff --git a/docs/pkg/models/shared/accessreviewtemplate.md b/docs/pkg/models/shared/accessreviewtemplate.md index 0f5bd5fe8..611f745ea 100644 --- a/docs/pkg/models/shared/accessreviewtemplate.md +++ b/docs/pkg/models/shared/accessreviewtemplate.md @@ -5,6 +5,7 @@ A reusable template that defines the configuration for creating access review ca This message contains a oneof named slack_channel_details. Only a single field of the following list may be set at a time: - slackChannel + - msTeamsChannel @@ -29,6 +30,7 @@ This message contains a oneof named slack_channel_details. Only a single field o | `ID` | `*string` | :heavy_minus_sign: | The unique identifier of this template. | | `InclusionScope` | [*shared.AccessReviewInclusionScope](../../../pkg/models/shared/accessreviewinclusionscope.md) | :heavy_minus_sign: | N/A | | `IsCampaignScheduleEnabled` | `*bool` | :heavy_minus_sign: | Whether automatic campaign creation on the recurrence schedule is enabled. | +| `MsTeamsChannel` | [*shared.MSTeamsChannel](../../../pkg/models/shared/msteamschannel.md) | :heavy_minus_sign: | N/A | | `NextScheduledCampaignAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | | `NotificationConfig` | [*shared.NotificationConfig](../../../pkg/models/shared/notificationconfig.md) | :heavy_minus_sign: | N/A | | `Occurrences` | `*int` | :heavy_minus_sign: | The number of campaigns that have been created from this template. | diff --git a/docs/pkg/models/shared/accessreviewtemplateinput.md b/docs/pkg/models/shared/accessreviewtemplateinput.md index f31d24055..0781fd9d7 100644 --- a/docs/pkg/models/shared/accessreviewtemplateinput.md +++ b/docs/pkg/models/shared/accessreviewtemplateinput.md @@ -5,6 +5,7 @@ A reusable template that defines the configuration for creating access review ca This message contains a oneof named slack_channel_details. Only a single field of the following list may be set at a time: - slackChannel + - msTeamsChannel @@ -27,6 +28,7 @@ This message contains a oneof named slack_channel_details. Only a single field o | `ID` | `*string` | :heavy_minus_sign: | The unique identifier of this template. | | `InclusionScope` | [*shared.AccessReviewInclusionScope](../../../pkg/models/shared/accessreviewinclusionscope.md) | :heavy_minus_sign: | N/A | | `IsCampaignScheduleEnabled` | `*bool` | :heavy_minus_sign: | Whether automatic campaign creation on the recurrence schedule is enabled. | +| `MsTeamsChannel` | [*shared.MSTeamsChannel](../../../pkg/models/shared/msteamschannel.md) | :heavy_minus_sign: | N/A | | `NextScheduledCampaignAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | | `NotificationConfig` | [*shared.NotificationConfig](../../../pkg/models/shared/notificationconfig.md) | :heavy_minus_sign: | N/A | | `Occurrences` | `*int` | :heavy_minus_sign: | The number of campaigns that have been created from this template. | diff --git a/docs/pkg/models/shared/accountstatuses.md b/docs/pkg/models/shared/accountstatuses.md new file mode 100644 index 000000000..2b8d48bc6 --- /dev/null +++ b/docs/pkg/models/shared/accountstatuses.md @@ -0,0 +1,24 @@ +# AccountStatuses + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AccountStatusesStatusUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AccountStatuses("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------- | ---------------------------------- | +| `AccountStatusesStatusUnspecified` | STATUS_UNSPECIFIED | +| `AccountStatusesStatusEnabled` | STATUS_ENABLED | +| `AccountStatusesStatusDisabled` | STATUS_DISABLED | +| `AccountStatusesStatusDeleted` | STATUS_DELETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/actions.md b/docs/pkg/models/shared/actions.md index 9e0ab49e3..e0146b4e4 100644 --- a/docs/pkg/models/shared/actions.md +++ b/docs/pkg/models/shared/actions.md @@ -44,4 +44,5 @@ custom := shared.Actions("custom_value") | `ActionsTaskActionTypeSkipStep` | TASK_ACTION_TYPE_SKIP_STEP | | `ActionsTaskActionTypeRollbackCancelled` | TASK_ACTION_TYPE_ROLLBACK_CANCELLED | | `ActionsTaskActionTypeUpdateRequestData` | TASK_ACTION_TYPE_UPDATE_REQUEST_DATA | -| `ActionsTaskActionTypeUpdateGrantDuration` | TASK_ACTION_TYPE_UPDATE_GRANT_DURATION | \ No newline at end of file +| `ActionsTaskActionTypeUpdateGrantDuration` | TASK_ACTION_TYPE_UPDATE_GRANT_DURATION | +| `ActionsTaskActionTypeRetryProvisioning` | TASK_ACTION_TYPE_RETRY_PROVISIONING | \ No newline at end of file diff --git a/docs/pkg/models/shared/actiontype.md b/docs/pkg/models/shared/actiontype.md index 17e7a5834..866a5724c 100644 --- a/docs/pkg/models/shared/actiontype.md +++ b/docs/pkg/models/shared/actiontype.md @@ -46,4 +46,5 @@ custom := shared.ActionType("custom_value") | `ActionTypeTaskActionTypeSkipStep` | TASK_ACTION_TYPE_SKIP_STEP | | `ActionTypeTaskActionTypeRollbackCancelled` | TASK_ACTION_TYPE_ROLLBACK_CANCELLED | | `ActionTypeTaskActionTypeUpdateRequestData` | TASK_ACTION_TYPE_UPDATE_REQUEST_DATA | -| `ActionTypeTaskActionTypeUpdateGrantDuration` | TASK_ACTION_TYPE_UPDATE_GRANT_DURATION | \ No newline at end of file +| `ActionTypeTaskActionTypeUpdateGrantDuration` | TASK_ACTION_TYPE_UPDATE_GRANT_DURATION | +| `ActionTypeTaskActionTypeRetryProvisioning` | TASK_ACTION_TYPE_RETRY_PROVISIONING | \ No newline at end of file diff --git a/docs/pkg/models/shared/agentstatus.md b/docs/pkg/models/shared/agentstatus.md new file mode 100644 index 000000000..cc7d2f28c --- /dev/null +++ b/docs/pkg/models/shared/agentstatus.md @@ -0,0 +1,28 @@ +# AgentStatus + +AI-agent lifecycle status when this app user carries the agent trait. + UNSPECIFIED marks a non-agent account. Read-only; translated from the + model's agent_trait at the API boundary. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AgentStatusAppUserAgentStatusUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AgentStatus("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------ | ------------------------------------------ | +| `AgentStatusAppUserAgentStatusUnspecified` | APP_USER_AGENT_STATUS_UNSPECIFIED | +| `AgentStatusAppUserAgentStatusReady` | APP_USER_AGENT_STATUS_READY | +| `AgentStatusAppUserAgentStatusDisabled` | APP_USER_AGENT_STATUS_DISABLED | +| `AgentStatusAppUserAgentStatusDeleted` | APP_USER_AGENT_STATUS_DELETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/agentstatuses.md b/docs/pkg/models/shared/agentstatuses.md index 6b8b7395e..1d3231a28 100644 --- a/docs/pkg/models/shared/agentstatuses.md +++ b/docs/pkg/models/shared/agentstatuses.md @@ -7,7 +7,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.AgentStatusesAgentStatusUnspecified +value := shared.AgentStatusesAppUserAgentStatusUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.AgentStatuses("custom_value") @@ -16,9 +16,9 @@ custom := shared.AgentStatuses("custom_value") ## Values -| Name | Value | -| ------------------------------------- | ------------------------------------- | -| `AgentStatusesAgentStatusUnspecified` | AGENT_STATUS_UNSPECIFIED | -| `AgentStatusesAgentStatusReady` | AGENT_STATUS_READY | -| `AgentStatusesAgentStatusDisabled` | AGENT_STATUS_DISABLED | -| `AgentStatusesAgentStatusDeleted` | AGENT_STATUS_DELETED | \ No newline at end of file +| Name | Value | +| -------------------------------------------- | -------------------------------------------- | +| `AgentStatusesAppUserAgentStatusUnspecified` | APP_USER_AGENT_STATUS_UNSPECIFIED | +| `AgentStatusesAppUserAgentStatusReady` | APP_USER_AGENT_STATUS_READY | +| `AgentStatusesAppUserAgentStatusDisabled` | APP_USER_AGENT_STATUS_DISABLED | +| `AgentStatusesAppUserAgentStatusDeleted` | APP_USER_AGENT_STATUS_DELETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/aigovernancesettings.md b/docs/pkg/models/shared/aigovernancesettings.md index 900013052..78157687f 100644 --- a/docs/pkg/models/shared/aigovernancesettings.md +++ b/docs/pkg/models/shared/aigovernancesettings.md @@ -23,4 +23,5 @@ AIGovernanceSettings holds the tenant-wide AI governance policy that controls | `PreferCodeModeOverDirectTools` | `*bool` | :heavy_minus_sign: | When true, the MCP server hides direct tool listings from capable clients
    whenever the code-mode entrypoints (describe + execute) are registered, so
    agents discover and invoke MCP tools through TypeScript code mode instead
    of direct tool calls. A small allowlist of high-traffic direct tools
    remains exposed. Incapable clients (e.g. SERVICE, EPHEMERAL) see the
    normal tool set regardless. Defaults to false. | | `RequireToolApproval` | `*bool` | :heavy_minus_sign: | When true, newly discovered tools start in a pending state and must be
    approved by an admin before they can be granted or invoked. | | `SurfaceRequestableTools` | `*bool` | :heavy_minus_sign: | When true, MCP discovery surfaces tools the caller could request (no
    active grant, but reachable through a request catalog) alongside granted
    tools — both on the classic tools/list path and inside the code-mode
    describe entrypoint. Invoking such a tool opens (or reuses) an
    access-request ticket and returns a request_created envelope instead of
    executing. Defaults to true. | +| `UntrustedJudgeDisable` | `*bool` | :heavy_minus_sign: | When true, the A2 (untrusted-content) judge is skipped and the untrusted
    dimension always scores LOW. When false (the default), the judge scores
    agent turn input and tool output for prompt-injection risk on every turn.

    Defaults to false, so the judge runs by default. | | `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/app.md b/docs/pkg/models/shared/app.md index 4d2b3ce80..2f4abd70f 100644 --- a/docs/pkg/models/shared/app.md +++ b/docs/pkg/models/shared/app.md @@ -30,6 +30,7 @@ The App object provides all of the details for an app, as well as some configura | `IsDirectory` | `*bool` | :heavy_minus_sign: | Specifies if the app is a directory. | | `IsManuallyManaged` | `*bool` | :heavy_minus_sign: | The isManuallyManaged field. | | `LogoURI` | `*string` | :heavy_minus_sign: | The URL of a logo to display for the app. | +| `MatchBatonRef` | [*shared.AppMatchBatonRef](../../../pkg/models/shared/appmatchbatonref.md) | :heavy_minus_sign: | N/A | | `MonthlyCostUsd` | `*int` | :heavy_minus_sign: | The cost of an app per-seat, so that total cost can be calculated by the grant count. | | `ParentAppID` | `*string` | :heavy_minus_sign: | The ID of the app that created this app, if any. | | `RevokeGrantSources` | `*bool` | :heavy_minus_sign: | When enabled, revoking a grant also revokes the grants that source it. | diff --git a/docs/pkg/models/shared/appcap.md b/docs/pkg/models/shared/appcap.md new file mode 100644 index 000000000..9a9b3eb35 --- /dev/null +++ b/docs/pkg/models/shared/appcap.md @@ -0,0 +1,14 @@ +# AppCap + +AppCap is one app's tenant-wide ceiling as the API renders it. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | The C1 App the spend is attributed to. | +| `Controls` | [*shared.SpendControls](../../../pkg/models/shared/spendcontrols.md) | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcaphistoryentry.md b/docs/pkg/models/shared/appcaphistoryentry.md new file mode 100644 index 000000000..38ddaf03b --- /dev/null +++ b/docs/pkg/models/shared/appcaphistoryentry.md @@ -0,0 +1,11 @@ +# AppCapHistoryEntry + +The AppCapHistoryEntry message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicedeleterequest.md b/docs/pkg/models/shared/appcapservicedeleterequest.md new file mode 100644 index 000000000..02dbf0546 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicedeleterequest.md @@ -0,0 +1,9 @@ +# AppCapServiceDeleteRequest + +The AppCapServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicedeleteresponse.md b/docs/pkg/models/shared/appcapservicedeleteresponse.md new file mode 100644 index 000000000..230278474 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicedeleteresponse.md @@ -0,0 +1,9 @@ +# AppCapServiceDeleteResponse + +The AppCapServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicegetresponse.md b/docs/pkg/models/shared/appcapservicegetresponse.md new file mode 100644 index 000000000..a4572ca92 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicegetresponse.md @@ -0,0 +1,10 @@ +# AppCapServiceGetResponse + +The AppCapServiceGetResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Cap` | [*shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicelisthistoryresponse.md b/docs/pkg/models/shared/appcapservicelisthistoryresponse.md new file mode 100644 index 000000000..ae2a7ac14 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# AppCapServiceListHistoryResponse + +The AppCapServiceListHistoryResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | +| `List` | [][shared.AppCapHistoryEntry](../../../pkg/models/shared/appcaphistoryentry.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicelistresponse.md b/docs/pkg/models/shared/appcapservicelistresponse.md new file mode 100644 index 000000000..6cb758789 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicelistresponse.md @@ -0,0 +1,11 @@ +# AppCapServiceListResponse + +The AppCapServiceListResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | +| `List` | [][shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicesetlimitrequest.md b/docs/pkg/models/shared/appcapservicesetlimitrequest.md new file mode 100644 index 000000000..2cefeffc8 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicesetlimitrequest.md @@ -0,0 +1,11 @@ +# AppCapServiceSetLimitRequest + +The AppCapServiceSetLimitRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.Period](../../../pkg/models/shared/period.md) | :heavy_minus_sign: | Optional period override. Only valid together with the limit it denominates. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicesetlimitresponse.md b/docs/pkg/models/shared/appcapservicesetlimitresponse.md new file mode 100644 index 000000000..9803e7d83 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicesetlimitresponse.md @@ -0,0 +1,10 @@ +# AppCapServiceSetLimitResponse + +The AppCapServiceSetLimitResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Cap` | [*shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicesuspendrequest.md b/docs/pkg/models/shared/appcapservicesuspendrequest.md new file mode 100644 index 000000000..21bc22848 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicesuspendrequest.md @@ -0,0 +1,10 @@ +# AppCapServiceSuspendRequest + +The AppCapServiceSuspendRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapservicesuspendresponse.md b/docs/pkg/models/shared/appcapservicesuspendresponse.md new file mode 100644 index 000000000..b8234f329 --- /dev/null +++ b/docs/pkg/models/shared/appcapservicesuspendresponse.md @@ -0,0 +1,10 @@ +# AppCapServiceSuspendResponse + +The AppCapServiceSuspendResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Cap` | [*shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapserviceunsuspendrequest.md b/docs/pkg/models/shared/appcapserviceunsuspendrequest.md new file mode 100644 index 000000000..4ceaf22c1 --- /dev/null +++ b/docs/pkg/models/shared/appcapserviceunsuspendrequest.md @@ -0,0 +1,9 @@ +# AppCapServiceUnsuspendRequest + +The AppCapServiceUnsuspendRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/appcapserviceunsuspendresponse.md b/docs/pkg/models/shared/appcapserviceunsuspendresponse.md new file mode 100644 index 000000000..57fec8fac --- /dev/null +++ b/docs/pkg/models/shared/appcapserviceunsuspendresponse.md @@ -0,0 +1,10 @@ +# AppCapServiceUnsuspendResponse + +The AppCapServiceUnsuspendResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Cap` | [*shared.AppCap](../../../pkg/models/shared/appcap.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md b/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md new file mode 100644 index 000000000..1c590323a --- /dev/null +++ b/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md @@ -0,0 +1,14 @@ +# AppEntitlementSearchServiceSearchReachableResourcesForUserRequest + +SearchReachableResourcesForUser request. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | +| `AppIds` | []`string` | :heavy_minus_sign: | Restrict results to resources belonging to these applications. Empty
    searches across every application the user can reach. | +| `PageSize` | `*int` | :heavy_minus_sign: | Maximum number of results to return per page. | +| `PageToken` | `*string` | :heavy_minus_sign: | Token for fetching the next page of results. | +| `Query` | `*string` | :heavy_minus_sign: | Fuzzy search over the resource display name. | +| `UserID` | `*string` | :heavy_minus_sign: | The user whose reachable resources to search. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md b/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md new file mode 100644 index 000000000..724c8183a --- /dev/null +++ b/docs/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.md @@ -0,0 +1,12 @@ +# AppEntitlementSearchServiceSearchReachableResourcesForUserResponse + +SearchReachableResourcesForUser response. Resources are deduplicated: a + resource reachable through more than one grant or entitlement appears once. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `List` | [][shared.GraphNode](../../../pkg/models/shared/graphnode.md) | :heavy_minus_sign: | The reachable resources, one GraphNode (type = GRAPH_NODE_TYPE_RESOURCE)
    per distinct resource. Uses the same node representation as SearchGraph. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token for fetching the next page of results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appentitlementuserbindinghistory.md b/docs/pkg/models/shared/appentitlementuserbindinghistory.md index 01456325f..0817597b5 100644 --- a/docs/pkg/models/shared/appentitlementuserbindinghistory.md +++ b/docs/pkg/models/shared/appentitlementuserbindinghistory.md @@ -11,4 +11,5 @@ The AppEntitlementUserBindingHistory message. | `AppID` | `*string` | :heavy_minus_sign: | The ID of the app associated with the app entitlement | | `AppUserID` | `*string` | :heavy_minus_sign: | The ID of the app user that has access to the app entitlement | | `GrantedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `ID` | `*string` | :heavy_minus_sign: | The unique ID of this grant history record | | `RevokedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appinput.md b/docs/pkg/models/shared/appinput.md index 7225d9aa5..d882a2b02 100644 --- a/docs/pkg/models/shared/appinput.md +++ b/docs/pkg/models/shared/appinput.md @@ -21,6 +21,7 @@ The App object provides all of the details for an app, as well as some configura | `IdentityMatching` | [*shared.IdentityMatching](../../../pkg/models/shared/identitymatching.md) | :heavy_minus_sign: | The identityMatching field. | | `Instructions` | `*string` | :heavy_minus_sign: | If you add instructions here, they will be shown to users in the access request form when requesting access for this app. | | `IsManuallyManaged` | `*bool` | :heavy_minus_sign: | The isManuallyManaged field. | +| `MatchBatonRef` | [*shared.AppMatchBatonRef](../../../pkg/models/shared/appmatchbatonref.md) | :heavy_minus_sign: | N/A | | `MonthlyCostUsd` | `*int` | :heavy_minus_sign: | The cost of an app per-seat, so that total cost can be calculated by the grant count. | | `RevokeGrantSources` | `*bool` | :heavy_minus_sign: | When enabled, revoking a grant also revokes the grants that source it. | | `RevokePolicyID` | `*string` | :heavy_minus_sign: | The ID of the Revoke Policy associated with this App. | diff --git a/docs/pkg/models/shared/appmanagedstate.md b/docs/pkg/models/shared/appmanagedstate.md new file mode 100644 index 000000000..8f024057d --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstate.md @@ -0,0 +1,16 @@ +# AppManagedState + +AppManagedState identifies whether a discovered application is managed. + +This message contains a oneof named state. Only a single field of the following list may be set at a time: + - unmanaged + - managed + + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `Managed` | [*shared.AppManagedStateManaged](../../../pkg/models/shared/appmanagedstatemanaged.md) | :heavy_minus_sign: | N/A | +| `Unmanaged` | [*shared.AppManagedStateUnmanaged](../../../pkg/models/shared/appmanagedstateunmanaged.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstatebinding.md b/docs/pkg/models/shared/appmanagedstatebinding.md new file mode 100644 index 000000000..7c300096d --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstatebinding.md @@ -0,0 +1,17 @@ +# AppManagedStateBinding + +AppManagedStateBinding records whether a connector-discovered application is managed in ConductorOne. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | Application that owns the connector which discovered this application. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | Display name of the discovered application. | +| `ResourceID` | `*string` | :heavy_minus_sign: | Resource ID of the discovered application. | +| `ResourceTypeID` | `*string` | :heavy_minus_sign: | Resource type used by the connector to represent discovered applications. | +| `State` | [*shared.AppManagedState](../../../pkg/models/shared/appmanagedstate.md) | :heavy_minus_sign: | N/A | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstatebindingexpandmask.md b/docs/pkg/models/shared/appmanagedstatebindingexpandmask.md new file mode 100644 index 000000000..ffc2b71f8 --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstatebindingexpandmask.md @@ -0,0 +1,10 @@ +# AppManagedStateBindingExpandMask + +AppManagedStateBindingExpandMask controls which related objects are included in a response. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Paths` | []`string` | :heavy_minus_sign: | Related objects to include. Supported values are `app_id`, `resource_id`, and `*`. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstatebindingref.md b/docs/pkg/models/shared/appmanagedstatebindingref.md index 8f78f8f62..72ee1cbd0 100644 --- a/docs/pkg/models/shared/appmanagedstatebindingref.md +++ b/docs/pkg/models/shared/appmanagedstatebindingref.md @@ -1,12 +1,12 @@ # AppManagedStateBindingRef -The AppManagedStateBindingRef message. +AppManagedStateBindingRef identifies an application discovered by a connector. ## Fields -| Field | Type | Required | Description | -| ------------------------- | ------------------------- | ------------------------- | ------------------------- | -| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | -| `ResourceID` | `*string` | :heavy_minus_sign: | The resourceId field. | -| `ResourceTypeID` | `*string` | :heavy_minus_sign: | The resourceTypeId field. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | ID of the application that owns the connector. | +| `ResourceID` | `*string` | :heavy_minus_sign: | Resource ID of the discovered application. | +| `ResourceTypeID` | `*string` | :heavy_minus_sign: | ID of the resource type used for discovered applications. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstatebindingview.md b/docs/pkg/models/shared/appmanagedstatebindingview.md new file mode 100644 index 000000000..3162a26d3 --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstatebindingview.md @@ -0,0 +1,12 @@ +# AppManagedStateBindingView + +AppManagedStateBindingView contains a managed-state binding and paths to its related objects. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | +| `AppManagementStateBinding` | [*shared.AppManagedStateBinding](../../../pkg/models/shared/appmanagedstatebinding.md) | :heavy_minus_sign: | N/A | +| `AppPath` | `*string` | :heavy_minus_sign: | Path of the application that owns the connector. | +| `ResourcePath` | `*string` | :heavy_minus_sign: | Path of the connector resource representing the discovered application. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstatemanaged.md b/docs/pkg/models/shared/appmanagedstatemanaged.md new file mode 100644 index 000000000..ed1352531 --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstatemanaged.md @@ -0,0 +1,10 @@ +# AppManagedStateManaged + +AppManagedStateManaged identifies the application created by promotion. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------ | ------------------------------ | ------------------------------ | ------------------------------ | +| `AppID` | `*string` | :heavy_minus_sign: | ID of the managed application. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmanagedstateunmanaged.md b/docs/pkg/models/shared/appmanagedstateunmanaged.md new file mode 100644 index 000000000..b040f9ecc --- /dev/null +++ b/docs/pkg/models/shared/appmanagedstateunmanaged.md @@ -0,0 +1,9 @@ +# AppManagedStateUnmanaged + +AppManagedStateUnmanaged indicates that the discovered application has not been promoted. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/appmatchbatonref.md b/docs/pkg/models/shared/appmatchbatonref.md new file mode 100644 index 000000000..b4ae3f245 --- /dev/null +++ b/docs/pkg/models/shared/appmatchbatonref.md @@ -0,0 +1,12 @@ +# AppMatchBatonRef + +AppMatchBatonRef identifies the connector application that should adopt a manually-created application during uplift. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `AppID` | `string` | :heavy_check_mark: | Application that owns the connector. | +| `ConnectorID` | `string` | :heavy_check_mark: | Connector that discovers the application. | +| `ExternalID` | `string` | :heavy_check_mark: | Canonical connector-v2 application resource ID in
    `::` form (for example, `app::0oa123`). | \ No newline at end of file diff --git a/docs/pkg/models/shared/appuser.md b/docs/pkg/models/shared/appuser.md index 6adf001e5..b6e17e372 100644 --- a/docs/pkg/models/shared/appuser.md +++ b/docs/pkg/models/shared/appuser.md @@ -5,21 +5,24 @@ Application User that represents an account in the application. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -| `AppID` | `*string` | :heavy_minus_sign: | The ID of the application. | -| `AppUserType` | [*shared.AppUserType](../../../pkg/models/shared/appusertype.md) | :heavy_minus_sign: | The appplication user type. Type can be user, system or service. | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the application user. | -| `Email` | `*string` | :heavy_minus_sign: | The email field of the application user. | -| `Emails` | []`string` | :heavy_minus_sign: | The emails field of the application user. | -| `EmployeeIds` | []`string` | :heavy_minus_sign: | The employee IDs field of the application user. | -| `ID` | `*string` | :heavy_minus_sign: | A unique idenditfier of the application user. | -| `IdentityUserID` | `*string` | :heavy_minus_sign: | The conductor one user ID of the account owner. | -| `IsExternal` | `*bool` | :heavy_minus_sign: | The isExternal field. | -| `Profile` | map[string]`any` | :heavy_minus_sign: | N/A | -| `Status` | [*shared.AppUserStatus](../../../pkg/models/shared/appuserstatus.md) | :heavy_minus_sign: | N/A | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Username` | `*string` | :heavy_minus_sign: | The username field of the application user. | -| `Usernames` | []`string` | :heavy_minus_sign: | The usernames field of the application user. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AgentStatus` | [*shared.AgentStatus](../../../pkg/models/shared/agentstatus.md) | :heavy_minus_sign: | AI-agent lifecycle status when this app user carries the agent trait.
    UNSPECIFIED marks a non-agent account. Read-only; translated from the
    model's agent_trait at the API boundary. | +| `AppID` | `*string` | :heavy_minus_sign: | The ID of the application. | +| `AppUserType` | [*shared.AppUserType](../../../pkg/models/shared/appusertype.md) | :heavy_minus_sign: | The appplication user type. Type can be user, system or service. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the application user. | +| `Email` | `*string` | :heavy_minus_sign: | The email field of the application user. | +| `Emails` | []`string` | :heavy_minus_sign: | The emails field of the application user. | +| `EmployeeIds` | []`string` | :heavy_minus_sign: | The employee IDs field of the application user. | +| `ID` | `*string` | :heavy_minus_sign: | A unique idenditfier of the application user. | +| `IdentityUserID` | `*string` | :heavy_minus_sign: | The conductor one user ID of the account owner. | +| `IsExternal` | `*bool` | :heavy_minus_sign: | The isExternal field. | +| `NhiDetail` | `*string` | :heavy_minus_sign: | Axis-2 detail refining nhi_type (e.g. "aws.role.lambda"). Read-only. | +| `NhiType` | [*shared.AppUserNhiType](../../../pkg/models/shared/appusernhitype.md) | :heavy_minus_sign: | NHI classification when this app user carries the non-human-identity trait.
    Read-only; translated from the model's nhi_trait at the API boundary. | +| `Profile` | map[string]`any` | :heavy_minus_sign: | N/A | +| `Status` | [*shared.AppUserStatus](../../../pkg/models/shared/appuserstatus.md) | :heavy_minus_sign: | N/A | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Username` | `*string` | :heavy_minus_sign: | The username field of the application user. | +| `Usernames` | []`string` | :heavy_minus_sign: | The usernames field of the application user. | \ No newline at end of file diff --git a/docs/pkg/models/shared/appusernhitype.md b/docs/pkg/models/shared/appusernhitype.md new file mode 100644 index 000000000..0d86a7b17 --- /dev/null +++ b/docs/pkg/models/shared/appusernhitype.md @@ -0,0 +1,27 @@ +# AppUserNhiType + +NHI classification when this app user carries the non-human-identity trait. + Read-only; translated from the model's nhi_trait at the API boundary. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.AppUserNhiTypeAppUserNhiTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.AppUserNhiType("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------- | --------------------------------------------- | +| `AppUserNhiTypeAppUserNhiTypeUnspecified` | APP_USER_NHI_TYPE_UNSPECIFIED | +| `AppUserNhiTypeAppUserNhiTypeAppRegistration` | APP_USER_NHI_TYPE_APP_REGISTRATION | +| `AppUserNhiTypeAppUserNhiTypeAssumableRole` | APP_USER_NHI_TYPE_ASSUMABLE_ROLE | +| `AppUserNhiTypeAppUserNhiTypeManagedIdentity` | APP_USER_NHI_TYPE_MANAGED_IDENTITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/appuserservicesearchrequest.md b/docs/pkg/models/shared/appuserservicesearchrequest.md index 489c56063..ddbc232dc 100644 --- a/docs/pkg/models/shared/appuserservicesearchrequest.md +++ b/docs/pkg/models/shared/appuserservicesearchrequest.md @@ -7,6 +7,7 @@ Search App users based on filters specified in the request body | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AgentStatuses` | [][shared.AgentStatuses](../../../pkg/models/shared/agentstatuses.md) | :heavy_minus_sign: | Restrict to app users whose agent trait lifecycle status (agent_status)
    matches one of these values. When empty, agent_status is not used as a filter. | | `AppID` | `*string` | :heavy_minus_sign: | The app ID to restrict the search to. | | `AppIds` | []`string` | :heavy_minus_sign: | A list of app IDs to restrict the search to. | | `AppUserDomains` | [][shared.AppUserDomains](../../../pkg/models/shared/appuserdomains.md) | :heavy_minus_sign: | A list of account domains to restrict the search to. | @@ -17,6 +18,7 @@ Search App users based on filters specified in the request body | `ExcludeAppUserIds` | []`string` | :heavy_minus_sign: | A list of app user IDs to remove from the results. | | `ExcludeDeletedApps` | `*bool` | :heavy_minus_sign: | When true, excludes app users belonging to soft-deleted apps. | | `ExpandMask` | [*shared.AppUserExpandMask](../../../pkg/models/shared/appuserexpandmask.md) | :heavy_minus_sign: | N/A | +| `NhiTypes` | [][shared.NhiTypes](../../../pkg/models/shared/nhitypes.md) | :heavy_minus_sign: | Restrict to app users whose NHI trait classification (nhi_type) matches one of
    these values. When empty, nhi_type is not used as a filter. | | `PageSize` | `*int` | :heavy_minus_sign: | The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) | | `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | | `Query` | `*string` | :heavy_minus_sign: | Query the apps with a fuzzy search on display name and description. | diff --git a/docs/pkg/models/shared/blockoutputconfig.md b/docs/pkg/models/shared/blockoutputconfig.md new file mode 100644 index 000000000..d246c4c47 --- /dev/null +++ b/docs/pkg/models/shared/blockoutputconfig.md @@ -0,0 +1,12 @@ +# BlockOutputConfig + +BlockOutputConfig denies the in-flight response chunk when its hook's + filter matches. Only valid for HOOK_EVENT_TYPE_PRE_OUTPUT. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Message` | `*string` | :heavy_minus_sign: | Message shown to the user when this hook blocks the response. Empty
    falls back to the curating AgentGuardrailRule's deny_reason, then to a
    generic default. | +| `Surfaces` | [][shared.Surfaces](../../../pkg/models/shared/surfaces.md) | :heavy_minus_sign: | Output surfaces this hook applies to. Empty means none — the hook is
    inert until at least one surface is explicitly selected. | \ No newline at end of file diff --git a/docs/pkg/models/shared/blocktoolcallconfig.md b/docs/pkg/models/shared/blocktoolcallconfig.md new file mode 100644 index 000000000..7a30a88d9 --- /dev/null +++ b/docs/pkg/models/shared/blocktoolcallconfig.md @@ -0,0 +1,11 @@ +# BlockToolCallConfig + +BlockToolCallConfig unconditionally denies the tool call when its hook's + filter matches. Only valid for HOOK_EVENT_TYPE_POST_TOOL_USE. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | +| `Message` | `*string` | :heavy_minus_sign: | Message shown when the tool call is denied. Empty falls back to a
    generic default. | \ No newline at end of file diff --git a/docs/pkg/models/shared/builtin.md b/docs/pkg/models/shared/builtin.md new file mode 100644 index 000000000..74d38bc0f --- /dev/null +++ b/docs/pkg/models/shared/builtin.md @@ -0,0 +1,55 @@ +# Builtin + +The builtin field. +This field is part of the `column` oneof. +See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.BuiltinAccessReviewTaskColumnUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Builtin("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------- | ----------------------------------------------------- | +| `BuiltinAccessReviewTaskColumnUnspecified` | ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED | +| `BuiltinAccessReviewTaskColumnViewLink` | ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK | +| `BuiltinAccessReviewTaskColumnCurrentState` | ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE | +| `BuiltinAccessReviewTaskColumnAccount` | ACCESS_REVIEW_TASK_COLUMN_ACCOUNT | +| `BuiltinAccessReviewTaskColumnAccountOwner` | ACCESS_REVIEW_TASK_COLUMN_ACCOUNT_OWNER | +| `BuiltinAccessReviewTaskColumnEntitlement` | ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT | +| `BuiltinAccessReviewTaskColumnEntitlementDescription` | ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT_DESCRIPTION | +| `BuiltinAccessReviewTaskColumnResource` | ACCESS_REVIEW_TASK_COLUMN_RESOURCE | +| `BuiltinAccessReviewTaskColumnResourceType` | ACCESS_REVIEW_TASK_COLUMN_RESOURCE_TYPE | +| `BuiltinAccessReviewTaskColumnInsights` | ACCESS_REVIEW_TASK_COLUMN_INSIGHTS | +| `BuiltinAccessReviewTaskColumnRecommendation` | ACCESS_REVIEW_TASK_COLUMN_RECOMMENDATION | +| `BuiltinAccessReviewTaskColumnAssignedTo` | ACCESS_REVIEW_TASK_COLUMN_ASSIGNED_TO | +| `BuiltinAccessReviewTaskColumnStatus` | ACCESS_REVIEW_TASK_COLUMN_STATUS | +| `BuiltinAccessReviewTaskColumnApp` | ACCESS_REVIEW_TASK_COLUMN_APP | +| `BuiltinAccessReviewTaskColumnDue` | ACCESS_REVIEW_TASK_COLUMN_DUE | +| `BuiltinAccessReviewTaskColumnProject` | ACCESS_REVIEW_TASK_COLUMN_PROJECT | +| `BuiltinAccessReviewTaskColumnCreatedOn` | ACCESS_REVIEW_TASK_COLUMN_CREATED_ON | +| `BuiltinAccessReviewTaskColumnTaskAge` | ACCESS_REVIEW_TASK_COLUMN_TASK_AGE | +| `BuiltinAccessReviewTaskColumnResolvedOn` | ACCESS_REVIEW_TASK_COLUMN_RESOLVED_ON | +| `BuiltinAccessReviewTaskColumnEnrollmentStatus` | ACCESS_REVIEW_TASK_COLUMN_ENROLLMENT_STATUS | +| `BuiltinAccessReviewTaskColumnInheritedFrom` | ACCESS_REVIEW_TASK_COLUMN_INHERITED_FROM | +| `BuiltinAccessReviewTaskColumnDepartment` | ACCESS_REVIEW_TASK_COLUMN_DEPARTMENT | +| `BuiltinAccessReviewTaskColumnJobTitle` | ACCESS_REVIEW_TASK_COLUMN_JOB_TITLE | +| `BuiltinAccessReviewTaskColumnCreatedBy` | ACCESS_REVIEW_TASK_COLUMN_CREATED_BY | +| `BuiltinAccessReviewTaskColumnLastLogin` | ACCESS_REVIEW_TASK_COLUMN_LAST_LOGIN | +| `BuiltinAccessReviewTaskColumnResourceParent` | ACCESS_REVIEW_TASK_COLUMN_RESOURCE_PARENT | +| `BuiltinAccessReviewTaskColumnResourceChildren` | ACCESS_REVIEW_TASK_COLUMN_RESOURCE_CHILDREN | +| `BuiltinAccessReviewTaskColumnAppUserUsername` | ACCESS_REVIEW_TASK_COLUMN_APP_USER_USERNAME | +| `BuiltinAccessReviewTaskColumnAccessHolderType` | ACCESS_REVIEW_TASK_COLUMN_ACCESS_HOLDER_TYPE | +| `BuiltinAccessReviewTaskColumnRiskLevel` | ACCESS_REVIEW_TASK_COLUMN_RISK_LEVEL | +| `BuiltinAccessReviewTaskColumnComplianceFramework` | ACCESS_REVIEW_TASK_COLUMN_COMPLIANCE_FRAMEWORK | \ No newline at end of file diff --git a/docs/pkg/models/shared/builtinpattern.md b/docs/pkg/models/shared/builtinpattern.md index dd4ac39ec..0d3ad50c9 100644 --- a/docs/pkg/models/shared/builtinpattern.md +++ b/docs/pkg/models/shared/builtinpattern.md @@ -10,6 +10,13 @@ This message contains a oneof named config. Only a single field of the following - writeAuthorization - sensitiveFileGuard - toolOutputSizeGuard + - secretsMasking + - linkFilter + - encodedContentGuard + - promptInjectionScan + - blockOutput + - blockToolCall + - preToolBlock @@ -17,9 +24,16 @@ This message contains a oneof named config. Only a single field of the following | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | +| `BlockOutput` | [*shared.BlockOutputConfig](../../../pkg/models/shared/blockoutputconfig.md) | :heavy_minus_sign: | N/A | +| `BlockToolCall` | [*shared.BlockToolCallConfig](../../../pkg/models/shared/blocktoolcallconfig.md) | :heavy_minus_sign: | N/A | | `CreditCardBlocking` | [*shared.CreditCardBlockingConfig](../../../pkg/models/shared/creditcardblockingconfig.md) | :heavy_minus_sign: | N/A | +| `EncodedContentGuard` | [*shared.EncodedContentGuardConfig](../../../pkg/models/shared/encodedcontentguardconfig.md) | :heavy_minus_sign: | N/A | +| `LinkFilter` | [*shared.LinkFilterConfig](../../../pkg/models/shared/linkfilterconfig.md) | :heavy_minus_sign: | N/A | | `PiiRedaction` | [*shared.PIIRedactionConfig](../../../pkg/models/shared/piiredactionconfig.md) | :heavy_minus_sign: | N/A | +| `PreToolBlock` | [*shared.PreToolBlockConfig](../../../pkg/models/shared/pretoolblockconfig.md) | :heavy_minus_sign: | N/A | +| `PromptInjectionScan` | [*shared.PromptInjectionScanConfig](../../../pkg/models/shared/promptinjectionscanconfig.md) | :heavy_minus_sign: | N/A | | `QueryScopeLimit` | [*shared.QueryScopeLimitConfig](../../../pkg/models/shared/queryscopelimitconfig.md) | :heavy_minus_sign: | N/A | +| `SecretsMasking` | [*shared.SecretsMaskingConfig](../../../pkg/models/shared/secretsmaskingconfig.md) | :heavy_minus_sign: | N/A | | `SensitiveFileGuard` | [*shared.SensitiveFileGuardConfig](../../../pkg/models/shared/sensitivefileguardconfig.md) | :heavy_minus_sign: | N/A | | `ToolOutputSizeGuard` | [*shared.ToolOutputSizeGuardConfig](../../../pkg/models/shared/tooloutputsizeguardconfig.md) | :heavy_minus_sign: | N/A | | `WriteAuthorization` | [*shared.WriteAuthorizationConfig](../../../pkg/models/shared/writeauthorizationconfig.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/bulkreprocessaction.md b/docs/pkg/models/shared/bulkreprocessaction.md new file mode 100644 index 000000000..d75a25076 --- /dev/null +++ b/docs/pkg/models/shared/bulkreprocessaction.md @@ -0,0 +1,30 @@ +# BulkReprocessAction + +BulkReprocessAction re-evaluates eligible findings against transformation + and routing rules using each finding's original detector-created state + (original severity, original annotations) rather than any rule-mutated + current state. + + `override_human_edits` chooses how far re-derivation goes for + human-attributed edits: + + - Open findings are re-derived and re-routed in both modes. + - Findings parked by a rule (snoozed, suppressed, or risk-accepted by a + routing rule with no subsequent human action) are released to open, + re-derived, and re-routed in both modes. + - Findings parked by a person re-derive their content in both modes, but + the state is only released, and a human severity override only cleared, + when `override_human_edits` is true. + - Findings in progress re-derive their content and keep both their state + and any linked ticket in both modes. + - Resolved, archived, and deleted findings are skipped in both modes. + + Assigned owners and ticket links are never touched; rules do not derive them. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `OverrideHumanEdits` | `*bool` | :heavy_minus_sign: | When false (the default), a person's parked state and severity override
    survive the re-derivation. When true, reprocessing additionally releases
    findings a person parked and clears human severity overrides. | +| `RunDispatchers` | `*bool` | :heavy_minus_sign: | When true, matched rules may re-send notification dispatches for
    findings your team may have already seen. Off by default. | \ No newline at end of file diff --git a/docs/pkg/models/shared/bulkupdatefindingstaterequest.md b/docs/pkg/models/shared/bulkupdatefindingstaterequest.md index 055092465..d6c4e5c72 100644 --- a/docs/pkg/models/shared/bulkupdatefindingstaterequest.md +++ b/docs/pkg/models/shared/bulkupdatefindingstaterequest.md @@ -9,6 +9,7 @@ This message contains a oneof named action. Only a single field of the following - unsuppress - assignOwner - reopen + - reprocess @@ -20,6 +21,7 @@ This message contains a oneof named action. Only a single field of the following | `AssignOwner` | [*shared.BulkAssignOwnerAction](../../../pkg/models/shared/bulkassignowneraction.md) | :heavy_minus_sign: | N/A | | `Refs` | [][shared.FindingRef](../../../pkg/models/shared/findingref.md) | :heavy_minus_sign: | By-ID mode: specify individual finding refs. | | `Reopen` | [*shared.BulkReopenAction](../../../pkg/models/shared/bulkreopenaction.md) | :heavy_minus_sign: | N/A | +| `Reprocess` | [*shared.BulkReprocessAction](../../../pkg/models/shared/bulkreprocessaction.md) | :heavy_minus_sign: | N/A | | `SearchRequest` | [*shared.FindingSearchRequest](../../../pkg/models/shared/findingsearchrequest.md) | :heavy_minus_sign: | N/A | | `Snooze` | [*shared.BulkSnoozeAction](../../../pkg/models/shared/bulksnoozeaction.md) | :heavy_minus_sign: | N/A | | `Suppress` | [*shared.BulkSuppressAction](../../../pkg/models/shared/bulksuppressaction.md) | :heavy_minus_sign: | N/A | diff --git a/docs/pkg/models/shared/c1metriccard.md b/docs/pkg/models/shared/c1metriccard.md new file mode 100644 index 000000000..773b1e616 --- /dev/null +++ b/docs/pkg/models/shared/c1metriccard.md @@ -0,0 +1,15 @@ +# C1MetricCard + +C1MetricCard is one aggregate stat: label, formatted value, optional delta + and sparkline trend. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | +| `Delta` | `*string` | :heavy_minus_sign: | The delta field. | +| `DeltaSentiment` | [*shared.DeltaSentiment](../../../pkg/models/shared/deltasentiment.md) | :heavy_minus_sign: | The deltaSentiment field. | +| `Label` | `*string` | :heavy_minus_sign: | The label field. | +| `Sparkline` | []`float64` | :heavy_minus_sign: | Optional trend values, oldest first. Bounds double as NaN/Inf rejection. | +| `Value` | `*string` | :heavy_minus_sign: | The value field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/c1metriccardscomponent.md b/docs/pkg/models/shared/c1metriccardscomponent.md new file mode 100644 index 000000000..b4679281f --- /dev/null +++ b/docs/pkg/models/shared/c1metriccardscomponent.md @@ -0,0 +1,12 @@ +# C1MetricCardsComponent + +C1MetricCardsComponent renders a row of aggregate stat cards. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------- | --------------------------------------------------------------------- | --------------------------------------------------------------------- | --------------------------------------------------------------------- | +| `Cards` | [][shared.C1MetricCard](../../../pkg/models/shared/c1metriccard.md) | :heavy_minus_sign: | The cards field. | +| `Sources` | [][shared.C1ChartSource](../../../pkg/models/shared/c1chartsource.md) | :heavy_minus_sign: | Provenance: the queries the producing function ran. | +| `Title` | [*shared.DynamicString](../../../pkg/models/shared/dynamicstring.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/c1tablecomponent.md b/docs/pkg/models/shared/c1tablecomponent.md new file mode 100644 index 000000000..3f1281a6a --- /dev/null +++ b/docs/pkg/models/shared/c1tablecomponent.md @@ -0,0 +1,17 @@ +# C1TableComponent + +C1TableComponent renders a tabular view: typed columns + rows, capped and + paginated client-side; the full data set lives behind the artifact link. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | +| `ArtifactURL` | [*shared.DynamicString](../../../pkg/models/shared/dynamicstring.md) | :heavy_minus_sign: | N/A | +| `Columns` | []`string` | :heavy_minus_sign: | The columns field. | +| `PageSize` | `*int` | :heavy_minus_sign: | Rows per page for client-side pagination; 0 shows all rows on one page. | +| `Rows` | [][shared.C1TableRow](../../../pkg/models/shared/c1tablerow.md) | :heavy_minus_sign: | The rows field. | +| `Sources` | [][shared.C1ChartSource](../../../pkg/models/shared/c1chartsource.md) | :heavy_minus_sign: | Provenance: the queries the producing function ran. | +| `Title` | [*shared.DynamicString](../../../pkg/models/shared/dynamicstring.md) | :heavy_minus_sign: | N/A | +| `TotalRows` | `*int64` | :heavy_minus_sign: | Full count when rows are truncated. | \ No newline at end of file diff --git a/docs/pkg/models/shared/c1tablerow.md b/docs/pkg/models/shared/c1tablerow.md new file mode 100644 index 000000000..dbb8301c6 --- /dev/null +++ b/docs/pkg/models/shared/c1tablerow.md @@ -0,0 +1,11 @@ +# C1TableRow + +C1TableRow is one row; cells align 1:1 with columns (enforced at the + parse boundary). + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Cells` | []`string` | :heavy_minus_sign: | The cells field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/c1userfilter.md b/docs/pkg/models/shared/c1userfilter.md index f483b3ddb..842d6f44b 100644 --- a/docs/pkg/models/shared/c1userfilter.md +++ b/docs/pkg/models/shared/c1userfilter.md @@ -6,5 +6,8 @@ C1UserFilter is used to configure a picker for selecting ConductorOne users. ## Fields -| Field | Type | Required | Description | -| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ExcludeUserIds` | []`string` | :heavy_minus_sign: | Remove these users from the selectable set, after user_ids is applied. | +| `IncludeDeactivated` | `*bool` | :heavy_minus_sign: | Make deactivated and deleted users selectable. Defaults to enabled-only. | +| `UserIds` | []`string` | :heavy_minus_sign: | Restrict the selectable set to these users. Empty means every user is selectable.
    Capped at the number of refs SearchUsers accepts in one request. | \ No newline at end of file diff --git a/docs/pkg/models/shared/clearprovidercredentialrequest.md b/docs/pkg/models/shared/clearprovidercredentialrequest.md new file mode 100644 index 000000000..616127869 --- /dev/null +++ b/docs/pkg/models/shared/clearprovidercredentialrequest.md @@ -0,0 +1,9 @@ +# ClearProviderCredentialRequest + +The ClearProviderCredentialRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/clearprovidercredentialresponse.md b/docs/pkg/models/shared/clearprovidercredentialresponse.md new file mode 100644 index 000000000..aa5534e82 --- /dev/null +++ b/docs/pkg/models/shared/clearprovidercredentialresponse.md @@ -0,0 +1,10 @@ +# ClearProviderCredentialResponse + +The ClearProviderCredentialResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | +| `Credential` | [*shared.ProviderCredential](../../../pkg/models/shared/providercredential.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/clientidtype.md b/docs/pkg/models/shared/clientidtype.md index 42d9277b1..b51a21882 100644 --- a/docs/pkg/models/shared/clientidtype.md +++ b/docs/pkg/models/shared/clientidtype.md @@ -22,4 +22,5 @@ custom := shared.ClientIDType("custom_value") | ------------------------------------- | ------------------------------------- | | `ClientIDTypeClientIDTypeUnspecified` | CLIENT_ID_TYPE_UNSPECIFIED | | `ClientIDTypeClientIDTypeDcr` | CLIENT_ID_TYPE_DCR | -| `ClientIDTypeClientIDTypeMetadataURL` | CLIENT_ID_TYPE_METADATA_URL | \ No newline at end of file +| `ClientIDTypeClientIDTypeMetadataURL` | CLIENT_ID_TYPE_METADATA_URL | +| `ClientIDTypeClientIDTypeApp` | CLIENT_ID_TYPE_APP | \ No newline at end of file diff --git a/docs/pkg/models/shared/component.md b/docs/pkg/models/shared/component.md new file mode 100644 index 000000000..d93738511 --- /dev/null +++ b/docs/pkg/models/shared/component.md @@ -0,0 +1,31 @@ +# Component + +Where the finding fits in the parsed document. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ComponentComponentUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Component("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------- | ----------------------------------------- | +| `ComponentComponentUnspecified` | COMPONENT_UNSPECIFIED | +| `ComponentComponentDocument` | COMPONENT_DOCUMENT | +| `ComponentComponentEntityID` | COMPONENT_ENTITY_ID | +| `ComponentComponentAcsURL` | COMPONENT_ACS_URL | +| `ComponentComponentNameIDFormat` | COMPONENT_NAME_ID_FORMAT | +| `ComponentComponentSigningCertificate` | COMPONENT_SIGNING_CERTIFICATE | +| `ComponentComponentEncryptionCertificate` | COMPONENT_ENCRYPTION_CERTIFICATE | +| `ComponentComponentRequirement` | COMPONENT_REQUIREMENT | +| `ComponentComponentBinding` | COMPONENT_BINDING | \ No newline at end of file diff --git a/docs/pkg/models/shared/composite.md b/docs/pkg/models/shared/composite.md index 7a2a1fe3d..60ea550dd 100644 --- a/docs/pkg/models/shared/composite.md +++ b/docs/pkg/models/shared/composite.md @@ -6,7 +6,7 @@ Composite import IDs combine values from multiple component fields ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | -| `Fields` | [][shared.CompositeField](../../../pkg/models/shared/compositefield.md) | :heavy_minus_sign: | Component fields, in the order they participate in the import
    ID. | -| `Format` | [*shared.Format](../../../pkg/models/shared/format.md) | :heavy_minus_sign: | Wire format the provider expects. Defaults to
    FORMAT_JSON_OBJECT. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | +| `Fields` | [][shared.CompositeField](../../../pkg/models/shared/compositefield.md) | :heavy_minus_sign: | Component fields, in the order they participate in the import
    ID. | +| `Format` | [*shared.CompositeFormat](../../../pkg/models/shared/compositeformat.md) | :heavy_minus_sign: | Wire format the provider expects. Defaults to
    FORMAT_JSON_OBJECT. | \ No newline at end of file diff --git a/docs/pkg/models/shared/compositeformat.md b/docs/pkg/models/shared/compositeformat.md new file mode 100644 index 000000000..39908bd40 --- /dev/null +++ b/docs/pkg/models/shared/compositeformat.md @@ -0,0 +1,26 @@ +# CompositeFormat + +Wire format the provider expects. Defaults to + FORMAT_JSON_OBJECT. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.CompositeFormatFormatJSONObject + +// Open enum: custom values can be created with a direct type cast +custom := shared.CompositeFormat("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------ | ------------------------------------------ | +| `CompositeFormatFormatJSONObject` | FORMAT_JSON_OBJECT | +| `CompositeFormatFormatColonSeparated` | FORMAT_COLON_SEPARATED | +| `CompositeFormatFormatUnderscoreSeparated` | FORMAT_UNDERSCORE_SEPARATED | \ No newline at end of file diff --git a/docs/pkg/models/shared/connectoractionref.md b/docs/pkg/models/shared/connectoractionref.md index 5b9448ce9..9467af608 100644 --- a/docs/pkg/models/shared/connectoractionref.md +++ b/docs/pkg/models/shared/connectoractionref.md @@ -7,8 +7,8 @@ ConnectorActionRef describes dispatch through a connector's built-in ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | -| `AppID` | `*string` | :heavy_minus_sign: | The app whose connector handles the operation. | -| `ConnectorID` | `*string` | :heavy_minus_sign: | The connector that will execute the Grant / Revoke. | -| `Operation` | [*shared.Operation](../../../pkg/models/shared/operation.md) | :heavy_minus_sign: | Which connector RPC this dispatches to. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | +| `AppID` | `*string` | :heavy_minus_sign: | The app whose connector handles the operation. | +| `ConnectorID` | `*string` | :heavy_minus_sign: | The connector that will execute the Grant / Revoke. | +| `Operation` | [*shared.ConnectorActionRefOperation](../../../pkg/models/shared/connectoractionrefoperation.md) | :heavy_minus_sign: | Which connector RPC this dispatches to. | \ No newline at end of file diff --git a/docs/pkg/models/shared/connectoractionrefoperation.md b/docs/pkg/models/shared/connectoractionrefoperation.md new file mode 100644 index 000000000..1346b7b5a --- /dev/null +++ b/docs/pkg/models/shared/connectoractionrefoperation.md @@ -0,0 +1,24 @@ +# ConnectorActionRefOperation + +Which connector RPC this dispatches to. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ConnectorActionRefOperationOperationUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.ConnectorActionRefOperation("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------- | ------------------------------------------------- | +| `ConnectorActionRefOperationOperationUnspecified` | OPERATION_UNSPECIFIED | +| `ConnectorActionRefOperationOperationGrant` | OPERATION_GRANT | \ No newline at end of file diff --git a/docs/pkg/models/shared/connectorexpandmask.md b/docs/pkg/models/shared/connectorexpandmask.md index 07850c22c..e48fdaedf 100644 --- a/docs/pkg/models/shared/connectorexpandmask.md +++ b/docs/pkg/models/shared/connectorexpandmask.md @@ -5,6 +5,6 @@ The ConnectorExpandMask is used to expand related objects on a connector. ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | -| `Paths` | []`string` | :heavy_minus_sign: | Paths that you want expanded in the response. Possible values are "app_id" and "*". | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `Paths` | []`string` | :heavy_minus_sign: | Paths that you want expanded in the response. Possible values are "app_id",
    "user_ids", "capabilities" and "*". | \ No newline at end of file diff --git a/docs/pkg/models/shared/connectorsyncfailingevidence.md b/docs/pkg/models/shared/connectorsyncfailingevidence.md new file mode 100644 index 000000000..93cf4cc2e --- /dev/null +++ b/docs/pkg/models/shared/connectorsyncfailingevidence.md @@ -0,0 +1,14 @@ +# ConnectorSyncFailingEvidence + +ConnectorSyncFailingEvidence describes the failure streak behind a + CONNECTOR_SYNC_FAILING finding, refreshed on every re-observation. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ConsecutiveFailureCount` | `*int64` | :heavy_minus_sign: | The consecutiveFailureCount field. | +| `LastFailedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `LastSyncLifecycleID` | `*string` | :heavy_minus_sign: | Id of the newest failing sync run, not a copy of its error text -- see the
    c1models message for why the error itself is deliberately not carried here. | +| `StreakStartedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/connectorsyncfailingtype.md b/docs/pkg/models/shared/connectorsyncfailingtype.md new file mode 100644 index 000000000..12861ec9c --- /dev/null +++ b/docs/pkg/models/shared/connectorsyncfailingtype.md @@ -0,0 +1,11 @@ +# ConnectorSyncFailingType + +ConnectorSyncFailingType: a connector's completed sync runs have ended in + error for at least two consecutive runs, with no intervening success. + Target: ConnectorTarget. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/createapprequest.md b/docs/pkg/models/shared/createapprequest.md index 3ff2d326d..3f716180a 100644 --- a/docs/pkg/models/shared/createapprequest.md +++ b/docs/pkg/models/shared/createapprequest.md @@ -8,14 +8,15 @@ The CreateAppRequest message is used to create a new app. | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `Annotations` | map[string]`string` | :heavy_minus_sign: | Bounded key/value metadata bag for IaC marking and customer tags.
    See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128
    chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars
    matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting
    with `c1/` are reserved for server-managed use and rejected on write.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | -| `AppEntitlementOwnerRefs` | [][shared.AppEntitlementRef](../../../pkg/models/shared/appentitlementref.md) | :heavy_minus_sign: | Sets entitlement owners on the app. | +| `AppEntitlementOwnerRefs` | [][shared.AppEntitlementRef](../../../pkg/models/shared/appentitlementref.md) | :heavy_minus_sign: | Initial entitlement owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_entitlement`. | | `CertifyPolicyID` | `*string` | :heavy_minus_sign: | Creates the app with this certify policy. | | `Description` | `*string` | :heavy_minus_sign: | Creates the app with this description. | | `DisplayName` | `string` | :heavy_check_mark: | Creates the app with this display name. | | `GrantPolicyID` | `*string` | :heavy_minus_sign: | Creates the app with this grant policy. | | `IdentityMatching` | [*shared.CreateAppRequestIdentityMatching](../../../pkg/models/shared/createapprequestidentitymatching.md) | :heavy_minus_sign: | Define the app user identity matching strategy for this app. | | `Instructions` | `*string` | :heavy_minus_sign: | Instructions shown to users in the access request form when requesting access for this app. | +| `MatchBatonRef` | [*shared.AppMatchBatonRef](../../../pkg/models/shared/appmatchbatonref.md) | :heavy_minus_sign: | N/A | | `MonthlyCostUsd` | `*int` | :heavy_minus_sign: | Creates the app with this monthly cost per seat. | -| `Owners` | []`string` | :heavy_minus_sign: | Creates the app with this array of user owners. | +| `Owners` | []`string` | :heavy_minus_sign: | Initial user owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_user`. | | `RevokePolicyID` | `*string` | :heavy_minus_sign: | Creates the app with this revoke policy. | | `StrictAccessEntitlementProvisioning` | `*bool` | :heavy_minus_sign: | This flag enforces a provisioning mode where the access entitlement is always included in the provisioning flow, if the app user doesn't exist | \ No newline at end of file diff --git a/docs/pkg/models/shared/createappresponse.md b/docs/pkg/models/shared/createappresponse.md index f455ab92a..b6ff921ec 100644 --- a/docs/pkg/models/shared/createappresponse.md +++ b/docs/pkg/models/shared/createappresponse.md @@ -1,6 +1,6 @@ # CreateAppResponse -Returns the new app's values. +CreateAppResponse contains the newly created application. ## Fields diff --git a/docs/pkg/models/shared/createpolicyrequest.md b/docs/pkg/models/shared/createpolicyrequest.md index 2c5df3e24..e73796101 100644 --- a/docs/pkg/models/shared/createpolicyrequest.md +++ b/docs/pkg/models/shared/createpolicyrequest.md @@ -8,10 +8,12 @@ The CreatePolicyRequest message is used to create a new policy. | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `Annotations` | map[string]`string` | :heavy_minus_sign: | Bounded key/value metadata bag for IaC marking and customer tags.
    See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128
    chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars
    matching URL-safe ASCII; total serialized ≤4096 bytes. Keys starting
    with `c1/` are reserved for server-managed use and rejected on write.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | +| `BaselinePolicyID` | `*string` | :heavy_minus_sign: | When set, the new policy's baseline defers to another policy of the same
    type when no rule matches, instead of an inline baseline step list.
    Mutually exclusive with the baseline entry in policy_steps. Requires the
    POLICY_REFERENCES_POLICY feature; obeys the same depth/cycle/self rules as
    Rule.policy_id. | | `Description` | `*string` | :heavy_minus_sign: | The description of the new policy. | | `DisplayName` | `string` | :heavy_check_mark: | The display name of the new policy. | | `PolicySteps` | map[string][shared.PolicyStepsInput](../../../pkg/models/shared/policystepsinput.md) | :heavy_minus_sign: | Step sequences for this policy. The map must include a baseline entry keyed
    by the lowercased policy type (e.g., "grant"). Additional entries with
    opaque keys can be added for conditional routing via the rules array. | | `PolicyType` | [*shared.PolicyType](../../../pkg/models/shared/policytype.md) | :heavy_minus_sign: | The type of policy to create (grant, revoke, or certify). | | `PostActions` | [][shared.PolicyPostActions](../../../pkg/models/shared/policypostactions.md) | :heavy_minus_sign: | Ordered actions to execute after the policy completes processing. | | ~~`ReassignTasksToDelegates`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    This field is no longer used. Configure delegate reassignment in the policy step instead. | -| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Conditional routing rules. See the Policy message for details on evaluation order. | \ No newline at end of file +| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Conditional routing rules. See the Policy message for details on evaluation order. | +| `Scope` | [*shared.PolicyScope](../../../pkg/models/shared/policyscope.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/createrevoketasksv2.md b/docs/pkg/models/shared/createrevoketasksv2.md index fdebef7b4..b2d29bc2e 100644 --- a/docs/pkg/models/shared/createrevoketasksv2.md +++ b/docs/pkg/models/shared/createrevoketasksv2.md @@ -26,17 +26,18 @@ This message contains a oneof named exclusion. Only a single field of the follow ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `ExclusionCriteria` | [*shared.EntitlementExclusionCriteria](../../../pkg/models/shared/entitlementexclusioncriteria.md) | :heavy_minus_sign: | N/A | -| `ExclusionList` | [*shared.EntitlementExclusionList](../../../pkg/models/shared/entitlementexclusionlist.md) | :heavy_minus_sign: | N/A | -| `ExclusionListCel` | [*shared.EntitlementExclusionListCel](../../../pkg/models/shared/entitlementexclusionlistcel.md) | :heavy_minus_sign: | N/A | -| `ExclusionNone` | [*shared.EntitlementExclusionNone](../../../pkg/models/shared/entitlementexclusionnone.md) | :heavy_minus_sign: | N/A | -| `InclusionAccessOnly` | [*shared.EntitlementInclusionAccessOnly](../../../pkg/models/shared/entitlementinclusionaccessonly.md) | :heavy_minus_sign: | N/A | -| `InclusionAll` | [*shared.EntitlementInclusionAll](../../../pkg/models/shared/entitlementinclusionall.md) | :heavy_minus_sign: | N/A | -| `InclusionCriteria` | [*shared.EntitlementInclusionCriteria](../../../pkg/models/shared/entitlementinclusioncriteria.md) | :heavy_minus_sign: | N/A | -| `InclusionList` | [*shared.EntitlementInclusionList](../../../pkg/models/shared/entitlementinclusionlist.md) | :heavy_minus_sign: | N/A | -| `InclusionListCel` | [*shared.EntitlementInclusionListCel](../../../pkg/models/shared/entitlementinclusionlistcel.md) | :heavy_minus_sign: | N/A | -| `UseSubjectUser` | `*bool` | :heavy_minus_sign: | The useSubjectUser field.
    This field is part of the `user` oneof.
    See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. | -| `UserIDCel` | `*string` | :heavy_minus_sign: | The userIdCel field.
    This field is part of the `user` oneof.
    See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. | -| `UserRef` | [*shared.UserRef](../../../pkg/models/shared/userref.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ExclusionCriteria` | [*shared.EntitlementExclusionCriteria](../../../pkg/models/shared/entitlementexclusioncriteria.md) | :heavy_minus_sign: | N/A | +| `ExclusionList` | [*shared.EntitlementExclusionList](../../../pkg/models/shared/entitlementexclusionlist.md) | :heavy_minus_sign: | N/A | +| `ExclusionListCel` | [*shared.EntitlementExclusionListCel](../../../pkg/models/shared/entitlementexclusionlistcel.md) | :heavy_minus_sign: | N/A | +| `ExclusionNone` | [*shared.EntitlementExclusionNone](../../../pkg/models/shared/entitlementexclusionnone.md) | :heavy_minus_sign: | N/A | +| `GrantSourceFilter` | [*shared.GrantSourceFilter](../../../pkg/models/shared/grantsourcefilter.md) | :heavy_minus_sign: | Restricts the step to grants of either DIRECT (grants the user holds directly,
    including grants that are also inherited) or UNSPECIFIED (all grants).
    Composes with every inclusion mode, including inclusion_list_cel. | +| `InclusionAccessOnly` | [*shared.EntitlementInclusionAccessOnly](../../../pkg/models/shared/entitlementinclusionaccessonly.md) | :heavy_minus_sign: | N/A | +| `InclusionAll` | [*shared.EntitlementInclusionAll](../../../pkg/models/shared/entitlementinclusionall.md) | :heavy_minus_sign: | N/A | +| `InclusionCriteria` | [*shared.EntitlementInclusionCriteria](../../../pkg/models/shared/entitlementinclusioncriteria.md) | :heavy_minus_sign: | N/A | +| `InclusionList` | [*shared.EntitlementInclusionList](../../../pkg/models/shared/entitlementinclusionlist.md) | :heavy_minus_sign: | N/A | +| `InclusionListCel` | [*shared.EntitlementInclusionListCel](../../../pkg/models/shared/entitlementinclusionlistcel.md) | :heavy_minus_sign: | N/A | +| `UseSubjectUser` | `*bool` | :heavy_minus_sign: | The useSubjectUser field.
    This field is part of the `user` oneof.
    See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. | +| `UserIDCel` | `*string` | :heavy_minus_sign: | The userIdCel field.
    This field is part of the `user` oneof.
    See the documentation for `c1.api.automations.v1.CreateRevokeTasksV2` for more details. | +| `UserRef` | [*shared.UserRef](../../../pkg/models/shared/userref.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/credentialexpiringevidence.md b/docs/pkg/models/shared/credentialexpiringevidence.md new file mode 100644 index 000000000..ae3affc91 --- /dev/null +++ b/docs/pkg/models/shared/credentialexpiringevidence.md @@ -0,0 +1,11 @@ +# CredentialExpiringEvidence + +The CredentialExpiringEvidence message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | +| `Expired` | `*bool` | :heavy_minus_sign: | Whether the expiry was already past when last observed. | +| `ExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/credentialexpiringtype.md b/docs/pkg/models/shared/credentialexpiringtype.md new file mode 100644 index 000000000..287c95fb2 --- /dev/null +++ b/docs/pkg/models/shared/credentialexpiringtype.md @@ -0,0 +1,18 @@ +# CredentialExpiringType + +CredentialExpiringType: a ConductorOne-managed credential is inside the + detector's expiry warning window, or already past it. Dedup is + (credential arm, credential_id). Target: IdentityUserTarget -- the identity + holding the credential. + +This message contains a oneof named credential. Only a single field of the following list may be set at a time: + - userClientId + + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `CredentialDisplayName` | `*string` | :heavy_minus_sign: | The credentialDisplayName field. | +| `UserClientID` | `*string` | :heavy_minus_sign: | Service-principal credential.
    This field is part of the `credential` oneof.
    See the documentation for `c1.api.finding.v1.CredentialExpiringType` for more details. | \ No newline at end of file diff --git a/docs/pkg/models/shared/credentialpubliclyexposedevidence.md b/docs/pkg/models/shared/credentialpubliclyexposedevidence.md new file mode 100644 index 000000000..bb2d3da89 --- /dev/null +++ b/docs/pkg/models/shared/credentialpubliclyexposedevidence.md @@ -0,0 +1,17 @@ +# CredentialPubliclyExposedEvidence + +CredentialPubliclyExposedEvidence carries scanner attribution for a public exposure. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `CredentialRevoked` | `*bool` | :heavy_minus_sign: | The credentialRevoked field. | +| `FingerprintPrefix` | `*string` | :heavy_minus_sign: | The fingerprintPrefix field. | +| `FirstObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `FirstScannerID` | `*string` | :heavy_minus_sign: | The firstScannerId field. | +| `ReportingScanners` | []`string` | :heavy_minus_sign: | The reportingScanners field. | +| `RevokedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `SourceKind` | `*string` | :heavy_minus_sign: | The sourceKind field. | +| `SourceURL` | `*string` | :heavy_minus_sign: | The sourceUrl field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/credentialpubliclyexposedtype.md b/docs/pkg/models/shared/credentialpubliclyexposedtype.md new file mode 100644 index 000000000..444af7ea2 --- /dev/null +++ b/docs/pkg/models/shared/credentialpubliclyexposedtype.md @@ -0,0 +1,22 @@ +# CredentialPubliclyExposedType + +CredentialPubliclyExposedType: a live credential was reported as publicly exposed. + Dedup is (credential arm, credential_id). + +This message contains a oneof named credential. Only a single field of the following list may be set at a time: + - userClientId + - connectorClientId + - connectorManagedCredentialId + - functionClientId + + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ConnectorClientID` | `*string` | :heavy_minus_sign: | The connectorClientId field.
    This field is part of the `credential` oneof.
    See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. | +| `ConnectorManagedCredentialID` | `*string` | :heavy_minus_sign: | The connectorManagedCredentialId field.
    This field is part of the `credential` oneof.
    See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. | +| `CredentialDisplayName` | `*string` | :heavy_minus_sign: | The credentialDisplayName field. | +| `FunctionClientID` | `*string` | :heavy_minus_sign: | The functionClientId field.
    This field is part of the `credential` oneof.
    See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. | +| `UserClientID` | `*string` | :heavy_minus_sign: | The userClientId field.
    This field is part of the `credential` oneof.
    See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. | \ No newline at end of file diff --git a/docs/pkg/models/shared/datefield.md b/docs/pkg/models/shared/datefield.md new file mode 100644 index 000000000..fc642787a --- /dev/null +++ b/docs/pkg/models/shared/datefield.md @@ -0,0 +1,15 @@ +# DateField + +DateField renders a date picker. The value is an ISO-8601 calendar date + ("YYYY-MM-DD") stored in the enclosing StringField's string value. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `DefaultToToday` | `*bool` | :heavy_minus_sign: | Default the field to the render date when the StringField has no default_value. | +| `MaxDate` | `*string` | :heavy_minus_sign: | Latest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. | +| `MaxDaysFromToday` | `*int` | :heavy_minus_sign: | Latest selectable date expressed as an offset in days from the date the
    form is rendered; negative is in the past. Set this to 365 to cap a date at
    one year out. When both are set, the earlier of this and max_date applies.
    Enforcement is one day slack in each direction: the picker anchors today at
    the submitter's local midnight and the server anchors in UTC, so 365 admits
    366 days rather than reject a date the picker itself offered. | +| `MinDate` | `*string` | :heavy_minus_sign: | Earliest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. | +| `MinDaysFromToday` | `*int` | :heavy_minus_sign: | Earliest selectable date expressed as an offset in days from the date the
    form is rendered; negative is in the past. Prefer this over min_date for a
    rolling window, which would otherwise go stale. When both are set, the
    later of the two applies. | \ No newline at end of file diff --git a/docs/pkg/models/shared/deactivatedownerdetail.md b/docs/pkg/models/shared/deactivatedownerdetail.md new file mode 100644 index 000000000..ee28be373 --- /dev/null +++ b/docs/pkg/models/shared/deactivatedownerdetail.md @@ -0,0 +1,13 @@ +# DeactivatedOwnerDetail + +DeactivatedOwnerDetail is one deactivated owner found for the target at + detection time. A target can have more than one owner, and more than one + can read as deactivated. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Reason` | [*shared.Reason](../../../pkg/models/shared/reason.md) | :heavy_minus_sign: | The reason field. | +| `UserID` | `*string` | :heavy_minus_sign: | The userId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/deactivatedownerevidence.md b/docs/pkg/models/shared/deactivatedownerevidence.md new file mode 100644 index 000000000..e0373a9e7 --- /dev/null +++ b/docs/pkg/models/shared/deactivatedownerevidence.md @@ -0,0 +1,10 @@ +# DeactivatedOwnerEvidence + +The DeactivatedOwnerEvidence message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | +| `DeactivatedOwners` | [][shared.DeactivatedOwnerDetail](../../../pkg/models/shared/deactivatedownerdetail.md) | :heavy_minus_sign: | The deactivatedOwners field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/deactivatedownertype.md b/docs/pkg/models/shared/deactivatedownertype.md new file mode 100644 index 000000000..8461af06b --- /dev/null +++ b/docs/pkg/models/shared/deactivatedownertype.md @@ -0,0 +1,13 @@ +# DeactivatedOwnerType + +DeactivatedOwnerType: the human responsible for a target -- either the + AppUser's own correlated identity, an ownership_v2-assigned owner, or a + secret's run-as identity is deactivated. Target: AppUserTarget or + AppResourceTarget. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `Source` | [*shared.DeactivatedOwnerTypeSource](../../../pkg/models/shared/deactivatedownertypesource.md) | :heavy_minus_sign: | The source field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/deactivatedownertypesource.md b/docs/pkg/models/shared/deactivatedownertypesource.md new file mode 100644 index 000000000..99424f986 --- /dev/null +++ b/docs/pkg/models/shared/deactivatedownertypesource.md @@ -0,0 +1,26 @@ +# DeactivatedOwnerTypeSource + +The source field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DeactivatedOwnerTypeSourceDeactivatedOwnerSourceUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DeactivatedOwnerTypeSource("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------------------------- | --------------------------------------------------------------------- | +| `DeactivatedOwnerTypeSourceDeactivatedOwnerSourceUnspecified` | DEACTIVATED_OWNER_SOURCE_UNSPECIFIED | +| `DeactivatedOwnerTypeSourceDeactivatedOwnerSourceIdentityCorrelation` | DEACTIVATED_OWNER_SOURCE_IDENTITY_CORRELATION | +| `DeactivatedOwnerTypeSourceDeactivatedOwnerSourceOwnershipAssigned` | DEACTIVATED_OWNER_SOURCE_OWNERSHIP_ASSIGNED | +| `DeactivatedOwnerTypeSourceDeactivatedOwnerSourceSecretRunAsIdentity` | DEACTIVATED_OWNER_SOURCE_SECRET_RUN_AS_IDENTITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/decoypubliclyexposedevidence.md b/docs/pkg/models/shared/decoypubliclyexposedevidence.md new file mode 100644 index 000000000..878a8ea75 --- /dev/null +++ b/docs/pkg/models/shared/decoypubliclyexposedevidence.md @@ -0,0 +1,17 @@ +# DecoyPubliclyExposedEvidence + +DecoyPubliclyExposedEvidence mirrors CredentialPubliclyExposedEvidence for decoys. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `CredentialRevoked` | `*bool` | :heavy_minus_sign: | The credentialRevoked field. | +| `FingerprintPrefix` | `*string` | :heavy_minus_sign: | The fingerprintPrefix field. | +| `FirstObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `FirstScannerID` | `*string` | :heavy_minus_sign: | The firstScannerId field. | +| `ReportingScanners` | []`string` | :heavy_minus_sign: | The reportingScanners field. | +| `RevokedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `SourceKind` | `*string` | :heavy_minus_sign: | The sourceKind field. | +| `SourceURL` | `*string` | :heavy_minus_sign: | The sourceUrl field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/decoypubliclyexposedtype.md b/docs/pkg/models/shared/decoypubliclyexposedtype.md new file mode 100644 index 000000000..b6d723898 --- /dev/null +++ b/docs/pkg/models/shared/decoypubliclyexposedtype.md @@ -0,0 +1,12 @@ +# DecoyPubliclyExposedType + +DecoyPubliclyExposedType: a planted decoy was reported as publicly exposed. + Dedup is decoy_id. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------- | --------------------------- | --------------------------- | --------------------------- | +| `DecoyDisplayName` | `*string` | :heavy_minus_sign: | The decoyDisplayName field. | +| `DecoyID` | `*string` | :heavy_minus_sign: | The decoyId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/defaultidtokensignedresponsealg.md b/docs/pkg/models/shared/defaultidtokensignedresponsealg.md new file mode 100644 index 000000000..127580e9a --- /dev/null +++ b/docs/pkg/models/shared/defaultidtokensignedresponsealg.md @@ -0,0 +1,27 @@ +# DefaultIDTokenSignedResponseAlg + +The id_token signing algorithm applied to OIDC applications that do not + choose one. When unset, the server uses EdDSA. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DefaultIDTokenSignedResponseAlg("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified` | OIDC_SIGNING_ALGORITHM_UNSPECIFIED | +| `DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmEddsa` | OIDC_SIGNING_ALGORITHM_EDDSA | +| `DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmEs256` | OIDC_SIGNING_ALGORITHM_ES256 | +| `DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmRs256` | OIDC_SIGNING_ALGORITHM_RS256 | \ No newline at end of file diff --git a/docs/pkg/models/shared/defaultsubjecttype.md b/docs/pkg/models/shared/defaultsubjecttype.md new file mode 100644 index 000000000..3ff2241ca --- /dev/null +++ b/docs/pkg/models/shared/defaultsubjecttype.md @@ -0,0 +1,28 @@ +# DefaultSubjectType + +The subject type materialized onto new SSO applications that do not choose + one. Changing this default does not change existing applications. When + unset, the server uses pairwise subjects. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DefaultSubjectTypeSsoSubjectTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DefaultSubjectType("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------- | ----------------------------------------------- | +| `DefaultSubjectTypeSsoSubjectTypeUnspecified` | SSO_SUBJECT_TYPE_UNSPECIFIED | +| `DefaultSubjectTypeSsoSubjectTypePairwise` | SSO_SUBJECT_TYPE_PAIRWISE | +| `DefaultSubjectTypeSsoSubjectTypePublic` | SSO_SUBJECT_TYPE_PUBLIC | +| `DefaultSubjectTypeSsoSubjectTypeCompatibility` | SSO_SUBJECT_TYPE_COMPATIBILITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/deltasentiment.md b/docs/pkg/models/shared/deltasentiment.md new file mode 100644 index 000000000..65d878fb1 --- /dev/null +++ b/docs/pkg/models/shared/deltasentiment.md @@ -0,0 +1,26 @@ +# DeltaSentiment + +The deltaSentiment field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DeltaSentimentC1MetricDeltaSentimentUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DeltaSentiment("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------- | ------------------------------------------------- | +| `DeltaSentimentC1MetricDeltaSentimentUnspecified` | C1_METRIC_DELTA_SENTIMENT_UNSPECIFIED | +| `DeltaSentimentC1MetricDeltaSentimentPositive` | C1_METRIC_DELTA_SENTIMENT_POSITIVE | +| `DeltaSentimentC1MetricDeltaSentimentNegative` | C1_METRIC_DELTA_SENTIMENT_NEGATIVE | +| `DeltaSentimentC1MetricDeltaSentimentNeutral` | C1_METRIC_DELTA_SENTIMENT_NEUTRAL | \ No newline at end of file diff --git a/docs/pkg/models/shared/destination.md b/docs/pkg/models/shared/destination.md new file mode 100644 index 000000000..ad4127acf --- /dev/null +++ b/docs/pkg/models/shared/destination.md @@ -0,0 +1,25 @@ +# Destination + +Where the claim is released. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DestinationOidcClaimDestinationUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Destination("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------- | --------------------------------------------- | +| `DestinationOidcClaimDestinationUnspecified` | OIDC_CLAIM_DESTINATION_UNSPECIFIED | +| `DestinationOidcClaimDestinationIDTokenOnly` | OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY | +| `DestinationOidcClaimDestinationUserinfoOnly` | OIDC_CLAIM_DESTINATION_USERINFO_ONLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/detaillevel.md b/docs/pkg/models/shared/detaillevel.md new file mode 100644 index 000000000..6edc8fe8a --- /dev/null +++ b/docs/pkg/models/shared/detaillevel.md @@ -0,0 +1,25 @@ +# DetailLevel + +How much the notification reveals. Defaults to SUMMARY. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DetailLevelFindingNotifyDetailLevelUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DetailLevel("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------ | ------------------------------------------------ | +| `DetailLevelFindingNotifyDetailLevelUnspecified` | FINDING_NOTIFY_DETAIL_LEVEL_UNSPECIFIED | +| `DetailLevelFindingNotifyDetailLevelSummary` | FINDING_NOTIFY_DETAIL_LEVEL_SUMMARY | +| `DetailLevelFindingNotifyDetailLevelFullDetail` | FINDING_NOTIFY_DETAIL_LEVEL_FULL_DETAIL | \ No newline at end of file diff --git a/docs/pkg/models/shared/deviceplacementprovision.md b/docs/pkg/models/shared/deviceplacementprovision.md new file mode 100644 index 000000000..2c4508157 --- /dev/null +++ b/docs/pkg/models/shared/deviceplacementprovision.md @@ -0,0 +1,10 @@ +# DevicePlacementProvision + +This provision step is fulfilled by a Latchkey member device producing an MLS Welcome for the recipient. It has no assignee and no instructions because the step is not human-actionable. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------- | -------------------------- | -------------------------- | -------------------------- | +| `VaultBoundaryID` | `*string` | :heavy_minus_sign: | The vaultBoundaryId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/disabledmodules.md b/docs/pkg/models/shared/disabledmodules.md new file mode 100644 index 000000000..931c59331 --- /dev/null +++ b/docs/pkg/models/shared/disabledmodules.md @@ -0,0 +1,22 @@ +# DisabledModules + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DisabledModulesModuleIDUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DisabledModules("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------- | -------------------------------------- | +| `DisabledModulesModuleIDUnspecified` | MODULE_ID_UNSPECIFIED | +| `DisabledModulesModuleIDSecretSharing` | MODULE_ID_SECRET_SHARING | \ No newline at end of file diff --git a/docs/pkg/models/shared/disabledreasoncircuitbreaker.md b/docs/pkg/models/shared/disabledreasoncircuitbreaker.md index 28912b43b..858a35d2b 100644 --- a/docs/pkg/models/shared/disabledreasoncircuitbreaker.md +++ b/docs/pkg/models/shared/disabledreasoncircuitbreaker.md @@ -7,9 +7,9 @@ DisabledReasonCircuitBreaker carries the trip context when an automation ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | -| `ObservedCount` | `*int64` | :heavy_minus_sign: | Observed execution count in the period at trip time. | -| `Period` | [*shared.Period](../../../pkg/models/shared/period.md) | :heavy_minus_sign: | Snapshot of the period at trip time. | -| `Threshold` | `*int64` | :heavy_minus_sign: | Snapshot of the threshold at trip time. | -| `TrippedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `ObservedCount` | `*int64` | :heavy_minus_sign: | Observed execution count in the period at trip time. | +| `Period` | [*shared.DisabledReasonCircuitBreakerPeriod](../../../pkg/models/shared/disabledreasoncircuitbreakerperiod.md) | :heavy_minus_sign: | Snapshot of the period at trip time. | +| `Threshold` | `*int64` | :heavy_minus_sign: | Snapshot of the threshold at trip time. | +| `TrippedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/disabledreasoncircuitbreakerperiod.md b/docs/pkg/models/shared/disabledreasoncircuitbreakerperiod.md new file mode 100644 index 000000000..c69198b12 --- /dev/null +++ b/docs/pkg/models/shared/disabledreasoncircuitbreakerperiod.md @@ -0,0 +1,27 @@ +# DisabledReasonCircuitBreakerPeriod + +Snapshot of the period at trip time. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.DisabledReasonCircuitBreakerPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------- | ------------------------------------------------------------------- | +| `DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodUnspecified` | CIRCUIT_BREAKER_PERIOD_UNSPECIFIED | +| `DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodHour` | CIRCUIT_BREAKER_PERIOD_HOUR | +| `DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodDay` | CIRCUIT_BREAKER_PERIOD_DAY | +| `DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodWeek` | CIRCUIT_BREAKER_PERIOD_WEEK | +| `DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodMonth` | CIRCUIT_BREAKER_PERIOD_MONTH | \ No newline at end of file diff --git a/docs/pkg/models/shared/emailchannelsettings.md b/docs/pkg/models/shared/emailchannelsettings.md index 03f1ff573..6f52972d5 100644 --- a/docs/pkg/models/shared/emailchannelsettings.md +++ b/docs/pkg/models/shared/emailchannelsettings.md @@ -16,5 +16,7 @@ The EmailChannelSettings message. | `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | | `ExpiringAccess` | [*shared.ExpiringAccessPreference](../../../pkg/models/shared/expiringaccesspreference.md) | :heavy_minus_sign: | N/A | | `ProvisioningRequest` | [*shared.ProvisioningRequestPreference](../../../pkg/models/shared/provisioningrequestpreference.md) | :heavy_minus_sign: | N/A | +| `RequestCreated` | [*shared.RequestCreatedPreference](../../../pkg/models/shared/requestcreatedpreference.md) | :heavy_minus_sign: | N/A | | `Reviews` | [*shared.ReviewsPreference](../../../pkg/models/shared/reviewspreference.md) | :heavy_minus_sign: | N/A | +| `System` | [*shared.SystemPreference](../../../pkg/models/shared/systempreference.md) | :heavy_minus_sign: | N/A | | `TaskReminders` | [*shared.TaskRemindersPreference](../../../pkg/models/shared/taskreminderspreference.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/encodedcontentguardconfig.md b/docs/pkg/models/shared/encodedcontentguardconfig.md new file mode 100644 index 000000000..57dcea0d8 --- /dev/null +++ b/docs/pkg/models/shared/encodedcontentguardconfig.md @@ -0,0 +1,13 @@ +# EncodedContentGuardConfig + +EncodedContentGuardConfig detects encoded/obfuscated smuggling in tool input: + long base64 blobs, long hex runs, and invisible/zero-width unicode. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `FlagOnly` | `*bool` | :heavy_minus_sign: | When true, detection records the finding but does not deny (observe-only). | +| `MinBase64Run` | `*int` | :heavy_minus_sign: | Minimum contiguous base64 run length to flag. <= 0 = default (256). | +| `MinHexRun` | `*int` | :heavy_minus_sign: | Minimum contiguous hex run length to flag. <= 0 = default (128). | \ No newline at end of file diff --git a/docs/pkg/models/shared/encryptionalgorithm.md b/docs/pkg/models/shared/encryptionalgorithm.md new file mode 100644 index 000000000..829931771 --- /dev/null +++ b/docs/pkg/models/shared/encryptionalgorithm.md @@ -0,0 +1,26 @@ +# EncryptionAlgorithm + +The algorithm used when encrypt_assertions is set. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.EncryptionAlgorithmSamlEncryptionAlgorithmUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.EncryptionAlgorithm("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------- | ------------------------------------------------------- | +| `EncryptionAlgorithmSamlEncryptionAlgorithmUnspecified` | SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED | +| `EncryptionAlgorithmSamlEncryptionAlgorithmAes256Gcm` | SAML_ENCRYPTION_ALGORITHM_AES256_GCM | +| `EncryptionAlgorithmSamlEncryptionAlgorithmAes128Gcm` | SAML_ENCRYPTION_ALGORITHM_AES128_GCM | +| `EncryptionAlgorithmSamlEncryptionAlgorithmAes256Cbc` | SAML_ENCRYPTION_ALGORITHM_AES256_CBC | \ No newline at end of file diff --git a/docs/pkg/models/shared/ensureonboardingsessionrequest.md b/docs/pkg/models/shared/ensureonboardingsessionrequest.md new file mode 100644 index 000000000..657993a07 --- /dev/null +++ b/docs/pkg/models/shared/ensureonboardingsessionrequest.md @@ -0,0 +1,9 @@ +# EnsureOnboardingSessionRequest + +Requests the active onboarding conversation for the caller's tenant. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ensureonboardingsessionresponse.md b/docs/pkg/models/shared/ensureonboardingsessionresponse.md new file mode 100644 index 000000000..16aad91ae --- /dev/null +++ b/docs/pkg/models/shared/ensureonboardingsessionresponse.md @@ -0,0 +1,11 @@ +# EnsureOnboardingSessionResponse + +Returns the active onboarding conversation and whether this call created it. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `ConversationID` | `*string` | :heavy_minus_sign: | The active onboarding conversation ID. | +| `Created` | `*bool` | :heavy_minus_sign: | True only when this call created and started the conversation. | \ No newline at end of file diff --git a/docs/pkg/models/shared/entitlementcutoffimpactpoint.md b/docs/pkg/models/shared/entitlementcutoffimpactpoint.md new file mode 100644 index 000000000..c48acb134 --- /dev/null +++ b/docs/pkg/models/shared/entitlementcutoffimpactpoint.md @@ -0,0 +1,13 @@ +# EntitlementCutoffImpactPoint + +EntitlementCutoffImpactPoint reports the exact effect of an inclusive + entitlement coverage cutoff on the analyzed cohort. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `EntitlementCount` | `*int` | :heavy_minus_sign: | Number of analyzed entitlements included at this cutoff. | +| `MinimumCoverageBasisPoints` | `*int` | :heavy_minus_sign: | Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. | +| `UsersWithAllEntitlements` | `*int` | :heavy_minus_sign: | Exact number of cohort users who hold every included entitlement. | \ No newline at end of file diff --git a/docs/pkg/models/shared/entitlementref.md b/docs/pkg/models/shared/entitlementref.md index f13f8ce0c..13df5a157 100644 --- a/docs/pkg/models/shared/entitlementref.md +++ b/docs/pkg/models/shared/entitlementref.md @@ -1,11 +1,11 @@ # EntitlementRef -EntitlementRef identifies an entitlement by app and entitlement ID. +EntitlementRef identifies an entitlement by application and entitlement ID. ## Fields -| Field | Type | Required | Description | -| ------------------------ | ------------------------ | ------------------------ | ------------------------ | -| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | -| `EntitlementID` | `*string` | :heavy_minus_sign: | The entitlementId field. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------- | -------------------------------------- | -------------------------------------- | -------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | Application that owns the entitlement. | +| `EntitlementID` | `*string` | :heavy_minus_sign: | Entitlement within the application. | \ No newline at end of file diff --git a/docs/pkg/models/shared/evaluateentitlementselectionrequest.md b/docs/pkg/models/shared/evaluateentitlementselectionrequest.md new file mode 100644 index 000000000..f9226eefc --- /dev/null +++ b/docs/pkg/models/shared/evaluateentitlementselectionrequest.md @@ -0,0 +1,14 @@ +# EvaluateEntitlementSelectionRequest + +EvaluateEntitlementSelectionRequest selects analyzed entitlements using an + inclusive coverage cutoff plus optional manual overrides. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `ExplicitlyExcluded` | [][shared.EntitlementRef](../../../pkg/models/shared/entitlementref.md) | :heavy_minus_sign: | Analyzed entitlements to exclude when they meet the cutoff. | +| `ExplicitlyIncluded` | [][shared.EntitlementRef](../../../pkg/models/shared/entitlementref.md) | :heavy_minus_sign: | Analyzed entitlements to include even when they fall below the cutoff. | +| `IncludeFacets` | `*bool` | :heavy_minus_sign: | Whether to return profile attribute facets for exact holders. | +| `MinimumCoverageBasisPoints` | `*int` | :heavy_minus_sign: | Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. | \ No newline at end of file diff --git a/docs/pkg/models/shared/evaluateentitlementselectionresponse.md b/docs/pkg/models/shared/evaluateentitlementselectionresponse.md new file mode 100644 index 000000000..512dddea4 --- /dev/null +++ b/docs/pkg/models/shared/evaluateentitlementselectionresponse.md @@ -0,0 +1,13 @@ +# EvaluateEntitlementSelectionResponse + +EvaluateEntitlementSelectionResponse contains the exact impact of the + resolved entitlement selection. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | +| `CoreHolderFacets` | [][shared.AttributeFacet](../../../pkg/models/shared/attributefacet.md) | :heavy_minus_sign: | Profile attribute facets narrowed to users who hold every selected entitlement. | +| `SelectedEntitlementCount` | `*int` | :heavy_minus_sign: | Number of entitlements in the resolved selection. | +| `UsersWithAllEntitlements` | `*int` | :heavy_minus_sign: | Exact number of cohort users who hold every selected entitlement. | \ No newline at end of file diff --git a/docs/pkg/models/shared/evaluateexpressions.md b/docs/pkg/models/shared/evaluateexpressions.md index fcf7d241f..552098d4d 100644 --- a/docs/pkg/models/shared/evaluateexpressions.md +++ b/docs/pkg/models/shared/evaluateexpressions.md @@ -1,7 +1,9 @@ -# EvaluateExpressions +# ~~EvaluateExpressions~~ The EvaluateExpressions message. +> :warning: **DEPRECATED**: This will be removed in a future release, please migrate away from it as soon as possible. + ## Fields diff --git a/docs/pkg/models/shared/event.md b/docs/pkg/models/shared/event.md index a797558c2..5eb13c6b3 100644 --- a/docs/pkg/models/shared/event.md +++ b/docs/pkg/models/shared/event.md @@ -22,4 +22,5 @@ custom := shared.Event("custom_value") | ------------------------------- | ------------------------------- | | `EventHookEventTypeUnspecified` | HOOK_EVENT_TYPE_UNSPECIFIED | | `EventHookEventTypePreToolUse` | HOOK_EVENT_TYPE_PRE_TOOL_USE | -| `EventHookEventTypePostToolUse` | HOOK_EVENT_TYPE_POST_TOOL_USE | \ No newline at end of file +| `EventHookEventTypePostToolUse` | HOOK_EVENT_TYPE_POST_TOOL_USE | +| `EventHookEventTypePreOutput` | HOOK_EVENT_TYPE_PRE_OUTPUT | \ No newline at end of file diff --git a/docs/pkg/models/shared/eventtypes.md b/docs/pkg/models/shared/eventtypes.md index b0057303e..4d772d2a1 100644 --- a/docs/pkg/models/shared/eventtypes.md +++ b/docs/pkg/models/shared/eventtypes.md @@ -36,4 +36,6 @@ custom := shared.EventTypes("custom_value") | `EventTypesFindingAuditEventTypeTaskCancelled` | FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED | | `EventTypesFindingAuditEventTypeEvidenceUpdated` | FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED | | `EventTypesFindingAuditEventTypeRoutingEvaluated` | FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED | -| `EventTypesFindingAuditEventTypeTransformed` | FINDING_AUDIT_EVENT_TYPE_TRANSFORMED | \ No newline at end of file +| `EventTypesFindingAuditEventTypeTransformed` | FINDING_AUDIT_EVENT_TYPE_TRANSFORMED | +| `EventTypesFindingAuditEventTypeReprocessRequested` | FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED | +| `EventTypesFindingAuditEventTypeReprocessCompleted` | FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/expression.md b/docs/pkg/models/shared/expression.md index cad5f8e01..3ef384019 100644 --- a/docs/pkg/models/shared/expression.md +++ b/docs/pkg/models/shared/expression.md @@ -1,7 +1,9 @@ -# Expression +# ~~Expression~~ The Expression message. +> :warning: **DEPRECATED**: This will be removed in a future release, please migrate away from it as soon as possible. + ## Fields diff --git a/docs/pkg/models/shared/finding.md b/docs/pkg/models/shared/finding.md index 0cf40132e..564506361 100644 --- a/docs/pkg/models/shared/finding.md +++ b/docs/pkg/models/shared/finding.md @@ -10,6 +10,12 @@ This message contains a oneof named finding_type. Only a single field of the fol - decoyCredentialUsed - custom - connectorAnomalyDetectionDisabled + - deactivatedOwner + - unusedSecret + - credentialPubliclyExposed + - decoyPubliclyExposed + - credentialExpiring + - connectorSyncFailing This message contains a oneof named target. Only a single field of the following list may be set at a time: @@ -24,54 +30,73 @@ This message contains a oneof named target. Only a single field of the following This message contains a oneof named evidence. Only a single field of the following list may be set at a time: - similarUsernameMatchEvidence - serviceAccountMisclassificationEvidence + - deactivatedOwnerEvidence + - unusedSecretEvidence + - credentialPubliclyExposedEvidence + - decoyPubliclyExposedEvidence + - credentialExpiringEvidence + - connectorSyncFailingEvidence ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | -| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | -| `AppResourceTarget` | [*shared.AppResourceTarget](../../../pkg/models/shared/appresourcetarget.md) | :heavy_minus_sign: | N/A | -| `AppUserTarget` | [*shared.AppUserTarget](../../../pkg/models/shared/appusertarget.md) | :heavy_minus_sign: | N/A | -| `AssignedOwner` | [*shared.FindingOwnerRef](../../../pkg/models/shared/findingownerref.md) | :heavy_minus_sign: | N/A | -| `ComputedOwner` | [*shared.FindingOwnerRef](../../../pkg/models/shared/findingownerref.md) | :heavy_minus_sign: | N/A | -| `ConnectorAnomalyDetectionDisabled` | [*shared.ConnectorAnomalyDetectionDisabledType](../../../pkg/models/shared/connectoranomalydetectiondisabledtype.md) | :heavy_minus_sign: | N/A | -| `ConnectorTarget` | [*shared.ConnectorTarget](../../../pkg/models/shared/connectortarget.md) | :heavy_minus_sign: | N/A | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Custom` | [*shared.CustomFindingType](../../../pkg/models/shared/customfindingtype.md) | :heavy_minus_sign: | N/A | -| `CustomSubType` | `*string` | :heavy_minus_sign: | User-supplied sub-classification for custom findings (e.g. "shadow_it"). | -| `CustomTags` | map[string]`string` | :heavy_minus_sign: | The customTags field. | -| `DecoyCredentialUsed` | [*shared.DecoyCredentialUsedType](../../../pkg/models/shared/decoycredentialusedtype.md) | :heavy_minus_sign: | N/A | -| `DecoyTarget` | [*shared.DecoyTarget](../../../pkg/models/shared/decoytarget.md) | :heavy_minus_sign: | N/A | -| `DedupKeyParts` | []`string` | :heavy_minus_sign: | Caller-supplied dedup identity for custom findings; echoed back so IaC
    clients can roundtrip it. Empty for detector findings. | -| `Description` | `*string` | :heavy_minus_sign: | User-authored finding body (markdown by convention). Set for custom findings. | -| `Fingerprint` | `*string` | :heavy_minus_sign: | The fingerprint field. | -| `FirstObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `ID` | `*string` | :heavy_minus_sign: | The id field. | -| `IdentityUserTarget` | [*shared.IdentityUserTarget](../../../pkg/models/shared/identityusertarget.md) | :heavy_minus_sign: | N/A | -| `LastAppearedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `LastObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `NhiUnowned` | [*shared.NhiUnownedType](../../../pkg/models/shared/nhiunownedtype.md) | :heavy_minus_sign: | N/A | -| `RecurrenceCount` | `*int64` | :heavy_minus_sign: | The recurrenceCount field. | -| `RemediationDescription` | `*string` | :heavy_minus_sign: | The remediationDescription field. | -| `ResolvedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `RiskAcceptanceExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `RiskAcceptanceJustification` | `*string` | :heavy_minus_sign: | The riskAcceptanceJustification field. | -| `RiskScore` | [*shared.FindingRiskScore](../../../pkg/models/shared/findingriskscore.md) | :heavy_minus_sign: | N/A | -| `ServiceAccountMisclassification` | [*shared.ServiceAccountMisclassificationType](../../../pkg/models/shared/serviceaccountmisclassificationtype.md) | :heavy_minus_sign: | N/A | -| `ServiceAccountMisclassificationEvidence` | [*shared.ServiceAccountMisclassificationEvidence](../../../pkg/models/shared/serviceaccountmisclassificationevidence.md) | :heavy_minus_sign: | N/A | -| `ServiceAccountUnowned` | [*shared.ServiceAccountUnownedType](../../../pkg/models/shared/serviceaccountunownedtype.md) | :heavy_minus_sign: | N/A | -| `Severity` | [*shared.FindingSeverity](../../../pkg/models/shared/findingseverity.md) | :heavy_minus_sign: | The severity field. | -| `SimilarUsernameMatch` | [*shared.SimilarUsernameMatchType](../../../pkg/models/shared/similarusernamematchtype.md) | :heavy_minus_sign: | N/A | -| `SimilarUsernameMatchEvidence` | [*shared.SimilarUsernameMatchEvidence](../../../pkg/models/shared/similarusernamematchevidence.md) | :heavy_minus_sign: | N/A | -| `SnoozeReason` | `*string` | :heavy_minus_sign: | The snoozeReason field. | -| `SnoozeUntil` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `SourceDetectorID` | `*string` | :heavy_minus_sign: | The sourceDetectorId field. | -| `SourceKind` | [*shared.SourceKind](../../../pkg/models/shared/sourcekind.md) | :heavy_minus_sign: | Who authored the finding (detector, user, external). | -| `State` | [*shared.FindingState](../../../pkg/models/shared/findingstate.md) | :heavy_minus_sign: | The state field. | -| `StateUpdatedByID` | `*string` | :heavy_minus_sign: | The stateUpdatedById field. | -| `SuppressReason` | `*string` | :heavy_minus_sign: | The suppressReason field. | -| `TaskID` | `*string` | :heavy_minus_sign: | The taskId field. | -| `TenantTarget` | [*shared.TenantTarget](../../../pkg/models/shared/tenanttarget.md) | :heavy_minus_sign: | N/A | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `Annotations` | map[string]`string` | :heavy_minus_sign: | Bounded key/value metadata bag. Limits: ≤16 entries; keys 1-128 chars
    matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0-256 chars; total
    serialized ≤4096 bytes. Keys matching ^c1/ are reserved. Also readable
    (and settable) via CEL as both finding.annotations and finding.custom_tags. | +| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | +| `AppResourceTarget` | [*shared.AppResourceTarget](../../../pkg/models/shared/appresourcetarget.md) | :heavy_minus_sign: | N/A | +| `AppUserTarget` | [*shared.AppUserTarget](../../../pkg/models/shared/appusertarget.md) | :heavy_minus_sign: | N/A | +| `AssignedOwner` | [*shared.FindingOwnerRef](../../../pkg/models/shared/findingownerref.md) | :heavy_minus_sign: | N/A | +| `ComputedOwner` | [*shared.FindingOwnerRef](../../../pkg/models/shared/findingownerref.md) | :heavy_minus_sign: | N/A | +| `ConnectorAnomalyDetectionDisabled` | [*shared.ConnectorAnomalyDetectionDisabledType](../../../pkg/models/shared/connectoranomalydetectiondisabledtype.md) | :heavy_minus_sign: | N/A | +| `ConnectorSyncFailing` | [*shared.ConnectorSyncFailingType](../../../pkg/models/shared/connectorsyncfailingtype.md) | :heavy_minus_sign: | N/A | +| `ConnectorSyncFailingEvidence` | [*shared.ConnectorSyncFailingEvidence](../../../pkg/models/shared/connectorsyncfailingevidence.md) | :heavy_minus_sign: | N/A | +| `ConnectorTarget` | [*shared.ConnectorTarget](../../../pkg/models/shared/connectortarget.md) | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `CredentialExpiring` | [*shared.CredentialExpiringType](../../../pkg/models/shared/credentialexpiringtype.md) | :heavy_minus_sign: | N/A | +| `CredentialExpiringEvidence` | [*shared.CredentialExpiringEvidence](../../../pkg/models/shared/credentialexpiringevidence.md) | :heavy_minus_sign: | N/A | +| `CredentialPubliclyExposed` | [*shared.CredentialPubliclyExposedType](../../../pkg/models/shared/credentialpubliclyexposedtype.md) | :heavy_minus_sign: | N/A | +| `CredentialPubliclyExposedEvidence` | [*shared.CredentialPubliclyExposedEvidence](../../../pkg/models/shared/credentialpubliclyexposedevidence.md) | :heavy_minus_sign: | N/A | +| `Custom` | [*shared.CustomFindingType](../../../pkg/models/shared/customfindingtype.md) | :heavy_minus_sign: | N/A | +| `CustomSubType` | `*string` | :heavy_minus_sign: | User-supplied sub-classification for custom findings (e.g. "shadow_it"). | +| ~~`CustomTags`~~ | map[string]`string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: use annotations instead. Read-only mirror of annotations;
    writes to this field are ignored. | +| `DeactivatedOwner` | [*shared.DeactivatedOwnerType](../../../pkg/models/shared/deactivatedownertype.md) | :heavy_minus_sign: | N/A | +| `DeactivatedOwnerEvidence` | [*shared.DeactivatedOwnerEvidence](../../../pkg/models/shared/deactivatedownerevidence.md) | :heavy_minus_sign: | N/A | +| `DecoyCredentialUsed` | [*shared.DecoyCredentialUsedType](../../../pkg/models/shared/decoycredentialusedtype.md) | :heavy_minus_sign: | N/A | +| `DecoyPubliclyExposed` | [*shared.DecoyPubliclyExposedType](../../../pkg/models/shared/decoypubliclyexposedtype.md) | :heavy_minus_sign: | N/A | +| `DecoyPubliclyExposedEvidence` | [*shared.DecoyPubliclyExposedEvidence](../../../pkg/models/shared/decoypubliclyexposedevidence.md) | :heavy_minus_sign: | N/A | +| `DecoyTarget` | [*shared.DecoyTarget](../../../pkg/models/shared/decoytarget.md) | :heavy_minus_sign: | N/A | +| `DedupKeyParts` | []`string` | :heavy_minus_sign: | Caller-supplied dedup identity for custom findings; echoed back so IaC
    clients can roundtrip it. Empty for detector findings. | +| `Description` | `*string` | :heavy_minus_sign: | User-authored finding body (markdown by convention). Set for custom findings. | +| `Fingerprint` | `*string` | :heavy_minus_sign: | The fingerprint field. | +| `FirstObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `IdentityUserTarget` | [*shared.IdentityUserTarget](../../../pkg/models/shared/identityusertarget.md) | :heavy_minus_sign: | N/A | +| `LastAppearedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `LastObservedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `NhiUnowned` | [*shared.NhiUnownedType](../../../pkg/models/shared/nhiunownedtype.md) | :heavy_minus_sign: | N/A | +| `RecurrenceCount` | `*int64` | :heavy_minus_sign: | The recurrenceCount field. | +| `RemediationDescription` | `*string` | :heavy_minus_sign: | The remediationDescription field. | +| `ResolvedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `RiskAcceptanceExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `RiskAcceptanceJustification` | `*string` | :heavy_minus_sign: | The riskAcceptanceJustification field. | +| `RiskScore` | [*shared.FindingRiskScore](../../../pkg/models/shared/findingriskscore.md) | :heavy_minus_sign: | N/A | +| `ServiceAccountMisclassification` | [*shared.ServiceAccountMisclassificationType](../../../pkg/models/shared/serviceaccountmisclassificationtype.md) | :heavy_minus_sign: | N/A | +| `ServiceAccountMisclassificationEvidence` | [*shared.ServiceAccountMisclassificationEvidence](../../../pkg/models/shared/serviceaccountmisclassificationevidence.md) | :heavy_minus_sign: | N/A | +| `ServiceAccountUnowned` | [*shared.ServiceAccountUnownedType](../../../pkg/models/shared/serviceaccountunownedtype.md) | :heavy_minus_sign: | N/A | +| `Severity` | [*shared.FindingSeverity](../../../pkg/models/shared/findingseverity.md) | :heavy_minus_sign: | The severity field. | +| `SimilarUsernameMatch` | [*shared.SimilarUsernameMatchType](../../../pkg/models/shared/similarusernamematchtype.md) | :heavy_minus_sign: | N/A | +| `SimilarUsernameMatchEvidence` | [*shared.SimilarUsernameMatchEvidence](../../../pkg/models/shared/similarusernamematchevidence.md) | :heavy_minus_sign: | N/A | +| `SnoozeReason` | `*string` | :heavy_minus_sign: | The snoozeReason field. | +| `SnoozeUntil` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `SourceDetectorID` | `*string` | :heavy_minus_sign: | The sourceDetectorId field. | +| `SourceKind` | [*shared.SourceKind](../../../pkg/models/shared/sourcekind.md) | :heavy_minus_sign: | Who authored the finding (detector, user, external). | +| `State` | [*shared.FindingState](../../../pkg/models/shared/findingstate.md) | :heavy_minus_sign: | The state field. | +| `StateUpdatedByID` | `*string` | :heavy_minus_sign: | The human who authored the CURRENT state. Empty when a routing rule or the
    system authored it, so do not read a populated value as "this finding has a
    human owner" -- read it as "a human set the state it is in right now". | +| `SuppressReason` | `*string` | :heavy_minus_sign: | The suppressReason field. | +| `TaskID` | `*string` | :heavy_minus_sign: | The taskId field. | +| `TenantTarget` | [*shared.TenantTarget](../../../pkg/models/shared/tenanttarget.md) | :heavy_minus_sign: | N/A | +| `UnusedSecret` | [*shared.UnusedSecretType](../../../pkg/models/shared/unusedsecrettype.md) | :heavy_minus_sign: | N/A | +| `UnusedSecretEvidence` | [*shared.UnusedSecretEvidence](../../../pkg/models/shared/unusedsecretevidence.md) | :heavy_minus_sign: | N/A | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingaudience.md b/docs/pkg/models/shared/findingaudience.md new file mode 100644 index 000000000..4e87f3786 --- /dev/null +++ b/docs/pkg/models/shared/findingaudience.md @@ -0,0 +1,16 @@ +# FindingAudience + +FindingAudience resolves to a set of identity user IDs to notify. Step-less: + notifications have no escalation ladder. An empty resolution falls back to + enabled system owners rather than notifying nobody. + +This message contains a oneof named typ. Only a single field of the following list may be set at a time: + - users + + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Users` | [*shared.FindingAudienceUsers](../../../pkg/models/shared/findingaudienceusers.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingaudienceusers.md b/docs/pkg/models/shared/findingaudienceusers.md new file mode 100644 index 000000000..019373f07 --- /dev/null +++ b/docs/pkg/models/shared/findingaudienceusers.md @@ -0,0 +1,10 @@ +# FindingAudienceUsers + +The FindingAudienceUsers message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `UserIds` | []`string` | :heavy_minus_sign: | The userIds field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingauditeventeventtype.md b/docs/pkg/models/shared/findingauditeventeventtype.md index 2f2b70a67..ab0650fa7 100644 --- a/docs/pkg/models/shared/findingauditeventeventtype.md +++ b/docs/pkg/models/shared/findingauditeventeventtype.md @@ -38,4 +38,6 @@ custom := shared.FindingAuditEventEventType("custom_value") | `FindingAuditEventEventTypeFindingAuditEventTypeTaskCancelled` | FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED | | `FindingAuditEventEventTypeFindingAuditEventTypeEvidenceUpdated` | FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED | | `FindingAuditEventEventTypeFindingAuditEventTypeRoutingEvaluated` | FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED | -| `FindingAuditEventEventTypeFindingAuditEventTypeTransformed` | FINDING_AUDIT_EVENT_TYPE_TRANSFORMED | \ No newline at end of file +| `FindingAuditEventEventTypeFindingAuditEventTypeTransformed` | FINDING_AUDIT_EVENT_TYPE_TRANSFORMED | +| `FindingAuditEventEventTypeFindingAuditEventTypeReprocessRequested` | FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED | +| `FindingAuditEventEventTypeFindingAuditEventTypeReprocessCompleted` | FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingdispatcher.md b/docs/pkg/models/shared/findingdispatcher.md new file mode 100644 index 000000000..9592e9bac --- /dev/null +++ b/docs/pkg/models/shared/findingdispatcher.md @@ -0,0 +1,27 @@ +# FindingDispatcher + +FindingDispatcher is one dispatch that fires when a routing rule matches (the + "Then dispatch" authoring step). A rule carries zero-to-many; every enabled + dispatcher fires, order-independent. + +This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - triggerAutomation + - invokeFunction + - webhook + - notify + + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | Human-facing label. Optional. | +| `Enabled` | `*bool` | :heavy_minus_sign: | Per-dispatcher kill switch. | +| `InvokeFunction` | [*shared.InvokeFunctionDispatcher](../../../pkg/models/shared/invokefunctiondispatcher.md) | :heavy_minus_sign: | N/A | +| `Key` | `*string` | :heavy_minus_sign: | Stable id within the rule; survives edits, part of the dispatch idempotency
    key. Minted server-side when empty. | +| `Notify` | [*shared.NotifyDispatcher](../../../pkg/models/shared/notifydispatcher.md) | :heavy_minus_sign: | N/A | +| `NotifyOnOutcome` | [*shared.FindingDispatchOutcomeNotify](../../../pkg/models/shared/findingdispatchoutcomenotify.md) | :heavy_minus_sign: | N/A | +| `TierOverride` | [*shared.TierOverride](../../../pkg/models/shared/tieroverride.md) | :heavy_minus_sign: | Author tier override; may only tighten the derived tier. | +| `TriggerAutomation` | [*shared.TriggerAutomationDispatcher](../../../pkg/models/shared/triggerautomationdispatcher.md) | :heavy_minus_sign: | N/A | +| `Webhook` | [*shared.WebhookDispatcher](../../../pkg/models/shared/webhookdispatcher.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingdispatchoutcomenotify.md b/docs/pkg/models/shared/findingdispatchoutcomenotify.md new file mode 100644 index 000000000..b6dafe527 --- /dev/null +++ b/docs/pkg/models/shared/findingdispatchoutcomenotify.md @@ -0,0 +1,12 @@ +# FindingDispatchOutcomeNotify + +FindingDispatchOutcomeNotify notifies recipients once a dispatch settles. + + +## Fields + +| Field | Type | Required | Description | +| --------------------- | --------------------- | --------------------- | --------------------- | +| `OnDone` | `*bool` | :heavy_minus_sign: | The onDone field. | +| `OnError` | `*bool` | :heavy_minus_sign: | The onError field. | +| `Recipients` | []`string` | :heavy_minus_sign: | The recipients field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingroutingrule.md b/docs/pkg/models/shared/findingroutingrule.md index 1928d5109..3879fc91f 100644 --- a/docs/pkg/models/shared/findingroutingrule.md +++ b/docs/pkg/models/shared/findingroutingrule.md @@ -12,8 +12,10 @@ The FindingRoutingRule message. | `Condition` | `*string` | :heavy_minus_sign: | The condition field. | | `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | | `Description` | `*string` | :heavy_minus_sign: | The description field. | +| `Dispatchers` | [][shared.FindingDispatcher](../../../pkg/models/shared/findingdispatcher.md) | :heavy_minus_sign: | Dispatchers that fire when the rule matches ("Then dispatch"). Max 10. | | `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | | `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | +| `FindingType` | [*shared.FindingType](../../../pkg/models/shared/findingtype.md) | :heavy_minus_sign: | The findingType field. | | `ID` | `*string` | :heavy_minus_sign: | The id field. | | `Priority` | `*int` | :heavy_minus_sign: | The priority field. | | `TemplateID` | `*string` | :heavy_minus_sign: | The templateId field. | diff --git a/docs/pkg/models/shared/findingsearchrequest.md b/docs/pkg/models/shared/findingsearchrequest.md index dd9200312..d92a4200b 100644 --- a/docs/pkg/models/shared/findingsearchrequest.md +++ b/docs/pkg/models/shared/findingsearchrequest.md @@ -18,7 +18,7 @@ The FindingSearchRequest message. | `DecoyIds` | []`string` | :heavy_minus_sign: | Filter by decoy IDs (OR within field). Matches findings whose
    target.decoy_target.decoy_id is in this list. | | `FindingTypes` | [][shared.FindingTypes](../../../pkg/models/shared/findingtypes.md) | :heavy_minus_sign: | Filter by finding type (OR within field). | | `IncludeUnassigned` | `*bool` | :heavy_minus_sign: | When true, includes findings with no effective identity-user owner. An
    explicit predicate for direct API callers who prefer a bool over the
    "unassigned" sentinel in owner_identity_user_ids; both signals are accepted. | -| `NhiTypes` | [][shared.NhiTypes](../../../pkg/models/shared/nhitypes.md) | :heavy_minus_sign: | Filter to findings whose target resource's nhi_type is one of these (OR
    within field). Empty = not applied; pass all NhiType values to match any
    nhi resource. | +| `NhiTypes` | [][shared.FindingSearchRequestNhiTypes](../../../pkg/models/shared/findingsearchrequestnhitypes.md) | :heavy_minus_sign: | Filter to findings whose target resource's nhi_type is one of these (OR
    within field). Empty = not applied; pass all NhiType values to match any
    nhi resource. | | `OwnerIdentityUserIds` | []`string` | :heavy_minus_sign: | Filter by effective owner identity-user IDs (OR within field). Matches
    findings whose effective owner (assigned_owner if set, else computed_owner)
    resolves to an identity user in this list. The reserved "unassigned"
    sentinel token selects findings with no effective identity-user owner; real
    identity-user IDs are exactly 27 alphanumerics so the token cannot collide. | | `PageSize` | `*int` | :heavy_minus_sign: | Maximum number of findings to return per page. | | `PageToken` | `*string` | :heavy_minus_sign: | Pagination token from a previous response. | diff --git a/docs/pkg/models/shared/findingsearchrequestnhitypes.md b/docs/pkg/models/shared/findingsearchrequestnhitypes.md new file mode 100644 index 000000000..8863d72ee --- /dev/null +++ b/docs/pkg/models/shared/findingsearchrequestnhitypes.md @@ -0,0 +1,24 @@ +# FindingSearchRequestNhiTypes + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FindingSearchRequestNhiTypesNhiTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FindingSearchRequestNhiTypes("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------------------- | ---------------------------------------------------- | +| `FindingSearchRequestNhiTypesNhiTypeUnspecified` | NHI_TYPE_UNSPECIFIED | +| `FindingSearchRequestNhiTypesNhiTypeAppRegistration` | NHI_TYPE_APP_REGISTRATION | +| `FindingSearchRequestNhiTypesNhiTypeAssumableRole` | NHI_TYPE_ASSUMABLE_ROLE | +| `FindingSearchRequestNhiTypesNhiTypeManagedIdentity` | NHI_TYPE_MANAGED_IDENTITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingsettingsentry.md b/docs/pkg/models/shared/findingsettingsentry.md new file mode 100644 index 000000000..f3100e4b6 --- /dev/null +++ b/docs/pkg/models/shared/findingsettingsentry.md @@ -0,0 +1,15 @@ +# FindingSettingsEntry + +FindingSettingsEntry is a requested change to one type, which is why it is a + separate message from FindingTypeSetting rather than the same one reused: an + update needs enum validation and presence on `enabled` so an omitted field is + an error, while a response always carries a value and must not make callers + handle an absent one. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `Enabled` | `*bool` | :heavy_minus_sign: | Target state. Required: explicit presence keeps an omitted field from
    reading as false and silently switching a detector off. | +| `FindingType` | [*shared.FindingSettingsEntryFindingType](../../../pkg/models/shared/findingsettingsentryfindingtype.md) | :heavy_minus_sign: | The finding type to configure. Must be a detector-backed type. | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingsettingsentryfindingtype.md b/docs/pkg/models/shared/findingsettingsentryfindingtype.md new file mode 100644 index 000000000..d4fc97f48 --- /dev/null +++ b/docs/pkg/models/shared/findingsettingsentryfindingtype.md @@ -0,0 +1,36 @@ +# FindingSettingsEntryFindingType + +The finding type to configure. Must be a detector-backed type. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FindingSettingsEntryFindingTypeFindingTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FindingSettingsEntryFindingType("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `FindingSettingsEntryFindingTypeFindingTypeUnspecified` | FINDING_TYPE_UNSPECIFIED | +| `FindingSettingsEntryFindingTypeFindingTypeSimilarUsernameMatch` | FINDING_TYPE_SIMILAR_USERNAME_MATCH | +| `FindingSettingsEntryFindingTypeFindingTypeServiceAccountMisclassification` | FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION | +| `FindingSettingsEntryFindingTypeFindingTypeNhiUnowned` | FINDING_TYPE_NHI_UNOWNED | +| `FindingSettingsEntryFindingTypeFindingTypeServiceAccountUnowned` | FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED | +| `FindingSettingsEntryFindingTypeFindingTypeDecoyCredentialUsed` | FINDING_TYPE_DECOY_CREDENTIAL_USED | +| `FindingSettingsEntryFindingTypeFindingTypeCustom` | FINDING_TYPE_CUSTOM | +| `FindingSettingsEntryFindingTypeFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | +| `FindingSettingsEntryFindingTypeFindingTypeDeactivatedOwner` | FINDING_TYPE_DEACTIVATED_OWNER | +| `FindingSettingsEntryFindingTypeFindingTypeUnusedSecret` | FINDING_TYPE_UNUSED_SECRET | +| `FindingSettingsEntryFindingTypeFindingTypeCredentialPubliclyExposed` | FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED | +| `FindingSettingsEntryFindingTypeFindingTypeDecoyPubliclyExposed` | FINDING_TYPE_DECOY_PUBLICLY_EXPOSED | +| `FindingSettingsEntryFindingTypeFindingTypeCredentialExpiring` | FINDING_TYPE_CREDENTIAL_EXPIRING | +| `FindingSettingsEntryFindingTypeFindingTypeConnectorSyncFailing` | FINDING_TYPE_CONNECTOR_SYNC_FAILING | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingtransformationrule.md b/docs/pkg/models/shared/findingtransformationrule.md index db74f4ff8..7e6d42dc3 100644 --- a/docs/pkg/models/shared/findingtransformationrule.md +++ b/docs/pkg/models/shared/findingtransformationrule.md @@ -16,6 +16,7 @@ FindingTransformationRule transforms a finding at processing time, before | `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | | `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | | `EvaluationOrder` | `*int` | :heavy_minus_sign: | Application order (ascending; last-applied rule wins per field). A sequence,
    not a precedence rank. | +| `FindingType` | [*shared.FindingTransformationRuleFindingType](../../../pkg/models/shared/findingtransformationrulefindingtype.md) | :heavy_minus_sign: | The findingType field. | | `ID` | `*string` | :heavy_minus_sign: | The id field. | | `TemplateID` | `*string` | :heavy_minus_sign: | The templateId field. | | `Transforms` | [][shared.FindingTransform](../../../pkg/models/shared/findingtransform.md) | :heavy_minus_sign: | Ordered transforms applied when the rule matches. | diff --git a/docs/pkg/models/shared/findingtransformationrulefindingtype.md b/docs/pkg/models/shared/findingtransformationrulefindingtype.md new file mode 100644 index 000000000..4d78998f5 --- /dev/null +++ b/docs/pkg/models/shared/findingtransformationrulefindingtype.md @@ -0,0 +1,36 @@ +# FindingTransformationRuleFindingType + +The findingType field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FindingTransformationRuleFindingTypeFindingTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FindingTransformationRuleFindingType("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `FindingTransformationRuleFindingTypeFindingTypeUnspecified` | FINDING_TYPE_UNSPECIFIED | +| `FindingTransformationRuleFindingTypeFindingTypeSimilarUsernameMatch` | FINDING_TYPE_SIMILAR_USERNAME_MATCH | +| `FindingTransformationRuleFindingTypeFindingTypeServiceAccountMisclassification` | FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION | +| `FindingTransformationRuleFindingTypeFindingTypeNhiUnowned` | FINDING_TYPE_NHI_UNOWNED | +| `FindingTransformationRuleFindingTypeFindingTypeServiceAccountUnowned` | FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED | +| `FindingTransformationRuleFindingTypeFindingTypeDecoyCredentialUsed` | FINDING_TYPE_DECOY_CREDENTIAL_USED | +| `FindingTransformationRuleFindingTypeFindingTypeCustom` | FINDING_TYPE_CUSTOM | +| `FindingTransformationRuleFindingTypeFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | +| `FindingTransformationRuleFindingTypeFindingTypeDeactivatedOwner` | FINDING_TYPE_DEACTIVATED_OWNER | +| `FindingTransformationRuleFindingTypeFindingTypeUnusedSecret` | FINDING_TYPE_UNUSED_SECRET | +| `FindingTransformationRuleFindingTypeFindingTypeCredentialPubliclyExposed` | FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED | +| `FindingTransformationRuleFindingTypeFindingTypeDecoyPubliclyExposed` | FINDING_TYPE_DECOY_PUBLICLY_EXPOSED | +| `FindingTransformationRuleFindingTypeFindingTypeCredentialExpiring` | FINDING_TYPE_CREDENTIAL_EXPIRING | +| `FindingTransformationRuleFindingTypeFindingTypeConnectorSyncFailing` | FINDING_TYPE_CONNECTOR_SYNC_FAILING | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingtype.md b/docs/pkg/models/shared/findingtype.md new file mode 100644 index 000000000..709e92437 --- /dev/null +++ b/docs/pkg/models/shared/findingtype.md @@ -0,0 +1,36 @@ +# FindingType + +The findingType field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FindingTypeFindingTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FindingType("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------------- | --------------------------------------------------------- | +| `FindingTypeFindingTypeUnspecified` | FINDING_TYPE_UNSPECIFIED | +| `FindingTypeFindingTypeSimilarUsernameMatch` | FINDING_TYPE_SIMILAR_USERNAME_MATCH | +| `FindingTypeFindingTypeServiceAccountMisclassification` | FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION | +| `FindingTypeFindingTypeNhiUnowned` | FINDING_TYPE_NHI_UNOWNED | +| `FindingTypeFindingTypeServiceAccountUnowned` | FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED | +| `FindingTypeFindingTypeDecoyCredentialUsed` | FINDING_TYPE_DECOY_CREDENTIAL_USED | +| `FindingTypeFindingTypeCustom` | FINDING_TYPE_CUSTOM | +| `FindingTypeFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | +| `FindingTypeFindingTypeDeactivatedOwner` | FINDING_TYPE_DEACTIVATED_OWNER | +| `FindingTypeFindingTypeUnusedSecret` | FINDING_TYPE_UNUSED_SECRET | +| `FindingTypeFindingTypeCredentialPubliclyExposed` | FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED | +| `FindingTypeFindingTypeDecoyPubliclyExposed` | FINDING_TYPE_DECOY_PUBLICLY_EXPOSED | +| `FindingTypeFindingTypeCredentialExpiring` | FINDING_TYPE_CREDENTIAL_EXPIRING | +| `FindingTypeFindingTypeConnectorSyncFailing` | FINDING_TYPE_CONNECTOR_SYNC_FAILING | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingtypes.md b/docs/pkg/models/shared/findingtypes.md index 9f777030c..67d2e8ebc 100644 --- a/docs/pkg/models/shared/findingtypes.md +++ b/docs/pkg/models/shared/findingtypes.md @@ -25,4 +25,10 @@ custom := shared.FindingTypes("custom_value") | `FindingTypesFindingTypeServiceAccountUnowned` | FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED | | `FindingTypesFindingTypeDecoyCredentialUsed` | FINDING_TYPE_DECOY_CREDENTIAL_USED | | `FindingTypesFindingTypeCustom` | FINDING_TYPE_CUSTOM | -| `FindingTypesFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | \ No newline at end of file +| `FindingTypesFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | +| `FindingTypesFindingTypeDeactivatedOwner` | FINDING_TYPE_DEACTIVATED_OWNER | +| `FindingTypesFindingTypeUnusedSecret` | FINDING_TYPE_UNUSED_SECRET | +| `FindingTypesFindingTypeCredentialPubliclyExposed` | FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED | +| `FindingTypesFindingTypeDecoyPubliclyExposed` | FINDING_TYPE_DECOY_PUBLICLY_EXPOSED | +| `FindingTypesFindingTypeCredentialExpiring` | FINDING_TYPE_CREDENTIAL_EXPIRING | +| `FindingTypesFindingTypeConnectorSyncFailing` | FINDING_TYPE_CONNECTOR_SYNC_FAILING | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingtypesetting.md b/docs/pkg/models/shared/findingtypesetting.md new file mode 100644 index 000000000..2a4766cdc --- /dev/null +++ b/docs/pkg/models/shared/findingtypesetting.md @@ -0,0 +1,15 @@ +# FindingTypeSetting + +FindingTypeSetting is one finding type's detection switch as it currently + stands. Named for a single type on purpose: the stored model + c1.models.finding.v1.FindingSettings is the tenant-wide object holding every + type, and one name for both granularities reads as the same thing twice. + Display copy for the type is client-owned; this carries state only. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Enabled` | `*bool` | :heavy_minus_sign: | Whether the system detects this finding type. Types never configured read
    back their shipped default, which is per type rather than uniformly on. | +| `FindingType` | [*shared.FindingTypeSettingFindingType](../../../pkg/models/shared/findingtypesettingfindingtype.md) | :heavy_minus_sign: | The findingType field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/findingtypesettingfindingtype.md b/docs/pkg/models/shared/findingtypesettingfindingtype.md new file mode 100644 index 000000000..2cd5167df --- /dev/null +++ b/docs/pkg/models/shared/findingtypesettingfindingtype.md @@ -0,0 +1,36 @@ +# FindingTypeSettingFindingType + +The findingType field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FindingTypeSettingFindingTypeFindingTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FindingTypeSettingFindingType("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | +| `FindingTypeSettingFindingTypeFindingTypeUnspecified` | FINDING_TYPE_UNSPECIFIED | +| `FindingTypeSettingFindingTypeFindingTypeSimilarUsernameMatch` | FINDING_TYPE_SIMILAR_USERNAME_MATCH | +| `FindingTypeSettingFindingTypeFindingTypeServiceAccountMisclassification` | FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION | +| `FindingTypeSettingFindingTypeFindingTypeNhiUnowned` | FINDING_TYPE_NHI_UNOWNED | +| `FindingTypeSettingFindingTypeFindingTypeServiceAccountUnowned` | FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED | +| `FindingTypeSettingFindingTypeFindingTypeDecoyCredentialUsed` | FINDING_TYPE_DECOY_CREDENTIAL_USED | +| `FindingTypeSettingFindingTypeFindingTypeCustom` | FINDING_TYPE_CUSTOM | +| `FindingTypeSettingFindingTypeFindingTypeConnectorAnomalyDetectionDisabled` | FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED | +| `FindingTypeSettingFindingTypeFindingTypeDeactivatedOwner` | FINDING_TYPE_DEACTIVATED_OWNER | +| `FindingTypeSettingFindingTypeFindingTypeUnusedSecret` | FINDING_TYPE_UNUSED_SECRET | +| `FindingTypeSettingFindingTypeFindingTypeCredentialPubliclyExposed` | FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED | +| `FindingTypeSettingFindingTypeFindingTypeDecoyPubliclyExposed` | FINDING_TYPE_DECOY_PUBLICLY_EXPOSED | +| `FindingTypeSettingFindingTypeFindingTypeCredentialExpiring` | FINDING_TYPE_CREDENTIAL_EXPIRING | +| `FindingTypeSettingFindingTypeFindingTypeConnectorSyncFailing` | FINDING_TYPE_CONNECTOR_SYNC_FAILING | \ No newline at end of file diff --git a/docs/pkg/models/shared/forcesyncresponse.md b/docs/pkg/models/shared/forcesyncresponse.md index 56a995716..f4573b3e5 100644 --- a/docs/pkg/models/shared/forcesyncresponse.md +++ b/docs/pkg/models/shared/forcesyncresponse.md @@ -1,6 +1,7 @@ # ForceSyncResponse -Empty response body. Status code indicates success. +Empty response body. Status code indicates success. Poll the connector sync status + for progress after ForceSync accepts the request. ## Fields diff --git a/docs/pkg/models/shared/format.md b/docs/pkg/models/shared/format.md index 2813deae1..e69139973 100644 --- a/docs/pkg/models/shared/format.md +++ b/docs/pkg/models/shared/format.md @@ -1,7 +1,9 @@ # Format -Wire format the provider expects. Defaults to - FORMAT_JSON_OBJECT. +Output format for the report. When unspecified, programmatic public-API + callers (REST gateway and MCP) get JSON and the in-app UI gets XLSX. JSON + and CSV return the per-decision certification rows; XLSX returns the full + multi-sheet Excel workbook. ## Example Usage @@ -10,7 +12,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.FormatFormatJSONObject +value := shared.FormatAccessReviewReportFormatUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.Format("custom_value") @@ -19,8 +21,9 @@ custom := shared.Format("custom_value") ## Values -| Name | Value | -| --------------------------------- | --------------------------------- | -| `FormatFormatJSONObject` | FORMAT_JSON_OBJECT | -| `FormatFormatColonSeparated` | FORMAT_COLON_SEPARATED | -| `FormatFormatUnderscoreSeparated` | FORMAT_UNDERSCORE_SEPARATED | \ No newline at end of file +| Name | Value | +| ------------------------------------------- | ------------------------------------------- | +| `FormatAccessReviewReportFormatUnspecified` | ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED | +| `FormatAccessReviewReportFormatXlsx` | ACCESS_REVIEW_REPORT_FORMAT_XLSX | +| `FormatAccessReviewReportFormatJSON` | ACCESS_REVIEW_REPORT_FORMAT_JSON | +| `FormatAccessReviewReportFormatCsv` | ACCESS_REVIEW_REPORT_FORMAT_CSV | \ No newline at end of file diff --git a/docs/pkg/models/shared/formstringfield.md b/docs/pkg/models/shared/formstringfield.md index c8248da8c..09a80517d 100644 --- a/docs/pkg/models/shared/formstringfield.md +++ b/docs/pkg/models/shared/formstringfield.md @@ -7,6 +7,7 @@ This message contains a oneof named view. Only a single field of the following l - passwordField - selectField - pickerField + - dateField @@ -14,6 +15,7 @@ This message contains a oneof named view. Only a single field of the following l | Field | Type | Required | Description | | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | +| `DateField` | [*shared.DateField](../../../pkg/models/shared/datefield.md) | :heavy_minus_sign: | N/A | | `DefaultValue` | `*string` | :heavy_minus_sign: | The defaultValue field. | | `PasswordField` | [*shared.PasswordField](../../../pkg/models/shared/passwordfield.md) | :heavy_minus_sign: | N/A | | `PickerField` | [*shared.PickerField](../../../pkg/models/shared/pickerfield.md) | :heavy_minus_sign: | N/A | diff --git a/docs/pkg/models/shared/function.md b/docs/pkg/models/shared/function.md index 10b6b3dfc..9aa3d3f75 100644 --- a/docs/pkg/models/shared/function.md +++ b/docs/pkg/models/shared/function.md @@ -13,6 +13,7 @@ Function represents a customer-provided code extension in the API | `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | | `FunctionType` | [*shared.FunctionType](../../../pkg/models/shared/functiontype.md) | :heavy_minus_sign: | The functionType field. | | `Head` | `*string` | :heavy_minus_sign: | The head field. | +| `HookRefs` | []`string` | :heavy_minus_sign: | IDs of every non-deleted hook that still references this function.
    Read-only: maintained by the Hook API, not by CreateFunction/UpdateFunction.
    Non-empty means DeleteFunction will refuse to delete until these are
    removed or retargeted. | | `ID` | `*string` | :heavy_minus_sign: | The id field. | | `IsDraft` | `*bool` | :heavy_minus_sign: | The isDraft field. | | `OutboundNetworkAllowlist` | []`string` | :heavy_minus_sign: | The outboundNetworkAllowlist field. | @@ -21,4 +22,5 @@ Function represents a customer-provided code extension in the API | `ScopedRoleIds` | []`string` | :heavy_minus_sign: | Scoped role IDs define the permissions granted to this function when calling
    ConductorOne APIs. These are role IDs (not service roles) that get resolved
    to their service roles at authentication time.

    Currently only the "Read-Only Administrator" role (system:viewer) is supported.
    The role ID can be obtained from the roles API. | | `Secret` | map[string]`string` | :heavy_minus_sign: | The secret field. | | `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `UseSpn` | `*bool` | :heavy_minus_sign: | FN-347 transition flag. When true, the function authenticates to c1-api
    as user: via the AssumeIdentity token exchange using its
    ServicePrincipalBinding; when false, it authenticates as
    function:. Read-only from clients: set by CreateFunction (when the
    tenant has completed the FunctionsToSPN migration) and by the migration
    itself, never by UpdateFunction. Retired once all functions are on SPN. | \ No newline at end of file +| `UseSpn` | `*bool` | :heavy_minus_sign: | FN-347 transition flag. When true, the function authenticates to c1-api
    as user: via the AssumeIdentity token exchange using its
    ServicePrincipalBinding; when false, it authenticates as
    function:. Read-only from clients: set by CreateFunction (when the
    tenant has completed the FunctionsToSPN migration) and by the migration
    itself, never by UpdateFunction. Retired once all functions are on SPN. | +| `WorkflowTemplateRefs` | []`string` | :heavy_minus_sign: | IDs of every non-deleted workflow template whose CallFunction step still
    references this function. Read-only, same semantics as hook_refs. | \ No newline at end of file diff --git a/docs/pkg/models/shared/functionsserviceupdatefunctionrequest.md b/docs/pkg/models/shared/functionsserviceupdatefunctionrequest.md index ce2fcdea7..583a8ff5f 100644 --- a/docs/pkg/models/shared/functionsserviceupdatefunctionrequest.md +++ b/docs/pkg/models/shared/functionsserviceupdatefunctionrequest.md @@ -5,7 +5,9 @@ The FunctionsServiceUpdateFunctionRequest message. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -| `Function` | [*shared.FunctionInput](../../../pkg/models/shared/functioninput.md) | :heavy_minus_sign: | N/A | -| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CommitMessage` | `*string` | :heavy_minus_sign: | The commit message describing this code update. Defaults to a generic
    message if content is set and this is empty. Ignored if content is empty. | +| `Content` | map[string]`string` | :heavy_minus_sign: | File map for a new code commit, applied as the function's new head
    commit. Keys are file paths in the function root; values are file
    contents as bytes. See CreateFunctionRequest.initial_content for the
    required entry-file signature. Independent of update_mask. | +| `Function` | [*shared.FunctionInput](../../../pkg/models/shared/functioninput.md) | :heavy_minus_sign: | N/A | +| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/functionsserviceupdatefunctionresponse.md b/docs/pkg/models/shared/functionsserviceupdatefunctionresponse.md index c7c255987..22440339a 100644 --- a/docs/pkg/models/shared/functionsserviceupdatefunctionresponse.md +++ b/docs/pkg/models/shared/functionsserviceupdatefunctionresponse.md @@ -5,6 +5,7 @@ The FunctionsServiceUpdateFunctionResponse message. ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `Function` | [*shared.Function](../../../pkg/models/shared/function.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Commit` | [*shared.FunctionCommit](../../../pkg/models/shared/functioncommit.md) | :heavy_minus_sign: | N/A | +| `Function` | [*shared.Function](../../../pkg/models/shared/function.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignment.md b/docs/pkg/models/shared/fundassignment.md new file mode 100644 index 000000000..9ef7fd452 --- /dev/null +++ b/docs/pkg/models/shared/fundassignment.md @@ -0,0 +1,14 @@ +# FundAssignment + +FundAssignment is one principal's fund exception as the API renders it. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | +| `Controls` | [*shared.SpendControls](../../../pkg/models/shared/spendcontrols.md) | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `UserID` | `*string` | :heavy_minus_sign: | Canonical c1.models.user.v2.User id, every UserType. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmenthistoryentry.md b/docs/pkg/models/shared/fundassignmenthistoryentry.md new file mode 100644 index 000000000..638dbbfc2 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmenthistoryentry.md @@ -0,0 +1,11 @@ +# FundAssignmentHistoryEntry + +The FundAssignmentHistoryEntry message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentserviceclearextensionrequest.md b/docs/pkg/models/shared/fundassignmentserviceclearextensionrequest.md new file mode 100644 index 000000000..d5d573123 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentserviceclearextensionrequest.md @@ -0,0 +1,9 @@ +# FundAssignmentServiceClearExtensionRequest + +The FundAssignmentServiceClearExtensionRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentserviceclearextensionresponse.md b/docs/pkg/models/shared/fundassignmentserviceclearextensionresponse.md new file mode 100644 index 000000000..ce558d306 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentserviceclearextensionresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceClearExtensionResponse + +The FundAssignmentServiceClearExtensionResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicedeleterequest.md b/docs/pkg/models/shared/fundassignmentservicedeleterequest.md new file mode 100644 index 000000000..a780af739 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicedeleterequest.md @@ -0,0 +1,9 @@ +# FundAssignmentServiceDeleteRequest + +The FundAssignmentServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicedeleteresponse.md b/docs/pkg/models/shared/fundassignmentservicedeleteresponse.md new file mode 100644 index 000000000..7145c8af7 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicedeleteresponse.md @@ -0,0 +1,9 @@ +# FundAssignmentServiceDeleteResponse + +The FundAssignmentServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicegetresponse.md b/docs/pkg/models/shared/fundassignmentservicegetresponse.md new file mode 100644 index 000000000..78ab2c978 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicegetresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceGetResponse + +The FundAssignmentServiceGetResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicegrantextensionrequest.md b/docs/pkg/models/shared/fundassignmentservicegrantextensionrequest.md new file mode 100644 index 000000000..ab2d050bf --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicegrantextensionrequest.md @@ -0,0 +1,12 @@ +# FundAssignmentServiceGrantExtensionRequest + +The FundAssignmentServiceGrantExtensionRequest message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `ExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Reason` | `*string` | :heavy_minus_sign: | Subject-visible: "why do I have this bump". | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicegrantextensionresponse.md b/docs/pkg/models/shared/fundassignmentservicegrantextensionresponse.md new file mode 100644 index 000000000..7c4f84471 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicegrantextensionresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceGrantExtensionResponse + +The FundAssignmentServiceGrantExtensionResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicelisthistoryresponse.md b/docs/pkg/models/shared/fundassignmentservicelisthistoryresponse.md new file mode 100644 index 000000000..430c6853d --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# FundAssignmentServiceListHistoryResponse + +The FundAssignmentServiceListHistoryResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | +| `List` | [][shared.FundAssignmentHistoryEntry](../../../pkg/models/shared/fundassignmenthistoryentry.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesearchrequest.md b/docs/pkg/models/shared/fundassignmentservicesearchrequest.md new file mode 100644 index 000000000..dab4ed1c2 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesearchrequest.md @@ -0,0 +1,12 @@ +# FundAssignmentServiceSearchRequest + +The FundAssignmentServiceSearchRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------- | +| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize field. | +| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | +| `UserIds` | []`string` | :heavy_minus_sign: | Restrict to these subjects; empty returns every assignment in the tenant. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesearchresponse.md b/docs/pkg/models/shared/fundassignmentservicesearchresponse.md new file mode 100644 index 000000000..2cade0554 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesearchresponse.md @@ -0,0 +1,11 @@ +# FundAssignmentServiceSearchResponse + +The FundAssignmentServiceSearchResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | +| `List` | [][shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesetlimitrequest.md b/docs/pkg/models/shared/fundassignmentservicesetlimitrequest.md new file mode 100644 index 000000000..709d0c6aa --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesetlimitrequest.md @@ -0,0 +1,11 @@ +# FundAssignmentServiceSetLimitRequest + +The FundAssignmentServiceSetLimitRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.FundAssignmentServiceSetLimitRequestPeriod](../../../pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md) | :heavy_minus_sign: | Optional period override. Only valid together with the limit it denominates. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md b/docs/pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md new file mode 100644 index 000000000..f1e5f7fac --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesetlimitrequestperiod.md @@ -0,0 +1,28 @@ +# FundAssignmentServiceSetLimitRequestPeriod + +Optional period override. Only valid together with the limit it denominates. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FundAssignmentServiceSetLimitRequestPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FundAssignmentServiceSetLimitRequestPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------- | ----------------------------------------------------------------- | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `FundAssignmentServiceSetLimitRequestPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesetlimitresponse.md b/docs/pkg/models/shared/fundassignmentservicesetlimitresponse.md new file mode 100644 index 000000000..ed36dfe53 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesetlimitresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceSetLimitResponse + +The FundAssignmentServiceSetLimitResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesuspendrequest.md b/docs/pkg/models/shared/fundassignmentservicesuspendrequest.md new file mode 100644 index 000000000..2433961ca --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesuspendrequest.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceSuspendRequest + +The FundAssignmentServiceSuspendRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentservicesuspendresponse.md b/docs/pkg/models/shared/fundassignmentservicesuspendresponse.md new file mode 100644 index 000000000..6ec18861f --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentservicesuspendresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceSuspendResponse + +The FundAssignmentServiceSuspendResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentserviceunsuspendrequest.md b/docs/pkg/models/shared/fundassignmentserviceunsuspendrequest.md new file mode 100644 index 000000000..9ca1ca7f3 --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentserviceunsuspendrequest.md @@ -0,0 +1,9 @@ +# FundAssignmentServiceUnsuspendRequest + +The FundAssignmentServiceUnsuspendRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundassignmentserviceunsuspendresponse.md b/docs/pkg/models/shared/fundassignmentserviceunsuspendresponse.md new file mode 100644 index 000000000..bf73c8d0f --- /dev/null +++ b/docs/pkg/models/shared/fundassignmentserviceunsuspendresponse.md @@ -0,0 +1,10 @@ +# FundAssignmentServiceUnsuspendResponse + +The FundAssignmentServiceUnsuspendResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Assignment` | [*shared.FundAssignment](../../../pkg/models/shared/fundassignment.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicy.md b/docs/pkg/models/shared/fundpolicy.md new file mode 100644 index 000000000..775392ffe --- /dev/null +++ b/docs/pkg/models/shared/fundpolicy.md @@ -0,0 +1,18 @@ +# FundPolicy + +FundPolicy is the tenant's fund policy as the API renders it. Every field is + server-owned on the way out; requests name the fields they change rather than + sending this message back. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `CurrencyCode` | `*string` | :heavy_minus_sign: | ISO 4217. Set at Create and immutable thereafter. | +| `DefaultLimit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `OrgCeiling` | [*shared.SpendControls](../../../pkg/models/shared/spendcontrols.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.FundPolicyPeriod](../../../pkg/models/shared/fundpolicyperiod.md) | :heavy_minus_sign: | The root period every amount in the tenant is denominated in. | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyhistoryentry.md b/docs/pkg/models/shared/fundpolicyhistoryentry.md new file mode 100644 index 000000000..2d4360c6b --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyhistoryentry.md @@ -0,0 +1,11 @@ +# FundPolicyHistoryEntry + +The FundPolicyHistoryEntry message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyperiod.md b/docs/pkg/models/shared/fundpolicyperiod.md new file mode 100644 index 000000000..40e63966f --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyperiod.md @@ -0,0 +1,28 @@ +# FundPolicyPeriod + +The root period every amount in the tenant is denominated in. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FundPolicyPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FundPolicyPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------- | --------------------------------------- | +| `FundPolicyPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `FundPolicyPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `FundPolicyPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `FundPolicyPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `FundPolicyPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `FundPolicyPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicecreaterequest.md b/docs/pkg/models/shared/fundpolicyservicecreaterequest.md new file mode 100644 index 000000000..f3cb1deb0 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicecreaterequest.md @@ -0,0 +1,12 @@ +# FundPolicyServiceCreateRequest + +The FundPolicyServiceCreateRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `CurrencyCode` | `*string` | :heavy_minus_sign: | ISO 4217. Immutable once set. | +| `DefaultLimit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.FundPolicyServiceCreateRequestPeriod](../../../pkg/models/shared/fundpolicyservicecreaterequestperiod.md) | :heavy_minus_sign: | The period field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicecreaterequestperiod.md b/docs/pkg/models/shared/fundpolicyservicecreaterequestperiod.md new file mode 100644 index 000000000..9c03c837b --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicecreaterequestperiod.md @@ -0,0 +1,28 @@ +# FundPolicyServiceCreateRequestPeriod + +The period field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FundPolicyServiceCreateRequestPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FundPolicyServiceCreateRequestPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------- | ----------------------------------------------------------- | +| `FundPolicyServiceCreateRequestPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `FundPolicyServiceCreateRequestPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `FundPolicyServiceCreateRequestPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `FundPolicyServiceCreateRequestPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `FundPolicyServiceCreateRequestPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `FundPolicyServiceCreateRequestPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicecreateresponse.md b/docs/pkg/models/shared/fundpolicyservicecreateresponse.md new file mode 100644 index 000000000..7da0b6107 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicecreateresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceCreateResponse + +The FundPolicyServiceCreateResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicedeleterequest.md b/docs/pkg/models/shared/fundpolicyservicedeleterequest.md new file mode 100644 index 000000000..5f3c7cb0a --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicedeleterequest.md @@ -0,0 +1,9 @@ +# FundPolicyServiceDeleteRequest + +The FundPolicyServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicedeleteresponse.md b/docs/pkg/models/shared/fundpolicyservicedeleteresponse.md new file mode 100644 index 000000000..78df7b105 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicedeleteresponse.md @@ -0,0 +1,9 @@ +# FundPolicyServiceDeleteResponse + +The FundPolicyServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicefreezetenantrequest.md b/docs/pkg/models/shared/fundpolicyservicefreezetenantrequest.md new file mode 100644 index 000000000..1d729bb66 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicefreezetenantrequest.md @@ -0,0 +1,10 @@ +# FundPolicyServiceFreezeTenantRequest + +The FundPolicyServiceFreezeTenantRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicefreezetenantresponse.md b/docs/pkg/models/shared/fundpolicyservicefreezetenantresponse.md new file mode 100644 index 000000000..917ffb4b7 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicefreezetenantresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceFreezeTenantResponse + +The FundPolicyServiceFreezeTenantResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicegetresponse.md b/docs/pkg/models/shared/fundpolicyservicegetresponse.md new file mode 100644 index 000000000..050f44401 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicegetresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceGetResponse + +The FundPolicyServiceGetResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicelisthistoryresponse.md b/docs/pkg/models/shared/fundpolicyservicelisthistoryresponse.md new file mode 100644 index 000000000..559deee36 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# FundPolicyServiceListHistoryResponse + +The FundPolicyServiceListHistoryResponse message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | +| `List` | [][shared.FundPolicyHistoryEntry](../../../pkg/models/shared/fundpolicyhistoryentry.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequest.md b/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequest.md new file mode 100644 index 000000000..a0b23faa6 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequest.md @@ -0,0 +1,11 @@ +# FundPolicyServiceSetOrgCeilingRequest + +The FundPolicyServiceSetOrgCeilingRequest message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.FundPolicyServiceSetOrgCeilingRequestPeriod](../../../pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md) | :heavy_minus_sign: | Optional period override for the ceiling. Only valid together with limit. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md b/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md new file mode 100644 index 000000000..b4c7f2e89 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicesetorgceilingrequestperiod.md @@ -0,0 +1,28 @@ +# FundPolicyServiceSetOrgCeilingRequestPeriod + +Optional period override for the ceiling. Only valid together with limit. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.FundPolicyServiceSetOrgCeilingRequestPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyservicesetorgceilingresponse.md b/docs/pkg/models/shared/fundpolicyservicesetorgceilingresponse.md new file mode 100644 index 000000000..0e1faecb0 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyservicesetorgceilingresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceSetOrgCeilingResponse + +The FundPolicyServiceSetOrgCeilingResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md b/docs/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md new file mode 100644 index 000000000..98195e8d6 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md @@ -0,0 +1,9 @@ +# FundPolicyServiceUnfreezeTenantRequest + +The FundPolicyServiceUnfreezeTenantRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md b/docs/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md new file mode 100644 index 000000000..31c399778 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceUnfreezeTenantResponse + +The FundPolicyServiceUnfreezeTenantResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyserviceupdaterequest.md b/docs/pkg/models/shared/fundpolicyserviceupdaterequest.md new file mode 100644 index 000000000..c2605ea90 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyserviceupdaterequest.md @@ -0,0 +1,11 @@ +# FundPolicyServiceUpdateRequest + +The FundPolicyServiceUpdateRequest message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | +| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundpolicyserviceupdateresponse.md b/docs/pkg/models/shared/fundpolicyserviceupdateresponse.md new file mode 100644 index 000000000..7b882bf43 --- /dev/null +++ b/docs/pkg/models/shared/fundpolicyserviceupdateresponse.md @@ -0,0 +1,10 @@ +# FundPolicyServiceUpdateResponse + +The FundPolicyServiceUpdateResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `Policy` | [*shared.FundPolicy](../../../pkg/models/shared/fundpolicy.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundrule.md b/docs/pkg/models/shared/fundrule.md new file mode 100644 index 000000000..53532b49b --- /dev/null +++ b/docs/pkg/models/shared/fundrule.md @@ -0,0 +1,17 @@ +# FundRule + +FundRule is one group grant as the API renders it. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | Admin-facing label, so a rule list reads as policy rather than as ids.
    Bounded on the message rather than only on Create: Update carries a whole
    FundRule, and this is the column the mirror's full-text and btree indexes
    are built on. | +| `Grant` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `GroupRef` | [*shared.AppEntitlementRef](../../../pkg/models/shared/appentitlementref.md) | :heavy_minus_sign: | N/A | +| `Reason` | `*string` | :heavy_minus_sign: | Why this cohort is funded. Subject-visible where a grant is explained. | +| `RuleID` | `*string` | :heavy_minus_sign: | The ruleId field. | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundrulehistoryentry.md b/docs/pkg/models/shared/fundrulehistoryentry.md new file mode 100644 index 000000000..9d662d08c --- /dev/null +++ b/docs/pkg/models/shared/fundrulehistoryentry.md @@ -0,0 +1,11 @@ +# FundRuleHistoryEntry + +The FundRuleHistoryEntry message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicecreaterequest.md b/docs/pkg/models/shared/fundruleservicecreaterequest.md new file mode 100644 index 000000000..19c426705 --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicecreaterequest.md @@ -0,0 +1,13 @@ +# FundRuleServiceCreateRequest + +The FundRuleServiceCreateRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `Grant` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `GroupRef` | [*shared.AppEntitlementRef](../../../pkg/models/shared/appentitlementref.md) | :heavy_minus_sign: | N/A | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicecreateresponse.md b/docs/pkg/models/shared/fundruleservicecreateresponse.md new file mode 100644 index 000000000..a73699fb3 --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicecreateresponse.md @@ -0,0 +1,10 @@ +# FundRuleServiceCreateResponse + +The FundRuleServiceCreateResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | +| `Rule` | [*shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicedeleterequest.md b/docs/pkg/models/shared/fundruleservicedeleterequest.md new file mode 100644 index 000000000..ca533a509 --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicedeleterequest.md @@ -0,0 +1,9 @@ +# FundRuleServiceDeleteRequest + +The FundRuleServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicedeleteresponse.md b/docs/pkg/models/shared/fundruleservicedeleteresponse.md new file mode 100644 index 000000000..221bd7d29 --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicedeleteresponse.md @@ -0,0 +1,9 @@ +# FundRuleServiceDeleteResponse + +The FundRuleServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicegetresponse.md b/docs/pkg/models/shared/fundruleservicegetresponse.md new file mode 100644 index 000000000..aa3b88381 --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicegetresponse.md @@ -0,0 +1,10 @@ +# FundRuleServiceGetResponse + +The FundRuleServiceGetResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | +| `Rule` | [*shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicelisthistoryresponse.md b/docs/pkg/models/shared/fundruleservicelisthistoryresponse.md new file mode 100644 index 000000000..b6631838f --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# FundRuleServiceListHistoryResponse + +The FundRuleServiceListHistoryResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | +| `List` | [][shared.FundRuleHistoryEntry](../../../pkg/models/shared/fundrulehistoryentry.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicelistresponse.md b/docs/pkg/models/shared/fundruleservicelistresponse.md new file mode 100644 index 000000000..8fe0b565c --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicelistresponse.md @@ -0,0 +1,11 @@ +# FundRuleServiceListResponse + +The FundRuleServiceListResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | +| `List` | [][shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicesearchrequest.md b/docs/pkg/models/shared/fundruleservicesearchrequest.md new file mode 100644 index 000000000..83e92040b --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicesearchrequest.md @@ -0,0 +1,12 @@ +# FundRuleServiceSearchRequest + +The FundRuleServiceSearchRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize field. | +| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | +| `Query` | `*string` | :heavy_minus_sign: | Case-insensitive search over the rule display name; empty returns all. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleservicesearchresponse.md b/docs/pkg/models/shared/fundruleservicesearchresponse.md new file mode 100644 index 000000000..2d5d0c81a --- /dev/null +++ b/docs/pkg/models/shared/fundruleservicesearchresponse.md @@ -0,0 +1,11 @@ +# FundRuleServiceSearchResponse + +The FundRuleServiceSearchResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------- | +| `List` | [][shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleserviceupdaterequest.md b/docs/pkg/models/shared/fundruleserviceupdaterequest.md new file mode 100644 index 000000000..18ff2ce44 --- /dev/null +++ b/docs/pkg/models/shared/fundruleserviceupdaterequest.md @@ -0,0 +1,11 @@ +# FundRuleServiceUpdateRequest + +The FundRuleServiceUpdateRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | +| `Rule` | [*shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | N/A | +| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/fundruleserviceupdateresponse.md b/docs/pkg/models/shared/fundruleserviceupdateresponse.md new file mode 100644 index 000000000..54c70b0a1 --- /dev/null +++ b/docs/pkg/models/shared/fundruleserviceupdateresponse.md @@ -0,0 +1,10 @@ +# FundRuleServiceUpdateResponse + +The FundRuleServiceUpdateResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | +| `Rule` | [*shared.FundRule](../../../pkg/models/shared/fundrule.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/gatewaykey.md b/docs/pkg/models/shared/gatewaykey.md new file mode 100644 index 000000000..fb1870fa2 --- /dev/null +++ b/docs/pkg/models/shared/gatewaykey.md @@ -0,0 +1,15 @@ +# GatewayKey + +The GatewayKey message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `KeyPrefix` | `*string` | :heavy_minus_sign: | The keyPrefix field. | +| `RevokedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/getappmanagedstatebindingresponse.md b/docs/pkg/models/shared/getappmanagedstatebindingresponse.md new file mode 100644 index 000000000..b4f3461ba --- /dev/null +++ b/docs/pkg/models/shared/getappmanagedstatebindingresponse.md @@ -0,0 +1,11 @@ +# GetAppManagedStateBindingResponse + +GetAppManagedStateBindingResponse contains the managed state of a discovered application. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | +| `AppManagementState` | [*shared.AppManagedStateBindingView](../../../pkg/models/shared/appmanagedstatebindingview.md) | :heavy_minus_sign: | N/A | +| `Expanded` | [][shared.GetAppManagedStateBindingResponseExpanded](../../../pkg/models/shared/getappmanagedstatebindingresponseexpanded.md) | :heavy_minus_sign: | Related objects requested through expand_mask. REST Get requests do not support expansions; REST Promote requests do. | \ No newline at end of file diff --git a/docs/pkg/models/shared/getappmanagedstatebindingresponseexpanded.md b/docs/pkg/models/shared/getappmanagedstatebindingresponseexpanded.md new file mode 100644 index 000000000..b7bfd1768 --- /dev/null +++ b/docs/pkg/models/shared/getappmanagedstatebindingresponseexpanded.md @@ -0,0 +1,11 @@ +# GetAppManagedStateBindingResponseExpanded + +Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------- | ----------------------------------- | ----------------------------------- | ----------------------------------- | +| `AtType` | `*string` | :heavy_minus_sign: | The type of the serialized message. | +| `AdditionalProperties` | map[string]`any` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/getcustomanalysisresultresponse.md b/docs/pkg/models/shared/getcustomanalysisresultresponse.md index 8eee86132..fe877188f 100644 --- a/docs/pkg/models/shared/getcustomanalysisresultresponse.md +++ b/docs/pkg/models/shared/getcustomanalysisresultresponse.md @@ -10,6 +10,7 @@ The GetCustomAnalysisResultResponse message. | `AppsAnalyzed` | `*int` | :heavy_minus_sign: | The appsAnalyzed field. | | `Clusters` | [][shared.EntitlementCluster](../../../pkg/models/shared/entitlementcluster.md) | :heavy_minus_sign: | Cluster results. | | `CohortSize` | `*int` | :heavy_minus_sign: | The cohortSize field. | +| `CutoffImpactPoints` | [][shared.EntitlementCutoffImpactPoint](../../../pkg/models/shared/entitlementcutoffimpactpoint.md) | :heavy_minus_sign: | Exact holder counts at each distinct inclusive entitlement coverage cutoff. | | `Entitlements` | [][shared.CohortEntitlement](../../../pkg/models/shared/cohortentitlement.md) | :heavy_minus_sign: | Entitlement coverage results. | | `ErrorMessage` | `*string` | :heavy_minus_sign: | The errorMessage field. | | `FacetUserCount` | `*int` | :heavy_minus_sign: | The facetUserCount field. | diff --git a/docs/pkg/models/shared/getprovidercredentialresponse.md b/docs/pkg/models/shared/getprovidercredentialresponse.md new file mode 100644 index 000000000..59a4dbb96 --- /dev/null +++ b/docs/pkg/models/shared/getprovidercredentialresponse.md @@ -0,0 +1,10 @@ +# GetProviderCredentialResponse + +The GetProviderCredentialResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | +| `Credential` | [*shared.ProviderCredential](../../../pkg/models/shared/providercredential.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/grantfilter.md b/docs/pkg/models/shared/grantfilter.md index e6f9b1165..f2c7b6078 100644 --- a/docs/pkg/models/shared/grantfilter.md +++ b/docs/pkg/models/shared/grantfilter.md @@ -5,8 +5,8 @@ The GrantFilter message. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -| `GrantFilterType` | [*shared.GrantFilterType](../../../pkg/models/shared/grantfiltertype.md) | :heavy_minus_sign: | The grantFilterType field. | -| `GrantJustificationType` | [*shared.GrantJustificationType](../../../pkg/models/shared/grantjustificationtype.md) | :heavy_minus_sign: | The grantJustificationType field. | -| `GrantSourceFilter` | [*shared.GrantSourceFilter](../../../pkg/models/shared/grantsourcefilter.md) | :heavy_minus_sign: | The grantSourceFilter field. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `GrantFilterType` | [*shared.GrantFilterType](../../../pkg/models/shared/grantfiltertype.md) | :heavy_minus_sign: | The grantFilterType field. | +| `GrantJustificationType` | [*shared.GrantJustificationType](../../../pkg/models/shared/grantjustificationtype.md) | :heavy_minus_sign: | The grantJustificationType field. | +| `GrantSourceFilter` | [*shared.GrantFilterGrantSourceFilter](../../../pkg/models/shared/grantfiltergrantsourcefilter.md) | :heavy_minus_sign: | The grantSourceFilter field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/grantfiltergrantsourcefilter.md b/docs/pkg/models/shared/grantfiltergrantsourcefilter.md new file mode 100644 index 000000000..c65d6edc5 --- /dev/null +++ b/docs/pkg/models/shared/grantfiltergrantsourcefilter.md @@ -0,0 +1,25 @@ +# GrantFilterGrantSourceFilter + +The grantSourceFilter field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.GrantFilterGrantSourceFilterGrantSourceFilterUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.GrantFilterGrantSourceFilter("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------------------------- | ---------------------------------------------------------- | +| `GrantFilterGrantSourceFilterGrantSourceFilterUnspecified` | GRANT_SOURCE_FILTER_UNSPECIFIED | +| `GrantFilterGrantSourceFilterGrantSourceFilterDirect` | GRANT_SOURCE_FILTER_DIRECT | +| `GrantFilterGrantSourceFilterGrantSourceFilterInherited` | GRANT_SOURCE_FILTER_INHERITED | \ No newline at end of file diff --git a/docs/pkg/models/shared/grantsourcefilter.md b/docs/pkg/models/shared/grantsourcefilter.md index e646b393c..2c4fd85a1 100644 --- a/docs/pkg/models/shared/grantsourcefilter.md +++ b/docs/pkg/models/shared/grantsourcefilter.md @@ -1,6 +1,8 @@ # GrantSourceFilter -The grantSourceFilter field. +Restricts the step to grants of either DIRECT (grants the user holds directly, + including grants that are also inherited) or UNSPECIFIED (all grants). + Composes with every inclusion mode, including inclusion_list_cel. ## Example Usage @@ -21,5 +23,4 @@ custom := shared.GrantSourceFilter("custom_value") | Name | Value | | ----------------------------------------------- | ----------------------------------------------- | | `GrantSourceFilterGrantSourceFilterUnspecified` | GRANT_SOURCE_FILTER_UNSPECIFIED | -| `GrantSourceFilterGrantSourceFilterDirect` | GRANT_SOURCE_FILTER_DIRECT | -| `GrantSourceFilterGrantSourceFilterInherited` | GRANT_SOURCE_FILTER_INHERITED | \ No newline at end of file +| `GrantSourceFilterGrantSourceFilterDirect` | GRANT_SOURCE_FILTER_DIRECT | \ No newline at end of file diff --git a/docs/pkg/models/shared/headerstyle.md b/docs/pkg/models/shared/headerstyle.md new file mode 100644 index 000000000..aa462a8e5 --- /dev/null +++ b/docs/pkg/models/shared/headerstyle.md @@ -0,0 +1,25 @@ +# HeaderStyle + +The headerStyle field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.HeaderStyleProviderCredentialHeaderStyleUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.HeaderStyle("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------- | ------------------------------------------------------------- | +| `HeaderStyleProviderCredentialHeaderStyleUnspecified` | PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED | +| `HeaderStyleProviderCredentialHeaderStyleXAPIKey` | PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY | +| `HeaderStyleProviderCredentialHeaderStyleAuthorizationBearer` | PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER | \ No newline at end of file diff --git a/docs/pkg/models/shared/hook.md b/docs/pkg/models/shared/hook.md index 8121d275f..ee8fe56a6 100644 --- a/docs/pkg/models/shared/hook.md +++ b/docs/pkg/models/shared/hook.md @@ -5,21 +5,24 @@ Hook represents a customer-configured interception point for tool calls. This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - function - builtinPattern + - jsonPatch ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `BuiltinPattern` | [*shared.BuiltInPattern](../../../pkg/models/shared/builtinpattern.md) | :heavy_minus_sign: | N/A | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Description` | `*string` | :heavy_minus_sign: | The description field. | -| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | -| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | -| `Event` | [*shared.Event](../../../pkg/models/shared/event.md) | :heavy_minus_sign: | The event field. | -| `Filter` | [*shared.HookFilter](../../../pkg/models/shared/hookfilter.md) | :heavy_minus_sign: | N/A | -| `Function` | [*shared.HookFunctionRef](../../../pkg/models/shared/hookfunctionref.md) | :heavy_minus_sign: | N/A | -| `ID` | `*string` | :heavy_minus_sign: | The id field. | -| `Priority` | `*int` | :heavy_minus_sign: | The priority field. | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `BuiltinPattern` | [*shared.BuiltInPattern](../../../pkg/models/shared/builtinpattern.md) | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | The description field. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | +| `Event` | [*shared.Event](../../../pkg/models/shared/event.md) | :heavy_minus_sign: | The event field. | +| `Filter` | [*shared.HookFilter](../../../pkg/models/shared/hookfilter.md) | :heavy_minus_sign: | N/A | +| `Function` | [*shared.HookFunctionRef](../../../pkg/models/shared/hookfunctionref.md) | :heavy_minus_sign: | N/A | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `JSONPatch` | [*shared.JSONPatchConfig](../../../pkg/models/shared/jsonpatchconfig.md) | :heavy_minus_sign: | N/A | +| `ManagedByGuardrails` | `*bool` | :heavy_minus_sign: | managed_by_guardrails marks a hook as selectable in a guardrail rule's
    curated pre_hook_ids/post_hook_ids. A hook left false (the default,
    including every pre-existing hook) always runs regardless of guardrail
    state; a hook set true only runs when a matched rule selects it. | +| `Priority` | `*int` | :heavy_minus_sign: | The priority field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/hookfilter.md b/docs/pkg/models/shared/hookfilter.md index b00088a18..705e8c92d 100644 --- a/docs/pkg/models/shared/hookfilter.md +++ b/docs/pkg/models/shared/hookfilter.md @@ -1,10 +1,11 @@ # HookFilter -HookFilter determines which tool calls a hook applies to. +HookFilter determines which calls (or, for HOOK_EVENT_TYPE_PRE_OUTPUT, + which outgoing response chunks) a hook applies to. ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | -| `CelExpression` | `*string` | :heavy_minus_sign: | CEL expression evaluated against tool call context.
    Available variable: ctx.tool_name (string).
    Must evaluate to bool. Empty matches all tools. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CelExpression` | `*string` | :heavy_minus_sign: | CEL expression evaluated against event context. Must evaluate to bool,
    empty = matches everything for the event type.
    HOOK_EVENT_TYPE_PRE_TOOL_USE / POST_TOOL_USE: ctx.tool_name (string),
    and for a call originating from a chat channel ctx.surface (string,
    "slack", "web", or "teams"), ctx.channel_id (string, the channel the
    message arrived on — only set for "slack"/"teams"; "web" channel refs are
    per-conversation and not admin-predictable), and ctx.workspace_id
    (string, the Slack/Teams workspace, when known). All three are absent
    otherwise, so guard them with has(ctx.surface) / has(ctx.channel_id) /
    has(ctx.workspace_id).
    HOOK_EVENT_TYPE_PRE_OUTPUT: ctx.untrusted_class (string), ctx.surface
    (string, "slack" or "web"). | \ No newline at end of file diff --git a/docs/pkg/models/shared/hookinput.md b/docs/pkg/models/shared/hookinput.md index 3ba45c1b1..d2001bb95 100644 --- a/docs/pkg/models/shared/hookinput.md +++ b/docs/pkg/models/shared/hookinput.md @@ -5,19 +5,22 @@ Hook represents a customer-configured interception point for tool calls. This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - function - builtinPattern + - jsonPatch ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `BuiltinPattern` | [*shared.BuiltInPattern](../../../pkg/models/shared/builtinpattern.md) | :heavy_minus_sign: | N/A | -| `Description` | `*string` | :heavy_minus_sign: | The description field. | -| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | -| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | -| `Event` | [*shared.Event](../../../pkg/models/shared/event.md) | :heavy_minus_sign: | The event field. | -| `Filter` | [*shared.HookFilter](../../../pkg/models/shared/hookfilter.md) | :heavy_minus_sign: | N/A | -| `Function` | [*shared.HookFunctionRef](../../../pkg/models/shared/hookfunctionref.md) | :heavy_minus_sign: | N/A | -| `ID` | `*string` | :heavy_minus_sign: | The id field. | -| `Priority` | `*int` | :heavy_minus_sign: | The priority field. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `BuiltinPattern` | [*shared.BuiltInPattern](../../../pkg/models/shared/builtinpattern.md) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | The description field. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | +| `Event` | [*shared.Event](../../../pkg/models/shared/event.md) | :heavy_minus_sign: | The event field. | +| `Filter` | [*shared.HookFilter](../../../pkg/models/shared/hookfilter.md) | :heavy_minus_sign: | N/A | +| `Function` | [*shared.HookFunctionRef](../../../pkg/models/shared/hookfunctionref.md) | :heavy_minus_sign: | N/A | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `JSONPatch` | [*shared.JSONPatchConfig](../../../pkg/models/shared/jsonpatchconfig.md) | :heavy_minus_sign: | N/A | +| `ManagedByGuardrails` | `*bool` | :heavy_minus_sign: | managed_by_guardrails marks a hook as selectable in a guardrail rule's
    curated pre_hook_ids/post_hook_ids. A hook left false (the default,
    including every pre-existing hook) always runs regardless of guardrail
    state; a hook set true only runs when a matched rule selects it. | +| `Priority` | `*int` | :heavy_minus_sign: | The priority field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/hooksservicecreaterequest.md b/docs/pkg/models/shared/hooksservicecreaterequest.md index 3cb42d5f8..24c9a3d63 100644 --- a/docs/pkg/models/shared/hooksservicecreaterequest.md +++ b/docs/pkg/models/shared/hooksservicecreaterequest.md @@ -5,6 +5,7 @@ The HooksServiceCreateRequest message. This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: - function - builtinPattern + - jsonPatch @@ -19,4 +20,6 @@ This message contains a oneof named hook_type. Only a single field of the follow | `Event` | [*shared.HooksServiceCreateRequestEvent](../../../pkg/models/shared/hooksservicecreaterequestevent.md) | :heavy_minus_sign: | The event field. | | `Filter` | [*shared.HookFilter](../../../pkg/models/shared/hookfilter.md) | :heavy_minus_sign: | N/A | | `Function` | [*shared.HookFunctionRef](../../../pkg/models/shared/hookfunctionref.md) | :heavy_minus_sign: | N/A | +| `JSONPatch` | [*shared.JSONPatchConfig](../../../pkg/models/shared/jsonpatchconfig.md) | :heavy_minus_sign: | N/A | +| `ManagedByGuardrails` | `*bool` | :heavy_minus_sign: | The managedByGuardrails field. | | `Priority` | `*int` | :heavy_minus_sign: | The priority field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/hooksservicecreaterequestevent.md b/docs/pkg/models/shared/hooksservicecreaterequestevent.md index 3701983b1..58114ae62 100644 --- a/docs/pkg/models/shared/hooksservicecreaterequestevent.md +++ b/docs/pkg/models/shared/hooksservicecreaterequestevent.md @@ -22,4 +22,5 @@ custom := shared.HooksServiceCreateRequestEvent("custom_value") | -------------------------------------------------------- | -------------------------------------------------------- | | `HooksServiceCreateRequestEventHookEventTypeUnspecified` | HOOK_EVENT_TYPE_UNSPECIFIED | | `HooksServiceCreateRequestEventHookEventTypePreToolUse` | HOOK_EVENT_TYPE_PRE_TOOL_USE | -| `HooksServiceCreateRequestEventHookEventTypePostToolUse` | HOOK_EVENT_TYPE_POST_TOOL_USE | \ No newline at end of file +| `HooksServiceCreateRequestEventHookEventTypePostToolUse` | HOOK_EVENT_TYPE_POST_TOOL_USE | +| `HooksServiceCreateRequestEventHookEventTypePreOutput` | HOOK_EVENT_TYPE_PRE_OUTPUT | \ No newline at end of file diff --git a/docs/pkg/models/shared/idtokensignedresponsealg.md b/docs/pkg/models/shared/idtokensignedresponsealg.md new file mode 100644 index 000000000..24c482e02 --- /dev/null +++ b/docs/pkg/models/shared/idtokensignedresponsealg.md @@ -0,0 +1,26 @@ +# IDTokenSignedResponseAlg + +The algorithm used to sign this application's id_token. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.IDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.IDTokenSignedResponseAlg("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------------- | --------------------------------------------------------- | +| `IDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified` | OIDC_SIGNING_ALGORITHM_UNSPECIFIED | +| `IDTokenSignedResponseAlgOidcSigningAlgorithmEddsa` | OIDC_SIGNING_ALGORITHM_EDDSA | +| `IDTokenSignedResponseAlgOidcSigningAlgorithmEs256` | OIDC_SIGNING_ALGORITHM_ES256 | +| `IDTokenSignedResponseAlgOidcSigningAlgorithmRs256` | OIDC_SIGNING_ALGORITHM_RS256 | \ No newline at end of file diff --git a/docs/pkg/models/shared/introspectresponse.md b/docs/pkg/models/shared/introspectresponse.md index a84554d1c..f4ccc80bf 100644 --- a/docs/pkg/models/shared/introspectresponse.md +++ b/docs/pkg/models/shared/introspectresponse.md @@ -5,12 +5,13 @@ IntrospectResponse contains information about the current user who is authentica ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `DeviceClientID` | `*string` | :heavy_minus_sign: | The OAuth client_id of the device client registered for this token. Present
    only on tokens issued by the device registration grant; the client reads it
    once and presents it on the subsequent token exchange. Empty for all other
    tokens. | -| `Features` | []`string` | :heavy_minus_sign: | The list of feature flags enabled for the tenant the logged in user belongs to. | -| `Permissions` | []`string` | :heavy_minus_sign: | The list of permissions that the current logged in user has. | -| `PrincipleID` | `*string` | :heavy_minus_sign: | The principleID of the current logged in user. | -| `Roles` | []`string` | :heavy_minus_sign: | The list of roles that the current logged in user has. | -| `TenantID` | `*string` | :heavy_minus_sign: | The tenantID from the authenticated caller's passport. | -| `UserID` | `*string` | :heavy_minus_sign: | The userID of the current logged in user. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `DeviceClientID` | `*string` | :heavy_minus_sign: | The OAuth client_id of the device client registered for this token. Present
    only on tokens issued by the device registration grant; the client reads it
    once and presents it on the subsequent token exchange. Empty for all other
    tokens. | +| `DisabledModules` | [][shared.DisabledModules](../../../pkg/models/shared/disabledmodules.md) | :heavy_minus_sign: | The modules turned off for the tenant the logged in user belongs to. Absent
    from this list means enabled: every module is on by default. Clients MUST
    treat an unrecognized value as "a module this client does not know about is
    disabled". | +| `Features` | []`string` | :heavy_minus_sign: | The list of feature flags enabled for the tenant the logged in user belongs to. | +| `Permissions` | []`string` | :heavy_minus_sign: | The list of permissions that the current logged in user has. | +| `PrincipleID` | `*string` | :heavy_minus_sign: | The principleID of the current logged in user. | +| `Roles` | []`string` | :heavy_minus_sign: | The list of roles that the current logged in user has. | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantID from the authenticated caller's passport. | +| `UserID` | `*string` | :heavy_minus_sign: | The userID of the current logged in user. | \ No newline at end of file diff --git a/docs/pkg/models/shared/invokefunctiondispatcher.md b/docs/pkg/models/shared/invokefunctiondispatcher.md new file mode 100644 index 000000000..22caf3a5f --- /dev/null +++ b/docs/pkg/models/shared/invokefunctiondispatcher.md @@ -0,0 +1,12 @@ +# InvokeFunctionDispatcher + +InvokeFunctionDispatcher runs a published C1 function by id. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------ | +| `Args` | map[string]`string` | :heavy_minus_sign: | Arguments passed to the function, keyed by arg name (v0: verbatim values;
    CEL evaluation is a later phase). | +| `FunctionCommitID` | `*string` | :heavy_minus_sign: | Optional pinned function commit; empty floats to the published commit. | +| `FunctionID` | `*string` | :heavy_minus_sign: | ID of the published function to invoke. | \ No newline at end of file diff --git a/docs/pkg/models/shared/jsonpatchconfig.md b/docs/pkg/models/shared/jsonpatchconfig.md new file mode 100644 index 000000000..9055bf629 --- /dev/null +++ b/docs/pkg/models/shared/jsonpatchconfig.md @@ -0,0 +1,22 @@ +# JSONPatchConfig + +JSONPatchConfig adds, overwrites, or removes fields on a tool call's JSON + input, with no function invocation. Only valid on + HOOK_EVENT_TYPE_PRE_TOOL_USE. cel_expression is evaluated against + ctx/input/caller and must produce a map; static_overlay is a fixed map. + Either result is shallow-merged onto the input under RFC 7396 merge patch + semantics: a key overwrites or adds that key, a null value removes it, and a + nested object replaces rather than merging into the existing one. + +This message contains a oneof named source. Only a single field of the following list may be set at a time: + - celExpression + - staticOverlay + + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `CelExpression` | `*string` | :heavy_minus_sign: | The celExpression field.
    This field is part of the `source` oneof.
    See the documentation for `c1.api.hooks.v1.JSONPatchConfig` for more details. | +| `StaticOverlay` | map[string]`any` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/kindfilter.md b/docs/pkg/models/shared/kindfilter.md new file mode 100644 index 000000000..7c71a3ce8 --- /dev/null +++ b/docs/pkg/models/shared/kindfilter.md @@ -0,0 +1,23 @@ +# KindFilter + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.KindFilterMcpResourceKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.KindFilter("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------- | -------------------------------------- | +| `KindFilterMcpResourceKindUnspecified` | MCP_RESOURCE_KIND_UNSPECIFIED | +| `KindFilterMcpResourceKindStatic` | MCP_RESOURCE_KIND_STATIC | +| `KindFilterMcpResourceKindTemplate` | MCP_RESOURCE_KIND_TEMPLATE | \ No newline at end of file diff --git a/docs/pkg/models/shared/level.md b/docs/pkg/models/shared/level.md index 1f051a6f6..3eca9142d 100644 --- a/docs/pkg/models/shared/level.md +++ b/docs/pkg/models/shared/level.md @@ -1,6 +1,6 @@ # Level -The level field. +The severity of this finding. ## Example Usage @@ -9,7 +9,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.LevelAuthLevelUnspecified +value := shared.LevelLevelUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.Level("custom_value") @@ -18,11 +18,8 @@ custom := shared.Level("custom_value") ## Values -| Name | Value | -| ---------------------------- | ---------------------------- | -| `LevelAuthLevelUnspecified` | AUTH_LEVEL_UNSPECIFIED | -| `LevelAuthLevelNone` | AUTH_LEVEL_NONE | -| `LevelAuthLevelSingleFactor` | AUTH_LEVEL_SINGLE_FACTOR | -| `LevelAuthLevelMultiFactor` | AUTH_LEVEL_MULTI_FACTOR | -| `LevelAuthLevelPhr` | AUTH_LEVEL_PHR | -| `LevelAuthLevelPhrh` | AUTH_LEVEL_PHRH | \ No newline at end of file +| Name | Value | +| ----------------------- | ----------------------- | +| `LevelLevelUnspecified` | LEVEL_UNSPECIFIED | +| `LevelLevelBlocking` | LEVEL_BLOCKING | +| `LevelLevelWarning` | LEVEL_WARNING | \ No newline at end of file diff --git a/docs/pkg/models/shared/linkfilterconfig.md b/docs/pkg/models/shared/linkfilterconfig.md new file mode 100644 index 000000000..f0a231d78 --- /dev/null +++ b/docs/pkg/models/shared/linkfilterconfig.md @@ -0,0 +1,13 @@ +# LinkFilterConfig + +LinkFilterConfig strips or annotates URLs and markdown images in tool output + whose host is not in allowed_hosts. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | +| `Action` | [*shared.LinkFilterConfigAction](../../../pkg/models/shared/linkfilterconfigaction.md) | :heavy_minus_sign: | Action taken on a disallowed link. Unspecified = REDACT. | +| `AllowedHosts` | []`string` | :heavy_minus_sign: | Hosts that are permitted. Empty = every host is disallowed. Matched
    case-insensitively; a leading "." allows subdomains. | +| `BlockImages` | `*bool` | :heavy_minus_sign: | When true, markdown image links to disallowed hosts are also acted on. | \ No newline at end of file diff --git a/docs/pkg/models/shared/linkfilterconfigaction.md b/docs/pkg/models/shared/linkfilterconfigaction.md new file mode 100644 index 000000000..4c897e330 --- /dev/null +++ b/docs/pkg/models/shared/linkfilterconfigaction.md @@ -0,0 +1,25 @@ +# LinkFilterConfigAction + +Action taken on a disallowed link. Unspecified = REDACT. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.LinkFilterConfigActionLinkFilterActionUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.LinkFilterConfigAction("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------- | --------------------------------------------------- | +| `LinkFilterConfigActionLinkFilterActionUnspecified` | LINK_FILTER_ACTION_UNSPECIFIED | +| `LinkFilterConfigActionLinkFilterActionRedact` | LINK_FILTER_ACTION_REDACT | +| `LinkFilterConfigActionLinkFilterActionAnnotate` | LINK_FILTER_ACTION_ANNOTATE | \ No newline at end of file diff --git a/docs/pkg/models/shared/listappmanagedstatebindingsresponse.md b/docs/pkg/models/shared/listappmanagedstatebindingsresponse.md new file mode 100644 index 000000000..ced27667f --- /dev/null +++ b/docs/pkg/models/shared/listappmanagedstatebindingsresponse.md @@ -0,0 +1,12 @@ +# ListAppManagedStateBindingsResponse + +ListAppManagedStateBindingsResponse contains one page of discovered application managed states. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | +| `Expanded` | [][shared.ListAppManagedStateBindingsResponseExpanded](../../../pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md) | :heavy_minus_sign: | Related objects included for gRPC requests that set expand_mask. | +| `List` | [][shared.AppManagedStateBindingView](../../../pkg/models/shared/appmanagedstatebindingview.md) | :heavy_minus_sign: | Managed states of the discovered applications. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page. Empty when there are no more results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md b/docs/pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md new file mode 100644 index 000000000..1eff66e57 --- /dev/null +++ b/docs/pkg/models/shared/listappmanagedstatebindingsresponseexpanded.md @@ -0,0 +1,11 @@ +# ListAppManagedStateBindingsResponseExpanded + +Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------- | ----------------------------------- | ----------------------------------- | ----------------------------------- | +| `AtType` | `*string` | :heavy_minus_sign: | The type of the serialized message. | +| `AdditionalProperties` | map[string]`any` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/listfindingsettingsresponse.md b/docs/pkg/models/shared/listfindingsettingsresponse.md new file mode 100644 index 000000000..996460d60 --- /dev/null +++ b/docs/pkg/models/shared/listfindingsettingsresponse.md @@ -0,0 +1,11 @@ +# ListFindingSettingsResponse + +The ListFindingSettingsResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Configured` | `*bool` | :heavy_minus_sign: | True once the tenant has explicitly saved their finding-type settings at
    least once, regardless of whether any value differs from default. False
    means the tenant has never saved, so every entry in `list` is the
    shipped default, unconfirmed by the tenant. | +| `List` | [][shared.FindingTypeSetting](../../../pkg/models/shared/findingtypesetting.md) | :heavy_minus_sign: | One entry per configurable finding type, in FindingType declaration order.
    Custom findings are excluded: they arrive over CreateFinding rather than
    from a detector, so there is nothing to switch off. | \ No newline at end of file diff --git a/docs/pkg/models/shared/listgatewaykeysresponse.md b/docs/pkg/models/shared/listgatewaykeysresponse.md new file mode 100644 index 000000000..d6f04c2f0 --- /dev/null +++ b/docs/pkg/models/shared/listgatewaykeysresponse.md @@ -0,0 +1,11 @@ +# ListGatewayKeysResponse + +The ListGatewayKeysResponse message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------- | +| `List` | [][shared.GatewayKey](../../../pkg/models/shared/gatewaykey.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpaccessprofile.md b/docs/pkg/models/shared/mcpaccessprofile.md index e183cce89..b46b6ff37 100644 --- a/docs/pkg/models/shared/mcpaccessprofile.md +++ b/docs/pkg/models/shared/mcpaccessprofile.md @@ -5,15 +5,17 @@ MCPAccessProfile represents an admin-curated grouping of MCP tools. ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | -| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The ID of the AppEntitlement created for this profile. | -| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | -| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Description` | `*string` | :heavy_minus_sign: | Description of what access this profile grants. | -| `DisplayName` | `*string` | :heavy_minus_sign: | Display name for the profile. | -| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this access profile. | -| `ToolCount` | `*int` | :heavy_minus_sign: | The number of tools currently bound to this profile. | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The ID of the AppEntitlement created for this profile. | +| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | +| `ConnectorDisplayName` | `*string` | :heavy_minus_sign: | Display name of the connector this toolset belongs to. Computed read-only;
    populated on every read. The
    auto-maintained default toolsets share a display name across connectors, so
    this is what tells two of them apart. | +| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description of what access this profile grants. | +| `DisplayName` | `*string` | :heavy_minus_sign: | Display name for the profile. | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this access profile. | +| `Requestable` | `*bool` | :heavy_minus_sign: | Whether this toolset's backing entitlement is exposed in at least one
    request catalog (i.e. can be requested). Computed read-only; populated on List. | +| `ToolCount` | `*int` | :heavy_minus_sign: | The number of tools currently bound to this profile. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpaccessprofileinput.md b/docs/pkg/models/shared/mcpaccessprofileinput.md new file mode 100644 index 000000000..554c9bd91 --- /dev/null +++ b/docs/pkg/models/shared/mcpaccessprofileinput.md @@ -0,0 +1,19 @@ +# MCPAccessProfileInput + +MCPAccessProfile represents an admin-curated grouping of MCP tools. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The ID of the AppEntitlement created for this profile. | +| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | +| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description of what access this profile grants. | +| `DisplayName` | `*string` | :heavy_minus_sign: | Display name for the profile. | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this access profile. | +| `ToolCount` | `*int` | :heavy_minus_sign: | The number of tools currently bound to this profile. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md b/docs/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md new file mode 100644 index 000000000..320b6b063 --- /dev/null +++ b/docs/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.md @@ -0,0 +1,12 @@ +# MCPAccessProfileServiceSearchAccessProfilesResponse + +MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of + tenant-wide MCP access profiles. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token for next page. | +| `Profiles` | [][shared.MCPAccessProfile](../../../pkg/models/shared/mcpaccessprofile.md) | :heavy_minus_sign: | The page of matching MCP access profiles. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpaccessprofileserviceupdaterequest.md b/docs/pkg/models/shared/mcpaccessprofileserviceupdaterequest.md index cd53cd3e6..1d5e4e7a8 100644 --- a/docs/pkg/models/shared/mcpaccessprofileserviceupdaterequest.md +++ b/docs/pkg/models/shared/mcpaccessprofileserviceupdaterequest.md @@ -5,7 +5,7 @@ MCPAccessProfileServiceUpdateRequest updates an existing MCP access profile. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -| `Profile` | [*shared.MCPAccessProfile](../../../pkg/models/shared/mcpaccessprofile.md) | :heavy_minus_sign: | N/A | -| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | +| `Profile` | [*shared.MCPAccessProfileInput](../../../pkg/models/shared/mcpaccessprofileinput.md) | :heavy_minus_sign: | N/A | +| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresource.md b/docs/pkg/models/shared/mcpresource.md new file mode 100644 index 000000000..24bdb5adc --- /dev/null +++ b/docs/pkg/models/shared/mcpresource.md @@ -0,0 +1,28 @@ +# MCPResource + +MCPResource represents metadata about an individual resource discovered from an MCP server. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | Bound AppEntitlement created during sync. | +| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | +| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description from the MCP resource spec. | +| `DiscoveryHash` | `*string` | :heavy_minus_sign: | Hash of resource definition for change detection. | +| `EntitlementActive` | `*bool` | :heavy_minus_sign: | Whether the bound app entitlement exists and is not deleted. Computed
    read-only; populated on Search only when the request had
    include_grant_status = true; ignored on write. | +| `GrantCount` | `*int64` | :heavy_minus_sign: | Number of active grants on the bound app entitlement. Computed read-only;
    populated on Search only when the request had include_grant_status = true;
    ignored on write. | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this MCP resource record. | +| `Kind` | [*shared.MCPResourceKind](../../../pkg/models/shared/mcpresourcekind.md) | :heavy_minus_sign: | Whether this is a static resource or a URI template. | +| `LastDiscoveredAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `MimeType` | `*string` | :heavy_minus_sign: | MIME type of the resource content, when known. | +| `Name` | `*string` | :heavy_minus_sign: | Native MCP resource name (unique within an MCP server). | +| `State` | [*shared.MCPResourceState](../../../pkg/models/shared/mcpresourcestate.md) | :heavy_minus_sign: | Resource approval/lifecycle state. | +| `Title` | `*string` | :heavy_minus_sign: | Human-readable title from the MCP resource spec. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `URI` | `*string` | :heavy_minus_sign: | Raw resource URI from MCP discovery (set for STATIC resources). | +| `URITemplate` | `*string` | :heavy_minus_sign: | Raw RFC 6570 URI template from MCP discovery (set for TEMPLATE resources). | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourcehistoryentry.md b/docs/pkg/models/shared/mcpresourcehistoryentry.md new file mode 100644 index 000000000..448999e7b --- /dev/null +++ b/docs/pkg/models/shared/mcpresourcehistoryentry.md @@ -0,0 +1,11 @@ +# MCPResourceHistoryEntry + +MCPResourceHistoryEntry is one version of an MCP resource and its history metadata. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.MCPResource](../../../pkg/models/shared/mcpresource.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceinput.md b/docs/pkg/models/shared/mcpresourceinput.md new file mode 100644 index 000000000..6926e53a4 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceinput.md @@ -0,0 +1,26 @@ +# MCPResourceInput + +MCPResource represents metadata about an individual resource discovered from an MCP server. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | Bound AppEntitlement created during sync. | +| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | +| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description from the MCP resource spec. | +| `DiscoveryHash` | `*string` | :heavy_minus_sign: | Hash of resource definition for change detection. | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this MCP resource record. | +| `Kind` | [*shared.MCPResourceKind](../../../pkg/models/shared/mcpresourcekind.md) | :heavy_minus_sign: | Whether this is a static resource or a URI template. | +| `LastDiscoveredAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `MimeType` | `*string` | :heavy_minus_sign: | MIME type of the resource content, when known. | +| `Name` | `*string` | :heavy_minus_sign: | Native MCP resource name (unique within an MCP server). | +| `State` | [*shared.MCPResourceState](../../../pkg/models/shared/mcpresourcestate.md) | :heavy_minus_sign: | Resource approval/lifecycle state. | +| `Title` | `*string` | :heavy_minus_sign: | Human-readable title from the MCP resource spec. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `URI` | `*string` | :heavy_minus_sign: | Raw resource URI from MCP discovery (set for STATIC resources). | +| `URITemplate` | `*string` | :heavy_minus_sign: | Raw RFC 6570 URI template from MCP discovery (set for TEMPLATE resources). | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourcekind.md b/docs/pkg/models/shared/mcpresourcekind.md new file mode 100644 index 000000000..8e73494f1 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourcekind.md @@ -0,0 +1,25 @@ +# MCPResourceKind + +Whether this is a static resource or a URI template. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPResourceKindMcpResourceKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPResourceKind("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------- | ------------------------------------------- | +| `MCPResourceKindMcpResourceKindUnspecified` | MCP_RESOURCE_KIND_UNSPECIFIED | +| `MCPResourceKindMcpResourceKindStatic` | MCP_RESOURCE_KIND_STATIC | +| `MCPResourceKindMcpResourceKindTemplate` | MCP_RESOURCE_KIND_TEMPLATE | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicegetresponse.md b/docs/pkg/models/shared/mcpresourceservicegetresponse.md new file mode 100644 index 000000000..89d2a15b0 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicegetresponse.md @@ -0,0 +1,10 @@ +# MCPResourceServiceGetResponse + +MCPResourceServiceGetResponse returns a single MCP resource. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Resource` | [*shared.MCPResource](../../../pkg/models/shared/mcpresource.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicelisthistoryresponse.md b/docs/pkg/models/shared/mcpresourceservicelisthistoryresponse.md new file mode 100644 index 000000000..5ea6bfa1a --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# MCPResourceServiceListHistoryResponse + +MCPResourceServiceListHistoryResponse returns MCP resource history entries. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | +| `List` | [][shared.MCPResourceHistoryEntry](../../../pkg/models/shared/mcpresourcehistoryentry.md) | :heavy_minus_sign: | The page of history entries, newest first. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page, or empty if there are no more results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicelistresponse.md b/docs/pkg/models/shared/mcpresourceservicelistresponse.md new file mode 100644 index 000000000..593ee9dca --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicelistresponse.md @@ -0,0 +1,11 @@ +# MCPResourceServiceListResponse + +MCPResourceServiceListResponse returns a list of MCP resources. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token for next page. | +| `Resources` | [][shared.MCPResource](../../../pkg/models/shared/mcpresource.md) | :heavy_minus_sign: | List of MCP resources. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicesearchrequest.md b/docs/pkg/models/shared/mcpresourceservicesearchrequest.md new file mode 100644 index 000000000..3897aa23b --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicesearchrequest.md @@ -0,0 +1,17 @@ +# MCPResourceServiceSearchRequest + +MCPResourceServiceSearchRequest searches MCP resources with filters. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `IncludeGrantStatus` | `*bool` | :heavy_minus_sign: | When true, the server populates the computed entitlement_active and
    grant_count fields on each returned row (an extra batched entitlement
    lookup per page). Off by default so callers that don't render grant
    status don't pay for it. | +| `KindFilter` | [][shared.KindFilter](../../../pkg/models/shared/kindfilter.md) | :heavy_minus_sign: | Optional filter by resource kind. An empty list means no filter. | +| `PageSize` | `*int` | :heavy_minus_sign: | Page size (max 100). | +| `PageToken` | `*string` | :heavy_minus_sign: | Page token for pagination. | +| `Query` | `*string` | :heavy_minus_sign: | Optional text query matched against name, title, description, and uri. | +| `SortBy` | [*shared.MCPResourceServiceSearchRequestSortBy](../../../pkg/models/shared/mcpresourceservicesearchrequestsortby.md) | :heavy_minus_sign: | Sort order for results. UNSPECIFIED sorts by resource name ascending. | +| `SortDirection` | [*shared.SortDirection](../../../pkg/models/shared/sortdirection.md) | :heavy_minus_sign: | Direction for sort_by. UNSPECIFIED means ascending. | +| `StateFilter` | [][shared.StateFilter](../../../pkg/models/shared/statefilter.md) | :heavy_minus_sign: | Optional filter by resource state. An empty list defaults to
    PENDING_REVIEW, APPROVED, and DISABLED (REMOVED is hidden unless
    explicitly requested). | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicesearchrequestsortby.md b/docs/pkg/models/shared/mcpresourceservicesearchrequestsortby.md new file mode 100644 index 000000000..f0333359c --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicesearchrequestsortby.md @@ -0,0 +1,27 @@ +# MCPResourceServiceSearchRequestSortBy + +Sort order for results. UNSPECIFIED sorts by resource name ascending. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPResourceServiceSearchRequestSortByMcpResourceSortByUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPResourceServiceSearchRequestSortBy("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------- | ------------------------------------------------------------------- | +| `MCPResourceServiceSearchRequestSortByMcpResourceSortByUnspecified` | MCP_RESOURCE_SORT_BY_UNSPECIFIED | +| `MCPResourceServiceSearchRequestSortByMcpResourceSortByName` | MCP_RESOURCE_SORT_BY_NAME | +| `MCPResourceServiceSearchRequestSortByMcpResourceSortByURI` | MCP_RESOURCE_SORT_BY_URI | +| `MCPResourceServiceSearchRequestSortByMcpResourceSortByState` | MCP_RESOURCE_SORT_BY_STATE | +| `MCPResourceServiceSearchRequestSortByMcpResourceSortByUpdatedAt` | MCP_RESOURCE_SORT_BY_UPDATED_AT | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceservicesearchresponse.md b/docs/pkg/models/shared/mcpresourceservicesearchresponse.md new file mode 100644 index 000000000..022db41b4 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceservicesearchresponse.md @@ -0,0 +1,11 @@ +# MCPResourceServiceSearchResponse + +MCPResourceServiceSearchResponse returns matching MCP resources. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | +| `List` | [][shared.MCPResource](../../../pkg/models/shared/mcpresource.md) | :heavy_minus_sign: | Matching MCP resources. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token for next page. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceserviceupdaterequest.md b/docs/pkg/models/shared/mcpresourceserviceupdaterequest.md new file mode 100644 index 000000000..91964c287 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceserviceupdaterequest.md @@ -0,0 +1,11 @@ +# MCPResourceServiceUpdateRequest + +MCPResourceServiceUpdateRequest updates an existing MCP resource. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `Resource` | [*shared.MCPResourceInput](../../../pkg/models/shared/mcpresourceinput.md) | :heavy_minus_sign: | N/A | +| `UpdateMask` | `*string` | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourceserviceupdateresponse.md b/docs/pkg/models/shared/mcpresourceserviceupdateresponse.md new file mode 100644 index 000000000..e8afd7741 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourceserviceupdateresponse.md @@ -0,0 +1,10 @@ +# MCPResourceServiceUpdateResponse + +MCPResourceServiceUpdateResponse returns the updated MCP resource. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Resource` | [*shared.MCPResource](../../../pkg/models/shared/mcpresource.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpresourcestate.md b/docs/pkg/models/shared/mcpresourcestate.md new file mode 100644 index 000000000..6e87e7009 --- /dev/null +++ b/docs/pkg/models/shared/mcpresourcestate.md @@ -0,0 +1,27 @@ +# MCPResourceState + +Resource approval/lifecycle state. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPResourceStateMcpResourceStateUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPResourceState("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------- | ----------------------------------------------- | +| `MCPResourceStateMcpResourceStateUnspecified` | MCP_RESOURCE_STATE_UNSPECIFIED | +| `MCPResourceStateMcpResourceStatePendingReview` | MCP_RESOURCE_STATE_PENDING_REVIEW | +| `MCPResourceStateMcpResourceStateApproved` | MCP_RESOURCE_STATE_APPROVED | +| `MCPResourceStateMcpResourceStateDisabled` | MCP_RESOURCE_STATE_DISABLED | +| `MCPResourceStateMcpResourceStateRemoved` | MCP_RESOURCE_STATE_REMOVED | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpservercatalogauthmode.md b/docs/pkg/models/shared/mcpservercatalogauthmode.md index e2bb20866..2d9898aa2 100644 --- a/docs/pkg/models/shared/mcpservercatalogauthmode.md +++ b/docs/pkg/models/shared/mcpservercatalogauthmode.md @@ -13,6 +13,7 @@ MCPServerCatalogAuthMode describes a single authentication method an impl | `AuthMethod` | [*shared.MCPServerCatalogAuthModeAuthMethod](../../../pkg/models/shared/mcpservercatalogauthmodeauthmethod.md) | :heavy_minus_sign: | Authentication method enum. UNSPECIFIED entries are dropped on the way out. | | `AuthStyle` | `*string` | :heavy_minus_sign: | Credential placement on the OAuth2 token request. Allowed values:
    "in_params" (form body), "in_header" (HTTP Basic), or empty
    (autodetect). Set by the impl bundle and shown read-only on the form. | | `AuthorizeURL` | `*string` | :heavy_minus_sign: | OAuth2 authorization endpoint URL. Empty for non-OAuth2 methods. | +| `ClientIDMode` | [*shared.MCPServerCatalogAuthModeClientIDMode](../../../pkg/models/shared/mcpservercatalogauthmodeclientidmode.md) | :heavy_minus_sign: | How the OAuth2 client_id is acquired for this mode. Set by the impl bundle
    and shown read-only on the form. authorization_code grant only. | | `CredentialURL` | `*string` | :heavy_minus_sign: | Documentation URL where the user can obtain a credential for this method
    (e.g., a link to the SaaS app's "create API token" page). Empty if not set. | | `Description` | `*string` | :heavy_minus_sign: | Optional admin-facing hint describing the use case this mode targets
    (e.g. "Per user OAuth option"). | | `ExtraAuthorizeParams` | map[string]`string` | :heavy_minus_sign: | Static query params the bundle declares for the authorize URL
    (e.g. Notion `owner=user`). authorization_code grant only. Surfaced
    read-only so the form can pre-populate its editable copy. | @@ -21,6 +22,7 @@ MCPServerCatalogAuthMode describes a single authentication method an impl | `IssuerURL` | `*string` | :heavy_minus_sign: | OAuth2 issuer URL (used for OIDC discovery). Empty when not an OIDC issuer. | | `JwtAudience` | `*string` | :heavy_minus_sign: | JWT-bearer assertion audience when it differs from token_url. | | `Oauth2Grant` | `*string` | :heavy_minus_sign: | OAuth2 grant for this mode. Prefills the form's OAuth2 mode selection.
    Raw bundle string: "client_credentials", "authorization_code",
    "jwt_bearer", "google_service_account", or empty (infer from authorize_url). | +| `OptionalScopes` | []`string` | :heavy_minus_sign: | Optional (opt-in) OAuth2 scopes from the config's optional_scopes.
    Disjoint from `scopes` and not pre-selected. Empty for non-OAuth2 methods. | | `Passthrough` | `*bool` | :heavy_minus_sign: | Per-user OAuth: each user authorizes individually instead of sharing a
    service-level credential. Only meaningful for OAuth2. | | `Pkce` | `*string` | :heavy_minus_sign: | PKCE behavior for authorization_code: "discover" (or empty), "s256", or
    "disabled". Set by the impl bundle and shown read-only on the form. | | `Scopes` | []`string` | :heavy_minus_sign: | OAuth2 scopes requested by this method. Empty for non-OAuth2 methods. | diff --git a/docs/pkg/models/shared/mcpservercatalogauthmodeclientidmode.md b/docs/pkg/models/shared/mcpservercatalogauthmodeclientidmode.md new file mode 100644 index 000000000..e73782c9c --- /dev/null +++ b/docs/pkg/models/shared/mcpservercatalogauthmodeclientidmode.md @@ -0,0 +1,27 @@ +# MCPServerCatalogAuthModeClientIDMode + +How the OAuth2 client_id is acquired for this mode. Set by the impl bundle + and shown read-only on the form. authorization_code grant only. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPServerCatalogAuthModeClientIDMode("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeUnspecified` | MCP_SERVER_CATALOG_CLIENT_ID_MODE_UNSPECIFIED | +| `MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeManual` | MCP_SERVER_CATALOG_CLIENT_ID_MODE_MANUAL | +| `MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeDcr` | MCP_SERVER_CATALOG_CLIENT_ID_MODE_DCR | +| `MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeCimd` | MCP_SERVER_CATALOG_CLIENT_ID_MODE_CIMD | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpservercatalogentry.md b/docs/pkg/models/shared/mcpservercatalogentry.md index fce6086fc..052422470 100644 --- a/docs/pkg/models/shared/mcpservercatalogentry.md +++ b/docs/pkg/models/shared/mcpservercatalogentry.md @@ -15,6 +15,7 @@ MCPServerCatalogEntry describes a supported MCP server in the catalog. | ~~`DefaultAuthorizeURL`~~ | `*string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: read the OAUTH2 entry's authorize_url from auth_modes instead. | | ~~`DefaultScopes`~~ | []`string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: read the OAUTH2 entry's scopes from auth_modes instead. | | ~~`DefaultTokenURL`~~ | `*string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: read the OAUTH2 entry's token_url from auth_modes instead. | +| `DefaultToolPrefix` | `*string` | :heavy_minus_sign: | Curated default tool-name prefix an admin gets when they register this
    catalog entry and set no custom prefix: the impl's declared server_prefix,
    else its service_name. Shown as a placeholder in the create wizard's tool
    prefix field. Empty when the impl declares no curated default. Mirrors the
    read-only default_tool_prefix on MCPServerView surfaced in the edit flow. | | `Description` | `*string` | :heavy_minus_sign: | Short description of what the MCP server does. | | `DisplayName` | `*string` | :heavy_minus_sign: | Human-readable display name. | | `IconURL` | `*string` | :heavy_minus_sign: | Icon URL (e.g. "/static/app-icons/datadog.svg"). | diff --git a/docs/pkg/models/shared/mcpserverserviceregisterrequest.md b/docs/pkg/models/shared/mcpserverserviceregisterrequest.md index c9825d98d..47b50e3a7 100644 --- a/docs/pkg/models/shared/mcpserverserviceregisterrequest.md +++ b/docs/pkg/models/shared/mcpserverserviceregisterrequest.md @@ -7,6 +7,7 @@ MCPServerServiceRegisterRequest creates a new MCP server (Connector + config). | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AccessProfileIds` | []`string` | :heavy_minus_sign: | Optional access profiles (request catalogs) the server should be requestable
    through. Register creates the server's "All approved tools" toolset empty and adds
    its entitlement to each profile, so members can request the server before discovery
    has found a single tool; the sync later adopts the same toolset and fills it. Empty
    skips both steps. | | `AcknowledgedFindingIds` | []`string` | :heavy_minus_sign: | finding_ids from the diagnostic the admin acknowledged. Each must cover a
    blocking-relaxable finding on oauth_diagnostic_id. | | `AppManagedStateBindingRef` | [*shared.AppManagedStateBindingRef](../../../pkg/models/shared/appmanagedstatebindingref.md) | :heavy_minus_sign: | N/A | | `DataSensitivity` | [*shared.DataSensitivity](../../../pkg/models/shared/datasensitivity.md) | :heavy_minus_sign: | Data sensitivity classification. | diff --git a/docs/pkg/models/shared/mcpserverserviceregisterresponse.md b/docs/pkg/models/shared/mcpserverserviceregisterresponse.md index a9981993c..686818413 100644 --- a/docs/pkg/models/shared/mcpserverserviceregisterresponse.md +++ b/docs/pkg/models/shared/mcpserverserviceregisterresponse.md @@ -5,6 +5,7 @@ MCPServerServiceRegisterResponse returns the newly created MCP server. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -| `McpServer` | [*shared.MCPServerView](../../../pkg/models/shared/mcpserverview.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `AccessProfilesAttached` | `*bool` | :heavy_minus_sign: | Whether the "All approved tools" toolset reached every profile in
    access_profile_ids. False means the server registered but the attach failed
    afterwards, and the profiles have to be wired from the server page. Always true
    when access_profile_ids was empty, since there was nothing to attach. | +| `McpServer` | [*shared.MCPServerView](../../../pkg/models/shared/mcpserverview.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcpserverview.md b/docs/pkg/models/shared/mcpserverview.md index 91c12fec3..f97e20c60 100644 --- a/docs/pkg/models/shared/mcpserverview.md +++ b/docs/pkg/models/shared/mcpserverview.md @@ -26,6 +26,7 @@ MCPServerView is the API representation of an MCP server (backed by a Connector) | `Description` | `*string` | :heavy_minus_sign: | Admin-provided description. | | `DisplayName` | `*string` | :heavy_minus_sign: | Admin-provided display name. | | `EndpointURL` | `*string` | :heavy_minus_sign: | Endpoint URL for external MCP servers. Read-only. | +| `EndpointURLLocked` | `*bool` | :heavy_minus_sign: | Whether the endpoint URL is immutable. True once the connector has
    completed its first successful sync; the URL cannot be changed after
    that point. Read-only. | | `LastCalledAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | | `McpServerCatalogID` | `*string` | :heavy_minus_sign: | Opaque catalog entry ID for hosted MCP servers (27-character KSUID).
    Obtain valid IDs from the ListCatalog or GetCatalog RPCs. | | `Oauth2AuthorizeURL` | `*string` | :heavy_minus_sign: | OAuth2 authorization URL. Read-only; derived from stored config. | diff --git a/docs/pkg/models/shared/mcptool.md b/docs/pkg/models/shared/mcptool.md index 8d4b219ea..767f32e26 100644 --- a/docs/pkg/models/shared/mcptool.md +++ b/docs/pkg/models/shared/mcptool.md @@ -5,25 +5,27 @@ MCPTool represents metadata about individual tools discovered from an MCP server ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | -| `AllowedClientTypes` | [][shared.MCPToolAllowedClientTypes](../../../pkg/models/shared/mcptoolallowedclienttypes.md) | :heavy_minus_sign: | Which client types may use this tool.
    Empty = all allowed types from tenant config. | -| `AppEntitlementID` | `*string` | :heavy_minus_sign: | Bound AppEntitlement created during sync. | -| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | -| `Classification` | [*shared.Classification](../../../pkg/models/shared/classification.md) | :heavy_minus_sign: | Tool risk classification for policy decisions. | -| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DefaultClassification` | [*shared.DefaultClassification](../../../pkg/models/shared/defaultclassification.md) | :heavy_minus_sign: | Default tool classification from MCP config (system-managed during discovery). | -| `DefaultDisplayName` | `*string` | :heavy_minus_sign: | Default display name from MCP tool spec (title field). | -| `DefaultVisibility` | [*shared.DefaultVisibility](../../../pkg/models/shared/defaultvisibility.md) | :heavy_minus_sign: | System-managed default visibility from MCP config (set during discovery). | -| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Description` | `*string` | :heavy_minus_sign: | Admin-editable description. | -| `DiscoveryHash` | `*string` | :heavy_minus_sign: | Hash of tool definition for change detection. | -| `DisplayName` | `*string` | :heavy_minus_sign: | Admin-editable display name (overrides default_display_name when set). | -| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this MCP tool record. | -| `InputSchemaJSON` | `*string` | :heavy_minus_sign: | JSON-encoded input schema from MCP discovery. | -| `LastCalledAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `State` | [*shared.MCPToolState](../../../pkg/models/shared/mcptoolstate.md) | :heavy_minus_sign: | Tool approval/lifecycle state. | -| `ToolName` | `*string` | :heavy_minus_sign: | Native MCP tool name (unique within an MCP server). | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Visibility` | [*shared.Visibility](../../../pkg/models/shared/visibility.md) | :heavy_minus_sign: | Admin-settable visibility override (how this tool is surfaced to users). | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AllowedClientTypes` | [][shared.MCPToolAllowedClientTypes](../../../pkg/models/shared/mcptoolallowedclienttypes.md) | :heavy_minus_sign: | Which client types may use this tool.
    Empty = all allowed types from tenant config. | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | Bound AppEntitlement created during sync. | +| `AppID` | `*string` | :heavy_minus_sign: | App identifier (app that owns the connector). | +| `Classification` | [*shared.Classification](../../../pkg/models/shared/classification.md) | :heavy_minus_sign: | Tool risk classification for policy decisions. | +| `ConnectorID` | `*string` | :heavy_minus_sign: | Connector identifier. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DefaultClassification` | [*shared.DefaultClassification](../../../pkg/models/shared/defaultclassification.md) | :heavy_minus_sign: | Default tool classification from MCP config (system-managed during discovery). | +| `DefaultDisplayName` | `*string` | :heavy_minus_sign: | Default display name from MCP tool spec (title field). | +| `DefaultVisibility` | [*shared.DefaultVisibility](../../../pkg/models/shared/defaultvisibility.md) | :heavy_minus_sign: | System-managed default visibility from MCP config (set during discovery). | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Admin-editable description. | +| `DiscoveryHash` | `*string` | :heavy_minus_sign: | Hash of tool definition for change detection. | +| `DisplayName` | `*string` | :heavy_minus_sign: | Admin-editable display name (overrides default_display_name when set). | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this MCP tool record. | +| `InputSchemaJSON` | `*string` | :heavy_minus_sign: | JSON-encoded input schema from MCP discovery. | +| `LastCalledAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Requestable` | `*bool` | :heavy_minus_sign: | Whether this tool's backing entitlement is exposed in at least one request
    catalog directly (i.e. can be requested on its own). Computed read-only;
    populated on Search. | +| `RequestableViaToolset` | `*bool` | :heavy_minus_sign: | Whether this tool is requestable indirectly — it belongs to at least one
    toolset (access profile) whose backing entitlement is exposed in a request
    catalog. Independent of `requestable`. Computed read-only; populated on Search. | +| `State` | [*shared.MCPToolState](../../../pkg/models/shared/mcptoolstate.md) | :heavy_minus_sign: | Tool approval/lifecycle state. | +| `ToolName` | `*string` | :heavy_minus_sign: | Native MCP tool name (unique within an MCP server). | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Visibility` | [*shared.Visibility](../../../pkg/models/shared/visibility.md) | :heavy_minus_sign: | Admin-settable visibility override (how this tool is surfaced to users). | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcptoolservicesearchrequest.md b/docs/pkg/models/shared/mcptoolservicesearchrequest.md index b79114c6e..059c7b8d2 100644 --- a/docs/pkg/models/shared/mcptoolservicesearchrequest.md +++ b/docs/pkg/models/shared/mcptoolservicesearchrequest.md @@ -13,11 +13,12 @@ MCPToolServiceSearchRequest searches MCP tools with filters. | ~~`ExcludeAccessProfileID`~~ | `*string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: use exclude_access_profile_ids instead. | | `ExcludeAccessProfileIds` | []`string` | :heavy_minus_sign: | Optional: exclude tools that are bound to any of these access profiles. | | `IncludeLastCalledAt` | `*bool` | :heavy_minus_sign: | When true, the server populates MCPTool.last_called_at on each
    returned row by querying TSDB for the most recent `mcp_tool_calls`
    raw emit time per tool. Costs one Dynamo Limit(1) read per row;
    callers that don't render the "Last used" column should leave false. | +| `IncludeRequestable` | `*bool` | :heavy_minus_sign: | When true, populate the computed `requestable` / `requestable_via_toolset`
    fields on each tool (an extra catalog-membership lookup). Off by default so
    callers that don't render requestability — e.g. tool-picker and
    tools-by-toolset views — don't pay for it. | | `PageSize` | `*int` | :heavy_minus_sign: | Page size (max 100). | | `PageToken` | `*string` | :heavy_minus_sign: | Page token for pagination. | | `Query` | `*string` | :heavy_minus_sign: | Optional text query matched against tool_name and display_name | | `Refs` | [][shared.MCPToolRef](../../../pkg/models/shared/mcptoolref.md) | :heavy_minus_sign: | Optional: filter by specific tool refs (used by websocket notify to re-fetch individual tools). | | `SortBy` | [*shared.MCPToolServiceSearchRequestSortBy](../../../pkg/models/shared/mcptoolservicesearchrequestsortby.md) | :heavy_minus_sign: | Sort order for results. UNSPECIFIED sorts by tool name ascending. | -| `SortDirection` | [*shared.SortDirection](../../../pkg/models/shared/sortdirection.md) | :heavy_minus_sign: | Direction for sort_by. UNSPECIFIED means ascending. | -| `StateFilter` | [][shared.StateFilter](../../../pkg/models/shared/statefilter.md) | :heavy_minus_sign: | Optional filter by tool state. 0 (UNSPECIFIED) means no filter. | +| `SortDirection` | [*shared.MCPToolServiceSearchRequestSortDirection](../../../pkg/models/shared/mcptoolservicesearchrequestsortdirection.md) | :heavy_minus_sign: | Direction for sort_by. UNSPECIFIED means ascending. | +| `StateFilter` | [][shared.MCPToolServiceSearchRequestStateFilter](../../../pkg/models/shared/mcptoolservicesearchrequeststatefilter.md) | :heavy_minus_sign: | Optional filter by tool state. 0 (UNSPECIFIED) means no filter. | | `VisibilityFilter` | [][shared.VisibilityFilter](../../../pkg/models/shared/visibilityfilter.md) | :heavy_minus_sign: | Optional filter by visibility. 0 (UNSPECIFIED) means no filter. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcptoolservicesearchrequestsortdirection.md b/docs/pkg/models/shared/mcptoolservicesearchrequestsortdirection.md new file mode 100644 index 000000000..e32d56d55 --- /dev/null +++ b/docs/pkg/models/shared/mcptoolservicesearchrequestsortdirection.md @@ -0,0 +1,25 @@ +# MCPToolServiceSearchRequestSortDirection + +Direction for sort_by. UNSPECIFIED means ascending. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPToolServiceSearchRequestSortDirectionSortDirectionUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPToolServiceSearchRequestSortDirection("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `MCPToolServiceSearchRequestSortDirectionSortDirectionUnspecified` | SORT_DIRECTION_UNSPECIFIED | +| `MCPToolServiceSearchRequestSortDirectionSortDirectionAsc` | SORT_DIRECTION_ASC | +| `MCPToolServiceSearchRequestSortDirectionSortDirectionDesc` | SORT_DIRECTION_DESC | \ No newline at end of file diff --git a/docs/pkg/models/shared/mcptoolservicesearchrequeststatefilter.md b/docs/pkg/models/shared/mcptoolservicesearchrequeststatefilter.md new file mode 100644 index 000000000..90b739cdc --- /dev/null +++ b/docs/pkg/models/shared/mcptoolservicesearchrequeststatefilter.md @@ -0,0 +1,25 @@ +# MCPToolServiceSearchRequestStateFilter + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MCPToolServiceSearchRequestStateFilterMcpToolStateUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MCPToolServiceSearchRequestStateFilter("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------- | ----------------------------------------------------------------- | +| `MCPToolServiceSearchRequestStateFilterMcpToolStateUnspecified` | MCP_TOOL_STATE_UNSPECIFIED | +| `MCPToolServiceSearchRequestStateFilterMcpToolStatePendingReview` | MCP_TOOL_STATE_PENDING_REVIEW | +| `MCPToolServiceSearchRequestStateFilterMcpToolStateApproved` | MCP_TOOL_STATE_APPROVED | +| `MCPToolServiceSearchRequestStateFilterMcpToolStateDisabled` | MCP_TOOL_STATE_DISABLED | +| `MCPToolServiceSearchRequestStateFilterMcpToolStateRemoved` | MCP_TOOL_STATE_REMOVED | \ No newline at end of file diff --git a/docs/pkg/models/shared/mintgatewaykeyrequest.md b/docs/pkg/models/shared/mintgatewaykeyrequest.md new file mode 100644 index 000000000..c5a1e1060 --- /dev/null +++ b/docs/pkg/models/shared/mintgatewaykeyrequest.md @@ -0,0 +1,10 @@ +# MintGatewayKeyRequest + +The MintGatewayKeyRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------- | ---------------------- | ---------------------- | ---------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/mintgatewaykeyresponse.md b/docs/pkg/models/shared/mintgatewaykeyresponse.md new file mode 100644 index 000000000..f7cb9755e --- /dev/null +++ b/docs/pkg/models/shared/mintgatewaykeyresponse.md @@ -0,0 +1,11 @@ +# MintGatewayKeyResponse + +The MintGatewayKeyResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `GatewayKey` | [*shared.GatewayKey](../../../pkg/models/shared/gatewaykey.md) | :heavy_minus_sign: | N/A | +| `PlaintextKey` | `*string` | :heavy_minus_sign: | The plaintextKey field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/money.md b/docs/pkg/models/shared/money.md new file mode 100644 index 000000000..408f62adf --- /dev/null +++ b/docs/pkg/models/shared/money.md @@ -0,0 +1,15 @@ +# Money + +Money is wire-compatible with google.type.Money field-for-field, so the public + API converts with a field copy. Declared here rather than imported because + protoc-gen-pgdb mirrors a nested message by calling its generated DBReflect, + which only exists for messages this repo generates. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CurrencyCode` | `*string` | :heavy_minus_sign: | ISO 4217 currency code. Must equal the tenant's FundPolicy.currency_code. | +| `Nanos` | `*int` | :heavy_minus_sign: | Nano-unit remainder, 0 <= nanos < 10^9. Non-negative for the same reason
    as units, which also keeps the (units, nanos) pair unambiguous. | +| `Units` | `*int64` | :heavy_minus_sign: | Non-negative — grants, never debts — and bounded so units * 10^9 + nanos
    always fits int64. Without the ceiling a large value wraps positive and
    installs a limit nobody granted. The pair check spans two fields, so
    pkg/funds re-checks it on every conversion. | \ No newline at end of file diff --git a/docs/pkg/models/shared/msteamschannel.md b/docs/pkg/models/shared/msteamschannel.md new file mode 100644 index 000000000..df01ea7ab --- /dev/null +++ b/docs/pkg/models/shared/msteamschannel.md @@ -0,0 +1,11 @@ +# MSTeamsChannel + +The MSTeamsChannel message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------ | ------------------------------ | ------------------------------ | ------------------------------ | +| `ChannelName` | `*string` | :heavy_minus_sign: | The channelName field. | +| `ExternalDirectoryID` | `*string` | :heavy_minus_sign: | The externalDirectoryId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/msteamschannelsettings.md b/docs/pkg/models/shared/msteamschannelsettings.md index 181f6349a..9aa6775e6 100644 --- a/docs/pkg/models/shared/msteamschannelsettings.md +++ b/docs/pkg/models/shared/msteamschannelsettings.md @@ -17,5 +17,7 @@ The MSTeamsChannelSettings message. | `ExpiringAccess` | [*shared.ExpiringAccessPreference](../../../pkg/models/shared/expiringaccesspreference.md) | :heavy_minus_sign: | N/A | | `IsConfigured` | `*bool` | :heavy_minus_sign: | The isConfigured field. | | `ProvisioningRequest` | [*shared.ProvisioningRequestPreference](../../../pkg/models/shared/provisioningrequestpreference.md) | :heavy_minus_sign: | N/A | +| `RequestCreated` | [*shared.RequestCreatedPreference](../../../pkg/models/shared/requestcreatedpreference.md) | :heavy_minus_sign: | N/A | | `Reviews` | [*shared.ReviewsPreference](../../../pkg/models/shared/reviewspreference.md) | :heavy_minus_sign: | N/A | +| `System` | [*shared.SystemPreference](../../../pkg/models/shared/systempreference.md) | :heavy_minus_sign: | N/A | | `TaskReminders` | [*shared.TaskRemindersPreference](../../../pkg/models/shared/taskreminderspreference.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimit.md b/docs/pkg/models/shared/myfundlimit.md new file mode 100644 index 000000000..c31744682 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimit.md @@ -0,0 +1,14 @@ +# MyFundLimit + +MyFundLimit is one of the caller's own per-app limits. It carries no user id: + it is always the caller's. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | The C1 App this limit applies to. | +| `Controls` | [*shared.SpendControls](../../../pkg/models/shared/spendcontrols.md) | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimithistoryentry.md b/docs/pkg/models/shared/myfundlimithistoryentry.md new file mode 100644 index 000000000..11ac38809 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimithistoryentry.md @@ -0,0 +1,11 @@ +# MyFundLimitHistoryEntry + +The MyFundLimitHistoryEntry message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.MyFundLimit](../../../pkg/models/shared/myfundlimit.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicedeleterequest.md b/docs/pkg/models/shared/myfundlimitsservicedeleterequest.md new file mode 100644 index 000000000..f04523555 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicedeleterequest.md @@ -0,0 +1,9 @@ +# MyFundLimitsServiceDeleteRequest + +The MyFundLimitsServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicedeleteresponse.md b/docs/pkg/models/shared/myfundlimitsservicedeleteresponse.md new file mode 100644 index 000000000..53f9fc3bd --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicedeleteresponse.md @@ -0,0 +1,9 @@ +# MyFundLimitsServiceDeleteResponse + +The MyFundLimitsServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicelisthistoryresponse.md b/docs/pkg/models/shared/myfundlimitsservicelisthistoryresponse.md new file mode 100644 index 000000000..702eed0ec --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# MyFundLimitsServiceListHistoryResponse + +The MyFundLimitsServiceListHistoryResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | +| `List` | [][shared.MyFundLimitHistoryEntry](../../../pkg/models/shared/myfundlimithistoryentry.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicelistresponse.md b/docs/pkg/models/shared/myfundlimitsservicelistresponse.md new file mode 100644 index 000000000..48dbf6698 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicelistresponse.md @@ -0,0 +1,11 @@ +# MyFundLimitsServiceListResponse + +The MyFundLimitsServiceListResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | +| `List` | [][shared.MyFundLimit](../../../pkg/models/shared/myfundlimit.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicepauserequest.md b/docs/pkg/models/shared/myfundlimitsservicepauserequest.md new file mode 100644 index 000000000..594ff59eb --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicepauserequest.md @@ -0,0 +1,10 @@ +# MyFundLimitsServicePauseRequest + +The MyFundLimitsServicePauseRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicepauseresponse.md b/docs/pkg/models/shared/myfundlimitsservicepauseresponse.md new file mode 100644 index 000000000..52b5f5754 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicepauseresponse.md @@ -0,0 +1,10 @@ +# MyFundLimitsServicePauseResponse + +The MyFundLimitsServicePauseResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Limit` | [*shared.MyFundLimit](../../../pkg/models/shared/myfundlimit.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsserviceresumerequest.md b/docs/pkg/models/shared/myfundlimitsserviceresumerequest.md new file mode 100644 index 000000000..5b7618476 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsserviceresumerequest.md @@ -0,0 +1,9 @@ +# MyFundLimitsServiceResumeRequest + +The MyFundLimitsServiceResumeRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsserviceresumeresponse.md b/docs/pkg/models/shared/myfundlimitsserviceresumeresponse.md new file mode 100644 index 000000000..424fd8901 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsserviceresumeresponse.md @@ -0,0 +1,10 @@ +# MyFundLimitsServiceResumeResponse + +The MyFundLimitsServiceResumeResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Limit` | [*shared.MyFundLimit](../../../pkg/models/shared/myfundlimit.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicesetlimitrequest.md b/docs/pkg/models/shared/myfundlimitsservicesetlimitrequest.md new file mode 100644 index 000000000..d8ccd4b2f --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicesetlimitrequest.md @@ -0,0 +1,11 @@ +# MyFundLimitsServiceSetLimitRequest + +The MyFundLimitsServiceSetLimitRequest message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.MyFundLimitsServiceSetLimitRequestPeriod](../../../pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md) | :heavy_minus_sign: | Optional period override. Only valid together with the limit it denominates. | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md b/docs/pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md new file mode 100644 index 000000000..0ab70b123 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicesetlimitrequestperiod.md @@ -0,0 +1,28 @@ +# MyFundLimitsServiceSetLimitRequestPeriod + +Optional period override. Only valid together with the limit it denominates. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.MyFundLimitsServiceSetLimitRequestPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.MyFundLimitsServiceSetLimitRequestPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| --------------------------------------------------------------- | --------------------------------------------------------------- | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `MyFundLimitsServiceSetLimitRequestPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/myfundlimitsservicesetlimitresponse.md b/docs/pkg/models/shared/myfundlimitsservicesetlimitresponse.md new file mode 100644 index 000000000..03705b141 --- /dev/null +++ b/docs/pkg/models/shared/myfundlimitsservicesetlimitresponse.md @@ -0,0 +1,10 @@ +# MyFundLimitsServiceSetLimitResponse + +The MyFundLimitsServiceSetLimitResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Limit` | [*shared.MyFundLimit](../../../pkg/models/shared/myfundlimit.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/nameformat.md b/docs/pkg/models/shared/nameformat.md new file mode 100644 index 000000000..db60314e1 --- /dev/null +++ b/docs/pkg/models/shared/nameformat.md @@ -0,0 +1,26 @@ +# NameFormat + +The NameFormat attribute. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.NameFormatSamlAttributeNameFormatUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.NameFormat("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------- | ------------------------------------------------- | +| `NameFormatSamlAttributeNameFormatUnspecified` | SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED | +| `NameFormatSamlAttributeNameFormatURI` | SAML_ATTRIBUTE_NAME_FORMAT_URI | +| `NameFormatSamlAttributeNameFormatBasic` | SAML_ATTRIBUTE_NAME_FORMAT_BASIC | +| `NameFormatSamlAttributeNameFormatUnspecifiedUrn` | SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN | \ No newline at end of file diff --git a/docs/pkg/models/shared/nameidformat.md b/docs/pkg/models/shared/nameidformat.md new file mode 100644 index 000000000..011befbc6 --- /dev/null +++ b/docs/pkg/models/shared/nameidformat.md @@ -0,0 +1,30 @@ +# NameIDFormat + +Set this when the service provider requires a specific NameID format. This + also selects the NameID value semantics: EMAIL_ADDRESS uses the user's + primary email, TRANSIENT creates a new value for each sign-in, and + PERSISTENT uses the application's pairwise subject. Immutable once set. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.NameIDFormatSamlNameIDFormatUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.NameIDFormat("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------------- | -------------------------------------------- | +| `NameIDFormatSamlNameIDFormatUnspecified` | SAML_NAME_ID_FORMAT_UNSPECIFIED | +| `NameIDFormatSamlNameIDFormatPersistent` | SAML_NAME_ID_FORMAT_PERSISTENT | +| `NameIDFormatSamlNameIDFormatEmailAddress` | SAML_NAME_ID_FORMAT_EMAIL_ADDRESS | +| `NameIDFormatSamlNameIDFormatUnspecifiedUrn` | SAML_NAME_ID_FORMAT_UNSPECIFIED_URN | +| `NameIDFormatSamlNameIDFormatTransient` | SAML_NAME_ID_FORMAT_TRANSIENT | \ No newline at end of file diff --git a/docs/pkg/models/shared/nhitypes.md b/docs/pkg/models/shared/nhitypes.md index 906c73ad3..f7fda3360 100644 --- a/docs/pkg/models/shared/nhitypes.md +++ b/docs/pkg/models/shared/nhitypes.md @@ -7,7 +7,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.NhiTypesNhiTypeUnspecified +value := shared.NhiTypesAppUserNhiTypeUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.NhiTypes("custom_value") @@ -16,9 +16,9 @@ custom := shared.NhiTypes("custom_value") ## Values -| Name | Value | -| -------------------------------- | -------------------------------- | -| `NhiTypesNhiTypeUnspecified` | NHI_TYPE_UNSPECIFIED | -| `NhiTypesNhiTypeAppRegistration` | NHI_TYPE_APP_REGISTRATION | -| `NhiTypesNhiTypeAssumableRole` | NHI_TYPE_ASSUMABLE_ROLE | -| `NhiTypesNhiTypeManagedIdentity` | NHI_TYPE_MANAGED_IDENTITY | \ No newline at end of file +| Name | Value | +| --------------------------------------- | --------------------------------------- | +| `NhiTypesAppUserNhiTypeUnspecified` | APP_USER_NHI_TYPE_UNSPECIFIED | +| `NhiTypesAppUserNhiTypeAppRegistration` | APP_USER_NHI_TYPE_APP_REGISTRATION | +| `NhiTypesAppUserNhiTypeAssumableRole` | APP_USER_NHI_TYPE_ASSUMABLE_ROLE | +| `NhiTypesAppUserNhiTypeManagedIdentity` | APP_USER_NHI_TYPE_MANAGED_IDENTITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/notifydispatcher.md b/docs/pkg/models/shared/notifydispatcher.md new file mode 100644 index 000000000..e2b1860fa --- /dev/null +++ b/docs/pkg/models/shared/notifydispatcher.md @@ -0,0 +1,16 @@ +# NotifyDispatcher + +NotifyDispatcher emits a notifications_v2 notification about the matched + finding. Exactly one of audience / slack_channel is set: audience notifies + people (each on whichever channels they enabled in their own notification + settings), slack_channel posts to one channel. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | +| `Audience` | [*shared.FindingAudience](../../../pkg/models/shared/findingaudience.md) | :heavy_minus_sign: | N/A | +| `BatchWindowSeconds` | `*int64` | :heavy_minus_sign: | Wait-group window in seconds; 0 sends immediately. A quiet-period length,
    not a fixed delay — the batcher slides it forward on each arrival. | +| `DetailLevel` | [*shared.DetailLevel](../../../pkg/models/shared/detaillevel.md) | :heavy_minus_sign: | How much the notification reveals. Defaults to SUMMARY. | +| `SlackChannel` | [*shared.SlackChannelTarget](../../../pkg/models/shared/slackchanneltarget.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/oidcclaimmapping.md b/docs/pkg/models/shared/oidcclaimmapping.md new file mode 100644 index 000000000..dedbd325a --- /dev/null +++ b/docs/pkg/models/shared/oidcclaimmapping.md @@ -0,0 +1,13 @@ +# OIDCClaimMapping + +OIDCClaimMapping releases one user attribute to the application as one + OIDC claim. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | +| `ClaimName` | `string` | :heavy_check_mark: | The name of the claim as the application sees it. Namespace custom claims
    so they cannot collide with the registered OIDC claim set. | +| `Destination` | [*shared.Destination](../../../pkg/models/shared/destination.md) | :heavy_minus_sign: | Where the claim is released. | +| `UserAttributeMappingID` | `string` | :heavy_check_mark: | The user attribute mapping that resolves the value, including its fallback
    chain. | \ No newline at end of file diff --git a/docs/pkg/models/shared/operation.md b/docs/pkg/models/shared/operation.md index b6b3b08a5..e122466ed 100644 --- a/docs/pkg/models/shared/operation.md +++ b/docs/pkg/models/shared/operation.md @@ -1,6 +1,6 @@ # Operation -Which connector RPC this dispatches to. +The operation field. ## Example Usage @@ -9,7 +9,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.OperationOperationUnspecified +value := shared.OperationA2UIProvenanceOperationUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.Operation("custom_value") @@ -18,7 +18,16 @@ custom := shared.Operation("custom_value") ## Values -| Name | Value | -| ------------------------------- | ------------------------------- | -| `OperationOperationUnspecified` | OPERATION_UNSPECIFIED | -| `OperationOperationGrant` | OPERATION_GRANT | \ No newline at end of file +| Name | Value | +| ----------------------------------------------- | ----------------------------------------------- | +| `OperationA2UIProvenanceOperationUnspecified` | A2UI_PROVENANCE_OPERATION_UNSPECIFIED | +| `OperationA2UIProvenanceOperationLookedUp` | A2UI_PROVENANCE_OPERATION_LOOKED_UP | +| `OperationA2UIProvenanceOperationCounted` | A2UI_PROVENANCE_OPERATION_COUNTED | +| `OperationA2UIProvenanceOperationFetchedRecord` | A2UI_PROVENANCE_OPERATION_FETCHED_RECORD | +| `OperationA2UIProvenanceOperationSearched` | A2UI_PROVENANCE_OPERATION_SEARCHED | +| `OperationA2UIProvenanceOperationReadTrend` | A2UI_PROVENANCE_OPERATION_READ_TREND | +| `OperationA2UIProvenanceOperationCreated` | A2UI_PROVENANCE_OPERATION_CREATED | +| `OperationA2UIProvenanceOperationUpdated` | A2UI_PROVENANCE_OPERATION_UPDATED | +| `OperationA2UIProvenanceOperationDeleted` | A2UI_PROVENANCE_OPERATION_DELETED | +| `OperationA2UIProvenanceOperationRanProgram` | A2UI_PROVENANCE_OPERATION_RAN_PROGRAM | +| `OperationA2UIProvenanceOperationBuiltReport` | A2UI_PROVENANCE_OPERATION_BUILT_REPORT | \ No newline at end of file diff --git a/docs/pkg/models/shared/payloadfindingdispatch.md b/docs/pkg/models/shared/payloadfindingdispatch.md new file mode 100644 index 000000000..ad89b1653 --- /dev/null +++ b/docs/pkg/models/shared/payloadfindingdispatch.md @@ -0,0 +1,14 @@ +# PayloadFindingDispatch + +The PayloadFindingDispatch message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `DispatchID` | `*string` | :heavy_minus_sign: | The FindingDispatch row recording this execution. | +| `Finding` | [*shared.Finding](../../../pkg/models/shared/finding.md) | :heavy_minus_sign: | N/A | +| `FindingID` | `*string` | :heavy_minus_sign: | The finding that matched the routing rule. | +| `PayloadTemplate` | `*string` | :heavy_minus_sign: | The dispatcher's rendered payload template. Empty when the dispatcher used
    the default finding payload. | +| `RuleID` | `*string` | :heavy_minus_sign: | The routing rule whose match caused this dispatch. | \ No newline at end of file diff --git a/docs/pkg/models/shared/period.md b/docs/pkg/models/shared/period.md index 69ce46fae..778745e83 100644 --- a/docs/pkg/models/shared/period.md +++ b/docs/pkg/models/shared/period.md @@ -1,6 +1,6 @@ # Period -Snapshot of the period at trip time. +Optional period override. Only valid together with the limit it denominates. ## Example Usage @@ -9,7 +9,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.PeriodCircuitBreakerPeriodUnspecified +value := shared.PeriodPeriodKindUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.Period("custom_value") @@ -18,10 +18,11 @@ custom := shared.Period("custom_value") ## Values -| Name | Value | -| --------------------------------------- | --------------------------------------- | -| `PeriodCircuitBreakerPeriodUnspecified` | CIRCUIT_BREAKER_PERIOD_UNSPECIFIED | -| `PeriodCircuitBreakerPeriodHour` | CIRCUIT_BREAKER_PERIOD_HOUR | -| `PeriodCircuitBreakerPeriodDay` | CIRCUIT_BREAKER_PERIOD_DAY | -| `PeriodCircuitBreakerPeriodWeek` | CIRCUIT_BREAKER_PERIOD_WEEK | -| `PeriodCircuitBreakerPeriodMonth` | CIRCUIT_BREAKER_PERIOD_MONTH | \ No newline at end of file +| Name | Value | +| ----------------------------- | ----------------------------- | +| `PeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `PeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `PeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `PeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `PeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `PeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/pkcepolicy.md b/docs/pkg/models/shared/pkcepolicy.md new file mode 100644 index 000000000..d72fbc6ab --- /dev/null +++ b/docs/pkg/models/shared/pkcepolicy.md @@ -0,0 +1,25 @@ +# PkcePolicy + +Effective PKCE policy. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.PkcePolicySsoApplicationOidcPkcePolicyUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.PkcePolicy("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------- | ------------------------------------------------------------- | +| `PkcePolicySsoApplicationOidcPkcePolicyUnspecified` | SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED | +| `PkcePolicySsoApplicationOidcPkcePolicyRequiredS256` | SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256 | +| `PkcePolicySsoApplicationOidcPkcePolicyAllowMissingForLegacy` | SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY | \ No newline at end of file diff --git a/docs/pkg/models/shared/policy.md b/docs/pkg/models/shared/policy.md index 2d519a6cd..45f63bcc2 100644 --- a/docs/pkg/models/shared/policy.md +++ b/docs/pkg/models/shared/policy.md @@ -8,18 +8,20 @@ A policy defines a workflow (sequence of steps) that runs when processing ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `Annotations` | map[string]`string` | :heavy_minus_sign: | Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256
    chars; URL-safe ASCII. Keys starting with `c1/` are reserved.

    Updates have PATCH semantics: keys absent from the request are
    preserved; an empty value deletes the key.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Description` | `*string` | :heavy_minus_sign: | The description of the Policy. | -| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the Policy. | -| `ID` | `*string` | :heavy_minus_sign: | The ID of the Policy. | -| `PolicySteps` | map[string][shared.PolicySteps](../../../pkg/models/shared/policysteps.md) | :heavy_minus_sign: | A map from string keys to step sequences. One entry is always the baseline,
    keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify").
    Additional entries have opaque keys (UUIDs) and are referenced by the rules
    array for conditional routing. If no conditional rules are configured, only
    the baseline entry exists. | -| `PolicyType` | [*shared.PolicyPolicyType](../../../pkg/models/shared/policypolicytype.md) | :heavy_minus_sign: | The type of this policy (grant, revoke, or certify). The lowercased type
    name (e.g., "grant") is also the key for the baseline entry in policy_steps. | -| `PostActions` | [][shared.PolicyPostActions](../../../pkg/models/shared/policypostactions.md) | :heavy_minus_sign: | Ordered actions to execute after the policy completes processing. | -| ~~`ReassignTasksToDelegates`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    This field is no longer used. Configure delegate reassignment in the policy step instead. | -| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Ordered conditional routing rules. Evaluated top-to-bottom; the first
    matching rule selects a step sequence from policy_steps. If no rule matches
    (or if this array is empty), the baseline entry in policy_steps is used. | -| `SystemBuiltin` | `*bool` | :heavy_minus_sign: | Whether this policy is a builtin system policy. Builtin system policies cannot be edited. | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Annotations` | map[string]`string` | :heavy_minus_sign: | Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256
    chars; URL-safe ASCII. Keys starting with `c1/` are reserved.

    Updates have PATCH semantics: keys absent from the request are
    preserved; an empty value deletes the key.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | +| `BaselinePolicyID` | `*string` | :heavy_minus_sign: | When set, the baseline defers to another policy of the same type when no
    rule matches, instead of the baseline entry in policy_steps (keyed by the
    lowercased policy_type). Mutually exclusive with that baseline entry: set
    one or the other, not both. The referenced policy must share this
    policy's policy_type, must not introduce a cycle or self-reference, and
    must not push any reachable chain over depth 5. Gated by the
    POLICY_REFERENCES_POLICY feature flag. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | The description of the Policy. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the Policy. | +| `ID` | `*string` | :heavy_minus_sign: | The ID of the Policy. | +| `PolicySteps` | map[string][shared.PolicySteps](../../../pkg/models/shared/policysteps.md) | :heavy_minus_sign: | A map from string keys to step sequences. One entry is always the baseline,
    keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify").
    Additional entries have opaque keys (UUIDs) and are referenced by the rules
    array for conditional routing. If no conditional rules are configured, only
    the baseline entry exists. | +| `PolicyType` | [*shared.PolicyPolicyType](../../../pkg/models/shared/policypolicytype.md) | :heavy_minus_sign: | The type of this policy (grant, revoke, or certify). The lowercased type
    name (e.g., "grant") is also the key for the baseline entry in policy_steps. | +| `PostActions` | [][shared.PolicyPostActions](../../../pkg/models/shared/policypostactions.md) | :heavy_minus_sign: | Ordered actions to execute after the policy completes processing. | +| ~~`ReassignTasksToDelegates`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    This field is no longer used. Configure delegate reassignment in the policy step instead. | +| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Ordered conditional routing rules. Evaluated top-to-bottom; the first
    matching rule selects a step sequence from policy_steps. If no rule matches
    (or if this array is empty), the baseline entry in policy_steps is used. | +| `Scope` | [*shared.PolicyScope](../../../pkg/models/shared/policyscope.md) | :heavy_minus_sign: | N/A | +| `SystemBuiltin` | `*bool` | :heavy_minus_sign: | Whether this policy is a builtin system policy. Builtin system policies cannot be edited. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/policyinput.md b/docs/pkg/models/shared/policyinput.md index 6032e2f80..3cc435242 100644 --- a/docs/pkg/models/shared/policyinput.md +++ b/docs/pkg/models/shared/policyinput.md @@ -8,13 +8,15 @@ A policy defines a workflow (sequence of steps) that runs when processing ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `Annotations` | map[string]`string` | :heavy_minus_sign: | Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256
    chars; URL-safe ASCII. Keys starting with `c1/` are reserved.

    Updates have PATCH semantics: keys absent from the request are
    preserved; an empty value deletes the key.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | -| `Description` | `*string` | :heavy_minus_sign: | The description of the Policy. | -| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the Policy. | -| `PolicySteps` | map[string][shared.PolicyStepsInput](../../../pkg/models/shared/policystepsinput.md) | :heavy_minus_sign: | A map from string keys to step sequences. One entry is always the baseline,
    keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify").
    Additional entries have opaque keys (UUIDs) and are referenced by the rules
    array for conditional routing. If no conditional rules are configured, only
    the baseline entry exists. | -| `PolicyType` | [*shared.PolicyPolicyType](../../../pkg/models/shared/policypolicytype.md) | :heavy_minus_sign: | The type of this policy (grant, revoke, or certify). The lowercased type
    name (e.g., "grant") is also the key for the baseline entry in policy_steps. | -| `PostActions` | [][shared.PolicyPostActions](../../../pkg/models/shared/policypostactions.md) | :heavy_minus_sign: | Ordered actions to execute after the policy completes processing. | -| ~~`ReassignTasksToDelegates`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    This field is no longer used. Configure delegate reassignment in the policy step instead. | -| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Ordered conditional routing rules. Evaluated top-to-bottom; the first
    matching rule selects a step sequence from policy_steps. If no rule matches
    (or if this array is empty), the baseline entry in policy_steps is used. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Annotations` | map[string]`string` | :heavy_minus_sign: | Key/value metadata. Up to 16 entries; keys 1-128 chars; values 0-256
    chars; URL-safe ASCII. Keys starting with `c1/` are reserved.

    Updates have PATCH semantics: keys absent from the request are
    preserved; an empty value deletes the key.

    Well-known keys: `managed_by`, `iac_workspace`,
    `iac_resource_address`, `iac_tool_version`. | +| `BaselinePolicyID` | `*string` | :heavy_minus_sign: | When set, the baseline defers to another policy of the same type when no
    rule matches, instead of the baseline entry in policy_steps (keyed by the
    lowercased policy_type). Mutually exclusive with that baseline entry: set
    one or the other, not both. The referenced policy must share this
    policy's policy_type, must not introduce a cycle or self-reference, and
    must not push any reachable chain over depth 5. Gated by the
    POLICY_REFERENCES_POLICY feature flag. | +| `Description` | `*string` | :heavy_minus_sign: | The description of the Policy. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The display name of the Policy. | +| `PolicySteps` | map[string][shared.PolicyStepsInput](../../../pkg/models/shared/policystepsinput.md) | :heavy_minus_sign: | A map from string keys to step sequences. One entry is always the baseline,
    keyed by the lowercased policy_type (e.g., "grant", "revoke", "certify").
    Additional entries have opaque keys (UUIDs) and are referenced by the rules
    array for conditional routing. If no conditional rules are configured, only
    the baseline entry exists. | +| `PolicyType` | [*shared.PolicyPolicyType](../../../pkg/models/shared/policypolicytype.md) | :heavy_minus_sign: | The type of this policy (grant, revoke, or certify). The lowercased type
    name (e.g., "grant") is also the key for the baseline entry in policy_steps. | +| `PostActions` | [][shared.PolicyPostActions](../../../pkg/models/shared/policypostactions.md) | :heavy_minus_sign: | Ordered actions to execute after the policy completes processing. | +| ~~`ReassignTasksToDelegates`~~ | `*bool` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    This field is no longer used. Configure delegate reassignment in the policy step instead. | +| `Rules` | [][shared.Rule](../../../pkg/models/shared/rule.md) | :heavy_minus_sign: | Ordered conditional routing rules. Evaluated top-to-bottom; the first
    matching rule selects a step sequence from policy_steps. If no rule matches
    (or if this array is empty), the baseline entry in policy_steps is used. | +| `Scope` | [*shared.PolicyScope](../../../pkg/models/shared/policyscope.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/policyscope.md b/docs/pkg/models/shared/policyscope.md new file mode 100644 index 000000000..f14c51f76 --- /dev/null +++ b/docs/pkg/models/shared/policyscope.md @@ -0,0 +1,12 @@ +# PolicyScope + +Scopes a policy to an app or to a single entitlement within an app. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | Optional. When set, the policy is scoped to this entitlement of app_id
    rather than to the whole app. | +| `AppID` | `*string` | :heavy_minus_sign: | The ID of the app this policy is scoped to. | +| `Slot` | [*shared.Slot](../../../pkg/models/shared/slot.md) | :heavy_minus_sign: | Which of the object's local-policy slots this policy occupies. Part of the
    scope, and immutable with it. | \ No newline at end of file diff --git a/docs/pkg/models/shared/pretoolblockconfig.md b/docs/pkg/models/shared/pretoolblockconfig.md new file mode 100644 index 000000000..d732ce47b --- /dev/null +++ b/docs/pkg/models/shared/pretoolblockconfig.md @@ -0,0 +1,11 @@ +# PreToolBlockConfig + +PreToolBlockConfig unconditionally denies the tool call before it executes + when its hook's filter matches. Only valid for HOOK_EVENT_TYPE_PRE_TOOL_USE. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | +| `Message` | `*string` | :heavy_minus_sign: | Message shown when the tool call is denied. Empty falls back to a
    generic default. | \ No newline at end of file diff --git a/docs/pkg/models/shared/programref.md b/docs/pkg/models/shared/programref.md new file mode 100644 index 000000000..d706747e2 --- /dev/null +++ b/docs/pkg/models/shared/programref.md @@ -0,0 +1,12 @@ +# ProgramRef + +ProgramRef points at a pinned, executable program. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CommitID` | `*string` | :heavy_minus_sign: | Code mode invokes by explicit commit, so the commit — not the function — is
    what a refresh re-executes. | +| `FunctionID` | `*string` | :heavy_minus_sign: | A saved report owns its Function, so this is per-report rather than the
    shared code-mode scratch function the program first ran on. | +| `PlannedFromPrompt` | `*string` | :heavy_minus_sign: | The prompt this program was planned from. Report.prompt is editable and a
    refresh never re-plans, so this is the only way to detect that a report's
    question has drifted from the program answering it. | \ No newline at end of file diff --git a/docs/pkg/models/shared/promoteappmanagedstatebindingrequest.md b/docs/pkg/models/shared/promoteappmanagedstatebindingrequest.md new file mode 100644 index 000000000..6f98dbc0f --- /dev/null +++ b/docs/pkg/models/shared/promoteappmanagedstatebindingrequest.md @@ -0,0 +1,12 @@ +# PromoteAppManagedStateBindingRequest + +PromoteAppManagedStateBindingRequest identifies an unmanaged application and configures its owners. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `AppEntitlementOwnerRefs` | [][shared.AppEntitlementRef](../../../pkg/models/shared/appentitlementref.md) | :heavy_minus_sign: | Entitlements to assign as owners of the new application. | +| `ExpandMask` | [*shared.AppManagedStateBindingExpandMask](../../../pkg/models/shared/appmanagedstatebindingexpandmask.md) | :heavy_minus_sign: | N/A | +| `UserIds` | []`string` | :heavy_minus_sign: | User IDs to assign as owners of the new application.
    If omitted, the application inherits the owners of the source connector application. | \ No newline at end of file diff --git a/docs/pkg/models/shared/promptinjectionscanconfig.md b/docs/pkg/models/shared/promptinjectionscanconfig.md new file mode 100644 index 000000000..42eacc53e --- /dev/null +++ b/docs/pkg/models/shared/promptinjectionscanconfig.md @@ -0,0 +1,12 @@ +# PromptInjectionScanConfig + +PromptInjectionScanConfig scans tool output for prompt-injection using the + aigov A2 judge and acts when the verdict is at or above threshold. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | +| `FlagOnly` | `*bool` | :heavy_minus_sign: | When true, a detection records the finding but does not deny (observe-only). | +| `Threshold` | [*shared.Threshold](../../../pkg/models/shared/threshold.md) | :heavy_minus_sign: | Deny (or flag) when the judge scores at or above this level. Unspecified =
    HIGH. | \ No newline at end of file diff --git a/docs/pkg/models/shared/providercredential.md b/docs/pkg/models/shared/providercredential.md new file mode 100644 index 000000000..583197111 --- /dev/null +++ b/docs/pkg/models/shared/providercredential.md @@ -0,0 +1,17 @@ +# ProviderCredential + +The ProviderCredential message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `HeaderStyle` | [*shared.HeaderStyle](../../../pkg/models/shared/headerstyle.md) | :heavy_minus_sign: | The headerStyle field. | +| `KeyPrefix` | `*string` | :heavy_minus_sign: | The keyPrefix field. | +| `RevokedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `SlotID` | `*string` | :heavy_minus_sign: | The slotId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `UserID` | `*string` | :heavy_minus_sign: | The userId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/provisioninstance.md b/docs/pkg/models/shared/provisioninstance.md index bdeb7b29f..3ee1532ce 100644 --- a/docs/pkg/models/shared/provisioninstance.md +++ b/docs/pkg/models/shared/provisioninstance.md @@ -26,5 +26,6 @@ This message contains a oneof named outcome. Only a single field of the followin | `ReassignedByError` | [*shared.ReassignedByErrorAction](../../../pkg/models/shared/reassignedbyerroraction.md) | :heavy_minus_sign: | N/A | | `Skipped` | [*shared.SkippedAction](../../../pkg/models/shared/skippedaction.md) | :heavy_minus_sign: | N/A | | `State` | [*shared.ProvisionInstanceState](../../../pkg/models/shared/provisioninstancestate.md) | :heavy_minus_sign: | This property indicates the current state of this step. | +| `WaitingOn` | [*shared.ProvisionWaitingOn](../../../pkg/models/shared/provisionwaitingon.md) | :heavy_minus_sign: | N/A | | `WebhookID` | `*string` | :heavy_minus_sign: | This indicates the webhook id for this step. | | `WebhookInstanceID` | `*string` | :heavy_minus_sign: | This indicates the webhook instance id for this step. | \ No newline at end of file diff --git a/docs/pkg/models/shared/provisioninstancestate.md b/docs/pkg/models/shared/provisioninstancestate.md index 604b4ef6d..26ea1eff7 100644 --- a/docs/pkg/models/shared/provisioninstancestate.md +++ b/docs/pkg/models/shared/provisioninstancestate.md @@ -31,4 +31,5 @@ custom := shared.ProvisionInstanceState("custom_value") | `ProvisionInstanceStateProvisionInstanceStateExternalTicketWaiting` | PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING | | `ProvisionInstanceStateProvisionInstanceStateAccountLifecycleActions` | PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS | | `ProvisionInstanceStateProvisionInstanceStateAccountLifecycleActionsWaiting` | PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING | +| `ProvisionInstanceStateProvisionInstanceStateDevicePlacement` | PROVISION_INSTANCE_STATE_DEVICE_PLACEMENT | | `ProvisionInstanceStateProvisionInstanceStateDone` | PROVISION_INSTANCE_STATE_DONE | \ No newline at end of file diff --git a/docs/pkg/models/shared/provisionpolicy.md b/docs/pkg/models/shared/provisionpolicy.md index cff4aad12..46f829b69 100644 --- a/docs/pkg/models/shared/provisionpolicy.md +++ b/docs/pkg/models/shared/provisionpolicy.md @@ -11,18 +11,20 @@ This message contains a oneof named typ. Only a single field of the following li - externalTicket - unconfigured - action + - devicePlacement ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | -| `Action` | [*shared.ActionProvision](../../../pkg/models/shared/actionprovision.md) | :heavy_minus_sign: | N/A | -| `Connector` | [*shared.ConnectorProvision](../../../pkg/models/shared/connectorprovision.md) | :heavy_minus_sign: | N/A | -| `Delegated` | [*shared.DelegatedProvision](../../../pkg/models/shared/delegatedprovision.md) | :heavy_minus_sign: | N/A | -| `ExternalTicket` | [*shared.ExternalTicketProvision](../../../pkg/models/shared/externalticketprovision.md) | :heavy_minus_sign: | N/A | -| `Manual` | [*shared.ManualProvision](../../../pkg/models/shared/manualprovision.md) | :heavy_minus_sign: | N/A | -| `MultiStep` | [*shared.MultiStep](../../../pkg/models/shared/multistep.md) | :heavy_minus_sign: | N/A | -| `Unconfigured` | [*shared.UnconfiguredProvision](../../../pkg/models/shared/unconfiguredprovision.md) | :heavy_minus_sign: | N/A | -| `Webhook` | [*shared.WebhookProvision](../../../pkg/models/shared/webhookprovision.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `Action` | [*shared.ActionProvision](../../../pkg/models/shared/actionprovision.md) | :heavy_minus_sign: | N/A | +| `Connector` | [*shared.ConnectorProvision](../../../pkg/models/shared/connectorprovision.md) | :heavy_minus_sign: | N/A | +| `Delegated` | [*shared.DelegatedProvision](../../../pkg/models/shared/delegatedprovision.md) | :heavy_minus_sign: | N/A | +| `DevicePlacement` | [*shared.DevicePlacementProvision](../../../pkg/models/shared/deviceplacementprovision.md) | :heavy_minus_sign: | N/A | +| `ExternalTicket` | [*shared.ExternalTicketProvision](../../../pkg/models/shared/externalticketprovision.md) | :heavy_minus_sign: | N/A | +| `Manual` | [*shared.ManualProvision](../../../pkg/models/shared/manualprovision.md) | :heavy_minus_sign: | N/A | +| `MultiStep` | [*shared.MultiStep](../../../pkg/models/shared/multistep.md) | :heavy_minus_sign: | N/A | +| `Unconfigured` | [*shared.UnconfiguredProvision](../../../pkg/models/shared/unconfiguredprovision.md) | :heavy_minus_sign: | N/A | +| `Webhook` | [*shared.WebhookProvision](../../../pkg/models/shared/webhookprovision.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/provisionpolicyinput.md b/docs/pkg/models/shared/provisionpolicyinput.md index 9fd9c6ca4..5bbdcf435 100644 --- a/docs/pkg/models/shared/provisionpolicyinput.md +++ b/docs/pkg/models/shared/provisionpolicyinput.md @@ -11,18 +11,20 @@ This message contains a oneof named typ. Only a single field of the following li - externalTicket - unconfigured - action + - devicePlacement ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | -| `Action` | [*shared.ActionProvision](../../../pkg/models/shared/actionprovision.md) | :heavy_minus_sign: | N/A | -| `Connector` | [*shared.ConnectorProvision](../../../pkg/models/shared/connectorprovision.md) | :heavy_minus_sign: | N/A | -| `Delegated` | [*shared.DelegatedProvision](../../../pkg/models/shared/delegatedprovision.md) | :heavy_minus_sign: | N/A | -| `ExternalTicket` | [*shared.ExternalTicketProvision](../../../pkg/models/shared/externalticketprovision.md) | :heavy_minus_sign: | N/A | -| `Manual` | [*shared.ManualProvision](../../../pkg/models/shared/manualprovision.md) | :heavy_minus_sign: | N/A | -| `MultiStep` | [*shared.MultiStep](../../../pkg/models/shared/multistep.md) | :heavy_minus_sign: | N/A | -| `Unconfigured` | [*shared.UnconfiguredProvision](../../../pkg/models/shared/unconfiguredprovision.md) | :heavy_minus_sign: | N/A | -| `Webhook` | [*shared.WebhookProvision](../../../pkg/models/shared/webhookprovision.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `Action` | [*shared.ActionProvision](../../../pkg/models/shared/actionprovision.md) | :heavy_minus_sign: | N/A | +| `Connector` | [*shared.ConnectorProvision](../../../pkg/models/shared/connectorprovision.md) | :heavy_minus_sign: | N/A | +| `Delegated` | [*shared.DelegatedProvision](../../../pkg/models/shared/delegatedprovision.md) | :heavy_minus_sign: | N/A | +| `DevicePlacement` | [*shared.DevicePlacementProvision](../../../pkg/models/shared/deviceplacementprovision.md) | :heavy_minus_sign: | N/A | +| `ExternalTicket` | [*shared.ExternalTicketProvision](../../../pkg/models/shared/externalticketprovision.md) | :heavy_minus_sign: | N/A | +| `Manual` | [*shared.ManualProvision](../../../pkg/models/shared/manualprovision.md) | :heavy_minus_sign: | N/A | +| `MultiStep` | [*shared.MultiStep](../../../pkg/models/shared/multistep.md) | :heavy_minus_sign: | N/A | +| `Unconfigured` | [*shared.UnconfiguredProvision](../../../pkg/models/shared/unconfiguredprovision.md) | :heavy_minus_sign: | N/A | +| `Webhook` | [*shared.WebhookProvision](../../../pkg/models/shared/webhookprovision.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/provisionwaitingon.md b/docs/pkg/models/shared/provisionwaitingon.md new file mode 100644 index 000000000..b28152b2d --- /dev/null +++ b/docs/pkg/models/shared/provisionwaitingon.md @@ -0,0 +1,18 @@ +# ProvisionWaitingOn + +Describes why a provision step is paused in the WAITING state. + +This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - entitlementMerge + - devicePlacement + + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `DevicePlacement` | [*shared.WaitingForDevicePlacement](../../../pkg/models/shared/waitingfordeviceplacement.md) | :heavy_minus_sign: | N/A | +| `EntitlementMerge` | [*shared.WaitingForEntitlementMerge](../../../pkg/models/shared/waitingforentitlementmerge.md) | :heavy_minus_sign: | N/A | +| `FallbackAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `StartedWaitingAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reason.md b/docs/pkg/models/shared/reason.md new file mode 100644 index 000000000..8e491734a --- /dev/null +++ b/docs/pkg/models/shared/reason.md @@ -0,0 +1,26 @@ +# Reason + +The reason field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ReasonDeactivatedOwnerReasonUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Reason("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------ | ------------------------------------------------ | +| `ReasonDeactivatedOwnerReasonUnspecified` | DEACTIVATED_OWNER_REASON_UNSPECIFIED | +| `ReasonDeactivatedOwnerReasonUserDeleted` | DEACTIVATED_OWNER_REASON_USER_DELETED | +| `ReasonDeactivatedOwnerReasonUserDisabled` | DEACTIVATED_OWNER_REASON_USER_DISABLED | +| `ReasonDeactivatedOwnerReasonEmploymentInactive` | DEACTIVATED_OWNER_REASON_EMPLOYMENT_INACTIVE | \ No newline at end of file diff --git a/docs/pkg/models/shared/recordtype.md b/docs/pkg/models/shared/recordtype.md new file mode 100644 index 000000000..16401d5e7 --- /dev/null +++ b/docs/pkg/models/shared/recordtype.md @@ -0,0 +1,52 @@ +# RecordType + +Not always the step's own type: a step over grants can be narrowed to one + app, and the app is the record worth naming. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.RecordTypeA2UIProvenanceRecordTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.RecordType("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------- | ----------------------------------------------------------- | +| `RecordTypeA2UIProvenanceRecordTypeUnspecified` | A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED | +| `RecordTypeA2UIProvenanceRecordTypeApp` | A2UI_PROVENANCE_RECORD_TYPE_APP | +| `RecordTypeA2UIProvenanceRecordTypeUser` | A2UI_PROVENANCE_RECORD_TYPE_USER | +| `RecordTypeA2UIProvenanceRecordTypeGrant` | A2UI_PROVENANCE_RECORD_TYPE_GRANT | +| `RecordTypeA2UIProvenanceRecordTypeAppEntitlement` | A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT | +| `RecordTypeA2UIProvenanceRecordTypeAppUser` | A2UI_PROVENANCE_RECORD_TYPE_APP_USER | +| `RecordTypeA2UIProvenanceRecordTypeAppResource` | A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE | +| `RecordTypeA2UIProvenanceRecordTypeAppResourceType` | A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE | +| `RecordTypeA2UIProvenanceRecordTypeTask` | A2UI_PROVENANCE_RECORD_TYPE_TASK | +| `RecordTypeA2UIProvenanceRecordTypePolicy` | A2UI_PROVENANCE_RECORD_TYPE_POLICY | +| `RecordTypeA2UIProvenanceRecordTypeConnector` | A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR | +| `RecordTypeA2UIProvenanceRecordTypeAccessReview` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW | +| `RecordTypeA2UIProvenanceRecordTypeAccessReviewTemplate` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE | +| `RecordTypeA2UIProvenanceRecordTypeAccessReviewSelection` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION | +| `RecordTypeA2UIProvenanceRecordTypeConflictMonitor` | A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR | +| `RecordTypeA2UIProvenanceRecordTypeAccessViolation` | A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION | +| `RecordTypeA2UIProvenanceRecordTypeRequestCatalog` | A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG | +| `RecordTypeA2UIProvenanceRecordTypeWebhook` | A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK | +| `RecordTypeA2UIProvenanceRecordTypeDirectory` | A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY | +| `RecordTypeA2UIProvenanceRecordTypeProfileType` | A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE | +| `RecordTypeA2UIProvenanceRecordTypeRoleBinding` | A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING | +| `RecordTypeA2UIProvenanceRecordTypeAutomationExecution` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION | +| `RecordTypeA2UIProvenanceRecordTypeAutomationExecutionStep` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP | +| `RecordTypeA2UIProvenanceRecordTypeFinding` | A2UI_PROVENANCE_RECORD_TYPE_FINDING | +| `RecordTypeA2UIProvenanceRecordTypeMetric` | A2UI_PROVENANCE_RECORD_TYPE_METRIC | +| `RecordTypeA2UIProvenanceRecordTypeAutomation` | A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION | +| `RecordTypeA2UIProvenanceRecordTypeGrantHistory` | A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY | +| `RecordTypeA2UIProvenanceRecordTypeGrantReason` | A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON | +| `RecordTypeA2UIProvenanceRecordTypeAppOwner` | A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER | \ No newline at end of file diff --git a/docs/pkg/models/shared/recurrencerule.md b/docs/pkg/models/shared/recurrencerule.md index 6e179b4e8..266b4da58 100644 --- a/docs/pkg/models/shared/recurrencerule.md +++ b/docs/pkg/models/shared/recurrencerule.md @@ -13,7 +13,7 @@ This message contains a oneof named end_condition. Only a single field of the fo | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | | `EndDate` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Frequency` | [*shared.RecurrenceRuleFrequency](../../../pkg/models/shared/recurrencerulefrequency.md) | :heavy_minus_sign: | The frequency field. | +| `Frequency` | [shared.RecurrenceRuleFrequency](../../../pkg/models/shared/recurrencerulefrequency.md) | :heavy_check_mark: | Frequency of the recurrence: FREQUENCY_DAILY, FREQUENCY_WEEKLY, FREQUENCY_MONTHLY, or FREQUENCY_YEARLY.
    Use FREQUENCY_NONE for a non-recurring schedule. | | `Interval` | `*int` | :heavy_minus_sign: | The interval field. | | `Occurrences` | `*int` | :heavy_minus_sign: | The occurrences field.
    This field is part of the `end_condition` oneof.
    See the documentation for `c1.api.accessreview.v1.RecurrenceRule` for more details. | | `StartDate` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/recurrencerulefrequency.md b/docs/pkg/models/shared/recurrencerulefrequency.md index 5362138af..35a26697d 100644 --- a/docs/pkg/models/shared/recurrencerulefrequency.md +++ b/docs/pkg/models/shared/recurrencerulefrequency.md @@ -1,6 +1,7 @@ # RecurrenceRuleFrequency -The frequency field. +Frequency of the recurrence: FREQUENCY_DAILY, FREQUENCY_WEEKLY, FREQUENCY_MONTHLY, or FREQUENCY_YEARLY. + Use FREQUENCY_NONE for a non-recurring schedule. ## Example Usage diff --git a/docs/pkg/models/shared/report.md b/docs/pkg/models/shared/report.md new file mode 100644 index 000000000..2a7cd23ef --- /dev/null +++ b/docs/pkg/models/shared/report.md @@ -0,0 +1,23 @@ +# Report + +Report is a saved report: the question, the program that answers it, and the + parameters a re-run may vary. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `CreatedByUserID` | `*string` | :heavy_minus_sign: | The createdByUserId field. | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `ID` | `*string` | :heavy_minus_sign: | The id field. | +| `LatestRunID` | `*string` | :heavy_minus_sign: | Separate pointers: the last attempt may have failed while callers still need
    the last renderable result. | +| `LatestSuccessfulRunID` | `*string` | :heavy_minus_sign: | The latestSuccessfulRunId field. | +| `ParameterSchema` | map[string]`any` | :heavy_minus_sign: | N/A | +| `ParameterValues` | map[string]`any` | :heavy_minus_sign: | N/A | +| `Program` | [*shared.ProgramRef](../../../pkg/models/shared/programref.md) | :heavy_minus_sign: | N/A | +| `Prompt` | `*string` | :heavy_minus_sign: | The editable natural-language question. Only a re-plan reads this. | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicedeleterequest.md b/docs/pkg/models/shared/reportingservicedeleterequest.md new file mode 100644 index 000000000..ae2f6b8de --- /dev/null +++ b/docs/pkg/models/shared/reportingservicedeleterequest.md @@ -0,0 +1,9 @@ +# ReportingServiceDeleteRequest + +The ReportingServiceDeleteRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicedeleteresponse.md b/docs/pkg/models/shared/reportingservicedeleteresponse.md new file mode 100644 index 000000000..798ade828 --- /dev/null +++ b/docs/pkg/models/shared/reportingservicedeleteresponse.md @@ -0,0 +1,9 @@ +# ReportingServiceDeleteResponse + +The ReportingServiceDeleteResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicegetresponse.md b/docs/pkg/models/shared/reportingservicegetresponse.md new file mode 100644 index 000000000..b6a48db85 --- /dev/null +++ b/docs/pkg/models/shared/reportingservicegetresponse.md @@ -0,0 +1,13 @@ +# ReportingServiceGetResponse + +The ReportingServiceGetResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `LatestRun` | [*shared.ReportRun](../../../pkg/models/shared/reportrun.md) | :heavy_minus_sign: | N/A | +| `LatestSuccessfulRun` | [*shared.ReportRun](../../../pkg/models/shared/reportrun.md) | :heavy_minus_sign: | N/A | +| `PromptDrifted` | `*bool` | :heavy_minus_sign: | True when prompt no longer matches program.planned_from_prompt. A rerun
    re-executes and never re-plans, so an edited question leaves the program
    answering the old one. | +| `Report` | [*shared.Report](../../../pkg/models/shared/report.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicegetrunprovenanceresponse.md b/docs/pkg/models/shared/reportingservicegetrunprovenanceresponse.md new file mode 100644 index 000000000..4e890055e --- /dev/null +++ b/docs/pkg/models/shared/reportingservicegetrunprovenanceresponse.md @@ -0,0 +1,16 @@ +# ReportingServiceGetRunProvenanceResponse + +The ReportingServiceGetRunProvenanceResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | +| `ProgramCommitID` | `*string` | :heavy_minus_sign: | The programCommitId field. | +| `ProgramFunctionID` | `*string` | :heavy_minus_sign: | The programFunctionId field. | +| `ProgramInput` | `*string` | :heavy_minus_sign: | The parameters this run was bound to, as JSON. "{}" for a program that
    takes none — a real answer, distinct from absent. | +| `ProgramSource` | `*string` | :heavy_minus_sign: | The programSource field. | +| `Sources` | [][shared.A2UIProvenanceSource](../../../pkg/models/shared/a2uiprovenancesource.md) | :heavy_minus_sign: | What each part of the report shows, read off the run's own copy of the
    surface rather than a live one. | +| `Steps` | [][shared.A2UIProvenanceStep](../../../pkg/models/shared/a2uiprovenancestep.md) | :heavy_minus_sign: | What the program looked at, derived from its source. | +| `StepsAvailable` | `*bool` | :heavy_minus_sign: | False when the program's source could not be read, which is what makes an
    empty steps list mean "unknown" rather than "it read nothing". | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicelistresponse.md b/docs/pkg/models/shared/reportingservicelistresponse.md new file mode 100644 index 000000000..967bc1b81 --- /dev/null +++ b/docs/pkg/models/shared/reportingservicelistresponse.md @@ -0,0 +1,11 @@ +# ReportingServiceListResponse + +The ReportingServiceListResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | +| `List` | [][shared.Report](../../../pkg/models/shared/report.md) | :heavy_minus_sign: | The list field. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | The nextPageToken field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicerunrequest.md b/docs/pkg/models/shared/reportingservicerunrequest.md new file mode 100644 index 000000000..77caa5a0f --- /dev/null +++ b/docs/pkg/models/shared/reportingservicerunrequest.md @@ -0,0 +1,9 @@ +# ReportingServiceRunRequest + +The ReportingServiceRunRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicerunresponse.md b/docs/pkg/models/shared/reportingservicerunresponse.md new file mode 100644 index 000000000..1f484e3d7 --- /dev/null +++ b/docs/pkg/models/shared/reportingservicerunresponse.md @@ -0,0 +1,10 @@ +# ReportingServiceRunResponse + +The ReportingServiceRunResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `Run` | [*shared.ReportRun](../../../pkg/models/shared/reportrun.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicesaverequest.md b/docs/pkg/models/shared/reportingservicesaverequest.md new file mode 100644 index 000000000..6db664d76 --- /dev/null +++ b/docs/pkg/models/shared/reportingservicesaverequest.md @@ -0,0 +1,13 @@ +# ReportingServiceSaveRequest + +The ReportingServiceSaveRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ConversationID` | `*string` | :heavy_minus_sign: | The conversation and surface are both required to address a rendered
    surface; neither identifies one alone. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `Prompt` | `*string` | :heavy_minus_sign: | The question this surface answered. The surface records its program but not
    the words behind it, so the caller supplies them; without it the report has
    nothing to compare against when deciding its program has gone stale. | +| `SurfaceID` | `*string` | :heavy_minus_sign: | The surfaceId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingservicesaveresponse.md b/docs/pkg/models/shared/reportingservicesaveresponse.md new file mode 100644 index 000000000..65a2436fa --- /dev/null +++ b/docs/pkg/models/shared/reportingservicesaveresponse.md @@ -0,0 +1,10 @@ +# ReportingServiceSaveResponse + +The ReportingServiceSaveResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Report` | [*shared.Report](../../../pkg/models/shared/report.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingserviceupdaterequest.md b/docs/pkg/models/shared/reportingserviceupdaterequest.md new file mode 100644 index 000000000..cd27ec780 --- /dev/null +++ b/docs/pkg/models/shared/reportingserviceupdaterequest.md @@ -0,0 +1,13 @@ +# ReportingServiceUpdateRequest + +Both editable fields are optional; an empty one leaves the stored value alone. + At least one must be set. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `ParameterValues` | map[string]`any` | :heavy_minus_sign: | N/A | +| `Prompt` | `*string` | :heavy_minus_sign: | Editing this does not re-plan, so it may drift from
    program.planned_from_prompt — that drift is how a stale report is detected. | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportingserviceupdateresponse.md b/docs/pkg/models/shared/reportingserviceupdateresponse.md new file mode 100644 index 000000000..17c8ce94c --- /dev/null +++ b/docs/pkg/models/shared/reportingserviceupdateresponse.md @@ -0,0 +1,10 @@ +# ReportingServiceUpdateResponse + +The ReportingServiceUpdateResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `Report` | [*shared.Report](../../../pkg/models/shared/report.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportrun.md b/docs/pkg/models/shared/reportrun.md new file mode 100644 index 000000000..a5c2dfd12 --- /dev/null +++ b/docs/pkg/models/shared/reportrun.md @@ -0,0 +1,29 @@ +# ReportRun + +ReportRun is one execution of a Report's program. Write-once. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ArtifactURL` | `*string` | :heavy_minus_sign: | The artifactUrl field. | +| `ConversationID` | `*string` | :heavy_minus_sign: | Where the output came from, kept for provenance rather than to read it back:
    the surface itself is in surface_snapshot. Both are required to address a
    surface, and a headless refresh has neither. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Error` | `*string` | :heavy_minus_sign: | The error field. | +| `ExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `ID` | `*string` | :heavy_minus_sign: | KSUID, so runs sort by time. | +| `InvocationID` | `*string` | :heavy_minus_sign: | Not a live join: the originating code-mode invocation is archived at the
    code-mode retention cutoff. | +| `Lineage` | map[string]`any` | :heavy_minus_sign: | N/A | +| `ParameterValues` | map[string]`any` | :heavy_minus_sign: | N/A | +| `Program` | [*shared.ProgramRef](../../../pkg/models/shared/programref.md) | :heavy_minus_sign: | N/A | +| `ReportID` | `*string` | :heavy_minus_sign: | The reportId field. | +| `RunByUserID` | `*string` | :heavy_minus_sign: | Copied from the invocation's user_id, which is archived at the code-mode
    retention cutoff. Not Report.created_by_user_id — a refresh may execute as a
    different principal than the report's owner. | +| ~~`Sources`~~ | [][shared.ReportSource](../../../pkg/models/shared/reportsource.md) | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Never written: for a run saved out of a conversation, provenance is read back
    through A2UIService.GetSurfaceProvenance, which reads the surface's own
    components. A headless refresh has no conversation or surface to ask about,
    and how such a run reports what it read is still open. | +| `Status` | [*shared.ReportRunStatus](../../../pkg/models/shared/reportrunstatus.md) | :heavy_minus_sign: | The status field. | +| `SurfaceID` | `*string` | :heavy_minus_sign: | The surfaceId field. | +| `SurfaceSnapshot` | [*shared.A2UISurface](../../../pkg/models/shared/a2uisurface.md) | :heavy_minus_sign: | N/A | +| `TenantID` | `*string` | :heavy_minus_sign: | The tenantId field. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `VfsID` | `*string` | :heavy_minus_sign: | The vfsId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportrunstatus.md b/docs/pkg/models/shared/reportrunstatus.md new file mode 100644 index 000000000..0b28a4638 --- /dev/null +++ b/docs/pkg/models/shared/reportrunstatus.md @@ -0,0 +1,27 @@ +# ReportRunStatus + +The status field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ReportRunStatusReportRunStatusUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.ReportRunStatus("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------------- | -------------------------------------------- | +| `ReportRunStatusReportRunStatusUnspecified` | REPORT_RUN_STATUS_UNSPECIFIED | +| `ReportRunStatusReportRunStatusPending` | REPORT_RUN_STATUS_PENDING | +| `ReportRunStatusReportRunStatusSucceeded` | REPORT_RUN_STATUS_SUCCEEDED | +| `ReportRunStatusReportRunStatusFailed` | REPORT_RUN_STATUS_FAILED | +| `ReportRunStatusReportRunStatusStaleProgram` | REPORT_RUN_STATUS_STALE_PROGRAM | \ No newline at end of file diff --git a/docs/pkg/models/shared/reportsource.md b/docs/pkg/models/shared/reportsource.md new file mode 100644 index 000000000..2fadf6327 --- /dev/null +++ b/docs/pkg/models/shared/reportsource.md @@ -0,0 +1,19 @@ +# ~~ReportSource~~ + +ReportSource is one provenance entry: what a run read to produce its numbers. + + Retired: a run saved out of a conversation records the surface it came from, + and provenance is read back through A2UIService.GetSurfaceProvenance rather + than copied here. Kept because a published message may not be deleted. + +> :warning: **DEPRECATED**: This will be removed in a future release, please migrate away from it as soon as possible. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | +| `Count` | `*int64` | :heavy_minus_sign: | Rows contributing. | +| `Kind` | `*string` | :heavy_minus_sign: | The kind field. | +| `Label` | `*string` | :heavy_minus_sign: | The label field. | +| `Ref` | `*string` | :heavy_minus_sign: | Tool + query fingerprint, or object type/id. | \ No newline at end of file diff --git a/docs/pkg/models/shared/requestcatalog.md b/docs/pkg/models/shared/requestcatalog.md index 550f3ffc4..548c9f6d5 100644 --- a/docs/pkg/models/shared/requestcatalog.md +++ b/docs/pkg/models/shared/requestcatalog.md @@ -18,6 +18,7 @@ The RequestCatalog is used for managing which entitlements are requestable, and | `ID` | `*string` | :heavy_minus_sign: | The id of the request catalog. | | `Published` | `*bool` | :heavy_minus_sign: | Whether or not this catalog is published. | | `RequestBundle` | `*bool` | :heavy_minus_sign: | Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. | +| `Type` | [*shared.RequestCatalogType](../../../pkg/models/shared/requestcatalogtype.md) | :heavy_minus_sign: | The type of this access profile. Reports CATALOG_AND_BUNDLE for a profile
    created before the type was recorded; UNSPECIFIED only for a tenant whose
    backfill has not been run. | | `UnenrollmentBehavior` | [*shared.UnenrollmentBehavior](../../../pkg/models/shared/unenrollmentbehavior.md) | :heavy_minus_sign: | Defines how to handle the revocation of the entitlements in the catalog during unenrollment. | | `UnenrollmentEntitlementBehavior` | [*shared.UnenrollmentEntitlementBehavior](../../../pkg/models/shared/unenrollmententitlementbehavior.md) | :heavy_minus_sign: | Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. | | `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | diff --git a/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequest.md b/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequest.md index 4ee1abdd9..90c2bc3ba 100644 --- a/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequest.md +++ b/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequest.md @@ -14,6 +14,7 @@ Create a request catalog. | `ExpandMask` | [*shared.RequestCatalogExpandMask](../../../pkg/models/shared/requestcatalogexpandmask.md) | :heavy_minus_sign: | N/A | | `Published` | `*bool` | :heavy_minus_sign: | Whether or not the new catalog should be created as published. | | `RequestBundle` | `*bool` | :heavy_minus_sign: | Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. | +| `Type` | [*shared.RequestCatalogManagementServiceCreateRequestType](../../../pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md) | :heavy_minus_sign: | The type of access profile to create. Leave unset for
    REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE, which is what every profile
    created before this field existed is. Setting it requires the
    ACCESS_PROFILE_TYPES feature.

    PROFILE is rejected rather than resolved: it is deprecated, has no stored
    counterpart, and shares wire number 2 with the stored BUNDLE, so honoring
    it would silently persist a type the caller did not ask for. | | `UnenrollmentBehavior` | [*shared.RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior](../../../pkg/models/shared/requestcatalogmanagementservicecreaterequestunenrollmentbehavior.md) | :heavy_minus_sign: | Defines how to handle the revocation of the entitlements in the catalog during unenrollment. | | `UnenrollmentEntitlementBehavior` | [*shared.RequestCatalogManagementServiceCreateRequestUnenrollmentEntitlementBehavior](../../../pkg/models/shared/requestcatalogmanagementservicecreaterequestunenrollmententitlementbehavior.md) | :heavy_minus_sign: | Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. | | `VisibleToEveryone` | `*bool` | :heavy_minus_sign: | Whether or not the new catalog is visible to everyone by default. | \ No newline at end of file diff --git a/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md b/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md new file mode 100644 index 000000000..a7c33ab8c --- /dev/null +++ b/docs/pkg/models/shared/requestcatalogmanagementservicecreaterequesttype.md @@ -0,0 +1,34 @@ +# RequestCatalogManagementServiceCreateRequestType + +The type of access profile to create. Leave unset for + REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE, which is what every profile + created before this field existed is. Setting it requires the + ACCESS_PROFILE_TYPES feature. + + PROFILE is rejected rather than resolved: it is deprecated, has no stored + counterpart, and shares wire number 2 with the stored BUNDLE, so honoring + it would silently persist a type the caller did not ask for. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.RequestCatalogManagementServiceCreateRequestType("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | +| `RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeUnspecified` | REQUEST_CATALOG_TYPE_UNSPECIFIED | +| `RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeCatalog` | REQUEST_CATALOG_TYPE_CATALOG | +| `RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeProfile` | REQUEST_CATALOG_TYPE_PROFILE | +| `RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeCatalogAndBundle` | REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE | +| `RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeBundle` | REQUEST_CATALOG_TYPE_BUNDLE | \ No newline at end of file diff --git a/docs/pkg/models/shared/requestcatalogtype.md b/docs/pkg/models/shared/requestcatalogtype.md new file mode 100644 index 000000000..d76027d57 --- /dev/null +++ b/docs/pkg/models/shared/requestcatalogtype.md @@ -0,0 +1,29 @@ +# RequestCatalogType + +The type of this access profile. Reports CATALOG_AND_BUNDLE for a profile + created before the type was recorded; UNSPECIFIED only for a tenant whose + backfill has not been run. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.RequestCatalogTypeRequestCatalogTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.RequestCatalogType("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------ | ------------------------------------------------------ | +| `RequestCatalogTypeRequestCatalogTypeUnspecified` | REQUEST_CATALOG_TYPE_UNSPECIFIED | +| `RequestCatalogTypeRequestCatalogTypeCatalog` | REQUEST_CATALOG_TYPE_CATALOG | +| `RequestCatalogTypeRequestCatalogTypeProfile` | REQUEST_CATALOG_TYPE_PROFILE | +| `RequestCatalogTypeRequestCatalogTypeCatalogAndBundle` | REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE | +| `RequestCatalogTypeRequestCatalogTypeBundle` | REQUEST_CATALOG_TYPE_BUNDLE | \ No newline at end of file diff --git a/docs/pkg/models/shared/requestcreatedpreference.md b/docs/pkg/models/shared/requestcreatedpreference.md new file mode 100644 index 000000000..041dbd811 --- /dev/null +++ b/docs/pkg/models/shared/requestcreatedpreference.md @@ -0,0 +1,11 @@ +# RequestCreatedPreference + +The RequestCreatedPreference message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | +| `Locked` | `*bool` | :heavy_minus_sign: | The locked field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/requestsettings.md b/docs/pkg/models/shared/requestsettings.md index cf3a95cf6..3154d53e7 100644 --- a/docs/pkg/models/shared/requestsettings.md +++ b/docs/pkg/models/shared/requestsettings.md @@ -5,6 +5,7 @@ RequestSettings holds tenant-wide configuration for the access-request flow. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -| `SkipJustification` | `*bool` | :heavy_minus_sign: | When true, request surfaces (webapp, Slack, MS Teams) skip prompting the
    requester for a justification. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `MaxBulkEntitlementSelection` | `*int` | :heavy_minus_sign: | MaxBulkEntitlementSelection caps the number of entitlements a requester
    may select in a single bulk access request. Reads always return the
    effective value — an unset (0) value is presented as the system default of
    10. Writing 0 resets the field to unset in storage. Maximum 100. | +| `SkipJustification` | `*bool` | :heavy_minus_sign: | When true, request surfaces (webapp, Slack, MS Teams) skip prompting the
    requester for a justification. | \ No newline at end of file diff --git a/docs/pkg/models/shared/resourcetype.md b/docs/pkg/models/shared/resourcetype.md index a86fe4125..9cb191e10 100644 --- a/docs/pkg/models/shared/resourcetype.md +++ b/docs/pkg/models/shared/resourcetype.md @@ -28,4 +28,5 @@ custom := shared.ResourceType("custom_value") | `ResourceTypeCustom` | CUSTOM | | `ResourceTypeVault` | VAULT | | `ResourceTypeProfileType` | PROFILE_TYPE | -| `ResourceTypeSessionPolicy` | SESSION_POLICY | \ No newline at end of file +| `ResourceTypeSessionPolicy` | SESSION_POLICY | +| `ResourceTypeClawAgent` | CLAW_AGENT | \ No newline at end of file diff --git a/docs/pkg/models/shared/revokegatewaykeyrequest.md b/docs/pkg/models/shared/revokegatewaykeyrequest.md new file mode 100644 index 000000000..9f41a7e12 --- /dev/null +++ b/docs/pkg/models/shared/revokegatewaykeyrequest.md @@ -0,0 +1,9 @@ +# RevokeGatewayKeyRequest + +The RevokeGatewayKeyRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/revokegatewaykeyresponse.md b/docs/pkg/models/shared/revokegatewaykeyresponse.md new file mode 100644 index 000000000..74aa3f91f --- /dev/null +++ b/docs/pkg/models/shared/revokegatewaykeyresponse.md @@ -0,0 +1,10 @@ +# RevokeGatewayKeyResponse + +The RevokeGatewayKeyResponse message. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `GatewayKey` | [*shared.GatewayKey](../../../pkg/models/shared/gatewaykey.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/rule.md b/docs/pkg/models/shared/rule.md index 41589625f..ed774fbb5 100644 --- a/docs/pkg/models/shared/rule.md +++ b/docs/pkg/models/shared/rule.md @@ -1,14 +1,24 @@ # Rule -A conditional routing rule that maps a CEL expression to a step sequence. - Rules are evaluated top-to-bottom; the first matching rule's policy_key - selects the step sequence from the policy's policy_steps map. If no rule - matches, the baseline entry is used. +A conditional routing rule that maps a CEL expression to an outcome. + Rules are evaluated top-to-bottom; the first matching rule's outcome + determines which steps run. If the outcome is policy_key, the step sequence + of that key in this policy's policy_steps map is used. If the outcome is + policy_id, the referenced policy is evaluated recursively (depth-bounded, + cycle-free, same policy_type). If no rule matches, the baseline entry of + policy_steps is used. + +This message contains a oneof named outcome. Only a single field of the following list may be set at a time: + - stepKey + - policyId + ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `Condition` | `*string` | :heavy_minus_sign: | A CEL expression that is evaluated against the request context. If it
    returns true, the step sequence identified by policy_key is used. | -| `PolicyKey` | `*string` | :heavy_minus_sign: | A key into the policy's policy_steps map identifying which step sequence
    to execute when this rule's condition matches. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Condition` | `*string` | :heavy_minus_sign: | A CEL expression that is evaluated against the request context. If it
    returns true, the step sequence identified by the outcome is used. | +| `PolicyID` | `*string` | :heavy_minus_sign: | The ID of another Policy that is evaluated recursively when this
    rule matches. The referenced policy must share this policy's
    policy_type, must not introduce a cycle, and must not push any
    reachable chain over depth 5. Gated by the
    POLICY_REFERENCES_POLICY feature flag.
    This field is part of the `outcome` oneof.
    See the documentation for `c1.api.policy.v1.Rule` for more details. | +| ~~`PolicyKey`~~ | `*string` | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated: prefer outcome.step_key. Still read by the request path
    for backward compatibility with rules persisted before the outcome
    oneof existed. | +| `StepKey` | `*string` | :heavy_minus_sign: | A key into the policy's policy_steps map identifying which step
    sequence to execute when this rule's condition matches.
    This field is part of the `outcome` oneof.
    See the documentation for `c1.api.policy.v1.Rule` for more details. | \ No newline at end of file diff --git a/docs/pkg/models/shared/samlattributemapping.md b/docs/pkg/models/shared/samlattributemapping.md new file mode 100644 index 000000000..cc873abe2 --- /dev/null +++ b/docs/pkg/models/shared/samlattributemapping.md @@ -0,0 +1,14 @@ +# SAMLAttributeMapping + +SAMLAttributeMapping releases one user attribute to the service provider + as one Attribute in the assertion's AttributeStatement. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `FriendlyName` | `*string` | :heavy_minus_sign: | Optional FriendlyName, for service providers that display it. | +| `Name` | `string` | :heavy_check_mark: | The Name attribute, dictated by the service provider. | +| `NameFormat` | [*shared.NameFormat](../../../pkg/models/shared/nameformat.md) | :heavy_minus_sign: | The NameFormat attribute. | +| `UserAttributeMappingID` | `string` | :heavy_check_mark: | The user attribute mapping that resolves the value, including its fallback
    chain. | \ No newline at end of file diff --git a/docs/pkg/models/shared/samlmetadatafinding.md b/docs/pkg/models/shared/samlmetadatafinding.md new file mode 100644 index 000000000..3580ae5a9 --- /dev/null +++ b/docs/pkg/models/shared/samlmetadatafinding.md @@ -0,0 +1,13 @@ +# SAMLMetadataFinding + +SAMLMetadataFinding is one thing ConductorOne noticed while parsing a service + provider's metadata document. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `Component` | [*shared.Component](../../../pkg/models/shared/component.md) | :heavy_minus_sign: | Where the finding fits in the parsed document. | +| `Level` | [*shared.Level](../../../pkg/models/shared/level.md) | :heavy_minus_sign: | The severity of this finding. | +| `Reason` | `*string` | :heavy_minus_sign: | Plain-language explanation of why the finding was raised. | \ No newline at end of file diff --git a/docs/pkg/models/shared/scopeobjecttype.md b/docs/pkg/models/shared/scopeobjecttype.md new file mode 100644 index 000000000..409311a66 --- /dev/null +++ b/docs/pkg/models/shared/scopeobjecttype.md @@ -0,0 +1,26 @@ +# ScopeObjectType + +When scope_view is POLICY_SCOPE_VIEW_SCOPED, narrow local policies to a + coarse object type (app-local vs entitlement-local). + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ScopeObjectTypePolicyScopeObjectTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.ScopeObjectType("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------- | ------------------------------------------------- | +| `ScopeObjectTypePolicyScopeObjectTypeUnspecified` | POLICY_SCOPE_OBJECT_TYPE_UNSPECIFIED | +| `ScopeObjectTypePolicyScopeObjectTypeApp` | POLICY_SCOPE_OBJECT_TYPE_APP | +| `ScopeObjectTypePolicyScopeObjectTypeEntitlement` | POLICY_SCOPE_OBJECT_TYPE_ENTITLEMENT | \ No newline at end of file diff --git a/docs/pkg/models/shared/scopeslot.md b/docs/pkg/models/shared/scopeslot.md new file mode 100644 index 000000000..b70a4a934 --- /dev/null +++ b/docs/pkg/models/shared/scopeslot.md @@ -0,0 +1,26 @@ +# ScopeSlot + +When scope_view narrows to one object, only return that object's local + policies in this slot. Ignored when no object is identified by + scope_app_id, which lists every local policy regardless of slot. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ScopeSlotPolicyScopeSlotUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.ScopeSlot("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------- | ------------------------------------- | +| `ScopeSlotPolicyScopeSlotUnspecified` | POLICY_SCOPE_SLOT_UNSPECIFIED | +| `ScopeSlotPolicyScopeSlotEmergency` | POLICY_SCOPE_SLOT_EMERGENCY | \ No newline at end of file diff --git a/docs/pkg/models/shared/scopeview.md b/docs/pkg/models/shared/scopeview.md new file mode 100644 index 000000000..f09167fe6 --- /dev/null +++ b/docs/pkg/models/shared/scopeview.md @@ -0,0 +1,29 @@ +# ScopeView + +Which policies to return based on scope. Defaults to global-only, so + app/entitlement-scoped policies never appear unless explicitly requested. + Ignored when refs are provided (explicit ID lookups always resolve). + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ScopeViewPolicyScopeViewUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.ScopeView("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------- | ----------------------------------------- | +| `ScopeViewPolicyScopeViewUnspecified` | POLICY_SCOPE_VIEW_UNSPECIFIED | +| `ScopeViewPolicyScopeViewGlobal` | POLICY_SCOPE_VIEW_GLOBAL | +| `ScopeViewPolicyScopeViewScoped` | POLICY_SCOPE_VIEW_SCOPED | +| `ScopeViewPolicyScopeViewAll` | POLICY_SCOPE_VIEW_ALL | +| `ScopeViewPolicyScopeViewGlobalAndObject` | POLICY_SCOPE_VIEW_GLOBAL_AND_OBJECT | \ No newline at end of file diff --git a/docs/pkg/models/shared/searchappresourcesrequest.md b/docs/pkg/models/shared/searchappresourcesrequest.md index 96f170129..eea682954 100644 --- a/docs/pkg/models/shared/searchappresourcesrequest.md +++ b/docs/pkg/models/shared/searchappresourcesrequest.md @@ -7,7 +7,7 @@ Search app resources based on filters specified in the request body. | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `AgentStatuses` | [][shared.AgentStatuses](../../../pkg/models/shared/agentstatuses.md) | :heavy_minus_sign: | Restrict the search to AI-agent resources with one of the given agent
    lifecycle statuses (READY, DISABLED, DELETED). When empty, agent status is
    not used as a filter. | +| `AgentStatuses` | [][shared.SearchAppResourcesRequestAgentStatuses](../../../pkg/models/shared/searchappresourcesrequestagentstatuses.md) | :heavy_minus_sign: | Restrict the search to AI-agent resources with one of the given agent
    lifecycle statuses (READY, DISABLED, DELETED). When empty, agent status is
    not used as a filter. | | `AppID` | `*string` | :heavy_minus_sign: | The app ID to restrict the search to. | | `AppIds` | []`string` | :heavy_minus_sign: | A list of app IDs to restrict the search to. Mirrors the singular app_id;
    both fold into the same filter, so callers may set either or both. | | `AppUserIds` | []`string` | :heavy_minus_sign: | A list of app user IDs to restrict the search by. | diff --git a/docs/pkg/models/shared/searchappresourcesrequestagentstatuses.md b/docs/pkg/models/shared/searchappresourcesrequestagentstatuses.md new file mode 100644 index 000000000..243e01580 --- /dev/null +++ b/docs/pkg/models/shared/searchappresourcesrequestagentstatuses.md @@ -0,0 +1,24 @@ +# SearchAppResourcesRequestAgentStatuses + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SearchAppResourcesRequestAgentStatusesAgentStatusUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SearchAppResourcesRequestAgentStatuses("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------------------------------- | -------------------------------------------------------------- | +| `SearchAppResourcesRequestAgentStatusesAgentStatusUnspecified` | AGENT_STATUS_UNSPECIFIED | +| `SearchAppResourcesRequestAgentStatusesAgentStatusReady` | AGENT_STATUS_READY | +| `SearchAppResourcesRequestAgentStatusesAgentStatusDisabled` | AGENT_STATUS_DISABLED | +| `SearchAppResourcesRequestAgentStatusesAgentStatusDeleted` | AGENT_STATUS_DELETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/searchcohortusersrequest.md b/docs/pkg/models/shared/searchcohortusersrequest.md index 2ba1f0686..165556728 100644 --- a/docs/pkg/models/shared/searchcohortusersrequest.md +++ b/docs/pkg/models/shared/searchcohortusersrequest.md @@ -5,9 +5,9 @@ The SearchCohortUsersRequest message. ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | -| `PageSize` | `*int` | :heavy_minus_sign: | Maximum number of users to return per page. | -| `PageToken` | `*string` | :heavy_minus_sign: | Pagination token from a previous response. | -| `ProfileFilters` | [][shared.ProfileFilter](../../../pkg/models/shared/profilefilter.md) | :heavy_minus_sign: | Additional profile filters to narrow the cohort user search. | -| `SelectedEntitlements` | [][shared.EntitlementRef](../../../pkg/models/shared/entitlementref.md) | :heavy_minus_sign: | Optional list of entitlements to compute per-user coverage for. | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `PageSize` | `*int` | :heavy_minus_sign: | Maximum number of users to return per page. | +| `PageToken` | `*string` | :heavy_minus_sign: | Pagination token from a previous response. | +| `ProfileFilters` | [][shared.ProfileFilter](../../../pkg/models/shared/profilefilter.md) | :heavy_minus_sign: | Additional profile filters to narrow the cohort user search. | +| ~~`SelectedEntitlements`~~ | [][shared.EntitlementRef](../../../pkg/models/shared/entitlementref.md) | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated. This endpoint no longer computes per-user coverage and
    ignores this field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/searchcohortusersresponse.md b/docs/pkg/models/shared/searchcohortusersresponse.md index c90042a57..e4a320dbe 100644 --- a/docs/pkg/models/shared/searchcohortusersresponse.md +++ b/docs/pkg/models/shared/searchcohortusersresponse.md @@ -5,8 +5,8 @@ The SearchCohortUsersResponse message. ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | -| `List` | [][shared.User](../../../pkg/models/shared/user.md) | :heavy_minus_sign: | The list of users matching the cohort and optional filters. | -| `NextPageToken` | `*string` | :heavy_minus_sign: | Token to retrieve the next page of results, empty if no more results. | -| `UsersWithCoverage` | [][shared.CohortUserWithCoverage](../../../pkg/models/shared/cohortuserwithcoverage.md) | :heavy_minus_sign: | Per-user coverage counts, populated when selected_entitlements is non-empty. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `List` | [][shared.User](../../../pkg/models/shared/user.md) | :heavy_minus_sign: | The list of users matching the cohort and optional filters. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token to retrieve the next page of results, empty if no more results. | +| ~~`UsersWithCoverage`~~ | [][shared.CohortUserWithCoverage](../../../pkg/models/shared/cohortuserwithcoverage.md) | :heavy_minus_sign: | : warning: ** DEPRECATED **: This will be removed in a future release, please migrate away from it as soon as possible.

    Deprecated. This endpoint no longer computes per-user coverage; this
    list is always empty. | \ No newline at end of file diff --git a/docs/pkg/models/shared/searchpoliciesrequest.md b/docs/pkg/models/shared/searchpoliciesrequest.md index 56d4f6ff5..3140dec49 100644 --- a/docs/pkg/models/shared/searchpoliciesrequest.md +++ b/docs/pkg/models/shared/searchpoliciesrequest.md @@ -5,13 +5,18 @@ Search Policies by a few properties. ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `DisplayName` | `*string` | :heavy_minus_sign: | Search for policies with a case insensitive match on the display name. | -| `ExcludePolicyIds` | []`string` | :heavy_minus_sign: | The policy IDs to exclude from the search. | -| `IncludeDeleted` | `*bool` | :heavy_minus_sign: | The includeDeleted field. | -| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) | -| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | -| `PolicyTypes` | [][shared.PolicyTypes](../../../pkg/models/shared/policytypes.md) | :heavy_minus_sign: | The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. | -| `Query` | `*string` | :heavy_minus_sign: | Query the policies with a fuzzy search on display name and description. | -| `Refs` | [][shared.PolicyRef](../../../pkg/models/shared/policyref.md) | :heavy_minus_sign: | The refs field. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `DisplayName` | `*string` | :heavy_minus_sign: | Search for policies with a case insensitive match on the display name. | +| `ExcludePolicyIds` | []`string` | :heavy_minus_sign: | The policy IDs to exclude from the search. | +| `IncludeDeleted` | `*bool` | :heavy_minus_sign: | The includeDeleted field. | +| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) | +| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | +| `PolicyTypes` | [][shared.PolicyTypes](../../../pkg/models/shared/policytypes.md) | :heavy_minus_sign: | The policy type to search on. This can be POLICY_TYPE_GRANT, POLICY_TYPE_REVOKE, POLICY_TYPE_CERTIFY, POLICY_TYPE_ACCESS_REQUEST, or POLICY_TYPE_PROVISION. | +| `Query` | `*string` | :heavy_minus_sign: | Query the policies with a fuzzy search on display name and description. | +| `Refs` | [][shared.PolicyRef](../../../pkg/models/shared/policyref.md) | :heavy_minus_sign: | The refs field. | +| `ScopeAppEntitlementID` | `*string` | :heavy_minus_sign: | When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped
    to this entitlement. | +| `ScopeAppID` | `*string` | :heavy_minus_sign: | When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped
    to this app. | +| `ScopeObjectType` | [*shared.ScopeObjectType](../../../pkg/models/shared/scopeobjecttype.md) | :heavy_minus_sign: | When scope_view is POLICY_SCOPE_VIEW_SCOPED, narrow local policies to a
    coarse object type (app-local vs entitlement-local). | +| `ScopeSlot` | [*shared.ScopeSlot](../../../pkg/models/shared/scopeslot.md) | :heavy_minus_sign: | When scope_view narrows to one object, only return that object's local
    policies in this slot. Ignored when no object is identified by
    scope_app_id, which lists every local policy regardless of slot. | +| `ScopeView` | [*shared.ScopeView](../../../pkg/models/shared/scopeview.md) | :heavy_minus_sign: | Which policies to return based on scope. Defaults to global-only, so
    app/entitlement-scoped policies never appear unless explicitly requested.
    Ignored when refs are provided (explicit ID lookups always resolve). | \ No newline at end of file diff --git a/docs/pkg/models/shared/searchusersrequest.md b/docs/pkg/models/shared/searchusersrequest.md index c0eecbfa6..270701f31 100644 --- a/docs/pkg/models/shared/searchusersrequest.md +++ b/docs/pkg/models/shared/searchusersrequest.md @@ -5,24 +5,25 @@ Search for users based on some filters. ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | -| `DelegateStatus` | [*shared.DelegateStatus](../../../pkg/models/shared/delegatestatus.md) | :heavy_minus_sign: | Filter for users based on their delegate status. | -| `DelegatedUserIds` | []`string` | :heavy_minus_sign: | Filter for users that have any of the delegated user IDs on this list. | -| `Departments` | []`string` | :heavy_minus_sign: | Search for users that have any of the departments on this list. | -| `Email` | `*string` | :heavy_minus_sign: | Search for users based on their email (exact match). | -| `ExcludeIds` | []`string` | :heavy_minus_sign: | An array of users IDs to exclude from the results. | -| `ExcludeOrigins` | [][shared.ExcludeOrigins](../../../pkg/models/shared/excludeorigins.md) | :heavy_minus_sign: | Filter to exclude users with these origins. | -| `ExcludeTypes` | [][shared.ExcludeTypes](../../../pkg/models/shared/excludetypes.md) | :heavy_minus_sign: | An array of types to exclude from the results. | -| `ExpandMask` | [*shared.UserExpandMask](../../../pkg/models/shared/userexpandmask.md) | :heavy_minus_sign: | N/A | -| `Ids` | []`string` | :heavy_minus_sign: | Deprecated. Use refs array instead. | -| `IsDelegate` | `*bool` | :heavy_minus_sign: | Filter for users who are delegates of at least one other user. | -| `JobTitles` | []`string` | :heavy_minus_sign: | Search for users that have any of the job titles on this list. | -| `ManagerIds` | []`string` | :heavy_minus_sign: | Search for users that have any of the manager IDs on this list. | -| `Origins` | [][shared.Origins](../../../pkg/models/shared/origins.md) | :heavy_minus_sign: | Filter to include only users with these origins. | -| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) | -| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | -| `Query` | `*string` | :heavy_minus_sign: | Query the apps with a fuzzy search on display name and emails. | -| `Refs` | [][shared.UserRef](../../../pkg/models/shared/userref.md) | :heavy_minus_sign: | An array of user refs to restrict the return values to by ID. | -| `RoleIds` | []`string` | :heavy_minus_sign: | Search for users that have any of the role IDs on this list. | -| `UserStatuses` | [][shared.SearchUsersRequestUserStatuses](../../../pkg/models/shared/searchusersrequestuserstatuses.md) | :heavy_minus_sign: | Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `DelegateStatus` | [*shared.DelegateStatus](../../../pkg/models/shared/delegatestatus.md) | :heavy_minus_sign: | Filter for users based on their delegate status. | +| `DelegatedUserIds` | []`string` | :heavy_minus_sign: | Filter for users that have any of the delegated user IDs on this list. | +| `Departments` | []`string` | :heavy_minus_sign: | Search for users that have any of the departments on this list. | +| `Email` | `*string` | :heavy_minus_sign: | Search for users based on their email (exact match). | +| `ExcludeIds` | []`string` | :heavy_minus_sign: | An array of users IDs to exclude from the results. | +| `ExcludeOrigins` | [][shared.ExcludeOrigins](../../../pkg/models/shared/excludeorigins.md) | :heavy_minus_sign: | Filter to exclude users with these origins. | +| `ExcludeTypes` | [][shared.ExcludeTypes](../../../pkg/models/shared/excludetypes.md) | :heavy_minus_sign: | An array of types to exclude from the results. | +| `ExpandMask` | [*shared.UserExpandMask](../../../pkg/models/shared/userexpandmask.md) | :heavy_minus_sign: | N/A | +| `Ids` | []`string` | :heavy_minus_sign: | Deprecated. Use refs array instead. | +| `IsDelegate` | `*bool` | :heavy_minus_sign: | Filter for users who are delegates of at least one other user. | +| `JobTitles` | []`string` | :heavy_minus_sign: | Search for users that have any of the job titles on this list. | +| `ManagerIds` | []`string` | :heavy_minus_sign: | Search for users that have any of the manager IDs on this list. | +| `Origins` | [][shared.Origins](../../../pkg/models/shared/origins.md) | :heavy_minus_sign: | Filter to include only users with these origins. | +| `PageSize` | `*int` | :heavy_minus_sign: | The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) | +| `PageToken` | `*string` | :heavy_minus_sign: | The pageToken field. | +| `Query` | `*string` | :heavy_minus_sign: | Query the apps with a fuzzy search on display name and emails. | +| `Refs` | [][shared.UserRef](../../../pkg/models/shared/userref.md) | :heavy_minus_sign: | An array of user refs to restrict the return values to by ID. | +| `RoleIds` | []`string` | :heavy_minus_sign: | Search for users that have any of the role IDs on this list. | +| `SourceAppIds` | []`string` | :heavy_minus_sign: | Filter to include only users sourced from any of these apps (directories).
    Each value is an app ID; a user matches when its source_app_ids map
    contains any of the listed app IDs. Combined with `origins` using OR. | +| `UserStatuses` | [][shared.SearchUsersRequestUserStatuses](../../../pkg/models/shared/searchusersrequestuserstatuses.md) | :heavy_minus_sign: | Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED | \ No newline at end of file diff --git a/docs/pkg/models/shared/secretsmaskingconfig.md b/docs/pkg/models/shared/secretsmaskingconfig.md new file mode 100644 index 000000000..f3b5dee5c --- /dev/null +++ b/docs/pkg/models/shared/secretsmaskingconfig.md @@ -0,0 +1,12 @@ +# SecretsMaskingConfig + +SecretsMaskingConfig configures post-tool-use redaction of secret-shaped + substrings (API keys, tokens, private keys) in tool output. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `AdditionalPatterns` | []`string` | :heavy_minus_sign: | Extra RE2 regexes whose matches are redacted in addition to the built-in
    secret patterns. | +| `Placeholder` | `*string` | :heavy_minus_sign: | Replacement string for a matched secret. Empty = "***REDACTED-SECRET***". | \ No newline at end of file diff --git a/docs/pkg/models/shared/sessionpolicystepuprequired.md b/docs/pkg/models/shared/sessionpolicystepuprequired.md index 15816b6ad..c35f91296 100644 --- a/docs/pkg/models/shared/sessionpolicystepuprequired.md +++ b/docs/pkg/models/shared/sessionpolicystepuprequired.md @@ -8,6 +8,6 @@ StepUpRequired demands a stronger re-authentication before the session may | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | -| `Level` | [*shared.Level](../../../pkg/models/shared/level.md) | :heavy_minus_sign: | The level field. | +| `Level` | [*shared.SessionPolicyStepUpRequiredLevel](../../../pkg/models/shared/sessionpolicystepuprequiredlevel.md) | :heavy_minus_sign: | The level field. | | `MaxAgeSeconds` | `*int` | :heavy_minus_sign: | How fresh the step-up must be, in seconds. | | `Types` | [][shared.SessionPolicyStepUpRequiredTypes](../../../pkg/models/shared/sessionpolicystepuprequiredtypes.md) | :heavy_minus_sign: | The types field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/sessionpolicystepuprequiredlevel.md b/docs/pkg/models/shared/sessionpolicystepuprequiredlevel.md new file mode 100644 index 000000000..75a24bb2a --- /dev/null +++ b/docs/pkg/models/shared/sessionpolicystepuprequiredlevel.md @@ -0,0 +1,28 @@ +# SessionPolicyStepUpRequiredLevel + +The level field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SessionPolicyStepUpRequiredLevelAuthLevelUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SessionPolicyStepUpRequiredLevel("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------- | ------------------------------------------------------- | +| `SessionPolicyStepUpRequiredLevelAuthLevelUnspecified` | AUTH_LEVEL_UNSPECIFIED | +| `SessionPolicyStepUpRequiredLevelAuthLevelNone` | AUTH_LEVEL_NONE | +| `SessionPolicyStepUpRequiredLevelAuthLevelSingleFactor` | AUTH_LEVEL_SINGLE_FACTOR | +| `SessionPolicyStepUpRequiredLevelAuthLevelMultiFactor` | AUTH_LEVEL_MULTI_FACTOR | +| `SessionPolicyStepUpRequiredLevelAuthLevelPhr` | AUTH_LEVEL_PHR | +| `SessionPolicyStepUpRequiredLevelAuthLevelPhrh` | AUTH_LEVEL_PHRH | \ No newline at end of file diff --git a/docs/pkg/models/shared/setprovidercredentialrequest.md b/docs/pkg/models/shared/setprovidercredentialrequest.md new file mode 100644 index 000000000..64631dc01 --- /dev/null +++ b/docs/pkg/models/shared/setprovidercredentialrequest.md @@ -0,0 +1,12 @@ +# SetProviderCredentialRequest + +The SetProviderCredentialRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | +| `APIKey` | `*string` | :heavy_minus_sign: | The apiKey field. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `HeaderStyle` | [*shared.SetProviderCredentialRequestHeaderStyle](../../../pkg/models/shared/setprovidercredentialrequestheaderstyle.md) | :heavy_minus_sign: | The headerStyle field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/setprovidercredentialrequestheaderstyle.md b/docs/pkg/models/shared/setprovidercredentialrequestheaderstyle.md new file mode 100644 index 000000000..9b7e1d47e --- /dev/null +++ b/docs/pkg/models/shared/setprovidercredentialrequestheaderstyle.md @@ -0,0 +1,25 @@ +# SetProviderCredentialRequestHeaderStyle + +The headerStyle field. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SetProviderCredentialRequestHeaderStyle("custom_value") +``` + + +## Values + +| Name | Value | +| ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | +| `SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleUnspecified` | PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED | +| `SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleXAPIKey` | PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY | +| `SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleAuthorizationBearer` | PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER | \ No newline at end of file diff --git a/docs/pkg/models/shared/setprovidercredentialresponse.md b/docs/pkg/models/shared/setprovidercredentialresponse.md new file mode 100644 index 000000000..3213b3e80 --- /dev/null +++ b/docs/pkg/models/shared/setprovidercredentialresponse.md @@ -0,0 +1,10 @@ +# SetProviderCredentialResponse + +The SetProviderCredentialResponse message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------ | +| `Credential` | [*shared.ProviderCredential](../../../pkg/models/shared/providercredential.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/slackchannelsettings.md b/docs/pkg/models/shared/slackchannelsettings.md index 423c92567..97269d12f 100644 --- a/docs/pkg/models/shared/slackchannelsettings.md +++ b/docs/pkg/models/shared/slackchannelsettings.md @@ -17,5 +17,7 @@ The SlackChannelSettings message. | `ExpiringAccess` | [*shared.ExpiringAccessPreference](../../../pkg/models/shared/expiringaccesspreference.md) | :heavy_minus_sign: | N/A | | `IsConfigured` | `*bool` | :heavy_minus_sign: | The isConfigured field. | | `ProvisioningRequest` | [*shared.ProvisioningRequestPreference](../../../pkg/models/shared/provisioningrequestpreference.md) | :heavy_minus_sign: | N/A | +| `RequestCreated` | [*shared.RequestCreatedPreference](../../../pkg/models/shared/requestcreatedpreference.md) | :heavy_minus_sign: | N/A | | `Reviews` | [*shared.ReviewsPreference](../../../pkg/models/shared/reviewspreference.md) | :heavy_minus_sign: | N/A | +| `System` | [*shared.SystemPreference](../../../pkg/models/shared/systempreference.md) | :heavy_minus_sign: | N/A | | `TaskReminders` | [*shared.TaskRemindersPreference](../../../pkg/models/shared/taskreminderspreference.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/slackchanneltarget.md b/docs/pkg/models/shared/slackchanneltarget.md new file mode 100644 index 000000000..4fd55f148 --- /dev/null +++ b/docs/pkg/models/shared/slackchanneltarget.md @@ -0,0 +1,13 @@ +# SlackChannelTarget + +SlackChannelTarget names one Slack channel. Exactly one of channel_name / + channel_id is set; a name is resolved at send time, so an unresolvable name + fails the dispatch rather than the rule edit. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------- | ---------------------- | ---------------------- | ---------------------- | +| `ChannelID` | `*string` | :heavy_minus_sign: | The channelId field. | +| `ChannelName` | `*string` | :heavy_minus_sign: | The channelName field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/slot.md b/docs/pkg/models/shared/slot.md new file mode 100644 index 000000000..9b4ce5bc6 --- /dev/null +++ b/docs/pkg/models/shared/slot.md @@ -0,0 +1,25 @@ +# Slot + +Which of the object's local-policy slots this policy occupies. Part of the + scope, and immutable with it. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SlotPolicyScopeSlotUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Slot("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------- | -------------------------------- | +| `SlotPolicyScopeSlotUnspecified` | POLICY_SCOPE_SLOT_UNSPECIFIED | +| `SlotPolicyScopeSlotEmergency` | POLICY_SCOPE_SLOT_EMERGENCY | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendcontrols.md b/docs/pkg/models/shared/spendcontrols.md new file mode 100644 index 000000000..0cc56a06f --- /dev/null +++ b/docs/pkg/models/shared/spendcontrols.md @@ -0,0 +1,21 @@ +# SpendControls + +SpendControls is the one control shape carried by every authority scope. + Per-row resolution, identical everywhere: suspension present -> deny; + unexpired extension -> extension.limit; limit present -> limit; + otherwise this row states no opinion and resolution falls through. + + Not a oneof: two transitions need the losing field to survive. Unsuspending + restores the limit it froze, and a lapsed extension falls back to its base + rather than to the next layer. Pinned by + TestControlsCoPresenceSurvivesEveryTransition in pkg/funds. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Extension` | [*shared.SpendExtension](../../../pkg/models/shared/spendextension.md) | :heavy_minus_sign: | N/A | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Period` | [*shared.SpendControlsPeriod](../../../pkg/models/shared/spendcontrolsperiod.md) | :heavy_minus_sign: | Only valid together with limit: a period without its amount would
    reinterpret some other layer's number in a cadence that layer never
    agreed to. | +| `Suspension` | [*shared.SpendSuspension](../../../pkg/models/shared/spendsuspension.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendcontrolsperiod.md b/docs/pkg/models/shared/spendcontrolsperiod.md new file mode 100644 index 000000000..ff9ddf936 --- /dev/null +++ b/docs/pkg/models/shared/spendcontrolsperiod.md @@ -0,0 +1,30 @@ +# SpendControlsPeriod + +Only valid together with limit: a period without its amount would + reinterpret some other layer's number in a cadence that layer never + agreed to. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SpendControlsPeriodPeriodKindUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SpendControlsPeriod("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------ | ------------------------------------------ | +| `SpendControlsPeriodPeriodKindUnspecified` | PERIOD_KIND_UNSPECIFIED | +| `SpendControlsPeriodPeriodKindDaily` | PERIOD_KIND_DAILY | +| `SpendControlsPeriodPeriodKindWeekly` | PERIOD_KIND_WEEKLY | +| `SpendControlsPeriodPeriodKindMonthly` | PERIOD_KIND_MONTHLY | +| `SpendControlsPeriodPeriodKindQuarterly` | PERIOD_KIND_QUARTERLY | +| `SpendControlsPeriodPeriodKindYearly` | PERIOD_KIND_YEARLY | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendextension.md b/docs/pkg/models/shared/spendextension.md new file mode 100644 index 000000000..22f1b3db2 --- /dev/null +++ b/docs/pkg/models/shared/spendextension.md @@ -0,0 +1,14 @@ +# SpendExtension + +SpendExtension replaces the row's total with a temporary one until + expires_at. It never changes the period, and it never expresses a refusal — + a temporary refusal is a SpendSuspension. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | +| `ExpiresAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Limit` | [*shared.SpendLimit](../../../pkg/models/shared/spendlimit.md) | :heavy_minus_sign: | N/A | +| `Reason` | `*string` | :heavy_minus_sign: | Subject-visible: "why do I have this bump". Mutation rationale rides the
    history change_reason annotation instead. | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendlimit.md b/docs/pkg/models/shared/spendlimit.md new file mode 100644 index 000000000..d0ea4b3c2 --- /dev/null +++ b/docs/pkg/models/shared/spendlimit.md @@ -0,0 +1,20 @@ +# SpendLimit + +SpendLimit is the three-way behavior fork. Which arms are legal depends on the + scope carrying it; pkg/funds enforces that matrix, not the schema, because one + SpendControls shape is shared by every scope. + +This message contains a oneof named kind. Only a single field of the following list may be set at a time: + - unlimited + - amount + - blocked + + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | +| `Amount` | [*shared.SpendLimitAmount](../../../pkg/models/shared/spendlimitamount.md) | :heavy_minus_sign: | N/A | +| `Blocked` | [*shared.SpendLimitBlocked](../../../pkg/models/shared/spendlimitblocked.md) | :heavy_minus_sign: | N/A | +| `Unlimited` | [*shared.SpendLimitUnlimited](../../../pkg/models/shared/spendlimitunlimited.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendlimitamount.md b/docs/pkg/models/shared/spendlimitamount.md new file mode 100644 index 000000000..89ff8f078 --- /dev/null +++ b/docs/pkg/models/shared/spendlimitamount.md @@ -0,0 +1,10 @@ +# SpendLimitAmount + +SpendLimitAmount caps spend at money per resolved period. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | +| `Money` | [*shared.Money](../../../pkg/models/shared/money.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendlimitblocked.md b/docs/pkg/models/shared/spendlimitblocked.md new file mode 100644 index 000000000..f8da57604 --- /dev/null +++ b/docs/pkg/models/shared/spendlimitblocked.md @@ -0,0 +1,11 @@ +# SpendLimitBlocked + +SpendLimitBlocked refuses supply at this scope. Distinct from suspension: + blocked is a stated policy posture, suspension is a reversible freeze that + preserves the numbers underneath it. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendlimitunlimited.md b/docs/pkg/models/shared/spendlimitunlimited.md new file mode 100644 index 000000000..ea285e3b6 --- /dev/null +++ b/docs/pkg/models/shared/spendlimitunlimited.md @@ -0,0 +1,11 @@ +# SpendLimitUnlimited + +SpendLimitUnlimited is a tracking limit: full accounting, no admission + condition. The maximum element, so an unlimited default makes grant rules + no-ops. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/spendsuspension.md b/docs/pkg/models/shared/spendsuspension.md new file mode 100644 index 000000000..63e4ad5b1 --- /dev/null +++ b/docs/pkg/models/shared/spendsuspension.md @@ -0,0 +1,13 @@ +# SpendSuspension + +SpendSuspension freezes a scope without erasing the limit it must restore + on unsuspend, which is why it lives beside the SpendLimit oneof rather than + inside it. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | +| `SuspendedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplication.md b/docs/pkg/models/shared/ssoapplication.md new file mode 100644 index 000000000..16dbe691d --- /dev/null +++ b/docs/pkg/models/shared/ssoapplication.md @@ -0,0 +1,28 @@ +# SSOApplication + +SSOApplication is one application your users sign in to through ConductorOne. + +This message contains a oneof named protocol. Only a single field of the following list may be set at a time: + - oidc + - saml + + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The entitlement a user must hold to sign in. Created with the SSO
    application and not settable by the caller. | +| `AppID` | `*string` | :heavy_minus_sign: | The application in your catalog that owns this sign-in configuration. Its
    owners, entitlements, and access reviews govern who may sign in. | +| `AssertionLifetime` | `*string` | :heavy_minus_sign: | N/A | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description of the SSO application. | +| `Disabled` | `*bool` | :heavy_minus_sign: | When true, sign-in through this application is refused. The application
    and its entitlement are left in place. | +| `DisplayName` | `*string` | :heavy_minus_sign: | Display name for the SSO application. | +| `ID` | `*string` | :heavy_minus_sign: | Unique identifier for this SSO application. | +| `Oidc` | [*shared.SSOApplicationOIDCConfig](../../../pkg/models/shared/ssoapplicationoidcconfig.md) | :heavy_minus_sign: | N/A | +| `Saml` | [*shared.SSOApplicationSAMLConfig](../../../pkg/models/shared/ssoapplicationsamlconfig.md) | :heavy_minus_sign: | N/A | +| `SectorID` | `*string` | :heavy_minus_sign: | The pairwise sector this application belongs to. Empty means the
    application is its own sector and shares linkability with nothing; set a
    shared value to issue one identifier across applications a user should
    appear the same to. Ignored when the subject type resolves to PUBLIC.
    Immutable once set. | +| `SubjectCompatibility` | [*shared.SSOSubjectCompatibility](../../../pkg/models/shared/ssosubjectcompatibility.md) | :heavy_minus_sign: | N/A | +| `SubjectType` | [*shared.SubjectType](../../../pkg/models/shared/subjecttype.md) | :heavy_minus_sign: | How the user's identifier reaches this application. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationhistoryentry.md b/docs/pkg/models/shared/ssoapplicationhistoryentry.md new file mode 100644 index 000000000..faa66d2bb --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationhistoryentry.md @@ -0,0 +1,12 @@ +# SSOApplicationHistoryEntry + +SSOApplicationHistoryEntry is one version of an SSO application and its + history metadata. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclient.md b/docs/pkg/models/shared/ssoapplicationoidcclient.md new file mode 100644 index 000000000..ce15c90ec --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclient.md @@ -0,0 +1,18 @@ +# SSOApplicationOIDCClient + +SSOApplicationOIDCClient is an App-owned OAuth client minted by C1. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `AppID` | `*string` | :heavy_minus_sign: | Application that owns this client. | +| `Authentication` | [*shared.SSOApplicationOIDCClientAuthentication](../../../pkg/models/shared/ssoapplicationoidcclientauthentication.md) | :heavy_minus_sign: | N/A | +| `ClientID` | `*string` | :heavy_minus_sign: | Client ID generated by ConductorOne. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DisplayName` | `*string` | :heavy_minus_sign: | Human-readable client name. | +| `PkcePolicy` | [*shared.PkcePolicy](../../../pkg/models/shared/pkcepolicy.md) | :heavy_minus_sign: | Effective PKCE policy. | +| `RedirectUris` | []`string` | :heavy_minus_sign: | Exact callback URLs registered for this client. | +| `SsoApplicationID` | `*string` | :heavy_minus_sign: | SSO application whose identity policy applies to this client. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md b/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md new file mode 100644 index 000000000..b49839f5e --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md @@ -0,0 +1,9 @@ +# SSOApplicationOIDCClientAuthClientSecretBasic + +RFC 6749 client_secret_basic. C1 generates and returns the secret once. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md b/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md new file mode 100644 index 000000000..d61dea723 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md @@ -0,0 +1,9 @@ +# SSOApplicationOIDCClientAuthClientSecretPost + +RFC 6749 client_secret_post. C1 generates and returns the secret once. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientauthentication.md b/docs/pkg/models/shared/ssoapplicationoidcclientauthentication.md new file mode 100644 index 000000000..aeff6e23e --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientauthentication.md @@ -0,0 +1,21 @@ +# SSOApplicationOIDCClientAuthentication + +SSOApplicationOIDCClientAuthentication is the exact token-endpoint client + authentication method assigned to an OIDC client. + +This message contains a oneof named method. Only a single field of the following list may be set at a time: + - none + - clientSecretBasic + - clientSecretPost + - privateKeyJwt + + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ClientSecretBasic` | [*shared.SSOApplicationOIDCClientAuthClientSecretBasic](../../../pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.md) | :heavy_minus_sign: | N/A | +| `ClientSecretPost` | [*shared.SSOApplicationOIDCClientAuthClientSecretPost](../../../pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.md) | :heavy_minus_sign: | N/A | +| `None` | [*shared.SSOApplicationOIDCClientAuthNone](../../../pkg/models/shared/ssoapplicationoidcclientauthnone.md) | :heavy_minus_sign: | N/A | +| `PrivateKeyJwt` | [*shared.SSOApplicationOIDCClientAuthPrivateKeyJWT](../../../pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientauthnone.md b/docs/pkg/models/shared/ssoapplicationoidcclientauthnone.md new file mode 100644 index 000000000..562fced96 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientauthnone.md @@ -0,0 +1,9 @@ +# SSOApplicationOIDCClientAuthNone + +Public client authentication. No client credential is issued. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md b/docs/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md new file mode 100644 index 000000000..3dc426c35 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.md @@ -0,0 +1,12 @@ +# SSOApplicationOIDCClientAuthPrivateKeyJWT + +RFC 7523 private_key_jwt using an inline RFC 7517 JWK Set. Multiple public + signing keys allow overlap during relying-party key rotation; C1 selects by + the assertion's `kid`. The relying party retains every private key. + + +## Fields + +| Field | Type | Required | Description | +| --------------------- | --------------------- | --------------------- | --------------------- | +| `PublicJwks` | `string` | :heavy_check_mark: | The publicJwks field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientconfig.md b/docs/pkg/models/shared/ssoapplicationoidcclientconfig.md new file mode 100644 index 000000000..ccabfdc12 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientconfig.md @@ -0,0 +1,14 @@ +# SSOApplicationOIDCClientConfig + +SSOApplicationOIDCClientConfig is the administrator-supplied configuration + from which C1 mints an App-owned OAuth client. The client ID is never input. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Authentication` | [*shared.SSOApplicationOIDCClientAuthentication](../../../pkg/models/shared/ssoapplicationoidcclientauthentication.md) | :heavy_check_mark: | N/A | +| `DisplayName` | `string` | :heavy_check_mark: | Human-readable client name shown to administrators. | +| `PkcePolicy` | [*shared.SSOApplicationOIDCClientConfigPkcePolicy](../../../pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md) | :heavy_minus_sign: | PKCE is required by default on create. On update, UNSPECIFIED preserves
    the current policy; set REQUIRED_S256 explicitly to tighten a legacy
    confidential client. | +| `RedirectUris` | []`string` | :heavy_minus_sign: | Exact redirect URIs the client may use after authorization. HTTPS and
    loopback HTTP are accepted; public clients may also use a reversed-DNS
    private-use scheme for native-app redirects. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md b/docs/pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md new file mode 100644 index 000000000..52fd0e451 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcclientconfigpkcepolicy.md @@ -0,0 +1,27 @@ +# SSOApplicationOIDCClientConfigPkcePolicy + +PKCE is required by default on create. On update, UNSPECIFIED preserves + the current policy; set REQUIRED_S256 explicitly to tighten a legacy + confidential client. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SSOApplicationOIDCClientConfigPkcePolicy("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | +| `SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyUnspecified` | SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED | +| `SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyRequiredS256` | SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256 | +| `SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyAllowMissingForLegacy` | SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationoidcconfig.md b/docs/pkg/models/shared/ssoapplicationoidcconfig.md new file mode 100644 index 000000000..1368c70e9 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationoidcconfig.md @@ -0,0 +1,11 @@ +# SSOApplicationOIDCConfig + +SSOApplicationOIDCConfig is the OIDC-specific sign-in configuration. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | +| `ClaimMappings` | [][shared.OIDCClaimMapping](../../../pkg/models/shared/oidcclaimmapping.md) | :heavy_minus_sign: | Custom claims released to this application, in addition to the standard
    claims its granted scopes already release. | +| `IDTokenSignedResponseAlg` | [*shared.IDTokenSignedResponseAlg](../../../pkg/models/shared/idtokensignedresponsealg.md) | :heavy_minus_sign: | The algorithm used to sign this application's id_token. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationsamlconfig.md b/docs/pkg/models/shared/ssoapplicationsamlconfig.md new file mode 100644 index 000000000..15355be59 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationsamlconfig.md @@ -0,0 +1,20 @@ +# SSOApplicationSAMLConfig + +SSOApplicationSAMLConfig is the SAML-specific sign-in configuration. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AcsUrls` | []`string` | :heavy_check_mark: | The Assertion Consumer Service URLs the assertion may be posted to.
    Matched exactly; a URL that is not in this list is refused. | +| `AttributeMappings` | [][shared.SAMLAttributeMapping](../../../pkg/models/shared/samlattributemapping.md) | :heavy_minus_sign: | The attributes released in the assertion's AttributeStatement. SAML has no
    scopes, so this list is the whole release: the NameID carries the
    identifier and these carry everything else. | +| `EncryptAssertions` | `*bool` | :heavy_minus_sign: | Encrypt the assertion. | +| `EncryptionAlgorithm` | [*shared.EncryptionAlgorithm](../../../pkg/models/shared/encryptionalgorithm.md) | :heavy_minus_sign: | The algorithm used when encrypt_assertions is set. | +| `NameIDFormat` | [*shared.NameIDFormat](../../../pkg/models/shared/nameidformat.md) | :heavy_minus_sign: | Set this when the service provider requires a specific NameID format. This
    also selects the NameID value semantics: EMAIL_ADDRESS uses the user's
    primary email, TRANSIENT creates a new value for each sign-in, and
    PERSISTENT uses the application's pairwise subject. Immutable once set. | +| `RequireSignedAuthnRequests` | `*bool` | :heavy_minus_sign: | Reject any AuthnRequest that is not signed by one of
    sp_signing_certificates. At least one signing certificate is required when
    this is set. | +| `SignAssertions` | `*bool` | :heavy_minus_sign: | Sign the assertion. At least one of sign_assertions or sign_responses must
    be set. | +| `SignResponses` | `*bool` | :heavy_minus_sign: | Sign the response envelope. At least one of sign_assertions or
    sign_responses must be set. | +| `SpEncryptionCertificate` | `*string` | :heavy_minus_sign: | The service provider's DER-encoded encryption certificate, taken from the
    encryption KeyDescriptor in its metadata. Required when encrypt_assertions
    is set. | +| `SpEntityID` | `string` | :heavy_check_mark: | The service provider's entity ID, taken from its metadata. It is the
    audience every assertion this application issues is restricted to, and it
    is what the service provider presents at sign-in. Set it at creation: it is
    fixed for the life of the application, because changing it re-points every
    assertion already issued. An entity ID already in use by another SSO
    application in the tenant is rejected. | +| `SpSigningCertificates` | []`string` | :heavy_minus_sign: | The service provider's DER-encoded signing certificates, taken from the
    signing KeyDescriptors in its metadata. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md b/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md new file mode 100644 index 000000000..abf7f7332 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest + +SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest deletes a + bounded batch of compatibility-subject bindings. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `UserIds` | []`string` | :heavy_minus_sign: | The userIds field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md b/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md new file mode 100644 index 000000000..ec90a702a --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse + +SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded + recovery progress. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | +| `DeletedRows` | `*int` | :heavy_minus_sign: | The deletedRows field. | +| `Issues` | [][shared.SSOSubjectCompatibilityDeleteIssue](../../../pkg/models/shared/ssosubjectcompatibilitydeleteissue.md) | :heavy_minus_sign: | The issues field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md b/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md new file mode 100644 index 000000000..5c0ddf819 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.md @@ -0,0 +1,13 @@ +# SSOApplicationServiceBatchImportSubjectCompatibilityRequest + +SSOApplicationServiceBatchImportSubjectCompatibilityRequest validates or + imports a bounded batch of per-user subject bindings. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | +| `Apply` | `*bool` | :heavy_minus_sign: | When false, validate without writing. Clients should validate every batch
    before beginning the apply pass. | +| `Entries` | [][shared.SSOSubjectCompatibilityImportEntry](../../../pkg/models/shared/ssosubjectcompatibilityimportentry.md) | :heavy_minus_sign: | Client-parsed rows. Each request is bounded to 50 entries. | +| `ImportID` | `*string` | :heavy_minus_sign: | Client-generated identifier shared by every batch from one source file. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md b/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md new file mode 100644 index 000000000..15a6cbbf5 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.md @@ -0,0 +1,17 @@ +# SSOApplicationServiceBatchImportSubjectCompatibilityResponse + +SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one + bounded validation or apply batch. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `BlockingUserIds` | []`string` | :heavy_minus_sign: | Import-created binding owners that block one or more submitted corrections.
    This is a subset of recoverable_user_ids. | +| `ImportedRows` | `*int` | :heavy_minus_sign: | Number of bindings successfully written. Zero for validation-only
    requests; may be less than valid_rows if apply stops on a write failure. | +| `ImportedUserIds` | []`string` | :heavy_minus_sign: | Users whose bindings were created by this import, or were already created
    by an earlier retry carrying the same import_id. | +| `Issues` | [][shared.SSOSubjectCompatibilityImportIssue](../../../pkg/models/shared/ssosubjectcompatibilityimportissue.md) | :heavy_minus_sign: | Row-level validation or apply failures. | +| `RecoverableUserIds` | []`string` | :heavy_minus_sign: | Users whose import-created binding is implicated by a submitted row. This
    may include the current owner of a submitted subject even when that owner
    was not itself submitted. | +| `TotalRows` | `*int` | :heavy_minus_sign: | Number of entries in this batch. | +| `ValidRows` | `*int` | :heavy_minus_sign: | Number of rows that can be imported. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicecreateclientrequest.md b/docs/pkg/models/shared/ssoapplicationservicecreateclientrequest.md new file mode 100644 index 000000000..071f84a2e --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicecreateclientrequest.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceCreateClientRequest + +SSOApplicationServiceCreateClientRequest mints an additional App-owned + client. The caller supplies configuration, never a client ID. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `Client` | [*shared.SSOApplicationOIDCClientConfig](../../../pkg/models/shared/ssoapplicationoidcclientconfig.md) | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicecreateclientresponse.md b/docs/pkg/models/shared/ssoapplicationservicecreateclientresponse.md new file mode 100644 index 000000000..40bcea0ae --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicecreateclientresponse.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceCreateClientResponse + +SSOApplicationServiceCreateClientResponse contains the generated client and + its one-time secret, when applicable. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `Client` | [*shared.SSOApplicationOIDCClient](../../../pkg/models/shared/ssoapplicationoidcclient.md) | :heavy_minus_sign: | N/A | +| `ClientSecret` | `*string` | :heavy_minus_sign: | Returned once for client_secret_basic/client_secret_post; empty for
    none/private_key_jwt. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicecreaterequest.md b/docs/pkg/models/shared/ssoapplicationservicecreaterequest.md new file mode 100644 index 000000000..030250237 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicecreaterequest.md @@ -0,0 +1,23 @@ +# SSOApplicationServiceCreateRequest + +SSOApplicationServiceCreateRequest creates an SSO application. + +This message contains a oneof named protocol. Only a single field of the following list may be set at a time: + - oidc + - saml + + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `AssertionLifetime` | `*string` | :heavy_minus_sign: | N/A | +| `Description` | `*string` | :heavy_minus_sign: | Description of the SSO application. | +| `DisplayName` | `string` | :heavy_check_mark: | Display name for the SSO application. | +| `InitialClient` | [*shared.SSOApplicationOIDCClientConfig](../../../pkg/models/shared/ssoapplicationoidcclientconfig.md) | :heavy_minus_sign: | N/A | +| `Oidc` | [*shared.SSOApplicationOIDCConfig](../../../pkg/models/shared/ssoapplicationoidcconfig.md) | :heavy_minus_sign: | N/A | +| `Saml` | [*shared.SSOApplicationSAMLConfig](../../../pkg/models/shared/ssoapplicationsamlconfig.md) | :heavy_minus_sign: | N/A | +| `SectorID` | `*string` | :heavy_minus_sign: | The pairwise sector this application belongs to. Empty means the
    application is its own sector. Immutable after creation. | +| `SubjectCompatibility` | [*shared.SSOSubjectCompatibility](../../../pkg/models/shared/ssosubjectcompatibility.md) | :heavy_minus_sign: | N/A | +| `SubjectType` | [*shared.SSOApplicationServiceCreateRequestSubjectType](../../../pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md) | :heavy_minus_sign: | How the user's identifier reaches this application. Leave unset to use the
    tenant default. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md b/docs/pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md new file mode 100644 index 000000000..f6f51c4bb --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicecreaterequestsubjecttype.md @@ -0,0 +1,27 @@ +# SSOApplicationServiceCreateRequestSubjectType + +How the user's identifier reaches this application. Leave unset to use the + tenant default. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SSOApplicationServiceCreateRequestSubjectType("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypeUnspecified` | SSO_SUBJECT_TYPE_UNSPECIFIED | +| `SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypePairwise` | SSO_SUBJECT_TYPE_PAIRWISE | +| `SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypePublic` | SSO_SUBJECT_TYPE_PUBLIC | +| `SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypeCompatibility` | SSO_SUBJECT_TYPE_COMPATIBILITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicecreateresponse.md b/docs/pkg/models/shared/ssoapplicationservicecreateresponse.md new file mode 100644 index 000000000..8cfaada0c --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicecreateresponse.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceCreateResponse + +SSOApplicationServiceCreateResponse returns the created SSO application. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | +| `Application` | [*shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | N/A | +| `Client` | [*shared.SSOApplicationOIDCClient](../../../pkg/models/shared/ssoapplicationoidcclient.md) | :heavy_minus_sign: | N/A | +| `ClientSecret` | `*string` | :heavy_minus_sign: | Confidential-client secret returned once. Empty for SAML and public OIDC
    clients. C1 stores only its hash. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicedeleteclientrequest.md b/docs/pkg/models/shared/ssoapplicationservicedeleteclientrequest.md new file mode 100644 index 000000000..50cfe24d9 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicedeleteclientrequest.md @@ -0,0 +1,10 @@ +# SSOApplicationServiceDeleteClientRequest + +SSOApplicationServiceDeleteClientRequest deletes one App-owned OAuth client. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------ | ------------------------------ | ------------------------------ | ------------------------------ | +| `ClientID` | `string` | :heavy_check_mark: | Generated client ID to delete. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicedeleteclientresponse.md b/docs/pkg/models/shared/ssoapplicationservicedeleteclientresponse.md new file mode 100644 index 000000000..4c77f1bdb --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicedeleteclientresponse.md @@ -0,0 +1,9 @@ +# SSOApplicationServiceDeleteClientResponse + +SSOApplicationServiceDeleteClientResponse confirms deletion. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicedeleterequest.md b/docs/pkg/models/shared/ssoapplicationservicedeleterequest.md new file mode 100644 index 000000000..daebc0984 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicedeleterequest.md @@ -0,0 +1,9 @@ +# SSOApplicationServiceDeleteRequest + +SSOApplicationServiceDeleteRequest deletes an SSO application. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicedeleteresponse.md b/docs/pkg/models/shared/ssoapplicationservicedeleteresponse.md new file mode 100644 index 000000000..17c499d7a --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicedeleteresponse.md @@ -0,0 +1,9 @@ +# SSOApplicationServiceDeleteResponse + +SSOApplicationServiceDeleteResponse confirms deletion. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicegetresponse.md b/docs/pkg/models/shared/ssoapplicationservicegetresponse.md new file mode 100644 index 000000000..421b6cd86 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicegetresponse.md @@ -0,0 +1,10 @@ +# SSOApplicationServiceGetResponse + +SSOApplicationServiceGetResponse returns a single SSO application. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Application` | [*shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicelistclientsresponse.md b/docs/pkg/models/shared/ssoapplicationservicelistclientsresponse.md new file mode 100644 index 000000000..f05a2229f --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicelistclientsresponse.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceListClientsResponse + +SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth + clients. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | +| `List` | [][shared.SSOApplicationOIDCClient](../../../pkg/models/shared/ssoapplicationoidcclient.md) | :heavy_minus_sign: | App-owned clients in this page. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page, or empty when complete. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicelisthistoryresponse.md b/docs/pkg/models/shared/ssoapplicationservicelisthistoryresponse.md new file mode 100644 index 000000000..cf9d3d411 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicelisthistoryresponse.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceListHistoryResponse + +SSOApplicationServiceListHistoryResponse returns SSO application history + entries. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | +| `List` | [][shared.SSOApplicationHistoryEntry](../../../pkg/models/shared/ssoapplicationhistoryentry.md) | :heavy_minus_sign: | The page of history entries, newest first. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page, or empty if there are no more results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicelistresponse.md b/docs/pkg/models/shared/ssoapplicationservicelistresponse.md new file mode 100644 index 000000000..9bb9330cc --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicelistresponse.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceListResponse + +SSOApplicationServiceListResponse returns a page of SSO applications. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `List` | [][shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | The page of SSO applications. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page, or empty if there are no more results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md b/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md new file mode 100644 index 000000000..99524b01f --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceParseSAMLServiceProviderMetadataRequest + +SSOApplicationServiceParseSAMLServiceProviderMetadataRequest carries one + SAML service-provider metadata document to parse. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `MetadataXML` | `string` | :heavy_check_mark: | The SP metadata XML document, exactly as downloaded or exported from the
    service provider. Maximum 1 MiB. The document is parsed, never stored. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md b/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md new file mode 100644 index 000000000..79a7bd448 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md @@ -0,0 +1,13 @@ +# SSOApplicationServiceParseSAMLServiceProviderMetadataResponse + +SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the + SAML configuration derived from one metadata document and every finding the + parser raised about it. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `Config` | [*shared.SSOApplicationSAMLConfig](../../../pkg/models/shared/ssoapplicationsamlconfig.md) | :heavy_minus_sign: | N/A | +| `Findings` | [][shared.SAMLMetadataFinding](../../../pkg/models/shared/samlmetadatafinding.md) | :heavy_minus_sign: | Everything the parser noticed about the document, including requirements
    it could not map into the configuration. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md b/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md new file mode 100644 index 000000000..80319473d --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceRotateClientSecretRequest + +SSOApplicationServiceRotateClientSecretRequest rotates one confidential + App-owned client's secret. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------- | ------------------------------------------------- | ------------------------------------------------- | ------------------------------------------------- | +| `ClientID` | `string` | :heavy_check_mark: | Generated client ID whose secret will be rotated. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md b/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md new file mode 100644 index 000000000..a076e35a7 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceRotateClientSecretResponse + +SSOApplicationServiceRotateClientSecretResponse contains the replacement + secret. The value cannot be retrieved again. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------- | -------------------------------------- | -------------------------------------- | -------------------------------------- | +| `ClientSecret` | `*string` | :heavy_minus_sign: | New client secret, shown exactly once. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicesearchrequest.md b/docs/pkg/models/shared/ssoapplicationservicesearchrequest.md new file mode 100644 index 000000000..bd13d394f --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicesearchrequest.md @@ -0,0 +1,13 @@ +# SSOApplicationServiceSearchRequest + +SSOApplicationServiceSearchRequest searches SSO applications with filters. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | +| `AppIds` | []`string` | :heavy_minus_sign: | Optional filter by applications in your catalog. Empty matches any
    application. | +| `PageSize` | `*int` | :heavy_minus_sign: | Maximum number of results to return per page. | +| `PageToken` | `*string` | :heavy_minus_sign: | Pagination token from a previous response. | +| `Query` | `*string` | :heavy_minus_sign: | Optional text query matched against display_name and description. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationservicesearchresponse.md b/docs/pkg/models/shared/ssoapplicationservicesearchresponse.md new file mode 100644 index 000000000..b4bfce350 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationservicesearchresponse.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceSearchResponse + +SSOApplicationServiceSearchResponse returns matching SSO applications. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------------------- | +| `List` | [][shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | Matching SSO applications. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Token for the next page. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceupdateclientrequest.md b/docs/pkg/models/shared/ssoapplicationserviceupdateclientrequest.md new file mode 100644 index 000000000..579f9e6d6 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceupdateclientrequest.md @@ -0,0 +1,12 @@ +# SSOApplicationServiceUpdateClientRequest + +SSOApplicationServiceUpdateClientRequest replaces display name, redirect + URIs, private-key JWKS, or tightens legacy PKCE to required. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `Client` | [*shared.SSOApplicationOIDCClientConfig](../../../pkg/models/shared/ssoapplicationoidcclientconfig.md) | :heavy_check_mark: | N/A | +| `ClientID` | `string` | :heavy_check_mark: | Generated client ID to update. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceupdateclientresponse.md b/docs/pkg/models/shared/ssoapplicationserviceupdateclientresponse.md new file mode 100644 index 000000000..61d7850f1 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceupdateclientresponse.md @@ -0,0 +1,10 @@ +# SSOApplicationServiceUpdateClientResponse + +SSOApplicationServiceUpdateClientResponse contains the updated client. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `Client` | [*shared.SSOApplicationOIDCClient](../../../pkg/models/shared/ssoapplicationoidcclient.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceupdaterequest.md b/docs/pkg/models/shared/ssoapplicationserviceupdaterequest.md new file mode 100644 index 000000000..e5a65fe56 --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceupdaterequest.md @@ -0,0 +1,11 @@ +# SSOApplicationServiceUpdateRequest + +SSOApplicationServiceUpdateRequest updates an SSO application. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Application` | [*shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_check_mark: | N/A | +| `UpdateMask` | `*string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssoapplicationserviceupdateresponse.md b/docs/pkg/models/shared/ssoapplicationserviceupdateresponse.md new file mode 100644 index 000000000..fcd1671ae --- /dev/null +++ b/docs/pkg/models/shared/ssoapplicationserviceupdateresponse.md @@ -0,0 +1,10 @@ +# SSOApplicationServiceUpdateResponse + +SSOApplicationServiceUpdateResponse returns the updated SSO application. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Application` | [*shared.SSOApplication](../../../pkg/models/shared/ssoapplication.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettings.md b/docs/pkg/models/shared/ssosettings.md new file mode 100644 index 000000000..1b10bb9e7 --- /dev/null +++ b/docs/pkg/models/shared/ssosettings.md @@ -0,0 +1,16 @@ +# SSOSettings + +SSOSettings is the per-tenant configuration for ConductorOne acting as an SSO + provider. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DefaultAssertionLifetime` | `*string` | :heavy_minus_sign: | N/A | +| `DefaultIDTokenSignedResponseAlg` | [*shared.DefaultIDTokenSignedResponseAlg](../../../pkg/models/shared/defaultidtokensignedresponsealg.md) | :heavy_minus_sign: | The id_token signing algorithm applied to OIDC applications that do not
    choose one. When unset, the server uses EdDSA. | +| `DefaultSubjectType` | [*shared.DefaultSubjectType](../../../pkg/models/shared/defaultsubjecttype.md) | :heavy_minus_sign: | The subject type materialized onto new SSO applications that do not choose
    one. Changing this default does not change existing applications. When
    unset, the server uses pairwise subjects. | +| `Enabled` | `*bool` | :heavy_minus_sign: | Master switch for the SSO provider. ConductorOne also gates the feature
    behind an operator-controlled rollout flag; this is the tenant
    administrator's intent. Individual SSO applications can still be disabled
    one at a time. | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettingshistoryentry.md b/docs/pkg/models/shared/ssosettingshistoryentry.md new file mode 100644 index 000000000..8c8b6fa75 --- /dev/null +++ b/docs/pkg/models/shared/ssosettingshistoryentry.md @@ -0,0 +1,12 @@ +# SSOSettingsHistoryEntry + +SSOSettingsHistoryEntry is one version of the tenant's SSO settings and its + change metadata. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | +| `Metadata` | [*shared.HistoryEntryMetadata](../../../pkg/models/shared/historyentrymetadata.md) | :heavy_minus_sign: | N/A | +| `Snapshot` | [*shared.SSOSettings](../../../pkg/models/shared/ssosettings.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettingsservicegetresponse.md b/docs/pkg/models/shared/ssosettingsservicegetresponse.md new file mode 100644 index 000000000..ad5b82947 --- /dev/null +++ b/docs/pkg/models/shared/ssosettingsservicegetresponse.md @@ -0,0 +1,10 @@ +# SSOSettingsServiceGetResponse + +SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Settings` | [*shared.SSOSettings](../../../pkg/models/shared/ssosettings.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettingsservicelisthistoryresponse.md b/docs/pkg/models/shared/ssosettingsservicelisthistoryresponse.md new file mode 100644 index 000000000..45d2635b8 --- /dev/null +++ b/docs/pkg/models/shared/ssosettingsservicelisthistoryresponse.md @@ -0,0 +1,11 @@ +# SSOSettingsServiceListHistoryResponse + +SSOSettingsServiceListHistoryResponse returns SSO settings history entries. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | +| `List` | [][shared.SSOSettingsHistoryEntry](../../../pkg/models/shared/ssosettingshistoryentry.md) | :heavy_minus_sign: | The page of history entries, newest first. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | Pagination token for the next page, or empty if there are no more results. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettingsserviceupdaterequest.md b/docs/pkg/models/shared/ssosettingsserviceupdaterequest.md new file mode 100644 index 000000000..a3e67d67e --- /dev/null +++ b/docs/pkg/models/shared/ssosettingsserviceupdaterequest.md @@ -0,0 +1,11 @@ +# SSOSettingsServiceUpdateRequest + +SSOSettingsServiceUpdateRequest updates the tenant's SSO provider settings. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Settings` | [*shared.SSOSettings](../../../pkg/models/shared/ssosettings.md) | :heavy_check_mark: | N/A | +| `UpdateMask` | `*string` | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosettingsserviceupdateresponse.md b/docs/pkg/models/shared/ssosettingsserviceupdateresponse.md new file mode 100644 index 000000000..3077388a2 --- /dev/null +++ b/docs/pkg/models/shared/ssosettingsserviceupdateresponse.md @@ -0,0 +1,10 @@ +# SSOSettingsServiceUpdateResponse + +SSOSettingsServiceUpdateResponse returns the updated settings. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | +| `Settings` | [*shared.SSOSettings](../../../pkg/models/shared/ssosettings.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosubjectcompatibility.md b/docs/pkg/models/shared/ssosubjectcompatibility.md new file mode 100644 index 000000000..fe4020196 --- /dev/null +++ b/docs/pkg/models/shared/ssosubjectcompatibility.md @@ -0,0 +1,11 @@ +# SSOSubjectCompatibility + +SSOSubjectCompatibility configures preservation of subjects issued by a + previous identity provider. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `UserAttributeMappingID` | `*string` | :heavy_minus_sign: | Optional user-attribute mapping used to resolve a legacy subject on first
    sign-in. The resolved value is frozen in an immutable per-user binding.
    Correct the source attribute before deleting an attribute-derived binding;
    otherwise the next sign-in resolves and freezes the same value again. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosubjectcompatibilitydeleteissue.md b/docs/pkg/models/shared/ssosubjectcompatibilitydeleteissue.md new file mode 100644 index 000000000..ec3b4c027 --- /dev/null +++ b/docs/pkg/models/shared/ssosubjectcompatibilitydeleteissue.md @@ -0,0 +1,12 @@ +# SSOSubjectCompatibilityDeleteIssue + +SSOSubjectCompatibilityDeleteIssue describes one compatibility binding that + could not be deleted. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Reason` | `*string` | :heavy_minus_sign: | The reason field. | +| `UserID` | `*string` | :heavy_minus_sign: | The userId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosubjectcompatibilityimportentry.md b/docs/pkg/models/shared/ssosubjectcompatibilityimportentry.md new file mode 100644 index 000000000..76dbd3185 --- /dev/null +++ b/docs/pkg/models/shared/ssosubjectcompatibilityimportentry.md @@ -0,0 +1,12 @@ +# SSOSubjectCompatibilityImportEntry + +SSOSubjectCompatibilityImportEntry is one client-parsed source row. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Row` | `*int` | :heavy_minus_sign: | One-based row number in the source file, including its header. | +| `Subject` | `*string` | :heavy_minus_sign: | Exact legacy subject. C1 preserves these UTF-8 bytes without trimming. | +| `UserID` | `*string` | :heavy_minus_sign: | ConductorOne user ID resolved by the client before this batch is sent. | \ No newline at end of file diff --git a/docs/pkg/models/shared/ssosubjectcompatibilityimportissue.md b/docs/pkg/models/shared/ssosubjectcompatibilityimportissue.md new file mode 100644 index 000000000..309e90547 --- /dev/null +++ b/docs/pkg/models/shared/ssosubjectcompatibilityimportissue.md @@ -0,0 +1,14 @@ +# SSOSubjectCompatibilityImportIssue + +SSOSubjectCompatibilityImportIssue describes one CSV row that cannot be + imported. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------- | --------------------------------------------------- | --------------------------------------------------- | --------------------------------------------------- | +| `Reason` | `*string` | :heavy_minus_sign: | Human-readable reason this row cannot be imported. | +| `Row` | `*int` | :heavy_minus_sign: | One-based CSV row number, including the header row. | +| `Subject` | `*string` | :heavy_minus_sign: | Legacy subject supplied by the batch entry. | +| `UserID` | `*string` | :heavy_minus_sign: | ConductorOne user ID supplied by the batch entry. | \ No newline at end of file diff --git a/docs/pkg/models/shared/statefilter.md b/docs/pkg/models/shared/statefilter.md index 6d9404d48..88d611bc5 100644 --- a/docs/pkg/models/shared/statefilter.md +++ b/docs/pkg/models/shared/statefilter.md @@ -7,7 +7,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" ) -value := shared.StateFilterMcpToolStateUnspecified +value := shared.StateFilterMcpResourceStateUnspecified // Open enum: custom values can be created with a direct type cast custom := shared.StateFilter("custom_value") @@ -16,10 +16,10 @@ custom := shared.StateFilter("custom_value") ## Values -| Name | Value | -| -------------------------------------- | -------------------------------------- | -| `StateFilterMcpToolStateUnspecified` | MCP_TOOL_STATE_UNSPECIFIED | -| `StateFilterMcpToolStatePendingReview` | MCP_TOOL_STATE_PENDING_REVIEW | -| `StateFilterMcpToolStateApproved` | MCP_TOOL_STATE_APPROVED | -| `StateFilterMcpToolStateDisabled` | MCP_TOOL_STATE_DISABLED | -| `StateFilterMcpToolStateRemoved` | MCP_TOOL_STATE_REMOVED | \ No newline at end of file +| Name | Value | +| ------------------------------------------ | ------------------------------------------ | +| `StateFilterMcpResourceStateUnspecified` | MCP_RESOURCE_STATE_UNSPECIFIED | +| `StateFilterMcpResourceStatePendingReview` | MCP_RESOURCE_STATE_PENDING_REVIEW | +| `StateFilterMcpResourceStateApproved` | MCP_RESOURCE_STATE_APPROVED | +| `StateFilterMcpResourceStateDisabled` | MCP_RESOURCE_STATE_DISABLED | +| `StateFilterMcpResourceStateRemoved` | MCP_RESOURCE_STATE_REMOVED | \ No newline at end of file diff --git a/docs/pkg/models/shared/subjecttype.md b/docs/pkg/models/shared/subjecttype.md new file mode 100644 index 000000000..55c8a281c --- /dev/null +++ b/docs/pkg/models/shared/subjecttype.md @@ -0,0 +1,26 @@ +# SubjectType + +How the user's identifier reaches this application. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SubjectTypeSsoSubjectTypeUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.SubjectType("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------- | ---------------------------------------- | +| `SubjectTypeSsoSubjectTypeUnspecified` | SSO_SUBJECT_TYPE_UNSPECIFIED | +| `SubjectTypeSsoSubjectTypePairwise` | SSO_SUBJECT_TYPE_PAIRWISE | +| `SubjectTypeSsoSubjectTypePublic` | SSO_SUBJECT_TYPE_PUBLIC | +| `SubjectTypeSsoSubjectTypeCompatibility` | SSO_SUBJECT_TYPE_COMPATIBILITY | \ No newline at end of file diff --git a/docs/pkg/models/shared/surfaces.md b/docs/pkg/models/shared/surfaces.md new file mode 100644 index 000000000..c226b13f3 --- /dev/null +++ b/docs/pkg/models/shared/surfaces.md @@ -0,0 +1,23 @@ +# Surfaces + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.SurfacesHookOutputSurfaceUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Surfaces("custom_value") +``` + + +## Values + +| Name | Value | +| -------------------------------------- | -------------------------------------- | +| `SurfacesHookOutputSurfaceUnspecified` | HOOK_OUTPUT_SURFACE_UNSPECIFIED | +| `SurfacesHookOutputSurfaceSlack` | HOOK_OUTPUT_SURFACE_SLACK | +| `SurfacesHookOutputSurfaceWeb` | HOOK_OUTPUT_SURFACE_WEB | \ No newline at end of file diff --git a/docs/pkg/models/shared/systempreference.md b/docs/pkg/models/shared/systempreference.md new file mode 100644 index 000000000..e8c910c19 --- /dev/null +++ b/docs/pkg/models/shared/systempreference.md @@ -0,0 +1,11 @@ +# SystemPreference + +The SystemPreference message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `Enabled` | `*bool` | :heavy_minus_sign: | The enabled field. | +| `Locked` | `*bool` | :heavy_minus_sign: | The locked field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskactionsserviceretryprovisioningrequest.md b/docs/pkg/models/shared/taskactionsserviceretryprovisioningrequest.md new file mode 100644 index 000000000..f4f29c0f6 --- /dev/null +++ b/docs/pkg/models/shared/taskactionsserviceretryprovisioningrequest.md @@ -0,0 +1,12 @@ +# TaskActionsServiceRetryProvisioningRequest + +Request to retry a task's failed connector provisioning. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `Comment` | `*string` | :heavy_minus_sign: | An optional comment attached to the action. | +| `ExpandMask` | [*shared.TaskExpandMask](../../../pkg/models/shared/taskexpandmask.md) | :heavy_minus_sign: | N/A | +| `PolicyStepID` | `*string` | :heavy_minus_sign: | The ID of the provision policy step to retry. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditaccountdeleted.md b/docs/pkg/models/shared/taskauditaccountdeleted.md new file mode 100644 index 000000000..47b14b5ff --- /dev/null +++ b/docs/pkg/models/shared/taskauditaccountdeleted.md @@ -0,0 +1,16 @@ +# TaskAuditAccountDeleted + +TaskAuditAccountDeleted records an account deletion reported by a connector + while completing a revoke action. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------ | ------------------------------ | ------------------------------ | ------------------------------ | +| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | +| `AppUserID` | `*string` | :heavy_minus_sign: | The appUserId field. | +| `ConnectorResourceID` | `*string` | :heavy_minus_sign: | The connectorResourceId field. | +| `DisplayName` | `*string` | :heavy_minus_sign: | The displayName field. | +| `Email` | `*string` | :heavy_minus_sign: | The email field. | +| `Username` | `*string` | :heavy_minus_sign: | The username field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditautomationtriggered.md b/docs/pkg/models/shared/taskauditautomationtriggered.md new file mode 100644 index 000000000..46b20f4ab --- /dev/null +++ b/docs/pkg/models/shared/taskauditautomationtriggered.md @@ -0,0 +1,13 @@ +# TaskAuditAutomationTriggered + +TaskAuditAutomationTriggered attributes a system-created task to the + automation execution that created it. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- | +| `AutomationExecutionID` | `*int64` | :heavy_minus_sign: | The specific execution of the automation that created the task. | +| `AutomationID` | `*string` | :heavy_minus_sign: | The automation that created the task. | +| `AutomationName` | `*string` | :heavy_minus_sign: | The automation's display name as of task creation, so the event stays
    readable after the automation is renamed or deleted. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditconditionalpolicyexecutionresult.md b/docs/pkg/models/shared/taskauditconditionalpolicyexecutionresult.md index 8db6f82ea..7150a43bd 100644 --- a/docs/pkg/models/shared/taskauditconditionalpolicyexecutionresult.md +++ b/docs/pkg/models/shared/taskauditconditionalpolicyexecutionresult.md @@ -5,10 +5,13 @@ The TaskAuditConditionalPolicyExecutionResult message. ## Fields -| Field | Type | Required | Description | -| --------------------------- | --------------------------- | --------------------------- | --------------------------- | -| `Condition` | `*string` | :heavy_minus_sign: | The condition field. | -| `ConditionMatched` | `*bool` | :heavy_minus_sign: | The conditionMatched field. | -| `DefaultCondition` | `*bool` | :heavy_minus_sign: | The defaultCondition field. | -| `Error` | `*string` | :heavy_minus_sign: | The error field. | -| `PolicyKey` | `*string` | :heavy_minus_sign: | The policyKey field. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ChainDepth` | `*int` | :heavy_minus_sign: | The depth of this policy in the chain (0 = root, 1 = first hop, etc.). | +| `Condition` | `*string` | :heavy_minus_sign: | The condition field. | +| `ConditionMatched` | `*bool` | :heavy_minus_sign: | The conditionMatched field. | +| `DefaultCondition` | `*bool` | :heavy_minus_sign: | The defaultCondition field. | +| `Error` | `*string` | :heavy_minus_sign: | The error field. | +| `OutcomePolicyID` | `*string` | :heavy_minus_sign: | When this rule's outcome is a reference to another Policy, the ID of
    that referenced policy. Empty when the outcome is an inline policy_key. | +| `PolicyID` | `*string` | :heavy_minus_sign: | The policy in which this rule was evaluated. Empty for results recorded
    before chained policy references existed; populated for every result
    emitted by recursive evaluation. | +| `PolicyKey` | `*string` | :heavy_minus_sign: | The policyKey field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditlistrequest.md b/docs/pkg/models/shared/taskauditlistrequest.md index 11380c753..9d5a2eae3 100644 --- a/docs/pkg/models/shared/taskauditlistrequest.md +++ b/docs/pkg/models/shared/taskauditlistrequest.md @@ -5,11 +5,12 @@ The TaskAuditListRequest message. ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -| `CommentsOnly` | `*bool` | :heavy_minus_sign: | When true, only comment events are returned, so a page of page_size holds
    page_size comments rather than a mix of comments and state-change events. | -| `NewestFirst` | `*bool` | :heavy_minus_sign: | When true, events are returned newest-first (descending created_at) instead
    of the default chronological (ascending) order. | -| `PageSize` | `*int` | :heavy_minus_sign: | The maximum number of audit events to return per page. | -| `PageToken` | `*string` | :heavy_minus_sign: | A pagination token from a previous response to retrieve the next page. | -| `Refs` | [][shared.TaskAuditViewRef](../../../pkg/models/shared/taskauditviewref.md) | :heavy_minus_sign: | References to specific audit events to retrieve. If provided, only these events are returned. | -| `TaskID` | `*string` | :heavy_minus_sign: | The ID of the task to list audit events for. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `CommentsOnly` | `*bool` | :heavy_minus_sign: | When true, only comment events are returned, so a page of page_size holds
    page_size comments rather than a mix of comments and state-change events. | +| `ExcludeComments` | `*bool` | :heavy_minus_sign: | When true, comment events are excluded from the response and the count, so
    a page of page_size holds page_size non-comment events. Mutually exclusive
    with comments_only. | +| `NewestFirst` | `*bool` | :heavy_minus_sign: | When true, events are returned newest-first (descending created_at) instead
    of the default chronological (ascending) order. | +| `PageSize` | `*int` | :heavy_minus_sign: | The maximum number of audit events to return per page. | +| `PageToken` | `*string` | :heavy_minus_sign: | A pagination token from a previous response to retrieve the next page. | +| `Refs` | [][shared.TaskAuditViewRef](../../../pkg/models/shared/taskauditviewref.md) | :heavy_minus_sign: | References to specific audit events to retrieve. If provided, only these events are returned. | +| `TaskID` | `*string` | :heavy_minus_sign: | The ID of the task to list audit events for. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditlistresponse.md b/docs/pkg/models/shared/taskauditlistresponse.md index e8bcb8fd1..5cf2523d1 100644 --- a/docs/pkg/models/shared/taskauditlistresponse.md +++ b/docs/pkg/models/shared/taskauditlistresponse.md @@ -5,7 +5,8 @@ The TaskAuditListResponse message. ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------- | --------------------------------------------------------------------- | --------------------------------------------------------------------- | --------------------------------------------------------------------- | -| `List` | [][shared.TaskAuditView](../../../pkg/models/shared/taskauditview.md) | :heavy_minus_sign: | The list of audit events for the task. | -| `NextPageToken` | `*string` | :heavy_minus_sign: | A pagination token to retrieve the next page of results. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `List` | [][shared.TaskAuditView](../../../pkg/models/shared/taskauditview.md) | :heavy_minus_sign: | The list of audit events for the task. | +| `NextPageToken` | `*string` | :heavy_minus_sign: | A pagination token to retrieve the next page of results. | +| `TotalCount` | `*int64` | :heavy_minus_sign: | The total number of audit events the list returns for this request:
    comment events when comments_only is true, non-comment events when
    exclude_comments is true, all events otherwise. This is an upper bound:
    a small number of internal-only events (e.g. connector-action results
    with no pending reason) are omitted from list, so the count can exceed
    the rows reachable by paging. Only returned for the first page (a request
    with no page_token). Unset when the request filters by refs (the count is
    undefined for ref lookups) or when the count could not be computed. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditprovisionentitlementmergecompleted.md b/docs/pkg/models/shared/taskauditprovisionentitlementmergecompleted.md new file mode 100644 index 000000000..3aaf0f195 --- /dev/null +++ b/docs/pkg/models/shared/taskauditprovisionentitlementmergecompleted.md @@ -0,0 +1,11 @@ +# TaskAuditProvisionEntitlementMergeCompleted + +The TaskAuditProvisionEntitlementMergeCompleted message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------- | --------------------------- | --------------------------- | --------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The appEntitlementId field. | +| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditprovisionentitlementmergetimedout.md b/docs/pkg/models/shared/taskauditprovisionentitlementmergetimedout.md new file mode 100644 index 000000000..19aa0c007 --- /dev/null +++ b/docs/pkg/models/shared/taskauditprovisionentitlementmergetimedout.md @@ -0,0 +1,11 @@ +# TaskAuditProvisionEntitlementMergeTimedOut + +The TaskAuditProvisionEntitlementMergeTimedOut message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------- | --------------------------- | --------------------------- | --------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The appEntitlementId field. | +| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md b/docs/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md new file mode 100644 index 000000000..78bdcf880 --- /dev/null +++ b/docs/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md @@ -0,0 +1,12 @@ +# TaskAuditProvisionWaitingForEntitlementMerge + +The TaskAuditProvisionWaitingForEntitlementMerge message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The appEntitlementId field. | +| `AppID` | `*string` | :heavy_minus_sign: | The appId field. | +| `FallbackAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/taskauditview.md b/docs/pkg/models/shared/taskauditview.md index 8a1ea7870..26f3afb2a 100644 --- a/docs/pkg/models/shared/taskauditview.md +++ b/docs/pkg/models/shared/taskauditview.md @@ -65,6 +65,11 @@ This message contains a oneof named typ. Only a single field of the following li - taskCreatedFrom - reassignmentFallbackToAdmin - requestDefaultsApplied + - provisionWaitingForEntitlementMerge + - provisionEntitlementMergeCompleted + - provisionEntitlementMergeTimedOut + - accountDeleted + - automationTriggered @@ -73,6 +78,7 @@ This message contains a oneof named typ. Only a single field of the following li | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | | `AccessRequestOutcome` | [*shared.TaskAuditAccessRequestOutcome](../../../pkg/models/shared/taskauditaccessrequestoutcome.md) | :heavy_minus_sign: | N/A | +| `AccountDeleted` | [*shared.TaskAuditAccountDeleted](../../../pkg/models/shared/taskauditaccountdeleted.md) | :heavy_minus_sign: | N/A | | `AccountLifecycleActionCreated` | [*shared.TaskAuditAccountLifecycleActionCreated](../../../pkg/models/shared/taskauditaccountlifecycleactioncreated.md) | :heavy_minus_sign: | N/A | | `AccountLifecycleActionFailed` | [*shared.TaskAuditAccountLifecycleActionFailed](../../../pkg/models/shared/taskauditaccountlifecycleactionfailed.md) | :heavy_minus_sign: | N/A | | `ActionInstanceCreated` | [*shared.TaskAuditActionInstanceCreated](../../../pkg/models/shared/taskauditactioninstancecreated.md) | :heavy_minus_sign: | N/A | @@ -85,6 +91,7 @@ This message contains a oneof named typ. Only a single field of the following li | `ApprovalInstanceChange` | [*shared.TaskAuditApprovalInstanceChange](../../../pkg/models/shared/taskauditapprovalinstancechange.md) | :heavy_minus_sign: | N/A | | `ApprovalReassigned` | [*shared.TaskAuditPolicyApprovalReassigned](../../../pkg/models/shared/taskauditpolicyapprovalreassigned.md) | :heavy_minus_sign: | N/A | | `ApprovedAutomatically` | [*shared.TaskAuditApprovalHappenedAutomatically](../../../pkg/models/shared/taskauditapprovalhappenedautomatically.md) | :heavy_minus_sign: | N/A | +| `AutomationTriggered` | [*shared.TaskAuditAutomationTriggered](../../../pkg/models/shared/taskauditautomationtriggered.md) | :heavy_minus_sign: | N/A | | `BulkActionError` | [*shared.TaskAuditBulkActionError](../../../pkg/models/shared/taskauditbulkactionerror.md) | :heavy_minus_sign: | N/A | | `CertifyOutcome` | [*shared.TaskAuditCertifyOutcome](../../../pkg/models/shared/taskauditcertifyoutcome.md) | :heavy_minus_sign: | N/A | | `Comment` | [*shared.TaskAuditComment](../../../pkg/models/shared/taskauditcomment.md) | :heavy_minus_sign: | N/A | @@ -109,8 +116,11 @@ This message contains a oneof named typ. Only a single field of the following li | `PolicyChanged` | [*shared.TaskAuditPolicyChanged](../../../pkg/models/shared/taskauditpolicychanged.md) | :heavy_minus_sign: | N/A | | `PolicyEvaluationStep` | [*shared.TaskAuditPolicyEvaluationStep](../../../pkg/models/shared/taskauditpolicyevaluationstep.md) | :heavy_minus_sign: | N/A | | `ProvisionCancelled` | [*shared.TaskAuditPolicyProvisionCancelled](../../../pkg/models/shared/taskauditpolicyprovisioncancelled.md) | :heavy_minus_sign: | N/A | +| `ProvisionEntitlementMergeCompleted` | [*shared.TaskAuditProvisionEntitlementMergeCompleted](../../../pkg/models/shared/taskauditprovisionentitlementmergecompleted.md) | :heavy_minus_sign: | N/A | +| `ProvisionEntitlementMergeTimedOut` | [*shared.TaskAuditProvisionEntitlementMergeTimedOut](../../../pkg/models/shared/taskauditprovisionentitlementmergetimedout.md) | :heavy_minus_sign: | N/A | | `ProvisionError` | [*shared.TaskAuditPolicyProvisionError](../../../pkg/models/shared/taskauditpolicyprovisionerror.md) | :heavy_minus_sign: | N/A | | `ProvisionReassigned` | [*shared.TaskAuditPolicyProvisionReassigned](../../../pkg/models/shared/taskauditpolicyprovisionreassigned.md) | :heavy_minus_sign: | N/A | +| `ProvisionWaitingForEntitlementMerge` | [*shared.TaskAuditProvisionWaitingForEntitlementMerge](../../../pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.md) | :heavy_minus_sign: | N/A | | `ReassignedToDelegate` | [*shared.TaskAuditReassignedToDelegate](../../../pkg/models/shared/taskauditreassignedtodelegate.md) | :heavy_minus_sign: | N/A | | `ReassignmentFallbackToAdmin` | [*shared.TaskAuditReassignmentFallbackToAdmin](../../../pkg/models/shared/taskauditreassignmentfallbacktoadmin.md) | :heavy_minus_sign: | N/A | | `ReassignmentListError` | [*shared.TaskAuditReassignmentListError](../../../pkg/models/shared/taskauditreassignmentlisterror.md) | :heavy_minus_sign: | N/A | diff --git a/docs/pkg/models/shared/taskauditwebhooksuccess.md b/docs/pkg/models/shared/taskauditwebhooksuccess.md index 9a6d1da0e..fc5611def 100644 --- a/docs/pkg/models/shared/taskauditwebhooksuccess.md +++ b/docs/pkg/models/shared/taskauditwebhooksuccess.md @@ -5,9 +5,10 @@ The TaskAuditWebhookSuccess message. ## Fields -| Field | Type | Required | Description | -| ---------------------------- | ---------------------------- | ---------------------------- | ---------------------------- | -| `WebhookID` | `*string` | :heavy_minus_sign: | The webhookId field. | -| `WebhookInstanceID` | `*string` | :heavy_minus_sign: | The webhookInstanceId field. | -| `WebhookName` | `*string` | :heavy_minus_sign: | The webhookName field. | -| `WebhookURL` | `*string` | :heavy_minus_sign: | The webhookUrl field. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------- | +| `Comment` | `*string` | :heavy_minus_sign: | Optional comment supplied by the provisioning callback. | +| `WebhookID` | `*string` | :heavy_minus_sign: | The webhookId field. | +| `WebhookInstanceID` | `*string` | :heavy_minus_sign: | The webhookInstanceId field. | +| `WebhookName` | `*string` | :heavy_minus_sign: | The webhookName field. | +| `WebhookURL` | `*string` | :heavy_minus_sign: | The webhookUrl field. | \ No newline at end of file diff --git a/docs/pkg/models/shared/tasksearchrequest.md b/docs/pkg/models/shared/tasksearchrequest.md index 1f19e9d91..0b232262e 100644 --- a/docs/pkg/models/shared/tasksearchrequest.md +++ b/docs/pkg/models/shared/tasksearchrequest.md @@ -9,6 +9,7 @@ Search for tasks based on a plethora filters. | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `AccessReviewIds` | []`string` | :heavy_minus_sign: | Search tasks that belong to any of the access reviews included in this list. | | `AccountOwnerIds` | []`string` | :heavy_minus_sign: | Search tasks that have any of these account owners. | +| `AccountStatuses` | [][shared.AccountStatuses](../../../pkg/models/shared/accountstatuses.md) | :heavy_minus_sign: | Search tasks by the account status of the app user subject. | | `AccountTypes` | [][shared.TaskSearchRequestAccountTypes](../../../pkg/models/shared/tasksearchrequestaccounttypes.md) | :heavy_minus_sign: | The accountTypes field. | | `ActorID` | `*string` | :heavy_minus_sign: | Search tasks that have this actor ID. | | `AppEntitlementIds` | []`string` | :heavy_minus_sign: | Search tasks that have any of these app entitlement IDs. | diff --git a/docs/pkg/models/shared/threshold.md b/docs/pkg/models/shared/threshold.md new file mode 100644 index 000000000..df7c79e4d --- /dev/null +++ b/docs/pkg/models/shared/threshold.md @@ -0,0 +1,27 @@ +# Threshold + +Deny (or flag) when the judge scores at or above this level. Unspecified = + HIGH. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.ThresholdPromptInjectionThresholdUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.Threshold("custom_value") +``` + + +## Values + +| Name | Value | +| ---------------------------------------------- | ---------------------------------------------- | +| `ThresholdPromptInjectionThresholdUnspecified` | PROMPT_INJECTION_THRESHOLD_UNSPECIFIED | +| `ThresholdPromptInjectionThresholdLow` | PROMPT_INJECTION_THRESHOLD_LOW | +| `ThresholdPromptInjectionThresholdMedium` | PROMPT_INJECTION_THRESHOLD_MEDIUM | +| `ThresholdPromptInjectionThresholdHigh` | PROMPT_INJECTION_THRESHOLD_HIGH | \ No newline at end of file diff --git a/docs/pkg/models/shared/tieroverride.md b/docs/pkg/models/shared/tieroverride.md new file mode 100644 index 000000000..9c9755def --- /dev/null +++ b/docs/pkg/models/shared/tieroverride.md @@ -0,0 +1,25 @@ +# TierOverride + +Author tier override; may only tighten the derived tier. + +## Example Usage + +```go +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" +) + +value := shared.TierOverrideFindingDispatchTierUnspecified + +// Open enum: custom values can be created with a direct type cast +custom := shared.TierOverride("custom_value") +``` + + +## Values + +| Name | Value | +| ------------------------------------------------- | ------------------------------------------------- | +| `TierOverrideFindingDispatchTierUnspecified` | FINDING_DISPATCH_TIER_UNSPECIFIED | +| `TierOverrideFindingDispatchTierAuto` | FINDING_DISPATCH_TIER_AUTO | +| `TierOverrideFindingDispatchTierRequiresApproval` | FINDING_DISPATCH_TIER_REQUIRES_APPROVAL | \ No newline at end of file diff --git a/docs/pkg/models/shared/triggerautomationdispatcher.md b/docs/pkg/models/shared/triggerautomationdispatcher.md new file mode 100644 index 000000000..c7f794c3f --- /dev/null +++ b/docs/pkg/models/shared/triggerautomationdispatcher.md @@ -0,0 +1,11 @@ +# TriggerAutomationDispatcher + +TriggerAutomationDispatcher runs a C1 automation by id (the "Run now" path). + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | +| `AutomationID` | `*string` | :heavy_minus_sign: | ID of the C1 automation/workflow to run. | +| `InputMapping` | map[string]`string` | :heavy_minus_sign: | Inputs passed to the automation, keyed by input name (v0: verbatim values;
    CEL evaluation is a later phase). | \ No newline at end of file diff --git a/docs/pkg/models/shared/unusedsecretevidence.md b/docs/pkg/models/shared/unusedsecretevidence.md new file mode 100644 index 000000000..8e9594552 --- /dev/null +++ b/docs/pkg/models/shared/unusedsecretevidence.md @@ -0,0 +1,10 @@ +# UnusedSecretEvidence + +The UnusedSecretEvidence message. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | +| `LastUsedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/pkg/models/shared/unusedsecrettype.md b/docs/pkg/models/shared/unusedsecrettype.md new file mode 100644 index 000000000..61416d94f --- /dev/null +++ b/docs/pkg/models/shared/unusedsecrettype.md @@ -0,0 +1,10 @@ +# UnusedSecretType + +UnusedSecretType: a secret-trait AppResource has not been used in over the + detector's staleness threshold. Target: AppResourceTarget. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/pkg/models/shared/updatefindingsettingsrequest.md b/docs/pkg/models/shared/updatefindingsettingsrequest.md new file mode 100644 index 000000000..fb75e2529 --- /dev/null +++ b/docs/pkg/models/shared/updatefindingsettingsrequest.md @@ -0,0 +1,10 @@ +# UpdateFindingSettingsRequest + +The UpdateFindingSettingsRequest message. + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Settings` | [][shared.FindingSettingsEntry](../../../pkg/models/shared/findingsettingsentry.md) | :heavy_minus_sign: | Applied as one atomic write, so an admin changing several types either
    lands all of them or none. Empty is valid: a never-configured tenant's
    "accept the defaults" save has nothing to diff, and the empty write still
    creates the settings row. | \ No newline at end of file diff --git a/docs/pkg/models/shared/updatefindingsettingsresponse.md b/docs/pkg/models/shared/updatefindingsettingsresponse.md new file mode 100644 index 000000000..c62317e48 --- /dev/null +++ b/docs/pkg/models/shared/updatefindingsettingsresponse.md @@ -0,0 +1,10 @@ +# UpdateFindingSettingsResponse + +The UpdateFindingSettingsResponse message. + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | +| `List` | [][shared.FindingTypeSetting](../../../pkg/models/shared/findingtypesetting.md) | :heavy_minus_sign: | The full catalog after the write, in the same shape ListFindingSettings
    returns. | \ No newline at end of file diff --git a/docs/pkg/models/shared/waitingfordeviceplacement.md b/docs/pkg/models/shared/waitingfordeviceplacement.md new file mode 100644 index 000000000..bcf2cbad6 --- /dev/null +++ b/docs/pkg/models/shared/waitingfordeviceplacement.md @@ -0,0 +1,11 @@ +# WaitingForDevicePlacement + +Describes a provision step that is paused until the recipient joins the vault's MLS group. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `RecipientUserID` | `*string` | :heavy_minus_sign: | The ID of the user being placed. | +| `VaultBoundaryID` | `*string` | :heavy_minus_sign: | The ID of the vault boundary the recipient is being placed in. | \ No newline at end of file diff --git a/docs/pkg/models/shared/waitingforentitlementmerge.md b/docs/pkg/models/shared/waitingforentitlementmerge.md new file mode 100644 index 000000000..7a5e2aaf5 --- /dev/null +++ b/docs/pkg/models/shared/waitingforentitlementmerge.md @@ -0,0 +1,11 @@ +# WaitingForEntitlementMerge + +Describes a provision step that is paused until the target entitlement, created ahead of connector sync with a Baton match ID, is merged with its connector-synced counterpart. + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------- | ----------------------------------------------------- | ----------------------------------------------------- | ----------------------------------------------------- | +| `AppEntitlementID` | `*string` | :heavy_minus_sign: | The ID of the entitlement being waited on. | +| `AppID` | `*string` | :heavy_minus_sign: | The ID of the app the awaited entitlement belongs to. | \ No newline at end of file diff --git a/docs/pkg/models/shared/webhookdispatcher.md b/docs/pkg/models/shared/webhookdispatcher.md new file mode 100644 index 000000000..896f31a85 --- /dev/null +++ b/docs/pkg/models/shared/webhookdispatcher.md @@ -0,0 +1,11 @@ +# WebhookDispatcher + +WebhookDispatcher POSTs to a registered webhook (webhooks v3). + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `PayloadTemplate` | `*string` | :heavy_minus_sign: | Optional payload template; empty uses the default finding payload. | +| `WebhookID` | `*string` | :heavy_minus_sign: | ID of a registered webhook to POST to. | \ No newline at end of file diff --git a/docs/pkg/models/shared/xaaclientaudiencemapping.md b/docs/pkg/models/shared/xaaclientaudiencemapping.md index c1ab33624..e4c6d2db6 100644 --- a/docs/pkg/models/shared/xaaclientaudiencemapping.md +++ b/docs/pkg/models/shared/xaaclientaudiencemapping.md @@ -6,12 +6,12 @@ XAAClientAudienceMapping maps a client to its identifier at one resource ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `AudienceClientID` | `*string` | :heavy_minus_sign: | The client's identifier at the resource authorization server. Stamped
    verbatim into the grant's client_id claim. | -| `ClientKey` | `*string` | :heavy_minus_sign: | Stable client registration key. One of: a DCR software_id form
    (dcr://), a CIMD client_id URL, a native C1 form
    (c1://), or a raw client_id. | -| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `Disabled` | `*bool` | :heavy_minus_sign: | When true, exchange requests from this client for this resource server are
    rejected without removing the mapping (a kill switch). | -| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | -| `XaaResourceServerID` | `*string` | :heavy_minus_sign: | The resource server this mapping applies to. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `AudienceClientID` | `*string` | :heavy_minus_sign: | The client's identifier at the resource authorization server. Stamped
    verbatim into the grant's client_id claim. | +| `ClientKey` | `*string` | :heavy_minus_sign: | Stable client registration key. One of: a DCR client_id form
    (dcr://), a CIMD client_id URL, a native C1 form
    (c1://), or a raw client_id. | +| `CreatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `DeletedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `Disabled` | `*bool` | :heavy_minus_sign: | When true, exchange requests from this client for this resource server are
    rejected without removing the mapping (a kill switch). | +| `UpdatedAt` | [*time.Time](https://pkg.go.dev/time#Time) | :heavy_minus_sign: | N/A | +| `XaaResourceServerID` | `*string` | :heavy_minus_sign: | The resource server this mapping applies to. | \ No newline at end of file diff --git a/docs/sdks/a2ui/README.md b/docs/sdks/a2ui/README.md index 9b683f6ab..4b0ce2218 100644 --- a/docs/sdks/a2ui/README.md +++ b/docs/sdks/a2ui/README.md @@ -5,6 +5,7 @@ ### Available Operations * [CreateSurfaceFeedback](#createsurfacefeedback) - Create Surface Feedback +* [GetSurfaceProvenance](#getsurfaceprovenance) - Get Surface Provenance * [ListSurfaceFeedback](#listsurfacefeedback) - List Surface Feedback * [ListSurfaces](#listsurfaces) - List Surfaces * [SubmitAction](#submitaction) - Submit Action @@ -67,6 +68,67 @@ func main() { | ------------------ | ------------------ | ------------------ | | sdkerrors.SDKError | 4XX, 5XX | \*/\* | +## GetSurfaceProvenance + +GetSurfaceProvenance returns, in plain terms, what the surface's report + was built from: every record its program touched, in the order it touched + them. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.A2UI.GetSurfaceProvenance(ctx, operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest{ + ConversationID: "", + SurfaceID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.A2UIServiceGetSurfaceProvenanceResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest](../../pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenancerequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse](../../pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + ## ListSurfaceFeedback ListSurfaceFeedback lists feedback for a surface. diff --git a/docs/sdks/accessreviewactions/README.md b/docs/sdks/accessreviewactions/README.md new file mode 100644 index 000000000..44e29a613 --- /dev/null +++ b/docs/sdks/accessreviewactions/README.md @@ -0,0 +1,68 @@ +# AccessReviewActions + +## Overview + +### Available Operations + +* [GenerateReport](#generatereport) - Generate Report + +## GenerateReport + +Generate a report of the campaign's reviews and decisions. The format + defaults to JSON (also available: CSV, XLSX). Works on in-flight (OPEN) + and closed campaigns. Asynchronous — the report record is created + immediately; the file is materialized in the background. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AccessReviewActions.GenerateReport(ctx, operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest{ + AccessReviewID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AccessReviewActionsServiceGenerateReportResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest](../../pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse](../../pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/accessreviewreport/README.md b/docs/sdks/accessreviewreport/README.md new file mode 100644 index 000000000..f83162ec4 --- /dev/null +++ b/docs/sdks/accessreviewreport/README.md @@ -0,0 +1,66 @@ +# AccessReviewReport + +## Overview + +### Available Operations + +* [List](#list) - List + +## List + +List the generated reports for an access review campaign, each with a + time-limited download_url and its output format. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AccessReviewReport.List(ctx, operations.C1APIAccessreviewV1AccessReviewReportServiceListRequest{ + AccessReviewID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AccessReviewReportServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAccessreviewV1AccessReviewReportServiceListRequest](../../pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAccessreviewV1AccessReviewReportServiceListResponse](../../pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/aigovernancesettings/README.md b/docs/sdks/aigovernancesettings/README.md index 1bc3a7c38..dea8c8c67 100644 --- a/docs/sdks/aigovernancesettings/README.md +++ b/docs/sdks/aigovernancesettings/README.md @@ -15,7 +15,8 @@ Get the tenant's AI governance settings — the controls behind the admin /admin/settings/ai-governance page. Returns the full AIGovernanceSettings: allowed MCP client types, default client lifecycle, require_tool_approval, default tool classification, audit verbosity, auto-discovery toggle + - interval, prefer_code_mode_over_direct_tools, and surface_requestable_tools. + interval, prefer_code_mode_over_direct_tools, surface_requestable_tools, + and untrusted_judge_disable. ### Example Usage @@ -184,7 +185,8 @@ Update the tenant's AI governance settings. Requires update_mask listing which fields to apply (e.g. require_tool_approval, default_tool_classification, audit_verbosity, auto_discovery_enabled, discovery_interval, prefer_code_mode_over_direct_tools, - surface_requestable_tools, allowed_client_types, default_client_lifecycle). + surface_requestable_tools, untrusted_judge_disable, allowed_client_types, + default_client_lifecycle). Only masked fields change. Returns the updated settings. ### Example Usage diff --git a/docs/sdks/appcap/README.md b/docs/sdks/appcap/README.md new file mode 100644 index 000000000..398e2874e --- /dev/null +++ b/docs/sdks/appcap/README.md @@ -0,0 +1,424 @@ +# AppCap + +## Overview + +### Available Operations + +* [Delete](#delete) - Delete +* [Get](#get) - Get +* [List](#list) - List +* [ListHistory](#listhistory) - List History +* [SetLimit](#setlimit) - Set Limit +* [Suspend](#suspend) - Suspend +* [Unsuspend](#unsuspend) - Unsuspend + +## Delete + +Delete the cap entirely. The app is no longer bounded tenant-wide. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.Delete(ctx, operations.C1APIFundsV1AppCapServiceDeleteRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceDeleteRequest](../../pkg/models/operations/c1apifundsv1appcapservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceDeleteResponse](../../pkg/models/operations/c1apifundsv1appcapservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns the tenant's ceiling for one app, together with any suspension + acting as that app's kill switch. An app with no cap is not found, meaning + nothing bounds it beyond the fund the spender already has. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.Get(ctx, operations.C1APIFundsV1AppCapServiceGetRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceGetRequest](../../pkg/models/operations/c1apifundsv1appcapservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceGetResponse](../../pkg/models/operations/c1apifundsv1appcapservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List every capped app in the tenant. Cardinality is the tenant's installed + App count, so this is one runtime-plane query. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.List(ctx, operations.C1APIFundsV1AppCapServiceListRequest{}) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceListRequest](../../pkg/models/operations/c1apifundsv1appcapservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceListResponse](../../pkg/models/operations/c1apifundsv1appcapservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +List the change history for one app's cap, newest first. Admin-tier per the + object-history convention. A cap cleared down to nothing is deleted, and its + history is where the kill switch that preceded the delete is still readable. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.ListHistory(ctx, operations.C1APIFundsV1AppCapServiceListHistoryRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceListHistoryRequest](../../pkg/models/operations/c1apifundsv1appcapservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceListHistoryResponse](../../pkg/models/operations/c1apifundsv1appcapservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## SetLimit + +Set the app's tenant-wide ceiling, creating the cap if absent. Leaves any + suspension in place. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.SetLimit(ctx, operations.C1APIFundsV1AppCapServiceSetLimitRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceSetLimitResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceSetLimitRequest](../../pkg/models/operations/c1apifundsv1appcapservicesetlimitrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceSetLimitResponse](../../pkg/models/operations/c1apifundsv1appcapservicesetlimitresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Suspend + +Kill the app tenant-wide. The cap amount underneath is preserved and + restored by Unsuspend. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.Suspend(ctx, operations.C1APIFundsV1AppCapServiceSuspendRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceSuspendResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceSuspendRequest](../../pkg/models/operations/c1apifundsv1appcapservicesuspendrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceSuspendResponse](../../pkg/models/operations/c1apifundsv1appcapservicesuspendresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Unsuspend + +Bring the app back, restoring the cap it froze. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppCap.Unsuspend(ctx, operations.C1APIFundsV1AppCapServiceUnsuspendRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.AppCapServiceUnsuspendResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1AppCapServiceUnsuspendRequest](../../pkg/models/operations/c1apifundsv1appcapserviceunsuspendrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1AppCapServiceUnsuspendResponse](../../pkg/models/operations/c1apifundsv1appcapserviceunsuspendresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/appentitlementroutingrule/README.md b/docs/sdks/appentitlementroutingrule/README.md index 72557cc6e..d422468cc 100644 --- a/docs/sdks/appentitlementroutingrule/README.md +++ b/docs/sdks/appentitlementroutingrule/README.md @@ -13,7 +13,10 @@ ## CreateAppEntitlementRoutingRule -Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.CreateAppEntitlementRoutingRule method. +CreateAppEntitlementRoutingRule creates an entitlement configuration rule + for an application. Rules are evaluated in priority order and the first + rule whose condition matches supplies the entitlement's request settings. + An app can have at most 5 rules. ### Example Usage @@ -71,7 +74,8 @@ func main() { ## DeleteAppEntitlementRoutingRule -Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.DeleteAppEntitlementRoutingRule method. +DeleteAppEntitlementRoutingRule deletes an entitlement configuration rule + by ID. ### Example Usage @@ -130,7 +134,8 @@ func main() { ## GetAppEntitlementRoutingRule -Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.GetAppEntitlementRoutingRule method. +GetAppEntitlementRoutingRule returns a single entitlement configuration + rule by ID. ### Example Usage @@ -189,7 +194,8 @@ func main() { ## ListAppEntitlementRoutingRules -Invokes the c1.api.app.v1.AppEntitlementRoutingRuleService.ListAppEntitlementRoutingRules method. +ListAppEntitlementRoutingRules returns an application's entitlement + configuration rules in evaluation order, by priority then by ID. ### Example Usage diff --git a/docs/sdks/appentitlements/README.md b/docs/sdks/appentitlements/README.md index 1258e44b5..ac1ea04b7 100644 --- a/docs/sdks/appentitlements/README.md +++ b/docs/sdks/appentitlements/README.md @@ -84,6 +84,7 @@ func main() { ## AddManuallyManagedMembers Add users as manually managed members of an app entitlement. These memberships are tracked directly by ConductorOne rather than synced from the app. + Adding members to an access profile's enrollment entitlement requires the JML feature; without it the request fails with a failed-precondition error. ### Example Usage @@ -495,7 +496,10 @@ func main() { ## List -List app entitlements associated with an app. +List app entitlements associated with an app. Query parameters are + accepted in snake_case (page_size, page_token, app_user_id) and, as a + compatibility shim, their camelCase equivalents (pageSize, pageToken, + appUserId). ### Example Usage @@ -851,7 +855,13 @@ func main() { ## RemoveEntitlementMembership -Remove a user from a ConductorOne-managed entitlement (catalog, group, or profile type). For access profiles, this creates a revoke task to deprovision access. +Remove a user from a manually managed entitlement. For ConductorOne + catalogs, groups, and profile types, the existing resource-specific + removal behavior applies. When the SSO provider feature is enabled, an SSO + application's sign-in entitlement removes only direct manual access and + preserves independent requested, connector, and group-derived access. + Removing a member from an access profile requires the JML feature; without + it the request fails with a failed-precondition error. ### Example Usage diff --git a/docs/sdks/appentitlementsearch/README.md b/docs/sdks/appentitlementsearch/README.md index 0c18105a8..7b376fb17 100644 --- a/docs/sdks/appentitlementsearch/README.md +++ b/docs/sdks/appentitlementsearch/README.md @@ -10,6 +10,7 @@ * [SearchAppEntitlementsWithExpired](#searchappentitlementswithexpired) - Search App Entitlements With Expired * [SearchGrants](#searchgrants) - Search Grants * [SearchGraph](#searchgraph) - Search Graph +* [SearchReachableResourcesForUser](#searchreachableresourcesforuser) - Search Reachable Resources For User ## CountGrantsForUserByApp @@ -366,6 +367,65 @@ func main() { ### Errors +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## SearchReachableResourcesForUser + +SearchReachableResourcesForUser returns the distinct app resources a user + can reach through any of their grants, deduplicated across entitlements + (a resource reachable via more than one grant appears once). Powers the + Resources lane of the access graph's list view: supports free-text search + over resource display name and narrowing to specific applications. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppEntitlementSearch.SearchReachableResourcesForUser(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.AppEntitlementSearchServiceSearchReachableResourcesForUserRequest](../../pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse](../../pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse.md), error** + +### Errors + | Error Type | Status Code | Content Type | | ------------------ | ------------------ | ------------------ | | sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/appmanagedstate/README.md b/docs/sdks/appmanagedstate/README.md new file mode 100644 index 000000000..38de6023f --- /dev/null +++ b/docs/sdks/appmanagedstate/README.md @@ -0,0 +1,190 @@ +# AppManagedState + +## Overview + +### Available Operations + +* [Get](#get) - Get +* [List](#list) - List +* [Promote](#promote) - Promote + +## Get + +Get the managed state of a discovered application. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppManagedState.Get(ctx, operations.C1APIAppV1AppManagedStateServiceGetRequest{ + AppID: "", + ResourceID: "", + ResourceTypeID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.GetAppManagedStateBindingResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAppV1AppManagedStateServiceGetRequest](../../pkg/models/operations/c1apiappv1appmanagedstateservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAppV1AppManagedStateServiceGetResponse](../../pkg/models/operations/c1apiappv1appmanagedstateservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List the managed states of applications discovered by a connector. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppManagedState.List(ctx, operations.C1APIAppV1AppManagedStateServiceListRequest{ + AppID: "", + ResourceTypeID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ListAppManagedStateBindingsResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAppV1AppManagedStateServiceListRequest](../../pkg/models/operations/c1apiappv1appmanagedstateservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAppV1AppManagedStateServiceListResponse](../../pkg/models/operations/c1apiappv1appmanagedstateservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Promote + +Promote an unmanaged application into a managed application. + Returns AlreadyExists when the application is already managed. The new application inherits source owners when user_ids is omitted. + Concurrent promotion requests are not supported. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.AppManagedState.Promote(ctx, operations.C1APIAppV1AppManagedStateServicePromoteRequest{ + AppID: "", + ResourceID: "", + ResourceTypeID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.GetAppManagedStateBindingResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAppV1AppManagedStateServicePromoteRequest](../../pkg/models/operations/c1apiappv1appmanagedstateservicepromoterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAppV1AppManagedStateServicePromoteResponse](../../pkg/models/operations/c1apiappv1appmanagedstateservicepromoteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/automation/README.md b/docs/sdks/automation/README.md index e05482b96..84ac3b6eb 100644 --- a/docs/sdks/automation/README.md +++ b/docs/sdks/automation/README.md @@ -77,7 +77,7 @@ func main() { Create a new automation with the specified steps, triggers, and configuration. See get_authoring_guide for the AutomationStep contract - (step kinds, evaluate_expressions shape, CEL identifier scope). + (step kinds and their required fields, CEL identifier scope). At create time, draft_automation_steps and draft_triggers default to their published counterparts when omitted — callers writing a single diff --git a/docs/sdks/connector/README.md b/docs/sdks/connector/README.md index 9a14e52b8..91c5d37ad 100644 --- a/docs/sdks/connector/README.md +++ b/docs/sdks/connector/README.md @@ -259,7 +259,9 @@ func main() { ## ForceSync -Trigger an immediate sync for a connector. The sync is queued and may not start instantly. +Trigger an immediate sync for a connector. The sync is queued and may not start + instantly. Poll the connector's sync_status (or GetConnector) for progress; an empty + success response means the sync was accepted onto the queue, not that it has finished. ### Example Usage diff --git a/docs/sdks/contacts/README.md b/docs/sdks/contacts/README.md index a24c4ee74..cdcf39e4d 100644 --- a/docs/sdks/contacts/README.md +++ b/docs/sdks/contacts/README.md @@ -9,7 +9,8 @@ ## GetContacts -Invokes the c1.api.settings.v1.ContactsService.GetContacts method. +GetContacts returns the organization's security, billing, and operations + contact email addresses. ### Example Usage @@ -63,7 +64,10 @@ func main() { ## UpdateContacts -Invokes the c1.api.settings.v1.ContactsService.UpdateContacts method. +UpdateContacts updates the organization's security, billing, and + operations contact email addresses. If update_mask is set, only the + selected fields are changed; otherwise all contact fields are replaced + with the values in the request. ### Example Usage diff --git a/docs/sdks/findingsettings/README.md b/docs/sdks/findingsettings/README.md new file mode 100644 index 000000000..e5733063a --- /dev/null +++ b/docs/sdks/findingsettings/README.md @@ -0,0 +1,119 @@ +# FindingSettings + +## Overview + +### Available Operations + +* [ListFindingSettings](#listfindingsettings) - List Finding Settings +* [UpdateFindingSettings](#updatefindingsettings) - Update Finding Settings + +## ListFindingSettings + +List every configurable finding type and whether detection is enabled. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FindingSettings.ListFindingSettings(ctx) + if err != nil { + log.Fatal(err) + } + if res.ListFindingSettingsResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse](../../pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettingsresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## UpdateFindingSettings + +Enable or disable detection for one or more finding types in a single + write. Enabling a type whose detector is a scheduled job also queues an + immediate run. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FindingSettings.UpdateFindingSettings(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.UpdateFindingSettingsResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.UpdateFindingSettingsRequest](../../pkg/models/shared/updatefindingsettingsrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse](../../pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/functions/README.md b/docs/sdks/functions/README.md index 2c08037b3..53fefe04e 100644 --- a/docs/sdks/functions/README.md +++ b/docs/sdks/functions/README.md @@ -779,9 +779,15 @@ func main() { ## UpdateFunction -Update an existing function's metadata. Also the publish path: set - function.published_commit_id and include "published_commit_id" in - update_mask to make a commit the default runnable version. +Update an existing function's metadata, code, or both. Also the publish + path: set function.published_commit_id and include "published_commit_id" + in update_mask to make a commit the default runnable version. To push a + new code commit, set content (and optionally commit_message); this is + independent of update_mask, since commits are versioned separately from + function metadata. A single request cannot publish the commit it just + created, since published_commit_id is validated against existing commits + before content is committed: publishing new code takes two calls, push + then publish with the returned commit.id. ### Example Usage diff --git a/docs/sdks/fundassignment/README.md b/docs/sdks/fundassignment/README.md new file mode 100644 index 000000000..5af07b55d --- /dev/null +++ b/docs/sdks/fundassignment/README.md @@ -0,0 +1,543 @@ +# FundAssignment + +## Overview + +### Available Operations + +* [ClearExtension](#clearextension) - Clear Extension +* [Delete](#delete) - Delete +* [Get](#get) - Get +* [GrantExtension](#grantextension) - Grant Extension +* [ListHistory](#listhistory) - List History +* [Search](#search) - Search +* [SetLimit](#setlimit) - Set Limit +* [Suspend](#suspend) - Suspend +* [Unsuspend](#unsuspend) - Unsuspend + +## ClearExtension + +Revoke the extension early. The base limit underneath is untouched. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.ClearExtension(ctx, operations.C1APIFundsV1FundAssignmentServiceClearExtensionRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceClearExtensionResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceClearExtensionRequest](../../pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceClearExtensionResponse](../../pkg/models/operations/c1apifundsv1fundassignmentserviceclearextensionresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Delete + +Delete the whole assignment. The subject falls back to the rules and the + tenant default. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.Delete(ctx, operations.C1APIFundsV1FundAssignmentServiceDeleteRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceDeleteRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceDeleteResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns one subject's exception: their own limit, any extension + running on top of it, and any suspension. A subject with no exception is + not found rather than reported at the tenant default, because no row is + what "this subject is governed by the layers above" looks like. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.Get(ctx, operations.C1APIFundsV1FundAssignmentServiceGetRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceGetRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceGetResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## GrantExtension + +Grant a temporary total until expires_at. Never changes the period, and + never expresses a refusal — a temporary refusal is a suspension. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.GrantExtension(ctx, operations.C1APIFundsV1FundAssignmentServiceGrantExtensionRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceGrantExtensionResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceGrantExtensionRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceGrantExtensionResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicegrantextensionresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +List the change history for one subject's assignment, newest first. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.ListHistory(ctx, operations.C1APIFundsV1FundAssignmentServiceListHistoryRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceListHistoryRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceListHistoryResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Search + +Search the tenant's assignments. Reads the Postgres mirror: the runtime + row is keyed on (tenant, user), so there is no cross-subject query on the + runtime plane at all. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.Search(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceSearchResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundAssignmentServiceSearchRequest](../../pkg/models/shared/fundassignmentservicesearchrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceSearchResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicesearchresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## SetLimit + +Set the subject's base limit, creating the assignment if absent. Leaves any + extension and any suspension in place. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.SetLimit(ctx, operations.C1APIFundsV1FundAssignmentServiceSetLimitRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceSetLimitResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceSetLimitRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceSetLimitResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicesetlimitresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Suspend + +Freeze the subject's fund. The limit and any extension underneath are + preserved and restored by Unsuspend. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.Suspend(ctx, operations.C1APIFundsV1FundAssignmentServiceSuspendRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceSuspendResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceSuspendRequest](../../pkg/models/operations/c1apifundsv1fundassignmentservicesuspendrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceSuspendResponse](../../pkg/models/operations/c1apifundsv1fundassignmentservicesuspendresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Unsuspend + +Lift the suspension, restoring the numbers it froze. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundAssignment.Unsuspend(ctx, operations.C1APIFundsV1FundAssignmentServiceUnsuspendRequest{ + UserID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundAssignmentServiceUnsuspendResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundAssignmentServiceUnsuspendRequest](../../pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundAssignmentServiceUnsuspendResponse](../../pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspendresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/fundpolicy/README.md b/docs/sdks/fundpolicy/README.md new file mode 100644 index 000000000..f57c9b653 --- /dev/null +++ b/docs/sdks/fundpolicy/README.md @@ -0,0 +1,466 @@ +# FundPolicy + +## Overview + +### Available Operations + +* [Create](#create) - Create +* [Delete](#delete) - Delete +* [FreezeTenant](#freezetenant) - Freeze Tenant +* [Get](#get) - Get +* [ListHistory](#listhistory) - List History +* [SetOrgCeiling](#setorgceiling) - Set Org Ceiling +* [UnfreezeTenant](#unfreezetenant) - Unfreeze Tenant +* [Update](#update) - Update + +## Create + +Create the tenant's fund policy, opting the tenant in to spend governance. + default_limit is required: a tenant states its posture explicitly, and + there is no implicit default anywhere in the write path. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.Create(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceCreateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceCreateRequest](../../pkg/models/shared/fundpolicyservicecreaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceCreateResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicecreateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Delete + +Delete the tenant's fund policy, opting the tenant back out of spend + governance. Rules, assignments and app caps are left in place and go + dormant; a later Create restores every one of them. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.Delete(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceDeleteRequest](../../pkg/models/shared/fundpolicyservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceDeleteResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## FreezeTenant + +Freeze the whole tenant. The ceiling amount underneath is preserved and + restored by Unfreeze. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.FreezeTenant(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceFreezeTenantResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceFreezeTenantRequest](../../pkg/models/shared/fundpolicyservicefreezetenantrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceFreezeTenantResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenantresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get the tenant's fund policy. An absent policy in the response means the + tenant has not opted in to spend governance, which is an ordinary state + rather than an error. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.Get(ctx) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceGetResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +List the change history for the fund policy, newest first. Admin-tier per + the object-history convention. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.ListHistory(ctx, operations.C1APIFundsV1FundPolicyServiceListHistoryRequest{}) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundPolicyServiceListHistoryRequest](../../pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceListHistoryResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## SetOrgCeiling + +Set the org-wide ceiling: the bound on the tenant's total regardless of + what any principal was granted. Amount arm only. Clears the ceiling when + limit is absent. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.SetOrgCeiling(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceSetOrgCeilingResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceSetOrgCeilingRequest](../../pkg/models/shared/fundpolicyservicesetorgceilingrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse](../../pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceilingresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## UnfreezeTenant + +Lift the tenant freeze, restoring the ceiling it froze. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.UnfreezeTenant(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceUnfreezeTenantResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceUnfreezeTenantRequest](../../pkg/models/shared/fundpolicyserviceunfreezetenantrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse](../../pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenantresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update the period or the default limit. currency_code is immutable after + Create and update_mask rejects it: an amount denominated in a currency the + policy no longer names faults the acquire path rather than denying it. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundPolicy.Update(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundPolicyServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundPolicyServiceUpdateRequest](../../pkg/models/shared/fundpolicyserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundPolicyServiceUpdateResponse](../../pkg/models/operations/c1apifundsv1fundpolicyserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/fundrule/README.md b/docs/sdks/fundrule/README.md new file mode 100644 index 000000000..c7861ab3d --- /dev/null +++ b/docs/sdks/fundrule/README.md @@ -0,0 +1,423 @@ +# FundRule + +## Overview + +### Available Operations + +* [Create](#create) - Create +* [Delete](#delete) - Delete +* [Get](#get) - Get +* [List](#list) - List +* [ListHistory](#listhistory) - List History +* [Search](#search) - Search +* [Update](#update) - Update + +## Create + +Create funds a group. The group is an AppEntitlement, so membership + resolves through that entitlement's bindings on every acquire rather than + being captured here. Creating the tenant's first rule is what turns group + resolution on for that tenant. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.Create(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceCreateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundRuleServiceCreateRequest](../../pkg/models/shared/fundruleservicecreaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceCreateResponse](../../pkg/models/operations/c1apifundsv1fundruleservicecreateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Delete + +Delete withdraws a group grant. The cohort keeps whatever the tenant + default and any other rule matching them still allow, so this narrows their + fund rather than necessarily cutting it off. The rule's history survives. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.Delete(ctx, operations.C1APIFundsV1FundRuleServiceDeleteRequest{ + RuleID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundRuleServiceDeleteRequest](../../pkg/models/operations/c1apifundsv1fundruleservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceDeleteResponse](../../pkg/models/operations/c1apifundsv1fundruleservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns one rule: the group it funds, the grant it carries, and the + label and reason an admin reads it by. A deleted rule is not found. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.Get(ctx, operations.C1APIFundsV1FundRuleServiceGetRequest{ + RuleID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundRuleServiceGetRequest](../../pkg/models/operations/c1apifundsv1fundruleservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceGetResponse](../../pkg/models/operations/c1apifundsv1fundruleservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List every rule in the tenant. Reads the runtime plane: rule cardinality + is the tenant's rule count, so this is the same one-partition read + resolution does. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.List(ctx, operations.C1APIFundsV1FundRuleServiceListRequest{}) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundRuleServiceListRequest](../../pkg/models/operations/c1apifundsv1fundruleservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceListResponse](../../pkg/models/operations/c1apifundsv1fundruleservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +List the change history for one rule, newest first. Admin-tier per the + object-history convention. A deleted rule keeps its history: the delete is + the last entry, and the one before it is the rule as it last stood. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.ListHistory(ctx, operations.C1APIFundsV1FundRuleServiceListHistoryRequest{ + RuleID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundRuleServiceListHistoryRequest](../../pkg/models/operations/c1apifundsv1fundruleservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceListHistoryResponse](../../pkg/models/operations/c1apifundsv1fundruleservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Search + +Search rules by display name. Reads the Postgres mirror. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.Search(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceSearchResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.FundRuleServiceSearchRequest](../../pkg/models/shared/fundruleservicesearchrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceSearchResponse](../../pkg/models/operations/c1apifundsv1fundruleservicesearchresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update replaces the group, grant, label or reason on one rule, whichever + the field mask names. The new grant governs the next acquire; spend already + accounted for against the old one is not revisited. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.FundRule.Update(ctx, operations.C1APIFundsV1FundRuleServiceUpdateRequest{ + RuleID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.FundRuleServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1FundRuleServiceUpdateRequest](../../pkg/models/operations/c1apifundsv1fundruleserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1FundRuleServiceUpdateResponse](../../pkg/models/operations/c1apifundsv1fundruleserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/gatewaykey/README.md b/docs/sdks/gatewaykey/README.md new file mode 100644 index 000000000..9d4030c01 --- /dev/null +++ b/docs/sdks/gatewaykey/README.md @@ -0,0 +1,179 @@ +# GatewayKey + +## Overview + +### Available Operations + +* [List](#list) - List +* [Mint](#mint) - Mint +* [Revoke](#revoke) - Revoke + +## List + +List returns the tenant's LLM gateway API keys. Only key metadata and a + key prefix are returned, never the full key. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.GatewayKey.List(ctx) + if err != nil { + log.Fatal(err) + } + if res.ListGatewayKeysResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1GatewayKeyServiceListResponse](../../pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Mint + +Mint creates a new LLM gateway API key. The key value is shown only in + this response and cannot be retrieved again; store it immediately. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.GatewayKey.Mint(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.MintGatewayKeyResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.MintGatewayKeyRequest](../../pkg/models/shared/mintgatewaykeyrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1GatewayKeyServiceMintResponse](../../pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemintresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Revoke + +Revoke revokes an LLM gateway API key by ID. The key immediately stops + authenticating gateway requests. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.GatewayKey.Revoke(ctx, operations.C1APILlmGatewayV1GatewayKeyServiceRevokeRequest{ + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.RevokeGatewayKeyResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APILlmGatewayV1GatewayKeyServiceRevokeRequest](../../pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokerequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1GatewayKeyServiceRevokeResponse](../../pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevokeresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/hooks/README.md b/docs/sdks/hooks/README.md index 4aaca2d6b..ebe19250b 100644 --- a/docs/sdks/hooks/README.md +++ b/docs/sdks/hooks/README.md @@ -12,7 +12,9 @@ ## Create -Invokes the c1.api.hooks.v1.HooksService.Create method. +Create creates a hook. The hook fires on the configured event, optionally + filtered by a CEL expression. Creating a Patch tool input hook requires the + preview feature to be enabled for the tenant. ### Example Usage @@ -67,7 +69,8 @@ func main() { ## Delete -Invokes the c1.api.hooks.v1.HooksService.Delete method. +Delete removes a hook by ID. A hook referenced by a guardrail rule cannot + be deleted until the reference is removed. ### Example Usage @@ -125,7 +128,7 @@ func main() { ## Get -Invokes the c1.api.hooks.v1.HooksService.Get method. +Get returns a hook by ID. ### Example Usage @@ -183,7 +186,7 @@ func main() { ## List -Invokes the c1.api.hooks.v1.HooksService.List method. +List returns all hooks for the tenant, paginated. ### Example Usage @@ -239,7 +242,9 @@ func main() { ## Update -Invokes the c1.api.hooks.v1.HooksService.Update method. +Update modifies a hook's display name, description, event, filter, priority, + or configuration. A hook referenced by a guardrail rule cannot stop being + managed by guardrails until the reference is removed. ### Example Usage diff --git a/docs/sdks/hookssearch/README.md b/docs/sdks/hookssearch/README.md index 040e2fc78..cdee7254a 100644 --- a/docs/sdks/hookssearch/README.md +++ b/docs/sdks/hookssearch/README.md @@ -8,7 +8,8 @@ ## Search -Invokes the c1.api.hooks.v1.HooksSearch.Search method. +Search returns hooks for the tenant, paginated. Setting query or refs + returns UNIMPLEMENTED; filtering is not yet supported. ### Example Usage diff --git a/docs/sdks/mcpaccessprofile/README.md b/docs/sdks/mcpaccessprofile/README.md index fdeefa9f4..f7411aef6 100644 --- a/docs/sdks/mcpaccessprofile/README.md +++ b/docs/sdks/mcpaccessprofile/README.md @@ -10,6 +10,7 @@ * [GetByAppEntitlementID](#getbyappentitlementid) - Get By App Entitlement Id * [List](#list) - List * [ListRequestableConnectors](#listrequestableconnectors) - List Requestable Connectors +* [SearchAccessProfiles](#searchaccessprofiles) - Search Access Profiles * [SearchRequestableConnectors](#searchrequestableconnectors) - Search Requestable Connectors * [Update](#update) - Update @@ -376,6 +377,65 @@ func main() { | ------------------ | ------------------ | ------------------ | | sdkerrors.SDKError | 4XX, 5XX | \*/\* | +## SearchAccessProfiles + +SearchAccessProfiles returns the tenant's MCP toolsets (access profiles) + across every (app_id, connector_id), filtered by a case-insensitive search + over display_name and paginated. Backs the agent-config multi-select that + binds toolsets to a ClawAgent. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPAccessProfile.SearchAccessProfiles(ctx, operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest{}) + if err != nil { + log.Fatal(err) + } + if res.MCPAccessProfileServiceSearchAccessProfilesResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest](../../pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse](../../pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + ## SearchRequestableConnectors SearchRequestableConnectors returns card-ready entries — one per MCP diff --git a/docs/sdks/mcpresource/README.md b/docs/sdks/mcpresource/README.md new file mode 100644 index 000000000..c90943856 --- /dev/null +++ b/docs/sdks/mcpresource/README.md @@ -0,0 +1,319 @@ +# MCPResource + +## Overview + +### Available Operations + +* [Get](#get) - Get +* [List](#list) - List +* [ListHistory](#listhistory) - List History +* [Search](#search) - Search +* [Update](#update) - Update + +## Get + +Get retrieves a single discovered MCP resource by app_id + connector_id + + id, including its approval state, kind, URI or URI template, and bound + app_entitlement_id. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPResource.Get(ctx, operations.C1APIAiGovernanceV1MCPResourceServiceGetRequest{ + AppID: "", + ConnectorID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MCPResourceServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPResourceServiceGetRequest](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPResourceServiceGetResponse](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List returns the MCP resources discovered for a single (app_id, + connector_id), paginated. To filter by kind or state, use Search. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPResource.List(ctx, operations.C1APIAiGovernanceV1MCPResourceServiceListRequest{ + AppID: "", + ConnectorID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MCPResourceServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPResourceServiceListRequest](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPResourceServiceListResponse](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +ListHistory returns the change history (newest first) for a single MCP + resource — each entry is a snapshot plus who/when metadata. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPResource.ListHistory(ctx, operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest{ + AppID: "", + ConnectorID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MCPResourceServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Search + +Search returns a connector's MCP resources filtered by kind, state, or + text query. Filter on MCP_RESOURCE_STATE_PENDING_REVIEW to find resources + awaiting approval, then approve them with Update. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPResource.Search(ctx, operations.C1APIAiGovernanceV1MCPResourceServiceSearchRequest{ + AppID: "", + ConnectorID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MCPResourceServiceSearchResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPResourceServiceSearchRequest](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPResourceServiceSearchResponse](../../pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearchresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update modifies a resource's lifecycle state via update_mask. Set + resource.state = MCP_RESOURCE_STATE_APPROVED with update_mask "state" to + move it out of PENDING_REVIEW (or DISABLED to block it). Resource metadata + is discovery-owned and read-only. resource must include id, app_id, and + connector_id. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MCPResource.Update(ctx, operations.C1APIAiGovernanceV1MCPResourceServiceUpdateRequest{ + AppID: "", + ConnectorID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MCPResourceServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIAiGovernanceV1MCPResourceServiceUpdateRequest](../../pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIAiGovernanceV1MCPResourceServiceUpdateResponse](../../pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/myfundlimits/README.md b/docs/sdks/myfundlimits/README.md new file mode 100644 index 000000000..de0890941 --- /dev/null +++ b/docs/sdks/myfundlimits/README.md @@ -0,0 +1,369 @@ +# MyFundLimits + +## Overview + +### Available Operations + +* [Delete](#delete) - Delete +* [List](#list) - List +* [ListHistory](#listhistory) - List History +* [Pause](#pause) - Pause +* [Resume](#resume) - Resume +* [SetLimit](#setlimit) - Set Limit + +## Delete + +Remove the caller's limit on this app entirely. The app is then bounded + only by the fund and by any tenant-wide cap. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.Delete(ctx, operations.C1APIFundsV1MyFundLimitsServiceDeleteRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServiceDeleteRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServiceDeleteResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List the caller's own per-app limits. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.List(ctx, operations.C1APIFundsV1MyFundLimitsServiceListRequest{}) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServiceListRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServiceListResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +List the change history for one of the caller's own per-app limits, newest + first. Removing the last control deletes the row, so this is where a subject + reads back the pause they lifted and when they lifted it. + + VIEWER, not the OWNER the two admin-plane history RPCs use. This service + carries no user id in any request, so it can only ever return the caller's + own rows: gating it at OWNER would put an owner role in front of the + caller's own data and still return nothing but that. An admin auditing + another subject's app limits needs an admin-plane read, which this service + is not and deliberately does not become. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.ListHistory(ctx, operations.C1APIFundsV1MyFundLimitsServiceListHistoryRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServiceListHistoryRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServiceListHistoryResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Pause + +Pause one app on the caller's own fund. The limit underneath is preserved + and restored by Resume. Denials name this as paused by you. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.Pause(ctx, operations.C1APIFundsV1MyFundLimitsServicePauseRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServicePauseResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServicePauseRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsservicepauserequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServicePauseResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsservicepauseresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Resume + +Un-pause the app, restoring the limit it froze. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.Resume(ctx, operations.C1APIFundsV1MyFundLimitsServiceResumeRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServiceResumeResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServiceResumeRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsserviceresumerequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServiceResumeResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsserviceresumeresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## SetLimit + +Cap what one app may take from the caller's own fund. Amount arm only. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.MyFundLimits.SetLimit(ctx, operations.C1APIFundsV1MyFundLimitsServiceSetLimitRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.MyFundLimitsServiceSetLimitResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIFundsV1MyFundLimitsServiceSetLimitRequest](../../pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIFundsV1MyFundLimitsServiceSetLimitResponse](../../pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimitresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/providercredential/README.md b/docs/sdks/providercredential/README.md new file mode 100644 index 000000000..7d8106b77 --- /dev/null +++ b/docs/sdks/providercredential/README.md @@ -0,0 +1,188 @@ +# ProviderCredential + +## Overview + +### Available Operations + +* [Clear](#clear) - Clear +* [Get](#get) - Get +* [Set](#set) - Set + +## Clear + +Clear deletes the provider credential stored in the given slot. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.ProviderCredential.Clear(ctx, operations.C1APILlmGatewayV1ProviderCredentialServiceClearRequest{ + SlotID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ClearProviderCredentialResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APILlmGatewayV1ProviderCredentialServiceClearRequest](../../pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1ProviderCredentialServiceClearResponse](../../pkg/models/operations/c1apillmgatewayv1providercredentialserviceclearresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns metadata for the provider credential in the given slot. The + stored API key is never returned. Returns an empty response if no + credential has ever been set for the slot; a cleared slot returns + FAILED_PRECONDITION. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.ProviderCredential.Get(ctx, operations.C1APILlmGatewayV1ProviderCredentialServiceGetRequest{ + SlotID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.GetProviderCredentialResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APILlmGatewayV1ProviderCredentialServiceGetRequest](../../pkg/models/operations/c1apillmgatewayv1providercredentialservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1ProviderCredentialServiceGetResponse](../../pkg/models/operations/c1apillmgatewayv1providercredentialservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Set + +Set stores or replaces the provider API key used by the LLM gateway for + the given slot. The API key is stored encrypted and is never returned by + the API. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.ProviderCredential.Set(ctx, operations.C1APILlmGatewayV1ProviderCredentialServiceSetRequest{ + SlotID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SetProviderCredentialResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APILlmGatewayV1ProviderCredentialServiceSetRequest](../../pkg/models/operations/c1apillmgatewayv1providercredentialservicesetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APILlmGatewayV1ProviderCredentialServiceSetResponse](../../pkg/models/operations/c1apillmgatewayv1providercredentialservicesetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/reporting/README.md b/docs/sdks/reporting/README.md new file mode 100644 index 000000000..ebd251170 --- /dev/null +++ b/docs/sdks/reporting/README.md @@ -0,0 +1,427 @@ +# Reporting + +## Overview + +### Available Operations + +* [Delete](#delete) - Delete +* [Get](#get) - Get +* [GetRunProvenance](#getrunprovenance) - Get Run Provenance +* [List](#list) - List +* [Run](#run) - Run +* [Save](#save) - Save +* [Update](#update) - Update + +## Delete + +Delete removes a report by ID. The report's saved program is removed with + it, so the report can no longer be re-run. Only the report's creator can + delete it. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.Delete(ctx, operations.C1APIReportingV1ReportingServiceDeleteRequest{ + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceDeleteRequest](../../pkg/models/operations/c1apireportingv1reportingservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceDeleteResponse](../../pkg/models/operations/c1apireportingv1reportingservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns a report by ID, including its latest run and latest successful + run. Reports are visible only to the user who created them. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.Get(ctx, operations.C1APIReportingV1ReportingServiceGetRequest{ + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceGetRequest](../../pkg/models/operations/c1apireportingv1reportingservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceGetResponse](../../pkg/models/operations/c1apireportingv1reportingservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## GetRunProvenance + +GetRunProvenance explains a run: what it read, what its program looked at, + and the program itself. A2UIService.GetSurfaceProvenance answers the same + question for a surface, but needs a live one — and a rerun is headless, so + a report would become less explainable every time it refreshed. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.GetRunProvenance(ctx, operations.C1APIReportingV1ReportingServiceGetRunProvenanceRequest{ + ID: "", + RunID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceGetRunProvenanceResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceGetRunProvenanceRequest](../../pkg/models/operations/c1apireportingv1reportingservicegetrunprovenancerequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceGetRunProvenanceResponse](../../pkg/models/operations/c1apireportingv1reportingservicegetrunprovenanceresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List returns reports created by the caller, newest first. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.List(ctx, operations.C1APIReportingV1ReportingServiceListRequest{}) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceListRequest](../../pkg/models/operations/c1apireportingv1reportingservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceListResponse](../../pkg/models/operations/c1apireportingv1reportingservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Run + +Run re-executes the report's pinned program against today's data. It never + re-plans: the commit is fixed, so a rerun can only change the numbers, not + the question. Returns as soon as the invocation starts — see the response. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.Run(ctx, operations.C1APIReportingV1ReportingServiceRunRequest{ + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceRunResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceRunRequest](../../pkg/models/operations/c1apireportingv1reportingservicerunrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceRunResponse](../../pkg/models/operations/c1apireportingv1reportingservicerunresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Save + +Save promotes the program behind an already-rendered reporting surface into + a report. The caller identifies the surface; the server resolves which + program produced it. There is no create-from-prompt: the prompt has already + been answered by the time a report is worth keeping. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.Save(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceSaveResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.ReportingServiceSaveRequest](../../pkg/models/shared/reportingservicesaverequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceSaveResponse](../../pkg/models/operations/c1apireportingv1reportingservicesaveresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update modifies a report's display name, prompt, or parameter values. + Only the report's creator can update it. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.Reporting.Update(ctx, operations.C1APIReportingV1ReportingServiceUpdateRequest{ + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.ReportingServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIReportingV1ReportingServiceUpdateRequest](../../pkg/models/operations/c1apireportingv1reportingserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIReportingV1ReportingServiceUpdateResponse](../../pkg/models/operations/c1apireportingv1reportingserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/roleminingmanagement/README.md b/docs/sdks/roleminingmanagement/README.md index 53c30501a..6dd1e3e82 100644 --- a/docs/sdks/roleminingmanagement/README.md +++ b/docs/sdks/roleminingmanagement/README.md @@ -5,6 +5,7 @@ ### Available Operations * [CreateAccessProfileFromCohort](#createaccessprofilefromcohort) - Create Access Profile From Cohort +* [EvaluateEntitlementSelection](#evaluateentitlementselection) - Evaluate Entitlement Selection * [GetCustomAnalysisResult](#getcustomanalysisresult) - Get Custom Analysis Result * [GetLatestRun](#getlatestrun) - Get Latest Run * [GetRoleMiningConfig](#getroleminingconfig) - Get Role Mining Config @@ -75,9 +76,71 @@ func main() { | ------------------ | ------------------ | ------------------ | | sdkerrors.SDKError | 4XX, 5XX | \*/\* | +## EvaluateEntitlementSelection + +Evaluate the exact cohort impact of an entitlement cutoff and manual overrides. + The analysis determines the eligible entitlements and cohort definition. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.RoleMiningManagement.EvaluateEntitlementSelection(ctx, operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest{ + AnalysisID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.EvaluateEntitlementSelectionResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest](../../pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse](../../pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + ## GetCustomAnalysisResult -Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult method. +GetCustomAnalysisResult returns the status and results of a custom cohort + analysis started with TriggerCustomAnalysis, including entitlement + coverage, entitlement clusters, attribute facets, and cutoff impact + points. Requires the agentic role mining feature. ### Example Usage @@ -576,7 +639,10 @@ func main() { ## TriggerCustomAnalysis -Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis method. +TriggerCustomAnalysis starts an asynchronous custom cohort analysis defined + by the given profile filters and returns the ID of the analysis result. + Requires the agentic role mining feature. Poll GetCustomAnalysisResult + until the analysis completes. ### Example Usage diff --git a/docs/sdks/ssoapplication/README.md b/docs/sdks/ssoapplication/README.md new file mode 100644 index 000000000..106e538d2 --- /dev/null +++ b/docs/sdks/ssoapplication/README.md @@ -0,0 +1,927 @@ +# SSOApplication + +## Overview + +### Available Operations + +* [BatchDeleteSubjectCompatibility](#batchdeletesubjectcompatibility) - Batch Delete Subject Compatibility +* [BatchImportSubjectCompatibility](#batchimportsubjectcompatibility) - Batch Import Subject Compatibility +* [Create](#create) - Create +* [CreateClient](#createclient) - Create Client +* [Delete](#delete) - Delete +* [DeleteClient](#deleteclient) - Delete Client +* [Get](#get) - Get +* [List](#list) - List +* [ListClients](#listclients) - List Clients +* [ListHistory](#listhistory) - List History +* [ParseSAMLServiceProviderMetadata](#parsesamlserviceprovidermetadata) - Parse Saml Service Provider Metadata +* [RotateClientSecret](#rotateclientsecret) - Rotate Client Secret +* [Search](#search) - Search +* [Update](#update) - Update +* [UpdateClient](#updateclient) - Update Client + +## BatchDeleteSubjectCompatibility + +Deletes one bounded batch of compatibility bindings. Imported and + user-attribute-derived bindings are recoverable so corrected source data + can be applied on the next import or sign-in. Correct attribute source data + before deleting its binding so a concurrent sign-in cannot recreate the + stale value. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.BatchDeleteSubjectCompatibility(ctx, operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## BatchImportSubjectCompatibility + +Validates or imports one bounded batch of compatibility-subject bindings. + Clients parse source files and submit at most 50 rows per request so they + can expose progress and retry from a known boundary. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.BatchImportSubjectCompatibility(ctx, operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceBatchImportSubjectCompatibilityResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Create + +Create an SSO application for an application in your catalog. The + entitlement that governs sign-in is created alongside it. OIDC creation + also server-mints the required initial client and returns its secret once + when the client is confidential. SAML creation has no OAuth-client step. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.Create(ctx, operations.C1APISSOV1SSOApplicationServiceCreateRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceCreateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceCreateRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicecreaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceCreateResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicecreateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## CreateClient + +CreateClient mints an additional App-owned OAuth client for an OIDC + application. C1 generates the client ID and any confidential-client secret. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.CreateClient(ctx, operations.C1APISSOV1SSOApplicationServiceCreateClientRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceCreateClientResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceCreateClientRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicecreateclientrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceCreateClientResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicecreateclientresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Delete + +Delete retires an SSO application and its sign-in entitlement, stopping + OIDC and SAML sign-in through it. OAuth clients and locator bindings remain + so administrators can list and delete retained clients; the bindings are + inert while their parent application is deleted. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.Delete(ctx, operations.C1APISSOV1SSOApplicationServiceDeleteRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceDeleteResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceDeleteRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicedeleterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceDeleteResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicedeleteresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## DeleteClient + +DeleteClient deletes one App-owned OAuth client and its sign-in binding. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.DeleteClient(ctx, operations.C1APISSOV1SSOApplicationServiceDeleteClientRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceDeleteClientResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceDeleteClientRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceDeleteClientResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicedeleteclientresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Get + +Get returns a single SSO application by app_id + id. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.Get(ctx, operations.C1APISSOV1SSOApplicationServiceGetRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceGetRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicegetrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceGetResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## List + +List returns the SSO applications configured for an application, one page + at a time. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.List(ctx, operations.C1APISSOV1SSOApplicationServiceListRequest{ + AppID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceListResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceListRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicelistrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceListResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicelistresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListClients + +ListClients returns the App-owned OAuth clients minted for an OIDC + application, one page at a time. Results hydrate from the PostgreSQL + projection, so a newly created client may appear after a brief delay. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.ListClients(ctx, operations.C1APISSOV1SSOApplicationServiceListClientsRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceListClientsResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceListClientsRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicelistclientsrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceListClientsResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicelistclientsresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +ListHistory returns the change history (newest first) for a single SSO + application — each entry is a snapshot plus who/when metadata. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.ListHistory(ctx, operations.C1APISSOV1SSOApplicationServiceListHistoryRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceListHistoryRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceListHistoryResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ParseSAMLServiceProviderMetadata + +ParseSAMLServiceProviderMetadata parses one uploaded SAML service-provider + metadata document and returns the SAML configuration it implies, without + creating or changing anything. The document is not stored. Use it to + preview an SP's capabilities before creating a SAML application; edit the + returned configuration before passing it to Create. Only upload or paste a + customer-supplied document -- C1 does not fetch metadata URLs. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.ParseSAMLServiceProviderMetadata(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest](../../pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse](../../pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## RotateClientSecret + +RotateClientSecret replaces a confidential App-owned client's secret and + returns the new value once. The old secret stops working immediately; for + an overlap window, create a second client, migrate, then delete the first. + Public clients have no secret to rotate. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.RotateClientSecret(ctx, operations.C1APISSOV1SSOApplicationServiceRotateClientSecretRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceRotateClientSecretResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceRotateClientSecretRequest](../../pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceRotateClientSecretResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecretresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Search + +Search SSO applications across the tenant. Supports filtering by the + applications in your catalog and by display-name or description text. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.Search(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceSearchResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.SSOApplicationServiceSearchRequest](../../pkg/models/shared/ssoapplicationservicesearchrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceSearchResponse](../../pkg/models/operations/c1apissov1ssoapplicationservicesearchresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update changes an SSO application's mutable display, lifetime, enablement, + OIDC claim/signing settings, or SAML endpoint/signing/encryption settings. + Protocol, subject type, sector, SAML entity ID, and NameID format remain + immutable; requests that would change them are rejected. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.Update(ctx, operations.C1APISSOV1SSOApplicationServiceUpdateRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceUpdateRequest](../../pkg/models/operations/c1apissov1ssoapplicationserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceUpdateResponse](../../pkg/models/operations/c1apissov1ssoapplicationserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## UpdateClient + +UpdateClient replaces mutable client configuration. The authentication + method and generated ID are immutable; private-key JWKS may rotate and a + legacy PKCE policy may tighten to required. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOApplication.UpdateClient(ctx, operations.C1APISSOV1SSOApplicationServiceUpdateClientRequest{ + AppID: "", + ID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.SSOApplicationServiceUpdateClientResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOApplicationServiceUpdateClientRequest](../../pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOApplicationServiceUpdateClientResponse](../../pkg/models/operations/c1apissov1ssoapplicationserviceupdateclientresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/ssosettings/README.md b/docs/sdks/ssosettings/README.md new file mode 100644 index 000000000..e464b1982 --- /dev/null +++ b/docs/sdks/ssosettings/README.md @@ -0,0 +1,177 @@ +# SSOSettings + +## Overview + +### Available Operations + +* [Get](#get) - Get +* [ListHistory](#listhistory) - List History +* [Update](#update) - Update + +## Get + +Get returns the tenant's SSO provider settings. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOSettings.Get(ctx) + if err != nil { + log.Fatal(err) + } + if res.SSOSettingsServiceGetResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOSettingsServiceGetResponse](../../pkg/models/operations/c1apissov1ssosettingsservicegetresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## ListHistory + +ListHistory returns the SSO settings change history, newest first. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOSettings.ListHistory(ctx, operations.C1APISSOV1SSOSettingsServiceListHistoryRequest{}) + if err != nil { + log.Fatal(err) + } + if res.SSOSettingsServiceListHistoryResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APISSOV1SSOSettingsServiceListHistoryRequest](../../pkg/models/operations/c1apissov1ssosettingsservicelisthistoryrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOSettingsServiceListHistoryResponse](../../pkg/models/operations/c1apissov1ssosettingsservicelisthistoryresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + +## Update + +Update changes the tenant's SSO provider settings. Supply the settings + object and an update mask listing the fields to change; only masked fields + are applied. Editable paths: enabled, default_subject_type, + default_assertion_lifetime, default_id_token_signed_response_alg. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.SSOSettings.Update(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.SSOSettingsServiceUpdateResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.SSOSettingsServiceUpdateRequest](../../pkg/models/shared/ssosettingsserviceupdaterequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APISSOV1SSOSettingsServiceUpdateResponse](../../pkg/models/operations/c1apissov1ssosettingsserviceupdateresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/docs/sdks/taskactions/README.md b/docs/sdks/taskactions/README.md index bfa2caee2..395e67b9c 100644 --- a/docs/sdks/taskactions/README.md +++ b/docs/sdks/taskactions/README.md @@ -14,6 +14,7 @@ * [ProcessNow](#processnow) - Process Now * [Reassign](#reassign) - Reassign * [Restart](#restart) - Restart +* [RetryProvisioning](#retryprovisioning) - Retry Provisioning * [SkipStep](#skipstep) - Skip Step * [UpdateGrantDuration](#updategrantduration) - Update Grant Duration * [UpdateRequestData](#updaterequestdata) - Update Request Data @@ -603,6 +604,66 @@ func main() { | ------------------ | ------------------ | ------------------ | | sdkerrors.SDKError | 4XX, 5XX | \*/\* | +## RetryProvisioning + +Retry the provisioning of a task whose connector provisioning failed. Resets the + failed connector actions and re-drives the connector, preserving the already-collected + approvals. Only valid when the task's current provision step ended in an error. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.TaskActions.RetryProvisioning(ctx, operations.C1APITaskV1TaskActionsServiceRetryProvisioningRequest{ + TaskID: "", + }) + if err != nil { + log.Fatal(err) + } + if res.TaskServiceActionResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [operations.C1APITaskV1TaskActionsServiceRetryProvisioningRequest](../../pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APITaskV1TaskActionsServiceRetryProvisioningResponse](../../pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioningresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | + ## SkipStep Skip a specific policy step in a task, advancing the task to the next step in the workflow. diff --git a/docs/sdks/uiconversations/README.md b/docs/sdks/uiconversations/README.md new file mode 100644 index 000000000..183615937 --- /dev/null +++ b/docs/sdks/uiconversations/README.md @@ -0,0 +1,63 @@ +# UIConversations + +## Overview + +### Available Operations + +* [EnsureOnboardingSession](#ensureonboardingsession) - Ensure Onboarding Session + +## EnsureOnboardingSession + +EnsureOnboardingSession returns the tenant's active onboarding conversation, + or creates and starts it once. Retries converge on the stored conversation. + +### Example Usage + + +```go +package main + +import( + "context" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + conductoronesdkgo "github.com/conductorone/conductorone-sdk-go" + "log" +) + +func main() { + ctx := context.Background() + + s := conductoronesdkgo.New( + conductoronesdkgo.WithSecurity(shared.Security{ + BearerAuth: "", + Oauth: "", + }), + ) + + res, err := s.UIConversations.EnsureOnboardingSession(ctx, nil) + if err != nil { + log.Fatal(err) + } + if res.EnsureOnboardingSessionResponse != nil { + // handle response + } +} +``` + +### Parameters + +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | +| `ctx` | [context.Context](https://pkg.go.dev/context#Context) | :heavy_check_mark: | The context to use for the request. | +| `request` | [shared.EnsureOnboardingSessionRequest](../../pkg/models/shared/ensureonboardingsessionrequest.md) | :heavy_check_mark: | The request object to use for the request. | +| `opts` | [][operations.Option](../../pkg/models/operations/option.md) | :heavy_minus_sign: | The options for this request. | + +### Response + +**[*operations.C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse](../../pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse.md), error** + +### Errors + +| Error Type | Status Code | Content Type | +| ------------------ | ------------------ | ------------------ | +| sdkerrors.SDKError | 4XX, 5XX | \*/\* | \ No newline at end of file diff --git a/findingsettings.go b/findingsettings.go new file mode 100644 index 000000000..ad6e36ddd --- /dev/null +++ b/findingsettings.go @@ -0,0 +1,452 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type FindingSettings struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newFindingSettings(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *FindingSettings { + return &FindingSettings{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// ListFindingSettings - List Finding Settings +// List every configurable finding type and whether detection is enabled. +func (s *FindingSettings) ListFindingSettings(ctx context.Context, opts ...operations.Option) (*operations.C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/findings/settings") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.finding.v1.FindingSettingsService.ListFindingSettings", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ListFindingSettingsResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ListFindingSettingsResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// UpdateFindingSettings - Update Finding Settings +// Enable or disable detection for one or more finding types in a single +// +// write. Enabling a type whose detector is a scheduled job also queues an +// immediate run. +func (s *FindingSettings) UpdateFindingSettings(ctx context.Context, request *shared.UpdateFindingSettingsRequest, opts ...operations.Option) (*operations.C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/findings/settings/update") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.finding.v1.FindingSettingsService.UpdateFindingSettings", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.UpdateFindingSettingsResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.UpdateFindingSettingsResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/functions.go b/functions.go index 6a7690d7a..2aabc81c6 100644 --- a/functions.go +++ b/functions.go @@ -2756,10 +2756,16 @@ func (s *Functions) Test(ctx context.Context, request operations.C1APIFunctionsV } // UpdateFunction - Update Function -// Update an existing function's metadata. Also the publish path: set +// Update an existing function's metadata, code, or both. Also the publish // -// function.published_commit_id and include "published_commit_id" in -// update_mask to make a commit the default runnable version. +// path: set function.published_commit_id and include "published_commit_id" +// in update_mask to make a commit the default runnable version. To push a +// new code commit, set content (and optionally commit_message); this is +// independent of update_mask, since commits are versioned separately from +// function metadata. A single request cannot publish the commit it just +// created, since published_commit_id is validated against existing commits +// before content is committed: publishing new code takes two calls, push +// then publish with the returned commit.id. func (s *Functions) UpdateFunction(ctx context.Context, request *shared.FunctionsServiceUpdateFunctionRequest, opts ...operations.Option) (*operations.C1APIFunctionsV1FunctionsServiceUpdateFunctionResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/fundassignment.go b/fundassignment.go new file mode 100644 index 000000000..b0dcf5030 --- /dev/null +++ b/fundassignment.go @@ -0,0 +1,1945 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type FundAssignment struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newFundAssignment(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *FundAssignment { + return &FundAssignment{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// ClearExtension - Clear Extension +// Revoke the extension early. The base limit underneath is untouched. +func (s *FundAssignment) ClearExtension(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceClearExtensionRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceClearExtensionResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/extension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.ClearExtension", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceClearExtensionRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceClearExtensionResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceClearExtensionResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceClearExtensionResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Delete +// Delete the whole assignment. The subject falls back to the rules and the +// +// tenant default. +func (s *FundAssignment) Delete(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns one subject's exception: their own limit, any extension +// +// running on top of it, and any suspension. A subject with no exception is +// not found rather than reported at the tenant default, because no row is +// what "this subject is governed by the layers above" looks like. +func (s *FundAssignment) Get(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceGetRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// GrantExtension - Grant Extension +// Grant a temporary total until expires_at. Never changes the period, and +// +// never expresses a refusal — a temporary refusal is a suspension. +func (s *FundAssignment) GrantExtension(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceGrantExtensionRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceGrantExtensionResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/extension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.GrantExtension", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceGrantExtensionRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceGrantExtensionResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceGrantExtensionResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceGrantExtensionResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// List the change history for one subject's assignment, newest first. +func (s *FundAssignment) ListHistory(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Search +// Search the tenant's assignments. Reads the Postgres mirror: the runtime +// +// row is keyed on (tenant, user), so there is no cross-subject query on the +// runtime plane at all. +func (s *FundAssignment) Search(ctx context.Context, request *shared.FundAssignmentServiceSearchRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceSearchResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/assignments/search") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.Search", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceSearchResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceSearchResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceSearchResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// SetLimit - Set Limit +// Set the subject's base limit, creating the assignment if absent. Leaves any +// +// extension and any suspension in place. +func (s *FundAssignment) SetLimit(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceSetLimitRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceSetLimitResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/limit", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.SetLimit", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceSetLimitRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceSetLimitResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceSetLimitResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceSetLimitResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Suspend +// Freeze the subject's fund. The limit and any extension underneath are +// +// preserved and restored by Unsuspend. +func (s *FundAssignment) Suspend(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceSuspendRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceSuspendResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.Suspend", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceSuspendRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceSuspendResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceSuspendResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceSuspendResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Unsuspend +// Lift the suspension, restoring the numbers it froze. +func (s *FundAssignment) Unsuspend(ctx context.Context, request operations.C1APIFundsV1FundAssignmentServiceUnsuspendRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundAssignmentServiceUnsuspendResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/assignments/{user_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundAssignmentService.Unsuspend", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundAssignmentServiceUnsuspendRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundAssignmentServiceUnsuspendResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundAssignmentServiceUnsuspendResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundAssignmentServiceUnsuspendResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/fundpolicy.go b/fundpolicy.go new file mode 100644 index 000000000..855761157 --- /dev/null +++ b/fundpolicy.go @@ -0,0 +1,1737 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type FundPolicy struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newFundPolicy(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *FundPolicy { + return &FundPolicy{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Create +// Create the tenant's fund policy, opting the tenant in to spend governance. +// +// default_limit is required: a tenant states its posture explicitly, and +// there is no implicit default anywhere in the write path. +func (s *FundPolicy) Create(ctx context.Context, request *shared.FundPolicyServiceCreateRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceCreateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.Create", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceCreateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceCreateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceCreateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Delete +// Delete the tenant's fund policy, opting the tenant back out of spend +// +// governance. Rules, assignments and app caps are left in place and go +// dormant; a later Create restores every one of them. +func (s *FundPolicy) Delete(ctx context.Context, request *shared.FundPolicyServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// FreezeTenant - Freeze Tenant +// Freeze the whole tenant. The ceiling amount underneath is preserved and +// +// restored by Unfreeze. +func (s *FundPolicy) FreezeTenant(ctx context.Context, request *shared.FundPolicyServiceFreezeTenantRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceFreezeTenantResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy/ceiling/suspension") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.FreezeTenant", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceFreezeTenantResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceFreezeTenantResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceFreezeTenantResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get the tenant's fund policy. An absent policy in the response means the +// +// tenant has not opted in to spend governance, which is an ordinary state +// rather than an error. +func (s *FundPolicy) Get(ctx context.Context, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// List the change history for the fund policy, newest first. Admin-tier per +// +// the object-history convention. +func (s *FundPolicy) ListHistory(ctx context.Context, request operations.C1APIFundsV1FundPolicyServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy/history") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// SetOrgCeiling - Set Org Ceiling +// Set the org-wide ceiling: the bound on the tenant's total regardless of +// +// what any principal was granted. Amount arm only. Clears the ceiling when +// limit is absent. +func (s *FundPolicy) SetOrgCeiling(ctx context.Context, request *shared.FundPolicyServiceSetOrgCeilingRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy/ceiling/limit") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.SetOrgCeiling", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceSetOrgCeilingResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceSetOrgCeilingResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// UnfreezeTenant - Unfreeze Tenant +// Lift the tenant freeze, restoring the ceiling it froze. +func (s *FundPolicy) UnfreezeTenant(ctx context.Context, request *shared.FundPolicyServiceUnfreezeTenantRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy/ceiling/suspension") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.UnfreezeTenant", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceUnfreezeTenantResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceUnfreezeTenantResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update the period or the default limit. currency_code is immutable after +// +// Create and update_mask rejects it: an amount denominated in a currency the +// policy no longer names faults the acquire path rather than denying it. +func (s *FundPolicy) Update(ctx context.Context, request *shared.FundPolicyServiceUpdateRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundPolicyServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/policy/update") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundPolicyService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundPolicyServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundPolicyServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundPolicyServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/fundrule.go b/fundrule.go new file mode 100644 index 000000000..0d3e0a142 --- /dev/null +++ b/fundrule.go @@ -0,0 +1,1521 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type FundRule struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newFundRule(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *FundRule { + return &FundRule{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Create +// Create funds a group. The group is an AppEntitlement, so membership +// +// resolves through that entitlement's bindings on every acquire rather than +// being captured here. Creating the tenant's first rule is what turns group +// resolution on for that tenant. +func (s *FundRule) Create(ctx context.Context, request *shared.FundRuleServiceCreateRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceCreateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/rules") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.Create", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceCreateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceCreateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceCreateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Delete +// Delete withdraws a group grant. The cohort keeps whatever the tenant +// +// default and any other rule matching them still allow, so this narrows their +// fund rather than necessarily cutting it off. The rule's history survives. +func (s *FundRule) Delete(ctx context.Context, request operations.C1APIFundsV1FundRuleServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/rules/{rule_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundRuleServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns one rule: the group it funds, the grant it carries, and the +// +// label and reason an admin reads it by. A deleted rule is not found. +func (s *FundRule) Get(ctx context.Context, request operations.C1APIFundsV1FundRuleServiceGetRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/rules/{rule_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List every rule in the tenant. Reads the runtime plane: rule cardinality +// +// is the tenant's rule count, so this is the same one-partition read +// resolution does. +func (s *FundRule) List(ctx context.Context, request operations.C1APIFundsV1FundRuleServiceListRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/rules") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// List the change history for one rule, newest first. Admin-tier per the +// +// object-history convention. A deleted rule keeps its history: the delete is +// the last entry, and the one before it is the rule as it last stood. +func (s *FundRule) ListHistory(ctx context.Context, request operations.C1APIFundsV1FundRuleServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/rules/{rule_id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Search +// Search rules by display name. Reads the Postgres mirror. +func (s *FundRule) Search(ctx context.Context, request *shared.FundRuleServiceSearchRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceSearchResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/rules/search") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.Search", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceSearchResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceSearchResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceSearchResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update replaces the group, grant, label or reason on one rule, whichever +// +// the field mask names. The new grant governs the next acquire; spend already +// accounted for against the old one is not revisited. +func (s *FundRule) Update(ctx context.Context, request operations.C1APIFundsV1FundRuleServiceUpdateRequest, opts ...operations.Option) (*operations.C1APIFundsV1FundRuleServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/rules/{rule_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.FundRuleService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "FundRuleServiceUpdateRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1FundRuleServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.FundRuleServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.FundRuleServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/gatewaykey.go b/gatewaykey.go new file mode 100644 index 000000000..5298b003a --- /dev/null +++ b/gatewaykey.go @@ -0,0 +1,667 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type GatewayKey struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newGatewayKey(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *GatewayKey { + return &GatewayKey{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// List +// List returns the tenant's LLM gateway API keys. Only key metadata and a +// +// key prefix are returned, never the full key. +func (s *GatewayKey) List(ctx context.Context, opts ...operations.Option) (*operations.C1APILlmGatewayV1GatewayKeyServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/llm-gateway/keys") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.GatewayKeyService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1GatewayKeyServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ListGatewayKeysResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ListGatewayKeysResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Mint +// Mint creates a new LLM gateway API key. The key value is shown only in +// +// this response and cannot be retrieved again; store it immediately. +func (s *GatewayKey) Mint(ctx context.Context, request *shared.MintGatewayKeyRequest, opts ...operations.Option) (*operations.C1APILlmGatewayV1GatewayKeyServiceMintResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/llm-gateway/keys") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.GatewayKeyService.Mint", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1GatewayKeyServiceMintResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MintGatewayKeyResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MintGatewayKeyResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Revoke +// Revoke revokes an LLM gateway API key by ID. The key immediately stops +// +// authenticating gateway requests. +func (s *GatewayKey) Revoke(ctx context.Context, request operations.C1APILlmGatewayV1GatewayKeyServiceRevokeRequest, opts ...operations.Option) (*operations.C1APILlmGatewayV1GatewayKeyServiceRevokeResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/llm-gateway/keys/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.GatewayKeyService.Revoke", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "RevokeGatewayKeyRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1GatewayKeyServiceRevokeResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.RevokeGatewayKeyResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.RevokeGatewayKeyResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/gen.yaml b/gen.yaml index 8baad4504..2a9fbce04 100644 --- a/gen.yaml +++ b/gen.yaml @@ -26,7 +26,7 @@ generation: generateNewTests: false skipResponseBodyAssertions: false go: - version: 1.29.0 + version: 1.29.1 additionalDependencies: {} allowUnknownFieldsInWeakUnions: false baseErrorName: ConductoroneAPIError @@ -37,6 +37,7 @@ go: flattenGlobalSecurity: true forwardCompatibleEnumsByDefault: false forwardCompatibleUnionsByDefault: "false" + idiomaticMethodCollisionNames: false imports: option: openapi paths: @@ -53,10 +54,12 @@ go: modulePath: "" multipartArrayFormat: legacy nullableOptionalWrapper: false + optionalMethodArguments: pointers outputModelSuffix: output packageName: github.com/conductorone/conductorone-sdk-go respectRequiredFields: false respectTitlesForPrimitiveUnionMembers: false responseFormat: envelope sdkPackageName: "" + unionGenerics: false unionStrategy: left-to-right diff --git a/hooks.go b/hooks.go index 42ac61ca4..b2fedf77a 100644 --- a/hooks.go +++ b/hooks.go @@ -32,7 +32,10 @@ func newHooks(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks } // Create -// Invokes the c1.api.hooks.v1.HooksService.Create method. +// Create creates a hook. The hook fires on the configured event, optionally +// +// filtered by a CEL expression. Creating a Patch tool input hook requires the +// preview feature to be enabled for the tenant. func (s *Hooks) Create(ctx context.Context, request *shared.HooksServiceCreateRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksServiceCreateResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -244,7 +247,9 @@ func (s *Hooks) Create(ctx context.Context, request *shared.HooksServiceCreateRe } // Delete -// Invokes the c1.api.hooks.v1.HooksService.Delete method. +// Delete removes a hook by ID. A hook referenced by a guardrail rule cannot +// +// be deleted until the reference is removed. func (s *Hooks) Delete(ctx context.Context, request operations.C1APIHooksV1HooksServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksServiceDeleteResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -456,7 +461,7 @@ func (s *Hooks) Delete(ctx context.Context, request operations.C1APIHooksV1Hooks } // Get -// Invokes the c1.api.hooks.v1.HooksService.Get method. +// Get returns a hook by ID. func (s *Hooks) Get(ctx context.Context, request operations.C1APIHooksV1HooksServiceGetRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksServiceGetResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -661,7 +666,7 @@ func (s *Hooks) Get(ctx context.Context, request operations.C1APIHooksV1HooksSer } // List -// Invokes the c1.api.hooks.v1.HooksService.List method. +// List returns all hooks for the tenant, paginated. func (s *Hooks) List(ctx context.Context, request operations.C1APIHooksV1HooksServiceListRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksServiceListResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -870,7 +875,10 @@ func (s *Hooks) List(ctx context.Context, request operations.C1APIHooksV1HooksSe } // Update -// Invokes the c1.api.hooks.v1.HooksService.Update method. +// Update modifies a hook's display name, description, event, filter, priority, +// +// or configuration. A hook referenced by a guardrail rule cannot stop being +// managed by guardrails until the reference is removed. func (s *Hooks) Update(ctx context.Context, request operations.C1APIHooksV1HooksServiceUpdateRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksServiceUpdateResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/hookssearch.go b/hookssearch.go index b9b97ffd7..8312eb39e 100644 --- a/hookssearch.go +++ b/hookssearch.go @@ -32,7 +32,9 @@ func newHooksSearch(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, } // Search -// Invokes the c1.api.hooks.v1.HooksSearch.Search method. +// Search returns hooks for the tenant, paginated. Setting query or refs +// +// returns UNIMPLEMENTED; filtering is not yet supported. func (s *HooksSearch) Search(ctx context.Context, request *shared.HooksSearchRequest, opts ...operations.Option) (*operations.C1APIHooksV1HooksSearchSearchResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/mcpaccessprofile.go b/mcpaccessprofile.go index c0218b94c..444065242 100644 --- a/mcpaccessprofile.go +++ b/mcpaccessprofile.go @@ -14,6 +14,7 @@ import ( "github.com/conductorone/conductorone-sdk-go/pkg/retry" "github.com/conductorone/conductorone-sdk-go/pkg/utils" "net/http" + "net/url" ) type MCPAccessProfile struct { @@ -1292,6 +1293,219 @@ func (s *MCPAccessProfile) ListRequestableConnectors(ctx context.Context, reques } +// SearchAccessProfiles - Search Access Profiles +// SearchAccessProfiles returns the tenant's MCP toolsets (access profiles) +// +// across every (app_id, connector_id), filtered by a case-insensitive search +// over display_name and paginated. Backs the agent-config multi-select that +// binds toolsets to a ClawAgent. +func (s *MCPAccessProfile) SearchAccessProfiles(ctx context.Context, request operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/mcp_toolsets/search") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPAccessProfileService.SearchAccessProfiles", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPAccessProfileServiceSearchAccessProfilesResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPAccessProfileServiceSearchAccessProfilesResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + // SearchRequestableConnectors - Search Requestable Connectors // SearchRequestableConnectors returns card-ready entries — one per MCP // diff --git a/mcpresource.go b/mcpresource.go new file mode 100644 index 000000000..e0132ca53 --- /dev/null +++ b/mcpresource.go @@ -0,0 +1,1093 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" +) + +type MCPResource struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newMCPResource(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *MCPResource { + return &MCPResource{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Get +// Get retrieves a single discovered MCP resource by app_id + connector_id + +// +// id, including its approval state, kind, URI or URI template, and bound +// app_entitlement_id. +func (s *MCPResource) Get(ctx context.Context, request operations.C1APIAiGovernanceV1MCPResourceServiceGetRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPResourceServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPResourceService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPResourceServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPResourceServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPResourceServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List returns the MCP resources discovered for a single (app_id, +// +// connector_id), paginated. To filter by kind or state, use Search. +func (s *MCPResource) List(ctx context.Context, request operations.C1APIAiGovernanceV1MCPResourceServiceListRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPResourceServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPResourceService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPResourceServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPResourceServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPResourceServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// ListHistory returns the change history (newest first) for a single MCP +// +// resource — each entry is a snapshot plus who/when metadata. +func (s *MCPResource) ListHistory(ctx context.Context, request operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/{id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPResourceService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPResourceServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPResourceServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Search +// Search returns a connector's MCP resources filtered by kind, state, or +// +// text query. Filter on MCP_RESOURCE_STATE_PENDING_REVIEW to find resources +// awaiting approval, then approve them with Update. +func (s *MCPResource) Search(ctx context.Context, request operations.C1APIAiGovernanceV1MCPResourceServiceSearchRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPResourceServiceSearchResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/search", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPResourceService.Search", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MCPResourceServiceSearchRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPResourceServiceSearchResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPResourceServiceSearchResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPResourceServiceSearchResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update modifies a resource's lifecycle state via update_mask. Set +// +// resource.state = MCP_RESOURCE_STATE_APPROVED with update_mask "state" to +// move it out of PENDING_REVIEW (or DISABLED to block it). Resource metadata +// is discovery-owned and read-only. resource must include id, app_id, and +// connector_id. +func (s *MCPResource) Update(ctx context.Context, request operations.C1APIAiGovernanceV1MCPResourceServiceUpdateRequest, opts ...operations.Option) (*operations.C1APIAiGovernanceV1MCPResourceServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/connectors/{connector_id}/mcp_resources/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.ai_governance.v1.MCPResourceService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MCPResourceServiceUpdateRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIAiGovernanceV1MCPResourceServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MCPResourceServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MCPResourceServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/myfundlimits.go b/myfundlimits.go new file mode 100644 index 000000000..ba7325970 --- /dev/null +++ b/myfundlimits.go @@ -0,0 +1,1312 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type MyFundLimits struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newMyFundLimits(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *MyFundLimits { + return &MyFundLimits{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Delete +// Remove the caller's limit on this app entirely. The app is then bounded +// +// only by the fund and by any tenant-wide cap. +func (s *MyFundLimits) Delete(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/my/app-limits/{app_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MyFundLimitsServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List the caller's own per-app limits. +func (s *MyFundLimits) List(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServiceListRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/funds/my/app-limits") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// List the change history for one of the caller's own per-app limits, newest +// +// first. Removing the last control deletes the row, so this is where a subject +// reads back the pause they lifted and when they lifted it. +// +// VIEWER, not the OWNER the two admin-plane history RPCs use. This service +// carries no user id in any request, so it can only ever return the caller's +// own rows: gating it at OWNER would put an owner role in front of the +// caller's own data and still return nothing but that. An admin auditing +// another subject's app limits needs an admin-plane read, which this service +// is not and deliberately does not become. +func (s *MyFundLimits) ListHistory(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/my/app-limits/{app_id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Pause +// Pause one app on the caller's own fund. The limit underneath is preserved +// +// and restored by Resume. Denials name this as paused by you. +func (s *MyFundLimits) Pause(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServicePauseRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServicePauseResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/my/app-limits/{app_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.Pause", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MyFundLimitsServicePauseRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServicePauseResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServicePauseResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServicePauseResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Resume +// Un-pause the app, restoring the limit it froze. +func (s *MyFundLimits) Resume(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServiceResumeRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServiceResumeResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/my/app-limits/{app_id}/suspension", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.Resume", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MyFundLimitsServiceResumeRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServiceResumeResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServiceResumeResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServiceResumeResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// SetLimit - Set Limit +// Cap what one app may take from the caller's own fund. Amount arm only. +func (s *MyFundLimits) SetLimit(ctx context.Context, request operations.C1APIFundsV1MyFundLimitsServiceSetLimitRequest, opts ...operations.Option) (*operations.C1APIFundsV1MyFundLimitsServiceSetLimitResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/funds/my/app-limits/{app_id}/limit", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.funds.v1.MyFundLimitsService.SetLimit", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "MyFundLimitsServiceSetLimitRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIFundsV1MyFundLimitsServiceSetLimitResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.MyFundLimitsServiceSetLimitResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.MyFundLimitsServiceSetLimitResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenance.go b/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenance.go new file mode 100644 index 000000000..d258b3be4 --- /dev/null +++ b/pkg/models/operations/c1apia2uiv1a2uiservicegetsurfaceprovenance.go @@ -0,0 +1,73 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest struct { + ConversationID string `pathParam:"style=simple,explode=false,name=conversation_id"` + SurfaceID string `pathParam:"style=simple,explode=false,name=surface_id"` +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest) GetConversationID() string { + if c == nil { + return "" + } + return c.ConversationID +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceRequest) GetSurfaceID() string { + if c == nil { + return "" + } + return c.SurfaceID +} + +// #region class-body-c1apia2uiv1a2uiservicegetsurfaceprovenancerequest +// #endregion class-body-c1apia2uiv1a2uiservicegetsurfaceprovenancerequest + +type C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse struct { + // A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built + // from: the steps its program ran, and the sources its components report. + A2UIServiceGetSurfaceProvenanceResponse *shared.A2UIServiceGetSurfaceProvenanceResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse) GetA2UIServiceGetSurfaceProvenanceResponse() *shared.A2UIServiceGetSurfaceProvenanceResponse { + if c == nil { + return nil + } + return c.A2UIServiceGetSurfaceProvenanceResponse +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIA2uiV1A2UIServiceGetSurfaceProvenanceResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse +// #endregion class-body-c1apia2uiv1a2uiservicegetsurfaceprovenanceresponse diff --git a/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereport.go b/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereport.go new file mode 100644 index 000000000..ab755c416 --- /dev/null +++ b/pkg/models/operations/c1apiaccessreviewv1accessreviewactionsservicegeneratereport.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest struct { + AccessReviewActionsServiceGenerateReportRequest *shared.AccessReviewActionsServiceGenerateReportRequest `request:"mediaType=application/json"` + AccessReviewID string `pathParam:"style=simple,explode=false,name=access_review_id"` +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest) GetAccessReviewActionsServiceGenerateReportRequest() *shared.AccessReviewActionsServiceGenerateReportRequest { + if c == nil { + return nil + } + return c.AccessReviewActionsServiceGenerateReportRequest +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportRequest) GetAccessReviewID() string { + if c == nil { + return "" + } + return c.AccessReviewID +} + +// #region class-body-c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest +// #endregion class-body-c1apiaccessreviewv1accessreviewactionsservicegeneratereportrequest + +type C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse struct { + // Successful response + AccessReviewActionsServiceGenerateReportResponse *shared.AccessReviewActionsServiceGenerateReportResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse) GetAccessReviewActionsServiceGenerateReportResponse() *shared.AccessReviewActionsServiceGenerateReportResponse { + if c == nil { + return nil + } + return c.AccessReviewActionsServiceGenerateReportResponse +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAccessreviewV1AccessReviewActionsServiceGenerateReportResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse +// #endregion class-body-c1apiaccessreviewv1accessreviewactionsservicegeneratereportresponse diff --git a/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelist.go b/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelist.go new file mode 100644 index 000000000..e7eef6992 --- /dev/null +++ b/pkg/models/operations/c1apiaccessreviewv1accessreviewreportservicelist.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAccessreviewV1AccessReviewReportServiceListRequest struct { + AccessReviewID string `pathParam:"style=simple,explode=false,name=access_review_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListRequest) GetAccessReviewID() string { + if c == nil { + return "" + } + return c.AccessReviewID +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apiaccessreviewv1accessreviewreportservicelistrequest +// #endregion class-body-c1apiaccessreviewv1accessreviewreportservicelistrequest + +type C1APIAccessreviewV1AccessReviewReportServiceListResponse struct { + // Successful response + AccessReviewReportServiceListResponse *shared.AccessReviewReportServiceListResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListResponse) GetAccessReviewReportServiceListResponse() *shared.AccessReviewReportServiceListResponse { + if c == nil { + return nil + } + return c.AccessReviewReportServiceListResponse +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAccessreviewV1AccessReviewReportServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaccessreviewv1accessreviewreportservicelistresponse +// #endregion class-body-c1apiaccessreviewv1accessreviewreportservicelistresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofiles.go b/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofiles.go new file mode 100644 index 000000000..dc9a83cf5 --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofiles.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` + Query *string `queryParam:"style=form,explode=true,name=query"` +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesRequest) GetQuery() *string { + if c == nil { + return nil + } + return c.Query +} + +// #region class-body-c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest +// #endregion class-body-c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesrequest + +type C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of + // tenant-wide MCP access profiles. + MCPAccessProfileServiceSearchAccessProfilesResponse *shared.MCPAccessProfileServiceSearchAccessProfilesResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse) GetMCPAccessProfileServiceSearchAccessProfilesResponse() *shared.MCPAccessProfileServiceSearchAccessProfilesResponse { + if c == nil { + return nil + } + return c.MCPAccessProfileServiceSearchAccessProfilesResponse +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPAccessProfileServiceSearchAccessProfilesResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse +// #endregion class-body-c1apiaigovernancev1mcpaccessprofileservicesearchaccessprofilesresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceget.go b/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceget.go new file mode 100644 index 000000000..74f69e414 --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceget.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPResourceServiceGetRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ConnectorID string `pathParam:"style=simple,explode=false,name=connector_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetRequest) GetConnectorID() string { + if c == nil { + return "" + } + return c.ConnectorID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicegetrequest +// #endregion class-body-c1apiaigovernancev1mcpresourceservicegetrequest + +type C1APIAiGovernanceV1MCPResourceServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPResourceServiceGetResponse returns a single MCP resource. + MCPResourceServiceGetResponse *shared.MCPResourceServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetResponse) GetMCPResourceServiceGetResponse() *shared.MCPResourceServiceGetResponse { + if c == nil { + return nil + } + return c.MCPResourceServiceGetResponse +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicegetresponse +// #endregion class-body-c1apiaigovernancev1mcpresourceservicegetresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelist.go b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelist.go new file mode 100644 index 000000000..81d98c242 --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelist.go @@ -0,0 +1,88 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPResourceServiceListRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ConnectorID string `pathParam:"style=simple,explode=false,name=connector_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListRequest) GetConnectorID() string { + if c == nil { + return "" + } + return c.ConnectorID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicelistrequest +// #endregion class-body-c1apiaigovernancev1mcpresourceservicelistrequest + +type C1APIAiGovernanceV1MCPResourceServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPResourceServiceListResponse returns a list of MCP resources. + MCPResourceServiceListResponse *shared.MCPResourceServiceListResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListResponse) GetMCPResourceServiceListResponse() *shared.MCPResourceServiceListResponse { + if c == nil { + return nil + } + return c.MCPResourceServiceListResponse +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicelistresponse +// #endregion class-body-c1apiaigovernancev1mcpresourceservicelistresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistory.go b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistory.go new file mode 100644 index 000000000..61fc99458 --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicelisthistory.go @@ -0,0 +1,96 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ConnectorID string `pathParam:"style=simple,explode=false,name=connector_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest) GetConnectorID() string { + if c == nil { + return "" + } + return c.ConnectorID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicelisthistoryrequest +// #endregion class-body-c1apiaigovernancev1mcpresourceservicelisthistoryrequest + +type C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPResourceServiceListHistoryResponse returns MCP resource history entries. + MCPResourceServiceListHistoryResponse *shared.MCPResourceServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse) GetMCPResourceServiceListHistoryResponse() *shared.MCPResourceServiceListHistoryResponse { + if c == nil { + return nil + } + return c.MCPResourceServiceListHistoryResponse +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicelisthistoryresponse +// #endregion class-body-c1apiaigovernancev1mcpresourceservicelisthistoryresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearch.go b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearch.go new file mode 100644 index 000000000..18bfde079 --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpresourceservicesearch.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPResourceServiceSearchRequest struct { + MCPResourceServiceSearchRequest *shared.MCPResourceServiceSearchRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ConnectorID string `pathParam:"style=simple,explode=false,name=connector_id"` +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchRequest) GetMCPResourceServiceSearchRequest() *shared.MCPResourceServiceSearchRequest { + if c == nil { + return nil + } + return c.MCPResourceServiceSearchRequest +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchRequest) GetConnectorID() string { + if c == nil { + return "" + } + return c.ConnectorID +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicesearchrequest +// #endregion class-body-c1apiaigovernancev1mcpresourceservicesearchrequest + +type C1APIAiGovernanceV1MCPResourceServiceSearchResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPResourceServiceSearchResponse returns matching MCP resources. + MCPResourceServiceSearchResponse *shared.MCPResourceServiceSearchResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchResponse) GetMCPResourceServiceSearchResponse() *shared.MCPResourceServiceSearchResponse { + if c == nil { + return nil + } + return c.MCPResourceServiceSearchResponse +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceSearchResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpresourceservicesearchresponse +// #endregion class-body-c1apiaigovernancev1mcpresourceservicesearchresponse diff --git a/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdate.go b/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdate.go new file mode 100644 index 000000000..b7fea1d1d --- /dev/null +++ b/pkg/models/operations/c1apiaigovernancev1mcpresourceserviceupdate.go @@ -0,0 +1,88 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAiGovernanceV1MCPResourceServiceUpdateRequest struct { + MCPResourceServiceUpdateRequest *shared.MCPResourceServiceUpdateRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ConnectorID string `pathParam:"style=simple,explode=false,name=connector_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateRequest) GetMCPResourceServiceUpdateRequest() *shared.MCPResourceServiceUpdateRequest { + if c == nil { + return nil + } + return c.MCPResourceServiceUpdateRequest +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateRequest) GetConnectorID() string { + if c == nil { + return "" + } + return c.ConnectorID +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apiaigovernancev1mcpresourceserviceupdaterequest +// #endregion class-body-c1apiaigovernancev1mcpresourceserviceupdaterequest + +type C1APIAiGovernanceV1MCPResourceServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // MCPResourceServiceUpdateResponse returns the updated MCP resource. + MCPResourceServiceUpdateResponse *shared.MCPResourceServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateResponse) GetMCPResourceServiceUpdateResponse() *shared.MCPResourceServiceUpdateResponse { + if c == nil { + return nil + } + return c.MCPResourceServiceUpdateResponse +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAiGovernanceV1MCPResourceServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiaigovernancev1mcpresourceserviceupdateresponse +// #endregion class-body-c1apiaigovernancev1mcpresourceserviceupdateresponse diff --git a/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuser.go b/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuser.go new file mode 100644 index 000000000..8e166ef78 --- /dev/null +++ b/pkg/models/operations/c1apiappv1appentitlementsearchservicesearchreachableresourcesforuser.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse struct { + // SearchReachableResourcesForUser response. Resources are deduplicated: a + // resource reachable through more than one grant or entitlement appears once. + AppEntitlementSearchServiceSearchReachableResourcesForUserResponse *shared.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetAppEntitlementSearchServiceSearchReachableResourcesForUserResponse() *shared.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse { + if c == nil { + return nil + } + return c.AppEntitlementSearchServiceSearchReachableResourcesForUserResponse +} + +func (c *C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAppV1AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse +// #endregion class-body-c1apiappv1appentitlementsearchservicesearchreachableresourcesforuserresponse diff --git a/pkg/models/operations/c1apiappv1appentitlementslist.go b/pkg/models/operations/c1apiappv1appentitlementslist.go index e7242ef4f..32333740e 100644 --- a/pkg/models/operations/c1apiappv1appentitlementslist.go +++ b/pkg/models/operations/c1apiappv1appentitlementslist.go @@ -9,8 +9,10 @@ import ( type C1APIAppV1AppEntitlementsListRequest struct { AppID string `pathParam:"style=simple,explode=false,name=app_id"` + AppUserID *string `queryParam:"style=form,explode=true,name=app_user_id"` PageSize *int `queryParam:"style=form,explode=true,name=page_size"` PageToken *string `queryParam:"style=form,explode=true,name=page_token"` + Q *string `queryParam:"style=form,explode=true,name=q"` } func (c *C1APIAppV1AppEntitlementsListRequest) GetAppID() string { @@ -20,6 +22,13 @@ func (c *C1APIAppV1AppEntitlementsListRequest) GetAppID() string { return c.AppID } +func (c *C1APIAppV1AppEntitlementsListRequest) GetAppUserID() *string { + if c == nil { + return nil + } + return c.AppUserID +} + func (c *C1APIAppV1AppEntitlementsListRequest) GetPageSize() *int { if c == nil { return nil @@ -34,6 +43,13 @@ func (c *C1APIAppV1AppEntitlementsListRequest) GetPageToken() *string { return c.PageToken } +func (c *C1APIAppV1AppEntitlementsListRequest) GetQ() *string { + if c == nil { + return nil + } + return c.Q +} + // #region class-body-c1apiappv1appentitlementslistrequest // #endregion class-body-c1apiappv1appentitlementslistrequest diff --git a/pkg/models/operations/c1apiappv1appmanagedstateserviceget.go b/pkg/models/operations/c1apiappv1appmanagedstateserviceget.go new file mode 100644 index 000000000..5ac207798 --- /dev/null +++ b/pkg/models/operations/c1apiappv1appmanagedstateserviceget.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAppV1AppManagedStateServiceGetRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ResourceID string `pathParam:"style=simple,explode=false,name=resource_id"` + ResourceTypeID string `pathParam:"style=simple,explode=false,name=resource_type_id"` +} + +func (c *C1APIAppV1AppManagedStateServiceGetRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAppV1AppManagedStateServiceGetRequest) GetResourceID() string { + if c == nil { + return "" + } + return c.ResourceID +} + +func (c *C1APIAppV1AppManagedStateServiceGetRequest) GetResourceTypeID() string { + if c == nil { + return "" + } + return c.ResourceTypeID +} + +// #region class-body-c1apiappv1appmanagedstateservicegetrequest +// #endregion class-body-c1apiappv1appmanagedstateservicegetrequest + +type C1APIAppV1AppManagedStateServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // GetAppManagedStateBindingResponse contains the managed state of a discovered application. + GetAppManagedStateBindingResponse *shared.GetAppManagedStateBindingResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAppV1AppManagedStateServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAppV1AppManagedStateServiceGetResponse) GetGetAppManagedStateBindingResponse() *shared.GetAppManagedStateBindingResponse { + if c == nil { + return nil + } + return c.GetAppManagedStateBindingResponse +} + +func (c *C1APIAppV1AppManagedStateServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAppV1AppManagedStateServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiappv1appmanagedstateservicegetresponse +// #endregion class-body-c1apiappv1appmanagedstateservicegetresponse diff --git a/pkg/models/operations/c1apiappv1appmanagedstateservicelist.go b/pkg/models/operations/c1apiappv1appmanagedstateservicelist.go new file mode 100644 index 000000000..a7a5ef79a --- /dev/null +++ b/pkg/models/operations/c1apiappv1appmanagedstateservicelist.go @@ -0,0 +1,88 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAppV1AppManagedStateServiceListRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` + ResourceTypeID string `pathParam:"style=simple,explode=false,name=resource_type_id"` +} + +func (c *C1APIAppV1AppManagedStateServiceListRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAppV1AppManagedStateServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIAppV1AppManagedStateServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +func (c *C1APIAppV1AppManagedStateServiceListRequest) GetResourceTypeID() string { + if c == nil { + return "" + } + return c.ResourceTypeID +} + +// #region class-body-c1apiappv1appmanagedstateservicelistrequest +// #endregion class-body-c1apiappv1appmanagedstateservicelistrequest + +type C1APIAppV1AppManagedStateServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // ListAppManagedStateBindingsResponse contains one page of discovered application managed states. + ListAppManagedStateBindingsResponse *shared.ListAppManagedStateBindingsResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAppV1AppManagedStateServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAppV1AppManagedStateServiceListResponse) GetListAppManagedStateBindingsResponse() *shared.ListAppManagedStateBindingsResponse { + if c == nil { + return nil + } + return c.ListAppManagedStateBindingsResponse +} + +func (c *C1APIAppV1AppManagedStateServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAppV1AppManagedStateServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiappv1appmanagedstateservicelistresponse +// #endregion class-body-c1apiappv1appmanagedstateservicelistresponse diff --git a/pkg/models/operations/c1apiappv1appmanagedstateservicepromote.go b/pkg/models/operations/c1apiappv1appmanagedstateservicepromote.go new file mode 100644 index 000000000..2f08a265a --- /dev/null +++ b/pkg/models/operations/c1apiappv1appmanagedstateservicepromote.go @@ -0,0 +1,88 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIAppV1AppManagedStateServicePromoteRequest struct { + PromoteAppManagedStateBindingRequest *shared.PromoteAppManagedStateBindingRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ResourceID string `pathParam:"style=simple,explode=false,name=resource_id"` + ResourceTypeID string `pathParam:"style=simple,explode=false,name=resource_type_id"` +} + +func (c *C1APIAppV1AppManagedStateServicePromoteRequest) GetPromoteAppManagedStateBindingRequest() *shared.PromoteAppManagedStateBindingRequest { + if c == nil { + return nil + } + return c.PromoteAppManagedStateBindingRequest +} + +func (c *C1APIAppV1AppManagedStateServicePromoteRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIAppV1AppManagedStateServicePromoteRequest) GetResourceID() string { + if c == nil { + return "" + } + return c.ResourceID +} + +func (c *C1APIAppV1AppManagedStateServicePromoteRequest) GetResourceTypeID() string { + if c == nil { + return "" + } + return c.ResourceTypeID +} + +// #region class-body-c1apiappv1appmanagedstateservicepromoterequest +// #endregion class-body-c1apiappv1appmanagedstateservicepromoterequest + +type C1APIAppV1AppManagedStateServicePromoteResponse struct { + // HTTP response content type for this operation + ContentType string + // GetAppManagedStateBindingResponse contains the managed state of a discovered application. + GetAppManagedStateBindingResponse *shared.GetAppManagedStateBindingResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIAppV1AppManagedStateServicePromoteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIAppV1AppManagedStateServicePromoteResponse) GetGetAppManagedStateBindingResponse() *shared.GetAppManagedStateBindingResponse { + if c == nil { + return nil + } + return c.GetAppManagedStateBindingResponse +} + +func (c *C1APIAppV1AppManagedStateServicePromoteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIAppV1AppManagedStateServicePromoteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiappv1appmanagedstateservicepromoteresponse +// #endregion class-body-c1apiappv1appmanagedstateservicepromoteresponse diff --git a/pkg/models/operations/c1apiappv1appscreate.go b/pkg/models/operations/c1apiappv1appscreate.go index 7938303e3..f79d86540 100644 --- a/pkg/models/operations/c1apiappv1appscreate.go +++ b/pkg/models/operations/c1apiappv1appscreate.go @@ -10,7 +10,7 @@ import ( type C1APIAppV1AppsCreateResponse struct { // HTTP response content type for this operation ContentType string - // Returns the new app's values. + // CreateAppResponse contains the newly created application. CreateAppResponse *shared.CreateAppResponse // HTTP response status code for this operation StatusCode int diff --git a/pkg/models/operations/c1apiappv1connectorserviceforcesync.go b/pkg/models/operations/c1apiappv1connectorserviceforcesync.go index a1e60cc2f..0e5697549 100644 --- a/pkg/models/operations/c1apiappv1connectorserviceforcesync.go +++ b/pkg/models/operations/c1apiappv1connectorserviceforcesync.go @@ -40,7 +40,8 @@ func (c *C1APIAppV1ConnectorServiceForceSyncRequest) GetConnectorID() string { type C1APIAppV1ConnectorServiceForceSyncResponse struct { // HTTP response content type for this operation ContentType string - // Empty response body. Status code indicates success. + // Empty response body. Status code indicates success. Poll the connector sync status + // for progress after ForceSync accepts the request. ForceSyncResponse *shared.ForceSyncResponse // HTTP response status code for this operation StatusCode int diff --git a/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsession.go b/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsession.go new file mode 100644 index 000000000..49e1ec059 --- /dev/null +++ b/pkg/models/operations/c1apiconversationsv1uiconversationsserviceensureonboardingsession.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse struct { + // HTTP response content type for this operation + ContentType string + // Returns the active onboarding conversation and whether this call created it. + EnsureOnboardingSessionResponse *shared.EnsureOnboardingSessionResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse) GetEnsureOnboardingSessionResponse() *shared.EnsureOnboardingSessionResponse { + if c == nil { + return nil + } + return c.EnsureOnboardingSessionResponse +} + +func (c *C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse +// #endregion class-body-c1apiconversationsv1uiconversationsserviceensureonboardingsessionresponse diff --git a/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettings.go b/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettings.go new file mode 100644 index 000000000..fb574cf72 --- /dev/null +++ b/pkg/models/operations/c1apifindingv1findingsettingsservicelistfindingsettings.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ListFindingSettingsResponse *shared.ListFindingSettingsResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse) GetListFindingSettingsResponse() *shared.ListFindingSettingsResponse { + if c == nil { + return nil + } + return c.ListFindingSettingsResponse +} + +func (c *C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFindingV1FindingSettingsServiceListFindingSettingsResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifindingv1findingsettingsservicelistfindingsettingsresponse +// #endregion class-body-c1apifindingv1findingsettingsservicelistfindingsettingsresponse diff --git a/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettings.go b/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettings.go new file mode 100644 index 000000000..9775aa498 --- /dev/null +++ b/pkg/models/operations/c1apifindingv1findingsettingsserviceupdatefindingsettings.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse struct { + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response + // Successful response + UpdateFindingSettingsResponse *shared.UpdateFindingSettingsResponse +} + +func (c *C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +func (c *C1APIFindingV1FindingSettingsServiceUpdateFindingSettingsResponse) GetUpdateFindingSettingsResponse() *shared.UpdateFindingSettingsResponse { + if c == nil { + return nil + } + return c.UpdateFindingSettingsResponse +} + +// #region class-body-c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse +// #endregion class-body-c1apifindingv1findingsettingsserviceupdatefindingsettingsresponse diff --git a/pkg/models/operations/c1apifundsv1appcapservicedelete.go b/pkg/models/operations/c1apifundsv1appcapservicedelete.go new file mode 100644 index 000000000..2fde51ca4 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapservicedelete.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceDeleteRequest struct { + AppCapServiceDeleteRequest *shared.AppCapServiceDeleteRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1AppCapServiceDeleteRequest) GetAppCapServiceDeleteRequest() *shared.AppCapServiceDeleteRequest { + if c == nil { + return nil + } + return c.AppCapServiceDeleteRequest +} + +func (c *C1APIFundsV1AppCapServiceDeleteRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1appcapservicedeleterequest +// #endregion class-body-c1apifundsv1appcapservicedeleterequest + +type C1APIFundsV1AppCapServiceDeleteResponse struct { + // Successful response + AppCapServiceDeleteResponse *shared.AppCapServiceDeleteResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceDeleteResponse) GetAppCapServiceDeleteResponse() *shared.AppCapServiceDeleteResponse { + if c == nil { + return nil + } + return c.AppCapServiceDeleteResponse +} + +func (c *C1APIFundsV1AppCapServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicedeleteresponse +// #endregion class-body-c1apifundsv1appcapservicedeleteresponse diff --git a/pkg/models/operations/c1apifundsv1appcapserviceget.go b/pkg/models/operations/c1apifundsv1appcapserviceget.go new file mode 100644 index 000000000..1e0b0e243 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapserviceget.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceGetRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1AppCapServiceGetRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1appcapservicegetrequest +// #endregion class-body-c1apifundsv1appcapservicegetrequest + +type C1APIFundsV1AppCapServiceGetResponse struct { + // Successful response + AppCapServiceGetResponse *shared.AppCapServiceGetResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceGetResponse) GetAppCapServiceGetResponse() *shared.AppCapServiceGetResponse { + if c == nil { + return nil + } + return c.AppCapServiceGetResponse +} + +func (c *C1APIFundsV1AppCapServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicegetresponse +// #endregion class-body-c1apifundsv1appcapservicegetresponse diff --git a/pkg/models/operations/c1apifundsv1appcapservicelist.go b/pkg/models/operations/c1apifundsv1appcapservicelist.go new file mode 100644 index 000000000..61eb15a81 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapservicelist.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceListRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1AppCapServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1AppCapServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1appcapservicelistrequest +// #endregion class-body-c1apifundsv1appcapservicelistrequest + +type C1APIFundsV1AppCapServiceListResponse struct { + // Successful response + AppCapServiceListResponse *shared.AppCapServiceListResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceListResponse) GetAppCapServiceListResponse() *shared.AppCapServiceListResponse { + if c == nil { + return nil + } + return c.AppCapServiceListResponse +} + +func (c *C1APIFundsV1AppCapServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicelistresponse +// #endregion class-body-c1apifundsv1appcapservicelistresponse diff --git a/pkg/models/operations/c1apifundsv1appcapservicelisthistory.go b/pkg/models/operations/c1apifundsv1appcapservicelisthistory.go new file mode 100644 index 000000000..7aa4064a8 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapservicelisthistory.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceListHistoryRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1AppCapServiceListHistoryRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIFundsV1AppCapServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1AppCapServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1appcapservicelisthistoryrequest +// #endregion class-body-c1apifundsv1appcapservicelisthistoryrequest + +type C1APIFundsV1AppCapServiceListHistoryResponse struct { + // Successful response + AppCapServiceListHistoryResponse *shared.AppCapServiceListHistoryResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceListHistoryResponse) GetAppCapServiceListHistoryResponse() *shared.AppCapServiceListHistoryResponse { + if c == nil { + return nil + } + return c.AppCapServiceListHistoryResponse +} + +func (c *C1APIFundsV1AppCapServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicelisthistoryresponse +// #endregion class-body-c1apifundsv1appcapservicelisthistoryresponse diff --git a/pkg/models/operations/c1apifundsv1appcapservicesetlimit.go b/pkg/models/operations/c1apifundsv1appcapservicesetlimit.go new file mode 100644 index 000000000..4e5f46307 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapservicesetlimit.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceSetLimitRequest struct { + AppCapServiceSetLimitRequest *shared.AppCapServiceSetLimitRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1AppCapServiceSetLimitRequest) GetAppCapServiceSetLimitRequest() *shared.AppCapServiceSetLimitRequest { + if c == nil { + return nil + } + return c.AppCapServiceSetLimitRequest +} + +func (c *C1APIFundsV1AppCapServiceSetLimitRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1appcapservicesetlimitrequest +// #endregion class-body-c1apifundsv1appcapservicesetlimitrequest + +type C1APIFundsV1AppCapServiceSetLimitResponse struct { + // Successful response + AppCapServiceSetLimitResponse *shared.AppCapServiceSetLimitResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceSetLimitResponse) GetAppCapServiceSetLimitResponse() *shared.AppCapServiceSetLimitResponse { + if c == nil { + return nil + } + return c.AppCapServiceSetLimitResponse +} + +func (c *C1APIFundsV1AppCapServiceSetLimitResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceSetLimitResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceSetLimitResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicesetlimitresponse +// #endregion class-body-c1apifundsv1appcapservicesetlimitresponse diff --git a/pkg/models/operations/c1apifundsv1appcapservicesuspend.go b/pkg/models/operations/c1apifundsv1appcapservicesuspend.go new file mode 100644 index 000000000..46a04a4e7 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapservicesuspend.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceSuspendRequest struct { + AppCapServiceSuspendRequest *shared.AppCapServiceSuspendRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1AppCapServiceSuspendRequest) GetAppCapServiceSuspendRequest() *shared.AppCapServiceSuspendRequest { + if c == nil { + return nil + } + return c.AppCapServiceSuspendRequest +} + +func (c *C1APIFundsV1AppCapServiceSuspendRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1appcapservicesuspendrequest +// #endregion class-body-c1apifundsv1appcapservicesuspendrequest + +type C1APIFundsV1AppCapServiceSuspendResponse struct { + // Successful response + AppCapServiceSuspendResponse *shared.AppCapServiceSuspendResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceSuspendResponse) GetAppCapServiceSuspendResponse() *shared.AppCapServiceSuspendResponse { + if c == nil { + return nil + } + return c.AppCapServiceSuspendResponse +} + +func (c *C1APIFundsV1AppCapServiceSuspendResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceSuspendResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceSuspendResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapservicesuspendresponse +// #endregion class-body-c1apifundsv1appcapservicesuspendresponse diff --git a/pkg/models/operations/c1apifundsv1appcapserviceunsuspend.go b/pkg/models/operations/c1apifundsv1appcapserviceunsuspend.go new file mode 100644 index 000000000..a56c83d06 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1appcapserviceunsuspend.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1AppCapServiceUnsuspendRequest struct { + AppCapServiceUnsuspendRequest *shared.AppCapServiceUnsuspendRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendRequest) GetAppCapServiceUnsuspendRequest() *shared.AppCapServiceUnsuspendRequest { + if c == nil { + return nil + } + return c.AppCapServiceUnsuspendRequest +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1appcapserviceunsuspendrequest +// #endregion class-body-c1apifundsv1appcapserviceunsuspendrequest + +type C1APIFundsV1AppCapServiceUnsuspendResponse struct { + // Successful response + AppCapServiceUnsuspendResponse *shared.AppCapServiceUnsuspendResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendResponse) GetAppCapServiceUnsuspendResponse() *shared.AppCapServiceUnsuspendResponse { + if c == nil { + return nil + } + return c.AppCapServiceUnsuspendResponse +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1AppCapServiceUnsuspendResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1appcapserviceunsuspendresponse +// #endregion class-body-c1apifundsv1appcapserviceunsuspendresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextension.go b/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextension.go new file mode 100644 index 000000000..d84ed8f71 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentserviceclearextension.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceClearExtensionRequest struct { + FundAssignmentServiceClearExtensionRequest *shared.FundAssignmentServiceClearExtensionRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionRequest) GetFundAssignmentServiceClearExtensionRequest() *shared.FundAssignmentServiceClearExtensionRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceClearExtensionRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentserviceclearextensionrequest +// #endregion class-body-c1apifundsv1fundassignmentserviceclearextensionrequest + +type C1APIFundsV1FundAssignmentServiceClearExtensionResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceClearExtensionResponse *shared.FundAssignmentServiceClearExtensionResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionResponse) GetFundAssignmentServiceClearExtensionResponse() *shared.FundAssignmentServiceClearExtensionResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceClearExtensionResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceClearExtensionResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentserviceclearextensionresponse +// #endregion class-body-c1apifundsv1fundassignmentserviceclearextensionresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicedelete.go b/pkg/models/operations/c1apifundsv1fundassignmentservicedelete.go new file mode 100644 index 000000000..9cfca0980 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicedelete.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceDeleteRequest struct { + FundAssignmentServiceDeleteRequest *shared.FundAssignmentServiceDeleteRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteRequest) GetFundAssignmentServiceDeleteRequest() *shared.FundAssignmentServiceDeleteRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceDeleteRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicedeleterequest +// #endregion class-body-c1apifundsv1fundassignmentservicedeleterequest + +type C1APIFundsV1FundAssignmentServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceDeleteResponse *shared.FundAssignmentServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteResponse) GetFundAssignmentServiceDeleteResponse() *shared.FundAssignmentServiceDeleteResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceDeleteResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicedeleteresponse +// #endregion class-body-c1apifundsv1fundassignmentservicedeleteresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentserviceget.go b/pkg/models/operations/c1apifundsv1fundassignmentserviceget.go new file mode 100644 index 000000000..c4ae3a833 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentserviceget.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceGetRequest struct { + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceGetRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicegetrequest +// #endregion class-body-c1apifundsv1fundassignmentservicegetrequest + +type C1APIFundsV1FundAssignmentServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceGetResponse *shared.FundAssignmentServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceGetResponse) GetFundAssignmentServiceGetResponse() *shared.FundAssignmentServiceGetResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceGetResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicegetresponse +// #endregion class-body-c1apifundsv1fundassignmentservicegetresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextension.go b/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextension.go new file mode 100644 index 000000000..14b1419bd --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicegrantextension.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceGrantExtensionRequest struct { + FundAssignmentServiceGrantExtensionRequest *shared.FundAssignmentServiceGrantExtensionRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionRequest) GetFundAssignmentServiceGrantExtensionRequest() *shared.FundAssignmentServiceGrantExtensionRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceGrantExtensionRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicegrantextensionrequest +// #endregion class-body-c1apifundsv1fundassignmentservicegrantextensionrequest + +type C1APIFundsV1FundAssignmentServiceGrantExtensionResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceGrantExtensionResponse *shared.FundAssignmentServiceGrantExtensionResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionResponse) GetFundAssignmentServiceGrantExtensionResponse() *shared.FundAssignmentServiceGrantExtensionResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceGrantExtensionResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceGrantExtensionResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicegrantextensionresponse +// #endregion class-body-c1apifundsv1fundassignmentservicegrantextensionresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistory.go b/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistory.go new file mode 100644 index 000000000..806b0ca9a --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicelisthistory.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceListHistoryRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicelisthistoryrequest +// #endregion class-body-c1apifundsv1fundassignmentservicelisthistoryrequest + +type C1APIFundsV1FundAssignmentServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceListHistoryResponse *shared.FundAssignmentServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryResponse) GetFundAssignmentServiceListHistoryResponse() *shared.FundAssignmentServiceListHistoryResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceListHistoryResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicelisthistoryresponse +// #endregion class-body-c1apifundsv1fundassignmentservicelisthistoryresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicesearch.go b/pkg/models/operations/c1apifundsv1fundassignmentservicesearch.go new file mode 100644 index 000000000..fdf8def86 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicesearch.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceSearchResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceSearchResponse *shared.FundAssignmentServiceSearchResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceSearchResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceSearchResponse) GetFundAssignmentServiceSearchResponse() *shared.FundAssignmentServiceSearchResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceSearchResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceSearchResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceSearchResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicesearchresponse +// #endregion class-body-c1apifundsv1fundassignmentservicesearchresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimit.go b/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimit.go new file mode 100644 index 000000000..8182b9f83 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicesetlimit.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceSetLimitRequest struct { + FundAssignmentServiceSetLimitRequest *shared.FundAssignmentServiceSetLimitRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitRequest) GetFundAssignmentServiceSetLimitRequest() *shared.FundAssignmentServiceSetLimitRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceSetLimitRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicesetlimitrequest +// #endregion class-body-c1apifundsv1fundassignmentservicesetlimitrequest + +type C1APIFundsV1FundAssignmentServiceSetLimitResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceSetLimitResponse *shared.FundAssignmentServiceSetLimitResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitResponse) GetFundAssignmentServiceSetLimitResponse() *shared.FundAssignmentServiceSetLimitResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceSetLimitResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceSetLimitResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicesetlimitresponse +// #endregion class-body-c1apifundsv1fundassignmentservicesetlimitresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentservicesuspend.go b/pkg/models/operations/c1apifundsv1fundassignmentservicesuspend.go new file mode 100644 index 000000000..9ca3c1f6c --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentservicesuspend.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceSuspendRequest struct { + FundAssignmentServiceSuspendRequest *shared.FundAssignmentServiceSuspendRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendRequest) GetFundAssignmentServiceSuspendRequest() *shared.FundAssignmentServiceSuspendRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceSuspendRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentservicesuspendrequest +// #endregion class-body-c1apifundsv1fundassignmentservicesuspendrequest + +type C1APIFundsV1FundAssignmentServiceSuspendResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceSuspendResponse *shared.FundAssignmentServiceSuspendResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendResponse) GetFundAssignmentServiceSuspendResponse() *shared.FundAssignmentServiceSuspendResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceSuspendResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceSuspendResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentservicesuspendresponse +// #endregion class-body-c1apifundsv1fundassignmentservicesuspendresponse diff --git a/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspend.go b/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspend.go new file mode 100644 index 000000000..5d617a71f --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundassignmentserviceunsuspend.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundAssignmentServiceUnsuspendRequest struct { + FundAssignmentServiceUnsuspendRequest *shared.FundAssignmentServiceUnsuspendRequest `request:"mediaType=application/json"` + UserID string `pathParam:"style=simple,explode=false,name=user_id"` +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendRequest) GetFundAssignmentServiceUnsuspendRequest() *shared.FundAssignmentServiceUnsuspendRequest { + if c == nil { + return nil + } + return c.FundAssignmentServiceUnsuspendRequest +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendRequest) GetUserID() string { + if c == nil { + return "" + } + return c.UserID +} + +// #region class-body-c1apifundsv1fundassignmentserviceunsuspendrequest +// #endregion class-body-c1apifundsv1fundassignmentserviceunsuspendrequest + +type C1APIFundsV1FundAssignmentServiceUnsuspendResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundAssignmentServiceUnsuspendResponse *shared.FundAssignmentServiceUnsuspendResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendResponse) GetFundAssignmentServiceUnsuspendResponse() *shared.FundAssignmentServiceUnsuspendResponse { + if c == nil { + return nil + } + return c.FundAssignmentServiceUnsuspendResponse +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundAssignmentServiceUnsuspendResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundassignmentserviceunsuspendresponse +// #endregion class-body-c1apifundsv1fundassignmentserviceunsuspendresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyservicecreate.go b/pkg/models/operations/c1apifundsv1fundpolicyservicecreate.go new file mode 100644 index 000000000..f74b9118d --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyservicecreate.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceCreateResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceCreateResponse *shared.FundPolicyServiceCreateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceCreateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceCreateResponse) GetFundPolicyServiceCreateResponse() *shared.FundPolicyServiceCreateResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceCreateResponse +} + +func (c *C1APIFundsV1FundPolicyServiceCreateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceCreateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicecreateresponse +// #endregion class-body-c1apifundsv1fundpolicyservicecreateresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyservicedelete.go b/pkg/models/operations/c1apifundsv1fundpolicyservicedelete.go new file mode 100644 index 000000000..1bf5397d1 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyservicedelete.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceDeleteResponse *shared.FundPolicyServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceDeleteResponse) GetFundPolicyServiceDeleteResponse() *shared.FundPolicyServiceDeleteResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceDeleteResponse +} + +func (c *C1APIFundsV1FundPolicyServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicedeleteresponse +// #endregion class-body-c1apifundsv1fundpolicyservicedeleteresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenant.go b/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenant.go new file mode 100644 index 000000000..e8c43050b --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyservicefreezetenant.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceFreezeTenantResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceFreezeTenantResponse *shared.FundPolicyServiceFreezeTenantResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceFreezeTenantResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceFreezeTenantResponse) GetFundPolicyServiceFreezeTenantResponse() *shared.FundPolicyServiceFreezeTenantResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceFreezeTenantResponse +} + +func (c *C1APIFundsV1FundPolicyServiceFreezeTenantResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceFreezeTenantResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicefreezetenantresponse +// #endregion class-body-c1apifundsv1fundpolicyservicefreezetenantresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyserviceget.go b/pkg/models/operations/c1apifundsv1fundpolicyserviceget.go new file mode 100644 index 000000000..80332cb0e --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyserviceget.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceGetResponse *shared.FundPolicyServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceGetResponse) GetFundPolicyServiceGetResponse() *shared.FundPolicyServiceGetResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceGetResponse +} + +func (c *C1APIFundsV1FundPolicyServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicegetresponse +// #endregion class-body-c1apifundsv1fundpolicyservicegetresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistory.go b/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistory.go new file mode 100644 index 000000000..e30e7afe2 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyservicelisthistory.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceListHistoryRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1fundpolicyservicelisthistoryrequest +// #endregion class-body-c1apifundsv1fundpolicyservicelisthistoryrequest + +type C1APIFundsV1FundPolicyServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceListHistoryResponse *shared.FundPolicyServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryResponse) GetFundPolicyServiceListHistoryResponse() *shared.FundPolicyServiceListHistoryResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceListHistoryResponse +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicelisthistoryresponse +// #endregion class-body-c1apifundsv1fundpolicyservicelisthistoryresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceiling.go b/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceiling.go new file mode 100644 index 000000000..825c524a0 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyservicesetorgceiling.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceSetOrgCeilingResponse *shared.FundPolicyServiceSetOrgCeilingResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse) GetFundPolicyServiceSetOrgCeilingResponse() *shared.FundPolicyServiceSetOrgCeilingResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceSetOrgCeilingResponse +} + +func (c *C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceSetOrgCeilingResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyservicesetorgceilingresponse +// #endregion class-body-c1apifundsv1fundpolicyservicesetorgceilingresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenant.go b/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenant.go new file mode 100644 index 000000000..43faf6f77 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyserviceunfreezetenant.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceUnfreezeTenantResponse *shared.FundPolicyServiceUnfreezeTenantResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse) GetFundPolicyServiceUnfreezeTenantResponse() *shared.FundPolicyServiceUnfreezeTenantResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceUnfreezeTenantResponse +} + +func (c *C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceUnfreezeTenantResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyserviceunfreezetenantresponse +// #endregion class-body-c1apifundsv1fundpolicyserviceunfreezetenantresponse diff --git a/pkg/models/operations/c1apifundsv1fundpolicyserviceupdate.go b/pkg/models/operations/c1apifundsv1fundpolicyserviceupdate.go new file mode 100644 index 000000000..4373ab15c --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundpolicyserviceupdate.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundPolicyServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundPolicyServiceUpdateResponse *shared.FundPolicyServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundPolicyServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundPolicyServiceUpdateResponse) GetFundPolicyServiceUpdateResponse() *shared.FundPolicyServiceUpdateResponse { + if c == nil { + return nil + } + return c.FundPolicyServiceUpdateResponse +} + +func (c *C1APIFundsV1FundPolicyServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundPolicyServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundpolicyserviceupdateresponse +// #endregion class-body-c1apifundsv1fundpolicyserviceupdateresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleservicecreate.go b/pkg/models/operations/c1apifundsv1fundruleservicecreate.go new file mode 100644 index 000000000..4d6429c07 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleservicecreate.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceCreateResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceCreateResponse *shared.FundRuleServiceCreateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceCreateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceCreateResponse) GetFundRuleServiceCreateResponse() *shared.FundRuleServiceCreateResponse { + if c == nil { + return nil + } + return c.FundRuleServiceCreateResponse +} + +func (c *C1APIFundsV1FundRuleServiceCreateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceCreateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicecreateresponse +// #endregion class-body-c1apifundsv1fundruleservicecreateresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleservicedelete.go b/pkg/models/operations/c1apifundsv1fundruleservicedelete.go new file mode 100644 index 000000000..407f1bd8a --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleservicedelete.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceDeleteRequest struct { + FundRuleServiceDeleteRequest *shared.FundRuleServiceDeleteRequest `request:"mediaType=application/json"` + RuleID string `pathParam:"style=simple,explode=false,name=rule_id"` +} + +func (c *C1APIFundsV1FundRuleServiceDeleteRequest) GetFundRuleServiceDeleteRequest() *shared.FundRuleServiceDeleteRequest { + if c == nil { + return nil + } + return c.FundRuleServiceDeleteRequest +} + +func (c *C1APIFundsV1FundRuleServiceDeleteRequest) GetRuleID() string { + if c == nil { + return "" + } + return c.RuleID +} + +// #region class-body-c1apifundsv1fundruleservicedeleterequest +// #endregion class-body-c1apifundsv1fundruleservicedeleterequest + +type C1APIFundsV1FundRuleServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceDeleteResponse *shared.FundRuleServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceDeleteResponse) GetFundRuleServiceDeleteResponse() *shared.FundRuleServiceDeleteResponse { + if c == nil { + return nil + } + return c.FundRuleServiceDeleteResponse +} + +func (c *C1APIFundsV1FundRuleServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicedeleteresponse +// #endregion class-body-c1apifundsv1fundruleservicedeleteresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleserviceget.go b/pkg/models/operations/c1apifundsv1fundruleserviceget.go new file mode 100644 index 000000000..aa461677c --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleserviceget.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceGetRequest struct { + RuleID string `pathParam:"style=simple,explode=false,name=rule_id"` +} + +func (c *C1APIFundsV1FundRuleServiceGetRequest) GetRuleID() string { + if c == nil { + return "" + } + return c.RuleID +} + +// #region class-body-c1apifundsv1fundruleservicegetrequest +// #endregion class-body-c1apifundsv1fundruleservicegetrequest + +type C1APIFundsV1FundRuleServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceGetResponse *shared.FundRuleServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceGetResponse) GetFundRuleServiceGetResponse() *shared.FundRuleServiceGetResponse { + if c == nil { + return nil + } + return c.FundRuleServiceGetResponse +} + +func (c *C1APIFundsV1FundRuleServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicegetresponse +// #endregion class-body-c1apifundsv1fundruleservicegetresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleservicelist.go b/pkg/models/operations/c1apifundsv1fundruleservicelist.go new file mode 100644 index 000000000..cd5b0bcd4 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleservicelist.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceListRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1FundRuleServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1FundRuleServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1fundruleservicelistrequest +// #endregion class-body-c1apifundsv1fundruleservicelistrequest + +type C1APIFundsV1FundRuleServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceListResponse *shared.FundRuleServiceListResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceListResponse) GetFundRuleServiceListResponse() *shared.FundRuleServiceListResponse { + if c == nil { + return nil + } + return c.FundRuleServiceListResponse +} + +func (c *C1APIFundsV1FundRuleServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicelistresponse +// #endregion class-body-c1apifundsv1fundruleservicelistresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleservicelisthistory.go b/pkg/models/operations/c1apifundsv1fundruleservicelisthistory.go new file mode 100644 index 000000000..85d3d06bc --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleservicelisthistory.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceListHistoryRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` + RuleID string `pathParam:"style=simple,explode=false,name=rule_id"` +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryRequest) GetRuleID() string { + if c == nil { + return "" + } + return c.RuleID +} + +// #region class-body-c1apifundsv1fundruleservicelisthistoryrequest +// #endregion class-body-c1apifundsv1fundruleservicelisthistoryrequest + +type C1APIFundsV1FundRuleServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceListHistoryResponse *shared.FundRuleServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryResponse) GetFundRuleServiceListHistoryResponse() *shared.FundRuleServiceListHistoryResponse { + if c == nil { + return nil + } + return c.FundRuleServiceListHistoryResponse +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicelisthistoryresponse +// #endregion class-body-c1apifundsv1fundruleservicelisthistoryresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleservicesearch.go b/pkg/models/operations/c1apifundsv1fundruleservicesearch.go new file mode 100644 index 000000000..e06c7e331 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleservicesearch.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceSearchResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceSearchResponse *shared.FundRuleServiceSearchResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceSearchResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceSearchResponse) GetFundRuleServiceSearchResponse() *shared.FundRuleServiceSearchResponse { + if c == nil { + return nil + } + return c.FundRuleServiceSearchResponse +} + +func (c *C1APIFundsV1FundRuleServiceSearchResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceSearchResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleservicesearchresponse +// #endregion class-body-c1apifundsv1fundruleservicesearchresponse diff --git a/pkg/models/operations/c1apifundsv1fundruleserviceupdate.go b/pkg/models/operations/c1apifundsv1fundruleserviceupdate.go new file mode 100644 index 000000000..6c6215527 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1fundruleserviceupdate.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1FundRuleServiceUpdateRequest struct { + FundRuleServiceUpdateRequest *shared.FundRuleServiceUpdateRequest `request:"mediaType=application/json"` + RuleID string `pathParam:"style=simple,explode=false,name=rule_id"` +} + +func (c *C1APIFundsV1FundRuleServiceUpdateRequest) GetFundRuleServiceUpdateRequest() *shared.FundRuleServiceUpdateRequest { + if c == nil { + return nil + } + return c.FundRuleServiceUpdateRequest +} + +func (c *C1APIFundsV1FundRuleServiceUpdateRequest) GetRuleID() string { + if c == nil { + return "" + } + return c.RuleID +} + +// #region class-body-c1apifundsv1fundruleserviceupdaterequest +// #endregion class-body-c1apifundsv1fundruleserviceupdaterequest + +type C1APIFundsV1FundRuleServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + FundRuleServiceUpdateResponse *shared.FundRuleServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1FundRuleServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1FundRuleServiceUpdateResponse) GetFundRuleServiceUpdateResponse() *shared.FundRuleServiceUpdateResponse { + if c == nil { + return nil + } + return c.FundRuleServiceUpdateResponse +} + +func (c *C1APIFundsV1FundRuleServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1FundRuleServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1fundruleserviceupdateresponse +// #endregion class-body-c1apifundsv1fundruleserviceupdateresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsservicedelete.go b/pkg/models/operations/c1apifundsv1myfundlimitsservicedelete.go new file mode 100644 index 000000000..0c414db4c --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsservicedelete.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServiceDeleteRequest struct { + MyFundLimitsServiceDeleteRequest *shared.MyFundLimitsServiceDeleteRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteRequest) GetMyFundLimitsServiceDeleteRequest() *shared.MyFundLimitsServiceDeleteRequest { + if c == nil { + return nil + } + return c.MyFundLimitsServiceDeleteRequest +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1myfundlimitsservicedeleterequest +// #endregion class-body-c1apifundsv1myfundlimitsservicedeleterequest + +type C1APIFundsV1MyFundLimitsServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServiceDeleteResponse *shared.MyFundLimitsServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteResponse) GetMyFundLimitsServiceDeleteResponse() *shared.MyFundLimitsServiceDeleteResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServiceDeleteResponse +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsservicedeleteresponse +// #endregion class-body-c1apifundsv1myfundlimitsservicedeleteresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsservicelist.go b/pkg/models/operations/c1apifundsv1myfundlimitsservicelist.go new file mode 100644 index 000000000..c60fc9785 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsservicelist.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServiceListRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1MyFundLimitsServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1MyFundLimitsServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1myfundlimitsservicelistrequest +// #endregion class-body-c1apifundsv1myfundlimitsservicelistrequest + +type C1APIFundsV1MyFundLimitsServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServiceListResponse *shared.MyFundLimitsServiceListResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServiceListResponse) GetMyFundLimitsServiceListResponse() *shared.MyFundLimitsServiceListResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServiceListResponse +} + +func (c *C1APIFundsV1MyFundLimitsServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsservicelistresponse +// #endregion class-body-c1apifundsv1myfundlimitsservicelistresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistory.go b/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistory.go new file mode 100644 index 000000000..a27c380d5 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsservicelisthistory.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServiceListHistoryRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apifundsv1myfundlimitsservicelisthistoryrequest +// #endregion class-body-c1apifundsv1myfundlimitsservicelisthistoryrequest + +type C1APIFundsV1MyFundLimitsServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServiceListHistoryResponse *shared.MyFundLimitsServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryResponse) GetMyFundLimitsServiceListHistoryResponse() *shared.MyFundLimitsServiceListHistoryResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServiceListHistoryResponse +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsservicelisthistoryresponse +// #endregion class-body-c1apifundsv1myfundlimitsservicelisthistoryresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsservicepause.go b/pkg/models/operations/c1apifundsv1myfundlimitsservicepause.go new file mode 100644 index 000000000..87f79d729 --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsservicepause.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServicePauseRequest struct { + MyFundLimitsServicePauseRequest *shared.MyFundLimitsServicePauseRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseRequest) GetMyFundLimitsServicePauseRequest() *shared.MyFundLimitsServicePauseRequest { + if c == nil { + return nil + } + return c.MyFundLimitsServicePauseRequest +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1myfundlimitsservicepauserequest +// #endregion class-body-c1apifundsv1myfundlimitsservicepauserequest + +type C1APIFundsV1MyFundLimitsServicePauseResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServicePauseResponse *shared.MyFundLimitsServicePauseResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseResponse) GetMyFundLimitsServicePauseResponse() *shared.MyFundLimitsServicePauseResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServicePauseResponse +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServicePauseResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsservicepauseresponse +// #endregion class-body-c1apifundsv1myfundlimitsservicepauseresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsserviceresume.go b/pkg/models/operations/c1apifundsv1myfundlimitsserviceresume.go new file mode 100644 index 000000000..980d507cb --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsserviceresume.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServiceResumeRequest struct { + MyFundLimitsServiceResumeRequest *shared.MyFundLimitsServiceResumeRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeRequest) GetMyFundLimitsServiceResumeRequest() *shared.MyFundLimitsServiceResumeRequest { + if c == nil { + return nil + } + return c.MyFundLimitsServiceResumeRequest +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1myfundlimitsserviceresumerequest +// #endregion class-body-c1apifundsv1myfundlimitsserviceresumerequest + +type C1APIFundsV1MyFundLimitsServiceResumeResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServiceResumeResponse *shared.MyFundLimitsServiceResumeResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeResponse) GetMyFundLimitsServiceResumeResponse() *shared.MyFundLimitsServiceResumeResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServiceResumeResponse +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServiceResumeResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsserviceresumeresponse +// #endregion class-body-c1apifundsv1myfundlimitsserviceresumeresponse diff --git a/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimit.go b/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimit.go new file mode 100644 index 000000000..fecfe6f7c --- /dev/null +++ b/pkg/models/operations/c1apifundsv1myfundlimitsservicesetlimit.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIFundsV1MyFundLimitsServiceSetLimitRequest struct { + MyFundLimitsServiceSetLimitRequest *shared.MyFundLimitsServiceSetLimitRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitRequest) GetMyFundLimitsServiceSetLimitRequest() *shared.MyFundLimitsServiceSetLimitRequest { + if c == nil { + return nil + } + return c.MyFundLimitsServiceSetLimitRequest +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apifundsv1myfundlimitsservicesetlimitrequest +// #endregion class-body-c1apifundsv1myfundlimitsservicesetlimitrequest + +type C1APIFundsV1MyFundLimitsServiceSetLimitResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MyFundLimitsServiceSetLimitResponse *shared.MyFundLimitsServiceSetLimitResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitResponse) GetMyFundLimitsServiceSetLimitResponse() *shared.MyFundLimitsServiceSetLimitResponse { + if c == nil { + return nil + } + return c.MyFundLimitsServiceSetLimitResponse +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIFundsV1MyFundLimitsServiceSetLimitResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apifundsv1myfundlimitsservicesetlimitresponse +// #endregion class-body-c1apifundsv1myfundlimitsservicesetlimitresponse diff --git a/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelist.go b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelist.go new file mode 100644 index 000000000..47edd2584 --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicelist.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1GatewayKeyServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ListGatewayKeysResponse *shared.ListGatewayKeysResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceListResponse) GetListGatewayKeysResponse() *shared.ListGatewayKeysResponse { + if c == nil { + return nil + } + return c.ListGatewayKeysResponse +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1gatewaykeyservicelistresponse +// #endregion class-body-c1apillmgatewayv1gatewaykeyservicelistresponse diff --git a/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemint.go b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemint.go new file mode 100644 index 000000000..285e151b2 --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicemint.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1GatewayKeyServiceMintResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + MintGatewayKeyResponse *shared.MintGatewayKeyResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceMintResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceMintResponse) GetMintGatewayKeyResponse() *shared.MintGatewayKeyResponse { + if c == nil { + return nil + } + return c.MintGatewayKeyResponse +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceMintResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceMintResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1gatewaykeyservicemintresponse +// #endregion class-body-c1apillmgatewayv1gatewaykeyservicemintresponse diff --git a/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevoke.go b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevoke.go new file mode 100644 index 000000000..fa2e5076a --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1gatewaykeyservicerevoke.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1GatewayKeyServiceRevokeRequest struct { + RevokeGatewayKeyRequest *shared.RevokeGatewayKeyRequest `request:"mediaType=application/json"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeRequest) GetRevokeGatewayKeyRequest() *shared.RevokeGatewayKeyRequest { + if c == nil { + return nil + } + return c.RevokeGatewayKeyRequest +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apillmgatewayv1gatewaykeyservicerevokerequest +// #endregion class-body-c1apillmgatewayv1gatewaykeyservicerevokerequest + +type C1APILlmGatewayV1GatewayKeyServiceRevokeResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + RevokeGatewayKeyResponse *shared.RevokeGatewayKeyResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeResponse) GetRevokeGatewayKeyResponse() *shared.RevokeGatewayKeyResponse { + if c == nil { + return nil + } + return c.RevokeGatewayKeyResponse +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1GatewayKeyServiceRevokeResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1gatewaykeyservicerevokeresponse +// #endregion class-body-c1apillmgatewayv1gatewaykeyservicerevokeresponse diff --git a/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclear.go b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclear.go new file mode 100644 index 000000000..1db108f8d --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceclear.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1ProviderCredentialServiceClearRequest struct { + ClearProviderCredentialRequest *shared.ClearProviderCredentialRequest `request:"mediaType=application/json"` + SlotID string `pathParam:"style=simple,explode=false,name=slot_id"` +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearRequest) GetClearProviderCredentialRequest() *shared.ClearProviderCredentialRequest { + if c == nil { + return nil + } + return c.ClearProviderCredentialRequest +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearRequest) GetSlotID() string { + if c == nil { + return "" + } + return c.SlotID +} + +// #region class-body-c1apillmgatewayv1providercredentialserviceclearrequest +// #endregion class-body-c1apillmgatewayv1providercredentialserviceclearrequest + +type C1APILlmGatewayV1ProviderCredentialServiceClearResponse struct { + // Successful response + ClearProviderCredentialResponse *shared.ClearProviderCredentialResponse + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearResponse) GetClearProviderCredentialResponse() *shared.ClearProviderCredentialResponse { + if c == nil { + return nil + } + return c.ClearProviderCredentialResponse +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceClearResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1providercredentialserviceclearresponse +// #endregion class-body-c1apillmgatewayv1providercredentialserviceclearresponse diff --git a/pkg/models/operations/c1apillmgatewayv1providercredentialserviceget.go b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceget.go new file mode 100644 index 000000000..33d1e86cb --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceget.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1ProviderCredentialServiceGetRequest struct { + SlotID string `pathParam:"style=simple,explode=false,name=slot_id"` +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceGetRequest) GetSlotID() string { + if c == nil { + return "" + } + return c.SlotID +} + +// #region class-body-c1apillmgatewayv1providercredentialservicegetrequest +// #endregion class-body-c1apillmgatewayv1providercredentialservicegetrequest + +type C1APILlmGatewayV1ProviderCredentialServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + GetProviderCredentialResponse *shared.GetProviderCredentialResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceGetResponse) GetGetProviderCredentialResponse() *shared.GetProviderCredentialResponse { + if c == nil { + return nil + } + return c.GetProviderCredentialResponse +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1providercredentialservicegetresponse +// #endregion class-body-c1apillmgatewayv1providercredentialservicegetresponse diff --git a/pkg/models/operations/c1apillmgatewayv1providercredentialserviceset.go b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceset.go new file mode 100644 index 000000000..940bb453b --- /dev/null +++ b/pkg/models/operations/c1apillmgatewayv1providercredentialserviceset.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APILlmGatewayV1ProviderCredentialServiceSetRequest struct { + SetProviderCredentialRequest *shared.SetProviderCredentialRequest `request:"mediaType=application/json"` + SlotID string `pathParam:"style=simple,explode=false,name=slot_id"` +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetRequest) GetSetProviderCredentialRequest() *shared.SetProviderCredentialRequest { + if c == nil { + return nil + } + return c.SetProviderCredentialRequest +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetRequest) GetSlotID() string { + if c == nil { + return "" + } + return c.SlotID +} + +// #region class-body-c1apillmgatewayv1providercredentialservicesetrequest +// #endregion class-body-c1apillmgatewayv1providercredentialservicesetrequest + +type C1APILlmGatewayV1ProviderCredentialServiceSetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + SetProviderCredentialResponse *shared.SetProviderCredentialResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetResponse) GetSetProviderCredentialResponse() *shared.SetProviderCredentialResponse { + if c == nil { + return nil + } + return c.SetProviderCredentialResponse +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APILlmGatewayV1ProviderCredentialServiceSetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apillmgatewayv1providercredentialservicesetresponse +// #endregion class-body-c1apillmgatewayv1providercredentialservicesetresponse diff --git a/pkg/models/operations/c1apireportingv1reportingservicedelete.go b/pkg/models/operations/c1apireportingv1reportingservicedelete.go new file mode 100644 index 000000000..da447e15f --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingservicedelete.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceDeleteRequest struct { + ReportingServiceDeleteRequest *shared.ReportingServiceDeleteRequest `request:"mediaType=application/json"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIReportingV1ReportingServiceDeleteRequest) GetReportingServiceDeleteRequest() *shared.ReportingServiceDeleteRequest { + if c == nil { + return nil + } + return c.ReportingServiceDeleteRequest +} + +func (c *C1APIReportingV1ReportingServiceDeleteRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apireportingv1reportingservicedeleterequest +// #endregion class-body-c1apireportingv1reportingservicedeleterequest + +type C1APIReportingV1ReportingServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceDeleteResponse *shared.ReportingServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceDeleteResponse) GetReportingServiceDeleteResponse() *shared.ReportingServiceDeleteResponse { + if c == nil { + return nil + } + return c.ReportingServiceDeleteResponse +} + +func (c *C1APIReportingV1ReportingServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicedeleteresponse +// #endregion class-body-c1apireportingv1reportingservicedeleteresponse diff --git a/pkg/models/operations/c1apireportingv1reportingserviceget.go b/pkg/models/operations/c1apireportingv1reportingserviceget.go new file mode 100644 index 000000000..665cbb2ed --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingserviceget.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceGetRequest struct { + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIReportingV1ReportingServiceGetRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apireportingv1reportingservicegetrequest +// #endregion class-body-c1apireportingv1reportingservicegetrequest + +type C1APIReportingV1ReportingServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceGetResponse *shared.ReportingServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceGetResponse) GetReportingServiceGetResponse() *shared.ReportingServiceGetResponse { + if c == nil { + return nil + } + return c.ReportingServiceGetResponse +} + +func (c *C1APIReportingV1ReportingServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicegetresponse +// #endregion class-body-c1apireportingv1reportingservicegetresponse diff --git a/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenance.go b/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenance.go new file mode 100644 index 000000000..b662ee015 --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingservicegetrunprovenance.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceGetRunProvenanceRequest struct { + ID string `pathParam:"style=simple,explode=false,name=id"` + RunID string `pathParam:"style=simple,explode=false,name=run_id"` +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceRequest) GetRunID() string { + if c == nil { + return "" + } + return c.RunID +} + +// #region class-body-c1apireportingv1reportingservicegetrunprovenancerequest +// #endregion class-body-c1apireportingv1reportingservicegetrunprovenancerequest + +type C1APIReportingV1ReportingServiceGetRunProvenanceResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceGetRunProvenanceResponse *shared.ReportingServiceGetRunProvenanceResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceResponse) GetReportingServiceGetRunProvenanceResponse() *shared.ReportingServiceGetRunProvenanceResponse { + if c == nil { + return nil + } + return c.ReportingServiceGetRunProvenanceResponse +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceGetRunProvenanceResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicegetrunprovenanceresponse +// #endregion class-body-c1apireportingv1reportingservicegetrunprovenanceresponse diff --git a/pkg/models/operations/c1apireportingv1reportingservicelist.go b/pkg/models/operations/c1apireportingv1reportingservicelist.go new file mode 100644 index 000000000..659c4ff05 --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingservicelist.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceListRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APIReportingV1ReportingServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APIReportingV1ReportingServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apireportingv1reportingservicelistrequest +// #endregion class-body-c1apireportingv1reportingservicelistrequest + +type C1APIReportingV1ReportingServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceListResponse *shared.ReportingServiceListResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceListResponse) GetReportingServiceListResponse() *shared.ReportingServiceListResponse { + if c == nil { + return nil + } + return c.ReportingServiceListResponse +} + +func (c *C1APIReportingV1ReportingServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicelistresponse +// #endregion class-body-c1apireportingv1reportingservicelistresponse diff --git a/pkg/models/operations/c1apireportingv1reportingservicerun.go b/pkg/models/operations/c1apireportingv1reportingservicerun.go new file mode 100644 index 000000000..f36dff36a --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingservicerun.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceRunRequest struct { + ReportingServiceRunRequest *shared.ReportingServiceRunRequest `request:"mediaType=application/json"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIReportingV1ReportingServiceRunRequest) GetReportingServiceRunRequest() *shared.ReportingServiceRunRequest { + if c == nil { + return nil + } + return c.ReportingServiceRunRequest +} + +func (c *C1APIReportingV1ReportingServiceRunRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apireportingv1reportingservicerunrequest +// #endregion class-body-c1apireportingv1reportingservicerunrequest + +type C1APIReportingV1ReportingServiceRunResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceRunResponse *shared.ReportingServiceRunResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceRunResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceRunResponse) GetReportingServiceRunResponse() *shared.ReportingServiceRunResponse { + if c == nil { + return nil + } + return c.ReportingServiceRunResponse +} + +func (c *C1APIReportingV1ReportingServiceRunResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceRunResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicerunresponse +// #endregion class-body-c1apireportingv1reportingservicerunresponse diff --git a/pkg/models/operations/c1apireportingv1reportingservicesave.go b/pkg/models/operations/c1apireportingv1reportingservicesave.go new file mode 100644 index 000000000..a87ddd14f --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingservicesave.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceSaveResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceSaveResponse *shared.ReportingServiceSaveResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceSaveResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceSaveResponse) GetReportingServiceSaveResponse() *shared.ReportingServiceSaveResponse { + if c == nil { + return nil + } + return c.ReportingServiceSaveResponse +} + +func (c *C1APIReportingV1ReportingServiceSaveResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceSaveResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingservicesaveresponse +// #endregion class-body-c1apireportingv1reportingservicesaveresponse diff --git a/pkg/models/operations/c1apireportingv1reportingserviceupdate.go b/pkg/models/operations/c1apireportingv1reportingserviceupdate.go new file mode 100644 index 000000000..b6a1b3fd3 --- /dev/null +++ b/pkg/models/operations/c1apireportingv1reportingserviceupdate.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIReportingV1ReportingServiceUpdateRequest struct { + ReportingServiceUpdateRequest *shared.ReportingServiceUpdateRequest `request:"mediaType=application/json"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APIReportingV1ReportingServiceUpdateRequest) GetReportingServiceUpdateRequest() *shared.ReportingServiceUpdateRequest { + if c == nil { + return nil + } + return c.ReportingServiceUpdateRequest +} + +func (c *C1APIReportingV1ReportingServiceUpdateRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apireportingv1reportingserviceupdaterequest +// #endregion class-body-c1apireportingv1reportingserviceupdaterequest + +type C1APIReportingV1ReportingServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // Successful response + ReportingServiceUpdateResponse *shared.ReportingServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIReportingV1ReportingServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIReportingV1ReportingServiceUpdateResponse) GetReportingServiceUpdateResponse() *shared.ReportingServiceUpdateResponse { + if c == nil { + return nil + } + return c.ReportingServiceUpdateResponse +} + +func (c *C1APIReportingV1ReportingServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIReportingV1ReportingServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apireportingv1reportingserviceupdateresponse +// #endregion class-body-c1apireportingv1reportingserviceupdateresponse diff --git a/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselection.go b/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselection.go new file mode 100644 index 000000000..d75fa11f8 --- /dev/null +++ b/pkg/models/operations/c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselection.go @@ -0,0 +1,73 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest struct { + EvaluateEntitlementSelectionRequest *shared.EvaluateEntitlementSelectionRequest `request:"mediaType=application/json"` + AnalysisID string `pathParam:"style=simple,explode=false,name=analysis_id"` +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest) GetEvaluateEntitlementSelectionRequest() *shared.EvaluateEntitlementSelectionRequest { + if c == nil { + return nil + } + return c.EvaluateEntitlementSelectionRequest +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest) GetAnalysisID() string { + if c == nil { + return "" + } + return c.AnalysisID +} + +// #region class-body-c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest +// #endregion class-body-c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionrequest + +type C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse struct { + // HTTP response content type for this operation + ContentType string + // EvaluateEntitlementSelectionResponse contains the exact impact of the + // resolved entitlement selection. + EvaluateEntitlementSelectionResponse *shared.EvaluateEntitlementSelectionResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse) GetEvaluateEntitlementSelectionResponse() *shared.EvaluateEntitlementSelectionResponse { + if c == nil { + return nil + } + return c.EvaluateEntitlementSelectionResponse +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse +// #endregion class-body-c1apiroleminingmanagementv1roleminingmanagementserviceevaluateentitlementselectionresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibility.go b/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibility.go new file mode 100644 index 000000000..a581f1b7d --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicebatchdeletesubjectcompatibility.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest struct { + SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest *shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest) GetSSOApplicationServiceBatchDeleteSubjectCompatibilityRequest() *shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest +// #endregion class-body-c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityrequest + +type C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded + // recovery progress. + SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse *shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetSSOApplicationServiceBatchDeleteSubjectCompatibilityResponse() *shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse +// #endregion class-body-c1apissov1ssoapplicationservicebatchdeletesubjectcompatibilityresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibility.go b/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibility.go new file mode 100644 index 000000000..96c94e8a5 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicebatchimportsubjectcompatibility.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest struct { + SSOApplicationServiceBatchImportSubjectCompatibilityRequest *shared.SSOApplicationServiceBatchImportSubjectCompatibilityRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetSSOApplicationServiceBatchImportSubjectCompatibilityRequest() *shared.SSOApplicationServiceBatchImportSubjectCompatibilityRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceBatchImportSubjectCompatibilityRequest +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest +// #endregion class-body-c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityrequest + +type C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one + // bounded validation or apply batch. + SSOApplicationServiceBatchImportSubjectCompatibilityResponse *shared.SSOApplicationServiceBatchImportSubjectCompatibilityResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetSSOApplicationServiceBatchImportSubjectCompatibilityResponse() *shared.SSOApplicationServiceBatchImportSubjectCompatibilityResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceBatchImportSubjectCompatibilityResponse +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse +// #endregion class-body-c1apissov1ssoapplicationservicebatchimportsubjectcompatibilityresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicecreate.go b/pkg/models/operations/c1apissov1ssoapplicationservicecreate.go new file mode 100644 index 000000000..df461212d --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicecreate.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceCreateRequest struct { + SSOApplicationServiceCreateRequest *shared.SSOApplicationServiceCreateRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` +} + +func (c *C1APISSOV1SSOApplicationServiceCreateRequest) GetSSOApplicationServiceCreateRequest() *shared.SSOApplicationServiceCreateRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceCreateRequest +} + +func (c *C1APISSOV1SSOApplicationServiceCreateRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +// #region class-body-c1apissov1ssoapplicationservicecreaterequest +// #endregion class-body-c1apissov1ssoapplicationservicecreaterequest + +type C1APISSOV1SSOApplicationServiceCreateResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceCreateResponse returns the created SSO application. + SSOApplicationServiceCreateResponse *shared.SSOApplicationServiceCreateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceCreateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceCreateResponse) GetSSOApplicationServiceCreateResponse() *shared.SSOApplicationServiceCreateResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceCreateResponse +} + +func (c *C1APISSOV1SSOApplicationServiceCreateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceCreateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicecreateresponse +// #endregion class-body-c1apissov1ssoapplicationservicecreateresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicecreateclient.go b/pkg/models/operations/c1apissov1ssoapplicationservicecreateclient.go new file mode 100644 index 000000000..7b0e713e5 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicecreateclient.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceCreateClientRequest struct { + SSOApplicationServiceCreateClientRequest *shared.SSOApplicationServiceCreateClientRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientRequest) GetSSOApplicationServiceCreateClientRequest() *shared.SSOApplicationServiceCreateClientRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceCreateClientRequest +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicecreateclientrequest +// #endregion class-body-c1apissov1ssoapplicationservicecreateclientrequest + +type C1APISSOV1SSOApplicationServiceCreateClientResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceCreateClientResponse contains the generated client and + // its one-time secret, when applicable. + SSOApplicationServiceCreateClientResponse *shared.SSOApplicationServiceCreateClientResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientResponse) GetSSOApplicationServiceCreateClientResponse() *shared.SSOApplicationServiceCreateClientResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceCreateClientResponse +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceCreateClientResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicecreateclientresponse +// #endregion class-body-c1apissov1ssoapplicationservicecreateclientresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicedelete.go b/pkg/models/operations/c1apissov1ssoapplicationservicedelete.go new file mode 100644 index 000000000..997fc45ae --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicedelete.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceDeleteRequest struct { + SSOApplicationServiceDeleteRequest *shared.SSOApplicationServiceDeleteRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteRequest) GetSSOApplicationServiceDeleteRequest() *shared.SSOApplicationServiceDeleteRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceDeleteRequest +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicedeleterequest +// #endregion class-body-c1apissov1ssoapplicationservicedeleterequest + +type C1APISSOV1SSOApplicationServiceDeleteResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceDeleteResponse confirms deletion. + SSOApplicationServiceDeleteResponse *shared.SSOApplicationServiceDeleteResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteResponse) GetSSOApplicationServiceDeleteResponse() *shared.SSOApplicationServiceDeleteResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceDeleteResponse +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicedeleteresponse +// #endregion class-body-c1apissov1ssoapplicationservicedeleteresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclient.go b/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclient.go new file mode 100644 index 000000000..776753fd0 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicedeleteclient.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceDeleteClientRequest struct { + SSOApplicationServiceDeleteClientRequest *shared.SSOApplicationServiceDeleteClientRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientRequest) GetSSOApplicationServiceDeleteClientRequest() *shared.SSOApplicationServiceDeleteClientRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceDeleteClientRequest +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicedeleteclientrequest +// #endregion class-body-c1apissov1ssoapplicationservicedeleteclientrequest + +type C1APISSOV1SSOApplicationServiceDeleteClientResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceDeleteClientResponse confirms deletion. + SSOApplicationServiceDeleteClientResponse *shared.SSOApplicationServiceDeleteClientResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientResponse) GetSSOApplicationServiceDeleteClientResponse() *shared.SSOApplicationServiceDeleteClientResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceDeleteClientResponse +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceDeleteClientResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicedeleteclientresponse +// #endregion class-body-c1apissov1ssoapplicationservicedeleteclientresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationserviceget.go b/pkg/models/operations/c1apissov1ssoapplicationserviceget.go new file mode 100644 index 000000000..e77d8a75b --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationserviceget.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceGetRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceGetRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceGetRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicegetrequest +// #endregion class-body-c1apissov1ssoapplicationservicegetrequest + +type C1APISSOV1SSOApplicationServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceGetResponse returns a single SSO application. + SSOApplicationServiceGetResponse *shared.SSOApplicationServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceGetResponse) GetSSOApplicationServiceGetResponse() *shared.SSOApplicationServiceGetResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceGetResponse +} + +func (c *C1APISSOV1SSOApplicationServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicegetresponse +// #endregion class-body-c1apissov1ssoapplicationservicegetresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicelist.go b/pkg/models/operations/c1apissov1ssoapplicationservicelist.go new file mode 100644 index 000000000..12b9ce15c --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicelist.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceListRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APISSOV1SSOApplicationServiceListRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceListRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APISSOV1SSOApplicationServiceListRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apissov1ssoapplicationservicelistrequest +// #endregion class-body-c1apissov1ssoapplicationservicelistrequest + +type C1APISSOV1SSOApplicationServiceListResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceListResponse returns a page of SSO applications. + SSOApplicationServiceListResponse *shared.SSOApplicationServiceListResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceListResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceListResponse) GetSSOApplicationServiceListResponse() *shared.SSOApplicationServiceListResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceListResponse +} + +func (c *C1APISSOV1SSOApplicationServiceListResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceListResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicelistresponse +// #endregion class-body-c1apissov1ssoapplicationservicelistresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicelistclients.go b/pkg/models/operations/c1apissov1ssoapplicationservicelistclients.go new file mode 100644 index 000000000..7a90b859b --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicelistclients.go @@ -0,0 +1,89 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceListClientsRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apissov1ssoapplicationservicelistclientsrequest +// #endregion class-body-c1apissov1ssoapplicationservicelistclientsrequest + +type C1APISSOV1SSOApplicationServiceListClientsResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth + // clients. + SSOApplicationServiceListClientsResponse *shared.SSOApplicationServiceListClientsResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsResponse) GetSSOApplicationServiceListClientsResponse() *shared.SSOApplicationServiceListClientsResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceListClientsResponse +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceListClientsResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicelistclientsresponse +// #endregion class-body-c1apissov1ssoapplicationservicelistclientsresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicelisthistory.go b/pkg/models/operations/c1apissov1ssoapplicationservicelisthistory.go new file mode 100644 index 000000000..b761a8c2e --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicelisthistory.go @@ -0,0 +1,89 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceListHistoryRequest struct { + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apissov1ssoapplicationservicelisthistoryrequest +// #endregion class-body-c1apissov1ssoapplicationservicelisthistoryrequest + +type C1APISSOV1SSOApplicationServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceListHistoryResponse returns SSO application history + // entries. + SSOApplicationServiceListHistoryResponse *shared.SSOApplicationServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryResponse) GetSSOApplicationServiceListHistoryResponse() *shared.SSOApplicationServiceListHistoryResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceListHistoryResponse +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicelisthistoryresponse +// #endregion class-body-c1apissov1ssoapplicationservicelisthistoryresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadata.go b/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadata.go new file mode 100644 index 000000000..5db0b5b6a --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadata.go @@ -0,0 +1,52 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the + // SAML configuration derived from one metadata document and every finding the + // parser raised about it. + SSOApplicationServiceParseSAMLServiceProviderMetadataResponse *shared.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetSSOApplicationServiceParseSAMLServiceProviderMetadataResponse() *shared.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse +} + +func (c *C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse +// #endregion class-body-c1apissov1ssoapplicationserviceparsesamlserviceprovidermetadataresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecret.go b/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecret.go new file mode 100644 index 000000000..d65f8d61a --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicerotateclientsecret.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceRotateClientSecretRequest struct { + SSOApplicationServiceRotateClientSecretRequest *shared.SSOApplicationServiceRotateClientSecretRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretRequest) GetSSOApplicationServiceRotateClientSecretRequest() *shared.SSOApplicationServiceRotateClientSecretRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceRotateClientSecretRequest +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationservicerotateclientsecretrequest +// #endregion class-body-c1apissov1ssoapplicationservicerotateclientsecretrequest + +type C1APISSOV1SSOApplicationServiceRotateClientSecretResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceRotateClientSecretResponse contains the replacement + // secret. The value cannot be retrieved again. + SSOApplicationServiceRotateClientSecretResponse *shared.SSOApplicationServiceRotateClientSecretResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretResponse) GetSSOApplicationServiceRotateClientSecretResponse() *shared.SSOApplicationServiceRotateClientSecretResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceRotateClientSecretResponse +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceRotateClientSecretResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicerotateclientsecretresponse +// #endregion class-body-c1apissov1ssoapplicationservicerotateclientsecretresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationservicesearch.go b/pkg/models/operations/c1apissov1ssoapplicationservicesearch.go new file mode 100644 index 000000000..977ba4efd --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationservicesearch.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceSearchResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceSearchResponse returns matching SSO applications. + SSOApplicationServiceSearchResponse *shared.SSOApplicationServiceSearchResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceSearchResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceSearchResponse) GetSSOApplicationServiceSearchResponse() *shared.SSOApplicationServiceSearchResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceSearchResponse +} + +func (c *C1APISSOV1SSOApplicationServiceSearchResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceSearchResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationservicesearchresponse +// #endregion class-body-c1apissov1ssoapplicationservicesearchresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationserviceupdate.go b/pkg/models/operations/c1apissov1ssoapplicationserviceupdate.go new file mode 100644 index 000000000..254e56ff0 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationserviceupdate.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceUpdateRequest struct { + SSOApplicationServiceUpdateRequest *shared.SSOApplicationServiceUpdateRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateRequest) GetSSOApplicationServiceUpdateRequest() *shared.SSOApplicationServiceUpdateRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceUpdateRequest +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationserviceupdaterequest +// #endregion class-body-c1apissov1ssoapplicationserviceupdaterequest + +type C1APISSOV1SSOApplicationServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceUpdateResponse returns the updated SSO application. + SSOApplicationServiceUpdateResponse *shared.SSOApplicationServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateResponse) GetSSOApplicationServiceUpdateResponse() *shared.SSOApplicationServiceUpdateResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceUpdateResponse +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationserviceupdateresponse +// #endregion class-body-c1apissov1ssoapplicationserviceupdateresponse diff --git a/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclient.go b/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclient.go new file mode 100644 index 000000000..10aef18d0 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssoapplicationserviceupdateclient.go @@ -0,0 +1,80 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOApplicationServiceUpdateClientRequest struct { + SSOApplicationServiceUpdateClientRequest *shared.SSOApplicationServiceUpdateClientRequest `request:"mediaType=application/json"` + AppID string `pathParam:"style=simple,explode=false,name=app_id"` + ID string `pathParam:"style=simple,explode=false,name=id"` +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientRequest) GetSSOApplicationServiceUpdateClientRequest() *shared.SSOApplicationServiceUpdateClientRequest { + if c == nil { + return nil + } + return c.SSOApplicationServiceUpdateClientRequest +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientRequest) GetAppID() string { + if c == nil { + return "" + } + return c.AppID +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientRequest) GetID() string { + if c == nil { + return "" + } + return c.ID +} + +// #region class-body-c1apissov1ssoapplicationserviceupdateclientrequest +// #endregion class-body-c1apissov1ssoapplicationserviceupdateclientrequest + +type C1APISSOV1SSOApplicationServiceUpdateClientResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOApplicationServiceUpdateClientResponse contains the updated client. + SSOApplicationServiceUpdateClientResponse *shared.SSOApplicationServiceUpdateClientResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientResponse) GetSSOApplicationServiceUpdateClientResponse() *shared.SSOApplicationServiceUpdateClientResponse { + if c == nil { + return nil + } + return c.SSOApplicationServiceUpdateClientResponse +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOApplicationServiceUpdateClientResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssoapplicationserviceupdateclientresponse +// #endregion class-body-c1apissov1ssoapplicationserviceupdateclientresponse diff --git a/pkg/models/operations/c1apissov1ssosettingsserviceget.go b/pkg/models/operations/c1apissov1ssosettingsserviceget.go new file mode 100644 index 000000000..5fbcb1cad --- /dev/null +++ b/pkg/models/operations/c1apissov1ssosettingsserviceget.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOSettingsServiceGetResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. + SSOSettingsServiceGetResponse *shared.SSOSettingsServiceGetResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOSettingsServiceGetResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOSettingsServiceGetResponse) GetSSOSettingsServiceGetResponse() *shared.SSOSettingsServiceGetResponse { + if c == nil { + return nil + } + return c.SSOSettingsServiceGetResponse +} + +func (c *C1APISSOV1SSOSettingsServiceGetResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOSettingsServiceGetResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssosettingsservicegetresponse +// #endregion class-body-c1apissov1ssosettingsservicegetresponse diff --git a/pkg/models/operations/c1apissov1ssosettingsservicelisthistory.go b/pkg/models/operations/c1apissov1ssosettingsservicelisthistory.go new file mode 100644 index 000000000..7af9c0750 --- /dev/null +++ b/pkg/models/operations/c1apissov1ssosettingsservicelisthistory.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOSettingsServiceListHistoryRequest struct { + PageSize *int `queryParam:"style=form,explode=true,name=page_size"` + PageToken *string `queryParam:"style=form,explode=true,name=page_token"` +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryRequest) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryRequest) GetPageToken() *string { + if c == nil { + return nil + } + return c.PageToken +} + +// #region class-body-c1apissov1ssosettingsservicelisthistoryrequest +// #endregion class-body-c1apissov1ssosettingsservicelisthistoryrequest + +type C1APISSOV1SSOSettingsServiceListHistoryResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOSettingsServiceListHistoryResponse returns SSO settings history entries. + SSOSettingsServiceListHistoryResponse *shared.SSOSettingsServiceListHistoryResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryResponse) GetSSOSettingsServiceListHistoryResponse() *shared.SSOSettingsServiceListHistoryResponse { + if c == nil { + return nil + } + return c.SSOSettingsServiceListHistoryResponse +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOSettingsServiceListHistoryResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssosettingsservicelisthistoryresponse +// #endregion class-body-c1apissov1ssosettingsservicelisthistoryresponse diff --git a/pkg/models/operations/c1apissov1ssosettingsserviceupdate.go b/pkg/models/operations/c1apissov1ssosettingsserviceupdate.go new file mode 100644 index 000000000..88d792f8b --- /dev/null +++ b/pkg/models/operations/c1apissov1ssosettingsserviceupdate.go @@ -0,0 +1,50 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APISSOV1SSOSettingsServiceUpdateResponse struct { + // HTTP response content type for this operation + ContentType string + // SSOSettingsServiceUpdateResponse returns the updated settings. + SSOSettingsServiceUpdateResponse *shared.SSOSettingsServiceUpdateResponse + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response +} + +func (c *C1APISSOV1SSOSettingsServiceUpdateResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APISSOV1SSOSettingsServiceUpdateResponse) GetSSOSettingsServiceUpdateResponse() *shared.SSOSettingsServiceUpdateResponse { + if c == nil { + return nil + } + return c.SSOSettingsServiceUpdateResponse +} + +func (c *C1APISSOV1SSOSettingsServiceUpdateResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APISSOV1SSOSettingsServiceUpdateResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +// #region class-body-c1apissov1ssosettingsserviceupdateresponse +// #endregion class-body-c1apissov1ssosettingsserviceupdateresponse diff --git a/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioning.go b/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioning.go new file mode 100644 index 000000000..70abf11dc --- /dev/null +++ b/pkg/models/operations/c1apitaskv1taskactionsserviceretryprovisioning.go @@ -0,0 +1,72 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package operations + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "net/http" +) + +type C1APITaskV1TaskActionsServiceRetryProvisioningRequest struct { + TaskActionsServiceRetryProvisioningRequest *shared.TaskActionsServiceRetryProvisioningRequest `request:"mediaType=application/json"` + TaskID string `pathParam:"style=simple,explode=false,name=task_id"` +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningRequest) GetTaskActionsServiceRetryProvisioningRequest() *shared.TaskActionsServiceRetryProvisioningRequest { + if c == nil { + return nil + } + return c.TaskActionsServiceRetryProvisioningRequest +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningRequest) GetTaskID() string { + if c == nil { + return "" + } + return c.TaskID +} + +// #region class-body-c1apitaskv1taskactionsserviceretryprovisioningrequest +// #endregion class-body-c1apitaskv1taskactionsserviceretryprovisioningrequest + +type C1APITaskV1TaskActionsServiceRetryProvisioningResponse struct { + // HTTP response content type for this operation + ContentType string + // HTTP response status code for this operation + StatusCode int + // Raw HTTP response; suitable for custom response parsing + RawResponse *http.Response + // A generic response for task action endpoints, containing the updated task and the ID of the action that was created. + TaskServiceActionResponse *shared.TaskServiceActionResponse +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningResponse) GetContentType() string { + if c == nil { + return "" + } + return c.ContentType +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningResponse) GetStatusCode() int { + if c == nil { + return 0 + } + return c.StatusCode +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningResponse) GetRawResponse() *http.Response { + if c == nil { + return nil + } + return c.RawResponse +} + +func (c *C1APITaskV1TaskActionsServiceRetryProvisioningResponse) GetTaskServiceActionResponse() *shared.TaskServiceActionResponse { + if c == nil { + return nil + } + return c.TaskServiceActionResponse +} + +// #region class-body-c1apitaskv1taskactionsserviceretryprovisioningresponse +// #endregion class-body-c1apitaskv1taskactionsserviceretryprovisioningresponse diff --git a/pkg/models/shared/a2uicomponent.go b/pkg/models/shared/a2uicomponent.go index ad15aad64..1a4c40d08 100644 --- a/pkg/models/shared/a2uicomponent.go +++ b/pkg/models/shared/a2uicomponent.go @@ -32,6 +32,8 @@ package shared // - c1OnboardingPlan // - c1ConnectorSyncDetail // - c1Chart +// - c1MetricCards +// - c1Table type A2UIComponent struct { Button *ButtonComponent `json:"button,omitempty"` C1Chart *C1ChartComponent `json:"c1Chart,omitempty"` @@ -40,12 +42,14 @@ type A2UIComponent struct { C1ConnectorSyncDetail *C1ConnectorSyncDetailComponent `json:"c1ConnectorSyncDetail,omitempty"` C1ConnectorSyncProgress *C1ConnectorSyncProgressComponent `json:"c1ConnectorSyncProgress,omitempty"` C1DurationPicker *C1DurationPickerComponent `json:"c1DurationPicker,omitempty"` + C1MetricCards *C1MetricCardsComponent `json:"c1MetricCards,omitempty"` C1MsTeamsNotifications *C1MSTeamsNotificationsComponent `json:"c1MsTeamsNotifications,omitempty"` C1OnboardingPlan *C1OnboardingPlanComponent `json:"c1OnboardingPlan,omitempty"` C1OnboardingWelcome *C1OnboardingWelcomeComponent `json:"c1OnboardingWelcome,omitempty"` C1ResourcePicker *C1ResourcePickerComponent `json:"c1ResourcePicker,omitempty"` C1SlackNotifications *C1SlackNotificationsComponent `json:"c1SlackNotifications,omitempty"` C1StatusIndicator *C1StatusIndicatorComponent `json:"c1StatusIndicator,omitempty"` + C1Table *C1TableComponent `json:"c1Table,omitempty"` C1TodoList *C1TodoListComponent `json:"c1TodoList,omitempty"` Card *CardComponent `json:"card,omitempty"` CheckBox *CheckBoxComponent `json:"checkBox,omitempty"` @@ -113,6 +117,13 @@ func (a *A2UIComponent) GetC1DurationPicker() *C1DurationPickerComponent { return a.C1DurationPicker } +func (a *A2UIComponent) GetC1MetricCards() *C1MetricCardsComponent { + if a == nil { + return nil + } + return a.C1MetricCards +} + func (a *A2UIComponent) GetC1MsTeamsNotifications() *C1MSTeamsNotificationsComponent { if a == nil { return nil @@ -155,6 +166,13 @@ func (a *A2UIComponent) GetC1StatusIndicator() *C1StatusIndicatorComponent { return a.C1StatusIndicator } +func (a *A2UIComponent) GetC1Table() *C1TableComponent { + if a == nil { + return nil + } + return a.C1Table +} + func (a *A2UIComponent) GetC1TodoList() *C1TodoListComponent { if a == nil { return nil diff --git a/pkg/models/shared/a2uiprovenanceobject.go b/pkg/models/shared/a2uiprovenanceobject.go new file mode 100644 index 000000000..2db073693 --- /dev/null +++ b/pkg/models/shared/a2uiprovenanceobject.go @@ -0,0 +1,91 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// RecordType - Not always the step's own type: a step over grants can be narrowed to one +// +// app, and the app is the record worth naming. +type RecordType string + +const ( + RecordTypeA2UIProvenanceRecordTypeUnspecified RecordType = "A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED" + RecordTypeA2UIProvenanceRecordTypeApp RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP" + RecordTypeA2UIProvenanceRecordTypeUser RecordType = "A2UI_PROVENANCE_RECORD_TYPE_USER" + RecordTypeA2UIProvenanceRecordTypeGrant RecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT" + RecordTypeA2UIProvenanceRecordTypeAppEntitlement RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT" + RecordTypeA2UIProvenanceRecordTypeAppUser RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_USER" + RecordTypeA2UIProvenanceRecordTypeAppResource RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE" + RecordTypeA2UIProvenanceRecordTypeAppResourceType RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE" + RecordTypeA2UIProvenanceRecordTypeTask RecordType = "A2UI_PROVENANCE_RECORD_TYPE_TASK" + RecordTypeA2UIProvenanceRecordTypePolicy RecordType = "A2UI_PROVENANCE_RECORD_TYPE_POLICY" + RecordTypeA2UIProvenanceRecordTypeConnector RecordType = "A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR" + RecordTypeA2UIProvenanceRecordTypeAccessReview RecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW" + RecordTypeA2UIProvenanceRecordTypeAccessReviewTemplate RecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE" + RecordTypeA2UIProvenanceRecordTypeAccessReviewSelection RecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION" + RecordTypeA2UIProvenanceRecordTypeConflictMonitor RecordType = "A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR" + RecordTypeA2UIProvenanceRecordTypeAccessViolation RecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION" + RecordTypeA2UIProvenanceRecordTypeRequestCatalog RecordType = "A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG" + RecordTypeA2UIProvenanceRecordTypeWebhook RecordType = "A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK" + RecordTypeA2UIProvenanceRecordTypeDirectory RecordType = "A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY" + RecordTypeA2UIProvenanceRecordTypeProfileType RecordType = "A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE" + RecordTypeA2UIProvenanceRecordTypeRoleBinding RecordType = "A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING" + RecordTypeA2UIProvenanceRecordTypeAutomationExecution RecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION" + RecordTypeA2UIProvenanceRecordTypeAutomationExecutionStep RecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP" + RecordTypeA2UIProvenanceRecordTypeFinding RecordType = "A2UI_PROVENANCE_RECORD_TYPE_FINDING" + RecordTypeA2UIProvenanceRecordTypeMetric RecordType = "A2UI_PROVENANCE_RECORD_TYPE_METRIC" + RecordTypeA2UIProvenanceRecordTypeAutomation RecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION" + RecordTypeA2UIProvenanceRecordTypeGrantHistory RecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY" + RecordTypeA2UIProvenanceRecordTypeGrantReason RecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON" + RecordTypeA2UIProvenanceRecordTypeAppOwner RecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER" +) + +func (e RecordType) ToPointer() *RecordType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *RecordType) IsExact() bool { + if e != nil { + switch *e { + case "A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED", "A2UI_PROVENANCE_RECORD_TYPE_APP", "A2UI_PROVENANCE_RECORD_TYPE_USER", "A2UI_PROVENANCE_RECORD_TYPE_GRANT", "A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT", "A2UI_PROVENANCE_RECORD_TYPE_APP_USER", "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE", "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE", "A2UI_PROVENANCE_RECORD_TYPE_TASK", "A2UI_PROVENANCE_RECORD_TYPE_POLICY", "A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION", "A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION", "A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG", "A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK", "A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY", "A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE", "A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP", "A2UI_PROVENANCE_RECORD_TYPE_FINDING", "A2UI_PROVENANCE_RECORD_TYPE_METRIC", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION", "A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY", "A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON", "A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER": + return true + } + } + return false +} + +// A2UIProvenanceObject names one record a step referred to by id. +type A2UIProvenanceObject struct { + // Empty when the record's type has no name to resolve, or the record is + // gone. The id then stands alone rather than the whole row being dropped. + DisplayName *string `json:"displayName,omitempty"` + // The id field. + ID *string `json:"id,omitempty"` + // Not always the step's own type: a step over grants can be narrowed to one + // app, and the app is the record worth naming. + RecordType *RecordType `json:"recordType,omitempty"` +} + +func (a *A2UIProvenanceObject) GetDisplayName() *string { + if a == nil { + return nil + } + return a.DisplayName +} + +func (a *A2UIProvenanceObject) GetID() *string { + if a == nil { + return nil + } + return a.ID +} + +func (a *A2UIProvenanceObject) GetRecordType() *RecordType { + if a == nil { + return nil + } + return a.RecordType +} + +// #region class-body-a2uiprovenanceobject +// #endregion class-body-a2uiprovenanceobject diff --git a/pkg/models/shared/a2uiprovenancesource.go b/pkg/models/shared/a2uiprovenancesource.go new file mode 100644 index 000000000..c29efa530 --- /dev/null +++ b/pkg/models/shared/a2uiprovenancesource.go @@ -0,0 +1,96 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// A2UIProvenanceSource is one self-reported source from a reporting component: +// +// what a chart or table says it was drawn from, and how many rows fed it. +type A2UIProvenanceSource struct { + // The componentId field. + ComponentID *string `json:"componentId,omitempty"` + // The count field. + Count *int64 `integer:"string" json:"count,omitempty"` + // The kind field. + Kind *string `json:"kind,omitempty"` + // The label field. + Label *string `json:"label,omitempty"` + // Deprecated: always empty. See verified. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. + MatchedToolCall *string `json:"matchedToolCall,omitempty"` + // The ref field. + Ref *string `json:"ref,omitempty"` + // Deprecated: always false. Superseded by + // A2UIServiceGetSurfaceProvenanceResponse.steps, which reports what the + // program did rather than judging it. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. + Verified *bool `json:"verified,omitempty"` +} + +func (a A2UIProvenanceSource) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(a, "", false) +} + +func (a *A2UIProvenanceSource) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &a, "", false, nil); err != nil { + return err + } + return nil +} + +func (a *A2UIProvenanceSource) GetComponentID() *string { + if a == nil { + return nil + } + return a.ComponentID +} + +func (a *A2UIProvenanceSource) GetCount() *int64 { + if a == nil { + return nil + } + return a.Count +} + +func (a *A2UIProvenanceSource) GetKind() *string { + if a == nil { + return nil + } + return a.Kind +} + +func (a *A2UIProvenanceSource) GetLabel() *string { + if a == nil { + return nil + } + return a.Label +} + +func (a *A2UIProvenanceSource) GetMatchedToolCall() *string { + if a == nil { + return nil + } + return a.MatchedToolCall +} + +func (a *A2UIProvenanceSource) GetRef() *string { + if a == nil { + return nil + } + return a.Ref +} + +func (a *A2UIProvenanceSource) GetVerified() *bool { + if a == nil { + return nil + } + return a.Verified +} + +// #region class-body-a2uiprovenancesource +// #endregion class-body-a2uiprovenancesource diff --git a/pkg/models/shared/a2uiprovenancestep.go b/pkg/models/shared/a2uiprovenancestep.go new file mode 100644 index 000000000..d31b55434 --- /dev/null +++ b/pkg/models/shared/a2uiprovenancestep.go @@ -0,0 +1,122 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Operation - The operation field. +type Operation string + +const ( + OperationA2UIProvenanceOperationUnspecified Operation = "A2UI_PROVENANCE_OPERATION_UNSPECIFIED" + OperationA2UIProvenanceOperationLookedUp Operation = "A2UI_PROVENANCE_OPERATION_LOOKED_UP" + OperationA2UIProvenanceOperationCounted Operation = "A2UI_PROVENANCE_OPERATION_COUNTED" + OperationA2UIProvenanceOperationFetchedRecord Operation = "A2UI_PROVENANCE_OPERATION_FETCHED_RECORD" + OperationA2UIProvenanceOperationSearched Operation = "A2UI_PROVENANCE_OPERATION_SEARCHED" + OperationA2UIProvenanceOperationReadTrend Operation = "A2UI_PROVENANCE_OPERATION_READ_TREND" + OperationA2UIProvenanceOperationCreated Operation = "A2UI_PROVENANCE_OPERATION_CREATED" + OperationA2UIProvenanceOperationUpdated Operation = "A2UI_PROVENANCE_OPERATION_UPDATED" + OperationA2UIProvenanceOperationDeleted Operation = "A2UI_PROVENANCE_OPERATION_DELETED" + OperationA2UIProvenanceOperationRanProgram Operation = "A2UI_PROVENANCE_OPERATION_RAN_PROGRAM" + OperationA2UIProvenanceOperationBuiltReport Operation = "A2UI_PROVENANCE_OPERATION_BUILT_REPORT" +) + +func (e Operation) ToPointer() *Operation { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Operation) IsExact() bool { + if e != nil { + switch *e { + case "A2UI_PROVENANCE_OPERATION_UNSPECIFIED", "A2UI_PROVENANCE_OPERATION_LOOKED_UP", "A2UI_PROVENANCE_OPERATION_COUNTED", "A2UI_PROVENANCE_OPERATION_FETCHED_RECORD", "A2UI_PROVENANCE_OPERATION_SEARCHED", "A2UI_PROVENANCE_OPERATION_READ_TREND", "A2UI_PROVENANCE_OPERATION_CREATED", "A2UI_PROVENANCE_OPERATION_UPDATED", "A2UI_PROVENANCE_OPERATION_DELETED", "A2UI_PROVENANCE_OPERATION_RAN_PROGRAM", "A2UI_PROVENANCE_OPERATION_BUILT_REPORT": + return true + } + } + return false +} + +// A2UIProvenanceStepRecordType - The recordType field. +type A2UIProvenanceStepRecordType string + +const ( + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeUnspecified A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeApp A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeUser A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_USER" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrant A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppEntitlement A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppUser A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_USER" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppResource A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppResourceType A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeTask A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_TASK" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypePolicy A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_POLICY" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeConnector A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReview A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReviewTemplate A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessReviewSelection A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeConflictMonitor A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAccessViolation A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeRequestCatalog A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeWebhook A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeDirectory A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeProfileType A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeRoleBinding A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomationExecution A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomationExecutionStep A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeFinding A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_FINDING" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeMetric A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_METRIC" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAutomation A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrantHistory A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeGrantReason A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON" + A2UIProvenanceStepRecordTypeA2UIProvenanceRecordTypeAppOwner A2UIProvenanceStepRecordType = "A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER" +) + +func (e A2UIProvenanceStepRecordType) ToPointer() *A2UIProvenanceStepRecordType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *A2UIProvenanceStepRecordType) IsExact() bool { + if e != nil { + switch *e { + case "A2UI_PROVENANCE_RECORD_TYPE_UNSPECIFIED", "A2UI_PROVENANCE_RECORD_TYPE_APP", "A2UI_PROVENANCE_RECORD_TYPE_USER", "A2UI_PROVENANCE_RECORD_TYPE_GRANT", "A2UI_PROVENANCE_RECORD_TYPE_APP_ENTITLEMENT", "A2UI_PROVENANCE_RECORD_TYPE_APP_USER", "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE", "A2UI_PROVENANCE_RECORD_TYPE_APP_RESOURCE_TYPE", "A2UI_PROVENANCE_RECORD_TYPE_TASK", "A2UI_PROVENANCE_RECORD_TYPE_POLICY", "A2UI_PROVENANCE_RECORD_TYPE_CONNECTOR", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_TEMPLATE", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_REVIEW_SELECTION", "A2UI_PROVENANCE_RECORD_TYPE_CONFLICT_MONITOR", "A2UI_PROVENANCE_RECORD_TYPE_ACCESS_VIOLATION", "A2UI_PROVENANCE_RECORD_TYPE_REQUEST_CATALOG", "A2UI_PROVENANCE_RECORD_TYPE_WEBHOOK", "A2UI_PROVENANCE_RECORD_TYPE_DIRECTORY", "A2UI_PROVENANCE_RECORD_TYPE_PROFILE_TYPE", "A2UI_PROVENANCE_RECORD_TYPE_ROLE_BINDING", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION_EXECUTION_STEP", "A2UI_PROVENANCE_RECORD_TYPE_FINDING", "A2UI_PROVENANCE_RECORD_TYPE_METRIC", "A2UI_PROVENANCE_RECORD_TYPE_AUTOMATION", "A2UI_PROVENANCE_RECORD_TYPE_GRANT_HISTORY", "A2UI_PROVENANCE_RECORD_TYPE_GRANT_REASON", "A2UI_PROVENANCE_RECORD_TYPE_APP_OWNER": + return true + } + } + return false +} + +// A2UIProvenanceStep is one thing the report's program did. Steps are returned +// +// in the order the program performs them. +type A2UIProvenanceStep struct { + // The specific records this step named. Empty when the step names none, and + // withheld wholesale when step_objects_visible is false. + Objects []A2UIProvenanceObject `json:"objects,omitempty"` + // The operation field. + Operation *Operation `json:"operation,omitempty"` + // The recordType field. + RecordType *A2UIProvenanceStepRecordType `json:"recordType,omitempty"` +} + +func (a *A2UIProvenanceStep) GetObjects() []A2UIProvenanceObject { + if a == nil { + return nil + } + return a.Objects +} + +func (a *A2UIProvenanceStep) GetOperation() *Operation { + if a == nil { + return nil + } + return a.Operation +} + +func (a *A2UIProvenanceStep) GetRecordType() *A2UIProvenanceStepRecordType { + if a == nil { + return nil + } + return a.RecordType +} + +// #region class-body-a2uiprovenancestep +// #endregion class-body-a2uiprovenancestep diff --git a/pkg/models/shared/a2uiprovenancetoolcall.go b/pkg/models/shared/a2uiprovenancetoolcall.go new file mode 100644 index 000000000..104567eff --- /dev/null +++ b/pkg/models/shared/a2uiprovenancetoolcall.go @@ -0,0 +1,52 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// A2UIProvenanceToolCall is one tool call extracted from the transcript. +type A2UIProvenanceToolCall struct { + CalledAt *time.Time `json:"calledAt,omitempty"` + // Leading characters of the tool input, whitespace-collapsed. + InputDigest *string `json:"inputDigest,omitempty"` + // The toolName field. + ToolName *string `json:"toolName,omitempty"` +} + +func (a A2UIProvenanceToolCall) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(a, "", false) +} + +func (a *A2UIProvenanceToolCall) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &a, "", false, nil); err != nil { + return err + } + return nil +} + +func (a *A2UIProvenanceToolCall) GetCalledAt() *time.Time { + if a == nil { + return nil + } + return a.CalledAt +} + +func (a *A2UIProvenanceToolCall) GetInputDigest() *string { + if a == nil { + return nil + } + return a.InputDigest +} + +func (a *A2UIProvenanceToolCall) GetToolName() *string { + if a == nil { + return nil + } + return a.ToolName +} + +// #region class-body-a2uiprovenancetoolcall +// #endregion class-body-a2uiprovenancetoolcall diff --git a/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.go b/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.go new file mode 100644 index 000000000..0278e407e --- /dev/null +++ b/pkg/models/shared/a2uiservicegetsurfaceprovenanceresponse.go @@ -0,0 +1,126 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// A2UIServiceGetSurfaceProvenanceResponse returns what a surface was built +// +// from: the steps its program ran, and the sources its components report. +type A2UIServiceGetSurfaceProvenanceResponse struct { + // The program's identity: code mode invokes by explicit commit, so the commit + // — not the function — is what a refresh re-executes. + ProgramCommitID *string `json:"programCommitId,omitempty"` + // The program that produced a reporting surface. Flat rather than a nested + // ref: these five fields are read together by one drawer and nothing else, + // and a saved report's ProgramRef is the type worth converging on later. + // All empty for a surface carrying no report components, and for reports + // emitted before the report-program requirement was enabled for the tenant. + ProgramFunctionID *string `json:"programFunctionId,omitempty"` + // The JSON parameters the program ran with. Empty when the invocation has aged + // out of retention. + ProgramInput *string `json:"programInput,omitempty"` + // The run that produced this surface. + ProgramInvocationID *string `json:"programInvocationId,omitempty"` + // The program's source, read from the pinned commit. Empty when the commit has + // aged out of code-mode retention — the report still renders, but what + // produced it is no longer recoverable. + ProgramSource *string `json:"programSource,omitempty"` + // The sources field. + Sources []A2UIProvenanceSource `json:"sources,omitempty"` + // Whether the caller may see the ids each step named. False withholds every + // A2UIProvenanceStep.objects on the same boundary that withholds + // program_source: those ids are the program's parameters by another name. + StepObjectsVisible *bool `json:"stepObjectsVisible,omitempty"` + // Everything the surface's program did, in the order it does it. + Steps []A2UIProvenanceStep `json:"steps,omitempty"` + // False when neither the pinned program nor the conversation transcript could + // be read, so no record of what was looked at survives. Distinguishes that + // from a record that was read and genuinely contains no steps. + StepsAvailable *bool `json:"stepsAvailable,omitempty"` + // Deprecated: raw tool names, superseded by steps. Still populated for + // clients on the previous shape. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. + ToolCalls []A2UIProvenanceToolCall `json:"toolCalls,omitempty"` + // False when the backing session or its transcript steps are gone. + TranscriptAvailable *bool `json:"transcriptAvailable,omitempty"` +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetProgramCommitID() *string { + if a == nil { + return nil + } + return a.ProgramCommitID +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetProgramFunctionID() *string { + if a == nil { + return nil + } + return a.ProgramFunctionID +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetProgramInput() *string { + if a == nil { + return nil + } + return a.ProgramInput +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetProgramInvocationID() *string { + if a == nil { + return nil + } + return a.ProgramInvocationID +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetProgramSource() *string { + if a == nil { + return nil + } + return a.ProgramSource +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetSources() []A2UIProvenanceSource { + if a == nil { + return nil + } + return a.Sources +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetStepObjectsVisible() *bool { + if a == nil { + return nil + } + return a.StepObjectsVisible +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetSteps() []A2UIProvenanceStep { + if a == nil { + return nil + } + return a.Steps +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetStepsAvailable() *bool { + if a == nil { + return nil + } + return a.StepsAvailable +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetToolCalls() []A2UIProvenanceToolCall { + if a == nil { + return nil + } + return a.ToolCalls +} + +func (a *A2UIServiceGetSurfaceProvenanceResponse) GetTranscriptAvailable() *bool { + if a == nil { + return nil + } + return a.TranscriptAvailable +} + +// #region class-body-a2uiservicegetsurfaceprovenanceresponse +// #endregion class-body-a2uiservicegetsurfaceprovenanceresponse diff --git a/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.go b/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.go new file mode 100644 index 000000000..f9a121bd4 --- /dev/null +++ b/pkg/models/shared/accessreviewactionsservicegeneratereportrequest.go @@ -0,0 +1,56 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Format - Output format for the report. When unspecified, programmatic public-API +// +// callers (REST gateway and MCP) get JSON and the in-app UI gets XLSX. JSON +// and CSV return the per-decision certification rows; XLSX returns the full +// multi-sheet Excel workbook. +type Format string + +const ( + FormatAccessReviewReportFormatUnspecified Format = "ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED" + FormatAccessReviewReportFormatXlsx Format = "ACCESS_REVIEW_REPORT_FORMAT_XLSX" + FormatAccessReviewReportFormatJSON Format = "ACCESS_REVIEW_REPORT_FORMAT_JSON" + FormatAccessReviewReportFormatCsv Format = "ACCESS_REVIEW_REPORT_FORMAT_CSV" +) + +func (e Format) ToPointer() *Format { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Format) IsExact() bool { + if e != nil { + switch *e { + case "ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED", "ACCESS_REVIEW_REPORT_FORMAT_XLSX", "ACCESS_REVIEW_REPORT_FORMAT_JSON", "ACCESS_REVIEW_REPORT_FORMAT_CSV": + return true + } + } + return false +} + +// The AccessReviewActionsServiceGenerateReportRequest message. +type AccessReviewActionsServiceGenerateReportRequest struct { + // Output format for the report. When unspecified, programmatic public-API + // callers (REST gateway and MCP) get JSON and the in-app UI gets XLSX. JSON + // and CSV return the per-decision certification rows; XLSX returns the full + // multi-sheet Excel workbook. + Format *Format `json:"format,omitempty"` + ReportColumnConfig *AccessReviewReportColumnConfig `json:"reportColumnConfig,omitempty"` +} + +func (a *AccessReviewActionsServiceGenerateReportRequest) GetFormat() *Format { + if a == nil { + return nil + } + return a.Format +} + +func (a *AccessReviewActionsServiceGenerateReportRequest) GetReportColumnConfig() *AccessReviewReportColumnConfig { + if a == nil { + return nil + } + return a.ReportColumnConfig +} diff --git a/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.go b/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.go new file mode 100644 index 000000000..fbfeb4d35 --- /dev/null +++ b/pkg/models/shared/accessreviewactionsservicegeneratereportresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AccessReviewActionsServiceGenerateReportResponse message. +type AccessReviewActionsServiceGenerateReportResponse struct { +} diff --git a/pkg/models/shared/accessreviewcolumnconfig.go b/pkg/models/shared/accessreviewcolumnconfig.go index 2cd33210b..7fb8ad59b 100644 --- a/pkg/models/shared/accessreviewcolumnconfig.go +++ b/pkg/models/shared/accessreviewcolumnconfig.go @@ -55,9 +55,15 @@ func (e *Columns) IsExact() bool { // AccessReviewColumnConfig - Configuration for which columns are visible in the reviewer task list. type AccessReviewColumnConfig struct { - // Ordered list of columns visible to reviewers. - // If empty, the default column set for the campaign's default_view is used. + // Deprecated: use `ordered_columns`, which can also include app user + // attribute columns. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. Columns []Columns `json:"columns,omitempty"` + // Ordered columns visible to reviewers, built-ins and attributes + // interleaved. Falls back to `columns`, then to the default set for the + // campaign's default_view. + OrderedColumns []AccessReviewTaskColumnRef `json:"orderedColumns,omitempty"` } func (a *AccessReviewColumnConfig) GetColumns() []Columns { @@ -66,3 +72,10 @@ func (a *AccessReviewColumnConfig) GetColumns() []Columns { } return a.Columns } + +func (a *AccessReviewColumnConfig) GetOrderedColumns() []AccessReviewTaskColumnRef { + if a == nil { + return nil + } + return a.OrderedColumns +} diff --git a/pkg/models/shared/accessreviewreport.go b/pkg/models/shared/accessreviewreport.go new file mode 100644 index 000000000..0352c3e03 --- /dev/null +++ b/pkg/models/shared/accessreviewreport.go @@ -0,0 +1,135 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// AccessReviewReportFormat - Output format of the generated file (XLSX / JSON / CSV). +type AccessReviewReportFormat string + +const ( + AccessReviewReportFormatAccessReviewReportFormatUnspecified AccessReviewReportFormat = "ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED" + AccessReviewReportFormatAccessReviewReportFormatXlsx AccessReviewReportFormat = "ACCESS_REVIEW_REPORT_FORMAT_XLSX" + AccessReviewReportFormatAccessReviewReportFormatJSON AccessReviewReportFormat = "ACCESS_REVIEW_REPORT_FORMAT_JSON" + AccessReviewReportFormatAccessReviewReportFormatCsv AccessReviewReportFormat = "ACCESS_REVIEW_REPORT_FORMAT_CSV" +) + +func (e AccessReviewReportFormat) ToPointer() *AccessReviewReportFormat { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AccessReviewReportFormat) IsExact() bool { + if e != nil { + switch *e { + case "ACCESS_REVIEW_REPORT_FORMAT_UNSPECIFIED", "ACCESS_REVIEW_REPORT_FORMAT_XLSX", "ACCESS_REVIEW_REPORT_FORMAT_JSON", "ACCESS_REVIEW_REPORT_FORMAT_CSV": + return true + } + } + return false +} + +// AccessReviewReportState - The state field. +type AccessReviewReportState string + +const ( + AccessReviewReportStateReportStateUnspecified AccessReviewReportState = "REPORT_STATE_UNSPECIFIED" + AccessReviewReportStateReportStatePending AccessReviewReportState = "REPORT_STATE_PENDING" + AccessReviewReportStateReportStateOk AccessReviewReportState = "REPORT_STATE_OK" + AccessReviewReportStateReportStateError AccessReviewReportState = "REPORT_STATE_ERROR" +) + +func (e AccessReviewReportState) ToPointer() *AccessReviewReportState { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AccessReviewReportState) IsExact() bool { + if e != nil { + switch *e { + case "REPORT_STATE_UNSPECIFIED", "REPORT_STATE_PENDING", "REPORT_STATE_OK", "REPORT_STATE_ERROR": + return true + } + } + return false +} + +// The AccessReviewReport message. +type AccessReviewReport struct { + // The accessReviewId field. + AccessReviewID *string `json:"accessReviewId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The downloadUrl field. + DownloadURL *string `json:"downloadUrl,omitempty"` + // Output format of the generated file (XLSX / JSON / CSV). + Format *AccessReviewReportFormat `json:"format,omitempty"` + // The hashes field. + Hashes map[string]string `json:"hashes,omitempty"` + // The id field. + ID *string `json:"id,omitempty"` + // The state field. + State *AccessReviewReportState `json:"state,omitempty"` +} + +func (a AccessReviewReport) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(a, "", false) +} + +func (a *AccessReviewReport) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &a, "", false, nil); err != nil { + return err + } + return nil +} + +func (a *AccessReviewReport) GetAccessReviewID() *string { + if a == nil { + return nil + } + return a.AccessReviewID +} + +func (a *AccessReviewReport) GetCreatedAt() *time.Time { + if a == nil { + return nil + } + return a.CreatedAt +} + +func (a *AccessReviewReport) GetDownloadURL() *string { + if a == nil { + return nil + } + return a.DownloadURL +} + +func (a *AccessReviewReport) GetFormat() *AccessReviewReportFormat { + if a == nil { + return nil + } + return a.Format +} + +func (a *AccessReviewReport) GetHashes() map[string]string { + if a == nil { + return nil + } + return a.Hashes +} + +func (a *AccessReviewReport) GetID() *string { + if a == nil { + return nil + } + return a.ID +} + +func (a *AccessReviewReport) GetState() *AccessReviewReportState { + if a == nil { + return nil + } + return a.State +} diff --git a/pkg/models/shared/accessreviewreportcolumnconfig.go b/pkg/models/shared/accessreviewreportcolumnconfig.go new file mode 100644 index 000000000..6071ee0b6 --- /dev/null +++ b/pkg/models/shared/accessreviewreportcolumnconfig.go @@ -0,0 +1,69 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +type AccessReviewReportColumnConfigColumns string + +const ( + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnUnspecified AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_UNSPECIFIED" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmployeeID AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYEE_ID" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnJobTitle AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_JOB_TITLE" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDepartment AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_DEPARTMENT" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmploymentStatus AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_STATUS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEmploymentType AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_TYPE" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnManager AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_MANAGER" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnTask AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_TASK" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccount AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnUserName AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_USER_NAME" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnIdentityType AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_IDENTITY_TYPE" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccountOwner AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAccountOwnerEmail AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER_EMAIL" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnApplication AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_APPLICATION" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResource AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_RESOURCE" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResourceType AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_RESOURCE_TYPE" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnEntitlement AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_ENTITLEMENT" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDescription AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_DESCRIPTION" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnCertificationPolicy AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_CERTIFICATION_POLICY" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnAssignedTo AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_ASSIGNED_TO" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnReassignments AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_REASSIGNMENTS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnCertifiers AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_CERTIFIERS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnDecisions AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_DECISIONS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnResolvedOn AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_RESOLVED_ON" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnComments AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_COMMENTS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnLastLogin AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_LAST_LOGIN" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnSubmissions AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_SUBMISSIONS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnExternalTicket AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnExternalTicketStatus AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET_STATUS" + AccessReviewReportColumnConfigColumnsAccessReviewReportColumnSubjectUsername AccessReviewReportColumnConfigColumns = "ACCESS_REVIEW_REPORT_COLUMN_SUBJECT_USERNAME" +) + +func (e AccessReviewReportColumnConfigColumns) ToPointer() *AccessReviewReportColumnConfigColumns { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AccessReviewReportColumnConfigColumns) IsExact() bool { + if e != nil { + switch *e { + case "ACCESS_REVIEW_REPORT_COLUMN_UNSPECIFIED", "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYEE_ID", "ACCESS_REVIEW_REPORT_COLUMN_JOB_TITLE", "ACCESS_REVIEW_REPORT_COLUMN_DEPARTMENT", "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_STATUS", "ACCESS_REVIEW_REPORT_COLUMN_EMPLOYMENT_TYPE", "ACCESS_REVIEW_REPORT_COLUMN_MANAGER", "ACCESS_REVIEW_REPORT_COLUMN_TASK", "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT", "ACCESS_REVIEW_REPORT_COLUMN_USER_NAME", "ACCESS_REVIEW_REPORT_COLUMN_IDENTITY_TYPE", "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER", "ACCESS_REVIEW_REPORT_COLUMN_ACCOUNT_OWNER_EMAIL", "ACCESS_REVIEW_REPORT_COLUMN_APPLICATION", "ACCESS_REVIEW_REPORT_COLUMN_RESOURCE", "ACCESS_REVIEW_REPORT_COLUMN_RESOURCE_TYPE", "ACCESS_REVIEW_REPORT_COLUMN_ENTITLEMENT", "ACCESS_REVIEW_REPORT_COLUMN_DESCRIPTION", "ACCESS_REVIEW_REPORT_COLUMN_CERTIFICATION_POLICY", "ACCESS_REVIEW_REPORT_COLUMN_ASSIGNED_TO", "ACCESS_REVIEW_REPORT_COLUMN_REASSIGNMENTS", "ACCESS_REVIEW_REPORT_COLUMN_CERTIFIERS", "ACCESS_REVIEW_REPORT_COLUMN_DECISIONS", "ACCESS_REVIEW_REPORT_COLUMN_RESOLVED_ON", "ACCESS_REVIEW_REPORT_COLUMN_COMMENTS", "ACCESS_REVIEW_REPORT_COLUMN_LAST_LOGIN", "ACCESS_REVIEW_REPORT_COLUMN_SUBMISSIONS", "ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET", "ACCESS_REVIEW_REPORT_COLUMN_EXTERNAL_TICKET_STATUS", "ACCESS_REVIEW_REPORT_COLUMN_SUBJECT_USERNAME": + return true + } + } + return false +} + +// AccessReviewReportColumnConfig - Configuration for columns in the generated access review Excel report. +type AccessReviewReportColumnConfig struct { + // Ordered list of columns to include in the report's "Access Reviews" sheet. + // When non-empty, the report renders exactly these columns in the order given. + // When empty, the default column set is used (the original 19 columns without + // Employee ID or other user-attribute extras). + Columns []AccessReviewReportColumnConfigColumns `json:"columns,omitempty"` +} + +func (a *AccessReviewReportColumnConfig) GetColumns() []AccessReviewReportColumnConfigColumns { + if a == nil { + return nil + } + return a.Columns +} diff --git a/pkg/models/shared/accessreviewreportservicelistresponse.go b/pkg/models/shared/accessreviewreportservicelistresponse.go new file mode 100644 index 000000000..5ae0c699b --- /dev/null +++ b/pkg/models/shared/accessreviewreportservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AccessReviewReportServiceListResponse message. +type AccessReviewReportServiceListResponse struct { + // The list field. + List []AccessReviewReport `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (a *AccessReviewReportServiceListResponse) GetList() []AccessReviewReport { + if a == nil { + return nil + } + return a.List +} + +func (a *AccessReviewReportServiceListResponse) GetNextPageToken() *string { + if a == nil { + return nil + } + return a.NextPageToken +} diff --git a/pkg/models/shared/accessreviewtaskcolumnref.go b/pkg/models/shared/accessreviewtaskcolumnref.go new file mode 100644 index 000000000..974ccca09 --- /dev/null +++ b/pkg/models/shared/accessreviewtaskcolumnref.go @@ -0,0 +1,91 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Builtin - The builtin field. +// This field is part of the `column` oneof. +// See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. +type Builtin string + +const ( + BuiltinAccessReviewTaskColumnUnspecified Builtin = "ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED" + BuiltinAccessReviewTaskColumnViewLink Builtin = "ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK" + BuiltinAccessReviewTaskColumnCurrentState Builtin = "ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE" + BuiltinAccessReviewTaskColumnAccount Builtin = "ACCESS_REVIEW_TASK_COLUMN_ACCOUNT" + BuiltinAccessReviewTaskColumnAccountOwner Builtin = "ACCESS_REVIEW_TASK_COLUMN_ACCOUNT_OWNER" + BuiltinAccessReviewTaskColumnEntitlement Builtin = "ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT" + BuiltinAccessReviewTaskColumnEntitlementDescription Builtin = "ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT_DESCRIPTION" + BuiltinAccessReviewTaskColumnResource Builtin = "ACCESS_REVIEW_TASK_COLUMN_RESOURCE" + BuiltinAccessReviewTaskColumnResourceType Builtin = "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_TYPE" + BuiltinAccessReviewTaskColumnInsights Builtin = "ACCESS_REVIEW_TASK_COLUMN_INSIGHTS" + BuiltinAccessReviewTaskColumnRecommendation Builtin = "ACCESS_REVIEW_TASK_COLUMN_RECOMMENDATION" + BuiltinAccessReviewTaskColumnAssignedTo Builtin = "ACCESS_REVIEW_TASK_COLUMN_ASSIGNED_TO" + BuiltinAccessReviewTaskColumnStatus Builtin = "ACCESS_REVIEW_TASK_COLUMN_STATUS" + BuiltinAccessReviewTaskColumnApp Builtin = "ACCESS_REVIEW_TASK_COLUMN_APP" + BuiltinAccessReviewTaskColumnDue Builtin = "ACCESS_REVIEW_TASK_COLUMN_DUE" + BuiltinAccessReviewTaskColumnProject Builtin = "ACCESS_REVIEW_TASK_COLUMN_PROJECT" + BuiltinAccessReviewTaskColumnCreatedOn Builtin = "ACCESS_REVIEW_TASK_COLUMN_CREATED_ON" + BuiltinAccessReviewTaskColumnTaskAge Builtin = "ACCESS_REVIEW_TASK_COLUMN_TASK_AGE" + BuiltinAccessReviewTaskColumnResolvedOn Builtin = "ACCESS_REVIEW_TASK_COLUMN_RESOLVED_ON" + BuiltinAccessReviewTaskColumnEnrollmentStatus Builtin = "ACCESS_REVIEW_TASK_COLUMN_ENROLLMENT_STATUS" + BuiltinAccessReviewTaskColumnInheritedFrom Builtin = "ACCESS_REVIEW_TASK_COLUMN_INHERITED_FROM" + BuiltinAccessReviewTaskColumnDepartment Builtin = "ACCESS_REVIEW_TASK_COLUMN_DEPARTMENT" + BuiltinAccessReviewTaskColumnJobTitle Builtin = "ACCESS_REVIEW_TASK_COLUMN_JOB_TITLE" + BuiltinAccessReviewTaskColumnCreatedBy Builtin = "ACCESS_REVIEW_TASK_COLUMN_CREATED_BY" + BuiltinAccessReviewTaskColumnLastLogin Builtin = "ACCESS_REVIEW_TASK_COLUMN_LAST_LOGIN" + BuiltinAccessReviewTaskColumnResourceParent Builtin = "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_PARENT" + BuiltinAccessReviewTaskColumnResourceChildren Builtin = "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_CHILDREN" + BuiltinAccessReviewTaskColumnAppUserUsername Builtin = "ACCESS_REVIEW_TASK_COLUMN_APP_USER_USERNAME" + BuiltinAccessReviewTaskColumnAccessHolderType Builtin = "ACCESS_REVIEW_TASK_COLUMN_ACCESS_HOLDER_TYPE" + BuiltinAccessReviewTaskColumnRiskLevel Builtin = "ACCESS_REVIEW_TASK_COLUMN_RISK_LEVEL" + BuiltinAccessReviewTaskColumnComplianceFramework Builtin = "ACCESS_REVIEW_TASK_COLUMN_COMPLIANCE_FRAMEWORK" +) + +func (e Builtin) ToPointer() *Builtin { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Builtin) IsExact() bool { + if e != nil { + switch *e { + case "ACCESS_REVIEW_TASK_COLUMN_UNSPECIFIED", "ACCESS_REVIEW_TASK_COLUMN_VIEW_LINK", "ACCESS_REVIEW_TASK_COLUMN_CURRENT_STATE", "ACCESS_REVIEW_TASK_COLUMN_ACCOUNT", "ACCESS_REVIEW_TASK_COLUMN_ACCOUNT_OWNER", "ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT", "ACCESS_REVIEW_TASK_COLUMN_ENTITLEMENT_DESCRIPTION", "ACCESS_REVIEW_TASK_COLUMN_RESOURCE", "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_TYPE", "ACCESS_REVIEW_TASK_COLUMN_INSIGHTS", "ACCESS_REVIEW_TASK_COLUMN_RECOMMENDATION", "ACCESS_REVIEW_TASK_COLUMN_ASSIGNED_TO", "ACCESS_REVIEW_TASK_COLUMN_STATUS", "ACCESS_REVIEW_TASK_COLUMN_APP", "ACCESS_REVIEW_TASK_COLUMN_DUE", "ACCESS_REVIEW_TASK_COLUMN_PROJECT", "ACCESS_REVIEW_TASK_COLUMN_CREATED_ON", "ACCESS_REVIEW_TASK_COLUMN_TASK_AGE", "ACCESS_REVIEW_TASK_COLUMN_RESOLVED_ON", "ACCESS_REVIEW_TASK_COLUMN_ENROLLMENT_STATUS", "ACCESS_REVIEW_TASK_COLUMN_INHERITED_FROM", "ACCESS_REVIEW_TASK_COLUMN_DEPARTMENT", "ACCESS_REVIEW_TASK_COLUMN_JOB_TITLE", "ACCESS_REVIEW_TASK_COLUMN_CREATED_BY", "ACCESS_REVIEW_TASK_COLUMN_LAST_LOGIN", "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_PARENT", "ACCESS_REVIEW_TASK_COLUMN_RESOURCE_CHILDREN", "ACCESS_REVIEW_TASK_COLUMN_APP_USER_USERNAME", "ACCESS_REVIEW_TASK_COLUMN_ACCESS_HOLDER_TYPE", "ACCESS_REVIEW_TASK_COLUMN_RISK_LEVEL", "ACCESS_REVIEW_TASK_COLUMN_COMPLIANCE_FRAMEWORK": + return true + } + } + return false +} + +// AccessReviewTaskColumnRef - One column in the reviewer task list: a built-in column, or an app user +// +// profile attribute. An attribute only renders for apps whose +// reviewer_attribute_config permits it — that config is the authorization, +// this is the view preference. +// +// This message contains a oneof named column. Only a single field of the following list may be set at a time: +// - builtin +// - appUserAttributeKey +type AccessReviewTaskColumnRef struct { + // The appUserAttributeKey field. + // This field is part of the `column` oneof. + // See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. + AppUserAttributeKey *string `json:"appUserAttributeKey,omitempty"` + // The builtin field. + // This field is part of the `column` oneof. + // See the documentation for `c1.api.accessreview.v1.AccessReviewTaskColumnRef` for more details. + Builtin *Builtin `json:"builtin,omitempty"` +} + +func (a *AccessReviewTaskColumnRef) GetAppUserAttributeKey() *string { + if a == nil { + return nil + } + return a.AppUserAttributeKey +} + +func (a *AccessReviewTaskColumnRef) GetBuiltin() *Builtin { + if a == nil { + return nil + } + return a.Builtin +} diff --git a/pkg/models/shared/accessreviewtemplate.go b/pkg/models/shared/accessreviewtemplate.go index b852121d5..e76a9eaa7 100644 --- a/pkg/models/shared/accessreviewtemplate.go +++ b/pkg/models/shared/accessreviewtemplate.go @@ -115,6 +115,7 @@ func (e *AccessReviewTemplateScopeType) IsExact() bool { // // This message contains a oneof named slack_channel_details. Only a single field of the following list may be set at a time: // - slackChannel +// - msTeamsChannel type AccessReviewTemplate struct { AccessReviewDuration *string `json:"accessReviewDuration,omitempty"` // The accuracyIssueAction field. @@ -154,6 +155,7 @@ type AccessReviewTemplate struct { InclusionScope *AccessReviewInclusionScope `json:"inclusionScope,omitempty"` // Whether automatic campaign creation on the recurrence schedule is enabled. IsCampaignScheduleEnabled *bool `json:"isCampaignScheduleEnabled,omitempty"` + MsTeamsChannel *MSTeamsChannel `json:"msTeamsChannel,omitempty"` NextScheduledCampaignAt *time.Time `json:"nextScheduledCampaignAt,omitempty"` NotificationConfig *NotificationConfig `json:"notificationConfig,omitempty"` // The number of campaigns that have been created from this template. @@ -304,6 +306,13 @@ func (a *AccessReviewTemplate) GetIsCampaignScheduleEnabled() *bool { return a.IsCampaignScheduleEnabled } +func (a *AccessReviewTemplate) GetMsTeamsChannel() *MSTeamsChannel { + if a == nil { + return nil + } + return a.MsTeamsChannel +} + func (a *AccessReviewTemplate) GetNextScheduledCampaignAt() *time.Time { if a == nil { return nil @@ -401,6 +410,7 @@ func (a *AccessReviewTemplate) GetUsePolicyOverride() *bool { // // This message contains a oneof named slack_channel_details. Only a single field of the following list may be set at a time: // - slackChannel +// - msTeamsChannel type AccessReviewTemplateInput struct { AccessReviewDuration *string `json:"accessReviewDuration,omitempty"` // The accuracyIssueAction field. @@ -438,6 +448,7 @@ type AccessReviewTemplateInput struct { InclusionScope *AccessReviewInclusionScope `json:"inclusionScope,omitempty"` // Whether automatic campaign creation on the recurrence schedule is enabled. IsCampaignScheduleEnabled *bool `json:"isCampaignScheduleEnabled,omitempty"` + MsTeamsChannel *MSTeamsChannel `json:"msTeamsChannel,omitempty"` NextScheduledCampaignAt *time.Time `json:"nextScheduledCampaignAt,omitempty"` NotificationConfig *NotificationConfig `json:"notificationConfig,omitempty"` // The number of campaigns that have been created from this template. @@ -573,6 +584,13 @@ func (a *AccessReviewTemplateInput) GetIsCampaignScheduleEnabled() *bool { return a.IsCampaignScheduleEnabled } +func (a *AccessReviewTemplateInput) GetMsTeamsChannel() *MSTeamsChannel { + if a == nil { + return nil + } + return a.MsTeamsChannel +} + func (a *AccessReviewTemplateInput) GetNextScheduledCampaignAt() *time.Time { if a == nil { return nil diff --git a/pkg/models/shared/aigovernancesettings.go b/pkg/models/shared/aigovernancesettings.go index e4b83848b..a60dc93e5 100644 --- a/pkg/models/shared/aigovernancesettings.go +++ b/pkg/models/shared/aigovernancesettings.go @@ -139,8 +139,14 @@ type AIGovernanceSettings struct { // describe entrypoint. Invoking such a tool opens (or reuses) an // access-request ticket and returns a request_created envelope instead of // executing. Defaults to true. - SurfaceRequestableTools *bool `json:"surfaceRequestableTools,omitempty"` - UpdatedAt *time.Time `json:"updatedAt,omitempty"` + SurfaceRequestableTools *bool `json:"surfaceRequestableTools,omitempty"` + // When true, the A2 (untrusted-content) judge is skipped and the untrusted + // dimension always scores LOW. When false (the default), the judge scores + // agent turn input and tool output for prompt-injection risk on every turn. + // + // Defaults to false, so the judge runs by default. + UntrustedJudgeDisable *bool `json:"untrustedJudgeDisable,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` } func (a AIGovernanceSettings) MarshalJSON() ([]byte, error) { @@ -252,6 +258,13 @@ func (a *AIGovernanceSettings) GetSurfaceRequestableTools() *bool { return a.SurfaceRequestableTools } +func (a *AIGovernanceSettings) GetUntrustedJudgeDisable() *bool { + if a == nil { + return nil + } + return a.UntrustedJudgeDisable +} + func (a *AIGovernanceSettings) GetUpdatedAt() *time.Time { if a == nil { return nil diff --git a/pkg/models/shared/app.go b/pkg/models/shared/app.go index ebd33735d..7dabae0cb 100644 --- a/pkg/models/shared/app.go +++ b/pkg/models/shared/app.go @@ -110,7 +110,8 @@ type App struct { // The isManuallyManaged field. IsManuallyManaged *bool `json:"isManuallyManaged,omitempty"` // The URL of a logo to display for the app. - LogoURI *string `json:"logoUri,omitempty"` + LogoURI *string `json:"logoUri,omitempty"` + MatchBatonRef *AppMatchBatonRef `json:"matchBatonRef,omitempty"` // The cost of an app per-seat, so that total cost can be calculated by the grant count. MonthlyCostUsd *int `json:"monthlyCostUsd,omitempty"` // The ID of the app that created this app, if any. @@ -298,6 +299,13 @@ func (a *App) GetLogoURI() *string { return a.LogoURI } +func (a *App) GetMatchBatonRef() *AppMatchBatonRef { + if a == nil { + return nil + } + return a.MatchBatonRef +} + func (a *App) GetMonthlyCostUsd() *int { if a == nil { return nil @@ -383,7 +391,8 @@ type AppInput struct { // If you add instructions here, they will be shown to users in the access request form when requesting access for this app. Instructions *string `json:"instructions,omitempty"` // The isManuallyManaged field. - IsManuallyManaged *bool `json:"isManuallyManaged,omitempty"` + IsManuallyManaged *bool `json:"isManuallyManaged,omitempty"` + MatchBatonRef *AppMatchBatonRef `json:"matchBatonRef,omitempty"` // The cost of an app per-seat, so that total cost can be calculated by the grant count. MonthlyCostUsd *int `json:"monthlyCostUsd,omitempty"` // When enabled, revoking a grant also revokes the grants that source it. @@ -492,6 +501,13 @@ func (a *AppInput) GetIsManuallyManaged() *bool { return a.IsManuallyManaged } +func (a *AppInput) GetMatchBatonRef() *AppMatchBatonRef { + if a == nil { + return nil + } + return a.MatchBatonRef +} + func (a *AppInput) GetMonthlyCostUsd() *int { if a == nil { return nil diff --git a/pkg/models/shared/appcap.go b/pkg/models/shared/appcap.go new file mode 100644 index 000000000..df87805f2 --- /dev/null +++ b/pkg/models/shared/appcap.go @@ -0,0 +1,65 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// AppCap is one app's tenant-wide ceiling as the API renders it. +type AppCap struct { + // The C1 App the spend is attributed to. + AppID *string `json:"appId,omitempty"` + Controls *SpendControls `json:"controls,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (a AppCap) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(a, "", false) +} + +func (a *AppCap) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &a, "", false, nil); err != nil { + return err + } + return nil +} + +func (a *AppCap) GetAppID() *string { + if a == nil { + return nil + } + return a.AppID +} + +func (a *AppCap) GetControls() *SpendControls { + if a == nil { + return nil + } + return a.Controls +} + +func (a *AppCap) GetCreatedAt() *time.Time { + if a == nil { + return nil + } + return a.CreatedAt +} + +func (a *AppCap) GetTenantID() *string { + if a == nil { + return nil + } + return a.TenantID +} + +func (a *AppCap) GetUpdatedAt() *time.Time { + if a == nil { + return nil + } + return a.UpdatedAt +} diff --git a/pkg/models/shared/appcaphistoryentry.go b/pkg/models/shared/appcaphistoryentry.go new file mode 100644 index 000000000..87b5152d1 --- /dev/null +++ b/pkg/models/shared/appcaphistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapHistoryEntry message. +type AppCapHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *AppCap `json:"snapshot,omitempty"` +} + +func (a *AppCapHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if a == nil { + return nil + } + return a.Metadata +} + +func (a *AppCapHistoryEntry) GetSnapshot() *AppCap { + if a == nil { + return nil + } + return a.Snapshot +} diff --git a/pkg/models/shared/appcapservicedeleterequest.go b/pkg/models/shared/appcapservicedeleterequest.go new file mode 100644 index 000000000..ffeb5c36a --- /dev/null +++ b/pkg/models/shared/appcapservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceDeleteRequest message. +type AppCapServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/appcapservicedeleteresponse.go b/pkg/models/shared/appcapservicedeleteresponse.go new file mode 100644 index 000000000..7e90f0589 --- /dev/null +++ b/pkg/models/shared/appcapservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceDeleteResponse message. +type AppCapServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/appcapservicegetresponse.go b/pkg/models/shared/appcapservicegetresponse.go new file mode 100644 index 000000000..f65ea1d58 --- /dev/null +++ b/pkg/models/shared/appcapservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceGetResponse message. +type AppCapServiceGetResponse struct { + Cap *AppCap `json:"cap,omitempty"` +} + +func (a *AppCapServiceGetResponse) GetCap() *AppCap { + if a == nil { + return nil + } + return a.Cap +} diff --git a/pkg/models/shared/appcapservicelisthistoryresponse.go b/pkg/models/shared/appcapservicelisthistoryresponse.go new file mode 100644 index 000000000..318f22278 --- /dev/null +++ b/pkg/models/shared/appcapservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceListHistoryResponse message. +type AppCapServiceListHistoryResponse struct { + // The list field. + List []AppCapHistoryEntry `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (a *AppCapServiceListHistoryResponse) GetList() []AppCapHistoryEntry { + if a == nil { + return nil + } + return a.List +} + +func (a *AppCapServiceListHistoryResponse) GetNextPageToken() *string { + if a == nil { + return nil + } + return a.NextPageToken +} diff --git a/pkg/models/shared/appcapservicelistresponse.go b/pkg/models/shared/appcapservicelistresponse.go new file mode 100644 index 000000000..99c965044 --- /dev/null +++ b/pkg/models/shared/appcapservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceListResponse message. +type AppCapServiceListResponse struct { + // The list field. + List []AppCap `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (a *AppCapServiceListResponse) GetList() []AppCap { + if a == nil { + return nil + } + return a.List +} + +func (a *AppCapServiceListResponse) GetNextPageToken() *string { + if a == nil { + return nil + } + return a.NextPageToken +} diff --git a/pkg/models/shared/appcapservicesetlimitrequest.go b/pkg/models/shared/appcapservicesetlimitrequest.go new file mode 100644 index 000000000..156f111bc --- /dev/null +++ b/pkg/models/shared/appcapservicesetlimitrequest.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Period - Optional period override. Only valid together with the limit it denominates. +type Period string + +const ( + PeriodPeriodKindUnspecified Period = "PERIOD_KIND_UNSPECIFIED" + PeriodPeriodKindDaily Period = "PERIOD_KIND_DAILY" + PeriodPeriodKindWeekly Period = "PERIOD_KIND_WEEKLY" + PeriodPeriodKindMonthly Period = "PERIOD_KIND_MONTHLY" + PeriodPeriodKindQuarterly Period = "PERIOD_KIND_QUARTERLY" + PeriodPeriodKindYearly Period = "PERIOD_KIND_YEARLY" +) + +func (e Period) ToPointer() *Period { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Period) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// The AppCapServiceSetLimitRequest message. +type AppCapServiceSetLimitRequest struct { + Limit *SpendLimit `json:"limit,omitempty"` + // Optional period override. Only valid together with the limit it denominates. + Period *Period `json:"period,omitempty"` +} + +func (a *AppCapServiceSetLimitRequest) GetLimit() *SpendLimit { + if a == nil { + return nil + } + return a.Limit +} + +func (a *AppCapServiceSetLimitRequest) GetPeriod() *Period { + if a == nil { + return nil + } + return a.Period +} diff --git a/pkg/models/shared/appcapservicesetlimitresponse.go b/pkg/models/shared/appcapservicesetlimitresponse.go new file mode 100644 index 000000000..170017c9b --- /dev/null +++ b/pkg/models/shared/appcapservicesetlimitresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceSetLimitResponse message. +type AppCapServiceSetLimitResponse struct { + Cap *AppCap `json:"cap,omitempty"` +} + +func (a *AppCapServiceSetLimitResponse) GetCap() *AppCap { + if a == nil { + return nil + } + return a.Cap +} diff --git a/pkg/models/shared/appcapservicesuspendrequest.go b/pkg/models/shared/appcapservicesuspendrequest.go new file mode 100644 index 000000000..a94659752 --- /dev/null +++ b/pkg/models/shared/appcapservicesuspendrequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceSuspendRequest message. +type AppCapServiceSuspendRequest struct { + // The reason field. + Reason *string `json:"reason,omitempty"` +} + +func (a *AppCapServiceSuspendRequest) GetReason() *string { + if a == nil { + return nil + } + return a.Reason +} diff --git a/pkg/models/shared/appcapservicesuspendresponse.go b/pkg/models/shared/appcapservicesuspendresponse.go new file mode 100644 index 000000000..05e54a68a --- /dev/null +++ b/pkg/models/shared/appcapservicesuspendresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceSuspendResponse message. +type AppCapServiceSuspendResponse struct { + Cap *AppCap `json:"cap,omitempty"` +} + +func (a *AppCapServiceSuspendResponse) GetCap() *AppCap { + if a == nil { + return nil + } + return a.Cap +} diff --git a/pkg/models/shared/appcapserviceunsuspendrequest.go b/pkg/models/shared/appcapserviceunsuspendrequest.go new file mode 100644 index 000000000..b1d220b0b --- /dev/null +++ b/pkg/models/shared/appcapserviceunsuspendrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceUnsuspendRequest message. +type AppCapServiceUnsuspendRequest struct { +} diff --git a/pkg/models/shared/appcapserviceunsuspendresponse.go b/pkg/models/shared/appcapserviceunsuspendresponse.go new file mode 100644 index 000000000..3a93f86c7 --- /dev/null +++ b/pkg/models/shared/appcapserviceunsuspendresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The AppCapServiceUnsuspendResponse message. +type AppCapServiceUnsuspendResponse struct { + Cap *AppCap `json:"cap,omitempty"` +} + +func (a *AppCapServiceUnsuspendResponse) GetCap() *AppCap { + if a == nil { + return nil + } + return a.Cap +} diff --git a/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.go b/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.go new file mode 100644 index 000000000..224a36bee --- /dev/null +++ b/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserrequest.go @@ -0,0 +1,53 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppEntitlementSearchServiceSearchReachableResourcesForUserRequest - SearchReachableResourcesForUser request. +type AppEntitlementSearchServiceSearchReachableResourcesForUserRequest struct { + // Restrict results to resources belonging to these applications. Empty + // searches across every application the user can reach. + AppIds []string `json:"appIds,omitempty"` + // Maximum number of results to return per page. + PageSize *int `json:"pageSize,omitempty"` + // Token for fetching the next page of results. + PageToken *string `json:"pageToken,omitempty"` + // Fuzzy search over the resource display name. + Query *string `json:"query,omitempty"` + // The user whose reachable resources to search. + UserID *string `json:"userId,omitempty"` +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserRequest) GetAppIds() []string { + if a == nil { + return nil + } + return a.AppIds +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserRequest) GetPageSize() *int { + if a == nil { + return nil + } + return a.PageSize +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserRequest) GetPageToken() *string { + if a == nil { + return nil + } + return a.PageToken +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserRequest) GetQuery() *string { + if a == nil { + return nil + } + return a.Query +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserRequest) GetUserID() *string { + if a == nil { + return nil + } + return a.UserID +} diff --git a/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.go b/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.go new file mode 100644 index 000000000..2bc7b5e84 --- /dev/null +++ b/pkg/models/shared/appentitlementsearchservicesearchreachableresourcesforuserresponse.go @@ -0,0 +1,28 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppEntitlementSearchServiceSearchReachableResourcesForUserResponse - SearchReachableResourcesForUser response. Resources are deduplicated: a +// +// resource reachable through more than one grant or entitlement appears once. +type AppEntitlementSearchServiceSearchReachableResourcesForUserResponse struct { + // The reachable resources, one GraphNode (type = GRAPH_NODE_TYPE_RESOURCE) + // per distinct resource. Uses the same node representation as SearchGraph. + List []GraphNode `json:"list,omitempty"` + // Token for fetching the next page of results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetList() []GraphNode { + if a == nil { + return nil + } + return a.List +} + +func (a *AppEntitlementSearchServiceSearchReachableResourcesForUserResponse) GetNextPageToken() *string { + if a == nil { + return nil + } + return a.NextPageToken +} diff --git a/pkg/models/shared/appentitlementuserbindinghistory.go b/pkg/models/shared/appentitlementuserbindinghistory.go index 535c58f13..f7cdc5901 100644 --- a/pkg/models/shared/appentitlementuserbindinghistory.go +++ b/pkg/models/shared/appentitlementuserbindinghistory.go @@ -16,6 +16,8 @@ type AppEntitlementUserBindingHistory struct { // The ID of the app user that has access to the app entitlement AppUserID *string `json:"appUserId,omitempty"` GrantedAt *time.Time `json:"grantedAt,omitempty"` + // The unique ID of this grant history record + ID *string `json:"id,omitempty"` RevokedAt *time.Time `json:"revokedAt,omitempty"` } @@ -58,6 +60,13 @@ func (a *AppEntitlementUserBindingHistory) GetGrantedAt() *time.Time { return a.GrantedAt } +func (a *AppEntitlementUserBindingHistory) GetID() *string { + if a == nil { + return nil + } + return a.ID +} + func (a *AppEntitlementUserBindingHistory) GetRevokedAt() *time.Time { if a == nil { return nil diff --git a/pkg/models/shared/appmanagedstate.go b/pkg/models/shared/appmanagedstate.go new file mode 100644 index 000000000..98fece5a2 --- /dev/null +++ b/pkg/models/shared/appmanagedstate.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppManagedState identifies whether a discovered application is managed. +// +// This message contains a oneof named state. Only a single field of the following list may be set at a time: +// - unmanaged +// - managed +type AppManagedState struct { + Managed *AppManagedStateManaged `json:"managed,omitempty"` + Unmanaged *AppManagedStateUnmanaged `json:"unmanaged,omitempty"` +} + +func (a *AppManagedState) GetManaged() *AppManagedStateManaged { + if a == nil { + return nil + } + return a.Managed +} + +func (a *AppManagedState) GetUnmanaged() *AppManagedStateUnmanaged { + if a == nil { + return nil + } + return a.Unmanaged +} diff --git a/pkg/models/shared/appmanagedstatebinding.go b/pkg/models/shared/appmanagedstatebinding.go new file mode 100644 index 000000000..d0422a7e9 --- /dev/null +++ b/pkg/models/shared/appmanagedstatebinding.go @@ -0,0 +1,91 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// AppManagedStateBinding records whether a connector-discovered application is managed in ConductorOne. +type AppManagedStateBinding struct { + // Application that owns the connector which discovered this application. + AppID *string `json:"appId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // Display name of the discovered application. + DisplayName *string `json:"displayName,omitempty"` + // Resource ID of the discovered application. + ResourceID *string `json:"resourceId,omitempty"` + // Resource type used by the connector to represent discovered applications. + ResourceTypeID *string `json:"resourceTypeId,omitempty"` + State *AppManagedState `json:"state,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (a AppManagedStateBinding) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(a, "", false) +} + +func (a *AppManagedStateBinding) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &a, "", false, nil); err != nil { + return err + } + return nil +} + +func (a *AppManagedStateBinding) GetAppID() *string { + if a == nil { + return nil + } + return a.AppID +} + +func (a *AppManagedStateBinding) GetCreatedAt() *time.Time { + if a == nil { + return nil + } + return a.CreatedAt +} + +func (a *AppManagedStateBinding) GetDeletedAt() *time.Time { + if a == nil { + return nil + } + return a.DeletedAt +} + +func (a *AppManagedStateBinding) GetDisplayName() *string { + if a == nil { + return nil + } + return a.DisplayName +} + +func (a *AppManagedStateBinding) GetResourceID() *string { + if a == nil { + return nil + } + return a.ResourceID +} + +func (a *AppManagedStateBinding) GetResourceTypeID() *string { + if a == nil { + return nil + } + return a.ResourceTypeID +} + +func (a *AppManagedStateBinding) GetState() *AppManagedState { + if a == nil { + return nil + } + return a.State +} + +func (a *AppManagedStateBinding) GetUpdatedAt() *time.Time { + if a == nil { + return nil + } + return a.UpdatedAt +} diff --git a/pkg/models/shared/appmanagedstatebindingexpandmask.go b/pkg/models/shared/appmanagedstatebindingexpandmask.go new file mode 100644 index 000000000..3d29b09ea --- /dev/null +++ b/pkg/models/shared/appmanagedstatebindingexpandmask.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppManagedStateBindingExpandMask controls which related objects are included in a response. +type AppManagedStateBindingExpandMask struct { + // Related objects to include. Supported values are `app_id`, `resource_id`, and `*`. + Paths []string `json:"paths,omitempty"` +} + +func (a *AppManagedStateBindingExpandMask) GetPaths() []string { + if a == nil { + return nil + } + return a.Paths +} diff --git a/pkg/models/shared/appmanagedstatebindingref.go b/pkg/models/shared/appmanagedstatebindingref.go index d76e28b12..52cecac94 100644 --- a/pkg/models/shared/appmanagedstatebindingref.go +++ b/pkg/models/shared/appmanagedstatebindingref.go @@ -2,13 +2,13 @@ package shared -// The AppManagedStateBindingRef message. +// AppManagedStateBindingRef identifies an application discovered by a connector. type AppManagedStateBindingRef struct { - // The appId field. + // ID of the application that owns the connector. AppID *string `json:"appId,omitempty"` - // The resourceId field. + // Resource ID of the discovered application. ResourceID *string `json:"resourceId,omitempty"` - // The resourceTypeId field. + // ID of the resource type used for discovered applications. ResourceTypeID *string `json:"resourceTypeId,omitempty"` } diff --git a/pkg/models/shared/appmanagedstatebindingview.go b/pkg/models/shared/appmanagedstatebindingview.go new file mode 100644 index 000000000..c696be273 --- /dev/null +++ b/pkg/models/shared/appmanagedstatebindingview.go @@ -0,0 +1,33 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppManagedStateBindingView contains a managed-state binding and paths to its related objects. +type AppManagedStateBindingView struct { + AppManagementStateBinding *AppManagedStateBinding `json:"appManagementStateBinding,omitempty"` + // Path of the application that owns the connector. + AppPath *string `json:"appPath,omitempty"` + // Path of the connector resource representing the discovered application. + ResourcePath *string `json:"resourcePath,omitempty"` +} + +func (a *AppManagedStateBindingView) GetAppManagementStateBinding() *AppManagedStateBinding { + if a == nil { + return nil + } + return a.AppManagementStateBinding +} + +func (a *AppManagedStateBindingView) GetAppPath() *string { + if a == nil { + return nil + } + return a.AppPath +} + +func (a *AppManagedStateBindingView) GetResourcePath() *string { + if a == nil { + return nil + } + return a.ResourcePath +} diff --git a/pkg/models/shared/appmanagedstatemanaged.go b/pkg/models/shared/appmanagedstatemanaged.go new file mode 100644 index 000000000..9c176709a --- /dev/null +++ b/pkg/models/shared/appmanagedstatemanaged.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppManagedStateManaged identifies the application created by promotion. +type AppManagedStateManaged struct { + // ID of the managed application. + AppID *string `json:"appId,omitempty"` +} + +func (a *AppManagedStateManaged) GetAppID() *string { + if a == nil { + return nil + } + return a.AppID +} diff --git a/pkg/models/shared/appmanagedstateunmanaged.go b/pkg/models/shared/appmanagedstateunmanaged.go new file mode 100644 index 000000000..1cb6eb000 --- /dev/null +++ b/pkg/models/shared/appmanagedstateunmanaged.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppManagedStateUnmanaged indicates that the discovered application has not been promoted. +type AppManagedStateUnmanaged struct { +} diff --git a/pkg/models/shared/appmatchbatonref.go b/pkg/models/shared/appmatchbatonref.go new file mode 100644 index 000000000..d4c6a85cf --- /dev/null +++ b/pkg/models/shared/appmatchbatonref.go @@ -0,0 +1,35 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// AppMatchBatonRef identifies the connector application that should adopt a manually-created application during uplift. +type AppMatchBatonRef struct { + // Application that owns the connector. + AppID string `json:"appId"` + // Connector that discovers the application. + ConnectorID string `json:"connectorId"` + // Canonical connector-v2 application resource ID in + // `::` form (for example, `app::0oa123`). + ExternalID string `json:"externalId"` +} + +func (a *AppMatchBatonRef) GetAppID() string { + if a == nil { + return "" + } + return a.AppID +} + +func (a *AppMatchBatonRef) GetConnectorID() string { + if a == nil { + return "" + } + return a.ConnectorID +} + +func (a *AppMatchBatonRef) GetExternalID() string { + if a == nil { + return "" + } + return a.ExternalID +} diff --git a/pkg/models/shared/appuser.go b/pkg/models/shared/appuser.go index 14969b719..d45c6ed13 100644 --- a/pkg/models/shared/appuser.go +++ b/pkg/models/shared/appuser.go @@ -7,6 +7,34 @@ import ( "time" ) +// AgentStatus - AI-agent lifecycle status when this app user carries the agent trait. +// +// UNSPECIFIED marks a non-agent account. Read-only; translated from the +// model's agent_trait at the API boundary. +type AgentStatus string + +const ( + AgentStatusAppUserAgentStatusUnspecified AgentStatus = "APP_USER_AGENT_STATUS_UNSPECIFIED" + AgentStatusAppUserAgentStatusReady AgentStatus = "APP_USER_AGENT_STATUS_READY" + AgentStatusAppUserAgentStatusDisabled AgentStatus = "APP_USER_AGENT_STATUS_DISABLED" + AgentStatusAppUserAgentStatusDeleted AgentStatus = "APP_USER_AGENT_STATUS_DELETED" +) + +func (e AgentStatus) ToPointer() *AgentStatus { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AgentStatus) IsExact() bool { + if e != nil { + switch *e { + case "APP_USER_AGENT_STATUS_UNSPECIFIED", "APP_USER_AGENT_STATUS_READY", "APP_USER_AGENT_STATUS_DISABLED", "APP_USER_AGENT_STATUS_DELETED": + return true + } + } + return false +} + // AppUserType - The appplication user type. Type can be user, system or service. type AppUserType string @@ -32,8 +60,39 @@ func (e *AppUserType) IsExact() bool { return false } +// AppUserNhiType - NHI classification when this app user carries the non-human-identity trait. +// +// Read-only; translated from the model's nhi_trait at the API boundary. +type AppUserNhiType string + +const ( + AppUserNhiTypeAppUserNhiTypeUnspecified AppUserNhiType = "APP_USER_NHI_TYPE_UNSPECIFIED" + AppUserNhiTypeAppUserNhiTypeAppRegistration AppUserNhiType = "APP_USER_NHI_TYPE_APP_REGISTRATION" + AppUserNhiTypeAppUserNhiTypeAssumableRole AppUserNhiType = "APP_USER_NHI_TYPE_ASSUMABLE_ROLE" + AppUserNhiTypeAppUserNhiTypeManagedIdentity AppUserNhiType = "APP_USER_NHI_TYPE_MANAGED_IDENTITY" +) + +func (e AppUserNhiType) ToPointer() *AppUserNhiType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AppUserNhiType) IsExact() bool { + if e != nil { + switch *e { + case "APP_USER_NHI_TYPE_UNSPECIFIED", "APP_USER_NHI_TYPE_APP_REGISTRATION", "APP_USER_NHI_TYPE_ASSUMABLE_ROLE", "APP_USER_NHI_TYPE_MANAGED_IDENTITY": + return true + } + } + return false +} + // AppUser - Application User that represents an account in the application. type AppUser struct { + // AI-agent lifecycle status when this app user carries the agent trait. + // UNSPECIFIED marks a non-agent account. Read-only; translated from the + // model's agent_trait at the API boundary. + AgentStatus *AgentStatus `json:"agentStatus,omitempty"` // The ID of the application. AppID *string `json:"appId,omitempty"` // The appplication user type. Type can be user, system or service. @@ -53,10 +112,15 @@ type AppUser struct { // The conductor one user ID of the account owner. IdentityUserID *string `json:"identityUserId,omitempty"` // The isExternal field. - IsExternal *bool `json:"isExternal,omitempty"` - Profile map[string]any `json:"profile,omitempty"` - Status *AppUserStatus `json:"status,omitempty"` - UpdatedAt *time.Time `json:"updatedAt,omitempty"` + IsExternal *bool `json:"isExternal,omitempty"` + // Axis-2 detail refining nhi_type (e.g. "aws.role.lambda"). Read-only. + NhiDetail *string `json:"nhiDetail,omitempty"` + // NHI classification when this app user carries the non-human-identity trait. + // Read-only; translated from the model's nhi_trait at the API boundary. + NhiType *AppUserNhiType `json:"nhiType,omitempty"` + Profile map[string]any `json:"profile,omitempty"` + Status *AppUserStatus `json:"status,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` // The username field of the application user. Username *string `json:"username,omitempty"` // The usernames field of the application user. @@ -74,6 +138,13 @@ func (a *AppUser) UnmarshalJSON(data []byte) error { return nil } +func (a *AppUser) GetAgentStatus() *AgentStatus { + if a == nil { + return nil + } + return a.AgentStatus +} + func (a *AppUser) GetAppID() *string { if a == nil { return nil @@ -151,6 +222,20 @@ func (a *AppUser) GetIsExternal() *bool { return a.IsExternal } +func (a *AppUser) GetNhiDetail() *string { + if a == nil { + return nil + } + return a.NhiDetail +} + +func (a *AppUser) GetNhiType() *AppUserNhiType { + if a == nil { + return nil + } + return a.NhiType +} + func (a *AppUser) GetProfile() map[string]any { if a == nil { return nil diff --git a/pkg/models/shared/appuserservicesearchrequest.go b/pkg/models/shared/appuserservicesearchrequest.go index 7ed678e5a..038d15e11 100644 --- a/pkg/models/shared/appuserservicesearchrequest.go +++ b/pkg/models/shared/appuserservicesearchrequest.go @@ -2,6 +2,30 @@ package shared +type AgentStatuses string + +const ( + AgentStatusesAppUserAgentStatusUnspecified AgentStatuses = "APP_USER_AGENT_STATUS_UNSPECIFIED" + AgentStatusesAppUserAgentStatusReady AgentStatuses = "APP_USER_AGENT_STATUS_READY" + AgentStatusesAppUserAgentStatusDisabled AgentStatuses = "APP_USER_AGENT_STATUS_DISABLED" + AgentStatusesAppUserAgentStatusDeleted AgentStatuses = "APP_USER_AGENT_STATUS_DELETED" +) + +func (e AgentStatuses) ToPointer() *AgentStatuses { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AgentStatuses) IsExact() bool { + if e != nil { + switch *e { + case "APP_USER_AGENT_STATUS_UNSPECIFIED", "APP_USER_AGENT_STATUS_READY", "APP_USER_AGENT_STATUS_DISABLED", "APP_USER_AGENT_STATUS_DELETED": + return true + } + } + return false +} + type AppUserDomains string const ( @@ -73,6 +97,30 @@ func (e *AppUserServiceSearchRequestAppUserTypes) IsExact() bool { return false } +type NhiTypes string + +const ( + NhiTypesAppUserNhiTypeUnspecified NhiTypes = "APP_USER_NHI_TYPE_UNSPECIFIED" + NhiTypesAppUserNhiTypeAppRegistration NhiTypes = "APP_USER_NHI_TYPE_APP_REGISTRATION" + NhiTypesAppUserNhiTypeAssumableRole NhiTypes = "APP_USER_NHI_TYPE_ASSUMABLE_ROLE" + NhiTypesAppUserNhiTypeManagedIdentity NhiTypes = "APP_USER_NHI_TYPE_MANAGED_IDENTITY" +) + +func (e NhiTypes) ToPointer() *NhiTypes { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *NhiTypes) IsExact() bool { + if e != nil { + switch *e { + case "APP_USER_NHI_TYPE_UNSPECIFIED", "APP_USER_NHI_TYPE_APP_REGISTRATION", "APP_USER_NHI_TYPE_ASSUMABLE_ROLE", "APP_USER_NHI_TYPE_MANAGED_IDENTITY": + return true + } + } + return false +} + // SortBy - Ordering of the results. Defaults to display-name ordering. type SortBy string @@ -98,6 +146,9 @@ func (e *SortBy) IsExact() bool { // AppUserServiceSearchRequest - Search App users based on filters specified in the request body type AppUserServiceSearchRequest struct { + // Restrict to app users whose agent trait lifecycle status (agent_status) + // matches one of these values. When empty, agent_status is not used as a filter. + AgentStatuses []AgentStatuses `json:"agentStatuses,omitempty"` // The app ID to restrict the search to. AppID *string `json:"appId,omitempty"` // A list of app IDs to restrict the search to. @@ -117,6 +168,9 @@ type AppUserServiceSearchRequest struct { // When true, excludes app users belonging to soft-deleted apps. ExcludeDeletedApps *bool `json:"excludeDeletedApps,omitempty"` ExpandMask *AppUserExpandMask `json:"expandMask,omitempty"` + // Restrict to app users whose NHI trait classification (nhi_type) matches one of + // these values. When empty, nhi_type is not used as a filter. + NhiTypes []NhiTypes `json:"nhiTypes,omitempty"` // The pageSize where 0 <= pageSize <= 100. Values < 10 will be set to 10. A value of 0 returns the default page size (currently 25) PageSize *int `json:"pageSize,omitempty"` // The pageToken field. @@ -137,6 +191,13 @@ type AppUserServiceSearchRequest struct { WithoutResponsibleParty *bool `json:"withoutResponsibleParty,omitempty"` } +func (a *AppUserServiceSearchRequest) GetAgentStatuses() []AgentStatuses { + if a == nil { + return nil + } + return a.AgentStatuses +} + func (a *AppUserServiceSearchRequest) GetAppID() *string { if a == nil { return nil @@ -207,6 +268,13 @@ func (a *AppUserServiceSearchRequest) GetExpandMask() *AppUserExpandMask { return a.ExpandMask } +func (a *AppUserServiceSearchRequest) GetNhiTypes() []NhiTypes { + if a == nil { + return nil + } + return a.NhiTypes +} + func (a *AppUserServiceSearchRequest) GetPageSize() *int { if a == nil { return nil diff --git a/pkg/models/shared/blockoutputconfig.go b/pkg/models/shared/blockoutputconfig.go new file mode 100644 index 000000000..d3295a507 --- /dev/null +++ b/pkg/models/shared/blockoutputconfig.go @@ -0,0 +1,53 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +type Surfaces string + +const ( + SurfacesHookOutputSurfaceUnspecified Surfaces = "HOOK_OUTPUT_SURFACE_UNSPECIFIED" + SurfacesHookOutputSurfaceSlack Surfaces = "HOOK_OUTPUT_SURFACE_SLACK" + SurfacesHookOutputSurfaceWeb Surfaces = "HOOK_OUTPUT_SURFACE_WEB" +) + +func (e Surfaces) ToPointer() *Surfaces { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Surfaces) IsExact() bool { + if e != nil { + switch *e { + case "HOOK_OUTPUT_SURFACE_UNSPECIFIED", "HOOK_OUTPUT_SURFACE_SLACK", "HOOK_OUTPUT_SURFACE_WEB": + return true + } + } + return false +} + +// BlockOutputConfig denies the in-flight response chunk when its hook's +// +// filter matches. Only valid for HOOK_EVENT_TYPE_PRE_OUTPUT. +type BlockOutputConfig struct { + // Message shown to the user when this hook blocks the response. Empty + // falls back to the curating AgentGuardrailRule's deny_reason, then to a + // generic default. + Message *string `json:"message,omitempty"` + // Output surfaces this hook applies to. Empty means none — the hook is + // inert until at least one surface is explicitly selected. + Surfaces []Surfaces `json:"surfaces,omitempty"` +} + +func (b *BlockOutputConfig) GetMessage() *string { + if b == nil { + return nil + } + return b.Message +} + +func (b *BlockOutputConfig) GetSurfaces() []Surfaces { + if b == nil { + return nil + } + return b.Surfaces +} diff --git a/pkg/models/shared/blocktoolcallconfig.go b/pkg/models/shared/blocktoolcallconfig.go new file mode 100644 index 000000000..8cae484a3 --- /dev/null +++ b/pkg/models/shared/blocktoolcallconfig.go @@ -0,0 +1,19 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// BlockToolCallConfig unconditionally denies the tool call when its hook's +// +// filter matches. Only valid for HOOK_EVENT_TYPE_POST_TOOL_USE. +type BlockToolCallConfig struct { + // Message shown when the tool call is denied. Empty falls back to a + // generic default. + Message *string `json:"message,omitempty"` +} + +func (b *BlockToolCallConfig) GetMessage() *string { + if b == nil { + return nil + } + return b.Message +} diff --git a/pkg/models/shared/builtinpattern.go b/pkg/models/shared/builtinpattern.go index 697af2135..7c4bcd371 100644 --- a/pkg/models/shared/builtinpattern.go +++ b/pkg/models/shared/builtinpattern.go @@ -13,15 +13,43 @@ package shared // - writeAuthorization // - sensitiveFileGuard // - toolOutputSizeGuard +// - secretsMasking +// - linkFilter +// - encodedContentGuard +// - promptInjectionScan +// - blockOutput +// - blockToolCall +// - preToolBlock type BuiltInPattern struct { + BlockOutput *BlockOutputConfig `json:"blockOutput,omitempty"` + BlockToolCall *BlockToolCallConfig `json:"blockToolCall,omitempty"` CreditCardBlocking *CreditCardBlockingConfig `json:"creditCardBlocking,omitempty"` + EncodedContentGuard *EncodedContentGuardConfig `json:"encodedContentGuard,omitempty"` + LinkFilter *LinkFilterConfig `json:"linkFilter,omitempty"` PiiRedaction *PIIRedactionConfig `json:"piiRedaction,omitempty"` + PreToolBlock *PreToolBlockConfig `json:"preToolBlock,omitempty"` + PromptInjectionScan *PromptInjectionScanConfig `json:"promptInjectionScan,omitempty"` QueryScopeLimit *QueryScopeLimitConfig `json:"queryScopeLimit,omitempty"` + SecretsMasking *SecretsMaskingConfig `json:"secretsMasking,omitempty"` SensitiveFileGuard *SensitiveFileGuardConfig `json:"sensitiveFileGuard,omitempty"` ToolOutputSizeGuard *ToolOutputSizeGuardConfig `json:"toolOutputSizeGuard,omitempty"` WriteAuthorization *WriteAuthorizationConfig `json:"writeAuthorization,omitempty"` } +func (b *BuiltInPattern) GetBlockOutput() *BlockOutputConfig { + if b == nil { + return nil + } + return b.BlockOutput +} + +func (b *BuiltInPattern) GetBlockToolCall() *BlockToolCallConfig { + if b == nil { + return nil + } + return b.BlockToolCall +} + func (b *BuiltInPattern) GetCreditCardBlocking() *CreditCardBlockingConfig { if b == nil { return nil @@ -29,6 +57,20 @@ func (b *BuiltInPattern) GetCreditCardBlocking() *CreditCardBlockingConfig { return b.CreditCardBlocking } +func (b *BuiltInPattern) GetEncodedContentGuard() *EncodedContentGuardConfig { + if b == nil { + return nil + } + return b.EncodedContentGuard +} + +func (b *BuiltInPattern) GetLinkFilter() *LinkFilterConfig { + if b == nil { + return nil + } + return b.LinkFilter +} + func (b *BuiltInPattern) GetPiiRedaction() *PIIRedactionConfig { if b == nil { return nil @@ -36,6 +78,20 @@ func (b *BuiltInPattern) GetPiiRedaction() *PIIRedactionConfig { return b.PiiRedaction } +func (b *BuiltInPattern) GetPreToolBlock() *PreToolBlockConfig { + if b == nil { + return nil + } + return b.PreToolBlock +} + +func (b *BuiltInPattern) GetPromptInjectionScan() *PromptInjectionScanConfig { + if b == nil { + return nil + } + return b.PromptInjectionScan +} + func (b *BuiltInPattern) GetQueryScopeLimit() *QueryScopeLimitConfig { if b == nil { return nil @@ -43,6 +99,13 @@ func (b *BuiltInPattern) GetQueryScopeLimit() *QueryScopeLimitConfig { return b.QueryScopeLimit } +func (b *BuiltInPattern) GetSecretsMasking() *SecretsMaskingConfig { + if b == nil { + return nil + } + return b.SecretsMasking +} + func (b *BuiltInPattern) GetSensitiveFileGuard() *SensitiveFileGuardConfig { if b == nil { return nil diff --git a/pkg/models/shared/bulkreprocessaction.go b/pkg/models/shared/bulkreprocessaction.go new file mode 100644 index 000000000..c16370a3f --- /dev/null +++ b/pkg/models/shared/bulkreprocessaction.go @@ -0,0 +1,48 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// BulkReprocessAction re-evaluates eligible findings against transformation +// +// and routing rules using each finding's original detector-created state +// (original severity, original annotations) rather than any rule-mutated +// current state. +// +// `override_human_edits` chooses how far re-derivation goes for +// human-attributed edits: +// +// - Open findings are re-derived and re-routed in both modes. +// - Findings parked by a rule (snoozed, suppressed, or risk-accepted by a +// routing rule with no subsequent human action) are released to open, +// re-derived, and re-routed in both modes. +// - Findings parked by a person re-derive their content in both modes, but +// the state is only released, and a human severity override only cleared, +// when `override_human_edits` is true. +// - Findings in progress re-derive their content and keep both their state +// and any linked ticket in both modes. +// - Resolved, archived, and deleted findings are skipped in both modes. +// +// Assigned owners and ticket links are never touched; rules do not derive them. +type BulkReprocessAction struct { + // When false (the default), a person's parked state and severity override + // survive the re-derivation. When true, reprocessing additionally releases + // findings a person parked and clears human severity overrides. + OverrideHumanEdits *bool `json:"overrideHumanEdits,omitempty"` + // When true, matched rules may re-send notification dispatches for + // findings your team may have already seen. Off by default. + RunDispatchers *bool `json:"runDispatchers,omitempty"` +} + +func (b *BulkReprocessAction) GetOverrideHumanEdits() *bool { + if b == nil { + return nil + } + return b.OverrideHumanEdits +} + +func (b *BulkReprocessAction) GetRunDispatchers() *bool { + if b == nil { + return nil + } + return b.RunDispatchers +} diff --git a/pkg/models/shared/bulkupdatefindingstaterequest.go b/pkg/models/shared/bulkupdatefindingstaterequest.go index 87f97b625..e11d0ea71 100644 --- a/pkg/models/shared/bulkupdatefindingstaterequest.go +++ b/pkg/models/shared/bulkupdatefindingstaterequest.go @@ -11,12 +11,14 @@ package shared // - unsuppress // - assignOwner // - reopen +// - reprocess type BulkUpdateFindingStateRequest struct { AcceptRisk *BulkAcceptRiskAction `json:"acceptRisk,omitempty"` AssignOwner *BulkAssignOwnerAction `json:"assignOwner,omitempty"` // By-ID mode: specify individual finding refs. Refs []FindingRef `json:"refs,omitempty"` Reopen *BulkReopenAction `json:"reopen,omitempty"` + Reprocess *BulkReprocessAction `json:"reprocess,omitempty"` SearchRequest *FindingSearchRequest `json:"searchRequest,omitempty"` Snooze *BulkSnoozeAction `json:"snooze,omitempty"` Suppress *BulkSuppressAction `json:"suppress,omitempty"` @@ -51,6 +53,13 @@ func (b *BulkUpdateFindingStateRequest) GetReopen() *BulkReopenAction { return b.Reopen } +func (b *BulkUpdateFindingStateRequest) GetReprocess() *BulkReprocessAction { + if b == nil { + return nil + } + return b.Reprocess +} + func (b *BulkUpdateFindingStateRequest) GetSearchRequest() *FindingSearchRequest { if b == nil { return nil diff --git a/pkg/models/shared/c1metriccard.go b/pkg/models/shared/c1metriccard.go new file mode 100644 index 000000000..c044277cd --- /dev/null +++ b/pkg/models/shared/c1metriccard.go @@ -0,0 +1,82 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DeltaSentiment - The deltaSentiment field. +type DeltaSentiment string + +const ( + DeltaSentimentC1MetricDeltaSentimentUnspecified DeltaSentiment = "C1_METRIC_DELTA_SENTIMENT_UNSPECIFIED" + DeltaSentimentC1MetricDeltaSentimentPositive DeltaSentiment = "C1_METRIC_DELTA_SENTIMENT_POSITIVE" + DeltaSentimentC1MetricDeltaSentimentNegative DeltaSentiment = "C1_METRIC_DELTA_SENTIMENT_NEGATIVE" + DeltaSentimentC1MetricDeltaSentimentNeutral DeltaSentiment = "C1_METRIC_DELTA_SENTIMENT_NEUTRAL" +) + +func (e DeltaSentiment) ToPointer() *DeltaSentiment { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DeltaSentiment) IsExact() bool { + if e != nil { + switch *e { + case "C1_METRIC_DELTA_SENTIMENT_UNSPECIFIED", "C1_METRIC_DELTA_SENTIMENT_POSITIVE", "C1_METRIC_DELTA_SENTIMENT_NEGATIVE", "C1_METRIC_DELTA_SENTIMENT_NEUTRAL": + return true + } + } + return false +} + +// C1MetricCard is one aggregate stat: label, formatted value, optional delta +// +// and sparkline trend. +type C1MetricCard struct { + // The delta field. + Delta *string `json:"delta,omitempty"` + // The deltaSentiment field. + DeltaSentiment *DeltaSentiment `json:"deltaSentiment,omitempty"` + // The label field. + Label *string `json:"label,omitempty"` + // Optional trend values, oldest first. Bounds double as NaN/Inf rejection. + Sparkline []float64 `json:"sparkline,omitempty"` + // The value field. + Value *string `json:"value,omitempty"` +} + +func (c *C1MetricCard) GetDelta() *string { + if c == nil { + return nil + } + return c.Delta +} + +func (c *C1MetricCard) GetDeltaSentiment() *DeltaSentiment { + if c == nil { + return nil + } + return c.DeltaSentiment +} + +func (c *C1MetricCard) GetLabel() *string { + if c == nil { + return nil + } + return c.Label +} + +func (c *C1MetricCard) GetSparkline() []float64 { + if c == nil { + return nil + } + return c.Sparkline +} + +func (c *C1MetricCard) GetValue() *string { + if c == nil { + return nil + } + return c.Value +} + +// #region class-body-c1metriccard +// #endregion class-body-c1metriccard diff --git a/pkg/models/shared/c1metriccardscomponent.go b/pkg/models/shared/c1metriccardscomponent.go new file mode 100644 index 000000000..a1eb224d3 --- /dev/null +++ b/pkg/models/shared/c1metriccardscomponent.go @@ -0,0 +1,36 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// C1MetricCardsComponent renders a row of aggregate stat cards. +type C1MetricCardsComponent struct { + // The cards field. + Cards []C1MetricCard `json:"cards,omitempty"` + // Provenance: the queries the producing function ran. + Sources []C1ChartSource `json:"sources,omitempty"` + Title *DynamicString `json:"title,omitempty"` +} + +func (c *C1MetricCardsComponent) GetCards() []C1MetricCard { + if c == nil { + return nil + } + return c.Cards +} + +func (c *C1MetricCardsComponent) GetSources() []C1ChartSource { + if c == nil { + return nil + } + return c.Sources +} + +func (c *C1MetricCardsComponent) GetTitle() *DynamicString { + if c == nil { + return nil + } + return c.Title +} + +// #region class-body-c1metriccardscomponent +// #endregion class-body-c1metriccardscomponent diff --git a/pkg/models/shared/c1tablecomponent.go b/pkg/models/shared/c1tablecomponent.go new file mode 100644 index 000000000..0fcd7dfbe --- /dev/null +++ b/pkg/models/shared/c1tablecomponent.go @@ -0,0 +1,88 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// C1TableComponent renders a tabular view: typed columns + rows, capped and +// +// paginated client-side; the full data set lives behind the artifact link. +type C1TableComponent struct { + ArtifactURL *DynamicString `json:"artifactUrl,omitempty"` + // The columns field. + Columns []string `json:"columns,omitempty"` + // Rows per page for client-side pagination; 0 shows all rows on one page. + PageSize *int `json:"pageSize,omitempty"` + // The rows field. + Rows []C1TableRow `json:"rows,omitempty"` + // Provenance: the queries the producing function ran. + Sources []C1ChartSource `json:"sources,omitempty"` + Title *DynamicString `json:"title,omitempty"` + // Full count when rows are truncated. + TotalRows *int64 `integer:"string" json:"totalRows,omitempty"` +} + +func (c C1TableComponent) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(c, "", false) +} + +func (c *C1TableComponent) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &c, "", false, nil); err != nil { + return err + } + return nil +} + +func (c *C1TableComponent) GetArtifactURL() *DynamicString { + if c == nil { + return nil + } + return c.ArtifactURL +} + +func (c *C1TableComponent) GetColumns() []string { + if c == nil { + return nil + } + return c.Columns +} + +func (c *C1TableComponent) GetPageSize() *int { + if c == nil { + return nil + } + return c.PageSize +} + +func (c *C1TableComponent) GetRows() []C1TableRow { + if c == nil { + return nil + } + return c.Rows +} + +func (c *C1TableComponent) GetSources() []C1ChartSource { + if c == nil { + return nil + } + return c.Sources +} + +func (c *C1TableComponent) GetTitle() *DynamicString { + if c == nil { + return nil + } + return c.Title +} + +func (c *C1TableComponent) GetTotalRows() *int64 { + if c == nil { + return nil + } + return c.TotalRows +} + +// #region class-body-c1tablecomponent +// #endregion class-body-c1tablecomponent diff --git a/pkg/models/shared/c1tablerow.go b/pkg/models/shared/c1tablerow.go new file mode 100644 index 000000000..dc216026c --- /dev/null +++ b/pkg/models/shared/c1tablerow.go @@ -0,0 +1,21 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// C1TableRow is one row; cells align 1:1 with columns (enforced at the +// +// parse boundary). +type C1TableRow struct { + // The cells field. + Cells []string `json:"cells,omitempty"` +} + +func (c *C1TableRow) GetCells() []string { + if c == nil { + return nil + } + return c.Cells +} + +// #region class-body-c1tablerow +// #endregion class-body-c1tablerow diff --git a/pkg/models/shared/c1userfilter.go b/pkg/models/shared/c1userfilter.go index d3868856f..5965a178c 100644 --- a/pkg/models/shared/c1userfilter.go +++ b/pkg/models/shared/c1userfilter.go @@ -6,6 +6,34 @@ package shared // // This is distinct from AppUserFilter which selects accounts within a connected app. type C1UserFilter struct { + // Remove these users from the selectable set, after user_ids is applied. + ExcludeUserIds []string `json:"excludeUserIds,omitempty"` + // Make deactivated and deleted users selectable. Defaults to enabled-only. + IncludeDeactivated *bool `json:"includeDeactivated,omitempty"` + // Restrict the selectable set to these users. Empty means every user is selectable. + // Capped at the number of refs SearchUsers accepts in one request. + UserIds []string `json:"userIds,omitempty"` +} + +func (c *C1UserFilter) GetExcludeUserIds() []string { + if c == nil { + return nil + } + return c.ExcludeUserIds +} + +func (c *C1UserFilter) GetIncludeDeactivated() *bool { + if c == nil { + return nil + } + return c.IncludeDeactivated +} + +func (c *C1UserFilter) GetUserIds() []string { + if c == nil { + return nil + } + return c.UserIds } // #region class-body-c1userfilter diff --git a/pkg/models/shared/clearprovidercredentialrequest.go b/pkg/models/shared/clearprovidercredentialrequest.go new file mode 100644 index 000000000..2b727b615 --- /dev/null +++ b/pkg/models/shared/clearprovidercredentialrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ClearProviderCredentialRequest message. +type ClearProviderCredentialRequest struct { +} diff --git a/pkg/models/shared/clearprovidercredentialresponse.go b/pkg/models/shared/clearprovidercredentialresponse.go new file mode 100644 index 000000000..e9dd869eb --- /dev/null +++ b/pkg/models/shared/clearprovidercredentialresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ClearProviderCredentialResponse message. +type ClearProviderCredentialResponse struct { + Credential *ProviderCredential `json:"credential,omitempty"` +} + +func (c *ClearProviderCredentialResponse) GetCredential() *ProviderCredential { + if c == nil { + return nil + } + return c.Credential +} diff --git a/pkg/models/shared/composite.go b/pkg/models/shared/composite.go index 6142f46e8..b45f5530a 100644 --- a/pkg/models/shared/composite.go +++ b/pkg/models/shared/composite.go @@ -2,23 +2,23 @@ package shared -// Format - Wire format the provider expects. Defaults to +// CompositeFormat - Wire format the provider expects. Defaults to // // FORMAT_JSON_OBJECT. -type Format string +type CompositeFormat string const ( - FormatFormatJSONObject Format = "FORMAT_JSON_OBJECT" - FormatFormatColonSeparated Format = "FORMAT_COLON_SEPARATED" - FormatFormatUnderscoreSeparated Format = "FORMAT_UNDERSCORE_SEPARATED" + CompositeFormatFormatJSONObject CompositeFormat = "FORMAT_JSON_OBJECT" + CompositeFormatFormatColonSeparated CompositeFormat = "FORMAT_COLON_SEPARATED" + CompositeFormatFormatUnderscoreSeparated CompositeFormat = "FORMAT_UNDERSCORE_SEPARATED" ) -func (e Format) ToPointer() *Format { +func (e CompositeFormat) ToPointer() *CompositeFormat { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *Format) IsExact() bool { +func (e *CompositeFormat) IsExact() bool { if e != nil { switch *e { case "FORMAT_JSON_OBJECT", "FORMAT_COLON_SEPARATED", "FORMAT_UNDERSCORE_SEPARATED": @@ -37,7 +37,7 @@ type Composite struct { Fields []CompositeField `json:"fields,omitempty"` // Wire format the provider expects. Defaults to // FORMAT_JSON_OBJECT. - Format *Format `json:"format,omitempty"` + Format *CompositeFormat `json:"format,omitempty"` } func (c *Composite) GetFields() []CompositeField { @@ -47,7 +47,7 @@ func (c *Composite) GetFields() []CompositeField { return c.Fields } -func (c *Composite) GetFormat() *Format { +func (c *Composite) GetFormat() *CompositeFormat { if c == nil { return nil } diff --git a/pkg/models/shared/connectoractionref.go b/pkg/models/shared/connectoractionref.go index a514e301a..077262d55 100644 --- a/pkg/models/shared/connectoractionref.go +++ b/pkg/models/shared/connectoractionref.go @@ -2,20 +2,20 @@ package shared -// Operation - Which connector RPC this dispatches to. -type Operation string +// ConnectorActionRefOperation - Which connector RPC this dispatches to. +type ConnectorActionRefOperation string const ( - OperationOperationUnspecified Operation = "OPERATION_UNSPECIFIED" - OperationOperationGrant Operation = "OPERATION_GRANT" + ConnectorActionRefOperationOperationUnspecified ConnectorActionRefOperation = "OPERATION_UNSPECIFIED" + ConnectorActionRefOperationOperationGrant ConnectorActionRefOperation = "OPERATION_GRANT" ) -func (e Operation) ToPointer() *Operation { +func (e ConnectorActionRefOperation) ToPointer() *ConnectorActionRefOperation { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *Operation) IsExact() bool { +func (e *ConnectorActionRefOperation) IsExact() bool { if e != nil { switch *e { case "OPERATION_UNSPECIFIED", "OPERATION_GRANT": @@ -35,7 +35,7 @@ type ConnectorActionRef struct { // The connector that will execute the Grant / Revoke. ConnectorID *string `json:"connectorId,omitempty"` // Which connector RPC this dispatches to. - Operation *Operation `json:"operation,omitempty"` + Operation *ConnectorActionRefOperation `json:"operation,omitempty"` } func (c *ConnectorActionRef) GetAppID() *string { @@ -52,7 +52,7 @@ func (c *ConnectorActionRef) GetConnectorID() *string { return c.ConnectorID } -func (c *ConnectorActionRef) GetOperation() *Operation { +func (c *ConnectorActionRef) GetOperation() *ConnectorActionRefOperation { if c == nil { return nil } diff --git a/pkg/models/shared/connectorexpandmask.go b/pkg/models/shared/connectorexpandmask.go index 9de9e38e7..45be187a0 100644 --- a/pkg/models/shared/connectorexpandmask.go +++ b/pkg/models/shared/connectorexpandmask.go @@ -4,7 +4,8 @@ package shared // The ConnectorExpandMask is used to expand related objects on a connector. type ConnectorExpandMask struct { - // Paths that you want expanded in the response. Possible values are "app_id" and "*". + // Paths that you want expanded in the response. Possible values are "app_id", + // "user_ids", "capabilities" and "*". Paths []string `json:"paths,omitempty"` } diff --git a/pkg/models/shared/connectorsyncfailingevidence.go b/pkg/models/shared/connectorsyncfailingevidence.go new file mode 100644 index 000000000..70be14f4d --- /dev/null +++ b/pkg/models/shared/connectorsyncfailingevidence.go @@ -0,0 +1,60 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// ConnectorSyncFailingEvidence describes the failure streak behind a +// +// CONNECTOR_SYNC_FAILING finding, refreshed on every re-observation. +type ConnectorSyncFailingEvidence struct { + // The consecutiveFailureCount field. + ConsecutiveFailureCount *int64 `json:"consecutiveFailureCount,omitempty"` + LastFailedAt *time.Time `json:"lastFailedAt,omitempty"` + // Id of the newest failing sync run, not a copy of its error text -- see the + // c1models message for why the error itself is deliberately not carried here. + LastSyncLifecycleID *string `json:"lastSyncLifecycleId,omitempty"` + StreakStartedAt *time.Time `json:"streakStartedAt,omitempty"` +} + +func (c ConnectorSyncFailingEvidence) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(c, "", false) +} + +func (c *ConnectorSyncFailingEvidence) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &c, "", false, nil); err != nil { + return err + } + return nil +} + +func (c *ConnectorSyncFailingEvidence) GetConsecutiveFailureCount() *int64 { + if c == nil { + return nil + } + return c.ConsecutiveFailureCount +} + +func (c *ConnectorSyncFailingEvidence) GetLastFailedAt() *time.Time { + if c == nil { + return nil + } + return c.LastFailedAt +} + +func (c *ConnectorSyncFailingEvidence) GetLastSyncLifecycleID() *string { + if c == nil { + return nil + } + return c.LastSyncLifecycleID +} + +func (c *ConnectorSyncFailingEvidence) GetStreakStartedAt() *time.Time { + if c == nil { + return nil + } + return c.StreakStartedAt +} diff --git a/pkg/models/shared/connectorsyncfailingtype.go b/pkg/models/shared/connectorsyncfailingtype.go new file mode 100644 index 000000000..2ff2e3e86 --- /dev/null +++ b/pkg/models/shared/connectorsyncfailingtype.go @@ -0,0 +1,10 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// ConnectorSyncFailingType - ConnectorSyncFailingType: a connector's completed sync runs have ended in +// +// error for at least two consecutive runs, with no intervening success. +// Target: ConnectorTarget. +type ConnectorSyncFailingType struct { +} diff --git a/pkg/models/shared/createapprequest.go b/pkg/models/shared/createapprequest.go index 313bda086..f7fc79721 100644 --- a/pkg/models/shared/createapprequest.go +++ b/pkg/models/shared/createapprequest.go @@ -38,7 +38,7 @@ type CreateAppRequest struct { // Well-known keys: `managed_by`, `iac_workspace`, // `iac_resource_address`, `iac_tool_version`. Annotations map[string]string `json:"annotations,omitempty"` - // Sets entitlement owners on the app. + // Initial entitlement owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_entitlement`. AppEntitlementOwnerRefs []AppEntitlementRef `json:"appEntitlementOwnerRefs,omitempty"` // Creates the app with this certify policy. CertifyPolicyID *string `json:"certifyPolicyId,omitempty"` @@ -51,10 +51,11 @@ type CreateAppRequest struct { // Define the app user identity matching strategy for this app. IdentityMatching *CreateAppRequestIdentityMatching `json:"identityMatching,omitempty"` // Instructions shown to users in the access request form when requesting access for this app. - Instructions *string `json:"instructions,omitempty"` + Instructions *string `json:"instructions,omitempty"` + MatchBatonRef *AppMatchBatonRef `json:"matchBatonRef,omitempty"` // Creates the app with this monthly cost per seat. MonthlyCostUsd *int `json:"monthlyCostUsd,omitempty"` - // Creates the app with this array of user owners. + // Initial user owners for ordinary API creation. Requests with `match_baton_ref` must leave this empty; Terraform manages owners with `conductorone_app_owner_user`. Owners []string `json:"owners,omitempty"` // Creates the app with this revoke policy. RevokePolicyID *string `json:"revokePolicyId,omitempty"` @@ -118,6 +119,13 @@ func (c *CreateAppRequest) GetInstructions() *string { return c.Instructions } +func (c *CreateAppRequest) GetMatchBatonRef() *AppMatchBatonRef { + if c == nil { + return nil + } + return c.MatchBatonRef +} + func (c *CreateAppRequest) GetMonthlyCostUsd() *int { if c == nil { return nil diff --git a/pkg/models/shared/createappresponse.go b/pkg/models/shared/createappresponse.go index 04b9807d5..8c1a718e7 100644 --- a/pkg/models/shared/createappresponse.go +++ b/pkg/models/shared/createappresponse.go @@ -2,7 +2,7 @@ package shared -// CreateAppResponse - Returns the new app's values. +// CreateAppResponse contains the newly created application. type CreateAppResponse struct { App *App `json:"app,omitempty"` } diff --git a/pkg/models/shared/createmanuallymanagedresourcetyperequest.go b/pkg/models/shared/createmanuallymanagedresourcetyperequest.go index acd8948d2..d23d9f5c6 100644 --- a/pkg/models/shared/createmanuallymanagedresourcetyperequest.go +++ b/pkg/models/shared/createmanuallymanagedresourcetyperequest.go @@ -15,6 +15,7 @@ const ( ResourceTypeVault ResourceType = "VAULT" ResourceTypeProfileType ResourceType = "PROFILE_TYPE" ResourceTypeSessionPolicy ResourceType = "SESSION_POLICY" + ResourceTypeClawAgent ResourceType = "CLAW_AGENT" ) func (e ResourceType) ToPointer() *ResourceType { @@ -25,7 +26,7 @@ func (e ResourceType) ToPointer() *ResourceType { func (e *ResourceType) IsExact() bool { if e != nil { switch *e { - case "ROLE", "GROUP", "LICENSE", "PROJECT", "CATALOG", "CUSTOM", "VAULT", "PROFILE_TYPE", "SESSION_POLICY": + case "ROLE", "GROUP", "LICENSE", "PROJECT", "CATALOG", "CUSTOM", "VAULT", "PROFILE_TYPE", "SESSION_POLICY", "CLAW_AGENT": return true } } diff --git a/pkg/models/shared/createpolicyrequest.go b/pkg/models/shared/createpolicyrequest.go index 41f2131f7..155a2ec42 100644 --- a/pkg/models/shared/createpolicyrequest.go +++ b/pkg/models/shared/createpolicyrequest.go @@ -40,6 +40,12 @@ type CreatePolicyRequest struct { // Well-known keys: `managed_by`, `iac_workspace`, // `iac_resource_address`, `iac_tool_version`. Annotations map[string]string `json:"annotations,omitempty"` + // When set, the new policy's baseline defers to another policy of the same + // type when no rule matches, instead of an inline baseline step list. + // Mutually exclusive with the baseline entry in policy_steps. Requires the + // POLICY_REFERENCES_POLICY feature; obeys the same depth/cycle/self rules as + // Rule.policy_id. + BaselinePolicyID *string `json:"baselinePolicyId,omitempty"` // The description of the new policy. Description *string `json:"description,omitempty"` // The display name of the new policy. @@ -57,7 +63,8 @@ type CreatePolicyRequest struct { // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. ReassignTasksToDelegates *bool `json:"reassignTasksToDelegates,omitempty"` // Conditional routing rules. See the Policy message for details on evaluation order. - Rules []Rule `json:"rules,omitempty"` + Rules []Rule `json:"rules,omitempty"` + Scope *PolicyScope `json:"scope,omitempty"` } func (c *CreatePolicyRequest) GetAnnotations() map[string]string { @@ -67,6 +74,13 @@ func (c *CreatePolicyRequest) GetAnnotations() map[string]string { return c.Annotations } +func (c *CreatePolicyRequest) GetBaselinePolicyID() *string { + if c == nil { + return nil + } + return c.BaselinePolicyID +} + func (c *CreatePolicyRequest) GetDescription() *string { if c == nil { return nil @@ -115,3 +129,10 @@ func (c *CreatePolicyRequest) GetRules() []Rule { } return c.Rules } + +func (c *CreatePolicyRequest) GetScope() *PolicyScope { + if c == nil { + return nil + } + return c.Scope +} diff --git a/pkg/models/shared/createrevoketasksv2.go b/pkg/models/shared/createrevoketasksv2.go index f833a7c47..3c766e4bb 100644 --- a/pkg/models/shared/createrevoketasksv2.go +++ b/pkg/models/shared/createrevoketasksv2.go @@ -2,6 +2,32 @@ package shared +// GrantSourceFilter - Restricts the step to grants of either DIRECT (grants the user holds directly, +// +// including grants that are also inherited) or UNSPECIFIED (all grants). +// Composes with every inclusion mode, including inclusion_list_cel. +type GrantSourceFilter string + +const ( + GrantSourceFilterGrantSourceFilterUnspecified GrantSourceFilter = "GRANT_SOURCE_FILTER_UNSPECIFIED" + GrantSourceFilterGrantSourceFilterDirect GrantSourceFilter = "GRANT_SOURCE_FILTER_DIRECT" +) + +func (e GrantSourceFilter) ToPointer() *GrantSourceFilter { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *GrantSourceFilter) IsExact() bool { + if e != nil { + switch *e { + case "GRANT_SOURCE_FILTER_UNSPECIFIED", "GRANT_SOURCE_FILTER_DIRECT": + return true + } + } + return false +} + // The CreateRevokeTasksV2 message. // // This message contains a oneof named user. Only a single field of the following list may be set at a time: @@ -22,10 +48,14 @@ package shared // - exclusionCriteria // - exclusionListCel type CreateRevokeTasksV2 struct { - ExclusionCriteria *EntitlementExclusionCriteria `json:"exclusionCriteria,omitempty"` - ExclusionList *EntitlementExclusionList `json:"exclusionList,omitempty"` - ExclusionListCel *EntitlementExclusionListCel `json:"exclusionListCel,omitempty"` - ExclusionNone *EntitlementExclusionNone `json:"exclusionNone,omitempty"` + ExclusionCriteria *EntitlementExclusionCriteria `json:"exclusionCriteria,omitempty"` + ExclusionList *EntitlementExclusionList `json:"exclusionList,omitempty"` + ExclusionListCel *EntitlementExclusionListCel `json:"exclusionListCel,omitempty"` + ExclusionNone *EntitlementExclusionNone `json:"exclusionNone,omitempty"` + // Restricts the step to grants of either DIRECT (grants the user holds directly, + // including grants that are also inherited) or UNSPECIFIED (all grants). + // Composes with every inclusion mode, including inclusion_list_cel. + GrantSourceFilter *GrantSourceFilter `json:"grantSourceFilter,omitempty"` InclusionAccessOnly *EntitlementInclusionAccessOnly `json:"inclusionAccessOnly,omitempty"` InclusionAll *EntitlementInclusionAll `json:"inclusionAll,omitempty"` InclusionCriteria *EntitlementInclusionCriteria `json:"inclusionCriteria,omitempty"` @@ -70,6 +100,13 @@ func (c *CreateRevokeTasksV2) GetExclusionNone() *EntitlementExclusionNone { return c.ExclusionNone } +func (c *CreateRevokeTasksV2) GetGrantSourceFilter() *GrantSourceFilter { + if c == nil { + return nil + } + return c.GrantSourceFilter +} + func (c *CreateRevokeTasksV2) GetInclusionAccessOnly() *EntitlementInclusionAccessOnly { if c == nil { return nil diff --git a/pkg/models/shared/credentialexpiringevidence.go b/pkg/models/shared/credentialexpiringevidence.go new file mode 100644 index 000000000..289184618 --- /dev/null +++ b/pkg/models/shared/credentialexpiringevidence.go @@ -0,0 +1,40 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// The CredentialExpiringEvidence message. +type CredentialExpiringEvidence struct { + // Whether the expiry was already past when last observed. + Expired *bool `json:"expired,omitempty"` + ExpiresAt *time.Time `json:"expiresAt,omitempty"` +} + +func (c CredentialExpiringEvidence) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(c, "", false) +} + +func (c *CredentialExpiringEvidence) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &c, "", false, nil); err != nil { + return err + } + return nil +} + +func (c *CredentialExpiringEvidence) GetExpired() *bool { + if c == nil { + return nil + } + return c.Expired +} + +func (c *CredentialExpiringEvidence) GetExpiresAt() *time.Time { + if c == nil { + return nil + } + return c.ExpiresAt +} diff --git a/pkg/models/shared/credentialexpiringtype.go b/pkg/models/shared/credentialexpiringtype.go new file mode 100644 index 000000000..ce13bfc7d --- /dev/null +++ b/pkg/models/shared/credentialexpiringtype.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// CredentialExpiringType - CredentialExpiringType: a ConductorOne-managed credential is inside the +// +// detector's expiry warning window, or already past it. Dedup is +// (credential arm, credential_id). Target: IdentityUserTarget -- the identity +// holding the credential. +// +// This message contains a oneof named credential. Only a single field of the following list may be set at a time: +// - userClientId +type CredentialExpiringType struct { + // The credentialDisplayName field. + CredentialDisplayName *string `json:"credentialDisplayName,omitempty"` + // Service-principal credential. + // This field is part of the `credential` oneof. + // See the documentation for `c1.api.finding.v1.CredentialExpiringType` for more details. + UserClientID *string `json:"userClientId,omitempty"` +} + +func (c *CredentialExpiringType) GetCredentialDisplayName() *string { + if c == nil { + return nil + } + return c.CredentialDisplayName +} + +func (c *CredentialExpiringType) GetUserClientID() *string { + if c == nil { + return nil + } + return c.UserClientID +} diff --git a/pkg/models/shared/credentialpubliclyexposedevidence.go b/pkg/models/shared/credentialpubliclyexposedevidence.go new file mode 100644 index 000000000..2c8c22e06 --- /dev/null +++ b/pkg/models/shared/credentialpubliclyexposedevidence.go @@ -0,0 +1,93 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// CredentialPubliclyExposedEvidence carries scanner attribution for a public exposure. +type CredentialPubliclyExposedEvidence struct { + // The credentialRevoked field. + CredentialRevoked *bool `json:"credentialRevoked,omitempty"` + // The fingerprintPrefix field. + FingerprintPrefix *string `json:"fingerprintPrefix,omitempty"` + FirstObservedAt *time.Time `json:"firstObservedAt,omitempty"` + // The firstScannerId field. + FirstScannerID *string `json:"firstScannerId,omitempty"` + // The reportingScanners field. + ReportingScanners []string `json:"reportingScanners,omitempty"` + RevokedAt *time.Time `json:"revokedAt,omitempty"` + // The sourceKind field. + SourceKind *string `json:"sourceKind,omitempty"` + // The sourceUrl field. + SourceURL *string `json:"sourceUrl,omitempty"` +} + +func (c CredentialPubliclyExposedEvidence) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(c, "", false) +} + +func (c *CredentialPubliclyExposedEvidence) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &c, "", false, nil); err != nil { + return err + } + return nil +} + +func (c *CredentialPubliclyExposedEvidence) GetCredentialRevoked() *bool { + if c == nil { + return nil + } + return c.CredentialRevoked +} + +func (c *CredentialPubliclyExposedEvidence) GetFingerprintPrefix() *string { + if c == nil { + return nil + } + return c.FingerprintPrefix +} + +func (c *CredentialPubliclyExposedEvidence) GetFirstObservedAt() *time.Time { + if c == nil { + return nil + } + return c.FirstObservedAt +} + +func (c *CredentialPubliclyExposedEvidence) GetFirstScannerID() *string { + if c == nil { + return nil + } + return c.FirstScannerID +} + +func (c *CredentialPubliclyExposedEvidence) GetReportingScanners() []string { + if c == nil { + return nil + } + return c.ReportingScanners +} + +func (c *CredentialPubliclyExposedEvidence) GetRevokedAt() *time.Time { + if c == nil { + return nil + } + return c.RevokedAt +} + +func (c *CredentialPubliclyExposedEvidence) GetSourceKind() *string { + if c == nil { + return nil + } + return c.SourceKind +} + +func (c *CredentialPubliclyExposedEvidence) GetSourceURL() *string { + if c == nil { + return nil + } + return c.SourceURL +} diff --git a/pkg/models/shared/credentialpubliclyexposedtype.go b/pkg/models/shared/credentialpubliclyexposedtype.go new file mode 100644 index 000000000..7bc8bb2ec --- /dev/null +++ b/pkg/models/shared/credentialpubliclyexposedtype.go @@ -0,0 +1,68 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// CredentialPubliclyExposedType - CredentialPubliclyExposedType: a live credential was reported as publicly exposed. +// +// Dedup is (credential arm, credential_id). +// +// This message contains a oneof named credential. Only a single field of the following list may be set at a time: +// - userClientId +// - connectorClientId +// - connectorManagedCredentialId +// - functionClientId +type CredentialPubliclyExposedType struct { + // The connectorClientId field. + // This field is part of the `credential` oneof. + // See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + ConnectorClientID *string `json:"connectorClientId,omitempty"` + // The connectorManagedCredentialId field. + // This field is part of the `credential` oneof. + // See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + ConnectorManagedCredentialID *string `json:"connectorManagedCredentialId,omitempty"` + // The credentialDisplayName field. + CredentialDisplayName *string `json:"credentialDisplayName,omitempty"` + // The functionClientId field. + // This field is part of the `credential` oneof. + // See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + FunctionClientID *string `json:"functionClientId,omitempty"` + // The userClientId field. + // This field is part of the `credential` oneof. + // See the documentation for `c1.api.finding.v1.CredentialPubliclyExposedType` for more details. + UserClientID *string `json:"userClientId,omitempty"` +} + +func (c *CredentialPubliclyExposedType) GetConnectorClientID() *string { + if c == nil { + return nil + } + return c.ConnectorClientID +} + +func (c *CredentialPubliclyExposedType) GetConnectorManagedCredentialID() *string { + if c == nil { + return nil + } + return c.ConnectorManagedCredentialID +} + +func (c *CredentialPubliclyExposedType) GetCredentialDisplayName() *string { + if c == nil { + return nil + } + return c.CredentialDisplayName +} + +func (c *CredentialPubliclyExposedType) GetFunctionClientID() *string { + if c == nil { + return nil + } + return c.FunctionClientID +} + +func (c *CredentialPubliclyExposedType) GetUserClientID() *string { + if c == nil { + return nil + } + return c.UserClientID +} diff --git a/pkg/models/shared/datefield.go b/pkg/models/shared/datefield.go new file mode 100644 index 000000000..8e37c75ca --- /dev/null +++ b/pkg/models/shared/datefield.go @@ -0,0 +1,62 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DateField renders a date picker. The value is an ISO-8601 calendar date +// +// ("YYYY-MM-DD") stored in the enclosing StringField's string value. +type DateField struct { + // Default the field to the render date when the StringField has no default_value. + DefaultToToday *bool `json:"defaultToToday,omitempty"` + // Latest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. + MaxDate *string `json:"maxDate,omitempty"` + // Latest selectable date expressed as an offset in days from the date the + // form is rendered; negative is in the past. Set this to 365 to cap a date at + // one year out. When both are set, the earlier of this and max_date applies. + // Enforcement is one day slack in each direction: the picker anchors today at + // the submitter's local midnight and the server anchors in UTC, so 365 admits + // 366 days rather than reject a date the picker itself offered. + MaxDaysFromToday *int `json:"maxDaysFromToday,omitempty"` + // Earliest selectable date, inclusive, as "YYYY-MM-DD". Empty means unbounded. + MinDate *string `json:"minDate,omitempty"` + // Earliest selectable date expressed as an offset in days from the date the + // form is rendered; negative is in the past. Prefer this over min_date for a + // rolling window, which would otherwise go stale. When both are set, the + // later of the two applies. + MinDaysFromToday *int `json:"minDaysFromToday,omitempty"` +} + +func (d *DateField) GetDefaultToToday() *bool { + if d == nil { + return nil + } + return d.DefaultToToday +} + +func (d *DateField) GetMaxDate() *string { + if d == nil { + return nil + } + return d.MaxDate +} + +func (d *DateField) GetMaxDaysFromToday() *int { + if d == nil { + return nil + } + return d.MaxDaysFromToday +} + +func (d *DateField) GetMinDate() *string { + if d == nil { + return nil + } + return d.MinDate +} + +func (d *DateField) GetMinDaysFromToday() *int { + if d == nil { + return nil + } + return d.MinDaysFromToday +} diff --git a/pkg/models/shared/deactivatedownerdetail.go b/pkg/models/shared/deactivatedownerdetail.go new file mode 100644 index 000000000..7b3b435b0 --- /dev/null +++ b/pkg/models/shared/deactivatedownerdetail.go @@ -0,0 +1,53 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Reason - The reason field. +type Reason string + +const ( + ReasonDeactivatedOwnerReasonUnspecified Reason = "DEACTIVATED_OWNER_REASON_UNSPECIFIED" + ReasonDeactivatedOwnerReasonUserDeleted Reason = "DEACTIVATED_OWNER_REASON_USER_DELETED" + ReasonDeactivatedOwnerReasonUserDisabled Reason = "DEACTIVATED_OWNER_REASON_USER_DISABLED" + ReasonDeactivatedOwnerReasonEmploymentInactive Reason = "DEACTIVATED_OWNER_REASON_EMPLOYMENT_INACTIVE" +) + +func (e Reason) ToPointer() *Reason { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Reason) IsExact() bool { + if e != nil { + switch *e { + case "DEACTIVATED_OWNER_REASON_UNSPECIFIED", "DEACTIVATED_OWNER_REASON_USER_DELETED", "DEACTIVATED_OWNER_REASON_USER_DISABLED", "DEACTIVATED_OWNER_REASON_EMPLOYMENT_INACTIVE": + return true + } + } + return false +} + +// DeactivatedOwnerDetail is one deactivated owner found for the target at +// +// detection time. A target can have more than one owner, and more than one +// can read as deactivated. +type DeactivatedOwnerDetail struct { + // The reason field. + Reason *Reason `json:"reason,omitempty"` + // The userId field. + UserID *string `json:"userId,omitempty"` +} + +func (d *DeactivatedOwnerDetail) GetReason() *Reason { + if d == nil { + return nil + } + return d.Reason +} + +func (d *DeactivatedOwnerDetail) GetUserID() *string { + if d == nil { + return nil + } + return d.UserID +} diff --git a/pkg/models/shared/deactivatedownerevidence.go b/pkg/models/shared/deactivatedownerevidence.go new file mode 100644 index 000000000..0b8077c22 --- /dev/null +++ b/pkg/models/shared/deactivatedownerevidence.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The DeactivatedOwnerEvidence message. +type DeactivatedOwnerEvidence struct { + // The deactivatedOwners field. + DeactivatedOwners []DeactivatedOwnerDetail `json:"deactivatedOwners,omitempty"` +} + +func (d *DeactivatedOwnerEvidence) GetDeactivatedOwners() []DeactivatedOwnerDetail { + if d == nil { + return nil + } + return d.DeactivatedOwners +} diff --git a/pkg/models/shared/deactivatedownertype.go b/pkg/models/shared/deactivatedownertype.go new file mode 100644 index 000000000..315a5503b --- /dev/null +++ b/pkg/models/shared/deactivatedownertype.go @@ -0,0 +1,45 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DeactivatedOwnerTypeSource - The source field. +type DeactivatedOwnerTypeSource string + +const ( + DeactivatedOwnerTypeSourceDeactivatedOwnerSourceUnspecified DeactivatedOwnerTypeSource = "DEACTIVATED_OWNER_SOURCE_UNSPECIFIED" + DeactivatedOwnerTypeSourceDeactivatedOwnerSourceIdentityCorrelation DeactivatedOwnerTypeSource = "DEACTIVATED_OWNER_SOURCE_IDENTITY_CORRELATION" + DeactivatedOwnerTypeSourceDeactivatedOwnerSourceOwnershipAssigned DeactivatedOwnerTypeSource = "DEACTIVATED_OWNER_SOURCE_OWNERSHIP_ASSIGNED" + DeactivatedOwnerTypeSourceDeactivatedOwnerSourceSecretRunAsIdentity DeactivatedOwnerTypeSource = "DEACTIVATED_OWNER_SOURCE_SECRET_RUN_AS_IDENTITY" +) + +func (e DeactivatedOwnerTypeSource) ToPointer() *DeactivatedOwnerTypeSource { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DeactivatedOwnerTypeSource) IsExact() bool { + if e != nil { + switch *e { + case "DEACTIVATED_OWNER_SOURCE_UNSPECIFIED", "DEACTIVATED_OWNER_SOURCE_IDENTITY_CORRELATION", "DEACTIVATED_OWNER_SOURCE_OWNERSHIP_ASSIGNED", "DEACTIVATED_OWNER_SOURCE_SECRET_RUN_AS_IDENTITY": + return true + } + } + return false +} + +// DeactivatedOwnerType - DeactivatedOwnerType: the human responsible for a target -- either the +// +// AppUser's own correlated identity, an ownership_v2-assigned owner, or a +// secret's run-as identity is deactivated. Target: AppUserTarget or +// AppResourceTarget. +type DeactivatedOwnerType struct { + // The source field. + Source *DeactivatedOwnerTypeSource `json:"source,omitempty"` +} + +func (d *DeactivatedOwnerType) GetSource() *DeactivatedOwnerTypeSource { + if d == nil { + return nil + } + return d.Source +} diff --git a/pkg/models/shared/decoypubliclyexposedevidence.go b/pkg/models/shared/decoypubliclyexposedevidence.go new file mode 100644 index 000000000..9d24e76e7 --- /dev/null +++ b/pkg/models/shared/decoypubliclyexposedevidence.go @@ -0,0 +1,93 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// DecoyPubliclyExposedEvidence mirrors CredentialPubliclyExposedEvidence for decoys. +type DecoyPubliclyExposedEvidence struct { + // The credentialRevoked field. + CredentialRevoked *bool `json:"credentialRevoked,omitempty"` + // The fingerprintPrefix field. + FingerprintPrefix *string `json:"fingerprintPrefix,omitempty"` + FirstObservedAt *time.Time `json:"firstObservedAt,omitempty"` + // The firstScannerId field. + FirstScannerID *string `json:"firstScannerId,omitempty"` + // The reportingScanners field. + ReportingScanners []string `json:"reportingScanners,omitempty"` + RevokedAt *time.Time `json:"revokedAt,omitempty"` + // The sourceKind field. + SourceKind *string `json:"sourceKind,omitempty"` + // The sourceUrl field. + SourceURL *string `json:"sourceUrl,omitempty"` +} + +func (d DecoyPubliclyExposedEvidence) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(d, "", false) +} + +func (d *DecoyPubliclyExposedEvidence) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &d, "", false, nil); err != nil { + return err + } + return nil +} + +func (d *DecoyPubliclyExposedEvidence) GetCredentialRevoked() *bool { + if d == nil { + return nil + } + return d.CredentialRevoked +} + +func (d *DecoyPubliclyExposedEvidence) GetFingerprintPrefix() *string { + if d == nil { + return nil + } + return d.FingerprintPrefix +} + +func (d *DecoyPubliclyExposedEvidence) GetFirstObservedAt() *time.Time { + if d == nil { + return nil + } + return d.FirstObservedAt +} + +func (d *DecoyPubliclyExposedEvidence) GetFirstScannerID() *string { + if d == nil { + return nil + } + return d.FirstScannerID +} + +func (d *DecoyPubliclyExposedEvidence) GetReportingScanners() []string { + if d == nil { + return nil + } + return d.ReportingScanners +} + +func (d *DecoyPubliclyExposedEvidence) GetRevokedAt() *time.Time { + if d == nil { + return nil + } + return d.RevokedAt +} + +func (d *DecoyPubliclyExposedEvidence) GetSourceKind() *string { + if d == nil { + return nil + } + return d.SourceKind +} + +func (d *DecoyPubliclyExposedEvidence) GetSourceURL() *string { + if d == nil { + return nil + } + return d.SourceURL +} diff --git a/pkg/models/shared/decoypubliclyexposedtype.go b/pkg/models/shared/decoypubliclyexposedtype.go new file mode 100644 index 000000000..fc61e8ddf --- /dev/null +++ b/pkg/models/shared/decoypubliclyexposedtype.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DecoyPubliclyExposedType - DecoyPubliclyExposedType: a planted decoy was reported as publicly exposed. +// +// Dedup is decoy_id. +type DecoyPubliclyExposedType struct { + // The decoyDisplayName field. + DecoyDisplayName *string `json:"decoyDisplayName,omitempty"` + // The decoyId field. + DecoyID *string `json:"decoyId,omitempty"` +} + +func (d *DecoyPubliclyExposedType) GetDecoyDisplayName() *string { + if d == nil { + return nil + } + return d.DecoyDisplayName +} + +func (d *DecoyPubliclyExposedType) GetDecoyID() *string { + if d == nil { + return nil + } + return d.DecoyID +} diff --git a/pkg/models/shared/deviceplacementprovision.go b/pkg/models/shared/deviceplacementprovision.go new file mode 100644 index 000000000..33571d0b7 --- /dev/null +++ b/pkg/models/shared/deviceplacementprovision.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DevicePlacementProvision - This provision step is fulfilled by a Latchkey member device producing an MLS Welcome for the recipient. It has no assignee and no instructions because the step is not human-actionable. +type DevicePlacementProvision struct { + // The vaultBoundaryId field. + VaultBoundaryID *string `json:"vaultBoundaryId,omitempty"` +} + +func (d *DevicePlacementProvision) GetVaultBoundaryID() *string { + if d == nil { + return nil + } + return d.VaultBoundaryID +} diff --git a/pkg/models/shared/disabledreasoncircuitbreaker.go b/pkg/models/shared/disabledreasoncircuitbreaker.go index f115282a7..aac424631 100644 --- a/pkg/models/shared/disabledreasoncircuitbreaker.go +++ b/pkg/models/shared/disabledreasoncircuitbreaker.go @@ -7,23 +7,23 @@ import ( "time" ) -// Period - Snapshot of the period at trip time. -type Period string +// DisabledReasonCircuitBreakerPeriod - Snapshot of the period at trip time. +type DisabledReasonCircuitBreakerPeriod string const ( - PeriodCircuitBreakerPeriodUnspecified Period = "CIRCUIT_BREAKER_PERIOD_UNSPECIFIED" - PeriodCircuitBreakerPeriodHour Period = "CIRCUIT_BREAKER_PERIOD_HOUR" - PeriodCircuitBreakerPeriodDay Period = "CIRCUIT_BREAKER_PERIOD_DAY" - PeriodCircuitBreakerPeriodWeek Period = "CIRCUIT_BREAKER_PERIOD_WEEK" - PeriodCircuitBreakerPeriodMonth Period = "CIRCUIT_BREAKER_PERIOD_MONTH" + DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodUnspecified DisabledReasonCircuitBreakerPeriod = "CIRCUIT_BREAKER_PERIOD_UNSPECIFIED" + DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodHour DisabledReasonCircuitBreakerPeriod = "CIRCUIT_BREAKER_PERIOD_HOUR" + DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodDay DisabledReasonCircuitBreakerPeriod = "CIRCUIT_BREAKER_PERIOD_DAY" + DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodWeek DisabledReasonCircuitBreakerPeriod = "CIRCUIT_BREAKER_PERIOD_WEEK" + DisabledReasonCircuitBreakerPeriodCircuitBreakerPeriodMonth DisabledReasonCircuitBreakerPeriod = "CIRCUIT_BREAKER_PERIOD_MONTH" ) -func (e Period) ToPointer() *Period { +func (e DisabledReasonCircuitBreakerPeriod) ToPointer() *DisabledReasonCircuitBreakerPeriod { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *Period) IsExact() bool { +func (e *DisabledReasonCircuitBreakerPeriod) IsExact() bool { if e != nil { switch *e { case "CIRCUIT_BREAKER_PERIOD_UNSPECIFIED", "CIRCUIT_BREAKER_PERIOD_HOUR", "CIRCUIT_BREAKER_PERIOD_DAY", "CIRCUIT_BREAKER_PERIOD_WEEK", "CIRCUIT_BREAKER_PERIOD_MONTH": @@ -41,7 +41,7 @@ type DisabledReasonCircuitBreaker struct { // Observed execution count in the period at trip time. ObservedCount *int64 `json:"observedCount,omitempty"` // Snapshot of the period at trip time. - Period *Period `json:"period,omitempty"` + Period *DisabledReasonCircuitBreakerPeriod `json:"period,omitempty"` // Snapshot of the threshold at trip time. Threshold *int64 `json:"threshold,omitempty"` TrippedAt *time.Time `json:"trippedAt,omitempty"` @@ -65,7 +65,7 @@ func (d *DisabledReasonCircuitBreaker) GetObservedCount() *int64 { return d.ObservedCount } -func (d *DisabledReasonCircuitBreaker) GetPeriod() *Period { +func (d *DisabledReasonCircuitBreaker) GetPeriod() *DisabledReasonCircuitBreakerPeriod { if d == nil { return nil } diff --git a/pkg/models/shared/emailchannelsettings.go b/pkg/models/shared/emailchannelsettings.go index ecba1648c..8a5219906 100644 --- a/pkg/models/shared/emailchannelsettings.go +++ b/pkg/models/shared/emailchannelsettings.go @@ -14,7 +14,9 @@ type EmailChannelSettings struct { Enabled *bool `json:"enabled,omitempty"` ExpiringAccess *ExpiringAccessPreference `json:"expiringAccess,omitempty"` ProvisioningRequest *ProvisioningRequestPreference `json:"provisioningRequest,omitempty"` + RequestCreated *RequestCreatedPreference `json:"requestCreated,omitempty"` Reviews *ReviewsPreference `json:"reviews,omitempty"` + System *SystemPreference `json:"system,omitempty"` TaskReminders *TaskRemindersPreference `json:"taskReminders,omitempty"` } @@ -81,6 +83,13 @@ func (e *EmailChannelSettings) GetProvisioningRequest() *ProvisioningRequestPref return e.ProvisioningRequest } +func (e *EmailChannelSettings) GetRequestCreated() *RequestCreatedPreference { + if e == nil { + return nil + } + return e.RequestCreated +} + func (e *EmailChannelSettings) GetReviews() *ReviewsPreference { if e == nil { return nil @@ -88,6 +97,13 @@ func (e *EmailChannelSettings) GetReviews() *ReviewsPreference { return e.Reviews } +func (e *EmailChannelSettings) GetSystem() *SystemPreference { + if e == nil { + return nil + } + return e.System +} + func (e *EmailChannelSettings) GetTaskReminders() *TaskRemindersPreference { if e == nil { return nil diff --git a/pkg/models/shared/encodedcontentguardconfig.go b/pkg/models/shared/encodedcontentguardconfig.go new file mode 100644 index 000000000..c441eb168 --- /dev/null +++ b/pkg/models/shared/encodedcontentguardconfig.go @@ -0,0 +1,36 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EncodedContentGuardConfig detects encoded/obfuscated smuggling in tool input: +// +// long base64 blobs, long hex runs, and invisible/zero-width unicode. +type EncodedContentGuardConfig struct { + // When true, detection records the finding but does not deny (observe-only). + FlagOnly *bool `json:"flagOnly,omitempty"` + // Minimum contiguous base64 run length to flag. <= 0 = default (256). + MinBase64Run *int `json:"minBase64Run,omitempty"` + // Minimum contiguous hex run length to flag. <= 0 = default (128). + MinHexRun *int `json:"minHexRun,omitempty"` +} + +func (e *EncodedContentGuardConfig) GetFlagOnly() *bool { + if e == nil { + return nil + } + return e.FlagOnly +} + +func (e *EncodedContentGuardConfig) GetMinBase64Run() *int { + if e == nil { + return nil + } + return e.MinBase64Run +} + +func (e *EncodedContentGuardConfig) GetMinHexRun() *int { + if e == nil { + return nil + } + return e.MinHexRun +} diff --git a/pkg/models/shared/ensureonboardingsessionrequest.go b/pkg/models/shared/ensureonboardingsessionrequest.go new file mode 100644 index 000000000..c2c8afefc --- /dev/null +++ b/pkg/models/shared/ensureonboardingsessionrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EnsureOnboardingSessionRequest - Requests the active onboarding conversation for the caller's tenant. +type EnsureOnboardingSessionRequest struct { +} diff --git a/pkg/models/shared/ensureonboardingsessionresponse.go b/pkg/models/shared/ensureonboardingsessionresponse.go new file mode 100644 index 000000000..6c87507dc --- /dev/null +++ b/pkg/models/shared/ensureonboardingsessionresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EnsureOnboardingSessionResponse - Returns the active onboarding conversation and whether this call created it. +type EnsureOnboardingSessionResponse struct { + // The active onboarding conversation ID. + ConversationID *string `json:"conversationId,omitempty"` + // True only when this call created and started the conversation. + Created *bool `json:"created,omitempty"` +} + +func (e *EnsureOnboardingSessionResponse) GetConversationID() *string { + if e == nil { + return nil + } + return e.ConversationID +} + +func (e *EnsureOnboardingSessionResponse) GetCreated() *bool { + if e == nil { + return nil + } + return e.Created +} diff --git a/pkg/models/shared/entitlementcutoffimpactpoint.go b/pkg/models/shared/entitlementcutoffimpactpoint.go new file mode 100644 index 000000000..65eb1ee38 --- /dev/null +++ b/pkg/models/shared/entitlementcutoffimpactpoint.go @@ -0,0 +1,36 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EntitlementCutoffImpactPoint reports the exact effect of an inclusive +// +// entitlement coverage cutoff on the analyzed cohort. +type EntitlementCutoffImpactPoint struct { + // Number of analyzed entitlements included at this cutoff. + EntitlementCount *int `json:"entitlementCount,omitempty"` + // Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. + MinimumCoverageBasisPoints *int `json:"minimumCoverageBasisPoints,omitempty"` + // Exact number of cohort users who hold every included entitlement. + UsersWithAllEntitlements *int `json:"usersWithAllEntitlements,omitempty"` +} + +func (e *EntitlementCutoffImpactPoint) GetEntitlementCount() *int { + if e == nil { + return nil + } + return e.EntitlementCount +} + +func (e *EntitlementCutoffImpactPoint) GetMinimumCoverageBasisPoints() *int { + if e == nil { + return nil + } + return e.MinimumCoverageBasisPoints +} + +func (e *EntitlementCutoffImpactPoint) GetUsersWithAllEntitlements() *int { + if e == nil { + return nil + } + return e.UsersWithAllEntitlements +} diff --git a/pkg/models/shared/entitlementref.go b/pkg/models/shared/entitlementref.go index ce2b5b69a..a63ce1cec 100644 --- a/pkg/models/shared/entitlementref.go +++ b/pkg/models/shared/entitlementref.go @@ -2,11 +2,11 @@ package shared -// EntitlementRef identifies an entitlement by app and entitlement ID. +// EntitlementRef identifies an entitlement by application and entitlement ID. type EntitlementRef struct { - // The appId field. + // Application that owns the entitlement. AppID *string `json:"appId,omitempty"` - // The entitlementId field. + // Entitlement within the application. EntitlementID *string `json:"entitlementId,omitempty"` } diff --git a/pkg/models/shared/evaluateentitlementselectionrequest.go b/pkg/models/shared/evaluateentitlementselectionrequest.go new file mode 100644 index 000000000..4fd6ec1a2 --- /dev/null +++ b/pkg/models/shared/evaluateentitlementselectionrequest.go @@ -0,0 +1,45 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EvaluateEntitlementSelectionRequest selects analyzed entitlements using an +// +// inclusive coverage cutoff plus optional manual overrides. +type EvaluateEntitlementSelectionRequest struct { + // Analyzed entitlements to exclude when they meet the cutoff. + ExplicitlyExcluded []EntitlementRef `json:"explicitlyExcluded,omitempty"` + // Analyzed entitlements to include even when they fall below the cutoff. + ExplicitlyIncluded []EntitlementRef `json:"explicitlyIncluded,omitempty"` + // Whether to return profile attribute facets for exact holders. + IncludeFacets *bool `json:"includeFacets,omitempty"` + // Inclusive minimum entitlement coverage in basis points, where 8000 is 80%. + MinimumCoverageBasisPoints *int `json:"minimumCoverageBasisPoints,omitempty"` +} + +func (e *EvaluateEntitlementSelectionRequest) GetExplicitlyExcluded() []EntitlementRef { + if e == nil { + return nil + } + return e.ExplicitlyExcluded +} + +func (e *EvaluateEntitlementSelectionRequest) GetExplicitlyIncluded() []EntitlementRef { + if e == nil { + return nil + } + return e.ExplicitlyIncluded +} + +func (e *EvaluateEntitlementSelectionRequest) GetIncludeFacets() *bool { + if e == nil { + return nil + } + return e.IncludeFacets +} + +func (e *EvaluateEntitlementSelectionRequest) GetMinimumCoverageBasisPoints() *int { + if e == nil { + return nil + } + return e.MinimumCoverageBasisPoints +} diff --git a/pkg/models/shared/evaluateentitlementselectionresponse.go b/pkg/models/shared/evaluateentitlementselectionresponse.go new file mode 100644 index 000000000..9b7c564f3 --- /dev/null +++ b/pkg/models/shared/evaluateentitlementselectionresponse.go @@ -0,0 +1,36 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EvaluateEntitlementSelectionResponse contains the exact impact of the +// +// resolved entitlement selection. +type EvaluateEntitlementSelectionResponse struct { + // Profile attribute facets narrowed to users who hold every selected entitlement. + CoreHolderFacets []AttributeFacet `json:"coreHolderFacets,omitempty"` + // Number of entitlements in the resolved selection. + SelectedEntitlementCount *int `json:"selectedEntitlementCount,omitempty"` + // Exact number of cohort users who hold every selected entitlement. + UsersWithAllEntitlements *int `json:"usersWithAllEntitlements,omitempty"` +} + +func (e *EvaluateEntitlementSelectionResponse) GetCoreHolderFacets() []AttributeFacet { + if e == nil { + return nil + } + return e.CoreHolderFacets +} + +func (e *EvaluateEntitlementSelectionResponse) GetSelectedEntitlementCount() *int { + if e == nil { + return nil + } + return e.SelectedEntitlementCount +} + +func (e *EvaluateEntitlementSelectionResponse) GetUsersWithAllEntitlements() *int { + if e == nil { + return nil + } + return e.UsersWithAllEntitlements +} diff --git a/pkg/models/shared/evaluateexpressions.go b/pkg/models/shared/evaluateexpressions.go index 30667dfbe..66a4116a3 100644 --- a/pkg/models/shared/evaluateexpressions.go +++ b/pkg/models/shared/evaluateexpressions.go @@ -3,6 +3,8 @@ package shared // The EvaluateExpressions message. +// +// Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. type EvaluateExpressions struct { // The expressions field. Expressions []Expression `json:"expressions,omitempty"` diff --git a/pkg/models/shared/expression.go b/pkg/models/shared/expression.go index 49621fb7d..b7962894a 100644 --- a/pkg/models/shared/expression.go +++ b/pkg/models/shared/expression.go @@ -3,6 +3,8 @@ package shared // The Expression message. +// +// Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. type Expression struct { // The expressionCel field. ExpressionCel *string `json:"expressionCel,omitempty"` diff --git a/pkg/models/shared/externalclientinfo.go b/pkg/models/shared/externalclientinfo.go index 5ae47d64a..53590fe61 100644 --- a/pkg/models/shared/externalclientinfo.go +++ b/pkg/models/shared/externalclientinfo.go @@ -14,6 +14,7 @@ const ( ClientIDTypeClientIDTypeUnspecified ClientIDType = "CLIENT_ID_TYPE_UNSPECIFIED" ClientIDTypeClientIDTypeDcr ClientIDType = "CLIENT_ID_TYPE_DCR" ClientIDTypeClientIDTypeMetadataURL ClientIDType = "CLIENT_ID_TYPE_METADATA_URL" + ClientIDTypeClientIDTypeApp ClientIDType = "CLIENT_ID_TYPE_APP" ) func (e ClientIDType) ToPointer() *ClientIDType { @@ -24,7 +25,7 @@ func (e ClientIDType) ToPointer() *ClientIDType { func (e *ClientIDType) IsExact() bool { if e != nil { switch *e { - case "CLIENT_ID_TYPE_UNSPECIFIED", "CLIENT_ID_TYPE_DCR", "CLIENT_ID_TYPE_METADATA_URL": + case "CLIENT_ID_TYPE_UNSPECIFIED", "CLIENT_ID_TYPE_DCR", "CLIENT_ID_TYPE_METADATA_URL", "CLIENT_ID_TYPE_APP": return true } } diff --git a/pkg/models/shared/finding.go b/pkg/models/shared/finding.go index 2584b1e31..d5e626392 100644 --- a/pkg/models/shared/finding.go +++ b/pkg/models/shared/finding.go @@ -96,6 +96,12 @@ func (e *FindingState) IsExact() bool { // - decoyCredentialUsed // - custom // - connectorAnomalyDetectionDisabled +// - deactivatedOwner +// - unusedSecret +// - credentialPubliclyExposed +// - decoyPubliclyExposed +// - credentialExpiring +// - connectorSyncFailing // // This message contains a oneof named target. Only a single field of the following list may be set at a time: // - identityUserTarget @@ -108,7 +114,18 @@ func (e *FindingState) IsExact() bool { // This message contains a oneof named evidence. Only a single field of the following list may be set at a time: // - similarUsernameMatchEvidence // - serviceAccountMisclassificationEvidence +// - deactivatedOwnerEvidence +// - unusedSecretEvidence +// - credentialPubliclyExposedEvidence +// - decoyPubliclyExposedEvidence +// - credentialExpiringEvidence +// - connectorSyncFailingEvidence type Finding struct { + // Bounded key/value metadata bag. Limits: ≤16 entries; keys 1-128 chars + // matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0-256 chars; total + // serialized ≤4096 bytes. Keys matching ^c1/ are reserved. Also readable + // (and settable) via CEL as both finding.annotations and finding.custom_tags. + Annotations map[string]string `json:"annotations,omitempty"` // The appId field. AppID *string `json:"appId,omitempty"` AppResourceTarget *AppResourceTarget `json:"appResourceTarget,omitempty"` @@ -116,15 +133,28 @@ type Finding struct { AssignedOwner *FindingOwnerRef `json:"assignedOwner,omitempty"` ComputedOwner *FindingOwnerRef `json:"computedOwner,omitempty"` ConnectorAnomalyDetectionDisabled *ConnectorAnomalyDetectionDisabledType `json:"connectorAnomalyDetectionDisabled,omitempty"` + ConnectorSyncFailing *ConnectorSyncFailingType `json:"connectorSyncFailing,omitempty"` + ConnectorSyncFailingEvidence *ConnectorSyncFailingEvidence `json:"connectorSyncFailingEvidence,omitempty"` ConnectorTarget *ConnectorTarget `json:"connectorTarget,omitempty"` CreatedAt *time.Time `json:"createdAt,omitempty"` + CredentialExpiring *CredentialExpiringType `json:"credentialExpiring,omitempty"` + CredentialExpiringEvidence *CredentialExpiringEvidence `json:"credentialExpiringEvidence,omitempty"` + CredentialPubliclyExposed *CredentialPubliclyExposedType `json:"credentialPubliclyExposed,omitempty"` + CredentialPubliclyExposedEvidence *CredentialPubliclyExposedEvidence `json:"credentialPubliclyExposedEvidence,omitempty"` Custom *CustomFindingType `json:"custom,omitempty"` // User-supplied sub-classification for custom findings (e.g. "shadow_it"). CustomSubType *string `json:"customSubType,omitempty"` - // The customTags field. - CustomTags map[string]string `json:"customTags,omitempty"` - DecoyCredentialUsed *DecoyCredentialUsedType `json:"decoyCredentialUsed,omitempty"` - DecoyTarget *DecoyTarget `json:"decoyTarget,omitempty"` + // Deprecated: use annotations instead. Read-only mirror of annotations; + // writes to this field are ignored. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. + CustomTags map[string]string `json:"customTags,omitempty"` + DeactivatedOwner *DeactivatedOwnerType `json:"deactivatedOwner,omitempty"` + DeactivatedOwnerEvidence *DeactivatedOwnerEvidence `json:"deactivatedOwnerEvidence,omitempty"` + DecoyCredentialUsed *DecoyCredentialUsedType `json:"decoyCredentialUsed,omitempty"` + DecoyPubliclyExposed *DecoyPubliclyExposedType `json:"decoyPubliclyExposed,omitempty"` + DecoyPubliclyExposedEvidence *DecoyPubliclyExposedEvidence `json:"decoyPubliclyExposedEvidence,omitempty"` + DecoyTarget *DecoyTarget `json:"decoyTarget,omitempty"` // Caller-supplied dedup identity for custom findings; echoed back so IaC // clients can roundtrip it. Empty for detector findings. DedupKeyParts []string `json:"dedupKeyParts,omitempty"` @@ -164,14 +194,18 @@ type Finding struct { SourceKind *SourceKind `json:"sourceKind,omitempty"` // The state field. State *FindingState `json:"state,omitempty"` - // The stateUpdatedById field. + // The human who authored the CURRENT state. Empty when a routing rule or the + // system authored it, so do not read a populated value as "this finding has a + // human owner" -- read it as "a human set the state it is in right now". StateUpdatedByID *string `json:"stateUpdatedById,omitempty"` // The suppressReason field. SuppressReason *string `json:"suppressReason,omitempty"` // The taskId field. - TaskID *string `json:"taskId,omitempty"` - TenantTarget *TenantTarget `json:"tenantTarget,omitempty"` - UpdatedAt *time.Time `json:"updatedAt,omitempty"` + TaskID *string `json:"taskId,omitempty"` + TenantTarget *TenantTarget `json:"tenantTarget,omitempty"` + UnusedSecret *UnusedSecretType `json:"unusedSecret,omitempty"` + UnusedSecretEvidence *UnusedSecretEvidence `json:"unusedSecretEvidence,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` } func (f Finding) MarshalJSON() ([]byte, error) { @@ -185,6 +219,13 @@ func (f *Finding) UnmarshalJSON(data []byte) error { return nil } +func (f *Finding) GetAnnotations() map[string]string { + if f == nil { + return nil + } + return f.Annotations +} + func (f *Finding) GetAppID() *string { if f == nil { return nil @@ -227,6 +268,20 @@ func (f *Finding) GetConnectorAnomalyDetectionDisabled() *ConnectorAnomalyDetect return f.ConnectorAnomalyDetectionDisabled } +func (f *Finding) GetConnectorSyncFailing() *ConnectorSyncFailingType { + if f == nil { + return nil + } + return f.ConnectorSyncFailing +} + +func (f *Finding) GetConnectorSyncFailingEvidence() *ConnectorSyncFailingEvidence { + if f == nil { + return nil + } + return f.ConnectorSyncFailingEvidence +} + func (f *Finding) GetConnectorTarget() *ConnectorTarget { if f == nil { return nil @@ -241,6 +296,34 @@ func (f *Finding) GetCreatedAt() *time.Time { return f.CreatedAt } +func (f *Finding) GetCredentialExpiring() *CredentialExpiringType { + if f == nil { + return nil + } + return f.CredentialExpiring +} + +func (f *Finding) GetCredentialExpiringEvidence() *CredentialExpiringEvidence { + if f == nil { + return nil + } + return f.CredentialExpiringEvidence +} + +func (f *Finding) GetCredentialPubliclyExposed() *CredentialPubliclyExposedType { + if f == nil { + return nil + } + return f.CredentialPubliclyExposed +} + +func (f *Finding) GetCredentialPubliclyExposedEvidence() *CredentialPubliclyExposedEvidence { + if f == nil { + return nil + } + return f.CredentialPubliclyExposedEvidence +} + func (f *Finding) GetCustom() *CustomFindingType { if f == nil { return nil @@ -262,6 +345,20 @@ func (f *Finding) GetCustomTags() map[string]string { return f.CustomTags } +func (f *Finding) GetDeactivatedOwner() *DeactivatedOwnerType { + if f == nil { + return nil + } + return f.DeactivatedOwner +} + +func (f *Finding) GetDeactivatedOwnerEvidence() *DeactivatedOwnerEvidence { + if f == nil { + return nil + } + return f.DeactivatedOwnerEvidence +} + func (f *Finding) GetDecoyCredentialUsed() *DecoyCredentialUsedType { if f == nil { return nil @@ -269,6 +366,20 @@ func (f *Finding) GetDecoyCredentialUsed() *DecoyCredentialUsedType { return f.DecoyCredentialUsed } +func (f *Finding) GetDecoyPubliclyExposed() *DecoyPubliclyExposedType { + if f == nil { + return nil + } + return f.DecoyPubliclyExposed +} + +func (f *Finding) GetDecoyPubliclyExposedEvidence() *DecoyPubliclyExposedEvidence { + if f == nil { + return nil + } + return f.DecoyPubliclyExposedEvidence +} + func (f *Finding) GetDecoyTarget() *DecoyTarget { if f == nil { return nil @@ -486,6 +597,20 @@ func (f *Finding) GetTenantTarget() *TenantTarget { return f.TenantTarget } +func (f *Finding) GetUnusedSecret() *UnusedSecretType { + if f == nil { + return nil + } + return f.UnusedSecret +} + +func (f *Finding) GetUnusedSecretEvidence() *UnusedSecretEvidence { + if f == nil { + return nil + } + return f.UnusedSecretEvidence +} + func (f *Finding) GetUpdatedAt() *time.Time { if f == nil { return nil diff --git a/pkg/models/shared/findingaudience.go b/pkg/models/shared/findingaudience.go new file mode 100644 index 000000000..83cbc4fb5 --- /dev/null +++ b/pkg/models/shared/findingaudience.go @@ -0,0 +1,21 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FindingAudience resolves to a set of identity user IDs to notify. Step-less: +// +// notifications have no escalation ladder. An empty resolution falls back to +// enabled system owners rather than notifying nobody. +// +// This message contains a oneof named typ. Only a single field of the following list may be set at a time: +// - users +type FindingAudience struct { + Users *FindingAudienceUsers `json:"users,omitempty"` +} + +func (f *FindingAudience) GetUsers() *FindingAudienceUsers { + if f == nil { + return nil + } + return f.Users +} diff --git a/pkg/models/shared/findingaudienceusers.go b/pkg/models/shared/findingaudienceusers.go new file mode 100644 index 000000000..4263ab5b9 --- /dev/null +++ b/pkg/models/shared/findingaudienceusers.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FindingAudienceUsers message. +type FindingAudienceUsers struct { + // The userIds field. + UserIds []string `json:"userIds,omitempty"` +} + +func (f *FindingAudienceUsers) GetUserIds() []string { + if f == nil { + return nil + } + return f.UserIds +} diff --git a/pkg/models/shared/findingauditevent.go b/pkg/models/shared/findingauditevent.go index d21f08f97..8bc69e61a 100644 --- a/pkg/models/shared/findingauditevent.go +++ b/pkg/models/shared/findingauditevent.go @@ -30,6 +30,8 @@ const ( FindingAuditEventEventTypeFindingAuditEventTypeEvidenceUpdated FindingAuditEventEventType = "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED" FindingAuditEventEventTypeFindingAuditEventTypeRoutingEvaluated FindingAuditEventEventType = "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED" FindingAuditEventEventTypeFindingAuditEventTypeTransformed FindingAuditEventEventType = "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED" + FindingAuditEventEventTypeFindingAuditEventTypeReprocessRequested FindingAuditEventEventType = "FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED" + FindingAuditEventEventTypeFindingAuditEventTypeReprocessCompleted FindingAuditEventEventType = "FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED" ) func (e FindingAuditEventEventType) ToPointer() *FindingAuditEventEventType { @@ -40,7 +42,7 @@ func (e FindingAuditEventEventType) ToPointer() *FindingAuditEventEventType { func (e *FindingAuditEventEventType) IsExact() bool { if e != nil { switch *e { - case "FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED", "FINDING_AUDIT_EVENT_TYPE_CREATED", "FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SNOOZED", "FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_SUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_RESOLVED", "FINDING_AUDIT_EVENT_TYPE_REOPENED", "FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN", "FINDING_AUDIT_EVENT_TYPE_COMMENT", "FINDING_AUDIT_EVENT_TYPE_TASK_CREATED", "FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED", "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED", "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED", "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED": + case "FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED", "FINDING_AUDIT_EVENT_TYPE_CREATED", "FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SNOOZED", "FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_SUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_RESOLVED", "FINDING_AUDIT_EVENT_TYPE_REOPENED", "FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN", "FINDING_AUDIT_EVENT_TYPE_COMMENT", "FINDING_AUDIT_EVENT_TYPE_TASK_CREATED", "FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED", "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED", "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED", "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED", "FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED", "FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED": return true } } diff --git a/pkg/models/shared/findingauditservicesearchrequest.go b/pkg/models/shared/findingauditservicesearchrequest.go index 9708b1ca4..aa6ef55f3 100644 --- a/pkg/models/shared/findingauditservicesearchrequest.go +++ b/pkg/models/shared/findingauditservicesearchrequest.go @@ -29,6 +29,8 @@ const ( EventTypesFindingAuditEventTypeEvidenceUpdated EventTypes = "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED" EventTypesFindingAuditEventTypeRoutingEvaluated EventTypes = "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED" EventTypesFindingAuditEventTypeTransformed EventTypes = "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED" + EventTypesFindingAuditEventTypeReprocessRequested EventTypes = "FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED" + EventTypesFindingAuditEventTypeReprocessCompleted EventTypes = "FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED" ) func (e EventTypes) ToPointer() *EventTypes { @@ -39,7 +41,7 @@ func (e EventTypes) ToPointer() *EventTypes { func (e *EventTypes) IsExact() bool { if e != nil { switch *e { - case "FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED", "FINDING_AUDIT_EVENT_TYPE_CREATED", "FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SNOOZED", "FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_SUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_RESOLVED", "FINDING_AUDIT_EVENT_TYPE_REOPENED", "FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN", "FINDING_AUDIT_EVENT_TYPE_COMMENT", "FINDING_AUDIT_EVENT_TYPE_TASK_CREATED", "FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED", "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED", "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED", "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED": + case "FINDING_AUDIT_EVENT_TYPE_UNSPECIFIED", "FINDING_AUDIT_EVENT_TYPE_CREATED", "FINDING_AUDIT_EVENT_TYPE_STATE_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SNOOZED", "FINDING_AUDIT_EVENT_TYPE_SNOOZE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTED", "FINDING_AUDIT_EVENT_TYPE_RISK_ACCEPTANCE_EXPIRED", "FINDING_AUDIT_EVENT_TYPE_SUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_UNSUPPRESSED", "FINDING_AUDIT_EVENT_TYPE_RESOLVED", "FINDING_AUDIT_EVENT_TYPE_REOPENED", "FINDING_AUDIT_EVENT_TYPE_OWNER_CHANGED", "FINDING_AUDIT_EVENT_TYPE_SEVERITY_OVERRIDDEN", "FINDING_AUDIT_EVENT_TYPE_COMMENT", "FINDING_AUDIT_EVENT_TYPE_TASK_CREATED", "FINDING_AUDIT_EVENT_TYPE_TASK_CANCELLED", "FINDING_AUDIT_EVENT_TYPE_EVIDENCE_UPDATED", "FINDING_AUDIT_EVENT_TYPE_ROUTING_EVALUATED", "FINDING_AUDIT_EVENT_TYPE_TRANSFORMED", "FINDING_AUDIT_EVENT_TYPE_REPROCESS_REQUESTED", "FINDING_AUDIT_EVENT_TYPE_REPROCESS_COMPLETED": return true } } diff --git a/pkg/models/shared/findingdispatcher.go b/pkg/models/shared/findingdispatcher.go new file mode 100644 index 000000000..93095ce2c --- /dev/null +++ b/pkg/models/shared/findingdispatcher.go @@ -0,0 +1,117 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// TierOverride - Author tier override; may only tighten the derived tier. +type TierOverride string + +const ( + TierOverrideFindingDispatchTierUnspecified TierOverride = "FINDING_DISPATCH_TIER_UNSPECIFIED" + TierOverrideFindingDispatchTierAuto TierOverride = "FINDING_DISPATCH_TIER_AUTO" + TierOverrideFindingDispatchTierRequiresApproval TierOverride = "FINDING_DISPATCH_TIER_REQUIRES_APPROVAL" +) + +func (e TierOverride) ToPointer() *TierOverride { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *TierOverride) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_DISPATCH_TIER_UNSPECIFIED", "FINDING_DISPATCH_TIER_AUTO", "FINDING_DISPATCH_TIER_REQUIRES_APPROVAL": + return true + } + } + return false +} + +// FindingDispatcher is one dispatch that fires when a routing rule matches (the +// +// "Then dispatch" authoring step). A rule carries zero-to-many; every enabled +// dispatcher fires, order-independent. +// +// This message contains a oneof named kind. Only a single field of the following list may be set at a time: +// - triggerAutomation +// - invokeFunction +// - webhook +// - notify +type FindingDispatcher struct { + // Human-facing label. Optional. + DisplayName *string `json:"displayName,omitempty"` + // Per-dispatcher kill switch. + Enabled *bool `json:"enabled,omitempty"` + InvokeFunction *InvokeFunctionDispatcher `json:"invokeFunction,omitempty"` + // Stable id within the rule; survives edits, part of the dispatch idempotency + // key. Minted server-side when empty. + Key *string `json:"key,omitempty"` + Notify *NotifyDispatcher `json:"notify,omitempty"` + NotifyOnOutcome *FindingDispatchOutcomeNotify `json:"notifyOnOutcome,omitempty"` + // Author tier override; may only tighten the derived tier. + TierOverride *TierOverride `json:"tierOverride,omitempty"` + TriggerAutomation *TriggerAutomationDispatcher `json:"triggerAutomation,omitempty"` + Webhook *WebhookDispatcher `json:"webhook,omitempty"` +} + +func (f *FindingDispatcher) GetDisplayName() *string { + if f == nil { + return nil + } + return f.DisplayName +} + +func (f *FindingDispatcher) GetEnabled() *bool { + if f == nil { + return nil + } + return f.Enabled +} + +func (f *FindingDispatcher) GetInvokeFunction() *InvokeFunctionDispatcher { + if f == nil { + return nil + } + return f.InvokeFunction +} + +func (f *FindingDispatcher) GetKey() *string { + if f == nil { + return nil + } + return f.Key +} + +func (f *FindingDispatcher) GetNotify() *NotifyDispatcher { + if f == nil { + return nil + } + return f.Notify +} + +func (f *FindingDispatcher) GetNotifyOnOutcome() *FindingDispatchOutcomeNotify { + if f == nil { + return nil + } + return f.NotifyOnOutcome +} + +func (f *FindingDispatcher) GetTierOverride() *TierOverride { + if f == nil { + return nil + } + return f.TierOverride +} + +func (f *FindingDispatcher) GetTriggerAutomation() *TriggerAutomationDispatcher { + if f == nil { + return nil + } + return f.TriggerAutomation +} + +func (f *FindingDispatcher) GetWebhook() *WebhookDispatcher { + if f == nil { + return nil + } + return f.Webhook +} diff --git a/pkg/models/shared/findingdispatchoutcomenotify.go b/pkg/models/shared/findingdispatchoutcomenotify.go new file mode 100644 index 000000000..f7cf98ca1 --- /dev/null +++ b/pkg/models/shared/findingdispatchoutcomenotify.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FindingDispatchOutcomeNotify notifies recipients once a dispatch settles. +type FindingDispatchOutcomeNotify struct { + // The onDone field. + OnDone *bool `json:"onDone,omitempty"` + // The onError field. + OnError *bool `json:"onError,omitempty"` + // The recipients field. + Recipients []string `json:"recipients,omitempty"` +} + +func (f *FindingDispatchOutcomeNotify) GetOnDone() *bool { + if f == nil { + return nil + } + return f.OnDone +} + +func (f *FindingDispatchOutcomeNotify) GetOnError() *bool { + if f == nil { + return nil + } + return f.OnError +} + +func (f *FindingDispatchOutcomeNotify) GetRecipients() []string { + if f == nil { + return nil + } + return f.Recipients +} diff --git a/pkg/models/shared/findingroutingrule.go b/pkg/models/shared/findingroutingrule.go index 528116708..07d2829ad 100644 --- a/pkg/models/shared/findingroutingrule.go +++ b/pkg/models/shared/findingroutingrule.go @@ -7,6 +7,41 @@ import ( "time" ) +// FindingType - The findingType field. +type FindingType string + +const ( + FindingTypeFindingTypeUnspecified FindingType = "FINDING_TYPE_UNSPECIFIED" + FindingTypeFindingTypeSimilarUsernameMatch FindingType = "FINDING_TYPE_SIMILAR_USERNAME_MATCH" + FindingTypeFindingTypeServiceAccountMisclassification FindingType = "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION" + FindingTypeFindingTypeNhiUnowned FindingType = "FINDING_TYPE_NHI_UNOWNED" + FindingTypeFindingTypeServiceAccountUnowned FindingType = "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED" + FindingTypeFindingTypeDecoyCredentialUsed FindingType = "FINDING_TYPE_DECOY_CREDENTIAL_USED" + FindingTypeFindingTypeCustom FindingType = "FINDING_TYPE_CUSTOM" + FindingTypeFindingTypeConnectorAnomalyDetectionDisabled FindingType = "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED" + FindingTypeFindingTypeDeactivatedOwner FindingType = "FINDING_TYPE_DEACTIVATED_OWNER" + FindingTypeFindingTypeUnusedSecret FindingType = "FINDING_TYPE_UNUSED_SECRET" + FindingTypeFindingTypeCredentialPubliclyExposed FindingType = "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED" + FindingTypeFindingTypeDecoyPubliclyExposed FindingType = "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED" + FindingTypeFindingTypeCredentialExpiring FindingType = "FINDING_TYPE_CREDENTIAL_EXPIRING" + FindingTypeFindingTypeConnectorSyncFailing FindingType = "FINDING_TYPE_CONNECTOR_SYNC_FAILING" +) + +func (e FindingType) ToPointer() *FindingType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FindingType) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED", "FINDING_TYPE_DEACTIVATED_OWNER", "FINDING_TYPE_UNUSED_SECRET", "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED", "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED", "FINDING_TYPE_CREDENTIAL_EXPIRING", "FINDING_TYPE_CONNECTOR_SYNC_FAILING": + return true + } + } + return false +} + // The FindingRoutingRule message. type FindingRoutingRule struct { Action *FindingRoutingRuleAction `json:"action,omitempty"` @@ -17,10 +52,14 @@ type FindingRoutingRule struct { CreatedAt *time.Time `json:"createdAt,omitempty"` // The description field. Description *string `json:"description,omitempty"` + // Dispatchers that fire when the rule matches ("Then dispatch"). Max 10. + Dispatchers []FindingDispatcher `json:"dispatchers,omitempty"` // The displayName field. DisplayName *string `json:"displayName,omitempty"` // The enabled field. Enabled *bool `json:"enabled,omitempty"` + // The findingType field. + FindingType *FindingType `json:"findingType,omitempty"` // The id field. ID *string `json:"id,omitempty"` // The priority field. @@ -76,6 +115,13 @@ func (f *FindingRoutingRule) GetDescription() *string { return f.Description } +func (f *FindingRoutingRule) GetDispatchers() []FindingDispatcher { + if f == nil { + return nil + } + return f.Dispatchers +} + func (f *FindingRoutingRule) GetDisplayName() *string { if f == nil { return nil @@ -90,6 +136,13 @@ func (f *FindingRoutingRule) GetEnabled() *bool { return f.Enabled } +func (f *FindingRoutingRule) GetFindingType() *FindingType { + if f == nil { + return nil + } + return f.FindingType +} + func (f *FindingRoutingRule) GetID() *string { if f == nil { return nil diff --git a/pkg/models/shared/findingsearchrequest.go b/pkg/models/shared/findingsearchrequest.go index 3641805d7..b32b28ce1 100644 --- a/pkg/models/shared/findingsearchrequest.go +++ b/pkg/models/shared/findingsearchrequest.go @@ -37,6 +37,12 @@ const ( FindingTypesFindingTypeDecoyCredentialUsed FindingTypes = "FINDING_TYPE_DECOY_CREDENTIAL_USED" FindingTypesFindingTypeCustom FindingTypes = "FINDING_TYPE_CUSTOM" FindingTypesFindingTypeConnectorAnomalyDetectionDisabled FindingTypes = "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED" + FindingTypesFindingTypeDeactivatedOwner FindingTypes = "FINDING_TYPE_DEACTIVATED_OWNER" + FindingTypesFindingTypeUnusedSecret FindingTypes = "FINDING_TYPE_UNUSED_SECRET" + FindingTypesFindingTypeCredentialPubliclyExposed FindingTypes = "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED" + FindingTypesFindingTypeDecoyPubliclyExposed FindingTypes = "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED" + FindingTypesFindingTypeCredentialExpiring FindingTypes = "FINDING_TYPE_CREDENTIAL_EXPIRING" + FindingTypesFindingTypeConnectorSyncFailing FindingTypes = "FINDING_TYPE_CONNECTOR_SYNC_FAILING" ) func (e FindingTypes) ToPointer() *FindingTypes { @@ -47,28 +53,28 @@ func (e FindingTypes) ToPointer() *FindingTypes { func (e *FindingTypes) IsExact() bool { if e != nil { switch *e { - case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED": + case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED", "FINDING_TYPE_DEACTIVATED_OWNER", "FINDING_TYPE_UNUSED_SECRET", "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED", "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED", "FINDING_TYPE_CREDENTIAL_EXPIRING", "FINDING_TYPE_CONNECTOR_SYNC_FAILING": return true } } return false } -type NhiTypes string +type FindingSearchRequestNhiTypes string const ( - NhiTypesNhiTypeUnspecified NhiTypes = "NHI_TYPE_UNSPECIFIED" - NhiTypesNhiTypeAppRegistration NhiTypes = "NHI_TYPE_APP_REGISTRATION" - NhiTypesNhiTypeAssumableRole NhiTypes = "NHI_TYPE_ASSUMABLE_ROLE" - NhiTypesNhiTypeManagedIdentity NhiTypes = "NHI_TYPE_MANAGED_IDENTITY" + FindingSearchRequestNhiTypesNhiTypeUnspecified FindingSearchRequestNhiTypes = "NHI_TYPE_UNSPECIFIED" + FindingSearchRequestNhiTypesNhiTypeAppRegistration FindingSearchRequestNhiTypes = "NHI_TYPE_APP_REGISTRATION" + FindingSearchRequestNhiTypesNhiTypeAssumableRole FindingSearchRequestNhiTypes = "NHI_TYPE_ASSUMABLE_ROLE" + FindingSearchRequestNhiTypesNhiTypeManagedIdentity FindingSearchRequestNhiTypes = "NHI_TYPE_MANAGED_IDENTITY" ) -func (e NhiTypes) ToPointer() *NhiTypes { +func (e FindingSearchRequestNhiTypes) ToPointer() *FindingSearchRequestNhiTypes { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *NhiTypes) IsExact() bool { +func (e *FindingSearchRequestNhiTypes) IsExact() bool { if e != nil { switch *e { case "NHI_TYPE_UNSPECIFIED", "NHI_TYPE_APP_REGISTRATION", "NHI_TYPE_ASSUMABLE_ROLE", "NHI_TYPE_MANAGED_IDENTITY": @@ -194,7 +200,7 @@ type FindingSearchRequest struct { // Filter to findings whose target resource's nhi_type is one of these (OR // within field). Empty = not applied; pass all NhiType values to match any // nhi resource. - NhiTypes []NhiTypes `json:"nhiTypes,omitempty"` + NhiTypes []FindingSearchRequestNhiTypes `json:"nhiTypes,omitempty"` // Filter by effective owner identity-user IDs (OR within field). Matches // findings whose effective owner (assigned_owner if set, else computed_owner) // resolves to an identity user in this list. The reserved "unassigned" @@ -301,7 +307,7 @@ func (f *FindingSearchRequest) GetIncludeUnassigned() *bool { return f.IncludeUnassigned } -func (f *FindingSearchRequest) GetNhiTypes() []NhiTypes { +func (f *FindingSearchRequest) GetNhiTypes() []FindingSearchRequestNhiTypes { if f == nil { return nil } diff --git a/pkg/models/shared/findingsettingsentry.go b/pkg/models/shared/findingsettingsentry.go new file mode 100644 index 000000000..3461b7908 --- /dev/null +++ b/pkg/models/shared/findingsettingsentry.go @@ -0,0 +1,66 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FindingSettingsEntryFindingType - The finding type to configure. Must be a detector-backed type. +type FindingSettingsEntryFindingType string + +const ( + FindingSettingsEntryFindingTypeFindingTypeUnspecified FindingSettingsEntryFindingType = "FINDING_TYPE_UNSPECIFIED" + FindingSettingsEntryFindingTypeFindingTypeSimilarUsernameMatch FindingSettingsEntryFindingType = "FINDING_TYPE_SIMILAR_USERNAME_MATCH" + FindingSettingsEntryFindingTypeFindingTypeServiceAccountMisclassification FindingSettingsEntryFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION" + FindingSettingsEntryFindingTypeFindingTypeNhiUnowned FindingSettingsEntryFindingType = "FINDING_TYPE_NHI_UNOWNED" + FindingSettingsEntryFindingTypeFindingTypeServiceAccountUnowned FindingSettingsEntryFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED" + FindingSettingsEntryFindingTypeFindingTypeDecoyCredentialUsed FindingSettingsEntryFindingType = "FINDING_TYPE_DECOY_CREDENTIAL_USED" + FindingSettingsEntryFindingTypeFindingTypeCustom FindingSettingsEntryFindingType = "FINDING_TYPE_CUSTOM" + FindingSettingsEntryFindingTypeFindingTypeConnectorAnomalyDetectionDisabled FindingSettingsEntryFindingType = "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED" + FindingSettingsEntryFindingTypeFindingTypeDeactivatedOwner FindingSettingsEntryFindingType = "FINDING_TYPE_DEACTIVATED_OWNER" + FindingSettingsEntryFindingTypeFindingTypeUnusedSecret FindingSettingsEntryFindingType = "FINDING_TYPE_UNUSED_SECRET" + FindingSettingsEntryFindingTypeFindingTypeCredentialPubliclyExposed FindingSettingsEntryFindingType = "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED" + FindingSettingsEntryFindingTypeFindingTypeDecoyPubliclyExposed FindingSettingsEntryFindingType = "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED" + FindingSettingsEntryFindingTypeFindingTypeCredentialExpiring FindingSettingsEntryFindingType = "FINDING_TYPE_CREDENTIAL_EXPIRING" + FindingSettingsEntryFindingTypeFindingTypeConnectorSyncFailing FindingSettingsEntryFindingType = "FINDING_TYPE_CONNECTOR_SYNC_FAILING" +) + +func (e FindingSettingsEntryFindingType) ToPointer() *FindingSettingsEntryFindingType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FindingSettingsEntryFindingType) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED", "FINDING_TYPE_DEACTIVATED_OWNER", "FINDING_TYPE_UNUSED_SECRET", "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED", "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED", "FINDING_TYPE_CREDENTIAL_EXPIRING", "FINDING_TYPE_CONNECTOR_SYNC_FAILING": + return true + } + } + return false +} + +// FindingSettingsEntry is a requested change to one type, which is why it is a +// +// separate message from FindingTypeSetting rather than the same one reused: an +// update needs enum validation and presence on `enabled` so an omitted field is +// an error, while a response always carries a value and must not make callers +// handle an absent one. +type FindingSettingsEntry struct { + // Target state. Required: explicit presence keeps an omitted field from + // reading as false and silently switching a detector off. + Enabled *bool `json:"enabled,omitempty"` + // The finding type to configure. Must be a detector-backed type. + FindingType *FindingSettingsEntryFindingType `json:"findingType,omitempty"` +} + +func (f *FindingSettingsEntry) GetEnabled() *bool { + if f == nil { + return nil + } + return f.Enabled +} + +func (f *FindingSettingsEntry) GetFindingType() *FindingSettingsEntryFindingType { + if f == nil { + return nil + } + return f.FindingType +} diff --git a/pkg/models/shared/findingtransformationrule.go b/pkg/models/shared/findingtransformationrule.go index e5f6cb9e4..64f35e3cc 100644 --- a/pkg/models/shared/findingtransformationrule.go +++ b/pkg/models/shared/findingtransformationrule.go @@ -7,6 +7,41 @@ import ( "time" ) +// FindingTransformationRuleFindingType - The findingType field. +type FindingTransformationRuleFindingType string + +const ( + FindingTransformationRuleFindingTypeFindingTypeUnspecified FindingTransformationRuleFindingType = "FINDING_TYPE_UNSPECIFIED" + FindingTransformationRuleFindingTypeFindingTypeSimilarUsernameMatch FindingTransformationRuleFindingType = "FINDING_TYPE_SIMILAR_USERNAME_MATCH" + FindingTransformationRuleFindingTypeFindingTypeServiceAccountMisclassification FindingTransformationRuleFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION" + FindingTransformationRuleFindingTypeFindingTypeNhiUnowned FindingTransformationRuleFindingType = "FINDING_TYPE_NHI_UNOWNED" + FindingTransformationRuleFindingTypeFindingTypeServiceAccountUnowned FindingTransformationRuleFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED" + FindingTransformationRuleFindingTypeFindingTypeDecoyCredentialUsed FindingTransformationRuleFindingType = "FINDING_TYPE_DECOY_CREDENTIAL_USED" + FindingTransformationRuleFindingTypeFindingTypeCustom FindingTransformationRuleFindingType = "FINDING_TYPE_CUSTOM" + FindingTransformationRuleFindingTypeFindingTypeConnectorAnomalyDetectionDisabled FindingTransformationRuleFindingType = "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED" + FindingTransformationRuleFindingTypeFindingTypeDeactivatedOwner FindingTransformationRuleFindingType = "FINDING_TYPE_DEACTIVATED_OWNER" + FindingTransformationRuleFindingTypeFindingTypeUnusedSecret FindingTransformationRuleFindingType = "FINDING_TYPE_UNUSED_SECRET" + FindingTransformationRuleFindingTypeFindingTypeCredentialPubliclyExposed FindingTransformationRuleFindingType = "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED" + FindingTransformationRuleFindingTypeFindingTypeDecoyPubliclyExposed FindingTransformationRuleFindingType = "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED" + FindingTransformationRuleFindingTypeFindingTypeCredentialExpiring FindingTransformationRuleFindingType = "FINDING_TYPE_CREDENTIAL_EXPIRING" + FindingTransformationRuleFindingTypeFindingTypeConnectorSyncFailing FindingTransformationRuleFindingType = "FINDING_TYPE_CONNECTOR_SYNC_FAILING" +) + +func (e FindingTransformationRuleFindingType) ToPointer() *FindingTransformationRuleFindingType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FindingTransformationRuleFindingType) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED", "FINDING_TYPE_DEACTIVATED_OWNER", "FINDING_TYPE_UNUSED_SECRET", "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED", "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED", "FINDING_TYPE_CREDENTIAL_EXPIRING", "FINDING_TYPE_CONNECTOR_SYNC_FAILING": + return true + } + } + return false +} + // FindingTransformationRule transforms a finding at processing time, before // // routing runs. Rules fall through: every matching rule applies its transforms @@ -27,6 +62,8 @@ type FindingTransformationRule struct { // Application order (ascending; last-applied rule wins per field). A sequence, // not a precedence rank. EvaluationOrder *int `json:"evaluationOrder,omitempty"` + // The findingType field. + FindingType *FindingTransformationRuleFindingType `json:"findingType,omitempty"` // The id field. ID *string `json:"id,omitempty"` // The templateId field. @@ -96,6 +133,13 @@ func (f *FindingTransformationRule) GetEvaluationOrder() *int { return f.EvaluationOrder } +func (f *FindingTransformationRule) GetFindingType() *FindingTransformationRuleFindingType { + if f == nil { + return nil + } + return f.FindingType +} + func (f *FindingTransformationRule) GetID() *string { if f == nil { return nil diff --git a/pkg/models/shared/findingtypesetting.go b/pkg/models/shared/findingtypesetting.go new file mode 100644 index 000000000..88406a13c --- /dev/null +++ b/pkg/models/shared/findingtypesetting.go @@ -0,0 +1,66 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FindingTypeSettingFindingType - The findingType field. +type FindingTypeSettingFindingType string + +const ( + FindingTypeSettingFindingTypeFindingTypeUnspecified FindingTypeSettingFindingType = "FINDING_TYPE_UNSPECIFIED" + FindingTypeSettingFindingTypeFindingTypeSimilarUsernameMatch FindingTypeSettingFindingType = "FINDING_TYPE_SIMILAR_USERNAME_MATCH" + FindingTypeSettingFindingTypeFindingTypeServiceAccountMisclassification FindingTypeSettingFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION" + FindingTypeSettingFindingTypeFindingTypeNhiUnowned FindingTypeSettingFindingType = "FINDING_TYPE_NHI_UNOWNED" + FindingTypeSettingFindingTypeFindingTypeServiceAccountUnowned FindingTypeSettingFindingType = "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED" + FindingTypeSettingFindingTypeFindingTypeDecoyCredentialUsed FindingTypeSettingFindingType = "FINDING_TYPE_DECOY_CREDENTIAL_USED" + FindingTypeSettingFindingTypeFindingTypeCustom FindingTypeSettingFindingType = "FINDING_TYPE_CUSTOM" + FindingTypeSettingFindingTypeFindingTypeConnectorAnomalyDetectionDisabled FindingTypeSettingFindingType = "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED" + FindingTypeSettingFindingTypeFindingTypeDeactivatedOwner FindingTypeSettingFindingType = "FINDING_TYPE_DEACTIVATED_OWNER" + FindingTypeSettingFindingTypeFindingTypeUnusedSecret FindingTypeSettingFindingType = "FINDING_TYPE_UNUSED_SECRET" + FindingTypeSettingFindingTypeFindingTypeCredentialPubliclyExposed FindingTypeSettingFindingType = "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED" + FindingTypeSettingFindingTypeFindingTypeDecoyPubliclyExposed FindingTypeSettingFindingType = "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED" + FindingTypeSettingFindingTypeFindingTypeCredentialExpiring FindingTypeSettingFindingType = "FINDING_TYPE_CREDENTIAL_EXPIRING" + FindingTypeSettingFindingTypeFindingTypeConnectorSyncFailing FindingTypeSettingFindingType = "FINDING_TYPE_CONNECTOR_SYNC_FAILING" +) + +func (e FindingTypeSettingFindingType) ToPointer() *FindingTypeSettingFindingType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FindingTypeSettingFindingType) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_TYPE_UNSPECIFIED", "FINDING_TYPE_SIMILAR_USERNAME_MATCH", "FINDING_TYPE_SERVICE_ACCOUNT_MISCLASSIFICATION", "FINDING_TYPE_NHI_UNOWNED", "FINDING_TYPE_SERVICE_ACCOUNT_UNOWNED", "FINDING_TYPE_DECOY_CREDENTIAL_USED", "FINDING_TYPE_CUSTOM", "FINDING_TYPE_CONNECTOR_ANOMALY_DETECTION_DISABLED", "FINDING_TYPE_DEACTIVATED_OWNER", "FINDING_TYPE_UNUSED_SECRET", "FINDING_TYPE_CREDENTIAL_PUBLICLY_EXPOSED", "FINDING_TYPE_DECOY_PUBLICLY_EXPOSED", "FINDING_TYPE_CREDENTIAL_EXPIRING", "FINDING_TYPE_CONNECTOR_SYNC_FAILING": + return true + } + } + return false +} + +// FindingTypeSetting is one finding type's detection switch as it currently +// +// stands. Named for a single type on purpose: the stored model +// c1.models.finding.v1.FindingSettings is the tenant-wide object holding every +// type, and one name for both granularities reads as the same thing twice. +// Display copy for the type is client-owned; this carries state only. +type FindingTypeSetting struct { + // Whether the system detects this finding type. Types never configured read + // back their shipped default, which is per type rather than uniformly on. + Enabled *bool `json:"enabled,omitempty"` + // The findingType field. + FindingType *FindingTypeSettingFindingType `json:"findingType,omitempty"` +} + +func (f *FindingTypeSetting) GetEnabled() *bool { + if f == nil { + return nil + } + return f.Enabled +} + +func (f *FindingTypeSetting) GetFindingType() *FindingTypeSettingFindingType { + if f == nil { + return nil + } + return f.FindingType +} diff --git a/pkg/models/shared/forcesyncresponse.go b/pkg/models/shared/forcesyncresponse.go index 9af1cc2c3..0b89e7500 100644 --- a/pkg/models/shared/forcesyncresponse.go +++ b/pkg/models/shared/forcesyncresponse.go @@ -2,6 +2,8 @@ package shared -// ForceSyncResponse - Empty response body. Status code indicates success. +// ForceSyncResponse - Empty response body. Status code indicates success. Poll the connector sync status +// +// for progress after ForceSync accepts the request. type ForceSyncResponse struct { } diff --git a/pkg/models/shared/formstringfield.go b/pkg/models/shared/formstringfield.go index 2bbd79c03..3f9cc872f 100644 --- a/pkg/models/shared/formstringfield.go +++ b/pkg/models/shared/formstringfield.go @@ -9,7 +9,9 @@ package shared // - passwordField // - selectField // - pickerField +// - dateField type FormStringField struct { + DateField *DateField `json:"dateField,omitempty"` // The defaultValue field. DefaultValue *string `json:"defaultValue,omitempty"` PasswordField *PasswordField `json:"passwordField,omitempty"` @@ -21,6 +23,13 @@ type FormStringField struct { TextField *TextField `json:"textField,omitempty"` } +func (f *FormStringField) GetDateField() *DateField { + if f == nil { + return nil + } + return f.DateField +} + func (f *FormStringField) GetDefaultValue() *string { if f == nil { return nil diff --git a/pkg/models/shared/function.go b/pkg/models/shared/function.go index f50a268b9..b4f723c1e 100644 --- a/pkg/models/shared/function.go +++ b/pkg/models/shared/function.go @@ -43,6 +43,11 @@ type Function struct { FunctionType *FunctionType `json:"functionType,omitempty"` // The head field. Head *string `json:"head,omitempty"` + // IDs of every non-deleted hook that still references this function. + // Read-only: maintained by the Hook API, not by CreateFunction/UpdateFunction. + // Non-empty means DeleteFunction will refuse to delete until these are + // removed or retargeted. + HookRefs []string `json:"hookRefs,omitempty"` // The id field. ID *string `json:"id,omitempty"` // The isDraft field. @@ -74,6 +79,9 @@ type Function struct { // tenant has completed the FunctionsToSPN migration) and by the migration // itself, never by UpdateFunction. Retired once all functions are on SPN. UseSpn *bool `json:"useSpn,omitempty"` + // IDs of every non-deleted workflow template whose CallFunction step still + // references this function. Read-only, same semantics as hook_refs. + WorkflowTemplateRefs []string `json:"workflowTemplateRefs,omitempty"` } func (f Function) MarshalJSON() ([]byte, error) { @@ -129,6 +137,13 @@ func (f *Function) GetHead() *string { return f.Head } +func (f *Function) GetHookRefs() []string { + if f == nil { + return nil + } + return f.HookRefs +} + func (f *Function) GetID() *string { if f == nil { return nil @@ -192,6 +207,13 @@ func (f *Function) GetUseSpn() *bool { return f.UseSpn } +func (f *Function) GetWorkflowTemplateRefs() []string { + if f == nil { + return nil + } + return f.WorkflowTemplateRefs +} + // FunctionInput - Function represents a customer-provided code extension in the API type FunctionInput struct { // The description field. diff --git a/pkg/models/shared/functionsserviceupdatefunctionrequest.go b/pkg/models/shared/functionsserviceupdatefunctionrequest.go index 777e9794d..886ed4d5e 100644 --- a/pkg/models/shared/functionsserviceupdatefunctionrequest.go +++ b/pkg/models/shared/functionsserviceupdatefunctionrequest.go @@ -4,8 +4,30 @@ package shared // The FunctionsServiceUpdateFunctionRequest message. type FunctionsServiceUpdateFunctionRequest struct { - Function *FunctionInput `json:"function,omitempty"` - UpdateMask *string `json:"updateMask,omitempty"` + // The commit message describing this code update. Defaults to a generic + // message if content is set and this is empty. Ignored if content is empty. + CommitMessage *string `json:"commitMessage,omitempty"` + // File map for a new code commit, applied as the function's new head + // commit. Keys are file paths in the function root; values are file + // contents as bytes. See CreateFunctionRequest.initial_content for the + // required entry-file signature. Independent of update_mask. + Content map[string]string `json:"content,omitempty"` + Function *FunctionInput `json:"function,omitempty"` + UpdateMask *string `json:"updateMask,omitempty"` +} + +func (f *FunctionsServiceUpdateFunctionRequest) GetCommitMessage() *string { + if f == nil { + return nil + } + return f.CommitMessage +} + +func (f *FunctionsServiceUpdateFunctionRequest) GetContent() map[string]string { + if f == nil { + return nil + } + return f.Content } func (f *FunctionsServiceUpdateFunctionRequest) GetFunction() *FunctionInput { diff --git a/pkg/models/shared/functionsserviceupdatefunctionresponse.go b/pkg/models/shared/functionsserviceupdatefunctionresponse.go index bdd26ea68..c25a1fa19 100644 --- a/pkg/models/shared/functionsserviceupdatefunctionresponse.go +++ b/pkg/models/shared/functionsserviceupdatefunctionresponse.go @@ -4,7 +4,15 @@ package shared // The FunctionsServiceUpdateFunctionResponse message. type FunctionsServiceUpdateFunctionResponse struct { - Function *Function `json:"function,omitempty"` + Commit *FunctionCommit `json:"commit,omitempty"` + Function *Function `json:"function,omitempty"` +} + +func (f *FunctionsServiceUpdateFunctionResponse) GetCommit() *FunctionCommit { + if f == nil { + return nil + } + return f.Commit } func (f *FunctionsServiceUpdateFunctionResponse) GetFunction() *Function { diff --git a/pkg/models/shared/fundassignment.go b/pkg/models/shared/fundassignment.go new file mode 100644 index 000000000..cdc2c506c --- /dev/null +++ b/pkg/models/shared/fundassignment.go @@ -0,0 +1,65 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// FundAssignment is one principal's fund exception as the API renders it. +type FundAssignment struct { + Controls *SpendControls `json:"controls,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` + // Canonical c1.models.user.v2.User id, every UserType. + UserID *string `json:"userId,omitempty"` +} + +func (f FundAssignment) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(f, "", false) +} + +func (f *FundAssignment) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &f, "", false, nil); err != nil { + return err + } + return nil +} + +func (f *FundAssignment) GetControls() *SpendControls { + if f == nil { + return nil + } + return f.Controls +} + +func (f *FundAssignment) GetCreatedAt() *time.Time { + if f == nil { + return nil + } + return f.CreatedAt +} + +func (f *FundAssignment) GetTenantID() *string { + if f == nil { + return nil + } + return f.TenantID +} + +func (f *FundAssignment) GetUpdatedAt() *time.Time { + if f == nil { + return nil + } + return f.UpdatedAt +} + +func (f *FundAssignment) GetUserID() *string { + if f == nil { + return nil + } + return f.UserID +} diff --git a/pkg/models/shared/fundassignmenthistoryentry.go b/pkg/models/shared/fundassignmenthistoryentry.go new file mode 100644 index 000000000..edf653705 --- /dev/null +++ b/pkg/models/shared/fundassignmenthistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentHistoryEntry message. +type FundAssignmentHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *FundAssignment `json:"snapshot,omitempty"` +} + +func (f *FundAssignmentHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if f == nil { + return nil + } + return f.Metadata +} + +func (f *FundAssignmentHistoryEntry) GetSnapshot() *FundAssignment { + if f == nil { + return nil + } + return f.Snapshot +} diff --git a/pkg/models/shared/fundassignmentserviceclearextensionrequest.go b/pkg/models/shared/fundassignmentserviceclearextensionrequest.go new file mode 100644 index 000000000..b4deec027 --- /dev/null +++ b/pkg/models/shared/fundassignmentserviceclearextensionrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceClearExtensionRequest message. +type FundAssignmentServiceClearExtensionRequest struct { +} diff --git a/pkg/models/shared/fundassignmentserviceclearextensionresponse.go b/pkg/models/shared/fundassignmentserviceclearextensionresponse.go new file mode 100644 index 000000000..3ea77fbbf --- /dev/null +++ b/pkg/models/shared/fundassignmentserviceclearextensionresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceClearExtensionResponse message. +type FundAssignmentServiceClearExtensionResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceClearExtensionResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundassignmentservicedeleterequest.go b/pkg/models/shared/fundassignmentservicedeleterequest.go new file mode 100644 index 000000000..5bb97aa69 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceDeleteRequest message. +type FundAssignmentServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/fundassignmentservicedeleteresponse.go b/pkg/models/shared/fundassignmentservicedeleteresponse.go new file mode 100644 index 000000000..682e7b155 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceDeleteResponse message. +type FundAssignmentServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/fundassignmentservicegetresponse.go b/pkg/models/shared/fundassignmentservicegetresponse.go new file mode 100644 index 000000000..2ed1d671e --- /dev/null +++ b/pkg/models/shared/fundassignmentservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceGetResponse message. +type FundAssignmentServiceGetResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceGetResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundassignmentservicegrantextensionrequest.go b/pkg/models/shared/fundassignmentservicegrantextensionrequest.go new file mode 100644 index 000000000..8f98c597f --- /dev/null +++ b/pkg/models/shared/fundassignmentservicegrantextensionrequest.go @@ -0,0 +1,48 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// The FundAssignmentServiceGrantExtensionRequest message. +type FundAssignmentServiceGrantExtensionRequest struct { + ExpiresAt *time.Time `json:"expiresAt,omitempty"` + Limit *SpendLimit `json:"limit,omitempty"` + // Subject-visible: "why do I have this bump". + Reason *string `json:"reason,omitempty"` +} + +func (f FundAssignmentServiceGrantExtensionRequest) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(f, "", false) +} + +func (f *FundAssignmentServiceGrantExtensionRequest) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &f, "", false, nil); err != nil { + return err + } + return nil +} + +func (f *FundAssignmentServiceGrantExtensionRequest) GetExpiresAt() *time.Time { + if f == nil { + return nil + } + return f.ExpiresAt +} + +func (f *FundAssignmentServiceGrantExtensionRequest) GetLimit() *SpendLimit { + if f == nil { + return nil + } + return f.Limit +} + +func (f *FundAssignmentServiceGrantExtensionRequest) GetReason() *string { + if f == nil { + return nil + } + return f.Reason +} diff --git a/pkg/models/shared/fundassignmentservicegrantextensionresponse.go b/pkg/models/shared/fundassignmentservicegrantextensionresponse.go new file mode 100644 index 000000000..05cf771d7 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicegrantextensionresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceGrantExtensionResponse message. +type FundAssignmentServiceGrantExtensionResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceGrantExtensionResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundassignmentservicelisthistoryresponse.go b/pkg/models/shared/fundassignmentservicelisthistoryresponse.go new file mode 100644 index 000000000..f07f55d64 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceListHistoryResponse message. +type FundAssignmentServiceListHistoryResponse struct { + // The list field. + List []FundAssignmentHistoryEntry `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundAssignmentServiceListHistoryResponse) GetList() []FundAssignmentHistoryEntry { + if f == nil { + return nil + } + return f.List +} + +func (f *FundAssignmentServiceListHistoryResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundassignmentservicesearchrequest.go b/pkg/models/shared/fundassignmentservicesearchrequest.go new file mode 100644 index 000000000..a8101bdd7 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesearchrequest.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceSearchRequest message. +type FundAssignmentServiceSearchRequest struct { + // The pageSize field. + PageSize *int `json:"pageSize,omitempty"` + // The pageToken field. + PageToken *string `json:"pageToken,omitempty"` + // Restrict to these subjects; empty returns every assignment in the tenant. + UserIds []string `json:"userIds,omitempty"` +} + +func (f *FundAssignmentServiceSearchRequest) GetPageSize() *int { + if f == nil { + return nil + } + return f.PageSize +} + +func (f *FundAssignmentServiceSearchRequest) GetPageToken() *string { + if f == nil { + return nil + } + return f.PageToken +} + +func (f *FundAssignmentServiceSearchRequest) GetUserIds() []string { + if f == nil { + return nil + } + return f.UserIds +} diff --git a/pkg/models/shared/fundassignmentservicesearchresponse.go b/pkg/models/shared/fundassignmentservicesearchresponse.go new file mode 100644 index 000000000..d1c4a04b7 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesearchresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceSearchResponse message. +type FundAssignmentServiceSearchResponse struct { + // The list field. + List []FundAssignment `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundAssignmentServiceSearchResponse) GetList() []FundAssignment { + if f == nil { + return nil + } + return f.List +} + +func (f *FundAssignmentServiceSearchResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundassignmentservicesetlimitrequest.go b/pkg/models/shared/fundassignmentservicesetlimitrequest.go new file mode 100644 index 000000000..8d543c662 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesetlimitrequest.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FundAssignmentServiceSetLimitRequestPeriod - Optional period override. Only valid together with the limit it denominates. +type FundAssignmentServiceSetLimitRequestPeriod string + +const ( + FundAssignmentServiceSetLimitRequestPeriodPeriodKindUnspecified FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_UNSPECIFIED" + FundAssignmentServiceSetLimitRequestPeriodPeriodKindDaily FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_DAILY" + FundAssignmentServiceSetLimitRequestPeriodPeriodKindWeekly FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_WEEKLY" + FundAssignmentServiceSetLimitRequestPeriodPeriodKindMonthly FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_MONTHLY" + FundAssignmentServiceSetLimitRequestPeriodPeriodKindQuarterly FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_QUARTERLY" + FundAssignmentServiceSetLimitRequestPeriodPeriodKindYearly FundAssignmentServiceSetLimitRequestPeriod = "PERIOD_KIND_YEARLY" +) + +func (e FundAssignmentServiceSetLimitRequestPeriod) ToPointer() *FundAssignmentServiceSetLimitRequestPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FundAssignmentServiceSetLimitRequestPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// The FundAssignmentServiceSetLimitRequest message. +type FundAssignmentServiceSetLimitRequest struct { + Limit *SpendLimit `json:"limit,omitempty"` + // Optional period override. Only valid together with the limit it denominates. + Period *FundAssignmentServiceSetLimitRequestPeriod `json:"period,omitempty"` +} + +func (f *FundAssignmentServiceSetLimitRequest) GetLimit() *SpendLimit { + if f == nil { + return nil + } + return f.Limit +} + +func (f *FundAssignmentServiceSetLimitRequest) GetPeriod() *FundAssignmentServiceSetLimitRequestPeriod { + if f == nil { + return nil + } + return f.Period +} diff --git a/pkg/models/shared/fundassignmentservicesetlimitresponse.go b/pkg/models/shared/fundassignmentservicesetlimitresponse.go new file mode 100644 index 000000000..6180704f1 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesetlimitresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceSetLimitResponse message. +type FundAssignmentServiceSetLimitResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceSetLimitResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundassignmentservicesuspendrequest.go b/pkg/models/shared/fundassignmentservicesuspendrequest.go new file mode 100644 index 000000000..0df0a88a0 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesuspendrequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceSuspendRequest message. +type FundAssignmentServiceSuspendRequest struct { + // The reason field. + Reason *string `json:"reason,omitempty"` +} + +func (f *FundAssignmentServiceSuspendRequest) GetReason() *string { + if f == nil { + return nil + } + return f.Reason +} diff --git a/pkg/models/shared/fundassignmentservicesuspendresponse.go b/pkg/models/shared/fundassignmentservicesuspendresponse.go new file mode 100644 index 000000000..107abc561 --- /dev/null +++ b/pkg/models/shared/fundassignmentservicesuspendresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceSuspendResponse message. +type FundAssignmentServiceSuspendResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceSuspendResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundassignmentserviceunsuspendrequest.go b/pkg/models/shared/fundassignmentserviceunsuspendrequest.go new file mode 100644 index 000000000..4c33792f3 --- /dev/null +++ b/pkg/models/shared/fundassignmentserviceunsuspendrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceUnsuspendRequest message. +type FundAssignmentServiceUnsuspendRequest struct { +} diff --git a/pkg/models/shared/fundassignmentserviceunsuspendresponse.go b/pkg/models/shared/fundassignmentserviceunsuspendresponse.go new file mode 100644 index 000000000..527fc0acf --- /dev/null +++ b/pkg/models/shared/fundassignmentserviceunsuspendresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundAssignmentServiceUnsuspendResponse message. +type FundAssignmentServiceUnsuspendResponse struct { + Assignment *FundAssignment `json:"assignment,omitempty"` +} + +func (f *FundAssignmentServiceUnsuspendResponse) GetAssignment() *FundAssignment { + if f == nil { + return nil + } + return f.Assignment +} diff --git a/pkg/models/shared/fundpolicy.go b/pkg/models/shared/fundpolicy.go new file mode 100644 index 000000000..2d4b25256 --- /dev/null +++ b/pkg/models/shared/fundpolicy.go @@ -0,0 +1,112 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// FundPolicyPeriod - The root period every amount in the tenant is denominated in. +type FundPolicyPeriod string + +const ( + FundPolicyPeriodPeriodKindUnspecified FundPolicyPeriod = "PERIOD_KIND_UNSPECIFIED" + FundPolicyPeriodPeriodKindDaily FundPolicyPeriod = "PERIOD_KIND_DAILY" + FundPolicyPeriodPeriodKindWeekly FundPolicyPeriod = "PERIOD_KIND_WEEKLY" + FundPolicyPeriodPeriodKindMonthly FundPolicyPeriod = "PERIOD_KIND_MONTHLY" + FundPolicyPeriodPeriodKindQuarterly FundPolicyPeriod = "PERIOD_KIND_QUARTERLY" + FundPolicyPeriodPeriodKindYearly FundPolicyPeriod = "PERIOD_KIND_YEARLY" +) + +func (e FundPolicyPeriod) ToPointer() *FundPolicyPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FundPolicyPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// FundPolicy is the tenant's fund policy as the API renders it. Every field is +// +// server-owned on the way out; requests name the fields they change rather than +// sending this message back. +type FundPolicy struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + // ISO 4217. Set at Create and immutable thereafter. + CurrencyCode *string `json:"currencyCode,omitempty"` + DefaultLimit *SpendLimit `json:"defaultLimit,omitempty"` + OrgCeiling *SpendControls `json:"orgCeiling,omitempty"` + // The root period every amount in the tenant is denominated in. + Period *FundPolicyPeriod `json:"period,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (f FundPolicy) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(f, "", false) +} + +func (f *FundPolicy) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &f, "", false, nil); err != nil { + return err + } + return nil +} + +func (f *FundPolicy) GetCreatedAt() *time.Time { + if f == nil { + return nil + } + return f.CreatedAt +} + +func (f *FundPolicy) GetCurrencyCode() *string { + if f == nil { + return nil + } + return f.CurrencyCode +} + +func (f *FundPolicy) GetDefaultLimit() *SpendLimit { + if f == nil { + return nil + } + return f.DefaultLimit +} + +func (f *FundPolicy) GetOrgCeiling() *SpendControls { + if f == nil { + return nil + } + return f.OrgCeiling +} + +func (f *FundPolicy) GetPeriod() *FundPolicyPeriod { + if f == nil { + return nil + } + return f.Period +} + +func (f *FundPolicy) GetTenantID() *string { + if f == nil { + return nil + } + return f.TenantID +} + +func (f *FundPolicy) GetUpdatedAt() *time.Time { + if f == nil { + return nil + } + return f.UpdatedAt +} diff --git a/pkg/models/shared/fundpolicyhistoryentry.go b/pkg/models/shared/fundpolicyhistoryentry.go new file mode 100644 index 000000000..95bcfb830 --- /dev/null +++ b/pkg/models/shared/fundpolicyhistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyHistoryEntry message. +type FundPolicyHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *FundPolicy `json:"snapshot,omitempty"` +} + +func (f *FundPolicyHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if f == nil { + return nil + } + return f.Metadata +} + +func (f *FundPolicyHistoryEntry) GetSnapshot() *FundPolicy { + if f == nil { + return nil + } + return f.Snapshot +} diff --git a/pkg/models/shared/fundpolicyservicecreaterequest.go b/pkg/models/shared/fundpolicyservicecreaterequest.go new file mode 100644 index 000000000..fc4951513 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicecreaterequest.go @@ -0,0 +1,60 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FundPolicyServiceCreateRequestPeriod - The period field. +type FundPolicyServiceCreateRequestPeriod string + +const ( + FundPolicyServiceCreateRequestPeriodPeriodKindUnspecified FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_UNSPECIFIED" + FundPolicyServiceCreateRequestPeriodPeriodKindDaily FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_DAILY" + FundPolicyServiceCreateRequestPeriodPeriodKindWeekly FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_WEEKLY" + FundPolicyServiceCreateRequestPeriodPeriodKindMonthly FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_MONTHLY" + FundPolicyServiceCreateRequestPeriodPeriodKindQuarterly FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_QUARTERLY" + FundPolicyServiceCreateRequestPeriodPeriodKindYearly FundPolicyServiceCreateRequestPeriod = "PERIOD_KIND_YEARLY" +) + +func (e FundPolicyServiceCreateRequestPeriod) ToPointer() *FundPolicyServiceCreateRequestPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FundPolicyServiceCreateRequestPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// The FundPolicyServiceCreateRequest message. +type FundPolicyServiceCreateRequest struct { + // ISO 4217. Immutable once set. + CurrencyCode *string `json:"currencyCode,omitempty"` + DefaultLimit *SpendLimit `json:"defaultLimit,omitempty"` + // The period field. + Period *FundPolicyServiceCreateRequestPeriod `json:"period,omitempty"` +} + +func (f *FundPolicyServiceCreateRequest) GetCurrencyCode() *string { + if f == nil { + return nil + } + return f.CurrencyCode +} + +func (f *FundPolicyServiceCreateRequest) GetDefaultLimit() *SpendLimit { + if f == nil { + return nil + } + return f.DefaultLimit +} + +func (f *FundPolicyServiceCreateRequest) GetPeriod() *FundPolicyServiceCreateRequestPeriod { + if f == nil { + return nil + } + return f.Period +} diff --git a/pkg/models/shared/fundpolicyservicecreateresponse.go b/pkg/models/shared/fundpolicyservicecreateresponse.go new file mode 100644 index 000000000..f0e9d539c --- /dev/null +++ b/pkg/models/shared/fundpolicyservicecreateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceCreateResponse message. +type FundPolicyServiceCreateResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceCreateResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundpolicyservicedeleterequest.go b/pkg/models/shared/fundpolicyservicedeleterequest.go new file mode 100644 index 000000000..0293da665 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceDeleteRequest message. +type FundPolicyServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/fundpolicyservicedeleteresponse.go b/pkg/models/shared/fundpolicyservicedeleteresponse.go new file mode 100644 index 000000000..1a2bce753 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceDeleteResponse message. +type FundPolicyServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/fundpolicyservicefreezetenantrequest.go b/pkg/models/shared/fundpolicyservicefreezetenantrequest.go new file mode 100644 index 000000000..4f826b96c --- /dev/null +++ b/pkg/models/shared/fundpolicyservicefreezetenantrequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceFreezeTenantRequest message. +type FundPolicyServiceFreezeTenantRequest struct { + // The reason field. + Reason *string `json:"reason,omitempty"` +} + +func (f *FundPolicyServiceFreezeTenantRequest) GetReason() *string { + if f == nil { + return nil + } + return f.Reason +} diff --git a/pkg/models/shared/fundpolicyservicefreezetenantresponse.go b/pkg/models/shared/fundpolicyservicefreezetenantresponse.go new file mode 100644 index 000000000..869cc75a9 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicefreezetenantresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceFreezeTenantResponse message. +type FundPolicyServiceFreezeTenantResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceFreezeTenantResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundpolicyservicegetresponse.go b/pkg/models/shared/fundpolicyservicegetresponse.go new file mode 100644 index 000000000..2b6d9b663 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceGetResponse message. +type FundPolicyServiceGetResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceGetResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundpolicyservicelisthistoryresponse.go b/pkg/models/shared/fundpolicyservicelisthistoryresponse.go new file mode 100644 index 000000000..016bb5abf --- /dev/null +++ b/pkg/models/shared/fundpolicyservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceListHistoryResponse message. +type FundPolicyServiceListHistoryResponse struct { + // The list field. + List []FundPolicyHistoryEntry `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundPolicyServiceListHistoryResponse) GetList() []FundPolicyHistoryEntry { + if f == nil { + return nil + } + return f.List +} + +func (f *FundPolicyServiceListHistoryResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundpolicyservicesetorgceilingrequest.go b/pkg/models/shared/fundpolicyservicesetorgceilingrequest.go new file mode 100644 index 000000000..5e1f01e20 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicesetorgceilingrequest.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// FundPolicyServiceSetOrgCeilingRequestPeriod - Optional period override for the ceiling. Only valid together with limit. +type FundPolicyServiceSetOrgCeilingRequestPeriod string + +const ( + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindUnspecified FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_UNSPECIFIED" + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindDaily FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_DAILY" + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindWeekly FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_WEEKLY" + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindMonthly FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_MONTHLY" + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindQuarterly FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_QUARTERLY" + FundPolicyServiceSetOrgCeilingRequestPeriodPeriodKindYearly FundPolicyServiceSetOrgCeilingRequestPeriod = "PERIOD_KIND_YEARLY" +) + +func (e FundPolicyServiceSetOrgCeilingRequestPeriod) ToPointer() *FundPolicyServiceSetOrgCeilingRequestPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *FundPolicyServiceSetOrgCeilingRequestPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// The FundPolicyServiceSetOrgCeilingRequest message. +type FundPolicyServiceSetOrgCeilingRequest struct { + Limit *SpendLimit `json:"limit,omitempty"` + // Optional period override for the ceiling. Only valid together with limit. + Period *FundPolicyServiceSetOrgCeilingRequestPeriod `json:"period,omitempty"` +} + +func (f *FundPolicyServiceSetOrgCeilingRequest) GetLimit() *SpendLimit { + if f == nil { + return nil + } + return f.Limit +} + +func (f *FundPolicyServiceSetOrgCeilingRequest) GetPeriod() *FundPolicyServiceSetOrgCeilingRequestPeriod { + if f == nil { + return nil + } + return f.Period +} diff --git a/pkg/models/shared/fundpolicyservicesetorgceilingresponse.go b/pkg/models/shared/fundpolicyservicesetorgceilingresponse.go new file mode 100644 index 000000000..d8a709677 --- /dev/null +++ b/pkg/models/shared/fundpolicyservicesetorgceilingresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceSetOrgCeilingResponse message. +type FundPolicyServiceSetOrgCeilingResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceSetOrgCeilingResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.go b/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.go new file mode 100644 index 000000000..caaabd423 --- /dev/null +++ b/pkg/models/shared/fundpolicyserviceunfreezetenantrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceUnfreezeTenantRequest message. +type FundPolicyServiceUnfreezeTenantRequest struct { +} diff --git a/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.go b/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.go new file mode 100644 index 000000000..1b4b2af64 --- /dev/null +++ b/pkg/models/shared/fundpolicyserviceunfreezetenantresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceUnfreezeTenantResponse message. +type FundPolicyServiceUnfreezeTenantResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceUnfreezeTenantResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundpolicyserviceupdaterequest.go b/pkg/models/shared/fundpolicyserviceupdaterequest.go new file mode 100644 index 000000000..45648b768 --- /dev/null +++ b/pkg/models/shared/fundpolicyserviceupdaterequest.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceUpdateRequest message. +type FundPolicyServiceUpdateRequest struct { + Policy *FundPolicy `json:"policy,omitempty"` + UpdateMask *string `json:"updateMask,omitempty"` +} + +func (f *FundPolicyServiceUpdateRequest) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} + +func (f *FundPolicyServiceUpdateRequest) GetUpdateMask() *string { + if f == nil { + return nil + } + return f.UpdateMask +} diff --git a/pkg/models/shared/fundpolicyserviceupdateresponse.go b/pkg/models/shared/fundpolicyserviceupdateresponse.go new file mode 100644 index 000000000..b90067ecd --- /dev/null +++ b/pkg/models/shared/fundpolicyserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundPolicyServiceUpdateResponse message. +type FundPolicyServiceUpdateResponse struct { + Policy *FundPolicy `json:"policy,omitempty"` +} + +func (f *FundPolicyServiceUpdateResponse) GetPolicy() *FundPolicy { + if f == nil { + return nil + } + return f.Policy +} diff --git a/pkg/models/shared/fundrule.go b/pkg/models/shared/fundrule.go new file mode 100644 index 000000000..18939784d --- /dev/null +++ b/pkg/models/shared/fundrule.go @@ -0,0 +1,94 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// FundRule is one group grant as the API renders it. +type FundRule struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + // Admin-facing label, so a rule list reads as policy rather than as ids. + // Bounded on the message rather than only on Create: Update carries a whole + // FundRule, and this is the column the mirror's full-text and btree indexes + // are built on. + DisplayName *string `json:"displayName,omitempty"` + Grant *SpendLimit `json:"grant,omitempty"` + GroupRef *AppEntitlementRef `json:"groupRef,omitempty"` + // Why this cohort is funded. Subject-visible where a grant is explained. + Reason *string `json:"reason,omitempty"` + // The ruleId field. + RuleID *string `json:"ruleId,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (f FundRule) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(f, "", false) +} + +func (f *FundRule) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &f, "", false, nil); err != nil { + return err + } + return nil +} + +func (f *FundRule) GetCreatedAt() *time.Time { + if f == nil { + return nil + } + return f.CreatedAt +} + +func (f *FundRule) GetDisplayName() *string { + if f == nil { + return nil + } + return f.DisplayName +} + +func (f *FundRule) GetGrant() *SpendLimit { + if f == nil { + return nil + } + return f.Grant +} + +func (f *FundRule) GetGroupRef() *AppEntitlementRef { + if f == nil { + return nil + } + return f.GroupRef +} + +func (f *FundRule) GetReason() *string { + if f == nil { + return nil + } + return f.Reason +} + +func (f *FundRule) GetRuleID() *string { + if f == nil { + return nil + } + return f.RuleID +} + +func (f *FundRule) GetTenantID() *string { + if f == nil { + return nil + } + return f.TenantID +} + +func (f *FundRule) GetUpdatedAt() *time.Time { + if f == nil { + return nil + } + return f.UpdatedAt +} diff --git a/pkg/models/shared/fundrulehistoryentry.go b/pkg/models/shared/fundrulehistoryentry.go new file mode 100644 index 000000000..69a23febc --- /dev/null +++ b/pkg/models/shared/fundrulehistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleHistoryEntry message. +type FundRuleHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *FundRule `json:"snapshot,omitempty"` +} + +func (f *FundRuleHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if f == nil { + return nil + } + return f.Metadata +} + +func (f *FundRuleHistoryEntry) GetSnapshot() *FundRule { + if f == nil { + return nil + } + return f.Snapshot +} diff --git a/pkg/models/shared/fundruleservicecreaterequest.go b/pkg/models/shared/fundruleservicecreaterequest.go new file mode 100644 index 000000000..b66c3a8d6 --- /dev/null +++ b/pkg/models/shared/fundruleservicecreaterequest.go @@ -0,0 +1,41 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceCreateRequest message. +type FundRuleServiceCreateRequest struct { + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + Grant *SpendLimit `json:"grant,omitempty"` + GroupRef *AppEntitlementRef `json:"groupRef,omitempty"` + // The reason field. + Reason *string `json:"reason,omitempty"` +} + +func (f *FundRuleServiceCreateRequest) GetDisplayName() *string { + if f == nil { + return nil + } + return f.DisplayName +} + +func (f *FundRuleServiceCreateRequest) GetGrant() *SpendLimit { + if f == nil { + return nil + } + return f.Grant +} + +func (f *FundRuleServiceCreateRequest) GetGroupRef() *AppEntitlementRef { + if f == nil { + return nil + } + return f.GroupRef +} + +func (f *FundRuleServiceCreateRequest) GetReason() *string { + if f == nil { + return nil + } + return f.Reason +} diff --git a/pkg/models/shared/fundruleservicecreateresponse.go b/pkg/models/shared/fundruleservicecreateresponse.go new file mode 100644 index 000000000..7554d7037 --- /dev/null +++ b/pkg/models/shared/fundruleservicecreateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceCreateResponse message. +type FundRuleServiceCreateResponse struct { + Rule *FundRule `json:"rule,omitempty"` +} + +func (f *FundRuleServiceCreateResponse) GetRule() *FundRule { + if f == nil { + return nil + } + return f.Rule +} diff --git a/pkg/models/shared/fundruleservicedeleterequest.go b/pkg/models/shared/fundruleservicedeleterequest.go new file mode 100644 index 000000000..1d8bd65c3 --- /dev/null +++ b/pkg/models/shared/fundruleservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceDeleteRequest message. +type FundRuleServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/fundruleservicedeleteresponse.go b/pkg/models/shared/fundruleservicedeleteresponse.go new file mode 100644 index 000000000..a1a6bc182 --- /dev/null +++ b/pkg/models/shared/fundruleservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceDeleteResponse message. +type FundRuleServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/fundruleservicegetresponse.go b/pkg/models/shared/fundruleservicegetresponse.go new file mode 100644 index 000000000..791607209 --- /dev/null +++ b/pkg/models/shared/fundruleservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceGetResponse message. +type FundRuleServiceGetResponse struct { + Rule *FundRule `json:"rule,omitempty"` +} + +func (f *FundRuleServiceGetResponse) GetRule() *FundRule { + if f == nil { + return nil + } + return f.Rule +} diff --git a/pkg/models/shared/fundruleservicelisthistoryresponse.go b/pkg/models/shared/fundruleservicelisthistoryresponse.go new file mode 100644 index 000000000..e7f8f3b06 --- /dev/null +++ b/pkg/models/shared/fundruleservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceListHistoryResponse message. +type FundRuleServiceListHistoryResponse struct { + // The list field. + List []FundRuleHistoryEntry `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundRuleServiceListHistoryResponse) GetList() []FundRuleHistoryEntry { + if f == nil { + return nil + } + return f.List +} + +func (f *FundRuleServiceListHistoryResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundruleservicelistresponse.go b/pkg/models/shared/fundruleservicelistresponse.go new file mode 100644 index 000000000..a3454249d --- /dev/null +++ b/pkg/models/shared/fundruleservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceListResponse message. +type FundRuleServiceListResponse struct { + // The list field. + List []FundRule `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundRuleServiceListResponse) GetList() []FundRule { + if f == nil { + return nil + } + return f.List +} + +func (f *FundRuleServiceListResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundruleservicesearchrequest.go b/pkg/models/shared/fundruleservicesearchrequest.go new file mode 100644 index 000000000..5d3b68068 --- /dev/null +++ b/pkg/models/shared/fundruleservicesearchrequest.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceSearchRequest message. +type FundRuleServiceSearchRequest struct { + // The pageSize field. + PageSize *int `json:"pageSize,omitempty"` + // The pageToken field. + PageToken *string `json:"pageToken,omitempty"` + // Case-insensitive search over the rule display name; empty returns all. + Query *string `json:"query,omitempty"` +} + +func (f *FundRuleServiceSearchRequest) GetPageSize() *int { + if f == nil { + return nil + } + return f.PageSize +} + +func (f *FundRuleServiceSearchRequest) GetPageToken() *string { + if f == nil { + return nil + } + return f.PageToken +} + +func (f *FundRuleServiceSearchRequest) GetQuery() *string { + if f == nil { + return nil + } + return f.Query +} diff --git a/pkg/models/shared/fundruleservicesearchresponse.go b/pkg/models/shared/fundruleservicesearchresponse.go new file mode 100644 index 000000000..cfb0c0052 --- /dev/null +++ b/pkg/models/shared/fundruleservicesearchresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceSearchResponse message. +type FundRuleServiceSearchResponse struct { + // The list field. + List []FundRule `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (f *FundRuleServiceSearchResponse) GetList() []FundRule { + if f == nil { + return nil + } + return f.List +} + +func (f *FundRuleServiceSearchResponse) GetNextPageToken() *string { + if f == nil { + return nil + } + return f.NextPageToken +} diff --git a/pkg/models/shared/fundruleserviceupdaterequest.go b/pkg/models/shared/fundruleserviceupdaterequest.go new file mode 100644 index 000000000..8b4956caa --- /dev/null +++ b/pkg/models/shared/fundruleserviceupdaterequest.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceUpdateRequest message. +type FundRuleServiceUpdateRequest struct { + Rule *FundRule `json:"rule,omitempty"` + UpdateMask *string `json:"updateMask,omitempty"` +} + +func (f *FundRuleServiceUpdateRequest) GetRule() *FundRule { + if f == nil { + return nil + } + return f.Rule +} + +func (f *FundRuleServiceUpdateRequest) GetUpdateMask() *string { + if f == nil { + return nil + } + return f.UpdateMask +} diff --git a/pkg/models/shared/fundruleserviceupdateresponse.go b/pkg/models/shared/fundruleserviceupdateresponse.go new file mode 100644 index 000000000..b0a658ea0 --- /dev/null +++ b/pkg/models/shared/fundruleserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The FundRuleServiceUpdateResponse message. +type FundRuleServiceUpdateResponse struct { + Rule *FundRule `json:"rule,omitempty"` +} + +func (f *FundRuleServiceUpdateResponse) GetRule() *FundRule { + if f == nil { + return nil + } + return f.Rule +} diff --git a/pkg/models/shared/gatewaykey.go b/pkg/models/shared/gatewaykey.go new file mode 100644 index 000000000..78e82194e --- /dev/null +++ b/pkg/models/shared/gatewaykey.go @@ -0,0 +1,74 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// The GatewayKey message. +type GatewayKey struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The id field. + ID *string `json:"id,omitempty"` + // The keyPrefix field. + KeyPrefix *string `json:"keyPrefix,omitempty"` + RevokedAt *time.Time `json:"revokedAt,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (g GatewayKey) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(g, "", false) +} + +func (g *GatewayKey) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &g, "", false, nil); err != nil { + return err + } + return nil +} + +func (g *GatewayKey) GetCreatedAt() *time.Time { + if g == nil { + return nil + } + return g.CreatedAt +} + +func (g *GatewayKey) GetDisplayName() *string { + if g == nil { + return nil + } + return g.DisplayName +} + +func (g *GatewayKey) GetID() *string { + if g == nil { + return nil + } + return g.ID +} + +func (g *GatewayKey) GetKeyPrefix() *string { + if g == nil { + return nil + } + return g.KeyPrefix +} + +func (g *GatewayKey) GetRevokedAt() *time.Time { + if g == nil { + return nil + } + return g.RevokedAt +} + +func (g *GatewayKey) GetUpdatedAt() *time.Time { + if g == nil { + return nil + } + return g.UpdatedAt +} diff --git a/pkg/models/shared/getappmanagedstatebindingresponse.go b/pkg/models/shared/getappmanagedstatebindingresponse.go new file mode 100644 index 000000000..2c44aca42 --- /dev/null +++ b/pkg/models/shared/getappmanagedstatebindingresponse.go @@ -0,0 +1,60 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// GetAppManagedStateBindingResponseExpanded - Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. +type GetAppManagedStateBindingResponseExpanded struct { + // The type of the serialized message. + AtType *string `json:"@type,omitempty"` + AdditionalProperties map[string]any `additionalProperties:"true" json:"-"` +} + +func (g GetAppManagedStateBindingResponseExpanded) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(g, "", false) +} + +func (g *GetAppManagedStateBindingResponseExpanded) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &g, "", false, nil); err != nil { + return err + } + return nil +} + +func (g *GetAppManagedStateBindingResponseExpanded) GetAtType() *string { + if g == nil { + return nil + } + return g.AtType +} + +func (g *GetAppManagedStateBindingResponseExpanded) GetAdditionalProperties() map[string]any { + if g == nil { + return nil + } + return g.AdditionalProperties +} + +// GetAppManagedStateBindingResponse contains the managed state of a discovered application. +type GetAppManagedStateBindingResponse struct { + AppManagementState *AppManagedStateBindingView `json:"appManagementState,omitempty"` + // Related objects requested through expand_mask. REST Get requests do not support expansions; REST Promote requests do. + Expanded []GetAppManagedStateBindingResponseExpanded `json:"expanded,omitempty"` +} + +func (g *GetAppManagedStateBindingResponse) GetAppManagementState() *AppManagedStateBindingView { + if g == nil { + return nil + } + return g.AppManagementState +} + +func (g *GetAppManagedStateBindingResponse) GetExpanded() []GetAppManagedStateBindingResponseExpanded { + if g == nil { + return nil + } + return g.Expanded +} diff --git a/pkg/models/shared/getcustomanalysisresultresponse.go b/pkg/models/shared/getcustomanalysisresultresponse.go index 716bf3095..ff9e2daa9 100644 --- a/pkg/models/shared/getcustomanalysisresultresponse.go +++ b/pkg/models/shared/getcustomanalysisresultresponse.go @@ -35,6 +35,8 @@ type GetCustomAnalysisResultResponse struct { Clusters []EntitlementCluster `json:"clusters,omitempty"` // The cohortSize field. CohortSize *int `json:"cohortSize,omitempty"` + // Exact holder counts at each distinct inclusive entitlement coverage cutoff. + CutoffImpactPoints []EntitlementCutoffImpactPoint `json:"cutoffImpactPoints,omitempty"` // Entitlement coverage results. Entitlements []CohortEntitlement `json:"entitlements,omitempty"` // The errorMessage field. @@ -70,6 +72,13 @@ func (g *GetCustomAnalysisResultResponse) GetCohortSize() *int { return g.CohortSize } +func (g *GetCustomAnalysisResultResponse) GetCutoffImpactPoints() []EntitlementCutoffImpactPoint { + if g == nil { + return nil + } + return g.CutoffImpactPoints +} + func (g *GetCustomAnalysisResultResponse) GetEntitlements() []CohortEntitlement { if g == nil { return nil diff --git a/pkg/models/shared/getprovidercredentialresponse.go b/pkg/models/shared/getprovidercredentialresponse.go new file mode 100644 index 000000000..aba3f11db --- /dev/null +++ b/pkg/models/shared/getprovidercredentialresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The GetProviderCredentialResponse message. +type GetProviderCredentialResponse struct { + Credential *ProviderCredential `json:"credential,omitempty"` +} + +func (g *GetProviderCredentialResponse) GetCredential() *ProviderCredential { + if g == nil { + return nil + } + return g.Credential +} diff --git a/pkg/models/shared/grantfilter.go b/pkg/models/shared/grantfilter.go index e58edef3a..d9c19107c 100644 --- a/pkg/models/shared/grantfilter.go +++ b/pkg/models/shared/grantfilter.go @@ -51,21 +51,21 @@ func (e *GrantJustificationType) IsExact() bool { return false } -// GrantSourceFilter - The grantSourceFilter field. -type GrantSourceFilter string +// GrantFilterGrantSourceFilter - The grantSourceFilter field. +type GrantFilterGrantSourceFilter string const ( - GrantSourceFilterGrantSourceFilterUnspecified GrantSourceFilter = "GRANT_SOURCE_FILTER_UNSPECIFIED" - GrantSourceFilterGrantSourceFilterDirect GrantSourceFilter = "GRANT_SOURCE_FILTER_DIRECT" - GrantSourceFilterGrantSourceFilterInherited GrantSourceFilter = "GRANT_SOURCE_FILTER_INHERITED" + GrantFilterGrantSourceFilterGrantSourceFilterUnspecified GrantFilterGrantSourceFilter = "GRANT_SOURCE_FILTER_UNSPECIFIED" + GrantFilterGrantSourceFilterGrantSourceFilterDirect GrantFilterGrantSourceFilter = "GRANT_SOURCE_FILTER_DIRECT" + GrantFilterGrantSourceFilterGrantSourceFilterInherited GrantFilterGrantSourceFilter = "GRANT_SOURCE_FILTER_INHERITED" ) -func (e GrantSourceFilter) ToPointer() *GrantSourceFilter { +func (e GrantFilterGrantSourceFilter) ToPointer() *GrantFilterGrantSourceFilter { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *GrantSourceFilter) IsExact() bool { +func (e *GrantFilterGrantSourceFilter) IsExact() bool { if e != nil { switch *e { case "GRANT_SOURCE_FILTER_UNSPECIFIED", "GRANT_SOURCE_FILTER_DIRECT", "GRANT_SOURCE_FILTER_INHERITED": @@ -82,7 +82,7 @@ type GrantFilter struct { // The grantJustificationType field. GrantJustificationType *GrantJustificationType `json:"grantJustificationType,omitempty"` // The grantSourceFilter field. - GrantSourceFilter *GrantSourceFilter `json:"grantSourceFilter,omitempty"` + GrantSourceFilter *GrantFilterGrantSourceFilter `json:"grantSourceFilter,omitempty"` } func (g *GrantFilter) GetGrantFilterType() *GrantFilterType { @@ -99,7 +99,7 @@ func (g *GrantFilter) GetGrantJustificationType() *GrantJustificationType { return g.GrantJustificationType } -func (g *GrantFilter) GetGrantSourceFilter() *GrantSourceFilter { +func (g *GrantFilter) GetGrantSourceFilter() *GrantFilterGrantSourceFilter { if g == nil { return nil } diff --git a/pkg/models/shared/hook.go b/pkg/models/shared/hook.go index bbd14cde3..300ab716b 100644 --- a/pkg/models/shared/hook.go +++ b/pkg/models/shared/hook.go @@ -14,6 +14,7 @@ const ( EventHookEventTypeUnspecified Event = "HOOK_EVENT_TYPE_UNSPECIFIED" EventHookEventTypePreToolUse Event = "HOOK_EVENT_TYPE_PRE_TOOL_USE" EventHookEventTypePostToolUse Event = "HOOK_EVENT_TYPE_POST_TOOL_USE" + EventHookEventTypePreOutput Event = "HOOK_EVENT_TYPE_PRE_OUTPUT" ) func (e Event) ToPointer() *Event { @@ -24,7 +25,7 @@ func (e Event) ToPointer() *Event { func (e *Event) IsExact() bool { if e != nil { switch *e { - case "HOOK_EVENT_TYPE_UNSPECIFIED", "HOOK_EVENT_TYPE_PRE_TOOL_USE", "HOOK_EVENT_TYPE_POST_TOOL_USE": + case "HOOK_EVENT_TYPE_UNSPECIFIED", "HOOK_EVENT_TYPE_PRE_TOOL_USE", "HOOK_EVENT_TYPE_POST_TOOL_USE", "HOOK_EVENT_TYPE_PRE_OUTPUT": return true } } @@ -36,6 +37,7 @@ func (e *Event) IsExact() bool { // This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: // - function // - builtinPattern +// - jsonPatch type Hook struct { BuiltinPattern *BuiltInPattern `json:"builtinPattern,omitempty"` CreatedAt *time.Time `json:"createdAt,omitempty"` @@ -50,7 +52,13 @@ type Hook struct { Filter *HookFilter `json:"filter,omitempty"` Function *HookFunctionRef `json:"function,omitempty"` // The id field. - ID *string `json:"id,omitempty"` + ID *string `json:"id,omitempty"` + JSONPatch *JSONPatchConfig `json:"jsonPatch,omitempty"` + // managed_by_guardrails marks a hook as selectable in a guardrail rule's + // curated pre_hook_ids/post_hook_ids. A hook left false (the default, + // including every pre-existing hook) always runs regardless of guardrail + // state; a hook set true only runs when a matched rule selects it. + ManagedByGuardrails *bool `json:"managedByGuardrails,omitempty"` // The priority field. Priority *int `json:"priority,omitempty"` UpdatedAt *time.Time `json:"updatedAt,omitempty"` @@ -130,6 +138,20 @@ func (h *Hook) GetID() *string { return h.ID } +func (h *Hook) GetJSONPatch() *JSONPatchConfig { + if h == nil { + return nil + } + return h.JSONPatch +} + +func (h *Hook) GetManagedByGuardrails() *bool { + if h == nil { + return nil + } + return h.ManagedByGuardrails +} + func (h *Hook) GetPriority() *int { if h == nil { return nil @@ -149,6 +171,7 @@ func (h *Hook) GetUpdatedAt() *time.Time { // This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: // - function // - builtinPattern +// - jsonPatch type HookInput struct { BuiltinPattern *BuiltInPattern `json:"builtinPattern,omitempty"` // The description field. @@ -162,7 +185,13 @@ type HookInput struct { Filter *HookFilter `json:"filter,omitempty"` Function *HookFunctionRef `json:"function,omitempty"` // The id field. - ID *string `json:"id,omitempty"` + ID *string `json:"id,omitempty"` + JSONPatch *JSONPatchConfig `json:"jsonPatch,omitempty"` + // managed_by_guardrails marks a hook as selectable in a guardrail rule's + // curated pre_hook_ids/post_hook_ids. A hook left false (the default, + // including every pre-existing hook) always runs regardless of guardrail + // state; a hook set true only runs when a matched rule selects it. + ManagedByGuardrails *bool `json:"managedByGuardrails,omitempty"` // The priority field. Priority *int `json:"priority,omitempty"` } @@ -223,6 +252,20 @@ func (h *HookInput) GetID() *string { return h.ID } +func (h *HookInput) GetJSONPatch() *JSONPatchConfig { + if h == nil { + return nil + } + return h.JSONPatch +} + +func (h *HookInput) GetManagedByGuardrails() *bool { + if h == nil { + return nil + } + return h.ManagedByGuardrails +} + func (h *HookInput) GetPriority() *int { if h == nil { return nil diff --git a/pkg/models/shared/hookfilter.go b/pkg/models/shared/hookfilter.go index 73440df39..802edd64f 100644 --- a/pkg/models/shared/hookfilter.go +++ b/pkg/models/shared/hookfilter.go @@ -2,11 +2,22 @@ package shared -// HookFilter determines which tool calls a hook applies to. +// HookFilter determines which calls (or, for HOOK_EVENT_TYPE_PRE_OUTPUT, +// +// which outgoing response chunks) a hook applies to. type HookFilter struct { - // CEL expression evaluated against tool call context. - // Available variable: ctx.tool_name (string). - // Must evaluate to bool. Empty matches all tools. + // CEL expression evaluated against event context. Must evaluate to bool, + // empty = matches everything for the event type. + // HOOK_EVENT_TYPE_PRE_TOOL_USE / POST_TOOL_USE: ctx.tool_name (string), + // and for a call originating from a chat channel ctx.surface (string, + // "slack", "web", or "teams"), ctx.channel_id (string, the channel the + // message arrived on — only set for "slack"/"teams"; "web" channel refs are + // per-conversation and not admin-predictable), and ctx.workspace_id + // (string, the Slack/Teams workspace, when known). All three are absent + // otherwise, so guard them with has(ctx.surface) / has(ctx.channel_id) / + // has(ctx.workspace_id). + // HOOK_EVENT_TYPE_PRE_OUTPUT: ctx.untrusted_class (string), ctx.surface + // (string, "slack" or "web"). CelExpression *string `json:"celExpression,omitempty"` } diff --git a/pkg/models/shared/hooksservicecreaterequest.go b/pkg/models/shared/hooksservicecreaterequest.go index 4b1fe2f45..10bc658a8 100644 --- a/pkg/models/shared/hooksservicecreaterequest.go +++ b/pkg/models/shared/hooksservicecreaterequest.go @@ -9,6 +9,7 @@ const ( HooksServiceCreateRequestEventHookEventTypeUnspecified HooksServiceCreateRequestEvent = "HOOK_EVENT_TYPE_UNSPECIFIED" HooksServiceCreateRequestEventHookEventTypePreToolUse HooksServiceCreateRequestEvent = "HOOK_EVENT_TYPE_PRE_TOOL_USE" HooksServiceCreateRequestEventHookEventTypePostToolUse HooksServiceCreateRequestEvent = "HOOK_EVENT_TYPE_POST_TOOL_USE" + HooksServiceCreateRequestEventHookEventTypePreOutput HooksServiceCreateRequestEvent = "HOOK_EVENT_TYPE_PRE_OUTPUT" ) func (e HooksServiceCreateRequestEvent) ToPointer() *HooksServiceCreateRequestEvent { @@ -19,7 +20,7 @@ func (e HooksServiceCreateRequestEvent) ToPointer() *HooksServiceCreateRequestEv func (e *HooksServiceCreateRequestEvent) IsExact() bool { if e != nil { switch *e { - case "HOOK_EVENT_TYPE_UNSPECIFIED", "HOOK_EVENT_TYPE_PRE_TOOL_USE", "HOOK_EVENT_TYPE_POST_TOOL_USE": + case "HOOK_EVENT_TYPE_UNSPECIFIED", "HOOK_EVENT_TYPE_PRE_TOOL_USE", "HOOK_EVENT_TYPE_POST_TOOL_USE", "HOOK_EVENT_TYPE_PRE_OUTPUT": return true } } @@ -31,6 +32,7 @@ func (e *HooksServiceCreateRequestEvent) IsExact() bool { // This message contains a oneof named hook_type. Only a single field of the following list may be set at a time: // - function // - builtinPattern +// - jsonPatch type HooksServiceCreateRequest struct { BuiltinPattern *BuiltInPattern `json:"builtinPattern,omitempty"` // The description field. @@ -40,9 +42,12 @@ type HooksServiceCreateRequest struct { // The enabled field. Enabled *bool `json:"enabled,omitempty"` // The event field. - Event *HooksServiceCreateRequestEvent `json:"event,omitempty"` - Filter *HookFilter `json:"filter,omitempty"` - Function *HookFunctionRef `json:"function,omitempty"` + Event *HooksServiceCreateRequestEvent `json:"event,omitempty"` + Filter *HookFilter `json:"filter,omitempty"` + Function *HookFunctionRef `json:"function,omitempty"` + JSONPatch *JSONPatchConfig `json:"jsonPatch,omitempty"` + // The managedByGuardrails field. + ManagedByGuardrails *bool `json:"managedByGuardrails,omitempty"` // The priority field. Priority *int `json:"priority,omitempty"` } @@ -96,6 +101,20 @@ func (h *HooksServiceCreateRequest) GetFunction() *HookFunctionRef { return h.Function } +func (h *HooksServiceCreateRequest) GetJSONPatch() *JSONPatchConfig { + if h == nil { + return nil + } + return h.JSONPatch +} + +func (h *HooksServiceCreateRequest) GetManagedByGuardrails() *bool { + if h == nil { + return nil + } + return h.ManagedByGuardrails +} + func (h *HooksServiceCreateRequest) GetPriority() *int { if h == nil { return nil diff --git a/pkg/models/shared/introspectresponse.go b/pkg/models/shared/introspectresponse.go index a12d54205..00e705194 100644 --- a/pkg/models/shared/introspectresponse.go +++ b/pkg/models/shared/introspectresponse.go @@ -2,6 +2,28 @@ package shared +type DisabledModules string + +const ( + DisabledModulesModuleIDUnspecified DisabledModules = "MODULE_ID_UNSPECIFIED" + DisabledModulesModuleIDSecretSharing DisabledModules = "MODULE_ID_SECRET_SHARING" +) + +func (e DisabledModules) ToPointer() *DisabledModules { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DisabledModules) IsExact() bool { + if e != nil { + switch *e { + case "MODULE_ID_UNSPECIFIED", "MODULE_ID_SECRET_SHARING": + return true + } + } + return false +} + // IntrospectResponse contains information about the current user who is authenticated. type IntrospectResponse struct { // The OAuth client_id of the device client registered for this token. Present @@ -9,6 +31,11 @@ type IntrospectResponse struct { // once and presents it on the subsequent token exchange. Empty for all other // tokens. DeviceClientID *string `json:"deviceClientId,omitempty"` + // The modules turned off for the tenant the logged in user belongs to. Absent + // from this list means enabled: every module is on by default. Clients MUST + // treat an unrecognized value as "a module this client does not know about is + // disabled". + DisabledModules []DisabledModules `json:"disabledModules,omitempty"` // The list of feature flags enabled for the tenant the logged in user belongs to. Features []string `json:"features,omitempty"` // The list of permissions that the current logged in user has. @@ -30,6 +57,13 @@ func (i *IntrospectResponse) GetDeviceClientID() *string { return i.DeviceClientID } +func (i *IntrospectResponse) GetDisabledModules() []DisabledModules { + if i == nil { + return nil + } + return i.DisabledModules +} + func (i *IntrospectResponse) GetFeatures() []string { if i == nil { return nil diff --git a/pkg/models/shared/invokefunctiondispatcher.go b/pkg/models/shared/invokefunctiondispatcher.go new file mode 100644 index 000000000..1c1e5e283 --- /dev/null +++ b/pkg/models/shared/invokefunctiondispatcher.go @@ -0,0 +1,35 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// InvokeFunctionDispatcher runs a published C1 function by id. +type InvokeFunctionDispatcher struct { + // Arguments passed to the function, keyed by arg name (v0: verbatim values; + // CEL evaluation is a later phase). + Args map[string]string `json:"args,omitempty"` + // Optional pinned function commit; empty floats to the published commit. + FunctionCommitID *string `json:"functionCommitId,omitempty"` + // ID of the published function to invoke. + FunctionID *string `json:"functionId,omitempty"` +} + +func (i *InvokeFunctionDispatcher) GetArgs() map[string]string { + if i == nil { + return nil + } + return i.Args +} + +func (i *InvokeFunctionDispatcher) GetFunctionCommitID() *string { + if i == nil { + return nil + } + return i.FunctionCommitID +} + +func (i *InvokeFunctionDispatcher) GetFunctionID() *string { + if i == nil { + return nil + } + return i.FunctionID +} diff --git a/pkg/models/shared/jsonpatchconfig.go b/pkg/models/shared/jsonpatchconfig.go new file mode 100644 index 000000000..2ec776102 --- /dev/null +++ b/pkg/models/shared/jsonpatchconfig.go @@ -0,0 +1,37 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// JSONPatchConfig adds, overwrites, or removes fields on a tool call's JSON +// +// input, with no function invocation. Only valid on +// HOOK_EVENT_TYPE_PRE_TOOL_USE. cel_expression is evaluated against +// ctx/input/caller and must produce a map; static_overlay is a fixed map. +// Either result is shallow-merged onto the input under RFC 7396 merge patch +// semantics: a key overwrites or adds that key, a null value removes it, and a +// nested object replaces rather than merging into the existing one. +// +// This message contains a oneof named source. Only a single field of the following list may be set at a time: +// - celExpression +// - staticOverlay +type JSONPatchConfig struct { + // The celExpression field. + // This field is part of the `source` oneof. + // See the documentation for `c1.api.hooks.v1.JSONPatchConfig` for more details. + CelExpression *string `json:"celExpression,omitempty"` + StaticOverlay map[string]any `json:"staticOverlay,omitempty"` +} + +func (j *JSONPatchConfig) GetCelExpression() *string { + if j == nil { + return nil + } + return j.CelExpression +} + +func (j *JSONPatchConfig) GetStaticOverlay() map[string]any { + if j == nil { + return nil + } + return j.StaticOverlay +} diff --git a/pkg/models/shared/linkfilterconfig.go b/pkg/models/shared/linkfilterconfig.go new file mode 100644 index 000000000..65073ae34 --- /dev/null +++ b/pkg/models/shared/linkfilterconfig.go @@ -0,0 +1,61 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// LinkFilterConfigAction - Action taken on a disallowed link. Unspecified = REDACT. +type LinkFilterConfigAction string + +const ( + LinkFilterConfigActionLinkFilterActionUnspecified LinkFilterConfigAction = "LINK_FILTER_ACTION_UNSPECIFIED" + LinkFilterConfigActionLinkFilterActionRedact LinkFilterConfigAction = "LINK_FILTER_ACTION_REDACT" + LinkFilterConfigActionLinkFilterActionAnnotate LinkFilterConfigAction = "LINK_FILTER_ACTION_ANNOTATE" +) + +func (e LinkFilterConfigAction) ToPointer() *LinkFilterConfigAction { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *LinkFilterConfigAction) IsExact() bool { + if e != nil { + switch *e { + case "LINK_FILTER_ACTION_UNSPECIFIED", "LINK_FILTER_ACTION_REDACT", "LINK_FILTER_ACTION_ANNOTATE": + return true + } + } + return false +} + +// LinkFilterConfig strips or annotates URLs and markdown images in tool output +// +// whose host is not in allowed_hosts. +type LinkFilterConfig struct { + // Action taken on a disallowed link. Unspecified = REDACT. + Action *LinkFilterConfigAction `json:"action,omitempty"` + // Hosts that are permitted. Empty = every host is disallowed. Matched + // case-insensitively; a leading "." allows subdomains. + AllowedHosts []string `json:"allowedHosts,omitempty"` + // When true, markdown image links to disallowed hosts are also acted on. + BlockImages *bool `json:"blockImages,omitempty"` +} + +func (l *LinkFilterConfig) GetAction() *LinkFilterConfigAction { + if l == nil { + return nil + } + return l.Action +} + +func (l *LinkFilterConfig) GetAllowedHosts() []string { + if l == nil { + return nil + } + return l.AllowedHosts +} + +func (l *LinkFilterConfig) GetBlockImages() *bool { + if l == nil { + return nil + } + return l.BlockImages +} diff --git a/pkg/models/shared/listappmanagedstatebindingsresponse.go b/pkg/models/shared/listappmanagedstatebindingsresponse.go new file mode 100644 index 000000000..3b3119901 --- /dev/null +++ b/pkg/models/shared/listappmanagedstatebindingsresponse.go @@ -0,0 +1,70 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// ListAppManagedStateBindingsResponseExpanded - Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. +type ListAppManagedStateBindingsResponseExpanded struct { + // The type of the serialized message. + AtType *string `json:"@type,omitempty"` + AdditionalProperties map[string]any `additionalProperties:"true" json:"-"` +} + +func (l ListAppManagedStateBindingsResponseExpanded) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(l, "", false) +} + +func (l *ListAppManagedStateBindingsResponseExpanded) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &l, "", false, nil); err != nil { + return err + } + return nil +} + +func (l *ListAppManagedStateBindingsResponseExpanded) GetAtType() *string { + if l == nil { + return nil + } + return l.AtType +} + +func (l *ListAppManagedStateBindingsResponseExpanded) GetAdditionalProperties() map[string]any { + if l == nil { + return nil + } + return l.AdditionalProperties +} + +// ListAppManagedStateBindingsResponse contains one page of discovered application managed states. +type ListAppManagedStateBindingsResponse struct { + // Related objects included for gRPC requests that set expand_mask. + Expanded []ListAppManagedStateBindingsResponseExpanded `json:"expanded,omitempty"` + // Managed states of the discovered applications. + List []AppManagedStateBindingView `json:"list,omitempty"` + // Pagination token for the next page. Empty when there are no more results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (l *ListAppManagedStateBindingsResponse) GetExpanded() []ListAppManagedStateBindingsResponseExpanded { + if l == nil { + return nil + } + return l.Expanded +} + +func (l *ListAppManagedStateBindingsResponse) GetList() []AppManagedStateBindingView { + if l == nil { + return nil + } + return l.List +} + +func (l *ListAppManagedStateBindingsResponse) GetNextPageToken() *string { + if l == nil { + return nil + } + return l.NextPageToken +} diff --git a/pkg/models/shared/listfindingsettingsresponse.go b/pkg/models/shared/listfindingsettingsresponse.go new file mode 100644 index 000000000..f379d0c5a --- /dev/null +++ b/pkg/models/shared/listfindingsettingsresponse.go @@ -0,0 +1,30 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ListFindingSettingsResponse message. +type ListFindingSettingsResponse struct { + // True once the tenant has explicitly saved their finding-type settings at + // least once, regardless of whether any value differs from default. False + // means the tenant has never saved, so every entry in `list` is the + // shipped default, unconfirmed by the tenant. + Configured *bool `json:"configured,omitempty"` + // One entry per configurable finding type, in FindingType declaration order. + // Custom findings are excluded: they arrive over CreateFinding rather than + // from a detector, so there is nothing to switch off. + List []FindingTypeSetting `json:"list,omitempty"` +} + +func (l *ListFindingSettingsResponse) GetConfigured() *bool { + if l == nil { + return nil + } + return l.Configured +} + +func (l *ListFindingSettingsResponse) GetList() []FindingTypeSetting { + if l == nil { + return nil + } + return l.List +} diff --git a/pkg/models/shared/listgatewaykeysresponse.go b/pkg/models/shared/listgatewaykeysresponse.go new file mode 100644 index 000000000..3e3e430a8 --- /dev/null +++ b/pkg/models/shared/listgatewaykeysresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ListGatewayKeysResponse message. +type ListGatewayKeysResponse struct { + // The list field. + List []GatewayKey `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (l *ListGatewayKeysResponse) GetList() []GatewayKey { + if l == nil { + return nil + } + return l.List +} + +func (l *ListGatewayKeysResponse) GetNextPageToken() *string { + if l == nil { + return nil + } + return l.NextPageToken +} diff --git a/pkg/models/shared/mcpaccessprofile.go b/pkg/models/shared/mcpaccessprofile.go index a33923e07..f2c576124 100644 --- a/pkg/models/shared/mcpaccessprofile.go +++ b/pkg/models/shared/mcpaccessprofile.go @@ -13,6 +13,11 @@ type MCPAccessProfile struct { AppEntitlementID *string `json:"appEntitlementId,omitempty"` // App identifier (app that owns the connector). AppID *string `json:"appId,omitempty"` + // Display name of the connector this toolset belongs to. Computed read-only; + // populated on every read. The + // auto-maintained default toolsets share a display name across connectors, so + // this is what tells two of them apart. + ConnectorDisplayName *string `json:"connectorDisplayName,omitempty"` // Connector identifier. ConnectorID *string `json:"connectorId,omitempty"` CreatedAt *time.Time `json:"createdAt,omitempty"` @@ -23,6 +28,9 @@ type MCPAccessProfile struct { DisplayName *string `json:"displayName,omitempty"` // Unique identifier for this access profile. ID *string `json:"id,omitempty"` + // Whether this toolset's backing entitlement is exposed in at least one + // request catalog (i.e. can be requested). Computed read-only; populated on List. + Requestable *bool `json:"requestable,omitempty"` // The number of tools currently bound to this profile. ToolCount *int `json:"toolCount,omitempty"` UpdatedAt *time.Time `json:"updatedAt,omitempty"` @@ -53,6 +61,13 @@ func (m *MCPAccessProfile) GetAppID() *string { return m.AppID } +func (m *MCPAccessProfile) GetConnectorDisplayName() *string { + if m == nil { + return nil + } + return m.ConnectorDisplayName +} + func (m *MCPAccessProfile) GetConnectorID() *string { if m == nil { return nil @@ -95,6 +110,13 @@ func (m *MCPAccessProfile) GetID() *string { return m.ID } +func (m *MCPAccessProfile) GetRequestable() *bool { + if m == nil { + return nil + } + return m.Requestable +} + func (m *MCPAccessProfile) GetToolCount() *int { if m == nil { return nil diff --git a/pkg/models/shared/mcpaccessprofileinput.go b/pkg/models/shared/mcpaccessprofileinput.go new file mode 100644 index 000000000..7bb0770c2 --- /dev/null +++ b/pkg/models/shared/mcpaccessprofileinput.go @@ -0,0 +1,110 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// MCPAccessProfileInput - MCPAccessProfile represents an admin-curated grouping of MCP tools. +type MCPAccessProfileInput struct { + // The ID of the AppEntitlement created for this profile. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // App identifier (app that owns the connector). + AppID *string `json:"appId,omitempty"` + // Connector identifier. + ConnectorID *string `json:"connectorId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // Description of what access this profile grants. + Description *string `json:"description,omitempty"` + // Display name for the profile. + DisplayName *string `json:"displayName,omitempty"` + // Unique identifier for this access profile. + ID *string `json:"id,omitempty"` + // The number of tools currently bound to this profile. + ToolCount *int `json:"toolCount,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (m MCPAccessProfileInput) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(m, "", false) +} + +func (m *MCPAccessProfileInput) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &m, "", false, nil); err != nil { + return err + } + return nil +} + +func (m *MCPAccessProfileInput) GetAppEntitlementID() *string { + if m == nil { + return nil + } + return m.AppEntitlementID +} + +func (m *MCPAccessProfileInput) GetAppID() *string { + if m == nil { + return nil + } + return m.AppID +} + +func (m *MCPAccessProfileInput) GetConnectorID() *string { + if m == nil { + return nil + } + return m.ConnectorID +} + +func (m *MCPAccessProfileInput) GetCreatedAt() *time.Time { + if m == nil { + return nil + } + return m.CreatedAt +} + +func (m *MCPAccessProfileInput) GetDeletedAt() *time.Time { + if m == nil { + return nil + } + return m.DeletedAt +} + +func (m *MCPAccessProfileInput) GetDescription() *string { + if m == nil { + return nil + } + return m.Description +} + +func (m *MCPAccessProfileInput) GetDisplayName() *string { + if m == nil { + return nil + } + return m.DisplayName +} + +func (m *MCPAccessProfileInput) GetID() *string { + if m == nil { + return nil + } + return m.ID +} + +func (m *MCPAccessProfileInput) GetToolCount() *int { + if m == nil { + return nil + } + return m.ToolCount +} + +func (m *MCPAccessProfileInput) GetUpdatedAt() *time.Time { + if m == nil { + return nil + } + return m.UpdatedAt +} diff --git a/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.go b/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.go new file mode 100644 index 000000000..8bbf52ff7 --- /dev/null +++ b/pkg/models/shared/mcpaccessprofileservicesearchaccessprofilesresponse.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPAccessProfileServiceSearchAccessProfilesResponse returns one page of +// +// tenant-wide MCP access profiles. +type MCPAccessProfileServiceSearchAccessProfilesResponse struct { + // Token for next page. + NextPageToken *string `json:"nextPageToken,omitempty"` + // The page of matching MCP access profiles. + Profiles []MCPAccessProfile `json:"profiles,omitempty"` +} + +func (m *MCPAccessProfileServiceSearchAccessProfilesResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} + +func (m *MCPAccessProfileServiceSearchAccessProfilesResponse) GetProfiles() []MCPAccessProfile { + if m == nil { + return nil + } + return m.Profiles +} diff --git a/pkg/models/shared/mcpaccessprofileserviceupdaterequest.go b/pkg/models/shared/mcpaccessprofileserviceupdaterequest.go index 33c55fe3a..2a81b3240 100644 --- a/pkg/models/shared/mcpaccessprofileserviceupdaterequest.go +++ b/pkg/models/shared/mcpaccessprofileserviceupdaterequest.go @@ -4,11 +4,11 @@ package shared // MCPAccessProfileServiceUpdateRequest updates an existing MCP access profile. type MCPAccessProfileServiceUpdateRequest struct { - Profile *MCPAccessProfile `json:"profile,omitempty"` - UpdateMask *string `json:"updateMask,omitempty"` + Profile *MCPAccessProfileInput `json:"profile,omitempty"` + UpdateMask *string `json:"updateMask,omitempty"` } -func (m *MCPAccessProfileServiceUpdateRequest) GetProfile() *MCPAccessProfile { +func (m *MCPAccessProfileServiceUpdateRequest) GetProfile() *MCPAccessProfileInput { if m == nil { return nil } diff --git a/pkg/models/shared/mcpresource.go b/pkg/models/shared/mcpresource.go new file mode 100644 index 000000000..63b3df532 --- /dev/null +++ b/pkg/models/shared/mcpresource.go @@ -0,0 +1,408 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// MCPResourceKind - Whether this is a static resource or a URI template. +type MCPResourceKind string + +const ( + MCPResourceKindMcpResourceKindUnspecified MCPResourceKind = "MCP_RESOURCE_KIND_UNSPECIFIED" + MCPResourceKindMcpResourceKindStatic MCPResourceKind = "MCP_RESOURCE_KIND_STATIC" + MCPResourceKindMcpResourceKindTemplate MCPResourceKind = "MCP_RESOURCE_KIND_TEMPLATE" +) + +func (e MCPResourceKind) ToPointer() *MCPResourceKind { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *MCPResourceKind) IsExact() bool { + if e != nil { + switch *e { + case "MCP_RESOURCE_KIND_UNSPECIFIED", "MCP_RESOURCE_KIND_STATIC", "MCP_RESOURCE_KIND_TEMPLATE": + return true + } + } + return false +} + +// MCPResourceState - Resource approval/lifecycle state. +type MCPResourceState string + +const ( + MCPResourceStateMcpResourceStateUnspecified MCPResourceState = "MCP_RESOURCE_STATE_UNSPECIFIED" + MCPResourceStateMcpResourceStatePendingReview MCPResourceState = "MCP_RESOURCE_STATE_PENDING_REVIEW" + MCPResourceStateMcpResourceStateApproved MCPResourceState = "MCP_RESOURCE_STATE_APPROVED" + MCPResourceStateMcpResourceStateDisabled MCPResourceState = "MCP_RESOURCE_STATE_DISABLED" + MCPResourceStateMcpResourceStateRemoved MCPResourceState = "MCP_RESOURCE_STATE_REMOVED" +) + +func (e MCPResourceState) ToPointer() *MCPResourceState { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *MCPResourceState) IsExact() bool { + if e != nil { + switch *e { + case "MCP_RESOURCE_STATE_UNSPECIFIED", "MCP_RESOURCE_STATE_PENDING_REVIEW", "MCP_RESOURCE_STATE_APPROVED", "MCP_RESOURCE_STATE_DISABLED", "MCP_RESOURCE_STATE_REMOVED": + return true + } + } + return false +} + +// MCPResource represents metadata about an individual resource discovered from an MCP server. +type MCPResource struct { + // Bound AppEntitlement created during sync. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // App identifier (app that owns the connector). + AppID *string `json:"appId,omitempty"` + // Connector identifier. + ConnectorID *string `json:"connectorId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // Description from the MCP resource spec. + Description *string `json:"description,omitempty"` + // Hash of resource definition for change detection. + DiscoveryHash *string `json:"discoveryHash,omitempty"` + // Whether the bound app entitlement exists and is not deleted. Computed + // read-only; populated on Search only when the request had + // include_grant_status = true; ignored on write. + EntitlementActive *bool `json:"entitlementActive,omitempty"` + // Number of active grants on the bound app entitlement. Computed read-only; + // populated on Search only when the request had include_grant_status = true; + // ignored on write. + GrantCount *int64 `integer:"string" json:"grantCount,omitempty"` + // Unique identifier for this MCP resource record. + ID *string `json:"id,omitempty"` + // Whether this is a static resource or a URI template. + Kind *MCPResourceKind `json:"kind,omitempty"` + LastDiscoveredAt *time.Time `json:"lastDiscoveredAt,omitempty"` + // MIME type of the resource content, when known. + MimeType *string `json:"mimeType,omitempty"` + // Native MCP resource name (unique within an MCP server). + Name *string `json:"name,omitempty"` + // Resource approval/lifecycle state. + State *MCPResourceState `json:"state,omitempty"` + // Human-readable title from the MCP resource spec. + Title *string `json:"title,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` + // Raw resource URI from MCP discovery (set for STATIC resources). + URI *string `json:"uri,omitempty"` + // Raw RFC 6570 URI template from MCP discovery (set for TEMPLATE resources). + URITemplate *string `json:"uriTemplate,omitempty"` +} + +func (m MCPResource) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(m, "", false) +} + +func (m *MCPResource) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &m, "", false, nil); err != nil { + return err + } + return nil +} + +func (m *MCPResource) GetAppEntitlementID() *string { + if m == nil { + return nil + } + return m.AppEntitlementID +} + +func (m *MCPResource) GetAppID() *string { + if m == nil { + return nil + } + return m.AppID +} + +func (m *MCPResource) GetConnectorID() *string { + if m == nil { + return nil + } + return m.ConnectorID +} + +func (m *MCPResource) GetCreatedAt() *time.Time { + if m == nil { + return nil + } + return m.CreatedAt +} + +func (m *MCPResource) GetDeletedAt() *time.Time { + if m == nil { + return nil + } + return m.DeletedAt +} + +func (m *MCPResource) GetDescription() *string { + if m == nil { + return nil + } + return m.Description +} + +func (m *MCPResource) GetDiscoveryHash() *string { + if m == nil { + return nil + } + return m.DiscoveryHash +} + +func (m *MCPResource) GetEntitlementActive() *bool { + if m == nil { + return nil + } + return m.EntitlementActive +} + +func (m *MCPResource) GetGrantCount() *int64 { + if m == nil { + return nil + } + return m.GrantCount +} + +func (m *MCPResource) GetID() *string { + if m == nil { + return nil + } + return m.ID +} + +func (m *MCPResource) GetKind() *MCPResourceKind { + if m == nil { + return nil + } + return m.Kind +} + +func (m *MCPResource) GetLastDiscoveredAt() *time.Time { + if m == nil { + return nil + } + return m.LastDiscoveredAt +} + +func (m *MCPResource) GetMimeType() *string { + if m == nil { + return nil + } + return m.MimeType +} + +func (m *MCPResource) GetName() *string { + if m == nil { + return nil + } + return m.Name +} + +func (m *MCPResource) GetState() *MCPResourceState { + if m == nil { + return nil + } + return m.State +} + +func (m *MCPResource) GetTitle() *string { + if m == nil { + return nil + } + return m.Title +} + +func (m *MCPResource) GetUpdatedAt() *time.Time { + if m == nil { + return nil + } + return m.UpdatedAt +} + +func (m *MCPResource) GetURI() *string { + if m == nil { + return nil + } + return m.URI +} + +func (m *MCPResource) GetURITemplate() *string { + if m == nil { + return nil + } + return m.URITemplate +} + +// MCPResourceInput - MCPResource represents metadata about an individual resource discovered from an MCP server. +type MCPResourceInput struct { + // Bound AppEntitlement created during sync. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // App identifier (app that owns the connector). + AppID *string `json:"appId,omitempty"` + // Connector identifier. + ConnectorID *string `json:"connectorId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // Description from the MCP resource spec. + Description *string `json:"description,omitempty"` + // Hash of resource definition for change detection. + DiscoveryHash *string `json:"discoveryHash,omitempty"` + // Unique identifier for this MCP resource record. + ID *string `json:"id,omitempty"` + // Whether this is a static resource or a URI template. + Kind *MCPResourceKind `json:"kind,omitempty"` + LastDiscoveredAt *time.Time `json:"lastDiscoveredAt,omitempty"` + // MIME type of the resource content, when known. + MimeType *string `json:"mimeType,omitempty"` + // Native MCP resource name (unique within an MCP server). + Name *string `json:"name,omitempty"` + // Resource approval/lifecycle state. + State *MCPResourceState `json:"state,omitempty"` + // Human-readable title from the MCP resource spec. + Title *string `json:"title,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` + // Raw resource URI from MCP discovery (set for STATIC resources). + URI *string `json:"uri,omitempty"` + // Raw RFC 6570 URI template from MCP discovery (set for TEMPLATE resources). + URITemplate *string `json:"uriTemplate,omitempty"` +} + +func (m MCPResourceInput) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(m, "", false) +} + +func (m *MCPResourceInput) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &m, "", false, nil); err != nil { + return err + } + return nil +} + +func (m *MCPResourceInput) GetAppEntitlementID() *string { + if m == nil { + return nil + } + return m.AppEntitlementID +} + +func (m *MCPResourceInput) GetAppID() *string { + if m == nil { + return nil + } + return m.AppID +} + +func (m *MCPResourceInput) GetConnectorID() *string { + if m == nil { + return nil + } + return m.ConnectorID +} + +func (m *MCPResourceInput) GetCreatedAt() *time.Time { + if m == nil { + return nil + } + return m.CreatedAt +} + +func (m *MCPResourceInput) GetDeletedAt() *time.Time { + if m == nil { + return nil + } + return m.DeletedAt +} + +func (m *MCPResourceInput) GetDescription() *string { + if m == nil { + return nil + } + return m.Description +} + +func (m *MCPResourceInput) GetDiscoveryHash() *string { + if m == nil { + return nil + } + return m.DiscoveryHash +} + +func (m *MCPResourceInput) GetID() *string { + if m == nil { + return nil + } + return m.ID +} + +func (m *MCPResourceInput) GetKind() *MCPResourceKind { + if m == nil { + return nil + } + return m.Kind +} + +func (m *MCPResourceInput) GetLastDiscoveredAt() *time.Time { + if m == nil { + return nil + } + return m.LastDiscoveredAt +} + +func (m *MCPResourceInput) GetMimeType() *string { + if m == nil { + return nil + } + return m.MimeType +} + +func (m *MCPResourceInput) GetName() *string { + if m == nil { + return nil + } + return m.Name +} + +func (m *MCPResourceInput) GetState() *MCPResourceState { + if m == nil { + return nil + } + return m.State +} + +func (m *MCPResourceInput) GetTitle() *string { + if m == nil { + return nil + } + return m.Title +} + +func (m *MCPResourceInput) GetUpdatedAt() *time.Time { + if m == nil { + return nil + } + return m.UpdatedAt +} + +func (m *MCPResourceInput) GetURI() *string { + if m == nil { + return nil + } + return m.URI +} + +func (m *MCPResourceInput) GetURITemplate() *string { + if m == nil { + return nil + } + return m.URITemplate +} diff --git a/pkg/models/shared/mcpresourcehistoryentry.go b/pkg/models/shared/mcpresourcehistoryentry.go new file mode 100644 index 000000000..3ba1fbf78 --- /dev/null +++ b/pkg/models/shared/mcpresourcehistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceHistoryEntry is one version of an MCP resource and its history metadata. +type MCPResourceHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *MCPResource `json:"snapshot,omitempty"` +} + +func (m *MCPResourceHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if m == nil { + return nil + } + return m.Metadata +} + +func (m *MCPResourceHistoryEntry) GetSnapshot() *MCPResource { + if m == nil { + return nil + } + return m.Snapshot +} diff --git a/pkg/models/shared/mcpresourceservicegetresponse.go b/pkg/models/shared/mcpresourceservicegetresponse.go new file mode 100644 index 000000000..030d1c09a --- /dev/null +++ b/pkg/models/shared/mcpresourceservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceGetResponse returns a single MCP resource. +type MCPResourceServiceGetResponse struct { + Resource *MCPResource `json:"resource,omitempty"` +} + +func (m *MCPResourceServiceGetResponse) GetResource() *MCPResource { + if m == nil { + return nil + } + return m.Resource +} diff --git a/pkg/models/shared/mcpresourceservicelisthistoryresponse.go b/pkg/models/shared/mcpresourceservicelisthistoryresponse.go new file mode 100644 index 000000000..5cb83fdc8 --- /dev/null +++ b/pkg/models/shared/mcpresourceservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceListHistoryResponse returns MCP resource history entries. +type MCPResourceServiceListHistoryResponse struct { + // The page of history entries, newest first. + List []MCPResourceHistoryEntry `json:"list,omitempty"` + // Pagination token for the next page, or empty if there are no more results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (m *MCPResourceServiceListHistoryResponse) GetList() []MCPResourceHistoryEntry { + if m == nil { + return nil + } + return m.List +} + +func (m *MCPResourceServiceListHistoryResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} diff --git a/pkg/models/shared/mcpresourceservicelistresponse.go b/pkg/models/shared/mcpresourceservicelistresponse.go new file mode 100644 index 000000000..13828b32c --- /dev/null +++ b/pkg/models/shared/mcpresourceservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceListResponse returns a list of MCP resources. +type MCPResourceServiceListResponse struct { + // Token for next page. + NextPageToken *string `json:"nextPageToken,omitempty"` + // List of MCP resources. + Resources []MCPResource `json:"resources,omitempty"` +} + +func (m *MCPResourceServiceListResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} + +func (m *MCPResourceServiceListResponse) GetResources() []MCPResource { + if m == nil { + return nil + } + return m.Resources +} diff --git a/pkg/models/shared/mcpresourceservicesearchrequest.go b/pkg/models/shared/mcpresourceservicesearchrequest.go new file mode 100644 index 000000000..dea97780a --- /dev/null +++ b/pkg/models/shared/mcpresourceservicesearchrequest.go @@ -0,0 +1,182 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +type KindFilter string + +const ( + KindFilterMcpResourceKindUnspecified KindFilter = "MCP_RESOURCE_KIND_UNSPECIFIED" + KindFilterMcpResourceKindStatic KindFilter = "MCP_RESOURCE_KIND_STATIC" + KindFilterMcpResourceKindTemplate KindFilter = "MCP_RESOURCE_KIND_TEMPLATE" +) + +func (e KindFilter) ToPointer() *KindFilter { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *KindFilter) IsExact() bool { + if e != nil { + switch *e { + case "MCP_RESOURCE_KIND_UNSPECIFIED", "MCP_RESOURCE_KIND_STATIC", "MCP_RESOURCE_KIND_TEMPLATE": + return true + } + } + return false +} + +// MCPResourceServiceSearchRequestSortBy - Sort order for results. UNSPECIFIED sorts by resource name ascending. +type MCPResourceServiceSearchRequestSortBy string + +const ( + MCPResourceServiceSearchRequestSortByMcpResourceSortByUnspecified MCPResourceServiceSearchRequestSortBy = "MCP_RESOURCE_SORT_BY_UNSPECIFIED" + MCPResourceServiceSearchRequestSortByMcpResourceSortByName MCPResourceServiceSearchRequestSortBy = "MCP_RESOURCE_SORT_BY_NAME" + MCPResourceServiceSearchRequestSortByMcpResourceSortByURI MCPResourceServiceSearchRequestSortBy = "MCP_RESOURCE_SORT_BY_URI" + MCPResourceServiceSearchRequestSortByMcpResourceSortByState MCPResourceServiceSearchRequestSortBy = "MCP_RESOURCE_SORT_BY_STATE" + MCPResourceServiceSearchRequestSortByMcpResourceSortByUpdatedAt MCPResourceServiceSearchRequestSortBy = "MCP_RESOURCE_SORT_BY_UPDATED_AT" +) + +func (e MCPResourceServiceSearchRequestSortBy) ToPointer() *MCPResourceServiceSearchRequestSortBy { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *MCPResourceServiceSearchRequestSortBy) IsExact() bool { + if e != nil { + switch *e { + case "MCP_RESOURCE_SORT_BY_UNSPECIFIED", "MCP_RESOURCE_SORT_BY_NAME", "MCP_RESOURCE_SORT_BY_URI", "MCP_RESOURCE_SORT_BY_STATE", "MCP_RESOURCE_SORT_BY_UPDATED_AT": + return true + } + } + return false +} + +// SortDirection - Direction for sort_by. UNSPECIFIED means ascending. +type SortDirection string + +const ( + SortDirectionSortDirectionUnspecified SortDirection = "SORT_DIRECTION_UNSPECIFIED" + SortDirectionSortDirectionAsc SortDirection = "SORT_DIRECTION_ASC" + SortDirectionSortDirectionDesc SortDirection = "SORT_DIRECTION_DESC" +) + +func (e SortDirection) ToPointer() *SortDirection { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SortDirection) IsExact() bool { + if e != nil { + switch *e { + case "SORT_DIRECTION_UNSPECIFIED", "SORT_DIRECTION_ASC", "SORT_DIRECTION_DESC": + return true + } + } + return false +} + +type StateFilter string + +const ( + StateFilterMcpResourceStateUnspecified StateFilter = "MCP_RESOURCE_STATE_UNSPECIFIED" + StateFilterMcpResourceStatePendingReview StateFilter = "MCP_RESOURCE_STATE_PENDING_REVIEW" + StateFilterMcpResourceStateApproved StateFilter = "MCP_RESOURCE_STATE_APPROVED" + StateFilterMcpResourceStateDisabled StateFilter = "MCP_RESOURCE_STATE_DISABLED" + StateFilterMcpResourceStateRemoved StateFilter = "MCP_RESOURCE_STATE_REMOVED" +) + +func (e StateFilter) ToPointer() *StateFilter { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *StateFilter) IsExact() bool { + if e != nil { + switch *e { + case "MCP_RESOURCE_STATE_UNSPECIFIED", "MCP_RESOURCE_STATE_PENDING_REVIEW", "MCP_RESOURCE_STATE_APPROVED", "MCP_RESOURCE_STATE_DISABLED", "MCP_RESOURCE_STATE_REMOVED": + return true + } + } + return false +} + +// MCPResourceServiceSearchRequest searches MCP resources with filters. +type MCPResourceServiceSearchRequest struct { + // When true, the server populates the computed entitlement_active and + // grant_count fields on each returned row (an extra batched entitlement + // lookup per page). Off by default so callers that don't render grant + // status don't pay for it. + IncludeGrantStatus *bool `json:"includeGrantStatus,omitempty"` + // Optional filter by resource kind. An empty list means no filter. + KindFilter []KindFilter `json:"kindFilter,omitempty"` + // Page size (max 100). + PageSize *int `json:"pageSize,omitempty"` + // Page token for pagination. + PageToken *string `json:"pageToken,omitempty"` + // Optional text query matched against name, title, description, and uri. + Query *string `json:"query,omitempty"` + // Sort order for results. UNSPECIFIED sorts by resource name ascending. + SortBy *MCPResourceServiceSearchRequestSortBy `json:"sortBy,omitempty"` + // Direction for sort_by. UNSPECIFIED means ascending. + SortDirection *SortDirection `json:"sortDirection,omitempty"` + // Optional filter by resource state. An empty list defaults to + // PENDING_REVIEW, APPROVED, and DISABLED (REMOVED is hidden unless + // explicitly requested). + StateFilter []StateFilter `json:"stateFilter,omitempty"` +} + +func (m *MCPResourceServiceSearchRequest) GetIncludeGrantStatus() *bool { + if m == nil { + return nil + } + return m.IncludeGrantStatus +} + +func (m *MCPResourceServiceSearchRequest) GetKindFilter() []KindFilter { + if m == nil { + return nil + } + return m.KindFilter +} + +func (m *MCPResourceServiceSearchRequest) GetPageSize() *int { + if m == nil { + return nil + } + return m.PageSize +} + +func (m *MCPResourceServiceSearchRequest) GetPageToken() *string { + if m == nil { + return nil + } + return m.PageToken +} + +func (m *MCPResourceServiceSearchRequest) GetQuery() *string { + if m == nil { + return nil + } + return m.Query +} + +func (m *MCPResourceServiceSearchRequest) GetSortBy() *MCPResourceServiceSearchRequestSortBy { + if m == nil { + return nil + } + return m.SortBy +} + +func (m *MCPResourceServiceSearchRequest) GetSortDirection() *SortDirection { + if m == nil { + return nil + } + return m.SortDirection +} + +func (m *MCPResourceServiceSearchRequest) GetStateFilter() []StateFilter { + if m == nil { + return nil + } + return m.StateFilter +} diff --git a/pkg/models/shared/mcpresourceservicesearchresponse.go b/pkg/models/shared/mcpresourceservicesearchresponse.go new file mode 100644 index 000000000..51efde32f --- /dev/null +++ b/pkg/models/shared/mcpresourceservicesearchresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceSearchResponse returns matching MCP resources. +type MCPResourceServiceSearchResponse struct { + // Matching MCP resources. + List []MCPResource `json:"list,omitempty"` + // Token for next page. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (m *MCPResourceServiceSearchResponse) GetList() []MCPResource { + if m == nil { + return nil + } + return m.List +} + +func (m *MCPResourceServiceSearchResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} diff --git a/pkg/models/shared/mcpresourceserviceupdaterequest.go b/pkg/models/shared/mcpresourceserviceupdaterequest.go new file mode 100644 index 000000000..030a76564 --- /dev/null +++ b/pkg/models/shared/mcpresourceserviceupdaterequest.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceUpdateRequest updates an existing MCP resource. +type MCPResourceServiceUpdateRequest struct { + Resource *MCPResourceInput `json:"resource,omitempty"` + UpdateMask *string `json:"updateMask,omitempty"` +} + +func (m *MCPResourceServiceUpdateRequest) GetResource() *MCPResourceInput { + if m == nil { + return nil + } + return m.Resource +} + +func (m *MCPResourceServiceUpdateRequest) GetUpdateMask() *string { + if m == nil { + return nil + } + return m.UpdateMask +} diff --git a/pkg/models/shared/mcpresourceserviceupdateresponse.go b/pkg/models/shared/mcpresourceserviceupdateresponse.go new file mode 100644 index 000000000..508a8f5b0 --- /dev/null +++ b/pkg/models/shared/mcpresourceserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MCPResourceServiceUpdateResponse returns the updated MCP resource. +type MCPResourceServiceUpdateResponse struct { + Resource *MCPResource `json:"resource,omitempty"` +} + +func (m *MCPResourceServiceUpdateResponse) GetResource() *MCPResource { + if m == nil { + return nil + } + return m.Resource +} diff --git a/pkg/models/shared/mcpservercatalogauthmode.go b/pkg/models/shared/mcpservercatalogauthmode.go index d2cc81017..c69afc6ff 100644 --- a/pkg/models/shared/mcpservercatalogauthmode.go +++ b/pkg/models/shared/mcpservercatalogauthmode.go @@ -30,6 +30,33 @@ func (e *MCPServerCatalogAuthModeAuthMethod) IsExact() bool { return false } +// MCPServerCatalogAuthModeClientIDMode - How the OAuth2 client_id is acquired for this mode. Set by the impl bundle +// +// and shown read-only on the form. authorization_code grant only. +type MCPServerCatalogAuthModeClientIDMode string + +const ( + MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeUnspecified MCPServerCatalogAuthModeClientIDMode = "MCP_SERVER_CATALOG_CLIENT_ID_MODE_UNSPECIFIED" + MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeManual MCPServerCatalogAuthModeClientIDMode = "MCP_SERVER_CATALOG_CLIENT_ID_MODE_MANUAL" + MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeDcr MCPServerCatalogAuthModeClientIDMode = "MCP_SERVER_CATALOG_CLIENT_ID_MODE_DCR" + MCPServerCatalogAuthModeClientIDModeMcpServerCatalogClientIDModeCimd MCPServerCatalogAuthModeClientIDMode = "MCP_SERVER_CATALOG_CLIENT_ID_MODE_CIMD" +) + +func (e MCPServerCatalogAuthModeClientIDMode) ToPointer() *MCPServerCatalogAuthModeClientIDMode { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *MCPServerCatalogAuthModeClientIDMode) IsExact() bool { + if e != nil { + switch *e { + case "MCP_SERVER_CATALOG_CLIENT_ID_MODE_UNSPECIFIED", "MCP_SERVER_CATALOG_CLIENT_ID_MODE_MANUAL", "MCP_SERVER_CATALOG_CLIENT_ID_MODE_DCR", "MCP_SERVER_CATALOG_CLIENT_ID_MODE_CIMD": + return true + } + } + return false +} + // MCPServerCatalogAuthMode describes a single authentication method an impl // // supports. Multiple modes mean the user/admin can pick at registration time @@ -44,6 +71,9 @@ type MCPServerCatalogAuthMode struct { AuthStyle *string `json:"authStyle,omitempty"` // OAuth2 authorization endpoint URL. Empty for non-OAuth2 methods. AuthorizeURL *string `json:"authorizeUrl,omitempty"` + // How the OAuth2 client_id is acquired for this mode. Set by the impl bundle + // and shown read-only on the form. authorization_code grant only. + ClientIDMode *MCPServerCatalogAuthModeClientIDMode `json:"clientIdMode,omitempty"` // Documentation URL where the user can obtain a credential for this method // (e.g., a link to the SaaS app's "create API token" page). Empty if not set. CredentialURL *string `json:"credentialUrl,omitempty"` @@ -69,6 +99,9 @@ type MCPServerCatalogAuthMode struct { // Raw bundle string: "client_credentials", "authorization_code", // "jwt_bearer", "google_service_account", or empty (infer from authorize_url). Oauth2Grant *string `json:"oauth2Grant,omitempty"` + // Optional (opt-in) OAuth2 scopes from the config's optional_scopes. + // Disjoint from `scopes` and not pre-selected. Empty for non-OAuth2 methods. + OptionalScopes []string `json:"optionalScopes,omitempty"` // Per-user OAuth: each user authorizes individually instead of sharing a // service-level credential. Only meaningful for OAuth2. Passthrough *bool `json:"passthrough,omitempty"` @@ -102,6 +135,13 @@ func (m *MCPServerCatalogAuthMode) GetAuthorizeURL() *string { return m.AuthorizeURL } +func (m *MCPServerCatalogAuthMode) GetClientIDMode() *MCPServerCatalogAuthModeClientIDMode { + if m == nil { + return nil + } + return m.ClientIDMode +} + func (m *MCPServerCatalogAuthMode) GetCredentialURL() *string { if m == nil { return nil @@ -158,6 +198,13 @@ func (m *MCPServerCatalogAuthMode) GetOauth2Grant() *string { return m.Oauth2Grant } +func (m *MCPServerCatalogAuthMode) GetOptionalScopes() []string { + if m == nil { + return nil + } + return m.OptionalScopes +} + func (m *MCPServerCatalogAuthMode) GetPassthrough() *bool { if m == nil { return nil diff --git a/pkg/models/shared/mcpservercatalogentry.go b/pkg/models/shared/mcpservercatalogentry.go index ebe370b3f..c37400312 100644 --- a/pkg/models/shared/mcpservercatalogentry.go +++ b/pkg/models/shared/mcpservercatalogentry.go @@ -164,6 +164,12 @@ type MCPServerCatalogEntry struct { // // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. DefaultTokenURL *string `json:"defaultTokenUrl,omitempty"` + // Curated default tool-name prefix an admin gets when they register this + // catalog entry and set no custom prefix: the impl's declared server_prefix, + // else its service_name. Shown as a placeholder in the create wizard's tool + // prefix field. Empty when the impl declares no curated default. Mirrors the + // read-only default_tool_prefix on MCPServerView surfaced in the edit flow. + DefaultToolPrefix *string `json:"defaultToolPrefix,omitempty"` // Short description of what the MCP server does. Description *string `json:"description,omitempty"` // Human-readable display name. @@ -249,6 +255,13 @@ func (m *MCPServerCatalogEntry) GetDefaultTokenURL() *string { return m.DefaultTokenURL } +func (m *MCPServerCatalogEntry) GetDefaultToolPrefix() *string { + if m == nil { + return nil + } + return m.DefaultToolPrefix +} + func (m *MCPServerCatalogEntry) GetDescription() *string { if m == nil { return nil diff --git a/pkg/models/shared/mcpserverserviceregisterrequest.go b/pkg/models/shared/mcpserverserviceregisterrequest.go index 36499022b..e9638606d 100644 --- a/pkg/models/shared/mcpserverserviceregisterrequest.go +++ b/pkg/models/shared/mcpserverserviceregisterrequest.go @@ -54,6 +54,12 @@ func (e *MCPServerServiceRegisterRequestServerType) IsExact() bool { // MCPServerServiceRegisterRequest creates a new MCP server (Connector + config). type MCPServerServiceRegisterRequest struct { + // Optional access profiles (request catalogs) the server should be requestable + // through. Register creates the server's "All approved tools" toolset empty and adds + // its entitlement to each profile, so members can request the server before discovery + // has found a single tool; the sync later adopts the same toolset and fills it. Empty + // skips both steps. + AccessProfileIds []string `json:"accessProfileIds,omitempty"` // finding_ids from the diagnostic the admin acknowledged. Each must cover a // blocking-relaxable finding on oauth_diagnostic_id. AcknowledgedFindingIds []string `json:"acknowledgedFindingIds,omitempty"` @@ -106,6 +112,13 @@ type MCPServerServiceRegisterRequest struct { UserIds []string `json:"userIds,omitempty"` } +func (m *MCPServerServiceRegisterRequest) GetAccessProfileIds() []string { + if m == nil { + return nil + } + return m.AccessProfileIds +} + func (m *MCPServerServiceRegisterRequest) GetAcknowledgedFindingIds() []string { if m == nil { return nil diff --git a/pkg/models/shared/mcpserverserviceregisterresponse.go b/pkg/models/shared/mcpserverserviceregisterresponse.go index 2489324a3..78a70a178 100644 --- a/pkg/models/shared/mcpserverserviceregisterresponse.go +++ b/pkg/models/shared/mcpserverserviceregisterresponse.go @@ -4,7 +4,19 @@ package shared // MCPServerServiceRegisterResponse returns the newly created MCP server. type MCPServerServiceRegisterResponse struct { - McpServer *MCPServerView `json:"mcpServer,omitempty"` + // Whether the "All approved tools" toolset reached every profile in + // access_profile_ids. False means the server registered but the attach failed + // afterwards, and the profiles have to be wired from the server page. Always true + // when access_profile_ids was empty, since there was nothing to attach. + AccessProfilesAttached *bool `json:"accessProfilesAttached,omitempty"` + McpServer *MCPServerView `json:"mcpServer,omitempty"` +} + +func (m *MCPServerServiceRegisterResponse) GetAccessProfilesAttached() *bool { + if m == nil { + return nil + } + return m.AccessProfilesAttached } func (m *MCPServerServiceRegisterResponse) GetMcpServer() *MCPServerView { diff --git a/pkg/models/shared/mcpserverview.go b/pkg/models/shared/mcpserverview.go index 929bbb829..671ebc8f1 100644 --- a/pkg/models/shared/mcpserverview.go +++ b/pkg/models/shared/mcpserverview.go @@ -271,8 +271,12 @@ type MCPServerView struct { // Admin-provided display name. DisplayName *string `json:"displayName,omitempty"` // Endpoint URL for external MCP servers. Read-only. - EndpointURL *string `json:"endpointUrl,omitempty"` - LastCalledAt *time.Time `json:"lastCalledAt,omitempty"` + EndpointURL *string `json:"endpointUrl,omitempty"` + // Whether the endpoint URL is immutable. True once the connector has + // completed its first successful sync; the URL cannot be changed after + // that point. Read-only. + EndpointURLLocked *bool `json:"endpointUrlLocked,omitempty"` + LastCalledAt *time.Time `json:"lastCalledAt,omitempty"` // Opaque catalog entry ID for hosted MCP servers (27-character KSUID). // Obtain valid IDs from the ListCatalog or GetCatalog RPCs. McpServerCatalogID *string `json:"mcpServerCatalogId,omitempty"` @@ -517,6 +521,13 @@ func (m *MCPServerView) GetEndpointURL() *string { return m.EndpointURL } +func (m *MCPServerView) GetEndpointURLLocked() *bool { + if m == nil { + return nil + } + return m.EndpointURLLocked +} + func (m *MCPServerView) GetLastCalledAt() *time.Time { if m == nil { return nil diff --git a/pkg/models/shared/mcptool.go b/pkg/models/shared/mcptool.go index a71f9c7c9..0edb3323c 100644 --- a/pkg/models/shared/mcptool.go +++ b/pkg/models/shared/mcptool.go @@ -194,6 +194,14 @@ type MCPTool struct { // JSON-encoded input schema from MCP discovery. InputSchemaJSON *string `json:"inputSchemaJson,omitempty"` LastCalledAt *time.Time `json:"lastCalledAt,omitempty"` + // Whether this tool's backing entitlement is exposed in at least one request + // catalog directly (i.e. can be requested on its own). Computed read-only; + // populated on Search. + Requestable *bool `json:"requestable,omitempty"` + // Whether this tool is requestable indirectly — it belongs to at least one + // toolset (access profile) whose backing entitlement is exposed in a request + // catalog. Independent of `requestable`. Computed read-only; populated on Search. + RequestableViaToolset *bool `json:"requestableViaToolset,omitempty"` // Tool approval/lifecycle state. State *MCPToolState `json:"state,omitempty"` // Native MCP tool name (unique within an MCP server). @@ -326,6 +334,20 @@ func (m *MCPTool) GetLastCalledAt() *time.Time { return m.LastCalledAt } +func (m *MCPTool) GetRequestable() *bool { + if m == nil { + return nil + } + return m.Requestable +} + +func (m *MCPTool) GetRequestableViaToolset() *bool { + if m == nil { + return nil + } + return m.RequestableViaToolset +} + func (m *MCPTool) GetState() *MCPToolState { if m == nil { return nil diff --git a/pkg/models/shared/mcptoolservicesearchrequest.go b/pkg/models/shared/mcptoolservicesearchrequest.go index b7ab83954..42c4409b4 100644 --- a/pkg/models/shared/mcptoolservicesearchrequest.go +++ b/pkg/models/shared/mcptoolservicesearchrequest.go @@ -55,21 +55,21 @@ func (e *MCPToolServiceSearchRequestSortBy) IsExact() bool { return false } -// SortDirection - Direction for sort_by. UNSPECIFIED means ascending. -type SortDirection string +// MCPToolServiceSearchRequestSortDirection - Direction for sort_by. UNSPECIFIED means ascending. +type MCPToolServiceSearchRequestSortDirection string const ( - SortDirectionSortDirectionUnspecified SortDirection = "SORT_DIRECTION_UNSPECIFIED" - SortDirectionSortDirectionAsc SortDirection = "SORT_DIRECTION_ASC" - SortDirectionSortDirectionDesc SortDirection = "SORT_DIRECTION_DESC" + MCPToolServiceSearchRequestSortDirectionSortDirectionUnspecified MCPToolServiceSearchRequestSortDirection = "SORT_DIRECTION_UNSPECIFIED" + MCPToolServiceSearchRequestSortDirectionSortDirectionAsc MCPToolServiceSearchRequestSortDirection = "SORT_DIRECTION_ASC" + MCPToolServiceSearchRequestSortDirectionSortDirectionDesc MCPToolServiceSearchRequestSortDirection = "SORT_DIRECTION_DESC" ) -func (e SortDirection) ToPointer() *SortDirection { +func (e MCPToolServiceSearchRequestSortDirection) ToPointer() *MCPToolServiceSearchRequestSortDirection { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *SortDirection) IsExact() bool { +func (e *MCPToolServiceSearchRequestSortDirection) IsExact() bool { if e != nil { switch *e { case "SORT_DIRECTION_UNSPECIFIED", "SORT_DIRECTION_ASC", "SORT_DIRECTION_DESC": @@ -79,22 +79,22 @@ func (e *SortDirection) IsExact() bool { return false } -type StateFilter string +type MCPToolServiceSearchRequestStateFilter string const ( - StateFilterMcpToolStateUnspecified StateFilter = "MCP_TOOL_STATE_UNSPECIFIED" - StateFilterMcpToolStatePendingReview StateFilter = "MCP_TOOL_STATE_PENDING_REVIEW" - StateFilterMcpToolStateApproved StateFilter = "MCP_TOOL_STATE_APPROVED" - StateFilterMcpToolStateDisabled StateFilter = "MCP_TOOL_STATE_DISABLED" - StateFilterMcpToolStateRemoved StateFilter = "MCP_TOOL_STATE_REMOVED" + MCPToolServiceSearchRequestStateFilterMcpToolStateUnspecified MCPToolServiceSearchRequestStateFilter = "MCP_TOOL_STATE_UNSPECIFIED" + MCPToolServiceSearchRequestStateFilterMcpToolStatePendingReview MCPToolServiceSearchRequestStateFilter = "MCP_TOOL_STATE_PENDING_REVIEW" + MCPToolServiceSearchRequestStateFilterMcpToolStateApproved MCPToolServiceSearchRequestStateFilter = "MCP_TOOL_STATE_APPROVED" + MCPToolServiceSearchRequestStateFilterMcpToolStateDisabled MCPToolServiceSearchRequestStateFilter = "MCP_TOOL_STATE_DISABLED" + MCPToolServiceSearchRequestStateFilterMcpToolStateRemoved MCPToolServiceSearchRequestStateFilter = "MCP_TOOL_STATE_REMOVED" ) -func (e StateFilter) ToPointer() *StateFilter { +func (e MCPToolServiceSearchRequestStateFilter) ToPointer() *MCPToolServiceSearchRequestStateFilter { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *StateFilter) IsExact() bool { +func (e *MCPToolServiceSearchRequestStateFilter) IsExact() bool { if e != nil { switch *e { case "MCP_TOOL_STATE_UNSPECIFIED", "MCP_TOOL_STATE_PENDING_REVIEW", "MCP_TOOL_STATE_APPROVED", "MCP_TOOL_STATE_DISABLED", "MCP_TOOL_STATE_REMOVED": @@ -150,6 +150,11 @@ type MCPToolServiceSearchRequest struct { // raw emit time per tool. Costs one Dynamo Limit(1) read per row; // callers that don't render the "Last used" column should leave false. IncludeLastCalledAt *bool `json:"includeLastCalledAt,omitempty"` + // When true, populate the computed `requestable` / `requestable_via_toolset` + // fields on each tool (an extra catalog-membership lookup). Off by default so + // callers that don't render requestability — e.g. tool-picker and + // tools-by-toolset views — don't pay for it. + IncludeRequestable *bool `json:"includeRequestable,omitempty"` // Page size (max 100). PageSize *int `json:"pageSize,omitempty"` // Page token for pagination. @@ -161,9 +166,9 @@ type MCPToolServiceSearchRequest struct { // Sort order for results. UNSPECIFIED sorts by tool name ascending. SortBy *MCPToolServiceSearchRequestSortBy `json:"sortBy,omitempty"` // Direction for sort_by. UNSPECIFIED means ascending. - SortDirection *SortDirection `json:"sortDirection,omitempty"` + SortDirection *MCPToolServiceSearchRequestSortDirection `json:"sortDirection,omitempty"` // Optional filter by tool state. 0 (UNSPECIFIED) means no filter. - StateFilter []StateFilter `json:"stateFilter,omitempty"` + StateFilter []MCPToolServiceSearchRequestStateFilter `json:"stateFilter,omitempty"` // Optional filter by visibility. 0 (UNSPECIFIED) means no filter. VisibilityFilter []VisibilityFilter `json:"visibilityFilter,omitempty"` } @@ -210,6 +215,13 @@ func (m *MCPToolServiceSearchRequest) GetIncludeLastCalledAt() *bool { return m.IncludeLastCalledAt } +func (m *MCPToolServiceSearchRequest) GetIncludeRequestable() *bool { + if m == nil { + return nil + } + return m.IncludeRequestable +} + func (m *MCPToolServiceSearchRequest) GetPageSize() *int { if m == nil { return nil @@ -245,14 +257,14 @@ func (m *MCPToolServiceSearchRequest) GetSortBy() *MCPToolServiceSearchRequestSo return m.SortBy } -func (m *MCPToolServiceSearchRequest) GetSortDirection() *SortDirection { +func (m *MCPToolServiceSearchRequest) GetSortDirection() *MCPToolServiceSearchRequestSortDirection { if m == nil { return nil } return m.SortDirection } -func (m *MCPToolServiceSearchRequest) GetStateFilter() []StateFilter { +func (m *MCPToolServiceSearchRequest) GetStateFilter() []MCPToolServiceSearchRequestStateFilter { if m == nil { return nil } diff --git a/pkg/models/shared/mintgatewaykeyrequest.go b/pkg/models/shared/mintgatewaykeyrequest.go new file mode 100644 index 000000000..5edc509c4 --- /dev/null +++ b/pkg/models/shared/mintgatewaykeyrequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MintGatewayKeyRequest message. +type MintGatewayKeyRequest struct { + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` +} + +func (m *MintGatewayKeyRequest) GetDisplayName() *string { + if m == nil { + return nil + } + return m.DisplayName +} diff --git a/pkg/models/shared/mintgatewaykeyresponse.go b/pkg/models/shared/mintgatewaykeyresponse.go new file mode 100644 index 000000000..514af8dcb --- /dev/null +++ b/pkg/models/shared/mintgatewaykeyresponse.go @@ -0,0 +1,24 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MintGatewayKeyResponse message. +type MintGatewayKeyResponse struct { + GatewayKey *GatewayKey `json:"gatewayKey,omitempty"` + // The plaintextKey field. + PlaintextKey *string `json:"plaintextKey,omitempty"` +} + +func (m *MintGatewayKeyResponse) GetGatewayKey() *GatewayKey { + if m == nil { + return nil + } + return m.GatewayKey +} + +func (m *MintGatewayKeyResponse) GetPlaintextKey() *string { + if m == nil { + return nil + } + return m.PlaintextKey +} diff --git a/pkg/models/shared/money.go b/pkg/models/shared/money.go new file mode 100644 index 000000000..abc322b4f --- /dev/null +++ b/pkg/models/shared/money.go @@ -0,0 +1,57 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// Money is wire-compatible with google.type.Money field-for-field, so the public +// +// API converts with a field copy. Declared here rather than imported because +// protoc-gen-pgdb mirrors a nested message by calling its generated DBReflect, +// which only exists for messages this repo generates. +type Money struct { + // ISO 4217 currency code. Must equal the tenant's FundPolicy.currency_code. + CurrencyCode *string `json:"currencyCode,omitempty"` + // Nano-unit remainder, 0 <= nanos < 10^9. Non-negative for the same reason + // as units, which also keeps the (units, nanos) pair unambiguous. + Nanos *int `json:"nanos,omitempty"` + // Non-negative — grants, never debts — and bounded so units * 10^9 + nanos + // always fits int64. Without the ceiling a large value wraps positive and + // installs a limit nobody granted. The pair check spans two fields, so + // pkg/funds re-checks it on every conversion. + Units *int64 `integer:"string" json:"units,omitempty"` +} + +func (m Money) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(m, "", false) +} + +func (m *Money) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &m, "", false, nil); err != nil { + return err + } + return nil +} + +func (m *Money) GetCurrencyCode() *string { + if m == nil { + return nil + } + return m.CurrencyCode +} + +func (m *Money) GetNanos() *int { + if m == nil { + return nil + } + return m.Nanos +} + +func (m *Money) GetUnits() *int64 { + if m == nil { + return nil + } + return m.Units +} diff --git a/pkg/models/shared/msteamschannel.go b/pkg/models/shared/msteamschannel.go new file mode 100644 index 000000000..721b10259 --- /dev/null +++ b/pkg/models/shared/msteamschannel.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MSTeamsChannel message. +type MSTeamsChannel struct { + // The channelName field. + ChannelName *string `json:"channelName,omitempty"` + // The externalDirectoryId field. + ExternalDirectoryID *string `json:"externalDirectoryId,omitempty"` +} + +func (m *MSTeamsChannel) GetChannelName() *string { + if m == nil { + return nil + } + return m.ChannelName +} + +func (m *MSTeamsChannel) GetExternalDirectoryID() *string { + if m == nil { + return nil + } + return m.ExternalDirectoryID +} diff --git a/pkg/models/shared/msteamschannelsettings.go b/pkg/models/shared/msteamschannelsettings.go index 24697a5b5..640f874b2 100644 --- a/pkg/models/shared/msteamschannelsettings.go +++ b/pkg/models/shared/msteamschannelsettings.go @@ -16,7 +16,9 @@ type MSTeamsChannelSettings struct { // The isConfigured field. IsConfigured *bool `json:"isConfigured,omitempty"` ProvisioningRequest *ProvisioningRequestPreference `json:"provisioningRequest,omitempty"` + RequestCreated *RequestCreatedPreference `json:"requestCreated,omitempty"` Reviews *ReviewsPreference `json:"reviews,omitempty"` + System *SystemPreference `json:"system,omitempty"` TaskReminders *TaskRemindersPreference `json:"taskReminders,omitempty"` } @@ -90,6 +92,13 @@ func (m *MSTeamsChannelSettings) GetProvisioningRequest() *ProvisioningRequestPr return m.ProvisioningRequest } +func (m *MSTeamsChannelSettings) GetRequestCreated() *RequestCreatedPreference { + if m == nil { + return nil + } + return m.RequestCreated +} + func (m *MSTeamsChannelSettings) GetReviews() *ReviewsPreference { if m == nil { return nil @@ -97,6 +106,13 @@ func (m *MSTeamsChannelSettings) GetReviews() *ReviewsPreference { return m.Reviews } +func (m *MSTeamsChannelSettings) GetSystem() *SystemPreference { + if m == nil { + return nil + } + return m.System +} + func (m *MSTeamsChannelSettings) GetTaskReminders() *TaskRemindersPreference { if m == nil { return nil diff --git a/pkg/models/shared/myfundlimit.go b/pkg/models/shared/myfundlimit.go new file mode 100644 index 000000000..9772558c4 --- /dev/null +++ b/pkg/models/shared/myfundlimit.go @@ -0,0 +1,58 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// MyFundLimit is one of the caller's own per-app limits. It carries no user id: +// +// it is always the caller's. +type MyFundLimit struct { + // The C1 App this limit applies to. + AppID *string `json:"appId,omitempty"` + Controls *SpendControls `json:"controls,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (m MyFundLimit) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(m, "", false) +} + +func (m *MyFundLimit) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &m, "", false, nil); err != nil { + return err + } + return nil +} + +func (m *MyFundLimit) GetAppID() *string { + if m == nil { + return nil + } + return m.AppID +} + +func (m *MyFundLimit) GetControls() *SpendControls { + if m == nil { + return nil + } + return m.Controls +} + +func (m *MyFundLimit) GetCreatedAt() *time.Time { + if m == nil { + return nil + } + return m.CreatedAt +} + +func (m *MyFundLimit) GetUpdatedAt() *time.Time { + if m == nil { + return nil + } + return m.UpdatedAt +} diff --git a/pkg/models/shared/myfundlimithistoryentry.go b/pkg/models/shared/myfundlimithistoryentry.go new file mode 100644 index 000000000..8e29b7636 --- /dev/null +++ b/pkg/models/shared/myfundlimithistoryentry.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitHistoryEntry message. +type MyFundLimitHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *MyFundLimit `json:"snapshot,omitempty"` +} + +func (m *MyFundLimitHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if m == nil { + return nil + } + return m.Metadata +} + +func (m *MyFundLimitHistoryEntry) GetSnapshot() *MyFundLimit { + if m == nil { + return nil + } + return m.Snapshot +} diff --git a/pkg/models/shared/myfundlimitsservicedeleterequest.go b/pkg/models/shared/myfundlimitsservicedeleterequest.go new file mode 100644 index 000000000..2028c489e --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceDeleteRequest message. +type MyFundLimitsServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/myfundlimitsservicedeleteresponse.go b/pkg/models/shared/myfundlimitsservicedeleteresponse.go new file mode 100644 index 000000000..33cc810a4 --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceDeleteResponse message. +type MyFundLimitsServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/myfundlimitsservicelisthistoryresponse.go b/pkg/models/shared/myfundlimitsservicelisthistoryresponse.go new file mode 100644 index 000000000..aa157831a --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceListHistoryResponse message. +type MyFundLimitsServiceListHistoryResponse struct { + // The list field. + List []MyFundLimitHistoryEntry `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (m *MyFundLimitsServiceListHistoryResponse) GetList() []MyFundLimitHistoryEntry { + if m == nil { + return nil + } + return m.List +} + +func (m *MyFundLimitsServiceListHistoryResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} diff --git a/pkg/models/shared/myfundlimitsservicelistresponse.go b/pkg/models/shared/myfundlimitsservicelistresponse.go new file mode 100644 index 000000000..1516a0a51 --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceListResponse message. +type MyFundLimitsServiceListResponse struct { + // The list field. + List []MyFundLimit `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (m *MyFundLimitsServiceListResponse) GetList() []MyFundLimit { + if m == nil { + return nil + } + return m.List +} + +func (m *MyFundLimitsServiceListResponse) GetNextPageToken() *string { + if m == nil { + return nil + } + return m.NextPageToken +} diff --git a/pkg/models/shared/myfundlimitsservicepauserequest.go b/pkg/models/shared/myfundlimitsservicepauserequest.go new file mode 100644 index 000000000..27d7555ef --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicepauserequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServicePauseRequest message. +type MyFundLimitsServicePauseRequest struct { + // The reason field. + Reason *string `json:"reason,omitempty"` +} + +func (m *MyFundLimitsServicePauseRequest) GetReason() *string { + if m == nil { + return nil + } + return m.Reason +} diff --git a/pkg/models/shared/myfundlimitsservicepauseresponse.go b/pkg/models/shared/myfundlimitsservicepauseresponse.go new file mode 100644 index 000000000..1c768782c --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicepauseresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServicePauseResponse message. +type MyFundLimitsServicePauseResponse struct { + Limit *MyFundLimit `json:"limit,omitempty"` +} + +func (m *MyFundLimitsServicePauseResponse) GetLimit() *MyFundLimit { + if m == nil { + return nil + } + return m.Limit +} diff --git a/pkg/models/shared/myfundlimitsserviceresumerequest.go b/pkg/models/shared/myfundlimitsserviceresumerequest.go new file mode 100644 index 000000000..45cd18704 --- /dev/null +++ b/pkg/models/shared/myfundlimitsserviceresumerequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceResumeRequest message. +type MyFundLimitsServiceResumeRequest struct { +} diff --git a/pkg/models/shared/myfundlimitsserviceresumeresponse.go b/pkg/models/shared/myfundlimitsserviceresumeresponse.go new file mode 100644 index 000000000..2578998a8 --- /dev/null +++ b/pkg/models/shared/myfundlimitsserviceresumeresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceResumeResponse message. +type MyFundLimitsServiceResumeResponse struct { + Limit *MyFundLimit `json:"limit,omitempty"` +} + +func (m *MyFundLimitsServiceResumeResponse) GetLimit() *MyFundLimit { + if m == nil { + return nil + } + return m.Limit +} diff --git a/pkg/models/shared/myfundlimitsservicesetlimitrequest.go b/pkg/models/shared/myfundlimitsservicesetlimitrequest.go new file mode 100644 index 000000000..9b05001a3 --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicesetlimitrequest.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// MyFundLimitsServiceSetLimitRequestPeriod - Optional period override. Only valid together with the limit it denominates. +type MyFundLimitsServiceSetLimitRequestPeriod string + +const ( + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindUnspecified MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_UNSPECIFIED" + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindDaily MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_DAILY" + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindWeekly MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_WEEKLY" + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindMonthly MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_MONTHLY" + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindQuarterly MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_QUARTERLY" + MyFundLimitsServiceSetLimitRequestPeriodPeriodKindYearly MyFundLimitsServiceSetLimitRequestPeriod = "PERIOD_KIND_YEARLY" +) + +func (e MyFundLimitsServiceSetLimitRequestPeriod) ToPointer() *MyFundLimitsServiceSetLimitRequestPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *MyFundLimitsServiceSetLimitRequestPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// The MyFundLimitsServiceSetLimitRequest message. +type MyFundLimitsServiceSetLimitRequest struct { + Limit *SpendLimit `json:"limit,omitempty"` + // Optional period override. Only valid together with the limit it denominates. + Period *MyFundLimitsServiceSetLimitRequestPeriod `json:"period,omitempty"` +} + +func (m *MyFundLimitsServiceSetLimitRequest) GetLimit() *SpendLimit { + if m == nil { + return nil + } + return m.Limit +} + +func (m *MyFundLimitsServiceSetLimitRequest) GetPeriod() *MyFundLimitsServiceSetLimitRequestPeriod { + if m == nil { + return nil + } + return m.Period +} diff --git a/pkg/models/shared/myfundlimitsservicesetlimitresponse.go b/pkg/models/shared/myfundlimitsservicesetlimitresponse.go new file mode 100644 index 000000000..5e6e0a303 --- /dev/null +++ b/pkg/models/shared/myfundlimitsservicesetlimitresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The MyFundLimitsServiceSetLimitResponse message. +type MyFundLimitsServiceSetLimitResponse struct { + Limit *MyFundLimit `json:"limit,omitempty"` +} + +func (m *MyFundLimitsServiceSetLimitResponse) GetLimit() *MyFundLimit { + if m == nil { + return nil + } + return m.Limit +} diff --git a/pkg/models/shared/notifydispatcher.go b/pkg/models/shared/notifydispatcher.go new file mode 100644 index 000000000..bb7e9cd29 --- /dev/null +++ b/pkg/models/shared/notifydispatcher.go @@ -0,0 +1,70 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// DetailLevel - How much the notification reveals. Defaults to SUMMARY. +type DetailLevel string + +const ( + DetailLevelFindingNotifyDetailLevelUnspecified DetailLevel = "FINDING_NOTIFY_DETAIL_LEVEL_UNSPECIFIED" + DetailLevelFindingNotifyDetailLevelSummary DetailLevel = "FINDING_NOTIFY_DETAIL_LEVEL_SUMMARY" + DetailLevelFindingNotifyDetailLevelFullDetail DetailLevel = "FINDING_NOTIFY_DETAIL_LEVEL_FULL_DETAIL" +) + +func (e DetailLevel) ToPointer() *DetailLevel { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DetailLevel) IsExact() bool { + if e != nil { + switch *e { + case "FINDING_NOTIFY_DETAIL_LEVEL_UNSPECIFIED", "FINDING_NOTIFY_DETAIL_LEVEL_SUMMARY", "FINDING_NOTIFY_DETAIL_LEVEL_FULL_DETAIL": + return true + } + } + return false +} + +// NotifyDispatcher emits a notifications_v2 notification about the matched +// +// finding. Exactly one of audience / slack_channel is set: audience notifies +// people (each on whichever channels they enabled in their own notification +// settings), slack_channel posts to one channel. +type NotifyDispatcher struct { + Audience *FindingAudience `json:"audience,omitempty"` + // Wait-group window in seconds; 0 sends immediately. A quiet-period length, + // not a fixed delay — the batcher slides it forward on each arrival. + BatchWindowSeconds *int64 `json:"batchWindowSeconds,omitempty"` + // How much the notification reveals. Defaults to SUMMARY. + DetailLevel *DetailLevel `json:"detailLevel,omitempty"` + SlackChannel *SlackChannelTarget `json:"slackChannel,omitempty"` +} + +func (n *NotifyDispatcher) GetAudience() *FindingAudience { + if n == nil { + return nil + } + return n.Audience +} + +func (n *NotifyDispatcher) GetBatchWindowSeconds() *int64 { + if n == nil { + return nil + } + return n.BatchWindowSeconds +} + +func (n *NotifyDispatcher) GetDetailLevel() *DetailLevel { + if n == nil { + return nil + } + return n.DetailLevel +} + +func (n *NotifyDispatcher) GetSlackChannel() *SlackChannelTarget { + if n == nil { + return nil + } + return n.SlackChannel +} diff --git a/pkg/models/shared/oidcclaimmapping.go b/pkg/models/shared/oidcclaimmapping.go new file mode 100644 index 000000000..0f00c95be --- /dev/null +++ b/pkg/models/shared/oidcclaimmapping.go @@ -0,0 +1,62 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Destination - Where the claim is released. +type Destination string + +const ( + DestinationOidcClaimDestinationUnspecified Destination = "OIDC_CLAIM_DESTINATION_UNSPECIFIED" + DestinationOidcClaimDestinationIDTokenOnly Destination = "OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY" + DestinationOidcClaimDestinationUserinfoOnly Destination = "OIDC_CLAIM_DESTINATION_USERINFO_ONLY" +) + +func (e Destination) ToPointer() *Destination { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Destination) IsExact() bool { + if e != nil { + switch *e { + case "OIDC_CLAIM_DESTINATION_UNSPECIFIED", "OIDC_CLAIM_DESTINATION_ID_TOKEN_ONLY", "OIDC_CLAIM_DESTINATION_USERINFO_ONLY": + return true + } + } + return false +} + +// OIDCClaimMapping releases one user attribute to the application as one +// +// OIDC claim. +type OIDCClaimMapping struct { + // The name of the claim as the application sees it. Namespace custom claims + // so they cannot collide with the registered OIDC claim set. + ClaimName string `json:"claimName"` + // Where the claim is released. + Destination *Destination `json:"destination,omitempty"` + // The user attribute mapping that resolves the value, including its fallback + // chain. + UserAttributeMappingID string `json:"userAttributeMappingId"` +} + +func (o *OIDCClaimMapping) GetClaimName() string { + if o == nil { + return "" + } + return o.ClaimName +} + +func (o *OIDCClaimMapping) GetDestination() *Destination { + if o == nil { + return nil + } + return o.Destination +} + +func (o *OIDCClaimMapping) GetUserAttributeMappingID() string { + if o == nil { + return "" + } + return o.UserAttributeMappingID +} diff --git a/pkg/models/shared/payloadfindingdispatch.go b/pkg/models/shared/payloadfindingdispatch.go new file mode 100644 index 000000000..81fef8390 --- /dev/null +++ b/pkg/models/shared/payloadfindingdispatch.go @@ -0,0 +1,52 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The PayloadFindingDispatch message. +type PayloadFindingDispatch struct { + // The FindingDispatch row recording this execution. + DispatchID *string `json:"dispatchId,omitempty"` + Finding *Finding `json:"finding,omitempty"` + // The finding that matched the routing rule. + FindingID *string `json:"findingId,omitempty"` + // The dispatcher's rendered payload template. Empty when the dispatcher used + // the default finding payload. + PayloadTemplate *string `json:"payloadTemplate,omitempty"` + // The routing rule whose match caused this dispatch. + RuleID *string `json:"ruleId,omitempty"` +} + +func (p *PayloadFindingDispatch) GetDispatchID() *string { + if p == nil { + return nil + } + return p.DispatchID +} + +func (p *PayloadFindingDispatch) GetFinding() *Finding { + if p == nil { + return nil + } + return p.Finding +} + +func (p *PayloadFindingDispatch) GetFindingID() *string { + if p == nil { + return nil + } + return p.FindingID +} + +func (p *PayloadFindingDispatch) GetPayloadTemplate() *string { + if p == nil { + return nil + } + return p.PayloadTemplate +} + +func (p *PayloadFindingDispatch) GetRuleID() *string { + if p == nil { + return nil + } + return p.RuleID +} diff --git a/pkg/models/shared/policy.go b/pkg/models/shared/policy.go index 7a65fa4a9..3a233f17a 100644 --- a/pkg/models/shared/policy.go +++ b/pkg/models/shared/policy.go @@ -51,8 +51,16 @@ type Policy struct { // Well-known keys: `managed_by`, `iac_workspace`, // `iac_resource_address`, `iac_tool_version`. Annotations map[string]string `json:"annotations,omitempty"` - CreatedAt *time.Time `json:"createdAt,omitempty"` - DeletedAt *time.Time `json:"deletedAt,omitempty"` + // When set, the baseline defers to another policy of the same type when no + // rule matches, instead of the baseline entry in policy_steps (keyed by the + // lowercased policy_type). Mutually exclusive with that baseline entry: set + // one or the other, not both. The referenced policy must share this + // policy's policy_type, must not introduce a cycle or self-reference, and + // must not push any reachable chain over depth 5. Gated by the + // POLICY_REFERENCES_POLICY feature flag. + BaselinePolicyID *string `json:"baselinePolicyId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` // The description of the Policy. Description *string `json:"description,omitempty"` // The display name of the Policy. @@ -77,7 +85,8 @@ type Policy struct { // Ordered conditional routing rules. Evaluated top-to-bottom; the first // matching rule selects a step sequence from policy_steps. If no rule matches // (or if this array is empty), the baseline entry in policy_steps is used. - Rules []Rule `json:"rules,omitempty"` + Rules []Rule `json:"rules,omitempty"` + Scope *PolicyScope `json:"scope,omitempty"` // Whether this policy is a builtin system policy. Builtin system policies cannot be edited. SystemBuiltin *bool `json:"systemBuiltin,omitempty"` UpdatedAt *time.Time `json:"updatedAt,omitempty"` @@ -101,6 +110,13 @@ func (p *Policy) GetAnnotations() map[string]string { return p.Annotations } +func (p *Policy) GetBaselinePolicyID() *string { + if p == nil { + return nil + } + return p.BaselinePolicyID +} + func (p *Policy) GetCreatedAt() *time.Time { if p == nil { return nil @@ -171,6 +187,13 @@ func (p *Policy) GetRules() []Rule { return p.Rules } +func (p *Policy) GetScope() *PolicyScope { + if p == nil { + return nil + } + return p.Scope +} + func (p *Policy) GetSystemBuiltin() *bool { if p == nil { return nil @@ -200,6 +223,14 @@ type PolicyInput struct { // Well-known keys: `managed_by`, `iac_workspace`, // `iac_resource_address`, `iac_tool_version`. Annotations map[string]string `json:"annotations,omitempty"` + // When set, the baseline defers to another policy of the same type when no + // rule matches, instead of the baseline entry in policy_steps (keyed by the + // lowercased policy_type). Mutually exclusive with that baseline entry: set + // one or the other, not both. The referenced policy must share this + // policy's policy_type, must not introduce a cycle or self-reference, and + // must not push any reachable chain over depth 5. Gated by the + // POLICY_REFERENCES_POLICY feature flag. + BaselinePolicyID *string `json:"baselinePolicyId,omitempty"` // The description of the Policy. Description *string `json:"description,omitempty"` // The display name of the Policy. @@ -222,7 +253,8 @@ type PolicyInput struct { // Ordered conditional routing rules. Evaluated top-to-bottom; the first // matching rule selects a step sequence from policy_steps. If no rule matches // (or if this array is empty), the baseline entry in policy_steps is used. - Rules []Rule `json:"rules,omitempty"` + Rules []Rule `json:"rules,omitempty"` + Scope *PolicyScope `json:"scope,omitempty"` } func (p *PolicyInput) GetAnnotations() map[string]string { @@ -232,6 +264,13 @@ func (p *PolicyInput) GetAnnotations() map[string]string { return p.Annotations } +func (p *PolicyInput) GetBaselinePolicyID() *string { + if p == nil { + return nil + } + return p.BaselinePolicyID +} + func (p *PolicyInput) GetDescription() *string { if p == nil { return nil @@ -280,3 +319,10 @@ func (p *PolicyInput) GetRules() []Rule { } return p.Rules } + +func (p *PolicyInput) GetScope() *PolicyScope { + if p == nil { + return nil + } + return p.Scope +} diff --git a/pkg/models/shared/policyscope.go b/pkg/models/shared/policyscope.go new file mode 100644 index 000000000..629f2fef5 --- /dev/null +++ b/pkg/models/shared/policyscope.go @@ -0,0 +1,61 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Slot - Which of the object's local-policy slots this policy occupies. Part of the +// +// scope, and immutable with it. +type Slot string + +const ( + SlotPolicyScopeSlotUnspecified Slot = "POLICY_SCOPE_SLOT_UNSPECIFIED" + SlotPolicyScopeSlotEmergency Slot = "POLICY_SCOPE_SLOT_EMERGENCY" +) + +func (e Slot) ToPointer() *Slot { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Slot) IsExact() bool { + if e != nil { + switch *e { + case "POLICY_SCOPE_SLOT_UNSPECIFIED", "POLICY_SCOPE_SLOT_EMERGENCY": + return true + } + } + return false +} + +// PolicyScope - Scopes a policy to an app or to a single entitlement within an app. +type PolicyScope struct { + // Optional. When set, the policy is scoped to this entitlement of app_id + // rather than to the whole app. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The ID of the app this policy is scoped to. + AppID *string `json:"appId,omitempty"` + // Which of the object's local-policy slots this policy occupies. Part of the + // scope, and immutable with it. + Slot *Slot `json:"slot,omitempty"` +} + +func (p *PolicyScope) GetAppEntitlementID() *string { + if p == nil { + return nil + } + return p.AppEntitlementID +} + +func (p *PolicyScope) GetAppID() *string { + if p == nil { + return nil + } + return p.AppID +} + +func (p *PolicyScope) GetSlot() *Slot { + if p == nil { + return nil + } + return p.Slot +} diff --git a/pkg/models/shared/pretoolblockconfig.go b/pkg/models/shared/pretoolblockconfig.go new file mode 100644 index 000000000..cf874cf3a --- /dev/null +++ b/pkg/models/shared/pretoolblockconfig.go @@ -0,0 +1,19 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// PreToolBlockConfig unconditionally denies the tool call before it executes +// +// when its hook's filter matches. Only valid for HOOK_EVENT_TYPE_PRE_TOOL_USE. +type PreToolBlockConfig struct { + // Message shown when the tool call is denied. Empty falls back to a + // generic default. + Message *string `json:"message,omitempty"` +} + +func (p *PreToolBlockConfig) GetMessage() *string { + if p == nil { + return nil + } + return p.Message +} diff --git a/pkg/models/shared/programref.go b/pkg/models/shared/programref.go new file mode 100644 index 000000000..a2f5d98b3 --- /dev/null +++ b/pkg/models/shared/programref.go @@ -0,0 +1,38 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// ProgramRef points at a pinned, executable program. +type ProgramRef struct { + // Code mode invokes by explicit commit, so the commit — not the function — is + // what a refresh re-executes. + CommitID *string `json:"commitId,omitempty"` + // A saved report owns its Function, so this is per-report rather than the + // shared code-mode scratch function the program first ran on. + FunctionID *string `json:"functionId,omitempty"` + // The prompt this program was planned from. Report.prompt is editable and a + // refresh never re-plans, so this is the only way to detect that a report's + // question has drifted from the program answering it. + PlannedFromPrompt *string `json:"plannedFromPrompt,omitempty"` +} + +func (p *ProgramRef) GetCommitID() *string { + if p == nil { + return nil + } + return p.CommitID +} + +func (p *ProgramRef) GetFunctionID() *string { + if p == nil { + return nil + } + return p.FunctionID +} + +func (p *ProgramRef) GetPlannedFromPrompt() *string { + if p == nil { + return nil + } + return p.PlannedFromPrompt +} diff --git a/pkg/models/shared/promoteappmanagedstatebindingrequest.go b/pkg/models/shared/promoteappmanagedstatebindingrequest.go new file mode 100644 index 000000000..811229501 --- /dev/null +++ b/pkg/models/shared/promoteappmanagedstatebindingrequest.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// PromoteAppManagedStateBindingRequest identifies an unmanaged application and configures its owners. +type PromoteAppManagedStateBindingRequest struct { + // Entitlements to assign as owners of the new application. + AppEntitlementOwnerRefs []AppEntitlementRef `json:"appEntitlementOwnerRefs,omitempty"` + ExpandMask *AppManagedStateBindingExpandMask `json:"expandMask,omitempty"` + // User IDs to assign as owners of the new application. + // If omitted, the application inherits the owners of the source connector application. + UserIds []string `json:"userIds,omitempty"` +} + +func (p *PromoteAppManagedStateBindingRequest) GetAppEntitlementOwnerRefs() []AppEntitlementRef { + if p == nil { + return nil + } + return p.AppEntitlementOwnerRefs +} + +func (p *PromoteAppManagedStateBindingRequest) GetExpandMask() *AppManagedStateBindingExpandMask { + if p == nil { + return nil + } + return p.ExpandMask +} + +func (p *PromoteAppManagedStateBindingRequest) GetUserIds() []string { + if p == nil { + return nil + } + return p.UserIds +} diff --git a/pkg/models/shared/promptinjectionscanconfig.go b/pkg/models/shared/promptinjectionscanconfig.go new file mode 100644 index 000000000..eb61e89b3 --- /dev/null +++ b/pkg/models/shared/promptinjectionscanconfig.go @@ -0,0 +1,55 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Threshold - Deny (or flag) when the judge scores at or above this level. Unspecified = +// +// HIGH. +type Threshold string + +const ( + ThresholdPromptInjectionThresholdUnspecified Threshold = "PROMPT_INJECTION_THRESHOLD_UNSPECIFIED" + ThresholdPromptInjectionThresholdLow Threshold = "PROMPT_INJECTION_THRESHOLD_LOW" + ThresholdPromptInjectionThresholdMedium Threshold = "PROMPT_INJECTION_THRESHOLD_MEDIUM" + ThresholdPromptInjectionThresholdHigh Threshold = "PROMPT_INJECTION_THRESHOLD_HIGH" +) + +func (e Threshold) ToPointer() *Threshold { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Threshold) IsExact() bool { + if e != nil { + switch *e { + case "PROMPT_INJECTION_THRESHOLD_UNSPECIFIED", "PROMPT_INJECTION_THRESHOLD_LOW", "PROMPT_INJECTION_THRESHOLD_MEDIUM", "PROMPT_INJECTION_THRESHOLD_HIGH": + return true + } + } + return false +} + +// PromptInjectionScanConfig scans tool output for prompt-injection using the +// +// aigov A2 judge and acts when the verdict is at or above threshold. +type PromptInjectionScanConfig struct { + // When true, a detection records the finding but does not deny (observe-only). + FlagOnly *bool `json:"flagOnly,omitempty"` + // Deny (or flag) when the judge scores at or above this level. Unspecified = + // HIGH. + Threshold *Threshold `json:"threshold,omitempty"` +} + +func (p *PromptInjectionScanConfig) GetFlagOnly() *bool { + if p == nil { + return nil + } + return p.FlagOnly +} + +func (p *PromptInjectionScanConfig) GetThreshold() *Threshold { + if p == nil { + return nil + } + return p.Threshold +} diff --git a/pkg/models/shared/providercredential.go b/pkg/models/shared/providercredential.go new file mode 100644 index 000000000..0941f4379 --- /dev/null +++ b/pkg/models/shared/providercredential.go @@ -0,0 +1,116 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// HeaderStyle - The headerStyle field. +type HeaderStyle string + +const ( + HeaderStyleProviderCredentialHeaderStyleUnspecified HeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED" + HeaderStyleProviderCredentialHeaderStyleXAPIKey HeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY" + HeaderStyleProviderCredentialHeaderStyleAuthorizationBearer HeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER" +) + +func (e HeaderStyle) ToPointer() *HeaderStyle { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *HeaderStyle) IsExact() bool { + if e != nil { + switch *e { + case "PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED", "PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY", "PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER": + return true + } + } + return false +} + +// The ProviderCredential message. +type ProviderCredential struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The headerStyle field. + HeaderStyle *HeaderStyle `json:"headerStyle,omitempty"` + // The keyPrefix field. + KeyPrefix *string `json:"keyPrefix,omitempty"` + RevokedAt *time.Time `json:"revokedAt,omitempty"` + // The slotId field. + SlotID *string `json:"slotId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` + // The userId field. + UserID *string `json:"userId,omitempty"` +} + +func (p ProviderCredential) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(p, "", false) +} + +func (p *ProviderCredential) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &p, "", false, nil); err != nil { + return err + } + return nil +} + +func (p *ProviderCredential) GetCreatedAt() *time.Time { + if p == nil { + return nil + } + return p.CreatedAt +} + +func (p *ProviderCredential) GetDisplayName() *string { + if p == nil { + return nil + } + return p.DisplayName +} + +func (p *ProviderCredential) GetHeaderStyle() *HeaderStyle { + if p == nil { + return nil + } + return p.HeaderStyle +} + +func (p *ProviderCredential) GetKeyPrefix() *string { + if p == nil { + return nil + } + return p.KeyPrefix +} + +func (p *ProviderCredential) GetRevokedAt() *time.Time { + if p == nil { + return nil + } + return p.RevokedAt +} + +func (p *ProviderCredential) GetSlotID() *string { + if p == nil { + return nil + } + return p.SlotID +} + +func (p *ProviderCredential) GetUpdatedAt() *time.Time { + if p == nil { + return nil + } + return p.UpdatedAt +} + +func (p *ProviderCredential) GetUserID() *string { + if p == nil { + return nil + } + return p.UserID +} diff --git a/pkg/models/shared/provisioninstance.go b/pkg/models/shared/provisioninstance.go index 7698220e1..c346789f5 100644 --- a/pkg/models/shared/provisioninstance.go +++ b/pkg/models/shared/provisioninstance.go @@ -17,6 +17,7 @@ const ( ProvisionInstanceStateProvisionInstanceStateExternalTicketWaiting ProvisionInstanceState = "PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING" ProvisionInstanceStateProvisionInstanceStateAccountLifecycleActions ProvisionInstanceState = "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS" ProvisionInstanceStateProvisionInstanceStateAccountLifecycleActionsWaiting ProvisionInstanceState = "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING" + ProvisionInstanceStateProvisionInstanceStateDevicePlacement ProvisionInstanceState = "PROVISION_INSTANCE_STATE_DEVICE_PLACEMENT" ProvisionInstanceStateProvisionInstanceStateDone ProvisionInstanceState = "PROVISION_INSTANCE_STATE_DONE" ) @@ -28,7 +29,7 @@ func (e ProvisionInstanceState) ToPointer() *ProvisionInstanceState { func (e *ProvisionInstanceState) IsExact() bool { if e != nil { switch *e { - case "PROVISION_INSTANCE_STATE_UNSPECIFIED", "PROVISION_INSTANCE_STATE_INIT", "PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET", "PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS", "PROVISION_INSTANCE_STATE_WAITING", "PROVISION_INSTANCE_STATE_WEBHOOK", "PROVISION_INSTANCE_STATE_WEBHOOK_WAITING", "PROVISION_INSTANCE_STATE_EXTERNAL_TICKET", "PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING", "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS", "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING", "PROVISION_INSTANCE_STATE_DONE": + case "PROVISION_INSTANCE_STATE_UNSPECIFIED", "PROVISION_INSTANCE_STATE_INIT", "PROVISION_INSTANCE_STATE_CREATE_CONNECTOR_ACTIONS_FOR_TARGET", "PROVISION_INSTANCE_STATE_SENDING_NOTIFICATIONS", "PROVISION_INSTANCE_STATE_WAITING", "PROVISION_INSTANCE_STATE_WEBHOOK", "PROVISION_INSTANCE_STATE_WEBHOOK_WAITING", "PROVISION_INSTANCE_STATE_EXTERNAL_TICKET", "PROVISION_INSTANCE_STATE_EXTERNAL_TICKET_WAITING", "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS", "PROVISION_INSTANCE_STATE_ACCOUNT_LIFECYCLE_ACTIONS_WAITING", "PROVISION_INSTANCE_STATE_DEVICE_PLACEMENT", "PROVISION_INSTANCE_STATE_DONE": return true } } @@ -59,7 +60,8 @@ type ProvisionInstance struct { ReassignedByError *ReassignedByErrorAction `json:"reassignedByError,omitempty"` Skipped *SkippedAction `json:"skipped,omitempty"` // This property indicates the current state of this step. - State *ProvisionInstanceState `json:"state,omitempty"` + State *ProvisionInstanceState `json:"state,omitempty"` + WaitingOn *ProvisionWaitingOn `json:"waitingOn,omitempty"` // This indicates the webhook id for this step. WebhookID *string `json:"webhookId,omitempty"` // This indicates the webhook instance id for this step. @@ -143,6 +145,13 @@ func (p *ProvisionInstance) GetState() *ProvisionInstanceState { return p.State } +func (p *ProvisionInstance) GetWaitingOn() *ProvisionWaitingOn { + if p == nil { + return nil + } + return p.WaitingOn +} + func (p *ProvisionInstance) GetWebhookID() *string { if p == nil { return nil diff --git a/pkg/models/shared/provisionpolicy.go b/pkg/models/shared/provisionpolicy.go index 7d2d1e5f7..1b1024fee 100644 --- a/pkg/models/shared/provisionpolicy.go +++ b/pkg/models/shared/provisionpolicy.go @@ -13,15 +13,17 @@ package shared // - externalTicket // - unconfigured // - action +// - devicePlacement type ProvisionPolicy struct { - Action *ActionProvision `json:"action,omitempty"` - Connector *ConnectorProvision `json:"connector,omitempty"` - Delegated *DelegatedProvision `json:"delegated,omitempty"` - ExternalTicket *ExternalTicketProvision `json:"externalTicket,omitempty"` - Manual *ManualProvision `json:"manual,omitempty"` - MultiStep *MultiStep `json:"multiStep,omitempty"` - Unconfigured *UnconfiguredProvision `json:"unconfigured,omitempty"` - Webhook *WebhookProvision `json:"webhook,omitempty"` + Action *ActionProvision `json:"action,omitempty"` + Connector *ConnectorProvision `json:"connector,omitempty"` + Delegated *DelegatedProvision `json:"delegated,omitempty"` + DevicePlacement *DevicePlacementProvision `json:"devicePlacement,omitempty"` + ExternalTicket *ExternalTicketProvision `json:"externalTicket,omitempty"` + Manual *ManualProvision `json:"manual,omitempty"` + MultiStep *MultiStep `json:"multiStep,omitempty"` + Unconfigured *UnconfiguredProvision `json:"unconfigured,omitempty"` + Webhook *WebhookProvision `json:"webhook,omitempty"` } func (p *ProvisionPolicy) GetAction() *ActionProvision { @@ -45,6 +47,13 @@ func (p *ProvisionPolicy) GetDelegated() *DelegatedProvision { return p.Delegated } +func (p *ProvisionPolicy) GetDevicePlacement() *DevicePlacementProvision { + if p == nil { + return nil + } + return p.DevicePlacement +} + func (p *ProvisionPolicy) GetExternalTicket() *ExternalTicketProvision { if p == nil { return nil diff --git a/pkg/models/shared/provisionpolicyinput.go b/pkg/models/shared/provisionpolicyinput.go index 51f0bb755..e35822346 100644 --- a/pkg/models/shared/provisionpolicyinput.go +++ b/pkg/models/shared/provisionpolicyinput.go @@ -13,15 +13,17 @@ package shared // - externalTicket // - unconfigured // - action +// - devicePlacement type ProvisionPolicyInput struct { - Action *ActionProvision `json:"action,omitempty"` - Connector *ConnectorProvision `json:"connector,omitempty"` - Delegated *DelegatedProvision `json:"delegated,omitempty"` - ExternalTicket *ExternalTicketProvision `json:"externalTicket,omitempty"` - Manual *ManualProvision `json:"manual,omitempty"` - MultiStep *MultiStep `json:"multiStep,omitempty"` - Unconfigured *UnconfiguredProvision `json:"unconfigured,omitempty"` - Webhook *WebhookProvision `json:"webhook,omitempty"` + Action *ActionProvision `json:"action,omitempty"` + Connector *ConnectorProvision `json:"connector,omitempty"` + Delegated *DelegatedProvision `json:"delegated,omitempty"` + DevicePlacement *DevicePlacementProvision `json:"devicePlacement,omitempty"` + ExternalTicket *ExternalTicketProvision `json:"externalTicket,omitempty"` + Manual *ManualProvision `json:"manual,omitempty"` + MultiStep *MultiStep `json:"multiStep,omitempty"` + Unconfigured *UnconfiguredProvision `json:"unconfigured,omitempty"` + Webhook *WebhookProvision `json:"webhook,omitempty"` } func (p *ProvisionPolicyInput) GetAction() *ActionProvision { @@ -45,6 +47,13 @@ func (p *ProvisionPolicyInput) GetDelegated() *DelegatedProvision { return p.Delegated } +func (p *ProvisionPolicyInput) GetDevicePlacement() *DevicePlacementProvision { + if p == nil { + return nil + } + return p.DevicePlacement +} + func (p *ProvisionPolicyInput) GetExternalTicket() *ExternalTicketProvision { if p == nil { return nil diff --git a/pkg/models/shared/provisionwaitingon.go b/pkg/models/shared/provisionwaitingon.go new file mode 100644 index 000000000..5b1c79ac7 --- /dev/null +++ b/pkg/models/shared/provisionwaitingon.go @@ -0,0 +1,59 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// ProvisionWaitingOn - Describes why a provision step is paused in the WAITING state. +// +// This message contains a oneof named kind. Only a single field of the following list may be set at a time: +// - entitlementMerge +// - devicePlacement +type ProvisionWaitingOn struct { + DevicePlacement *WaitingForDevicePlacement `json:"devicePlacement,omitempty"` + EntitlementMerge *WaitingForEntitlementMerge `json:"entitlementMerge,omitempty"` + FallbackAt *time.Time `json:"fallbackAt,omitempty"` + StartedWaitingAt *time.Time `json:"startedWaitingAt,omitempty"` +} + +func (p ProvisionWaitingOn) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(p, "", false) +} + +func (p *ProvisionWaitingOn) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &p, "", false, nil); err != nil { + return err + } + return nil +} + +func (p *ProvisionWaitingOn) GetDevicePlacement() *WaitingForDevicePlacement { + if p == nil { + return nil + } + return p.DevicePlacement +} + +func (p *ProvisionWaitingOn) GetEntitlementMerge() *WaitingForEntitlementMerge { + if p == nil { + return nil + } + return p.EntitlementMerge +} + +func (p *ProvisionWaitingOn) GetFallbackAt() *time.Time { + if p == nil { + return nil + } + return p.FallbackAt +} + +func (p *ProvisionWaitingOn) GetStartedWaitingAt() *time.Time { + if p == nil { + return nil + } + return p.StartedWaitingAt +} diff --git a/pkg/models/shared/recurrencerule.go b/pkg/models/shared/recurrencerule.go index 46a116ae1..df7339a2f 100644 --- a/pkg/models/shared/recurrencerule.go +++ b/pkg/models/shared/recurrencerule.go @@ -7,7 +7,9 @@ import ( "time" ) -// RecurrenceRuleFrequency - The frequency field. +// RecurrenceRuleFrequency - Frequency of the recurrence: FREQUENCY_DAILY, FREQUENCY_WEEKLY, FREQUENCY_MONTHLY, or FREQUENCY_YEARLY. +// +// Use FREQUENCY_NONE for a non-recurring schedule. type RecurrenceRuleFrequency string const ( @@ -41,8 +43,9 @@ func (e *RecurrenceRuleFrequency) IsExact() bool { // - occurrences type RecurrenceRule struct { EndDate *time.Time `json:"endDate,omitempty"` - // The frequency field. - Frequency *RecurrenceRuleFrequency `json:"frequency,omitempty"` + // Frequency of the recurrence: FREQUENCY_DAILY, FREQUENCY_WEEKLY, FREQUENCY_MONTHLY, or FREQUENCY_YEARLY. + // Use FREQUENCY_NONE for a non-recurring schedule. + Frequency RecurrenceRuleFrequency `json:"frequency"` // The interval field. Interval *int `json:"interval,omitempty"` // The occurrences field. @@ -70,9 +73,9 @@ func (r *RecurrenceRule) GetEndDate() *time.Time { return r.EndDate } -func (r *RecurrenceRule) GetFrequency() *RecurrenceRuleFrequency { +func (r *RecurrenceRule) GetFrequency() RecurrenceRuleFrequency { if r == nil { - return nil + return RecurrenceRuleFrequency("") } return r.Frequency } diff --git a/pkg/models/shared/report.go b/pkg/models/shared/report.go new file mode 100644 index 000000000..90a3e9333 --- /dev/null +++ b/pkg/models/shared/report.go @@ -0,0 +1,137 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// Report is a saved report: the question, the program that answers it, and the +// +// parameters a re-run may vary. +type Report struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + // The createdByUserId field. + CreatedByUserID *string `json:"createdByUserId,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The id field. + ID *string `json:"id,omitempty"` + // Separate pointers: the last attempt may have failed while callers still need + // the last renderable result. + LatestRunID *string `json:"latestRunId,omitempty"` + // The latestSuccessfulRunId field. + LatestSuccessfulRunID *string `json:"latestSuccessfulRunId,omitempty"` + ParameterSchema map[string]any `json:"parameterSchema,omitempty"` + ParameterValues map[string]any `json:"parameterValues,omitempty"` + Program *ProgramRef `json:"program,omitempty"` + // The editable natural-language question. Only a re-plan reads this. + Prompt *string `json:"prompt,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (r Report) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(r, "", false) +} + +func (r *Report) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &r, "", false, nil); err != nil { + return err + } + return nil +} + +func (r *Report) GetCreatedAt() *time.Time { + if r == nil { + return nil + } + return r.CreatedAt +} + +func (r *Report) GetCreatedByUserID() *string { + if r == nil { + return nil + } + return r.CreatedByUserID +} + +func (r *Report) GetDeletedAt() *time.Time { + if r == nil { + return nil + } + return r.DeletedAt +} + +func (r *Report) GetDisplayName() *string { + if r == nil { + return nil + } + return r.DisplayName +} + +func (r *Report) GetID() *string { + if r == nil { + return nil + } + return r.ID +} + +func (r *Report) GetLatestRunID() *string { + if r == nil { + return nil + } + return r.LatestRunID +} + +func (r *Report) GetLatestSuccessfulRunID() *string { + if r == nil { + return nil + } + return r.LatestSuccessfulRunID +} + +func (r *Report) GetParameterSchema() map[string]any { + if r == nil { + return nil + } + return r.ParameterSchema +} + +func (r *Report) GetParameterValues() map[string]any { + if r == nil { + return nil + } + return r.ParameterValues +} + +func (r *Report) GetProgram() *ProgramRef { + if r == nil { + return nil + } + return r.Program +} + +func (r *Report) GetPrompt() *string { + if r == nil { + return nil + } + return r.Prompt +} + +func (r *Report) GetTenantID() *string { + if r == nil { + return nil + } + return r.TenantID +} + +func (r *Report) GetUpdatedAt() *time.Time { + if r == nil { + return nil + } + return r.UpdatedAt +} diff --git a/pkg/models/shared/reportingservicedeleterequest.go b/pkg/models/shared/reportingservicedeleterequest.go new file mode 100644 index 000000000..1575efbc8 --- /dev/null +++ b/pkg/models/shared/reportingservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceDeleteRequest message. +type ReportingServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/reportingservicedeleteresponse.go b/pkg/models/shared/reportingservicedeleteresponse.go new file mode 100644 index 000000000..d1ab6d569 --- /dev/null +++ b/pkg/models/shared/reportingservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceDeleteResponse message. +type ReportingServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/reportingservicegetresponse.go b/pkg/models/shared/reportingservicegetresponse.go new file mode 100644 index 000000000..fc0babbb7 --- /dev/null +++ b/pkg/models/shared/reportingservicegetresponse.go @@ -0,0 +1,42 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceGetResponse message. +type ReportingServiceGetResponse struct { + LatestRun *ReportRun `json:"latestRun,omitempty"` + LatestSuccessfulRun *ReportRun `json:"latestSuccessfulRun,omitempty"` + // True when prompt no longer matches program.planned_from_prompt. A rerun + // re-executes and never re-plans, so an edited question leaves the program + // answering the old one. + PromptDrifted *bool `json:"promptDrifted,omitempty"` + Report *Report `json:"report,omitempty"` +} + +func (r *ReportingServiceGetResponse) GetLatestRun() *ReportRun { + if r == nil { + return nil + } + return r.LatestRun +} + +func (r *ReportingServiceGetResponse) GetLatestSuccessfulRun() *ReportRun { + if r == nil { + return nil + } + return r.LatestSuccessfulRun +} + +func (r *ReportingServiceGetResponse) GetPromptDrifted() *bool { + if r == nil { + return nil + } + return r.PromptDrifted +} + +func (r *ReportingServiceGetResponse) GetReport() *Report { + if r == nil { + return nil + } + return r.Report +} diff --git a/pkg/models/shared/reportingservicegetrunprovenanceresponse.go b/pkg/models/shared/reportingservicegetrunprovenanceresponse.go new file mode 100644 index 000000000..c396fe0d4 --- /dev/null +++ b/pkg/models/shared/reportingservicegetrunprovenanceresponse.go @@ -0,0 +1,73 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceGetRunProvenanceResponse message. +type ReportingServiceGetRunProvenanceResponse struct { + // The programCommitId field. + ProgramCommitID *string `json:"programCommitId,omitempty"` + // The programFunctionId field. + ProgramFunctionID *string `json:"programFunctionId,omitempty"` + // The parameters this run was bound to, as JSON. "{}" for a program that + // takes none — a real answer, distinct from absent. + ProgramInput *string `json:"programInput,omitempty"` + // The programSource field. + ProgramSource *string `json:"programSource,omitempty"` + // What each part of the report shows, read off the run's own copy of the + // surface rather than a live one. + Sources []A2UIProvenanceSource `json:"sources,omitempty"` + // What the program looked at, derived from its source. + Steps []A2UIProvenanceStep `json:"steps,omitempty"` + // False when the program's source could not be read, which is what makes an + // empty steps list mean "unknown" rather than "it read nothing". + StepsAvailable *bool `json:"stepsAvailable,omitempty"` +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetProgramCommitID() *string { + if r == nil { + return nil + } + return r.ProgramCommitID +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetProgramFunctionID() *string { + if r == nil { + return nil + } + return r.ProgramFunctionID +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetProgramInput() *string { + if r == nil { + return nil + } + return r.ProgramInput +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetProgramSource() *string { + if r == nil { + return nil + } + return r.ProgramSource +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetSources() []A2UIProvenanceSource { + if r == nil { + return nil + } + return r.Sources +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetSteps() []A2UIProvenanceStep { + if r == nil { + return nil + } + return r.Steps +} + +func (r *ReportingServiceGetRunProvenanceResponse) GetStepsAvailable() *bool { + if r == nil { + return nil + } + return r.StepsAvailable +} diff --git a/pkg/models/shared/reportingservicelistresponse.go b/pkg/models/shared/reportingservicelistresponse.go new file mode 100644 index 000000000..dfbf3b1b5 --- /dev/null +++ b/pkg/models/shared/reportingservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceListResponse message. +type ReportingServiceListResponse struct { + // The list field. + List []Report `json:"list,omitempty"` + // The nextPageToken field. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (r *ReportingServiceListResponse) GetList() []Report { + if r == nil { + return nil + } + return r.List +} + +func (r *ReportingServiceListResponse) GetNextPageToken() *string { + if r == nil { + return nil + } + return r.NextPageToken +} diff --git a/pkg/models/shared/reportingservicerunrequest.go b/pkg/models/shared/reportingservicerunrequest.go new file mode 100644 index 000000000..3920e7bd7 --- /dev/null +++ b/pkg/models/shared/reportingservicerunrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceRunRequest message. +type ReportingServiceRunRequest struct { +} diff --git a/pkg/models/shared/reportingservicerunresponse.go b/pkg/models/shared/reportingservicerunresponse.go new file mode 100644 index 000000000..b9f0f980e --- /dev/null +++ b/pkg/models/shared/reportingservicerunresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceRunResponse message. +type ReportingServiceRunResponse struct { + Run *ReportRun `json:"run,omitempty"` +} + +func (r *ReportingServiceRunResponse) GetRun() *ReportRun { + if r == nil { + return nil + } + return r.Run +} diff --git a/pkg/models/shared/reportingservicesaverequest.go b/pkg/models/shared/reportingservicesaverequest.go new file mode 100644 index 000000000..e80fe9632 --- /dev/null +++ b/pkg/models/shared/reportingservicesaverequest.go @@ -0,0 +1,46 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceSaveRequest message. +type ReportingServiceSaveRequest struct { + // The conversation and surface are both required to address a rendered + // surface; neither identifies one alone. + ConversationID *string `json:"conversationId,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The question this surface answered. The surface records its program but not + // the words behind it, so the caller supplies them; without it the report has + // nothing to compare against when deciding its program has gone stale. + Prompt *string `json:"prompt,omitempty"` + // The surfaceId field. + SurfaceID *string `json:"surfaceId,omitempty"` +} + +func (r *ReportingServiceSaveRequest) GetConversationID() *string { + if r == nil { + return nil + } + return r.ConversationID +} + +func (r *ReportingServiceSaveRequest) GetDisplayName() *string { + if r == nil { + return nil + } + return r.DisplayName +} + +func (r *ReportingServiceSaveRequest) GetPrompt() *string { + if r == nil { + return nil + } + return r.Prompt +} + +func (r *ReportingServiceSaveRequest) GetSurfaceID() *string { + if r == nil { + return nil + } + return r.SurfaceID +} diff --git a/pkg/models/shared/reportingservicesaveresponse.go b/pkg/models/shared/reportingservicesaveresponse.go new file mode 100644 index 000000000..e3e38ba36 --- /dev/null +++ b/pkg/models/shared/reportingservicesaveresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceSaveResponse message. +type ReportingServiceSaveResponse struct { + Report *Report `json:"report,omitempty"` +} + +func (r *ReportingServiceSaveResponse) GetReport() *Report { + if r == nil { + return nil + } + return r.Report +} diff --git a/pkg/models/shared/reportingserviceupdaterequest.go b/pkg/models/shared/reportingserviceupdaterequest.go new file mode 100644 index 000000000..23444611e --- /dev/null +++ b/pkg/models/shared/reportingserviceupdaterequest.go @@ -0,0 +1,36 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// ReportingServiceUpdateRequest - Both editable fields are optional; an empty one leaves the stored value alone. +// +// At least one must be set. +type ReportingServiceUpdateRequest struct { + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + ParameterValues map[string]any `json:"parameterValues,omitempty"` + // Editing this does not re-plan, so it may drift from + // program.planned_from_prompt — that drift is how a stale report is detected. + Prompt *string `json:"prompt,omitempty"` +} + +func (r *ReportingServiceUpdateRequest) GetDisplayName() *string { + if r == nil { + return nil + } + return r.DisplayName +} + +func (r *ReportingServiceUpdateRequest) GetParameterValues() map[string]any { + if r == nil { + return nil + } + return r.ParameterValues +} + +func (r *ReportingServiceUpdateRequest) GetPrompt() *string { + if r == nil { + return nil + } + return r.Prompt +} diff --git a/pkg/models/shared/reportingserviceupdateresponse.go b/pkg/models/shared/reportingserviceupdateresponse.go new file mode 100644 index 000000000..8cd4eee70 --- /dev/null +++ b/pkg/models/shared/reportingserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The ReportingServiceUpdateResponse message. +type ReportingServiceUpdateResponse struct { + Report *Report `json:"report,omitempty"` +} + +func (r *ReportingServiceUpdateResponse) GetReport() *Report { + if r == nil { + return nil + } + return r.Report +} diff --git a/pkg/models/shared/reportrun.go b/pkg/models/shared/reportrun.go new file mode 100644 index 000000000..70a12a831 --- /dev/null +++ b/pkg/models/shared/reportrun.go @@ -0,0 +1,231 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// ReportRunStatus - The status field. +type ReportRunStatus string + +const ( + ReportRunStatusReportRunStatusUnspecified ReportRunStatus = "REPORT_RUN_STATUS_UNSPECIFIED" + ReportRunStatusReportRunStatusPending ReportRunStatus = "REPORT_RUN_STATUS_PENDING" + ReportRunStatusReportRunStatusSucceeded ReportRunStatus = "REPORT_RUN_STATUS_SUCCEEDED" + ReportRunStatusReportRunStatusFailed ReportRunStatus = "REPORT_RUN_STATUS_FAILED" + ReportRunStatusReportRunStatusStaleProgram ReportRunStatus = "REPORT_RUN_STATUS_STALE_PROGRAM" +) + +func (e ReportRunStatus) ToPointer() *ReportRunStatus { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *ReportRunStatus) IsExact() bool { + if e != nil { + switch *e { + case "REPORT_RUN_STATUS_UNSPECIFIED", "REPORT_RUN_STATUS_PENDING", "REPORT_RUN_STATUS_SUCCEEDED", "REPORT_RUN_STATUS_FAILED", "REPORT_RUN_STATUS_STALE_PROGRAM": + return true + } + } + return false +} + +// ReportRun is one execution of a Report's program. Write-once. +type ReportRun struct { + // The artifactUrl field. + ArtifactURL *string `json:"artifactUrl,omitempty"` + // Where the output came from, kept for provenance rather than to read it back: + // the surface itself is in surface_snapshot. Both are required to address a + // surface, and a headless refresh has neither. + ConversationID *string `json:"conversationId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + DeletedAt *time.Time `json:"deletedAt,omitempty"` + // The error field. + Error *string `json:"error,omitempty"` + ExpiresAt *time.Time `json:"expiresAt,omitempty"` + // KSUID, so runs sort by time. + ID *string `json:"id,omitempty"` + // Not a live join: the originating code-mode invocation is archived at the + // code-mode retention cutoff. + InvocationID *string `json:"invocationId,omitempty"` + Lineage map[string]any `json:"lineage,omitempty"` + ParameterValues map[string]any `json:"parameterValues,omitempty"` + Program *ProgramRef `json:"program,omitempty"` + // The reportId field. + ReportID *string `json:"reportId,omitempty"` + // Copied from the invocation's user_id, which is archived at the code-mode + // retention cutoff. Not Report.created_by_user_id — a refresh may execute as a + // different principal than the report's owner. + RunByUserID *string `json:"runByUserId,omitempty"` + // Never written: for a run saved out of a conversation, provenance is read back + // through A2UIService.GetSurfaceProvenance, which reads the surface's own + // components. A headless refresh has no conversation or surface to ask about, + // and how such a run reports what it read is still open. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. + Sources []ReportSource `json:"sources,omitempty"` + // The status field. + Status *ReportRunStatus `json:"status,omitempty"` + // The surfaceId field. + SurfaceID *string `json:"surfaceId,omitempty"` + SurfaceSnapshot *A2UISurface `json:"surfaceSnapshot,omitempty"` + // The tenantId field. + TenantID *string `json:"tenantId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` + // The vfsId field. + VfsID *string `json:"vfsId,omitempty"` +} + +func (r ReportRun) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(r, "", false) +} + +func (r *ReportRun) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &r, "", false, nil); err != nil { + return err + } + return nil +} + +func (r *ReportRun) GetArtifactURL() *string { + if r == nil { + return nil + } + return r.ArtifactURL +} + +func (r *ReportRun) GetConversationID() *string { + if r == nil { + return nil + } + return r.ConversationID +} + +func (r *ReportRun) GetCreatedAt() *time.Time { + if r == nil { + return nil + } + return r.CreatedAt +} + +func (r *ReportRun) GetDeletedAt() *time.Time { + if r == nil { + return nil + } + return r.DeletedAt +} + +func (r *ReportRun) GetError() *string { + if r == nil { + return nil + } + return r.Error +} + +func (r *ReportRun) GetExpiresAt() *time.Time { + if r == nil { + return nil + } + return r.ExpiresAt +} + +func (r *ReportRun) GetID() *string { + if r == nil { + return nil + } + return r.ID +} + +func (r *ReportRun) GetInvocationID() *string { + if r == nil { + return nil + } + return r.InvocationID +} + +func (r *ReportRun) GetLineage() map[string]any { + if r == nil { + return nil + } + return r.Lineage +} + +func (r *ReportRun) GetParameterValues() map[string]any { + if r == nil { + return nil + } + return r.ParameterValues +} + +func (r *ReportRun) GetProgram() *ProgramRef { + if r == nil { + return nil + } + return r.Program +} + +func (r *ReportRun) GetReportID() *string { + if r == nil { + return nil + } + return r.ReportID +} + +func (r *ReportRun) GetRunByUserID() *string { + if r == nil { + return nil + } + return r.RunByUserID +} + +func (r *ReportRun) GetSources() []ReportSource { + if r == nil { + return nil + } + return r.Sources +} + +func (r *ReportRun) GetStatus() *ReportRunStatus { + if r == nil { + return nil + } + return r.Status +} + +func (r *ReportRun) GetSurfaceID() *string { + if r == nil { + return nil + } + return r.SurfaceID +} + +func (r *ReportRun) GetSurfaceSnapshot() *A2UISurface { + if r == nil { + return nil + } + return r.SurfaceSnapshot +} + +func (r *ReportRun) GetTenantID() *string { + if r == nil { + return nil + } + return r.TenantID +} + +func (r *ReportRun) GetUpdatedAt() *time.Time { + if r == nil { + return nil + } + return r.UpdatedAt +} + +func (r *ReportRun) GetVfsID() *string { + if r == nil { + return nil + } + return r.VfsID +} diff --git a/pkg/models/shared/reportsource.go b/pkg/models/shared/reportsource.go new file mode 100644 index 000000000..b57580a7b --- /dev/null +++ b/pkg/models/shared/reportsource.go @@ -0,0 +1,64 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// ReportSource is one provenance entry: what a run read to produce its numbers. +// +// Retired: a run saved out of a conversation records the surface it came from, +// and provenance is read back through A2UIService.GetSurfaceProvenance rather +// than copied here. Kept because a published message may not be deleted. +// +// Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. +type ReportSource struct { + // Rows contributing. + Count *int64 `integer:"string" json:"count,omitempty"` + // The kind field. + Kind *string `json:"kind,omitempty"` + // The label field. + Label *string `json:"label,omitempty"` + // Tool + query fingerprint, or object type/id. + Ref *string `json:"ref,omitempty"` +} + +func (r ReportSource) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(r, "", false) +} + +func (r *ReportSource) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &r, "", false, nil); err != nil { + return err + } + return nil +} + +func (r *ReportSource) GetCount() *int64 { + if r == nil { + return nil + } + return r.Count +} + +func (r *ReportSource) GetKind() *string { + if r == nil { + return nil + } + return r.Kind +} + +func (r *ReportSource) GetLabel() *string { + if r == nil { + return nil + } + return r.Label +} + +func (r *ReportSource) GetRef() *string { + if r == nil { + return nil + } + return r.Ref +} diff --git a/pkg/models/shared/requestcatalog.go b/pkg/models/shared/requestcatalog.go index 8cfc6129e..24468f910 100644 --- a/pkg/models/shared/requestcatalog.go +++ b/pkg/models/shared/requestcatalog.go @@ -31,6 +31,35 @@ func (e *EnrollmentBehavior) IsExact() bool { return false } +// RequestCatalogType - The type of this access profile. Reports CATALOG_AND_BUNDLE for a profile +// +// created before the type was recorded; UNSPECIFIED only for a tenant whose +// backfill has not been run. +type RequestCatalogType string + +const ( + RequestCatalogTypeRequestCatalogTypeUnspecified RequestCatalogType = "REQUEST_CATALOG_TYPE_UNSPECIFIED" + RequestCatalogTypeRequestCatalogTypeCatalog RequestCatalogType = "REQUEST_CATALOG_TYPE_CATALOG" + RequestCatalogTypeRequestCatalogTypeProfile RequestCatalogType = "REQUEST_CATALOG_TYPE_PROFILE" + RequestCatalogTypeRequestCatalogTypeCatalogAndBundle RequestCatalogType = "REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE" + RequestCatalogTypeRequestCatalogTypeBundle RequestCatalogType = "REQUEST_CATALOG_TYPE_BUNDLE" +) + +func (e RequestCatalogType) ToPointer() *RequestCatalogType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *RequestCatalogType) IsExact() bool { + if e != nil { + switch *e { + case "REQUEST_CATALOG_TYPE_UNSPECIFIED", "REQUEST_CATALOG_TYPE_CATALOG", "REQUEST_CATALOG_TYPE_PROFILE", "REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE", "REQUEST_CATALOG_TYPE_BUNDLE": + return true + } + } + return false +} + // UnenrollmentBehavior - Defines how to handle the revocation of the entitlements in the catalog during unenrollment. type UnenrollmentBehavior string @@ -109,6 +138,10 @@ type RequestCatalog struct { Published *bool `json:"published,omitempty"` // Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. RequestBundle *bool `json:"requestBundle,omitempty"` + // The type of this access profile. Reports CATALOG_AND_BUNDLE for a profile + // created before the type was recorded; UNSPECIFIED only for a tenant whose + // backfill has not been run. + Type *RequestCatalogType `json:"type,omitempty"` // Defines how to handle the revocation of the entitlements in the catalog during unenrollment. UnenrollmentBehavior *UnenrollmentBehavior `json:"unenrollmentBehavior,omitempty"` // Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. @@ -206,6 +239,13 @@ func (r *RequestCatalog) GetRequestBundle() *bool { return r.RequestBundle } +func (r *RequestCatalog) GetType() *RequestCatalogType { + if r == nil { + return nil + } + return r.Type +} + func (r *RequestCatalog) GetUnenrollmentBehavior() *UnenrollmentBehavior { if r == nil { return nil diff --git a/pkg/models/shared/requestcatalogmanagementservicecreaterequest.go b/pkg/models/shared/requestcatalogmanagementservicecreaterequest.go index e08abf692..2a31e4c78 100644 --- a/pkg/models/shared/requestcatalogmanagementservicecreaterequest.go +++ b/pkg/models/shared/requestcatalogmanagementservicecreaterequest.go @@ -26,6 +26,40 @@ func (e *RequestCatalogManagementServiceCreateRequestEnrollmentBehavior) IsExact return false } +// RequestCatalogManagementServiceCreateRequestType - The type of access profile to create. Leave unset for +// +// REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE, which is what every profile +// created before this field existed is. Setting it requires the +// ACCESS_PROFILE_TYPES feature. +// +// PROFILE is rejected rather than resolved: it is deprecated, has no stored +// counterpart, and shares wire number 2 with the stored BUNDLE, so honoring +// it would silently persist a type the caller did not ask for. +type RequestCatalogManagementServiceCreateRequestType string + +const ( + RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeUnspecified RequestCatalogManagementServiceCreateRequestType = "REQUEST_CATALOG_TYPE_UNSPECIFIED" + RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeCatalog RequestCatalogManagementServiceCreateRequestType = "REQUEST_CATALOG_TYPE_CATALOG" + RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeProfile RequestCatalogManagementServiceCreateRequestType = "REQUEST_CATALOG_TYPE_PROFILE" + RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeCatalogAndBundle RequestCatalogManagementServiceCreateRequestType = "REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE" + RequestCatalogManagementServiceCreateRequestTypeRequestCatalogTypeBundle RequestCatalogManagementServiceCreateRequestType = "REQUEST_CATALOG_TYPE_BUNDLE" +) + +func (e RequestCatalogManagementServiceCreateRequestType) ToPointer() *RequestCatalogManagementServiceCreateRequestType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *RequestCatalogManagementServiceCreateRequestType) IsExact() bool { + if e != nil { + switch *e { + case "REQUEST_CATALOG_TYPE_UNSPECIFIED", "REQUEST_CATALOG_TYPE_CATALOG", "REQUEST_CATALOG_TYPE_PROFILE", "REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE", "REQUEST_CATALOG_TYPE_BUNDLE": + return true + } + } + return false +} + // RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior - Defines how to handle the revocation of the entitlements in the catalog during unenrollment. type RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior string @@ -97,6 +131,15 @@ type RequestCatalogManagementServiceCreateRequest struct { Published *bool `json:"published,omitempty"` // Whether all the entitlements in the catalog can be requests at once. Your tenant must have the bundles feature to use this. RequestBundle *bool `json:"requestBundle,omitempty"` + // The type of access profile to create. Leave unset for + // REQUEST_CATALOG_TYPE_CATALOG_AND_BUNDLE, which is what every profile + // created before this field existed is. Setting it requires the + // ACCESS_PROFILE_TYPES feature. + // + // PROFILE is rejected rather than resolved: it is deprecated, has no stored + // counterpart, and shares wire number 2 with the stored BUNDLE, so honoring + // it would silently persist a type the caller did not ask for. + Type *RequestCatalogManagementServiceCreateRequestType `json:"type,omitempty"` // Defines how to handle the revocation of the entitlements in the catalog during unenrollment. UnenrollmentBehavior *RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior `json:"unenrollmentBehavior,omitempty"` // Defines how to handle the revoke policies of the entitlements in the catalog during unenrollment. @@ -154,6 +197,13 @@ func (r *RequestCatalogManagementServiceCreateRequest) GetRequestBundle() *bool return r.RequestBundle } +func (r *RequestCatalogManagementServiceCreateRequest) GetType() *RequestCatalogManagementServiceCreateRequestType { + if r == nil { + return nil + } + return r.Type +} + func (r *RequestCatalogManagementServiceCreateRequest) GetUnenrollmentBehavior() *RequestCatalogManagementServiceCreateRequestUnenrollmentBehavior { if r == nil { return nil diff --git a/pkg/models/shared/requestcreatedpreference.go b/pkg/models/shared/requestcreatedpreference.go new file mode 100644 index 000000000..991310e78 --- /dev/null +++ b/pkg/models/shared/requestcreatedpreference.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The RequestCreatedPreference message. +type RequestCreatedPreference struct { + // The enabled field. + Enabled *bool `json:"enabled,omitempty"` + // The locked field. + Locked *bool `json:"locked,omitempty"` +} + +func (r *RequestCreatedPreference) GetEnabled() *bool { + if r == nil { + return nil + } + return r.Enabled +} + +func (r *RequestCreatedPreference) GetLocked() *bool { + if r == nil { + return nil + } + return r.Locked +} diff --git a/pkg/models/shared/requestsettings.go b/pkg/models/shared/requestsettings.go index a5b9ac617..809c7b7bd 100644 --- a/pkg/models/shared/requestsettings.go +++ b/pkg/models/shared/requestsettings.go @@ -4,11 +4,23 @@ package shared // RequestSettings holds tenant-wide configuration for the access-request flow. type RequestSettings struct { + // MaxBulkEntitlementSelection caps the number of entitlements a requester + // may select in a single bulk access request. Reads always return the + // effective value — an unset (0) value is presented as the system default of + // 10. Writing 0 resets the field to unset in storage. Maximum 100. + MaxBulkEntitlementSelection *int `json:"maxBulkEntitlementSelection,omitempty"` // When true, request surfaces (webapp, Slack, MS Teams) skip prompting the // requester for a justification. SkipJustification *bool `json:"skipJustification,omitempty"` } +func (r *RequestSettings) GetMaxBulkEntitlementSelection() *int { + if r == nil { + return nil + } + return r.MaxBulkEntitlementSelection +} + func (r *RequestSettings) GetSkipJustification() *bool { if r == nil { return nil diff --git a/pkg/models/shared/revokegatewaykeyrequest.go b/pkg/models/shared/revokegatewaykeyrequest.go new file mode 100644 index 000000000..c6546c46e --- /dev/null +++ b/pkg/models/shared/revokegatewaykeyrequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The RevokeGatewayKeyRequest message. +type RevokeGatewayKeyRequest struct { +} diff --git a/pkg/models/shared/revokegatewaykeyresponse.go b/pkg/models/shared/revokegatewaykeyresponse.go new file mode 100644 index 000000000..641d40275 --- /dev/null +++ b/pkg/models/shared/revokegatewaykeyresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The RevokeGatewayKeyResponse message. +type RevokeGatewayKeyResponse struct { + GatewayKey *GatewayKey `json:"gatewayKey,omitempty"` +} + +func (r *RevokeGatewayKeyResponse) GetGatewayKey() *GatewayKey { + if r == nil { + return nil + } + return r.GatewayKey +} diff --git a/pkg/models/shared/rule.go b/pkg/models/shared/rule.go index 89efdd517..e82cdd675 100644 --- a/pkg/models/shared/rule.go +++ b/pkg/models/shared/rule.go @@ -2,18 +2,41 @@ package shared -// Rule - A conditional routing rule that maps a CEL expression to a step sequence. +// Rule - A conditional routing rule that maps a CEL expression to an outcome. // -// Rules are evaluated top-to-bottom; the first matching rule's policy_key -// selects the step sequence from the policy's policy_steps map. If no rule -// matches, the baseline entry is used. +// Rules are evaluated top-to-bottom; the first matching rule's outcome +// determines which steps run. If the outcome is policy_key, the step sequence +// of that key in this policy's policy_steps map is used. If the outcome is +// policy_id, the referenced policy is evaluated recursively (depth-bounded, +// cycle-free, same policy_type). If no rule matches, the baseline entry of +// policy_steps is used. +// +// This message contains a oneof named outcome. Only a single field of the following list may be set at a time: +// - stepKey +// - policyId type Rule struct { // A CEL expression that is evaluated against the request context. If it - // returns true, the step sequence identified by policy_key is used. + // returns true, the step sequence identified by the outcome is used. Condition *string `json:"condition,omitempty"` - // A key into the policy's policy_steps map identifying which step sequence - // to execute when this rule's condition matches. + // The ID of another Policy that is evaluated recursively when this + // rule matches. The referenced policy must share this policy's + // policy_type, must not introduce a cycle, and must not push any + // reachable chain over depth 5. Gated by the + // POLICY_REFERENCES_POLICY feature flag. + // This field is part of the `outcome` oneof. + // See the documentation for `c1.api.policy.v1.Rule` for more details. + PolicyID *string `json:"policyId,omitempty"` + // Deprecated: prefer outcome.step_key. Still read by the request path + // for backward compatibility with rules persisted before the outcome + // oneof existed. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. PolicyKey *string `json:"policyKey,omitempty"` + // A key into the policy's policy_steps map identifying which step + // sequence to execute when this rule's condition matches. + // This field is part of the `outcome` oneof. + // See the documentation for `c1.api.policy.v1.Rule` for more details. + StepKey *string `json:"stepKey,omitempty"` } func (r *Rule) GetCondition() *string { @@ -23,9 +46,23 @@ func (r *Rule) GetCondition() *string { return r.Condition } +func (r *Rule) GetPolicyID() *string { + if r == nil { + return nil + } + return r.PolicyID +} + func (r *Rule) GetPolicyKey() *string { if r == nil { return nil } return r.PolicyKey } + +func (r *Rule) GetStepKey() *string { + if r == nil { + return nil + } + return r.StepKey +} diff --git a/pkg/models/shared/samlattributemapping.go b/pkg/models/shared/samlattributemapping.go new file mode 100644 index 000000000..ad4674188 --- /dev/null +++ b/pkg/models/shared/samlattributemapping.go @@ -0,0 +1,71 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The NameFormat attribute. +type NameFormat string + +const ( + NameFormatSamlAttributeNameFormatUnspecified NameFormat = "SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED" + NameFormatSamlAttributeNameFormatURI NameFormat = "SAML_ATTRIBUTE_NAME_FORMAT_URI" + NameFormatSamlAttributeNameFormatBasic NameFormat = "SAML_ATTRIBUTE_NAME_FORMAT_BASIC" + NameFormatSamlAttributeNameFormatUnspecifiedUrn NameFormat = "SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN" +) + +func (e NameFormat) ToPointer() *NameFormat { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *NameFormat) IsExact() bool { + if e != nil { + switch *e { + case "SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED", "SAML_ATTRIBUTE_NAME_FORMAT_URI", "SAML_ATTRIBUTE_NAME_FORMAT_BASIC", "SAML_ATTRIBUTE_NAME_FORMAT_UNSPECIFIED_URN": + return true + } + } + return false +} + +// SAMLAttributeMapping releases one user attribute to the service provider +// +// as one Attribute in the assertion's AttributeStatement. +type SAMLAttributeMapping struct { + // Optional FriendlyName, for service providers that display it. + FriendlyName *string `json:"friendlyName,omitempty"` + // The Name attribute, dictated by the service provider. + Name string `json:"name"` + // The NameFormat attribute. + NameFormat *NameFormat `json:"nameFormat,omitempty"` + // The user attribute mapping that resolves the value, including its fallback + // chain. + UserAttributeMappingID string `json:"userAttributeMappingId"` +} + +func (s *SAMLAttributeMapping) GetFriendlyName() *string { + if s == nil { + return nil + } + return s.FriendlyName +} + +func (s *SAMLAttributeMapping) GetName() string { + if s == nil { + return "" + } + return s.Name +} + +func (s *SAMLAttributeMapping) GetNameFormat() *NameFormat { + if s == nil { + return nil + } + return s.NameFormat +} + +func (s *SAMLAttributeMapping) GetUserAttributeMappingID() string { + if s == nil { + return "" + } + return s.UserAttributeMappingID +} diff --git a/pkg/models/shared/samlmetadatafinding.go b/pkg/models/shared/samlmetadatafinding.go new file mode 100644 index 000000000..f4658ea72 --- /dev/null +++ b/pkg/models/shared/samlmetadatafinding.go @@ -0,0 +1,90 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// Component - Where the finding fits in the parsed document. +type Component string + +const ( + ComponentComponentUnspecified Component = "COMPONENT_UNSPECIFIED" + ComponentComponentDocument Component = "COMPONENT_DOCUMENT" + ComponentComponentEntityID Component = "COMPONENT_ENTITY_ID" + ComponentComponentAcsURL Component = "COMPONENT_ACS_URL" + ComponentComponentNameIDFormat Component = "COMPONENT_NAME_ID_FORMAT" + ComponentComponentSigningCertificate Component = "COMPONENT_SIGNING_CERTIFICATE" + ComponentComponentEncryptionCertificate Component = "COMPONENT_ENCRYPTION_CERTIFICATE" + ComponentComponentRequirement Component = "COMPONENT_REQUIREMENT" + ComponentComponentBinding Component = "COMPONENT_BINDING" +) + +func (e Component) ToPointer() *Component { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Component) IsExact() bool { + if e != nil { + switch *e { + case "COMPONENT_UNSPECIFIED", "COMPONENT_DOCUMENT", "COMPONENT_ENTITY_ID", "COMPONENT_ACS_URL", "COMPONENT_NAME_ID_FORMAT", "COMPONENT_SIGNING_CERTIFICATE", "COMPONENT_ENCRYPTION_CERTIFICATE", "COMPONENT_REQUIREMENT", "COMPONENT_BINDING": + return true + } + } + return false +} + +// Level - The severity of this finding. +type Level string + +const ( + LevelLevelUnspecified Level = "LEVEL_UNSPECIFIED" + LevelLevelBlocking Level = "LEVEL_BLOCKING" + LevelLevelWarning Level = "LEVEL_WARNING" +) + +func (e Level) ToPointer() *Level { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *Level) IsExact() bool { + if e != nil { + switch *e { + case "LEVEL_UNSPECIFIED", "LEVEL_BLOCKING", "LEVEL_WARNING": + return true + } + } + return false +} + +// SAMLMetadataFinding is one thing ConductorOne noticed while parsing a service +// +// provider's metadata document. +type SAMLMetadataFinding struct { + // Where the finding fits in the parsed document. + Component *Component `json:"component,omitempty"` + // The severity of this finding. + Level *Level `json:"level,omitempty"` + // Plain-language explanation of why the finding was raised. + Reason *string `json:"reason,omitempty"` +} + +func (s *SAMLMetadataFinding) GetComponent() *Component { + if s == nil { + return nil + } + return s.Component +} + +func (s *SAMLMetadataFinding) GetLevel() *Level { + if s == nil { + return nil + } + return s.Level +} + +func (s *SAMLMetadataFinding) GetReason() *string { + if s == nil { + return nil + } + return s.Reason +} diff --git a/pkg/models/shared/searchappresourcesrequest.go b/pkg/models/shared/searchappresourcesrequest.go index 6fb0136d1..7dc0e9f7f 100644 --- a/pkg/models/shared/searchappresourcesrequest.go +++ b/pkg/models/shared/searchappresourcesrequest.go @@ -2,21 +2,21 @@ package shared -type AgentStatuses string +type SearchAppResourcesRequestAgentStatuses string const ( - AgentStatusesAgentStatusUnspecified AgentStatuses = "AGENT_STATUS_UNSPECIFIED" - AgentStatusesAgentStatusReady AgentStatuses = "AGENT_STATUS_READY" - AgentStatusesAgentStatusDisabled AgentStatuses = "AGENT_STATUS_DISABLED" - AgentStatusesAgentStatusDeleted AgentStatuses = "AGENT_STATUS_DELETED" + SearchAppResourcesRequestAgentStatusesAgentStatusUnspecified SearchAppResourcesRequestAgentStatuses = "AGENT_STATUS_UNSPECIFIED" + SearchAppResourcesRequestAgentStatusesAgentStatusReady SearchAppResourcesRequestAgentStatuses = "AGENT_STATUS_READY" + SearchAppResourcesRequestAgentStatusesAgentStatusDisabled SearchAppResourcesRequestAgentStatuses = "AGENT_STATUS_DISABLED" + SearchAppResourcesRequestAgentStatusesAgentStatusDeleted SearchAppResourcesRequestAgentStatuses = "AGENT_STATUS_DELETED" ) -func (e AgentStatuses) ToPointer() *AgentStatuses { +func (e SearchAppResourcesRequestAgentStatuses) ToPointer() *SearchAppResourcesRequestAgentStatuses { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *AgentStatuses) IsExact() bool { +func (e *SearchAppResourcesRequestAgentStatuses) IsExact() bool { if e != nil { switch *e { case "AGENT_STATUS_UNSPECIFIED", "AGENT_STATUS_READY", "AGENT_STATUS_DISABLED", "AGENT_STATUS_DELETED": @@ -133,7 +133,7 @@ type SearchAppResourcesRequest struct { // Restrict the search to AI-agent resources with one of the given agent // lifecycle statuses (READY, DISABLED, DELETED). When empty, agent status is // not used as a filter. - AgentStatuses []AgentStatuses `json:"agentStatuses,omitempty"` + AgentStatuses []SearchAppResourcesRequestAgentStatuses `json:"agentStatuses,omitempty"` // The app ID to restrict the search to. AppID *string `json:"appId,omitempty"` // A list of app IDs to restrict the search to. Mirrors the singular app_id; @@ -193,7 +193,7 @@ type SearchAppResourcesRequest struct { WithOpenFindings *bool `json:"withOpenFindings,omitempty"` } -func (s *SearchAppResourcesRequest) GetAgentStatuses() []AgentStatuses { +func (s *SearchAppResourcesRequest) GetAgentStatuses() []SearchAppResourcesRequestAgentStatuses { if s == nil { return nil } diff --git a/pkg/models/shared/searchcohortusersrequest.go b/pkg/models/shared/searchcohortusersrequest.go index 5f5c55ca0..e9412087b 100644 --- a/pkg/models/shared/searchcohortusersrequest.go +++ b/pkg/models/shared/searchcohortusersrequest.go @@ -10,7 +10,10 @@ type SearchCohortUsersRequest struct { PageToken *string `json:"pageToken,omitempty"` // Additional profile filters to narrow the cohort user search. ProfileFilters []ProfileFilter `json:"profileFilters,omitempty"` - // Optional list of entitlements to compute per-user coverage for. + // Deprecated. This endpoint no longer computes per-user coverage and + // ignores this field. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. SelectedEntitlements []EntitlementRef `json:"selectedEntitlements,omitempty"` } diff --git a/pkg/models/shared/searchcohortusersresponse.go b/pkg/models/shared/searchcohortusersresponse.go index a489307ca..0717b99aa 100644 --- a/pkg/models/shared/searchcohortusersresponse.go +++ b/pkg/models/shared/searchcohortusersresponse.go @@ -8,7 +8,10 @@ type SearchCohortUsersResponse struct { List []User `json:"list,omitempty"` // Token to retrieve the next page of results, empty if no more results. NextPageToken *string `json:"nextPageToken,omitempty"` - // Per-user coverage counts, populated when selected_entitlements is non-empty. + // Deprecated. This endpoint no longer computes per-user coverage; this + // list is always empty. + // + // Deprecated: This will be removed in a future release, please migrate away from it as soon as possible. UsersWithCoverage []CohortUserWithCoverage `json:"usersWithCoverage,omitempty"` } diff --git a/pkg/models/shared/searchpoliciesrequest.go b/pkg/models/shared/searchpoliciesrequest.go index beed0626b..1d8f3823c 100644 --- a/pkg/models/shared/searchpoliciesrequest.go +++ b/pkg/models/shared/searchpoliciesrequest.go @@ -28,6 +28,87 @@ func (e *PolicyTypes) IsExact() bool { return false } +// ScopeObjectType - When scope_view is POLICY_SCOPE_VIEW_SCOPED, narrow local policies to a +// +// coarse object type (app-local vs entitlement-local). +type ScopeObjectType string + +const ( + ScopeObjectTypePolicyScopeObjectTypeUnspecified ScopeObjectType = "POLICY_SCOPE_OBJECT_TYPE_UNSPECIFIED" + ScopeObjectTypePolicyScopeObjectTypeApp ScopeObjectType = "POLICY_SCOPE_OBJECT_TYPE_APP" + ScopeObjectTypePolicyScopeObjectTypeEntitlement ScopeObjectType = "POLICY_SCOPE_OBJECT_TYPE_ENTITLEMENT" +) + +func (e ScopeObjectType) ToPointer() *ScopeObjectType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *ScopeObjectType) IsExact() bool { + if e != nil { + switch *e { + case "POLICY_SCOPE_OBJECT_TYPE_UNSPECIFIED", "POLICY_SCOPE_OBJECT_TYPE_APP", "POLICY_SCOPE_OBJECT_TYPE_ENTITLEMENT": + return true + } + } + return false +} + +// ScopeSlot - When scope_view narrows to one object, only return that object's local +// +// policies in this slot. Ignored when no object is identified by +// scope_app_id, which lists every local policy regardless of slot. +type ScopeSlot string + +const ( + ScopeSlotPolicyScopeSlotUnspecified ScopeSlot = "POLICY_SCOPE_SLOT_UNSPECIFIED" + ScopeSlotPolicyScopeSlotEmergency ScopeSlot = "POLICY_SCOPE_SLOT_EMERGENCY" +) + +func (e ScopeSlot) ToPointer() *ScopeSlot { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *ScopeSlot) IsExact() bool { + if e != nil { + switch *e { + case "POLICY_SCOPE_SLOT_UNSPECIFIED", "POLICY_SCOPE_SLOT_EMERGENCY": + return true + } + } + return false +} + +// ScopeView - Which policies to return based on scope. Defaults to global-only, so +// +// app/entitlement-scoped policies never appear unless explicitly requested. +// Ignored when refs are provided (explicit ID lookups always resolve). +type ScopeView string + +const ( + ScopeViewPolicyScopeViewUnspecified ScopeView = "POLICY_SCOPE_VIEW_UNSPECIFIED" + ScopeViewPolicyScopeViewGlobal ScopeView = "POLICY_SCOPE_VIEW_GLOBAL" + ScopeViewPolicyScopeViewScoped ScopeView = "POLICY_SCOPE_VIEW_SCOPED" + ScopeViewPolicyScopeViewAll ScopeView = "POLICY_SCOPE_VIEW_ALL" + ScopeViewPolicyScopeViewGlobalAndObject ScopeView = "POLICY_SCOPE_VIEW_GLOBAL_AND_OBJECT" +) + +func (e ScopeView) ToPointer() *ScopeView { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *ScopeView) IsExact() bool { + if e != nil { + switch *e { + case "POLICY_SCOPE_VIEW_UNSPECIFIED", "POLICY_SCOPE_VIEW_GLOBAL", "POLICY_SCOPE_VIEW_SCOPED", "POLICY_SCOPE_VIEW_ALL", "POLICY_SCOPE_VIEW_GLOBAL_AND_OBJECT": + return true + } + } + return false +} + // SearchPoliciesRequest - Search Policies by a few properties. type SearchPoliciesRequest struct { // Search for policies with a case insensitive match on the display name. @@ -46,6 +127,23 @@ type SearchPoliciesRequest struct { Query *string `json:"query,omitempty"` // The refs field. Refs []PolicyRef `json:"refs,omitempty"` + // When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped + // to this entitlement. + ScopeAppEntitlementID *string `json:"scopeAppEntitlementId,omitempty"` + // When scope_view is POLICY_SCOPE_VIEW_SCOPED, only return policies scoped + // to this app. + ScopeAppID *string `json:"scopeAppId,omitempty"` + // When scope_view is POLICY_SCOPE_VIEW_SCOPED, narrow local policies to a + // coarse object type (app-local vs entitlement-local). + ScopeObjectType *ScopeObjectType `json:"scopeObjectType,omitempty"` + // When scope_view narrows to one object, only return that object's local + // policies in this slot. Ignored when no object is identified by + // scope_app_id, which lists every local policy regardless of slot. + ScopeSlot *ScopeSlot `json:"scopeSlot,omitempty"` + // Which policies to return based on scope. Defaults to global-only, so + // app/entitlement-scoped policies never appear unless explicitly requested. + // Ignored when refs are provided (explicit ID lookups always resolve). + ScopeView *ScopeView `json:"scopeView,omitempty"` } func (s *SearchPoliciesRequest) GetDisplayName() *string { @@ -103,3 +201,38 @@ func (s *SearchPoliciesRequest) GetRefs() []PolicyRef { } return s.Refs } + +func (s *SearchPoliciesRequest) GetScopeAppEntitlementID() *string { + if s == nil { + return nil + } + return s.ScopeAppEntitlementID +} + +func (s *SearchPoliciesRequest) GetScopeAppID() *string { + if s == nil { + return nil + } + return s.ScopeAppID +} + +func (s *SearchPoliciesRequest) GetScopeObjectType() *ScopeObjectType { + if s == nil { + return nil + } + return s.ScopeObjectType +} + +func (s *SearchPoliciesRequest) GetScopeSlot() *ScopeSlot { + if s == nil { + return nil + } + return s.ScopeSlot +} + +func (s *SearchPoliciesRequest) GetScopeView() *ScopeView { + if s == nil { + return nil + } + return s.ScopeView +} diff --git a/pkg/models/shared/searchusersrequest.go b/pkg/models/shared/searchusersrequest.go index cdbfc9d0f..0d8baf1ce 100644 --- a/pkg/models/shared/searchusersrequest.go +++ b/pkg/models/shared/searchusersrequest.go @@ -160,6 +160,10 @@ type SearchUsersRequest struct { Refs []UserRef `json:"refs,omitempty"` // Search for users that have any of the role IDs on this list. RoleIds []string `json:"roleIds,omitempty"` + // Filter to include only users sourced from any of these apps (directories). + // Each value is an app ID; a user matches when its source_app_ids map + // contains any of the listed app IDs. Combined with `origins` using OR. + SourceAppIds []string `json:"sourceAppIds,omitempty"` // Search for users that have any of the statuses on this list. This can only be ENABLED, DISABLED, and DELETED UserStatuses []SearchUsersRequestUserStatuses `json:"userStatuses,omitempty"` } @@ -290,6 +294,13 @@ func (s *SearchUsersRequest) GetRoleIds() []string { return s.RoleIds } +func (s *SearchUsersRequest) GetSourceAppIds() []string { + if s == nil { + return nil + } + return s.SourceAppIds +} + func (s *SearchUsersRequest) GetUserStatuses() []SearchUsersRequestUserStatuses { if s == nil { return nil diff --git a/pkg/models/shared/secretsmaskingconfig.go b/pkg/models/shared/secretsmaskingconfig.go new file mode 100644 index 000000000..42c00d85d --- /dev/null +++ b/pkg/models/shared/secretsmaskingconfig.go @@ -0,0 +1,28 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SecretsMaskingConfig configures post-tool-use redaction of secret-shaped +// +// substrings (API keys, tokens, private keys) in tool output. +type SecretsMaskingConfig struct { + // Extra RE2 regexes whose matches are redacted in addition to the built-in + // secret patterns. + AdditionalPatterns []string `json:"additionalPatterns,omitempty"` + // Replacement string for a matched secret. Empty = "***REDACTED-SECRET***". + Placeholder *string `json:"placeholder,omitempty"` +} + +func (s *SecretsMaskingConfig) GetAdditionalPatterns() []string { + if s == nil { + return nil + } + return s.AdditionalPatterns +} + +func (s *SecretsMaskingConfig) GetPlaceholder() *string { + if s == nil { + return nil + } + return s.Placeholder +} diff --git a/pkg/models/shared/sessionpolicystepuprequired.go b/pkg/models/shared/sessionpolicystepuprequired.go index c14f88c3a..90941adf0 100644 --- a/pkg/models/shared/sessionpolicystepuprequired.go +++ b/pkg/models/shared/sessionpolicystepuprequired.go @@ -2,24 +2,24 @@ package shared -// Level - The level field. -type Level string +// SessionPolicyStepUpRequiredLevel - The level field. +type SessionPolicyStepUpRequiredLevel string const ( - LevelAuthLevelUnspecified Level = "AUTH_LEVEL_UNSPECIFIED" - LevelAuthLevelNone Level = "AUTH_LEVEL_NONE" - LevelAuthLevelSingleFactor Level = "AUTH_LEVEL_SINGLE_FACTOR" - LevelAuthLevelMultiFactor Level = "AUTH_LEVEL_MULTI_FACTOR" - LevelAuthLevelPhr Level = "AUTH_LEVEL_PHR" - LevelAuthLevelPhrh Level = "AUTH_LEVEL_PHRH" + SessionPolicyStepUpRequiredLevelAuthLevelUnspecified SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_UNSPECIFIED" + SessionPolicyStepUpRequiredLevelAuthLevelNone SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_NONE" + SessionPolicyStepUpRequiredLevelAuthLevelSingleFactor SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_SINGLE_FACTOR" + SessionPolicyStepUpRequiredLevelAuthLevelMultiFactor SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_MULTI_FACTOR" + SessionPolicyStepUpRequiredLevelAuthLevelPhr SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_PHR" + SessionPolicyStepUpRequiredLevelAuthLevelPhrh SessionPolicyStepUpRequiredLevel = "AUTH_LEVEL_PHRH" ) -func (e Level) ToPointer() *Level { +func (e SessionPolicyStepUpRequiredLevel) ToPointer() *SessionPolicyStepUpRequiredLevel { return &e } // IsExact returns true if the value matches a known enum value, false otherwise. -func (e *Level) IsExact() bool { +func (e *SessionPolicyStepUpRequiredLevel) IsExact() bool { if e != nil { switch *e { case "AUTH_LEVEL_UNSPECIFIED", "AUTH_LEVEL_NONE", "AUTH_LEVEL_SINGLE_FACTOR", "AUTH_LEVEL_MULTI_FACTOR", "AUTH_LEVEL_PHR", "AUTH_LEVEL_PHRH": @@ -63,14 +63,14 @@ func (e *SessionPolicyStepUpRequiredTypes) IsExact() bool { // continue. type SessionPolicyStepUpRequired struct { // The level field. - Level *Level `json:"level,omitempty"` + Level *SessionPolicyStepUpRequiredLevel `json:"level,omitempty"` // How fresh the step-up must be, in seconds. MaxAgeSeconds *int `json:"maxAgeSeconds,omitempty"` // The types field. Types []SessionPolicyStepUpRequiredTypes `json:"types,omitempty"` } -func (s *SessionPolicyStepUpRequired) GetLevel() *Level { +func (s *SessionPolicyStepUpRequired) GetLevel() *SessionPolicyStepUpRequiredLevel { if s == nil { return nil } diff --git a/pkg/models/shared/setprovidercredentialrequest.go b/pkg/models/shared/setprovidercredentialrequest.go new file mode 100644 index 000000000..1901932da --- /dev/null +++ b/pkg/models/shared/setprovidercredentialrequest.go @@ -0,0 +1,58 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SetProviderCredentialRequestHeaderStyle - The headerStyle field. +type SetProviderCredentialRequestHeaderStyle string + +const ( + SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleUnspecified SetProviderCredentialRequestHeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED" + SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleXAPIKey SetProviderCredentialRequestHeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY" + SetProviderCredentialRequestHeaderStyleProviderCredentialHeaderStyleAuthorizationBearer SetProviderCredentialRequestHeaderStyle = "PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER" +) + +func (e SetProviderCredentialRequestHeaderStyle) ToPointer() *SetProviderCredentialRequestHeaderStyle { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SetProviderCredentialRequestHeaderStyle) IsExact() bool { + if e != nil { + switch *e { + case "PROVIDER_CREDENTIAL_HEADER_STYLE_UNSPECIFIED", "PROVIDER_CREDENTIAL_HEADER_STYLE_X_API_KEY", "PROVIDER_CREDENTIAL_HEADER_STYLE_AUTHORIZATION_BEARER": + return true + } + } + return false +} + +// The SetProviderCredentialRequest message. +type SetProviderCredentialRequest struct { + // The apiKey field. + APIKey *string `json:"apiKey,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The headerStyle field. + HeaderStyle *SetProviderCredentialRequestHeaderStyle `json:"headerStyle,omitempty"` +} + +func (s *SetProviderCredentialRequest) GetAPIKey() *string { + if s == nil { + return nil + } + return s.APIKey +} + +func (s *SetProviderCredentialRequest) GetDisplayName() *string { + if s == nil { + return nil + } + return s.DisplayName +} + +func (s *SetProviderCredentialRequest) GetHeaderStyle() *SetProviderCredentialRequestHeaderStyle { + if s == nil { + return nil + } + return s.HeaderStyle +} diff --git a/pkg/models/shared/setprovidercredentialresponse.go b/pkg/models/shared/setprovidercredentialresponse.go new file mode 100644 index 000000000..3ea5b5186 --- /dev/null +++ b/pkg/models/shared/setprovidercredentialresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The SetProviderCredentialResponse message. +type SetProviderCredentialResponse struct { + Credential *ProviderCredential `json:"credential,omitempty"` +} + +func (s *SetProviderCredentialResponse) GetCredential() *ProviderCredential { + if s == nil { + return nil + } + return s.Credential +} diff --git a/pkg/models/shared/slackchannelsettings.go b/pkg/models/shared/slackchannelsettings.go index c4040e725..aeb708155 100644 --- a/pkg/models/shared/slackchannelsettings.go +++ b/pkg/models/shared/slackchannelsettings.go @@ -16,7 +16,9 @@ type SlackChannelSettings struct { // The isConfigured field. IsConfigured *bool `json:"isConfigured,omitempty"` ProvisioningRequest *ProvisioningRequestPreference `json:"provisioningRequest,omitempty"` + RequestCreated *RequestCreatedPreference `json:"requestCreated,omitempty"` Reviews *ReviewsPreference `json:"reviews,omitempty"` + System *SystemPreference `json:"system,omitempty"` TaskReminders *TaskRemindersPreference `json:"taskReminders,omitempty"` } @@ -90,6 +92,13 @@ func (s *SlackChannelSettings) GetProvisioningRequest() *ProvisioningRequestPref return s.ProvisioningRequest } +func (s *SlackChannelSettings) GetRequestCreated() *RequestCreatedPreference { + if s == nil { + return nil + } + return s.RequestCreated +} + func (s *SlackChannelSettings) GetReviews() *ReviewsPreference { if s == nil { return nil @@ -97,6 +106,13 @@ func (s *SlackChannelSettings) GetReviews() *ReviewsPreference { return s.Reviews } +func (s *SlackChannelSettings) GetSystem() *SystemPreference { + if s == nil { + return nil + } + return s.System +} + func (s *SlackChannelSettings) GetTaskReminders() *TaskRemindersPreference { if s == nil { return nil diff --git a/pkg/models/shared/slackchanneltarget.go b/pkg/models/shared/slackchanneltarget.go new file mode 100644 index 000000000..9bcc85b01 --- /dev/null +++ b/pkg/models/shared/slackchanneltarget.go @@ -0,0 +1,28 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SlackChannelTarget names one Slack channel. Exactly one of channel_name / +// +// channel_id is set; a name is resolved at send time, so an unresolvable name +// fails the dispatch rather than the rule edit. +type SlackChannelTarget struct { + // The channelId field. + ChannelID *string `json:"channelId,omitempty"` + // The channelName field. + ChannelName *string `json:"channelName,omitempty"` +} + +func (s *SlackChannelTarget) GetChannelID() *string { + if s == nil { + return nil + } + return s.ChannelID +} + +func (s *SlackChannelTarget) GetChannelName() *string { + if s == nil { + return nil + } + return s.ChannelName +} diff --git a/pkg/models/shared/spendcontrols.go b/pkg/models/shared/spendcontrols.go new file mode 100644 index 000000000..e1310549d --- /dev/null +++ b/pkg/models/shared/spendcontrols.go @@ -0,0 +1,81 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SpendControlsPeriod - Only valid together with limit: a period without its amount would +// +// reinterpret some other layer's number in a cadence that layer never +// agreed to. +type SpendControlsPeriod string + +const ( + SpendControlsPeriodPeriodKindUnspecified SpendControlsPeriod = "PERIOD_KIND_UNSPECIFIED" + SpendControlsPeriodPeriodKindDaily SpendControlsPeriod = "PERIOD_KIND_DAILY" + SpendControlsPeriodPeriodKindWeekly SpendControlsPeriod = "PERIOD_KIND_WEEKLY" + SpendControlsPeriodPeriodKindMonthly SpendControlsPeriod = "PERIOD_KIND_MONTHLY" + SpendControlsPeriodPeriodKindQuarterly SpendControlsPeriod = "PERIOD_KIND_QUARTERLY" + SpendControlsPeriodPeriodKindYearly SpendControlsPeriod = "PERIOD_KIND_YEARLY" +) + +func (e SpendControlsPeriod) ToPointer() *SpendControlsPeriod { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SpendControlsPeriod) IsExact() bool { + if e != nil { + switch *e { + case "PERIOD_KIND_UNSPECIFIED", "PERIOD_KIND_DAILY", "PERIOD_KIND_WEEKLY", "PERIOD_KIND_MONTHLY", "PERIOD_KIND_QUARTERLY", "PERIOD_KIND_YEARLY": + return true + } + } + return false +} + +// SpendControls is the one control shape carried by every authority scope. +// +// Per-row resolution, identical everywhere: suspension present -> deny; +// unexpired extension -> extension.limit; limit present -> limit; +// otherwise this row states no opinion and resolution falls through. +// +// Not a oneof: two transitions need the losing field to survive. Unsuspending +// restores the limit it froze, and a lapsed extension falls back to its base +// rather than to the next layer. Pinned by +// TestControlsCoPresenceSurvivesEveryTransition in pkg/funds. +type SpendControls struct { + Extension *SpendExtension `json:"extension,omitempty"` + Limit *SpendLimit `json:"limit,omitempty"` + // Only valid together with limit: a period without its amount would + // reinterpret some other layer's number in a cadence that layer never + // agreed to. + Period *SpendControlsPeriod `json:"period,omitempty"` + Suspension *SpendSuspension `json:"suspension,omitempty"` +} + +func (s *SpendControls) GetExtension() *SpendExtension { + if s == nil { + return nil + } + return s.Extension +} + +func (s *SpendControls) GetLimit() *SpendLimit { + if s == nil { + return nil + } + return s.Limit +} + +func (s *SpendControls) GetPeriod() *SpendControlsPeriod { + if s == nil { + return nil + } + return s.Period +} + +func (s *SpendControls) GetSuspension() *SpendSuspension { + if s == nil { + return nil + } + return s.Suspension +} diff --git a/pkg/models/shared/spendextension.go b/pkg/models/shared/spendextension.go new file mode 100644 index 000000000..7c660235b --- /dev/null +++ b/pkg/models/shared/spendextension.go @@ -0,0 +1,52 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// SpendExtension replaces the row's total with a temporary one until +// +// expires_at. It never changes the period, and it never expresses a refusal — +// a temporary refusal is a SpendSuspension. +type SpendExtension struct { + ExpiresAt *time.Time `json:"expiresAt,omitempty"` + Limit *SpendLimit `json:"limit,omitempty"` + // Subject-visible: "why do I have this bump". Mutation rationale rides the + // history change_reason annotation instead. + Reason *string `json:"reason,omitempty"` +} + +func (s SpendExtension) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(s, "", false) +} + +func (s *SpendExtension) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &s, "", false, nil); err != nil { + return err + } + return nil +} + +func (s *SpendExtension) GetExpiresAt() *time.Time { + if s == nil { + return nil + } + return s.ExpiresAt +} + +func (s *SpendExtension) GetLimit() *SpendLimit { + if s == nil { + return nil + } + return s.Limit +} + +func (s *SpendExtension) GetReason() *string { + if s == nil { + return nil + } + return s.Reason +} diff --git a/pkg/models/shared/spendlimit.go b/pkg/models/shared/spendlimit.go new file mode 100644 index 000000000..aa27da694 --- /dev/null +++ b/pkg/models/shared/spendlimit.go @@ -0,0 +1,39 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SpendLimit is the three-way behavior fork. Which arms are legal depends on the +// +// scope carrying it; pkg/funds enforces that matrix, not the schema, because one +// SpendControls shape is shared by every scope. +// +// This message contains a oneof named kind. Only a single field of the following list may be set at a time: +// - unlimited +// - amount +// - blocked +type SpendLimit struct { + Amount *SpendLimitAmount `json:"amount,omitempty"` + Blocked *SpendLimitBlocked `json:"blocked,omitempty"` + Unlimited *SpendLimitUnlimited `json:"unlimited,omitempty"` +} + +func (s *SpendLimit) GetAmount() *SpendLimitAmount { + if s == nil { + return nil + } + return s.Amount +} + +func (s *SpendLimit) GetBlocked() *SpendLimitBlocked { + if s == nil { + return nil + } + return s.Blocked +} + +func (s *SpendLimit) GetUnlimited() *SpendLimitUnlimited { + if s == nil { + return nil + } + return s.Unlimited +} diff --git a/pkg/models/shared/spendlimitamount.go b/pkg/models/shared/spendlimitamount.go new file mode 100644 index 000000000..9ba59c058 --- /dev/null +++ b/pkg/models/shared/spendlimitamount.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SpendLimitAmount caps spend at money per resolved period. +type SpendLimitAmount struct { + Money *Money `json:"money,omitempty"` +} + +func (s *SpendLimitAmount) GetMoney() *Money { + if s == nil { + return nil + } + return s.Money +} diff --git a/pkg/models/shared/spendlimitblocked.go b/pkg/models/shared/spendlimitblocked.go new file mode 100644 index 000000000..4b504e15e --- /dev/null +++ b/pkg/models/shared/spendlimitblocked.go @@ -0,0 +1,10 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SpendLimitBlocked refuses supply at this scope. Distinct from suspension: +// +// blocked is a stated policy posture, suspension is a reversible freeze that +// preserves the numbers underneath it. +type SpendLimitBlocked struct { +} diff --git a/pkg/models/shared/spendlimitunlimited.go b/pkg/models/shared/spendlimitunlimited.go new file mode 100644 index 000000000..21051476b --- /dev/null +++ b/pkg/models/shared/spendlimitunlimited.go @@ -0,0 +1,10 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SpendLimitUnlimited is a tracking limit: full accounting, no admission +// +// condition. The maximum element, so an unlimited default makes grant rules +// no-ops. +type SpendLimitUnlimited struct { +} diff --git a/pkg/models/shared/spendsuspension.go b/pkg/models/shared/spendsuspension.go new file mode 100644 index 000000000..597ff8710 --- /dev/null +++ b/pkg/models/shared/spendsuspension.go @@ -0,0 +1,43 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// SpendSuspension freezes a scope without erasing the limit it must restore +// +// on unsuspend, which is why it lives beside the SpendLimit oneof rather than +// inside it. +type SpendSuspension struct { + // The reason field. + Reason *string `json:"reason,omitempty"` + SuspendedAt *time.Time `json:"suspendedAt,omitempty"` +} + +func (s SpendSuspension) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(s, "", false) +} + +func (s *SpendSuspension) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &s, "", false, nil); err != nil { + return err + } + return nil +} + +func (s *SpendSuspension) GetReason() *string { + if s == nil { + return nil + } + return s.Reason +} + +func (s *SpendSuspension) GetSuspendedAt() *time.Time { + if s == nil { + return nil + } + return s.SuspendedAt +} diff --git a/pkg/models/shared/ssoapplication.go b/pkg/models/shared/ssoapplication.go new file mode 100644 index 000000000..337de4aa5 --- /dev/null +++ b/pkg/models/shared/ssoapplication.go @@ -0,0 +1,179 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// SubjectType - How the user's identifier reaches this application. +type SubjectType string + +const ( + SubjectTypeSsoSubjectTypeUnspecified SubjectType = "SSO_SUBJECT_TYPE_UNSPECIFIED" + SubjectTypeSsoSubjectTypePairwise SubjectType = "SSO_SUBJECT_TYPE_PAIRWISE" + SubjectTypeSsoSubjectTypePublic SubjectType = "SSO_SUBJECT_TYPE_PUBLIC" + SubjectTypeSsoSubjectTypeCompatibility SubjectType = "SSO_SUBJECT_TYPE_COMPATIBILITY" +) + +func (e SubjectType) ToPointer() *SubjectType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SubjectType) IsExact() bool { + if e != nil { + switch *e { + case "SSO_SUBJECT_TYPE_UNSPECIFIED", "SSO_SUBJECT_TYPE_PAIRWISE", "SSO_SUBJECT_TYPE_PUBLIC", "SSO_SUBJECT_TYPE_COMPATIBILITY": + return true + } + } + return false +} + +// SSOApplication is one application your users sign in to through ConductorOne. +// +// This message contains a oneof named protocol. Only a single field of the following list may be set at a time: +// - oidc +// - saml +type SSOApplication struct { + // The entitlement a user must hold to sign in. Created with the SSO + // application and not settable by the caller. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The application in your catalog that owns this sign-in configuration. Its + // owners, entitlements, and access reviews govern who may sign in. + AppID *string `json:"appId,omitempty"` + AssertionLifetime *string `json:"assertionLifetime,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + // Description of the SSO application. + Description *string `json:"description,omitempty"` + // When true, sign-in through this application is refused. The application + // and its entitlement are left in place. + Disabled *bool `json:"disabled,omitempty"` + // Display name for the SSO application. + DisplayName *string `json:"displayName,omitempty"` + // Unique identifier for this SSO application. + ID *string `json:"id,omitempty"` + Oidc *SSOApplicationOIDCConfig `json:"oidc,omitempty"` + Saml *SSOApplicationSAMLConfig `json:"saml,omitempty"` + // The pairwise sector this application belongs to. Empty means the + // application is its own sector and shares linkability with nothing; set a + // shared value to issue one identifier across applications a user should + // appear the same to. Ignored when the subject type resolves to PUBLIC. + // Immutable once set. + SectorID *string `json:"sectorId,omitempty"` + SubjectCompatibility *SSOSubjectCompatibility `json:"subjectCompatibility,omitempty"` + // How the user's identifier reaches this application. + SubjectType *SubjectType `json:"subjectType,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (s SSOApplication) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(s, "", false) +} + +func (s *SSOApplication) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &s, "", false, nil); err != nil { + return err + } + return nil +} + +func (s *SSOApplication) GetAppEntitlementID() *string { + if s == nil { + return nil + } + return s.AppEntitlementID +} + +func (s *SSOApplication) GetAppID() *string { + if s == nil { + return nil + } + return s.AppID +} + +func (s *SSOApplication) GetAssertionLifetime() *string { + if s == nil { + return nil + } + return s.AssertionLifetime +} + +func (s *SSOApplication) GetCreatedAt() *time.Time { + if s == nil { + return nil + } + return s.CreatedAt +} + +func (s *SSOApplication) GetDescription() *string { + if s == nil { + return nil + } + return s.Description +} + +func (s *SSOApplication) GetDisabled() *bool { + if s == nil { + return nil + } + return s.Disabled +} + +func (s *SSOApplication) GetDisplayName() *string { + if s == nil { + return nil + } + return s.DisplayName +} + +func (s *SSOApplication) GetID() *string { + if s == nil { + return nil + } + return s.ID +} + +func (s *SSOApplication) GetOidc() *SSOApplicationOIDCConfig { + if s == nil { + return nil + } + return s.Oidc +} + +func (s *SSOApplication) GetSaml() *SSOApplicationSAMLConfig { + if s == nil { + return nil + } + return s.Saml +} + +func (s *SSOApplication) GetSectorID() *string { + if s == nil { + return nil + } + return s.SectorID +} + +func (s *SSOApplication) GetSubjectCompatibility() *SSOSubjectCompatibility { + if s == nil { + return nil + } + return s.SubjectCompatibility +} + +func (s *SSOApplication) GetSubjectType() *SubjectType { + if s == nil { + return nil + } + return s.SubjectType +} + +func (s *SSOApplication) GetUpdatedAt() *time.Time { + if s == nil { + return nil + } + return s.UpdatedAt +} diff --git a/pkg/models/shared/ssoapplicationhistoryentry.go b/pkg/models/shared/ssoapplicationhistoryentry.go new file mode 100644 index 000000000..3cb0d52de --- /dev/null +++ b/pkg/models/shared/ssoapplicationhistoryentry.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationHistoryEntry is one version of an SSO application and its +// +// history metadata. +type SSOApplicationHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *SSOApplication `json:"snapshot,omitempty"` +} + +func (s *SSOApplicationHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if s == nil { + return nil + } + return s.Metadata +} + +func (s *SSOApplicationHistoryEntry) GetSnapshot() *SSOApplication { + if s == nil { + return nil + } + return s.Snapshot +} diff --git a/pkg/models/shared/ssoapplicationoidcclient.go b/pkg/models/shared/ssoapplicationoidcclient.go new file mode 100644 index 000000000..62e4ef9a3 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclient.go @@ -0,0 +1,125 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// PkcePolicy - Effective PKCE policy. +type PkcePolicy string + +const ( + PkcePolicySsoApplicationOidcPkcePolicyUnspecified PkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED" + PkcePolicySsoApplicationOidcPkcePolicyRequiredS256 PkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256" + PkcePolicySsoApplicationOidcPkcePolicyAllowMissingForLegacy PkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY" +) + +func (e PkcePolicy) ToPointer() *PkcePolicy { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *PkcePolicy) IsExact() bool { + if e != nil { + switch *e { + case "SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED", "SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256", "SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY": + return true + } + } + return false +} + +// SSOApplicationOIDCClient is an App-owned OAuth client minted by C1. +type SSOApplicationOIDCClient struct { + // Application that owns this client. + AppID *string `json:"appId,omitempty"` + Authentication *SSOApplicationOIDCClientAuthentication `json:"authentication,omitempty"` + // Client ID generated by ConductorOne. + ClientID *string `json:"clientId,omitempty"` + CreatedAt *time.Time `json:"createdAt,omitempty"` + // Human-readable client name. + DisplayName *string `json:"displayName,omitempty"` + // Effective PKCE policy. + PkcePolicy *PkcePolicy `json:"pkcePolicy,omitempty"` + // Exact callback URLs registered for this client. + RedirectUris []string `json:"redirectUris,omitempty"` + // SSO application whose identity policy applies to this client. + SsoApplicationID *string `json:"ssoApplicationId,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (s SSOApplicationOIDCClient) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(s, "", false) +} + +func (s *SSOApplicationOIDCClient) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &s, "", false, nil); err != nil { + return err + } + return nil +} + +func (s *SSOApplicationOIDCClient) GetAppID() *string { + if s == nil { + return nil + } + return s.AppID +} + +func (s *SSOApplicationOIDCClient) GetAuthentication() *SSOApplicationOIDCClientAuthentication { + if s == nil { + return nil + } + return s.Authentication +} + +func (s *SSOApplicationOIDCClient) GetClientID() *string { + if s == nil { + return nil + } + return s.ClientID +} + +func (s *SSOApplicationOIDCClient) GetCreatedAt() *time.Time { + if s == nil { + return nil + } + return s.CreatedAt +} + +func (s *SSOApplicationOIDCClient) GetDisplayName() *string { + if s == nil { + return nil + } + return s.DisplayName +} + +func (s *SSOApplicationOIDCClient) GetPkcePolicy() *PkcePolicy { + if s == nil { + return nil + } + return s.PkcePolicy +} + +func (s *SSOApplicationOIDCClient) GetRedirectUris() []string { + if s == nil { + return nil + } + return s.RedirectUris +} + +func (s *SSOApplicationOIDCClient) GetSsoApplicationID() *string { + if s == nil { + return nil + } + return s.SsoApplicationID +} + +func (s *SSOApplicationOIDCClient) GetUpdatedAt() *time.Time { + if s == nil { + return nil + } + return s.UpdatedAt +} diff --git a/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.go b/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.go new file mode 100644 index 000000000..8fb6be6d6 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientauthclientsecretbasic.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientAuthClientSecretBasic - RFC 6749 client_secret_basic. C1 generates and returns the secret once. +type SSOApplicationOIDCClientAuthClientSecretBasic struct { +} diff --git a/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.go b/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.go new file mode 100644 index 000000000..49eaa00a5 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientauthclientsecretpost.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientAuthClientSecretPost - RFC 6749 client_secret_post. C1 generates and returns the secret once. +type SSOApplicationOIDCClientAuthClientSecretPost struct { +} diff --git a/pkg/models/shared/ssoapplicationoidcclientauthentication.go b/pkg/models/shared/ssoapplicationoidcclientauthentication.go new file mode 100644 index 000000000..fa0994662 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientauthentication.go @@ -0,0 +1,47 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientAuthentication is the exact token-endpoint client +// +// authentication method assigned to an OIDC client. +// +// This message contains a oneof named method. Only a single field of the following list may be set at a time: +// - none +// - clientSecretBasic +// - clientSecretPost +// - privateKeyJwt +type SSOApplicationOIDCClientAuthentication struct { + ClientSecretBasic *SSOApplicationOIDCClientAuthClientSecretBasic `json:"clientSecretBasic,omitempty"` + ClientSecretPost *SSOApplicationOIDCClientAuthClientSecretPost `json:"clientSecretPost,omitempty"` + None *SSOApplicationOIDCClientAuthNone `json:"none,omitempty"` + PrivateKeyJwt *SSOApplicationOIDCClientAuthPrivateKeyJWT `json:"privateKeyJwt,omitempty"` +} + +func (s *SSOApplicationOIDCClientAuthentication) GetClientSecretBasic() *SSOApplicationOIDCClientAuthClientSecretBasic { + if s == nil { + return nil + } + return s.ClientSecretBasic +} + +func (s *SSOApplicationOIDCClientAuthentication) GetClientSecretPost() *SSOApplicationOIDCClientAuthClientSecretPost { + if s == nil { + return nil + } + return s.ClientSecretPost +} + +func (s *SSOApplicationOIDCClientAuthentication) GetNone() *SSOApplicationOIDCClientAuthNone { + if s == nil { + return nil + } + return s.None +} + +func (s *SSOApplicationOIDCClientAuthentication) GetPrivateKeyJwt() *SSOApplicationOIDCClientAuthPrivateKeyJWT { + if s == nil { + return nil + } + return s.PrivateKeyJwt +} diff --git a/pkg/models/shared/ssoapplicationoidcclientauthnone.go b/pkg/models/shared/ssoapplicationoidcclientauthnone.go new file mode 100644 index 000000000..0fba744d2 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientauthnone.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientAuthNone - Public client authentication. No client credential is issued. +type SSOApplicationOIDCClientAuthNone struct { +} diff --git a/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.go b/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.go new file mode 100644 index 000000000..9f25b9137 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientauthprivatekeyjwt.go @@ -0,0 +1,19 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientAuthPrivateKeyJWT - RFC 7523 private_key_jwt using an inline RFC 7517 JWK Set. Multiple public +// +// signing keys allow overlap during relying-party key rotation; C1 selects by +// the assertion's `kid`. The relying party retains every private key. +type SSOApplicationOIDCClientAuthPrivateKeyJWT struct { + // The publicJwks field. + PublicJwks string `json:"publicJwks"` +} + +func (s *SSOApplicationOIDCClientAuthPrivateKeyJWT) GetPublicJwks() string { + if s == nil { + return "" + } + return s.PublicJwks +} diff --git a/pkg/models/shared/ssoapplicationoidcclientconfig.go b/pkg/models/shared/ssoapplicationoidcclientconfig.go new file mode 100644 index 000000000..4d41b48b8 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcclientconfig.go @@ -0,0 +1,75 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationOIDCClientConfigPkcePolicy - PKCE is required by default on create. On update, UNSPECIFIED preserves +// +// the current policy; set REQUIRED_S256 explicitly to tighten a legacy +// confidential client. +type SSOApplicationOIDCClientConfigPkcePolicy string + +const ( + SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyUnspecified SSOApplicationOIDCClientConfigPkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED" + SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyRequiredS256 SSOApplicationOIDCClientConfigPkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256" + SSOApplicationOIDCClientConfigPkcePolicySsoApplicationOidcPkcePolicyAllowMissingForLegacy SSOApplicationOIDCClientConfigPkcePolicy = "SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY" +) + +func (e SSOApplicationOIDCClientConfigPkcePolicy) ToPointer() *SSOApplicationOIDCClientConfigPkcePolicy { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SSOApplicationOIDCClientConfigPkcePolicy) IsExact() bool { + if e != nil { + switch *e { + case "SSO_APPLICATION_OIDC_PKCE_POLICY_UNSPECIFIED", "SSO_APPLICATION_OIDC_PKCE_POLICY_REQUIRED_S256", "SSO_APPLICATION_OIDC_PKCE_POLICY_ALLOW_MISSING_FOR_LEGACY": + return true + } + } + return false +} + +// SSOApplicationOIDCClientConfig is the administrator-supplied configuration +// +// from which C1 mints an App-owned OAuth client. The client ID is never input. +type SSOApplicationOIDCClientConfig struct { + Authentication *SSOApplicationOIDCClientAuthentication `json:"authentication"` + // Human-readable client name shown to administrators. + DisplayName string `json:"displayName"` + // PKCE is required by default on create. On update, UNSPECIFIED preserves + // the current policy; set REQUIRED_S256 explicitly to tighten a legacy + // confidential client. + PkcePolicy *SSOApplicationOIDCClientConfigPkcePolicy `json:"pkcePolicy,omitempty"` + // Exact redirect URIs the client may use after authorization. HTTPS and + // loopback HTTP are accepted; public clients may also use a reversed-DNS + // private-use scheme for native-app redirects. + RedirectUris []string `json:"redirectUris,omitempty"` +} + +func (s *SSOApplicationOIDCClientConfig) GetAuthentication() *SSOApplicationOIDCClientAuthentication { + if s == nil { + return nil + } + return s.Authentication +} + +func (s *SSOApplicationOIDCClientConfig) GetDisplayName() string { + if s == nil { + return "" + } + return s.DisplayName +} + +func (s *SSOApplicationOIDCClientConfig) GetPkcePolicy() *SSOApplicationOIDCClientConfigPkcePolicy { + if s == nil { + return nil + } + return s.PkcePolicy +} + +func (s *SSOApplicationOIDCClientConfig) GetRedirectUris() []string { + if s == nil { + return nil + } + return s.RedirectUris +} diff --git a/pkg/models/shared/ssoapplicationoidcconfig.go b/pkg/models/shared/ssoapplicationoidcconfig.go new file mode 100644 index 000000000..1808ac215 --- /dev/null +++ b/pkg/models/shared/ssoapplicationoidcconfig.go @@ -0,0 +1,51 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// IDTokenSignedResponseAlg - The algorithm used to sign this application's id_token. +type IDTokenSignedResponseAlg string + +const ( + IDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified IDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_UNSPECIFIED" + IDTokenSignedResponseAlgOidcSigningAlgorithmEddsa IDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_EDDSA" + IDTokenSignedResponseAlgOidcSigningAlgorithmEs256 IDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_ES256" + IDTokenSignedResponseAlgOidcSigningAlgorithmRs256 IDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_RS256" +) + +func (e IDTokenSignedResponseAlg) ToPointer() *IDTokenSignedResponseAlg { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *IDTokenSignedResponseAlg) IsExact() bool { + if e != nil { + switch *e { + case "OIDC_SIGNING_ALGORITHM_UNSPECIFIED", "OIDC_SIGNING_ALGORITHM_EDDSA", "OIDC_SIGNING_ALGORITHM_ES256", "OIDC_SIGNING_ALGORITHM_RS256": + return true + } + } + return false +} + +// SSOApplicationOIDCConfig is the OIDC-specific sign-in configuration. +type SSOApplicationOIDCConfig struct { + // Custom claims released to this application, in addition to the standard + // claims its granted scopes already release. + ClaimMappings []OIDCClaimMapping `json:"claimMappings,omitempty"` + // The algorithm used to sign this application's id_token. + IDTokenSignedResponseAlg *IDTokenSignedResponseAlg `json:"idTokenSignedResponseAlg,omitempty"` +} + +func (s *SSOApplicationOIDCConfig) GetClaimMappings() []OIDCClaimMapping { + if s == nil { + return nil + } + return s.ClaimMappings +} + +func (s *SSOApplicationOIDCConfig) GetIDTokenSignedResponseAlg() *IDTokenSignedResponseAlg { + if s == nil { + return nil + } + return s.IDTokenSignedResponseAlg +} diff --git a/pkg/models/shared/ssoapplicationsamlconfig.go b/pkg/models/shared/ssoapplicationsamlconfig.go new file mode 100644 index 000000000..e9325db31 --- /dev/null +++ b/pkg/models/shared/ssoapplicationsamlconfig.go @@ -0,0 +1,179 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// EncryptionAlgorithm - The algorithm used when encrypt_assertions is set. +type EncryptionAlgorithm string + +const ( + EncryptionAlgorithmSamlEncryptionAlgorithmUnspecified EncryptionAlgorithm = "SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED" + EncryptionAlgorithmSamlEncryptionAlgorithmAes256Gcm EncryptionAlgorithm = "SAML_ENCRYPTION_ALGORITHM_AES256_GCM" + EncryptionAlgorithmSamlEncryptionAlgorithmAes128Gcm EncryptionAlgorithm = "SAML_ENCRYPTION_ALGORITHM_AES128_GCM" + EncryptionAlgorithmSamlEncryptionAlgorithmAes256Cbc EncryptionAlgorithm = "SAML_ENCRYPTION_ALGORITHM_AES256_CBC" +) + +func (e EncryptionAlgorithm) ToPointer() *EncryptionAlgorithm { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *EncryptionAlgorithm) IsExact() bool { + if e != nil { + switch *e { + case "SAML_ENCRYPTION_ALGORITHM_UNSPECIFIED", "SAML_ENCRYPTION_ALGORITHM_AES256_GCM", "SAML_ENCRYPTION_ALGORITHM_AES128_GCM", "SAML_ENCRYPTION_ALGORITHM_AES256_CBC": + return true + } + } + return false +} + +// NameIDFormat - Set this when the service provider requires a specific NameID format. This +// +// also selects the NameID value semantics: EMAIL_ADDRESS uses the user's +// primary email, TRANSIENT creates a new value for each sign-in, and +// PERSISTENT uses the application's pairwise subject. Immutable once set. +type NameIDFormat string + +const ( + NameIDFormatSamlNameIDFormatUnspecified NameIDFormat = "SAML_NAME_ID_FORMAT_UNSPECIFIED" + NameIDFormatSamlNameIDFormatPersistent NameIDFormat = "SAML_NAME_ID_FORMAT_PERSISTENT" + NameIDFormatSamlNameIDFormatEmailAddress NameIDFormat = "SAML_NAME_ID_FORMAT_EMAIL_ADDRESS" + NameIDFormatSamlNameIDFormatUnspecifiedUrn NameIDFormat = "SAML_NAME_ID_FORMAT_UNSPECIFIED_URN" + NameIDFormatSamlNameIDFormatTransient NameIDFormat = "SAML_NAME_ID_FORMAT_TRANSIENT" +) + +func (e NameIDFormat) ToPointer() *NameIDFormat { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *NameIDFormat) IsExact() bool { + if e != nil { + switch *e { + case "SAML_NAME_ID_FORMAT_UNSPECIFIED", "SAML_NAME_ID_FORMAT_PERSISTENT", "SAML_NAME_ID_FORMAT_EMAIL_ADDRESS", "SAML_NAME_ID_FORMAT_UNSPECIFIED_URN", "SAML_NAME_ID_FORMAT_TRANSIENT": + return true + } + } + return false +} + +// SSOApplicationSAMLConfig is the SAML-specific sign-in configuration. +type SSOApplicationSAMLConfig struct { + // The Assertion Consumer Service URLs the assertion may be posted to. + // Matched exactly; a URL that is not in this list is refused. + AcsUrls []string `json:"acsUrls"` + // The attributes released in the assertion's AttributeStatement. SAML has no + // scopes, so this list is the whole release: the NameID carries the + // identifier and these carry everything else. + AttributeMappings []SAMLAttributeMapping `json:"attributeMappings,omitempty"` + // Encrypt the assertion. + EncryptAssertions *bool `json:"encryptAssertions,omitempty"` + // The algorithm used when encrypt_assertions is set. + EncryptionAlgorithm *EncryptionAlgorithm `json:"encryptionAlgorithm,omitempty"` + // Set this when the service provider requires a specific NameID format. This + // also selects the NameID value semantics: EMAIL_ADDRESS uses the user's + // primary email, TRANSIENT creates a new value for each sign-in, and + // PERSISTENT uses the application's pairwise subject. Immutable once set. + NameIDFormat *NameIDFormat `json:"nameIdFormat,omitempty"` + // Reject any AuthnRequest that is not signed by one of + // sp_signing_certificates. At least one signing certificate is required when + // this is set. + RequireSignedAuthnRequests *bool `json:"requireSignedAuthnRequests,omitempty"` + // Sign the assertion. At least one of sign_assertions or sign_responses must + // be set. + SignAssertions *bool `json:"signAssertions,omitempty"` + // Sign the response envelope. At least one of sign_assertions or + // sign_responses must be set. + SignResponses *bool `json:"signResponses,omitempty"` + // The service provider's DER-encoded encryption certificate, taken from the + // encryption KeyDescriptor in its metadata. Required when encrypt_assertions + // is set. + SpEncryptionCertificate *string `json:"spEncryptionCertificate,omitempty"` + // The service provider's entity ID, taken from its metadata. It is the + // audience every assertion this application issues is restricted to, and it + // is what the service provider presents at sign-in. Set it at creation: it is + // fixed for the life of the application, because changing it re-points every + // assertion already issued. An entity ID already in use by another SSO + // application in the tenant is rejected. + SpEntityID string `json:"spEntityId"` + // The service provider's DER-encoded signing certificates, taken from the + // signing KeyDescriptors in its metadata. + SpSigningCertificates []string `json:"spSigningCertificates,omitempty"` +} + +func (s *SSOApplicationSAMLConfig) GetAcsUrls() []string { + if s == nil { + return nil + } + return s.AcsUrls +} + +func (s *SSOApplicationSAMLConfig) GetAttributeMappings() []SAMLAttributeMapping { + if s == nil { + return nil + } + return s.AttributeMappings +} + +func (s *SSOApplicationSAMLConfig) GetEncryptAssertions() *bool { + if s == nil { + return nil + } + return s.EncryptAssertions +} + +func (s *SSOApplicationSAMLConfig) GetEncryptionAlgorithm() *EncryptionAlgorithm { + if s == nil { + return nil + } + return s.EncryptionAlgorithm +} + +func (s *SSOApplicationSAMLConfig) GetNameIDFormat() *NameIDFormat { + if s == nil { + return nil + } + return s.NameIDFormat +} + +func (s *SSOApplicationSAMLConfig) GetRequireSignedAuthnRequests() *bool { + if s == nil { + return nil + } + return s.RequireSignedAuthnRequests +} + +func (s *SSOApplicationSAMLConfig) GetSignAssertions() *bool { + if s == nil { + return nil + } + return s.SignAssertions +} + +func (s *SSOApplicationSAMLConfig) GetSignResponses() *bool { + if s == nil { + return nil + } + return s.SignResponses +} + +func (s *SSOApplicationSAMLConfig) GetSpEncryptionCertificate() *string { + if s == nil { + return nil + } + return s.SpEncryptionCertificate +} + +func (s *SSOApplicationSAMLConfig) GetSpEntityID() string { + if s == nil { + return "" + } + return s.SpEntityID +} + +func (s *SSOApplicationSAMLConfig) GetSpSigningCertificates() []string { + if s == nil { + return nil + } + return s.SpSigningCertificates +} diff --git a/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.go b/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.go new file mode 100644 index 000000000..da0978ece --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityrequest.go @@ -0,0 +1,18 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest deletes a +// +// bounded batch of compatibility-subject bindings. +type SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest struct { + // The userIds field. + UserIds []string `json:"userIds,omitempty"` +} + +func (s *SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest) GetUserIds() []string { + if s == nil { + return nil + } + return s.UserIds +} diff --git a/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.go b/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.go new file mode 100644 index 000000000..62298454a --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicebatchdeletesubjectcompatibilityresponse.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse reports bounded +// +// recovery progress. +type SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse struct { + // The deletedRows field. + DeletedRows *int `json:"deletedRows,omitempty"` + // The issues field. + Issues []SSOSubjectCompatibilityDeleteIssue `json:"issues,omitempty"` +} + +func (s *SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetDeletedRows() *int { + if s == nil { + return nil + } + return s.DeletedRows +} + +func (s *SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse) GetIssues() []SSOSubjectCompatibilityDeleteIssue { + if s == nil { + return nil + } + return s.Issues +} diff --git a/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.go b/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.go new file mode 100644 index 000000000..820e19e93 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityrequest.go @@ -0,0 +1,37 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceBatchImportSubjectCompatibilityRequest validates or +// +// imports a bounded batch of per-user subject bindings. +type SSOApplicationServiceBatchImportSubjectCompatibilityRequest struct { + // When false, validate without writing. Clients should validate every batch + // before beginning the apply pass. + Apply *bool `json:"apply,omitempty"` + // Client-parsed rows. Each request is bounded to 50 entries. + Entries []SSOSubjectCompatibilityImportEntry `json:"entries,omitempty"` + // Client-generated identifier shared by every batch from one source file. + ImportID *string `json:"importId,omitempty"` +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetApply() *bool { + if s == nil { + return nil + } + return s.Apply +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetEntries() []SSOSubjectCompatibilityImportEntry { + if s == nil { + return nil + } + return s.Entries +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityRequest) GetImportID() *string { + if s == nil { + return nil + } + return s.ImportID +} diff --git a/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.go b/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.go new file mode 100644 index 000000000..1ff2c8f63 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicebatchimportsubjectcompatibilityresponse.go @@ -0,0 +1,77 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceBatchImportSubjectCompatibilityResponse summarizes one +// +// bounded validation or apply batch. +type SSOApplicationServiceBatchImportSubjectCompatibilityResponse struct { + // Import-created binding owners that block one or more submitted corrections. + // This is a subset of recoverable_user_ids. + BlockingUserIds []string `json:"blockingUserIds,omitempty"` + // Number of bindings successfully written. Zero for validation-only + // requests; may be less than valid_rows if apply stops on a write failure. + ImportedRows *int `json:"importedRows,omitempty"` + // Users whose bindings were created by this import, or were already created + // by an earlier retry carrying the same import_id. + ImportedUserIds []string `json:"importedUserIds,omitempty"` + // Row-level validation or apply failures. + Issues []SSOSubjectCompatibilityImportIssue `json:"issues,omitempty"` + // Users whose import-created binding is implicated by a submitted row. This + // may include the current owner of a submitted subject even when that owner + // was not itself submitted. + RecoverableUserIds []string `json:"recoverableUserIds,omitempty"` + // Number of entries in this batch. + TotalRows *int `json:"totalRows,omitempty"` + // Number of rows that can be imported. + ValidRows *int `json:"validRows,omitempty"` +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetBlockingUserIds() []string { + if s == nil { + return nil + } + return s.BlockingUserIds +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetImportedRows() *int { + if s == nil { + return nil + } + return s.ImportedRows +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetImportedUserIds() []string { + if s == nil { + return nil + } + return s.ImportedUserIds +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetIssues() []SSOSubjectCompatibilityImportIssue { + if s == nil { + return nil + } + return s.Issues +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetRecoverableUserIds() []string { + if s == nil { + return nil + } + return s.RecoverableUserIds +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetTotalRows() *int { + if s == nil { + return nil + } + return s.TotalRows +} + +func (s *SSOApplicationServiceBatchImportSubjectCompatibilityResponse) GetValidRows() *int { + if s == nil { + return nil + } + return s.ValidRows +} diff --git a/pkg/models/shared/ssoapplicationservicecreateclientrequest.go b/pkg/models/shared/ssoapplicationservicecreateclientrequest.go new file mode 100644 index 000000000..7cdb446be --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicecreateclientrequest.go @@ -0,0 +1,17 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceCreateClientRequest mints an additional App-owned +// +// client. The caller supplies configuration, never a client ID. +type SSOApplicationServiceCreateClientRequest struct { + Client *SSOApplicationOIDCClientConfig `json:"client"` +} + +func (s *SSOApplicationServiceCreateClientRequest) GetClient() *SSOApplicationOIDCClientConfig { + if s == nil { + return nil + } + return s.Client +} diff --git a/pkg/models/shared/ssoapplicationservicecreateclientresponse.go b/pkg/models/shared/ssoapplicationservicecreateclientresponse.go new file mode 100644 index 000000000..5ee4e6181 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicecreateclientresponse.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceCreateClientResponse contains the generated client and +// +// its one-time secret, when applicable. +type SSOApplicationServiceCreateClientResponse struct { + Client *SSOApplicationOIDCClient `json:"client,omitempty"` + // Returned once for client_secret_basic/client_secret_post; empty for + // none/private_key_jwt. + ClientSecret *string `json:"clientSecret,omitempty"` +} + +func (s *SSOApplicationServiceCreateClientResponse) GetClient() *SSOApplicationOIDCClient { + if s == nil { + return nil + } + return s.Client +} + +func (s *SSOApplicationServiceCreateClientResponse) GetClientSecret() *string { + if s == nil { + return nil + } + return s.ClientSecret +} diff --git a/pkg/models/shared/ssoapplicationservicecreaterequest.go b/pkg/models/shared/ssoapplicationservicecreaterequest.go new file mode 100644 index 000000000..72668f79f --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicecreaterequest.go @@ -0,0 +1,116 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceCreateRequestSubjectType - How the user's identifier reaches this application. Leave unset to use the +// +// tenant default. +type SSOApplicationServiceCreateRequestSubjectType string + +const ( + SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypeUnspecified SSOApplicationServiceCreateRequestSubjectType = "SSO_SUBJECT_TYPE_UNSPECIFIED" + SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypePairwise SSOApplicationServiceCreateRequestSubjectType = "SSO_SUBJECT_TYPE_PAIRWISE" + SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypePublic SSOApplicationServiceCreateRequestSubjectType = "SSO_SUBJECT_TYPE_PUBLIC" + SSOApplicationServiceCreateRequestSubjectTypeSsoSubjectTypeCompatibility SSOApplicationServiceCreateRequestSubjectType = "SSO_SUBJECT_TYPE_COMPATIBILITY" +) + +func (e SSOApplicationServiceCreateRequestSubjectType) ToPointer() *SSOApplicationServiceCreateRequestSubjectType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *SSOApplicationServiceCreateRequestSubjectType) IsExact() bool { + if e != nil { + switch *e { + case "SSO_SUBJECT_TYPE_UNSPECIFIED", "SSO_SUBJECT_TYPE_PAIRWISE", "SSO_SUBJECT_TYPE_PUBLIC", "SSO_SUBJECT_TYPE_COMPATIBILITY": + return true + } + } + return false +} + +// SSOApplicationServiceCreateRequest creates an SSO application. +// +// This message contains a oneof named protocol. Only a single field of the following list may be set at a time: +// - oidc +// - saml +type SSOApplicationServiceCreateRequest struct { + AssertionLifetime *string `json:"assertionLifetime,omitempty"` + // Description of the SSO application. + Description *string `json:"description,omitempty"` + // Display name for the SSO application. + DisplayName string `json:"displayName"` + InitialClient *SSOApplicationOIDCClientConfig `json:"initialClient,omitempty"` + Oidc *SSOApplicationOIDCConfig `json:"oidc,omitempty"` + Saml *SSOApplicationSAMLConfig `json:"saml,omitempty"` + // The pairwise sector this application belongs to. Empty means the + // application is its own sector. Immutable after creation. + SectorID *string `json:"sectorId,omitempty"` + SubjectCompatibility *SSOSubjectCompatibility `json:"subjectCompatibility,omitempty"` + // How the user's identifier reaches this application. Leave unset to use the + // tenant default. + SubjectType *SSOApplicationServiceCreateRequestSubjectType `json:"subjectType,omitempty"` +} + +func (s *SSOApplicationServiceCreateRequest) GetAssertionLifetime() *string { + if s == nil { + return nil + } + return s.AssertionLifetime +} + +func (s *SSOApplicationServiceCreateRequest) GetDescription() *string { + if s == nil { + return nil + } + return s.Description +} + +func (s *SSOApplicationServiceCreateRequest) GetDisplayName() string { + if s == nil { + return "" + } + return s.DisplayName +} + +func (s *SSOApplicationServiceCreateRequest) GetInitialClient() *SSOApplicationOIDCClientConfig { + if s == nil { + return nil + } + return s.InitialClient +} + +func (s *SSOApplicationServiceCreateRequest) GetOidc() *SSOApplicationOIDCConfig { + if s == nil { + return nil + } + return s.Oidc +} + +func (s *SSOApplicationServiceCreateRequest) GetSaml() *SSOApplicationSAMLConfig { + if s == nil { + return nil + } + return s.Saml +} + +func (s *SSOApplicationServiceCreateRequest) GetSectorID() *string { + if s == nil { + return nil + } + return s.SectorID +} + +func (s *SSOApplicationServiceCreateRequest) GetSubjectCompatibility() *SSOSubjectCompatibility { + if s == nil { + return nil + } + return s.SubjectCompatibility +} + +func (s *SSOApplicationServiceCreateRequest) GetSubjectType() *SSOApplicationServiceCreateRequestSubjectType { + if s == nil { + return nil + } + return s.SubjectType +} diff --git a/pkg/models/shared/ssoapplicationservicecreateresponse.go b/pkg/models/shared/ssoapplicationservicecreateresponse.go new file mode 100644 index 000000000..b97bee667 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicecreateresponse.go @@ -0,0 +1,33 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceCreateResponse returns the created SSO application. +type SSOApplicationServiceCreateResponse struct { + Application *SSOApplication `json:"application,omitempty"` + Client *SSOApplicationOIDCClient `json:"client,omitempty"` + // Confidential-client secret returned once. Empty for SAML and public OIDC + // clients. C1 stores only its hash. + ClientSecret *string `json:"clientSecret,omitempty"` +} + +func (s *SSOApplicationServiceCreateResponse) GetApplication() *SSOApplication { + if s == nil { + return nil + } + return s.Application +} + +func (s *SSOApplicationServiceCreateResponse) GetClient() *SSOApplicationOIDCClient { + if s == nil { + return nil + } + return s.Client +} + +func (s *SSOApplicationServiceCreateResponse) GetClientSecret() *string { + if s == nil { + return nil + } + return s.ClientSecret +} diff --git a/pkg/models/shared/ssoapplicationservicedeleteclientrequest.go b/pkg/models/shared/ssoapplicationservicedeleteclientrequest.go new file mode 100644 index 000000000..e2097f70b --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicedeleteclientrequest.go @@ -0,0 +1,16 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceDeleteClientRequest deletes one App-owned OAuth client. +type SSOApplicationServiceDeleteClientRequest struct { + // Generated client ID to delete. + ClientID string `json:"clientId"` +} + +func (s *SSOApplicationServiceDeleteClientRequest) GetClientID() string { + if s == nil { + return "" + } + return s.ClientID +} diff --git a/pkg/models/shared/ssoapplicationservicedeleteclientresponse.go b/pkg/models/shared/ssoapplicationservicedeleteclientresponse.go new file mode 100644 index 000000000..bca373b69 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicedeleteclientresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceDeleteClientResponse confirms deletion. +type SSOApplicationServiceDeleteClientResponse struct { +} diff --git a/pkg/models/shared/ssoapplicationservicedeleterequest.go b/pkg/models/shared/ssoapplicationservicedeleterequest.go new file mode 100644 index 000000000..06477bff5 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicedeleterequest.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceDeleteRequest deletes an SSO application. +type SSOApplicationServiceDeleteRequest struct { +} diff --git a/pkg/models/shared/ssoapplicationservicedeleteresponse.go b/pkg/models/shared/ssoapplicationservicedeleteresponse.go new file mode 100644 index 000000000..ba66bb55c --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicedeleteresponse.go @@ -0,0 +1,7 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceDeleteResponse confirms deletion. +type SSOApplicationServiceDeleteResponse struct { +} diff --git a/pkg/models/shared/ssoapplicationservicegetresponse.go b/pkg/models/shared/ssoapplicationservicegetresponse.go new file mode 100644 index 000000000..d3a0da5a5 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceGetResponse returns a single SSO application. +type SSOApplicationServiceGetResponse struct { + Application *SSOApplication `json:"application,omitempty"` +} + +func (s *SSOApplicationServiceGetResponse) GetApplication() *SSOApplication { + if s == nil { + return nil + } + return s.Application +} diff --git a/pkg/models/shared/ssoapplicationservicelistclientsresponse.go b/pkg/models/shared/ssoapplicationservicelistclientsresponse.go new file mode 100644 index 000000000..db61a7834 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicelistclientsresponse.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceListClientsResponse contains a page of App-owned OAuth +// +// clients. +type SSOApplicationServiceListClientsResponse struct { + // App-owned clients in this page. + List []SSOApplicationOIDCClient `json:"list,omitempty"` + // Pagination token for the next page, or empty when complete. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (s *SSOApplicationServiceListClientsResponse) GetList() []SSOApplicationOIDCClient { + if s == nil { + return nil + } + return s.List +} + +func (s *SSOApplicationServiceListClientsResponse) GetNextPageToken() *string { + if s == nil { + return nil + } + return s.NextPageToken +} diff --git a/pkg/models/shared/ssoapplicationservicelisthistoryresponse.go b/pkg/models/shared/ssoapplicationservicelisthistoryresponse.go new file mode 100644 index 000000000..0cd2f21c2 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicelisthistoryresponse.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceListHistoryResponse returns SSO application history +// +// entries. +type SSOApplicationServiceListHistoryResponse struct { + // The page of history entries, newest first. + List []SSOApplicationHistoryEntry `json:"list,omitempty"` + // Pagination token for the next page, or empty if there are no more results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (s *SSOApplicationServiceListHistoryResponse) GetList() []SSOApplicationHistoryEntry { + if s == nil { + return nil + } + return s.List +} + +func (s *SSOApplicationServiceListHistoryResponse) GetNextPageToken() *string { + if s == nil { + return nil + } + return s.NextPageToken +} diff --git a/pkg/models/shared/ssoapplicationservicelistresponse.go b/pkg/models/shared/ssoapplicationservicelistresponse.go new file mode 100644 index 000000000..1d98bb8ff --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicelistresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceListResponse returns a page of SSO applications. +type SSOApplicationServiceListResponse struct { + // The page of SSO applications. + List []SSOApplication `json:"list,omitempty"` + // Pagination token for the next page, or empty if there are no more results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (s *SSOApplicationServiceListResponse) GetList() []SSOApplication { + if s == nil { + return nil + } + return s.List +} + +func (s *SSOApplicationServiceListResponse) GetNextPageToken() *string { + if s == nil { + return nil + } + return s.NextPageToken +} diff --git a/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.go b/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.go new file mode 100644 index 000000000..3ba93ce0f --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadatarequest.go @@ -0,0 +1,19 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceParseSAMLServiceProviderMetadataRequest carries one +// +// SAML service-provider metadata document to parse. +type SSOApplicationServiceParseSAMLServiceProviderMetadataRequest struct { + // The SP metadata XML document, exactly as downloaded or exported from the + // service provider. Maximum 1 MiB. The document is parsed, never stored. + MetadataXML string `json:"metadataXml"` +} + +func (s *SSOApplicationServiceParseSAMLServiceProviderMetadataRequest) GetMetadataXML() string { + if s == nil { + return "" + } + return s.MetadataXML +} diff --git a/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.go b/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.go new file mode 100644 index 000000000..4adea2237 --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceparsesamlserviceprovidermetadataresponse.go @@ -0,0 +1,28 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceParseSAMLServiceProviderMetadataResponse returns the +// +// SAML configuration derived from one metadata document and every finding the +// parser raised about it. +type SSOApplicationServiceParseSAMLServiceProviderMetadataResponse struct { + Config *SSOApplicationSAMLConfig `json:"config,omitempty"` + // Everything the parser noticed about the document, including requirements + // it could not map into the configuration. + Findings []SAMLMetadataFinding `json:"findings,omitempty"` +} + +func (s *SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetConfig() *SSOApplicationSAMLConfig { + if s == nil { + return nil + } + return s.Config +} + +func (s *SSOApplicationServiceParseSAMLServiceProviderMetadataResponse) GetFindings() []SAMLMetadataFinding { + if s == nil { + return nil + } + return s.Findings +} diff --git a/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.go b/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.go new file mode 100644 index 000000000..7ca0fd13f --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicerotateclientsecretrequest.go @@ -0,0 +1,18 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceRotateClientSecretRequest rotates one confidential +// +// App-owned client's secret. +type SSOApplicationServiceRotateClientSecretRequest struct { + // Generated client ID whose secret will be rotated. + ClientID string `json:"clientId"` +} + +func (s *SSOApplicationServiceRotateClientSecretRequest) GetClientID() string { + if s == nil { + return "" + } + return s.ClientID +} diff --git a/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.go b/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.go new file mode 100644 index 000000000..ddbbec9d3 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicerotateclientsecretresponse.go @@ -0,0 +1,18 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceRotateClientSecretResponse contains the replacement +// +// secret. The value cannot be retrieved again. +type SSOApplicationServiceRotateClientSecretResponse struct { + // New client secret, shown exactly once. + ClientSecret *string `json:"clientSecret,omitempty"` +} + +func (s *SSOApplicationServiceRotateClientSecretResponse) GetClientSecret() *string { + if s == nil { + return nil + } + return s.ClientSecret +} diff --git a/pkg/models/shared/ssoapplicationservicesearchrequest.go b/pkg/models/shared/ssoapplicationservicesearchrequest.go new file mode 100644 index 000000000..40dbc31a6 --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicesearchrequest.go @@ -0,0 +1,44 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceSearchRequest searches SSO applications with filters. +type SSOApplicationServiceSearchRequest struct { + // Optional filter by applications in your catalog. Empty matches any + // application. + AppIds []string `json:"appIds,omitempty"` + // Maximum number of results to return per page. + PageSize *int `json:"pageSize,omitempty"` + // Pagination token from a previous response. + PageToken *string `json:"pageToken,omitempty"` + // Optional text query matched against display_name and description. + Query *string `json:"query,omitempty"` +} + +func (s *SSOApplicationServiceSearchRequest) GetAppIds() []string { + if s == nil { + return nil + } + return s.AppIds +} + +func (s *SSOApplicationServiceSearchRequest) GetPageSize() *int { + if s == nil { + return nil + } + return s.PageSize +} + +func (s *SSOApplicationServiceSearchRequest) GetPageToken() *string { + if s == nil { + return nil + } + return s.PageToken +} + +func (s *SSOApplicationServiceSearchRequest) GetQuery() *string { + if s == nil { + return nil + } + return s.Query +} diff --git a/pkg/models/shared/ssoapplicationservicesearchresponse.go b/pkg/models/shared/ssoapplicationservicesearchresponse.go new file mode 100644 index 000000000..7c2ac2d1f --- /dev/null +++ b/pkg/models/shared/ssoapplicationservicesearchresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceSearchResponse returns matching SSO applications. +type SSOApplicationServiceSearchResponse struct { + // Matching SSO applications. + List []SSOApplication `json:"list,omitempty"` + // Token for the next page. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (s *SSOApplicationServiceSearchResponse) GetList() []SSOApplication { + if s == nil { + return nil + } + return s.List +} + +func (s *SSOApplicationServiceSearchResponse) GetNextPageToken() *string { + if s == nil { + return nil + } + return s.NextPageToken +} diff --git a/pkg/models/shared/ssoapplicationserviceupdateclientrequest.go b/pkg/models/shared/ssoapplicationserviceupdateclientrequest.go new file mode 100644 index 000000000..695fe912b --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceupdateclientrequest.go @@ -0,0 +1,26 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceUpdateClientRequest replaces display name, redirect +// +// URIs, private-key JWKS, or tightens legacy PKCE to required. +type SSOApplicationServiceUpdateClientRequest struct { + Client *SSOApplicationOIDCClientConfig `json:"client"` + // Generated client ID to update. + ClientID string `json:"clientId"` +} + +func (s *SSOApplicationServiceUpdateClientRequest) GetClient() *SSOApplicationOIDCClientConfig { + if s == nil { + return nil + } + return s.Client +} + +func (s *SSOApplicationServiceUpdateClientRequest) GetClientID() string { + if s == nil { + return "" + } + return s.ClientID +} diff --git a/pkg/models/shared/ssoapplicationserviceupdateclientresponse.go b/pkg/models/shared/ssoapplicationserviceupdateclientresponse.go new file mode 100644 index 000000000..d07ab615a --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceupdateclientresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceUpdateClientResponse contains the updated client. +type SSOApplicationServiceUpdateClientResponse struct { + Client *SSOApplicationOIDCClient `json:"client,omitempty"` +} + +func (s *SSOApplicationServiceUpdateClientResponse) GetClient() *SSOApplicationOIDCClient { + if s == nil { + return nil + } + return s.Client +} diff --git a/pkg/models/shared/ssoapplicationserviceupdaterequest.go b/pkg/models/shared/ssoapplicationserviceupdaterequest.go new file mode 100644 index 000000000..650b409c8 --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceupdaterequest.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceUpdateRequest updates an SSO application. +type SSOApplicationServiceUpdateRequest struct { + Application *SSOApplication `json:"application"` + UpdateMask *string `json:"updateMask"` +} + +func (s *SSOApplicationServiceUpdateRequest) GetApplication() *SSOApplication { + if s == nil { + return nil + } + return s.Application +} + +func (s *SSOApplicationServiceUpdateRequest) GetUpdateMask() *string { + if s == nil { + return nil + } + return s.UpdateMask +} diff --git a/pkg/models/shared/ssoapplicationserviceupdateresponse.go b/pkg/models/shared/ssoapplicationserviceupdateresponse.go new file mode 100644 index 000000000..03f3d2d9a --- /dev/null +++ b/pkg/models/shared/ssoapplicationserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOApplicationServiceUpdateResponse returns the updated SSO application. +type SSOApplicationServiceUpdateResponse struct { + Application *SSOApplication `json:"application,omitempty"` +} + +func (s *SSOApplicationServiceUpdateResponse) GetApplication() *SSOApplication { + if s == nil { + return nil + } + return s.Application +} diff --git a/pkg/models/shared/ssosettings.go b/pkg/models/shared/ssosettings.go new file mode 100644 index 000000000..80f9f6293 --- /dev/null +++ b/pkg/models/shared/ssosettings.go @@ -0,0 +1,137 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// DefaultIDTokenSignedResponseAlg - The id_token signing algorithm applied to OIDC applications that do not +// +// choose one. When unset, the server uses EdDSA. +type DefaultIDTokenSignedResponseAlg string + +const ( + DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmUnspecified DefaultIDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_UNSPECIFIED" + DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmEddsa DefaultIDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_EDDSA" + DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmEs256 DefaultIDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_ES256" + DefaultIDTokenSignedResponseAlgOidcSigningAlgorithmRs256 DefaultIDTokenSignedResponseAlg = "OIDC_SIGNING_ALGORITHM_RS256" +) + +func (e DefaultIDTokenSignedResponseAlg) ToPointer() *DefaultIDTokenSignedResponseAlg { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DefaultIDTokenSignedResponseAlg) IsExact() bool { + if e != nil { + switch *e { + case "OIDC_SIGNING_ALGORITHM_UNSPECIFIED", "OIDC_SIGNING_ALGORITHM_EDDSA", "OIDC_SIGNING_ALGORITHM_ES256", "OIDC_SIGNING_ALGORITHM_RS256": + return true + } + } + return false +} + +// DefaultSubjectType - The subject type materialized onto new SSO applications that do not choose +// +// one. Changing this default does not change existing applications. When +// unset, the server uses pairwise subjects. +type DefaultSubjectType string + +const ( + DefaultSubjectTypeSsoSubjectTypeUnspecified DefaultSubjectType = "SSO_SUBJECT_TYPE_UNSPECIFIED" + DefaultSubjectTypeSsoSubjectTypePairwise DefaultSubjectType = "SSO_SUBJECT_TYPE_PAIRWISE" + DefaultSubjectTypeSsoSubjectTypePublic DefaultSubjectType = "SSO_SUBJECT_TYPE_PUBLIC" + DefaultSubjectTypeSsoSubjectTypeCompatibility DefaultSubjectType = "SSO_SUBJECT_TYPE_COMPATIBILITY" +) + +func (e DefaultSubjectType) ToPointer() *DefaultSubjectType { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *DefaultSubjectType) IsExact() bool { + if e != nil { + switch *e { + case "SSO_SUBJECT_TYPE_UNSPECIFIED", "SSO_SUBJECT_TYPE_PAIRWISE", "SSO_SUBJECT_TYPE_PUBLIC", "SSO_SUBJECT_TYPE_COMPATIBILITY": + return true + } + } + return false +} + +// SSOSettings is the per-tenant configuration for ConductorOne acting as an SSO +// +// provider. +type SSOSettings struct { + CreatedAt *time.Time `json:"createdAt,omitempty"` + DefaultAssertionLifetime *string `json:"defaultAssertionLifetime,omitempty"` + // The id_token signing algorithm applied to OIDC applications that do not + // choose one. When unset, the server uses EdDSA. + DefaultIDTokenSignedResponseAlg *DefaultIDTokenSignedResponseAlg `json:"defaultIdTokenSignedResponseAlg,omitempty"` + // The subject type materialized onto new SSO applications that do not choose + // one. Changing this default does not change existing applications. When + // unset, the server uses pairwise subjects. + DefaultSubjectType *DefaultSubjectType `json:"defaultSubjectType,omitempty"` + // Master switch for the SSO provider. ConductorOne also gates the feature + // behind an operator-controlled rollout flag; this is the tenant + // administrator's intent. Individual SSO applications can still be disabled + // one at a time. + Enabled *bool `json:"enabled,omitempty"` + UpdatedAt *time.Time `json:"updatedAt,omitempty"` +} + +func (s SSOSettings) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(s, "", false) +} + +func (s *SSOSettings) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &s, "", false, nil); err != nil { + return err + } + return nil +} + +func (s *SSOSettings) GetCreatedAt() *time.Time { + if s == nil { + return nil + } + return s.CreatedAt +} + +func (s *SSOSettings) GetDefaultAssertionLifetime() *string { + if s == nil { + return nil + } + return s.DefaultAssertionLifetime +} + +func (s *SSOSettings) GetDefaultIDTokenSignedResponseAlg() *DefaultIDTokenSignedResponseAlg { + if s == nil { + return nil + } + return s.DefaultIDTokenSignedResponseAlg +} + +func (s *SSOSettings) GetDefaultSubjectType() *DefaultSubjectType { + if s == nil { + return nil + } + return s.DefaultSubjectType +} + +func (s *SSOSettings) GetEnabled() *bool { + if s == nil { + return nil + } + return s.Enabled +} + +func (s *SSOSettings) GetUpdatedAt() *time.Time { + if s == nil { + return nil + } + return s.UpdatedAt +} diff --git a/pkg/models/shared/ssosettingshistoryentry.go b/pkg/models/shared/ssosettingshistoryentry.go new file mode 100644 index 000000000..d4ca5e223 --- /dev/null +++ b/pkg/models/shared/ssosettingshistoryentry.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSettingsHistoryEntry is one version of the tenant's SSO settings and its +// +// change metadata. +type SSOSettingsHistoryEntry struct { + Metadata *HistoryEntryMetadata `json:"metadata,omitempty"` + Snapshot *SSOSettings `json:"snapshot,omitempty"` +} + +func (s *SSOSettingsHistoryEntry) GetMetadata() *HistoryEntryMetadata { + if s == nil { + return nil + } + return s.Metadata +} + +func (s *SSOSettingsHistoryEntry) GetSnapshot() *SSOSettings { + if s == nil { + return nil + } + return s.Snapshot +} diff --git a/pkg/models/shared/ssosettingsservicegetresponse.go b/pkg/models/shared/ssosettingsservicegetresponse.go new file mode 100644 index 000000000..7b2f85833 --- /dev/null +++ b/pkg/models/shared/ssosettingsservicegetresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSettingsServiceGetResponse returns the tenant's SSO provider settings. +type SSOSettingsServiceGetResponse struct { + Settings *SSOSettings `json:"settings,omitempty"` +} + +func (s *SSOSettingsServiceGetResponse) GetSettings() *SSOSettings { + if s == nil { + return nil + } + return s.Settings +} diff --git a/pkg/models/shared/ssosettingsservicelisthistoryresponse.go b/pkg/models/shared/ssosettingsservicelisthistoryresponse.go new file mode 100644 index 000000000..052f6cdc4 --- /dev/null +++ b/pkg/models/shared/ssosettingsservicelisthistoryresponse.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSettingsServiceListHistoryResponse returns SSO settings history entries. +type SSOSettingsServiceListHistoryResponse struct { + // The page of history entries, newest first. + List []SSOSettingsHistoryEntry `json:"list,omitempty"` + // Pagination token for the next page, or empty if there are no more results. + NextPageToken *string `json:"nextPageToken,omitempty"` +} + +func (s *SSOSettingsServiceListHistoryResponse) GetList() []SSOSettingsHistoryEntry { + if s == nil { + return nil + } + return s.List +} + +func (s *SSOSettingsServiceListHistoryResponse) GetNextPageToken() *string { + if s == nil { + return nil + } + return s.NextPageToken +} diff --git a/pkg/models/shared/ssosettingsserviceupdaterequest.go b/pkg/models/shared/ssosettingsserviceupdaterequest.go new file mode 100644 index 000000000..25dbb80b2 --- /dev/null +++ b/pkg/models/shared/ssosettingsserviceupdaterequest.go @@ -0,0 +1,23 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSettingsServiceUpdateRequest updates the tenant's SSO provider settings. +type SSOSettingsServiceUpdateRequest struct { + Settings *SSOSettings `json:"settings"` + UpdateMask *string `json:"updateMask"` +} + +func (s *SSOSettingsServiceUpdateRequest) GetSettings() *SSOSettings { + if s == nil { + return nil + } + return s.Settings +} + +func (s *SSOSettingsServiceUpdateRequest) GetUpdateMask() *string { + if s == nil { + return nil + } + return s.UpdateMask +} diff --git a/pkg/models/shared/ssosettingsserviceupdateresponse.go b/pkg/models/shared/ssosettingsserviceupdateresponse.go new file mode 100644 index 000000000..4027a7ffd --- /dev/null +++ b/pkg/models/shared/ssosettingsserviceupdateresponse.go @@ -0,0 +1,15 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSettingsServiceUpdateResponse returns the updated settings. +type SSOSettingsServiceUpdateResponse struct { + Settings *SSOSettings `json:"settings,omitempty"` +} + +func (s *SSOSettingsServiceUpdateResponse) GetSettings() *SSOSettings { + if s == nil { + return nil + } + return s.Settings +} diff --git a/pkg/models/shared/ssosubjectcompatibility.go b/pkg/models/shared/ssosubjectcompatibility.go new file mode 100644 index 000000000..f0f40442f --- /dev/null +++ b/pkg/models/shared/ssosubjectcompatibility.go @@ -0,0 +1,21 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSubjectCompatibility configures preservation of subjects issued by a +// +// previous identity provider. +type SSOSubjectCompatibility struct { + // Optional user-attribute mapping used to resolve a legacy subject on first + // sign-in. The resolved value is frozen in an immutable per-user binding. + // Correct the source attribute before deleting an attribute-derived binding; + // otherwise the next sign-in resolves and freezes the same value again. + UserAttributeMappingID *string `json:"userAttributeMappingId,omitempty"` +} + +func (s *SSOSubjectCompatibility) GetUserAttributeMappingID() *string { + if s == nil { + return nil + } + return s.UserAttributeMappingID +} diff --git a/pkg/models/shared/ssosubjectcompatibilitydeleteissue.go b/pkg/models/shared/ssosubjectcompatibilitydeleteissue.go new file mode 100644 index 000000000..55b6dddac --- /dev/null +++ b/pkg/models/shared/ssosubjectcompatibilitydeleteissue.go @@ -0,0 +1,27 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSubjectCompatibilityDeleteIssue describes one compatibility binding that +// +// could not be deleted. +type SSOSubjectCompatibilityDeleteIssue struct { + // The reason field. + Reason *string `json:"reason,omitempty"` + // The userId field. + UserID *string `json:"userId,omitempty"` +} + +func (s *SSOSubjectCompatibilityDeleteIssue) GetReason() *string { + if s == nil { + return nil + } + return s.Reason +} + +func (s *SSOSubjectCompatibilityDeleteIssue) GetUserID() *string { + if s == nil { + return nil + } + return s.UserID +} diff --git a/pkg/models/shared/ssosubjectcompatibilityimportentry.go b/pkg/models/shared/ssosubjectcompatibilityimportentry.go new file mode 100644 index 000000000..8dace5ed3 --- /dev/null +++ b/pkg/models/shared/ssosubjectcompatibilityimportentry.go @@ -0,0 +1,34 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSubjectCompatibilityImportEntry is one client-parsed source row. +type SSOSubjectCompatibilityImportEntry struct { + // One-based row number in the source file, including its header. + Row *int `json:"row,omitempty"` + // Exact legacy subject. C1 preserves these UTF-8 bytes without trimming. + Subject *string `json:"subject,omitempty"` + // ConductorOne user ID resolved by the client before this batch is sent. + UserID *string `json:"userId,omitempty"` +} + +func (s *SSOSubjectCompatibilityImportEntry) GetRow() *int { + if s == nil { + return nil + } + return s.Row +} + +func (s *SSOSubjectCompatibilityImportEntry) GetSubject() *string { + if s == nil { + return nil + } + return s.Subject +} + +func (s *SSOSubjectCompatibilityImportEntry) GetUserID() *string { + if s == nil { + return nil + } + return s.UserID +} diff --git a/pkg/models/shared/ssosubjectcompatibilityimportissue.go b/pkg/models/shared/ssosubjectcompatibilityimportissue.go new file mode 100644 index 000000000..69d35bfe0 --- /dev/null +++ b/pkg/models/shared/ssosubjectcompatibilityimportissue.go @@ -0,0 +1,45 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// SSOSubjectCompatibilityImportIssue describes one CSV row that cannot be +// +// imported. +type SSOSubjectCompatibilityImportIssue struct { + // Human-readable reason this row cannot be imported. + Reason *string `json:"reason,omitempty"` + // One-based CSV row number, including the header row. + Row *int `json:"row,omitempty"` + // Legacy subject supplied by the batch entry. + Subject *string `json:"subject,omitempty"` + // ConductorOne user ID supplied by the batch entry. + UserID *string `json:"userId,omitempty"` +} + +func (s *SSOSubjectCompatibilityImportIssue) GetReason() *string { + if s == nil { + return nil + } + return s.Reason +} + +func (s *SSOSubjectCompatibilityImportIssue) GetRow() *int { + if s == nil { + return nil + } + return s.Row +} + +func (s *SSOSubjectCompatibilityImportIssue) GetSubject() *string { + if s == nil { + return nil + } + return s.Subject +} + +func (s *SSOSubjectCompatibilityImportIssue) GetUserID() *string { + if s == nil { + return nil + } + return s.UserID +} diff --git a/pkg/models/shared/submittedtaskaction.go b/pkg/models/shared/submittedtaskaction.go index d00f9ae80..b2511b622 100644 --- a/pkg/models/shared/submittedtaskaction.go +++ b/pkg/models/shared/submittedtaskaction.go @@ -38,6 +38,7 @@ const ( ActionTypeTaskActionTypeRollbackCancelled ActionType = "TASK_ACTION_TYPE_ROLLBACK_CANCELLED" ActionTypeTaskActionTypeUpdateRequestData ActionType = "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA" ActionTypeTaskActionTypeUpdateGrantDuration ActionType = "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION" + ActionTypeTaskActionTypeRetryProvisioning ActionType = "TASK_ACTION_TYPE_RETRY_PROVISIONING" ) func (e ActionType) ToPointer() *ActionType { @@ -48,7 +49,7 @@ func (e ActionType) ToPointer() *ActionType { func (e *ActionType) IsExact() bool { if e != nil { switch *e { - case "TASK_ACTION_TYPE_UNSPECIFIED", "TASK_ACTION_TYPE_CLOSE", "TASK_ACTION_TYPE_APPROVE", "TASK_ACTION_TYPE_DENY", "TASK_ACTION_TYPE_COMMENT", "TASK_ACTION_TYPE_DELETE", "TASK_ACTION_TYPE_REASSIGN", "TASK_ACTION_TYPE_RESTART", "TASK_ACTION_TYPE_SEND_REMINDER", "TASK_ACTION_TYPE_PROVISION_COMPLETE", "TASK_ACTION_TYPE_PROVISION_CANCELLED", "TASK_ACTION_TYPE_PROVISION_ERRORED", "TASK_ACTION_TYPE_ROLLBACK_SKIPPED", "TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED", "TASK_ACTION_TYPE_HARD_RESET", "TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS", "TASK_ACTION_TYPE_CHANGE_POLICY", "TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS", "TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION", "TASK_ACTION_TYPE_SET_ANALYSIS_ID", "TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST", "TASK_ACTION_TYPE_PROCESS_NOW", "TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP", "TASK_ACTION_TYPE_SKIP_STEP", "TASK_ACTION_TYPE_ROLLBACK_CANCELLED", "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA", "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION": + case "TASK_ACTION_TYPE_UNSPECIFIED", "TASK_ACTION_TYPE_CLOSE", "TASK_ACTION_TYPE_APPROVE", "TASK_ACTION_TYPE_DENY", "TASK_ACTION_TYPE_COMMENT", "TASK_ACTION_TYPE_DELETE", "TASK_ACTION_TYPE_REASSIGN", "TASK_ACTION_TYPE_RESTART", "TASK_ACTION_TYPE_SEND_REMINDER", "TASK_ACTION_TYPE_PROVISION_COMPLETE", "TASK_ACTION_TYPE_PROVISION_CANCELLED", "TASK_ACTION_TYPE_PROVISION_ERRORED", "TASK_ACTION_TYPE_ROLLBACK_SKIPPED", "TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED", "TASK_ACTION_TYPE_HARD_RESET", "TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS", "TASK_ACTION_TYPE_CHANGE_POLICY", "TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS", "TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION", "TASK_ACTION_TYPE_SET_ANALYSIS_ID", "TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST", "TASK_ACTION_TYPE_PROCESS_NOW", "TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP", "TASK_ACTION_TYPE_SKIP_STEP", "TASK_ACTION_TYPE_ROLLBACK_CANCELLED", "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA", "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION", "TASK_ACTION_TYPE_RETRY_PROVISIONING": return true } } diff --git a/pkg/models/shared/systempreference.go b/pkg/models/shared/systempreference.go new file mode 100644 index 000000000..cac10433f --- /dev/null +++ b/pkg/models/shared/systempreference.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The SystemPreference message. +type SystemPreference struct { + // The enabled field. + Enabled *bool `json:"enabled,omitempty"` + // The locked field. + Locked *bool `json:"locked,omitempty"` +} + +func (s *SystemPreference) GetEnabled() *bool { + if s == nil { + return nil + } + return s.Enabled +} + +func (s *SystemPreference) GetLocked() *bool { + if s == nil { + return nil + } + return s.Locked +} diff --git a/pkg/models/shared/task.go b/pkg/models/shared/task.go index e4318092e..2ed14bc08 100644 --- a/pkg/models/shared/task.go +++ b/pkg/models/shared/task.go @@ -37,6 +37,7 @@ const ( ActionsTaskActionTypeRollbackCancelled Actions = "TASK_ACTION_TYPE_ROLLBACK_CANCELLED" ActionsTaskActionTypeUpdateRequestData Actions = "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA" ActionsTaskActionTypeUpdateGrantDuration Actions = "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION" + ActionsTaskActionTypeRetryProvisioning Actions = "TASK_ACTION_TYPE_RETRY_PROVISIONING" ) func (e Actions) ToPointer() *Actions { @@ -47,7 +48,7 @@ func (e Actions) ToPointer() *Actions { func (e *Actions) IsExact() bool { if e != nil { switch *e { - case "TASK_ACTION_TYPE_UNSPECIFIED", "TASK_ACTION_TYPE_CLOSE", "TASK_ACTION_TYPE_APPROVE", "TASK_ACTION_TYPE_DENY", "TASK_ACTION_TYPE_COMMENT", "TASK_ACTION_TYPE_DELETE", "TASK_ACTION_TYPE_REASSIGN", "TASK_ACTION_TYPE_RESTART", "TASK_ACTION_TYPE_SEND_REMINDER", "TASK_ACTION_TYPE_PROVISION_COMPLETE", "TASK_ACTION_TYPE_PROVISION_CANCELLED", "TASK_ACTION_TYPE_PROVISION_ERRORED", "TASK_ACTION_TYPE_ROLLBACK_SKIPPED", "TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED", "TASK_ACTION_TYPE_HARD_RESET", "TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS", "TASK_ACTION_TYPE_CHANGE_POLICY", "TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS", "TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION", "TASK_ACTION_TYPE_SET_ANALYSIS_ID", "TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST", "TASK_ACTION_TYPE_PROCESS_NOW", "TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP", "TASK_ACTION_TYPE_SKIP_STEP", "TASK_ACTION_TYPE_ROLLBACK_CANCELLED", "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA", "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION": + case "TASK_ACTION_TYPE_UNSPECIFIED", "TASK_ACTION_TYPE_CLOSE", "TASK_ACTION_TYPE_APPROVE", "TASK_ACTION_TYPE_DENY", "TASK_ACTION_TYPE_COMMENT", "TASK_ACTION_TYPE_DELETE", "TASK_ACTION_TYPE_REASSIGN", "TASK_ACTION_TYPE_RESTART", "TASK_ACTION_TYPE_SEND_REMINDER", "TASK_ACTION_TYPE_PROVISION_COMPLETE", "TASK_ACTION_TYPE_PROVISION_CANCELLED", "TASK_ACTION_TYPE_PROVISION_ERRORED", "TASK_ACTION_TYPE_ROLLBACK_SKIPPED", "TASK_ACTION_TYPE_PROVISION_APP_USER_TARGET_CREATED", "TASK_ACTION_TYPE_HARD_RESET", "TASK_ACTION_TYPE_ESCALATE_TO_EMERGENCY_ACCESS", "TASK_ACTION_TYPE_CHANGE_POLICY", "TASK_ACTION_TYPE_RECALCULATE_DENIAL_FROM_BASE_POLICY_DECISIONS", "TASK_ACTION_TYPE_SET_INSIGHTS_AND_RECOMMENDATION", "TASK_ACTION_TYPE_SET_ANALYSIS_ID", "TASK_ACTION_TYPE_RECALCULATE_APPROVERS_LIST", "TASK_ACTION_TYPE_PROCESS_NOW", "TASK_ACTION_TYPE_APPROVE_WITH_STEP_UP", "TASK_ACTION_TYPE_SKIP_STEP", "TASK_ACTION_TYPE_ROLLBACK_CANCELLED", "TASK_ACTION_TYPE_UPDATE_REQUEST_DATA", "TASK_ACTION_TYPE_UPDATE_GRANT_DURATION", "TASK_ACTION_TYPE_RETRY_PROVISIONING": return true } } diff --git a/pkg/models/shared/taskactionsserviceretryprovisioningrequest.go b/pkg/models/shared/taskactionsserviceretryprovisioningrequest.go new file mode 100644 index 000000000..31ecddc67 --- /dev/null +++ b/pkg/models/shared/taskactionsserviceretryprovisioningrequest.go @@ -0,0 +1,33 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// TaskActionsServiceRetryProvisioningRequest - Request to retry a task's failed connector provisioning. +type TaskActionsServiceRetryProvisioningRequest struct { + // An optional comment attached to the action. + Comment *string `json:"comment,omitempty"` + ExpandMask *TaskExpandMask `json:"expandMask,omitempty"` + // The ID of the provision policy step to retry. + PolicyStepID *string `json:"policyStepId,omitempty"` +} + +func (t *TaskActionsServiceRetryProvisioningRequest) GetComment() *string { + if t == nil { + return nil + } + return t.Comment +} + +func (t *TaskActionsServiceRetryProvisioningRequest) GetExpandMask() *TaskExpandMask { + if t == nil { + return nil + } + return t.ExpandMask +} + +func (t *TaskActionsServiceRetryProvisioningRequest) GetPolicyStepID() *string { + if t == nil { + return nil + } + return t.PolicyStepID +} diff --git a/pkg/models/shared/taskauditaccountdeleted.go b/pkg/models/shared/taskauditaccountdeleted.go new file mode 100644 index 000000000..c5c69ef34 --- /dev/null +++ b/pkg/models/shared/taskauditaccountdeleted.go @@ -0,0 +1,63 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// TaskAuditAccountDeleted records an account deletion reported by a connector +// +// while completing a revoke action. +type TaskAuditAccountDeleted struct { + // The appId field. + AppID *string `json:"appId,omitempty"` + // The appUserId field. + AppUserID *string `json:"appUserId,omitempty"` + // The connectorResourceId field. + ConnectorResourceID *string `json:"connectorResourceId,omitempty"` + // The displayName field. + DisplayName *string `json:"displayName,omitempty"` + // The email field. + Email *string `json:"email,omitempty"` + // The username field. + Username *string `json:"username,omitempty"` +} + +func (t *TaskAuditAccountDeleted) GetAppID() *string { + if t == nil { + return nil + } + return t.AppID +} + +func (t *TaskAuditAccountDeleted) GetAppUserID() *string { + if t == nil { + return nil + } + return t.AppUserID +} + +func (t *TaskAuditAccountDeleted) GetConnectorResourceID() *string { + if t == nil { + return nil + } + return t.ConnectorResourceID +} + +func (t *TaskAuditAccountDeleted) GetDisplayName() *string { + if t == nil { + return nil + } + return t.DisplayName +} + +func (t *TaskAuditAccountDeleted) GetEmail() *string { + if t == nil { + return nil + } + return t.Email +} + +func (t *TaskAuditAccountDeleted) GetUsername() *string { + if t == nil { + return nil + } + return t.Username +} diff --git a/pkg/models/shared/taskauditautomationtriggered.go b/pkg/models/shared/taskauditautomationtriggered.go new file mode 100644 index 000000000..a356df924 --- /dev/null +++ b/pkg/models/shared/taskauditautomationtriggered.go @@ -0,0 +1,52 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + +// TaskAuditAutomationTriggered attributes a system-created task to the +// +// automation execution that created it. +type TaskAuditAutomationTriggered struct { + // The specific execution of the automation that created the task. + AutomationExecutionID *int64 `integer:"string" json:"automationExecutionId,omitempty"` + // The automation that created the task. + AutomationID *string `json:"automationId,omitempty"` + // The automation's display name as of task creation, so the event stays + // readable after the automation is renamed or deleted. + AutomationName *string `json:"automationName,omitempty"` +} + +func (t TaskAuditAutomationTriggered) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(t, "", false) +} + +func (t *TaskAuditAutomationTriggered) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &t, "", false, nil); err != nil { + return err + } + return nil +} + +func (t *TaskAuditAutomationTriggered) GetAutomationExecutionID() *int64 { + if t == nil { + return nil + } + return t.AutomationExecutionID +} + +func (t *TaskAuditAutomationTriggered) GetAutomationID() *string { + if t == nil { + return nil + } + return t.AutomationID +} + +func (t *TaskAuditAutomationTriggered) GetAutomationName() *string { + if t == nil { + return nil + } + return t.AutomationName +} diff --git a/pkg/models/shared/taskauditconditionalpolicyexecutionresult.go b/pkg/models/shared/taskauditconditionalpolicyexecutionresult.go index 72ee081fb..8e8037784 100644 --- a/pkg/models/shared/taskauditconditionalpolicyexecutionresult.go +++ b/pkg/models/shared/taskauditconditionalpolicyexecutionresult.go @@ -4,6 +4,8 @@ package shared // The TaskAuditConditionalPolicyExecutionResult message. type TaskAuditConditionalPolicyExecutionResult struct { + // The depth of this policy in the chain (0 = root, 1 = first hop, etc.). + ChainDepth *int `json:"chainDepth,omitempty"` // The condition field. Condition *string `json:"condition,omitempty"` // The conditionMatched field. @@ -12,10 +14,24 @@ type TaskAuditConditionalPolicyExecutionResult struct { DefaultCondition *bool `json:"defaultCondition,omitempty"` // The error field. Error *string `json:"error,omitempty"` + // When this rule's outcome is a reference to another Policy, the ID of + // that referenced policy. Empty when the outcome is an inline policy_key. + OutcomePolicyID *string `json:"outcomePolicyId,omitempty"` + // The policy in which this rule was evaluated. Empty for results recorded + // before chained policy references existed; populated for every result + // emitted by recursive evaluation. + PolicyID *string `json:"policyId,omitempty"` // The policyKey field. PolicyKey *string `json:"policyKey,omitempty"` } +func (t *TaskAuditConditionalPolicyExecutionResult) GetChainDepth() *int { + if t == nil { + return nil + } + return t.ChainDepth +} + func (t *TaskAuditConditionalPolicyExecutionResult) GetCondition() *string { if t == nil { return nil @@ -44,6 +60,20 @@ func (t *TaskAuditConditionalPolicyExecutionResult) GetError() *string { return t.Error } +func (t *TaskAuditConditionalPolicyExecutionResult) GetOutcomePolicyID() *string { + if t == nil { + return nil + } + return t.OutcomePolicyID +} + +func (t *TaskAuditConditionalPolicyExecutionResult) GetPolicyID() *string { + if t == nil { + return nil + } + return t.PolicyID +} + func (t *TaskAuditConditionalPolicyExecutionResult) GetPolicyKey() *string { if t == nil { return nil diff --git a/pkg/models/shared/taskauditlistrequest.go b/pkg/models/shared/taskauditlistrequest.go index 8a41fb94c..7bcab676f 100644 --- a/pkg/models/shared/taskauditlistrequest.go +++ b/pkg/models/shared/taskauditlistrequest.go @@ -7,6 +7,10 @@ type TaskAuditListRequest struct { // When true, only comment events are returned, so a page of page_size holds // page_size comments rather than a mix of comments and state-change events. CommentsOnly *bool `json:"commentsOnly,omitempty"` + // When true, comment events are excluded from the response and the count, so + // a page of page_size holds page_size non-comment events. Mutually exclusive + // with comments_only. + ExcludeComments *bool `json:"excludeComments,omitempty"` // When true, events are returned newest-first (descending created_at) instead // of the default chronological (ascending) order. NewestFirst *bool `json:"newestFirst,omitempty"` @@ -27,6 +31,13 @@ func (t *TaskAuditListRequest) GetCommentsOnly() *bool { return t.CommentsOnly } +func (t *TaskAuditListRequest) GetExcludeComments() *bool { + if t == nil { + return nil + } + return t.ExcludeComments +} + func (t *TaskAuditListRequest) GetNewestFirst() *bool { if t == nil { return nil diff --git a/pkg/models/shared/taskauditlistresponse.go b/pkg/models/shared/taskauditlistresponse.go index eef512130..5575c074a 100644 --- a/pkg/models/shared/taskauditlistresponse.go +++ b/pkg/models/shared/taskauditlistresponse.go @@ -2,12 +2,36 @@ package shared +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" +) + // The TaskAuditListResponse message. type TaskAuditListResponse struct { // The list of audit events for the task. List []TaskAuditView `json:"list,omitempty"` // A pagination token to retrieve the next page of results. NextPageToken *string `json:"nextPageToken,omitempty"` + // The total number of audit events the list returns for this request: + // comment events when comments_only is true, non-comment events when + // exclude_comments is true, all events otherwise. This is an upper bound: + // a small number of internal-only events (e.g. connector-action results + // with no pending reason) are omitted from list, so the count can exceed + // the rows reachable by paging. Only returned for the first page (a request + // with no page_token). Unset when the request filters by refs (the count is + // undefined for ref lookups) or when the count could not be computed. + TotalCount *int64 `integer:"string" json:"totalCount,omitempty"` +} + +func (t TaskAuditListResponse) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(t, "", false) +} + +func (t *TaskAuditListResponse) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &t, "", false, nil); err != nil { + return err + } + return nil } func (t *TaskAuditListResponse) GetList() []TaskAuditView { @@ -23,3 +47,10 @@ func (t *TaskAuditListResponse) GetNextPageToken() *string { } return t.NextPageToken } + +func (t *TaskAuditListResponse) GetTotalCount() *int64 { + if t == nil { + return nil + } + return t.TotalCount +} diff --git a/pkg/models/shared/taskauditprovisionentitlementmergecompleted.go b/pkg/models/shared/taskauditprovisionentitlementmergecompleted.go new file mode 100644 index 000000000..7e287a1b9 --- /dev/null +++ b/pkg/models/shared/taskauditprovisionentitlementmergecompleted.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The TaskAuditProvisionEntitlementMergeCompleted message. +type TaskAuditProvisionEntitlementMergeCompleted struct { + // The appEntitlementId field. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The appId field. + AppID *string `json:"appId,omitempty"` +} + +func (t *TaskAuditProvisionEntitlementMergeCompleted) GetAppEntitlementID() *string { + if t == nil { + return nil + } + return t.AppEntitlementID +} + +func (t *TaskAuditProvisionEntitlementMergeCompleted) GetAppID() *string { + if t == nil { + return nil + } + return t.AppID +} diff --git a/pkg/models/shared/taskauditprovisionentitlementmergetimedout.go b/pkg/models/shared/taskauditprovisionentitlementmergetimedout.go new file mode 100644 index 000000000..f94348178 --- /dev/null +++ b/pkg/models/shared/taskauditprovisionentitlementmergetimedout.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The TaskAuditProvisionEntitlementMergeTimedOut message. +type TaskAuditProvisionEntitlementMergeTimedOut struct { + // The appEntitlementId field. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The appId field. + AppID *string `json:"appId,omitempty"` +} + +func (t *TaskAuditProvisionEntitlementMergeTimedOut) GetAppEntitlementID() *string { + if t == nil { + return nil + } + return t.AppEntitlementID +} + +func (t *TaskAuditProvisionEntitlementMergeTimedOut) GetAppID() *string { + if t == nil { + return nil + } + return t.AppID +} diff --git a/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.go b/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.go new file mode 100644 index 000000000..3ed9702b9 --- /dev/null +++ b/pkg/models/shared/taskauditprovisionwaitingforentitlementmerge.go @@ -0,0 +1,49 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// The TaskAuditProvisionWaitingForEntitlementMerge message. +type TaskAuditProvisionWaitingForEntitlementMerge struct { + // The appEntitlementId field. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The appId field. + AppID *string `json:"appId,omitempty"` + FallbackAt *time.Time `json:"fallbackAt,omitempty"` +} + +func (t TaskAuditProvisionWaitingForEntitlementMerge) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(t, "", false) +} + +func (t *TaskAuditProvisionWaitingForEntitlementMerge) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &t, "", false, nil); err != nil { + return err + } + return nil +} + +func (t *TaskAuditProvisionWaitingForEntitlementMerge) GetAppEntitlementID() *string { + if t == nil { + return nil + } + return t.AppEntitlementID +} + +func (t *TaskAuditProvisionWaitingForEntitlementMerge) GetAppID() *string { + if t == nil { + return nil + } + return t.AppID +} + +func (t *TaskAuditProvisionWaitingForEntitlementMerge) GetFallbackAt() *time.Time { + if t == nil { + return nil + } + return t.FallbackAt +} diff --git a/pkg/models/shared/taskauditview.go b/pkg/models/shared/taskauditview.go index ab4a700a8..ea6360ae6 100644 --- a/pkg/models/shared/taskauditview.go +++ b/pkg/models/shared/taskauditview.go @@ -146,8 +146,14 @@ func (e *TaskAuditViewSource) IsExact() bool { // - taskCreatedFrom // - reassignmentFallbackToAdmin // - requestDefaultsApplied +// - provisionWaitingForEntitlementMerge +// - provisionEntitlementMergeCompleted +// - provisionEntitlementMergeTimedOut +// - accountDeleted +// - automationTriggered type TaskAuditView struct { AccessRequestOutcome *TaskAuditAccessRequestOutcome `json:"accessRequestOutcome,omitempty"` + AccountDeleted *TaskAuditAccountDeleted `json:"accountDeleted,omitempty"` AccountLifecycleActionCreated *TaskAuditAccountLifecycleActionCreated `json:"accountLifecycleActionCreated,omitempty"` AccountLifecycleActionFailed *TaskAuditAccountLifecycleActionFailed `json:"accountLifecycleActionFailed,omitempty"` ActionInstanceCreated *TaskAuditActionInstanceCreated `json:"actionInstanceCreated,omitempty"` @@ -160,6 +166,7 @@ type TaskAuditView struct { ApprovalInstanceChange *TaskAuditApprovalInstanceChange `json:"approvalInstanceChange,omitempty"` ApprovalReassigned *TaskAuditPolicyApprovalReassigned `json:"approvalReassigned,omitempty"` ApprovedAutomatically *TaskAuditApprovalHappenedAutomatically `json:"approvedAutomatically,omitempty"` + AutomationTriggered *TaskAuditAutomationTriggered `json:"automationTriggered,omitempty"` BulkActionError *TaskAuditBulkActionError `json:"bulkActionError,omitempty"` CertifyOutcome *TaskAuditCertifyOutcome `json:"certifyOutcome,omitempty"` Comment *TaskAuditComment `json:"comment,omitempty"` @@ -182,19 +189,22 @@ type TaskAuditView struct { GrantOutcome *TaskAuditGrantOutcome `json:"grantOutcome,omitempty"` HardReset *TaskAuditHardReset `json:"hardReset,omitempty"` // The id field. - ID *string `json:"id,omitempty"` - Metadata *TaskAuditMetaData `json:"metadata,omitempty"` - PolicyChanged *TaskAuditPolicyChanged `json:"policyChanged,omitempty"` - PolicyEvaluationStep *TaskAuditPolicyEvaluationStep `json:"policyEvaluationStep,omitempty"` - ProvisionCancelled *TaskAuditPolicyProvisionCancelled `json:"provisionCancelled,omitempty"` - ProvisionError *TaskAuditPolicyProvisionError `json:"provisionError,omitempty"` - ProvisionReassigned *TaskAuditPolicyProvisionReassigned `json:"provisionReassigned,omitempty"` - ReassignedToDelegate *TaskAuditReassignedToDelegate `json:"reassignedToDelegate,omitempty"` - ReassignmentFallbackToAdmin *TaskAuditReassignmentFallbackToAdmin `json:"reassignmentFallbackToAdmin,omitempty"` - ReassignmentListError *TaskAuditReassignmentListError `json:"reassignmentListError,omitempty"` - RequestDefaultsApplied *TaskAuditRequestDefaultsApplied `json:"requestDefaultsApplied,omitempty"` - RevokeOutcome *TaskAuditRevokeOutcome `json:"revokeOutcome,omitempty"` - SLAEscalation *TaskAuditSLAEscalation `json:"slaEscalation,omitempty"` + ID *string `json:"id,omitempty"` + Metadata *TaskAuditMetaData `json:"metadata,omitempty"` + PolicyChanged *TaskAuditPolicyChanged `json:"policyChanged,omitempty"` + PolicyEvaluationStep *TaskAuditPolicyEvaluationStep `json:"policyEvaluationStep,omitempty"` + ProvisionCancelled *TaskAuditPolicyProvisionCancelled `json:"provisionCancelled,omitempty"` + ProvisionEntitlementMergeCompleted *TaskAuditProvisionEntitlementMergeCompleted `json:"provisionEntitlementMergeCompleted,omitempty"` + ProvisionEntitlementMergeTimedOut *TaskAuditProvisionEntitlementMergeTimedOut `json:"provisionEntitlementMergeTimedOut,omitempty"` + ProvisionError *TaskAuditPolicyProvisionError `json:"provisionError,omitempty"` + ProvisionReassigned *TaskAuditPolicyProvisionReassigned `json:"provisionReassigned,omitempty"` + ProvisionWaitingForEntitlementMerge *TaskAuditProvisionWaitingForEntitlementMerge `json:"provisionWaitingForEntitlementMerge,omitempty"` + ReassignedToDelegate *TaskAuditReassignedToDelegate `json:"reassignedToDelegate,omitempty"` + ReassignmentFallbackToAdmin *TaskAuditReassignmentFallbackToAdmin `json:"reassignmentFallbackToAdmin,omitempty"` + ReassignmentListError *TaskAuditReassignmentListError `json:"reassignmentListError,omitempty"` + RequestDefaultsApplied *TaskAuditRequestDefaultsApplied `json:"requestDefaultsApplied,omitempty"` + RevokeOutcome *TaskAuditRevokeOutcome `json:"revokeOutcome,omitempty"` + SLAEscalation *TaskAuditSLAEscalation `json:"slaEscalation,omitempty"` // The source field. Source *TaskAuditViewSource `json:"source,omitempty"` StateChange *TaskAuditStateChange `json:"stateChange,omitempty"` @@ -245,6 +255,13 @@ func (t *TaskAuditView) GetAccessRequestOutcome() *TaskAuditAccessRequestOutcome return t.AccessRequestOutcome } +func (t *TaskAuditView) GetAccountDeleted() *TaskAuditAccountDeleted { + if t == nil { + return nil + } + return t.AccountDeleted +} + func (t *TaskAuditView) GetAccountLifecycleActionCreated() *TaskAuditAccountLifecycleActionCreated { if t == nil { return nil @@ -329,6 +346,13 @@ func (t *TaskAuditView) GetApprovedAutomatically() *TaskAuditApprovalHappenedAut return t.ApprovedAutomatically } +func (t *TaskAuditView) GetAutomationTriggered() *TaskAuditAutomationTriggered { + if t == nil { + return nil + } + return t.AutomationTriggered +} + func (t *TaskAuditView) GetBulkActionError() *TaskAuditBulkActionError { if t == nil { return nil @@ -497,6 +521,20 @@ func (t *TaskAuditView) GetProvisionCancelled() *TaskAuditPolicyProvisionCancell return t.ProvisionCancelled } +func (t *TaskAuditView) GetProvisionEntitlementMergeCompleted() *TaskAuditProvisionEntitlementMergeCompleted { + if t == nil { + return nil + } + return t.ProvisionEntitlementMergeCompleted +} + +func (t *TaskAuditView) GetProvisionEntitlementMergeTimedOut() *TaskAuditProvisionEntitlementMergeTimedOut { + if t == nil { + return nil + } + return t.ProvisionEntitlementMergeTimedOut +} + func (t *TaskAuditView) GetProvisionError() *TaskAuditPolicyProvisionError { if t == nil { return nil @@ -511,6 +549,13 @@ func (t *TaskAuditView) GetProvisionReassigned() *TaskAuditPolicyProvisionReassi return t.ProvisionReassigned } +func (t *TaskAuditView) GetProvisionWaitingForEntitlementMerge() *TaskAuditProvisionWaitingForEntitlementMerge { + if t == nil { + return nil + } + return t.ProvisionWaitingForEntitlementMerge +} + func (t *TaskAuditView) GetReassignedToDelegate() *TaskAuditReassignedToDelegate { if t == nil { return nil diff --git a/pkg/models/shared/taskauditwebhooksuccess.go b/pkg/models/shared/taskauditwebhooksuccess.go index eedc29b8d..6bd213d7a 100644 --- a/pkg/models/shared/taskauditwebhooksuccess.go +++ b/pkg/models/shared/taskauditwebhooksuccess.go @@ -4,6 +4,8 @@ package shared // The TaskAuditWebhookSuccess message. type TaskAuditWebhookSuccess struct { + // Optional comment supplied by the provisioning callback. + Comment *string `json:"comment,omitempty"` // The webhookId field. WebhookID *string `json:"webhookId,omitempty"` // The webhookInstanceId field. @@ -14,6 +16,13 @@ type TaskAuditWebhookSuccess struct { WebhookURL *string `json:"webhookUrl,omitempty"` } +func (t *TaskAuditWebhookSuccess) GetComment() *string { + if t == nil { + return nil + } + return t.Comment +} + func (t *TaskAuditWebhookSuccess) GetWebhookID() *string { if t == nil { return nil diff --git a/pkg/models/shared/tasksearchrequest.go b/pkg/models/shared/tasksearchrequest.go index e7a0c6c2f..2759ed71f 100644 --- a/pkg/models/shared/tasksearchrequest.go +++ b/pkg/models/shared/tasksearchrequest.go @@ -7,6 +7,30 @@ import ( "time" ) +type AccountStatuses string + +const ( + AccountStatusesStatusUnspecified AccountStatuses = "STATUS_UNSPECIFIED" + AccountStatusesStatusEnabled AccountStatuses = "STATUS_ENABLED" + AccountStatusesStatusDisabled AccountStatuses = "STATUS_DISABLED" + AccountStatusesStatusDeleted AccountStatuses = "STATUS_DELETED" +) + +func (e AccountStatuses) ToPointer() *AccountStatuses { + return &e +} + +// IsExact returns true if the value matches a known enum value, false otherwise. +func (e *AccountStatuses) IsExact() bool { + if e != nil { + switch *e { + case "STATUS_UNSPECIFIED", "STATUS_ENABLED", "STATUS_DISABLED", "STATUS_DELETED": + return true + } + } + return false +} + type TaskSearchRequestAccountTypes string const ( @@ -274,6 +298,8 @@ type TaskSearchRequest struct { AccessReviewIds []string `json:"accessReviewIds,omitempty"` // Search tasks that have any of these account owners. AccountOwnerIds []string `json:"accountOwnerIds,omitempty"` + // Search tasks by the account status of the app user subject. + AccountStatuses []AccountStatuses `json:"accountStatuses,omitempty"` // The accountTypes field. AccountTypes []TaskSearchRequestAccountTypes `json:"accountTypes,omitempty"` // Search tasks that have this actor ID. @@ -381,6 +407,13 @@ func (t *TaskSearchRequest) GetAccountOwnerIds() []string { return t.AccountOwnerIds } +func (t *TaskSearchRequest) GetAccountStatuses() []AccountStatuses { + if t == nil { + return nil + } + return t.AccountStatuses +} + func (t *TaskSearchRequest) GetAccountTypes() []TaskSearchRequestAccountTypes { if t == nil { return nil diff --git a/pkg/models/shared/triggerautomationdispatcher.go b/pkg/models/shared/triggerautomationdispatcher.go new file mode 100644 index 000000000..c677ef077 --- /dev/null +++ b/pkg/models/shared/triggerautomationdispatcher.go @@ -0,0 +1,26 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// TriggerAutomationDispatcher runs a C1 automation by id (the "Run now" path). +type TriggerAutomationDispatcher struct { + // ID of the C1 automation/workflow to run. + AutomationID *string `json:"automationId,omitempty"` + // Inputs passed to the automation, keyed by input name (v0: verbatim values; + // CEL evaluation is a later phase). + InputMapping map[string]string `json:"inputMapping,omitempty"` +} + +func (t *TriggerAutomationDispatcher) GetAutomationID() *string { + if t == nil { + return nil + } + return t.AutomationID +} + +func (t *TriggerAutomationDispatcher) GetInputMapping() map[string]string { + if t == nil { + return nil + } + return t.InputMapping +} diff --git a/pkg/models/shared/unusedsecretevidence.go b/pkg/models/shared/unusedsecretevidence.go new file mode 100644 index 000000000..7b766b4bc --- /dev/null +++ b/pkg/models/shared/unusedsecretevidence.go @@ -0,0 +1,31 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +import ( + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "time" +) + +// The UnusedSecretEvidence message. +type UnusedSecretEvidence struct { + LastUsedAt *time.Time `json:"lastUsedAt,omitempty"` +} + +func (u UnusedSecretEvidence) MarshalJSON() ([]byte, error) { + return utils.MarshalJSON(u, "", false) +} + +func (u *UnusedSecretEvidence) UnmarshalJSON(data []byte) error { + if err := utils.UnmarshalJSON(data, &u, "", false, nil); err != nil { + return err + } + return nil +} + +func (u *UnusedSecretEvidence) GetLastUsedAt() *time.Time { + if u == nil { + return nil + } + return u.LastUsedAt +} diff --git a/pkg/models/shared/unusedsecrettype.go b/pkg/models/shared/unusedsecrettype.go new file mode 100644 index 000000000..7bdef948e --- /dev/null +++ b/pkg/models/shared/unusedsecrettype.go @@ -0,0 +1,9 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// UnusedSecretType - UnusedSecretType: a secret-trait AppResource has not been used in over the +// +// detector's staleness threshold. Target: AppResourceTarget. +type UnusedSecretType struct { +} diff --git a/pkg/models/shared/updatefindingsettingsrequest.go b/pkg/models/shared/updatefindingsettingsrequest.go new file mode 100644 index 000000000..f70801e78 --- /dev/null +++ b/pkg/models/shared/updatefindingsettingsrequest.go @@ -0,0 +1,19 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The UpdateFindingSettingsRequest message. +type UpdateFindingSettingsRequest struct { + // Applied as one atomic write, so an admin changing several types either + // lands all of them or none. Empty is valid: a never-configured tenant's + // "accept the defaults" save has nothing to diff, and the empty write still + // creates the settings row. + Settings []FindingSettingsEntry `json:"settings,omitempty"` +} + +func (u *UpdateFindingSettingsRequest) GetSettings() []FindingSettingsEntry { + if u == nil { + return nil + } + return u.Settings +} diff --git a/pkg/models/shared/updatefindingsettingsresponse.go b/pkg/models/shared/updatefindingsettingsresponse.go new file mode 100644 index 000000000..3af3e5d9c --- /dev/null +++ b/pkg/models/shared/updatefindingsettingsresponse.go @@ -0,0 +1,17 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// The UpdateFindingSettingsResponse message. +type UpdateFindingSettingsResponse struct { + // The full catalog after the write, in the same shape ListFindingSettings + // returns. + List []FindingTypeSetting `json:"list,omitempty"` +} + +func (u *UpdateFindingSettingsResponse) GetList() []FindingTypeSetting { + if u == nil { + return nil + } + return u.List +} diff --git a/pkg/models/shared/waitingfordeviceplacement.go b/pkg/models/shared/waitingfordeviceplacement.go new file mode 100644 index 000000000..03fc51054 --- /dev/null +++ b/pkg/models/shared/waitingfordeviceplacement.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// WaitingForDevicePlacement - Describes a provision step that is paused until the recipient joins the vault's MLS group. +type WaitingForDevicePlacement struct { + // The ID of the user being placed. + RecipientUserID *string `json:"recipientUserId,omitempty"` + // The ID of the vault boundary the recipient is being placed in. + VaultBoundaryID *string `json:"vaultBoundaryId,omitempty"` +} + +func (w *WaitingForDevicePlacement) GetRecipientUserID() *string { + if w == nil { + return nil + } + return w.RecipientUserID +} + +func (w *WaitingForDevicePlacement) GetVaultBoundaryID() *string { + if w == nil { + return nil + } + return w.VaultBoundaryID +} diff --git a/pkg/models/shared/waitingforentitlementmerge.go b/pkg/models/shared/waitingforentitlementmerge.go new file mode 100644 index 000000000..5edc96633 --- /dev/null +++ b/pkg/models/shared/waitingforentitlementmerge.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// WaitingForEntitlementMerge - Describes a provision step that is paused until the target entitlement, created ahead of connector sync with a Baton match ID, is merged with its connector-synced counterpart. +type WaitingForEntitlementMerge struct { + // The ID of the entitlement being waited on. + AppEntitlementID *string `json:"appEntitlementId,omitempty"` + // The ID of the app the awaited entitlement belongs to. + AppID *string `json:"appId,omitempty"` +} + +func (w *WaitingForEntitlementMerge) GetAppEntitlementID() *string { + if w == nil { + return nil + } + return w.AppEntitlementID +} + +func (w *WaitingForEntitlementMerge) GetAppID() *string { + if w == nil { + return nil + } + return w.AppID +} diff --git a/pkg/models/shared/webhookdispatcher.go b/pkg/models/shared/webhookdispatcher.go new file mode 100644 index 000000000..3b4ad0475 --- /dev/null +++ b/pkg/models/shared/webhookdispatcher.go @@ -0,0 +1,25 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package shared + +// WebhookDispatcher POSTs to a registered webhook (webhooks v3). +type WebhookDispatcher struct { + // Optional payload template; empty uses the default finding payload. + PayloadTemplate *string `json:"payloadTemplate,omitempty"` + // ID of a registered webhook to POST to. + WebhookID *string `json:"webhookId,omitempty"` +} + +func (w *WebhookDispatcher) GetPayloadTemplate() *string { + if w == nil { + return nil + } + return w.PayloadTemplate +} + +func (w *WebhookDispatcher) GetWebhookID() *string { + if w == nil { + return nil + } + return w.WebhookID +} diff --git a/pkg/models/shared/xaaclientaudiencemapping.go b/pkg/models/shared/xaaclientaudiencemapping.go index 553f3463f..ea81143dc 100644 --- a/pkg/models/shared/xaaclientaudiencemapping.go +++ b/pkg/models/shared/xaaclientaudiencemapping.go @@ -14,8 +14,8 @@ type XAAClientAudienceMapping struct { // The client's identifier at the resource authorization server. Stamped // verbatim into the grant's client_id claim. AudienceClientID *string `json:"audienceClientId,omitempty"` - // Stable client registration key. One of: a DCR software_id form - // (dcr://), a CIMD client_id URL, a native C1 form + // Stable client registration key. One of: a DCR client_id form + // (dcr://), a CIMD client_id URL, a native C1 form // (c1://), or a raw client_id. ClientKey *string `json:"clientKey,omitempty"` CreatedAt *time.Time `json:"createdAt,omitempty"` diff --git a/providercredential.go b/providercredential.go new file mode 100644 index 000000000..ce20f362f --- /dev/null +++ b/providercredential.go @@ -0,0 +1,667 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" +) + +type ProviderCredential struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newProviderCredential(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *ProviderCredential { + return &ProviderCredential{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Clear +// Clear deletes the provider credential stored in the given slot. +func (s *ProviderCredential) Clear(ctx context.Context, request operations.C1APILlmGatewayV1ProviderCredentialServiceClearRequest, opts ...operations.Option) (*operations.C1APILlmGatewayV1ProviderCredentialServiceClearResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/llm-gateway/provider-credentials/{slot_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.ProviderCredentialService.Clear", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "ClearProviderCredentialRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1ProviderCredentialServiceClearResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ClearProviderCredentialResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ClearProviderCredentialResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns metadata for the provider credential in the given slot. The +// +// stored API key is never returned. Returns an empty response if no +// credential has ever been set for the slot; a cleared slot returns +// FAILED_PRECONDITION. +func (s *ProviderCredential) Get(ctx context.Context, request operations.C1APILlmGatewayV1ProviderCredentialServiceGetRequest, opts ...operations.Option) (*operations.C1APILlmGatewayV1ProviderCredentialServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/llm-gateway/provider-credentials/{slot_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.ProviderCredentialService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1ProviderCredentialServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.GetProviderCredentialResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.GetProviderCredentialResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Set +// Set stores or replaces the provider API key used by the LLM gateway for +// +// the given slot. The API key is stored encrypted and is never returned by +// the API. +func (s *ProviderCredential) Set(ctx context.Context, request operations.C1APILlmGatewayV1ProviderCredentialServiceSetRequest, opts ...operations.Option) (*operations.C1APILlmGatewayV1ProviderCredentialServiceSetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/llm-gateway/provider-credentials/{slot_id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.llm_gateway.v1.ProviderCredentialService.Set", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SetProviderCredentialRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "PUT", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APILlmGatewayV1ProviderCredentialServiceSetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SetProviderCredentialResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SetProviderCredentialResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/reporting.go b/reporting.go new file mode 100644 index 000000000..d6af605da --- /dev/null +++ b/reporting.go @@ -0,0 +1,1517 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type Reporting struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newReporting(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *Reporting { + return &Reporting{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Delete +// Delete removes a report by ID. The report's saved program is removed with +// +// it, so the report can no longer be re-run. Only the report's creator can +// delete it. +func (s *Reporting) Delete(ctx context.Context, request operations.C1APIReportingV1ReportingServiceDeleteRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/reporting/reports/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "ReportingServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns a report by ID, including its latest run and latest successful +// +// run. Reports are visible only to the user who created them. +func (s *Reporting) Get(ctx context.Context, request operations.C1APIReportingV1ReportingServiceGetRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/reporting/reports/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// GetRunProvenance - Get Run Provenance +// GetRunProvenance explains a run: what it read, what its program looked at, +// +// and the program itself. A2UIService.GetSurfaceProvenance answers the same +// question for a surface, but needs a live one — and a rerun is headless, so +// a report would become less explainable every time it refreshed. +func (s *Reporting) GetRunProvenance(ctx context.Context, request operations.C1APIReportingV1ReportingServiceGetRunProvenanceRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceGetRunProvenanceResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/reporting/reports/{id}/runs/{run_id}/provenance", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.GetRunProvenance", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceGetRunProvenanceResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceGetRunProvenanceResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceGetRunProvenanceResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List returns reports created by the caller, newest first. +func (s *Reporting) List(ctx context.Context, request operations.C1APIReportingV1ReportingServiceListRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/reporting/reports") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Run +// Run re-executes the report's pinned program against today's data. It never +// +// re-plans: the commit is fixed, so a rerun can only change the numbers, not +// the question. Returns as soon as the invocation starts — see the response. +func (s *Reporting) Run(ctx context.Context, request operations.C1APIReportingV1ReportingServiceRunRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceRunResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/reporting/reports/{id}/run", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.Run", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "ReportingServiceRunRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceRunResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceRunResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceRunResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Save +// Save promotes the program behind an already-rendered reporting surface into +// +// a report. The caller identifies the surface; the server resolves which +// program produced it. There is no create-from-prompt: the prompt has already +// been answered by the time a report is worth keeping. +func (s *Reporting) Save(ctx context.Context, request *shared.ReportingServiceSaveRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceSaveResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/reporting/reports") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.Save", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceSaveResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceSaveResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceSaveResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update modifies a report's display name, prompt, or parameter values. +// +// Only the report's creator can update it. +func (s *Reporting) Update(ctx context.Context, request operations.C1APIReportingV1ReportingServiceUpdateRequest, opts ...operations.Option) (*operations.C1APIReportingV1ReportingServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/reporting/reports/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.reporting.v1.ReportingService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "ReportingServiceUpdateRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIReportingV1ReportingServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.ReportingServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.ReportingServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/roleminingmanagement.go b/roleminingmanagement.go index 64612f840..d8a71b9b6 100644 --- a/roleminingmanagement.go +++ b/roleminingmanagement.go @@ -246,8 +246,226 @@ func (s *RoleMiningManagement) CreateAccessProfileFromCohort(ctx context.Context } +// EvaluateEntitlementSelection - Evaluate Entitlement Selection +// Evaluate the exact cohort impact of an entitlement cutoff and manual overrides. +// +// The analysis determines the eligible entitlements and cohort definition. +func (s *RoleMiningManagement) EvaluateEntitlementSelection(ctx context.Context, request operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionRequest, opts ...operations.Option) (*operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/role-mining/custom-analysis/{analysis_id}/evaluate-entitlement-selection", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.role_mining_management.v1.RoleMiningManagementService.EvaluateEntitlementSelection", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "EvaluateEntitlementSelectionRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceEvaluateEntitlementSelectionResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.EvaluateEntitlementSelectionResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.EvaluateEntitlementSelectionResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + // GetCustomAnalysisResult - Get Custom Analysis Result -// Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.GetCustomAnalysisResult method. +// GetCustomAnalysisResult returns the status and results of a custom cohort +// +// analysis started with TriggerCustomAnalysis, including entitlement +// coverage, entitlement clusters, attribute facets, and cutoff impact +// points. Requires the agentic role mining feature. func (s *RoleMiningManagement) GetCustomAnalysisResult(ctx context.Context, request operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceGetCustomAnalysisResultRequest, opts ...operations.Option) (*operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceGetCustomAnalysisResultResponse, error) { o := operations.Options{} supportedOptions := []string{ @@ -2106,7 +2324,11 @@ func (s *RoleMiningManagement) TriggerAnalysis(ctx context.Context, request *sha } // TriggerCustomAnalysis - Trigger Custom Analysis -// Invokes the c1.api.role_mining_management.v1.RoleMiningManagementService.TriggerCustomAnalysis method. +// TriggerCustomAnalysis starts an asynchronous custom cohort analysis defined +// +// by the given profile filters and returns the ID of the analysis result. +// Requires the agentic role mining feature. Poll GetCustomAnalysisResult +// until the analysis completes. func (s *RoleMiningManagement) TriggerCustomAnalysis(ctx context.Context, request *shared.TriggerCustomAnalysisRequest, opts ...operations.Option) (*operations.C1APIRoleMiningManagementV1RoleMiningManagementServiceTriggerCustomAnalysisResponse, error) { o := operations.Options{} supportedOptions := []string{ diff --git a/ssoapplication.go b/ssoapplication.go new file mode 100644 index 000000000..7e3f50277 --- /dev/null +++ b/ssoapplication.go @@ -0,0 +1,3240 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type SSOApplication struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newSSOApplication(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *SSOApplication { + return &SSOApplication{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// BatchDeleteSubjectCompatibility - Batch Delete Subject Compatibility +// Deletes one bounded batch of compatibility bindings. Imported and +// +// user-attribute-derived bindings are recoverable so corrected source data +// can be applied on the next import or sign-in. Correct attribute source data +// before deleting its binding so a concurrent sign-in cannot recreate the +// stale value. +func (s *SSOApplication) BatchDeleteSubjectCompatibility(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/subjects/delete", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.BatchDeleteSubjectCompatibility", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceBatchDeleteSubjectCompatibilityRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceBatchDeleteSubjectCompatibilityResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// BatchImportSubjectCompatibility - Batch Import Subject Compatibility +// Validates or imports one bounded batch of compatibility-subject bindings. +// +// Clients parse source files and submit at most 50 rows per request so they +// can expose progress and retry from a known boundary. +func (s *SSOApplication) BatchImportSubjectCompatibility(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/subjects/import", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.BatchImportSubjectCompatibility", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceBatchImportSubjectCompatibilityRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceBatchImportSubjectCompatibilityResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceBatchImportSubjectCompatibilityResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceBatchImportSubjectCompatibilityResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Create +// Create an SSO application for an application in your catalog. The +// +// entitlement that governs sign-in is created alongside it. OIDC creation +// also server-mints the required initial client and returns its secret once +// when the client is confidential. SAML creation has no OAuth-client step. +func (s *SSOApplication) Create(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceCreateRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceCreateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.Create", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceCreateRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceCreateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceCreateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceCreateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// CreateClient - Create Client +// CreateClient mints an additional App-owned OAuth client for an OIDC +// +// application. C1 generates the client ID and any confidential-client secret. +func (s *SSOApplication) CreateClient(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceCreateClientRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceCreateClientResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/clients", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.CreateClient", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceCreateClientRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceCreateClientResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceCreateClientResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceCreateClientResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Delete +// Delete retires an SSO application and its sign-in entitlement, stopping +// +// OIDC and SAML sign-in through it. OAuth clients and locator bindings remain +// so administrators can list and delete retained clients; the bindings are +// inert while their parent application is deleted. +func (s *SSOApplication) Delete(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceDeleteRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceDeleteResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.Delete", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceDeleteRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "DELETE", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceDeleteResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceDeleteResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceDeleteResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// DeleteClient - Delete Client +// DeleteClient deletes one App-owned OAuth client and its sign-in binding. +func (s *SSOApplication) DeleteClient(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceDeleteClientRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceDeleteClientResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/clients/delete", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.DeleteClient", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceDeleteClientRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceDeleteClientResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceDeleteClientResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceDeleteClientResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Get +// Get returns a single SSO application by app_id + id. +func (s *SSOApplication) Get(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceGetRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// List +// List returns the SSO applications configured for an application, one page +// +// at a time. +func (s *SSOApplication) List(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceListRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceListResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.List", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceListResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceListResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceListResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListClients - List Clients +// ListClients returns the App-owned OAuth clients minted for an OIDC +// +// application, one page at a time. Results hydrate from the PostgreSQL +// projection, so a newly created client may appear after a brief delay. +func (s *SSOApplication) ListClients(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceListClientsRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceListClientsResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/clients", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.ListClients", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceListClientsResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceListClientsResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceListClientsResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// ListHistory returns the change history (newest first) for a single SSO +// +// application — each entry is a snapshot plus who/when metadata. +func (s *SSOApplication) ListHistory(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/history", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ParseSAMLServiceProviderMetadata - Parse Saml Service Provider Metadata +// ParseSAMLServiceProviderMetadata parses one uploaded SAML service-provider +// +// metadata document and returns the SAML configuration it implies, without +// creating or changing anything. The document is not stored. Use it to +// preview an SP's capabilities before creating a SAML application; edit the +// returned configuration before passing it to Create. Only upload or paste a +// customer-supplied document -- C1 does not fetch metadata URLs. +func (s *SSOApplication) ParseSAMLServiceProviderMetadata(ctx context.Context, request *shared.SSOApplicationServiceParseSAMLServiceProviderMetadataRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/sso/applications/saml/parse-sp-metadata") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.ParseSAMLServiceProviderMetadata", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceParseSAMLServiceProviderMetadataResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceParseSAMLServiceProviderMetadataResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// RotateClientSecret - Rotate Client Secret +// RotateClientSecret replaces a confidential App-owned client's secret and +// +// returns the new value once. The old secret stops working immediately; for +// an overlap window, create a second client, migrate, then delete the first. +// Public clients have no secret to rotate. +func (s *SSOApplication) RotateClientSecret(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceRotateClientSecretRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceRotateClientSecretResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/clients/rotate-secret", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.RotateClientSecret", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceRotateClientSecretRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceRotateClientSecretResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceRotateClientSecretResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceRotateClientSecretResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Search +// Search SSO applications across the tenant. Supports filtering by the +// +// applications in your catalog and by display-name or description text. +func (s *SSOApplication) Search(ctx context.Context, request *shared.SSOApplicationServiceSearchRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceSearchResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/search/sso/applications") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.Search", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceSearchResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceSearchResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceSearchResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update changes an SSO application's mutable display, lifetime, enablement, +// +// OIDC claim/signing settings, or SAML endpoint/signing/encryption settings. +// Protocol, subject type, sector, SAML entity ID, and NameID format remain +// immutable; requests that would change them are rejected. +func (s *SSOApplication) Update(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceUpdateRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceUpdateRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// UpdateClient - Update Client +// UpdateClient replaces mutable client configuration. The authentication +// +// method and generated ID are immutable; private-key JWKS may rotate and a +// legacy PKCE policy may tighten to required. +func (s *SSOApplication) UpdateClient(ctx context.Context, request operations.C1APISSOV1SSOApplicationServiceUpdateClientRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOApplicationServiceUpdateClientResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/apps/{app_id}/sso/applications/{id}/clients/update", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOApplicationService.UpdateClient", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "SSOApplicationServiceUpdateClientRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOApplicationServiceUpdateClientResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOApplicationServiceUpdateClientResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOApplicationServiceUpdateClientResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/ssosettings.go b/ssosettings.go new file mode 100644 index 000000000..fe40f3c37 --- /dev/null +++ b/ssosettings.go @@ -0,0 +1,662 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type SSOSettings struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newSSOSettings(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *SSOSettings { + return &SSOSettings{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// Get +// Get returns the tenant's SSO provider settings. +func (s *SSOSettings) Get(ctx context.Context, opts ...operations.Option) (*operations.C1APISSOV1SSOSettingsServiceGetResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/settings/sso") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOSettingsService.Get", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOSettingsServiceGetResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOSettingsServiceGetResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOSettingsServiceGetResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// ListHistory - List History +// ListHistory returns the SSO settings change history, newest first. +func (s *SSOSettings) ListHistory(ctx context.Context, request operations.C1APISSOV1SSOSettingsServiceListHistoryRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOSettingsServiceListHistoryResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/settings/sso/history") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOSettingsService.ListHistory", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "GET", opURL, nil) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + + if err := utils.PopulateQueryParams(ctx, req, request, nil, nil); err != nil { + return nil, fmt.Errorf("error populating query params: %w", err) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOSettingsServiceListHistoryResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOSettingsServiceListHistoryResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOSettingsServiceListHistoryResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + +// Update +// Update changes the tenant's SSO provider settings. Supply the settings +// +// object and an update mask listing the fields to change; only masked fields +// are applied. Editable paths: enabled, default_subject_type, +// default_assertion_lifetime, default_id_token_signed_response_alg. +func (s *SSOSettings) Update(ctx context.Context, request *shared.SSOSettingsServiceUpdateRequest, opts ...operations.Option) (*operations.C1APISSOV1SSOSettingsServiceUpdateResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/settings/sso") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.sso.v1.SSOSettingsService.Update", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APISSOV1SSOSettingsServiceUpdateResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.SSOSettingsServiceUpdateResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.SSOSettingsServiceUpdateResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} diff --git a/taskactions.go b/taskactions.go index d7678b102..dd1870e69 100644 --- a/taskactions.go +++ b/taskactions.go @@ -2156,6 +2156,221 @@ func (s *TaskActions) Restart(ctx context.Context, request operations.C1APITaskV } +// RetryProvisioning - Retry Provisioning +// Retry the provisioning of a task whose connector provisioning failed. Resets the +// +// failed connector actions and re-drives the connector, preserving the already-collected +// approvals. Only valid when the task's current provision step ended in an error. +func (s *TaskActions) RetryProvisioning(ctx context.Context, request operations.C1APITaskV1TaskActionsServiceRetryProvisioningRequest, opts ...operations.Option) (*operations.C1APITaskV1TaskActionsServiceRetryProvisioningResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := utils.GenerateURL(ctx, baseURL, "/api/v1/tasks/{task_id}/action/retry-provisioning", request, nil) + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.task.v1.TaskActionsService.RetryProvisioning", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "TaskActionsServiceRetryProvisioningRequest", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APITaskV1TaskActionsServiceRetryProvisioningResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.TaskServiceActionResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.TaskServiceActionResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} + // SkipStep - Skip Step // Skip a specific policy step in a task, advancing the task to the next step in the workflow. func (s *TaskActions) SkipStep(ctx context.Context, request operations.C1APITaskV1TaskActionsServiceSkipStepRequest, opts ...operations.Option) (*operations.C1APITaskV1TaskActionsServiceSkipStepResponse, error) { diff --git a/uiconversations.go b/uiconversations.go new file mode 100644 index 000000000..f5b77e58c --- /dev/null +++ b/uiconversations.go @@ -0,0 +1,246 @@ +// Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT. + +package conductoronesdkgo + +import ( + "bytes" + "context" + "fmt" + "github.com/conductorone/conductorone-sdk-go/internal/config" + "github.com/conductorone/conductorone-sdk-go/internal/hooks" + "github.com/conductorone/conductorone-sdk-go/pkg/models/operations" + "github.com/conductorone/conductorone-sdk-go/pkg/models/sdkerrors" + "github.com/conductorone/conductorone-sdk-go/pkg/models/shared" + "github.com/conductorone/conductorone-sdk-go/pkg/retry" + "github.com/conductorone/conductorone-sdk-go/pkg/utils" + "net/http" + "net/url" +) + +type UIConversations struct { + rootSDK *ConductoroneAPI + sdkConfiguration config.SDKConfiguration + hooks *hooks.Hooks +} + +func newUIConversations(rootSDK *ConductoroneAPI, sdkConfig config.SDKConfiguration, hooks *hooks.Hooks) *UIConversations { + return &UIConversations{ + rootSDK: rootSDK, + sdkConfiguration: sdkConfig, + hooks: hooks, + } +} + +// EnsureOnboardingSession - Ensure Onboarding Session +// EnsureOnboardingSession returns the tenant's active onboarding conversation, +// +// or creates and starts it once. Retries converge on the stored conversation. +func (s *UIConversations) EnsureOnboardingSession(ctx context.Context, request *shared.EnsureOnboardingSessionRequest, opts ...operations.Option) (*operations.C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse, error) { + o := operations.Options{} + supportedOptions := []string{ + operations.SupportedOptionRetries, + operations.SupportedOptionTimeout, + } + + for _, opt := range opts { + if err := opt(&o, supportedOptions...); err != nil { + return nil, fmt.Errorf("error applying option: %w", err) + } + } + + var baseURL string + if o.ServerURL == nil { + baseURL = utils.ReplaceParameters(s.sdkConfiguration.GetServerDetails()) + } else { + baseURL = *o.ServerURL + } + opURL, err := url.JoinPath(baseURL, "/api/v1/conversations/onboarding:ensure") + if err != nil { + return nil, fmt.Errorf("error generating URL: %w", err) + } + + hookCtx := hooks.HookContext{ + SDK: s.rootSDK, + SDKConfiguration: s.sdkConfiguration, + BaseURL: baseURL, + Context: ctx, + OperationID: "c1.api.conversations.v1.UIConversationsService.EnsureOnboardingSession", + OAuth2Scopes: nil, + SecuritySource: s.sdkConfiguration.Security, + } + bodyReader, reqContentType, err := utils.SerializeRequestBody(ctx, request, false, true, "Request", "json", `request:"mediaType=application/json"`) + if err != nil { + return nil, err + } + + timeout := o.Timeout + if timeout == nil { + timeout = s.sdkConfiguration.Timeout + } + + if timeout != nil { + var cancel context.CancelFunc + ctx, cancel = context.WithTimeout(ctx, *timeout) + defer cancel() + } + + req, err := http.NewRequestWithContext(ctx, "POST", opURL, bodyReader) + if err != nil { + return nil, fmt.Errorf("error creating request: %w", err) + } + req.Header.Set("Accept", "application/json") + req.Header.Set("User-Agent", s.sdkConfiguration.UserAgent) + if reqContentType != "" { + req.Header.Set("Content-Type", reqContentType) + } + + if err := utils.PopulateSecurity(ctx, req, s.sdkConfiguration.Security); err != nil { + return nil, err + } + + for k, v := range o.SetHeaders { + req.Header.Set(k, v) + } + + globalRetryConfig := s.sdkConfiguration.RetryConfig + retryConfig := o.Retries + if retryConfig == nil { + if globalRetryConfig != nil { + retryConfig = globalRetryConfig + } + } + + var httpRes *http.Response + if retryConfig != nil { + httpRes, err = utils.Retry(ctx, utils.Retries{ + Config: retryConfig, + StatusCodes: []string{ + "429", + "500", + "502", + "503", + "504", + }, + }, func() (*http.Response, error) { + if req.Body != nil && req.Body != http.NoBody && req.GetBody != nil { + copyBody, err := req.GetBody() + + if err != nil { + return nil, err + } + + req.Body = copyBody + } + + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + if retry.IsPermanentError(err) || retry.IsTemporaryError(err) { + return nil, err + } + + return nil, retry.Permanent(err) + } + + httpRes, err := s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + } + return httpRes, err + }) + + if err != nil { + return nil, err + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } else { + req, err = s.hooks.BeforeRequest(hooks.BeforeRequestContext{HookContext: hookCtx}, req) + if err != nil { + return nil, err + } + + httpRes, err = s.sdkConfiguration.Client.Do(req) + if err != nil || httpRes == nil { + if err != nil { + err = fmt.Errorf("error sending request: %w", err) + } else { + err = fmt.Errorf("error sending request: no response") + } + + _, err = s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, nil, err) + return nil, err + } else if utils.MatchStatusCodes([]string{"4XX", "5XX"}, httpRes.StatusCode) { + _httpRes, err := s.hooks.AfterError(hooks.AfterErrorContext{HookContext: hookCtx}, httpRes, nil) + if err != nil { + return nil, err + } else if _httpRes != nil { + httpRes = _httpRes + } + } else { + httpRes, err = s.hooks.AfterSuccess(hooks.AfterSuccessContext{HookContext: hookCtx}, httpRes) + if err != nil { + return nil, err + } + } + } + + res := &operations.C1APIConversationsV1UIConversationsServiceEnsureOnboardingSessionResponse{ + StatusCode: httpRes.StatusCode, + ContentType: httpRes.Header.Get("Content-Type"), + RawResponse: httpRes, + } + + switch { + case httpRes.StatusCode == 200: + switch { + case utils.MatchContentType(httpRes.Header.Get("Content-Type"), `application/json`): + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + + var out shared.EnsureOnboardingSessionResponse + if err := utils.UnmarshalJsonFromResponseBody(bytes.NewBuffer(rawBody), &out, ""); err != nil { + return nil, err + } + + res.EnsureOnboardingSessionResponse = &out + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError(fmt.Sprintf("unknown content-type received: %s", httpRes.Header.Get("Content-Type")), httpRes.StatusCode, string(rawBody), httpRes) + } + case httpRes.StatusCode >= 400 && httpRes.StatusCode < 500: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + case httpRes.StatusCode >= 500 && httpRes.StatusCode < 600: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("API error occurred", httpRes.StatusCode, string(rawBody), httpRes) + default: + rawBody, err := utils.ConsumeRawBody(httpRes) + if err != nil { + return nil, err + } + return nil, sdkerrors.NewSDKError("unknown status code returned", httpRes.StatusCode, string(rawBody), httpRes) + } + + return res, nil + +} From ab1d5865d65bcca0f34701e5d030b460772df449 Mon Sep 17 00:00:00 2001 From: "speakeasy-github[bot]" <128539517+speakeasy-github[bot]@users.noreply.github.com> Date: Tue, 1 Sep 2026 00:59:08 +0000 Subject: [PATCH 2/2] empty commit to trigger [run-tests] workflow